Core Configuration
About 13% of the CIS-TPRM exam — see all 7 domains.
Roles (hierarchy, each inherits the one below)
- Third-Party Reader — read access to third-party and contact records.
- Third-Party Editor — create/update/delete third-party and contact records.
- Third-Party Assessment Reviewer (
sn_vdr_risk_asmt.vendor_assessment_reviewer) — view assessment and questionnaire data. - TPR Assessor (
sn_vdr_risk_asmt.vendor_assessor) — reviewer permissions plus manage third parties, engagements, assessments, and issues. - TPR Manager (
sn_vdr_risk_asmt.vendor_risk_manager) — assessor permissions plus manage assessment templates, scheduled assessments, property settings, and scoring rules. - Third-Party Risk Admin — manager permissions plus create/edit questionnaire and document-request templates.
The exact internal ID for "Third-Party Risk Admin" should be confirmed on the live roles page (see grounding). The four IDs above are the load-bearing ones to memorize.
Plugins / Store applications to activate
Standing up TPRM typically requires installing:
- Third-party Risk Management app —
com.sn_vdr_risk_asmt - Due diligence request workflow app —
com.sn_tprm_dd - Vendor Risk Management Workspace app —
sn_vrm_ws
On older (pre-Madrid) instances, the legacy entry point was the GRC: Vendor Risk Management plugin (com.sn_vdr_risk_asmt).
Tiering setup
Risk tiering is configured via tiering assessments and IRQ scoring models. The tiering score classifies the third party (Tier 1/2/3 by criticality) and the value lands on the third-party record once the tiering assessment is approved, reflecting the most recent approved result.
Sample questions from this domain
Three of the 39 in this domain, with the reasoning. The full set is in the question bank.
Which activity is part of the initial core configuration of a VRM implementation?
- A. Activating the Vendor Risk Management plugin/store application and assigning VRM roles ✓
- B. Building a custom payroll calculation engine
- C. Designing the corporate intranet homepage
- D. Configuring email for the company's marketing newsletters
Why: Core configuration begins with activating the VRM application and assigning the appropriate VRM roles so users can perform their functions. Payroll engines, marketing email, and intranet design are unrelated to VRM setup.
Which VRM role is typically granted to internal staff who create and manage vendor records and assessments but are not system administrators?
- A. The platform admin (sn_admin) role only
- B. The guest/public role
- C. A VRM-specific functional role such as a vendor risk manager/assessor role ✓
- D. The catalog_admin role
Why: Functional VRM roles (such as vendor risk manager/assessor) let internal staff manage vendors and assessments without full platform admin rights. Admin grants far more than needed, guest is for unauthenticated access, and catalog_admin governs the Service Catalog.
When configuring vendor tiers, what should the tier definitions be aligned to?
- A. The organization's criticality/risk criteria so tier assignment reflects vendor importance ✓
- B. The number of portal themes installed
- C. The alphabetical order of vendor names
- D. The size of the vendor's logo file
Why: Tier definitions should map to the organization's criticality/risk criteria so a vendor's tier reflects its importance and risk. Vendor name order, logo file size, and theme count are irrelevant to tiering.