A
Admin A VISO TRUST role with full platform access — manages users, settings, relationships, assessments, and all program activity. Artifact Any document or evidence collected as part of an assessment — audit reports, security certifications, policies, questionnaire responses, and more. Artifacts are analyzed by Artifact Intelligence to extract control evidence. Artifact Intelligence VISO TRUST’s AI document analysis engine. Reads security and compliance documents, extracts risk-relevant evidence, maps findings to controls, and assigns assurance levels — automatically. Artifact Type The classification of an artifact (e.g., SOC 2 Type II, ISO 27001, Penetration Test Report). VISO TRUST classifies artifacts automatically and uses the type to determine which controls the artifact can validate and how much assurance it carries. Artifact Validity The period during which an artifact is considered current. Each artifact type has a standard validity window (e.g., SOC 2 audit period, ISO 27001 3-year certificate). VISO TRUST tracks expiration and reduces assurance as artifacts age. Assessment The process by which VISO TRUST evaluates a vendor’s security posture. Assessments can be instant (using public data), artifact-based (uploading documents), or vendor-involved (requesting documentation through the collection portal). Assessment Lead A designated user responsible for running a vendor assessment, separate from the Business Owner of the relationship. Assurance Level A rating reflecting how trustworthy a piece of evidence is. Third-party audits carry higher assurance than self-attested policies. Assurance affects how much control credit an artifact receives — it’s the multiplier applied to a control’s weight when calculating mitigation. Levels are Limited, Moderate, Standard, and Advanced. An artifact’s level can be reduced when it expires, when it only describes a control without testing it, or when an auditor lowers it manually. Attestation A vendor’s formal declaration about their security practices. Includes submission certification (vendor confirms their responses are accurate), compliance attestations (publicly claimed certifications), and questionnaire responses.B
Business Case An intake selection that describes how your organization engages with a vendor — e.g., “stores customer data,” “has privileged system access,” “provides SaaS.” Business cases determine which controls are in scope for an assessment and contribute to the likelihood (threat surface) component of inherent risk. Business Owner The internal team member designated as the primary owner of a specific vendor relationship. Not a platform role — an assignment on a relationship. Business Owners manage assessments, receive notifications, and have expanded edit permissions on relationships they own. Business Unit An internal department or team grouping used to organize vendor relationships and scope Risk Insights dashboards. Each user and relationship belongs to a Business Unit.C
Collection Portal The secure, vendor-facing interface used to submit documentation and questionnaire responses during an assessment. Vendors access it via a one-time passcode from an email invitation. Collection Request A formal request sent to a vendor to submit security documentation and/or questionnaire responses through the collection portal. Complementary User Entity Controls (CUECs) Controls in a SOC 2 report that are the responsibility of the client (user entity) rather than the vendor. VISO TRUST auditors review CUECs as part of the AI Assessment + Auditor Review process. Contributor A VISO TRUST role that can view all relationships and create and manage assessments on relationships where they are assigned as Business Owner or Assessment Lead. Control A specific security requirement that must be satisfied by vendor evidence. Controls are organized into control domains and brought into scope by the business cases selected for a relationship. Control Domain A category grouping related security controls — for example, Access Control, Incident Response, or Data Privacy. The domains in scope for a relationship are determined by the selected business cases. Control Framework The structured set of controls that assessments are evaluated against. VISO TRUST’s default framework is grounded in NIST 800-53. Custom frameworks can be created for program-specific requirements. Control Mitigation The amount of likelihood removed by controls the vendor has proven. Calculated per control as control weight × assurance × presence, then summed across in-scope controls. Subtracted from likelihood to produce residual risk. Control Status The current state of evidence for a specific control: Present, Description Only, Not Present, No Information, or Not Applicable. Out of scope applies to a whole control domain rather than an individual control. Control Weight A single control’s contribution to likelihood. Calculated as control domain weight × relative control weight. Heavier controls move the residual risk score further when evidence is provided for them.D
Data Sensitivity A numeric value (0–1) representing how severe the consequences would be if data of this type were compromised. Drives the impact component of inherent risk. Levels range from None and Minimal up through Moderate, Elevated, and Critical. Data Type A category of information that may be shared with a vendor — e.g., Customer PII, Financial Reporting, Source Code, PHI. Data types determine data sensitivity and the impact component of inherent risk. Default Subscriber A user automatically subscribed to every relationship in the organization, existing and future. Useful for centralized risk or compliance teams that need full portfolio visibility.F
Follow-Up Questionnaire A targeted questionnaire sent to a vendor after initial assessment review to address specific control gaps. Shorter and more focused than an initial questionnaire. Vendors have a configurable window (7 days by default) to respond.I
Impact One of two inputs to inherent risk. Represents the severity of consequences if a vendor were compromised. Driven by the maximum data sensitivity across selected data types. Answers: “If something goes wrong, how bad could it be?” Inherent Risk The level of risk before accounting for any vendor security controls. Calculated as Impact × Likelihood. Represents worst-case exposure based on the relationship context. Instant Assessment An automatic assessment that runs when a relationship is created (if a vendor URL is provided). Uses publicly available data — certifications, security pages, breach disclosures — to generate an immediate risk score without vendor involvement.L
Lifecycle Management Automated features for maintaining vendor relationships over time: artifact validity tracking (alerts when documents expire), relationship recertification (scheduled reassessments), and automatic renewal requests. Likelihood One of two inputs to inherent risk. Represents the probability of a security incident occurring, based on the threat surface defined by the selected business cases. Reduced by the weight of control domains that are out of scope for the relationship, and by controls marked not applicable. Answers: “How likely is something to go wrong?”N
Nth Party A vendor’s vendor — a subservicer or technology provider that your direct vendor relies on. VISO TRUST surfaces nth-party risk through the Risk Network and monitors them for advisories alongside your direct vendors.O
Onboarded A relationship status indicating the vendor is actively managed in your TPRM program. Onboarded relationships appear in Risk Insights dashboards and are eligible for lifecycle management features.P
Pending Changes A flag on a relationship indicating new information exists that isn’t reflected in the current assessment summary — expired artifacts, context changes, new advisories, or newly discovered public artifacts. Resolved automatically on the next assessment update. Predicted Context Relationship context — intake answers and data classification — proposed by VISO TRUST instead of entered by hand, via Predict relationship context in the Relationship configuration dialog. Labeled “Context predicted by VISO TRUST” with an explanation of the reasoning. A suggestion to review, not a confirmed context. Program Manager A VISO TRUST role that can edit all relationships and manage all assessments, and can view — but not edit — program settings.R
Relationship The central record of a business connection with a third-party vendor. All assessments, risk scores, artifacts, advisories, and activity for a vendor are organized under a relationship. Remediation A formal request sent to a vendor to address specific control gaps identified in an assessment. Vendors respond with evidence. VISO TRUST initiates a new assessment update when a vendor responds. Residual Risk The level of risk after accounting for the vendor’s security controls. Calculated as impact × the likelihood remaining once control mitigation is subtracted. The primary risk score used for decision-making. Risk Advisory An alert generated when a vendor in your portfolio experiences a risk-relevant event — breach, vulnerability disclosure, regulatory action, etc. Generated automatically through continuous monitoring. Risk Model The configuration layer that controls how numeric risk scores map to labels (Low, Medium, High, Extreme) and how demanding the thresholds are. Includes risk tolerance settings, label names, and compliance certification influence. Risk Network A visual graph representation of your third-party and nth-party vendor relationships, built from subservicer data extracted from artifacts. Risk Tolerance An organization-level setting controlling how strict the risk model is when mapping scores to labels. Options: Minimal (strictest), Moderate, Significant (most flexible).S
Smart Summary An AI-generated narrative summary of assessment findings — formatted as a readable report for executives, auditors, or boards. Editable in-platform and downloadable. Sub-Processor A third party that your vendor uses to process personal data on your behalf. VISO TRUST collects sub-processor lists from vendors when the Privacy risk dimension is in scope. Subscriber An internal user who receives notifications about a specific relationship without being the Business Owner. Subscribers are informed without being responsible for the relationship.T
Tags Free-form labels applied to vendor relationships for filtering, organization, and reporting. Managed in Settings → Tags. Threat Surface The combination of exposures a vendor introduces based on the selected business cases — what systems they touch, what access they have, how they interact with your data. Drives the likelihood component of inherent risk. Transitional Risk A risk score not yet backed by a completed assessment — either none has completed or a new one is in progress. Shown in italics with an asterisk (*) on the Relationships list. The marker clears once an assessment completes.
Trust Profile
An organization’s repository of security documentation in VISO TRUST, used to answer inbound customer questionnaires via AI and power Vendor Discovery.