CIS-VRM Sample Questions & Answers
Assessment basics, tiering and risk scoring take the biggest share, next to a general grounding in the process itself, setting up portfolios and contact records, the vendor-facing portal, approval chains, and ties to other GRC capabilities.
Launch the full CIS-VRM simulator →Free CIS-VRM Sample Questions with Answers
Real questions from the Certified Implementation Specialist - Vendor Risk Management practice test — answers and explanations included. Showing 10 of 20 free samples.
- Question 1Intermediate
Supporting Processes · Third-party Risk Issues Approval
A TPRM manager has a requirement that any 'High' severity issue generated from an assessment for a 'Tier 1' third party must be approved by the Director of Compliance before it can be moved to the 'Awaiting Implementation' state. What is the most appropriate tool in ServiceNow to automate this specific approval requirement?
Show answer & explanation
Correct answer: D
Flow Designer is the modern and recommended approach for creating complex, conditional approval workflows. A flow can be triggered when an issue is created or updated. It can then use 'If' logic to check if the issue's severity is 'High' and the related third party's tier is 'Tier 1'. If both conditions are met, it can use the 'Ask for Approval' action to route the request to the specified user or group.
- Question 2Advanced
Application Relationships · Monitor Risk and Control Compliance
A healthcare organization uses ServiceNow TPRM to manage suppliers of critical medical software. After an assessment, a high-risk issue related to HIPAA compliance is identified. The risk team needs to formally track this risk and link it to a specific HIPAA control. Which is the best practice for handling this within the GRC and TPRM applications?
Show answer & explanation
Correct answer: B
The standard ServiceNow GRC process is to elevate a vendor risk issue into a formal Risk record in the Risk Register. This allows for comprehensive risk assessment, scoring, and treatment planning. The Risk record can then be directly associated with the specific Control Objective (e.g., a specific HIPAA control from the UCF), creating a clear audit trail from the assessment finding to the compliance framework.
- Question 3Intermediate
Core Configuration · Third-party Portfolio Configuration
A TPRM administrator is importing a large number of third-party records from a legacy system. The import set contains a 'Country' column. The administrator needs to ensure that the imported string for the country is correctly mapped to the corresponding
core_countryreference field on the Company table. Which feature of the import process should be used to accomplish this?Show answer & explanation
Correct answer: D
When mapping a source field containing a display value (like a country name) to a target reference field, the correct approach is to use a standard Field Map and specify the 'Referenced value field name'. By setting this to 'name', you instruct the Transform Map to look up records in the referenced table (
core_country) where the 'name' field matches the incoming source value, and then populate the target field with the sys_id of the found record. - Question 4Beginner
Assessment Configuration · Third-party IRQ (Tiering) and Due Diligence Configuration
What is the primary function of an Inherent Risk Questionnaire (IRQ) in the ServiceNow Third-party Risk Management process?
Show answer & explanation
Correct answer: B
The IRQ is an internal-facing questionnaire. Its primary purpose is for the business owner or relationship manager to provide information about the nature of the engagement with the third party (e.g., what data they will access, how they will connect). The answers are then used to calculate an inherent risk score and automatically determine the third party's tier, which in turn drives the level of due diligence required.
- Question 5Intermediate
Assessment Configuration · Assessment Lifecycle
A user with the
sn_vdr_risk_asmt.vendor_assessorrole reports that they are unable to see the 'Generate Observations' UI action on a Third-party Risk Assessment record that is in the 'Responses Received' state. What is the most likely reason for this issue?stateDiagram-v2 [*] --> Submitted Submitted --> "Responses Received" : vendor responds "Responses Received" --> "Generating Observations" : assessor action "Generating Observations" --> Finalizing : system process Finalizing --> ClosedShow answer & explanation
Correct answer: B
While the
sn_vdr_risk_asmt.vendor_assessorrole provides the necessary permissions to perform the action, the 'Generate Observations' UI action has a condition that requires the logged-in user to be the individual specified in the 'Assigned to' field of that specific assessment record. This ensures that only the designated assessor can advance the assessment. - Question 6Advanced
Fundamentals and Review · About Third-party Risk Management
Case Study: FinCorp, a large investment bank, is implementing ServiceNow TPRM. They have over 5,000 third parties, ranging from large technology providers to small independent contractors. The Chief Risk Officer (CRO) has mandated a new, highly structured governance process.
Current Situation: Third-party onboarding is manual and inconsistent. Risk assessments are performed using spreadsheets and are not standardized. There is no central repository of third-party information, leading to duplicate efforts and a lack of visibility into overall risk exposure. The process for managing identified issues is ad-hoc, with no formal tracking or approval.
Requirements:
- A centralized, authoritative source for all third-party data.
- An automated, risk-based tiering system to categorize all 5,000 third parties based on their inherent risk.
- A streamlined assessment process where the type and depth of the questionnaire are determined by the third party's tier.
- A formal, multi-level approval workflow for any 'High' or 'Critical' risk issues identified, requiring sign-off from the business owner, the risk team, and the CISO.
- A dedicated portal for third parties to respond to assessments and manage their information.
Which ServiceNow feature is LEAST relevant to meeting the CRO's mandated requirements?
Show answer & explanation
Correct answer: C
While SAM Pro can be a valuable related application for managing software vendors, it is not a core component for meeting the specified requirements of centralized data, risk-based tiering, automated assessments, issue approval workflows, and a vendor portal. The other options directly address the CRO's mandates using core TPRM functionality.
- Question 7Beginner
Portal Configuration · Third-party Portal Configuration
A TPRM administrator wants to provide third-party contacts with the ability to ask questions and get help directly within the Third-party Portal. Which feature should be enabled and configured to provide this functionality?
Show answer & explanation
Correct answer: D
The ServiceNow Virtual Agent can be configured and exposed on the Third-party Portal to provide a conversational interface for third parties. It can be designed to answer frequently asked questions, guide users through processes, or create cases for the internal TPRM team if the issue cannot be resolved automatically.
- Question 8BeginnerSelect 2
Assessment Configuration · Assessment Lifecycle
Which of the following are valid states in the default lifecycle of a Third-party Risk Assessment? (Select TWO)
Show answer & explanation
Correct answers: B, D
The default assessment lifecycle includes several key states. 'Submitted to Third Party' indicates the assessment is with the external contact for completion. 'Finalizing with Third Party' is a state where the internal team reviews the submitted responses and may ask for clarification before closing the assessment. 'Pending Approval' and 'Awaiting Implementation' are typically states for Issues, not the assessment itself.
- Question 9Advanced
Application Relationships · Other Application Relationships
A company has integrated ServiceNow TPRM with a third-party risk intelligence provider that continuously monitors for security incidents. An alert is received indicating a critical data breach at a 'Tier 1' third party. Which ServiceNow application should this alert be routed to for immediate investigation and response, while also linking it back to the third party's risk profile?
Show answer & explanation
Correct answer: C
For security-related events like data breaches, the best practice is to route the alert to the Security Incident Response (SIR) application within ServiceNow Security Operations. A security incident can be created, which allows for a formal, structured investigation by the security team. The security incident can then be linked to the third party's company record and a corresponding GRC Issue can be created to track the risk impact within the TPRM application.
- Question 10Beginner
Fundamentals and Review · Technical Details
True or False: The
sn_vdr_risk.vendor_adminrole allows a user to configure all aspects of the Third-party Risk Management application, including creating questionnaire templates and modifying risk scoring calculations.Show answer & explanation
Correct answer: B
False. The
sn_vdr_risk.vendor_adminrole has limited administrative capabilities, primarily focused on managing vendor records and contacts. The role required to configure core application settings like questionnaire templates, risk scoring, and tiering rules issn_vdr_risk_asmt.vendor_risk_manager.
Ready for the real thing?
The full CIS-VRM simulator has every exam-style question, timed mode, and instant scoring.