External assessment lifecycle states
Summarize
Summary of External assessment lifecycle states
The external assessment lifecycle in ServiceNow guides the process of collecting and managing assessment data from third parties. This lifecycle involves multiple states that track the progress of questionnaires, document requests, and issue resolution to ensure thorough third-party risk assessment and timely completion.
Show less
Key Lifecycle States
- Draft: The assessment record is initially created. It includes an assessment template (questionnaires and document requests auto-generated or manually specified), an auto-generated risk rating, and an assigned owner responsible for managing and monitoring the process. The owner must have either the TPR manager or TPR assessor role.
- Submitted to third party: Questionnaires and document requests are sent to the third party, who then responds.
- Responses received: The internal third-party risk team reviews third-party submissions, may request clarifications or missing information.
- Generating observations: The system auto-generates issues based on incorrect answers. Third-party contacts respond to these issues, and the internal team decides to accept responses or require remediation.
- Finalizing with a third party: The internal team reviews all assessment data and may reset the assessment to Draft if needed.
- Closed: When all data is accepted, the assessment is closed, which can trigger the contract risk process if engagement proceeds to contracting. Contracting only begins after approval is complete.
Questionnaire State Management
Questionnaire states differ slightly based on the engine version:
- Classic engine: Uses separate states for questionnaire requests and questionnaires themselves. Questionnaire requests track sending status (Ready to take, In progress, Complete, Canceled). Questionnaires track workflow from creation to review (New, Submitted, In Progress, Received, Returned, Canceled).
- Smart Assessment Engine (SAE) in Zurich: Simplifies questionnaire states to three key statuses—In progress, Completed, and Canceled—to streamline tracking.
Practical Implications for ServiceNow Customers
Understanding these lifecycle states helps ServiceNow customers effectively manage third-party risk assessments by:
- Assigning proper ownership and roles to ensure accountability.
- Tracking the progress of assessments and questionnaire completion in real time.
- Handling responses, follow-ups, and issue remediation efficiently.
- Ensuring assessments are finalized properly to trigger subsequent onboarding or contracting steps.
- Choosing the appropriate questionnaire engine and understanding state workflows based on your platform version.
The process of collecting assessment data from a third party moves through several states. For example, during the Submitted to third party state, the third party responds to tasks, issues, and works to complete the questionnaires.
Third-party assessment states
- Draft
- An external assessment record is opened in the Draft state.
- Assessment template: A set of external questionnaires and document requests that are auto-generated based on IRQ responses. Alternatively, an administrator could manually specify the questionnaires and document requests.
- Risk rating: The overall risk rating that is auto-generated based on IRQ responses.
- Owner: The owner is the person who owns an assessment for audit purposes and monitors and manages overall assessment processes. Owners are responsible for confirming that the assessment is completed in a timely fashion by the third party, reviewing their responses, and creating and resolving issues. To drive the assessment to its completion, owners are notified when an assessment reaches a particular milestone. The owner must have the TPR manager or TPR assessor role.
- Submitted to third party
- The questionnaires and document requests for the assessment have been sent to the third-party contact. Internal stakeholders await responses.
- Responses received
- After contacts at the third party have completed all questionnaires and document requests, your internal third-party risk team reviews and analyzes the responses. The team might return particular questions for follow-up, clarification, or missing answers.
- Generating observations
- When all responses are completed, the system can auto-generate issues for incorrect answers.
Third-party contacts respond to issues. Your internal third-party risk team makes a final determination to accept the responses or remediate the issues.
- Finalizing with a third party
- Your third-party risk team reviews all assessment data. In some cases, the team resets the assessment to the Draft state to restart the assessment life cycle.
- Closed
- When all data is acceptable, the assessment is complete and a member of the team closes the assessment. If the engagement will be contracted, the Closed state initiates the contract risk process.
Questionnaire states
In the Classic engine, questionnaire requests (previously called assessment instances) and questionnaires themselves have separate state systems. The SAE uses a simplified set of questionnaire states.
Questionnaire requests track the overall status of a questionnaire request sent to a third party.
| Questionnaire request state | Description |
|---|---|
| Ready to take | Questionnaire request is prepared and ready to be sent to the third party. |
| In progress | Questionnaire request has been sent to the third party and is being completed. |
| Complete | Questionnaire request is complete and the third party has submitted their response. |
| Canceled | Questionnaire request is canceled and is no longer active. |
Questionnaires themselves move through additional states that track the workflow of completing and reviewing the questionnaire content.
| Questionnaire state | Description |
|---|---|
| New | Questionnaire is created but not yet sent to the third party. |
| Submitted | Questionnaire is sent to the third party for completion. |
| In Progress | Third party is actively working on the questionnaire. |
| Received | Third party submits the completed questionnaire for review. |
| Returned | Questionnaire is sent back to the third party for updates and corrections. |
| Canceled | Questionnaire is canceled and is no longer active. |
| Questionnaire state | Description |
|---|---|
| In progress | Questionnaire is active and being completed by the third party. |
| Completed | Questionnaire is finished and submitted. |
| Canceled | Questionnaire is canceled before completion. |