PE PowerExams Prepare. Practice. Pass.
CIS-TPRM · Domain 6 of 7

Other Application Relationships

About 5% of the CIS-TPRM exam — see all 7 domains.

5%
of the exam
15
practice questions
7
domains total

Part of Integrated Risk Management (IRM/GRC)

TPRM is a component of ServiceNow Integrated Risk Management (IRM), which unifies risk data across Policy & Compliance Management, Risk Management, Compliance Case Management, audit, and third-party risk. (IRM Standard bundles Policy & Compliance Management, Compliance Case Management, and Risk Management.)

CMDB

The CMDB provides shared context across systems, assets, and business services used in risk analysis. TPRM and IRM lean on this for linking third parties/engagements to the business applications and services they support.

Continuous monitoring — external risk-intelligence providers

TPRM integrates external risk-intelligence / security-rating feeds for continuous monitoring. Incoming provider scores can auto-update third-party records and trigger threshold-based workflows (e.g., create an issue when a score drops). Provider domains and example integrations (available as ServiceNow Store apps):

  • Cyber security ratings: BitSight, SecurityScorecard, RiskRecon (by Mastercard), UpGuard
  • Supply chain: Interos
  • ESG: EcoVadis
  • Financial: Dun & Bradstreet
  • Sanctions/screening: World-Check

Sample questions from this domain

Three of the 15 in this domain, with the reasoning. The full set is in the question bank.

Question 1 · easy

How does VRM commonly relate to Policy and Compliance Management?

  • A. VRM disables all compliance controls
  • B. Vendor assessment questions can map to controls/authority documents, supporting compliance reporting
  • C. They cannot share any data
  • D. VRM replaces Policy and Compliance Management entirely

Why: VRM can map assessment questions to controls and authority documents managed in Policy and Compliance, supporting compliance reporting. VRM does not replace or disable Policy and Compliance, and the two can share data within the GRC/IRM core.

Question 2 · medium

How can VRM leverage the CMDB?

  • A. By deleting CIs that have vendors
  • B. By preventing CMDB discovery
  • C. By relating vendors to the services, applications, or CIs they support, adding business context to risk
  • D. By replacing the CMDB with vendor records

Why: VRM can relate vendors to the services/applications/CIs they support, enriching risk with business context. It does not replace the CMDB, delete CIs, or block discovery.

Question 3 · medium

What is the value of integrating VRM with Risk Management (IRM)?

  • A. It isolates vendor risk from the enterprise view
  • B. It converts all risks into incidents
  • C. Vendor risks can be rolled up and considered alongside enterprise risks for unified governance
  • D. It removes the need for vendor assessments

Why: Integration with Risk Management lets vendor risks roll up alongside enterprise risks for unified governance. It does not convert risks to incidents, remove assessments, or isolate vendor risk.