CIS-TPRM Certified Implementation Specialist - Third-party Risk Management Practice Questions
Prepare for CIS-TPRM with more than an answer.
- Level
- Certified Implementation Specialist
- Valid for
- Maintained via annual maintenance (delta) exams and yearly Certification Maintenance Program (CMP) fee
Domains covered on the exam 6
- Third-party Risk Management Fundamentals and Third-party Risk Management Review23%
- Core Configuration14%
- Assessment Configuration33%
- Third-party Portal12%
- Third-party Supporting Processes12%
- Other Application Relationships6%
- 1
True or False: In ServiceNow TPRM, third-party risk assessments can be used to monitor the compliance of specific GRC Controls associated with a third party.
Show answer details
Correct answer: A
True. ServiceNow TPRM is tightly integrated with the broader GRC suite. When a third party responds to an assessment, those responses can be mapped to automatically update the compliance status of specific GRC Controls applied to that vendor. This eliminates manual evidence gathering and ensures continuous compliance monitoring.
- 2
When configuring the Third-party Contact form, which of the following fields are included by default? (Select TWO)
Show answer details
Correct answer: A, C
The Third-party Contact form includes fields relevant to the individual user, such as whether they are the Primary contact for that vendor.
Email is a standard field on the Third-party Contact form, necessary for portal access and notifications. Fields like 'Rank tier' and 'Risk rating' belong on the parent Third-party organizational record, not the individual contact record.
- 3
When setting up the Third-party Portfolio, how are individual engagements or services provided by a third party represented?
Show answer details
Correct answer: B
In the TPRM data model, a single third party may provide multiple distinct services (e.g., cloud hosting and payroll processing). These are represented as separate Third-party Engagement records linked to the parent Third-party record, allowing for granular risk assessments specific to each service.
- 4
A global financial institution is implementing ServiceNow TPRM and wants to automate the initial risk scoring of new third parties before sending any questionnaires. They have subscribed to an external risk intelligence provider.
They need to ensure that the scoring data flows seamlessly into the TPRM application and updates the third-party record appropriately.
Which configuration approach is required to enable this automated risk intelligence scoring?
Show answer details
Correct answer: B
ServiceNow TPRM provides native integration capabilities for risk intelligence scoring. The correct approach is to enable the specific integration, map the external data feeds to the internal scoring logic, and use scheduled jobs to pull the data automatically. Manual methods or screen scraping are not best practices.
graph LR Ext[Risk Intelligence Provider] -->|API Feed| Int[Risk Intel Integration] Int --> Score[Scoring Logic] Score --> TPR[Third-party Record] TPR --> Tier[Rank Tier Update] - 5
What is the primary business value of the ServiceNow Third-party Risk Management (TPRM) application?
Show answer details
Correct answer: B
The primary purpose of the TPRM application is to centralize, standardize, and automate the third-party risk lifecycle. It eliminates the need for manual tracking via emails and spreadsheets, providing a single source of truth for vendor risk data, assessments, and issues.
- 6
Which of the following represents the standard logical sequence of the end-to-end Third-party Risk Management process in ServiceNow?
Show answer details
Correct answer: C
The standard TPRM process begins with Onboarding the third party. Next, Tiering (via IRQ) determines the risk level. Based on the tier, an Assessment is conducted. Any findings result in Issue Management. Finally, the relationship enters Continuous Monitoring to track ongoing risk.
