---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Third-party (external) risk assessment management

# Third-party (external) risk assessment management {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Third-party (external) risk assessment management

Third-party (external) risk assessment management in ServiceNow enables you to efficiently manage risk assessments for third-party organizations following the completion of the Initial Risk Questionnaire (IRQ) process.
This process involves sending questionnaires and document requests to third-party contacts and collaborating to ensure responses are complete and accurate.
The platform provides a structured workflow and tools to track, communicate, and manage these assessments within the Due Diligence Management module.
Show full answer Show less  

## Key Features

* **Accessing External Assessments:** View all third-party risk assessments linked to engagement due diligence requests via the External Assessments tab on the Due Diligence Management page.
* **Unique Risk Assessment IDs:** Each external risk assessment is assigned a unique VRA number, which helps track assessments for third-party organizations or sub-groups within parent organizations.
* **Comprehensive Tabs to Manage Assessments:**
  * **Risk Overview:** Displays the status of assessments, associated questionnaires, document requests, and fourth-party engagements.
  * **Details:** Provides general information about the third party, schedules, and an activity log for communications and updates.
  * **Questionnaire and Document Templates:** Lists questionnaires and document requests sent to third parties, with options to configure permissions for assessors to modify responses.
  * **Fourth-party Templates:** Manages questionnaires related to fourth parties and their sub-parties.
  * **Third-party Risk Areas:** Defines risk domains (e.g., security risk, financial risk) applicable to different third parties.
  * **Issues and Tasks Management:** Enables creating, assigning, and tracking non-compliance issues and tasks during the assessment lifecycle, with communication facilitated through comments.
* **Lifecycle State Tracking:** The assessment process moves through defined lifecycle states, such as "Submitted to third party," to monitor progress and completion.
* **Template and Form Creation:** Allows third-party risk administrators and managers to create and manage questionnaire templates, assessment templates, and tasks using tailored forms within the Third-party Risk Management application.
* **Communication and Collaboration Tools:** Features such as the Discuss action and activity logs support transparent communication and record-keeping between internal users and third-party contacts.

## Practical Benefits for ServiceNow Customers

* Streamlines the third-party risk assessment process by centralizing engagement requests, questionnaires, documents, and communications in one interface.
* Enhances collaboration with third-party contacts to ensure timely and accurate submission of risk-related information.
* Improves risk management through structured tracking of issues, tasks, and risk domains tailored to the nature of the third party.
* Enables efficient monitoring of assessment progress via lifecycle states and assessment metrics.
* Supports customization and flexibility by allowing configuration of assessor permissions and creation of tailored questionnaires and templates aligned with organizational risk domains.

## Next Steps

To effectively leverage this functionality, ServiceNow customers should familiarize themselves with creating and managing questionnaire and document request templates, defining third-party risk domains, and managing issues and tasks related to third-party assessments. Administrators and risk managers can use the provided forms to create and customize assessments and tasks to fit their organizational requirements.  
After the IRQ process is complete, you send questionnaires and document requests to the third-party contact. You manage the third-party risk assessment by working with the contacts to help ensure that the responses are complete and accurate.

## Accessing an external assessment {#tprm-ws-dd-mgt-pg-extrnl-assessment__section_kgf_qvt_2yb}

On the Due diligence management page, select the DDR number for any engagement due diligence request and the select the External assessments tab. The tab displays the list of
all third-party risk assessments (external due diligence processes) for the selected engagement request.

## Working on a third-party risk assessment {#tprm-ws-dd-mgt-pg-extrnl-assessment__id_qxg_2xw_fyb}

For each external risk assessment, the system auto-assigns a unique ID number that starts with the text VRA. A risk assessment can represent the work on an engagement request for a third-party organization or an engagement request for a group within the parent organization.
Select a VRA number to work on the risk assessment on the External assessments tab.

## Actions on any tab {#tprm-ws-dd-mgt-pg-extrnl-assessment__section_m1m_51j_fyb}

{#tprm-ws-dd-mgt-pg-extrnl-assessment__table_dld_1dt_fyb__entry__2}

| Action | Description |
|-|-|
| Discuss | Select Discuss to send a message to other users. The message is recorded in the Activity section of the Details tab. |
| Create | Create an issue or task as describe in the following sections. |
| Save | Select Save to save any change you made to a value on any tab. |
| Submit to third party | Submit all questionnaires and document requests to the TP contact. The action is recorded in the Activity section on the Details tab. |
| ... Delete | Select Delete to delete the record of the engagement request. |
| Adding an attachment | Select Browse in the Attachments section or select the attachment icon to select and add an attachment. |
[Table 1. Actions]

{#tprm-ws-dd-mgt-pg-extrnl-assessment__table_dld_1dt_fyb}

## Working on third-party risk assessments {#tprm-ws-dd-mgt-pg-extrnl-assessment__section_k2k_3vt_2yb}

Risk overview tab on the External assessments page
:
    * The symbols indicate the current state of the external assessment process for the engagement request. See [External assessment lifecycle states](https://servicenow-prod.fluidtopics.net/3_W6vz8huC7Kh8MXNb4SpQ "The process of collecting assessment data from a third party moves through several states. For example, during the Submitted to third party state, the third party responds to tasks, issues, and works to complete the questionnaires.") for descriptions of the states.

    * Overview section: List of assessments that are associated with the engagement.
    * Questionnaires and document requests section: List of questionnaires and document requests for the engagement.
    * Fourth-party questionnaires section: List of questionnaires and document requests for fourth parties and their sub-parties that are associated with the engagement.
    * Tracking section: Count of assessments associated with the third party that are in the Open, Overdue, and Closed status.
    {#tprm-ws-dd-mgt-pg-extrnl-assessment__ul_xxl_opj_fyb}

Details tab on the External assessments page
:
    * Third-party risk assessment section: General information on the third party plus schedules for the overall assessment and questionnaire due dates from the engagement due diligence request.
    * The Compose section on the Details tab enables you to permanently add text to the record. The Activity section is updated with any actions on issues and tasks, submissions to TP contacts, and also with work notes and comments that users add to the record. Add text in the following fields as needed:
      * Work notes (Private): Information about the third-party risk assessment. Work notes are visible only to internal users who are assigned to the process.
      * Comments: Comments about the third-party risk assessment are visible both to internal users and to third-party contacts.
      {#tprm-ws-dd-mgt-pg-extrnl-assessment__ul_g1d_3kn_cqb}
    {#tprm-ws-dd-mgt-pg-extrnl-assessment__ul_exr_x2n_2yb}

Questionnaire templates tab on the External assessments page
:   The tab lists the questionnaires that the third-party contact will respond to. Select a name to view the details. For more information, see [Create a questionnaire or document request template](https://servicenow-prod.fluidtopics.net/jcT0RLyAjHfX1dxaHkfdRg "You can reuse questionnaire templates and document-request templates to speed up the creation of new questionnaires and document requests.") and [Create a questionnaire or document request template using the Designer](https://servicenow-prod.fluidtopics.net/wkjLFNCaqkOct3DQLATAuw "Use the Questionnaire Template Designer to create and edit questionnaire or document request templates that you can use as the basis for other templates.").  
    To enable TPR assessors to modify responses, configure the Allow TPR assessors to modify responses in third-party questionnaires \[`sn_svdp.allow_assessor_edit`\] system property. You can set the following options:

    * Enable TPR assessors to answer questions or modify responses (default)
    * Enable TPR assessors to modify responses
    * Do not enable TPR assessors to answer questions or modify responses

    {#tprm-ws-dd-mgt-pg-extrnl-assessment__ul_at3_m1f_zyb}See [Configure TPRM properties](https://servicenow-prod.fluidtopics.net/9lJM8SW1APiGqRwL7gM6Zg "Configure property settings for a variety of TPRM operations.").

Document templates tab on the External assessments page
:   The tab lists the requests for documents that the third-party contact should return. The information in the columns helps you to prioritize your work in following up with third-party contact. In particular, the state and
    percent complete values are key indicators. Select a name to view the details. For more information, see [Create a questionnaire or document request template](https://servicenow-prod.fluidtopics.net/jcT0RLyAjHfX1dxaHkfdRg "You can reuse questionnaire templates and document-request templates to speed up the creation of new questionnaires and document requests.") and [Create a questionnaire or document request template using the Designer](https://servicenow-prod.fluidtopics.net/wkjLFNCaqkOct3DQLATAuw "Use the Questionnaire Template Designer to create and edit questionnaire or document request templates that you can use as the basis for other templates.").

Fourth-party templates tab on the External assessments page
:   The tab lists the fourth-party questionnaires that the third-party contact will respond to. Select a name to view the details. For more information, see [Monitoring your fourth-nth parties](https://servicenow-prod.fluidtopics.net/c5BM4I7i3xxJQrX6HpvQ6A "You can identify and manage the third-party risks that depend on the services of the fourth-nth parties by using the Third-party Risk Management application. By monitoring your fourth-nth parties, you can help to ensure that they adhere to the same security and compliance standards as the primary third party.").

Third-party risk areas tab on the External assessments page
:   A risk domain defines the type of risk to assess for a third party. For example, you might want to assess a data-management third party in terms of security risk and a bank in terms of financial risk. Security risk and financial risk are risk domains. Some platform applications refer to risk domains as "risk areas." See [Define a third-party risk domain](https://servicenow-prod.fluidtopics.net/lGnKWPSsb3~KWsd80CuSyg "A risk domain defines the type of risk to assess for a third party. For example, you might want to assess a data-management third party in terms of security risk and a bank in terms of financial risk. Security risk and financial risk are risk domains. Some platform applications refer to risk domains as \"risk areas.\"").

Issues tab on the External assessments page

:   In an iterative process, before the TPR manager closes an assessment, the TPR manager can generate non-compliance issues and tasks. The TPR manager communicates with the TP contacts and engagement contacts by using comments to close the issues and tasks. The TPR manager can also assign different contacts as needed. See [Create an issue for a third party or engagement](https://servicenow-prod.fluidtopics.net/q0ELWsPpVSo9WoEiik7hgA "Create an issue to help ensure that your concerns about a third party or engagement are remediated.") and [Manage issues](https://servicenow-prod.fluidtopics.net/gr4m1V4YUDrDdB2P_XASOw "Verify that an issue that is associated with a risk assessment is understood, communicated to the appropriate persons, and is acted on as needed.").

Tasks tab on the External assessments page

:   In an iterative process, before the TPR manager closes an assessment, the TPR manager can generate non-compliance issues and tasks. The TPR manager communicates with the TP contacts and engagement contacts by using comments to close the issues and tasks. The TPR manager can also assign different contacts as needed. See [Create a task for a third party or engagement](https://servicenow-prod.fluidtopics.net/MPC40gMDINR66X6J3WV9wg "Create a task to help ensure that a user at your organization or the third-party contact responds to your concerns about questionnaire responses or requested documents during the due diligence process.") and [Manage a task for a third party or engagement](https://servicenow-prod.fluidtopics.net/65_~BivA3nz9Q20MYNS1oQ "Verify that the Assigned to user at your organization or the third-party contact responds to a task and update the state of the task as needed.").

* **[External assessment lifecycle states](https://servicenow-prod.fluidtopics.net/3_W6vz8huC7Kh8MXNb4SpQ)**   
  The process of collecting assessment data from a third party moves through several states. For example, during the Submitted to third party state, the third party responds to tasks, issues, and works to complete the questionnaires.
* **[Assessment metric type form](https://servicenow-prod.fluidtopics.net/msT6OjUnh_P9S2jC9qG~Xg)**   
  Use the assessment metric type form to capture all the information that you need to create a questionnaire template using the Third-party Risk Management application. As a third-party risk admin, you can create a questionnaire template.
* **[Create new external assessment template form](https://servicenow-prod.fluidtopics.net/vLiN7FqDk9J1GHpjLX~b~g)**   
  Use the external assessment template form to capture all the information that you need to create an external assessment template. As a third-party risk manager, you can create an assessment template.
* **[Create New TPRM SAE questionnaire template form](https://servicenow-prod.fluidtopics.net/3wRXTwtJFLG_dQARIBQoJA)**   
  Use the Create New TPRM questionnaire template form to capture all the information that you need to create a TPRM SAE questionnaire template using the Smart Assessment template designer. As a third-party risk admin, you can create a questionnaire template.
* **[Third-party risk assessment form](https://servicenow-prod.fluidtopics.net/zJ57JKjK3N0pW_Kb~4asiA)**   
  Use the third-party risk assessment form to capture all the information that you need to create an assessment using the Third-party Risk Management application. As a third-party risk assessor or manager, you can create an external assessment.
* **[Third-party element form](https://servicenow-prod.fluidtopics.net/ozInr6fbL1oRobvaNkEF_A)**   
  Use the third-party element form to capture all the information that you need to create a third-party element record using the Third-party Risk Management application. As a third-party risk manager, third-party risk assessor, or due diligence request owner, you can create a third-party element record.
* **[Create new third-party risk task form](https://servicenow-prod.fluidtopics.net/s3TSZoXot1DxHhh6QbhhtQ)**   
  Use the third-party risk task form to capture the information needed to create a task in the Third-party Risk Management application. As a third-party risk assessor or manager, you can create an external task.

**Related concepts**   

* [External assessment lifecycle states](https://servicenow-prod.fluidtopics.net/3_W6vz8huC7Kh8MXNb4SpQ "The process of collecting assessment data from a third party moves through several states. For example, during the Submitted to third party state, the third party responds to tasks, issues, and works to complete the questionnaires.")  
**Related tasks**   

* [Define a third-party risk domain](https://servicenow-prod.fluidtopics.net/lGnKWPSsb3~KWsd80CuSyg "A risk domain defines the type of risk to assess for a third party. For example, you might want to assess a data-management third party in terms of security risk and a bank in terms of financial risk. Security risk and financial risk are risk domains. Some platform applications refer to risk domains as \"risk areas.\"")
* [Manage issues](https://servicenow-prod.fluidtopics.net/gr4m1V4YUDrDdB2P_XASOw "Verify that an issue that is associated with a risk assessment is understood, communicated to the appropriate persons, and is acted on as needed.")
* [Manage a task for a third party or engagement](https://servicenow-prod.fluidtopics.net/65_~BivA3nz9Q20MYNS1oQ "Verify that the Assigned to user at your organization or the third-party contact responds to a task and update the state of the task as needed.")  
**Related reference**   

* [Assessment metric type form](https://servicenow-prod.fluidtopics.net/msT6OjUnh_P9S2jC9qG~Xg "Use the assessment metric type form to capture all the information that you need to create a questionnaire template using the Third-party Risk Management application. As a third-party risk admin, you can create a questionnaire template.")
* [Third-party risk assessment form](https://servicenow-prod.fluidtopics.net/zJ57JKjK3N0pW_Kb~4asiA "Use the third-party risk assessment form to capture all the information that you need to create an assessment using the Third-party Risk Management application. As a third-party risk assessor or manager, you can create an external assessment.")
* [Third-party element form](https://servicenow-prod.fluidtopics.net/ozInr6fbL1oRobvaNkEF_A "Use the third-party element form to capture all the information that you need to create a third-party element record using the Third-party Risk Management application. As a third-party risk manager, third-party risk assessor, or due diligence request owner, you can create a third-party element record.")

