Skip to main content
An assessment is how VISO TRUST evaluates a vendor’s security posture and produces a risk score. Assessments can run automatically, be initiated by you, or involve the vendor directly — depending on how much depth you need.

Assessment Types

Starting an Assessment

From any relationship, select Start assessment (or Update assessment if one already exists) to begin. To add documents without starting a new collection, use Add information.

Request Artifacts from the Vendor

Send a collection request to the vendor’s contact:
  • Ask for everything — VISO TRUST requests all artifacts and questionnaire responses needed to satisfy in-scope controls
  • Request specific artifacts — specify which document types you need (e.g., SOC 2, ISO 27001, pen test)
  • Request manual response — send a questionnaire for the vendor to answer in writing
You can mix and match these options in a single collection request.
Use Advanced Settings when sending a collection request to configure follow-up timelines, response deadlines, and what happens if the vendor doesn’t respond. These can also be set as defaults at the relationship or organization level.

Upload Artifacts Directly

If you already have documentation, upload it directly without involving the vendor. VISO TRUST will classify the artifact type and begin analysis immediately. You can upload artifacts at any time, even alongside an active collection request.

Conduct Research

VISO TRUST can automatically search public sources for the vendor — finding compliance attestations, publicly available artifacts, risk advisories, and other relevant data. This runs automatically for instant assessments and can be triggered manually at any time.

Assessment Phases

Assessments move through a defined lifecycle. Understanding each phase helps you know what actions are available and what’s happening behind the scenes.

Follow-Up Questionnaires

If controls remain unvalidated after initial review, VISO TRUST surfaces a follow-up questionnaire to request additional information from the vendor. You can configure this behavior in three ways:
  • Always ask before following up — review results and decide whether to follow up
  • Conditional based on residual risk — automatically follow up if residual risk meets a threshold (e.g., Medium or above)
  • Use assessment concierge service — VISO TRUST manages the follow-up on your behalf
This setting can be configured at the assessment, relationship, or organization level.

The Vendor Experience

When you send a collection request, the vendor receives an email with a secure link and a one-time passcode. Through the collection portal, they can:
  1. Review what’s being requested and access guidance on typical artifacts for each control
  2. Upload documents (SOC 2, ISO 27001, pen tests, DPAs, etc.)
  3. Answer questionnaires if requested
  4. Forward the request to the right internal contact if needed
  5. Certify and submit their response when complete
After submission, VISO TRUST processes the artifacts using AI to classify, analyze, and map findings to your control framework.

Collection Timelines and Reminders

The default collection window is 30 days. Reminders are sent automatically:
  • Business owners and subscribers: every 5 business days
  • Vendor contacts: every 3 days, with a final notice 3 days before the deadline
You can extend the collection timeline at any time while an assessment is in the Collecting Information phase. There’s no limit on extensions. If the vendor doesn’t respond by the deadline, VISO TRUST either notifies you or closes the collection request, depending on your configuration.

Sub-Processor Collection

When the Privacy risk dimension is in scope, VISO TRUST prompts vendors to provide a list of their sub-processors — third parties that process personal data on your behalf. Sub-processors are displayed in the Risk Analysis tab and mapped in the relationship’s graph view for nth-party visibility.

Reviewing and Acting on Results

When an assessment reaches Completed status, a Review risk action becomes available — indicating that findings are ready and your team needs to record a decision.

Review Risk Actions

Once a remediation request is sent and the vendor responds, VISO TRUST automatically starts a new assessment update and returns the relationship to Review Risk for re-evaluation.

Assessment Completion

An assessment is marked Completed when:
  • All submitted artifacts and questionnaire responses have been analyzed
  • Any follow-up questionnaire has been responded to, skipped, or determined unnecessary
  • An assessment summary has been generated
Completion does not mean no action is required — you still need to review risk and record a decision.

Lifecycle Management

For onboarded relationships, VISO TRUST can automate ongoing vendor management: Artifact Validity — VISO TRUST tracks when artifacts expire and alerts you (or automatically contacts the vendor) 30 days before expiration to request updated documentation. Relationship Recertification — schedule recurring reassessments on a cadence you define (e.g., annually). VISO TRUST sends reminders when it’s time to recertify and can initiate the collection process automatically. Lifecycle management settings are in the relationship’s Relationship configuration dialog (gear icon) under Onboarding and lifecycle management.