ServiceNow Vendor risk management notes and videos
Create vendor risk assessment
2. Vendor Tiering (None, minor, low, Mod, High, Critical)
Risk manager role is needed to create a template
risk assessor can assign a template to a vendor to create VRA
Vendor -> assessment -> New
If template is not used, then select questionnaire and or document request
Assessments -> All open assessments -> New
vendor tiering assessment -> tiering assessment -> vendor tier
tier-based assessment submission rules -> vendor -> vendor tier -> assessment template -> auto submit to vendor
vendor risk assessment -> assessment template (if there is a primary contact)
Bitsight -1000, security scorecard - 600
provider-based submission rules -> score provider -> vendor -> security score -> vendor tier -> assessment template -> auto-submit to vendor
vendor risk assessment -> assessment template (if there is a primary contact)
scoring components for vendor risk rating
assessments assigned directly to vendor
risk rating on the assessment
3rd party score normalized rating
risk rating on child vendor
risk rating on engagement
engagement risk scoring rule
questionnaire risk rating
document request risk rating
risk rating on engagement
question rating = (value-minValue)/(maxValue - minValue)
question rating = 1- {(value-minValue)/(maxValue - minValue)}
questionpercentagecontribution
= questionweight / sumofAllQuestionweightswithincategory
questionnormalizedvalue = 100*questionrating*questionpercentagecontribution
categoryrating = sumofallquestionnormalizedvalueswithincategory
categorynormalizedvalue = categoryrating * (category weight / sum of all category weights)
questionnairequantitativescore = sumofallCategoryNormalizedValues
assessmentRating = AVG ((Questionnaire + DocRequest for risk area) * weightassigned to risk area + (questionnaire + DocRequest for another risk area)
* weight assigned to risk area) / sum of weights
If there are 18 categories and if they have same weight then normalized value will be 100/18 for all correct answers = 5.56
Vendor risk rating - breakdown
risk rating component breakdown
Vendor risk scoring rules
vendor risk area criteria
vendor risk component criteria
has association to components
weight (can be different)
weight = 100 ( from vendor risk assessment)
vendor risk area definition = Financial
assessment metric type = vendor risk area (Financial risk)
Risk area criteria - examples
risk area scoring method weight
Consulting partner criteria
Strategic partner criteria
Rank Tier -> strategic partner
Risk area criteria -> strategic parnter criteria
vendor risk scoring rule -> Strategic partner rule
Vendor risk assessment lifecycle
Draft = assessment is created
-> Submitted to vendor = assessment is available in vendor assessment portal
-> responses received = assessor can review results, return questionnaire to vendor
-> generating observations = assessor may begin generating observations such as creating Issues
-> Finalizing with vendor = oustanding issues and tasks are addressed with vendor
-> closed = assessment is complete and risk evaluation is documented in the closed state
return questionnaire -> give more time to complete
resubmit counter indicates how many times assessment is returned
platform assessment egine
questionnaire and document request template
identify calculations on assessment forms
**Vendor risk Issue configuration
Vendor risk life cycle = New -> Analyze -> Submitted to Vendor -> Finalize with Vendor -> Review -> Closed Complete
For internal use Submitted to Vendor -> Finalize with Vendor can be bypassed
Maual issue creation at question level
Vendor wont see until issue state is in Submitted to Vendor
Explanation is mandatory field before submitting to vendor
visible in vendor portal is checkbox used to display issue in vendor portal
questionnaire / document request template
Module = Issues -> Issue generation rules
assessment setup -> Issue templates and task templates
vendor risk issue -> Create task
-> Request additional information
Role : vendor risk manager or assessor
Vendor risk management workspace
Risk and Exception handling
Policy exception tab appears if GRC: Policy and compliance management is installed.
task ->planned_task -> sn_grc_issue -> sn_vdr_risk_asmt_issue --> Issue to question (sn_vdr_asmt_m2m_issue)
vendor risk assessment (sn_vdr_risk_asmt_assessment), assessment instance (asmt_assessment_instance), Assessment Instance Question (asmt_assessment_instance_question)
standard task generation based on an action
specific to accepting a risk
Vendor risk task configuration
can be created from issue, assessment or vendor record to bring issue or assessment to close
role :sn_vdr_risk_asmt.vendor_assessment_reviewer can create task from related list of an issue
role : sn_vdr_risk_asmt.vendor_assessor has option to create task from system navigator menu option
Open = risk tasks are created
-> submitted to vendor = vendor can see tasks in vendor portal
-> work in progress = work has begun
-> review = vendor risk team completes a final review and a final recommendation is made.
-> closed = task is updated and moved to closed status.
Table structure -> task -> planned_task -> sn_vdr_risk_asmt_task -> risk reviewer or above can raise task
-> sn_vdr_risk_asmt_assessment
-> sn_vdr_risk_asmt_issue
Vendor risk process Workflows
Vendor assessment reminders workflow contains various reminders to vendors based on duedate of questionnaire.
system policy ->Events -> Registry
sn_vdr_risk_asmt_assessment table has events -> email notifications
**Vendor portal configuration
system property = sn_vdr_risk_asmt.vendor_portal_endpoint = svdp
/vdp => bypass sso by default to true
/svdp => bypass sso by default to false
page svdp_login {bypass_sso = true}
primary contact can create additional contacts for assessments or for particular assessments
can create additional contacts and view their profiles
Menu options -> Manage team, Tour
once an assessment nd or document request is submitted to vendor primary contact can
invite others to collaborate
assign to another contact entirely
contacts cant be assigned after assessment is already been submitted
vendor contact support process
when a vendor is proposed they are assigned to a dept, tat dept is responsible for maintaining the contacts
on a regular frequency if we recieve a bounced email .. update primary contact
First incremental load which covers data from Jul-22 to Aug-02 are getting loaded, we have completed parent and child loads
we will be loading install base item and characteristics tonight at 8 PM MT
From tomorrow we will continue to do daily incrementals
**Application relationships
erviceNow Governance, Risk, and Compliance (GRC) helps transform inefficient processes across the extended enterprise into an integrated risk program.
Through continuous monitoring and automation, the GRC applications deliver a real time view of compliance and risk, improve decision making,
and increase performance across the organization and with vendors.
Primary applications in GRC
Common entity type from VRM perpsective is vendor
entity types * control objective -> entity (control) -> control attestation
entity types * risk statement -> entity (control) -> risk assessment
Vendor Risk Management integrates with the Policy and Compliance and Risk applications in ServiceNow to provide real time metrics
which affect an organization’s risk and compliance posture.
question (assessment metric) -> control objective -> control
vendor response -> control status will be compliant / non compliant
vendor risk assessment state dependency
control status is automatically updated after VRA state moved to finalizing with vendor or Closed
control -> registered risk (classic risk assessment process)
Other application integration
Control objective -> relate to assessment metric
-> controls for each Vendor
-> vendor risk assessment questions
Analytics for assessor, risk manager, executive
Labels:
https://www.servicenow.com/community/grc-blog/servicenow-vendor-risk-management-notes-and-videos/ba-p/2274288