Skip to main content

A

Admin A VISO TRUST role with full platform access — manages users, settings, relationships, assessments, and all program activity. Artifact Any document or evidence collected as part of an assessment — audit reports, security certifications, policies, questionnaire responses, and more. Artifacts are analyzed by Artifact Intelligence to extract control evidence. Artifact Intelligence VISO TRUST’s AI document analysis engine. Reads security and compliance documents, extracts risk-relevant evidence, maps findings to controls, and assigns assurance levels — automatically. Artifact Type The classification of an artifact (e.g., SOC 2 Type II, ISO 27001, Penetration Test Report). VISO TRUST classifies artifacts automatically and uses the type to determine which controls the artifact can validate and how much assurance it carries. Artifact Validity The period during which an artifact is considered current. Each artifact type has a standard validity window (e.g., SOC 2 audit period, ISO 27001 3-year certificate). VISO TRUST tracks expiration and reduces assurance as artifacts age. Assessment The process by which VISO TRUST evaluates a vendor’s security posture. Assessments can be instant (using public data), artifact-based (uploading documents), or vendor-involved (requesting documentation through the collection portal). Assessment Lead A designated user responsible for running a vendor assessment, separate from the Business Owner of the relationship. Assurance Level A rating reflecting how trustworthy a piece of evidence is. Third-party audits carry higher assurance than self-attested policies. Assurance affects how much control credit an artifact receives. Levels are Limited, Moderate, Standard, and Advanced. Attestation A vendor’s formal declaration about their security practices. Includes submission certification (vendor confirms their responses are accurate), compliance attestations (publicly claimed certifications), and questionnaire responses.

B

Business Case An intake selection that describes how your organization engages with a vendor — e.g., “stores customer data,” “has privileged system access,” “provides SaaS.” Business cases determine which controls are in scope for an assessment and contribute to the likelihood (threat surface) component of inherent risk. Business Owner The internal team member designated as the primary owner of a specific vendor relationship. Not a platform role — an assignment on a relationship. Business Owners manage assessments, receive notifications, and have expanded edit permissions on relationships they own. Business Unit An internal department or team grouping used to organize vendor relationships and scope Risk Insights dashboards. Each user and relationship belongs to a Business Unit.

C

Collection Portal The secure, vendor-facing interface used to submit documentation and questionnaire responses during an assessment. Vendors access it via a one-time passcode from an email invitation. Collection Request A formal request sent to a vendor to submit security documentation and/or questionnaire responses through the collection portal. Complementary User Entity Controls (CUECs) Controls in a SOC 2 report that are the responsibility of the client (user entity) rather than the vendor. VISO TRUST auditors review CUECs as part of the AI Assessment + Auditor Review process. Contributor A VISO TRUST role that can view all relationships and create and manage assessments on relationships where they are assigned as Business Owner or Assessment Lead. Control A specific security requirement that must be satisfied by vendor evidence. Controls are organized into control domains and brought into scope by the business cases selected for a relationship. Control Domain A category grouping related security controls — for example, Access Control, Incident Response, or Data Privacy. The domains in scope for a relationship are determined by the selected business cases. Control Framework The structured set of controls that assessments are evaluated against. VISO TRUST’s default framework is grounded in NIST 800-53. Custom frameworks can be created for program-specific requirements. Control Status The current state of evidence for a specific control: Present, Not Present, Unvalidated, No Info, Out of Scope, or Not Applicable.

D

Data Sensitivity A numeric value (0–1) representing how severe the consequences would be if data of this type were compromised. Drives the impact component of inherent risk. Levels range from None and Minimal up through Moderate, Elevated, and Critical. Data Type A category of information that may be shared with a vendor — e.g., Customer PII, Financial Reporting, Source Code, PHI. Data types determine data sensitivity and the impact component of inherent risk. Default Subscriber A user automatically subscribed to every relationship in the organization, existing and future. Useful for centralized risk or compliance teams that need full portfolio visibility.

F

Follow-Up Questionnaire A targeted questionnaire sent to a vendor after initial assessment review to address specific control gaps. Shorter and more focused than an initial questionnaire. Vendors have a configurable window (7 days by default) to respond.

I

Impact One of two inputs to inherent risk. Represents the severity of consequences if a vendor were compromised. Driven by the maximum data sensitivity across selected data types. Answers: “If something goes wrong, how bad could it be?” Inherent Risk The level of risk before accounting for any vendor security controls. Calculated as Impact × Likelihood. Represents worst-case exposure based on the relationship context. Instant Assessment An automatic assessment that runs when a relationship is created (if a vendor URL is provided). Uses publicly available data — certifications, security pages, breach disclosures — to generate an immediate risk score without vendor involvement.

L

Lifecycle Management Automated features for maintaining vendor relationships over time: artifact validity tracking (alerts when documents expire), relationship recertification (scheduled reassessments), and automatic renewal requests. Likelihood One of two inputs to inherent risk. Represents the probability of a security incident occurring, based on the threat surface defined by the selected business cases. Answers: “How likely is something to go wrong?”

N

Nth Party A vendor’s vendor — a subservicer or technology provider that your direct vendor relies on. VISO TRUST surfaces nth-party risk through the Risk Network and monitors them for advisories alongside your direct vendors.

O

Onboarded A relationship status indicating the vendor is actively managed in your TPRM program. Onboarded relationships appear in Risk Insights dashboards and are eligible for lifecycle management features.

P

Pending Changes A flag on a relationship indicating new information exists that isn’t reflected in the current assessment summary — expired artifacts, context changes, new advisories, or newly discovered public artifacts. Resolved automatically on the next assessment update. Program Manager A VISO TRUST role that can edit all relationships and manage all assessments, and can view — but not edit — program settings.

R

Relationship The central record of a business connection with a third-party vendor. All assessments, risk scores, artifacts, advisories, and activity for a vendor are organized under a relationship. Remediation A formal request sent to a vendor to address specific control gaps identified in an assessment. Vendors respond with evidence. VISO TRUST initiates a new assessment update when a vendor responds. Residual Risk The level of risk after accounting for the vendor’s security controls. Inherent risk minus credit for proven controls. The primary risk score used for decision-making. Risk Advisory An alert generated when a vendor in your portfolio experiences a risk-relevant event — breach, vulnerability disclosure, regulatory action, etc. Generated automatically through continuous monitoring. Risk Model The configuration layer that controls how numeric risk scores map to labels (Low, Medium, High, Extreme) and how demanding the thresholds are. Includes risk tolerance settings, label names, and compliance certification influence. Risk Network A visual graph representation of your third-party and nth-party vendor relationships, built from subservicer data extracted from artifacts. Risk Tolerance An organization-level setting controlling how strict the risk model is when mapping scores to labels. Options: Minimal (strictest), Moderate, Significant (most flexible).

S

Smart Summary An AI-generated narrative summary of assessment findings — formatted as a readable report for executives, auditors, or boards. Editable in-platform and downloadable. Sub-Processor A third party that your vendor uses to process personal data on your behalf. VISO TRUST collects sub-processor lists from vendors when the Privacy risk dimension is in scope. Subscriber An internal user who receives notifications about a specific relationship without being the Business Owner. Subscribers are informed without being responsible for the relationship.

T

Tags Free-form labels applied to vendor relationships for filtering, organization, and reporting. Managed in Settings → Tags. Threat Surface The combination of exposures a vendor introduces based on the selected business cases — what systems they touch, what access they have, how they interact with your data. Drives the likelihood component of inherent risk. Trust Profile An organization’s repository of security documentation in VISO TRUST, used to answer inbound customer questionnaires via AI and power Vendor Discovery.

V

Vendor Collection Portal See Collection Portal. Vendor Discovery A feature that automatically surfaces third-party vendors identified through subservicer analysis of your Trust Profile artifacts — helping you find vendors you may not be tracking yet. Vendor Tier A grouping structure (up to 5 tiers) for organizing vendor relationships by priority or risk treatment. Managed from the Relationships list page. Viewer A VISO TRUST role with view-only access. Can see relationships, assessments, risk metrics, and advisories but cannot make changes. VISO Chat Agent An AI assistant built into VISO TRUST that answers questions about your vendor portfolio, assessment findings, and risk data using natural language.