> ## Documentation Index
> Fetch the complete documentation index at: https://docs.visotrust.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Assessments

> Create, track, and review vendor risk assessments in VISO TRUST — from instant assessments to artifact uploads and vendor collection requests.

An **assessment** is how VISO TRUST evaluates a vendor's security posture and produces a risk score. Assessments can run automatically, be initiated by you, or involve the vendor directly — depending on how much depth you need.

## Assessment Types

| Type                   | How it works                                                                                                                                                                       | Vendor involved? |
| ---------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------- |
| **Instant Assessment** | Runs automatically when a relationship is created. VISO TRUST searches public sources for certifications, security pages, and audit reports.                                       | No               |
| **Artifact Upload**    | You upload security documents directly (SOC 2, ISO 27001, pen test reports, etc.). VISO TRUST analyzes them immediately.                                                           | No               |
| **Vendor Collection**  | You send the vendor a collection request. They submit documentation through a secure portal. VISO TRUST analyzes submissions and optionally routes them through an auditor review. | Yes              |

## Starting an Assessment

From any relationship, select **Start assessment** (or **Update assessment** if one already exists) to begin. To add documents without starting a new collection, use **Add information**.

### Request Artifacts from the Vendor

Send a collection request to the vendor's contact:

* **Ask for everything** — VISO TRUST requests all artifacts and questionnaire responses needed to satisfy in-scope controls
* **Request specific artifacts** — specify which document types you need (e.g., SOC 2, ISO 27001, pen test)
* **Request manual response** — send a questionnaire for the vendor to answer in writing

You can mix and match these options in a single collection request.

<Tip>
  Use **Advanced Settings** when sending a collection request to configure follow-up timelines, response deadlines, and what happens if the vendor doesn't respond. These can also be set as defaults at the relationship or organization level.
</Tip>

### Upload Artifacts Directly

If you already have documentation, upload it directly without involving the vendor. VISO TRUST will classify the artifact type and begin analysis immediately. You can upload artifacts at any time, even alongside an active collection request.

### Conduct Research

VISO TRUST can automatically search public sources for the vendor — finding compliance attestations, publicly available artifacts, risk advisories, and other relevant data. This runs automatically for instant assessments and can be triggered manually at any time.

## Assessment Phases

Assessments move through a defined lifecycle. Understanding each phase helps you know what actions are available and what's happening behind the scenes.

| Phase                      | Description                                                                      | Available actions                               |
| -------------------------- | -------------------------------------------------------------------------------- | ----------------------------------------------- |
| **Not Assessed**           | No active assessment, and the vendor has no prior assessment                     | Start a new assessment                          |
| **Started**                | A collection request has been sent; the vendor hasn't opened it yet              | Close request, upload artifacts                 |
| **Collecting Information** | The vendor has opened the portal and started submitting                          | Close request                                   |
| **Review Started**         | VISO TRUST is reviewing submitted materials using AI (and auditor if configured) | Skip auditor review, close request              |
| **Follow-Up Recommended**  | Review is complete but additional information is needed                          | Send follow-up questionnaire, skip and complete |
| **Completed**              | All submitted information has been reviewed; findings are ready                  | Review risk, accept risk, request remediation   |

### Follow-Up Questionnaires

If controls remain unvalidated after initial review, VISO TRUST surfaces a follow-up questionnaire to request additional information from the vendor. You can configure this behavior in three ways:

* **Always ask before following up** — review results and decide whether to follow up
* **Conditional based on residual risk** — automatically follow up if residual risk meets a threshold (e.g., Medium or above)
* **Use assessment concierge service** — VISO TRUST manages the follow-up on your behalf

This setting can be configured at the assessment, relationship, or organization level.

## The Vendor Experience

When you send a collection request, the vendor receives an email with a secure link and a one-time passcode. Through the collection portal, they can:

1. Review what's being requested and access guidance on typical artifacts for each control
2. Upload documents (SOC 2, ISO 27001, pen tests, DPAs, etc.)
3. Answer questionnaires if requested
4. Forward the request to the right internal contact if needed
5. Certify and submit their response when complete

After submission, VISO TRUST processes the artifacts using AI to classify, analyze, and map findings to your control framework.

### Collection Timelines and Reminders

The default collection window is **30 days**. Reminders are sent automatically:

* Business owners and subscribers: every 5 business days
* Vendor contacts: every 3 days, with a final notice 3 days before the deadline

You can extend the collection timeline at any time while an assessment is in the **Collecting Information** phase. There's no limit on extensions.

If the vendor doesn't respond by the deadline, VISO TRUST either notifies you or closes the collection request, depending on your configuration.

## Sub-Processor Collection

When the Privacy risk dimension is in scope, VISO TRUST prompts vendors to provide a list of their sub-processors — third parties that process personal data on your behalf. Sub-processors are displayed in the Risk Analysis tab and mapped in the relationship's graph view for nth-party visibility.

## Reviewing and Acting on Results

When an assessment reaches **Completed** status, a **Review risk** action becomes available — indicating that findings are ready and your team needs to record a decision.

### Review Risk Actions

| Action                  | What it does                                                                                                                                                                              |
| ----------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Accept Risk**         | Records that your organization accepts the residual risk based on current findings. Closes the review.                                                                                    |
| **Override Risk**       | Manually sets a different inherent or residual risk value — used when compensating controls exist that aren't fully reflected in the model, or when context isn't appropriately captured. |
| **Request Remediation** | Sends a remediation request to the vendor identifying specific control gaps. You set a target date for resolution.                                                                        |
| **Add review note**     | Records an optional note with your decision on the relationship history — useful for executive approvals or audit trail context.                                                          |

Once a remediation request is sent and the vendor responds, VISO TRUST automatically starts a new assessment update and returns the relationship to **Review Risk** for re-evaluation.

## Assessment Completion

An assessment is marked **Completed** when:

* All submitted artifacts and questionnaire responses have been analyzed
* Any follow-up questionnaire has been responded to, skipped, or determined unnecessary
* An assessment summary has been generated

Completion does not mean no action is required — you still need to review risk and record a decision.

## Lifecycle Management

For onboarded relationships, VISO TRUST can automate ongoing vendor management:

**Artifact Validity** — VISO TRUST tracks when artifacts expire and alerts you (or automatically contacts the vendor) 30 days before expiration to request updated documentation.

**Relationship Recertification** — schedule recurring reassessments on a cadence you define (e.g., annually). VISO TRUST sends reminders when it's time to recertify and can initiate the collection process automatically.

Lifecycle management settings are in the relationship's **Relationship configuration** dialog (gear icon) under **Onboarding and lifecycle management**.
