---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Tracking a managed activity

# Tracking a managed activity {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Tracking a managed activity

ServiceNow's Third-party Risk Management application enables you to track and verify managed activities using theUsage analytics activities \[snvdrriskasmtuaactivity\]table.
Each engagement consumes only one license, regardless of the number of managed activities per contract year.
Managed activity usage is recorded only when an activity is initiated, excluding onboarding activities related to new third parties not yet in the Company \[corecompany\] table.
Show full answer Show less  
Managed activities include:

* Inherent Risk Questionnaires (IRQ) with status "Awaiting response"
* Tiering assessments with questionnaires sent and awaiting response
* Third-party risk assessments with questionnaires submitted to the third party
* Creation of tasks or issues related to third-party risk assessments

Automatically created assessments from event-driven management rules that are later recalled do not count as managed activities, but canceled assessments do.

## Using the Usage Analytics Activities Table

The **Usage analytics activities** table logs each occurrence of a managed activity and is read-only. Records older than two years are archived automatically. To view this table, you need the **Third-party assessment reviewer \[snvdrriskasmt.vendorassessmentreviewer\]** role. The table is accessible via:

* All \> Third Party Risk Management \> Administration \> Managed Activity Analytics

The table includes key fields such as:

* **Created:** Timestamp of the activity
* **Activity:** Reference to the related record
* **Activity type:** Types include tiering assessments, internal assessments, third-party risk assessments, issues, and tasks
* **Applies to:** Whether the activity applies to the third party or engagement
* **Third party:** The related third-party organization
* **Engagement:** The related engagement
* **Status:** Indicates if the activity is logged (Tracked) or was recalled

Note that while calculated risk scores updated by assessments are considered managed activities, these updates are not logged in the Usage analytics activities table. Similarly, risk intelligence score updates from providers are not managed activities.  
View managed activities in the usage analytics activities table for tracking and verification purposes in the Third-party Risk Management application.

## Overview of managed activities {#tprm-managed-activity__section_qsg_3tj_41c}

You can track and verify managed activities in the Usage analytics activities \[sn_vdr_risk_asmt_ua_activity\] table.

An engagement only consumes one license, regardless of whether there's one managed activity or many managed activities per contract year. Managed activity usage is triggered only when an activity is initiated.

Activities that are associated with a new third party going through the due diligence onboarding workflow aren't counted as managed activities. In this context, a new third party is defined as a company that is not in the Company
\[core_company\] table.

If any of the following activities aren't related to a new third party going through the due diligence onboarding workflow, they're counted as managed activities:

* An Inherent risk questionnaire (IRQ) that is sent by the system has a status of Awaiting response. For more information, see [Assessing your third-party risk](https://servicenow-prod.fluidtopics.net/HhMe7LKkoxctYhTzh0d5Aw "Use Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships. The information gathered from internal questionnaires, external questionnaires, and documentation requests helps you to understand the third party's risk profile, determine the appropriate risk mitigation strategies, and determine whether the third party or engagement meets all necessary compliance requirements.").
* A tiering assessment with a questionnaire that is sent by the system has a status of Awaiting response.
* A third-party risk assessment with a questionnaire that is sent by the system has a status of Submitted to third party. For more information, see [External assessment lifecycle states](https://servicenow-prod.fluidtopics.net/3_W6vz8huC7Kh8MXNb4SpQ "The process of collecting assessment data from a third party moves through several states. For example, during the Submitted to third party state, the third party responds to tasks, issues, and works to complete the questionnaires.").
* The creation of a task or issue for a third-party risk assessment. For more information, see [Create a task for a third party or engagement](https://servicenow-prod.fluidtopics.net/MPC40gMDINR66X6J3WV9wg "Create a task to help ensure that a user at your organization or the third-party contact responds to your concerns about questionnaire responses or requested documents during the due diligence process.") and [Create an issue for a third party or engagement](https://servicenow-prod.fluidtopics.net/q0ELWsPpVSo9WoEiik7hgA "Create an issue to help ensure that your concerns about a third party or engagement are remediated.").

{#tprm-managed-activity__ul_dsg_5pt_zzb}  
If a third-party risk assessment or due diligence request is automatically created by an event-driven management rule and later recalled, it isn't counted as a managed activity. An assessment that is related to an event-driven management rule can be recalled up until the time that it's submitted to the third party. For more information, see [Event-driven management --- automate assessment processes](https://servicenow-prod.fluidtopics.net/jXcmUm72N5UmKih2BmTgZg "Use the Event-driven management feature to configure rules that auto-generate and send questionnaires and doc requests to engagements and third parties. For engagements and third parties that meet the criteria you define, you specify the schedule and the assessment templates. You can automate all assessment types except onboarding.").  
Note:  
If an assessment isn't related to an event-driven management rule, you can't recall it and it's counted as a managed activity. If an assessment is canceled, it's still considered as a managed activity.

## Using the usage analytics activities table for verification {#tprm-managed-activity__section_xkq_dqj_41c}

The usage analytics activities table stores a record every time a managed activity occurs. This table is read only. Records that are two years or older are automatically archived. You must have the Third-party assessment reviewer
\[sn_vdr_risk_asmt.vendor_assessment_reviewer\] role to view this table.

You can access the Usage analytics activities table by navigating to AllThird Party Risk ManagementAdministrationManaged Activity Analytics.

The following example and table show the Usage analytics activities \[sn_vdr_risk_asmt_ua_activity\] table.
Figure 1. Usage analytics activities table  
{#tprm-managed-activity__table_tpddr__entry__2}

| Field | Description |
|-|-|
| Created | Date and time that the activity occurred. |
| Activity | Record that is related to the activity. |
| Activity type | Managed activities that can be associated with tiering assessments, internal assessments, third-party risk assessments (TPRA), issues, and tasks. |
| Applies to | * Third party: The activity applies to the parent third-party organization. * Engagement: The activity applies to the engagement. {#tprm-managed-activity__ul_dbb_pw3_2yb} |
| Third party | Third party that is related to the activity. |
| Engagement | Engagement that is related to the activity. |
| Status | State of the activity: * Tracked: The activity is logged. * Recalled: The activity was recalled by a user after it occurred. {#tprm-managed-activity__ul_t1h_dz3_vzb} |
[Table 1. Usage analytics activities]

{#tprm-managed-activity__table_tpddr}  
Note:  
The calculated risk scores that are updated by assessments are managed activities. However, they aren't logged in the Usage analytics activities \[sn_vdr_risk_asmt_ua_activity\] table. The score updates from the risk intelligence score providers aren't managed activities. For more information on the risk intelligence scores, see [Viewing risk intelligence scores](https://servicenow-prod.fluidtopics.net/dB9I4EN6DLOCjlFRsP2RvQ "For DD requests, risk intelligence scores appear in a list. For an individual third party, a card displays the most recent score or rating and a link for each risk intelligence report.").

*[\>]: and then


