TPRM Home page

  • Release version: Zurich
  • Updated March 12, 2026
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of TPRM Home page

    The TPRM (Third-Party Risk Management) Home page in the Vendor Management Workspace provides ServiceNow customers with a centralized dashboard to view critical risk information and perform key actions related to third-party risk management. It enables quick access to reports, risk metrics, and operational tasks essential for third-party risk managers and assessors.

    Show full answer Show less

    Accessing the Page

    Users can open the Home page by navigating to Workspaces > Vendor Management Workspace and selecting the home page icon on the Risk tab.

    Key Features

    • Third-party risk overview: Interactive boxes display counts of third parties or engagements by risk category. Users can drill down into lists, export data, or create new engagement requests directly from the overview.
    • Quick actions: The page offers shortcuts to create essential records such as:
      • Third party records with key data and contact information for potential engagements.
      • Engagements to assess risks related to third-party products or services, including those from subsidiaries or partners.
      • Internal assessments for due diligence or ongoing risk monitoring, influencing subsequent questionnaires sent to third parties.
      • External assessments to initiate the third-party risk assessment lifecycle.
      • Issues and tasks to track and remediate concerns or follow up on questionnaire responses and document requests.
    • Third-party population overview:
      • Risk rating by tiers showing the number of engagements at each risk level, supporting risk scoring setup and visualization.
      • Top risk areas reflecting average risk scores across defined risk domains (e.g., security, financial), helping prioritize risk focus.
      • Issues by priority displaying counts and highest priority open issues with direct navigation to issue details.
    • Fourth-nth party overview: Visual counts and categorizations of fourth parties and their sub-parties linked to third parties or engagements, distinguishing between known and unknown entities to enhance visibility into extended supply chain risks.

    Practical Benefits for ServiceNow Customers

    This Home page streamlines third-party risk management by consolidating relevant data and actions in one place, allowing customers to:

    • Quickly identify and prioritize third-party risk exposures through visual summaries and metrics.
    • Efficiently create and manage third-party records, engagements, assessments, issues, and tasks from a single interface.
    • Gain insights into extended risk through fourth-party visibility, supporting comprehensive risk assessment.
    • Export and analyze data to support reporting and decision-making processes.

    Overall, the TPRM Home page supports proactive, organized, and transparent third-party risk management aligned with organizational risk strategies.

    The home page displays reports of important risk information and provides quick access to actions for TPR managers and TPR assessors.

    Accessing the page

    To open the Home page in the Vendor Management Workspace, select Workspaces > Vendor Management Workspace and on the Risk tab select the home page icon .

    Reports on the TPRM home page.

    Third-party risk overview

    Select any number in a box to open the associated list of third parties or engagements.

    Reports on the TPRM home page.

    After you open a list, you can select Export to export the data or select New to create a new engagement request.

    Quick actions
    • Create a third party record. Set up the key data and contact information for a third party that your organization will possibly engage.
    • Create an engagement. Define an engagement so that you can assess the risks that are associated with the services or products offered by a third party. Engagements can also represent the products or services that are provided to the parent third party, either directly or from departments, partners, or subsidiaries that you can also assess for risk.
    • Create an internal assessment. Create an internal assessment as part of a due diligence request or ongoing risk monitoring using Third-party Risk Management. An internal assessment can affect which questionnaires are later sent to the third party or engagement. See Create an internal assessment.
    • Create an assessment and initiate the third-party risk assessment life cycle. See Create an external assessment.
    • Create an issue to help ensure that your concerns about a third party or engagement are remediated. See Create an issue for a third party or engagement.
    • Create a task to help ensure that a user at your organization or the third-party contact responds to your concerns about questionnaire responses or requested documents during the due diligence process. See Create a task for a third party or engagement.
    Third-party population overview
    • Risk rating by risk tiers: The number of engagements at each risk rating for each third-party risk tier. See Set up risk rating scales for scoring.
    • Top risk areas:

      The average risk score for engagements that are associated with each risk domain that you’ve defined.

      Note:
      Risk domains are called "risk areas" in some platform applications.

      A risk domain defines the type of risk to assess for a third party. For example, you might want to assess a data-management third party in terms of security risk and a bank in terms of financial risk. Security risk and financial risk are risk domains. Some platform applications refer to risk domains as "risk areas." See Define a third-party risk domain.

    Issues by priority
    Count and priority of the highest priority open issues. Select an issue name to view the Risk overview tab of the issue page. See Manage issues.
    Fourth-nth party overview
    Counts of fourth parties and their sub-parties that are associated with third parties or engagements and unknown fourth parties. Select a segment of the corresponding graph to view a list of known or unknown fourth-parties.
    Note:
    Known fourth parties are organizations that have already been utilized as third parties in your risk management program and unknown fourth parties are only categorized as fourth parties and haven’t been utilized or identified as third parties.