Assessment Types
Starting an Assessment
From any relationship, select Start assessment (or Update assessment if one already exists) to begin. To add documents without starting a new collection, use Add information.Request Artifacts from the Vendor
Send a collection request to the vendor’s contact:- Ask for everything — VISO TRUST requests all artifacts and questionnaire responses needed to satisfy in-scope controls
- Request specific artifacts — specify which document types you need (e.g., SOC 2, ISO 27001, pen test)
- Request manual response — send a questionnaire for the vendor to answer in writing
Upload Artifacts Directly
If you already have documentation, upload it directly without involving the vendor. VISO TRUST will classify the artifact type and begin analysis immediately. You can upload artifacts at any time, even alongside an active collection request.Conduct Research
VISO TRUST can automatically search public sources for the vendor — finding compliance attestations, publicly available artifacts, risk advisories, and other relevant data. This runs automatically for instant assessments and can be triggered manually at any time.Assessment Phases
Assessments move through a defined lifecycle. Understanding each phase helps you know what actions are available and what’s happening behind the scenes.Follow-Up Questionnaires
If controls remain unvalidated after initial review, VISO TRUST surfaces a follow-up questionnaire to request additional information from the vendor. You can configure this behavior in three ways:- Always ask before following up — review results and decide whether to follow up
- Conditional based on residual risk — automatically follow up if residual risk meets a threshold (e.g., Medium or above)
- Use assessment concierge service — VISO TRUST manages the follow-up on your behalf
The Vendor Experience
When you send a collection request, the vendor receives an email with a secure link and a one-time passcode. Through the collection portal, they can:- Review what’s being requested and access guidance on typical artifacts for each control
- Upload documents (SOC 2, ISO 27001, pen tests, DPAs, etc.)
- Answer questionnaires if requested
- Forward the request to the right internal contact if needed
- Certify and submit their response when complete
Collection Timelines and Reminders
The default collection window is 30 days. Reminders are sent automatically:- Business owners and subscribers: every 5 business days
- Vendor contacts: every 3 days, with a final notice 3 days before the deadline
Sub-Processor Collection
When the Privacy risk dimension is in scope, VISO TRUST prompts vendors to provide a list of their sub-processors — third parties that process personal data on your behalf. Sub-processors are displayed in the Risk Analysis tab and mapped in the relationship’s graph view for nth-party visibility.Reviewing and Acting on Results
When an assessment reaches Completed status, a Review risk action becomes available — indicating that findings are ready and your team needs to record a decision.Review Risk Actions
Once a remediation request is sent and the vendor responds, VISO TRUST automatically starts a new assessment update and returns the relationship to Review Risk for re-evaluation.
Assessment Completion
An assessment is marked Completed when:- All submitted artifacts and questionnaire responses have been analyzed
- Any follow-up questionnaire has been responded to, skipped, or determined unnecessary
- An assessment summary has been generated