---
sourceDocument: Xanadu Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/governance-risk-compliance

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Scores from risk intelligence providers

# Integrating scores from risk intelligence providers {#ariaid-title1}

* Release version: Xanadu
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Risk intelligence providers generate risk scores for a variety of third-party risk domains. Your organization can purchase services from providers that return data that is analogous to personal credit scores. The scores provide insight on how trustworthy and safe a particular third party can be.

## Working with data from risk intelligence providers {#tprm-riskintelprvdr-overview__section_tq1_nzc_yxb}

Note:  
You can request risk data for third parties but not for engagements.

* After you register a risk intelligence provider, you specify which of the provider's scoring or rating services you'll use. You also specify how their scores or ratings map to your TPRM ratings. For more information, see [Register a risk intelligence provider](https://www.servicenow.com/docs/xl7pH9MqqxQSXpVoeBIBwA "Create a record for each risk intelligence provider from which you’ll request reports. The risk scores and ratings that risk intelligence providers generate are analogous to personal credit scores. The scores provide insight on how trustworthy and safe a particular third party can be."), [Set up a risk intelligence provider service](https://www.servicenow.com/docs/1bvJP2ePkV1C07kOT4mQJg "After you register a risk intelligence provider, you specify which of the provider's scoring or rating services you’ll use. You also specify how their scores or ratings map to your TPRM ratings."), and [Set up a request type for a provider](https://www.servicenow.com/docs/XC1BjS380LcYwjs9TV0YSA "After you register a risk intelligence provider and service, you specify the available request types that you and your organization will use.").
* You add a raw score from a provider to the provider service record for a third party. The system uses the mapping that you specified to normalize the value to the appropriate TPRM rating. For more information, see [Add a risk intelligence score to risk data for a third party](https://www.servicenow.com/docs/WAEoTp0wa6j~PzOnHUz2tg "You add a raw score from a provider to the provider service record for a third party. The system uses the mapping that you specified to normalize the value to the appropriate TPRM rating.").
* A provider-based submission rule is a set of conditions and actions. In a rule, you can specify that an update to a rating from a risk intelligence provider is the condition that triggers the action that is specified in the rule. The action might be to create and send a third-party risk assessment, issue, task, or email. For more information, see [Automate actions upon risk intelligence updates](https://www.servicenow.com/docs/adGr6BIZEyjjyAAlHIJ~iQ "A provider-based submission rule is a set of conditions and actions. In a rule, you can specify that an update to a rating from a risk intelligence provider is the condition that triggers the action that is specified in the rule. The action might be to create and send a third-party risk assessment, issue, task, or email.").
{#tprm-riskintelprvdr-overview__ul_i5w_k1d_yxb}

## Integration types {#tprm-riskintelprvdr-overview__section_mmd_kkf_3bc}

Here are some examples of the types of integrations supported by ServiceNow and ServiceNow partners:

* Independent software vendor (ISV) integration types involve integrating ISV services such as EcoVadis or Black Kite.

* Content integration types involve integrating external content sources such as regulatory databases or industry standards.

* Data integration types involve integrating external data sources to gather and analyze relevant data such as data from financial systems, security tools, or vendor management systems.

* Environmental, social, and governance (ESG) integration types involve incorporating ESG factors into the TPRM process.

{#tprm-riskintelprvdr-overview__ul_yfd_w3f_3bc}

## Integrations supported by ServiceNow {#tprm-riskintelprvdr-overview__section_z52_dnx_hyb}

Note:  
You can find the integration apps on the ServiceNow Store.
{#tprm-riskintelprvdr-overview__table_wlb_wrx_hyb__entry__5}

| Provider | Product name | Content | Service provided | Type |
|-|-|-|-|-|
| Shared Assessments | Standard information-gathering (SIG) questionnaire | Standard assessment | Industry standard questionnaire for use in assessments. | Content |
| EcoVadis | EcoVadis | Sustainability ratings | Sustainability scores in support of assessments and continuous monitoring. | ISV, data, ESG |
[Table 1. Integrations supported by ServiceNow]

{#tprm-riskintelprvdr-overview__table_wlb_wrx_hyb}

## Integrations supported by ServiceNow partners {#tprm-riskintelprvdr-overview__id_k51_fnx_hyb}

Note:  
You can find the integration apps on the ServiceNow Store.
{#tprm-riskintelprvdr-overview__table_pvx_wsx_hyb__entry__5}

| Provider | Product name | Content | Use case | Type |
|-|-|-|-|-|
| BitSight | BitSight | Cyber risk ratings | Cyber risk scores in support of assessments and continuous third-party risk monitoring. | ISV, data |
| Security Scorecard | Security Scorecard | Cyber risk ratings | Cyber risk scores in support of assessments and continuous third-party risk monitoring. | ISV, data |
| RiskRecon | Risk Recon | Cyber risk ratings | Cyber risk scores in support of assessments and continuous third-party risk monitoring. | ISV, data |
| Upguard | Upguard Vendor Risk | Cyber risk | Cyber risk scores in support of assessments and continuous third-party risk monitoring. | ISV, data |
| Recorded Future | Recorded Future Intelligence | Cyber risk ratings | Cyber risk scores in support of assessments and continuous third-party risk monitoring. | ISV, data |
| Black Kite | Black Kite | Third-party risk management | Technical security, financial risk, ransomware susceptibility index, and compliance scores in addition to overall security ratings. | ISV |
| Interos | Interos | Supply chain and multiple domain ratings | Cyber, financial, ESG, geopolitical, operations, and restrictions ratings to support risk assessments and monitoring. | ISV, content |
| TruSight | TruSight | Third-party risk assessments | Access to TruSight-validated third-party risk assessments. | ISV |
| ISS Corporate Solutions | ISS ESG Cyber Risk Score for Vendor Risk Management | ESG ratings | Access to a comprehensive view of ISS Corporate Solutions' cyber risk management program through cyber risk and supply chain. | ISV |
| Securitybricks | CMMC - NIST-800-171 - Vendor Compliance Assessment | Template | Access to an automated assessment for Federal organizations. | data, content |
| Templarshield | HECVAT-Questionnaire for Higher Education | Content | Access to an automated questionnaire for Higher education organizations. | ISV, content |
[Table 2. Integrations supported by partners]

{#tprm-riskintelprvdr-overview__table_pvx_wsx_hyb}
* **[Register a risk intelligence provider](https://www.servicenow.com/docs/xl7pH9MqqxQSXpVoeBIBwA)**   
  Create a record for each risk intelligence provider from which you'll request reports. The risk scores and ratings that risk intelligence providers generate are analogous to personal credit scores. The scores provide insight on how trustworthy and safe a particular third party can be.
* **[Set up a risk intelligence provider service](https://www.servicenow.com/docs/1bvJP2ePkV1C07kOT4mQJg)**   
  After you register a risk intelligence provider, you specify which of the provider's scoring or rating services you'll use. You also specify how their scores or ratings map to your TPRM ratings.
* **[Set up a request type for a provider](https://www.servicenow.com/docs/XC1BjS380LcYwjs9TV0YSA)**   
  After you register a risk intelligence provider and service, you specify the available request types that you and your organization will use.
* **[Add a risk intelligence score to risk data for a third party](https://www.servicenow.com/docs/WAEoTp0wa6j~PzOnHUz2tg)**   
  You add a raw score from a provider to the provider service record for a third party. The system uses the mapping that you specified to normalize the value to the appropriate TPRM rating.
* **[Automate actions upon risk intelligence updates](https://www.servicenow.com/docs/adGr6BIZEyjjyAAlHIJ~iQ)**   
  A provider-based submission rule is a set of conditions and actions. In a rule, you can specify that an update to a rating from a risk intelligence provider is the condition that triggers the action that is specified in the rule. The action might be to create and send a third-party risk assessment, issue, task, or email.

**Related tasks**   

* [Register a risk intelligence provider](https://www.servicenow.com/docs/xl7pH9MqqxQSXpVoeBIBwA "Create a record for each risk intelligence provider from which you’ll request reports. The risk scores and ratings that risk intelligence providers generate are analogous to personal credit scores. The scores provide insight on how trustworthy and safe a particular third party can be.")
* [Set up a risk intelligence provider service](https://www.servicenow.com/docs/1bvJP2ePkV1C07kOT4mQJg "After you register a risk intelligence provider, you specify which of the provider's scoring or rating services you’ll use. You also specify how their scores or ratings map to your TPRM ratings.")
* [Set up a request type for a provider](https://www.servicenow.com/docs/XC1BjS380LcYwjs9TV0YSA "After you register a risk intelligence provider and service, you specify the available request types that you and your organization will use.")  
**Related reference**   

* [Viewing risk intelligence scores](https://www.servicenow.com/docs/uZMoneNvccDuVOx77avn1A "For DD requests, risk intelligence scores appear in a list. For an individual third party, a card displays the most recent score or rating and a link for each risk intelligence report.")

