> ## Documentation Index
> Fetch the complete documentation index at: https://docs.visotrust.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Risk Advisories

> Risk Advisories surface vendor breaches, vulnerabilities, regulatory actions, and other material events automatically so you can respond the day they happen.

**Risk Advisories** are alerts generated when something risk-relevant happens to a vendor in your portfolio — a breach, regulatory action, software vulnerability, or other material event. VISO TRUST monitors your vendors continuously and surfaces advisories automatically, so you're informed the same day an event is published rather than at your next review cycle.

## What a Risk Advisory Contains

Each advisory includes:

* **Title** — a clear description of the event
* **Organization** — the vendor the advisory pertains to
* **Type** — the category of event (see below)
* **Materiality** — the assessed severity and significance of the advisory
* **Network Exposure** — the number of direct vendors and nth parties impacted
* **Source** — a link to the original documentation and its publication date
* **VISO TRUST Statement** (when applicable) — additional context or guidance from the VISO TRUST team

## Advisory Types

| Type              | What it covers                                                                                                                                           |
| ----------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Security**      | Events related to the confidentiality, integrity, or availability of information being compromised — breaches, ransomware incidents, unauthorized access |
| **Vulnerability** | Disclosure of a specific flaw or weakness that could be exploited (CVEs, zero-days)                                                                      |
| **Compliance**    | Failures to meet regulatory requirements, resulting in fines, enforcement actions, or legal consequences                                                 |
| **SEC 8-K**       | Material security incident disclosures by public companies — significant enough to require shareholder notification                                      |
| **Legal**         | Legal disputes, lawsuits, or regulatory actions affecting a company's risk profile                                                                       |
| **Geopolitical**  | Sanctions, international conflicts, or political instability that could affect vendor operations or supply chain continuity                              |
| **Financial**     | Material financial events such as earnings losses, bankruptcy filings, or significant funding issues                                                     |
| **Operational**   | Events affecting a vendor's operational capacity — system outages, natural disasters, workforce disruptions                                              |

## Materiality

Each advisory is assigned a **materiality rating** that reflects its potential significance. Materiality is assessed through an automated process with human oversight, based on whether a reasonable stakeholder would consider the event important in evaluating the vendor's risk profile.

Use materiality ratings to triage which advisories require immediate action versus which to monitor.

## Where to Find Advisories

**Portfolio level:** Navigate to **Monitoring** in the left sidebar to see all advisories across your entire vendor portfolio. Switch between the **Risk Advisories** and **Vulnerabilities** tabs to view each feed.

**Relationship level:** Open any vendor relationship and go to the **Monitoring** tab to see advisories specific to that vendor and their nth parties.

**Nth-party visibility:** VISO TRUST surfaces advisories not just for your direct vendors, but for their subservicers and technology providers — giving you visibility into supply chain risk beyond your immediate vendor list.

## Requesting a Vendor Response

When a high-impact advisory affects multiple vendors, you can send a targeted collection request directly from the advisory — asking affected vendors to confirm their exposure and provide evidence of their response.

<Steps>
  <Step title="Open the advisory">
    Navigate to **Monitoring**, open the **Risk Advisories** tab, and select the advisory you want to act on.
  </Step>

  <Step title="Select Request vendor response">
    At the bottom of the advisory, select **Request vendor response**.
  </Step>

  <Step title="Select affected relationships">
    Use filters (tiers, tags, business units, business cases, data types) to identify the relevant vendor relationships. Select individual vendors or bulk-select your entire portfolio.

    <Note>
      Relationships without a third-party contact cannot be included. Add a contact to the relationship first.
    </Note>
  </Step>

  <Step title="Define your questions">
    Add specific questions for vendors to answer — tailored to the advisory rather than generic requests. VISO Chat Agent can help you draft context-specific questions based on the advisory details.
  </Step>

  <Step title="Configure and send">
    Use Advanced Settings to define collection timelines, non-response behavior, and follow-up options. Send the request — each vendor's contact receives a targeted collection request.
  </Step>
</Steps>

Track vendor responses in the relationship's artifact list under the **Questionnaire** artifact type.

## Continuous Monitoring

VISO TRUST continuously scans OSINT feeds, regulatory filings, security disclosures, and news sources to surface advisories as they emerge. There's no manual setup required — once a relationship exists and the vendor is onboarded, monitoring is active.

Point-in-time assessments capture risk at a single moment. Continuous monitoring keeps that picture current between assessment cycles, giving you the ability to react to material events before they affect your risk posture.
