The Core Formula
Everything in the VISO TRUST risk model flows from a single industry-standard principle:Step 1 — Establish Impact
Impact is driven by data sensitivity — the types of data your vendor handles. The most sensitive data type selected for the relationship sets the impact score. Data types fall into sensitivity levels — None, Minimal, Moderate, Elevated, and Critical. A vendor handling payment card data (Critical) starts with a higher impact score than one handling only low-sensitivity data (Minimal). See Data Types for the full list of data types and their sensitivity levels.Step 2 — Assess Likelihood (Threat Surface)
Likelihood is driven by threat surface — how the vendor interacts with your environment. This is determined by the business cases selected when configuring relationship context. Business cases capture factors like:- Does the vendor store or process your data?
- Does the vendor have privileged access to your systems?
- Does the vendor operate a production environment?
- Does the vendor have physical access to your facilities?
Step 3 — Determine Controls in Scope
Not all security controls matter equally for every vendor. Based on the business cases selected, VISO TRUST automatically determines which control domains are relevant for the assessment. A SaaS vendor on a hyperscale cloud needs different controls validated than a vendor with physical server access. Controls in scope define what evidence must be collected and reviewed.Step 4 — Gather and Weigh Evidence
VISO TRUST collects evidence from multiple sources:- Independent audits (SOC 2, ISO 27001, HITRUST, PCI DSS)
- Security policies and procedures
- Technical assessments (penetration tests)
- Questionnaire responses
- Publicly available artifacts and certifications
Multiplied together across every in-scope control, these produce control mitigation — the total credit subtracted from likelihood. See Risk Analysis for the per-control breakdown.
Step 5 — Calculate the Scores
Inherent Risk is the starting point — potential risk before any controls are considered. It reflects Impact × Likelihood based solely on relationship context. Residual Risk is the end point — impact applied to the likelihood that remains after control mitigation is subtracted. Risk only goes down when there’s verified evidence. A vendor that claims good security practices but can’t prove them gets no credit. Both scores are mapped to risk labels:
Label names and the thresholds that map to them can be customized to align with your organization’s risk language. See Your Risk Model.
Scores Before an Assessment Completes
A relationship is scored as soon as it has context — you don’t have to wait for an assessment. The instant assessment researches public sources and the model runs against whatever evidence that turns up. Until a completed assessment backs the score, it’s transitional. On the Relationships list a transitional score is shown in italics with an asterisk (*). Treat it as a starting estimate: it reflects the relationship context plus whatever public evidence exists, not reviewed documentation. The marker clears once an assessment completes, and the score then rests on analyzed evidence.
A score also goes back to transitional while a new assessment is in progress, since the result isn’t settled yet.
Predicted Context
Context — the intake answers and data classification — is what drives impact and likelihood, so it has to be right before the score means much. VISO TRUST can propose it for you. Prediction runs on its own when you add a relationship with Predict relationship context and instantly assess selected. You can also run it later: open the Relationship configuration dialog and select Predict relationship context. Either way, VISO TRUST fills in the intake questionnaire and data classification from what it knows about the vendor, and the section header changes to Context predicted by VISO TRUST — hover it to see the reasoning behind the prediction. Whether prediction happens automatically for new relationships is an org-level default in Settings → Assessments.What Drives Score Changes
Risk scores update automatically when:- New artifacts are uploaded or analyzed
- Business cases or data types are changed
- Artifacts expire (reducing assurance on previously credited controls)
- New risk advisories are detected (flagged as pending changes)
- An assessment update runs