---
sourceDocument: Zurich Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/governance-risk-compliance

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Request due diligence

# Requesting third-party risk due diligence {#ariaid-title1}

* Release version: Zurich
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Requesting third-party risk due diligence

ServiceNow's Third-party Risk Management enables any employee in your organization to request due diligence on third-party engagements.
This process evaluates the risk associated with interactions involving third parties, subsidiaries, or fourth parties to help you make informed decisions, establish controls, and mitigate potential negative impacts when working with external organizations or individuals.
Show full answer Show less  
An engagement refers to the contracted or informal relationship with a third party outlining services or products provided, which may expose your organization to risk. Due diligence is the investigation or examination of these risks before and during the engagement.

## Due Diligence Request Process

* An employee submits a due diligence request for a third-party engagement.
* The system sends notifications to the requester and the due diligence request assignment group.
* A group member assigns a Third-party risk (TPR) manager or assessor to own the request.
* The system notifies the assigned owner.
* The TPR manager reviews the request and either approves it to start the Inherent Risk Questionnaire (IRQ) process or rejects it if information is insufficient or the engagement is not feasible.

Each due diligence request is automatically assigned a unique ID starting with "DDR" to enable easy tracking. You can communicate with reviewers and attach supporting documents within the request page.

## Types of Due Diligence Requests

* **Onboard a new engagement:** Initiate onboarding for a new engagement with an existing third party.
* **Reassess an existing engagement:** Conduct additional due diligence when conditions change, such as adverse news or supply chain changes.
* **Reassess for contract renewal:** Evaluate risks before renewing contracts with current third parties.
* **Offboard an engagement with due diligence:** Assess whether terminating the relationship is optimal, considering risks and business context.
* **Offboard an engagement without due diligence:** Request permanent termination without additional due diligence when ending engagements or switching third parties; includes the IRQ process to confirm service discontinuation.

## Practical Benefits for ServiceNow Customers

This due diligence process empowers your organization to proactively manage third-party risks throughout the lifecycle of engagements. It ensures transparency and accountability by involving risk managers, automating notifications, and tracking requests efficiently. By leveraging these capabilities, you can reduce exposure to third-party risks, support compliant vendor management, and make well-informed decisions about onboarding, reassessing, or offboarding external partners.  
Request third-party risk due diligence to determine the level of risk for interactions with a third party, engagement, or fourth party by using Third-party Risk Management. You conduct due diligence to become aware of the associated risks so that you can make informed decisions, establish appropriate controls, and mitigate the potential negative impact when working with external parties.
Any employee at your organization can request due diligence, which is an investigation or examination of business relationship risk, for an engagement.

* An engagement is the informal or contracted relationship that you intend to form with a third party that could potentially expose your organization to risk. The engagement outlines the services or products to be provided by the third party and other details of the relationship.
* A third party is any organization or individual that you have interacted or entered into a business relationship with. Third parties can have subsidiaries and can contract with fourth parties. For example, departments are subsidiaries.
* A fourth party can contract with further parties. All downstream parties, such as the fourth through the nth parties, carry risk in the same ways as third parties.
{#tprm-requesting-tpr-due-diligence__ul_pvt_mxy_21c}

For more information about the terms that are used in these sections or why you might conduct due diligence, see [Terminology](https://www.servicenow.com/docs/ESVX_kQkGALx7rrXJl3UIg "Learn more about the key concepts and terms that are used in the TPRM application.") and [Why you conduct due diligence](https://www.servicenow.com/docs/4R0CWp~NuipqRG1GQDaS3g "Conducting due diligence on third parties is a crucial component of your comprehensive third-party risk program. You conduct due diligence to become aware of the risks that are associated with a third party so that you can confidently decide how to form your relationship.").

The following infographic shows the due diligence request process.  

<br />

The following are the steps of the due diligence request process.

1. An employee at your organization requests due diligence for a third-party engagement.
2. The system sends an email notification to the employee who made the request.
3. The system sends an email notification to the Due diligence request assignment group.
4. A member of the group can assign a Third-party risk (TPR) manager \[sn_vdr_risk_asmt.vendor_risk_manager\] or TPR assessor \[sn_vdr_risk_asmt.vendor_assessor\] to act as the owner of the request.
5. The system sends an email notification to the assigned owner of the due diligence request.
6. The TPR manager reviews the request for due diligence for the engagement and approves it. If the information provided by the requester was insufficient or the engagement is not possible for your organization, the TPR manager rejects it.
7. The IRQ process starts after the TPR manager approves the request for due diligence.
{#tprm-requesting-tpr-due-diligence__ol_xzs_3ft_cjc}

To learn more about creating or monitoring a due diligence request, see [Request due diligence for a third-party engagement](https://www.servicenow.com/docs/SVcVA_VcLPqQO8OTzjJ46Q "Request due diligence to assess the risk that is associated with doing business with an engagement. By conducting due diligence, you gain access to the most up-to-date, comprehensive, and accurate information before making a decision on entering into a business relationship.") and [Monitoring the due diligence request process](https://www.servicenow.com/docs/Z_uslRla7H6cKjJ~MhfD3A "TPR managers and TPR admins can perform a wide variety of tasks from the due diligence management dashboard. They can work on all processes in the workflow for a due diligence request: IRQs, external due diligence, approval, contract risk, and closed requests.").

When creating a due diligence request, the following options are available:  
* Onboard a new engagement Start the onboarding process for a new engagement with an existing third party. For more information about this type of onboarding, see [Example: Onboarding a third party](https://www.servicenow.com/docs/pQPUcYj1Zkgpb22~Uzivwg "Acme, a large manufacturing company, is in the process of onboarding a new third party to supply critical components for their production line. To help ensure the third party's reliability and to mitigate potential risks, Acme starts a thorough third-party risk management onboarding process.").
* Reassess an existing engagement Reassess an existing engagement when the conditions change. For example, let's say that you hear adverse news or have changes in your third-party's supply lines. You might want to reassess the risk by conducting additional due diligence.
* Reassess an existing engagement for contract renewal Reassess the risk before your organization renews the contract with a current third party or engagement by conducting due diligence.
* Offboard an engagement with due diligence Determine if offboarding (terminating the relationship) with an engagement is the optimal course of action by conducting due diligence. For example, it might be too risky to switch third parties or engagements even if their current performance doesn't meet expectations.

  Extenuating circumstances can contribute to the decision. For example, if the third party is sourcing materials that are difficult to obtain, switching providers might be costly and introduce additional risks. In such cases,
  continuing with the existing third party, with whom a long-term relationship exists, might be preferable to mitigate potential disruptions and higher risks.
* Offboard an engagement with no due diligence Request that an engagement be permanently terminated when an engagement ends or you want to switch to a different third party for other reasons. In this case, you typically don't need to conduct additional due diligence. The process does, however, include the normal Inherent Risk Questionnaire (IRQ) process to confirm that the services provided by the engagement will no longer continue. For more information about this type of offboarding, see [Offboarding an engagement without conducting due diligence](https://www.servicenow.com/docs/7S3f0VSmNw9H_rxHjzEN4w "Request that an engagement be permanently terminated when an engagement ends or you want to switch to a different third party for other reasons. In this case, you typically don't need to conduct additional due diligence. The process does, however, include the normal Inherent Risk Questionnaire (IRQ) process to confirm that the services provided by the engagement will no longer continue.").
{#tprm-requesting-tpr-due-diligence__ul_pjp_g1f_pzb}

To learn more about creating or monitoring a due diligence request, see [Request due diligence for a third-party engagement](https://www.servicenow.com/docs/SVcVA_VcLPqQO8OTzjJ46Q "Request due diligence to assess the risk that is associated with doing business with an engagement. By conducting due diligence, you gain access to the most up-to-date, comprehensive, and accurate information before making a decision on entering into a business relationship.") and [Monitoring the due diligence request process](https://www.servicenow.com/docs/Z_uslRla7H6cKjJ~MhfD3A "TPR managers and TPR admins can perform a wide variety of tasks from the due diligence management dashboard. They can work on all processes in the workflow for a due diligence request: IRQs, external due diligence, approval, contract risk, and closed requests.").
For each due diligence request, the system auto-assigns a unique ID number that starts with the text DDR. Use the ID to track your request. You can post a message to reviewers and add attachments from the page.

The following example shows how a new due diligence request
appears.
Figure 1. Due diligence request tracking example

For more information on the different processes that make up the overall due diligence workflow, see [Due diligence workflow](https://www.servicenow.com/docs/oa2CJCPg4eVC9NKnvL3_PQ "The Third-party risk management (TPRM) processes provide a consistent framework for your third-party risk management program. You can customize the workflow processes to meet your organization's needs.") and [Assessing your third-party risk](https://www.servicenow.com/docs/Irep7LZWyN_XTR9KnfuuVg "Use Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships. The information gathered from internal questionnaires, external questionnaires, and documentation requests helps you to understand the third party's risk profile, determine the appropriate risk mitigation strategies, and determine whether the third party or engagement meets all necessary compliance requirements.").

