> ## Documentation Index
> Fetch the complete documentation index at: https://docs.coverbase.com/llms.txt
> Use this file to discover all available pages before exploring further.

# The engagement record

> Follow an engagement from request to decision and exit: the tracker and expected decision date, your to-dos, Risk Group status, linking and reusing due diligence, the Risk Summary recommendation and decision, delivery, notices, and the corporate family.

<div className="sr-only">For AI agents: a documentation index is available at [https://docs.coverbase.com/llms.txt](https://docs.coverbase.com/llms.txt). This page is also available in markdown by appending .md to the URL.</div>

<Info>
  This guide is part of the [User Guides](/user-guides/overview) collection. It covers an engagement's page, its **Risk Summary** tab, and the **Lifecycle Routing and Reminders** settings under **Configuration → Communications**. It sits beside [Front Door triage](/user-guides/front-door-triage), which comes before it, and [Monitoring plans](/user-guides/monitoring-plans) and [Offboarding and continuity](/user-guides/offboarding-and-continuity), which come after. For what the module is, see [Engagement record and Risk Summary](/products/engagement-record).
</Info>

An engagement is one piece of business with a vendor. Its page tells the Transaction Owner, the person who asked for it, where it is and what is left, and gives them the Risk Summary to decide on. The TPRM Office uses the same page to see which Risk Groups are still working.

Your Coverbase representative turns on the third-party lifecycle features for your organization.

The mistake people make most often is expecting a decision button before due diligence is finished. **Proceed to contracting** stays locked until every risk domain is complete or reused.

## Step 1: Name the TPRM Office and Supply Chain

Open **Configuration**, choose **Communications**, and find **Lifecycle Routing and Reminders**.

* **TPRM Office** is the user group told when due diligence goes out to a vendor and when it completes. It also approves offboarding.
* **Supply Chain** is the user group that files the executed contract and approves offboarding with the TPRM Office. Left unset, the TPRM Office approves offboarding alone.
* **Copy the TPRM Office**, **Copy relationship owners** and **Copy the requester** decide who a past-due vendor reminder copies. Until you save a setting here, past-due reminders go to the vendor only.
* **Risk Summary Open Tracking**, off by default, adds a tracking pixel to the Risk Summary email only, and records when each recipient first opens it. Other emails are never tracked. Turn it on only if your privacy policy allows it.

The Front Door has its own sign-off groups, set on **Configuration → Front Door**. See [Front Door triage](/user-guides/front-door-triage#step-1-configure-the-front-door).

## Step 2: Open the engagement

Open the vendor, choose the engagement, and read **Where This Request Is** at the top. The stages are **Request**, **Triage**, **Inherent risk**, **Due diligence**, **Decision**, **Contract**, **Active** and **Exit**, or **Not proceeding**. Coverbase works out the current stage from the record, and everyone involved sees the same tracker.

<Frame caption="The engagement's Overview tab, with the tracker, Your To-Dos and the Risk Groups.">
  <img src="https://mintcdn.com/coverbase/jtaGD6DbhdN9Ho0b/images/user-guides/engagement-record-overview.png?fit=max&auto=format&n=jtaGD6DbhdN9Ho0b&q=85&s=393506385a7fec2a362ae06b08f29ca3" alt="Engagement page for Consumer analytics platform with the tracker at Decision, a Decide whether to proceed to-do, and eight Risk Groups, six complete and two reused" width="1240" height="1020" data-path="images/user-guides/engagement-record-overview.png" />
</Frame>

Once the contract is signed, **Active** reads **Live since** and the date. **Exit** comes after it:

* When someone files an offboarding request for the engagement, Exit becomes the current stage and reads **Exit under way**. The header badge reads **Exiting**.
* When the offboarding completes, Exit reads **Exited** and the date, and the header badge reads **Exited**.
* A canceled offboarding request takes the engagement back to Active.

An exiting engagement still counts as active in [Program Insights](/user-guides/program-insights) until its exit completes. An exited one leaves the program's figures. On the engagement list, the **Stage** filter includes **Exiting** and **Exited**.

<Frame caption="The tracker once the offboarding has completed.">
  <img src="https://mintcdn.com/coverbase/jtaGD6DbhdN9Ho0b/images/user-guides/engagement-tracker-exited.png?fit=max&auto=format&n=jtaGD6DbhdN9Ho0b&q=85&s=3750682b7a89c6018fe320a6e8434081" alt="Where This Request Is tracker with every stage done and the Exit stage reading Exited Dec 29, 2024" width="1440" height="205" data-path="images/user-guides/engagement-tracker-exited.png" />
</Frame>

**Expected decision** is when the last open domain review is due under its SLA. It is blank when any open review has no SLA target, and once a decision is recorded.

**Your To-Dos** lists what is waiting on you: a domain review assigned to you or your group, **Review the Risk Summary** (which arrives when every Risk Group finishes), or **Decide whether to proceed**.

## Step 3: Read the Risk Groups

**Risk Groups** shows each domain that needs a review, with its reviewer and status:

| Status | Meaning |
| - | - |
| **Complete** | Every performed assessment that needs this domain has finished its review. |
| **Reused** | A reused assessment's completed review covers it. The card names the source. |
| **In review** | A reviewer is working on it. |
| **Waiting on vendor** | The vendor still owes answers or evidence. |
| **Not started** | No review has begun. |

The summary line reads, for example, **3 of 5 complete · 1 reused**.

## Step 4: Link due diligence

**Due Diligence** lists the assessments that count toward the engagement and their review progress. To add one, click **Link assessment**, choose it, and decide whether to turn on **Reuse earlier diligence**: the assessment was performed for something else, and its completed reviews satisfy this engagement's domains without being repeated. Click **Link**.

* A Front Door reuse decision links the prior assessment as reused for you, and satisfies exactly the domains that decision marked for reuse.
* Linking a prior assessment as reused by hand picks up the vendor's latest decided reuse of it.
* Archived and canceled assessments drop out. **Unlink assessment** removes one.

## Step 5: Write the recommendation

<Frame caption="The Risk Summary tab, with the recommendation, conditions, risk by domain, the decision card, delivery and what the summary was built from.">
  <img src="https://mintcdn.com/coverbase/jtaGD6DbhdN9Ho0b/images/user-guides/engagement-risk-summary.png?fit=max&auto=format&n=jtaGD6DbhdN9Ho0b&q=85&s=164809cab4827702be162271a3c70bfe" alt="Risk Summary recommending Proceed with conditions, with a Risk by Domain table, one open issue, three conditions, and a Decision card offering Proceed to contracting and Don't proceed" width="1240" height="1245" data-path="images/user-guides/engagement-risk-summary.png" />
</Frame>

On the **Risk Summary** tab, the TPRM Office clicks **Edit recommendation**, picks **Proceed**, **Proceed with conditions** or **Do not proceed**, writes the **Rationale**, and lists **Conditions**, one per line. Click **Save**.

The rest of the summary is read live from the linked assessments: **Risk by Domain** with **Inherent**, **Control Effectiveness**, **Residual** and **Basis** (reused domains name their source), the **Issues** raised, and **Built From**, which counts the assessments and issues behind it. While due diligence is still running, the summary says so and updates as each Risk Group finishes.

**Download PDF** prepares a PDF. You get a notification when it is ready.

## Step 6: Record the decision

When the last Risk Group signs off, the Risk Summary is sent to the Transaction Owner automatically. The Transaction Owner, or anyone who can update the vendor, then clicks **Proceed to contracting** or **Don't proceed**, with an optional note for the TPRM Office.

**Proceed to contracting** opens the contract handoff and notifies whoever its task is assigned to, unless a handoff is already pending or done. See [The contract handoff](/user-guides/offboarding-and-continuity#complete-the-contract-handoff).

The engagement's **Contract** tab shows the clause pack and linked contracts on the left. On the right, **CLM Sync** shows each contract's record in your contract lifecycle system (Ironclad or Icertis): its status there, when it was last received and pushed, when the executed copy was filed, and any open conflicts in the steward queue. **Contract Family** shows the parent agreement, the other agreements under it, and what the contract renews or is renewed by. **Execution Handoff** sits below them.

## Who is told what

| Notice | When | Who |
| - | - | - |
| Due diligence launched | Once per performed assessment, when its portal invitation goes out | The Transaction Owner and the TPRM Office |
| Due diligence complete | The first time every domain is complete or reused | The TPRM Office and the Risk Groups |
| Risk Summary ready | At the same moment | The Transaction Owner |

Both completion notices list the domains satisfied by reused diligence. If a review reopens before anyone decided, the completion is cleared and sent again when it completes. After a decision, it is not.

The **Transaction Owner** is the engagement's relationship owners (people and groups), plus whoever raised the intake request a linked assessment came from. An engagement with no owners of its own uses the vendor's.

## Delivery

**Delivery** on the Risk Summary shows, for each recipient, **Sent**, **In their notifications**, **Seen** or **Read in app** with dates, and **Emailed** with the time the email went out.

With **Risk Summary Open Tracking** on (step 1), it also shows **Email opened** with the date of the first open, or **Email not opened yet**. The card says whether tracking is on. An open is an image load: a mail client that blocks images never reports one, and a security scanner can report one before anyone read the email, so **Read in app** is the stronger fact.

## The corporate family

On the vendor's page, **Corporate Family** shows the vendor's parent and subsidiaries. Click **Set parent company**, choose the parent vendor and **Save**. The family's rating, contract value and engagements roll up to the ultimate parent. **Remove parent** detaches it.

Vendors and engagements can also carry a **Business Unit**, which the reviewer matrix and dashboards use.

## Troubleshooting

| What you see | Cause | Fix |
| - | - | - |
| **Opens when due diligence is complete.** instead of the decision buttons | A risk domain is still not complete or reused. | Check **Risk Groups** for the domain still open. |
| **Link an assessment to start due diligence.** | No assessment is linked. | Click **Link assessment**. |
| The tracker reads **Exit under way** | The engagement has an open offboarding request. | Work the exit plan on the **Exit** tab, or cancel the request. |
| No expected decision date | An open review has no SLA target, or a decision is already recorded. | Set SLA targets on your risk domains. |
| A domain shows **Not started** although a reused assessment covers it | The reuse decision marked the domain for an abbreviated review or new due diligence, not reuse. | Expected. Only domains marked for reuse are satisfied. |
| The TPRM Office got no notices | No TPRM Office group is set. | Set it under **Lifecycle Routing and Reminders**. |
| The **CLM Sync** card says the contract is not synced yet | Your contract lifecycle system is connected, but this contract has not been sent to it or received from it. | Wait for the next sync, or open the connection from the card. |
| **Proceed to contracting** did not open a new handoff | A handoff is already pending or done for this engagement. | Open the **Contract** tab. |
| A past-due reminder copied nobody internal | The lifecycle settings were never saved. | Change a setting under **Lifecycle Routing and Reminders** to save them. |

## Related

<CardGroup cols={2}>
  <Card title="Front Door triage" icon="door-open" href="/user-guides/front-door-triage">
    Where reuse is decided.
  </Card>

  <Card title="Monitoring plans" icon="calendar-check" href="/user-guides/monitoring-plans">
    What the engagement owes once active.
  </Card>

  <Card title="Offboarding and continuity" icon="right-from-bracket" href="/user-guides/offboarding-and-continuity">
    The contract handoff and the exit.
  </Card>

  <Card title="The vendor record" icon="building" href="/user-guides/vendor-record">
    Vendors, services and engagements.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.