> ## Documentation Index
> Fetch the complete documentation index at: https://docs.visotrust.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Your Framework

> Customize your VISO TRUST risk framework — intake questions, data classification, and risk calculations that determine assessment scope and scoring.

By default, VISO TRUST assesses vendors against its standard risk framework — grounded in NIST 800-53 and covering security, privacy, artificial intelligence, resilience, product security, cyber insurance, and service locations. **Your Framework** lets you tailor that framework to your organization's requirements — adjusting the intake questions that scope controls, the data types you track, and how risk is calculated.

<Note>
  Your Framework is an add-on capability. If you don't see it in Settings, contact your Customer Success Manager to enable it. Editing the framework requires Admin or Program Manager access.
</Note>

## How Your Framework Works

Unlike a per-relationship framework picker, VISO TRUST uses a single, organization-wide framework. Customizing it changes assessment scope and scoring for every relationship. Your Framework is organized into three tabs:

| Tab                      | What it controls                                                                                                                                    |
| ------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Intake questionnaire** | The intake questions asked when configuring a relationship's context. Each question maps to the **controls in scope** it brings into an assessment. |
| **Data classification**  | The data types your organization tracks and the **data sensitivity** level assigned to each — driving the impact side of risk scoring.              |
| **Risk calculations**    | How risk is calculated — risk tolerance thresholds and whether publicly claimed compliance certifications count toward residual risk.               |

Evidence collected through assessments (artifacts, questionnaire responses, compliance attestations) is still analyzed by Artifact Intelligence and mapped to controls — the framework determines which controls are in scope and how they're weighted.

## Editing Your Framework

Your Framework is managed in **Settings → Your Framework**.

<Steps>
  <Step title="Open the framework">
    Go to **Settings → Your Framework** and select **Edit framework** to start a draft.
  </Step>

  <Step title="Make your changes">
    Work through the **Intake questionnaire**, **Data classification**, and **Risk calculations** tabs — editing intake questions and their controls in scope, adjusting data types and their sensitivity, and tuning risk calculations.
  </Step>

  <Step title="Publish or discard">
    Your edits are saved as a draft. Click **Publish changes** to apply them across your organization, or **Discard draft** to revert.
  </Step>
</Steps>

## How the Framework Applies to Relationships

Because the framework is organization-wide, publishing changes updates the scope and scoring for all relationships. Each relationship's individual **Context** — its intake-questionnaire answers and data classification — is set per relationship in the **Relationship configuration** dialog, within the bounds your framework defines.

<Tip>
  Changes take effect when you **Publish**. Review the impact on your portfolio after publishing, since re-scoping controls can shift risk scores.
</Tip>
