Configure a third-party risk assessment to recur on a schedule to regularly update risk results for a third party or an engagement.

Before you begin

Role required: sn_vdr_risk_asmt.vendor_assessor

About this task

You can create repeating assessments if you are using the classic assessment engine. You can configure rules that auto-generate and send questionnaires and doc requests to engagements and third parties using the Event-driven management feature if you are using the Smart Assessment Engine. For more information, see Configure a risk assessment to recur on a schedule and Event-driven management — automate assessment processes.

Procedure

  1. Navigate to All > Third-party Risk Management > External Risk Assessments > Assessment scheduling.
  2. Click New, fill in the form, and then click Submit.
    Table 1. Repeating Assessment form
    Field Description
    Number For each external risk assessment, the system auto-assigns a unique ID number that starts with the text VRA.

    The unique ID is used in all references to the item. You can use the ID to search or filter for the item that you want to work on.

    Description Detailed description of the recurring assessment.
    Name Name of the recurring assessment.
    Assessment template Template used to create the current assessment.
    Applies to The entity to which the assessment applies: Third party or Engagement.
    Third party

    Select the third party being assessed.

    Engagement

    Select the engagement being assessed.

    The field is visible only if you selected Engagement in the Applies to field.

    Active Option to enable the current recurring assessment to run when scheduled.
    Next assessment creation (months) The next assessment will be created in the specified number of months after the previous assessment is closed.
    Next assessment end date (months) The end date for the new assessment after the previous assessment is closed.
    Assessment results valid duration (days) The number of days that the assessment results are valid.

    The Assessment occurrences related list displays the status of each time the assessment took place and the risk rating that resulted from the assessment.