Assessing your third-party risk
Summarize
Summary of Assessing your third-party risk
The Third-party Risk Management (TPRM) process in ServiceNow helps organizations identify and assess risks linked to their third-party relationships. It involves collecting information through internal and external questionnaires and document requests to understand third parties’ risk profiles, compliance status, and to decide on appropriate risk mitigation strategies.
Show less
Key Processes
- Inherent Risk Questionnaire (IRQ) Process: The TPR manager or assessor initiates the IRQ by assigning it to an internal assessor who completes the questionnaire. After review and closure by the TPR manager, the due diligence request status moves forward. Important: Questionnaire templates should not be modified after sending; instead, duplicate and update templates.
- Third-party (TP) Element Collection: Following the IRQ, if needed, TP element questionnaires are assigned to external assessments and sent to third-party contacts to collect specific element information. Responses are reviewed, and element records are manually created and approved as part of due diligence.
- Due Diligence and Compliance Verification: After prior processes, questionnaires and document requests are sent to third parties to verify compliance with laws, regulations, and internal standards. Responses are reviewed, remediation tasks or issues are created if necessary, and assessments are approved to complete the process. The TPR team also evaluates data security and privacy practices, potentially requiring cybersecurity audits.
Features and Tools
- Questionnaire Templates and Assessment Templates: TPR managers can create reusable templates grouping questionnaires and document requests to streamline sending assessments to similar third parties.
- Pre-populating Questionnaires: Questionnaires can be pre-filled with responses from previous assessments to expedite completion. This feature notifies third parties of copied responses and applies only to compatible question types.
- Issues and Tasks Management: TPR assessors and managers create and manage tasks and issues to address concerns arising from questionnaire responses or documentation, ensuring timely remediation and communication.
- Reopening and Canceling Assessments: Assessments can be reopened to gather additional information or canceled to expedite engagement onboarding or renewal, with due diligence continuing regardless of assessment cancellation.
Practical Guidance for ServiceNow Customers
- Follow the structured IRQ, TP element collection, and due diligence processes to comprehensively assess third-party risks and compliance.
- Use questionnaire and assessment templates to standardize and automate assessments for efficiency and consistency.
- Pre-populate assessments to reduce repetitive data entry and speed up third-party responses while maintaining accuracy.
- Leverage tasks and issues features to track and resolve assessment findings collaboratively.
- Manage assessments flexibly by reopening or canceling them as needed based on engagement changes or urgency.
By applying these processes and tools, ServiceNow customers can effectively evaluate third-party risks, ensure compliance, and maintain strong risk mitigation practices across their vendor ecosystem.
Use Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships. The information gathered from internal questionnaires, external questionnaires, and documentation requests helps you to understand the third party's risk profile, determine the appropriate risk mitigation strategies, and determine whether the third party or engagement meets all necessary compliance requirements.
Responding to questionnaires
The following processes outline the timing and methods for responding to internal and external questionnaires:
- Inherent Risk Questionnaire (IRQ) process
-
The following infographic shows the IRQ process.
- Third-party (TP) element collection process: Collect TP element information
-
The following infographic shows the TP element collection process.
- Due diligence process: Compliance verification
-
The following infographic shows the due diligence process.
Pre-populate questionnaires with responses
When a third-party or engagement contact opens a pre-populated questionnaire in the Third-party portal, they receive a notification that the responses were copied from an earlier questionnaire. The notification includes a link to the assessment that supplied the responses and its last updated date as shown in the following example.
- Some question types and their responses can’t be pre-populated such as the attachment, duration, and signature question types. These question responses remain blank and previous responses aren’t included.
- Responses are copied from the original assessment (Assessment A) to the newer assessment (Assessment B) one time. This copying occurs when Assessment B is submitted to a third party or an engagement. Any changes you make to Assessment A afterward won't be reflected in Assessment B. Both assessments remain separate.
Issues and tasks
The role of TPR assessor [sn_vdr_risk_asmt.vendor_assessor] is required to create and manage both tasks and issues.
The TPR manager, TPR assessor, or contract negotiator can create tasks to help ensure that a team member or the third-party contact responds to concerns about the questionnaire responses or requested documents. They can manage existing tasks to verify that the assigned team member or third-party contact responds to a task and updates it as needed. For more information about creating and managing issues, see Create a task for a third party or engagement and Manage a task for a third party or engagement.
The TPR manager, TPR assessor, or contract negotiator can create an issue to help ensure the teams concerns about a third party or engagement are remediated. They can also manage the existing issues to verify that they’re understood, shared with the correct persons, and are acted on as needed. For more information about creating and managing tasks, see Create an issue for a third party or engagement and Manage issues.
Additional assessment actions
The TPR manager, due-diligence request owner, or contract negotiator may need to reopen an assessment because there’s new information available that impacts the engagement or some other change has occurred. For more information, see Why you conduct due diligence.
- Navigate to the Due diligence request record page by selecting the relevant DDR number.
- View the related third-party risk assessment by selecting the VRA number on the External assessments tab.
- Select Re-open.
The due diligence request state updates from Ready for TPRM approval to Due diligence. The TPR manager, owner, or contract negotiator can request questionnaires and document requests as needed. For more information, see Reopen an assessment.
- Navigate to the Due diligence request record page by selecting the relevant DDR number.
- View the related third-party risk assessment by selecting the VRA number on the External assessments tab.
- Select Cancel.