---
sourceDocument: Brazil Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/governance-risk-compliance

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Roles in TPRM

# Roles in Third-party Risk Management {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Roles in Third-party Risk Management

In Third-party Risk Management (TPRM), roles define the permissions and access levels for users managing third-party risk activities within ServiceNow.
These roles control what users can view, create, update, or approve across various TPRM functions, ensuring appropriate access based on responsibilities.
Show full answer Show less  

## Key Roles and Their Permissions

* **Third-party reader \[vendorreader\]**: Read-only access to third-party contact records.
* **Third-party editor \[vendoreditor\]**: Can create, update, or delete third-party contact records.
* **Third-party assessment reviewer \[snvdrriskasmt.vendorassessmentreviewer\]**: View assessments and questionnaires, and comment on assessments, risk issues, and tasks.
* **TPR internal task responder \[snvdrriskasmtinternaltaskresponder\]**: Manage internal tasks assigned to the user as respondent.
* **TPR assessor \[snvdrriskasmt.vendorassessor\]**: Includes all reviewer permissions plus managing third parties, contacts, external assessments, and issues. Configurable to allow questionnaire response edits.
* **TPR approver \[snvdrriskasmt.approver\]**: Reviewer permissions plus the ability to approve Internal Risk Questionnaires (IRQs).
* **TPR manager \[snvdrriskasmt.vendorriskmanager\]**: Adds management of assessment templates, engagements, and scoring rules to assessor capabilities.
* **TPR admin \[snvdrriskasmt.vendorriskadmin\]**: Full management of templates, automation rules, and advanced TPRM configurations.
* **Contract risk negotiator \[snvdrriskasmt.contractnegotiator\]**: Legal department role that can modify contract statuses and dates, with permissions aligned to the assessor role.
* **Third-party / engagement contact \[vendorcontact\]**: External users assigned to respond to questionnaires or tasks via the Third-party portal, with limited access to your ServiceNow instance.

## Roles for Digital Resilience Third-party Registers

Specific roles provide access to Digital Resilience modules in Vendor Management Workspace:

* **TPRM DORA user \[sndoraaccel.user\]**: Included in assessment reviewer and approver roles.
* **TPRM DORA manager \[sndoraaccel.manager\]**: Included in assessor and manager roles.
* **TPRM DORA admin \[sndoraaccel.admin\]**: Included in admin role.

## Roles Related to Smart Assessment Engine (SAE)

* Roles allow viewing of templates, responding to questionnaires (internal and external), and creating SAE templates and automation rules.
* Key roles include template readers, assessment readers, internal and external assessment users, and SAE admins.
* Reassignment of SAE questionnaires within the organization is enabled for admin, assessor, and manager roles.
* The minimum role to view external questionnaires and document requests is the Third-party assessment reviewer.

## ServiceNow Otto for TPRM Roles

The Third-party assessment reviewer role enables use of ServiceNow Otto for TPRM skills. After installation, this role automatically receives the TPRM GenAI User role for enhanced AI capabilities.

## Practical Implications for ServiceNow Customers

* Assign roles to users and groups based on their responsibilities to control access to third-party risk data and actions.
* Use defined roles to separate duties such as assessment review, management, approval, contract negotiation, and external third-party interaction.
* Leverage the integration with Digital Resilience and Smart Assessment Engine by assigning the appropriate roles for enhanced functionality.
* Ensure external contacts are assigned the **vendorcontact** role to provide controlled portal access without exposing internal ServiceNow data.  
Roles determine permissions and access in TPRM.

## TPRM roles {#tprm-roles__section_rcc_nl2_5xb}

{#tprm-roles__table_o14_t2s_2mb__entry__3}

| Friendly name \[role name\] | Description | Contains roles |
|-|-|-|
| Third-party reader \[vendor_reader\] | Read access to third-party contact records. | None |
| Third-party editor \[vendor_editor\] | Create, update, or delete third-party contact records. | None |
| Third-party assessment reviewer \[sn_vdr_risk_asmt.vendor_assessment_reviewer\] | View assessment and questionnaire data. Users with this role can also leave comments on the following tables: * Tiering assessment * Internal assessment * External assessment * Third-party risk issues * Third-party risk tasks * Third-party risk due diligence request {#tprm-roles__ul_gmy_qjz_fyb} | Contains: * sn_risk.implementation_reader * sn_compliance.control_framework_reader * sn_compliance.policy_reader * sn_grc.library_reader * sn_smart_asmt.actor * task_editor * vendor_reader * sn_dora_accel.user * sn_smart_asmt.template_reader * sn_smart_asmt.assessment_reader * sn_tprm_genai.nowassist_user {#tprm-roles__ul_mm2_g4p_qxb} |
| TPR internal task responder \[sn_vdr_risk_asmt_internal_task_responder\] | Create, read, update, and delete the elements linked to the internal tasks for which the user is the respondent. This role is automatically granted to the assigned respondent when an internal task moves to the Submitted to respondent state, and replaces use of the internal assessment user \[sn_vdr_risk_asmt.internal_assessment_responder\] role for internal tasks specifically. | * sn_grc_workspace.task_reader * sn_grc_workspace.user {#tprm-roles__ul_umw_4tx_zjc} |
| TPR assessor (Third-party risk assessor) \[sn_vdr_risk_asmt.vendor_assessor\] | * All permissions of the Third-party assessment reviewer role, plus the ability to manage third parties, third-party contacts, external risk assessments, and issues. * You can set the following options for the sn_svdp.allow_assessor_edit property: * Enable TPR assessors to answer questions or modify responses in third-party questionnaires (default). * Enable TPR assessors to modify responses. * Don't enable TPR assessors to answer questions or modify responses. {#tprm-roles__ul_at3_m1f_zyb}See [Configure TPRM properties](https://www.servicenow.com/docs/YvWIcxNml8gfXOX0ilIyXg "Configure property settings for a variety of TPRM operations."). {#tprm-roles__ul_twn_g1x_11c} | Contains: * vendor_assessment_reviewer * sn_grc.library_reader * vendor_editor * vendor_reader * sn_dora_accel.manager * sn_smart_asmt.reassign {#tprm-roles__ul_w3n_l4p_qxb} |
| TPR approver \[sn_vdr_risk_asmt.approver\] | Includes all permissions of the Third-party assessment reviewer role plus: approve IRQs. | Contains: * vendor_assessment_reviewer * sn_dora_accel.user {#tprm-roles__ul_wps_rqh_xcc} |
| TPR manager (Third-party risk manager) \[sn_vdr_risk_asmt.vendor_risk_manager\] | Includes all permissions of the TPR assessor role plus: * Manage third-party assessment templates and scheduled assessments. * Manage engagements and engagement contacts. * Manage scoring rules for both third parties and engagements. {#tprm-roles__ul_yrt_xxj_mxb} | Contains: * vendor_assessor * sn_dora_accel.manager * sn_smart_asmt.reassign {#tprm-roles__ul_klf_vqh_xcc} |
| TPR admin (Third-party risk admin) \[sn_vdr_risk_asmt.vendor_risk_admin\] | Includes all permissions of the TPR manager role plus: Create and edit the following items: * Third-party assessment templates * Risk tiering templates * Risk tier questionnaire templates * Third-party questionnaire templates * Document request templates * Post assessment automation rules {#tprm-roles__ul_z5g_qxf_lzb} Note: Templates include both classic and SAE templates. | Contains: * vendor_risk_manager * assessment_admin * sn_dora_accel.admin * sn_smart_asmt.assessment_admin * sn_smart_imp_auto.automation_creator * sn_smart_asmt.reassign {#tprm-roles__ul_ulc_42y_zjc} |
| Contract risk negotiator \[sn_vdr_risk_asmt.contract_negotiator\] | Includes all permissions of the TPR assessor role plus: Users in the legal department can modify contract status and the start and expiration dates. You can add users with this role to the Contract risk negotiators user group. See [Add users to groups based on responsibilities](https://www.servicenow.com/docs/26RApqghbX3O9C3G_V48zQ "Assign users to groups before you implement or use the Third-party Risk Management application. Each group contains users with particular roles. Well-organized user groups simplify and improve process management and help to ensure that users are promptly notified of tasks in their areas of responsibility."). | Contains: * vendor_assessor * sn_dora_accel.manager {#tprm-roles__ul_mbw_brh_xcc} |
| Third-party / engagement contact \[vendor_contact\] * Called a third-party contact when responding to an external questionnaire or task or issue for a third party. * Called an engagement contact when responding to a questionnaire or task or issue for an engagement. {#tprm-roles__ul_upd_34n_cyb} | You assign the third-party contact role to users at the third-party organization whose risk is being assessed. Third-party contacts are assigned the snc_external role to give them access to resources and actions in the Third-party portal. Important: The third-party contact role should be used only for external contacts. The role prohibits access to your ServiceNow AI Platform instance and grants access only to the Third-party portal. You assign the primary contact responsibility to the third-party contact who can directly answer assessment questions or assign another contact at the third party to answer the questions. Primary contacts can manage other contacts for the third party. | Contains: snc_external |
[ ]

{#tprm-roles__table_o14_t2s_2mb}

## Roles required for accessing the Digital resilience third-party registers {#tprm-roles__section_xny_kcv_zzb}

A user with one of the following roles can access the Digital resilience third-party registers related modules in the Vendor Management Workspace:

* TPRM DORA user \[sn_dora_accel.user\] roleThird-party assessment reviewer and TPR approver contain this role.

* TPRM DORA manager \[sn_dora_accel.manager\] roleTPR assessor and TPR manager contain this role.

* TPRM DORA admin \[sn_dora_accel.admin\]The TPR admin contains this role.

{#tprm-roles__ul_jj1_jdv_zzb} For more information on DORA related roles, see [Roles installed with Digital resilience third-party registers](https://www.servicenow.com/docs/rd6BfakYQPS3q5wAIEM3ZA "Specific roles are installed with Digital resilience third-party registers.").

## Roles required for using Smart Assessment Engine {#tprm-roles__section_lbx_kcb_l2c}

A user with one of the following roles can view templates in the Assessment Workspace:

* TPRM SAE template reader \[sn_smart_asmt.template_reader\] role

  Third-party assessment reviewer contains this role.
* TPRM SAE assessment reader \[sn_smart_asmt.assessment_reader\] role

  Third-party assessment reviewer contains this role.
{#tprm-roles__ul_mbx_kcb_l2c}  
A user with one of the following roles can respond to questionnaires in the Vendor Management Workspace, GRC portal, or Third-party portal.

* TPRM SAE internal assessment user \[sn_vdr_risk_asmt.internal_assessment_responder\]

  This role is automatically assigned to an assigned IRQ assessor or internal assessment respondent.

  This role is required to respond to internal/IRQ assessment questionnaires using the GRC Portal.

  This role contains the following roles: canvas_user, sn_smart_asmt.actor, sn_grc_workspace.user, and
  sn_grc_workspace.task_reader.
* TPRMSAE external assessment user \[sn_vdr_risk_asmt.external_assessment_responder\]

  This role is automatically assigned to the assigned third-party contact.

  This role is required to
  respond to external questionnaires using the Third-party portal.

  This contains the role: sn_smart_asmt.actor.
{#tprm-roles__ul_bpm_ltt_ffc}

A user with the TPRM
SAE admin \[sn_smart_asmt.assessment_admin\] role can create SAE templates in the Vendor Management Workspace and Assessment Workspace.

A user with the sn_smart_imp_auto.automation_creator role can create post assessment impact automation rules. The TPR admin contains this role.

The TPR administrator \[sn_vdr_risk_asmt.vendor_risk_admin\], TPR assessor \[sn_vdr_risk_asmt.vendor_assessor\], and TPR manager \[sn_vdr_risk_asmt.vendor_risk_manager\] roles now include the
sn_smart_asmt.reassign role. You can reassign Smart Assessment Engine questionnaires to another member of your organization.  
Note:  
The Third-party assessment reviewer \[sn_vdr_risk_asmt.vendor_assessment_reviewer\] role is the minimum role required to view any template that is a member of the TPRM external questionnaire, TPRM external document request, TPRM internal tiering questionnaire, and TPRM internal IRQ purposes.

For more information on SAE related roles, see [Roles installed in Smart Assessment Engine](https://www.servicenow.com/docs/HCS7nR896lZMU3_OzJHQbg "Roles determine the permissions and access in the Smart Assessment Engine application.").

## Roles required for using ServiceNow Otto for Third-party Risk Management (TPRM) {#tprm-roles__section_ddc_dt1_lhc}

A user with the Third-party Assessment reviewer \[sn_vdr_risk_asmt.vendor_assessment_reviewer\] role can use the ServiceNow Otto for TPRM skills.

The system automatically grants the TPRM GenAI User \[sn_tprm_genai.nowassist_user\] role to Third-party Assessment reviewers \[sn_vdr_risk_asmt.vendor_assessment_reviewer\] after the ServiceNow Otto for TPRM application is installed. For more information about a ServiceNow Otto for TPRM, see [ServiceNow Otto for Third-party Risk Management (TPRM)](https://www.servicenow.com/docs/9x3so~mKQiERqV_VRtydqg "With the ServiceNow Otto for Third-party Risk Management (TPRM) application, you can use skills to automate the collection of TPRM risk data.").
**Related tasks**   

* [Assign TPRM roles to users and user groups](https://www.servicenow.com/docs/MYTgv1juTU1DzZ_3taVXKA "Assign roles to users before you implement or use the Third-party Risk Management application. Assigning roles in a well-organized manner simplifies and improves process management and helps to ensure that users are promptly notified of tasks in their areas of responsibility.")  
**Related reference**   

* [Roles installed with Digital resilience third-party registers](https://www.servicenow.com/docs/rd6BfakYQPS3q5wAIEM3ZA "Specific roles are installed with Digital resilience third-party registers.")
* [Roles installed in Smart Assessment Engine](https://www.servicenow.com/docs/HCS7nR896lZMU3_OzJHQbg "Roles determine the permissions and access in the Smart Assessment Engine application.")

