ServiceNow Vendor Risk Management Training
Assess third party risk on ServiceNow. Vendor tiering, assessments, findings and continuous monitoring within Integrated Risk Management.
ServiceNow Vendor Risk Management (VRM) training teaches you to manage third party risk on the Now Platform. You handle vendor onboarding and tiering, assessments and questionnaires, findings and remediation, and continuous monitoring, within the Integrated Risk Management suite.
Who this course is for
Prerequisite: Basic administration. GRC and IRM basics help but core concepts are introduced.
What makes this different
You build, not just watch
From the first session you are on your own developer instance, configuring, scripting and breaking things safely. That is what makes it stick.
Taught on the current release
No outdated screenshots. Everything maps to the release ServiceNow runs today, including current AI and platform features.
One trainer who still implements
One working consultant for the whole batch, no rotation, so the teaching is consistent and grounded in real projects.
Support continues to the offer
Resume review, mock interviews on real scenario questions, and referrals. Support does not stop when the last class ends.

ServiceNow Vendor Risk Management curriculum
8 modules and 3 projects, updated to the current release. Every module maps to real Vendor Risk Management work and expands into its full topic list, practised on a live developer instance.
ServiceNow Vendor Risk Management Training module list: 8 modules, what each one covers, and how many topics it expands into. Full topic lists are in the accordions below.
| # | Module | What you configure | Topics |
|---|---|---|---|
| 01 | VRM within IRM and the data model3.5 hours | Explain where Vendor Risk Management sits within IRM and how its records relate. | 4 |
| 02 | Vendor onboarding, tiering and the portal3.5 hours | Onboard a vendor, assign a tier and grant portal access to its contacts. | 4 |
| 03 | Assessment design3 hours | Build assessment templates and questionnaires that match a vendor tier. | 4 |
| 04 | Running assessments and scoring3 hours | Issue an assessment, collect vendor responses and produce a score. | 4 |
| 05 | Findings, issues and remediation3 hours | Raise findings from assessment results and drive remediation to an agreed plan. | 4 |
| 06 | Escalation and closure3 hours | Escalate stalled remediation and close findings with recorded evidence. | 4 |
| 07 | Continuous monitoring3 hours | Configure ongoing monitoring, reassessment cycles and alerting for vendors. | 4 |
| 08 | Reporting, integrations and delivery3 hours | Report third party risk position and prepare for the certification path. | 4 |
1VRM within IRM and the data modelModule 1 of 8 · 3.5 hours
Explain where Vendor Risk Management sits within IRM and how its records relate.
- VRM within IRM
- IRM application family and scope
- relationship to risk and policy management
- plugin activation and dependencies
- shared taxonomy across IRM
- Data model
- vendor, contact and assessment tables
- assessment to finding relationships
- risk register linkage
- custom fields and extension points
- Third party risk lifecycle
- onboarding through offboarding stages
- periodic versus event driven review
- ownership at each stage
- record states across the lifecycle
- Contract and engagement records
- engagement scope and criticality
- contract references and dates
- services provided by a vendor
- data handled under an engagement
2Vendor onboarding, tiering and the portalModule 2 of 8 · 3.5 hours
Onboard a vendor, assign a tier and grant portal access to its contacts.
- Vendor hierarchy and tiering
- parent and subsidiary vendor structure
- tiering criteria and definitions
- tier driven assessment requirements
- retiering after a material change
- Roles and the vendor portal
- internal risk and assessor roles
- vendor contact roles
- vendor portal layout and tasks
- portal access provisioning
- Vendor onboarding intake
- intake request and required data
- duplicate vendor checks
- onboarding approval steps
- vendor record creation
- Vendor contacts and communication
- primary and secondary contacts
- notification templates
- reminder and chase cadence
- contact changes over time
3Assessment designModule 3 of 8 · 3 hours
Build assessment templates and questionnaires that match a vendor tier.
- Assessment templates and questionnaires
- template structure and sections
- question banks and reuse
- answer types and conditions
- template versioning
- Evidence
- evidence requests per question
- attachment and document handling
- evidence review and acceptance
- evidence retention on the record
- Assessment triggers by tier
- tier to template mapping
- event driven assessment triggers
- scheduled assessment generation
- exceptions and waivers
- Assessment scope and instructions
- scoping questions to an engagement
- instructions for vendor respondents
- due dates and effort expectations
- internal reviewer assignment
4Running assessments and scoringModule 4 of 8 · 3 hours
Issue an assessment, collect vendor responses and produce a score.
- Vendor portal responses
- assessment delivery to the portal
- response capture and saving
- clarification requests
- submission and lock
- Scoring
- scoring methods and weightings
- answer level scores
- score thresholds and bands
- manual score overrides
- Third party risk scoring
- inherent versus residual risk view
- combining assessment and tier inputs
- score history over cycles
- feeding scores to the risk register
- Assessment review
- internal reviewer workflow
- response validation against evidence
- assessment completion states
- handover to findings
5Findings, issues and remediationModule 5 of 8 · 3 hours
Raise findings from assessment results and drive remediation to an agreed plan.
- Findings and remediation
- finding creation from responses
- severity and due date rules
- remediation plans and tasks
- owner assignment on the vendor side
- Issues and risk
- issue records and linkage to risk
- risk statements from findings
- impact and likelihood capture
- aggregating issues per vendor
- Remediation tracking
- task progress and updates
- overdue remediation handling
- re-testing after remediation
- evidence of completed actions
- Risk acceptance and exceptions
- exception request and approval
- time bound acceptance
- compensating controls
- review of open acceptances
6Escalation and closureModule 6 of 8 · 3 hours
Escalate stalled remediation and close findings with recorded evidence.
- Escalation
- escalation triggers and thresholds
- escalation paths internally and to the vendor
- notification and reminder rules
- management review of escalations
- Closure
- closure criteria per finding type
- verification before closure
- closure approvals
- reopening a closed finding
- Audit trail and records retention
- activity history on risk records
- retaining evidence after closure
- reporting on closed items
- record retention expectations
- Vendor communication on outcomes
- outcome summaries to the vendor
- agreed action confirmation
- dispute handling
- relationship impact of outcomes
7Continuous monitoringModule 7 of 8 · 3 hours
Configure ongoing monitoring, reassessment cycles and alerting for vendors.
- Continuous monitoring
- monitoring scope per tier
- monitoring frequency and triggers
- change events that prompt review
- monitoring ownership
- Reassessment cycles
- periodic reassessment scheduling
- carrying forward prior responses
- reassessment scope reduction
- cycle tracking and completion
- External feeds
- external data source integration
- mapping feed data to vendor records
- feed reliability and refresh
- acting on feed signals
- Alerts
- alert conditions and severity
- alert routing to owners
- alert triage and dismissal
- alerts that create assessments or findings
8Reporting, integrations and deliveryModule 8 of 8 · 3 hours
Report third party risk position and prepare for the certification path.
- Dashboards and reporting
- vendor risk dashboards by audience
- reports on findings and cycles
- indicators for portfolio level risk
- scheduled distribution
- Integrations
- procurement and contract system integration
- identity and vendor master data
- integration patterns and error handling
- data ownership across systems
- Best practices
- tiering discipline and consistency
- assessment fatigue and question reuse
- clean data as a reporting prerequisite
- operating model for the risk team
- Prep
- exam domain review
- practice scenarios on the instance
- gap review against the modules
- study plan construction
Onboard and tier a vendor, issue the tier appropriate assessment, score the responses, raise and remediate a finding, close it with evidence, then place the vendor under continuous monitoring and report the position.
How this course covers the CIS-Risk aligned exam blueprint.
| Exam area | Weight | Covered in |
|---|---|---|
| VRM foundations and data model | - | Module 1 |
| Vendor onboarding and tiering | - | Module 2 |
| Assessments and scoring | - | Module 3, Module 4 |
| Findings, issues and remediation | - | Module 5, Module 6 |
| Monitoring and reporting | - | Module 7, Module 8 |
Not covered: Security Operations incident response configuration; internal audit management and control testing.
Curriculum version 2026-09-01 · approved by mohsin
What you'll be able to do
Real projects you'll build
Interview-ready scenarios on a live instance, not toy demos.
Vendor onboarding
Onboard a vendor, tier it and trigger the right assessment based on the tier.
Assessment cycle
Send a questionnaire, capture vendor responses through the portal and score the result.
Finding to closure
Raise a finding from an assessment, drive remediation and close it with evidence.
Certification and hands-on
Every session runs on a real ServiceNow developer instance, so you configure and build rather than watch. The course maps to the CIS-Risk aligned exam and finishes with an IT Canvass certificate plus a certification roadmap. VRM maps to the CIS-Risk and Compliance exam (US$300, ServiceNow University). IT Canvass does not issue the official ServiceNow credential.
ServiceNow has an official certification catalog with four tiers: Expert (Certified Technical Architect, Certified Master Architect), Mainline (Certified System Administrator, Certified Application Developer, Certified Application Specialist and the Certified Implementation Specialist product tracks), Micro-Certifications (focused product skills such as Now Assist, Flow Designer and CMDB), and Suite Certifications (bundled credentials such as the ITSM and CSM Professional suites).
Certification facts. Vendor figures change, so confirm against the official ServiceNow catalogue before booking.
| Exam code | CIS-Risk |
|---|---|
| Credential | ServiceNow CIS-Risk aligned |
| Issued by | ServiceNow, Inc. (not by IT Canvass) |
| Exam duration | 90 minutes |
| Exam cost | US$300 per exam attempt, plus the mandatory training where required |
| Prerequisite | CSA is the prerequisite for every CIS exam. Mandatory paid training applies to most CIS tracks. |
| What IT Canvass issues | An IT Canvass course completion certificate and a certification roadmap |
Your Vendor Risk Management career roadmap
The security and risk path from admin to security architect, with indicative 2026 bands.
Salary snapshot: Third Party Risk Analyst
Indicative ranges aggregated from public salary data. Actual pay varies by location, employer and experience.
How IT Canvass compares
Against a typical training provider, this Vendor Risk Management course is taught on the current ServiceNow release, gives you your own developer instance from day one, and keeps one working consultant for the whole batch instead of rotating trainers. Every module is mapped to the CIS-Risk aligned exam, sessions are recorded with lifetime access, and job support (resume review, mock interviews and referrals) is included in one transparent fee. Most providers still teach older release material, run slide-first sessions with limited lab time, and bill support and recordings as add-ons.
Fees and training modes
Choose how you want to learn Vendor Risk Management. No-cost EMI available on all modes.
Interactive live batches, weekday or weekend, with the full cohort and lifetime recordings.
Private one-on-one coaching at your pace, whether you need interview-ready fast or hands-on help with your current project.
Learn on your own time with recorded sessions, labs and Q&A doubt support.
Train your team on ServiceNow Vendor Risk Management Training
Tailored curriculum, flexible scheduling, a dedicated ServiceNow architect, and progress reporting for your managers. Delivered live online or on-site for cohorts of any size.
Your trainer
Neelima, ServiceNow Architect, 12+ years
I still deliver ITSM, ITOM and HRSD implementations for enterprise clients, so I teach from what is breaking in production this quarter, not from a slide deck. In class I show the patterns that scale and the mistakes that cost teams days.
Learner reviews
The vendor portal and assessment cycle are exactly what we run. The course mirrored real work.
Tiering drives everything and the course started there, which is the right way to teach VRM.
Practical and focused. Continuous monitoring was the piece I was missing.
Fees, batches and policies
The questions people actually ask before enrolling, answered plainly.