Best Practices for cleaning up third-party vendor engagements
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
Looking for best practices for managing large numbers of engagements under a vendor
Colleagues who work in TPRM in my organization are dismayed that some of our third-party vendor records have dozens of engagements associated with them (sometimes 50+). As a result, it's becoming increasingly difficult for users to:
- Quickly locate an existing engagement.
- Determine whether a new assessment should be created under an existing engagement.
- Decide when a new engagement should be created instead.
The current proposal is to retire old engagements and have users filter their views to display only active engagements.
I've been testing engagement retirement/reactivation, and unlike say retiring entities, it appears changing the state of an engagement to 'retired' only changes the engagement record (specifically its status) and does not affect other records. Is that understanding correct?
I'm interested in hearing how others manage engagement sprawl under vendors. Specifically:
- Do you retire old engagements, or use another approach?
- Are there any drawbacks or unintended consequences to retiring and later reactivating engagements?
- What naming conventions, governance processes, or other best practices have you implemented to keep engagements organized and easy to navigate?
I'd appreciate any recommendations or lessons learned from organizations managing a large volume of engagements in ServiceNow GRC.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
We ran into a similar challenge with engagement sprawl, and retiring old engagements helped, but it wasn’t the only solution. The biggest improvement came from putting some governance around when a new engagement should be created versus when an existing one should be reused.
A consistent naming convention (vendor + service type + business owner + year, for example) and clear ownership rules can make a huge difference. We also found it helpful to regularly review inactive engagements and archive them from normal user views while keeping the historical data available for reporting.
I agree that simply changing the status may not solve the navigation problem by itself. The goal should be making active engagements easy to find while still preserving the audit trail. ServiceNow TPRM works best when the engagement lifecycle and data structure are managed intentionally rather than allowing records to grow without controls.
Curious if others have implemented automated cleanup reviews or dashboards to identify vendors with a high number of engagements before they become difficult to manage.
