PE PowerExams Prepare. Practice. Pass.
CIS-TPRM · Domain 3 of 7

Assessment Configuration

About 25% of the CIS-TPRM exam — see all 7 domains.

25%
of the exam
75
practice questions
7
domains total

This is the single heaviest domain. Master how assessments are built, generated, scored, and progressed through their life cycle.

Building blocks: templates, questionnaires, document requests

An assessment in TPRM combines two collection mechanisms: questionnaires (sets of questions the third party answers) and document requests (artifacts such as SOC 2 reports or certifications the third party uploads). Both feed the score.

Assessment templates are reusable containers that bundle the questionnaires, document requests, and scoring rules to apply for a given situation. Because they are reusable, a template can be triggered repeatedly as a third party's risk tier or responses change, without rebuilding the assessment each time. Questionnaire and document-request templates are themselves managed objects (created/edited by the Third-Party Risk Admin role).

TPRM supports industry-standard questionnaires, notably the SIG (Standardized Information Gathering) questionnaire from Shared Assessments, so organizations can assess vendors consistently and at scale rather than authoring every question from scratch.

Risk areas (risk domains) and weighting

Assessments are organized by risk area / risk domain. Out-of-the-box areas include security risk, privacy and data protection, regulatory/compliance, financial risk, operational risk, business continuity, and resilience. Each risk area is assigned a weight and a scoring method. The weight is a numeric value expressing the relative importance of that area — a higher weight means that area contributes more to the overall rating. This is how an implementer makes, say, security risk matter more than operational risk for a critical SaaS vendor.

Scoring and rating calculations (classic engine)

Under the classic assessment engine, the assessment rating is calculated by averaging the questionnaire and document-request scores within each risk area, then multiplying by that risk area's weight. A normalized value is derived by multiplying a category's rating by its weight, which standardizes comparison across categories of differing weight.

The resulting risk score is mapped to a band using a risk rating scale. The default scale takes a score on a 0–100 range and maps it to a five-tier band: 1 – Very High, 2 – High, 3 – Medium, 4 – Low, 5 – Very Low. The default scoring rule relies on "default risk criteria" and "default component criteria" (the default component criteria consider only third-party risk assessment results). Implementers can configure these rating scales and scoring rules.

Watch the direction of the scale. A low number (1) means higher risk (Very High), and a high number (5) means lower risk (Very Low). Exam items like to invert this.

Smart Assessment Engine (SAE)

The Smart Assessment Engine is a shared/core capability across the ServiceNow GRC (IRM) portfolio — common assessment infrastructure used by multiple modules, not a standalone tool. It is the forward-looking alternative to the classic engine. (The classic-engine scoring doc page is now explicitly titled for the "classic" engine, signaling the two coexist; the older external-assessment creation flow is now labeled the "Legacy process.")

Key SAE concepts:

  • Assessment metric categories group related metrics; each category and metric carries a weight.
  • Scoring can be configured at the question, subsection, section, and assessment levels, with optional normalization for fair cross-assessment comparison.
  • A weighted, normalized score is calculated for each target record. Questions and section metrics can be reused as variables.
  • In TPRM, SAE enables automated third-party assessments with scoring, issue generation, and event-driven rules.

Assessment generation, scheduling, and submission rules

Assessments can be generated automatically rather than hand-launched. Two submission rule types drive this:

  • Tier-based submission rules — auto-submit an assessment to a third party based on the third party's tier + an assessment template.
  • Provider-based submission rules — auto-submit based on a security-score provider, the vendor, the security score, and the vendor tier (i.e., an external rating feed can trigger an assessment).

For continuous coverage, organizations configure recurring reassessment cycles (e.g., annual). Assessments are distributed to the third party at the configured interval, and an assessment can auto-submit when a tier changes — provided a primary contact exists to receive it.

Assessment life cycle states

The third-party (external) risk assessment progresses through states. The documented progression is approximately: Draft → Submitted to vendor → Responses received → Generating observations → Finalizing with vendor → Closed. During "Submitted to vendor", the third party works the tasks, issues, and questionnaires. For an internal-only assessment, the Submitted to Vendor → Finalize with Vendor steps can be bypassed (no external party to wait on).

Disambiguation (FLAG). Do not conflate the assessment record states (Draft / Submitted to vendor / Responses received / Generating observations / Finalizing with vendor / Closed) with the issue/record workflow wording (New / Analyze / Submitted to Vendor / Finalize with Vendor / Review / Closed Complete). The exam may test exact labels for each — read the official "Life cycle states of a third-party (external) risk assessment" page directly to confirm.


Sample questions from this domain

Three of the 75 in this domain, with the reasoning. The full set is in the question bank.

Question 1 · easy

In VRM, what is an assessment questionnaire template primarily used for?

  • A. Storing the vendor's invoices
  • B. Configuring the instance's logging level
  • C. Defining a reusable set of questions and structure that can be issued to vendors
  • D. Managing internal employee onboarding

Why: A questionnaire template defines a reusable, structured set of questions to issue to vendors. It is not for invoices, logging configuration, or employee onboarding.

Question 2 · medium

Which component organizes related questions within an assessment into logical groupings?

  • A. Categories/sections within the questionnaire
  • B. The instance node cluster
  • C. The email notification footer
  • D. CMDB relationship rules

Why: Questions are organized into categories/sections that group related items (for example access control, data protection). CMDB rules, node clusters, and email footers do not structure questionnaire content.

Question 3 · medium

When configuring scoring, what determines how much a given question or category contributes to the overall assessment score?

  • A. The time of day the assessment is opened
  • B. The vendor's mailing address
  • C. The weighting assigned to questions/categories and the response scoring values
  • D. The alphabetical position of the question

Why: Weighting on questions/categories combined with the scoring values of responses determines each item's contribution to the overall score. Address, alphabetical order, and time of day have no effect on scoring.