The ServiceNow® Third-party Risk Management application provides a centralized process for managing your third-party portfolio and completing the third-party assessment and remediation life cycle. Integration with other GRC applications provides additional traceability for compliance with controls and risks.
Note: In version 17.x, Vendor Risk Management was renamed to Third-party Risk Management.
The Third-party Risk Management application includes the following features:
- Third-party portfolio - third-party hierarchy and third-party contacts
- Third-party engagements
- Tiering setup, tiering assessments, and IRQs
- Risk assessment setup, and risk assessments, including risk domains (risk areas)
- Configurable risk calculation
- Automated tiering and risk assessment submission rules
- Security score integration
- Issue management
- Support for third-party scores roll up to risk rating
- Reports and dashboards
- GRC Integration: associate policies and controls to questions in a third-party risk assessment
- GRC Integration: roll-up third-party risk information to an enterprise risk program
New
- Added engagement and element risk-rating calculations.
- Added element-assessment evidence rollups and deduplication.
- Added internal task management and responder actions.
- Added SAE questionnaire notifications and assessment improvements.
- Added AIDE semantic configurations and SBOM-related enhancements.
Changed
- Expanded risk-rating calculations across vendor, engagement, and element relationships.
- Added task types, internal-task access, and responder permissions.
- Updated assessment reassignment and issue-generation behavior.
- Improved role exclusions, ACL conditions, and secure query handling.
Fixed
- Corrected issue-generation handling for invalid or hidden SAE questions (PRB2021879).
- Fixed vendor assessment reminder failures when due dates are missing (PRB2029246).
- Corrected document-link navigation from internal assessments (PRB2030116).
- Fixed risk ratings not being set after assessment submission (PRB2034741).
- Corrected exclusion mappings for assessment responder and business-user roles (PRB2039159).
- Fixed SBOM product-model creation after document processing (PRB2052847).
The following applications are automatically installed when the Third-party Risk Management application is activated:
- GRC: Profiles
- GRC: Compliance Assessment
- GRC: Vendor Portal
Permissions and roles:
- Role required to install the app: System admin (admin)
When you upgrade the Third-party Risk Management application, make sure to upgrade the Vendor Risk Management Workspace and any other installed GRC applications to the equivalent release version. For example, Third-party Risk Management version 18.x is certified to work with Vendor Risk Management Workspace version 18.x and other version 18.x GRC applications.