---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Create a VRM third party record

# Create a VRM third party record {#ariaid-title1}

* Release version: Yokohama
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read

Set up the key data and contact information for a third party that your organization will engage.

## Before you begin

Contact your system administrator before you update the portfolio of third parties.

Role required: sn_vdr_risk_asmt.vendor_risk_manager or sn_vdr_risk_asmt.vendor_risk_admin

## About this task

In addition to adding new records, TPR managers make ongoing updates to third-party information, including risk security scores, risk tiers, critical third-party contacts, and the business services that
the third parties fulfill.
You can import third-party data from a spreadsheet, integrate the data from an onboarding system, or import data from the vendor table.

## Procedure

1. Use either of the following methods to start the process:
   * In the Vendor Management Workspace, select the list icon ![]() and then navigate to Third partiesAll Third parties.
   * Navigate to AllThird-party Risk ManagementAll Third parties.
   {#tprm-ws-third-party-create-new__choices_ds3_gkl_dyb}
2. Select New and then fill in the fields.  
   {#tprm-ws-third-party-create-new__table_epy_qrq_f5__entry__2}

   | Field | Description |
   |-|-|
   | Name | Third party name. |
   | Website | URL for the third party. |
   | DUNS number | Unique numeric identifier for the single business entity. A DUNS number is not legally required for a business. |
   | Industry | Type of industry. |
   | Vendor type | Specify the type of product or service that the third party will provide. |
   | Parent | If you set up third-party hierarchies, and this third party is a subsidiary, select the parent third party. |
   | Total annual spend | Expected amount that you expect to spend annually on this third party. |
   | Security Score | The security score provided by a risk intelligence provider. |
   | Score provider | The risk intelligence provider that provided the normalized security score. |
   | Status | Status of the third party. |
   | Contract start date | Date that the contracted engagement should start. |
   | Risk rating | After third-party risk assessment responses have been received, this weighted average of the components (that is, the risk ratings of assessments, engagements, and subsidiaries) is calculated. For more information, see [Setting up VRM third-party hierarchies and engagements](https://servicenow-prod.fluidtopics.net/tva8YavgrKLqzOawglm18g "Create third-party hierarchies by defining the parent-child relationships between the parent third party and all of their subsidiaries. You do this task because some organizations work with third parties that have subsidiaries (or subsidiaries of subsidiaries) that can pose a potential risk to your business. You can perform assessments at each subsidiary organization and roll up the results to calculate an overall risk score for the parent third party."). |
   | Rank tier | Type of supplier. |
   | Third-party tier | Risk tier for the third party calculated by mapping the tiering score to a risk tier. |
   | Vendor manager | The employee assigned as the manager to this third party. |
   | Business owner | The employees that use this third party in their daily business. |
   | Notes | Additional information. |
   | Contact tab ||
   | Street | Street address of third party. |
   | City | City of third party. |
   | State / Province | State or Province of the third party. |
   | Zip / Postal code | Zip code or postal code of the third party. |
   | Country | Country of the third party. |
   | Phone | Phone number of the third party. |
   | Fax phone | Fax number of the third party. |
   | Profile tab ||
   | Publicly traded | Is the third party publicly traded? |
   | Stock symbol | Stock symbol of the third party. |
   | Revenue per year | Annual revenue of the third party. |
   | Number of employees | Count of the third party's employees. |
   | Banner image | Banner image for the third party. |
   | Banner text | Banner text for the third party. |
   | Risk Scoring tab ||
   | Computed risk rating | Average of the third-party risk area risk ratings. |
   | Override risk rating | Enables you to override the computer risk rating for the third party. |
   | Assessment risk rating | Calculated risk assessment rating. The risk rating scale helps business users better understand risk assessment results. For example, in the default settings, risk scores in the 20 through 39 range indicate high risk, while scores in the 60 through 79 range indicate low risk. |
   | Engagement risk rating | Calculated engagement rating. The risk rating scale helps business users better understand risk assessment results. For example, in the default settings, risk scores in the 20 through 39 range indicate high risk, while scores in the 60 through 79 range indicate low risk. |
   | Subsidiary risk rating Child third-party risk rating | Calculated risk rating for subsidiaries. The risk rating scale helps business users better understand risk assessment results. For example, in the default settings, risk scores in the 20 through 39 range indicate high risk, while scores in the 60 through 79 range indicate low risk. |
   | Risk intelligence rating | See [Integrating scores from risk intelligence providers](https://servicenow-prod.fluidtopics.net/w82CPzWn0lb8NllJVqjiHw "Risk intelligence providers generate risk scores for a variety of third-party risk domains. Your organization can purchase services from providers that return data that is analogous to personal credit scores. The scores provide insight on how trustworthy and safe a particular third party can be."). |
   | Overridden risk rating | If you selected Override risk rating, enter the new risk rating. |
   | Overridden on | If you selected Override risk rating, date that the override occurred. |
   | Justification | If you selected Override risk rating, you must enter a reason for the override. |
   [Table 1. Third party form]

   {#tprm-ws-third-party-create-new__table_epy_qrq_f5}
3. If Third-party Risk Management is integrated with other GRC applications, or if you set up vendor hierarchies (that is, third-party risk domains, component criteria, and risk scoring rules), the form can include some or all of the following related lists.  
   For more information, see [Setting up VRM third-party hierarchies and engagements](https://servicenow-prod.fluidtopics.net/tva8YavgrKLqzOawglm18g "Create third-party hierarchies by defining the parent-child relationships between the parent third party and all of their subsidiaries. You do this task because some organizations work with third parties that have subsidiaries (or subsidiaries of subsidiaries) that can pose a potential risk to your business. You can perform assessments at each subsidiary organization and roll up the results to calculate an overall risk score for the parent third party.").  
   Note:  
   Risk domains are called "risk areas" in some platform applications.
   * Child Vendors: This table stores all information for subsidiaries. Subsidiary risk ratings are automatically aggregated and displayed on the Risk Rating tab on the Third-party form.
   * Vendor Contacts: This table stores information for all of the third-party stakeholders. Typically, the customer creates one primary third-party contact and one or more secondary contacts. The primary contact adds other contacts to the list.
   * Business Services: The Services table is part of the CMDB. It relates the third parties to the services they provide. For example, assume the IT team has a service called "Video Conference Services" that is used for internal employees to communicate internally and with customers. That business service, they have decided, comes from Zoom rather than building anything in-house.
   * Vendor Engagements: This table stores all engagement information for third parties. Engagements risk ratings are automatically aggregated as displayed on the Risk rating tab on the Third-party form.
   * Tiering Assessments: This table stores the history of tiering assessments.
   * Repeating Assessments: This table stores the history of recurring assessments.
   * Assessments: This table stores the history of assessments. Assessment risk ratings are automatically aggregated and displayed on the Risk rating tab on the Third-party form.
   * Vendor Risk Components: This table stores all third-party risk components. If third-party risk components (that is, assessments, engagements, or subsidiaries) are present, their risk ratings are automatically aggregated and displayed on the Risk rating tab on the Third-party form.
   * Issues: This table stores the history of issues.
   * Tasks: This table stores the history of tasks.
   {#tprm-ws-third-party-create-new__ul_r4v_x3b_l2b}

*[\>]: and then


