Combined Third-party Risk Management release notes for upgrades from Zurich to Australia
Summarize
Summary of Combined Third-party Risk Management release notes for upgrades from Zurich to Australia
This consolidated release notes document guides ServiceNow customers upgrading Third-party Risk Management (TPRM) from the Zurich release family to the Australia release family. It highlights important upgrade instructions, new features, changes, removals, and activations necessary for smooth transition and optimal use of TPRM capabilities.
Show less
Upgrade Guidance
- Sequential Upgrades Required: Customers upgrading from Vendor Risk Management (VRM) to TPRM must apply upgrades sequentially (e.g., Utah → Vancouver → Washington DC → etc.) to ensure fix scripts execute properly and avoid data inconsistencies or broken functionality.
- Smart Assessment Engine (SAE): After upgrading to version 21.0.x, customers can enable the SAE by setting the snvdrriskasmt.saeenabled property. This replaces the legacy assessment engine irreversibly, so extensive testing in non-production environments is critical before enabling in production.
- Data Migration: Industry data in the Company [corecompany] table is migrated to a new tprmindustry column after upgrading to version 21.0.3. Customers should update any customizations referencing the old field and can drop it after validation.
- Role Changes: From version 22.3.3, roles grcbusinessuser and grcreader are no longer inherited by TPRM roles. Manual role review may be required for users with custom role combinations.
New Features
- Document Management System (DMS): Introduced in version 21.1.x, DMS centralizes third-party document storage with metadata, version control, and access permissions to improve evidence tracking and audit readiness.
- Register of Information (RoI) Regulatory Packages: Enables generation of regulator-ready packages in compliant CSV formats to support EU DORA regulations, including automated validation and reporting features.
- Smart Assessment Engine Enhancements: Enhanced navigation, question organization, auto-save, risk rating standardization, bulk migration of classic templates, and support for internal/external assessments via GRC and third-party portals.
- AI-Assisted Questionnaire Pre-fill: Available in version 22.3.3, this feature uses uploaded documents and past responses to suggest questionnaire answers with source citations, reducing manual effort.
- Software Bill of Materials (SBOM) Support: Added in version 22.3.2, allows collection and management of SBOM data to support regulatory disclosure requirements when the relevant applications are installed.
- Updated Standardized Information Gathering (SIG) 2026 Templates: Expanded coverage for security and privacy frameworks with existing versions remaining available.
- Smart Assessment Template Versioning: Manages template lifecycle explicitly so that in-flight assessments retain the template version active at creation.
- LEI Validation for DORA Reporting: Validates Legal Entity Identifiers against GLEIF database to ensure regulatory accuracy during reporting.
- Aggregate Regulatory Reporting: Supports currency conversion and third-party expense aggregation to generate consistent, regulator-ready reports.
- Centralized Repository for SAE Templates: Unified Content Management integration provides a single library of Smart Assessment templates for consistent assessments.
- Generative AI for Issue Recommendations (Early Availability): Automatically suggests TPRM issues based on assessment responses for reviewer validation.
- Expanded AI Model Support: Supports multiple advanced AI models including Google Gemini 3.5 Flash and OpenAI GPT 5.x series, providing flexibility based on subscription.
- Improved Email Notifications: External assessment notifications are consolidated into summary emails with configurable frequency and multi-language support.
- Data Integrity Enhancements: Automatic cascading updates to supply chain data in DORA contracts, duplicate record detection with blocking and warnings, and exclusion of inactive metrics in assessments to improve accuracy and compliance.
- Simplified Third-party Element Process: Third-party elements now link exclusively to a single third party, simplifying due diligence workflows.
Changes
- Risk areas with weighted questions and scored responses are now configurable for internal assessments using SAE.
- Advanced SAE plugins automate post-assessment actions and response automation.
- Feature-specific roles replace broad admin access; users must be assigned appropriate TPRM roles to access features.
- Security enhancements for read-only fields across multiple TPRM-related plugins.
- Enhanced contract records can associate multiple entities per contract and support DORA compliance reporting.
- Assessment counts in third-party portal now consider only active, pending, and in-progress assessments.
Removals
- Assessment using entities is no longer supported.
- Direct inheritance of grcbusinessuser and <
Consolidated page of all release notes for Third-party Risk Management from Zurich to Australia.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Third-party Risk Management release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Zurich to Australia.
Important information for upgrading Third-party Risk Management to Australia
Before you upgrade to Australia, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release | Release notes |
|---|---|
Zurich |
If you’re a VRM user upgrading to TPRM and upgrading to Vancouver or a later release from an earlier release, you must run each upgrade sequentially to ensure that fix scripts run correctly. For example, you must upgrade from Utah to Vancouver, Vancouver to Washington DC, and so on. If the scripts don’t run in the correct order, you can get data inconsistencies, broken functionalities, and conflicts. After upgrading to version 21.0.x, you can enable the Smart Assessment Engine (SAE) by setting the Smart Assessment Engine enabled (sn_vdr_risk_asmt.sae_enabled) property. After setting this property, Smart Assessment Engine (SAE) becomes the default assessment engine and replaces the legacy experience. The transition isn’t reversible. Warning: Set this property in your non-production instances and conduct thorough testing before changing your production instances. Failure to do so may result in unexpected issues. For more information on upgrading from VRM to TPRM and the differences between the Smart and Classic Assessment engines, see Third-party Risk Management upgrade information. For existing TPRM customers, after upgrading to version 21.0.3, data from the Industry column in the Company [core_company] table is automatically migrated to the tprm_industry column. Migration can take several hours depending on the number of records in the Company [core_company] table. After migration, a system log message confirms that the migration is complete. Review the Company [core_company] table content and update any customizations referencing the Industry field to use tprm_industry. After verifying the migration and updating customizations, you can drop the Industry column. |
Australia |
If you're a VRM user upgrading to TPRM and upgrading to Australia from an earlier release, you must run each upgrade sequentially to ensure that fix scripts run correctly. For example, you must upgrade from Xanadu to Yokohama, Yokohama to Zurich, and so on. If the scripts don't run in the correct order, you can get data inconsistencies, broken functionalities, and conflicts. After upgrading to version 21.0.x, you can enable the Smart Assessment Engine (SAE) by setting the Smart Assessment Engine enabled (sn_vdr_risk_asmt.sae_enabled) property. After setting this property, Smart Assessment Engine (SAE) is set to the default assessment engine and replaces the legacy experience. The transition is irreversible.
Warning: Set this property in your non-production instances and conduct thorough testing before changing your production instances. Failure to do so can result in unexpected issues. For more information on upgrading from VRM to TPRM and the differences between the Smart and Classic Assessment engines, see Third-party Risk Management upgrade information. For existing TPRM customers, after upgrading to version 21.0.3, data from the Industry column in the Company [core_company] table is automatically migrated to the tprm_industry column. Migration can take several hours depending on the number of records in the Company [core_company] table. After migration, a system log message confirms that the migration is complete. Review the Company [core_company] table content. Update any customizations that reference the Industry field to use tprm_industry. After verifying the migration and updating customizations, you can drop the Industry column. After upgrading to version 22.3.3, the |
New features
Between your current release family and Australia, new features were introduced for Third-party Risk Management.
| Release | Release notes |
|---|---|
Zurich |
|
Australia |
|
Changes
Between your current release family and Australia, some changes were made to existing Third-party Risk Management features.
| Release | Release notes |
|---|---|
Zurich |
|
Australia |
|
Removed
Between your current release family and Australia, some Third-party Risk Management features or functionality were removed.
| Release | Release notes |
|---|---|
Zurich |
No updates for this release. |
Australia |
|
Deprecations
Between your current release family and Australia, some Third-party Risk Management features or functionality were deprecated.
| Release | Release notes |
|---|---|
Zurich |
No updates for this release. |
Australia |
No updates for this release. |
Activation information
Review information on how to activate Third-party Risk Management.
| Release | Release notes |
|---|---|
Zurich |
Install Third-party Risk Management by requesting it from ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Australia |
Install Third-party Risk Management by requesting it from ServiceNow Store. |
Additional requirements
If any additional requirements were introduced or changed for Third-party Risk Management we have noted them here.
| Release | Release notes |
|---|---|
Zurich |
No updates for this release. |
Australia |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Third-party Risk Management we have noted them here.
| Release | Release notes |
|---|---|
Zurich |
No updates for this release. |
Australia |
No updates for this release. |
Accessibility information
Review details on accessibility information for Third-party Risk Management, such as specific requirements or compliance levels.
| Release | Release notes |
|---|---|
Zurich |
|
Australia |
The Vendor Management Workspace and the third-party portal include accessibility improvements in this release, including improved color contrast, enhanced focus indicators, skip navigation links, and full keyboard navigation. |
Localization information
If there are specific localization considerations for Third-party Risk Management we have noted them here.
| Release | Release notes |
|---|---|
Zurich |
No updates for this release. |
Australia |
Third-party portal strings are externalized and translated for supported languages. Newly introduced features may have incomplete translations. |
Highlight information
If there are specific highlight considerations for Third-party Risk Management we have noted them here.
| Release | Release notes |
|---|---|
Zurich |
See Third-party Risk Management for more information. |
Australia |
Starting with Australia Patch 5, Now Assist for Third-party Risk Management is now ServiceNow Otto® for TPRM. Your product entitlements remain unchanged. Check your entitlements to determine your access to specific features.
Review the updated AI experience with three licensing tiers. See Third-party Risk Management for more information. Use generative AI to recommend TPRM issues for reviewer validation. |