External assessment lifecycle states

  • Release version: Australia
  • Updated June 30, 2026
  • 3 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of External assessment lifecycle states

    The external assessment lifecycle describes the process of collecting and managing assessment data from third parties. This process moves through defined states that guide internal teams and third-party contacts from initial questionnaire creation through completion, review, issue resolution, and final closure. Understanding these states helps ServiceNow customers effectively monitor and control third-party risk assessments.

    Show full answer Show less

    Key Stages in the External Assessment Lifecycle

    • Draft: An external assessment record is created, using either auto-generated questionnaires based on IRQ (Information Request Questionnaire) responses or manually specified questionnaires and document requests. An owner, typically with TPR manager or assessor roles, oversees the assessment progress.
    • Submitted to third party: The questionnaires and document requests are sent to the third-party contact, who then works on completing them while internal stakeholders await responses.
    • Responses received: The third-party completes all requests, and the internal third-party risk team reviews the responses, possibly requesting clarifications or additional information.
    • Generating observations: The system can automatically generate issues based on incorrect answers, which the third party addresses. The internal team then decides whether to accept responses or require remediation.
    • Finalizing with a third party: The internal team reviews all data and may reset the assessment to Draft to restart if necessary.
    • Closed: Once all data is acceptable, the assessment is closed. Closing can trigger the contract risk process if contracting is involved, but contracting only begins after approval is complete.

    Questionnaire States

    ServiceNow supports two engines for questionnaire management, each with distinct states:

    • Classic engine: Uses separate state systems for questionnaire requests and questionnaires themselves.
      • Questionnaire request states: Ready to take (prepared), In progress (sent and being completed), Complete (submitted), Canceled (no longer active).
      • Questionnaire states: New (created, not sent), Submitted (sent for completion), In Progress (actively worked on), Received (submitted for review), Returned (sent back for updates), Canceled.
    • Smart Assessment Engine (SAE): Employs a simplified state system with three states: In progress (active and being completed), Completed (finished and submitted), and Canceled (canceled before completion). This simplification applies especially after upgrades from earlier releases like Yokohama or Zurich.

    Practical Considerations for ServiceNow Customers

    • Assign appropriate owners with TPR roles to manage assessments and ensure timely completion and issue resolution.
    • Use state transitions to monitor assessment progress and identify when follow-ups or escalations are necessary.
    • Understand that closing an assessment can initiate contract risk processes, but contracting only proceeds after assessment approval.
    • Be aware of the engine (Classic or SAE) in use to understand questionnaire state workflows and manage responses accordingly.

    The process of collecting assessment data from a third party moves through several states. For example, during the Submitted to third party state, the third party responds to tasks, issues, and works to complete the questionnaires.

    Third-party assessment states

    Figure 1. Third-party assessment states
    States of an external assessment.
    Draft
    An external assessment record is opened in the Draft state.
    • Assessment template: A set of external questionnaires and document requests that are auto-generated based on IRQ responses. Alternatively, an administrator could manually specify the questionnaires and document requests.
    • Risk rating: The overall risk rating that is auto-generated based on IRQ responses.
    • Owner: The owner is the person who owns an assessment for audit purposes and monitors and manages overall assessment processes. Owners are responsible for confirming that the assessment is completed in a timely fashion by the third party, reviewing their responses, and creating and resolving issues. To drive the assessment to its completion, owners are notified when an assessment reaches a particular milestone. The owner must have the TPR manager or TPR assessor role.
    Submitted to third party
    The questionnaires and document requests for the assessment have been sent to the third-party contact. Internal stakeholders await responses.
    Responses received
    After contacts at the third party have completed all questionnaires and document requests, your internal third-party risk team reviews and analyzes the responses. The team might return particular questions for follow-up, clarification, or missing answers.
    Generating observations
    When all responses are completed, the system can auto-generate issues for incorrect answers.

    Third-party contacts respond to issues. Your internal third-party risk team makes a final determination to accept the responses or remediate the issues.

    Finalizing with a third party
    Your third-party risk team reviews all assessment data. In some cases, the team resets the assessment to the Draft state to restart the assessment life cycle.
    Closed
    When all data is acceptable, the assessment is complete and a member of the team closes the assessment. If the engagement will be contracted, the Closed state initiates the contract risk process.
    Note:
    After the questionnaire is completed and approved, the assessment can proceed to the next stage of onboarding or contracting. The contract process does not begin until the approval process is complete.

    Questionnaire states

    In the Classic engine, questionnaire requests (previously called assessment instances) and questionnaires themselves have separate state systems. The SAE uses a simplified set of questionnaire states.

    Note:
    If you upgraded from Yokohama or earlier and enabled the Smart Assessment Engine (SAE) in Zurich, questionnaire states are simplified to the three states shown above. For information about assessment status changes, see Third-party Risk Management upgrade information.

    Questionnaire requests track the overall status of a questionnaire request sent to a third party.

    Table 1. Classic engine questionnaire request states
    Questionnaire request state Description
    Ready to take Questionnaire request is prepared and ready to be sent to the third party.
    In progress Questionnaire request has been sent to the third party and is being completed.
    Complete Questionnaire request is complete and the third party has submitted their response.
    Canceled Questionnaire request is canceled and is no longer active.

    Questionnaires themselves move through additional states that track the workflow of completing and reviewing the questionnaire content.

    Table 2. Classic engine questionnaire states
    Questionnaire state Description
    New Questionnaire is created but not yet sent to the third party.
    Submitted Questionnaire is sent to the third party for completion.
    In Progress Third party is actively working on the questionnaire.
    Received Third party submits the completed questionnaire for review.
    Returned Questionnaire is sent back to the third party for updates and corrections.
    Canceled Questionnaire is canceled and is no longer active.
    Table 3. SAE questionnaire states
    Questionnaire state Description
    In progress Questionnaire is active and being completed by the third party.
    Completed Questionnaire is finished and submitted.
    Canceled Questionnaire is canceled before completion.