Manage the access for your third-party contacts
View your existing third-party contacts and adjust their information and access permissions as needed by using Third-party Risk Management. When you keep the contact details up to date, you can help to avoid your third-party contacts from getting unauthorized access or losing authorized access to the third-party portal.
Before you begin
The third-party risk (TPR) manager must contact a team member with the admin role to complete the last 3 options of step 3.
Role required: sn_vdr_risk_asmt.vendor_risk_manager and admin to complete the last 3 options of step 3.
About this task
Your third-party contacts are external users at the third-party organization. They use the third-party portal to securely organize, prioritize, and perform tasks like responding to questionnaires for assessments and communicating with your risk-assessment staff about issues. You can also adjust the access to the third-party portal and permissions for your third-party contacts.
Procedure
Navigate to All > Third-party Risk Management > Third Parties > Third-party Contacts to view your existing third-party contacts.
The number of contacts is listed for each third party on the third-party contacts page.
Select the third party that you want to view the list of associated contacts for and then select the third-party contact.
Third-party contact's information and the relevant buttons, options, and related link locations on the form. For a description of each action, refer to the steps that follow.
- Manage the access to the portal for your third-party contacts.
| Option | Description |
|---|---|
| Deactivate the account | Deactivate the account by clearing the Active check box. After you deactivate the account, the third-party contact can't log in or appear in the list of associated contacts. |
| Resend Invite | Resend an email invitation for accessing the third-party contact portal by selecting the Resend Invite related link. The email contains a link to the third-party portal and login credentials. |
| Delete Contact | Remove the snc_external role from the third-party contact and deactivate the third-party contact by selecting the Delete Contact related link. |
| Locked out | Lock out the third-party contact by selecting the Locked out option. After you lock out the third-party contact, that person can't log in anymore. This option enables the third-party contact to lose access while still being active. This action can be useful as a precautionary measure while the third-party contact's password is being reset. |
| Set password | Generate a new password and send it to the third-party contact by selecting Set Password. |
| Reset a password | Send an email with a link for resetting a third-party contact's password by selecting the Reset a password related link. Additional setup by your team member with the admin role is required. |
Select Update.
Note: For more information on setting up third-party contacts, see Set up third-party contacts and Enable email with third-party contacts.