> ## Documentation Index
> Fetch the complete documentation index at: https://docs.visotrust.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Assessment Settings

> Set default assessment behavior in VISO TRUST at the organization, business unit, and relationship level for consistent and predictable automation.

Assessment settings let you define default behavior for how assessments are initiated, managed, and completed — across your entire organization or for individual relationships. Consistent defaults reduce repetitive configuration and ensure automation behaves predictably.

## Where to Configure Settings

Settings can be applied at three levels, from broadest to most specific:

| Level            | Where to find it                       | Scope                                            |
| ---------------- | -------------------------------------- | ------------------------------------------------ |
| **Organization** | Settings → Assessments                 | Applies to all relationships unless overridden   |
| **Relationship** | Relationship → gear icon → Assessments | Applies to all assessments for this relationship |
| **Assessment**   | Start assessment → Advanced Settings   | Applies to this one collection request only      |

More specific settings override broader ones. A relationship-level setting overrides the org default; an assessment-level setting overrides both.

<Note>
  Organization and relationship defaults also apply to assessments started by automation — such as scheduled recertifications and artifact update requests.
</Note>

## Available Settings

### Instant Assessment (Organization level only)

When enabled, VISO TRUST automatically runs an instant assessment for every newly created relationship — analyzing publicly available data to generate an immediate risk profile. This setting can be toggled on or off per relationship at creation time.

### Collection Request Defaults

**Initial collection timeline** — how long the vendor has to respond before the request expires. Default is 30 days. Configurable per assessment via Advanced Settings.

**No-vendor-response behavior** — what happens when the collection deadline passes without a vendor response:

* **Notify me** — send an alert to the Business Owner and assessment creator
* **Close collection request** — automatically close the request when the deadline passes

**Automate follow-ups** — controls whether follow-up questionnaires are sent automatically when controls remain unvalidated:

* **Always ask before following up** — prompt the reviewer to decide whether to follow up after each assessment
* **Conditional based on residual risk** — automatically follow up when residual risk meets or exceeds a configured threshold (e.g., Medium)
* **Use assessment concierge service** — VISO TRUST manages the follow-up on your behalf

### Analysis Method

Controls whether submitted artifacts are reviewed by AI only, or by AI plus an expert auditor:

* **AI Assessment** — faster; uses Artifact Intelligence to analyze and map controls
* **AI Assessment + Auditor Review** — AI analysis is supplemented by a VISO TRUST analyst who reviews high-assurance artifacts (SOC 2 reports, ISO certificates, penetration tests, etc.) for qualified opinions, exceptions, and coverage gaps

The analysis method can be configured at the organization or relationship level and overridden per assessment.

### Follow-up Questionnaire Timeline

How long the vendor has to respond to a follow-up questionnaire before it's considered expired (7, 14, 30, 60, or 90 days). Configurable at the organization and relationship level.
