---
sourceDocument: Zurich Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/governance-risk-compliance

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Classic assessments

# Classic assessment configuration {#ariaid-title1}

* Release version: Zurich
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read

The TPR manager and TPR admin roles involve a broad variety of responsibilities. After the TPRM base system is set up, you configure additional settings that enable and enhance everyday risk-assessment tasks.

## Assessment setup overview {#tprm-ongoing-config__section_mk2_bc1_3cc}

By performing the tasks in the Assessment setup checklist for TPRM, you're setting up and configuring the TPRM application to address your unique requirements for scoring and assessing risk for third parties, engagements, and other entities using the classic assessment engine.  
Note:  
For any custom messages you create, it is your responsibility to generate the corresponding `sys_ui_message` records. This step is crucial if you want the custom messages to be extracted and translated.

## Assessment setup checklist for TPRM {#tprm-ongoing-config__section_u4n_rsx_hcc}

{#tprm-ongoing-config__table_fc1_vsx_hcc__entry__2}

| Task | Description |
|-|-|
| Set up risk rating scales for scoring assessments and questionnaires. | You can configure the risk rating scale that is selected by default for all questionnaires. For more information, see [Set up risk rating scales for scoring](https://www.servicenow.com/docs/PVWn_1DimU9RDSOOjqkdhg "The risk rating scale helps business users better understand risk assessment results. For example, in the default settings, risk scores in the 20 through 39 range indicate high risk, while scores in the 60 through 79 range indicate low risk."). Role required: admin or sn_vdr_risk_asmt.vendor_risk_manager |
| Set up third-party risk domains or areas. | You can configure the scoring method and weight that is selected by default for all third parties associated with a specific risk area. For more information, see [Define a third-party risk domain](https://www.servicenow.com/docs/6YSbf9wRqo1ViWdSiESYpg "A risk domain defines the type of risk to assess for a third party. For example, you might want to assess a data-management third party in terms of security risk and a bank in terms of financial risk. Security risk and financial risk are risk domains. Some platform applications refer to risk domains as \"risk areas.\""). Role required: sn_vdr_risk_asmt.vendor_risk_manager |
| Set up third-party risk area criteria, which are the group of risk domains or areas that apply to a type of third party. | You can adjust the weight and scoring method of each risk area within a criteria definition. For more information, see [Define third-party risk area criteria](https://www.servicenow.com/docs/RXPB2FHtv7ubOKYGCi~2OQ "A third-party risk area criteria is a group of risk domains (sometimes called risk areas in other platform features) that applies to a particular type of third party."). Role required: sn_vdr_risk_asmt.vendor_risk_manager |
| Set up third party and engagement component criteria. | Components are entities that can be assessed for risk. Component criteria are groups of components that are related to a particular type of third party or engagement. You can't add new components or modify existing ones. You can, however, define the criteria (in terms of scoring method and weight) to be used to assess the components. You can update the Default scoring method to specify how multiple scores for each risk area are calculated. You can use the Default weight to adjust the weight of third-party provider scores in the third party's overall risk rating. The following component classifications are available. * Third-party components * Third-party risk assessments (External risk assessments) * Subsidiaries * Engagements * Risk intelligence rating {#tprm-ongoing-config__ul_npf_wtw_xbc} * Engagement components * Engagement risk assessments * Product * Principal * Facility * Other {#tprm-ongoing-config__ul_c3g_ytw_xbc} {#tprm-ongoing-config__ul_sq2_dv2_jlb} For more information on setting up component criteria, see [Define component criteria](https://www.servicenow.com/docs/bTunYxWbBwZdDH_dl0yVuA "Components are the entities for which you can assess risk (for example, subsidiaries or engagements). A component criteria is a group of components that should apply to a particular type of third party or engagement."). For more information on how engagement components impact third-party elements, see [Monitoring third-party elements](https://www.servicenow.com/docs/Yfp~n_hbxXXKwPuC4N0CLA "You can monitor third-party elements through scalable scoring models, relationship analysis, and due diligence workflow integration by using the Third-party Risk Management application. Monitoring third-party elements and leveraging that information can help with conducting more informed risk assessments as part of your third-party risk program."). Role required: sn_vdr_risk_asmt.vendor_risk_manager |
| Set up third-party and engagement risk scoring rules. | Define the criteria, based on risk scores, that determine which third parties or engagements require assessments. Third-party risk scoring rules apply to subsidiaries, engagements, and third-party risk areas. Engagement risk scoring rules only apply to engagements. For more information, see [Define third-party risk scoring rules](https://www.servicenow.com/docs/Q67XhLQOV8gyDsiqVJ4Lrg "Define criteria, based on risk scores, that determine which third parties require assessments. Third-party risk scoring rules apply to subsidiaries and engagements and to third-party risk areas.") and [Define engagement risk scoring rules](https://www.servicenow.com/docs/6C_u_JyKU4Elj5XPujFeDg "An engagement risk-scoring rule specifies component criteria that determine which engagements are selected for assessment. For example, a rule could enable assessments for engagements that involve more than $40,000 annual business. Engagement scoring rules apply only to engagements."). Role required: sn_vdr_risk_asmt.vendor_risk_manager |
| Create questionnaire or document request templates. | You can reuse questionnaire templates and document-request templates to streamline the creation of new questionnaires and document requests. The following template classifications are available. * Questionnaire template * Document request template * Tiering questionnaire template * Fourth-party template * IRQ template * Collection template {#tprm-ongoing-config__ul_mqt_s32_3cc}For more information, see [Create a questionnaire or document request template](https://www.servicenow.com/docs/3h1dqg9Xi6HasV_XbYtIJQ "You can reuse questionnaire templates and document-request templates to speed up the creation of new questionnaires and document requests.") and [Create a questionnaire or document request template using the Designer](https://www.servicenow.com/docs/T~jRzYuc45R7ars0g9QdPw "Use the Questionnaire Template Designer to create and edit questionnaire or document request templates that you can use as the basis for other templates."). Role required: admin or sn_vdr_risk_asmt.vendor_risk_admin |
| Import questionnaires using an excel spreadsheet. | This task is optional. After preparing your excel spreadsheet, you can import your data and then create questionnaires automatically from templates. For more information, see [Import a questionnaire from a spreadsheet](https://www.servicenow.com/docs/TwpH1kwuEZJ7z2lGjFtdgg "If you maintain questionnaires using Microsoft Excel spreadsheets, you can save time and effort by importing your spreadsheet data directly into TPRM tables. You can then create questionnaires automatically from templates."). Role required: sn_vdr_risk_asmt.vendor_risk_manager |
| Set up a metric category (question bank), which is a group of questions related to a type of an assessment. | Add questions to a question bank so that you can reuse sets of questions in a questionnaire template. You can add new questions and questions from existing questionnaires. For more information, see [Set up and maintain a question bank](https://www.servicenow.com/docs/XH9jbIMGMCuUqEf_mB~d~w "After you add a question to a question bank, you can reuse it in any assessment by dropping it into the assessment. You can create custom questions, add existing questions, or add and customize the sample questions that are included with the base system."). Role required: admin or sn_vdr_risk_asmt.vendor_risk_admin |
| Create questions to meet your assessment requirements. | You can create custom questions, add existing questions, or add and customize the sample questions that are included with the base system. For more information, see [Define a question](https://www.servicenow.com/docs/LCsJ9CqLG2YSb470LHjlOQ "After you add a question to a question bank, you can reuse it in any assessment by dropping it into the assessment. You can create custom questions, add existing questions, or add and customize the sample questions that are included with the base system."). Role required: admin or sn_vdr_risk_asmt.vendor_risk_manager |
| Set up option to use normalized values for scoring. | You can use the Maximum normalization input setting to use normalized values to calculate assessment scores for Choice or Multiple Selection questions with the scored check box not selected. Normalization of values can help ensure consistent comparisons across different entities. For more information on how this setting impacts scoring, see [Normalize the scores for metrics](https://www.servicenow.com/docs/Xi1g00Oxz9CY54lN_eR_8w "You can use the Maximum normalization input setting to use normalized values to calculate assessment scores for questions (metrics)."). Note: This option is available under the question type tab of an assessment metric (question) record. For more information on setting up questions, see [Define a question](https://www.servicenow.com/docs/LCsJ9CqLG2YSb470LHjlOQ "After you add a question to a question bank, you can reuse it in any assessment by dropping it into the assessment. You can create custom questions, add existing questions, or add and customize the sample questions that are included with the base system."). Role required: admin or sn_vdr_risk_asmt.vendor_risk_manager |
| Create assessment templates for external questionnaires. | You can create an assessment template with set duration requirements and questionnaires attached by default to help streamline the assessment process for different types of third parties and engagements. For more information, see [Create an external assessment template](https://www.servicenow.com/docs/swLf75QiB56TVJg7~xU3UA "When defining an assessment template, the third-party risk manager provides scheduling information for the third-party risk assessment."). Role required: admin or sn_vdr_risk_asmt.vendor_risk_manager |
| Create issue generation rules. | This task is optional. Set up rules that auto-generate issues for external assessments. Specify a Third-party risk assessment, a Questionnaire template, and the Questions to apply the rule to, as well as an Issue template and a Task template to use while generating it. For more information on setting up these rules, see [Create an issue generation rule](https://www.servicenow.com/docs/A6crIfg~T3X2Pxc0xv863w "Create an issue generation rule that will automatically create an issue based on question responses to external assessments. Issues help ensure that your concerns about a third party or engagement are remediated."). Role required: admin or sn_vdr_risk_asmt.vendor_risk_admin |
| Schedule recurring assessments. | This task is optional. Recurring assessments can be scheduled for third parties or engagements. You can use an assessment template you created or manually attach questionnaire and document requests as needed. For more information, see [Configure a risk assessment to recur on a schedule](https://www.servicenow.com/docs/I1yVygalLdf1FlJxyQ_mvw "Configure a third-party risk assessment to recur on a schedule to regularly update risk results for a third party or an engagement."). Role required: sn_vdr_risk_asmt.vendor_assessor |
| Set up an internal questionnaire's responses to automatically attach questionnaires to external assessments that are based on the responses, the calculated risk tier, or both. | This task is optional. For more information, see [Set up internal questionnaire responses to automatically attach external questionnaires to assessments](https://www.servicenow.com/docs/kh_5elyqJIvAsQtS_4JxeQ "Set up an internal questionnaire's responses to automatically attach questionnaires to external assessments that are based on the responses, the calculated risk tier, or both by using Third-party Risk Management. By setting up this configuration, you can help to improve your ability to respond to risk tier changes and internal questionnaire responses."). Role required: admin or sn_vdr_risk_asmt.vendor_risk_admin |
| Set up event-driven management rules. | This task is optional. Set up rules that auto-generate and send questionnaires and doc requests to engagements and third parties. For engagements and third parties that meet the criteria you define, you specify the schedule and the assessment templates. You can automate all request types except onboarding. For more information on setting up these rules, see [Event-driven management --- automate assessment processes](https://www.servicenow.com/docs/rjWkf~eYXfSzDQmEJU30Xg "Use the Event-driven management feature to configure rules that auto-generate and send questionnaires and doc requests to engagements and third parties. For engagements and third parties that meet the criteria you define, you specify the schedule and the assessment templates. You can automate all assessment types except onboarding."). Role required: sn_vdr_risk_asmt.vendor_risk_manager |
| Verify risk ratings and scoring calculations. | This task is optional. Review scores and risk ratings in your questionnaires and help ensure the accuracy and consistency of risk scoring by verifying the correct application of weights, normalized values, scoring methods, and risk rating scales. For more information, see [Verifying scoring calculations using the classic assessment engine](https://www.servicenow.com/docs/_suqnM2XogOeWdFcwyFMfg "You can review scores and risk ratings in your questionnaires to help ensure the accuracy and consistency of risk scoring by verifying the correct application of weights, normalized values, scoring methods, and risk rating scales. Based on the different weights you assign, Third-party Risk Management aggregates these values and produces a composite score."). |
[Table 1. Setup tasks for assessments and questionnaires]

{#tprm-ongoing-config__table_fc1_vsx_hcc}

For more information on calculations for risk ratings and scoring, see [Scoring calculations using the classic assessment engine](https://www.servicenow.com/docs/1FuueNLnhcaEAyR0SVLJ7A "Perform a comprehensive external risk assessment when calculating multiple ratings and scores by using the Third-party Risk Management application. You can gain a deeper understanding of the overall calculation process and learn how user-defined parameters and configurations influence the results of the questionnaires.").

For more information on assessment and score-related automation, see [Set up internal questionnaire responses to automatically attach external questionnaires to assessments](https://www.servicenow.com/docs/kh_5elyqJIvAsQtS_4JxeQ "Set up an internal questionnaire's responses to automatically attach questionnaires to external assessments that are based on the responses, the calculated risk tier, or both by using Third-party Risk Management. By setting up this configuration, you can help to improve your ability to respond to risk tier changes and internal questionnaire responses."), [Assessing your third-party risk](https://www.servicenow.com/docs/Irep7LZWyN_XTR9KnfuuVg "Use Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships. The information gathered from internal questionnaires, external questionnaires, and documentation requests helps you to understand the third party's risk profile, determine the appropriate risk mitigation strategies, and determine whether the third party or engagement meets all necessary compliance requirements."), [Event-driven management --- automate assessment processes](https://www.servicenow.com/docs/rjWkf~eYXfSzDQmEJU30Xg "Use the Event-driven management feature to configure rules that auto-generate and send questionnaires and doc requests to engagements and third parties. For engagements and third parties that meet the criteria you define, you specify the schedule and the assessment templates. You can automate all assessment types except onboarding."), and [Automate actions upon risk intelligence updates](https://www.servicenow.com/docs/P9uJXNcXU0YrgcOFbBFsBQ "A provider-based submission rule is a set of conditions and actions. In a rule, you can specify that an update to a rating from a risk intelligence provider is the condition that triggers the action that is specified in the rule. The action might be to create and send a third-party risk assessment, issue, task, or email.").

