External assessment lifecycle states

  • Release version: Zurich
  • Updated June 30, 2026
  • 3 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of External assessment lifecycle states

    The external assessment lifecycle in ServiceNow guides the process of collecting and managing assessment data from third parties. This lifecycle involves multiple states that track the progress of questionnaires, document requests, and issue resolution to ensure thorough third-party risk assessment and timely completion.

    Show full answer Show less

    Key Lifecycle States

    • Draft: The assessment record is initially created. It includes an assessment template (questionnaires and document requests auto-generated or manually specified), an auto-generated risk rating, and an assigned owner responsible for managing and monitoring the process. The owner must have either the TPR manager or TPR assessor role.
    • Submitted to third party: Questionnaires and document requests are sent to the third party, who then responds.
    • Responses received: The internal third-party risk team reviews third-party submissions, may request clarifications or missing information.
    • Generating observations: The system auto-generates issues based on incorrect answers. Third-party contacts respond to these issues, and the internal team decides to accept responses or require remediation.
    • Finalizing with a third party: The internal team reviews all assessment data and may reset the assessment to Draft if needed.
    • Closed: When all data is accepted, the assessment is closed, which can trigger the contract risk process if engagement proceeds to contracting. Contracting only begins after approval is complete.

    Questionnaire State Management

    Questionnaire states differ slightly based on the engine version:

    • Classic engine: Uses separate states for questionnaire requests and questionnaires themselves. Questionnaire requests track sending status (Ready to take, In progress, Complete, Canceled). Questionnaires track workflow from creation to review (New, Submitted, In Progress, Received, Returned, Canceled).
    • Smart Assessment Engine (SAE) in Zurich: Simplifies questionnaire states to three key statuses—In progress, Completed, and Canceled—to streamline tracking.

    Practical Implications for ServiceNow Customers

    Understanding these lifecycle states helps ServiceNow customers effectively manage third-party risk assessments by:

    • Assigning proper ownership and roles to ensure accountability.
    • Tracking the progress of assessments and questionnaire completion in real time.
    • Handling responses, follow-ups, and issue remediation efficiently.
    • Ensuring assessments are finalized properly to trigger subsequent onboarding or contracting steps.
    • Choosing the appropriate questionnaire engine and understanding state workflows based on your platform version.

    The process of collecting assessment data from a third party moves through several states. For example, during the Submitted to third party state, the third party responds to tasks, issues, and works to complete the questionnaires.

    Third-party assessment states

    Figure 1. Third-party assessment states
    States of an external assessment.
    Draft
    An external assessment record is opened in the Draft state.
    • Assessment template: A set of external questionnaires and document requests that are auto-generated based on IRQ responses. Alternatively, an administrator could manually specify the questionnaires and document requests.
    • Risk rating: The overall risk rating that is auto-generated based on IRQ responses.
    • Owner: The owner is the person who owns an assessment for audit purposes and monitors and manages overall assessment processes. Owners are responsible for confirming that the assessment is completed in a timely fashion by the third party, reviewing their responses, and creating and resolving issues. To drive the assessment to its completion, owners are notified when an assessment reaches a particular milestone. The owner must have the TPR manager or TPR assessor role.
    Submitted to third party
    The questionnaires and document requests for the assessment have been sent to the third-party contact. Internal stakeholders await responses.
    Responses received
    After contacts at the third party have completed all questionnaires and document requests, your internal third-party risk team reviews and analyzes the responses. The team might return particular questions for follow-up, clarification, or missing answers.
    Generating observations
    When all responses are completed, the system can auto-generate issues for incorrect answers.

    Third-party contacts respond to issues. Your internal third-party risk team makes a final determination to accept the responses or remediate the issues.

    Finalizing with a third party
    Your third-party risk team reviews all assessment data. In some cases, the team resets the assessment to the Draft state to restart the assessment life cycle.
    Closed
    When all data is acceptable, the assessment is complete and a member of the team closes the assessment. If the engagement will be contracted, the Closed state initiates the contract risk process.
    Note:
    After the questionnaire is completed and approved, the assessment can proceed to the next stage of onboarding or contracting. The contract process does not begin until the approval process is complete.

    Questionnaire states

    In the Classic engine, questionnaire requests (previously called assessment instances) and questionnaires themselves have separate state systems. The SAE uses a simplified set of questionnaire states.

    Note:
    If you upgraded from Yokohama or earlier and enabled the Smart Assessment Engine (SAE) in Zurich, questionnaire states are simplified to the three states shown above. For information about assessment status changes, see Third-party Risk Management upgrade information.

    Questionnaire requests track the overall status of a questionnaire request sent to a third party.

    Table 1. Classic engine questionnaire request states
    Questionnaire request state Description
    Ready to take Questionnaire request is prepared and ready to be sent to the third party.
    In progress Questionnaire request has been sent to the third party and is being completed.
    Complete Questionnaire request is complete and the third party has submitted their response.
    Canceled Questionnaire request is canceled and is no longer active.

    Questionnaires themselves move through additional states that track the workflow of completing and reviewing the questionnaire content.

    Table 2. Classic engine questionnaire states
    Questionnaire state Description
    New Questionnaire is created but not yet sent to the third party.
    Submitted Questionnaire is sent to the third party for completion.
    In Progress Third party is actively working on the questionnaire.
    Received Third party submits the completed questionnaire for review.
    Returned Questionnaire is sent back to the third party for updates and corrections.
    Canceled Questionnaire is canceled and is no longer active.
    Table 3. SAE questionnaire states
    Questionnaire state Description
    In progress Questionnaire is active and being completed by the third party.
    Completed Questionnaire is finished and submitted.
    Canceled Questionnaire is canceled before completion.