The Core Formula
Everything in the VISO TRUST risk model flows from a single industry-standard principle:Step 1 — Establish Impact
Impact is driven by data sensitivity — the types of data your vendor handles. The most sensitive data type selected for the relationship sets the impact score. Data types fall into sensitivity levels — None, Minimal, Moderate, Elevated, and Critical. A vendor handling payment card data (Critical) starts with a higher impact score than one handling only low-sensitivity data (Minimal). See Data Types for the full list of data types and their sensitivity levels.Step 2 — Assess Likelihood (Threat Surface)
Likelihood is driven by threat surface — how the vendor interacts with your environment. This is determined by the business cases selected when configuring relationship context. Business cases capture factors like:- Does the vendor store or process your data?
- Does the vendor have privileged access to your systems?
- Does the vendor operate a production environment?
- Does the vendor have physical access to your facilities?
Step 3 — Determine Controls in Scope
Not all security controls matter equally for every vendor. Based on the business cases selected, VISO TRUST automatically determines which control domains are relevant for the assessment. A SaaS vendor on a hyperscale cloud needs different controls validated than a vendor with physical server access. Controls in scope define what evidence must be collected and reviewed.Step 4 — Gather and Weigh Evidence
VISO TRUST collects evidence from multiple sources:- Independent audits (SOC 2, ISO 27001, HITRUST, PCI DSS)
- Security policies and procedures
- Technical assessments (penetration tests)
- Questionnaire responses
- Publicly available artifacts and certifications
Step 5 — Calculate the Scores
Inherent Risk is the starting point — potential risk before any controls are considered. It reflects Impact × Likelihood based solely on relationship context. Residual Risk is the end point — inherent risk minus credit for proven controls. Risk only goes down when there’s verified evidence. A vendor that claims good security practices but can’t prove them gets no credit. Both scores are mapped to risk labels:
Label names and the thresholds that map to them can be customized to align with your organization’s risk language. See Your Risk Model.
Predicted vs. Validated Scores
VISO TRUST provides two flavors of risk scores: Predicted — calculated immediately when a relationship is created using publicly available data and vendor profile information. Provides an immediate estimate before any documentation is reviewed. Validated — calculated after evidence has been submitted and analyzed through an assessment. More accurate and carries higher confidence. As assessments complete and evidence is added, predicted scores are replaced by validated scores. You can see which score type is displayed on any relationship.What Drives Score Changes
Risk scores update automatically when:- New artifacts are uploaded or analyzed
- Business cases or data types are changed
- Artifacts expire (reducing assurance on previously credited controls)
- New risk advisories are detected (flagged as pending changes)
- An assessment update runs