---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Smart Assessment Engine assessments

# Smart assessment configuration {#ariaid-title1}

* Release version: Australia
* 
* Updated May 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 8 minutes to read

The TPR manager and TPR admin roles involve a broad variety of responsibilities. After the TPRM
base system is set up, you configure Smart Assessment Engine specific settings as well as other assessment settings that enable and enhance everyday risk-assessment tasks. TPRM admins can enable SAE and work with SAE templates.

## Assessment setup overview {#tprm-sae-assessment-config__section_mk2_bc1_3cc}

By performing the tasks in the Assessment setup checklist for TPRM, you're setting up and configuring the TPRM application to address your unique requirements for scoring and assessing risk for third parties, engagements, and other entities using the Smart Assessment Engine for TPRM assessments.  
Note:  
For any custom messages you create, it is your responsibility to generate the corresponding `sys_ui_message` records. This step is crucial if you want the custom messages to be extracted and translated.

## Assessment setup checklist for Smart Assessment Engine integration with TPRM {#tprm-sae-assessment-config__section_u4n_rsx_hcc}

{#tprm-sae-assessment-config__table_fc1_vsx_hcc__entry__2}

| Task | Description |
|-|-|
| Set Smart Assessment Engine enabled \[sn_vdr_risk_asmt.sae_enabled\] property. | After setting this property, SAE becomes the default assessment engine and replaces the legacy experience. Warning: After this option is enabled, this selection can't be reversed. For more information, see [Configure TPRM properties](https://servicenow-prod.fluidtopics.net/9lJM8SW1APiGqRwL7gM6Zg "Configure property settings for a variety of TPRM operations.") and [Migrating from Classic Assessment Engine to Smart Assessment Engine](https://servicenow-prod.fluidtopics.net/_IFNHdAAg~lR1jG6oNNjLQ "Learn what changes when you migrate from the Classic Assessment Engine to the Smart Assessment Engine, including feature differences, limitations, and setup requirements. This overview can help you and your team evaluate the impact before enabling the new engine."). Role required: sn_vdr_risk_asmt.vendor_risk_admin |
| Migrate questionnaire templates. | This task is optional. You can migrate existing questionnaire or document request templates to an SAE template. Note: If you're setting up assessments for TPRM for the first time, you don't need to complete this task. For more information, see [Migrating from Classic Assessment Engine to Smart Assessment Engine](https://servicenow-prod.fluidtopics.net/_IFNHdAAg~lR1jG6oNNjLQ "Learn what changes when you migrate from the Classic Assessment Engine to the Smart Assessment Engine, including feature differences, limitations, and setup requirements. This overview can help you and your team evaluate the impact before enabling the new engine."), [Migrate a template to an SAE template](https://servicenow-prod.fluidtopics.net/77LBemuP2fHAvSZIVdM5Sw "Migrate an existing questionnaire or document request template to a TPRM SAE questionnaire template. You must migrate all classic templates to TPRM SAE templates or create new ones before you can use SAE in TPRM."), [Results of migrating a template to a TPRM SAE template](https://servicenow-prod.fluidtopics.net/AVS3tLqazNbXD299QuHVbQ "You can view the templates that were migrated to Smart Assessment format."), and [How legacy metric types are migrated to sections in templates](https://servicenow-prod.fluidtopics.net/CWCw4ad5bxJGyiQCEnFMyA "Legacy metric types are migrated to specific sections in the assessment templates in the Smart Assessment Engine application."). Role required: sn_vdr_risk_asmt.vendor_risk_admin |
| Update assessment templates and issue generation rules. | This task is optional. Add published SAE questionnaire templates to all related assessment templates and Issue generation rules. For more information, see [Create an external assessment template](https://servicenow-prod.fluidtopics.net/IwU0fCVVzYP7MjHOsvWDaw "When defining an assessment template, the third-party risk manager provides scheduling information for the third-party risk assessment.") and [Create an issue generation rule](https://servicenow-prod.fluidtopics.net/mc3UH~l8AlOJETYSLDjH2w "Create an issue generation rule that will automatically create an issue based on question responses to external assessments. Issues help ensure that your concerns about a third party or engagement are remediated."). Note: If assessment templates aren't updated to be compatible with SAE templates, tier-based, provider-based, issue generation, and event-driven management rules won't run as expected. Role required: sn_vdr_risk_asmt.vendor_risk_admin |
| Create post assessment impact automation rules. | This task is optional. Configure automation rules that trigger impact actions after an assessment is completed. These rules can initiate workflows such as risk mitigation, notifications, or updates to related records based on assessment outcomes. Plugin Dependency: Smart Assessment Post-assessment Actions (com.sn_impact_fwk and com.sn_smart_imp_auto). Access vendor risk assessment configurations, including automation rule setup and impact framework integration. Rules are asynchronous and can be tailored to specific assessment types or risk thresholds. Role required: sn_vdr_risk_asmt.vendor_risk_admin |
| Create response automation rules. | This task is optional. Enable automatic responses for assessments based on predefined conditions. For example, if a vendor scores below a certain threshold, the system can auto-generate follow-up actions or flag the record for review. Plugin Dependency: Smart Response Automation (com.sn_smart_resp_auto) Configure response logic and manage automation settings within the Smart Assessment Engine. Rules can be configured using templates and conditions based on scoring, risk levels, or assessment responses. Role required: sn_vdr_risk_asmt.vendor_risk_admin |
| Set up risk rating scales for scoring assessments and questionnaires. | This task is required for the initial setup of TPRM. You can configure the risk rating scale that is selected by default for all questionnaires. For more information, see [Set up risk rating scales for scoring](https://servicenow-prod.fluidtopics.net/rWk79zC~4SwwIybHPumZhA "The risk rating scale helps business users better understand risk assessment results. For example, in the default settings, risk scores in the 20 through 39 range indicate high risk, while scores in the 60 through 79 range indicate low risk."). Role required: admin or sn_vdr_risk_asmt.vendor_risk_manager |
| Set up third-party risk domains or areas. | This task is required for the initial setup of TPRM. You can configure the scoring method and weight that is selected by default for all third parties associated with a specific risk area. For more information, see [Define a third-party risk domain](https://servicenow-prod.fluidtopics.net/lGnKWPSsb3~KWsd80CuSyg "A risk domain defines the type of risk to assess for a third party. For example, you might want to assess a data-management third party in terms of security risk and a bank in terms of financial risk. Security risk and financial risk are risk domains. Some platform applications refer to risk domains as \"risk areas.\""). Role required: sn_vdr_risk_asmt.vendor_risk_manager |
| Set up third-party risk area criteria, which are the group of risk domains or areas that apply to a type of third party. | This task is required for the initial setup of TPRM. You can adjust the weight and scoring method of each risk area within a criteria definition. For more information, see [Define third-party risk area criteria](https://servicenow-prod.fluidtopics.net/~AWsDlc03Vfmwk_yz6IwWQ "A third-party risk area criteria is a group of risk domains (sometimes called risk areas in other platform features) that applies to a particular type of third party."). Role required: sn_vdr_risk_asmt.vendor_risk_manager |
| Set up third party and engagement component criteria. | This task is required for the initial setup of TPRM. Components are entities that can be assessed for risk. Component criteria are groups of components that are related to a particular type of third party or engagement. You can't add new components or modify existing ones. You can, however, define the criteria (in terms of scoring method and weight) to be used to assess the components. You can update the Default scoring method to specify how multiple scores for each risk area are calculated. You can use the Default weight to adjust the weight of third-party provider scores in the third party's overall risk rating. The following component classifications are available. * Third-party components * Third-party risk assessments (External risk assessments) * Subsidiaries * Engagements * Risk intelligence rating {#tprm-sae-assessment-config__ul_npf_wtw_xbc} * Engagement components * Engagement risk assessments * Product * Principal * Facility * Other {#tprm-sae-assessment-config__ul_c3g_ytw_xbc} {#tprm-sae-assessment-config__ul_sq2_dv2_jlb} For more information on setting up component criteria, see [Define component criteria](https://servicenow-prod.fluidtopics.net/~F7VoYCzNt8K3yc~TcIb4w "Components are the entities for which you can assess risk (for example, subsidiaries or engagements). A component criteria is a group of components that should apply to a particular type of third party or engagement."). For more information on how engagement components impact third-party elements, see [Monitoring third-party elements](https://servicenow-prod.fluidtopics.net/Y_fxTAUDrR5N9jLlvmFTVQ "You can monitor third-party elements through scalable scoring models, relationship analysis, and due diligence workflow integration by using the Third-party Risk Management application. Monitoring third-party elements and leveraging that information can help with conducting more informed risk assessments as part of your third-party risk program."). Role required: sn_vdr_risk_asmt.vendor_risk_manager |
| Set up third-party and engagement risk scoring rules. | This task is required for the initial setup of TPRM. Define the criteria, based on risk scores, that determine which third parties or engagements require assessments. Third-party risk scoring rules apply to subsidiaries, engagements, and third-party risk areas. Engagement risk scoring rules only apply to engagements. For more information, see [Define third-party risk scoring rules](https://servicenow-prod.fluidtopics.net/zPOrOsgp2jTF9RQmj~~ifg "Define criteria, based on risk scores, that determine which third parties require assessments. Third-party risk scoring rules apply to subsidiaries and engagements and to third-party risk areas.") and [Define engagement risk scoring rules](https://servicenow-prod.fluidtopics.net/E~dY6oWW8Bkz~1A1~jECSw "An engagement risk-scoring rule specifies component criteria that determine which engagements are selected for assessment. For example, a rule could enable assessments for engagements that involve more than $40,000 annual business. Engagement scoring rules apply only to engagements."). Role required: sn_vdr_risk_asmt.vendor_risk_manager |
| Create questionnaire or document request templates. | This task is required for the initial setup of TPRM. You can reuse questionnaire templates and document-request templates to streamline the creation of new questionnaires and document requests. The following template purposes (classifications) are available. * TPRM external 3rd-party element questionnaire * TPRM external 4th-party questionnaire * TPRM external document request * TPRM external questionnaire * TPRM internal IRQ * TPRM internal tiering questionnaire {#tprm-sae-assessment-config__ul_chn_fwh_gfc} Note: Only use the available template purposes. Creating custom purposes (categories or classifications) will cause SAE assessments to fail during m2m linkage processing. When creating or migrating SAE questionnaire templates, make sure the Purpose field is set to one of the supported categories only. For more information, see [Create a TPRM SAE questionnaire or document request template](https://servicenow-prod.fluidtopics.net/KdjQDs99~QJX2ZasxlJO~w "Create a TPRM SAE questionnaire or document request template that supports SAE for risk identification. After integrating SAE, new users must create SAE templates, and existing users can create additional templates after migrating their existing ones."). Role required: sn_vdr_risk_asmt.vendor_risk_admin |
| Create assessment templates for external questionnaires. | This task is required for the initial setup of TPRM. You can create an assessment template with set duration requirements and questionnaires attached by default to help streamline the assessment process for different types of third parties and engagements. For more information, see [Create an external assessment template](https://servicenow-prod.fluidtopics.net/IwU0fCVVzYP7MjHOsvWDaw "When defining an assessment template, the third-party risk manager provides scheduling information for the third-party risk assessment."). Role required: admin or sn_vdr_risk_asmt.vendor_risk_manager |
| Create issue generation rules. | This task is optional. Set up rules that auto-generate issues for external assessments. Specify a Third-party risk assessment, a Questionnaire template, and the Questions to apply the rule to, as well as an Issue template and a Task template to use while generating it. For more information on setting up these rules, see [Create an issue generation rule](https://servicenow-prod.fluidtopics.net/mc3UH~l8AlOJETYSLDjH2w "Create an issue generation rule that will automatically create an issue based on question responses to external assessments. Issues help ensure that your concerns about a third party or engagement are remediated."). Role required: admin or sn_vdr_risk_asmt.vendor_risk_admin |
| Set up event-driven management rules. | This task is optional. Set up rules that auto-generate and send questionnaires and doc requests to engagements and third parties. For engagements and third parties that meet the criteria you define, you specify the schedule and the assessment templates. You can automate all request types except onboarding. For more information on setting up these rules, see [Event-driven management --- automate assessment processes](https://servicenow-prod.fluidtopics.net/jXcmUm72N5UmKih2BmTgZg "Use the Event-driven management feature to configure rules that auto-generate and send questionnaires and doc requests to engagements and third parties. For engagements and third parties that meet the criteria you define, you specify the schedule and the assessment templates. You can automate all assessment types except onboarding."). Note: The Event-driven management rules feature is the default option for scheduling assessments and replaces Recurring assessments. Role required: sn_vdr_risk_asmt.vendor_risk_manager |
| Set up scoring for questionnaires. | This task is required for the initial setup of TPRM. You can configure how questionnaires and document requests are scored. For more information, see [Configure scoring for an assessment](https://servicenow-prod.fluidtopics.net/tmcbN7_myQlZu~Z5QAb9vg "Set up scoring for your assessment responses to calculate meaningful scores at the assessment, section, or subsection level."), [Normalization in assessment](https://servicenow-prod.fluidtopics.net/nwVNpasbKaGfv5cutjni7w "Normalization in Smart Assessment Engine refers to adjusting assessment question scores to a common scale to promote fair comparison and prioritization."), and[Configure normalization in assessment](https://servicenow-prod.fluidtopics.net/MPmA4y2Nay4y~vPnS7M6Kw "In Smart Assessment Engine, set up normalization to adjust assessment response scores to a common scale at the assessment, section, or subsection level."). Role required: sn_vdr_risk_asmt.vendor_risk_admin |
| Set up Unified Content Management | This task is optional. Install the Unified Content Management application. If you have the TPR manager \[sn_vdr_risk_asmt.vendor_risk_manager\] role you can access and update Smart Assessment Engine templates from the Unified Content Management page in the Vendor Management Workspace. The UCM application serves as a starter template library, providing ready-to-use SAE templates for TPRM assessments, including SIG Full, SIG Core, and SIG Lite templates for 2026. You can view available templates, and activate or update template versions for use in TPRM assessments. For more information, see [Managing TPRM SAE templates with Unified Content Management](https://servicenow-prod.fluidtopics.net/3JCsCssdZVRm3mAEQ3x5fg "Use Unified Content Management (UCM) as a centralized, managed repository of pre-built smart assessment templates for Third-party Risk Management. With UCM installed, TPR managers can browse, preview, and activate templates for assessments, and update templates when newer versions are released."), [Activate or update Smart Assessment templates](https://servicenow-prod.fluidtopics.net/p8PCvdnhKjj4lRJ8tWSo5Q "Manage SAE templates for TPRM from the Unified Content Management page in the Vendor Management Workspace. You can view available templates, select template versions, activate or update templates for use in Third-party Risk Management assessments, and update templates when newer versions are released."), and [Using the SIG questionnaire for a risk assessment](https://servicenow-prod.fluidtopics.net/_PAntfWX755MlsrKV8ez_Q "Third parties can use the Shared Assessments Standardized Information Gathering questionnaire (SIG) to provide assessment documentation in the Third-party Risk Management application. The third-party contact can upload the pre-filled SIG spreadsheet or respond to a form-based questionnaire that is imported to the instance."). Role required: sn_vdr_risk_asmt.vendor_risk_admin |
| Manage Smart Assessment template versions | This task is optional. SAE template versioning uses a deep copy approach: each version is a full copy of the template. When you publish a new version, the previously published version is automatically retired. Retired versions remain visible but cannot be used for new assessments. Template versions can also be deleted. To create a new version, use the Create Version action on the template record in the Vendor Management Workspace. Editing a published template in place is no longer supported. Role required: sn_vdr_risk_asmt.vendor_risk_admin |
| Set up Smart Assessment Response Assist skill | This task is optional. Set up the Smart Assessment Response Assist skill to generate initial draft responses from vendor documents and previously completed assessments. The skill works at the template category level. Install ServiceNow Otto for Smart Assessment Engine (SAE) and activate the Smart Assessment Response Assist skill, then configure template categories for document-assisted drafting in TPRM. For more information, see [Activate Smart Assessment response assist skill](https://servicenow-prod.fluidtopics.net/QlrhjFjPBCcMWW_ZktS36Q "Activate and configure the Smart Assessment response assist skill in ServiceNow Otto. The skill automatically drafts responses for assessment questionnaires by using previously answered questions and supporting documents to improve accuracy and consistency.") and [Configure AI-assisted questionnaire pre-fill for TPRM](https://servicenow-prod.fluidtopics.net/6~cuAhQtimBCFk5SqHOFFw "Turn on AI-assisted questionnaire pre-fill for a smart assessment template category by selecting the Is AI response enabled check box."). |
| Activate Software Bill of Materials (SBOM) support. | Install and activate the required SBOM applications to enable SBOM collection in TPRM. SBOM information is collected using engagement-level external assessments and requires the Smart Assessment Engine. At a minimum, activate the following applications: * SBOM Core (`sn_sbom_core`) * Data Model for SBOM (`sn_sbom_dm`) To include vulnerability insights for SBOM components, also activate SBOM Response and Vulnerability Response. After activation, verify that SBOM fields and related lists are available on engagement records. For more information, see [Activate SBOM support](https://servicenow-prod.fluidtopics.net/DNVHdQMYI_hGoTSiXmMM9w "Install the required applications and verify prerequisites to enable SBOM collection in Third-party Risk Management (TPRM)."). Role required: admin |
[Table 1. Setup tasks for assessments and questionnaires]

{#tprm-sae-assessment-config__table_fc1_vsx_hcc}

