What’s new in Third party Risk Management
so we're just at the top of the hour um I'll give people one more minute to roll in if you want to say where you're from um in the chat we'll use chat for conversation and the Q&A for any questions so that we can track that and follow up with any questions after the session if we don't get to them on the call I guess I can't complain about the cold if they've got people calling in from Minnesota it's early out there in California so welcome and uh Charlotte North Carolina Tennessee uh Brazil I've always wanted to go to Portugal it's on my list I've been to Canada so we'll get started in just a second so definitely want to welcome you um we'll let people roll in quietly um on and if you want to continue in the chat that's great we'd love to converse with you and talk with you throughout the session um I will put a link to all of our upcoming events in there as well shortly after uh I do the introduction but let's get started on what's new in thirdparty Risk Management um and I do need to quickly go over our Safe Harbor statements um and just make sure let me know if you can't see my screen or if there's anything that uh looks a little funky but um for Safe Harbor uh notice and forward-looking statements we do try to be as open and transparent with these sessions on what we think is coming um what we want to introduce the product but as you know um we can't always guarantee that we achieve those plans on time or meet the expectations that we've set in these sessions so please just understand that things could change um in new products or features as we introduce them you're joining us for live on service now uh event series um today's session is part of this curated Series where we connect with on Ser when service now experts and peers so you can help deploy your products better and Achieve value faster um we want you to join us for as many webinars and meetups as possible so you can scan the schedule with a QR code or as I said I'll put a link to the current GRC blog post which gives you past events which you can um see things on demand or sign up for futur EVS so definitely check that out once I put that in the chat couple of housek uh I'll introduce folks and then I'll go through the housekeeping Stephanie Greer is joining us today um she's the senior product marketing manager for thirdparty risk management she and her team are responsible for bringing together um the road map and projecting out and delivering on all of the great features and functionality that you see coming in tprm from the transition to vrm to tpr RM Stephanie has been leading this march to really broaden the product um and our scope and what we can deliver to customers and I'm really excited every time we have her on because she's got a wealth of Knowledge from having history um and a variety of competitors and being in the space for um a great deal of time so definitely uh rely on Stephanie ask questions and make sure that you're uh using her time wisely because she's very busy but she does try to make as much time for customers as possible possible and these sessions are great for getting some of your questions answered so welcome Stephanie for housekeeping everyone's on mute um as I said please use a Q&A feature to ask questions throughout the session um the session will be recorded and shared on the service now Community Forum afterwards and if a survey prompts up at the end of your session please just fill that out so that we can get more insight into future sessions that we deliver for you um excited to let you know that all of our new risk applications everything that we're talking about today and in some of the uh sessions that I'll show you uh shortly um are live now in the store so you can access those live now on demand sessions we've got uh we've done our privacy management uh which we released as a standalone uh product offering um but we do have another privacy management uh session coming up at the end of the month that will go more into our radar first integration we also already discussed risk management um definitely check out the on demand for that um I was in the business continuity management and that went uh almost an hour as that usually does with a variety of questions and a lot of interaction so definitely check that out if you're interested in business continuity man management we've got continuous authorization and monitoring coming up compliance and audit and as I said the radar first privacy session should be a good one because that's with our partner So today we're just going to go over briefly uh the third party risk management enhancements we've got some enhancements around the um employee Center ongoing management and autop population of questionnaires but rather than go through slides and talk about that I am going to pass this over to Stephanie so she can walk you through the features in a demo so Stephanie if you want to take control of the screen that would be great absolutely one second me share my screen and I can see the vendor vendor management workspace fantastic all right thank you everybody and I'm so glad that you could join us today and Rosen thank you for the excellent introduction and as rosin pointed out uh I have been in the space for um about 13 years worked as several competitors um I've known Roslin a long time because she's also been in the space for a long time so we met prior to being at service now to bring thirdparty risk management from service now to everybody her and I did this together so some of the things as you know in August that were released which was our Vancouver release was we are moving from vendor risk management to third party risk management one of the major changes with that is is US providing you the full life cycle of workflows from onboarding reassessment contract um renewals over to offboarding with due diligence and off due diligence what this page is that you're looking at today is a due diligence management page so it's allowing you to watch all of these workflows that um go through and what stage they're in so we have um as you know all active processes I'm going on the assumption that most of you have seen thirdparty risk management but there are probably some of you on this call that have not so I am going to re-explain some things that we talked about in August just to ensure that everybody knows where we're at so all active processes these are all of the workflows that are sent out so we have the third party and the engagement everything is engagement driven within third party risk management agement working on the assumption that most cases companies have a reason to do business so the way that we Define engagements within third party risk management at service now is an engagement is a product it is the service provided or it is the reason that you are engaging and there should always be a reason in which you are engaging with the third party even if it is just to assess them for a preferred vendor list then the reason you're engaging with them is that you're assessing them to be on the vendor um the preferred list so the engagement should be the name of the reason that you're doing business with them and then that will drive the type of due diligence that you will do against this third- party engagement so the first part in this process is the new requests now this is something that we have driven from the employee Center so when you go to the employee Center we can go ahead and we can do our new request from the employee Center um so and when you do that it will come in to your surveys and you'll now have the ability to get to this from the employee Center to request to do third party um to request to add a new third party engagement so the new requests will come into this card right here in which the third party manager can see how many new requests that you have now before we had the new requests just being in the all active processes So within this new release we've added this card here for new requests once you approve the new request it will go into the irq process which will send out a questionnaire to the employee Center to the appropriate person that has the business knowledge of that engagement to complete the irq which will be a set of questions in the February release the irq allows you to send out questions based on the answers of individual questions and you can send out additional questionnaires to your thirdparty responders another new feature that we have in February is that we do have a tier that will be updated so you can set up your scoring in the irq and you can set up a tier whether or not it's high medium or low and with business rules you can define whether or not you want to send out them if they're high medium or low we will have May release coming out soon where you'll be able to Define that within the irq but for now um you'll need business rules to manage that process but it'll soon be updated so it'll be within the irq to manage the questions and the risk level at the same time once the questioners are completed by the responder in the employee Center then you can look at the questioners that are automatically going to go to your third parties or to your engagements and you can take out some of those questionnair if you'd like so if I open up one of these onboarding questionnair you're going to be able to see that you'll be able to sign questionnaires so first off this is the inherent risk assessment that was um sent out for the onboarding and after that is complete then you'll have the ability to go ahead and send out thirdparty risk questioners and see the risk intelligence scores Within that iute process once you decide on the questioners you want to send out they'll be in the due diligence process during this due diligence process it will go out to your thirdparty engagement contacts or your third parties and you'll be able to see what questionnaires will go to each one of those the next stage that we have added in here is we have the approval process after the due diligence requests come back we have an approval process that came out where you can set up up to 10 different levels of multiple different levels of approvers within your company to review the questioners that are coming back you have an optional step of a contract risk process so that you can send all of the information that you have collected to go and allow either your legal team or your procurement team whoever is your legal process whoever's handling the contract and they can come out here they can see all the ANS to the inherent risk questionnaires they'll be able to see all of the answers to the thirdparty risk assessments that went out to the third party or to the engagements if there was any risk intelligence scores they would be able to see that and they'll be able to see the approvers who has approved it in this case only one person was required to do an approval so um that is how um that was handled and they can then go ahead and make comments or upload a contract when they log in after they review all of this information so that'll be all in one single place the reason that we have this new user to log in and see this information is there's been requests and it's been a longtime paino for customers to create reports with all of this key information and get it to their legal team this allows them to log in and see everything that they want now what we added was after the contract risk person goes ahead and um approves that they have a contract that they've put in place or if you've skipped that step and we've just gone through the approval process then your thirdparty risk manager does need to do a final process review so they'll go through review what everybody has done and then they will close this so the new stages is we now have the final review process card here which we didn't have before and we have this new request card before they just fell within the all active processes so that makes it a little bit cleaner for you to work through this entire work workflow are there any I see some questions in here we have a custom we will cover assessments for how we cover assessments for established third parties um will we cover assessments for established third part so now what I think your question is is can we do a reassessment so here you can see the request types the question that I have in the chat session is will we cover assessments for established third parties now a new third party is when you onboard them or a new engagement is when you onboard them but we also have a workflow for reassessing an engagement and that is for an established third party so when you go into the employee Center you have the ability to go ahead and um choose that you want to reassess a third party and when you do that that's how you manage the that's how you manage existing third parties does that answer the question can [Music] you respond if that answers it we have a couple of questions and the there's a post in the chat as well can you talk a little bit about the difference between tearing and irq absolutely so right now that's an excellent question so for right now the main difference is is that a tiering assessment is only used to do a tiering where you come up with high medium and low and you can send out a group of questioners based on high medium and low it is not currently being utilized within the workflows instead when you upgrade your processes if you have an existing process and you're using existing um tiering assessments they will continue to work and all your processes will work as they have always work now when you go to an irq an irq has some additional capabilities and the additional capabilities that they have is that you can now Define within an irq whether or not something is a um I'll I'll open up an irq for you in in one second let's see here let me come on over here I have some irqs let me do that instead of describing it so out of the box if you load the sample data I will provide you a bunch of sample irqs just to give you an idea of how to use them so there's an onboarding irq as an example I have some offboarding examples and I have a example of additional due diligence so this is for that reassessment uh those assessments aha awesome thank you let me go back here so I went into the questionnaires and I did a search for irq if you load the demo data when you install thirdparty bris management you'll get these example sample questionnaires I have about 61 of them out of the box of different sample questioners and I have um it looks like I have about seven or eight irqs as examples so you can go ahead and take a look at these we have onboarding ones you can see that they say onboarding on them and these are examples okay so that means you need to create your own IQs but at least you have something to follow somebody asked me about how to handle um third parties that already exist well that's where we have an irq for like a renewal or reassessment or if you want to offboard them I have some questionnaires for offboarding them so if I open up the irq let's say for a renewal the difference that you're going to see is that when I go into my renewal questions um you can see here does this third party have access to organizational data if the answer is yes it's going to reveal these other questions three a b c and d now the first question that they would receive is do they have access to sensitive data now if I open this question up let's see here it looks like it's freezing up on me real quick here it's going a little slow there we go then you can set up this here where it says if the answer to this question which is um do they have access to sensitive data my description in here is as my example is it triggers a n questionnaire so I come down here and I can say NIS sample questionnaire if the answer is yes send it to the third party let's say that we wanted to do something like say I their answer is no I could choose a different questioner maybe if they said no I want to send it to a I don't know why I'm being picky about this right now I can really just pick any question here um let's say I want to send them that wouldn't make any sense but I'm going to just choose it for my example I would send them my OSHA questioner and maybe I want to send it to the engagement if the answer is no okay so I do know that this example doesn't make sense but I am coming up with it on flly so here if my answer to this question was yes they would get the N sample question here if the answer was no then they would get the oosha sample questionnaire in this case it would go to the third party contact in this case it would go to the engagement contact okay I'm not going to save this example because it would never want to it wouldn't be between those questioners I can pull up another questionnaire to give you a more reasonable example real quick here so let's say I open up the EU onboarding irq questions you're going to see that the difference between the irq for for the EU if I open this up and the US one is that my questions might be very very similar but I may send out different questioners to you European customers than I would to for us customers so in this case the irq question is does this third party have access to organizational data and then the question here is do they have access to European data now if they have access to European data then we would want to send out the gdpr but let's say that the answer into this one is no then we would want to send out a questioner such as the California um the California uh app so let me see if I can get that real quick I think it's CCPA CCPA s the CPR sorry sorry yep I know I have it in here so now this this example makes a little bit more sense so and I the reason I wanted to interject in that um I wanted to make a comment all these questionnaires are sample questionnaires correct so Stephanie's team has done uh primarily Stephanie um has put in a ton of examples and samples that you can draw from we' always recommend that you go through those questionnaires look at the questions make sure they're appropriate for your audience and or review those with your legal team to ensure that that's written in the way that your customers would understand it and that it would be um binding for your organization so just want to put that caveat out there there's a whole whole host of different variety you know different different for countries different for Regions different for types of organizations but definitely make sure that you're reviewing those questionnaires um because we can't be legal authorities absolutely so so that is the purpose of it now with the irqs to use these irqs within the workflow you can use multiple irqs and then based on the answers to the questions when they request to start the workflow you can have business rules automatically choose the appropriate irq which is why I have so many different irqs in here so I could have 50 different irqs if I wanted to okay and if it was a supplier in Asia I might want to have one irq set up if it was a supplier in Europe I might want to have another irq set up and the reason that it's a good idea to break this up into multiple different irqs based on the subject level maybe maybe by region Maybe by type of third party maybe based on type of Engagement whatever it is that makes sense for your business is that this way you can send out the least amount of questions to the person that is completing the irq as possible right so that it's more efficient because there is a big issue throughout the industry right now of what's called vendor fatigue um and it's not just your vendors that are fatigued by all the questionnaires but it's also your internal users that are fatigued by having to review all of the questionnaires so if you do The Upfront work and planning of the different types of scenarios that you could have and the types of questionnair and then just send out these the least amount of questioners as possible then this is going to help you manage that process of people being able to answer fewer questions so the onboarding for the EU the difference between that one and I have a generic onboarding irq is that if I look at my questions in my generic one which was really more focused based on the US is that I did not um you know I might have the California question in here where I didn't have that for the one that was just dealing with Europe right so do they have access to California customer data right and then that automatically sent out my CCP where the European one sent out my GDP hard so currently the way this The irq Works is somebody answers these questions and if they answer yes or no to the questions then it will trigger out the appropriate questioners now you can also set up the tier and with a business rule maybe you only want to send out the appropriate questioners if they're high medium or medium that is something that can be set up now the difference will be coming in May is that when we we're going to have this set up a new feature that will come out soon is is that I'll let you define the level instead of just yes no I'll also allow you to set up if the tier is high medium or low and the answer is yes then send out the question here and then you can put in multiple logic within here so that will be coming very shortly um in the next May release so that is how we use the irqs now something that another new feature that we have is that we have the ability to prepopulate questioners so this is a questioner template for my PST D2 payments now remember all my questioners like Rasin brought up are sample questioners so that means that these are samples for you to review but it doesn't mean that you should you know use these questions to run your program you definitely need to review the questions come up with your own questions and have legal review um so the new capability is include previous responses so that means is if this was sent out last year when you resend it out it will automatically bring in the responses from the previous year for the third-party vendor to start with their existing responses from the year before for them to review and make changes They will receive a message when they receive this question year that says um these have been prepopulated from previous results okay so this is an example of the questions that have been sent out okay like does your organization will provide payment services to customers and things like that if there was any answers these will be sent out to the appropriate third party just to kind of give them um a starting point and the whole point of this is to help alleviate some of that vendor fatigue that we're seeing in the market today okay um I wanted to bring up one other thing with the um irq because you can see here that we have a third-party risk area of compliance risk um we in the future will be changing this to risk domain a risk arean risk domain and third party risk management is the same thing but I'm slowly going to change some of the terms to some of the things that are um more commonly or more standardized in the industry because a there are a lot of different names to um a lot of different names for the same thing so let's go ahead and go in here and let's say I want to open up this Singapore onboarding question here you can see the third party risk area is set to default if I take a copy of this per se of course I lost it I call a copy so now I have this copy of this irq so I can make changes to this okay and let's say that I want to have this set up specifically for environmental risk or anti-bribery and Corruption risk or business continuity risk I can go ahead and have this here for my business continuity um business continuity irq for Singapore onboarding process I would go through my questions here and then I would probably want to delete all of my questions that don't have anything to do with business continuity right and then make sure the person that has um that receives this irq is the one that is responsible for business continuity and this way you can send out multiple different irqs and you can do it based on the risk area okay so in this case I would create a irq potentially based on the risk area it will then create a um score for that irq and this will allow you to create an inherent risk for business continuity an inherent risk for ESG an inherent risk for financials it will then if you sent out five different irqs per se um with different questions spe specifically for each one of these risk areas your total irq score or your total inherent risk score will be an average of all of those but this will allow you to break up the down to the risk domain area for inherent risk and of course those will trigger out the questions based on the answer of um the the questions within the irq okay I see I have some more questions in [Music] here um [Music] um chat there's a lot of questions within here I answered a few of them but did you okay so that was um I think I had a couple of questions in here what is the difference between the irq and the the the tiering assessment uh we will slowly make sure that everything that you have in the tearing assessment will also be in the irq so that you can leverage both that and then if some time in the future is possible we retire the tiering assessment um probably in a year or two we'll wait until everybody is upgraded and then there'll be a real easy way to convert from a tiing assessment over to an irq now the next questions that we had included um how to handle reassessment so we have these different workflows as you can see I've run some and then you can have different irqs to do a reassessment of an existing third party you can have a and then I'm going to get to um some of the business rules for this you could either manually start up a workflow to reassess a third party by going into the employee Center that's one way of handling this another way is to set up rules which I can go through in a minute now and these different rules will allow you to go ahead and um automatically trigger these workflows or you can just send out questioners like you have been doing um and have them scheduled one at a time so the capabilities that we had before we will continue to provide to you the question would be is whether or not you um you know want to continue with the processes that you have that you had or if you would like to um adopt some of our new processes okay okay so let me kind of come over here now if I go into my lists you're going to see that I have two new things I have something called event driven management rules and event driven management history event driven management rules allows us to set up rules that we can run either on a reoccurring basis or one-time run I can schedule this to go this set of rules to go once maybe next Friday I want to send out all my AI assessments to a group of people um maybe I would like to go ahead and On Demand like right now send out a bunch of questionnair to some people so my external assessment is where I'm just sending out the assessment now here we can also set up a reoccurring workflow to start in this case is being sent out on a daily basis which is probably not really a good idea but if you'd like to do that you could send out a workflow start up a workflow on a daily basis so what it would do would automatically send out an CU so let me go ahead and open up this gdpr privacy assessment Rule and you can see we have a name for it and it's an active rule it is the status is it's right is that it's ready to run we have a business justification of why we are creating this Rule and then we're coming out here we're giving a technical description like how am I setting up this rule what is it actually doing well I'm sending out um you know this to these different to the UK Germany and Sweden in this country in N State and I'm sending it out to the type which is Professional Services outbound um Outsource services so these are going to be my criteria I am going to send it to external assessments I could send it to reassess and engagement um that initial question of how to handle existing third parties well this would be your reassessments we could set it up to offboard third parties under certain criteria this will apply to the engagement and then this is the assessment template that's going to be sent out we're going to reoccur run this on a reoccurring basis and you can see it's annual based on those the filter conditions that are set up we have one third party that is going to receive this and we can see the history so this has been run once manually okay so just for fun you can see that we have these are all of my active rules maybe I have some inactive rules that I have started to create I haven't activated because I haven't fully reviewed them and then of course we can see all of them we have the ability to see all of the ones that have run successfully okay and if I've recalled one of them any of them we can recall it so maybe this was an accidental run if I look out here and I'm like oh no um I didn't mean to send this one here in fact no third party risk assessments were even sent out in this I'm going to recall it I have a mandatory field uh oh what is that mandatory field I got to say why I'm recalling it I can't just start recalling things um this has no assessments and shouldn't have been run okay so I made a mistake so I'm going to go ahead and I'm going to recall this okay why do we recall things well mistakes happen right if this is going to be automatically if you have some scheduled jobs going so you we allow you to recall those assessments so you don't have runaway processes now there is an exception for these recalls the exception is now if I come over here to my successful runs and I open this up here hold on wrong one here so I said I look at this one that was sent out and there's four risk assessments that have been sent out I sent it out to the third party Cloud MSP I have an sap is still in draft Vault Line energy vast these are all the third party that based on this run received assessments if I tried to recall this now and Cloud MSP you can see it was already submitted to the third party if they've already completed these questioners if I recall this then it will get recalled for all of the ones except for the third party that actually already got those questioners and completed them because after we've got the third party involved they've already created to the questioners at this point one you've already gotten value two you don't want to wipe out those answers right so we're going to keep the answers for the ones that are completed and only take away recall the ones that haven't been worked out on just to cut down on that confusion so this one would or in that situation would not be recalled and that is um a planned limitation of this so that we are not wiping out work that third parties have already done okay so the way an active rule would be set up a rule be set up it's pretty easy um you just come out here you say new you give a justification [Music] use the scope now we can send out just an external assessment I can send start up a workflow to reassess the engagement so these are all the workflows where the external assessment is just when I'm going to pull just send one assessment I have the choice to send it to my third party contact or my engagement contact I will choose the appropriate assessment here I have the new AI assessment which um we do have included in this my run options is I could do it a reoccurring so reoccurring I can set it up to go ahead and send it out maybe quarterly semiannually or annually then I can have a start date maybe I want to start this no sooner than next week and then I have an end date maybe you know we want to do this in you know stop it in 10 years or whatever maybe 2062 because we'll all still be working on this in 2062 right so set conditions and then this is going to allow you to say like maybe I wanted to be um an annual spend of a certain amount maybe I wanted to be in a country and then um let's say uh contains and then we can have you know USA or us I can do or statements in here maybe I want USA or is I'm going to do this I'm gonna say is empty and I'm going to set this and then based on this filter condition what it's doing is it's going out there and it's seeing how many results I have so in my data there are 15 different third parties that fit that criteria that I set up okay and these are all of those third parties so before you set this rule up you know how many you're impacting the value of this is that you can set up these filter conditions and let's say you have 10,000 third parties you want to send out a risk assessment really quick like a log j4 problem and you don't want to go into each one of your third parties and try to send them out individually if I had 10,000 of them it would spin through them and say based on my career criteria I have 15 in this situation but let's say there were 5,220 then it would automatically find those 5,220 I'd be like great that was exactly what I wanted and then I can save this and then I will be able to run that okay um it will stop me from doing silly things like apparently I've messed up my start date and end dates so let's go ahead and uh figure that out and then we'll do that so it will dummy proof it and of course I am just completing this so let's go ahead and uh there we go talking and doing this at the same time is not always a good thing so there we have it you can see that I have no history of this rule okay but if I run it now we're going to find that it is being run I'll go into my successful runs it should come up here pretty soon here but it will it'll come in here for my successful run soon okay and that is how um we use these rules okay feature is incredibly powerful it's also something that that you want to get your hands around and your arms around and specifically as Stephanie showed you understanding how many third parties or engagements that impacts so definitely um you know understanding that before you hit before you send and submit um or schedule a run um is incredibly important um and just understanding who has access to create those and making sure that that's appropriate for your organization aha so here we have it was just a refresh thing so we can see that 15 different assessments were sent out to these different companies so if I was to log into the vendor risk portal for all of these they would all right now have that AI um risk assessment and that's how quickly it is to go ahead and this is very powerful so what we call a bulk run is something like this where I just go ahead and I Define the third parties that are going to get it I hit you know submit now and then it will go ahead and it will send those out now here if I wanted to recall it because let's say I made a mistake once again we can go through that whole process and then I can say this is an accident it was a test now something I do want to tell you here is some of you may be worried about licensing with this now that I've recalled it this will not go to count towards you will not have these if that was the only engagement that received a third party that will come out of your um your licensing these will not be charged to you okay if I just recalled those 15 of them they will not count as active manag active U manag uh active managed um third parties because I have recalled it and that was one of the things that uh we set this up to ensure that there wasn't some accidents you accidentally sent out a 100,000 um assessments and you're like oh shoot well go ahead and recall it and then you will not get a managed um activity for those 100,000 that you accidentally sent out okay that's great what are the filter options the filter options are anything that you have on the third party um and engagement record so any of those fields so in the Q&A section we've got a few uh lingering questions if you don't mind if you can open that up or do you need me to let you know what those questions are you answered my questions for existing third parties oh thank you Jack where is tearing oh that was from a half hour ago I think we hit tearing so tearing is not used for the workflows instead we're going to make sure that all the capabilities you had in tearing were are going to be within that irq so you will not need that right now we can create a tier level and then you can use business rules to um ensure that you can send out the questioners only when it's a certain tier level I think you're answering the questions from the chat currently if you don't mind the Q&A yes specific questions that uh would be helpful a is not opening up for me not a problem I can ask you the questions if that works for you absolutely or um yes that would be great so we have a custom questionnaire for tearing can the irq be utilized using our own catalog form or would we necessarily use the DDR process to make use of irq and we don't use the engagement mod module yet um but only the third party assessment so we have a custom questionnaire for tearing can the irq be utilized using our own catalog form so um I'm not sure what exactly um so what you can do in here if you have a tiering assessment is um actually I don't think I have an example one let me see is that you can convert the tiering assessment to an irq it's pretty simple so if you make a copy of your tiering assessment you can then just change it from a tiering questionnaire to an irq template and then that will go ahead and convert it so it could be used within the workflows oh here's the questions I'm sorry they're down here um if someone uses if someone doesn't use irm application but uses vendor management work to do vendor Performance Management with a account against irm operator like some doesn't use an irm application if you don't have a answer to pricing questions we can follow up because I know that's yeah that's yeah do you have a Chevron diagram of where you can show where the sequence timelines of the DTR process of uh reviews and approvals we do have a diagram of something that might help with that let me open that up real quick see I only have 10 minutes it might take me a couple minutes to pull up the diagram while you're pulling that up can I ask you if IR do the irqs support setting a third-party tier based on the answers like the tiering assessments do as of February release the answer is yes in the February release we support that and you'll need business rules to go ahead and combine the two con to combine utilizing that score to drive next steps in may we will have it have a minor release to allow you to Define it within the irq okay so that is that is definitely coming um let's see if I can an anonymous attendee asked can you speak to the impact of moving from vrm to tprm so I can start with this in that um Stephanie's team has made efforts to include everything that was in vrm into tprm so a lot of what the changes in tprm is the ability to access those workflows as well as a pricing change so that we're giving you fair market value for how you're using the product we can talk to you about better about that on an individual basis if you want to talk with your sales rep um but the goal of moving to tprm was to expand to a broader list of audiences so not just vendors but any type of third party you might be interacting with enhancing around a lot of the irq capabilities that Stephanie has talked about building in better workflows from end to end from onboarding through all the due diligence through to offboarding as well so there's a lot of great capabilities but if you talk about impact for moving from vrm to tprm Stephanie's team did a lot of redundancy work so that people who are moving from vrm maintain and retain what they had in vrm and then can move to tprm and then leverage the capabilities so I want to make sure that you understand the impact would be a lot less it's not we designed it specifically so there was less impact if that makes sense yes so that you should be able to upgrade and the reason for this is so that if you would like to take some time to review what is in tprm before you jump on into it um that's going to allow you to continue to do business as usual and then determine what you want to adopt and what you don't want to adopt what I don't want to do is I know there's a lot of companies that have created custom workflows is that I'm not forcing you to leave what you already have if you choose to you can so what I have here is a workflow uh diagram and I and one of the questions is is um to explain the approval process so basically um we start by the request right from the request we go to the irq process you can do approvals in multiple levels of approvals within the irq process that is possible and then once you've send out the questionnaires to either the engagement contacts or the third party contacts you need to validate those responses and then within the approval process you can set up um approvals using the service now platform approval um capabilities which we have built in here to set up up to 10 different levels of approvals with multiple different users in there they can be done concurrently sequentially you can have it where if one answers it then the other doesn't have to so you can handle committees you can handle it just if um you know either of these two people's approvals is good enough um so all of that is supported here if for some reason during the approval process you choose that you need to get another um risk assessment completed by a third party then you can add a new assessment to go to the third party or to the engagement and you can send it here now somebody which will allow that third party contact to complete the new risk assessment once they complete it it will then come right back through to the approval process now if your contract risk process person your legal team is looking through all of the information that has been collected from the request through the approval process and they feel that a new risk assessment needs to be sent out they can put comments in there send it back to the third party manager the third party manager then can choose the appropriate questionnaire to have either the thirdparty contact or the engagement contact to complete and then they will send it back here so that that way we can kind kind of have this full loop going through here um to get the appropriate information someone mentioned that they don't use the engagement model you can send things out just at the thirdparty level now the importance and the value of the engagement model is is that it's helping you keep like full history of what's happening with your third party so for example let's say you hired a company to do Consulting for you you're managing them at the third party level let's say you manage them at the engagement level the engagement will allow you to put a description in there call it um Consulting for project XYZ that project ends in six months you don't use that third party for two years you go back to use them again and you want to do another Consulting project with them two years later but it isn't to manage your data instead is to manage your customer outbound call center or something like that something completely different even though it's Consulting you might need to have them do a different type of d diligence so what you can do is is that other engagement you've retired it You' you've been activated it's it's you're no longer using it but now you're re-engaging with them in a different way and now you can see the different ways that you've engaged with them and why you're doing different risk assessments with them and you can keep different notes on them that is appropriate for the type of product service um or um the reason that you engage with them that's appropriate for that because in many cases when you do business with companies you might need to do something that is completely different and and this allows you to have a better understanding of why one group in your company is using IBM maybe to buy mainframes and another group is using IBM to manage and Outsource their data they're very different and it allows you to keep all the appropriate notes in with the appropriate activities and it's a good way of structuring and maintaining um you know the the reasons for doing doing things and then as you stop engaging with them and that way you can inactivate it so I think we only have a couple more minutes to go um currently um Raz what are some of the top questions that are in here yeah is due diligence the name of an assessment at anytime so tiering and risk assessments due diligence is not a term limited only the initial tiering so due diligence is what we're using for our workflows so these are our due diligence workflows and teering assessments are not actually supported in the due diligence workflows irqs are but the irqs will have all the capabilities that the tiering assessments will have awesome um we currently collect info on vendor data type and some other data points in our VTA which is quite to report on for example how many vendors have access to Phi question is where will the irq responses be stored so that they can improve their reporting capabilities um there is a though there's a table for the questionnaires that you can in in our documentation it can give you the exact table in which the irq's fields are um being um stored awesome um so if you want to include your email um Natasha that would be great um and does tprm integrate with PPM what is PPM I'm not sure um so if the anonymous attendee uh would like to answer that question uh we can try and get that live or if you want to send your email address we'd be happy to follow up with you so Stephanie I know that was a lot of information we are up against time out of respect for your time um I want to make sure that we're going to uh the end but if there are questions following this um by all means we're happy to um always engage with customers and speak with customers at any point so definitely uh follow up with us um I am rosin morville servicenow.com um so definitely if there's someone I can put you in touch with I'm happy to do so um so for key highlights um I think you went over the uh improved irq uh you went over the user experience um ongoing due diligence management with the event r TOs and event man driven management and of course uh my favorite feature uh obviously is the bulk assessments um I know that the questionnaire pre-population is something that a lot of customers are asking for so thank you for including that and as we continue to delve further and further into the AI realm um and add features and functions to our products as well um the sample questionnaire is a great uh first step in in delivering some of those um capabilities because I know that their Forefront of customers Minds today so I think we went through a lot of the questions um and as I said if there are additional questions please feel free to put them in the Q&A we can uh capture that um and we will follow up um thank you very much for your time today Stephanie um definitely continue to join us for future service now Community webinars um we've got a great deal coming out in Washington across the entire risk portfolio so make sure that you're coming and asking questions the community is a great place as well to interact and get um questions not only from Stephanie and her team but also from uh a wide array of experts within our community so make sure that you're utilizing that as much as possible and as I said new this year um this is a little bit of an updated uh timeline but we have a the blog post that I put in the in the chat at the beginning of the session um is one of the uh one of my colleagues uh put together a monthly chart um and so what that does is it not only gives you a view of what's coming up but if you did miss a session then you can start to access the on demand sessions there so check out that blog post as I said I put it in the chat early on um if you need follow up on that let me know um otherwise you can just uh search in a community where you as will this so thank you so much Stephanie for your time thank you everyone for the breadth of questions we really appreciate your interaction um and definitely uh feel free to follow up with us afterwards and I will be taking content from the Q&A with email addresses and such and following up with people directly so have a great day um and thanks again Stephanie for for all you do
https://www.youtube.com/watch?v=yeZqPM5smFU