Skip to main content
Control domains are the categories of security requirements that VISO TRUST assesses vendors against. Artifact types are the documents and evidence that validate whether those requirements are met. Together, they form the evidence-to-controls mapping that drives every risk score.

Control Domains

A control domain is a grouping of related security controls — for example, Access Control, Incident Response, Data Protection, or Vendor Management. The domains in scope for a given assessment are determined by the business cases selected for that relationship. VISO TRUST’s default framework covers these dimensions: Every dimension that has controls in scope gets its own section in the relationship’s risk analysis, where you can see those controls and the evidence behind them. Only the Security dimension produces the inherent and residual risk scores used across the platform. Controls introduced by your organization’s own supplemental questionnaires are tracked separately — they appear under Questionnaires in the risk analysis rather than as a risk dimension. You can further tailor the controls in scope through Custom Frameworks. The full framework is listed in-platform under Glossary → Control Domains.

How Controls Come In Scope

Controls are brought into scope by the business cases selected during relationship context configuration. Each business case maps to a set of control domains — the combination of selected business cases determines the full set of controls that must be assessed. Example: A vendor selected with the business cases “Stores customer data” and “Has privileged system access” will have a broader set of controls in scope than a vendor selected only as a “Provides software as a service.” Changing a relationship’s business cases immediately updates which controls are in scope. Control domains that fall out of scope are marked Out of scope. New in-scope controls show No Information until evidence is collected.

Control Status

Each in-scope control has a status that reflects the current state of evidence: Out of scope applies at the control domain level: the domain is enabled in your organization, but doesn’t apply to this relationship based on its business context. In the risk analysis view, these statuses are grouped into three indicators — Present (green), Not present (red), and Not applicable (grey) — with a ring showing how much of the control’s weight the evidence actually mitigated. Controls with no supporting evidence represent gaps — they keep the residual risk score high and are the primary targets for remediation requests and follow-up questionnaires. Controls marked Not applicable are handled differently: their weight is removed from likelihood rather than counted as mitigation, so they neither raise nor lower the score.

Artifact Types and Control Mapping

Every artifact type recognized by VISO TRUST maps to a defined set of controls it can validate. When an artifact is uploaded and analyzed, Artifact Intelligence extracts evidence from the document and credits the controls it satisfies. Each type covers a characteristic set of domains:

Assurance Levels

Every artifact type carries a numeric assurance value, displayed as one of four levels on a four-dot meter: Assurance is what scales control credit: a present control backed by an Advanced artifact mitigates nearly all of its weight, while the same control backed by a questionnaire mitigates well under it. Every artifact type’s own level is listed in-platform under Glossary → Artifact Types. Assurance can also be reduced below an artifact type’s normal level. The risk analysis view labels the reason:

The Assurance Hierarchy

When multiple artifacts of different assurance levels address the same control, VISO TRUST uses the highest-assurance artifact to determine the control’s status. A validated SOC 2 report supersedes a self-attested security policy for the same control. When a high-assurance artifact is available, it also supersedes expired lower-assurance artifacts of the same type, and older versions of the same artifact type.

Compliance Certifications vs. Validated Artifacts

When VISO TRUST detects a publicly claimed certification (a SOC 2 badge on a vendor’s website) but doesn’t have the actual report, it grants partial credit — a lower-confidence signal that the vendor likely meets those controls. To upgrade from partial to full credit, request the actual certification document through a collection request. Submitting and analyzing the full report replaces the partial credit with validated evidence.