Control Domains
A control domain is a grouping of related security controls — for example, Access Control, Incident Response, Data Protection, or Vendor Management. The domains in scope for a given assessment are determined by the business cases selected for that relationship. VISO TRUST’s default framework covers these dimensions:
Every dimension that has controls in scope gets its own section in the relationship’s risk analysis, where you can see those controls and the evidence behind them. Only the Security dimension produces the inherent and residual risk scores used across the platform.
Controls introduced by your organization’s own supplemental questionnaires are tracked separately — they appear under Questionnaires in the risk analysis rather than as a risk dimension.
You can further tailor the controls in scope through Custom Frameworks. The full framework is listed in-platform under Glossary → Control Domains.
How Controls Come In Scope
Controls are brought into scope by the business cases selected during relationship context configuration. Each business case maps to a set of control domains — the combination of selected business cases determines the full set of controls that must be assessed. Example: A vendor selected with the business cases “Stores customer data” and “Has privileged system access” will have a broader set of controls in scope than a vendor selected only as a “Provides software as a service.” Changing a relationship’s business cases immediately updates which controls are in scope. Control domains that fall out of scope are marked Out of scope. New in-scope controls show No Information until evidence is collected.Control Status
Each in-scope control has a status that reflects the current state of evidence:
Out of scope applies at the control domain level: the domain is enabled in your organization, but doesn’t apply to this relationship based on its business context.
In the risk analysis view, these statuses are grouped into three indicators — Present (green), Not present (red), and Not applicable (grey) — with a ring showing how much of the control’s weight the evidence actually mitigated.
Controls with no supporting evidence represent gaps — they keep the residual risk score high and are the primary targets for remediation requests and follow-up questionnaires. Controls marked Not applicable are handled differently: their weight is removed from likelihood rather than counted as mitigation, so they neither raise nor lower the score.
Artifact Types and Control Mapping
Every artifact type recognized by VISO TRUST maps to a defined set of controls it can validate. When an artifact is uploaded and analyzed, Artifact Intelligence extracts evidence from the document and credits the controls it satisfies. Each type covers a characteristic set of domains:Assurance Levels
Every artifact type carries a numeric assurance value, displayed as one of four levels on a four-dot meter:
Assurance is what scales control credit: a present control backed by an Advanced artifact mitigates nearly all of its weight, while the same control backed by a questionnaire mitigates well under it. Every artifact type’s own level is listed in-platform under Glossary → Artifact Types.
Assurance can also be reduced below an artifact type’s normal level. The risk analysis view labels the reason: