Roles in Third-party Risk Management
Summarize
Summary of Roles in Third-party Risk Management
In Third-party Risk Management (TPRM) on ServiceNow, roles define permissions and access levels to manage third-party contacts, assessments, questionnaires, and risk-related activities. Assigning appropriate roles to users ensures controlled, secure, and efficient management of third-party risk processes.
Show less
Key Roles and Their Responsibilities
- Third-party reader [vendorreader]: Read-only access to third-party contact records.
- Third-party editor [vendoreditor]: Can create, update, and delete third-party contact records.
- Third-party assessment reviewer [snvdrriskasmt.vendorassessmentreviewer]: Views assessment and questionnaire data and can comment on risk-related tables; this is the minimum role to view TPRM templates.
- TPR assessor [snvdrriskasmt.vendorassessor]: All reviewer permissions plus managing third parties, contacts, assessments, and risk issues; can be configured to answer or modify questionnaire responses.
- TPR approver [snvdrriskasmt.approver]: Reviewer permissions plus approval capabilities for Internal Risk Questionnaires (IRQs).
- TPR manager [snvdrriskasmt.vendorriskmanager]: Assessor permissions plus managing assessment templates, scheduled assessments, engagements, contacts, and scoring rules.
- TPR admin [snvdrriskasmt.vendorriskadmin]: Manager permissions plus creating and editing assessment, tiering, questionnaire, document request templates, and post-assessment automation rules.
- Contract risk negotiator [snvdrriskasmt.contractnegotiator]: Assessor permissions plus legal team access to modify contract statuses and dates; typically assigned to legal users.
- Third-party contact [vendorcontact]: External users assigned by third-party organizations to respond to questionnaires, tasks, and issues via the Third-party portal; access is limited to external portal functions only.
Roles for Digital Resilience Third-party Registers
- TPRM DORA user [sndoraaccel.user]: Included in Third-party assessment reviewer and TPR approver roles; grants access to Digital Resilience modules.
- TPRM DORA manager [sndoraaccel.manager]: Included in TPR assessor and manager roles.
- TPRM DORA admin [sndoraaccel.admin]: Included in TPR admin role.
Roles for Smart Assessment Engine (SAE)
- Template and assessment viewers: Roles like TPRM SAE template reader and assessment reader allow users to view SAE templates and assessments.
- Questionnaire responders: Internal and external assessment user roles enable responding to questionnaires via various portals; these roles are automatically assigned as appropriate.
- SAE admin and automation creators: Roles that enable creating SAE templates and post-assessment automation rules; included in the TPR admin role.
- Minimum role to view SAE templates: Third-party assessment reviewer role is required to access TPRM external and internal questionnaire templates.
Roles for ServiceNow Otto for TPRM
- Third-party assessment reviewers can use ServiceNow Otto skills for TPRM.
- The TPRM GenAI User role is automatically granted to Third-party assessment reviewers after installing the ServiceNow Otto for TPRM application.
Practical Application for ServiceNow Customers
Assigning the correct TPRM roles ensures users have appropriate access to perform their responsibilities securely and efficiently. Roles range from read-only viewers to administrators who manage templates and automation. External third-party contacts have limited portal access to protect your ServiceNow environment. Additionally, integration with Digital Resilience registers, Smart Assessment Engine, and ServiceNow Otto expands functionality but requires specific roles for access and use.
For effective role management, assign roles according to user responsibilities, and leverage user groups where applicable, such as adding legal users to the Contract risk negotiators group. Understanding these roles helps maintain compliance, streamline third-party risk processes, and enhance collaboration between internal teams and external vendors.
Roles determine permissions and access in TPRM.
TPRM roles
| Friendly name [role name] | Description | Contains roles |
|---|---|---|
| Third-party reader [vendor_reader] |
Read access to third-party contact records. | None |
| Third-party editor [vendor_editor] |
Create/update/delete third-party contact records. | None |
| Third-party assessment reviewer [sn_vdr_risk_asmt.vendor_assessment_reviewer] |
View assessment and questionnaire data. In addition to viewing, they can leave comments on the following tables:
|
Contains:
|
TPR assessor (Third-party risk assessor) [sn_vdr_risk_asmt.vendor_assessor] |
|
Contains:
|
TPR approver [sn_vdr_risk_asmt.approver] |
Includes all permissions of the Third-party assessment reviewer role plus: approve IRQs. |
Contains:
|
| TPR manager (Third-party risk manager) [sn_vdr_risk_asmt.vendor_risk_manager] |
Includes all permissions of the TPR assessor role plus:
|
Contains:
|
| TPR admin (Third-party risk admin) [sn_vdr_risk_asmt.vendor_risk_admin] |
Includes all permissions of the TPR manager role plus: Create and edit the following items:
Note: All the templates include both classic and SAE templates. |
Contains:
|
| Contract risk negotiator [sn_vdr_risk_asmt.contract_negotiator] |
Includes all permissions of the TPR assessor role plus: Gives users in the legal department access to modify contract status and the start and expiration dates. You can add users with this role to the Contract risk negotiators user group. See Add users to groups based on responsibilities. |
Contains:
|
[vendor_contact]
|
You assign the third-party contact role to users at the third-party organization whose risk is being assessed. Third-party contacts are assigned the snc_external role to give them access to resources and actions in the Third-party portal. Important:
The third-party contact role should be used only for external contacts. The role prohibits access to your ServiceNow AI Platform instance and grants access only to the Third-party portal. You assign the primary contact responsibility to the third-party contact who can directly answer assessment questions or assign another contact at the third party to answer the questions. Primary contacts can manage other contacts for the third party. |
Contains: snc_external |
Roles required for accessing the Digital resilience third-party registers
- TPRM DORA user [sn_dora_accel.user] role
Third-party assessment reviewer and TPR approver contain this role.
- TPRM DORA manager [sn_dora_accel.manager] role
TPR assessor and TPR manager contain this role.
- TPRM DORA admin [sn_dora_accel.admin]
The TPR admin contains this role.
Roles required for using Smart Assessment Engine
- TPRM
SAE template reader [sn_smart_asmt.template_reader] role
Third-party assessment reviewer contains this role.
- TPRM
SAE assessment reader [sn_smart_asmt.assessment_reader] role
Third-party assessment reviewer contains this role.
- TPRM
SAE internal assessment user [sn_vdr_risk_asmt.internal_assessment_responder]
This role is automatically assigned to an assigned IRQ assessor or internal assessment respondent.
This role is required to respond to internal/IRQ assessment questionnaires using the GRC Portal.
This role contains the following roles: sn_grc_business_user, canvas_user, and sn_smart_asmt.actor.
- TPRMSAE external assessment user [sn_vdr_risk_asmt.external_assessment_responder]
This role is automatically assigned to the assigned third-party contact.
This role is required to respond to external questionnaires using the Third-party portal.
This contains the role: sn_smart_asmt.actor.
A user with the TPRM SAE admin [sn_smart_asmt.assessment_admin] role can create SAE templates in the Vendor Management Workspace and Assessment Workspace.
Third-party admin contains this role.
A user with the sn_smart_imp_auto.automation_creator role can create post assessment impact automation rules.
Third-party admin contains this role.
For more information on SAE related roles, see Roles in Smart Assessment Engine.
Roles required for using ServiceNow Otto for Third-party Risk Management (TPRM)
A user with the Third-party Assessment reviewer [sn_vdr_risk_asmt.vendor_assessment_reviewer] role can use the ServiceNow Otto for TPRM skills.
The TPRM GenAI User [sn_tprm_genai.nowassist_user] role is granted to Third-party Assessment reviewers [sn_vdr_risk_asmt.vendor_assessment_reviewer] automatically after you install the ServiceNow Otto for TPRM application. For more information about a ServiceNow Otto for TPRM, see ServiceNow Otto for Third-party Risk Management (TPRM).