Vendor Risk Management - Contracts - SLAs & Tasks Step-by-Step Tutorial
Vendor Risk Management - Contracts - SLAs & Tasks Step-by-Step Tutorial
If you are using an Rsam sandbox environment, you should have provided Rsam with your
organization’s internet facing IP address. To find this information, open a browser and connect to an
IP discovery site such as www.whatismyip.com, or contact your organization’s Network Administrator
for assistance. You may also contact your Rsam Customer Representative with any questions.
Sign-In Page
Tutorials leverage pre-defined accounts that require manual authentication. While your organization
may intend to use SSO authentication, Rsam sandbox environments require manual authentication
through the Rsam Sign-In page so that you can easily toggle between various sample accounts used
throughout the tutorial.
Like most elements in Rsam, the Sign-In page can be configured in a number of ways. Different
authentication options such as user self-registration, integration with customer user directories (such
as Active Directory), or integration with Single Sign-On products, such as Shibboleth, can be applied.
You can also embed your own branding and logo on the Sign-In page.
• Role-based workflows enable effective collaboration between internal and external users.
• Automated workflow for classifying vendors against pre-defined criticality factors guarantees
that vendors are asked to respond only to relevant control self-assessment questionnaires.
• Out-of-the-box content allows you to jump-start your vendor assessment program by leveraging
industry best practices and standards.
• Automatic identification of gaps and findings allows your team to spend less time deciphering
responses and more time responding to them.
Note: Rsam also offers optional connector products that enhance the Vendor Risk Management
module by integrating third-party intelligence feeds relating to a vendor’s IT security risk posture,
financial viability, compliance status, etc. This tutorial does not cover such integrations explicitly;
however, you may see references to BitSight, and other partner-provided content in some of the
screen shots that appear in this tutorial.
A note on additional tutorials: This tutorial covers specific workflows around contract, SLA, and
task management. This tutorial should be regarded as a supplement to the primary Vendor Risk
Management step-by-step tutorial, which covers the core questionnaire assessment workflow. Please
refer to the Rsam Community Forum or contact your Rsam representative to obtain that guide.
• Tasks Workflow
Before proceeding to the specific workflows, it is recommended that you familiarize yourself with the
following Rsam workflow diagram key.
Note: Administrators may create variations to any pre-defined workflow configuration to match your
specific business processes.
Complete Reject
Ap prove Draft Vendor Respondent / Deliverable Owner Contract Owner
Contract Reviewer
Pending Confirmation
3. Negotiations
Record
Contract Owner Record
Activate
Contract Owner
5. Active Re-Activate
Record Contract Owner
5.Renewal in Progress
6. Termination in
Record
Progress
Record
Renew Contract
Contract Owner
Complete Termination
Contract Owner
7. Terminated
Record
Task Workflow
The following diagram depicts the out-of-the-box Task workflow.
Start
Manager
0. Draft
Record
Schedule
Manager
Task Own er
Start Complete
Manager Task Owner
1. Scheduled 2. Started 3. Completed
Record Record Record
Note: Sample users for each of these roles are optionally provided with the baseline module
installation package.
r_vendor_owner Contract This user will be assigned Contract Owner role that represents the
Owner business line owner responsible for managing contract with the vendor.
This user represents an individual assigned to carry our certain vendor
oversight tasks. Can be internal business owner or vendor representative.
r_vendor_revie Vendor This user will be assigned role that represents business line manager who
wer Reviewe is responsible to approve contracts.
r
r_vendor_respo Vendor This user will be assigned role that represent a vendor representative
ndent Respond responsible for managing contract deliverables. Often times Vendor
ent Respondent and Deliverable Owner are the same individuals.
r_vendor_mana Vendor This user is responsible for overseeing the vendor risk management
ger Manager processes and can create, assign and start new tasks.
The default password for all accounts in the Rsam Vendor Risk Management sandbox is p a s s w o r d .
Individual users may change their passwords from within Rsam, and users with administrator
permissions may also reset passwords for other users.
Step 1: Creating a Vendor In this step, the Vendor Owner creates a new contract and
New Contract Owner submits it to the Vendor Reviewer for approval of contract.
Step 2: Create a Vendor In this step, the Vendor Owner creates a new deliverable and
New Deliverable Owner submits the deliverable to the Vendor Respondent user for
completion.
Step 3: Approving Vendor In this step, the Vendor Reviewer approves the contract.
the Contract Reviewer
Step 4: Executing Vendor In this step, the Vendor Owner user executes the contract.
the Contract Owner
Step 5: Activating Vendor In this step, the Vendor Owner user activates the contract.
the Contract Owner
Step 6: Completing Vendor In this step, the Vendor Respondent user completes the
the Deliverable Respondent deliverable.
Step 7: Confirming Vendor In this step, the Vendor Owner user confirms the deliverable.
the Deliverable Owner
Step 8: Creating a Vendor In this step, Vendor Manager creates a new task and assigns the
New Task Manager task to the Vendor Owner user for flagging as complete.
Step 9: Completing Vendor In this step, the Vendor Owner user flags the task as complete.
the Task Owner
Step 10: Creating Vendor In this step, the Vendor Manager user creates an SLA Input.
an SLA Manager
Step 11: Submitting Vendor In this step, the Vendor Owner user submits the SLA Input.
SLA Input Owner
a. Some organizations may deploy Rsam in a single sign-on environment, which utilizes your
corporate login to bypass the Rsam login screen. However, each step in this tutorial potentially
requires a different user account, so be sure you have the access to the Rsam login screen and
can log in using the different username / password combinations as stated in the steps.
b. Some workflow state transitions may trigger email notifications to users in the workflow. If you
want to ensure that your users receive these notifications, please see the Setting up Email
Addresses section later in this tutorial.
1. Open an Rsam-supported browser and enter the URL of the Rsam instance where you will
complete this tutorial.
4. In the list of objects, click the Contracts link associated with the object for which you want to
create a contract. As part of this tutorial, we will use the Alliance Ltd object. The Vendor /
Service Provider object opens with the Contracts category selected.
9. Complete any other attributes that are required to you. Ensure that the attributes marked with
an asterisk (*) are completed.
11. In the message that appears indicating to save the changes and continue, click OK.
The newly created contract enters the Drafted, Pending Approval workflow state.
2. From within the navigation panel on the left-hand side of the screen, navigate to Vendor Risk
Management > Contracts, Deliverables & SLAs.
3. From within the navigation panel at the left-hand side, select Contracts by Vendor and click
your Vendor object. As part of this tutorial, we will select the Alliance Ltd vendor object.
4. Double-click the active contract. The Contract record opens with the Contracts tab selected.
Note: The amount paid for the deliverable must be less than the total contract value.
9. Click In Progress. The Contract Deliverables record enters the In Progress workflow state.
1. Open an Rsam-supported browser and enter the URL of the Rsam instance where you will
complete this tutorial.
3. From within the navigation panel on the left-hand side of the screen, navigate to Vendor Risk
Management > Contracts, Deliverables & SLAs.
4. From within the navigation panel at the left-hand side, select Contracts by Vendor and click
your vendor object. As part of this tutorial, we will select the Alliance Ltd vendor object.
6. Click Action and select Approve Draft. The Contract record enters the Negotiations
workflow state.
1. Open an Rsam-supported browser and enter the URL of the Rsam instance where you will
complete this tutorial.
3. From within the navigation panel on the left-hand side of the screen, navigate to Vendor Risk
Management > Contracts, Deliverables & SLAs.
4. From within the navigation panel at the left-hand side, select Contracts by Vendor and click
your vendor object. As part of this tutorial, we will select the Alliance Ltd vendor object.
6. Click Action and select Start Execution. The Contracts record enters the Execution in
Progress workflow state.
1. Double-click the contract in the Execution in Progress workflow state. The Contract record
opens with the Contract tab selected.
3. Click Action and select Activate. The Contract record enters the Active workflow state.
1. Open an Rsam-supported browser and enter the URL of the Rsam instance where you will
complete this tutorial.
3. From within the navigation panel on the left-hand side of the screen, navigate to Vendor
Respondent Home > Vendor Respondent Deliverables & Tasks.
4. From within the navigation panel at the left-hand side, select Contracts by Vendor and click
your vendor object. As part of this tutorial, we will select the Alliance Ltd vendor object.
5. Double-click the contract for the Alliance Ltd vendor object. The Contract record opens with
the Contracts tab selected.
7. Select the deliverable, then click Action and select Complete. The deliverable record enters
the Pending Confirmation workflow state.
1. Open an Rsam-supported browser and enter the URL of the Rsam instance where you will
complete this tutorial.
3. From within the navigation panel on the left-hand side of the screen, navigate to Vendor Risk
Management > Contracts, Deliverables & SLAs.
4. From within the navigation panel at the left-hand side, select Contracts by Vendor and click
your vendor object. As part of this tutorial, we will select the Alliance Ltd vendor object.
5. Double-click the contract for the Alliance Ltd vendor object. The Contract record opens with
the Contracts tab selected.
7. Select the deliverable, then click Action and select Confirmed. The deliverable record enters
the Complete workflow state.
1. Open an Rsam-supported browser and enter the URL of the Rsam instance where you will
complete this tutorial.
3. From within the navigation panel on the left-hand side of the screen, navigate to Vendor Risk
Management > Vendor Navigator.
4. In the vendors list, double-click your object. As part of this tutorial, we will use the Alliance Ltd
vendor object.
Rsam displays the Alliance Ltd vendor object details.
The Alliance Ltd vendor object opens with the Tasks tab selected.
Note: If not started manually (that is when the user does not click the Start button), all
scheduled tasks will start automatically based on the start date.
1. Open an Rsam-supported browser and enter the URL of the Rsam instance where you will
complete this tutorial.
3. From within the navigation panel on the left-hand side of the screen, navigate to Vendor Risk
Management > Vendor Navigator.
4. In the vendors list, double-click your object. As part of this tutorial, we will use the Alliance Ltd
vendor object. Rsam displays the Alliance Ltd vendor object details.
5. Under Supplemental Records, click Tasks. The Alliance Ltd vendor object opens with the
Tasks tab selected.
1. Open an Rsam-supported browser and enter the URL of the Rsam instance where you will
complete this tutorial.
4. In the list of objects, click the SLA Library link associated with the object for which you want
to create an SLA. As part of this tutorial, we will use the Alliance Ltd object.
The Vendor / Service Provider object opens with the SLA Library category selected.
A new SLA Measurement record opens with the SLA Measurement Target tab selected.
12. Complete the L o w R a n g e and H i gh Ra n ge attributes. For the sake of completing this
tutorial, we will enter 0 for L o w R an g e and 2 for Hi g h R an g e.
13. Select SLA results (List) to indicate this range will constitute a Fail result.
15. Select SLA results to indicate this range will constitute a Pass result.
19. Select a desired contract and click Update. The contract is added to the Related Contracts
grid.
20. Click Action and select Generate SLA Input Records (for Manual input).
1. Open an Rsam-supported browser and enter the URL of the Rsam instance where you will
complete this tutorial.
3. From within the navigation panel on the left-hand side of the screen, navigate to Vendor Risk
Management > Contracts, Deliverable & SLAs.
4. In the navigator, select SLA Inputs (nav) and select the SLA Input Pending group.
1. Open an Rsam supported browser and enter the URL of your Rsam instance containing the
Vendor Risk Management Module.
6. Click OK.
The email address of the user account is saved.
Offline Decision Making is a powerful and popular feature of Rsam. It provides the Rsam platform
directly to the users to perform workflow actions without connecting to the Rsam module. The
following image illustrates an example notification template that has custom text, data from the
record, embedded links to the application, and Offline Decision Making actions.
Online Help
This tutorial provides the step-by-step instructions on the Rsam Vendor Risk Management Module. To
get familiar with the specific Rsam features used in this configuration, refer the Rsam End-User Help ,
Rsam Administrator Help , or both. The Online help you can access depends on your user permissions.
To access the Online Help, perform the following steps:
1. Sign in to your Rsam instance. For example, sign in as Example Administrator user. Enter
Us er na m e as r _ a d m i n and P a s sw or d as p a s s w o r d .
2. Hover the cursor over Help and select an Online help from the menu that appears. Depending
on your user permissions, you will be able to access the Rsam End-User Help, Rsam
Administrator Help, Step-by-Step Tutorials, or all.
The following image shows the Rsam Administrator Help , opened from the Example
Administrator user account.