Roles in Third-party Risk Management
Summarize
Summary of Roles in Third-party Risk Management
In Third-party Risk Management (TPRM) on ServiceNow, roles define user permissions and access levels for managing third-party contacts, assessments, risk tasks, and related activities. Proper role assignment ensures users can perform their responsibilities securely and efficiently within the TPRM application.
Show less
Key Roles and Their Permissions
- Third-party reader [vendorreader]: Read-only access to third-party contact records.
- Third-party editor [vendoreditor]: Create, update, and delete third-party contact records.
- Third-party assessment reviewer [snvdrriskasmt.vendorassessmentreviewer]: View assessment and questionnaire data plus add comments on assessments, risk issues, tasks, and due diligence requests. This is the minimum role required to view external and internal TPRM questionnaires and requests.
- TPR assessor [snvdrriskasmt.vendorassessor]: Includes reviewer permissions plus manage third parties, contacts, external risk assessments, and issues. Assessor permissions for modifying questionnaire responses are configurable.
- TPR approver [snvdrriskasmt.approver]: Reviewer permissions plus authority to approve Internal Risk Questionnaires (IRQs).
- TPR manager [snvdrriskasmt.vendorriskmanager]: Assessor permissions plus manage assessment templates, scheduled assessments, engagements, contacts, and scoring rules.
- TPR admin [snvdrriskasmt.vendorriskadmin]: Manager permissions plus create and edit all assessment templates, tiering questionnaires, document requests, and automation rules. Covers both classic and Smart Assessment Engine (SAE) templates.
- Contract risk negotiator [snvdrriskasmt.contractnegotiator]: Assessor permissions plus legal department access to modify contract status and dates, assigned via user groups.
- Third-party contact [vendorcontact]: External users assigned to respond to third-party or engagement questionnaires, tasks, and issues through the Third-party portal. Restricted to external portal access only.
Roles for Digital Resilience and Smart Assessment Engine
- Digital resilience roles (DORA user, manager, admin) grant access to third-party registers within Vendor Management Workspace, aligned with TPRM roles such as assessment reviewer, approver, assessor, manager, and admin.
- Smart Assessment Engine (SAE) roles: Enable users to view templates, respond to questionnaires, and administer SAE templates and automation rules. These roles integrate with TPRM roles ensuring appropriate access for internal and external assessment tasks.
Practical Guidance for ServiceNow Customers
- Assign roles based on user responsibilities to control access to sensitive third-party risk data and workflows.
- Use the third-party contact role exclusively for external users to restrict access to the Third-party portal only.
- Configure assessor permissions carefully via system properties to govern questionnaire response capabilities.
- Leverage role group assignments, such as for contract risk negotiators, to streamline user management.
- Ensure users with assessment-related responsibilities have at least the Third-party assessment reviewer role to access necessary templates and data.
Understanding and applying these roles helps ServiceNow customers securely manage third-party risks, streamline risk assessments, and maintain compliance through appropriate access control and delegation within the TPRM application.
Roles determine permissions and access in TPRM.
TPRM roles
| Friendly name [role name] | Description | Contains roles |
|---|---|---|
| Third-party reader [vendor_reader] |
Read access to third-party contact records. | None |
| Third-party editor [vendor_editor] |
Create/update/delete third-party contact records. | None |
| Third-party assessment reviewer [sn_vdr_risk_asmt.vendor_assessment_reviewer] |
View assessment and questionnaire data. In addition to viewing, they can leave comments on the following tables:
|
Contains:
|
TPR assessor (Third-party risk assessor) [sn_vdr_risk_asmt.vendor_assessor] |
|
Contains:
|
TPR approver [sn_vdr_risk_asmt.approver] |
Includes all permissions of the Third-party assessment reviewer role plus: approve IRQs. |
Contains:
|
| TPR manager (Third-party risk manager) [sn_vdr_risk_asmt.vendor_risk_manager] |
Includes all permissions of the TPR assessor role plus:
|
Contains:
|
| TPR admin (Third-party risk admin) [sn_vdr_risk_asmt.vendor_risk_admin] |
Includes all permissions of the TPR manager role plus: Create and edit the following items:
Note: All the templates include both classic and SAE templates. |
Contains:
|
| Contract risk negotiator [sn_vdr_risk_asmt.contract_negotiator] |
Includes all permissions of the TPR assessor role plus: Gives users in the legal department access to modify contract status and the start and expiration dates. You can add users with this role to the Contract risk negotiators user group. See Add users to groups based on responsibilities. |
Contains:
|
[vendor_contact]
|
You assign the third-party contact role to users at the third-party organization whose risk is being assessed. Third-party contacts are assigned the snc_external role to give them access to resources and actions in the Third-party portal. Important:
The third-party contact role should be used only for external contacts. The role prohibits access to your ServiceNow AI Platform instance and grants access only to the Third-party portal. You assign the primary contact responsibility to the third-party contact who can directly answer assessment questions or assign another contact at the third party to answer the questions. Primary contacts can manage other contacts for the third party. |
Contains: snc_external |
Roles required for accessing the Digital resilience third-party registers
- TPRM DORA user [sn_dora_accel.user] role
Third-party assessment reviewer and TPR approver contain this role.
- TPRM DORA manager [sn_dora_accel.manager] role
TPR assessor and TPR manager contain this role.
- TPRM DORA admin [sn_dora_accel.admin]
The TPR admin contains this role.
Roles required for using Smart Assessment Engine
- TPRM
SAE template reader [sn_smart_asmt.template_reader] role
Third-party assessment reviewer contains this role.
- TPRM
SAE assessment reader [sn_smart_asmt.assessment_reader] role
Third-party assessment reviewer contains this role.
- TPRM
SAE internal assessment user [sn_vdr_risk_asmt.internal_assessment_responder]
This is role is automatically assigned to an assigned IRQ assessor or internal assessment respondent.
This role is required to respond to internal/IRQ assessment questionnaires using the GRC Portal.
This role contains the following roles: sn_grc_business_user, canvas_user, and sn_smart_asmt.actor.
- TPRMSAE external assessment user [sn_vdr_risk_asmt.external_assessment_responder]
This is role is automatically assigned to the assigned third-party contact.
This role is required to respond to external questionnaires using the Third-party portal.
This contains the role: sn_smart_asmt.actor.
A user with the TPRM SAE admin [sn_smart_asmt.assessment_admin] role can create SAE templates in the Configure domain separation for Vendor Management Workspace and Assessment Workspace.
Third-party admin contains this role.
A user with the sn_smart_imp_auto.automation_creator role can create post assessment impact automation rules.
Third-party admin contains this role.
For more information on SAE related roles, see Roles in Smart Assessment Engine.