IRQ process management

  • Release version: Washingtondc
  • Updated January 30, 2025
  • 3 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of IRQ Process Management

    The IRQ process management begins post-approval of an engagement request by assessing the third party's risk score. This is crucial for identifying and mitigating potential risks associated with third-party engagements.

    Show full answer Show less

    Key Features

    • Accessing the IRQ Process: Navigate to the Due Diligence Management page, select the DDR number, and access the Inherent Risk Assessments tab to view all IRQ processes.
    • Unique Identification: Each IRQ process is assigned an ID starting with "INA," which can be used for searching or filtering.
    • Risk Overview: The Risk Overview tab provides a snapshot of the IRQ process, including associated assessments and their statuses (Open, Overdue, Closed).
    • Details and Activity Tracking: The Details tab contains general information about the third party, assessment schedules, and a section for adding notes and comments visible to internal users or third-party contacts.
    • Questionnaires and Scales: The Questionnaires tab lists open IRQs, while the Scales tab defines the rating and tier values.
    • Assessment Instances: This tab summarizes the results from internal assessments, including metrics, assigned users, due dates, and current states.

    Key Outcomes

    Utilizing the IRQ process allows ServiceNow customers to effectively manage third-party risks by enabling structured assessments, tracking engagement statuses, and facilitating communication through shared notes and comments. This structured approach helps ensure compliance and risk mitigation throughout the third-party engagement lifecycle.

    The first internal step after an engagement request is approved is to start the IRQ process to scope the risk by determining the third party's risk score.

    Accessing the IRQ process

    On the Due diligence management page, select the DDR number for any due diligence request and then the select the Inherent risk assessments tab.

    The tab displays the list of all IRQ processes for the engagement request. For each IRQ process, the system auto-assigns a unique ID number that starts with the text INA.

    Accessing the Vendor Management Workspace.

    Viewing the list of internal risk assessments

    Inherent risk assessments tab
    Table 1. Inherent risk assessments tab
    Column Description
    Number

    For each IRQ process, the system auto-assigns a unique ID number that starts with the text INA.

    Select an INA number to work on the Third-party risk assessments page to the Risk overview tab.

    The unique ID is used in all references to the item. You can use the ID to search or filter for the item that you want to work on.

    Name, Assigned to, Risk rating Data from the engagement request.
    State The current state of the inherent risk assessment: Draft, Awaiting response, Response received, or Closed.
    Respondents Users who responded to the request.
    Risk overview tab on the Inherent risk assessments page

    For each IRQ process, the system auto-assigns a unique ID number that starts with the text INA. Select an INA number to work on the IRQ process on the Inherent risk assessments page.

    Click the INA number to work on the Third-party risk assessments page.

    • The symbols indicate the state of each stage in the IRQ process for the request.

      IRQ process stages.

    • Assessment instances section: List of assessments that are associated with the third party.
    • Tracking section: Count of assessments associated with the third party that are in the Open, Overdue, and Closed status.
    Details tab on the Inherent risk assessments page
    • Internal assessment section: General information on the third party plus schedules for the overall assessment and questionnaire due dates from the engagement due diligence request.
    • The Compose section on the Details tab enables you to permanently add text to the record. The Activity section is updated with any actions on issues and tasks, submissions to TP contacts, and also with work notes and comments that users add to the record. Add text in the following fields as needed:
      • Work notes (Private): Information about the third-party risk assessment. Work notes are visible only to internal users who are assigned to the process.
      • Comments: Comments about the third-party risk assessment are visible both to internal users and to third-party contacts.
    • The Third-party overview section provides key information on the third party that is associated with the engagement request.
    Questionnaires tab on the Inherent risk assessments page
    The tab lists all open IRQs. Select a questionnaire name to view the details.
    Scales tab on the Inherent risk assessments page
    The tab lists the definitions of the calculated rating and tier values. See Set up risk rating scales for scoring and Third-party risk tiering assessments — Legacy process for instructions for defining the settings.
    Assessment instances tab on the Inherent risk assessments page

    All values on the tab come from the internal assessments that have been conducted on the third part in the engagement.

    Table 2. Assessment instances tab
    Column Description
    Number

    For each IRQ process, the system auto-assigns a unique ID number that starts with the text INA.

    The unique ID is used in all references to the item. You can use the ID to search or filter for the item that you want to work on.

    Metric type Questionnaire that determined the questionnaires used in the assessment.
    Assigned to User that is responsible for managing and responding to the IRQ.
    Due date Deadline for third party to respond to and return all questionnaires.
    State Current stage of the IRQ process for the engagement request.
    Internal risk score

    An engagement risk-scoring rule specifies component criteria that determine which engagements are selected for assessment. For example, a rule could enable assessments for engagements that involve more than $40,000 annual business. Engagement scoring rules apply only to engagements.

    See Define engagement risk scoring rules.