Skip to main content
An assessment is how VISO TRUST evaluates a vendor’s security posture and produces a risk score. Assessments can run automatically, be initiated by you, or involve the vendor directly — depending on how much depth you need.

Assessment Types

Starting an Assessment

From any relationship, select Start assessment (or Update assessment if one already exists) to begin. To add documents without starting a new collection, use Add information.

Request Artifacts from the Vendor

Send a collection request to the vendor’s contact:
  • Ask for everything — VISO TRUST requests all artifacts and questionnaire responses needed to satisfy in-scope controls
  • Request specific artifacts — specify which document types you need (e.g., SOC 2, ISO 27001, pen test)
  • Request manual response — send a questionnaire for the vendor to answer in writing
You can mix and match these options in a single collection request.
Use Advanced Settings when sending a collection request to configure follow-up timelines, response deadlines, and what happens if the vendor doesn’t respond. These can also be set as defaults at the relationship or organization level.

Upload Artifacts Directly

If you already have documentation, upload it directly without involving the vendor. VISO TRUST will classify the artifact type and begin analysis immediately. You can upload artifacts at any time, even alongside an active collection request.

Conduct Research

VISO TRUST can automatically search public sources for the vendor — finding compliance attestations, publicly available artifacts, risk advisories, and other relevant data. This runs automatically for instant assessments and can be triggered manually at any time.

Assessment Phases

Assessments move through a defined lifecycle. Understanding each phase helps you know what actions are available and what’s happening behind the scenes.

Follow-Up Questionnaires

If controls remain unvalidated after initial review, VISO TRUST surfaces a follow-up questionnaire to request additional information from the vendor. You can configure this behavior in three ways:
  • Always ask before following up — review results and decide whether to follow up
  • Conditional based on residual risk — automatically follow up if residual risk meets a threshold (e.g., Medium or above)
  • Use assessment concierge service — VISO TRUST manages the follow-up on your behalf
This setting can be configured at the assessment, relationship, or organization level.

The Vendor Experience

When you send a collection request, the vendor receives an email with a secure link and a one-time passcode. Through the collection portal, they can:
  1. Review what’s being requested and access guidance on typical artifacts for each control
  2. Upload documents (SOC 2, ISO 27001, pen tests, DPAs, etc.)
  3. Answer questionnaires if requested
  4. Forward the request to the right internal contact if needed
  5. Certify and submit their response when complete
After submission, VISO TRUST processes the artifacts using AI to classify, analyze, and map findings to your control framework. For a step-by-step walkthrough of the collection portal, including forwarding the request, requesting more time, and opting out, see The Vendor Experience. To share with a vendor, point them at Responding to a VISO TRUST Request: Vendor’s Guide — the same process written for their side.

Collection Timelines and Reminders

The default collection window is 30 days. VISO TRUST sends reminders automatically:
  • Internal recipients (the Business Owner, Assessment Lead, Subscribers, and the assessment creator): every 5 business days
  • Vendor contacts: every 3 days, with a final notice 3 days before the deadline
You can toggle each internal recipient on or off for the Assessment reminder notification in the settings matrix under Settings → Org Profile → Notifications. See Notifications & Alerts. You can extend the collection timeline at any time while an assessment is in the Collecting Information phase. There’s no limit on extensions. If the vendor doesn’t respond by the deadline, the assessment moves to the Expired phase. What happens next depends on the No-vendor-response setting configured under Assessment Settings:
  • Notify me — the assessment stays in the Expired phase and shows an Assessment expired banner on the timeline. From the Take action menu, select:
    • Extend timeline — return the assessment to Collecting Information with a new deadline, giving the vendor more time to submit
    • Complete assessment — close the collection request and move the assessment to Completed using whatever evidence has been gathered so far
  • Close collection request — VISO TRUST automatically completes the assessment. The timeline records an Expired node before Completed so you can see why the collection ended.
On the Relationships list, expired assessments show an Expired phase chip, and you can filter the list by that phase. Expired assessment events also appear in the relationship’s audit log and activity feed.

Sub-Processor Collection

When the Privacy risk dimension is in scope, VISO TRUST prompts vendors to provide a list of their sub-processors — third parties that process personal data on your behalf. Sub-processors are displayed in the risk analysis on the relationship’s Assessments tab and mapped in the relationship’s graph view for nth-party visibility. In the risk analysis, the collected list appears as a table under the Sub-Processor List control, showing each company, its purpose, and its location of processing. A collected list counts as full-assurance evidence, so VISO TRUST treats the Sub-Processor List control as fully mitigated once the vendor provides it.

Reviewing and Acting on Results

When an assessment reaches Completed status, a Review risk action becomes available — indicating that findings are ready and your team needs to record a decision.

Review Risk Actions

Once a remediation request is sent and the vendor responds, VISO TRUST automatically starts a new assessment update and returns the relationship to Review Risk for re-evaluation.

Viewing Past Assessments

The Assessments tab holds the relationship’s assessment history — every assessment except cancelled ones. Use the selector at the top of the tab to switch between them; the risk analysis, control evidence, and summary below it all update to the assessment you pick. Each assessment is a snapshot. Selecting an older one shows the evidence and scores as they stood when it completed, not today’s picture, so you can see exactly what a past decision was based on. See Risk Analysis for how to read it.

Assessment Completion

An assessment is marked Completed when:
  • All submitted artifacts and questionnaire responses have been analyzed
  • Any follow-up questionnaire has been responded to, skipped, or determined unnecessary
  • An assessment summary has been generated
Completion does not mean no action is required — you still need to review risk and record a decision.

If Summary Generation Fails

If the assessment summary fails to generate, the latest assessment shows a “We couldn’t generate this summary” alert. When a previous summary exists it remains visible below the alert until a new one is generated. Select Try again to regenerate the summary from the current assessment data — the action is available to the relationship’s business owner, the assessment lead, and admins. If generation keeps failing, contact support@visotrust.com.

Lifecycle Management

For onboarded relationships, VISO TRUST can automate ongoing vendor management: Artifact Validity — VISO TRUST tracks when artifacts expire and alerts you (or automatically contacts the vendor) 30 days before expiration to request updated documentation. VISO TRUST sends one automatic update request per expiration window. If you cancel that assessment, VISO TRUST does not create another automatic request for the same expiring artifacts. You can start an assessment manually at any time. Relationship Recertification — schedule recurring reassessments on a cadence you define (e.g., annually). VISO TRUST sends reminders when it’s time to recertify and can initiate the collection process automatically. VISO TRUST starts one automatic assessment per recertification cycle. If you cancel a recertification assessment, including one you started manually within 30 days of the recertification date, VISO TRUST does not start another automatic assessment for that cycle. The relationship stays overdue until you start an assessment manually or advance its recertification date, which begins a new cycle. Lifecycle management settings are in the relationship’s Relationship configuration dialog (gear icon) under Onboarding and lifecycle management.