---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Verifying scoring calculations using the classic assessment engine

# Verifying scoring calculations using the classic assessment engine {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Verifying scoring calculations using the classic assessment engine

This guide helps ServiceNow customers verify the accuracy and consistency of risk scoring in third-party risk questionnaires using the classic assessment engine.
It focuses on confirming that weights, normalized values, scoring methods, and risk rating scales are correctly applied to produce reliable composite scores in Third-party Risk Management.
Show full answer Show less  

## Verification Checklist

Users with **snvdrriskasmt.vendorassessor** or **snvdrriskasmt.vendormanager** roles can perform verification actions via the Vendor Management Workspace or VRM Classic interface. Key configurations to review include:

* **Scoring Method:** Ensure the correct method is selected for risk domains, criteria, and components (e.g., using Min Risk instead of Average Risk if appropriate).
* **Weights:** Check the accuracy of weights assigned to risk areas, criteria, components, and questions. Weights must be whole integers to avoid incorrect scores (e.g., use 56, not 0.56).
* **Scoring Calculations:** Validate calculations including normalized values and treatment of unanswered questions, which should be excluded from scoring. Understanding the formulas used is critical for accurate score verification.

## Viewing Risk Ratings

Risk ratings can be viewed for third parties, engagements, assessments, and questionnaires after assessments are completed and scores integrated from providers. Available rating types include:

* **Computed Risk Rating:** Overall risk for the third party post-assessment.
* **Third Party Rating:** Aggregate of all engagement ratings.
* **Engagement Risk Rating:** Based on component criteria.
* **Subsidiary Risk Rating:** Aggregate ratings of subsidiaries rolled up to parent companies.
* **Risk Intelligence Rating:** Aggregate of all provider ratings.
* **Assessment Rating:** Determined by category weights and scoring calculations.

To view these ratings, navigate through Third-party Risk Management records in ServiceNow, such as Third Parties, Engagements, Assessments, or Questionnaires, and access their respective Risk ratings related lists.

## Practical Benefits

By following this verification process, ServiceNow customers can ensure that their third-party risk assessments produce accurate and meaningful scores and risk ratings. This supports informed decision-making in vendor risk management and helps maintain a consistent, reliable risk evaluation framework.  
You can review scores and risk ratings in your questionnaires to help ensure the accuracy and consistency of risk scoring by verifying the correct application of weights, normalized values, scoring methods, and risk rating
scales. Based on the different weights you assign, Third-party Risk Management aggregates these values and produces a composite score.

## Verification checklist {#tprm-verif-q__section_rnj_vln_syb}

The \[sn_vdr_risk_asmt.vendor_assessor\] or \[sn_vdr_risk_asmt.vendor_manager\] role is required to perform all related actions by using the Vendor Management Workspace or VRM Classic user interface. For full descriptions of assessment configuration and set up, see [Classic assessment configuration](https://servicenow-prod.fluidtopics.net/gam5c858LRrJSbsFn6__1A "The TPR manager and TPR admin roles involve a broad variety of responsibilities. After the TPRM base system is set up, you configure additional settings that enable and enhance everyday risk-assessment tasks.").

Here are some of the configurations that you can check while reviewing scores and risk ratings:
{#tprm-verif-q__table_vkx_hjq_hcc__entry__2}

| Configurations | Description |
|-|-|
| Scoring method | Verify that the correct scoring method has been selected. You can select or update scoring methods for risk area domains, risk area criteria, and component criteria. For example, confirm that Min Risk is used instead of Average Risk if that aligns better with your assessment goals. For more information, see [Define a third-party risk domain](https://servicenow-prod.fluidtopics.net/lGnKWPSsb3~KWsd80CuSyg "A risk domain defines the type of risk to assess for a third party. For example, you might want to assess a data-management third party in terms of security risk and a bank in terms of financial risk. Security risk and financial risk are risk domains. Some platform applications refer to risk domains as \"risk areas.\""), [Define third-party risk area criteria](https://servicenow-prod.fluidtopics.net/~AWsDlc03Vfmwk_yz6IwWQ "A third-party risk area criteria is a group of risk domains (sometimes called risk areas in other platform features) that applies to a particular type of third party."), and [Define component criteria](https://servicenow-prod.fluidtopics.net/~F7VoYCzNt8K3yc~TcIb4w "Components are the entities for which you can assess risk (for example, subsidiaries or engagements). A component criteria is a group of components that should apply to a particular type of third party or engagement."). |
| Weights | Verify the accuracy of weights applied to risk areas, risk criteria, risk components, and questions. You can apply custom weights to reflect the importance and priority of different types of risk. Weight values for questions must be whole integers. Using decimals results in incorrect scores. For example, use 56 and not 0.56. For more information on how to assign or update weights, see [Define a third-party risk domain](https://servicenow-prod.fluidtopics.net/lGnKWPSsb3~KWsd80CuSyg "A risk domain defines the type of risk to assess for a third party. For example, you might want to assess a data-management third party in terms of security risk and a bank in terms of financial risk. Security risk and financial risk are risk domains. Some platform applications refer to risk domains as \"risk areas.\""), [Define third-party risk area criteria](https://servicenow-prod.fluidtopics.net/~AWsDlc03Vfmwk_yz6IwWQ "A third-party risk area criteria is a group of risk domains (sometimes called risk areas in other platform features) that applies to a particular type of third party."), [Define component criteria](https://servicenow-prod.fluidtopics.net/~F7VoYCzNt8K3yc~TcIb4w "Components are the entities for which you can assess risk (for example, subsidiaries or engagements). A component criteria is a group of components that should apply to a particular type of third party or engagement."), and [Define a question](https://servicenow-prod.fluidtopics.net/IeKMOnbtbUVXX7jYEeMdXg "After you add a question to a question bank, you can reuse it in any assessment by dropping it into the assessment. You can create custom questions, add existing questions, or add and customize the sample questions that are included with the base system."). |
| Scoring calculations | Verify that calculations, normalized values, and unanswered questions are behaving as expected. For example, confirm that you're accounting for unanswered questions not being included as part of the scoring calculation. For information on the different formulas used to calculate scores and ratings, see [Scoring calculations using the classic assessment engine](https://servicenow-prod.fluidtopics.net/K5hALopCdDX2LbdeHv06EQ "Perform a comprehensive external risk assessment when calculating multiple ratings and scores by using the Third-party Risk Management application. You can gain a deeper understanding of the overall calculation process and learn how user-defined parameters and configurations influence the results of the questionnaires."). For information on how to use normalized values to calculate assessment scores for Choice or Multiple Selection questions with the scored check box not selected [Normalize the scores for metrics](https://servicenow-prod.fluidtopics.net/UFoxtF8n6eNjWVL~1WyQhw "You can use the Maximum normalization input setting to use normalized values to calculate assessment scores for questions (metrics)."). |
[Table 1. Checklist items]

{#tprm-verif-q__table_vkx_hjq_hcc}

## How to view risk ratings {#tprm-verif-q__section_txk_ty2_3cc}

You can view risk ratings for individual third parties, engagements, assessments, and questionnaires.  
The following risk ratings are available to view.

* Computed risk rating: The overall risk rating for the third party, calculated after the assessment.
* Third party rating: An aggregate of all engagement ratings.
* Engagement risk rating: Determined by the component criteria
* Subsidiary risk rating: If company1 has company2 and company3 as subsidiaries, the aggregate of final ratings on company2 and company3 are the subsidiary ratings on company1.
* Risk intelligence rating: Aggregate of all provider ratings.
* Assessment rating: Determined by weights defined by category, calculations, and more.

{#tprm-verif-q__ul_drq_ttj_y1c}  
Note:  
Risk ratings and scores are only available to view after assessments have been completed and scores have been integrated from a provider.  
You can view all associated ratings for a third party by navigating to its Risk ratings related list. Navigate to AllThird-party Risk ManagementThird PartiesAll Third Parties and select the third party you want. The following example shows you can view all available risk ratings as well as the Third-party risk components, Third-party risk areas, Assessments, Tiering assessments, Repeating assessments related lists, and more.Figure 1. Example of a third-party record  
You can view all associated ratings for an engagement by navigating to its Risk ratings related list. Navigate to AllThird-party Risk ManagementEngagementsAll Engagements and select the engagement you want. The following example shows you can view all available risk ratings as well as the Engagement risk components, Third-party risk areas, Assessments, Tiering assessments, Repeating assessments related lists, and more.Figure 2. Example of an engagement record  
You can view all associated ratings for an assessment by navigating to its Risk ratings related list. Navigate to AllThird-party Risk ManagementExternal Risk AssessmentsAll Assessments and then select the assessment you want. The following example shows you can view all available risk ratings as well as the Third-party risk areas, Questionnaires, Document requests, Downstream supplier related lists, and more.Figure 3. Example of assessment record  
You can view all associated ratings for a questionnaire by navigating to its Risk ratings list. After navigating to an assessment, select the questionnaire you want to view. The following example shows you can view all available risk ratings, risk scores, and more.Figure 4. Example of a questionnaire record

*[\>]: and then


