Governance › Risk › and Compliance
Third-party Risk Management
The ServiceNow® GRC: Third-party Risk Management (TPRM) application enables you to proactively identify, assess, and mitigate risks that are associated with your third-party relationships. TPRM provides a centralized process for managing your portfolio of third parties, assessing and scoring risk, and performing remediation.
Get started
Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release note information for all released apps, see the ServiceNow Store version history release notes.
ExploreLearn about how third-party risk managers, third-party risk users, and third-party risk administrators use the Third-party Risk Management application.ConfigureYou can activate or upgrade TPRM, by downloading the applications from the ServiceNow Store and then configuring the settings to meet your needs.IntegrateExtend TPRM capabilities by integrating with other applications.Migrate Classic to Smart Assessment EngineLearn what changes when you migrate from the Classic Assessment Engine to the Smart Assessment Engine, including feature differences, limitations, and setup requirements.Request third-party risk due diligenceRequest third-party risk due diligence to determine the level of risk for interactions with a third party and their engagement.Assess third-party riskUse Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships.Monitor third-party riskUse the Third-party Risk Management application to monitor potential risks associated with your third-party relationships.Approve or reject requests for due diligenceSet up the approval levels and rules for due diligence requests in the Third-party Risk Management application to use while approving or rejecting requests after reviewing questionnaire responses and due diligence process results.Manage the contract risk processProtect your organization's interests, as the Third-party risk contract negotiator by incorporating specific contractual provisions so that you can address identified risks.Use Digital resilience third-party registersUse the Digital resilience third-party registers application in the Vendor Management Workspace to set up and maintain registers of contractual arrangements with ICT third-party service providers.Use risk intelligence reportsManage and request risk Intelligence reports or scores from external risk intelligence content providers.Integrate scores from risk intelligence providersIntegrate scores from risk intelligence providers. The scores provide insight on how trustworthy and safe a particular third party can be.Use the third-party portalUse the third-party portal to respond to questionnaires, requests for documentation, tasks, and issues. The portal is the point of interaction between third-party contacts and risk assessors.ReferenceReference topics provide detailed descriptions of tables, properties, forms, and roles that are installed with the Third-party Risk Management application. Important:
The Vendor Management Workspace for ITSM (sn_itsm_vendor) is deprecated as of the Australia release. It is hidden and no longer available for activation for new customers. References to Vendor Management Workspace throughout this documentation refer to the GRC: Vendor Management Workspace (sn_vrm_ws), which is a separate application included with Third-party Risk Management and is not affected by this deprecation. For details about the deprecation process, see the Deprecation Process [KB0867184] article in the Now Support Knowledge Base.
Troubleshoot and get help