Assessing and Monitoring Compliance Risks During Third-Party Due Diligence
Integrating Policy and Compliance Management with Third-party Risk Management dynamically updates compliance status based on third-party questionnaire responses, improving visibility and enabling risk-informed decisions.
Combined benefits of integrating Policy and Compliance Management with Third-party Risk Management
Use these applications together to:
- Evaluate compliance risk during onboarding and ongoing third-party engagements.
- Update compliance status automatically based on questionnaire responses.
- Combine compliance and risk data for more complete risk scoring.
- Enable collaboration between compliance and risk teams to mitigate issues quickly.
| Feature | Policy and Compliance Management | Third-party Risk Management | All applications together |
|---|---|---|---|
| Create policies and controls | |||
| Continuously monitor compliance and control changes | |||
| Third-party risk due diligence | |||
| Risk intelligence | |||
| Risk scoring and monitoring |
Workflow for Policy and Compliance Management integration with Third-party Risk Management
Using these applications together provides the following benefits:
- Evaluate compliance risk when onboarding third parties and engagements.
- Leverage combined compliance and risk data for better decision-making.
- Compliance Manager creates and manages policies, control objectives, and controls.
- TPR Assessor initiates external risk assessments for third parties and engagements.
- The third party completes the assessments.
- Responses update compliance status dynamically.
- TPR Assessor evaluates risk based on updated compliance status and other assessment data.
- Compliance Manager and TPR Assessor collaborate to mitigate identified risks.
Nota:
Direct mapping of control objectives to Smart Assessment Engine questions is not supported; compliance updates occur through post-assessment actions.
Requirements for integration
Install the following plugins:
- Third-party Risk Management (com.sn_vdr_risk_asmt)
- Due Diligence Request Workflow (com.sn_tprm_dd)
- Policy and Compliance Management (com.sn_compliance)
Get started with integration
Complete these tasks:
- Create a policy (Create a policy using the Compliance Workspace).
- Create control objectives and controls (Create a control objective using the Compliance Workspace and Create a control using the Compliance Workspace).
- Add controls to third parties, engagements, and questions ( and ).
- Create and submit a due diligence request (Request due diligence for a third-party engagement).
- Approve request → IRQ sent to TPR Assessor.
- TPR Assessor completes IRQ → due diligence begins.
- Due diligence creates two risk assessments (third-party and engagement).
- Third party completes questionnaires → TPR Manager reviews (Assessing your third-party risk).
- Compliance Manager and TPR Assessor collaborate to mitigate risks based on:
- Updated compliance status from responses.
- Risk scores and assessment data.
- Insights from due diligence.