IT CanvassEnquire now
ServiceNow · Security, Risk & GRCUpdated , aligned to the current ServiceNow release family

ServiceNow Vendor Risk Management Training

Assess third party risk on ServiceNow. Vendor tiering, assessments, findings and continuous monitoring within Integrated Risk Management.

25 hours, live online
Next weekday batch: Next weekend batch:

Book a free demo class

Sit in on a live session before you enrol.

By submitting, you agree to the IT Canvass Privacy Policy and Terms & Conditions.

Download the curriculum

By submitting, you agree to the IT Canvass Privacy Policy and Terms & Conditions.

Quick answer

ServiceNow Vendor Risk Management (VRM) training teaches you to manage third party risk on the Now Platform. You handle vendor onboarding and tiering, assessments and questionnaires, findings and remediation, and continuous monitoring, within the Integrated Risk Management suite.

Certification
CIS-Risk aligned
Level
Intermediate
Duration
25 hours
Mode
Live, 1-to-1, self-paced, corporate
Certification
CIS-Risk aligned
Exam fee
US$300
Duration
25 hours
Level
Intermediate
Prerequisite
Basic admin
Live Vendor Risk Management batches are open. Get the full curriculum, fees and schedule.
Next live batch starts

Get the curriculum and fees

By submitting, you agree to the IT Canvass Privacy Policy and Terms & Conditions.

ServiceNow Vendor Risk Management skills sit in the Security, Risk & GRC area of the Now Platform, and this 25 hours live, instructor-led course is built to make them job-ready. You start with VRM foundations and progress through Delivery across 8 modules and 3 hands-on projects, working the way a Third Party Risk Analyst does on real delivery rather than through slides. It is pitched at a intermediate level, maps module by module to the CIS-Risk aligned certification, and every session runs on your own developer instance so you leave able to build it, not just describe it.

Who this course is for

Prerequisite: Basic administration. GRC and IRM basics help but core concepts are introduced.

Great fit if
Admins moving into third party risk
Risk or procurement staff learning the platform
GRC learners adding VRM
Also ideal for
ServiceNow admins supporting risk
Third party risk and procurement staff
Consultants implementing VRM

What makes this different

You build, not just watch

From the first session you are on your own developer instance, configuring, scripting and breaking things safely. That is what makes it stick.

Taught on the current release

No outdated screenshots. Everything maps to the release ServiceNow runs today, including current AI and platform features.

One trainer who still implements

One working consultant for the whole batch, no rotation, so the teaching is consistent and grounded in real projects.

Support continues to the offer

Resume review, mock interviews on real scenario questions, and referrals. Support does not stop when the last class ends.

ServiceNow Vendor Risk Management Training learning path: 5 modules from vrm foundations to delivery
ServiceNow Vendor Risk Management Training: the 8-module path we teach, in order.

ServiceNow Vendor Risk Management curriculum

8 modules and 3 projects, updated to the current release. Every module maps to real Vendor Risk Management work and expands into its full topic list, practised on a live developer instance.

Vendor Risk Management learning path
1VRM within IRM and the data model2Vendor onboarding, tiering and the portal3Assessment design4Running assessments and scoring5Findings, issues and remediation6Escalation and closure7Continuous monitoring8Reporting, integrations and delivery

Download the curriculum

By submitting, you agree to the IT Canvass Privacy Policy and Terms & Conditions.

ServiceNow Vendor Risk Management Training module list: 8 modules, what each one covers, and how many topics it expands into. Full topic lists are in the accordions below.

#ModuleWhat you configureTopics
01VRM within IRM and the data model3.5 hoursExplain where Vendor Risk Management sits within IRM and how its records relate.4
02Vendor onboarding, tiering and the portal3.5 hoursOnboard a vendor, assign a tier and grant portal access to its contacts.4
03Assessment design3 hoursBuild assessment templates and questionnaires that match a vendor tier.4
04Running assessments and scoring3 hoursIssue an assessment, collect vendor responses and produce a score.4
05Findings, issues and remediation3 hoursRaise findings from assessment results and drive remediation to an agreed plan.4
06Escalation and closure3 hoursEscalate stalled remediation and close findings with recorded evidence.4
07Continuous monitoring3 hoursConfigure ongoing monitoring, reassessment cycles and alerting for vendors.4
08Reporting, integrations and delivery3 hoursReport third party risk position and prepare for the certification path.4
1VRM within IRM and the data modelModule 1 of 8 · 3.5 hours

Explain where Vendor Risk Management sits within IRM and how its records relate.

  • VRM within IRM
    • IRM application family and scope
    • relationship to risk and policy management
    • plugin activation and dependencies
    • shared taxonomy across IRM
  • Data model
    • vendor, contact and assessment tables
    • assessment to finding relationships
    • risk register linkage
    • custom fields and extension points
  • Third party risk lifecycle
    • onboarding through offboarding stages
    • periodic versus event driven review
    • ownership at each stage
    • record states across the lifecycle
  • Contract and engagement records
    • engagement scope and criticality
    • contract references and dates
    • services provided by a vendor
    • data handled under an engagement
Lab
Map the VRM data model on an instance
Environment: ServiceNow Personal Developer Instance (PDI) · Deliverable: A record level map of vendor, engagement, assessment and finding relationships.
2Vendor onboarding, tiering and the portalModule 2 of 8 · 3.5 hours

Onboard a vendor, assign a tier and grant portal access to its contacts.

  • Vendor hierarchy and tiering
    • parent and subsidiary vendor structure
    • tiering criteria and definitions
    • tier driven assessment requirements
    • retiering after a material change
  • Roles and the vendor portal
    • internal risk and assessor roles
    • vendor contact roles
    • vendor portal layout and tasks
    • portal access provisioning
  • Vendor onboarding intake
    • intake request and required data
    • duplicate vendor checks
    • onboarding approval steps
    • vendor record creation
  • Vendor contacts and communication
    • primary and secondary contacts
    • notification templates
    • reminder and chase cadence
    • contact changes over time
Lab
Onboard and tier a vendor with portal access
Environment: ServiceNow Personal Developer Instance (PDI) · Deliverable: An onboarded vendor record with an assigned tier and an active portal contact.
3Assessment designModule 3 of 8 · 3 hours

Build assessment templates and questionnaires that match a vendor tier.

  • Assessment templates and questionnaires
    • template structure and sections
    • question banks and reuse
    • answer types and conditions
    • template versioning
  • Evidence
    • evidence requests per question
    • attachment and document handling
    • evidence review and acceptance
    • evidence retention on the record
  • Assessment triggers by tier
    • tier to template mapping
    • event driven assessment triggers
    • scheduled assessment generation
    • exceptions and waivers
  • Assessment scope and instructions
    • scoping questions to an engagement
    • instructions for vendor respondents
    • due dates and effort expectations
    • internal reviewer assignment
Lab
Build a tier based assessment template
Environment: ServiceNow Personal Developer Instance (PDI) · Deliverable: An assessment template with a question set and evidence requests, mapped to a tier.
4Running assessments and scoringModule 4 of 8 · 3 hours

Issue an assessment, collect vendor responses and produce a score.

  • Vendor portal responses
    • assessment delivery to the portal
    • response capture and saving
    • clarification requests
    • submission and lock
  • Scoring
    • scoring methods and weightings
    • answer level scores
    • score thresholds and bands
    • manual score overrides
  • Third party risk scoring
    • inherent versus residual risk view
    • combining assessment and tier inputs
    • score history over cycles
    • feeding scores to the risk register
  • Assessment review
    • internal reviewer workflow
    • response validation against evidence
    • assessment completion states
    • handover to findings
Lab
Run an assessment cycle end to end
Environment: ServiceNow Personal Developer Instance (PDI) · Deliverable: A submitted vendor assessment with a calculated score and a reviewer decision.
5Findings, issues and remediationModule 5 of 8 · 3 hours

Raise findings from assessment results and drive remediation to an agreed plan.

  • Findings and remediation
    • finding creation from responses
    • severity and due date rules
    • remediation plans and tasks
    • owner assignment on the vendor side
  • Issues and risk
    • issue records and linkage to risk
    • risk statements from findings
    • impact and likelihood capture
    • aggregating issues per vendor
  • Remediation tracking
    • task progress and updates
    • overdue remediation handling
    • re-testing after remediation
    • evidence of completed actions
  • Risk acceptance and exceptions
    • exception request and approval
    • time bound acceptance
    • compensating controls
    • review of open acceptances
Lab
Raise a finding and build a remediation plan
Environment: ServiceNow Personal Developer Instance (PDI) · Deliverable: A finding with a linked issue and a remediation plan with owners and dates.
6Escalation and closureModule 6 of 8 · 3 hours

Escalate stalled remediation and close findings with recorded evidence.

  • Escalation
    • escalation triggers and thresholds
    • escalation paths internally and to the vendor
    • notification and reminder rules
    • management review of escalations
  • Closure
    • closure criteria per finding type
    • verification before closure
    • closure approvals
    • reopening a closed finding
  • Audit trail and records retention
    • activity history on risk records
    • retaining evidence after closure
    • reporting on closed items
    • record retention expectations
  • Vendor communication on outcomes
    • outcome summaries to the vendor
    • agreed action confirmation
    • dispute handling
    • relationship impact of outcomes
Lab
Close a finding with verified evidence
Environment: ServiceNow Personal Developer Instance (PDI) · Deliverable: A closed finding with verification evidence and a complete activity trail.
7Continuous monitoringModule 7 of 8 · 3 hours

Configure ongoing monitoring, reassessment cycles and alerting for vendors.

  • Continuous monitoring
    • monitoring scope per tier
    • monitoring frequency and triggers
    • change events that prompt review
    • monitoring ownership
  • Reassessment cycles
    • periodic reassessment scheduling
    • carrying forward prior responses
    • reassessment scope reduction
    • cycle tracking and completion
  • External feeds
    • external data source integration
    • mapping feed data to vendor records
    • feed reliability and refresh
    • acting on feed signals
  • Alerts
    • alert conditions and severity
    • alert routing to owners
    • alert triage and dismissal
    • alerts that create assessments or findings
Lab
Configure monitoring and alerts for a tiered vendor
Environment: ServiceNow Personal Developer Instance (PDI) · Deliverable: A monitoring configuration with a reassessment schedule and working alert rules.
8Reporting, integrations and deliveryModule 8 of 8 · 3 hours

Report third party risk position and prepare for the certification path.

  • Dashboards and reporting
    • vendor risk dashboards by audience
    • reports on findings and cycles
    • indicators for portfolio level risk
    • scheduled distribution
  • Integrations
    • procurement and contract system integration
    • identity and vendor master data
    • integration patterns and error handling
    • data ownership across systems
  • Best practices
    • tiering discipline and consistency
    • assessment fatigue and question reuse
    • clean data as a reporting prerequisite
    • operating model for the risk team
  • Prep
    • exam domain review
    • practice scenarios on the instance
    • gap review against the modules
    • study plan construction
Lab
Build a third party risk dashboard
Environment: ServiceNow Personal Developer Instance (PDI) · Deliverable: A dashboard showing vendor tiers, open findings and assessment cycle status.
Capstone · 4 hours
Vendor lifecycle end to end

Onboard and tier a vendor, issue the tier appropriate assessment, score the responses, raise and remediate a finding, close it with evidence, then place the vendor under continuous monitoring and report the position.

How this course covers the CIS-Risk aligned exam blueprint.

Exam areaWeightCovered in
VRM foundations and data model-Module 1
Vendor onboarding and tiering-Module 2
Assessments and scoring-Module 3, Module 4
Findings, issues and remediation-Module 5, Module 6
Monitoring and reporting-Module 7, Module 8

Not covered: Security Operations incident response configuration; internal audit management and control testing.

Curriculum version 2026-09-01 · approved by mohsin

What you'll be able to do

Onboard and tier vendors
Run assessments and questionnaires
Manage findings and remediation
Set up continuous monitoring
Report third party risk
Operate the vendor portal

Real projects you'll build

Interview-ready scenarios on a live instance, not toy demos.

Project 1

Vendor onboarding

Onboard a vendor, tier it and trigger the right assessment based on the tier.

Project 2

Assessment cycle

Send a questionnaire, capture vendor responses through the portal and score the result.

Project 3

Finding to closure

Raise a finding from an assessment, drive remediation and close it with evidence.

Certification and hands-on

Every session runs on a real ServiceNow developer instance, so you configure and build rather than watch. The course maps to the CIS-Risk aligned exam and finishes with an IT Canvass certificate plus a certification roadmap. VRM maps to the CIS-Risk and Compliance exam (US$300, ServiceNow University). IT Canvass does not issue the official ServiceNow credential.

ServiceNow has an official certification catalog with four tiers: Expert (Certified Technical Architect, Certified Master Architect), Mainline (Certified System Administrator, Certified Application Developer, Certified Application Specialist and the Certified Implementation Specialist product tracks), Micro-Certifications (focused product skills such as Now Assist, Flow Designer and CMDB), and Suite Certifications (bundled credentials such as the ITSM and CSM Professional suites).

Certification facts. Vendor figures change, so confirm against the official ServiceNow catalogue before booking.

Exam codeCIS-Risk
CredentialServiceNow CIS-Risk aligned
Issued byServiceNow, Inc. (not by IT Canvass)
Exam duration90 minutes
Exam costUS$300 per exam attempt, plus the mandatory training where required
PrerequisiteCSA is the prerequisite for every CIS exam. Mandatory paid training applies to most CIS tracks.
What IT Canvass issuesAn IT Canvass course completion certificate and a certification roadmap
Start with Admin and Development →

Your Vendor Risk Management career roadmap

The security and risk path from admin to security architect, with indicative 2026 bands.

1. Platform basics
₹4-6 LPA · $55-72k
Now Platform fundamentals plus CMDB and security basics. Target: junior admin.
2. GRC / SecOps Associate
₹7-12 LPA · $90-120k
IRM or SecOps config under supervision. Target: GRC / SecOps administrator.
3. CIS Consultant
₹12-22 LPA · $110-160k
CIS Risk & Compliance or SecOps end to end. Target: security / risk consultant.
4. Senior Consultant / Lead
₹20-34 LPA · $140-180k
Continuous monitoring, threat automation, multi-team delivery. Target: senior specialist.
5. Security Architect
₹30-52 LPA · $170k+
Enterprise risk and security architecture and strategy. Target: security architect.

Salary snapshot: Third Party Risk Analyst

India (per year)
8-18 LPA
United States (per year)
$95k-140k

Indicative ranges aggregated from public salary data. Actual pay varies by location, employer and experience.

How IT Canvass compares

Against a typical training provider, this Vendor Risk Management course is taught on the current ServiceNow release, gives you your own developer instance from day one, and keeps one working consultant for the whole batch instead of rotating trainers. Every module is mapped to the CIS-Risk aligned exam, sessions are recorded with lifetime access, and job support (resume review, mock interviews and referrals) is included in one transparent fee. Most providers still teach older release material, run slide-first sessions with limited lab time, and bill support and recordings as add-ons.

Fees and training modes

Choose how you want to learn Vendor Risk Management. No-cost EMI available on all modes.

Recommended
Live Online TrainingMost popular
Talk to us
Batch fee · no-cost EMI

Interactive live batches, weekday or weekend, with the full cohort and lifetime recordings.

Live online training

Share your details and an advisor will send the next batch dates and fees.

By submitting, you agree to the IT Canvass Privacy Policy and Terms & Conditions.

Live, instructor-led sessions
Practice on a real developer instance and labs
3 hands-on projects
Complete 8-module curriculum, mapped to CIS-Risk aligned
Session recordings available the same day
Complimentary upgrades to future batch recordings
Lifetime access to recordings and course material
Placement support: resume, mock interviews and referrals
Course completion certificate
1-to-1 TrainingFastest
₹49,000
Fixed for every course · no-cost EMI

Private one-on-one coaching at your pace, whether you need interview-ready fast or hands-on help with your current project.

Get a free demo

Sit in on a live session with the trainer before you decide on 1-to-1.

By submitting, you agree to the IT Canvass Privacy Policy and Terms & Conditions.

Flexible scheduling, evenings and weekends
Last-minute interview preparation
Support on your live project work, standard curriculum or fully customised to your needs
Doubt clearing in every session
Real instance and all 3 projects
Priority CIS-Risk aligned exam preparation
Lifetime recordings and materials
One fixed price for every course
Self-paced TrainingAffordable
₹9,000
One-time fee · lowest-cost option

Learn on your own time with recorded sessions, labs and Q&A doubt support.

Buy self-paced course

Share your details and we will send access details and the current price.

By submitting, you agree to the IT Canvass Privacy Policy and Terms & Conditions.

Complete library of recorded sessions
Hands-on labs and exercises
Doubt support through Q&A
A dedicated one-to-one live doubt-clearing session with a trainer on completion
Upgrade to Live Online anytime by paying only the fee difference
Lifetime complimentary upgrades to the latest videos and material with every version update
Course material aligned to CIS-Risk aligned
Course completion certificate
₹ No-cost EMI on all training modes

Group & batch discount

Enrolling 3 or more? Share your details and an advisor will send group pricing.

By submitting, you agree to the IT Canvass Privacy Policy and Terms & Conditions.

Corporate training

Train your team on ServiceNow Vendor Risk Management Training

Tailored curriculum, flexible scheduling, a dedicated ServiceNow architect, and progress reporting for your managers. Delivered live online or on-site for cohorts of any size.

Explore corporate training

Request a team quote

Tell us about your team and an advisor will send a tailored corporate proposal.

By submitting, you agree to the IT Canvass Privacy Policy and Terms & Conditions.

Custom curriculum and outcomes
Onboarding and upskilling at scale
Dedicated trainer and account manager
Attendance and progress reporting

Your trainer

Neelima, ServiceNow Architect, 12+ years

I still deliver ITSM, ITOM and HRSD implementations for enterprise clients, so I teach from what is breaking in production this quarter, not from a slide deck. In class I show the patterns that scale and the mistakes that cost teams days.

CSA and CAD certified50+ implementationsFull bio →

Learner reviews

The vendor portal and assessment cycle are exactly what we run. The course mirrored real work.
Meera S.
Third Party Risk Analyst
Tiering drives everything and the course started there, which is the right way to teach VRM.
Rakesh K.
Risk Consultant
Practical and focused. Continuous monitoring was the piece I was missing.
Tanvi R.
Procurement Analyst
Already working on Vendor Risk Management and stuck on a live ticket?Get an expert Vendor Risk Management developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support

Fees, batches and policies

The questions people actually ask before enrolling, answered plainly.

What is the total fee and what does it include?
The fee covers every live session, lab access on a practice system, the project work, recordings, resume review and interview preparation. There is no separate charge for materials. Exam fees are paid to ServiceNow, Inc. directly and are not included. Ask for the current fee and any running offer on the enquiry form, since batch pricing changes.
What are the batch timings, and do they work outside India?
Weekday batches run early morning and evening IST, and weekend batches run across both days. Early-morning IST suits US evenings (EST) and late-evening IST suits UK and Gulf mornings. If none of the published slots work, a one-to-one fast-track batch is scheduled around your timezone.
What happens if I miss a session?
Every session is recorded and shared the same day, so you can catch up before the next class. You can also sit the same session again in a parallel or later batch at no extra cost, which is the better option for configuration-heavy topics.
How long do I keep access to the recordings?
Lifetime access, with upgrades to the latest recordings on request. Lab access to the practice system is time-boxed to the course plus a short extension window, because the systems are shared.
Is there a refund if the course is not right for me?
You can attend the first two sessions and withdraw for a full refund if it is not the right fit. After that, the fee is transferable to another batch or another course rather than refundable. Confirm the current terms in writing before you pay.
Is the certificate issued by ServiceNow?
No, and no training provider can issue it. IT Canvass issues a course completion certificate. The ServiceNow credential is awarded only by ServiceNow, Inc. when you pass their exam, which you book directly with them. This course prepares you for that exam and gives you the project experience the exam assumes.

ServiceNow Vendor Risk Management FAQs

Is this part of GRC and IRM?
Yes. VRM is part of Integrated Risk Management, and this track focuses on third party risk.
Is there a vendor portal?
Yes. Vendors respond to assessments through a portal, and we configure it.
Do I need GRC knowledge?
GRC and IRM basics help, and core concepts are introduced.
Is continuous monitoring covered?
Yes, including reassessment cycles and external signals.
Which certification does this support?
It maps to the CIS-Risk and Compliance track.
How long is the course?
About 25 hours of live sessions plus lab practice.
Are recordings included?
Yes, with lifetime access.