---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Explore

# Exploring Third-party Risk Management {#ariaid-title1}

* Release version: Yokohama
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 9 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Exploring Third-party Risk Management

The Third-party Risk Management (TPRM) application centralizes and standardizes the management of third-party risks related to outsourced providers, partners, and suppliers.
It enables organizations to identify, assess, track, and mitigate risks associated with external engagements, protecting assets, reputation, and operational continuity.
By automating risk assessment workflows, TPRM reduces manual effort and costs while consolidating all third-party risk data into a single environment.
Show full answer Show less  

## Key Features

* **Risk Assessment Workflows:** Includes onboarding, offboarding, renewals, and additional due diligence processes.
* **Assessment Management:** Uses internal and external assessments, including Inherent Risk Questionnaires (IRQ) and third-party element questionnaires, to evaluate risk.
* **Continuous Risk Monitoring:** Supports ongoing observation of third-party risk performance through dashboards and workspace tools.
* **Risk Intelligence Integration:** Allows integration of external risk scores and reports from providers to enhance assessment accuracy.
* **Due Diligence Roles:** Supports distinct user roles such as requesters, assessors (compliance, cybersecurity, operational), approvers, contract negotiators, risk managers, and administrators to ensure thorough risk governance.
* **Contract Risk Management:** Facilitates contract negotiation using due diligence data and tracks contract execution status with notifications to stakeholders.
* **Third-party Portal:** Enables third-party contacts to interact, respond to assessments, delegate tasks, and manage information directly.
* **Data Import Capability:** Supports importing third-party data from other risk platforms without additional charges.

## Third-party Risk Management Workflow

The typical workflow includes:

* Requesting due diligence for third-party engagements by internal employees.
* Conducting internal risk assessments with IRQs, followed by optional third-party element collection.
* Performing external assessments and collecting documentation from third parties.
* Integrating risk intelligence reports and scores to augment internal findings.
* Reviewing and approving due diligence by senior approvers before contract negotiation.
* Negotiating and executing contracts, with automated notifications to relevant parties.
* Monitoring ongoing third-party risk using Vendor Management Workspace and other tools.

## Benefits for ServiceNow Customers

* **Comprehensive Risk Visibility:** Centralized dashboards and reports provide quick access to important risk data, enabling informed decision-making.
* **Efficient Risk Management:** Automation of due diligence and assessment workflows reduces manual work and accelerates processes.
* **Improved Collaboration:** Role-based access and the third-party portal facilitate collaboration among internal teams and external vendors.
* **Better Risk Prioritization:** Tools like risk concentration maps and activity pages help prioritize assessments and issues requiring attention.
* **Seamless Integration:** Ability to import existing third-party data and integrate third-party risk intelligence scores enhances risk assessment quality.
* **Contract Risk Alignment:** Links due diligence outcomes directly to contract negotiation and execution, ensuring risk mitigation is embedded in agreements.

## Next Steps

ServiceNow customers can explore detailed guidance on configuring and using TPRM through specific resources covering:

* Configuring TPRM and assessment engines
* Requesting and managing third-party risk due diligence
* Monitoring and approving risk assessments
* Managing contract risk processes
* Utilizing digital resilience registers and third-party portals
* Integrating and using risk intelligence reports and scores  
The Third-party Risk Management application centralizes and standardizes the processes, source materials, responsible persons, and methods of your third-party risk management program. You can improve your operations by managing your portfolio of third parties and by identifying, tracking, and mitigating the issues that arise with third parties.

## Third-party Risk Management overview {#tprm-exploring__section_gmp_pxq_hzb}

To protect your organization's assets, reputation, and operations, your third-party risk management program must identify, assess, and mitigate the risks that are associated with external parties. The TPRM application helps you to prevent your outsourced providers, partners, and suppliers from creating a business disruption or a negative impact on your business performance. By
using the TPRM application, you can reduce the manual burden and costs of your risk assessment process through automation.

TPRM brings all third-party risk information into one environment.  
The following key capabilities can help you to assess risk more effectively:

* Onboarding, Offboarding, Renewals, and additional due diligence workflows
* Assessment management
* Continuous risk monitoring
* Risk performance management
{#tprm-exploring__ul_r1c_ypx_jzb}

## Third-party Risk Management Users {#tprm-exploring__section_lz3_hvk_rcc}

{#tprm-exploring__table_azr_yvk_rcc__entry__2}

| User | Description |
|-|-|
| Due diligence requesters | Requesters can be any employee at your organization interested in onboarding, reassessing, or offboarding an engagement. For more information on the different types of due diligence requests, see [Requesting third-party risk due diligence](https://servicenow-prod.fluidtopics.net/yUyZFmUWfUXOQzFZd3d7fA "Request third-party risk due diligence to determine the level of risk for interactions with a third party, engagement, or fourth party by using Third-party Risk Management. You conduct due diligence to become aware of the associated risks so that you can make informed decisions, establish appropriate controls, and mitigate the potential negative impact when working with external parties."). |
| TPRM Assessors | TPRM Assessors are members of the Risk manager's team that help with mitigating the risk of a potential engagement by reviewing information collected through the due diligence process. They could be potentially assigned as owners of due diligence requests based on their expertise or knowledge of the engagement. Here are some examples of different types of assessors and how they would impact the due diligence process for TPRM: * **Compliance Risk Assessor**: Confirms that engagements comply with industry standards, legal requirements, and contractual obligations. They regularly review engagement processes and activities to help ensure compliance. * **Cybersecurity Risk Assessor**: Evaluates the cybersecurity practices and infrastructures of engagements to protect against data breaches and cyber threats. They regularly review the engagement's security measures and suggest necessary enhancements. * **Operational Risk Assessor**: Analyzes the existing operational practices of engagements, focusing on aspects such as business continuity, supply chain logistics, and quality of service. They regularly review the engagement's operational practices to help ensure they are in alignment with the organization's standards and that appropriate contingencies are in place for potential disruptions. {#tprm-exploring__ul_jky_x2l_rcc} |
| TPRM Approvers | TPRM approvers are typically a senior member within the organization. They're responsible for the final review and approval of the due diligence findings. They help confirm that all risk management requirements have been satisfactorily addressed before proceeding with any third-party engagement, whether it involves onboarding, continuing, or offboarding an engagement. Here are some examples of different types of approvers: * **Senior Risk Manager**: Oversees risk management strategies and alignment with organizational goals. * **Chief Compliance Officer**: Responsible for the company adhering to legal standards and internal policies. * **Legal Executive**: A senior member of the legal team who ensures that all contractual and regulatory requirements are met. {#tprm-exploring__ul_hvc_nrl_rcc} |
| Contract negotiator | Contract negotiators orchestrate and finalize agreements between your organization and potential engagements. They use all the information collected through the due diligence process to help ensure that all contracts reflect your strategic interests and adhere to your risk management protocols. |
| Risk Manager | Risk managers lead thorough risk assessments of third parties and engagements. Based on the information collected and reviewed by the Risk manager and their team, they prioritize risks, develop mitigation strategies, and use TPRM to monitor and manage ongoing third-party relationships effectively. |
| TPRM Admin | Administrators manage user roles, permissions, and system settings to set up TPRM to meet your organization's specific risk management needs and compliance requirements. |
[Table 1. Users]

{#tprm-exploring__table_azr_yvk_rcc}

For more information on TPRM roles, see [Roles in Third-party Risk Management](https://servicenow-prod.fluidtopics.net/dMM_QNhOPsjr0LzBHA455g "Roles determine permissions and access in TPRM.").

## Third-party Risk Management workflow {#tprm-exploring__section_oqg_bgj_jzb}

The following infographic shows the workflow of the most important processes that you can use to manage risk.  

<br />

Request due diligence for an engagement

:   An employee at your organization requests due diligence for a third-party engagement. The due diligence request is reviewed and approved by the Third-party risk (TPR) manager
    \[sn_vdr_risk_asmt.vendor_risk_manager\].

    For more information, see [Requesting third-party risk due diligence](https://servicenow-prod.fluidtopics.net/yUyZFmUWfUXOQzFZd3d7fA "Request third-party risk due diligence to determine the level of risk for interactions with a third party, engagement, or fourth party by using Third-party Risk Management. You conduct due diligence to become aware of the associated risks so that you can make informed decisions, establish appropriate controls, and mitigate the potential negative impact when working with external parties.").

Assess risk using an internal assessment containing an Inherent Risk Questionnaire (IRQ)

:   An IRQ is a set of questions that scores and scopes the required due diligence on the third parties or engagements. After the due diligence request is approved by the TPR manager or TPR assessor
    \[sn_vdr_risk_asmt.vendor_assessor\] that has been assigned as the owner of the due diligence request, they select an IRQ and attach it to an internal assessment.

    Note:  
    After the IRQ process enters the IRQ in progress state, you can request risk intelligence reports associated with your due diligence request. For more information, see [Using risk intelligence reports and scores](https://servicenow-prod.fluidtopics.net/_WfSOMHVCyhA736OPx2rRw "Request risk intelligence reports or scores directly from your external risk intelligence content providers by using the Third-party Risk Management application. This information can be requested and managed based on the importance or risk level of the individual third party.") and [Request a risk intelligence report associated with a due diligence request](https://servicenow-prod.fluidtopics.net/vP9KI_Bfl2GAgeBBfQIAJw "Request a risk intelligence report (RIR) or score to gain insight on how trustworthy a particular third party can be as part of the due diligence request process by using the Third-party Risk Management application. By associating your RIR request with a due diligence request, all activity, scores, reports, and details are available for you to see.").

    For more information, see [Assessing your third-party risk](https://servicenow-prod.fluidtopics.net/2D8z85RJH2DGftJ3bDcB3w "Use Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships. The information gathered from internal questionnaires, external questionnaires, and documentation requests helps you to understand the third party's risk profile, determine the appropriate risk mitigation strategies, and determine whether the third party or engagement meets all necessary compliance requirements.").

Create third-party elements

:   After your due diligence request has completed the IRQ process, if TP elements are needed, the TPR manager or due diligence request owner selects Start collection and a collection task is
    created. A third-party element questionnaire is sent to the third-party engagement contact. The TPR manager or owner manually creates third-party element records based on the responses.


    For more information, see
    [Assessing your third-party risk](https://servicenow-prod.fluidtopics.net/2D8z85RJH2DGftJ3bDcB3w "Use Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships. The information gathered from internal questionnaires, external questionnaires, and documentation requests helps you to understand the third party's risk profile, determine the appropriate risk mitigation strategies, and determine whether the third party or engagement meets all necessary compliance requirements.") and
    [Monitoring third-party elements](https://servicenow-prod.fluidtopics.net/yOIu5SyPRledcChT1Ekkmw "You can monitor third-party elements through scalable scoring models, relationship analysis, and due diligence workflow integration by using the Third-party Risk Management application. Monitoring third-party elements and leveraging that information can help with conducting more informed risk assessments as part of your third-party risk program.").

Assess risk using an external assessment
:   After the IRQ process or TP element collection process is completed, the TPR manager or owner selects questionnaires and requests for documentation to attach to external assessments for sending to the third party or
    engagement. For more information on creating assessments, see [Create an external assessment](https://servicenow-prod.fluidtopics.net/S6Sqo4CTuE7nNjjFVXs0SQ "Create an assessment and initiate the third-party risk assessment life cycle using Third-party Risk Management. An external assessment specifies the details for the third party or engagement and defines the plan for completing the assessment.") and [Third-party risk assessment form](https://servicenow-prod.fluidtopics.net/IykUUNLGjfRWXGOTyc3R7w "Use the third-party risk assessment form to capture all the information that you need to create an assessment using the Third-party Risk Management application. As a third-party risk assessor or manager, you can create an external assessment.").

    For more information on this process, see [Assessing your third-party risk](https://servicenow-prod.fluidtopics.net/2D8z85RJH2DGftJ3bDcB3w "Use Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships. The information gathered from internal questionnaires, external questionnaires, and documentation requests helps you to understand the third party's risk profile, determine the appropriate risk mitigation strategies, and determine whether the third party or engagement meets all necessary compliance requirements.") and [Monitoring third-party elements](https://servicenow-prod.fluidtopics.net/yOIu5SyPRledcChT1Ekkmw "You can monitor third-party elements through scalable scoring models, relationship analysis, and due diligence workflow integration by using the Third-party Risk Management application. Monitoring third-party elements and leveraging that information can help with conducting more informed risk assessments as part of your third-party risk program.").  
    Note:  
    If you have any integrated risk intelligence, relevant information is pulled at this time.

Integrate scores using risk intelligence providers

:   Your organization can purchase services from providers that return data that is analogous to personal credit scores. The scores provide insight on how trustworthy and safe a particular third party can be.

    For more information, see [Integrating scores from risk intelligence providers](https://servicenow-prod.fluidtopics.net/w82CPzWn0lb8NllJVqjiHw "Risk intelligence providers generate risk scores for a variety of third-party risk domains. Your organization can purchase services from providers that return data that is analogous to personal credit scores. The scores provide insight on how trustworthy and safe a particular third party can be.").

Request risk intelligence reports and scores

:   If you are the TPR assessor and are the due diligence request owner or have the TPR manager role, you can use the TPRM application to request scores or reports for third parties by using the risk intelligence request form. After the reports and scores are generated by the risk
    intelligence provider, the links to these reports are delivered and associated with that risk intelligence report record. If you have any integrated risk intelligence, relevant information is pulled at this time.
    For more information, see [Using risk intelligence reports and scores](https://servicenow-prod.fluidtopics.net/_WfSOMHVCyhA736OPx2rRw "Request risk intelligence reports or scores directly from your external risk intelligence content providers by using the Third-party Risk Management application. This information can be requested and managed based on the importance or risk level of the individual third party.").

View scores and related information

:   The information gathered is scored and combined into a single view of the due diligence process to display all scores, completed questionnaires, issues, approvals, and comments.

    For more information on scoring, see [Scoring calculations using the classic assessment engine](https://servicenow-prod.fluidtopics.net/3qYPn1LOGstG6fXBrf0JtA "Perform a comprehensive external risk assessment when calculating multiple ratings and scores by using the Third-party Risk Management application. You can gain a deeper understanding of the overall calculation process and learn how user-defined parameters and configurations influence the results of the questionnaires.") and [Verifying scoring calculations using the classic assessment engine](https://servicenow-prod.fluidtopics.net/zo_rVMOoPW8S6sjpBVJ3Jg "You can review scores and risk ratings in your questionnaires to help ensure the accuracy and consistency of risk scoring by verifying the correct application of weights, normalized values, scoring methods, and risk rating scales. Based on the different weights you assign, Third-party Risk Management aggregates these values and produces a composite score."). See [Classic assessment configuration](https://servicenow-prod.fluidtopics.net/hD54eFmI~b5A4jvnGQqGOw "The TPR manager and TPR admin roles involve a broad variety of responsibilities. After the TPRM base system is set up, you configure additional settings that enable and enhance everyday risk-assessment tasks.") for information on how scoring can be configured at the assessment and questionnaire level.

Approve due diligence requests

:   All approvers can review due diligence and see the detailed information before making an approval. After all approvers approve the due diligence request, all the due diligence information can be made available for
    the person that is negotiating the contract. The contract risk process only applies if a contract is required.

    For more information, see [Approving or rejecting requests for due diligence](https://servicenow-prod.fluidtopics.net/TcXVhcLyels~nMNkUMJljQ "Set up the approval levels and rules for due diligence requests in the Third-party Risk Management application to use while approving or rejecting requests after reviewing questionnaire responses and due diligence process results.").

Negotiate a contract

:   The contract negotiator can see the detailed information of all the scores and questionnaires. If additional due diligence is required, they can request it. If the contract negotiator successfully executes a
    contract with the third party, they can upload it and specify that the contract is executed. This action automatically notifies all key stakeholders of the contract's status. The contract negotiator can also skip
    the contract risk process, reject the due diligence request, or specify that the contract isn't executed and that the third party isn't engaged for business.

    Note:  
    If the third-party risk manager or owner selects the Skip contract risk process option during the due diligence process, the assigned contract negotiator isn't notified and the Contract risk process state is skipped. An approver and owner can update the Skip contract risk process selection up until the approval process is completed. For more information about this process, see [Due diligence request process management](https://servicenow-prod.fluidtopics.net/N5HrV~dAkko_nDUX5fSZww "From the Details tab, you can view and adjust the due diligence request information for a third party. You can also log external-facing comments and private work notes, attach files, and track request updates in the activity stream.").

    For more information on this process, see [Managing the contract risk process](https://servicenow-prod.fluidtopics.net/zmIET82CJNZfpeGpi98AJQ "Protect your organization's interests, as the Third-party risk contract negotiator, often the corporate counsel, by incorporating specific contractual provisions so that you can address the risks identified using the Third-party Risk Management application.").

Monitor third-party risk
:   TPR managers, TPR assessors, and Third-party assessment reviewers \[sn_vdr_risk_asmt.vendor_assessment_reviewer\] can monitor and review the performance of third parties with Vendor Management Workspace.

    For more information, see [Monitoring your third-party risk](https://servicenow-prod.fluidtopics.net/lTAnrKdaTY93oBnJdecLdg "You can monitor the potential risks that are associated with your third-party relationships by using the Third-party Risk Management application. An ongoing monitoring process can help you regularly assess the third party's performance and adherence to the agreed-upon terms.").

Manage the Third-party portal

:   TPR managers can manage third-party contacts, including creating logins, assigning roles, and tracking progress on questionnaires and tasks through the Third-party portal. Third-party contacts can use the portal
    to respond to assessments, delegate tasks, and manage their information, with options to use Microsoft Excel templates or the SIG questionnaire for responses.

    For more information, see [Managing the contract risk process](https://servicenow-prod.fluidtopics.net/zmIET82CJNZfpeGpi98AJQ "Protect your organization's interests, as the Third-party risk contract negotiator, often the corporate counsel, by incorporating specific contractual provisions so that you can address the risks identified using the Third-party Risk Management application.").

For an in-depth description of the TPRM Due diligence workflow, see [Due diligence workflow](https://servicenow-prod.fluidtopics.net/NLj2bbUiV1F80L9JpZ6N2Q "The Third-party risk management (TPRM) processes provide a consistent framework for your third-party risk management program. You can customize the workflow processes to meet your organization's needs.").  
Note:  
Starting with version 19.1.x of the Third-party Risk Management application, the tiering questionnaire and external assessment reminders workflows are deprecated and migrated to Workflow Studio. If you have customized these workflows, they won't be deprecated or migrated as part of this change.

## Third-party Risk Management benefits {#tprm-exploring__section_fsk_1b5_dyb}

The following table shows the benefits of the Third-party Risk Management application.
{#tprm-exploring__table_gsk_1b5_dyb__entry__3}

| Benefit | Feature | Users |
|-|-|-|
| View important risk information and quickly access actions. | [TPRM Home page](https://servicenow-prod.fluidtopics.net/sPNb~cJdC8fUSOpHIrGfuw "The home page displays reports of important risk information and provides quick access to actions for TPR managers and TPR assessors.") | All TPRM users |
| Use due diligence management reports to track, prioritize, and manage responsibilities. | [TPRM Due diligence management reports](https://servicenow-prod.fluidtopics.net/bT7fWuNnWIoH9ty9xe0Ruw "TPR managers and assessors use the due diligence management reports to track, prioritize, and manage their responsibilities.") | All TPRM users |
| Identify and assess the potential risk that is associated with your third-party relationship. | [TPRM Risk activity page](https://servicenow-prod.fluidtopics.net/tcfhRfd3_R0ccfoq20OePQ "The Risk activity page enables you to quickly identify assessments, issues, and tasks that need attention.") | All TPRM users |
| Pinpoint the geographical locations of active third parties and engagements. You can configure filters to view particular risk ratings and engagement types. | [TPRM Risk concentration map](https://servicenow-prod.fluidtopics.net/tUXHHCGeXb1ATWlfnc3ykQ "The Risk concentration map page pinpoints the geographical locations of active third parties and engagements. You can configure filters to view particular risk ratings and engagement types.") | All TPRM users |
| Prioritize assessments, issues, and tasks that need attention. | [TPRM Risk activity page](https://servicenow-prod.fluidtopics.net/tcfhRfd3_R0ccfoq20OePQ "The Risk activity page enables you to quickly identify assessments, issues, and tasks that need attention.") | All TPRM users |
| Access tasks that are assigned to you and to members of your group. | [TPRM Task page](https://servicenow-prod.fluidtopics.net/nUUYU5QL0Antp9H2s4td9Q "The task page gives you access to tasks that are assigned to you and to members of your group. You can further filter the lists of tasks by due diligence requests, type of third-party action, and by risk or tiering assessment.") | All TPRM users |
| Access all items that you can view or act on in TPRM. | [TPRM List page](https://servicenow-prod.fluidtopics.net/0BxWIn6~lfs32mEcfooWLQ "The List page is a general-purpose page that enables access to all items that you can view or act on in TPRM.") | All TPRM users |
| Use the engagement page to access all current information and status for a third party or engagement. | [Get an overview of a third party](https://servicenow-prod.fluidtopics.net/Yn~FnWNs1aJNbgqn58q5Jw "Use the third party page to access all current information and status for a third party.") | All internal users |
| Import existing data (third parties, engagements, assessments, questionnaires, issues, and so on) from other systems (like the Aravo platform, the ProcessUnity platform, and so on). You aren't charged for importing the data. | [Import existing data from other systems](https://servicenow-prod.fluidtopics.net/u9t2l3Xin_GKQKQlsz2WTA "Import existing data (third parties, engagements, assessments, questionnaires, issues, and so on) from other systems (like the Aravo platform, the ProcessUnity platform, and so on). You aren’t charged for importing the data.") | TPR Managers and TPR Admins |
| Work on all processes in the workflow for a due diligence request: IRQs, external due diligence, approval, contract risk, and closed requests. | [Monitoring the due diligence request process](https://servicenow-prod.fluidtopics.net/MzxFOcReohr~PqhOLpgHNA "TPR managers and TPR admins can perform a wide variety of tasks from the due diligence management dashboard. They can work on all processes in the workflow for a due diligence request: IRQs, external due diligence, approval, contract risk, and closed requests.") | TPR Managers and TPR Admins |
| Use the third-party portal as a primary point of interaction for third parties and risk assessors. | [Managing the Third-party portal](https://servicenow-prod.fluidtopics.net/Ed3AGNrvzA7CQx134MN5lA "Third-party contacts respond to questionnaires, requests for documentation, tasks, and issues on the Third-party portal. The portal is the point of interaction between third parties and risk assessors.") | TPR Managers, TPR Assessors, and Third parties |
[ ]

{#tprm-exploring__table_gsk_1b5_dyb}

For more information on the terminology used in TPRM, see [Terminology](https://servicenow-prod.fluidtopics.net/RlaqlnHXriTIslxtcJ1JCQ "Learn more about the key concepts and terms that are used in the TPRM application.").

## What to explore next {#tprm-exploring__section_gxd_mvh_ldc}

To learn more about configuring and using Third-party Risk Management, see:

* [Configuring Third-party Risk Management](https://servicenow-prod.fluidtopics.net/sw8jnA5HlWn~FCAXDl4QCg "You can activate or upgrade TPRM, by downloading the applications from the ServiceNow Store and then configuring the settings to meet your needs.")
* [Classic assessment configuration](https://servicenow-prod.fluidtopics.net/hD54eFmI~b5A4jvnGQqGOw "The TPR manager and TPR admin roles involve a broad variety of responsibilities. After the TPRM base system is set up, you configure additional settings that enable and enhance everyday risk-assessment tasks.")
* [Smart assessment configuration](https://servicenow-prod.fluidtopics.net/HFvD8YewpjEukyw4MOMTwQ "The TPR manager and TPR admin roles involve a broad variety of responsibilities. After the TPRM base system is set up, you configure Smart Assessment Engine specific settings as well as other assessment settings that enable and enhance everyday risk-assessment tasks. TPRM admins can enable SAE and work with SAE templates.")
* [Requesting third-party risk due diligence](https://servicenow-prod.fluidtopics.net/yUyZFmUWfUXOQzFZd3d7fA "Request third-party risk due diligence to determine the level of risk for interactions with a third party, engagement, or fourth party by using Third-party Risk Management. You conduct due diligence to become aware of the associated risks so that you can make informed decisions, establish appropriate controls, and mitigate the potential negative impact when working with external parties.")
* [Assessing your third-party risk](https://servicenow-prod.fluidtopics.net/2D8z85RJH2DGftJ3bDcB3w "Use Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships. The information gathered from internal questionnaires, external questionnaires, and documentation requests helps you to understand the third party's risk profile, determine the appropriate risk mitigation strategies, and determine whether the third party or engagement meets all necessary compliance requirements.")
* [Monitoring your third-party risk](https://servicenow-prod.fluidtopics.net/lTAnrKdaTY93oBnJdecLdg "You can monitor the potential risks that are associated with your third-party relationships by using the Third-party Risk Management application. An ongoing monitoring process can help you regularly assess the third party's performance and adherence to the agreed-upon terms.")
* [Approving or rejecting requests for due diligence](https://servicenow-prod.fluidtopics.net/TcXVhcLyels~nMNkUMJljQ "Set up the approval levels and rules for due diligence requests in the Third-party Risk Management application to use while approving or rejecting requests after reviewing questionnaire responses and due diligence process results.")
* [Managing the contract risk process](https://servicenow-prod.fluidtopics.net/zmIET82CJNZfpeGpi98AJQ "Protect your organization's interests, as the Third-party risk contract negotiator, often the corporate counsel, by incorporating specific contractual provisions so that you can address the risks identified using the Third-party Risk Management application.")
* [Using digital resilience third-party registers](https://servicenow-prod.fluidtopics.net/63~FjDMHAs74wDAhGYL1nA "Use the Digital Resilience Third-party Information Register application in the Vendor Management Workspace to create, update, and track assessments, branches, legal entities, and so on, and maintain registers of contractual arrangements with ICT third-party service providers.")
* [Managing the Third-party portal](https://servicenow-prod.fluidtopics.net/Ed3AGNrvzA7CQx134MN5lA "Third-party contacts respond to questionnaires, requests for documentation, tasks, and issues on the Third-party portal. The portal is the point of interaction between third parties and risk assessors.")
* [Using risk intelligence reports and scores](https://servicenow-prod.fluidtopics.net/_WfSOMHVCyhA736OPx2rRw "Request risk intelligence reports or scores directly from your external risk intelligence content providers by using the Third-party Risk Management application. This information can be requested and managed based on the importance or risk level of the individual third party.")
* [Integrating scores from risk intelligence providers](https://servicenow-prod.fluidtopics.net/w82CPzWn0lb8NllJVqjiHw "Risk intelligence providers generate risk scores for a variety of third-party risk domains. Your organization can purchase services from providers that return data that is analogous to personal credit scores. The scores provide insight on how trustworthy and safe a particular third party can be.")
* [Third-party Risk Management reference](https://servicenow-prod.fluidtopics.net/FMpsZYgwptxHlMsWusXP2g "Reference topics provide detailed descriptions of tables, properties, forms, and roles that are installed with the Third-party Risk Management application.")
{#tprm-exploring__ul_szq_5vh_ldc}
**Related concepts**   

* [Smart assessments with Third-party Risk Management](https://servicenow-prod.fluidtopics.net/aL9mgEdAzD2F9smCyVLFvA "With the integration of Smart Assessment Engine (SAE), TPRM now supports both the Classic assessment engine and SAE. You can create questionnaire templates and add instructions, questions, and reference information by creating templates using SAE in the Vendor Management Workspace.")

