Skip to main content
Control domains are the categories of security requirements that VISO TRUST assesses vendors against. Artifact types are the documents and evidence that validate whether those requirements are met. Together, they form the evidence-to-controls mapping that drives every risk score.

Control Domains

A control domain is a grouping of related security controls — for example, Access Control, Incident Response, Data Protection, or Vendor Management. The domains in scope for a given assessment are determined by the business cases selected for that relationship. VISO TRUST’s default framework covers seven primary dimensions: You can further tailor the controls in scope through Custom Frameworks.

How Controls Come In Scope

Controls are brought into scope by the business cases selected during relationship context configuration. Each business case maps to a set of control domains — the combination of selected business cases determines the full set of controls that must be assessed. Example: A vendor selected with the business cases “Stores customer data” and “Has privileged system access” will have a broader set of controls in scope than a vendor selected only as a “Provides software as a service.” Changing a relationship’s business cases immediately updates which controls are in scope. Controls that fall out of scope are marked as Out of Scope. New in-scope controls begin as Unvalidated until evidence is collected.

Control Status

Each in-scope control has a status that reflects the current state of evidence: Controls marked Not Present or No Info represent gaps — these drive the residual risk score upward and are the primary targets for remediation requests and follow-up questionnaires.

Artifact Types and Control Mapping

Every artifact type recognized by VISO TRUST maps to a defined set of controls it can validate. When an artifact is uploaded and analyzed, Artifact Intelligence extracts evidence from the document and credits the controls it satisfies. Higher-assurance artifact types validate controls with greater confidence:

The Assurance Hierarchy

When multiple artifacts of different assurance levels address the same control, VISO TRUST uses the highest-assurance artifact to determine the control’s status. A validated SOC 2 report supersedes a self-attested security policy for the same control. When a high-assurance artifact is available, it also supersedes expired lower-assurance artifacts of the same type, and older versions of the same artifact type.

Compliance Certifications vs. Validated Artifacts

When VISO TRUST detects a publicly claimed certification (a SOC 2 badge on a vendor’s website) but doesn’t have the actual report, it grants partial credit — a lower-confidence signal that the vendor likely meets those controls. To upgrade from partial to full credit, request the actual certification document through a collection request. Submitting and analyzing the full report replaces the partial credit with validated evidence.