Tracking a managed activity
Summarize
Summary of Tracking a managed activity
ServiceNow’s Third-party Risk Management application enables you to track managed activities via the Usage analytics activities table [snvdrriskasmtuaactivity]. This tracking helps verify activity consumption related to third-party risk assessments and engagements.
Show less
Each engagement consumes only one license regardless of the number of managed activities within a contract year. Managed activity usage is only counted when an activity is initiated, excluding activities linked to onboarding new third parties (companies not yet in the Company [corecompany] table).
Managed activities include:
- Inherent risk questionnaires (IRQ) with status "Awaiting response"
- Tiering assessments with questionnaires in "Awaiting response" status
- Third-party risk assessments with questionnaires "Submitted to third party"
- Creation of tasks or issues related to third-party risk assessments
Automatically created assessments via event-driven management rules that are recalled before submission to the third party do not count as managed activities. However, assessments canceled after initiation are still counted.
Using the Usage Analytics Activities Table
The Usage analytics activities table logs each managed activity occurrence and is read-only. Records older than two years are archived automatically. Access requires the Third-party assessment reviewer [snvdrriskasmt.vendorassessmentreviewer] role and is available via:
All > Third Party Risk Management > Administration > Managed Activity Analytics
Key fields in the table include:
- Created: Timestamp of the activity
- Activity: Reference to the related record
- Activity type: Type of managed activity (e.g., tiering assessment, internal assessment, TPRA, issue, or task)
- Applies to: Whether the activity pertains to the third party or engagement
- Third party / Engagement: Related entities
- Status: Indicates if the activity is "Tracked" or "Recalled"
Note that while calculated risk scores updated by assessments are considered managed activities, they are not logged in this table. Similarly, risk intelligence score updates from providers are not managed activities.
View managed activities in the usage analytics activities table for tracking and verification purposes in the Third-party Risk Management application.
Overview of managed activities
You can track and verify managed activities in the Usage analytics activities [sn_vdr_risk_asmt_ua_activity] table.
An engagement only consumes one license, regardless of whether there’s one managed activity or many managed activities per contract year. Managed activity usage is triggered only when an activity is initiated.
Activities that are associated with a new third party going through the due diligence onboarding workflow aren’t counted as managed activities. In this context, a new third party is defined as a company that is not in the Company [core_company] table.
If any of the following activities aren’t related to a new third party going through the due diligence onboarding workflow, they’re counted as managed activities:
- An Inherent risk questionnaire (IRQ) that is sent by the system has a status of Awaiting response. For more information, see Assessing your third-party risk.
- A tiering assessment with a questionnaire that is sent by the system has a status of Awaiting response.
- A third-party risk assessment with a questionnaire that is sent by the system has a status of Submitted to third party. For more information, see External assessment lifecycle states.
- The creation of a task or issue for a third-party risk assessment. For more information, see Create a task for a third party or engagement and Create an issue for a third party or engagement.
Using the usage analytics activities table for verification
The usage analytics activities table stores a record every time a managed activity occurs. This table is read only. Records that are two years or older are automatically archived. You must have the Third-party assessment reviewer [sn_vdr_risk_asmt.vendor_assessment_reviewer] role to view this table.
You can access the Usage analytics activities table by navigating to .
The following example and table show the Usage analytics activities [sn_vdr_risk_asmt_ua_activity] table.
| Field | Description |
|---|---|
| Created | Date and time that the activity occurred. |
| Activity | Record that is related to the activity. |
| Activity type | Managed activities that can be associated with tiering assessments, internal assessments, third-party risk assessments (TPRA), issues, and tasks. |
| Applies to |
|
| Third party | Third party that is related to the activity. |
| Engagement | Engagement that is related to the activity. |
| Status | State of the activity:
|