---
sourceDocument: Australia Release Notes
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/release-notes

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Release Notes

ft:clusterId :

    - rn

bundleId :

    - rn


---

# Third-party Risk Management upgrade information

# Third-party Risk Management upgrade information {#ariaid-title1}

Release version: Australia  
Updated June 2, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 8 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Third-party Risk Management upgrade information

This document provides essential guidance for ServiceNow customers upgrading the Third-party Risk Management (TPRM) application to the Australia release, with a focus on enabling the Smart Assessment Engine (SAE) introduced in the Zurich release.
It details the upgrade sequence, plugin dependencies, migration process, feature comparisons, and data model changes relevant to customers transitioning from Vendor Risk Management (VRM) to TPRM.
Show full answer Show less  

## Key Upgrade Information

* **Smart Assessment Engine (SAE) Activation:** After upgrading to Zurich, customers can enable SAE by setting the `snvdrriskasmt.saeenabled` property. This engine replaces the legacy assessment experience, bringing scalability and innovation. Enable SAE only after thorough testing in non-production instances, as this change is irreversible.
* **Plugin Dependencies:** Enabling SAE automatically installs the Vendor Risk Management Workspace and multiple Smart Assessment Engine plugins, which deliver core functionality, design tools, automation, scoring, and response capabilities.
* **Migration to SAE:** Upon enabling SAE, all new assessments use SAE templates and automation rules exclusively. Existing assessments in progress continue with classic templates until completion. Templates can be migrated individually or in bulk, but must be reviewed and published to activate their full functionality and automation support.
* **Assessment Template and Rule Updates:** Publishing migrated templates updates related assessment templates and automation rules to support SAE. Issue generation rules require at least one question with "Enable preferred response" enabled to function properly.
* **Limitations of SAE:** Certain question types (percentage, ranking, image scale, custom metric) are unsupported and must be converted or recreated. Signature features and some automated questionnaire attachments are not yet supported. Issue creation from the View responses page is disabled; issues must be generated via rules.
* **Assessment Status Changes:** Enabling SAE updates external assessment statuses to align with the SAE lifecycle. Classic engine assessments retain their original statuses if SAE is not enabled.

## VRM to TPRM Upgrade Considerations

* **Sequential Upgrades Required:** Customers upgrading from VRM to TPRM must upgrade through each intermediate release sequentially to ensure proper execution of fix scripts and avoid data inconsistencies.
* **Application Renaming and Workflow Changes:** The application name changed from Vendor Risk Management to Third-party Risk Management starting Vancouver release. A new internal assessment table and Due Diligence Review workflow were introduced, impacting customizations related to tiering and external assessments.
* **Data Model Differences:** The VRM data model centers on "vendor" terminology and includes tiering and vendor risk assessment tables. The TPRM model uses "third-party" terminology and incorporates both internal and external assessments along with due diligence components, risk intelligence scores, and event-driven management rules.

## Practical Guidance for ServiceNow Customers

* Test SAE enablement extensively in non-production environments before applying in production to prevent disruptions.
* Review and publish all migrated SAE questionnaire templates and related assessment templates to ensure automation and scoring function correctly.
* Convert unsupported question types during template migration to maintain questionnaire integrity.
* Follow the prescribed upgrade path from VRM to TPRM without skipping versions to maintain data and functionality consistency.
* Update any customizations dependent on assessment tables or workflows to align with the new DDR workflow if applicable.  
ServiceNow®
Third-party Risk Management application upgrade information for the Australia release.

## Important information for upgrading Third-party Risk Management to Australia {#grc-tprm-upgrade-info__section_in2_pss_rfc}

After upgrading to Zurich, you can enable the Smart Assessment Engine (SAE) by setting the Smart Assessment Engine enabled (sn_vdr_risk_asmt.sae_enabled) property. After setting this property, SAE becomes the default assessment engine and replaces the legacy experience to ensure consistency, scalability, and innovation moving forward. While this transition isn't
reversible, it empowers customers to future-proof their assessment strategy with an engine built to evolve with emerging needs.{#grc-tprm-upgrade-info__grc-tprm-upgrade-info-2}  
Warning:  
Set this property in your non-production instances and conduct thorough testing before changing your production instances. Failure to do so may result in unexpected issues.

## Plugin dependencies {#grc-tprm-upgrade-info__section_ekf_sss_rfc}

After upgrading to Zurich and setting the Smart Assessment Engine enabled (sn_vdr_risk_asmt.sae_enabled) property, the following applications and plugins are installed automatically:

* The Vendor Risk Management Workspace application \[sn_vrm_ws\] is automatically installed so you can use the Vendor Risk Management workspace where you can access SAE questionnaires and features.
* The Smart Assessment Engine application and plugins are automatically installed enabling you to use the features of the Smart Assessment Engine for your assessments.

  Smart Assessment Engine application package that includes the following:
  * Smart Assessment Core plugin \[com.sn_smart_asmt\]
  * Smart Assessment Designer plugin \[com.sn_smart_asmt_desg\]
  * Smart Assessment Connected plugin \[com.sn_smart_asmt_conn\]
  * Smart Assessment Migration Tools plugin \[com.sn_smart_asmt_mig\]
  * Smart Assessment Dependencies plugin \[com.sn_smart_asmt_dep\]
  * Smart Assessment Post-assessment Actions plugin \[com.sn_impact_fwk\] and \[com.sn_smart_imp_auto\]
  * Smart Assessment Response Automation plugin \[com.sn_smart_resp_auto\]
  * Smart Assessment Scoring plugin \[com.sn_smart_scoring\]
  {#grc-tprm-upgrade-info__ul_bst_zb5_rfc}

{#grc-tprm-upgrade-info__ul_njd_cb5_rfc}  
Note:  
For more information on these plugins, see [Configuring Smart Assessment Engine](https://www.servicenow.com/docs/access?context=smart-assessment-engine-cf-config&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US) and [Smart assessment configuration](https://www.servicenow.com/docs/access?context=tprm-sae-assessment-config&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US).

## Migrating to Smart Assessment Engine {#grc-tprm-upgrade-info__section_hgb_cj5_rfc}

After setting the Smart Assessment Engine enabled (sn_vdr_risk_asmt.sae_enabled) property, all TPRM assessments will automatically use SAE templates and automation rules (tier-based rules, provider-based rules, event-driven rules and issue generation rules) that support SAE only. You will be able to continue any in-flight assessment until they are completed. You will not be able to create any new assessments with classic questionnaire
templates.

The following diagram shows the questionnaire to TPRM
SAE template migration workflow.  
Figure 1. SAE migration workflow  
1. Migrate templates either one by one or in bulk. After migration, all templates are in the Draft state by default.
2. Review each migrated questionnaire template individually to confirm that they're accurate and complete.
3. Publish TPRM SAE questionnaire templates. After publishing, the following actions occur automatically:
   * All the related assessment templates are updated to use the migrated questionnaire template. If all the questionnaire templates in an assessment template are published, the assessment template is automatically marked as Support smart assessment.
   * All issue generation rules are automatically marked as Support smart assessment if their related questionnaire template is published.
   * All automation rules (tier-based rules, provider-based rules, event-driven rules and issue generation rules) are automatically marked as Support smart assessment after their related assessment template is marked as Support smart assessment.

   {#grc-tprm-upgrade-info__ul_pkh_2kd_cgc}  
   Note:  
   For Issue-generation rules to work as expected when applied to an TPRM SAE questionnaire template, at least one question must have the option, Enable preferred response, set to true.
4. Review each assessment template to confirm it's marked as Supports smart assessment. If an assessment template isn't marked as Supports smart assessment, manually adding a new TPRM SAE questionnaire template to it updates its status.
{#grc-tprm-upgrade-info__ol_zgq_xsq_xfc}

For more information, see [Migrate a template to an SAE template](https://www.servicenow.com/docs/access?context=tprm-asmnt-tmplt-migrate-metrics-to&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US), [Create a TPRM
SAE questionnaire or document request template](https://www.servicenow.com/docs/access?context=create-sae-q-template&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US), [Create an external assessment template](https://www.servicenow.com/docs/access?context=create-vendor-risk-assess-temp&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US), and [Create an issue generation rule](https://www.servicenow.com/docs/access?context=tprm-generate-issue-rule&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US).

## Classic assessment engine to Smart Assessment Engine comparison {#grc-tprm-upgrade-info__section_r1w_zj5_rfc}

The following table shows the comparable features between the Classic assessment engine and Smart Assessment Engine.
{#grc-tprm-upgrade-info__table_vkx_hjq_hcc__entry__2}

| Classic assessment engine features | Smart assessment engine features |
|-|-|
| Metric Type​ | Template |
| Metric Category | Section |
| Metrics | Questions |
| Additional Information​ | Justification |
| Assessable Record | Scope |
| Multiple Assessable Records in one Assessment | Combined Assessments |
| Schedule and Trigger Assessments | Trigger Assessment Flow Action |
| Domain Separation | Domain Separation |
| Question Dependency | Conditional Visibility |
| Correct Answer | Preferred Answer |
| Scoring | Scoring |
| Automated response | Response Automation |
[Table 1. Comparable features]

{#grc-tprm-upgrade-info__table_vkx_hjq_hcc}

The following diagram shows the relationship between assessment templates and questionnaires after upgrading.  
Figure 2. Assessment templates post-upgrade

* Before setting the Smart Assessment Engine enabled (sn_vdr_risk_asmt.sae_enabled) property, the following are used by default.
  * Existing questionnaire templates
  * Existing assessments
  {#grc-tprm-upgrade-info__ul_jdg_3nq_xfc}
* After setting the Smart Assessment Engine enabled (sn_vdr_risk_asmt.sae_enabled) property, the following are used by default.
  * SAE questionnaire templates (New or migrated).
  * Assessments marked as Supports smart assessment.
  * Tier-based, Provider-based, and Event-driven management rules only work with assessments marked as Supports smart assessment.
  {#grc-tprm-upgrade-info__ul_iqj_znq_xfc}

{#grc-tprm-upgrade-info__ul_wnq_2nq_xfc}  
Note:  
All questionnaire templates must be reviewed and published. All assessment templates and automation rules must be reviewed to confirm they're marked as Supports smart assessment.

## Smart Assessment Engine limitations {#grc-tprm-upgrade-info__section_k41_ch5_rfc}

The TPRM SAE questionnaire template has the following limitations.

* All new assessments must use SAE questionnaire templates.
* Third-party risk assessors can no longer create issues from the View responses page. Issues generation rules can be used to create issues automatically.
* The signature feature isn't supported.
* Automatic attachment of questionnaires to external assessments based on inherent risk questionnaire (IRQ) responses or IRQ-calculated risk tiers is currently not supported in Smart Assessment Engine.
* The following question types aren't supported: percentage, ranking, image scale, and custom metric. You must either convert these question types to supported formats before migration or create new questions in the template designer after migration.  
  Note:  
  For the percentage and image scale question types, customers can use the Number type and Radio button type, respectively. Ranking and custom metric question types aren't supported. You must either convert these question types to supported formats before migration or create new questions in the template designer after migration.
* If a section in the classic template contains only unsupported questions, an empty section is created in the TPRM SAE template. TPRM SAE templates with empty sections can't be published; therefore, you must either add replacement questions to these sections or delete the empty sections before publishing.

  For more information on migration results, migration limitations, and creating TPRM
  SAE questionnaires, see [Results of migrating a template to a TPRM
  SAE template](https://www.servicenow.com/docs/access?context=tprm-migrate-asmnt-template-result&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US) and [Create a TPRM
  SAE questionnaire or document request template](https://www.servicenow.com/docs/access?context=create-sae-q-template&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US).
* The TPRM scoring migration proceeds only if there were no errors during the template migration. If there were errors, the TPRM scoring migration doesn't occur.

  For more information, see [Configure scoring for an assessment](https://www.servicenow.com/docs/access?context=configure-scoring-for-assessments&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US) and [Normalization in assessment](https://www.servicenow.com/docs/access?context=normalization-in-assessment&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US).
* Event-driven management rules are the default option for scheduling assessments and replaces Repeating assessments.

## External assessment status changes when enabling SAE {#grc-tprm-upgrade-info__section_sae_status_vocab}

When you enable the Smart Assessment Engine (SAE) after upgrading to Zurich, external assessment statuses change to reflect the SAE lifecycle. The following table shows how Classic engine assessment statuses map to SAE assessment statuses.
{#grc-tprm-upgrade-info__table_sae_status_vocab__entry__2}

| Classic engine status | SAE status (Zurich and later) |
|-|-|
| Responses received | Submitted to third party |
| Returned | In progress |
[Table 2. External assessment status changes: Classic engine to SAE]

{#grc-tprm-upgrade-info__table_sae_status_vocab}

These status changes apply only when SAE is enabled. Assessments that continue to use the Classic engine retain the original states. For more information about the SAE assessment and questionnaire lifecycle, see [External assessment lifecycle states](https://www.servicenow.com/docs/access?context=tprm-external-assessment-lifecycle&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US).

## Important information for upgrading Vendor Risk Management to Australia {#grc-tprm-upgrade-info__section_cqv_gbn_k2c}

Starting with the Vancouver release, if you're a VRM user upgrading to TPRM, from an earlier release, you must run each upgrade sequentially to ensure that fix scripts run correctly. This means upgrading from one release to the next rather than skipping
to the latest release. Not running scripts in the correct order can result in data inconsistencies, broken functionalities, and conflicts.

## Plugin requirements {#grc-tprm-upgrade-info__section_j3v_hcn_k2c}

TPRM

* Activate the Third-party Risk Management application \[com.sn_vdr_risk_asmt\].
* Activate the Third-party Risk Due Diligence application \[com.sn_tprm_dd\].
* Activate the Vendor Risk Management Workspace application \[sn_vrm_ws\] if you want to use the Vendor Risk Management workspace.
{#grc-tprm-upgrade-info__ul_fs5_3cn_k2c}  
VRM

* Activate the Vendor Risk Management application \[com.sn_vdr_risk_asmt\].
* Activate the Vendor Risk Management Workspace application \[sn_vrm_ws\] if you want to use the Vendor Risk Management workspace.
{#grc-tprm-upgrade-info__ul_tmg_mcn_k2c}

For more information on licensing or metering, see [Tracking a managed activity](https://www.servicenow.com/docs/access?context=tprm-managed-activity&version=australia&pubname=australia-governance-risk-compliance&ft:locale=en-US), [Third-party Risk Management (TPRM) Licensing](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1431058), and [Vendor Risk Management (VRM) Licensing](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1362674).

## VRM to TPRM changes {#grc-tprm-upgrade-info__section_lkp_3bn_k2c}

* The name of the application changed from Vendor Risk Management to Third-party Risk Management as part of the Vancouver release.
* The internal assessment \[sn_vdr_asmt_internal_assessment\] table is introduced, extending the tiering assessment \[sn_vdr_risk_asmt_vdr_tiering_assessment\] table.
* The Due Diligence Review (DDR) workflow is introduced, which uses both the internal assessment and the external (VRA) assessment.  
  Note:  
  If you have customizations on the Tiering assessment \[sn_vdr_risk_asmt_vdr_tiering_assessment\] and VRA \[sn_vdr_risk_asmt_assessment\] tables, they might need modifications to work with the DDR workflow.
* The Third-party Scores \[sn_vdr_risk_asmt_security_score\] table has been relabeled to Risk Intelligence Scores \[sn_vdr_risk_asmt_security_score\] to reduce confusion.
* All instances of "vendor" are changed to "third party" in the user interface, though some global instances might remain unchanged.  
  Note:  
  If you don't want to use the due diligence workflow, your original workflow (Tiering assessment and External assessments (VRAs) should be the same).
{#grc-tprm-upgrade-info__ul_ovg_mbn_k2c}

## VRM and TPRM data model {#grc-tprm-upgrade-info__section_dnp_sbn_k2c}

The Vendor Risk Management data model primarily uses the term "vendor" and includes the Tiering assessment \[sn_vdr_risk_asmt_vdr_tiering_assessment\] and VRA \[sn_vdr_risk_asmt_assessment\] tables.

The Third-party Risk Management data model uses the term "third-party" in most user interface elements and introduces the DDR workflow, which uses both internal \[sn_vdr_asmt_internal_assessment\] and
\[sn_vdr_risk_asmt_assessment\] external assessments.

The following models show VRM's and TPRM's capabilities.  
Figure 3. VRM data model

The components included in the Vendor Risk Management data model are as follows:  
* Tiering assessment \[sn_vdr_risk_asmt_vdr_tiering_assessment\]
* Company \[core_company\]
* Vendor risk assessment \[sn_vdr_risk_asmt_assessment\]
* Vendor engagement \[sn_vdr_risk_asmt_vendor_engagement\]
* Vendor contact \[vm_dr_contact\]
* Assessment metric type \[asmt_metric_type\]
* Assessment template \[sn_vdr_risk_asmt_assessment_template\]
* Engagement risk scoring rule \[sn_vdr_risk_asmt_engagement_risk_scoring_rule\]
* Engagement level risk rating \[sn_vdr_risk_asmt_engagement_level_rating\]
{#grc-tprm-upgrade-info__ul_c4l_23n_k2c}  
Figure 4. TPRM data model

The components included in the Third-party Risk Management data model are as follows:  
* Risk intelligence score \[sn_vdr_risk_asmt_security _score\]
* Internal assessment \[sn_vdr_asmt_internal_assessment\]
* Tiering assessment \[sn_vdr_risk_asmt_vdr_tiering_assessment\]
* Event-driven management history \[sn_tprm_dd_rule_execution_history\]
* Third-party due diligence request \[sn_tprm_dd_request\]
* Company \[core_company\]
* Event-driven management rule \[sn_tprm_dd_generation_rule\]
* Third-party risk assessment \[sn_vdr_risk_asmt_assessment\]
* Third-party engagement \[sn_vdr_risk_asmt_vendor_engagement\]
* Vendor contact \[vm_dr_contact\]
* Assessment metric type \[asmt_metric_type\]
* Assessment template \[sn_vdr_risk_asmt_assessment_template\]
* Third-party risk issue \[sn_vdr_risk_asmt_issue\]
* Engagement risk scoring rule \[sn_vdr_risk_asmt_engagement_risk_scoring_rule\]
* Engagement level risk rating \[sn_vdr_risk_asmt_engagement_level_rating\]
{#grc-tprm-upgrade-info__ul_v5z_f4n_bcc}

