> ## Documentation Index
> Fetch the complete documentation index at: https://docs.visotrust.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Risk Insights

> Risk Insights provides portfolio-level VISO TRUST dashboards built on Metabase, giving program managers a complete view of third-party risk exposure.

**Risk Insights** provides portfolio-level dashboards that give program managers and security leaders a clear view of organizational risk across all vendor relationships. It's built on Metabase and accessible to all roles — Admins, Program Managers, Contributors, and Viewers.

Navigate to **Risk Insights** in the left sidebar to access the dashboards.

## Two Dashboards

Risk Insights contains two distinct dashboards with different scopes:

<CardGroup cols={2}>
  <Card title="Risk Metrics" icon="chart-pie">
    Scoped to **onboarded relationships only**. Shows your organization's actual cyber risk exposure — the vendors actively in your program with risk scores, control coverage, and assessment data.
  </Card>

  <Card title="Program Metrics" icon="chart-bar">
    Scoped to **all relationships** — onboarded, not onboarded, and deleted. Shows the operational health of your TPRM program — how much coverage you have, how active assessments are, and where VISO TRUST has had impact.
  </Card>
</CardGroup>

Clicking any number on either dashboard opens a filtered view of your Relationships list page — so you can drill directly into the underlying data.

## Filters

Both dashboards support the same set of filters for slicing the data:

| Filter             | Description                                                      |
| ------------------ | ---------------------------------------------------------------- |
| **Created Date**   | Apply date ranges based on when relationships were created       |
| **Business Units** | Show only relationships belonging to a specific department       |
| **Risk Levels**    | Show relationships at a specific inherent or residual risk level |
| **Business Case**  | Show relationships associated with one or more business cases    |
| **Data Types**     | Show relationships with specific data types in scope             |
| **Tags**           | Show relationships with specific tags applied                    |

## Risk Metrics Reports

Reports in this dashboard are scoped to onboarded relationships only.

| Report                       | Description                                                                                              |
| ---------------------------- | -------------------------------------------------------------------------------------------------------- |
| **Onboarded Relationships**  | Total count of onboarded vendor relationships                                                            |
| **Average Residual Risk**    | The average residual risk score across all onboarded relationships                                       |
| **Risk Timeline**            | Average organizational risk over time, relative to the number of onboarded relationships in your program |
| **Average Control Coverage** | Average percentage of in-scope controls with validated evidence (present controls ÷ in-scope controls)   |
| **Risk Distribution**        | Breakdown of vendors by risk level (Low / Medium / High / Extreme)                                       |
| **Assessment Coverage**      | Percentage of onboarded relationships with a completed assessment                                        |

## Program Metrics Reports

Reports in this dashboard cover your full relationship population.

| Report                             | Description                                                                  |
| ---------------------------------- | ---------------------------------------------------------------------------- |
| **Total Relationships**            | All relationships across your program, including non-onboarded               |
| **Assessment Activity**            | Assessments initiated, completed, and in progress over a time period         |
| **Relationships by Business Unit** | Relationship count broken down by owning department                          |
| **Relationships by Tier**          | Relationship count broken down by vendor tier                                |
| **Relationships Awaiting Action**  | Relationships pending risk review, remediation response, or lifecycle update |

<Note>
  Risk Insights is available to all roles. Both dashboards are visible to Admins, Program Managers, Contributors, and Viewers; the data shown may be scoped to the relationships each user can access.
</Note>

## Using Risk Insights for Program Reviews

Risk Insights is designed to support executive and stakeholder reporting, not just day-to-day operations. Common use cases:

* **Board or executive reporting** — share average residual risk and assessment coverage as program health indicators
* **Business unit reviews** — filter by Business Unit to give team leads a view of their own risk posture
* **Audit preparation** — use assessment coverage and control coverage metrics to demonstrate program completeness
* **Trend analysis** — track how organizational risk has changed over time as more vendors are assessed and risk is reduced

<Tip>
  Bookmark filtered dashboard views for specific business units or risk levels to build a recurring reporting workflow without re-applying filters each time.
</Tip>
