---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Onboarding third party example

# Example: Onboarding a third party {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Example: Onboarding a third party

This example demonstrates how a large manufacturing company, Acme, uses the Third-Party Risk Management (TPRM) application to onboard a new third-party supplier.
The process ensures reliability and mitigates risks through a structured workflow from request initiation to ongoing monitoring.
Show full answer Show less  

## Onboarding Workflow

* **Request Process:** An employee initiates a third-party due diligence request via the Employee Center. A Third-Party Risk (TPR) manager approves the request and starts the due diligence workflow.
* **Inherent Risk Questionnaire (IRQ):** An IRQ assessor completes an inherent risk assessment by answering relevant questions in the Vendor Management Workspace, which calculates the third party's inherent risk level.
* **Due Diligence:** The TPR manager or assessor submits questionnaires and document requests to the third party via the third-party portal, where the third party responds. Acme uses assessment templates to streamline questionnaires and document requests. Responses are reviewed for compliance, regulatory, and security requirements.
* **Contractual Agreements and Risk Mitigation:** Post-due diligence, the contract negotiator reviews findings to ensure all necessary contractual clauses addressing risk are included in the third-party agreement.
* **Ongoing Monitoring and Review:** After onboarding, Acme continuously monitors the third party throughout the engagement lifecycle by reviewing assessments, monitoring results, and periodic reviews to track changes in risk posture.

## Key Benefits for ServiceNow Customers

* Provides a clear, step-by-step third-party onboarding process within the TPRM application.
* Supports thorough risk assessments and regulatory compliance through automated questionnaires and documentation requests.
* Enables contract risk management by linking assessment outcomes to contractual clauses.
* Facilitates ongoing risk monitoring to maintain visibility into third-party risk throughout the engagement.  
Acme, a large manufacturing company, is in the process of onboarding a new third party to supply critical components for their production line. To help ensure the third party's reliability and to mitigate potential risks, Acme starts a thorough third-party risk management onboarding process.

## Onboarding process example {#vrm-onboarding-example__section_k41_cpc_5xb}


This example illustrates a typical third-party onboarding flow in the
TPRM application, from initiating a request
through ongoing monitoring.

Request process

:   An employee initiates onboarding by submitting a third-party due diligence request in the Employee Center.


    A Third-party Risk (TPR) manager opens the request record from the Requests
    list and selects Approve.

    After approval, the TPR manager selects Start due diligence to move the request into the due diligence workflow.

    For more information, see [Requesting third-party risk due diligence](https://servicenow-prod.fluidtopics.net/Tox8oymaaXzAo4c7AdHemA "Request third-party risk due diligence to determine the level of risk for interactions with a third party, engagement, or fourth party by using Third-party Risk Management. You conduct due diligence to become aware of the associated risks so that you can make informed decisions, establish appropriate controls, and mitigate the potential negative impact when working with external parties.") and [Request due diligence for a third-party engagement](https://servicenow-prod.fluidtopics.net/hXoICdC6yfzFH8EhkMI1OQ "Request due diligence to assess the risk that is associated with doing business with an engagement. By conducting due diligence, you gain access to the most up-to-date, comprehensive, and accurate information before making a decision on entering into a business relationship.").

Inherent Risk Questionnaire (IRQ) process

:
    After due diligence starts, an inherent risk assessment is generated.

    On the Tasks page of the Vendor Management Workspace, the IRQ assessor opens the request record, navigates to the associated assessment, and opens the Inherent Risk Questionnaire.


    The assessor answers the IRQ questions and submits the assessment to calculate
    the third party's inherent risk level.

    For more information, see [Assessing your third-party risk](https://servicenow-prod.fluidtopics.net/HhMe7LKkoxctYhTzh0d5Aw "Use Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships. The information gathered from internal questionnaires, external questionnaires, and documentation requests helps you to understand the third party's risk profile, determine the appropriate risk mitigation strategies, and determine whether the third party or engagement meets all necessary compliance requirements.") and [Respond to an internal assessment](https://servicenow-prod.fluidtopics.net/NIHRKblHkO53M6nXO~yAQQ "Respond to an Inherent Risk Questionnaire (IRQ) or internal assessment that has been assigned to your queue. Your responses to the questionnaire help determine if the process moves forward and can affect which questionnaires are sent to the third party or engagement.").

Due diligence process: Compliance verification and data security and privacy assessment

:   When the IRQ is complete, the assessment continues through the due diligence phase.

    From the assessment record, the TPR manager or TPR assessor selects Submit to third party to send questionnaires and document requests.

    Third-party contacts receive and respond to questionnaires and document requests in the third-party portal.

    For more information, see [Assessing your third-party risk](https://servicenow-prod.fluidtopics.net/HhMe7LKkoxctYhTzh0d5Aw "Use Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships. The information gathered from internal questionnaires, external questionnaires, and documentation requests helps you to understand the third party's risk profile, determine the appropriate risk mitigation strategies, and determine whether the third party or engagement meets all necessary compliance requirements."), [Create an external assessment](https://servicenow-prod.fluidtopics.net/OsRUS7II7EVkcaW_YAOWrw "Create an assessment and initiate the third-party risk assessment life cycle using Third-party Risk Management. An external assessment specifies the details for the third party or engagement and defines the plan for completing the assessment."), [Respond to a questionnaire for a third party or engagement](https://servicenow-prod.fluidtopics.net/X7PBK32XtZXi_JpdlrmE8g "Answer questions, modify responses, or submit external questionnaires for a third party or engagement by using Third-party Risk Management. You can save valuable time by responding for a third party or engagement when they have already provided the required information for a previous questionnaire."), and [Review responses to external questionnaires](https://servicenow-prod.fluidtopics.net/oSBa1LG1iLdhUSUBfS3QSQ "Third-party contacts use the Third-party portal to complete assessments and collaborate with the TPR manager in the comments section for each question. When assessments reveal gaps, the TPR manager or the TPR assessor can generate an issue or task. In addition, the Vendor Management Workspace application can auto-generate issues.").  
    Note:  
    To streamline this step, Acme uses assessment templates, which group predefined questionnaire and document request templates for reuse.


    Acme reviews the submitted responses and uploaded documents from the assessment
    record to verify regulatory, compliance, and security requirements.

Contractual agreements and risk mitigation

:   After due diligence is complete, contract risk requirements are finalized.


    The TPR contract negotiator reviews assessment findings and confirms that required
    contractual clauses are included in the third-party agreement.

    For more information, see [Managing the contract risk process](https://servicenow-prod.fluidtopics.net/LiCX_HyxYjqvbfirkO7HQw "Protect your organization's interests, as the Third-party risk contract negotiator, often the corporate counsel, by incorporating specific contractual provisions so that you can address the risks identified using the Third-party Risk Management application.") and [Accessing DD requests that are in the contract risk process](https://servicenow-prod.fluidtopics.net/8s~P5aH6cSmLyz5YglQQsA "You can view the contracts associated with each engagement or third party and alongside detailed information such as the expiration, start date, end date, and state. You can also manage and update contract processes.").

Ongoing monitoring and review

:   Once onboarding is complete, Acme monitors the third party throughout the engagement lifecycle.


    Stakeholders review ongoing assessments, monitoring results, and periodic reviews
    from the third-party record to track changes in risk posture.

    For more information, see [Monitoring your third-party risk](https://servicenow-prod.fluidtopics.net/Mt0S6CJuB~PC7DNXGZ9m1w "You can monitor the potential risks that are associated with your third-party relationships by using the Third-party Risk Management application. An ongoing monitoring process can help you regularly assess the third party's performance and adherence to the agreed-upon terms.").

