Assessing your third-party risk
Summarize
Summary of Assessing your third-party risk
The Third-party Risk Management (TPRM) process helps organizations identify, assess, and mitigate risks related to third-party relationships. It leverages internal and external questionnaires and document requests to gather information, assess risk profiles, verify compliance, and ensure third parties meet necessary regulatory and security requirements.
Show less
Key Processes
- Inherent Risk Questionnaire (IRQ) Process: After approval of a due diligence request, the TPR manager or assessor assigns an IRQ linked to an internal assessment. The assigned internal assessor completes the IRQ, which is reviewed and closed by the manager, updating the request status accordingly. Questionnaire templates should not be modified after distribution; updates require duplicating and replacing the questionnaire.
- Third-party Element Collection Process: Post-IRQ, if additional third-party elements are needed, the manager initiates collection tasks and assigns external assessments to third-party contacts to gather specific element information. Responses are reviewed, and records are created manually before closing the collection task.
- Due Diligence and Compliance Verification: Following IRQ and element collection, questionnaires and document requests are sent externally for compliance verification. Responses are reviewed for completeness, and remediation tasks or issues can be generated if necessary. Templates can be reused across similar third parties to streamline the process.
- Pre-populating Questionnaires: To expedite assessments, questionnaires can be pre-filled with responses from the most recent completed versions for the same third party, reducing repetitive data entry. Some question types, such as attachments and signatures, cannot be pre-populated.
- Issues and Tasks Management: The TPR assessor role manages tasks and issues related to questionnaires, ensuring timely responses and remediation of concerns with third-party engagements.
- Additional Assessment Actions: Assessments can be reopened to gather new information or additional questionnaires. They can also be canceled if assessments are no longer required, though the due diligence request will still proceed to approval.
Practical Benefits for ServiceNow Customers
- Enables structured and automated collection of risk-related information from internal and external stakeholders.
- Facilitates comprehensive risk assessment including financial, operational, compliance, and security aspects of third parties.
- Supports compliance with regulatory requirements through document requests and questionnaires.
- Improves efficiency with reusable assessment templates and pre-populated questionnaire responses.
- Provides mechanisms to manage remediation through tasks and issues.
- Offers flexibility to update or cancel assessments as business needs evolve, maintaining control over third-party risk workflows.
Use Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships. The information gathered from internal questionnaires, external questionnaires, and documentation requests helps you to understand the third party's risk profile, determine the appropriate risk mitigation strategies, and determine whether the third party or engagement meets all necessary compliance requirements.
Responding to questionnaires
The following processes outline the timing and methods for responding to internal and external questionnaires:
- Inherent Risk Questionnaire (IRQ) process
-
The following infographic shows the IRQ process.
- Third-party (TP) element collection process: Collect TP element information
-
The following infographic shows the TP element collection process.
- Due diligence process: Compliance verification
-
The following infographic shows the due diligence process.
Pre-populate questionnaires with responses
When a third-party or engagement contact opens a pre-populated questionnaire in the Third-party portal, they receive a notification that the responses were copied from an earlier questionnaire. The notification includes a link to the assessment that supplied the responses and its last updated date as shown in the following example.
- Some question types and their responses can’t be pre-populated such as the attachment, duration, and signature question types. These question responses remain blank and previous responses aren’t included.
- Responses are copied from the original assessment (Assessment A) to the newer assessment (Assessment B) one time. This copying occurs when Assessment B is submitted to a third party or an engagement. Any changes you make to Assessment A afterward won't be reflected in Assessment B. Both assessments remain separate.
Issues and tasks
The role of TPR assessor [sn_vdr_risk_asmt.vendor_assessor] is required to create and manage both tasks and issues.
The TPR manager, TPR assessor, or contract negotiator can create tasks to help ensure that a team member or the third-party contact responds to concerns about the questionnaire responses or requested documents. They can manage existing tasks to verify that the assigned team member or third-party contact responds to a task and updates it as needed. For more information about creating and managing issues, see Create a task for a third party or engagement and Manage a task for a third party or engagement.
The TPR manager, TPR assessor, or contract negotiator can create an issue to help ensure the teams concerns about a third party or engagement are remediated. They can also manage the existing issues to verify that they’re understood, shared with the correct persons, and are acted on as needed. For more information about creating and managing tasks, see Create an issue for a third party or engagement and Manage issues.
Additional assessment actions
The TPR manager, due-diligence request owner, or contract negotiator may need to reopen an assessment because there’s new information available that impacts the engagement or some other change has occurred. For more information, see Why you conduct due diligence.
- Navigate to the Due diligence request record page by selecting the relevant DDR number.
- View the related third-party risk assessment by selecting the VRA number on the External assessments tab.
- Select Re-open.
The due diligence request state updates from Ready for TPRM approval to Due diligence. The TPR manager, owner, or contract negotiator can request questionnaires and document requests as needed. For more information, see Reopen an assessment.
- Navigate to the Due diligence request record page by selecting the relevant DDR number.
- View the related third-party risk assessment by selecting the VRA number on the External assessments tab.
- Select Cancel.