Skip to main content
By default, VISO TRUST assesses vendors against its standard risk framework — grounded in NIST 800-53 and covering security, privacy, artificial intelligence, resilience, product security, cyber insurance, and service locations. Your Framework lets you tailor that framework to your organization’s requirements — adjusting the intake questions that scope controls, the data types you track, and how risk is calculated.
Your Framework is an add-on capability. If you don’t see it in Settings, contact your Customer Success Manager to enable it. Editing the framework requires Admin or Program Manager access.

How Your Framework Works

Unlike a per-relationship framework picker, VISO TRUST uses a single, organization-wide framework. Customizing it changes assessment scope and scoring for every relationship. Your Framework is organized into three tabs: Evidence collected through assessments (artifacts, questionnaire responses, compliance attestations) is still analyzed by Artifact Intelligence and mapped to controls — the framework determines which controls are in scope and how they’re weighted.

Editing Your Framework

Your Framework is managed in Settings → Your Framework.
1

Open the framework

Go to Settings → Your Framework and select Edit framework to start a draft.
2

Make your changes

Work through the Intake questionnaire, Data classification, and Risk calculations tabs — editing intake questions and their controls in scope, adjusting data types and their sensitivity, and tuning risk calculations.
3

Publish or discard

Your edits are saved as a draft. Click Publish changes to apply them across your organization, or Discard draft to revert.

How the Framework Applies to Relationships

Because the framework is organization-wide, publishing changes updates the scope and scoring for all relationships. Each relationship’s individual Context — its intake-questionnaire answers and data classification — is set per relationship in the Relationship configuration dialog, within the bounds your framework defines.
Changes take effect when you Publish. Review the impact on your portfolio after publishing, since re-scoping controls can shift risk scores.