📖 About this Domain
The Vendor Portal provides an external-facing interface for vendors to interact directly with your ServiceNow instance. It is the primary channel for vendors to complete assessments, respond to issues, and manage their profile information.
🎓 What You Will Learn
- Learn the process for registering vendor contacts and granting them access to the Vendor Portal.
- Understand how vendors receive, complete, and submit questionnaires and assessments assigned to them.
- Explore the mechanisms for vendors to view and respond to issues, tasks, and document requests.
- Recognize the key components and configurable elements of the Vendor Portal user interface.
🛠️ Skills You Will Build
- Configuring vendor contact records and managing user accounts for portal access.
- Troubleshooting vendor login issues and guiding users through the assessment submission process.
- Interpreting vendor responses and data submitted through the portal within the VRM application.
- Customizing portal branding and layout to align with corporate standards.
💡 Top Tips to Prepare
- Know the specific role, sn_vdr_risk_asmt.vendor_contact, required for a user to access the Vendor Portal.
- Memorize the default portal pages and widgets available to a vendor contact upon login.
- Understand the end-to-end workflow from assigning an assessment to a vendor to its submission via the portal.
- Focus on how issues and tasks created in the core UI are presented to and actioned by the vendor in the portal.
📖 About this Domain
This domain details the lifecycle of vendor risk issues within the ServiceNow GRC: Vendor Risk Management application. It covers the processes for identifying, creating, managing, and remediating issues that arise from vendor risk assessments.
🎓 What You Will Learn
- You will learn how issues are generated, either automatically from assessment indicator results or manually by a vendor risk manager.
- You will understand the creation and management of remediation tasks, which are assigned to stakeholders to resolve identified issues.
- You will learn the state flows for both issues and tasks, including transitions from 'Open' to 'Closed Complete' states.
- You will understand how issue grouping and rollups contribute to the overall vendor risk score and posture.
🛠️ Skills You Will Build
- You will build the skill to configure the conditions under which issues are automatically created from assessment responses.
- You will be able to manage the end-to-end remediation lifecycle, including task assignment, progress monitoring, and final validation.
- You will develop the ability to report on issue and remediation metrics, such as overdue tasks and aging issues.
- You will gain proficiency in navigating the relationship between the Vendor, Assessment, Issue, and Remediation Task tables.
💡 Top Tips to Prepare
- Memorize the relationship between an assessment's Indicator Result, an Issue, and a Remediation Task.
- Understand the key tables involved, specifically sn_vdr_risk_asmt_issue for issues and sn_grc_task for remediation tasks.
- Practice creating and closing an issue in a Personal Developer Instance (PDI) to understand the state model and required fields.
- Review the Vendor Risk Management properties that control automatic issue creation and task assignment.
📖 About this Domain
This domain covers the foundational setup of the Vendor Risk Management application. It focuses on configuring core data, system properties, and templates required to operationalize the VRM lifecycle.
🎓 What You Will Learn
- Configure the vendor portfolio by managing company records, vendor contacts, and parent-child relationships.
- Set critical system properties that govern assessment workflows, notifications, and overall VRM application behavior.
- Create and manage assessment templates, including questionnaires and document requests, using the Assessment Designer.
- Implement vendor tiering assessments to classify vendors and determine the required level of due diligence.
🛠️ Skills You Will Build
- Implement the VRM data model by correctly populating and relating vendor and contact records.
- Administer system properties to tailor the VRM application to specific business requirements.
- Design dynamic and effective risk assessments using questionnaire templates and risk scoping.
- Configure automated vendor onboarding and tiering processes through guided setup and property settings.
💡 Top Tips to Prepare
- Understand the core_company table structure and the significance of the 'Vendor' checkbox for VRM processes.
- Gain practical experience in the Assessment Designer, focusing on question types, dependencies, and scoring logic.
- Utilize the VRM Guided Setup in a Personal Developer Instance to understand the configuration sequence.
- Familiarize yourself with the key properties in the Vendor Risk > Administration > Properties module.
📖 About this Domain
The Vendor Portfolio domain focuses on the foundational data structures for managing third parties in ServiceNow. It covers the creation and maintenance of vendor records, contacts, and hierarchies within the core_company table. This domain is critical for establishing the single source of truth for all vendor-related activities.
🎓 What You Will Learn
- You will learn to configure and manage the vendor portfolio, including creating vendor records and defining parent-child relationships.
- This domain teaches how to configure and utilize the Vendor Portal for external vendor collaboration and assessment submission.
- You will understand how to configure the Vendor Tiering engine to automatically classify vendors based on criticality.
- It covers defining Vendor Risk Areas to scope and categorize potential risks associated with each vendor.
🛠️ Skills You Will Build
- You will build proficiency in managing vendor data directly within the core_company table and its related lists.
- You will gain the ability to configure the Service Portal for vendors, including user provisioning and page customization.
- You will develop skills in creating and applying Tiering Assessments to automate vendor classification.
- You will be able to establish and manage vendor contacts and their specific roles within the VRM process.
💡 Top Tips to Prepare
- Focus on the relationship between the core_company table and the vendor-specific fields and related lists.
- Practice the end-to-end process of onboarding a new vendor, from record creation to portal access.
- Understand the properties and script includes that govern the Vendor Tiering Assessment process.
- Memorize the key roles like sn_vdr_risk_asmt.vendor_assessor and sn_vdr_risk_asmt.vendor_contact and their permissions.
📖 About this Domain
The Integrations domain covers connecting ServiceNow VRM with external data sources and internal applications. It focuses on leveraging third-party risk intelligence, GRC modules, and standardized content packs to enhance the vendor risk management process.
🎓 What You Will Learn
- Learn to configure integrations with third-party risk intelligence providers to pull in security scores and reports.
- Understand the data model relationship between VRM and ServiceNow GRC for escalating issues and managing risk.
- Discover how to import and utilize Standardized Information Gathering (SIG) content packs for assessments.
- Explore the use of Integration Hub and spokes to automate data collection from various external systems.
🛠️ Skills You Will Build
- You will build the skill to configure and map data from external security rating services into vendor risk scores.
- Develop the ability to integrate VRM processes with the broader GRC framework for centralized issue and risk tracking.
- Gain proficiency in deploying and managing SIG questionnaire templates for standardized vendor evaluations.
- Acquire the capability to use Integration Hub for creating custom data flows into the VRM application.
💡 Top Tips to Prepare
- Memorize the key configuration properties and scheduled jobs associated with third-party risk intelligence integrations.
- Study the table relationships between VRM and GRC, specifically how issues are generated from assessment findings.
- Practice the import process for SIG content packs in a PDI to understand the required steps and outcomes.
- Review the documentation for the VRM spokes available on the ServiceNow Store to know their capabilities.
📖 About this Domain
This domain covers the foundational concepts of the ServiceNow Vendor Risk Management (VRM) application. It explains the VRM lifecycle, key personas, and the application's architecture. You will understand how the VRM application functions within the Now Platform's GRC framework.
🎓 What You Will Learn
- You will learn the end-to-end VRM process, including vendor onboarding, tiering, assessment, issue management, and offboarding.
- You will identify the key personas like Vendor Risk Manager and Assessor and their specific roles within the VRM workflow.
- You will understand the core VRM data model, including key tables like core_company, sn_vdr_risk_asmt_assessment, and their relationships.
- You will learn how VRM integrates with other ServiceNow GRC applications and leverages the core GRC entity structure.
🛠️ Skills You Will Build
- You will build the skill to articulate the complete ServiceNow VRM lifecycle and its distinct phases.
- You will be able to configure the VRM application based on the functional requirements of different user personas.
- You will develop the ability to navigate the VRM schema and identify critical table relationships for reporting and configuration.
- You will gain foundational skills in configuring core VRM components like vendor portfolios, tiering, and assessment templates.
💡 Top Tips to Prepare
- Memorize the VRM process flow diagram, paying close attention to state transitions and triggers.
- Focus on the primary tables used for vendors, assessments, issues, and tasks to understand the data flow.
- Clearly differentiate the permissions and typical activities for the sn_vdr_risk_asmt.vendor_risk_manager and sn_vdr_risk_asmt.vendor_risk_assessor roles.
- Review the system properties under Vendor Risk > Administration, as they control fundamental application behavior and are common exam topics.
📖 About this Domain
Vendor Tiering is a core ServiceNow VRM process for classifying vendors based on inherent risk. This categorization dictates the level of due diligence and ongoing monitoring required. The tiering process directly impacts the scope and frequency of subsequent risk assessments.
🎓 What You Will Learn
- You will learn to configure and trigger Vendor Tiering Assessments to evaluate a vendor's inherent risk.
- You will understand how to create and apply Tiering Rules to automatically assign vendor tiers based on assessment scores.
- You will learn how the assigned vendor tier dictates the subsequent assessment and due diligence workflow.
- You will explore the relationship between Vendor Risk Areas and the tiering determination process.
🛠️ Skills You Will Build
- You will build the skill to customize the vendor tiering scale using the sn_vdr_risk_asmt.tiering_scale property.
- You will gain proficiency in using the Tiering Assessment Designer to create questionnaires for inherent risk evaluation.
- You will develop the ability to implement business rules that automate the tiering process based on assessment responses.
- You will be able to configure workflows that initiate appropriate due diligence based on the calculated vendor tier.
💡 Top Tips to Prepare
- Practice creating and modifying Tiering Assessments in your PDI to understand question and answer configuration.
- Manually trigger a tiering assessment from a Vendor record to trace the process from initiation to tier assignment.
- Review the relationship between the Vendor Tiering Assessment record and the Vendor record to see how the tier field is populated.
- Understand the flow of data and how tiering rules on the sn_vdr_risk_asmt table influence the final tier calculation.
📖 About this Domain
This domain covers the core process of evaluating vendor risk through structured assessments. It focuses on configuring, generating, and managing questionnaires and document requests sent to third parties. You will learn how the platform uses assessment data to calculate risk scores and drive remediation.
🎓 What You Will Learn
- Configure Questionnaire Templates and Document Request Templates to gather specific information from vendors.
- Understand the complete Vendor Risk Assessment lifecycle, from generation and submission to review and closure.
- Learn how Tiering Assessments are used to determine the initial risk level and assessment cadence for vendors.
- Explore the vendor portal interface and how vendors interact with assigned questionnaires and document requests.
🛠️ Skills You Will Build
- Creating and modifying assessment templates using the Questionnaire Designer and Metric Types.
- Automating the generation of recurring assessments based on vendor tier and risk ratings.
- Managing the assessment response process, including sending reminders and clarifying vendor queries.
- Analyzing assessment responses to identify issues, generate findings, and update vendor risk scores.
💡 Top Tips to Prepare
- Master the relationship between Vendor Risk Areas, Controls, and the questions within a Questionnaire Template.
- Memorize the different states of a Vendor Risk Assessment record and the actions available in each state.
- Understand how Assessment Metric Types and the associated script includes drive the creation of assessments.
- Practice configuring a Tiering Assessment and trace how its outcome influences the vendor's profile and future assessments.
Premium Access Includes
- ✓ Quiz Simulator
- ✓ Exam Mode
- ✓ Progress Tracking
- ✓ Question Saving
- ✓ Flash Cards
- ✓ Drag & Drops
- ✓ 3 Months Access
- ✓ PDF Downloads