What Artifact Intelligence Does
When an artifact is submitted, Artifact Intelligence:- Classifies the document — identifies the artifact type (SOC 2 Type II, ISO 27001, penetration test, DPA, etc.)
- Extracts evidence — reads the document and identifies language that describes security controls and practices
- Maps to controls — matches extracted evidence to the relevant controls in your risk framework
- Assigns assurance — rates the confidence level of each detection based on the artifact type and evidence quality
- Identifies gaps — flags in-scope controls that aren’t addressed by the submitted evidence
Assurance Levels
Not all documents carry equal weight. Artifact Intelligence assigns an assurance level to each artifact based on how rigorous and trustworthy the evidence is.
Assurance is also refined at the individual control level — a high-assurance artifact that only partially addresses a control will have a lower per-control assurance than one that addresses it comprehensively.
AI Assessment + Auditor Review
For assessments using the AI Assessment + Auditor Review method, Artifact Intelligence is supplemented by a VISO TRUST analyst who performs a focused review of high-assurance artifacts. Auditors look for things that require human judgment:- Qualified opinions or exceptions in SOC 2 reports
- Open critical or high findings in penetration test reports
- HITRUST validity dates and certification scope
- Subservice organizations and CUECs (complementary user entity controls) in SOC 2 reports
- Password-protected or confidential artifacts that require manual handling
AI analysis alone does not guarantee detection of every control in every artifact. For critical vendors or high-risk relationships, the AI Assessment + Auditor Review method provides the highest confidence in results.
What Happens After Analysis
Once analysis is complete:- Credited controls appear as Present in the Risk Analysis tab with the artifact as supporting evidence
- Control gaps appear as No Info or Unvalidated — primary candidates for follow-up questionnaires or additional document requests
- The residual risk score updates to reflect the new evidence
- The artifact appears in the Artifacts tab with its classification, assurance level, and validity period
Artifact Validity
Every artifact has a validity period reflecting how long the document is considered current. SOC 2 reports typically cover a 12-month audit period; ISO 27001 certificates are valid for 3 years. Artifact Intelligence identifies the validity window during analysis and tracks expiration. When an artifact approaches expiration:- Its assurance level is progressively reduced
- Pending Changes are surfaced on the relationship
- If lifecycle management is enabled, VISO TRUST can automatically request a renewal from the vendor
Managing Artifacts
All artifacts for a relationship are visible in the Artifacts tab of the relationship detail page. From here you can:- View artifact classification, source, assurance level, and validity period
- Correct a misclassification (available to users assigned to the relationship and Org Admins)
- Download artifacts
- Delete artifacts (subject to your role’s permissions)
- Add new artifacts at any time — even on an active or completed assessment
- Collected from the client — uploaded by your team
- Collected from the third party — submitted by the vendor through the collection portal
- Publicly collected — discovered by VISO TRUST through public research
- Collected from VISO TRUST — sourced from VISO TRUST’s own evidence