Other Application Relationships
About 5% of the CIS-TPRM exam — see all 7 domains.
Part of Integrated Risk Management (IRM/GRC)
TPRM is a component of ServiceNow Integrated Risk Management (IRM), which unifies risk data across Policy & Compliance Management, Risk Management, Compliance Case Management, audit, and third-party risk. (IRM Standard bundles Policy & Compliance Management, Compliance Case Management, and Risk Management.)
CMDB
The CMDB provides shared context across systems, assets, and business services used in risk analysis. TPRM and IRM lean on this for linking third parties/engagements to the business applications and services they support.
Continuous monitoring — external risk-intelligence providers
TPRM integrates external risk-intelligence / security-rating feeds for continuous monitoring. Incoming provider scores can auto-update third-party records and trigger threshold-based workflows (e.g., create an issue when a score drops). Provider domains and example integrations (available as ServiceNow Store apps):
- Cyber security ratings: BitSight, SecurityScorecard, RiskRecon (by Mastercard), UpGuard
- Supply chain: Interos
- ESG: EcoVadis
- Financial: Dun & Bradstreet
- Sanctions/screening: World-Check
Sample questions from this domain
Three of the 15 in this domain, with the reasoning. The full set is in the question bank.
How does VRM commonly relate to Policy and Compliance Management?
- A. VRM disables all compliance controls
- B. Vendor assessment questions can map to controls/authority documents, supporting compliance reporting ✓
- C. They cannot share any data
- D. VRM replaces Policy and Compliance Management entirely
Why: VRM can map assessment questions to controls and authority documents managed in Policy and Compliance, supporting compliance reporting. VRM does not replace or disable Policy and Compliance, and the two can share data within the GRC/IRM core.
How can VRM leverage the CMDB?
- A. By deleting CIs that have vendors
- B. By preventing CMDB discovery
- C. By relating vendors to the services, applications, or CIs they support, adding business context to risk ✓
- D. By replacing the CMDB with vendor records
Why: VRM can relate vendors to the services/applications/CIs they support, enriching risk with business context. It does not replace the CMDB, delete CIs, or block discovery.
What is the value of integrating VRM with Risk Management (IRM)?
- A. It isolates vendor risk from the enterprise view
- B. It converts all risks into incidents
- C. Vendor risks can be rolled up and considered alongside enterprise risks for unified governance ✓
- D. It removes the need for vendor assessments
Why: Integration with Risk Management lets vendor risks roll up alongside enterprise risks for unified governance. It does not convert risks to incidents, remove assessments, or isolate vendor risk.