The Due Diligence application, part of Third-Party Risk Management, offers preconfigured workflows for seamless onboarding, reassessments, renewals, and offboarding to manage the full due diligence lifecycle. It also includes a Risk Concentration Map and an intuitive Due Diligence Management page for efficient workflow oversight.
The Due Diligence application includes:
- Preconfigured due diligence workflows (onboarding, reassessments, renewals, and offboarding)
- Risk Concentration Map
- Event-driven Management Rules
- Due Diligence Management dashboard
- IRQ capabilities to manage the workflows
- Option to auto-populate third-party questionnaires with answers from previous questionnaires
New
- Added SBOM questionnaire auto-assignment on engagement creation.
- Added SAE template versioning capability support.
Changed
- Replaced GlideRecord with GlideRecordSecure in TPRMDueDiligenceAjax for security compliance.
- Updated ACL query rules based on 2025 May MSI (CVE-2025-3648).
- Replaced vendor reviewer role with GRC reader on report view ACLs.
- Added retired=false filter to SAE template reference qualifiers.
- Removed orphan ACLs from dd_element table.
Fixed
- Corrected domain separation issues on issues and event-driven rules (PRB2020926).
- Fixed duplicate audit creation on current.update() (PRB1992222).
- Resolved engagement primary contact creation issue when toggling "Same as third-party contact" option (PRB1988772).
- Permissions and roles
- Role required to install the app: System admin (admin)
When you upgrade the Third-party Risk Due Diligence application, make sure to upgrade the Vendor Risk Management Workspace and any other installed GRC applications to the equivalent release version. For example, Third-party Risk Due Diligence version 18.x is certified to work with Third-party Risk Management version 18.x and other version 18.x GRC applications.