---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Request SBOM

# Request a software bill of materials from an engagement {#ariaid-title1}

* Release version: Australia
* 
* Updated May 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Turn on SBOM collection on a due diligence request and send the external assessment to collect SBOM data from an engagement contact.

## Before you begin

* Confirm that the following applications are installed for SBOM file collection:
  * SBOM Core (sn_sbom_core)
  * Data Model for SBOM (sn_sbom_dm)
* If your organization requires vulnerability details for SBOM components, confirm that the following additional applications are installed:
  * SBOM Response (sn_sbom_resp)
  * Vulnerability Response (sn_vul)

  For more information see, [Activate SBOM support](https://servicenow-prod.fluidtopics.net/DNVHdQMYI_hGoTSiXmMM9w "Install the required applications and verify prerequisites to enable SBOM collection in Third-party Risk Management (TPRM).").
* Confirm that the engagement uses the Smart Assessment Engine. SBOM collection isn't supported for Classic assessments.
* Inform the engagement contact that they will receive an external assessment requesting an SBOM file in JSON or XML format. The third party generates this file using their own tooling. The ServiceNow platform does not create or edit SBOM files.

Important:  
Depending on your entitlements, some SBOM capabilities require additional configuration. For more information, see [Activate SBOM support](https://servicenow-prod.fluidtopics.net/DNVHdQMYI_hGoTSiXmMM9w "Install the required applications and verify prerequisites to enable SBOM collection in Third-party Risk Management (TPRM).").

Role required: sn_vdr_risk_asmt.vendor_risk_manager or sn_vdr_risk_asmt.vendor_risk_assessor

## About this task


SBOM collection uses the standard third-party
due diligence workflow and does not change onboarding or IRQ processes.

The engagement-level external assessment is the mechanism through which SBOM information is collected.

## Procedure

1. Turn on SBOM collection for the engagement.

   | Option | Steps |
   | New due diligence request | 1. Initiate the due diligence request. 2. Select SBOM required. 3. Complete the request. For details, see [Request due diligence for a third-party engagement](https://servicenow-prod.fluidtopics.net/hXoICdC6yfzFH8EhkMI1OQ "Request due diligence to assess the risk that is associated with doing business with an engagement. By conducting due diligence, you gain access to the most up-to-date, comprehensive, and accurate information before making a decision on entering into a business relationship."). |
   | Existing due diligence request | 1. Open the due diligence request. 2. Select SBOM required. 3. Save the record. |
   |-|-|

   {#tprm-sbom-collect__tprm-sbom-request-step-enable}
{#tprm-sbom-collect__tprm-sbom-request-step-enable}
2. Send the external assessment to request the SBOM.
   1. Complete the Request, IRQ, and third-party element steps (if applicable), to advance the engagement to the due diligence process.  
      The system associates the SBOM questionnaire with the engagement's external assessment.
   2. Send the external assessment to the engagement contact.  
      The engagement contact receives the assessment through the third-party portal.
   {#tprm-sbom-collect__tprm-sbom-request-step-send}
{#tprm-sbom-collect__tprm-sbom-request-step-send}

## What to do next


After the external assessment is submitted, review the submission outcome.
For details, see [Review an SBOM submission from an engagement](https://servicenow-prod.fluidtopics.net/jG3yj_LCt3V0evQEVR89Yg "Track processing status and review the outcome of a SBOM submission from an engagement, including successful upload, failed upload, and decline.").
**Related concepts**   

* [Exploring software bill of materials collection](https://servicenow-prod.fluidtopics.net/D5HKQ8~8LGj40YZyW_mXww "Third-party Risk Management (TPRM) collects software bill of materials (SBOM) files through engagement-level due diligence. This topic covers the users and workflow involved.")
* [Collecting software bill of materials](https://servicenow-prod.fluidtopics.net/tKBQ5MvyeX~S5Dq2WfvExQ "A software bill of materials provides an inventory of the components, libraries, and dependencies included in a vendor's software. Third-party Risk Management (TPRM) supports collecting SBOM files as part of the due diligence process.")  
**Related tasks**   

* [Activate SBOM support](https://servicenow-prod.fluidtopics.net/DNVHdQMYI_hGoTSiXmMM9w "Install the required applications and verify prerequisites to enable SBOM collection in Third-party Risk Management (TPRM).")
* [Review an SBOM submission from an engagement](https://servicenow-prod.fluidtopics.net/jG3yj_LCt3V0evQEVR89Yg "Track processing status and review the outcome of a SBOM submission from an engagement, including successful upload, failed upload, and decline.")  
**Related reference**   

* [SBOM records and relationships in Third-party Risk Management](https://servicenow-prod.fluidtopics.net/9ycIyON5lxlYjnJWbhXaKQ "The records, related lists, and relationships created when you collect SBOM data in Third-party Risk Management, and how those records relate to engagements and third parties.")

