---
sourceDocument: Xanadu Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/governance-risk-compliance

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Add users to groups

# Add users to groups based on responsibilities {#ariaid-title1}

* Release version: Xanadu
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Assign users to groups before you implement or use the Third-party Risk Management application. Each group contains users with particular roles. Well-organized user groups simplify and improve process management and help to ensure that users are promptly notified of tasks in their areas of responsibility.

## Before you begin

Role required: admin

## About this task

Several user groups are created when you activate the TPRM app. In this procedure, you add users to each group. The roles mentioned in this procedure are described in [Roles in Third-party Risk Management](https://www.servicenow.com/docs/88vNtKuR3objU55pWKZgPw "Roles determine permissions and access in TPRM.").

There's an important practical result of including all users with a particular role in a group: Your risk management process isn't affected when one or more members of the group are unavailable due to vacation, for example.  
Important:  
Consider this to be an ongoing process, where the user who is assigned as the group manager is responsible for continuously updating group membership.

Due diligence request assigners

:   Group members have the Third-party risk (TPR) assessor \[sn_vdr_risk_asmt.vendor_assessor\] role.

    Each member receives email notification of new requests for due diligence. For requests in the New or Unassigned state, no one has been specified in the Assigned to field. Any group member can assign or be assigned to a request.

    The individual who owns an assessment for audit purposes and monitors and manages overall assessment processes. The owner is responsible for confirming that the assessment is completed in a timely fashion by the third party, reviewing their responses, and creating and resolving issues. To drive the assessment to its completion, they are notified when an assessment reaches a particular milestone. They must have the TPR manager or TPR assessor role.

Third-party Risk Managers

:   Group members have both the TPR approver role \[sn_vdr_risk_asmt.approver\] and the TPR manager role \[sn_vdr_risk_asmt.vendor_risk_manager\].

    Members can monitor and manage overall due diligence processes and approve new requests for due diligence.

Third-party Risk Reviewers (External assessment reviewers)

:   Group members have the Third-party assessment reviewer role \[sn_vdr_risk_asmt.vendor_assessment_reviewer\].

    Members can monitor and manage interactions with third-party contacts during external due diligence processes.

Contract risk negotiators

:   Group members have the Contract risk negotiator \[sn_vdr_risk_asmt.contract_negotiator\] role.

    Members work in the contract risk process.

## Procedure

1. Navigate to AllThird-party Risk ManagementAdministrationUser Groups.  
   The list of user groups appears.  

   <br />

2. Select the name of the group to update.
3. **Optional:** Specify a manager for the group.  
   The group manager is responsible for continuously updating group membership. The group manager typically has the same role (or higher) as the members.
4. **Optional:** Specify an email alias for the group.  
   * If you don't specify an alias, then a separate email notification is sent to each member.
   * If you specify an alias, then a single email notification is sent with all members in the To: list.
   {#tprm-groups-add-users-to__ul_mvx_jg4_xyb}
5. On the Group Members related list, select Edit.
6. Move all appropriate users from the Collection list to the Group Members list and then select Save.
7. **Optional:** Use the Groups related list to add subgroups to the group that you're defining.  
   This option enables you to organize users into practical subsets.
8. Repeat the process for each group.
{#tprm-groups-add-users-to__steps_zxp_tlh_ymb}
**Related concepts**   

* [TPRM and the Explicit Roles plugin](https://www.servicenow.com/docs/FQq8H1FLJrFoU_GTHmZ2cA "Activating the Third-party Risk Management plugin also installs the Explicit Roles plugin. Administrators assign the snc_internal and snc_external roles to provide internal and external users access to the instance.")  
**Related reference**   

* [Roles in Third-party Risk Management](https://www.servicenow.com/docs/88vNtKuR3objU55pWKZgPw "Roles determine permissions and access in TPRM.")

*[\>]: and then


