Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Third-party Risk Management reference

Reference topics provide detailed descriptions of tables, properties, forms, and roles that are installed with the Third-party Risk Management application.

  • Terminology
    Learn more about the key concepts and terms that are used in the TPRM application.
  • Roles in Third-party Risk Management
    Roles determine permissions and access in TPRM.
  • Unique ID numbers for TPRM records
    When you create (or the system generates) a new record (for example, a request for due diligence or a task), the system auto-assigns a unique ID number that helps to identify the type of data in the record. You can use the ID number to search for or filter the item you want to work on.
  • Results of migrating a template to a TPRM SAE template
    You can view the templates that were migrated to Smart Assessment format.
  • Guidelines for importing spreadsheet data
    Before you try to import the questionnaire data from a Microsoft Excel spreadsheet into Third-party Risk Management tables, you must verify that its format meets particular guidelines.
  • Sample questionnaires
    The questionnaire that you use can depend on your industry, geographic area, jurisdiction, or the particular nature of your operations. These questionnaires are provided as part of the base system and are samples that shouldn’t be implemented into your risk management program without first being reviewed and approved by your legal team.
  • Due diligence request process management
    From the Details tab, you can view and adjust the due diligence request information for a third party. You can also log external-facing comments and private work notes, attach files, and track request updates in the activity stream.
  • IRQ process management
    The first internal step after an engagement request is approved is to start the IRQ process to scope the risk by determining the third party's risk score.
  • Third-party (external) risk assessment management
    After the IRQ process is complete, you send questionnaires and document requests to the third-party contact. You manage the third-party risk assessment by working with the contacts to help ensure that the responses are complete and accurate.
  • Approval process management
    You can view the list of users who can approve or reject a DD request and also view the details of their approval actions. In addition, you can view the approval levels for a request.
  • Risk intelligence report requests management
    You can view a list of risk intelligence report (RIR) requests, their associated providers, scores, and report URLs. In addition, you can create requests and make updates by using the Third-party Risk Management application.
  • Scoring calculations using the classic assessment engine
    Perform a comprehensive external risk assessment when calculating multiple ratings and scores by using the Third-party Risk Management application. You can gain a deeper understanding of the overall calculation process and learn how user-defined parameters and configurations influence the results of the questionnaires.
  • Third-party risk management data model
    Use the Third-party Risk Management (TPRM) data model to assess, monitor, and mitigate the risks for your risk management program.
  • Domain separation and Third-party Risk Management
    Domain separation is supported for TPRM. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
  • Vendor Risk Overview reports — Legacy view
    The Vendor Risk Overview page is replaced by the third-party risk reports on the Vendor Management Workspace.

Parent Topic:Governance, Risk, and Compliance