---
sourceDocument: Xanadu Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/governance-risk-compliance

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Monitoring third-party elements

# Monitoring third-party elements {#ariaid-title1}

* Release version: Xanadu
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

You can monitor third-party elements through scalable scoring models, relationship analysis, and due diligence workflow integration by using the Third-party Risk Management application. Monitoring third-party elements and leveraging that information can help with conducting more informed risk assessments as part of your third-party risk program.

## Third-party elements overview {#tprm-monitor-tp-elements__section_ad5_bpf_bbc}

Third-party elements (TP elements) are the external organizations that an engagement relies on to provide goods, services, or support. These
organizations can include the suppliers, contractors, facilities, individuals, or any other external organization that can access the engagement's systems, data, or facilities.
Let's look at some TP element class and risk examples:

Datacenter
:   A facility or location where an engagement or third party outsources the storage, processing, and management of their data and IT infrastructure. A datacenter could potentially experience a data breach, downtime, or
    compliance violation that exposes their engagements to unexpected risk. This example would be classified as a Facility TP element.

Manufacturing facility
:   A facility or location where an engagement or third party outsources the production or assembly of their products. A manufacturing facility could potentially experience a supply chain disruption, a counterfeit part,
    or regulatory compliance issue that exposes their engagements to unexpected risk. This example would be classified as a Facility TP element.

Beneficial owner
:   An individual who owns or controls an organization that is involved in a business relationship or transaction. These individuals may not be the registered or legal owners of the organization but have significant
    influence or control over its operations, decision-making, or financial affairs. This example would be classified as a Principal TP element.

The following infographic shows the TP element collection process.  

<br />

For more information on Third-party (TP) elements and examples of their associated controls and potential risks, see [Terminology](https://www.servicenow.com/docs/OammyPHucoPBR0xC4~6Hng "Learn more about the key concepts and terms that are used in the TPRM application.").

## Collecting and reviewing third-party elements {#tprm-monitor-tp-elements__section_cpb_drf_bbc}

Collecting and reviewing third-party elements is optional. If you have the Third-party risk (TPR) assessor \[sn_vdr_risk_asmt.vendor_assessor\] role and are the due diligence request owner or TPR manager
\[sn_vdr_risk_asmt.vendor_risk_manager\] role, you can start this process after your due diligence request has completed the Inherent Risk Questionnaire (IRQ) process.  
You would follow this process to collect and review TP elements:

1. In the Vendor Management Workspace, if TP elements are needed, the Third-party risk (TPR) manager or due diligence request owner selects Start collection and a collection task is created.
2. The TPR manager or owner opens the external assessment for collecting elements and adds the relevant TP element collection questionnaires.
3. The TPR manager or owner reviews and approves the questionnaires and they're sent to the engagement. For more information on assessments, see [Assessing your third-party risk](https://www.servicenow.com/docs/hicLzov08j~TUllla6~8Ew "Use Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships. The information gathered from internal questionnaires, external questionnaires, and documentation requests helps you to understand the third party's risk profile, determine the appropriate risk mitigation strategies, and determine whether the third party or engagement meets all necessary compliance requirements.").
4. In Vendor Management Workspace, the TPR manager or owner opens the questionnaires and verifies that all the required information was provided.
5. The TPR manager or owner then navigates to the list of TP elements and manually creates a TP element record for each set of responses in each questionnaire.
6. After all TP elements are created, the TPR manager or owner closes the collection task assessment. The system changes the state of the request from Collection in progress to Collection in review.
7. The internal stakeholders (TPR assessor, TPR approver, TPR manager, or TPR administrator) review and approve the element records.

{#tprm-monitor-tp-elements__ol_d2m_5kv_bcc}For more information, see [Create a third-party element record](https://www.servicenow.com/docs/Q17IkNjI8f378xWb4Z8EYQ "Create a third-party element record after you collect the responses from a third party by using a collection template questionnaire in the Third-party Risk Management application. After a third-party element record is created, an element entity is available to be assigned to an engagement.").

## Adding third-party elements to engagements {#tprm-monitor-tp-elements__section_gyl_5pp_4bc}

After the TP elements are reviewed and approved by the TPR manager and internal stakeholders in Vendor Management Workspace, the TPR manager or owner opens the engagement and manually adds the reviewed and approved TP elements as entities on the Entities tab of the engagement. For
more information, see [Add a third-party element record to an engagement](https://www.servicenow.com/docs/iUz3JpXrxvMq72dccyESsg "Assign a third-party element record to an engagement by using the Third-party Risk Management application. After you assign the element entity to an engagement, the third-party risk manager and internal stakeholders can assess it as part of the due diligence process."). After you add all TP element entities to an engagement, you can start the due diligence process. During the due diligence process, you must select and assign a questionnaire as part
of an external assessment for each TP element that you created. The third-party contact completes the TP element questionnaires. For more information, see [Assessing your third-party risk](https://www.servicenow.com/docs/hicLzov08j~TUllla6~8Ew "Use Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships. The information gathered from internal questionnaires, external questionnaires, and documentation requests helps you to understand the third party's risk profile, determine the appropriate risk mitigation strategies, and determine whether the third party or engagement meets all necessary compliance requirements.").

## Third-party element scoring {#tprm-monitor-tp-elements__section_tyt_ymp_4bc}

You can categorize each TP element into one of the following types: Facility, Product, Principal, or Other. This classification helps you with organizing the assessment criteria and subsequent scoring. Scoring on a TP element
is determined by averaging the risk ratings from its associated third-party risk assessments. If you conduct multiple assessments for the same TP element, the system considers only the latest assessment for each engagement
for scoring, disregarding duplicates. This process helps to ensure that the TP element's risk rating reflects the most current evaluation. For example, if a TP element has assessments with risk ratings of very high and very
low, the average of these ratings leads to the overall risk being moderate.

After an element is assessed and a risk rating is determined, this rating is first aggregated into a component score that is based on its classification, such as Facility. For example, all Facility-type elements are
aggregated into a single component score, which contributes to the overall score of the engagement. The engagement score is then compiled by aggregating the scores from all relevant component scores within that engagement.
If multiple assessments or TP elements are within an engagement, each is scored individually and then combined to form the overall engagement score. The engagement score is then rolled up to the third-party level by
aggregating the scores from all the engagements that are associated with a particular third party. The aggregation at this level could be based on different rules, such as averaging, taking the minimum, or maximum scores,
depending on the scoring rules set within the system. This rolled-up score represents the overall risk or performance score of the third party and reflects all the engagements and elements that are associated with
it.  
Note:  
You can create your own TP element classifications to meet your specific risk program requirements. For more information on creating classifications and assigning weights for scoring, see [Third-party element form](https://www.servicenow.com/docs/pxMVEUHqbSuVHzzZhMffVA "Use the third-party element form to capture all the information that you need to create a third-party element record using the Third-party Risk Management application. As a third-party risk manager, third-party risk assessor, or due diligence request owner, you can create a third-party element record.") and [Define component criteria](https://www.servicenow.com/docs/CW9MoXT6gc2itJlPq2W8VA "Components are the entities for which you can assess risk (for example, subsidiaries or engagements). A component criteria is a group of components that should apply to a particular type of third party or engagement.").

