Combined Third-party Risk Management release notes for upgrades from Yokohama to Zurich
Summarize
Summary of Combined Third-party Risk Management Release Notes for Upgrades from Yokohama to Zurich
This consolidated guide is designed to help ServiceNow customers prepare for upgrading Third-party Risk Management (TPRM) from the Yokohama release family to Zurich. It covers pre- and post-upgrade tasks, new features, changes, and important upgrade considerations to ensure a smooth transition while maintaining data integrity and compliance.
Show less
Upgrade Considerations
- Sequential Upgrades: VRM users upgrading to TPRM must run upgrades sequentially from one release to the next (e.g., Utah to Vancouver, Vancouver to Washington DC) to ensure fix scripts execute correctly. Skipping versions may cause data inconsistencies, broken functionalities, and conflicts.
- Data Migration: After upgrading to versions 20.2.4 (Yokohama) or 21.0.3 (Zurich), the Industry column in the Company table is migrated to the tprmindustry column. Migration can take hours depending on data volume. Customers must update customizations to reference the new column before dropping the old one.
- Smart Assessment Engine (SAE): Available from version 21.0.x onwards, SAE replaces the legacy assessment engine when enabled via the
snvdrriskasmt.saeenabledproperty. This change is irreversible and requires thorough testing in non-production environments before production deployment.
New Features
- TPRM Personalized Dashboards (Yokohama): Roles such as Third-party Risk Manager and Assessor can create and customize dashboards and reports for better decision-making aligned with organizational risk programs.
- Standardized Information Gathering (SIG) Questionnaires: Updated 2025 SIG templates support compliance with evolving regulatory and governance requirements.
- Quick Start Tests: Validate TPRM functionality after upgrades or deployments to ensure expected behavior, customizable for customer-specific configurations.
- Document Management System (DMS) (Zurich): Centralized repository for third-party documents with metadata, version control, and access permissions, enhancing evidence tracking and audit readiness.
- Register of Information (RoI) Regulatory Packages (Zurich): Third-party assessors can generate EU DORA-compliant, regulator-ready report packages in a structured ZIP format supporting automated validation.
- Validation Framework for RoI (Zurich): Enables risk managers to validate RoI packages against file format and data requirements with detailed validation reports and error mapping.
- Enhanced Smart Assessment Engine (SAE) Capabilities: Improved navigation, question grouping, auto-save, filtering, bulk template migration, risk score normalization, and support for internal/external assessments via GRC and third-party portals.
- Fourth-party Assessment Support (Zurich): Enabled in SAE to extend assessment capabilities to fourth-party risks.
- Feature-specific Administrator Roles (Zurich): Granular role assignments allow dedicated administration of vendor risk features without requiring broad administrator privileges.
- Dark Theme Support (Zurich): Coral theme introduces a dark mode option for the Vendor Management Workspace and mobile interfaces to improve readability and reduce eye strain.
Key Changes
- Pre-populated Questionnaires: Responses from completed questionnaires can pre-populate related engagements and entities, improving data consistency and reducing assessor workload.
- Microsoft Excel Questionnaire Templates: Third parties may respond offline using Excel templates, which can then be imported to streamline data collection.
- DORA Compliance Enhancements: Additional code types, legal names, function types, and support for multiple legal entities per contract have been added to digital resilience registers for regulatory compliance and transparency.
- Risk Areas for Internal Assessments: Risk managers can now configure weighted risk areas and scoring within SAE for internal assessments, with options for manual rating overrides and aggregation methods.
- Smart Assessment Engine Advanced Plugins: Automation plugins facilitate post-assessment actions and auto-fill responses based on prior data or logic, streamlining workflows.
- Read-only Field Security Enhancements: Strengthened security on key TPRM and GRC plugins ensures improved data protection for sensitive fields.
- Enhanced Contract Records: Support for associating multiple entities with contracts in the Vendor Management Workspace improves compliance with Digital Operational Resilience Management (DORA) regulations.
- Vertical Navigation Panel: Customizable vertical navigation in Vendor Management Workspace enhances access to related lists and third-party records.
Removed and Deprecated Features
There were no removals or deprecations of features between Yokohama and Zurich releases for Third-party Risk Management.
Activation and Additional Information
- Installation: TPRM is available via the ServiceNow Store; customers should request installation through the store portal.
- Browser and Accessibility: No new browser requirements or accessibility updates were introduced in
Consolidated page of all release notes for Third-party Risk Management from Yokohama to Zurich.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Third-party Risk Management release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Yokohama to Zurich.
Important information for upgrading Third-party Risk Management to Zurich
Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release | Release notes |
|---|---|
Yokohama |
Starting with the Vancouver release, if you’re a VRM user upgrading to TPRM, from an earlier release, you must run each upgrade sequentially to ensure that fix scripts run correctly. This means upgrading from one release to the next rather than skipping to the latest release. Not running scripts in the correct order can result in data inconsistencies, broken functionalities, and conflicts. For more information on upgrading from VRM to TPRM, see Third-party Risk Management upgrade information. For existing TPRM customers, after upgrading to version 20.2.4, data from the Industry column in the Company [core_company] table is automatically migrated to the tprm_industry column. Migration can take several hours depending on the number of records in the Company [core_company] table. After migration, a system log message confirms that the migration is complete. Review the Company [core_company] table content and update any customizations referencing the Industry field to use tprm_industry. After verifying the migration and updating customizations, you can drop the Industry column. |
Zurich |
If you’re a VRM user upgrading to TPRM and upgrading to Vancouver or a later release from an earlier release, you must run each upgrade sequentially to ensure that fix scripts run correctly. For example, you must upgrade from Utah to Vancouver, Vancouver to Washington DC, and so on. If the scripts don’t run in the correct order, you can get data inconsistencies, broken functionalities, and conflicts. After upgrading to version 21.0.x, you can enable the Smart Assessment Engine (SAE) by setting the Smart Assessment Engine enabled (sn_vdr_risk_asmt.sae_enabled) property. After setting this property, Smart Assessment Engine (SAE) becomes the default assessment engine and replaces the legacy experience. The transition isn’t reversible. Warning: Set this property in your non-production instances and conduct thorough testing before changing your production instances. Failure to do so may result in unexpected issues. For more information on upgrading from VRM to TPRM and the differences between the Smart and Classic Assessment engines, see Third-party Risk Management upgrade information. For existing TPRM customers, after upgrading to version 21.0.3, data from the Industry column in the Company [core_company] table is automatically migrated to the tprm_industry column. Migration can take several hours depending on the number of records in the Company [core_company] table. After migration, a system log message confirms that the migration is complete. Review the Company [core_company] table content and update any customizations referencing the Industry field to use tprm_industry. After verifying the migration and updating customizations, you can drop the Industry column. |
New features
Between your current release family and Zurich, new features were introduced for Third-party Risk Management.
| Release | Release notes |
|---|---|
Yokohama |
|
Zurich |
|
Changes
Between your current release family and Zurich, some changes were made to existing Third-party Risk Management features.
| Release | Release notes |
|---|---|
Yokohama |
|
Zurich |
|
Removed
Between your current release family and Zurich, some Third-party Risk Management features or functionality were removed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Deprecations
Between your current release family and Zurich, some Third-party Risk Management features or functionality were deprecated.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Activation information
Review information on how to activate Third-party Risk Management.
| Release | Release notes |
|---|---|
Yokohama |
Install Third-party Risk Management by requesting it from ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Zurich |
Install Third-party Risk Management by requesting it from ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Additional requirements
If any additional requirements were introduced or changed for Third-party Risk Management we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Third-party Risk Management we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Accessibility information
Review details on accessibility information for Third-party Risk Management, such as specific requirements or compliance levels.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
|
Localization information
If there are specific localization considerations for Third-party Risk Management we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Third-party Risk Management we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
See Third-party Risk Management for more information. |
Zurich |
See Third-party Risk Management for more information. |