Assessing your third-party risk
Summarize
Summary of Assessing your third-party risk
ServiceNow's Third-party Risk Management (TPRM) enables organizations to identify, assess, and mitigate risks associated with third-party relationships. By collecting data through internal and external questionnaires and document requests, TPRM helps you evaluate a third party’s risk profile, compliance status, and operational capabilities. This process supports informed decision-making and ensures third parties meet necessary compliance and security standards.
Show less
Questionnaire Response Processes
The assessment workflow involves several key processes:
- Inherent Risk Questionnaire (IRQ) process: After approval, the IRQ is assigned to an internal assessor who completes the questionnaire. The TPR manager reviews responses and updates the due diligence request status accordingly. Note that questionnaire templates should not be modified once sent; instead, duplicate and update copies to maintain version integrity.
- Third-party (TP) Element Collection process: Post-IRQ, if additional data is required, questionnaires are sent to third-party contacts to collect specific element information. Responses are reviewed and recorded as TP element records, which are optionally included in the due diligence workflow.
- Due Diligence process: Following IRQ and TP element collection, external assessments with questionnaires and document requests are sent to third parties or engagements. The TPR manager reviews responses, manages remediation tasks if needed, and determines compliance with laws, regulations, and security standards.
Key Features
- Questionnaire and Document Request Templates: Templates can be created and grouped into assessment templates for reuse, streamlining the process for similar third parties.
- Pre-populating Questionnaires: Responses from previously completed questionnaires can be copied to new assessments to accelerate completion, though some question types cannot be pre-populated.
- Issue and Task Management: Roles such as TPR assessor can create and manage tasks and issues to address concerns arising from questionnaire responses or document requests, ensuring accountability and resolution.
- Assessment Lifecycle Actions: Assessments can be reopened to collect additional information or canceled if no further evaluation is needed, while still proceeding to approval.
Key Outcomes
By implementing these processes, ServiceNow customers can:
- Gain a comprehensive understanding of third-party risk profiles including financial stability, compliance, operational capacity, and security posture.
- Ensure third parties meet regulatory and internal compliance requirements through structured due diligence and documentation.
- Efficiently manage assessment workflows with reusable templates, automated notifications, and pre-populated data to reduce manual effort.
- Maintain clear accountability and remediation through task and issue tracking tied to risk assessments.
- Adapt assessments dynamically by reopening or canceling as business needs evolve, without disrupting overall due diligence governance.
Use Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships. The information gathered from internal questionnaires, external questionnaires, and documentation requests helps you to understand the third party's risk profile, determine the appropriate risk mitigation strategies, and determine whether the third party or engagement meets all necessary compliance requirements.
Responding to questionnaires
The following processes outline the timing and methods for responding to internal and external questionnaires:
- Inherent Risk Questionnaire (IRQ) process
-
The following infographic shows the IRQ process.
- Third-party (TP) element collection process: Collect TP element information
-
The following infographic shows the TP element collection process.
- Due diligence process: Compliance verification
-
The following infographic shows the due diligence process.
Pre-populate questionnaires with responses
When a third-party or engagement contact opens a pre-populated questionnaire in the Third-party portal, they receive a notification that the responses were copied from an earlier questionnaire. The notification includes a link to the assessment that supplied the responses and its last updated date as shown in the following example.
- Some question types and their responses can’t be pre-populated such as the attachment, duration, and signature question types. These question responses remain blank and previous responses aren’t included.
- Responses are copied from the original assessment (Assessment A) to the newer assessment (Assessment B) one time. This copying occurs when Assessment B is submitted to a third party or an engagement. Any changes you make to Assessment A afterward won't be reflected in Assessment B. Both assessments remain separate.
Issues and tasks
The role of TPR assessor [sn_vdr_risk_asmt.vendor_assessor] is required to create and manage both tasks and issues.
The TPR manager, TPR assessor, or contract negotiator can create tasks to help ensure that a team member or the third-party contact responds to concerns about the questionnaire responses or requested documents. They can manage existing tasks to verify that the assigned team member or third-party contact responds to a task and updates it as needed. For more information about creating and managing issues, see Create a task for a third party or engagement and Manage a task for a third party or engagement.
The TPR manager, TPR assessor, or contract negotiator can create an issue to help ensure the teams concerns about a third party or engagement are remediated. They can also manage the existing issues to verify that they’re understood, shared with the correct persons, and are acted on as needed. For more information about creating and managing tasks, see Create an issue for a third party or engagement and Manage issues.
Additional assessment actions
The TPR manager, due-diligence request owner, or contract negotiator may need to reopen an assessment because there’s new information available that impacts the engagement or some other change has occurred. For more information, see Why you conduct due diligence.
- Navigate to the Due diligence request record page by selecting the relevant DDR number.
- View the related third-party risk assessment by selecting the VRA number on the External assessments tab.
- Select Re-open.
The due diligence request state updates from Ready for TPRM approval to Due diligence. The TPR manager, owner, or contract negotiator can request questionnaires and document requests as needed. For more information, see Reopen an assessment.
- Navigate to the Due diligence request record page by selecting the relevant DDR number.
- View the related third-party risk assessment by selecting the VRA number on the External assessments tab.
- Select Cancel.