---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/pt-BR/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# VRM third-party risk tiering assessments

# VRM third-party risk tiering assessments {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

Organizations use risk tiering to classify their third parties into categories of potential risk posed at the time of onboarding. The standard predefined risk tiers are None, Low, Minor, Moderate, High, and Critical. Each risk tier has associated assessment questions and document requests.

## The more complete IRQ process replaces tiering {#manage-risk-tiering-assessments__id_g4d_2lm_gyb}


In the TPRM application, the IRQ is an internal questionnaire that improves the original tiering assessment process. IRQs enhance internal risk assessments with increased flexibility, control, and scalability. Unlike a tiering assessment where external questionnaires are determined solely by the risk tier, an IRQ can dynamically trigger external questionnaires based on both respondents' answers and risk tier.{#manage-risk-tiering-assessments__ph-irq-replaces-tiering}


To enable a seamless transition to TPRM, you have the option to duplicate existing tiering assessments and designate them as IRQ internal assessments. Risk tiering is supported as an unchanging legacy process.{#manage-risk-tiering-assessments__ph-tiering-is-legacy}

## Legacy operation {#manage-risk-tiering-assessments__section_kv3_vwv_byb}

1. Most organizations import their third-party portfolio through a spreadsheet or an integration with another onboarding solution. Third-party risk (TPR) managers make ongoing updates to third-party information, including risk security scores and risk tiers.
2. The TPR manager or TPR assessor determines the risk tier or categories of risk exposure for the third party.
3. The TPR manager selects the third party, assigns the tiering questionnaire template, and assigns the internal assessor that is required to complete the assessment.Figura 1. Risk tiering assessment table relationship
4. Internal stakeholders navigate to Self-serviceMy Assessments and Surveys to complete and submit the assessment.
5. After the internal assessor has responded to the questionnaire, the system calculates the tiering score as the average of all scores. The TPR manager can initiate the risk assessment or a configured business rule can auto-send one. When the assessment is closed, the system assigns a risk tier to the third party based on the tiering score.

{#manage-risk-tiering-assessments__ol_shc_2nd_kz}  
Figura 2. Risk tier calculation based on responses

## Risk tiering scale and scoring calculations {#manage-risk-tiering-assessments__section_b4n_p1g_1lb}

Figura 3. Risk tiering process

1. The tiering assessment initiates an assessment instance for the assigned internal assessor.
2. Response scores are averaged to generate the tiering score.
3. The tiering score is mapped to risk tiers.
4. The risk tier is assigned to the third party when the tiering assessment is closed.
{#manage-risk-tiering-assessments__ol_m23_yfb_l2b}

