ServiceNow Vendor Risk Management: How to do a Tiering Assessment
Cerna is Now Thirdera
·
Sep 11, 2020
·
video
[Music] welcome to the cena solutions spotlight series videos today we will be looking at vendor risk management with vendor tiering assessments my name is philip roach i am a technical consultant at cena solutions i'm a member of the security and risk team a t-ring assessment is a core capability of the vendor risk module it allows the organization to perform assessments against the vendor using internal company resources to gauge the risk that the vendor possesses for the company you will ask why a vendor tiering assessment is important it will reduce the slow interview with requester process tie together inputs from multiple departments in a consistent manner help prioritize how much work needs to be done in a central location starting from the vendor risk overview dashboard we can see a variety of information from the vendor risk application from the vendor classification by tier we can select a company who has not yet carried out the tiering assessment from the list we can choose a company from the portfolio we can see that the vendor tier has not yet been set so we scroll down to the related list create a new tiering assessment by completing the fields some of them have already been filled in for us you will pick an assignee from within the van der risk application this is a user who already has a role we will choose the tiering assessor who will carry out the assessment this can be one or many once we save this record you will be given the option to pick up here in questionnaire from here we will choose the basic option different questionnaires are available based on the needs of the organization and can be configured and set up in advance we have a vendor tiering scale which is a property set up within the system that will define once the questionnaire is complete how those scores will be ranked we have a tiering assessment schedule which is how long the tiering assessment will take to complete and then we have the option of comments and notes that may be useful once we're ready we submit this to the assessment which will be evol tutor in this case by impersonating our assessor we can switch to sooner solutions integrated risk management portal where we can take this tiering assessment once we complete this we can submit it and get a score from the scoring framework we submit and the assessment is complete we can now return to our previous account to check to see the responses by returning to the company record and scrolling down to the tiering assessment we can see that it has been complete by our assessor and that we have a tiering level of critical we can look at this assessment take a look at the questionnaire and the assessment instance which is complete and we can look at the tiering score the tiering score is calculated based on the responses to the questionnaire and can be changed as needed the score has been passed to the tier level and once we close out this tiering assessment this value will be passed in to the company record the new vendor tier score has been set to critical as per our tiering assessment we can also carry out new tiering assessments as needed with a new score overwriting the previous we also have the option of modifying this manually ourselves if we return to the overview dashboard we can see that the empty has shifted it and moves us into the critical area where you can now see sooner solutions once the tiering assessment process is complete the next step depending on the configuration of the application can be to set up the actual vendor assessment based on the vendor rules in this case because we have a tiering assessment of critical we can automatically assign an assessment to that vendor this concludes today's spotlight video on vendor risk management tiering assessments please stay tuned for more spotlight videos from cerner solutions thank you very much
https://www.youtube.com/watch?v=K4Oh6wXS1VY