Integrating Third-party Risk Management with GRC: Policy and Compliance Management

  • Release version: Zurich
  • Updated March 12, 2026
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Integrating Third-party Risk Management with GRC: Policy and Compliance Management

    The integration between Third-party Risk Management (TPRM) and GRC: Policy and Compliance Management enhances the monitoring and assessment of third-party compliance. This integration enables compliance managers to associate controls and control objectives with specific questionnaire questions, third parties, and engagements. As third parties respond to questionnaires, their answers automatically update the compliance status of linked controls, providing real-time and accurate compliance assessments.

    Show full answer Show less

    Key Features

    • Control and Control Objective Association: Compliance managers can link controls and control objectives to individual questionnaire questions, third parties, and engagements, enabling granular compliance assessment.
    • Dynamic Compliance Status Updates: Based on third-party questionnaire responses, controls are automatically marked compliant or non-compliant, reflecting real-time compliance status.
    • Entity Categorization: All third parties are categorized as "Vendors," ensuring consistent representation as entities within the system, with controls created for each associated entity.
    • Role-Specific Access: Users with the Compliance Manager role in Policy and Compliance Management and Third-party risk assessors in TPRM can monitor control status effectively.
    • Manual Associations: Users can manually add controls to third parties or engagements and link control objectives to questionnaire questions for precise compliance management.
    • Read-Only Consumption in TPRM: Compliance objects are authored and managed within Policy and Compliance Management and consumed in a read-only mode within Third-party Risk Management.

    Practical Benefits for ServiceNow Customers

    • Enables precise and detailed compliance tracking at the level of questionnaire questions, improving risk assessments of third parties and engagements.
    • Automates compliance status updates, reducing manual effort and increasing accuracy in third-party risk evaluations.
    • Supports collaborative monitoring between compliance managers and third-party risk assessors, enhancing transparency and control.
    • Facilitates compliance management by linking policies, controls, and third-party responses, ensuring that risk management decisions are based on up-to-date compliance data.

    Next Steps

    To fully leverage this integration, ServiceNow customers should:

    • Ensure the Policy and Compliance Management application is installed and users have the Compliance Manager role.
    • Manually associate controls and control objectives with third parties, engagements, and questionnaire questions as needed.
    • Review third-party questionnaire responses regularly to monitor compliance status updates.
    • Refer to related tasks such as manually adding controls to third parties or linking control objectives to questions to configure the integration effectively.

    The GRC: Policy and Compliance Management integration updates the compliance status of controls and control objectives based on the questionnaire responses from a third party or engagement. Compliance managers [sn_compliance.manager] can associate controls and control objectives with specific questions, third parties, and engagements used in Third-party Risk Management.

    If you have the Policy and Compliance Management application installed, users with the Compliance Manager role can perform several key tasks that help manage and assess Third-party compliance.

    • You can associate third parties and engagements to specific control objectives. This association results in controls being applied to the third party or engagement

      For more information, see Manually add a control to a third party or engagement.

    • You can individually link the question to multiple control objectives for each question in a questionnaire template. This enables for a granular and detailed assessment of compliance.

      For more information, see Manually add a control objective to a question.

    • When third parties and engagements respond to questionnaires, the system automatically updates the compliance status of the linked controls. If they provide an incorrect answer, the associated controls are marked as non-compliant. Conversely, correct answers keep the controls compliant.
    Note:
    Although it is not possible to directly map control objectives to questions in SAE questionnaires, SAE provides the capability to flag controls as compliant or non-compliant through post-assessment actions.

    All third parties are automatically categorized into an entity type called Vendors. This helps ensure that each third party and engagement is represented as an entity.

    When an entity, such as a third party or engagement, is associated with a control objective a corresponding control is created for that entity. This association links the third party or engagement with the control, which can influence the compliance status of the control.

    In the context of Third-party Risk Management, each question in a questionnaire template can be individually linked to multiple control objectives through a related list. When a questionnaire is sent to a third party and the third party responds with an incorrect answer, the controls associated with the linked control objectives are marked as non-compliant. Conversely, if the third party provides the correct answer, the controls remain compliant.

    This feature helps ensure that the compliance status of controls is dynamically updated based on the third party or engagements responses, providing a real-time and accurate assessment of their compliance. Both Policy and Compliance Management users and Third-party risk assessors [sn_vdr_risk_asmt.vendor_assessor] can monitor the status of a control.

    Note:

    Third-party Risk Management consumes compliance objects in a read-only capacity. Controls and control objectives are authored and managed in GRC: Policy and Compliance Management.

    For more information on implementing Policy and Compliance Management, see Implementing Policy and Compliance Management.