---
sourceDocument: Zurich Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/governance-risk-compliance

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Third-party risk scoring rules

# Define third-party risk scoring rules {#ariaid-title1}

* Release version: Zurich
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Define criteria, based on risk scores, that determine which third parties require assessments. Third-party risk scoring rules apply to subsidiaries and engagements and to third-party risk areas.

## Before you begin

Role required: sn_vdr_risk_asmt.vendor_risk_manager

## Procedure

1. Navigate to AllThird-party Risk ManagementScoring SetupThird-party Risk Scoring Rules.
2. Select New, fill in the form, and then select Submit.  
   {#tprm-tp-risk-scoring-rules-define__table_eng-scoring-rule__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the scoring rule. |
   | Description | Description of the scoring rule that will help other users understand its intent. |
   | Number | For each third-party risk scoring rule, the system auto-assigns a unique ID number that starts with the text VRS. The unique ID is used in all references to the item. You can use the ID to search or filter for the item that you want to work on. |
   | Third-party risk area criteria | The risk area criteria that applies to this engagement risk scoring rule. A third-party risk area criteria is a group of risk domains (sometimes called risk areas in other platform features) that applies to a particular type of third party. See [Define third-party risk area criteria](https://www.servicenow.com/docs/RXPB2FHtv7ubOKYGCi~2OQ "A third-party risk area criteria is a group of risk domains (sometimes called risk areas in other platform features) that applies to a particular type of third party.") for details on how the criteria are defined. |
   | Third-party risk component criteria | Criteria for third-party risk assessments, engagements, and subsidiaries that applies to this risk scoring rule. Components are the entities for which you can assess risk (for example, subsidiaries or engagements). A component criteria is a group of components that should apply to a particular type of third party or engagement. See [Define component criteria](https://www.servicenow.com/docs/bTunYxWbBwZdDH_dl0yVuA "Components are the entities for which you can assess risk (for example, subsidiaries or engagements). A component criteria is a group of components that should apply to a particular type of third party or engagement."). |
   | Active | Option to activate the rule. Only active rules are applied. |
   | Order | Select the order to indicate the rule's precedence. If multiple rules apply to the same third-party risk area, engagement, or subsidiary, the one with the higher-order value is applied. |
   | Vendor filter | Use the [condition builder](https://www.servicenow.com/docs/access?context=c_ConditionBuilder&version=zurich&pubname=zurich-platform-user-interface&ft:locale=en-US) to define the rules for selecting third parties. For example, you can filter on third parties with whom you do considerable business (Size is $1,000,000) or third parties within a specific category (Category is software). |
   [Table 1. Third-party Risk Scoring Rule form]

   {#tprm-tp-risk-scoring-rules-define__table_eng-scoring-rule}

*[\>]: and then


