---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Monitor third-party risk

# Monitoring your third-party risk {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Monitoring your third-party risk

The Third-party Risk Management (TPRM) application in ServiceNow enables continuous monitoring and assessment of risks associated with third-party relationships.
It supports ongoing review of third-party performance and compliance with agreed terms, helping organizations maintain risk oversight and ensure vendor adherence to security and compliance standards.
Show full answer Show less  

## Key Features

* **Vendor Management Workspace:** Provides a centralized workspace with a vertical navigation panel for streamlined access to third-party records, assessments, dashboards, and risk reports. Designed for users with roles such as TPR manager, TPR assessor, and third-party assessment reviewer.
* **Risk Reporting and Dashboards:** Offers personalized dashboards like the Third-party insights dashboard and TPRM custom analytics dashboard for monitoring assessment data. TPR managers and assessors can create, customize, and share dashboards tailored to their risk programs.
* **Due Diligence Process Monitoring:** Tracks the status of due diligence requests, including inherent risk questionnaires, risk assessments, approval, and contract risk processes, accessible via the Due diligence request record page.
* **Management of Fourth-nth Parties:** Enables identification and management of risks related to fourth-nth parties---those dependent on primary third-party services---to ensure consistent security and compliance standards.
* **Third-party Element Monitoring:** Supports scalable scoring models, relationship analysis, and integration with due diligence workflows to aid in comprehensive risk assessments.
* **Smart Assessment Templates:** After upgrading to version 22.0.1 with Unified Content Management installed, TPR managers can access a centralized library of smart assessment templates aligned with global regulations and industry standards, which can be activated and updated within the Vendor Management Workspace.
* **Managed Activity Tracking:** Tracks managed activities related to engagements via a read-only Usage analytics activities table, helping verify activity usage and license consumption. Access requires the third-party assessment reviewer role and applicable application licenses.

## Practical Benefits for ServiceNow Customers

* Enables continuous and structured monitoring of third-party risks to enhance vendor compliance and performance oversight.
* Improves decision-making through tailored dashboards and risk reports that provide actionable insights at a glance.
* Supports compliance by monitoring due diligence processes and extending risk management to fourth-nth party relationships.
* Facilitates efficient risk assessments using smart templates aligned with industry standards and integrated workflows.
* Ensures transparent tracking of managed activities to optimize license utilization and audit readiness.  
You can monitor the potential risks that are associated with your third-party relationships by using the Third-party Risk Management application. An ongoing monitoring process can help you regularly assess the third party's performance and adherence to the agreed-upon terms.

## Ongoing monitoring and review {#tprm-monitoring-tpr__section_nfk_qrr_11c}

You can monitor and review the performance of your third parties with Vendor Management Workspace. For example, you can regularly assess whether the third party is adhering to the agreed-upon terms.  
Note:  
The Vendor Management Workspace is designed for users with the Third-party risk (TPR) manager \[sn_vdr_risk_asmt.vendor_risk_manager\], TPR assessor \[sn_vdr_risk_asmt.vendor_assessor\], and Third-party assessment reviewer \[sn_vdr_risk_asmt.vendor_assessment_reviewer\] roles.

## Viewing risk reports and other information {#tprm-monitoring-tpr__section_uht_dgw_2bc}

Starting with version 21.1.x, the legacy horizontal tab-based layout in the Vendor Management Workspace has been replaced by a structured vertical navigation panel. This design introduces:

* Grouped Related Lists: Organizes access to third-party records, assessments, and dashboards into logical sections.
* Clearer Workflows: Navigation is streamlined to support risk management processes and dependency tracking for third parties and engagements.
* Consistent Availability: The vertical panel is accessible across all internal user roles, ensuring a unified experience for managing vendor risk and resilience.

{#tprm-monitoring-tpr__ul_chm_cvw_3hc}For more information on configuring related lists, see [Configure related lists for vertical navigation on record pages](https://servicenow-prod.fluidtopics.net/1IJDvLNTZ3dtH4e7ZZXh_g "Configure the related lists that appear in the vertical navigation layout on record pages in the Vendor Management Workspace.").

You can view the risk reports for all third parties and engagements by navigating to WorkspacesVendor Management Workspace and then selecting the Risk tab to open the workspace to the home page. For more information, see [Viewing third-party risk reports](https://servicenow-prod.fluidtopics.net/2XIHmeVk6pn5dNs~iOeV7A "Use the Risk tab on the Vendor Management Workspace to access and prioritize activities such as managing your portfolio of third parties, assessing third-party risk, and completing the remediation life cycle. The workspace enables automation that reduces the manual burden and costs of risk assessment.").

You can also view the status and all current information for a third party or engagement by navigating to WorkspacesVendor Management Workspace. On the Risk tab, select the home page icon ![]().  
As shown in the following example, you can select any number in the Third-party risk overview section to open a list of third parties or engagements with that risk rating value. You can then select a third party or engagement. Figure 1. How to open a third party or engagement page by risk rating For more information, see [Get an overview of a third party](https://servicenow-prod.fluidtopics.net/40~ISDg76p0RXURuC9lhFA "Use the third party page to access all current information and status for a third party.").

## TPRM personalized dashboards {#tprm-monitoring-tpr__section_amr_rbs_4dc}

Monitor and analyze your assessment data at various levels using the Third-party insights dashboard and TPRM custom analytics dashboard. If you have the TPR manager \[sn_vdr_risk_asmt.vendor_risk_manager\] or TPR assessor \[sn_vdr_risk_asmt.vendor_assessor\] role, you can create and share
your own dashboards and reports. TPR managers can also customize report layouts, widgets, and data views to prioritize key metrics and workflows that align with your individual roles and risk programs. These dashboards
provide you and your team with tailored insights and deliver relevant information at a glance, improving your decision-making process. You can view TPRM personalized dashboards by navigating to WorkspacesVendor Management Workspace and selecting the dashboard page icon ![](). For more information, see [Monitoring assessment data using TPRM dashboards](https://servicenow-prod.fluidtopics.net/o0L8g4y0gcjOJTNxLYxbRg "You can monitor and analyze assessment data at various levels in the Third-party Risk Management application using the Third-party insights dashboard and TPRM custom analytics dashboard. These dashboards provide you and your team with tailored insights and deliver relevant information at a glance, improving your decision-making process.").

## Due diligence processes {#tprm-monitoring-tpr__section_fzd_ygw_2bc}

You can view the status of the following due diligence processes from the Due diligence request record page:

* Request process
* Inherent Risk Questionnaire (IRQ) process
* Third-party risk assessment process
* Approval process
* Contract risk process

{#tprm-monitoring-tpr__ul_ibq_3mr_11c}To access the Due diligence request record page, you can select the DDR number for any due diligence request. For more information about the due diligence process, see [Monitoring the due diligence request process](https://servicenow-prod.fluidtopics.net/VQBUvN0VMWYog1dR86_7Pw "TPR managers and TPR admins can perform a wide variety of tasks from the due diligence management dashboard. They can work on all processes in the workflow for a due diligence request: IRQs, external due diligence, approval, contract risk, and closed requests.").

## Managing fourth-nth parties {#tprm-monitoring-tpr__section_c3g_jvj_1bc}

You can use Third-party Risk Management to help identify, understand, and manage risks that are related to third parties dependent on the services of fourth-nth parties. Monitoring fourth-nth parties can help ensure that
they adhere to the same security and compliance standards as the primary third party. For more information about fourth-nth parties, see [Monitoring your fourth-nth parties](https://servicenow-prod.fluidtopics.net/c5BM4I7i3xxJQrX6HpvQ6A "You can identify and manage the third-party risks that depend on the services of the fourth-nth parties by using the Third-party Risk Management application. By monitoring your fourth-nth parties, you can help to ensure that they adhere to the same security and compliance standards as the primary third party.").

## Managing third-party elements {#tprm-monitoring-tpr__section_fn1_cnp_4bc}

You can monitor third-party elements through scalable scoring models, relationship analysis, and due diligence workflow integration as part of the third-party element collection process. Monitoring third-party elements and
leveraging that information can help with conducting more informed risk assessments as part of your third-party risk program. For more information about third-party elements, [Monitoring third-party elements](https://servicenow-prod.fluidtopics.net/Y_fxTAUDrR5N9jLlvmFTVQ "You can monitor third-party elements through scalable scoring models, relationship analysis, and due diligence workflow integration by using the Third-party Risk Management application. Monitoring third-party elements and leveraging that information can help with conducting more informed risk assessments as part of your third-party risk program.").

## Managing Smart assessment templates {#tprm-monitoring-tpr__section_qj1_5wb_23c}

After upgrading to version 22.0.1 and installing the Unified Content Management application, TPR managers \[sn_vdr_risk_asmt.vendor_risk_manager\] can view a centralized library of smart assessment templates aligned with global
regulations and industry standards. From the unified content management module in the Vendor Management Workspace you can activate and update templates. You can access the unified content module by navigating to WorkspacesVendor Management Workspace, select the unified content management icon ![]() and then navigate to Smart assessment templates. For more information, see [Managing TPRM SAE templates with Unified Content Management](https://servicenow-prod.fluidtopics.net/3JCsCssdZVRm3mAEQ3x5fg "Use Unified Content Management (UCM) as a centralized, managed repository of pre-built smart assessment templates for Third-party Risk Management. With UCM installed, TPR managers can browse, preview, and activate templates for assessments, and update templates when newer versions are released.") and [Sample questionnaires](https://servicenow-prod.fluidtopics.net/4XNa_43gXEjib4J5SvD5sQ "The questionnaire that you use can depend on your industry, geographic area, jurisdiction, or the particular nature of your operations. These questionnaires are provided as part of the base system and are samples that shouldn’t be implemented into your risk management program without first being reviewed and approved by your legal team.").

## Viewing managed activities {#tprm-monitoring-tpr__section_wj1_5rr_11c}

An engagement only consumes one license, regardless of whether there's one managed activity or many managed activities per contract year. Managed activity usage is triggered only when an activity is initiated. You can view
your managed activities for verification purposes with the Usage analytics activities \[sn_vdr_risk_asmt_ua_activity\] table. This read-only table stores a record whenever a managed activity occurs. You must have the
Third-party assessment reviewer \[sn_vdr_risk_asmt.vendor_assessment_reviewer\] role to view this table. You can access the Usage analytics activities table by navigating to AllThird Party Risk ManagementAdministrationManaged Activity Analytics. For more information, see [Tracking a managed activity](https://servicenow-prod.fluidtopics.net/HIR1QLbYcTZxcGbX9HDyqw "View managed activities in the usage analytics activities table for tracking and verification purposes in the Third-party Risk Management application.").  
Note:  
The Usage analytics activities \[sn_vdr_risk_asmt_ua_activity\] table is only available to those users that have purchased the Third-party Risk Management application and have access to the Due diligence management application. To see the instructions for downloading a GRC application from the ServiceNow® Store, see [Download a GRC application from the ServiceNow Store for the first time](https://servicenow-prod.fluidtopics.net/eYj0wRntYiS7rr7a0SPNyA "Downloading an application from the ServiceNow Store for the first time involves several easy steps. Some steps are performed on the ServiceNow Store and some in your ServiceNow AI Platform instance.").

*[\>]: and then


