Question 1
A financial services firm is configuring their ServiceNow TPRM instance to automatically calculate a third-party's tier based on responses to an Inherent Risk Questionnaire (IRQ). The requirement is that if the third party will handle Personally Identifiable Information (PII) AND will be integrated with production systems, they must be assigned to the 'Tier 1 - Critical' level. However, if they only handle PII but are not integrated, they should be 'Tier 2 - High'. A risk manager reports that a new third party answering 'Yes' to both questions is incorrectly being assigned 'Tier 2'. Which of the following is the most likely cause of this misconfiguration?
Answer and explanation
Correct answer: A
ServiceNow evaluates tiering rules based on the 'Order' field, starting with the lowest number. If the conditions for 'Tier 2' (handles PII) are met by a rule with a lower order number, the system will assign that tier and stop processing further rules, even if the third party also meets the criteria for the 'Tier 1' rule which has a higher order number. The other options are incorrect because the script include VdrTiering handles the logic but is driven by the rule configuration, a data policy would prevent saving but not mis-tier, and UI policies only affect the user interface.