Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Integrating scores from risk intelligence providers

Risk intelligence providers generate risk scores for a variety of third-party risk domains. Your organization can purchase services from providers that return data that is analogous to personal credit scores. The scores provide insight on how trustworthy and safe a particular third party can be.

Working with data from risk intelligence providers

Note: You can request risk data for third parties but not for engagements.

Integration types

Here are some examples of the types of integrations supported by ServiceNow and ServiceNow partners:

  • Independent software vendor (ISV) integration types involve integrating ISV services such as EcoVadis or Black Kite.

  • Content integration types involve integrating external content sources such as regulatory databases or industry standards.

  • Data integration types involve integrating external data sources to gather and analyze relevant data such as data from financial systems, security tools, or vendor management systems.

  • Environmental, social, and governance (ESG) integration types involve incorporating ESG factors into the TPRM process.

Integrations supported by ServiceNow

Note: You can find the integration apps on the ServiceNow Store.

ProviderProduct nameContentService providedType
Shared AssessmentsStandard information-gathering (SIG) questionnaireStandard assessmentIndustry standard questionnaire for use in assessments.Content
EcoVadisEcoVadisSustainability ratingsSustainability scores in support of assessments and continuous monitoring.ISV, data, ESG

Integrations supported by ServiceNow partners

Note: You can find the integration apps on the ServiceNow Store.

ProviderProduct nameContentUse caseType
BitSightBitSightCyber risk ratingsCyber risk scores in support of assessments and continuous third-party risk monitoring.ISV, data
Security ScorecardSecurity ScorecardCyber risk ratingsCyber risk scores in support of assessments and continuous third-party risk monitoring.ISV, data
RiskReconRisk ReconCyber risk ratingsCyber risk scores in support of assessments and continuous third-party risk monitoring.ISV, data
UpguardUpguard Vendor RiskCyber riskCyber risk scores in support of assessments and continuous third-party risk monitoring.ISV, data
Recorded FutureRecorded Future IntelligenceCyber risk ratingsCyber risk scores in support of assessments and continuous third-party risk monitoring.ISV, data
Black KiteBlack KiteThird-party risk managementTechnical security, financial risk, ransomware susceptibility index, and compliance scores in addition to overall security ratings.ISV
InterosInterosSupply chain and multiple domain ratingsCyber, financial, ESG, geopolitical, operations, and restrictions ratings to support risk assessments and monitoring.ISV, content
TruSightTruSightThird-party risk assessmentsAccess to TruSight-validated third-party risk assessments.ISV
ISS Corporate SolutionsISS ESG Cyber Risk Score for Vendor Risk ManagementESG ratingsAccess to a comprehensive view of ISS Corporate Solutions' cyber risk management program through cyber risk and supply chain.ISV
SecuritybricksCMMC - NIST-800-171 - Vendor Compliance AssessmentTemplateAccess to an automated assessment for Federal organizations.data, content
TemplarshieldHECVAT-Questionnaire for Higher EducationContentAccess to an automated questionnaire for Higher education organizations.ISV, content
  • Register a risk intelligence provider
    Create a record for each risk intelligence provider from which you’ll request reports. The risk scores and ratings that risk intelligence providers generate are analogous to personal credit scores. The scores provide insight on how trustworthy and safe a particular third party can be.
  • Set up a risk intelligence provider service
    After you register a risk intelligence provider, you specify which of the provider's scoring or rating services you’ll use. You also specify how their scores or ratings map to your TPRM ratings.
  • Set up a request type for a provider
    After you register a risk intelligence provider and service, you specify the available request types that you and your organization will use.
  • Add a risk intelligence score to risk data for a third party
    You add a raw score from a provider to the provider service record for a third party. The system uses the mapping that you specified to normalize the value to the appropriate TPRM rating.
  • Automate actions upon risk intelligence updates
    A provider-based submission rule is a set of conditions and actions. In a rule, you can specify that an update to a rating from a risk intelligence provider is the condition that triggers the action that is specified in the rule. The action might be to create and send a third-party risk assessment, issue, task, or email.

Parent Topic:Integrating TPRM with other applications

Related topics

Viewing risk intelligence scores

Register a risk intelligence provider

Set up a risk intelligence provider service

Set up a request type for a provider