> ## Documentation Index
> Fetch the complete documentation index at: https://docs.visotrust.com/llms.txt
> Use this file to discover all available pages before exploring further.

# The Complete Assessment Workflow

> An end-to-end walkthrough of working in VISO TRUST — configuring your organization, adding relationships, initiating each type of assessment, and reviewing results.

This guide walks through the full flow of working in VISO TRUST, from initial configuration to a completed risk decision. Each section links to a detailed page if you need more depth.

At a high level, the flow is:

1. **Configure your organization** — set defaults that apply to every relationship
2. **Add a relationship** and define its context
3. **Run an assessment** — instant, artifact upload, or vendor collection
4. **VISO TRUST analyzes the evidence** — AI analysis, optionally plus auditor review
5. **Review the results** and record a risk decision
6. **Monitor and maintain** the relationship over time

## Step 1 — Configure Your Organization

Organization-level settings define default behavior for every relationship and assessment. Configure these once under **Settings** in the left sidebar:

| Setting area        | Where                         | What it controls                                                                                                                                     |
| ------------------- | ----------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- |
| Assessment defaults | **Settings → Assessments**    | Instant assessment on/off, collection timelines, no-vendor-response behavior, follow-up automation, analysis method (AI only or AI + auditor review) |
| Org profile         | **Settings → Org Profile**    | Name, logo, branding, custom email domain, notification settings                                                                                     |
| Users and roles     | **Settings → Users**          | Admin, Program Manager, Contributor, and Viewer access; default subscribers                                                                          |
| Business units      | **Settings → Business Units** | Grouping relationships by internal division for reporting and ownership                                                                              |
| Tags                | **Settings → Tags**           | Labels for organizing and filtering relationships                                                                                                    |
| Tiers               | **Settings → Tiers**          | Up to five priority tiers for portfolio segmentation                                                                                                 |
| Control framework   | **Settings → Your Framework** | Which control domains apply to assessments; custom frameworks                                                                                        |
| Questionnaires      | **Settings → Questionnaires** | Supplemental questionnaires applied to all relationships or specific ones                                                                            |

See [Assessment Settings](/third-parties/advanced/assessment-settings), [Organization Profile](/organization-settings/organization-profile), [User Management](/organization-settings/user-management), [Business Units](/third-parties/business-units), [Tags](/organization-settings/tags), [Vendor Tiers](/organization-settings/tiers), [Custom Frameworks](/third-parties/advanced/custom-frameworks), and [Questionnaires](/trust-and-questionnaires/questionnaires).

## Step 2 — Add a Relationship

A **relationship** is the central record for each vendor. Every assessment, score, artifact, and advisory lives under one.

Go to **Third Parties → Relationships** and select **Add relationship**:

1. Search the VISO TRUST directory for the vendor, or create a new organization with the vendor's name and website
2. Assign a **Business Owner** — the internal owner who manages assessments and receives notifications
3. Write a short **business purpose** describing how you use the vendor
4. Optionally add tags and a tier
5. Leave **Predict relationship context and instantly assess** checked to get an immediate risk profile from public data

See [Manage Third-Party Vendor Relationships](/third-parties/relationships) for full steps, and [Bulk Import](/third-parties/bulk-import) to add many vendors at once.

### Relationship-Level Configuration

Open a relationship and select the **gear icon** to open the **Relationship configuration** dialog. This is where relationship-specific settings live:

* **Context** — the business cases (how you engage the vendor) and data types (what information is shared). Context defines the threat surface, the controls in scope, and inherent risk. Use **Predict context** to have VISO TRUST suggest both and verify it.
* **Assessments** — override organization defaults for this relationship: collection timelines, follow-up automation, analysis method, and no-vendor-response behavior.
* **Onboarding and lifecycle management** — onboard the relationship to include it in Risk Insights dashboards and enable recertification scheduling and automatic artifact renewal.
* **Tier** — assign or change the relationship's priority tier.

More specific settings always win: a relationship-level setting overrides the org default, and an assessment-level setting overrides both. See [Assessment Settings](/third-parties/advanced/assessment-settings) and [Data Types](/third-parties/advanced/data-types).

## Step 3 — Initiate an Assessment

There are three assessment types, depending on how much depth you need:

| Type                   | How it works                                                                                                                                 | Vendor involved? |
| ---------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- | ---------------- |
| **Instant Assessment** | Runs automatically when a relationship is created. VISO TRUST searches public sources for certifications, security pages, and audit reports. | No               |
| **Artifact Upload**    | You upload security documents you already have (SOC 2, ISO 27001, pen test reports, etc.). Analysis begins immediately.                      | No               |
| **Vendor Collection**  | You send the vendor a collection request. They submit documentation through a secure portal.                                                 | Yes              |

You can also **Conduct Research** at any time — VISO TRUST searches public sources for compliance attestations, publicly available artifacts, and risk advisories. This runs automatically for instant assessments and can be triggered manually.

### Instant Assessment

No action needed — if instant assessment is enabled, it runs when the relationship is created and produces a risk score within seconds. Scores are marked transitional until a full assessment completes.

### Artifact Upload

From the relationship, use **Add information** to upload documents without involving the vendor. VISO TRUST classifies each artifact and begins analysis immediately. You can upload artifacts at any time, even alongside an active collection request.

### Vendor Collection

From the relationship, select **Start assessment** (or **Update assessment** if one already exists). When requesting artifacts from the vendor you can mix and match:

* **Ask for everything** — VISO TRUST requests all artifacts and questionnaire responses needed to satisfy in-scope controls
* **Request specific artifacts** — name the document types you need
* **Request manual response** — send a questionnaire for the vendor to answer in writing

Use **Advanced Settings** on the request to set the response deadline, follow-up behavior, and what happens if the vendor doesn't respond — for this one assessment only.

The vendor receives an email with a secure link and one-time passcode, uploads documents through the collection portal, attests for anything they can't provide, answers any questions, and certifies their submission. The default collection window is 30 days, with automatic reminders. For the vendor's view of this process — the guide to send them — see [Responding to a VISO TRUST Request](/third-parties/responding-to-a-viso-trust-request-vendors-guide). For the same walkthrough written from your side, see [The Vendor Experience](/trust-and-questionnaires/questionnaire-answering#the-vendor-experience).

## Step 4 — Analysis and Review

Once evidence arrives, the assessment moves through review phases:

1. **Artifact Intelligence** reads each document, classifies it, extracts risk-relevant findings, and maps them to controls in your framework. See [Artifact Intelligence](/trust-and-questionnaires/artifact-intelligence).
2. If your analysis method is **AI Assessment + Auditor Review**, a VISO TRUST analyst additionally reviews high-assurance artifacts (SOC 2 reports, ISO certificates, penetration tests) for qualified opinions, exceptions, and coverage gaps.
3. If controls remain unvalidated, VISO TRUST recommends a **follow-up questionnaire** — a short, targeted set of questions, not a full re-do. Depending on your settings, follow-ups are sent after your approval, automatically based on residual risk, or handled by the assessment concierge service.

Assessments move through defined phases — Not Assessed, Started, Collecting Information, Review Started, Follow-Up Recommended, Expired, Completed — each with its own available actions. See the phase table in [Assessments](/third-parties/assessments#assessment-phases).

## Step 5 — Review Results and Record a Decision

When the assessment reaches **Completed**, findings are ready and a **Review risk** action becomes available:

| Action                  | What it does                                                                                                           |
| ----------------------- | ---------------------------------------------------------------------------------------------------------------------- |
| **Accept Risk**         | Records that your organization accepts the residual risk. Closes the review.                                           |
| **Override Risk**       | Manually sets a different inherent or residual risk value when context or compensating controls aren't fully captured. |
| **Request Remediation** | Sends the vendor a remediation request identifying specific control gaps, with a target resolution date.               |
| **Add review note**     | Records a note with your decision for the audit trail.                                                                 |

The relationship's **Assessments** tab holds the full risk analysis: impact, likelihood, inherent and residual risk, and the control-by-control evidence behind each score. See [Risk Analysis](/risk-and-monitoring/risk-analysis) and [Risk Scoring](/risk-and-monitoring/risk-scoring) for how to read it.

## Step 6 — Monitor and Maintain

After the first assessment, VISO TRUST keeps the relationship current:

* **Risk Advisories** — continuous monitoring alerts you when a vendor experiences a breach, incident, or certification change. See [Risk Advisories](/risk-and-monitoring/risk-advisories).
* **Artifact validity** — VISO TRUST tracks artifact expiration and can automatically request updated documentation 30 days before expiry, if Lifecycle Management is turned on.
* **Recertification** — schedule recurring reassessments on a cadence you define (for example, annually), if Lifecycle Management is turned on. VISO TRUST can initiate collection automatically.
* **Pending changes** — when new information exists that isn't reflected in the current assessment, the relationship flags it for the next update.

Lifecycle features require the relationship to be **Onboarded** in its configuration dialog. See [Assessments](/third-parties/assessments#lifecycle-management).

## Related Pages

* [Key Concepts](/getting-started/key-concepts) — the core objects: relationships, assessments, artifacts, scores
* [Quick Start Guide](/getting-started/quick-start) — a 30-day setup plan for new deployments
* [Assessments](/third-parties/assessments) — the full assessment lifecycle in detail
* [Assessment Settings](/third-parties/advanced/assessment-settings) — org, relationship, and assessment-level defaults
* [Risk Analysis](/risk-and-monitoring/risk-analysis) — reading assessment results
