Dashboards and Reports
About 5% of the CIS-TPRM exam — see all 7 domains.
Vendor Risk Management Workspace
The Vendor Risk Management Workspace is the single-pane workspace for third-party risk managers. It shows the overall risk posture of the third-party ecosystem, supports day-to-day work (performing/tracking assessments, issues, tasks), and offers a home page of actionable insights and quick links.
Vendor Risk Overview reports
Out-of-the-box Vendor Risk Overview reports/dashboards give visibility into vendor tiering, risk and tier assessment plans, open issues, and risk across vendors.
Performance Analytics and platform reporting
Dashboards are customizable; reports can be scheduled or run on demand using standard platform reporting and Performance Analytics. A GRC Risk Management PA content pack exists at the broader IRM/Risk layer. (There is no separately named, dedicated "TPRM Performance Analytics content pack" confirmed in docs — reporting is delivered via the workspace + Vendor Risk Overview reports + platform PA.)
Sample questions from this domain
Three of the 14 in this domain, with the reasoning. The full set is in the question bank.
What is the primary purpose of VRM dashboards?
- A. To give internal stakeholders visibility into vendor risk posture and program metrics at a glance ✓
- B. To store the vendor's invoices
- C. To configure the CMDB
- D. To let vendors edit their own risk scores
Why: VRM dashboards provide internal stakeholders an at-a-glance view of vendor risk posture and program metrics. They are not for vendor self-scoring, invoice storage, or CMDB configuration.
Which metric would most likely appear on a VRM program dashboard?
- A. The number of printers per floor
- B. The instance's CPU temperature
- C. The cafeteria's daily menu
- D. Number of vendors by tier or risk band ✓
Why: Vendors by tier or risk band is a typical VRM dashboard metric. Cafeteria menus, CPU temperature, and printer counts are not vendor-risk metrics.
Which TWO reports are commonly valuable in a VRM program? (Choose two)
- A. The color palette used in the portal
- B. Employee lunch preferences
- C. Overdue assessments by vendor ✓
- D. Network switch port utilization
- E. Open vendor risk issues by severity ✓
Why: Overdue-assessment and open-issues-by-severity reports give actionable program insight. Lunch preferences, switch utilization, and portal color palettes are not VRM reporting needs.