logo

NJP

What’s new in Third-party Risk Management

Import · Aug 17, 2023 · video

awesome so we'll get started if anybody's coming in late that's okay um today's webinar is on what's new in third party risk management thank you for joining us and we'll get started right now so first thing I need to do is I need to go over the safe harbor notice um we try to be as transparent as possible in working on these webinars and so if there's any forward-looking statements about things that are too common the product just understand that some things sometimes plans change and we make our best intentions to make sure that everything that we're talking about today is delivered on time and in the way that we promised but sometimes changes shift or timeline shift a little bit and so we want to be make sure that you're conscious of that and understand that as you're going through the information please join us for future webinars um we've got a lot of opportunities in the community where you can join for an interactive event series and the link will be shared just a few minutes into the chat um and I will share that with you but to get started I want to introduce myself Rosalyn Marvel I'm the senior product marketing manager here working on vendor risk management and I need to change that to third-party risk management because today we are introducing our new third-party risk management product Stephanie is the senior product manager for that product and she brings a wealth of background to this offering both working as a servicenow SC so helping people understand how they can use the product um for several for several months you worked in that capacity and then last year transitioned to become our product owner so this is the first release where she's had full uh development uh oversight and I think you're going to be delighted by some of the attributes and features that she's bringing to the product Stephanie also has an extensive background uh starting in business uh intelligence and analytics but then spending nearly a decade in third party risk management specifically so there's going to be a lot of information that she can share with you both from a perspective standpoint and intimacy with the product that she's delivering today so definitely feel free to ask questions on that everyone's placed on mute when you start out but feel free to use the Q a feature to ask questions throughout the session we'll try to get to as many questions as possible but if we don't get to questions please use the community forum for ongoing conversations or additional questions that may come up after the session at the conclusion of the session we will give you a short survey and we really appreciate your feedback for improving our format as well as our content moving forward so everything we're going to talk about today is available in the store now the risk applications are all available and in order to go over some of those we did discuss business continuity Management in an earlier session today we're talking about third party risk management we're also going to talk about the risk management enhancements on the 17th we'll talk about compliance case management specifically on the 22nd and our sessions for risk for this release will conclude with policy and audit management and core features and functions that were brought to this release on August 24th so stay tuned for that and I will drop the link later in the chat to register for any Community sessions coming up meaning of why we're introducing servicenow third-party risk management now so we heard from our customers that there's a variety of expansion across Industries roles and increased scope across the organization for managing your third party risk we are building on the existing capabilities of the vrm product to better meet these customer needs so I want to assure you that nothing that was in the vendor risk management product is being taken away we're building upon this and enhancing and adding features content pre-configured workflows and things that are going to help you grow and mature your third-party risk program and we do introduce a new licensing and pricing model that we think is becoming more competitive and will be based on a value-based reward system for only charging you for how you use the product not based on vendors alone so if you need more information about that please talk to your rep because your rep's going to be the best person to talk about license and pricing we're really here to talk to you today about the features that are in the product so what is new with third-party risk management we are giving you a single source for all your third parties to cover not only your critical or high risk parties but all the third parties that you may have access to or impact your organization systems data your reputation or your assets we have a comprehensive system that's end to end with some new risk due diligence workflows that are coming out of the box we've got a pre-configured due diligence workflow as well as renewals additional due diligence off-boarding and Stephanie's going to show you all that in just a minute we also have some opportunity for cross-cola departmental collaboration on risk acceptance and we're providing that holistic view across multiple risk domains we're also improving visualizations of your third parties with a concentration risk map that will help you visualize where your third parties are within the world and Stephanie is going to get into that in a lot more detail and we're including some out of the box sample questionnaires across those multiple risk domains across Industries across regions that will give you a starting point or templates if you will to create those Sam those questionnaires that you need to send out to your customers based on where your third parties are based on where they are or what type of service they're bringing you or what industry that you're in so that's going to be a really interesting enhancement that I want Stephanie to talk about as well so Stephanie instead of just looking at slides can we get into a demo and show everyone some of the things that you brought in the Vancouver release that are available now in the store hello yes absolutely I would love to show you what we've brought into the store so let me go ahead and share my screen real quick give me one second can you see my screen okay thank you for the wonderful introduction my name is Stephanie and I will be going through a demonstration of our new product so the way our product works today is that we now are going to be using the employee Center to be able to go ahead and start um your different due diligence questionnaire or request so we have five out of the box workflows the first one is for onboarding a new engagement the second one is for reassessing a current engagement and the other ones are for off-boarding and I'll show you those in a second so the way it would work is is that an employee will go to the employee Center and they're going to be able to come out here and say oh I have a new project that's going to happen and we need to request due diligence on a third party so we want to go ahead and perform a on we want to onboard a new engagement so this is a brand new project then you can check that and ask you a question some questions reassessing an existing engagement this means that maybe you're currently working with a company and you saw on the news that the CEO is in trouble for something so you may want to do some reassessment of an existing third-party engagement to see how that's impacting you you also could do a reassessment for a reason such as the contract is going to come due in the next 30 days or 90 days and before you agree to renew the contract you want to do some due diligence now the other options are off-boarding and engagement with due diligence or off-boarding and engagement with no do digit no due diligence now these are very different um Scopes you may want to off-board a third party for various reasons the example I'll use is performance maybe you're having performance issues with a third party they're not delivering supplies when they're supposed to and it's impacting your supply chain so you would like to consider off-boarding them but before you do that since you've been working with them for a long time you may want to do some due diligence what you might find during the due diligence is the reason that they're late is because some of the materials they're sourcing are coming out of a conflict area you may decide at the end that it's actually riskier to change suppliers than to stay with the same third party that is having performance issues because even if you change suppliers they will also be sourcing the materials from a conflict area and they also will be late so in that case you thought you were going to go into this and off board but by the end of it you realize that you're going to continue to do business with this third party now all forwarding an engagement with no due diligence the purpose of this is is that maybe as an example it's a Consulting engagement and the project will be done at the end of the year or in a couple of months and it does not matter how good or bad they did there's no more work that needs to get done so you're going to off-board them and there's no need to do additional due diligence and this will Mark the the engagement as an active so you don't continue to do activity due diligence activity on them over the next coming years because you're no longer using their services what I will do is I will start to show you an example of onboarding a new engagement and the kinds of questions that will be asked so essentially you'll say I want to onboard a new engagement it will say what third party and you can go and look for an existing third party so let's say that this is um big Tech or Big Bear there's no big bear or there's only a big networks so that in that case you know it doesn't exist so you're going to say the third party doesn't exist and then you can go ahead and you will need to provide big cat information right here and you'll give the name of the third party and the engagement information so if you found the third party in there so let's say it's work faster in this case it will automatically fill in the key information about this third party and you won't need to so that means that that third party you're already doing business with them you have an existing engagement but you want to add a new engagement now this engagement might be for Consulting Services the way we Define an engagement in third-party risk management at servicenow is an engagement is either the product or the service that you're doing with this third party or it could be the reason for the interaction so you may be interacting with this company um for you know they could be your customer they could be your client they could be a partner there could be a lot of different reasons to interact with a company that isn't necessarily just a product or a service so the name of the engagement is going to tell us what that interaction is you're going to specify the types now you can have full control over defining your types these are just some examples out of the box um if you have Consulting in there with the exact same name it will say the engagement already exists so it will automatically put in today's date so that you can have a unique name for your engagement okay so it will adjust you're not allowed to have two engagements with the exact same names so this is the example of that here you would give the requested start date the purpose of the requested start date is for you to go ahead and create a request and go ahead and create a new name of it so it seps being concerned you can put in a request for a start date and a request for an end date the purpose of this is that you may want to you have to start this thing called Consulting engagement on October 1st so you won't get the work done and it might only be a three three month engagement now the amount of risk that that exhib that opens your company up to maybe less than if it was a 10-year request now here the irq this is going to be the purpose or the person that is familiar with the engagement that you're requesting and they're going to need to answer some basic questions about this engagement so that that will scope our due diligence that will get sent out so in this case maybe I want to say that it's able tutor and he's going to be the one that's going to complete this you can see that we have a third party address that's their corporate headquarters most likely that's already filled in um there will be a address that you can provide for the engagement just because the corporate addresses in California does not mean that this engagement might be happening in China or India or in in Oklahoma so whatever that engagement address is you'll want to put in here we'll talk about a map this is what will get mapped out there on the map is we're going to map out the engagement addresses we can see who the primary contacts are and then we can go ahead and make them the same as the engagement so you can either provide a new contact or you could use the existing engagement um or the third party contact and you can maintain multiple different contacts you also can send out questionnaires at the engagement level or you can send them at the third party level so after that gets sent out someone will approve the third party request to do to do due diligence on that particular third party for that engagement and someone like able Tudor will receive in the employee Center they'll receive an email but they're also going to receive a request to complete a survey this is that irq that we talked about that you chose the person who's going to receive it and it will be just a set of general questions out of the box I've provided about seven different irqs as examples they can be based on any sets of questions and the purpose of this is to scope out the next set what's going to get sent out to the third party so in this case if I say is the total spend of the third party greater than 50 000 I'm going to send out a financial due diligence questionnaire does a third party interact with government officials on our behalf if I say yes then we'll send out an anti-bribery and Corruption or a fcpa depending on if this is in the US or Europe and you can send out different questionnaires based on the different regions does a third party have access to organizational data if yes then you can ask a bunch of conditional questions is it sensitive data is it Healthcare data is it European data if it's Healthcare data then we'll send out a questionnaire for HIPAA if it's European data then it might be a GDP gdpr so this is just giving you some examples of different questions that you can ask that are more tailored um to that particular section which in this case is data and then you can make sure that you're sending out the right questionnaires to the right people does this third party manufacturer products that manufacture products on your behalf once again you can set up a set of conditional questions and then you may want to consider sending out a OSHA uh questionnaire or a supply chain question or an ESG questionnaire it could be highly dependent on those products and services that they're offering for you once they complete all of these different questions then they can submit it when this gets submitted and approved that's what's going to determine what gets sent out to the third party portal where you'll have the person that you're working with complete these different questionnaires on such as antibiotic option information security export laws and regulations whatever that is that based on this is going to help determine the type of information that needs to be collected these questions are all configurable and you get to determine that these are an example so this is what we would do from the employee portal is that we would go ahead and be responsible for answering irqs you can do requests for a third party um due diligence you can also track the requests that have been sent out so we can see that this guy able tutor also sent out two months ago a request to do a engagement or software for data he can go in here and he can see what states in there and he can ask questions um back and forth with the person that's processing this he can ask you know they can do some Communications you can say how close is this to being um you know approved things of that nature but he'll be able to see what is happening and where it is all right I'm going to close this out and then the next thing is so they asked the person that is requesting the due diligence and that's the person that's also potentially giving you the key information to make a determination of the type of due diligence that will get sent out I'll get to the risk concentration map in one second so here I have a new page we have a new page called the due diligence management when we're looking at this due diligence management page we can see all of the active processes that are currently happening so these are all of the different workflows right so these could be I'm going to scroll down here and we're going to see that it is based on the third party you can say I I like work faster a lot but we've also got some engagement requests for 3com and Acer and Adobe we have different request types as you can see here some of these were onboarding new engagements some of these we are requesting to do additional due diligence renewal of an engagement contract offboarding all of these are the different types of workflows that could be executed then you'll also be able to see what state they're in like this is a brand new request this is in the irq process which means that somebody has an irq in their employee Center that they need to respond to once they respond to it then due diligence will get sent out to the third party portal for them to complete up here what we're seeing is the different stages in the workflow so this is just showing us all the different processes the first stage is is that you're going to be in this new state which is when somebody just requests a new third party to do due diligence after that it goes into the irq state we can see all of the different here third parties that have been sent out or are being robust to send out different irqs in the due diligence section we're going to see all of the different third parties that have received in their third party portal different questionnaires to respond to so for example if I want to open one of these up I'll open up work faster this is what your approvers are going to be able to see and this is also what whoever is going to go through the contract risk process which I'll get to in a second we'll be able to see they're going to be able to see all in one place the third party due diligence request so that was what was completed on the employee Center all of the information that was provided there um out of the box we don't necessarily provide all of this on the employee Center you can always add more questions on the employee Center and add Fields here um basic third-party information so that was the address field websites things of that nature the type we can collapse these as well then we have the engagement basic information so this is you know what is the name of that engagement what type of Engagement it is and what the address is and then we can see all of the different risk ratings okay so in this case our inherent risk assessment came out as moderate this particular record has already or this request has already had an inherent risk questionnaire go out to the employee Center and as you saw they could answer those basic questions if I want to see what the answers are to those questions that made a determination of that particular score as a third party manager as an approver as a contract risk processor they can all come in here and they can actually go in here they can see the the actual questionnaire that was sent out how the scores are determined so we have the different scales for these scores and they can see if they wanted to see the details in there but if you wanted to open up that actual questionnaire this is the questionnaire that was sent out and this is the question here and the these are the answers to the different questions so you just saw me go through something similar to that right and there you go you can see the answers to the questions I'm going to jump back using my bread crumbs that was my inherent risk questionnaire that inherent risk questionnaire based on the questions the answers to those questions what will happen is that questionnaires will either get sent to the at the third party level so the third party contact and then those will be scored and kept at the third party level or the questionnaires will get sent out to the engagement uh contact and the scores will be rolled up for that particular engagement if I open this up I'm going to be able to see the different questionnaires that are getting sent out to the engagement person so we can see that this was submitted to the third party they responded to some things and now right now we're doing some finalizing with the third parties but you can see all the key information such as what are the details right you can see if there is any kind of um changes and who made the changes you can see that Alex news and he's the person that responded to the questionnaires he had some kind of comment and he wrote a comment in here and you can communicate back and forth between the third party portal in here if you'd like you can see at the same time all the key information that we collected during that initial from the employee Center I can also come out here and I can see the different questionnaires that were sent out and you can see what the risk ratings were so they've completed an fcpa and they completed it and it's a very low risk they also completed an export control questionnaire and we can go in and if we wanted to and drill down to see the different answers to that and we can see how this was scored if you wanted to we can look at the scoring within here so this gives us an idea the ability to go in and see all of that if there was a document request which there wasn't in this case then we could go ahead and see the document requests from here okay so these are some of the key things if you wanted to create an issue based on the questionnaires you can create an issue from here or you can create a task okay so I'm going to go ahead and I'm going to close this real quick here all right and if I go ahead and I close this as well okay we'll save that out okay so now everything is closed for this particular third party oh one thing I didn't show you here is the risk intelligence scores you also will be able to see um so the risk intelligence scores you'll be able to see for that third party these are all of we used to call them third party scores but now we call them risk intelligence scores one because it is a industry standard that a lot of um that is being used pretty frequently to represent the scores that you would pay to import in from like a bid site security score card in tarots these are just some examples of some providers you can bring in scores and their ratings and we label those as a risk intelligence scores and you can go ahead and you can see them right there okay so I'll save that right there now if I come back out of here Stephanie yes while you're going through the irq questionnaire uh commentary there is a few questions that came in around specifically around by our cues do you want to address those now or do you want to wait till the end I would love to I'm so sorry I don't know that's fine you are focusing on third parties sometimes large organizations utilize product services um you are focusing on third parties sometimes larger reviews so the first question is um we are focusing on engagements we're focused on the different engagements Associated to the third parties so we're not focused on the third party if I go all the way to the bottom how does the irq review and challenge work does it go through multiple risk domains risk sneeze to prove their sanction that's an amazing question and the answer to that is this out of the box is set up for one um one person to um approve airq but it can be easily configured and I'm making sure it goes into the product documentation it can be easily configured to do multiple different levels of approvers at the irq level so maybe somebody completes an irq and the compliance manager needs to approve it and maybe you need to have your information security manager approve it you can have multiple different people approve the irq process and it will be done by creating different risk levels and you can have up to 10 different risk levels so you can have it go through even committees if you want to is what that means so the answer is yes we can do that now the other question that was in here was about the irqs in the irq I have it set up so that it is sending it out for regions for example so there's several different ways that strategies that you you can use these irqs you can send out you can have one or you can have a hundred different potential irqs and these different irqs can have um be set up for I might have an irq for the US and another one for Singapore or another one for Europe or I might have a different irq for suppliers versus Partners versus clients or you could create an irq specifically for information security you could have an irq specifically for business continuity management now this is important because then you can create an inherent risk score for these different risk areas so I could have a inherent risk score for for um for financial or information security and then you can send out the questionnaires based on those individual risk domain areas so all of that is supported I'm not going to bring up the environment with that example at this moment but I just want to say it is supported okay and there's a ton more questions that you don't need to get to now but just one other question about the RQ is it mandatory during the request process um yes it is mandatory but um I'm trying to think why you wouldn't want it to be mandatory what you could do yeah I definitely think that's a question you know if you want to uh talk with your rep about a certain scenario or uh bring that to our attention offline because I can't think of a reason you wouldn't want to but at the same time you could slim down the irq to a very minimal um and and run through it quickly if that's not but there's so many benefits to it I'd love to dig into that deeper if you want to take that offline yeah you could create a you could create ways around it but out of the box it is mandatory great so sorry you could move on I know there's a ton of questions and we'll try to get to as many as we can and if we don't then we can continue the conversation the community after the webinar yeah well then I'm trying to go through webinar chat I lost all the questions for some reason uh the Q a give you an a separate oh right I came to chat instead thank you um the difference between the irq and hearing process how does DDD process different from classes brm great question so the irq is based on the tiering assessment um questionnaire capabilities so you will still create a tiering score with an irq the difference between a questionnaire uh the difference between a um irq and a tiering assessment is there is new capabilities that are added for the tyrinus for the irq that allow you to trigger questions off not just based on um not just based on the answers to or to the overall score but it'll be based on the specific answers so for example if I open this up and I show you that this is the onboarding questionnaire that we went ahead and went through it will show you the list of questions and the list of questions will be things such as is the total spent on this third party greater than 50 000. if you remember that question it's right here now there is the ability to actually say if the answer is yes send out the financial questionnaire all right to either the third party or to the engagement so each one of these questions based on if it's a yes or no will trigger out to send a different questionnaire out to the third party so you have more control over what is being sent out to your third parties now this is where have the flexibility comes in with the workflow so in this example if they answered yes to does a third party interact with government officials on our behalf then it will automatically send out a anti-bribrating corruption questionnaire now if you create an irq with a slightly different name let's say you create one that says Europe which I can show you the European one you can then associate different questionnaires that get sent out and this is essentially saying I can send out any of these different questionnaires based on a yes no answer so if it was Europe you might want to go ahead and send out a foreign corruption fcpa questionnaire versus here versus the antibiary corruption so this could be regionally focused this could be focused on um or it can be focused on risk domains which was another question that somebody had so another strategy around this is that the at the irq level you can associate you'll have a score for the irq here's a classification and the classification in this case is the irq template which is what will allow for that ability to send out questionnaires based on the answers to the questions but you can also associate these irqs to different risk areas so if you created an irq specifically for business continuity management and another one for information security you would associate different risk areas and then you would have a different inherent risk score for each one of these and then you can have different people answer these irqs so you can send out multiple different irqs once again this is there's lots of different strategies to use this but the irqs are actually what will drive the process yes okay um how does the morning work during RFP meaning one engagement can provided by multiple third parties uh um we have some other products within service now just you know where we have a a new product line for procurement and there are some other capabilities during the early stages of onboarding that would be covered more from a procurement part a product including like awards for shortlisted third parties where after you've shortlisted it we're doing the due diligence aspects of this or they can do the short listing after they do the due diligence and we can integrate with the different um products to go ahead and send all of the key information in into them um is the irq feature able to calculate inherent for each risk domain area I already answered that and then aggregated up the answer is yes you can do it for different risk areas and the way you would do that is you'd create multiple irqs and then you would roll those up together to create one inherent risk score um isn't it confusing engagement here and then also under audit in around here okay that's a different question um we've always had engagements and we had engagements in brn so we're just continuing the engagement concept and we're just uh focusing more on the engagement level that at the third party level and the reason we're focusing at the engagement level is because each time you interact with a third party differently it exposes you to different risks and you're going to need to do different types of risk assessments on a third party if you have them managing your data versus if you were just buying servers from them so depending on what you're doing with the third party will make a determination of the type of due diligence that you will need to do and the level of due diligence that you will need to do and um the third party can access Tech of questionnaires in snow even without a snow a user account uh no to get access to the third party portal you would need to go ahead and um they will be added as a user to the third party portal and they'll need to log in there so they will need a user ID to use a third-party portal and when you collect who your third-party contact is and do your third party engagement is our engagement uh contact is that's how those IDs will automatically be created for them it will be based on their email okay so um are there any features being handled to handle ongoing monitoring and termination so termination is going to be focused on um you know if you want to go through those workflows to terminate those but in addition to that we will be in the next release coming out with ways of setting up Mass um questionnaire or mass enrollments for um your third parties so for example if you had 10 000 third parties and you knew that on an annual basis whenever a insurance document was going to come due you needed to once it started to expire you would need to request 90 days before the expiration date and new insurance document then it will automatically watch the insurance expiration dates for all of the third parties that you put in scope and we'll send out a request if you know that you want to send out a sync questionnaire to them on a bi-annual basis if it's a supplier that's medium risk or low risk that is in a certain country whatever you want to do you'll be able to set up the criteria it will automatically recognize any third party or the engagement that fits that criteria and send out the request based on a scheduling so you don't have to do those on a one-on-one basis anymore starting in February that will be our new feature to handle larger sets of third parties what if a third party yes is it possible to go through a little bit about the risk concentration map and a few of the other features down the irq there's so many good questions that keep coming in um but I want to make sure that we get to a few of the other exciting features that you've put in uh that's okay no that's fine thank you so much for spending so much time on that I know it's a important feature and I think that people will really be excited to start using it it will be it is actually um a huge Improvement and it will give you a significant amount of um control and hopefully I've hit on some of those points so the next thing here is before we get here I do want to complete this which is so we talked about going to the due diligence process then it can go through the approval process now the approval process can have multiple levels of approvers you can have um 10 levels of approvers that can happen can you can have concurrent and sequential approvals that is a new feature that's coming out and in addition to that after it's approved you can either say that it's approved and you're done here or there's an optional step and here this optional step you can send it to what I'm going to call like Risk contract risk process person and this is a differentiator of ours is that you can have somebody in either legal or procurement log in here they can you know get to this they'll be able to see all of the key information they'll be able to see the questions and answers to the inherent risk question assessment they'll be able to see the questions and answers to the um completed questionnaires they're going to be able to see all of the risk intelligence scores they're going to see who were the approvers you know and they can go ahead I'm not logged in as the contract risk person but if I was they would have the ability to upload the contract say when the contract expiration date is and when the start date is and they can go ahead and say that that contract that they had completed executing their contract and everybody will be notified when they complete their part this is an optional step to bring in that person but you now have a way of giving them a self-service environment to get all that key information in one place now overall what this is is that this is really cool we have a concentration risk treatment death and I can go ahead and I can see all of my different third parties that are out here engagements and we can go ahead and if I want to see those buy a third party level I can go out here and put in maybe if I wanted to say work faster I would be able to map out all of the different um engagements that work faster has which as you can see I have nine of them and I would be able to see all of those different engagements out here and we can go in and see the information for these different engagements and bring it in okay this is if I wanted to jump back into the workspace to see more details on that particular engagement I can always kind of jump back in here and I can see all of the details on this particular engagement we can see how it got to be high risk it was high risk due to the security risk and the reputational risk it was a security risk that brought it into high risk and if you wanted to go ahead and see the different questionnaires that were completed and the assessments you would be able to see that here at the main engagement page okay we have 15 minutes left I'm trying to think what else I have for so the employee centers new and huge the map is new and huge the overall due diligence management of the workspaces uh or I'm sorry all the different of the workflow to Swatch it go through this is new um and when we go into the list view the irq is new because it gives you more control of what's being sent out and then the list views you're going to be able to see such as like all of the due diligence that were requested and you can open those up and you can see what's happening in each one of these different due diligence um uh sections so those are our new main features that are coming out one thing that I didn't mention is that we now have the ability as a third party manager if you want to allow the third party manager to respond to questionnaires on behalf of the third party so for example you sent out them sent them questionnaires to their portal if the company says I'm not going to respond log into your portal and they send you an email with their responses then you can now look at that email look at their attachments you can attach things on their behalf you can answer questioneers on their behalf of course you want to you know message put that in the comments and everything and submit it on their behalf because we are aware that there are some companies that have a company policy where they will not log into these different portals so that has also been addressed in this some other things that have been addressed in here is is that you can now tie risks and controls at the engagement level because our new focus is going to be at the engagement level not at that third party level and then let's see I think that is a lot of our main new features is there anything else that you'd like me to cover for us if you um this question if you could just talk about how reassessments are kicked off is the engagement requester will they Autobot be notified to complete the reassessment um or how does that work or would they send uh to them individually can you just talk a little bit about reassessing a third party yes so the reassessment at this time the way it would work is um you can have questionnaires sent to the third parties portals automatically based on a schedule you can send out questionnaires based on like events you can set up business rules or if you wanted someone in on the business side to drive the reassessment so let's say that this is something that wasn't scheduled it was off um off schedule they have the control to come out here to do a reassessment and they will say I want to re reassess um the cloud MSP third party and then you got to say which engagement um well there's data center we here there was a data breach right and then you can go ahead and then in this case you would use an irq and the reason for this irq is because we don't know why we're doing an off-cycle reassessment and that this is really focused and you can see that it's automatically bringing in the address it's automatically bringing in any of the key information that was already out there okay and filling this in and this is really going to just send out an irq you can specify the questions and based on the answers of the irq it will send out those questionnaires so it's just another way of reassessing a third party if you want to do it off cycle um you can also if you if it's based on a contract renewal you can do it on that you may have a different irq that's driving this hopefully that answers your question yeah um I think we've got a lot more questions coming in um I'm sorry the question was also about on-cycle reassessments does that make sense to you yes and cycle so it would so the purpose of going to the employee Center is to really um do it manually and then for someone to complete an irq so then that's going to be you know they're requesting it but we have the ability to schedule an automatic reassessment so if you want to schedule it on an annual basis then you can like just use our scheduler this is if you want to manually trigger it uh if you want to manually trigger it to kind of override the automation hopefully that makes sense and not to put you on the spot but do you possibly have the release notes near or handy as I go through the last slides if you don't that's fine we can get back to if Edward would put his email address just to the hosts um not have those handy but I might be able to get them if you give me one second uh if you can that would be great if you can't I'll just go through the rest of the slides and if Edward wants to privately message uh your email address just to hosts and panelists in the chat um we'd be happy to send you that link afterwards sorry about that or we could get that and just yeah automatically send it to everybody if needed if you have a way to automatically send it all right do you have any other I can see we have open questions do you want me to hit these or do you want to do your final slides if you can answer any of the rest of the questions I'll we can take the time the slides are Superfluous to your expertise and interest so go for it what if a third party engagement changes from A to B in such a scenario what changes will be required not sure if I understand that question I didn't understand that either Charles if you want to send us a email with that or um take it offline we can do that so send us your email address and I'll give you an email address to send it you have the ability to reopen an irq if you want to you can reopen things um during a reassessment can you send previously um responded a completed question here so the vendors do not have to complete them that we will have in the next release that will be a new feature on the next release but it is coming so the answer to that is yes soon well next release not now all right why don't you go this is a lot of reading we only have six minutes why don't you go ahead not a problem if people have additional questions please feel free to put them in the community because I think that that's one of the best places to do uh conversations about this um so that everyone can benefit the answers otherwise um you can email me at rosalind.mourville servicenow.com and I'll try and Route it to the right person but as I said I think the community is a great place to answer some of those questions and we'll take some of these and see if we can uh develop content around uh some of the more generally uh applicable ones so thank you so much for the demo Stephanie uh it was great information as we said you know this is enabling you uh with the new uh third-party risk management uh upgrade from vendor risk management it's really uh allowing people to manage those different types of all types of third parties um that Stephanie mentioned uh you know not just vendors and suppliers but also your partners your counterpartners your Affiliates your franchises whatever type of third party you might be dealing with across the entire third-party risk management life cycle so it's really exciting to introduce these enhancements to you guys the concentration risk map you can see another picture of that here it's a great way to visualize the concentration risk globally and to understand the impact of your engagements across your third party ecosystem and a lot of the out of the box content and workflows should really help your team increase productivity so we're super excited to introduce this release to you thank you we answered a ton of questions we are close to time so I want to be respectful of people's hour that they gave us but if you want to join us for future servicenow events uh there's a link to additional webinars and content here I did put the GRC events in the chat and I'll follow up with folks emails once we uh move forward and thank you so much for your time Stephanie thank you for giving us such great insight into the product as a whole um we really appreciate the time that you have um and that you can share those uh you know kind of the directly applicable changes um the features come a lot from customer requests and enhancements so keep them coming we really want to make sure that we're servicing you um and introducing products so that it's going to be competitive but really so it's meeting your needs today and in the future so thank you so much Stephanie for your time uh thank you everybody for joining us and as I said if you have additional questions uh commentary uh we'll try back get back to some of these other question additional questions um in content moving forward so thanks so much Stephanie have a great day and everybody please have a fantastic afternoon thank you

View original source

https://www.youtube.com/watch?v=wWb9Yp7TDQQ