Skip to main content
A relationship is your record of a business connection with a third-party vendor. Every assessment, risk score, advisory, artifact, and audit trail in VISO TRUST lives under a relationship. Managing your relationships well is the foundation of your TPRM program.

Adding a Relationship

Go to Third Parties → Relationships in the left sidebar and select Add relationship.
1

Search for your vendor

Type the vendor’s name in the search field. VISO TRUST searches its directory of thousands of known organizations.If the vendor isn’t in the directory, select Create new third-party organization at the bottom of the results and enter the vendor’s name and website URL.
Risk analysis is significantly more accurate when a vendor website is provided. Always include the URL if you have it.
2

Assign a Business Owner

Select the internal team member who will own this relationship. The Business Owner manages assessments, responds to advisories, and receives notifications for this vendor. You can assign an existing user or invite a new one.
3

Define a business purpose

Write 1–3 sentences describing how your organization uses this vendor — what they provide, how your team engages with them, and what systems or data may be involved. This helps VISO TRUST predict the right risk context and is visible only to internal users, not the vendor.
4

Add details

  • Relationship name — customize to differentiate this relationship from others with the same vendor
  • Tags — add labels to organize and filter the relationship (see Tags)
  • Tier (optional) — assign the vendor to a priority tier
5

Enable instant assessment

Leave Predict relationship context and instantly assess checked to have VISO TRUST immediately analyze the vendor using publicly available data. This gives you a risk score within seconds of creating the relationship, with no vendor involvement required.To disable instant assessment by default for all new relationships, go to Settings → Assessments.

Configuring Relationship Context

Context defines the threat surface and controls in scope for a relationship. It’s made up of two components: Business Cases — how your organization engages with the vendor. Examples: SaaS provider, payment processor, IT support. Each selected business case brings relevant security controls into scope for the assessment. Data Types — what information is shared with the vendor. Examples: Customer PII, financial data, internal business data. Data types determine data sensitivity and drive impact scoring. Together, these two inputs define the relationship’s inherent risk and the controls that need to be assessed. To configure context:
  1. Open the relationship and select the gear icon in the relationship header
  2. Navigate to Context
  3. Select the relevant business cases and data types
Use the Predict context button to have VISO TRUST suggest business cases and data types based on the vendor’s profile and the business purpose you entered. You can accept, adjust, or override the suggestion.
Context can be updated at any time. VISO TRUST will flag when context may need attention as a relationship evolves.

Products & Services Scoping

When a vendor offers multiple distinct products or services, you can create a separate relationship for each one. Each relationship has its own assessment context — so artifacts and risk findings are scoped to the specific product being assessed rather than the vendor as a whole. This is especially useful for large platforms (cloud providers, productivity suites, AI tools) where different products carry meaningfully different risks. Vendor-level metadata (company details, profile information) is shared across all relationships with the same organization, so you don’t need to duplicate it.

Tags

Tags are labels you apply to relationships for filtering and organization. Use them to group vendors by category, program phase, team ownership, or any other dimension that fits your workflow. Tags are available as filters on the Relationships list page and on individual relationship detail pages. To manage your organization’s tag library, go to Settings → Tags.

Vendor Tiers

Vendor Tiers let you group relationships into up to five priority tiers for portfolio-level oversight. Tiers are useful for defining treatment standards, reporting segmentation, and prioritization criteria. To set up tiers:
  1. Go to the Relationships list page and select Manage Tiers
  2. Choose how many tiers to create (up to 5)
  3. Add a description to each tier to clarify criteria for your team
To assign relationships to a tier, select them on the Relationships list page and use the Move tier action.

Bulk Actions on Relationships

Select multiple relationships on the Relationships list page to apply changes across them at once. The toolbar exposes four bulk actions:
  • Move tier — assign the selected relationships to a Vendor Tier (Admin only).
  • Assign assessment lead — set the Assessment Lead on the selected relationships.
  • Assign business owner — set the Business Owner on the selected relationships. Only existing users can be selected in bulk; use the individual relationship dialog if you need to invite a new user.
  • Manage subscribers — add or remove Subscribers across the selected relationships in one operation.
Assessment lead, business owner, and subscriber bulk actions are available to Admins and to any Contributor who is already the Business Owner or Assessment Lead on every selected relationship. Move tier remains Admin-only. Large selections are processed in the background. The first batch applies immediately; the remainder continues asynchronously, and you’ll receive an in-app notification when the job completes. Assigning a new Business Owner also cascades the owner’s business unit and recomputes risk on each affected relationship.

Pending Changes

Pending Changes appear on a relationship when new information exists that isn’t yet reflected in the current assessment summary. Common causes include:
  • Controls were added to or removed from scope due to a context update
  • New artifacts were discovered via public search
  • Existing artifacts expired
  • New risk advisories were detected
Pending changes don’t require immediate action — they’ll be incorporated the next time an assessment update runs. To resolve them immediately, initiate a public search from the relationship.

Relationship Lifecycle

Relationships can be onboarded to include the vendor in Risk Insights dashboards and enable lifecycle management features like recertification scheduling and automatic artifact renewal. To onboard a relationship, open its Relationship configuration dialog (gear icon), go to Onboarding and lifecycle management, and set the status to Onboarded. See Assessments for details on lifecycle management, recertification, and archive behavior.