Third-party Risk Management

  • Release version: Australia
  • Updated March 12, 2026
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Third-party Risk Management

    The ServiceNow® GRC: Third-party Risk Management (TPRM) application enables your organization to proactively identify, assess, and mitigate risks associated with third-party relationships. It centralizes the management of your third-party portfolio, streamlines risk assessment and scoring, and supports remediation efforts to protect your organization.

    Show full answer Show less

    Key Features

    • Due Diligence Requests: Initiate risk due diligence requests to evaluate the risk level of third-party engagements.
    • Risk Assessment and Monitoring: Identify, assess, and continuously monitor risks related to your third parties to maintain awareness and control.
    • Approval Workflow: Configure approval levels and rules to manage due diligence requests, enabling informed approval or rejection based on questionnaire responses and due diligence results.
    • Contract Risk Management: Incorporate specific contractual provisions to address identified risks during contract negotiations.
    • Digital Resilience Registers: Utilize the Digital resilience third-party registers within the Vendor Management Workspace to maintain records of contractual arrangements with ICT third-party service providers.
    • Risk Intelligence Integration: Manage, request, and integrate risk intelligence reports and scores from external providers to gain insights into third-party trustworthiness and safety.
    • Third-party Portal: Facilitate interaction between third-party contacts and risk assessors through a portal for responding to questionnaires, documentation requests, tasks, and issues.
    • Smart Assessment Engine Migration: Learn and implement changes when migrating from the Classic Assessment Engine to the Smart Assessment Engine, including feature updates and setup requirements.
    • Application Activation and Configuration: Download and activate TPRM from the ServiceNow Store, then configure settings to align with your organizational needs.

    Important Notes

    The Vendor Management Workspace for ITSM (snitsmvendor) is deprecated as of the Australia release and is no longer available for new customer activation. Documentation references to Vendor Management Workspace pertain to the GRC: Vendor Management Workspace (snvrmws), which remains supported and included with TPRM.

    Support and Resources

    • Access the GRC community for questions and answers.
    • Search the Known Error Portal for troubleshooting articles.
    • Leverage developer resources to build and extend applications.
    • Contact Customer Service and Support for direct assistance.

    The ServiceNow® GRC: Third-party Risk Management (TPRM) application enables you to proactively identify, assess, and mitigate risks that are associated with your third-party relationships. TPRM provides a centralized process for managing your portfolio of third parties, assessing and scoring risk, and performing remediation.

    Get started

    Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release note information for all released apps, see the ServiceNow Store version history release notes.

    Important:

    The Vendor Management Workspace for ITSM (sn_itsm_vendor) is deprecated as of the Australia release. It is hidden and no longer available for activation for new customers. References to Vendor Management Workspace throughout this documentation refer to the GRC: Vendor Management Workspace (sn_vrm_ws), which is a separate application included with Third-party Risk Management and is not affected by this deprecation. For details about the deprecation process, see the Deprecation Process [KB0867184] article in the Now Support Knowledge Base.

    Troubleshoot and get help