External assessment lifecycle states
Summarize
Summary of External assessment lifecycle states
The external assessment lifecycle describes the process of collecting and managing assessment data from third parties. This process moves through defined states that guide internal teams and third-party contacts from initial questionnaire creation through completion, review, issue resolution, and final closure. Understanding these states helps ServiceNow customers effectively monitor and control third-party risk assessments.
Show less
Key Stages in the External Assessment Lifecycle
- Draft: An external assessment record is created, using either auto-generated questionnaires based on IRQ (Information Request Questionnaire) responses or manually specified questionnaires and document requests. An owner, typically with TPR manager or assessor roles, oversees the assessment progress.
- Submitted to third party: The questionnaires and document requests are sent to the third-party contact, who then works on completing them while internal stakeholders await responses.
- Responses received: The third-party completes all requests, and the internal third-party risk team reviews the responses, possibly requesting clarifications or additional information.
- Generating observations: The system can automatically generate issues based on incorrect answers, which the third party addresses. The internal team then decides whether to accept responses or require remediation.
- Finalizing with a third party: The internal team reviews all data and may reset the assessment to Draft to restart if necessary.
- Closed: Once all data is acceptable, the assessment is closed. Closing can trigger the contract risk process if contracting is involved, but contracting only begins after approval is complete.
Questionnaire States
ServiceNow supports two engines for questionnaire management, each with distinct states:
- Classic engine: Uses separate state systems for questionnaire requests and questionnaires themselves.
- Questionnaire request states: Ready to take (prepared), In progress (sent and being completed), Complete (submitted), Canceled (no longer active).
- Questionnaire states: New (created, not sent), Submitted (sent for completion), In Progress (actively worked on), Received (submitted for review), Returned (sent back for updates), Canceled.
- Smart Assessment Engine (SAE): Employs a simplified state system with three states: In progress (active and being completed), Completed (finished and submitted), and Canceled (canceled before completion). This simplification applies especially after upgrades from earlier releases like Yokohama or Zurich.
Practical Considerations for ServiceNow Customers
- Assign appropriate owners with TPR roles to manage assessments and ensure timely completion and issue resolution.
- Use state transitions to monitor assessment progress and identify when follow-ups or escalations are necessary.
- Understand that closing an assessment can initiate contract risk processes, but contracting only proceeds after assessment approval.
- Be aware of the engine (Classic or SAE) in use to understand questionnaire state workflows and manage responses accordingly.
The process of collecting assessment data from a third party moves through several states. For example, during the Submitted to third party state, the third party responds to tasks, issues, and works to complete the questionnaires.
Third-party assessment states
- Draft
- An external assessment record is opened in the Draft state.
- Assessment template: A set of external questionnaires and document requests that are auto-generated based on IRQ responses. Alternatively, an administrator could manually specify the questionnaires and document requests.
- Risk rating: The overall risk rating that is auto-generated based on IRQ responses.
- Owner: The owner is the person who owns an assessment for audit purposes and monitors and manages overall assessment processes. Owners are responsible for confirming that the assessment is completed in a timely fashion by the third party, reviewing their responses, and creating and resolving issues. To drive the assessment to its completion, owners are notified when an assessment reaches a particular milestone. The owner must have the TPR manager or TPR assessor role.
- Submitted to third party
- The questionnaires and document requests for the assessment have been sent to the third-party contact. Internal stakeholders await responses.
- Responses received
- After contacts at the third party have completed all questionnaires and document requests, your internal third-party risk team reviews and analyzes the responses. The team might return particular questions for follow-up, clarification, or missing answers.
- Generating observations
- When all responses are completed, the system can auto-generate issues for incorrect answers.
Third-party contacts respond to issues. Your internal third-party risk team makes a final determination to accept the responses or remediate the issues.
- Finalizing with a third party
- Your third-party risk team reviews all assessment data. In some cases, the team resets the assessment to the Draft state to restart the assessment life cycle.
- Closed
- When all data is acceptable, the assessment is complete and a member of the team closes the assessment. If the engagement will be contracted, the Closed state initiates the contract risk process.
Questionnaire states
In the Classic engine, questionnaire requests (previously called assessment instances) and questionnaires themselves have separate state systems. The SAE uses a simplified set of questionnaire states.
Questionnaire requests track the overall status of a questionnaire request sent to a third party.
| Questionnaire request state | Description |
|---|---|
| Ready to take | Questionnaire request is prepared and ready to be sent to the third party. |
| In progress | Questionnaire request has been sent to the third party and is being completed. |
| Complete | Questionnaire request is complete and the third party has submitted their response. |
| Canceled | Questionnaire request is canceled and is no longer active. |
Questionnaires themselves move through additional states that track the workflow of completing and reviewing the questionnaire content.
| Questionnaire state | Description |
|---|---|
| New | Questionnaire is created but not yet sent to the third party. |
| Submitted | Questionnaire is sent to the third party for completion. |
| In Progress | Third party is actively working on the questionnaire. |
| Received | Third party submits the completed questionnaire for review. |
| Returned | Questionnaire is sent back to the third party for updates and corrections. |
| Canceled | Questionnaire is canceled and is no longer active. |
| Questionnaire state | Description |
|---|---|
| In progress | Questionnaire is active and being completed by the third party. |
| Completed | Questionnaire is finished and submitted. |
| Canceled | Questionnaire is canceled before completion. |