Assessment overview

Evaluate and determine the risk exposure with your third parties and ecosystem.

With 3rdRisk, you can systematically evaluate and determine the risk exposure with your third parties and ecosystem. Create, schedule, perform and monitor generic or tailor-made, third-party risk assessments for all your third parties.

Process

The assessment module contains 5 different steps:

  1. Create/select an assessment template
  2. Create an assessment
  3. Fill in the assessment
  4. Review assessment
  5. Finish and close the assessment

Per step, there is a dedicated support page:

StepHigh-level activityResponsibleDocs page
1. Create/select an assessment template- Select one more available questionnaire templates from the store.
- or upload your questionnaire.
Risk officer / Risk manager / Procurement managerAssessment template
Store
2. Create an assessment- Select third-party, deadline and applicable requirements.
- Select the questionnaire, specific domains and reviewer(s).
Risk officer / Risk manager / Procurement managerCreate assessment
3. Fill in the assessment- The third party will receive an email invitation for the 3rdRisk assessment portal to fill in the assessment.
- The third party fills in the assessment and submits the response.
- The third party will receive an email confirmation that the assessment has been completed.
Third-partyFill in assessment
4. Review assessment- Reviewer(s) will receive an email that the assessment is ready for review.
- Reviewer reviews all questionnaires and closes review when there are no more outstanding questions.
- Risk manager/risk officer can register one or more incidents or risks based on assessment results.
ReviewerReview an assessment
5. Finish & close assessment- Platform closes and archives assessment.
- Third-party and his/her business-/contract owner and procurement manager will receive an email to confirm that the assessment is finished and closed.
Third-party / Reviewers / Business manager / Risk manager / Risk officerReview an assessment

Communication flows

In the assessment module, there are various automated e-mails sent by the platform:

Process stepMessageWhenTo
2. Create an assessmentInvite for a 3rdRisk assessmentAutomatically generated and sent when you create an assessment.

External

3. Fill in the assessmentNot yet a response and almost overdue4 days before the due date

External

 Overdue / assessment is cancelled.Past due date

External

Internal

  • Assessment creator
 Confirmation that assessment was successfully submittedWhen assessment submitted

External

4. Review assessmentAssessment ready for reviewWhen assessment submitted

Internal

  • All reviewers
5. Finish & close assessmentReview successfully performedWhen the review was successful

External

Internal

  • Business/contract owner
  • All involved reviewers
  • Third-party manager
  • Security Officer

Known limitations of the assessment management module
Is it not yet possible to have nested / dependency between answers to questions