Roles in Third-party Risk Management
Summarize
Summary of Roles in Third-party Risk Management
Third-party Risk Management (TPRM) roles in ServiceNow define permissions and access levels to manage and assess third-party risks efficiently. These roles enable organizations to control who can view, edit, approve, and manage third-party data, assessments, questionnaires, contracts, and related processes within the TPRM framework.
Show less
Key Roles and Their Permissions
- Third-party reader [vendorreader]: Provides read-only access to third-party contact records.
- Third-party editor [vendoreditor]: Allows creation, updating, and deletion of third-party contact records.
- Third-party assessment reviewer [snvdrriskasmt.vendorassessmentreviewer]: Enables viewing assessment and questionnaire data plus commenting on tiering, internal/external assessments, risk issues, tasks, and due diligence requests. This is the minimum role required to view TPRM templates.
- TPR assessor [snvdrriskasmt.vendorassessor]: Includes reviewer permissions and adds management of third parties, contacts, external assessments, and issues. Configurable permissions allow assessors to answer or modify questionnaire responses.
- TPR approver [snvdrriskasmt.approver]: Extends reviewer permissions with approval capabilities for Internal Risk Questionnaires (IRQs).
- TPR manager [snvdrriskasmt.vendorriskmanager]: Combines assessor permissions with management of assessment templates, scheduled assessments, engagements, and scoring rules.
- TPR admin [snvdrriskasmt.vendorriskadmin]: Adds full control over creating and editing all types of assessment templates, document request templates, and automation rules.
- Contract risk negotiator [snvdrriskasmt.contractnegotiator]: Grants legal department users ability to modify contract statuses and dates, working alongside the contract risk negotiators user group.
- Third-party contact [vendorcontact]: Assigned to external users from third-party organizations responsible for responding to assessments and questionnaires via the Third-party portal. This role restricts access to the ServiceNow AI platform and limits access to external portal resources.
Roles for Specialized Features
- Digital Resilience Third-party Registers: Access is controlled by specific roles such as TPRM DORA user, manager, and admin, integrated within other key TPRM roles.
- Smart Assessment Engine (SAE): Roles like template reader, assessment reader, internal/external assessment users, and SAE admin govern template viewing, questionnaire responses, and template creation within the Vendor Management and Assessment Workspaces.
- Now Assist for TPRM: The Third-party assessment reviewer role automatically gains the TPRM GenAI User role post-installation to enable Now Assist features for enhanced risk management support.
Practical Considerations
- Assign roles carefully based on user responsibilities to maintain appropriate access and control.
- The Third-party assessment reviewer role is a baseline for viewing external and internal assessment templates and questionnaires.
- Third-party contacts should only be assigned to external users and are limited to the Third-party portal to ensure security and data segregation.
- Properties like snsvdp.allowassessoredit allow customization of assessor capabilities regarding questionnaire responses.
Next Steps
ServiceNow customers should assign TPRM roles aligned with organizational responsibilities and compliance requirements to streamline third-party risk assessments, approvals, and management. Utilize role-based access to safeguard sensitive information and efficiently coordinate risk activities across internal teams and external partners.
Roles determine permissions and access in TPRM.
TPRM roles
| Friendly name [role name] | Description | Contains roles |
|---|---|---|
| Third-party reader [vendor_reader] |
Read access to third-party contact records. | None |
| Third-party editor [vendor_editor] |
Create/update/delete third-party contact records. | None |
| Third-party assessment reviewer [sn_vdr_risk_asmt.vendor_assessment_reviewer] |
View assessment and questionnaire data. In addition to viewing, they can leave comments on the following tables:
|
Contains:
|
TPR assessor (Third-party risk assessor) [sn_vdr_risk_asmt.vendor_assessor] |
|
Contains:
|
TPR approver [sn_vdr_risk_asmt.approver] |
Includes all permissions of the Third-party assessment reviewer role plus: approve IRQs. |
Contains:
|
| TPR manager (Third-party risk manager) [sn_vdr_risk_asmt.vendor_risk_manager] |
Includes all permissions of the TPR assessor role plus:
|
Contains:
|
| TPR admin (Third-party risk admin) [sn_vdr_risk_asmt.vendor_risk_admin] |
Includes all permissions of the TPR manager role plus: Create and edit the following items:
Note: All the templates include both classic and SAE templates. |
Contains:
|
| Contract risk negotiator [sn_vdr_risk_asmt.contract_negotiator] |
Includes all permissions of the TPR assessor role plus: Gives users in the legal department access to modify contract status and the start and expiration dates. You can add users with this role to the Contract risk negotiators user group. See Add users to groups based on responsibilities. |
Contains:
|
[vendor_contact]
|
You assign the third-party contact role to users at the third-party organization whose risk is being assessed. Third-party contacts are assigned the snc_external role to give them access to resources and actions in the Third-party portal. Important:
The third-party contact role should be used only for external contacts. The role prohibits access to your ServiceNow AI Platform instance and grants access only to the Third-party portal. You assign the primary contact responsibility to the third-party contact who can directly answer assessment questions or assign another contact at the third party to answer the questions. Primary contacts can manage other contacts for the third party. |
Contains: snc_external |
Roles required for accessing the Digital resilience third-party registers
- TPRM DORA user [sn_dora_accel.user] role
Third-party assessment reviewer and TPR approver contain this role.
- TPRM DORA manager [sn_dora_accel.manager] role
TPR assessor and TPR manager contain this role.
- TPRM DORA admin [sn_dora_accel.admin]
The TPR admin contains this role.
Roles required for using Smart Assessment Engine
- TPRM
SAE template reader [sn_smart_asmt.template_reader] role
Third-party assessment reviewer contains this role.
- TPRM
SAE assessment reader [sn_smart_asmt.assessment_reader] role
Third-party assessment reviewer contains this role.
- TPRM
SAE internal assessment user [sn_vdr_risk_asmt.internal_assessment_responder]
This role is automatically assigned to an assigned IRQ assessor or internal assessment respondent.
This role is required to respond to internal/IRQ assessment questionnaires using the GRC Portal.
This role contains the following roles: sn_grc_business_user, canvas_user, and sn_smart_asmt.actor.
- TPRMSAE external assessment user [sn_vdr_risk_asmt.external_assessment_responder]
This role is automatically assigned to the assigned third-party contact.
This role is required to respond to external questionnaires using the Third-party portal.
This contains the role: sn_smart_asmt.actor.
A user with the TPRM SAE admin [sn_smart_asmt.assessment_admin] role can create SAE templates in the Vendor Management Workspace and Assessment Workspace.
Third-party admin contains this role.
A user with the sn_smart_imp_auto.automation_creator role can create post assessment impact automation rules.
Third-party admin contains this role.
For more information on SAE related roles, see Roles in Smart Assessment Engine.
Roles required for using Now Assist for Third-party Risk Management (TPRM)
A user with the Third-party Assessment reviewer [sn_vdr_risk_asmt.vendor_assessment_reviewer] role can use the Now Assist for TPRM skills.
The TPRM GenAI User [sn_tprm_genai.nowassist_user] role is granted to Third-party Assessment reviewers [sn_vdr_risk_asmt.vendor_assessment_reviewer] automatically after you install the Now Assist for TPRM application. For more information about a Now Assist for TPRM, see Now Assist for Third-party Risk Management (TPRM).