With four hundred suppliers on the list and time to assess only forty this quarter, who goes first? Answering that well is most of what the ServiceNow Third-party Risk Management implementation exam checks. The credential, CIS-TPRM, has 60 questions in 90 minutes, costs USD $450 and is reported Pass or Fail. Its heaviest area, a third of the blueprint, is how assessments are built and scored.

Who gets assessed first when a supplier list runs to hundreds of names?
The honest answer is: not everyone, and not in the order they arrived. A risk team cannot send a long due diligence questionnaire to every supplier every year. It sorts suppliers into tiers, so that a payment processor holding customer data gets a deep review while a company that supplies office plants gets a short one, or none. ServiceNow's Third-party Risk Management application, often shortened to TPRM, turns that sorting into configuration. A candidate who understands why the tiers exist will find the exam's assessment questions far easier than one who has only memorised menu names.