---
sourceDocument: Zurich Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/governance-risk-compliance

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Approval process management

# Approval process management {#ariaid-title1}

* Release version: Zurich
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can view the list of users who can approve or reject a DD request and also view the details of their approval actions. In addition, you can view the approval levels for a request.

## Approval process {#tprm-ws-dd-mgt-pg-approvals__section_cc2_kvg_cyb}

During the approval process, each aspect of risk is analyzed by the appropriate internal stakeholders. All internal stakeholders (approvers) review the questionnaire responses and supporting documents from the third-party and engagement contacts. If the responses are good, one or more approvers approves and then closes the DD request. If a contract will be prepared, the approved request moves to the Contract Risk process.

## Accessing the Due diligence management page {#tprm-ws-dd-mgt-pg-approvals__section_qxg_4mv_qzb}

You can access the Due diligence management page from many locations by selecting the DDR number for any DD request. Select either the Approvers tab or the Approval levels tab.

## Approvers tab {#tprm-ws-dd-mgt-pg-approvals__section_bft_tvt_2yb}

The tab lists the users that have responded to the engagement request. Select the State value to view the details of the approval action that the approver performed.  
The state of the approval can be one of the following values:

* Not yet requested
* Requested
* Approved
* Rejected
* Cancelled
* No longer required
{#tprm-ws-dd-mgt-pg-approvals__ul_vmf_m5s_fyb}

Select the State value for a request to view the Details tab for the request.

## Approval levels tab {#tprm-ws-dd-mgt-pg-approvals__section_p45_wmc_fyb}


Note:  
For more information on how Third-party risk (TPR) admins can set approval levels and rules, see [Set up the approval levels for due diligence requests](https://www.servicenow.com/docs/cgmtiYEi~vi1jvssaBjBkw "Assign one or more approval levels to the users or groups that approve your due diligence requests in the Third-party Risk Management application. Because the approval levels are applied iteratively and each level contains different rules, you can help to ensure that the correct user or group is assigned as an approver.") and [Set up the approval rules for due diligence requests](https://www.servicenow.com/docs/xYshXtlwFKV7qn2NH_49~A "Set up the rules at each approval level for your due diligence requests by selecting an approver type and the number of approvals that you require in the Third-party Risk Management application. You can also filter the table conditions that apply to each rule so that you can help ensure that the correct user or group is assigned as an approver.").

## Approval business rules {#tprm-ws-dd-mgt-pg-approvals__section_ifx_p4t_k2c}

If you have the TPR admin \[sn_vdr_risk_asmt.vendor_risk_admin\] role, you can view all business rules by navigating to AllSystem DefinitionBusiness Rules.  
The following business rules are included when the Third-party Risk Due Diligence \[sn_tprm_dd\] application is activated. {#tprm-ws-dd-mgt-pg-approvals__table_hy1_bjt_k2c__entry__3}

| Business rule | Source table | Description |
|-|-|-|
| Create approval records | Third-party due diligence request \[sn_tprm_dd_request\] | Creates approval records for the evaluated approvers, setting the first record to Requested and subsequent records to Not yet requested when the due diligence request state updates to Awaiting for approval. |
| Roll up approval and update DD | Approval \[sn_tprm_approval\] | Marks next approval record as Requested if multiple approvals are required. If all required approval records are approved, then the due diligence record state is updated to Approved. |
| Cancel existing approvals | Third-party due diligence request \[sn_tprm_dd_request\] | Cancels approval requests if the state of the approval record is updated to No longer required. |
[Table 1. Third-party risk due diligence business rules]

{#tprm-ws-dd-mgt-pg-approvals__table_hy1_bjt_k2c}
* **[Approval rule form](https://www.servicenow.com/docs/IxqtEd~Y23Uk~iAUOa5f6w)**   
  The approval rule form captures all the information needed to create an approval rule. An admin or third-party risk admin can create an approval rule.

**Related concepts**   

* [Approving or rejecting requests for due diligence](https://www.servicenow.com/docs/5CFCAnng1xVz66jyv7iHAQ "Set up the approval levels and rules for due diligence requests in the Third-party Risk Management application to use while approving or rejecting requests after reviewing questionnaire responses and due diligence process results.")  
**Related tasks**   

* [Set up the approval levels for due diligence requests](https://www.servicenow.com/docs/cgmtiYEi~vi1jvssaBjBkw "Assign one or more approval levels to the users or groups that approve your due diligence requests in the Third-party Risk Management application. Because the approval levels are applied iteratively and each level contains different rules, you can help to ensure that the correct user or group is assigned as an approver.")
* [Set up the approval rules for due diligence requests](https://www.servicenow.com/docs/xYshXtlwFKV7qn2NH_49~A "Set up the rules at each approval level for your due diligence requests by selecting an approver type and the number of approvals that you require in the Third-party Risk Management application. You can also filter the table conditions that apply to each rule so that you can help ensure that the correct user or group is assigned as an approver.")  
**Related reference**   

* [Approval rule form](https://www.servicenow.com/docs/IxqtEd~Y23Uk~iAUOa5f6w "The approval rule form captures all the information needed to create an approval rule. An admin or third-party risk admin can create an approval rule.")

*[\>]: and then


