---
sourceDocument: Australia Release Notes
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/release-notes

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Release Notes

ft:clusterId :

    - rn

bundleId :

    - rn


---

# Third-party Risk Management release notes

# Third-party Risk Management release notes {#ariaid-title1}

Release version: Australia  
Updated May 22, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 20 minutes to read  
The ServiceNow®
Third-party Risk Management (TPRM) application provides a centralized process for managing your portfolio of third parties and their engagements, assessing and scoring risk and performing remediation. TPRM was enhanced and updated in the Australia release.

## About Third-party Risk Management {#grc-tprm-rn__grc-tprm-highlights}


[Australia Patch 5](https://servicenow-prod.fluidtopics.net/86~p_JZvUlBB3FD_j8roSw "The Australia Patch 5 release contains important problem fixes.")
{#grc-tprm-rn__grc-tprm-highlights-1}

Starting with Australia Patch 5, Now Assist for Third-party Risk Management is now ServiceNow Otto® for TPRM. Your product entitlements remain unchanged. Check your entitlements to determine your access to specific features.{#grc-tprm-rn__grc-tprm-highlights-2}  
* Reduce manual data entry by using AI to pre‑fill questionnaires for third-party contacts and business owners.
* Use updated Standardized Information Gathering (SIG) questionnaire content for 2026.
* Automate Software Bill of Materials (SBOM) collection, integration, and vulnerability correlation with Unified Security Exposure Management (USEM) integration.
* Manage SAE assessment template versions to prevent changes from affecting in‑flight assessments.
* Add question-level comments and follow-up capabilities during SAE reviews.
* Maintain DORA Register of Information accuracy with automatic supply chain cascading updates and duplicate record detection for contractual arrangement and supply chain tables.
* Validate Legal Entity Identifier (LEI) codes against the GLEIF database during Register of Information reporting to identify format errors, checksum failures, and inactive or unissued entities.
{#grc-tprm-rn__ul_xds_q3k_sjc}  
* Enhance DORA Register of Information reporting with optional currency conversion and third‑party expense aggregation to generate consistent, regulator‑ready reports.
* Review the simplified third‑party elements process in the due diligence workflow.
* Access the unified content management module in the Vendor Management Workspace to view a centralized library of smart assessment templates.
{#grc-tprm-rn__ul_fnm_rvm_fhc}


[Australia Patch 1](https://servicenow-prod.fluidtopics.net/YA7hULsClAMRpa0n7ju_1A "The Australia Patch 1 release contains important problem fixes.")
{#grc-tprm-rn__grc-tprm-highlights-5}

Review the updated AI experience with three licensing tiers.{#grc-tprm-rn__grc-tprm-highlights-6}

See [Third-party Risk Management](https://www.servicenow.com/docs/access?context=third-party-risk-mgt-landing-page&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US) for more information.{#grc-tprm-rn__grc-tprm-highlights-7}


[Early availability](https://servicenow-prod.fluidtopics.net/TXTe8MPKl5ffoAV6IlfT7A "The Australia release contains important problem fixes.")
{#grc-tprm-rn__grc-tprm-highlights-8}

Use generative AI to recommend TPRM issues for reviewer validation.{#grc-tprm-rn__grc-tprm-highlights-9}

## Activation and other requirements

Note:  
Third-party Risk Management is available in ServiceNow Store. For details, see the "Activation information" section of these release notes.

Activation information

:   Install Third-party Risk Management by requesting it from ServiceNow Store. Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) to view all the available apps, and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#grc-tprm-rn__grc-tprm-activation-1}

Upgrade information

:   If you're a VRM user upgrading to TPRM and upgrading to Australia from an earlier release, you must run each upgrade sequentially to ensure that fix scripts run correctly. For example, you must upgrade from Xanadu to Yokohama, Yokohama to Zurich, and so on. If the scripts don't run in the correct order, you can get data inconsistencies, broken functionalities, and conflicts.{#grc-tprm-rn__grc-tprm-upgrade-info-1}

    After upgrading to version 21.0.x, you can enable the Smart Assessment Engine (SAE) by setting the Smart Assessment Engine enabled (sn_vdr_risk_asmt.sae_enabled) property. After setting this property, Smart Assessment Engine (SAE) is set to the default assessment engine and replaces the legacy experience. The transition is irreversible.  
    Warning:  
    Set this property in your non-production instances and conduct thorough testing before changing your production instances. Failure to do so can result in unexpected issues.

    For more information on upgrading from VRM to TPRM and the differences between the Smart and Classic Assessment engines, see [Third-party Risk Management upgrade information](https://servicenow-prod.fluidtopics.net/FA2LkW_4ELMaRpawpdgETg#grc-tprm-upgrade-info "ServiceNow Third-party Risk Management application upgrade information for the Australia release.").{#grc-tprm-rn__grc-tprm-upgrade-info-4}

    For existing TPRM customers, after upgrading to version 21.0.3, data from the Industry column in the Company \[core_company\] table is automatically migrated to the tprm_industry column. Migration
    can take several hours depending on the number of records in the Company \[core_company\] table. After migration, a system log message confirms that the migration is complete. Review the Company \[core_company\] table content.
    Update any customizations that reference the Industry field to use tprm_industry. After verifying the migration and updating customizations, you can drop the Industry column.{#grc-tprm-rn__grc-tprm-upgrade-info-5}

    After upgrading to version 22.3.3, the `grc_business_user` and `grc_reader` roles are no longer directly inherited by TPRM roles. During upgrade, most users are automatically migrated to new feature‑specific roles. Users with custom role combinations may not be migrated automatically and require
    manual review before the grace period ends.{#grc-tprm-rn__grc-tprm-upgrade-info-6}

## Accessibility and localization

Accessibility information

:   The Vendor Management Workspace and the third-party portal include accessibility improvements in this release, including improved color contrast, enhanced focus indicators, skip navigation links, and full keyboard
    navigation.{#grc-tprm-rn__grc-tprm-accessibility-1}

Localization information

:   Third-party portal strings are externalized and translated for supported languages. Newly introduced features may have incomplete translations.{#grc-tprm-rn__grc-tprm-localization-1}

## Third-party Risk Management upgrade information {#ariaid-title2}

ServiceNow®
Third-party Risk Management application upgrade information for the Australia release.

### Important information for upgrading Third-party Risk Management to Australia {#grc-tprm-upgrade-info__section_in2_pss_rfc}

After upgrading to Zurich, you can enable the Smart Assessment Engine (SAE) by setting the Smart Assessment Engine enabled (sn_vdr_risk_asmt.sae_enabled) property. After setting this property, SAE becomes the default assessment engine and replaces the legacy experience to ensure consistency, scalability, and innovation moving forward. While this transition isn't
reversible, it empowers customers to future-proof their assessment strategy with an engine built to evolve with emerging needs.{#grc-tprm-upgrade-info__grc-tprm-upgrade-info-2}  
Warning:  
Set this property in your non-production instances and conduct thorough testing before changing your production instances. Failure to do so may result in unexpected issues.

### Plugin dependencies {#grc-tprm-upgrade-info__section_ekf_sss_rfc}

After upgrading to Zurich and setting the Smart Assessment Engine enabled (sn_vdr_risk_asmt.sae_enabled) property, the following applications and plugins are installed automatically:

* The Vendor Risk Management Workspace application \[sn_vrm_ws\] is automatically installed so you can use the Vendor Risk Management workspace where you can access SAE questionnaires and features.
* The Smart Assessment Engine application and plugins are automatically installed enabling you to use the features of the Smart Assessment Engine for your assessments.

  Smart Assessment Engine application package that includes the following:
  * Smart Assessment Core plugin \[com.sn_smart_asmt\]
  * Smart Assessment Designer plugin \[com.sn_smart_asmt_desg\]
  * Smart Assessment Connected plugin \[com.sn_smart_asmt_conn\]
  * Smart Assessment Migration Tools plugin \[com.sn_smart_asmt_mig\]
  * Smart Assessment Dependencies plugin \[com.sn_smart_asmt_dep\]
  * Smart Assessment Post-assessment Actions plugin \[com.sn_impact_fwk\] and \[com.sn_smart_imp_auto\]
  * Smart Assessment Response Automation plugin \[com.sn_smart_resp_auto\]
  * Smart Assessment Scoring plugin \[com.sn_smart_scoring\]
  {#grc-tprm-upgrade-info__ul_bst_zb5_rfc}

{#grc-tprm-upgrade-info__ul_njd_cb5_rfc}  
Note:  
For more information on these plugins, see [Configuring Smart Assessment Engine](https://www.servicenow.com/docs/access?context=smart-assessment-engine-cf-config&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US) and [Smart assessment configuration](https://www.servicenow.com/docs/access?context=tprm-sae-assessment-config&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US).

### Migrating to Smart Assessment Engine {#grc-tprm-upgrade-info__section_hgb_cj5_rfc}

After setting the Smart Assessment Engine enabled (sn_vdr_risk_asmt.sae_enabled) property, all TPRM assessments will automatically use SAE templates and automation rules (tier-based rules, provider-based rules, event-driven rules and issue generation rules) that support SAE only. You will be able to continue any in-flight assessment until they are completed. You will not be able to create any new assessments with classic questionnaire
templates.

The following diagram shows the questionnaire to TPRM
SAE template migration workflow.  
Figure 1. SAE migration workflow  
1. Migrate templates either one by one or in bulk. After migration, all templates are in the Draft state by default.
2. Review each migrated questionnaire template individually to confirm that they're accurate and complete.
3. Publish TPRM SAE questionnaire templates. After publishing, the following actions occur automatically:
   * All the related assessment templates are updated to use the migrated questionnaire template. If all the questionnaire templates in an assessment template are published, the assessment template is automatically marked as Support smart assessment.
   * All issue generation rules are automatically marked as Support smart assessment if their related questionnaire template is published.
   * All automation rules (tier-based rules, provider-based rules, event-driven rules and issue generation rules) are automatically marked as Support smart assessment after their related assessment template is marked as Support smart assessment.

   {#grc-tprm-upgrade-info__ul_pkh_2kd_cgc}  
   Note:  
   For Issue-generation rules to work as expected when applied to an TPRM SAE questionnaire template, at least one question must have the option, Enable preferred response, set to true.
4. Review each assessment template to confirm it's marked as Supports smart assessment. If an assessment template isn't marked as Supports smart assessment, manually adding a new TPRM SAE questionnaire template to it updates its status.
{#grc-tprm-upgrade-info__ol_zgq_xsq_xfc}

For more information, see [Migrate a template to an SAE template](https://www.servicenow.com/docs/access?context=tprm-asmnt-tmplt-migrate-metrics-to&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US), [Create a TPRM
SAE questionnaire or document request template](https://www.servicenow.com/docs/access?context=create-sae-q-template&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US), [Create an external assessment template](https://www.servicenow.com/docs/access?context=create-vendor-risk-assess-temp&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US), and [Create an issue generation rule](https://www.servicenow.com/docs/access?context=tprm-generate-issue-rule&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US).

### Classic assessment engine to Smart Assessment Engine comparison {#grc-tprm-upgrade-info__section_r1w_zj5_rfc}

The following table shows the comparable features between the Classic assessment engine and Smart Assessment Engine.
{#grc-tprm-upgrade-info__table_vkx_hjq_hcc__entry__2}

| Classic assessment engine features | Smart assessment engine features |
|-|-|
| Metric Type​ | Template |
| Metric Category | Section |
| Metrics | Questions |
| Additional Information​ | Justification |
| Assessable Record | Scope |
| Multiple Assessable Records in one Assessment | Combined Assessments |
| Schedule and Trigger Assessments | Trigger Assessment Flow Action |
| Domain Separation | Domain Separation |
| Question Dependency | Conditional Visibility |
| Correct Answer | Preferred Answer |
| Scoring | Scoring |
| Automated response | Response Automation |
[Table 1. Comparable features]

{#grc-tprm-upgrade-info__table_vkx_hjq_hcc}

The following diagram shows the relationship between assessment templates and questionnaires after upgrading.  
Figure 2. Assessment templates post-upgrade

* Before setting the Smart Assessment Engine enabled (sn_vdr_risk_asmt.sae_enabled) property, the following are used by default.
  * Existing questionnaire templates
  * Existing assessments
  {#grc-tprm-upgrade-info__ul_jdg_3nq_xfc}
* After setting the Smart Assessment Engine enabled (sn_vdr_risk_asmt.sae_enabled) property, the following are used by default.
  * SAE questionnaire templates (New or migrated).
  * Assessments marked as Supports smart assessment.
  * Tier-based, Provider-based, and Event-driven management rules only work with assessments marked as Supports smart assessment.
  {#grc-tprm-upgrade-info__ul_iqj_znq_xfc}

{#grc-tprm-upgrade-info__ul_wnq_2nq_xfc}  
Note:  
All questionnaire templates must be reviewed and published. All assessment templates and automation rules must be reviewed to confirm they're marked as Supports smart assessment.

### Smart Assessment Engine limitations {#grc-tprm-upgrade-info__section_k41_ch5_rfc}

The TPRM SAE questionnaire template has the following limitations.

* All new assessments must use SAE questionnaire templates.
* Third-party risk assessors can no longer create issues from the View responses page. Issues generation rules can be used to create issues automatically.
* The signature feature isn't supported.
* Automatic attachment of questionnaires to external assessments based on inherent risk questionnaire (IRQ) responses or IRQ-calculated risk tiers is currently not supported in Smart Assessment Engine.
* The following question types aren't supported: percentage, ranking, image scale, and custom metric. You must either convert these question types to supported formats before migration or create new questions in the template designer after migration.  
  Note:  
  For the percentage and image scale question types, customers can use the Number type and Radio button type, respectively. Ranking and custom metric question types aren't supported. You must either convert these question types to supported formats before migration or create new questions in the template designer after migration.
* If a section in the classic template contains only unsupported questions, an empty section is created in the TPRM SAE template. TPRM SAE templates with empty sections can't be published; therefore, you must either add replacement questions to these sections or delete the empty sections before publishing.

  For more information on migration results, migration limitations, and creating TPRM
  SAE questionnaires, see [Results of migrating a template to a TPRM
  SAE template](https://www.servicenow.com/docs/access?context=tprm-migrate-asmnt-template-result&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US) and [Create a TPRM
  SAE questionnaire or document request template](https://www.servicenow.com/docs/access?context=create-sae-q-template&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US).
* The TPRM scoring migration proceeds only if there were no errors during the template migration. If there were errors, the TPRM scoring migration doesn't occur.

  For more information, see [Configure scoring for an assessment](https://www.servicenow.com/docs/access?context=configure-scoring-for-assessments&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US) and [Normalization in assessment](https://www.servicenow.com/docs/access?context=normalization-in-assessment&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US).
* Event-driven management rules are the default option for scheduling assessments and replaces Repeating assessments.

### External assessment status changes when enabling SAE {#grc-tprm-upgrade-info__section_sae_status_vocab}

When you enable the Smart Assessment Engine (SAE) after upgrading to Zurich, external assessment statuses change to reflect the SAE lifecycle. The following table shows how Classic engine assessment statuses map to SAE assessment statuses.
{#grc-tprm-upgrade-info__table_sae_status_vocab__entry__2}

| Classic engine status | SAE status (Zurich and later) |
|-|-|
| Responses received | Submitted to third party |
| Returned | In progress |
[Table 2. External assessment status changes: Classic engine to SAE]

{#grc-tprm-upgrade-info__table_sae_status_vocab}

These status changes apply only when SAE is enabled. Assessments that continue to use the Classic engine retain the original states. For more information about the SAE assessment and questionnaire lifecycle, see [External assessment lifecycle states](https://www.servicenow.com/docs/access?context=tprm-external-assessment-lifecycle&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US).

### Important information for upgrading Vendor Risk Management to Australia {#grc-tprm-upgrade-info__section_cqv_gbn_k2c}

Starting with the Vancouver release, if you're a VRM user upgrading to TPRM, from an earlier release, you must run each upgrade sequentially to ensure that fix scripts run correctly. This means upgrading from one release to the next rather than skipping
to the latest release. Not running scripts in the correct order can result in data inconsistencies, broken functionalities, and conflicts.

### Plugin requirements {#grc-tprm-upgrade-info__section_j3v_hcn_k2c}

TPRM

* Activate the Third-party Risk Management application \[com.sn_vdr_risk_asmt\].
* Activate the Third-party Risk Due Diligence application \[com.sn_tprm_dd\].
* Activate the Vendor Risk Management Workspace application \[sn_vrm_ws\] if you want to use the Vendor Risk Management workspace.
{#grc-tprm-upgrade-info__ul_fs5_3cn_k2c}  
VRM

* Activate the Vendor Risk Management application \[com.sn_vdr_risk_asmt\].
* Activate the Vendor Risk Management Workspace application \[sn_vrm_ws\] if you want to use the Vendor Risk Management workspace.
{#grc-tprm-upgrade-info__ul_tmg_mcn_k2c}

For more information on licensing or metering, see [Tracking a managed activity](https://www.servicenow.com/docs/access?context=tprm-managed-activity&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US), [Third-party Risk Management (TPRM) Licensing](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1431058), and [Vendor Risk Management (VRM) Licensing](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1362674).

### VRM to TPRM changes {#grc-tprm-upgrade-info__section_lkp_3bn_k2c}

* The name of the application changed from Vendor Risk Management to Third-party Risk Management as part of the Vancouver release.
* The internal assessment \[sn_vdr_asmt_internal_assessment\] table is introduced, extending the tiering assessment \[sn_vdr_risk_asmt_vdr_tiering_assessment\] table.
* The Due Diligence Review (DDR) workflow is introduced, which uses both the internal assessment and the external (VRA) assessment.  
  Note:  
  If you have customizations on the Tiering assessment \[sn_vdr_risk_asmt_vdr_tiering_assessment\] and VRA \[sn_vdr_risk_asmt_assessment\] tables, they might need modifications to work with the DDR workflow.
* The Third-party Scores \[sn_vdr_risk_asmt_security_score\] table has been relabeled to Risk Intelligence Scores \[sn_vdr_risk_asmt_security_score\] to reduce confusion.
* All instances of "vendor" are changed to "third party" in the user interface, though some global instances might remain unchanged.  
  Note:  
  If you don't want to use the due diligence workflow, your original workflow (Tiering assessment and External assessments (VRAs) should be the same).
{#grc-tprm-upgrade-info__ul_ovg_mbn_k2c}

### VRM and TPRM data model {#grc-tprm-upgrade-info__section_dnp_sbn_k2c}

The Vendor Risk Management data model primarily uses the term "vendor" and includes the Tiering assessment \[sn_vdr_risk_asmt_vdr_tiering_assessment\] and VRA \[sn_vdr_risk_asmt_assessment\] tables.

The Third-party Risk Management data model uses the term "third-party" in most user interface elements and introduces the DDR workflow, which uses both internal \[sn_vdr_asmt_internal_assessment\] and
\[sn_vdr_risk_asmt_assessment\] external assessments.

The following models show VRM's and TPRM's capabilities.  
Figure 3. VRM data model

The components included in the Vendor Risk Management data model are as follows:  
* Tiering assessment \[sn_vdr_risk_asmt_vdr_tiering_assessment\]
* Company \[core_company\]
* Vendor risk assessment \[sn_vdr_risk_asmt_assessment\]
* Vendor engagement \[sn_vdr_risk_asmt_vendor_engagement\]
* Vendor contact \[vm_dr_contact\]
* Assessment metric type \[asmt_metric_type\]
* Assessment template \[sn_vdr_risk_asmt_assessment_template\]
* Engagement risk scoring rule \[sn_vdr_risk_asmt_engagement_risk_scoring_rule\]
* Engagement level risk rating \[sn_vdr_risk_asmt_engagement_level_rating\]
{#grc-tprm-upgrade-info__ul_c4l_23n_k2c}  
Figure 4. TPRM data model

The components included in the Third-party Risk Management data model are as follows:  
* Risk intelligence score \[sn_vdr_risk_asmt_security _score\]
* Internal assessment \[sn_vdr_asmt_internal_assessment\]
* Tiering assessment \[sn_vdr_risk_asmt_vdr_tiering_assessment\]
* Event-driven management history \[sn_tprm_dd_rule_execution_history\]
* Third-party due diligence request \[sn_tprm_dd_request\]
* Company \[core_company\]
* Event-driven management rule \[sn_tprm_dd_generation_rule\]
* Third-party risk assessment \[sn_vdr_risk_asmt_assessment\]
* Third-party engagement \[sn_vdr_risk_asmt_vendor_engagement\]
* Vendor contact \[vm_dr_contact\]
* Assessment metric type \[asmt_metric_type\]
* Assessment template \[sn_vdr_risk_asmt_assessment_template\]
* Third-party risk issue \[sn_vdr_risk_asmt_issue\]
* Engagement risk scoring rule \[sn_vdr_risk_asmt_engagement_risk_scoring_rule\]
* Engagement level risk rating \[sn_vdr_risk_asmt_engagement_level_rating\]
{#grc-tprm-upgrade-info__ul_v5z_f4n_bcc}

## September 2026 {#ariaid-title3}

The ServiceNow®
Third-party Risk Management (TPRM) application provides a centralized process for managing your portfolio of third parties and their engagements, assessing and scoring risk and performing remediation. TPRM was enhanced and updated in the Australia release.

### What's deprecated or removed {#grc-tprm-rn-2026-09__grc-tprm-rn-deprecations}


Starting with the September 2026 release, Now LLM Service is being prepared for future deprecation. The Now LLM Service is no longer the default model provider for new or inactive AI assets, and it is no longer selected by default in AI Control Tower. A third-party LLM is now selected by default for AI assets, while existing configurations using the Now LLM Service continue unchanged. The Now LLM Service is still available for manual selection. For details, see the [Deprecation Process \[KB0867184\]](https://support.servicenow.com/kb_view.do?sysparm_article=KB0867184) article in the Now Support Knowledge Base.
{#grc-tprm-rn-2026-09__grc-tprm-rn-deprecations-1}

## August 2026 {#ariaid-title4}

The ServiceNow®
Third-party Risk Management (TPRM) application provides a centralized process for managing your portfolio of third parties and their engagements, assessing and scoring risk and performing remediation. TPRM was enhanced and updated in the Australia release.

### What's changed {#grc-tprm-rn-2026-08__grc-tprm-changed-features}

[Australia Patch 5](https://servicenow-prod.fluidtopics.net/86~p_JZvUlBB3FD_j8roSw "The Australia Patch 5 release contains important problem fixes.")
:   Starting with Australia Patch 5, Now Assist for Third-party Risk Management is now ServiceNow Otto® for TPRM. Your product entitlements remain unchanged. Check your entitlements to determine your access to specific features.
{#grc-tprm-rn-2026-08__grc-tprm-changed-features-1}

## July 2026 {#ariaid-title5}

The ServiceNow®
Third-party Risk Management (TPRM) application provides a centralized process for managing your portfolio of third parties and their engagements, assessing and scoring risk and performing remediation. TPRM was enhanced and updated in the Australia release.

### What's new {#grc-tprm-rn-2026-07__grc-tprm-new-features}

[Extended AI model support for Now Assist for TPRM](https://www.servicenow.com/docs/access?context=supporting-information-now-assist-tprm&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading to version 22.3.4, ServiceNow Otto for Third-party Risk Management (TPRM) supports Google Gemini 3.5 Flash, OpenAI GPT 5.1, and OpenAI GPT 5.4 mini models in addition to previously supported models. Model availability depends on your ServiceNow Otto for Third-party Risk Management (TPRM) subscription, providing greater flexibility when selecting the AI model that meets your requirements.
{#grc-tprm-rn-2026-07__grc-tprm-new-features-3}

### What's changed {#grc-tprm-rn-2026-07__grc-tprm-changed-features}

[Default AI model for issue recommendation skill](https://www.servicenow.com/docs/access?context=supporting-information-now-assist-tprm&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading to version 22.3.4, the issue recommendation skill in ServiceNow Otto for Third-party Risk Management (TPRM) uses Azure OpenAI gpt-4-5-mini as the default model. This update changes the default model for issue recommendations. You can select alternative models, including the newly
    supported Google Gemini 3.5 Flash, OpenAI GPT 5.1, and OpenAI GPT 5.4 mini, based on your requirements.

[Large language models on the ServiceNow AI Platform®](https://www.servicenow.com/docs/access?context=exploring-large-language-models&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US)
:   The Now LLM Service is no longer the default model provider for new or inactive AI assets. A third-party LLM is now selected by default, while existing configurations using the Now LLM Service continue unchanged. The Now LLM Service is still available for manual selection.
{#grc-tprm-rn-2026-07__grc-tprm-changed-features-4}

## June 2026 {#ariaid-title6}

The ServiceNow®
Third-party Risk Management (TPRM) application provides a centralized process for managing your portfolio of third parties and their engagements, assessing and scoring risk and performing remediation. TPRM was enhanced and updated in the Australia release.

### What's new {#grc-tprm-rn-2026-06__grc-tprm-new-features}

[AI-assisted questionnaire pre-fill using the Document Management System](https://www.servicenow.com/docs/access?context=tprm-dms-sae&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading to version 22.3.3 and activating the ServiceNow Otto for Third-party Risk Management (TPRM) application, you can use uploaded documents and responses from previous assessments to generate suggested questionnaire responses with source citations. For internal
    assessments, the snc_internal role is required. For external assessments, primary contacts can complete all assessment response actions; secondary contacts must be assigned read and write access.

[Software Bill of Materials (SBOM) support](https://www.servicenow.com/docs/access?context=tprm-sbom-exploring&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading to version 22.3.2 and installing the required SBOM applications, if you have the third-party risk manager role \[sn_vdr_risk_asmt.vendor_risk_manager\] or third-party risk assessor role \[sn_vdr_risk_asmt.vendor_risk_assessor\], you can
    collect and manage SBOM data to support regulatory disclosure requirements.

[Standardized Information Gathering (SIG) 2026 questionnaires](https://www.servicenow.com/docs/access?context=tprm-sig-use-and-support&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading to version 22.3.0, if you have the third-party risk manager role
    \[sn_vdr_risk_asmt.vendor_risk_manager\], you can use updated SIG Full, SIG Core, and SIG Lite templates for 2026 with expanded coverage across major security and privacy frameworks. Existing SIG questionnaire
    versions remain available. In‑flight assessments aren't affected.

[Smart Assessment template versioning](https://www.servicenow.com/docs/access?context=tprm-sae-using&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading to version 22.3.3, if you have the third-party risk manager role
    \[sn_vdr_risk_asmt.vendor_risk_manager\], you can manage SAE template lifecycles using explicit versioning so that in-flight assessments use the version that was active when they were created.

[Legal Entity Identifier (LEI) validation for DORA reporting](https://www.servicenow.com/docs/access?context=tprm-valid-lei&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading the Digital Resilience Third-party Information Register application to version 22.3.1, if you have the third-party risk manager role \[sn_vdr_risk_asmt.vendor_risk_manager\], you can validate Legal Entity
    Identifier codes against the GLEIF database to support regulatory accuracy in Register of Information reporting. For descriptions of validation results and report columns, see [Level 4 LEI Validation Report columns](https://www.servicenow.com/docs/access?context=tprm-lei-validation-report&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US).
{#grc-tprm-rn-2026-06__grc-tprm-new-features-1}

### What's changed {#grc-tprm-rn-2026-06__grc-tprm-ui-changes}

[Improved handling of skipped conditional questions in SAE assessments](https://www.servicenow.com/docs/access?context=tprm-sae-using&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading to version 22.3.3, Smart Assessment Engine assessments hide conditional questions that are skipped based on response logic. Sections that contain skipped questions are visually de‑emphasized, and assessments
    render in a continuous scroll layout.This change affects the assessment review experience only and does not change assessment logic, scoring, or response data.

[Comments field in the third‑party portal saves when you leave the field](https://www.servicenow.com/docs/access?context=vendor-portal&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading to version 22.3.2, the comments field in the third‑party portal saves when you leave the field rather than on every keystroke.

[Issue indicators in the third-party portal shown only after submission](https://www.servicenow.com/docs/access?context=vendor-portal&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading to version 22.3.2, issue indicators appear in the third‑party portal only after an issue is submitted to the third party and the Visible in third‑party portal field is
    selected. Previously, indicators were visible before submission when the field was selected.
{#grc-tprm-rn-2026-06__grc-tprm-ui-changes-1}

[Consolidated assessment email notifications](https://www.servicenow.com/docs/access?context=set_sys_props_for_email&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading to version 22.3.3, external assessment‑related email notifications are sent as a single consolidated summary instead of individual per‑event messages. Users can configure notification frequency,
    detail level, and delivery channel in their notification preferences. Multi‑language templates are available.

[Assessment count mechanism updated in the third-party portal](https://www.servicenow.com/docs/access?context=vendor-portal&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading to version 22.3.3, engagement assessment counts in the third-party portal include only active, pending, and in‑progress assessments. Previously, counts included inactive and canceled
    assessments.

[Inactive metrics excluded when copying assessment responses](https://www.servicenow.com/docs/access?context=tprm-assessing-tpr&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading to version 22.3.3, inactive and retired metrics are excluded when copying responses between assessments. Previously, copying responses could include inactive metrics, causing scoring errors.

[Type of ICT services changes cascade to supply chain in DORA reporting](https://www.servicenow.com/docs/access?context=tprm-drtp-reg-contract&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading the Digital Resilience Third-party Information Register application to version 22.3.1, when the Type of ICT services value is updated on a Contractual Arrangements -- Specific Information (B.02.02) record,
    the ICT service supply chain (B.05.02) is now updated automatically. If a Type of ICT services value is removed from a Specific Information record, the corresponding supply chain records for Rank 1 and higher
    ranks are also deleted automatically. Previously, Rank 1 supply chain records were generated when the Specific Information record was first created, but subsequent changes or removals did not propagate to the
    supply chain, requiring manual correction.

[Duplicate contractual arrangements detected and warned in DORA Register of Information](https://www.servicenow.com/docs/access?context=tprm-drtp-reg-contract&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading the Digital Resilience Third-party Information Register application to version 22.3.1, duplicate records in the Contractual Arrangements -- Specific Information (B.02.02) table are now detected and handled
    across three scenarios. When saving a contractual arrangement from the UI, a business rule checks eight composite key fields and blocks the save if a duplicate is found. During Excel upload, duplicate rows are
    rejected and logged to the upload error report. During CSV package download, duplicate rows in B.02.02 are flagged in the DORA request record's error log; duplicates are warned but not removed from the generated CSV.

[Duplicate supply chain rows warned during DORA CSV package download](https://www.servicenow.com/docs/access?context=tprm-drtp-roi-packages&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading the Digital Resilience Third-party Information Register application to version 22.3.1, during CSV package download, duplicate rows in the ICT service supply chains (B.05.02) table are now detected and a
    warning is added to the request record. This applies to both Rank 1 supply chain records, which are auto-generated from Specific Information records, and higher-ranked records. Additionally, when the Storage of
    data field is set to No on a contractual arrangement, associated location field values are now cleared automatically.
{#grc-tprm-rn-2026-06__grc-tprm-changed-features-2}

### What's deprecated or removed {#grc-tprm-rn-2026-06__grc-tprm-removed-features}

* The `grc_business_user` and `grc_reader` roles are no longer directly inherited by TPRM roles.
* The `scoring_rule` and `scoring_rule_ref` fields are removed from assessment forms and UI sections. Custom scripts or integrations that reference these fields must be updated.
{#grc-tprm-rn-2026-06__grc-tprm-removed-features-1}

## April 2026 {#ariaid-title7}

The ServiceNow®
Third-party Risk Management (TPRM) application provides a centralized process for managing your portfolio of third parties and their engagements, assessing and scoring risk and performing remediation. TPRM was enhanced and updated in the Australia release.

### What's new {#grc-tprm-rn-2026-04__grc-tprm-new-features}

[Generate issue recommendations for TPRM](https://www.servicenow.com/docs/access?context=create-recommendation-tprm-issue&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading to version 22.0.8 if you have the third‑party assessment reviewer role
    \[sn_vdr_risk_asmt.vendor_assessment_reviewer\] and have installed the ServiceNow Otto for Third-party Risk Management (TPRM) application, you can use generative AI to automatically identify and recommend issues based on assessment responses. The TPRM issue management recommendation skill recommends issues with rationalized summaries. Recommended issues are presented for review and are created as standard TPRM issues only after user confirmation.
{#grc-tprm-rn-2026-04__grc-tprm-new-features-2}

### What's changed {#grc-tprm-rn-2026-04__grc-tprm-changed-features}

[ServiceNow product tiers](https://www.servicenow.com/docs/access?context=ai-native-sku-overview&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US)
:   The ServiceNow AI Platform now brings you a new AI experience with three licensing tiers available:

    * Foundation: AI basics to deliver insights
    * Advanced: AI to boost productivity across relevant use cases
    * Prime: Act autonomously with all AI assets, and create your own

    Depending on your license, you will have access to certain application features, generative AI skills, agentic workflows, and AI agents.
{#grc-tprm-rn-2026-04__grc-tprm-changed-features-3}

## Australia {#ariaid-title8}

The ServiceNow®
Third-party Risk Management (TPRM) application provides a centralized process for managing your portfolio of third parties and their engagements, assessing and scoring risk and performing remediation. TPRM was enhanced and updated in the Australia release.

### What's new {#grc-tprm-rn-release__grc-tprm-new-features}

[Generate aggregate regulatory reports in local currencies](https://www.servicenow.com/docs/access?context=tprm-dora-currency-aggregation&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading the Digital Resilience Third-party Information Register application to version 22.0.3, third‑party risk (TPR) managers \[sn_vdr_risk_asmt.vendor_manager\] can standardize annual expense values during
    Register of Information report generation by enabling currency conversion and third‑party total expense aggregation. To support this process, the generated reporting package includes summary and detail reports
    that indicate successful conversions, aggregation results, and any skipped providers.

[Centralized repository for TPRM SAE templates](https://www.servicenow.com/docs/access?context=tprm-integrating-ucm&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading to version 22.0.2 and installing the Unified Content Management
    application, TPR managers \[sn_vdr_risk_asmt.vendor_risk_manager\] can help ensure consistent and comprehensive assessments by activating and updating ready‑to‑use Smart Assessment Engine questionnaire templates through a single, managed repository in the Vendor Management Workspace.
{#grc-tprm-rn-release__grc-tprm-new-features-1}

### What's changed {#grc-tprm-rn-release__grc-tprm-ui-changes}

[Fields added to Create New Excel download/upload request form](https://www.servicenow.com/docs/access?context=tprm-create-report-aggregate-expenses&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading the Digital Resilience Third-party Information Register application to version 22.0.3, the Enable currency conversion and Enable third‑party total expense aggregation fields are available on the Excel download/upload request page. When creating Excel Master Template or Plain‑CSV Reporting Package requests, you can configure these options directly on
    the form.

[TPRM Unified content management page](https://www.servicenow.com/docs/access?context=tprm-ws-ucm-page&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading to version 22.0.2 and installing the Unified Content Management application, the unified content management module is available in the Vendor Management Workspace.
{#grc-tprm-rn-release__grc-tprm-ui-changes-1}

[Simplified third-party element process](https://www.servicenow.com/docs/access?context=tprm-workflow-in-workspace&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US)
:   After upgrading to version 22.0.1, third‑party elements are now linked to a single third party and can no longer be shared across third parties. Scoring rollups calculate results from element‑level assessments
    rather than entity records.
{#grc-tprm-rn-release__grc-tprm-changed-features-2}

### What's deprecated or removed {#grc-tprm-rn-release__grc-tprm-removed-features}

* Assessments using entities are no longer supported.
{#grc-tprm-rn-release__grc-tprm-removed-features-1}

