Describe the actual business relationship, the information it handles and the systems that depend on it. Keep enough context for another reviewer to understand the scope of the assessment.

Identity, responsibility and classification

Use Identity and contact for the name, parent company, description, contact fields and tier. Named contact fields describe people involved in the relationship; Manage owners and Manage stakeholders assign workspace members separately.

Under Classification, select the applicable third-party types, IT provider types, regions, countries and business units. Use your workspace's definitions consistently. A legacy category may appear separately on an older record; review its meaning before using it as a substitute for the current classification fields.

Information held

Use Data held to record information types and their confidentiality, integrity and availability needs. Review the data classification and the personal-data and health-data indicators.

The maximum summary does not show the full rationale behind the classification. Older records can retain aggregate values without detailed information-type rows. Check the actual rows and supporting evidence before treating the classification as complete.

Dependencies and scope

Use Link system to connect an existing system. Linked systems remain managed in the Systems module, and access to them follows your system permissions. Unlinking removes the relationship, not the system record.

Scoped risk demands is a read-only list of demands that name this third party in their scope. Manage those scope selections from the demand. A scoped demand can still be in progress and is not automatically the assessment of record.

  1. Open Manage assessments.
  2. Find the completed risk demand by title or RAD code.
  3. Select the appropriate cadence and choose Link assessment.
  4. Review the resulting assessment state, current analysis and next date on the record.

The cadence choices include daily, weekly, every two weeks, monthly, quarterly, half-yearly, annual and no recurrence. Choose a cadence that matches the relationship's review needs. The third-party workflow calculates the next assessment date from its schedule; it does not use the Systems module's separate manual-date control.

For a linked assessment, use Save schedule to change its cadence. Restore and Unlink act on the selected assessment history entry. Inspect the current analysis and schedule after each action; a historical assessment may no longer represent the current relationship.

Forms, evidence and notes

Send form lets you select a completed form, enter a recipient email and add a message. Review the remaining allowance and recipient before sending. Sending contacts the recipient; saving the third-party draft does not send it. Responses and previously sent requests remain under Forms sent.

Use evidence for supporting files or links and notes for context that does not belong in a structured field. Save section and note drafts through the page save bar. Assessment, relationship, owner and form actions use their own controls and are not undone by discarding the page draft.