logo

NJP

ServiceNow Vendor risk management notes and videos

Import · Aug 16, 2022 · article

Create vendor risk assessment

2. Vendor Tiering (None, minor, low, Mod, High, Critical)

Risk manager role is needed to create a template

risk assessor can assign a template to a vendor to create VRA

Vendor -> assessment -> New

If template is not used, then select questionnaire and or document request

Assessments -> All open assessments -> New

vendor tiering assessment -> tiering assessment -> vendor tier

tier-based assessment submission rules -> vendor -> vendor tier -> assessment template -> auto submit to vendor

vendor risk assessment -> assessment template (if there is a primary contact)

Bitsight -1000, security scorecard - 600

provider-based submission rules -> score provider -> vendor -> security score -> vendor tier -> assessment template -> auto-submit to vendor

vendor risk assessment -> assessment template (if there is a primary contact)

scoring components for vendor risk rating

assessments assigned directly to vendor

risk rating on the assessment

3rd party score normalized rating

risk rating on child vendor

risk rating on engagement

engagement risk scoring rule

questionnaire risk rating

document request risk rating

risk rating on engagement

question rating = (value-minValue)/(maxValue - minValue)

question rating = 1- {(value-minValue)/(maxValue - minValue)}

questionpercentagecontribution

= questionweight / sumofAllQuestionweightswithincategory

questionnormalizedvalue = 100*questionrating*questionpercentagecontribution

categoryrating = sumofallquestionnormalizedvalueswithincategory

categorynormalizedvalue = categoryrating * (category weight / sum of all category weights)

questionnairequantitativescore = sumofallCategoryNormalizedValues

assessmentRating = AVG ((Questionnaire + DocRequest for risk area) * weightassigned to risk area + (questionnaire + DocRequest for another risk area)

* weight assigned to risk area) / sum of weights

If there are 18 categories and if they have same weight then normalized value will be 100/18 for all correct answers = 5.56

Vendor risk rating - breakdown

risk rating component breakdown

Vendor risk scoring rules

vendor risk area criteria

vendor risk component criteria

has association to components

weight (can be different)

weight = 100 ( from vendor risk assessment)

vendor risk area definition = Financial

assessment metric type = vendor risk area (Financial risk)

Risk area criteria - examples

risk area scoring method weight

Consulting partner criteria

Strategic partner criteria

Rank Tier -> strategic partner

Risk area criteria -> strategic parnter criteria

vendor risk scoring rule -> Strategic partner rule

Vendor risk assessment lifecycle

Draft = assessment is created

-> Submitted to vendor = assessment is available in vendor assessment portal

-> responses received = assessor can review results, return questionnaire to vendor

-> generating observations = assessor may begin generating observations such as creating Issues

-> Finalizing with vendor = oustanding issues and tasks are addressed with vendor

-> closed = assessment is complete and risk evaluation is documented in the closed state

return questionnaire -> give more time to complete

resubmit counter indicates how many times assessment is returned

platform assessment egine

questionnaire and document request template

identify calculations on assessment forms

**Vendor risk Issue configuration

Vendor risk life cycle = New -> Analyze -> Submitted to Vendor -> Finalize with Vendor -> Review -> Closed Complete

For internal use Submitted to Vendor -> Finalize with Vendor can be bypassed

Maual issue creation at question level

Vendor wont see until issue state is in Submitted to Vendor

Explanation is mandatory field before submitting to vendor

visible in vendor portal is checkbox used to display issue in vendor portal

questionnaire / document request template

Module = Issues -> Issue generation rules

assessment setup -> Issue templates and task templates

vendor risk issue -> Create task

-> Request additional information

Role : vendor risk manager or assessor

Vendor risk management workspace

Risk and Exception handling

Policy exception tab appears if GRC: Policy and compliance management is installed.

task ->planned_task -> sn_grc_issue -> sn_vdr_risk_asmt_issue --> Issue to question (sn_vdr_asmt_m2m_issue)

vendor risk assessment (sn_vdr_risk_asmt_assessment), assessment instance (asmt_assessment_instance), Assessment Instance Question (asmt_assessment_instance_question)

standard task generation based on an action

specific to accepting a risk

Vendor risk task configuration

can be created from issue, assessment or vendor record to bring issue or assessment to close

role :sn_vdr_risk_asmt.vendor_assessment_reviewer can create task from related list of an issue

role : sn_vdr_risk_asmt.vendor_assessor has option to create task from system navigator menu option

Open = risk tasks are created

-> submitted to vendor = vendor can see tasks in vendor portal

-> work in progress = work has begun

-> review = vendor risk team completes a final review and a final recommendation is made.

-> closed = task is updated and moved to closed status.

Table structure -> task -> planned_task -> sn_vdr_risk_asmt_task -> risk reviewer or above can raise task

-> sn_vdr_risk_asmt_assessment

-> sn_vdr_risk_asmt_issue

Vendor risk process Workflows

Vendor assessment reminders workflow contains various reminders to vendors based on duedate of questionnaire.

system policy ->Events -> Registry

sn_vdr_risk_asmt_assessment table has events -> email notifications

**Vendor portal configuration

system property = sn_vdr_risk_asmt.vendor_portal_endpoint = svdp

/vdp => bypass sso by default to true

/svdp => bypass sso by default to false

page svdp_login {bypass_sso = true}

primary contact can create additional contacts for assessments or for particular assessments

can create additional contacts and view their profiles

Menu options -> Manage team, Tour

once an assessment nd or document request is submitted to vendor primary contact can

invite others to collaborate

assign to another contact entirely

contacts cant be assigned after assessment is already been submitted

vendor contact support process

when a vendor is proposed they are assigned to a dept, tat dept is responsible for maintaining the contacts

on a regular frequency if we recieve a bounced email .. update primary contact

First incremental load which covers data from Jul-22 to Aug-02 are getting loaded, we have completed parent and child loads

we will be loading install base item and characteristics tonight at 8 PM MT

From tomorrow we will continue to do daily incrementals

**Application relationships

erviceNow Governance, Risk, and Compliance (GRC) helps transform inefficient processes across the extended enterprise into an integrated risk program.

Through continuous monitoring and automation, the GRC applications deliver a real time view of compliance and risk, improve decision making,

and increase performance across the organization and with vendors.

Primary applications in GRC

Common entity type from VRM perpsective is vendor

entity types * control objective -> entity (control) -> control attestation

entity types * risk statement -> entity (control) -> risk assessment

Vendor Risk Management integrates with the Policy and Compliance and Risk applications in ServiceNow to provide real time metrics

which affect an organization’s risk and compliance posture.

question (assessment metric) -> control objective -> control

vendor response -> control status will be compliant / non compliant

vendor risk assessment state dependency

control status is automatically updated after VRA state moved to finalizing with vendor or Closed

control -> registered risk (classic risk assessment process)

Other application integration

Control objective -> relate to assessment metric

-> controls for each Vendor

-> vendor risk assessment questions

Analytics for assessor, risk manager, executive

Labels:

View original source

https://www.servicenow.com/community/grc-blog/servicenow-vendor-risk-management-notes-and-videos/ba-p/2274288