---
sourceDocument: Xanadu Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/governance-risk-compliance

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Create external assessments

# Create an external assessment {#ariaid-title1}

* Release version: Xanadu
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Create an assessment and initiate the third-party risk assessment life cycle using Third-party Risk Management. An external assessment specifies the details for the third party or engagement and defines the plan for completing the assessment.

## Before you begin

Role required: sn_vdr_risk_asmt.vendor_risk_manager or sn_vdr_risk_asmt.vendor_assessor

## About this task

Assessments can be created on-demand or can recur on a specified schedule. When creating an on-demand external assessment, Third-party risk (TPR) managers or TPR assessors select the questionnaire template or document
request template and the third party. You can select multiple third parties at a time and automatically trigger assessments.

## Procedure

1. Navigate to one of the following locations:  
   * AllThird-party Risk ManagementExternal Risk AssessmentsAll Assessments.
   * WorkspacesVendor Management Workspace, select the list icon ![]() and then navigate to External Risk AssessmentsAll Assessments.

   {#tprm-create-assessment__ul_zck_crf_c2c}  
   Important:  
   Smart assessments must be viewed in the Vendor Management Workspace.
2. Create an external assessment by selecting New and fill in the form.  
   For descriptions of all these fields, see [Third-party risk assessment form](https://www.servicenow.com/docs/rVJLU5Ge6logckWTOV1tDQ "Use the third-party risk assessment form to capture all the information that you need to create an assessment using the Third-party Risk Management application. As a third-party risk assessor or manager, you can create an external assessment.").
3. Select Submit.  
   Additional related lists appear. If you left the Assessment template field empty and want to use assessment templates to associate multiple questionnaires or document requests with this assessment,
   use the Questionnaires or Document Requests related lists.
4. Associate existing questionnaires or document requests with the assessment, by performing the following steps.
   1. Open the Questionnaires or Document Requests related list.
   2. Select Edit, select the questionnaires or document requests to use, and then select Save.
   3. Repeat for the other type of questions, if needed.

   {#tprm-create-assessment__substeps_i2p_3mv_ldc}  
   TPR administrators can create questionnaire or document request templates and associate them with the assessment. For more information, see [Create a questionnaire or document request template](https://www.servicenow.com/docs/Rx76DUJoZj0_B39Qd6Bp~w "You can reuse questionnaire templates and document-request templates to speed up the creation of new questionnaires and document requests.").
5. Select Submit to third party.  
   Important:  
   When the TPR manager or TPR assessor adds a questionnaire to an assessment, they have the option to select or deselect the Include previous responses option on the questionnaire page. The option can't be changed after the questionnaire is sent to the third party. For more information, see [Create a questionnaire or document request template](https://www.servicenow.com/docs/Rx76DUJoZj0_B39Qd6Bp~w "You can reuse questionnaire templates and document-request templates to speed up the creation of new questionnaires and document requests.") and [Assessment metric type form](https://www.servicenow.com/docs/iRFcM9~oUIpGEkaIiqKsSA "Use the assessment metric type form to capture all the information that you need to create a questionnaire template using the Third-party Risk Management application. As a third-party risk admin, you can create a questionnaire template.").  
   * The state of the assessment changes to Submitted to third party.
   * The templates that you selected generate questionnaires or document requests.
   * If the Include previous responses option is selected for a questionnaire, then previous responses are copied and added to the outgoing questionnaire. The notification in the Third-party portal includes the number, name, and last updated date of the previous assessment that supplied the responses. The notification also includes a link to the assessment.
   * The primary third-party contact receives an email notification that includes a link to the assessment in the Third-party portal.  
     Note:  
     When you use the Include previous responses option, responses are copied from the original assessment (Assessment A) to the newer assessment (Assessment B) one time. Any changes you make to Assessment A afterward won't be reflected in Assessment B. Both assessments remain separate.
   {#tprm-create-assessment__ul_gkg_vvp_4xb}
6. When the third-party contact is ready to respond to the assessment, they open the assessment in the Third-party portal.  
   Note:  
   If your questionnaire is set up to require a signature, the third party or reviewer must save and e-sign the questionnaire or document request before it can be submitted. The signature feature isn't supported for SAE questionnaires. For more information, see [E-signatures on questionnaires or document requests](https://www.servicenow.com/docs/IhK3xdeinbaib9lOKVdi0w "Questionnaires or document requests might require electronic signatures of third-party contacts and/or reviewers.").
7. The TPR assessor moves the state of the assessment to Generating Observations.  
   During this time, the TPR assessor can navigate to the Risk overview tab, in the Questionnaires and document requests section, select the Name or Questionnaire instance to view
   the responses. In the classic engine they can provide comments or change responses, as necessary.

   For any problems that arise, the TPR assessor creates an issue to track the remediation process (Finalizing with third party).
8. The TPR assessor moves the assessment to the Closed state.

## What to do next

The TPR assessor works through the third-party portal with the third party to close the assessment.
**Related concepts**   

* [Assessing your third-party risk](https://www.servicenow.com/docs/hicLzov08j~TUllla6~8Ew "Use Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships. The information gathered from internal questionnaires, external questionnaires, and documentation requests helps you to understand the third party's risk profile, determine the appropriate risk mitigation strategies, and determine whether the third party or engagement meets all necessary compliance requirements.")  
**Related tasks**   

* [Review responses to external questionnaires](https://www.servicenow.com/docs/G6RPuhxZElbq1_Tfs7j4VA "Third-party contacts use the Third-party portal to complete assessments and collaborate with the TPR manager in the comments section for each question. When assessments reveal gaps, the TPR manager or the TPR assessor can generate an issue or task. In addition, the Vendor Management Workspace application can auto-generate issues.")

*[\>]: and then


