- Configure your organization — set defaults that apply to every relationship
- Add a relationship and define its context
- Run an assessment — instant, artifact upload, or vendor collection
- VISO TRUST analyzes the evidence — AI analysis, optionally plus auditor review
- Review the results and record a risk decision
- Monitor and maintain the relationship over time
Step 1 — Configure Your Organization
Organization-level settings define default behavior for every relationship and assessment. Configure these once under Settings in the left sidebar:
See Assessment Settings, Organization Profile, User Management, Business Units, Tags, Vendor Tiers, Custom Frameworks, and Questionnaires.
Step 2 — Add a Relationship
A relationship is the central record for each vendor. Every assessment, score, artifact, and advisory lives under one. Go to Third Parties → Relationships and select Add relationship:- Search the VISO TRUST directory for the vendor, or create a new organization with the vendor’s name and website
- Assign a Business Owner — the internal owner who manages assessments and receives notifications
- Write a short business purpose describing how you use the vendor
- Optionally add tags and a tier
- Leave Predict relationship context and instantly assess checked to get an immediate risk profile from public data
Relationship-Level Configuration
Open a relationship and select the gear icon to open the Relationship configuration dialog. This is where relationship-specific settings live:- Context — the business cases (how you engage the vendor) and data types (what information is shared). Context defines the threat surface, the controls in scope, and inherent risk. Use Predict context to have VISO TRUST suggest both and verify it.
- Assessments — override organization defaults for this relationship: collection timelines, follow-up automation, analysis method, and no-vendor-response behavior.
- Onboarding and lifecycle management — onboard the relationship to include it in Risk Insights dashboards and enable recertification scheduling and automatic artifact renewal.
- Tier — assign or change the relationship’s priority tier.
Step 3 — Initiate an Assessment
There are three assessment types, depending on how much depth you need:
You can also Conduct Research at any time — VISO TRUST searches public sources for compliance attestations, publicly available artifacts, and risk advisories. This runs automatically for instant assessments and can be triggered manually.
Instant Assessment
No action needed — if instant assessment is enabled, it runs when the relationship is created and produces a risk score within seconds. Scores are marked transitional until a full assessment completes.Artifact Upload
From the relationship, use Add information to upload documents without involving the vendor. VISO TRUST classifies each artifact and begins analysis immediately. You can upload artifacts at any time, even alongside an active collection request.Vendor Collection
From the relationship, select Start assessment (or Update assessment if one already exists). When requesting artifacts from the vendor you can mix and match:- Ask for everything — VISO TRUST requests all artifacts and questionnaire responses needed to satisfy in-scope controls
- Request specific artifacts — name the document types you need
- Request manual response — send a questionnaire for the vendor to answer in writing
Step 4 — Analysis and Review
Once evidence arrives, the assessment moves through review phases:- Artifact Intelligence reads each document, classifies it, extracts risk-relevant findings, and maps them to controls in your framework. See Artifact Intelligence.
- If your analysis method is AI Assessment + Auditor Review, a VISO TRUST analyst additionally reviews high-assurance artifacts (SOC 2 reports, ISO certificates, penetration tests) for qualified opinions, exceptions, and coverage gaps.
- If controls remain unvalidated, VISO TRUST recommends a follow-up questionnaire — a short, targeted set of questions, not a full re-do. Depending on your settings, follow-ups are sent after your approval, automatically based on residual risk, or handled by the assessment concierge service.
Step 5 — Review Results and Record a Decision
When the assessment reaches Completed, findings are ready and a Review risk action becomes available:
The relationship’s Assessments tab holds the full risk analysis: impact, likelihood, inherent and residual risk, and the control-by-control evidence behind each score. See Risk Analysis and Risk Scoring for how to read it.
Step 6 — Monitor and Maintain
After the first assessment, VISO TRUST keeps the relationship current:- Risk Advisories — continuous monitoring alerts you when a vendor experiences a breach, incident, or certification change. See Risk Advisories.
- Artifact validity — VISO TRUST tracks artifact expiration and can automatically request updated documentation 30 days before expiry, if Lifecycle Management is turned on.
- Recertification — schedule recurring reassessments on a cadence you define (for example, annually), if Lifecycle Management is turned on. VISO TRUST can initiate collection automatically.
- Pending changes — when new information exists that isn’t reflected in the current assessment, the relationship flags it for the next update.
Related Pages
- Key Concepts — the core objects: relationships, assessments, artifacts, scores
- Quick Start Guide — a 30-day setup plan for new deployments
- Assessments — the full assessment lifecycle in detail
- Assessment Settings — org, relationship, and assessment-level defaults
- Risk Analysis — reading assessment results