---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Third-party Risk Management

# Third-party Risk Management {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Third-party Risk Management

The ServiceNow® GRC: Third-party Risk Management (TPRM) application enables your organization to proactively identify, assess, and mitigate risks associated with third-party relationships.
It centralizes the management of your third-party portfolio, streamlines risk assessment and scoring, and supports remediation efforts to protect your organization.
Show full answer Show less  

## Key Features

* **Due Diligence Requests:** Initiate risk due diligence requests to evaluate the risk level of third-party engagements.
* **Risk Assessment and Monitoring:** Identify, assess, and continuously monitor risks related to your third parties to maintain awareness and control.
* **Approval Workflow:** Configure approval levels and rules to manage due diligence requests, enabling informed approval or rejection based on questionnaire responses and due diligence results.
* **Contract Risk Management:** Incorporate specific contractual provisions to address identified risks during contract negotiations.
* **Digital Resilience Registers:** Utilize the Digital resilience third-party registers within the Vendor Management Workspace to maintain records of contractual arrangements with ICT third-party service providers.
* **Risk Intelligence Integration:** Manage, request, and integrate risk intelligence reports and scores from external providers to gain insights into third-party trustworthiness and safety.
* **Third-party Portal:** Facilitate interaction between third-party contacts and risk assessors through a portal for responding to questionnaires, documentation requests, tasks, and issues.
* **Smart Assessment Engine Migration:** Learn and implement changes when migrating from the Classic Assessment Engine to the Smart Assessment Engine, including feature updates and setup requirements.
* **Application Activation and Configuration:** Download and activate TPRM from the ServiceNow Store, then configure settings to align with your organizational needs.

## Important Notes

The Vendor Management Workspace for ITSM (snitsmvendor) is deprecated as of the Australia release and is no longer available for new customer activation. Documentation references to Vendor Management Workspace pertain to the GRC: Vendor Management Workspace (snvrmws), which remains supported and included with TPRM.

## Support and Resources

* Access the GRC community for questions and answers.
* Search the Known Error Portal for troubleshooting articles.
* Leverage developer resources to build and extend applications.
* Contact Customer Service and Support for direct assistance.  
The ServiceNow® GRC: Third-party Risk Management (TPRM) application enables you to proactively identify, assess, and mitigate risks that are associated with your third-party relationships. TPRM provides a centralized process for managing your portfolio of third parties, assessing and scoring risk, and performing remediation.

## Get started {#third-party-risk-mgt-landing-page__section_rt1_3v3_hzb}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release note information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#third-party-risk-mgt-landing-page__inline-send-to-store}

|-|-|-|
| [Explore Learn about how third-party risk managers, third-party risk users, and third-party risk administrators use the Third-party Risk Management application.](https://www.servicenow.com/docs/KZUDtXYLwSzolf97muVO2A "The Third-party Risk Management application centralizes and standardizes the processes, source materials, responsible persons, and methods of your third-party risk management program. You can improve your operations by managing your portfolio of third parties and by identifying, tracking, and mitigating the issues that arise with third parties.") | [Configure You can activate or upgrade TPRM, by downloading the applications from the ServiceNow Store and then configuring the settings to meet your needs.](https://www.servicenow.com/docs/fSbrfETvXhzOC1Ihw7li7Q "You can activate or upgrade TPRM, by downloading the applications from the ServiceNow Store and then configuring the settings to meet your needs.") | [Integrate Extend TPRM capabilities by integrating with other applications.](https://www.servicenow.com/docs/B3Zuas2ZL~p4ooeZA0GTNQ "Extend the capabilities of TPRM.") |
| [Migrate Classic to Smart Assessment Engine Learn what changes when you migrate from the Classic Assessment Engine to the Smart Assessment Engine, including feature differences, limitations, and setup requirements.](https://www.servicenow.com/docs/_IFNHdAAg~lR1jG6oNNjLQ "Learn what changes when you migrate from the Classic Assessment Engine to the Smart Assessment Engine, including feature differences, limitations, and setup requirements. This overview can help you and your team evaluate the impact before enabling the new engine.") | [Request third-party risk due diligence Request third-party risk due diligence to determine the level of risk for interactions with a third party and their engagement.](https://www.servicenow.com/docs/Tox8oymaaXzAo4c7AdHemA "Request third-party risk due diligence to determine the level of risk for interactions with a third party, engagement, or fourth party by using Third-party Risk Management. You conduct due diligence to become aware of the associated risks so that you can make informed decisions, establish appropriate controls, and mitigate the potential negative impact when working with external parties.") | [Assess third-party risk Use Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships.](https://www.servicenow.com/docs/HhMe7LKkoxctYhTzh0d5Aw "Use Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships. The information gathered from internal questionnaires, external questionnaires, and documentation requests helps you to understand the third party's risk profile, determine the appropriate risk mitigation strategies, and determine whether the third party or engagement meets all necessary compliance requirements.") |
| [Monitor third-party risk Use the Third-party Risk Management application to monitor potential risks associated with your third-party relationships.](https://www.servicenow.com/docs/Mt0S6CJuB~PC7DNXGZ9m1w "You can monitor the potential risks that are associated with your third-party relationships by using the Third-party Risk Management application. An ongoing monitoring process can help you regularly assess the third party's performance and adherence to the agreed-upon terms.") | [Approve or reject requests for due diligence Set up the approval levels and rules for due diligence requests in the Third-party Risk Management application to use while approving or rejecting requests after reviewing questionnaire responses and due diligence process results.](https://www.servicenow.com/docs/aqgpaVbgvxGp1gTVMdljvQ "Set up the approval levels and rules for due diligence requests in the Third-party Risk Management application to use while approving or rejecting requests after reviewing questionnaire responses and due diligence process results.") | [Manage the contract risk process Protect your organization's interests, as the Third-party risk contract negotiator by incorporating specific contractual provisions so that you can address identified risks.](https://www.servicenow.com/docs/LiCX_HyxYjqvbfirkO7HQw "Protect your organization's interests, as the Third-party risk contract negotiator, often the corporate counsel, by incorporating specific contractual provisions so that you can address the risks identified using the Third-party Risk Management application.") |
| [Use Digital resilience third-party registers Use the Digital resilience third-party registers application in the Vendor Management Workspace to set up and maintain registers of contractual arrangements with ICT third-party service providers.](https://www.servicenow.com/docs/pHXvo81xQelsQoCnL96JGg "Use the Digital Resilience Third-party Information Register application in the Vendor Management Workspace to create, update, and track assessments, branches, legal entities, and so on, and maintain registers of contractual arrangements with ICT third-party service providers.") | [Use risk intelligence reports Manage and request risk Intelligence reports or scores from external risk intelligence content providers.](https://www.servicenow.com/docs/HQQvz6CdIiNv6kTSamzivQ "Request risk intelligence reports or scores directly from your external risk intelligence content providers by using the Third-party Risk Management application. This information can be requested and managed based on the importance or risk level of the individual third party.") | [Integrate scores from risk intelligence providersIntegrate scores from risk intelligence providers. The scores provide insight on how trustworthy and safe a particular third party can be.](https://www.servicenow.com/docs/LyoDbZc3Vn9wCmv2fDSsRA "Risk intelligence providers generate risk scores for a variety of third-party risk domains. Your organization can purchase services from providers that return data that is analogous to personal credit scores. The scores provide insight on how trustworthy and safe a particular third party can be.") |
| [Use the third-party portalUse the third-party portal to respond to questionnaires, requests for documentation, tasks, and issues. The portal is the point of interaction between third-party contacts and risk assessors.](https://www.servicenow.com/docs/0~pzVvr~IuJOCqkyFNmYfA "Third-party contacts respond to questionnaires, requests for documentation, tasks, and issues on the Third-party portal. The portal is the point of interaction between third parties and risk assessors.") | [ReferenceReference topics provide detailed descriptions of tables, properties, forms, and roles that are installed with the Third-party Risk Management application.](https://www.servicenow.com/docs/tpLqwImQ~jHdKM9oSbTn9A "Reference topics provide detailed descriptions of tables, properties, forms, and roles that are installed with the Third-party Risk Management application.") |   |
[ ]

{#third-party-risk-mgt-landing-page__table_st1_3v3_hzb}  
Important:  
The Vendor Management Workspace for ITSM (sn_itsm_vendor) is deprecated as of the Australia release. It is hidden and no longer available for activation for new customers. References to Vendor Management Workspace throughout this documentation refer to the GRC: Vendor Management Workspace (sn_vrm_ws), which is a separate application included with Third-party Risk Management and is not affected by this deprecation. For details about the deprecation process, see the [Deprecation Process \[KB0867184\]](https://support.servicenow.com/kb_view.do?sysparm_article=KB0867184) article in the Now Support Knowledge Base.

## Troubleshoot and get help {#third-party-risk-mgt-landing-page__section_xt1_3v3_hzb}

* [Ask or answer questions in the GRC community](https://www.servicenow.com/community/forums/filteredbylabelpage/board-id/governance-risk-compliance-forum/label-name/vendor%20risk%20management).
* [Search the Known Error Portal for known error articles](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0597477).
* [Learn how to build apps on the developer site](https://developer.servicenow.com/app.do#!/training/landing).
* [Contact Customer Service and Support](https://support.servicenow.com/now?draw=case).
{#third-party-risk-mgt-landing-page__ul_yt1_3v3_hzb}

