PE PowerExams Prepare. Practice. Pass.
CIS-TPRM · Domain 1 of 7

VRM Fundamentals and Review

About 24% of the CIS-TPRM exam — see all 7 domains.

24%
of the exam
72
practice questions
7
domains total

What the product does

ServiceNow Third-party Risk Management provides a centralized process for managing a third-party portfolio and completing the third-party assessment and remediation life cycle — assessing, mitigating, remediating, and continuously monitoring risk across the third-party ecosystem. It maintains an inventory of third parties, their risk tiers, engagement details, and contacts.

VRM → TPRM rename and scope expansion

The product was renamed from Vendor Risk Management to Third-party Risk Management in the Vancouver release, and TPRM was built on the existing VRM foundation. The rename reflects a scope expansion beyond IT vendors: where VRM centered on technology/IT partner risk, TPRM also covers suppliers, service providers, partners, facilities, contractors, and even customers.

Third parties, engagements, hierarchy, and tiering

  • Third party (vendor) record — the master record for a supplier/partner. Carries the current risk tier, which reflects the latest approved tiering assessment.
  • Engagement — documents a distinct product or service a third party provides. Different engagements need different depths of risk data based on data sensitivity, system access, and business impact. One third party can have many engagements.
  • Vendor hierarchy / relationships — third parties can be related to one another (e.g., parent/subsidiary, fourth-party relationships), supporting concentration and dependency analysis.
  • Tiering / criticality — third parties are classified by criticality (commonly Tier 1 High/Critical, Tier 2 Medium, Tier 3 Low). The tier is set by a tiering assessment and surfaces on the third-party record after approval.

Inherent Risk Questionnaires (IRQs) and Due Diligence

An Inherent Risk Questionnaire (IRQ) produces a risk score via a configurable scoring model that determines the scope and frequency of due diligence and can dynamically trigger external questionnaires based on the answers and resulting tier.

The Due Diligence process (a flagship TPRM-era capability) is a guided flow spanning onboarding due diligence → automated assessment → domain-specific information validation → ongoing engagement-level monitoring → issue remediation → renewal/offboarding. TPR Managers approve due-diligence requests; IRQs are created and assigned to TPR Assessors. This lets risk teams engage earlier in the engagement life cycle.


Sample questions from this domain

Three of the 72 in this domain, with the reasoning. The full set is in the question bank.

Question 1 · easy

Within the ServiceNow GRC/IRM product family, which application is purpose-built to manage the risk an organization inherits from its vendors and third parties?

  • A. Audit Management
  • B. Third-party Risk Management (TPRM) - formerly Vendor Risk Management (VRM)
  • C. Operational Resilience Management
  • D. Policy and Compliance Management

Why: Third-party Risk Management (TPRM) - renamed from Vendor Risk Management (VRM) in the Vancouver release - is the dedicated ServiceNow application for assessing and monitoring third-party/vendor risk. (The exam is still published as CIS-VRM.) Policy and Compliance governs internal policy, Audit Management runs audits, and Operational Resilience is a separate IRM app.

Question 2 · easy

Third-party Risk Management (TPRM, formerly VRM) is built on which foundational ServiceNow capability that also underpins Policy and Compliance and Risk Management?

  • A. The ITSM Incident Management framework
  • B. The Customer Service Management account model
  • C. The Now Platform GRC/IRM common core (risk, control, and assessment framework)
  • D. The HR Service Delivery case framework

Why: TPRM/VRM is part of the Governance, Risk, and Compliance (GRC) / Integrated Risk Management (IRM) suite and reuses the common core of risk, control, and assessment objects shared with Policy and Compliance Management and Risk Management. It is not built on ITSM Incident, HR case, or CSM account frameworks.

Question 3 · medium

A customer wants to understand which record represents a company that supplies goods or services and that VRM tracks for risk. Which core record type is used as the central party in the vendor portfolio?

  • A. Risk Statement record
  • B. Vendor (third-party) record
  • C. Control Objective record
  • D. Assessment Instance record

Why: The vendor (third-party) record is the central object in the VRM portfolio; it anchors contacts, hierarchy, tiering, assessments, and issues. An assessment instance is a generated questionnaire occurrence tied to the vendor; a risk statement describes a potential risk; a control objective describes a desired control state. None of those is the central party record.