Vendor Portal Configuration
About 15% of the CIS-TPRM exam — see all 7 domains.
The Third-Party Portal
The Third-Party Portal (formerly the Vendor Portal) is a secure, external-facing interface where third parties collaborate with the risk team: view and respond to assessments, upload requested documents, and track tasks and deadlines. It is how external parties participate without access to the full Now Platform instance.
External user access and portal roles
Third-party contacts become external users. Each is automatically assigned two roles:
vendor_contact— grants access to the Third-Party Portal.snc_external— restricts the user to the portal only, preventing access into the full instance.
Together these mean a vendor contact can log in and work assessments but cannot roam the customer's instance.
Contacts and the primary contact
Each third party must have at least one primary contact. The primary contact receives assessment questionnaires. A TPR Manager or Assessor — or the primary contact themselves — can create additional contacts. Contacts can delegate tasks, update their information, and set notification preferences from the portal.
Responding to assessments
Vendors respond online in the portal and can use "Save and Sign" to apply an e-signature (typed or drawn). Alternatively they can use an offline path: download an Excel template, complete it offline, and re-import the responses.
Sample questions from this domain
Three of the 44 in this domain, with the reasoning. The full set is in the question bank.
What is the primary purpose of the VRM vendor portal?
- A. To run CMDB discovery
- B. To host the organization's public marketing website
- C. To provide internal admins a place to configure scoring
- D. To give external vendor users a secure interface to view and complete assessments and tasks ✓
Why: The vendor portal provides external vendor users a secure place to view and complete assessments and tasks. It is not a marketing site, the internal scoring console, or a discovery tool.
Which type of user account is provisioned for vendor contacts to access the portal?
- A. An internal employee account with all internal roles
- B. A full platform administrator account
- C. An external user account with limited, portal-appropriate roles/permissions ✓
- D. An anonymous account requiring no identity
Why: Vendor contacts receive external user accounts with limited, portal-appropriate permissions so they can only access what they should. They are not given admin or full internal accounts, and access is authenticated, not anonymous.
Why is access control especially important in the vendor portal?
- A. Access control only matters for internal users
- B. External vendor users must only see their own organization's data, not other vendors' information ✓
- C. External users should see all vendors' assessments for benchmarking
- D. The portal has no security requirements
Why: Portal access control must restrict each vendor user to their own organization's data, preventing cross-vendor exposure. Showing all vendors' data, ignoring security, or limiting concern to internal users would create serious data-isolation risks.