Skip to main content
Risk Advisories are alerts generated when something risk-relevant happens to a vendor in your portfolio — a breach, regulatory action, software vulnerability, or other material event. VISO TRUST monitors your vendors continuously and surfaces advisories automatically, so you’re informed the same day an event is published rather than at your next review cycle.

What a Risk Advisory Contains

Each advisory includes:
  • Title — a clear description of the event
  • Organization — the vendor the advisory pertains to
  • Type — the category of event (see below)
  • Materiality — the assessed severity and significance of the advisory
  • Network Exposure — the number of direct vendors and nth parties impacted
  • Source — a link to the original documentation and its publication date
  • VISO TRUST Statement (when applicable) — additional context or guidance from the VISO TRUST team

Advisory Types

Materiality

Each advisory is assigned a materiality rating that reflects its potential significance. Materiality is assessed through an automated process with human oversight, based on whether a reasonable stakeholder would consider the event important in evaluating the vendor’s risk profile. Use materiality ratings to triage which advisories require immediate action versus which to monitor.

Where to Find Advisories

Portfolio level: Navigate to Monitoring in the left sidebar to see all advisories across your entire vendor portfolio. Switch between the Risk Advisories and Vulnerabilities tabs to view each feed. Relationship level: Open any vendor relationship and go to the Monitoring tab to see advisories specific to that vendor and their nth parties. Nth-party visibility: VISO TRUST surfaces advisories not just for your direct vendors, but for their subservicers and technology providers — giving you visibility into supply chain risk beyond your immediate vendor list.

Requesting a Vendor Response

When a high-impact advisory affects multiple vendors, you can send a targeted collection request directly from the advisory — asking affected vendors to confirm their exposure and provide evidence of their response.
1

Open the advisory

Navigate to Monitoring, open the Risk Advisories tab, and select the advisory you want to act on.
2

Select Request vendor response

At the bottom of the advisory, select Request vendor response.
3

Select affected relationships

Use filters (tiers, tags, business units, business cases, data types) to identify the relevant vendor relationships. Select individual vendors or bulk-select your entire portfolio.
Relationships without a third-party contact cannot be included. Add a contact to the relationship first.
4

Define your questions

Add specific questions for vendors to answer — tailored to the advisory rather than generic requests. VISO Chat Agent can help you draft context-specific questions based on the advisory details.
5

Configure and send

Use Advanced Settings to define collection timelines, non-response behavior, and follow-up options. Send the request — each vendor’s contact receives a targeted collection request.
Track vendor responses in the relationship’s artifact list under the Questionnaire artifact type.

Continuous Monitoring

VISO TRUST continuously scans OSINT feeds, regulatory filings, security disclosures, and news sources to surface advisories as they emerge. There’s no manual setup required — once a relationship exists and the vendor is onboarded, monitoring is active. Point-in-time assessments capture risk at a single moment. Continuous monitoring keeps that picture current between assessment cycles, giving you the ability to react to material events before they affect your risk posture.