---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Create New Third-party engagement form

# Create New Third-party engagement form {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Use the create new third-party engagement form to capture all the information that you need to create a third-party engagement record in Digital resilience third-party registers using Third-party Risk Management. As a third-party risk assessor you can create a third-party engagement record.
{#tprm-create-engmt-form__table_jfh_cl4_ycc__entry__2}

| Field | Description |
|-|-|
| Name | Unique name for the engagement. Ideally, mention the product or service that is the subject of the engagement. |
| Third party | The third party for whom you are creating this engagement record. |
| Type | Type of product or service to be provided by the engagement organization. |
| Start date | Enter start and end dates to define how long the engagement is valid. |
| End date | Preferred dates for the beginning and end of interactions with the third party. |
| Status | Select the current status of the engagement. Available options are: * Active * Onboarding * Prospect * Active unauthorized * Terminated * Onboarding rejected {#tprm-create-engmt-form__ul_mk5_1ks_dyb} |
| Risk rating | Displays the risk rating assigned to the engagement after an assessment has been performed. |
| Engagement tier | The tier used for this engagement. See [VRM third-party risk tiering assessments](https://www.servicenow.com/docs/sDKK7UwER8TcWCIOuRD7JQ "Organizations use risk tiering to classify their third parties into categories of potential risk posed at the time of onboarding. The standard predefined risk tiers are None, Low, Minor, Moderate, High, and Critical. Each risk tier has associated assessment questions and document requests.") for details of how the tier is determined. |
| Annual spend | The annual monetary spend associated with this engagement's services. |
| Engagement manager | Specify the person who will monitor, prioritize, and act on responses to external questionnaires, issues, and tasks. Select the lock to lock/unlock the field. |
| Business owner | Specify the person who is familiar with the engagement organization and the product or services that will be engaged. Select the lock to lock/unlock the field. |
| Notes | Enter text that describes the engagement to other users. |
| Third-party engagement: Contact ||
| Street, City, State/Province, ZIP/Postal code, Country, Phone, Fax | Standard contact information for the engagement organization. |
| Latitude and Longitude | The Latitude and Longitude values are used to mark the location on the Risk concentration map. See [TPRM Risk concentration map](https://www.servicenow.com/docs/tUXHHCGeXb1ATWlfnc3ykQ "The Risk concentration map page pinpoints the geographical locations of active third parties and engagements. You can configure filters to view particular risk ratings and engagement types."). |
| Risk ratings ||
| Computed risk rating | Calculated Computed risk rating. This field is auto-filled. The value is overall risk rating for the third party, calculated after the assessment by rolling up all of the TPR assessors' risk ratings. |
| Override risk rating | Option to override the computed rating. If you select the check box, then specify the following values: * Overridden risk rating: Select the new risk rating. * Overridden on: Date that overridden risk rating or justification is updated. * Justification: Enter the reason for overriding the value. {#tprm-create-engmt-form__ul_mtv_njx_2yb} |
| Overridden risk rating | Rating that has been manually changed by a user, overriding the rating that was calculated by a system. Available options are: * 1 - Very High * 2 - High * 3 - Moderate * 4 - Low * 5 - Very Low {#tprm-create-engmt-form__ul_ppx_vtv_ddc} |
| Overridden on | Date that overridden risk rating or justification is updated. |
| Justification | Reason for overriding the value. |
| Assessment risk rating | Risk rating for the assessment. This field is auto-filled. |
| Engagement risk rating | Risk rating for the engagement. This field is auto-filled. |
| Subsidiary risk rating | Risk rating for the subsidiary. This field is auto-filled. |
| Risk intelligence rating | Score that corresponds to the likelihood and consequence of a risk event. This field is auto-filled. |
| Related lists on the form ||
| Engagement contacts | Engagement contacts for the third-party engagement. |
| Business services | Business services related to the third-party engagement. |
| Tiering assessments | Tiering assessments for the third-party engagement. |
| Repeating assessments | Repeating assessments for the third-party engagement. Note: You can create repeating assessments if you are using the classic assessment engine. You can configure rules that auto-generate and send questionnaires and doc requests to engagements and third parties using the Event-driven management feature if you are using the Smart Assessment Engine. For more information, see [Configure a risk assessment to recur on a schedule](https://www.servicenow.com/docs/g0~kCYsU~BlkOX~mx5~YJw "Configure a third-party risk assessment to recur on a schedule to regularly update risk results for a third party or an engagement.") and [Event-driven management --- automate assessment processes](https://www.servicenow.com/docs/kFEWcoF0hXLFDvRqULRQkw "Use the Event-driven management feature to configure rules that auto-generate and send questionnaires and doc requests to engagements and third parties. For engagements and third parties that meet the criteria you define, you specify the schedule and the assessment templates. You can automate all assessment types except onboarding."). |
| Assessments | Assessments for the third-party engagement. |
| Third-party risk areas | Risk areas related to the third-party engagement. |
| Issues | Issues related to the third-party engagement. |
| Tasks | Tasks related to the third-party engagement. |
| Entity types | Entity types related to the third-party engagement. |
| Digital resilience information | Digital resilience information for the third-party engagement. You can add the following parameters: * Name * Third party * Identification code of ICT third-party service provider * Type of code to identify the ICT third-party service provider * Name of the ICT third-party service provider {#tprm-create-engmt-form__ul_rqt_hzv_ddc} |
[Table 1. Create New Third-party engagement form]

{#tprm-create-engmt-form__table_jfh_cl4_ycc}

