Skip to main content
An attestation is a vendor’s formal declaration that certain security controls or compliance requirements are in place. Attestations differ from documentary artifacts — rather than providing an audit report or certification, the vendor asserts directly that a control exists or a standard is met.

Types of Attestations in VISO TRUST

Submission Certification

At the end of every vendor collection request, the vendor certifies that the information they submitted is accurate and complete before submitting. This certification is recorded and included in the assessment’s audit trail. It doesn’t affect the risk score directly, but it establishes a formal declaration of accuracy from the vendor.

Compliance Attestations

When a vendor publicly claims a compliance certification (e.g., displays a SOC 2, ISO 27001, or PCI DSS badge on their website or trust page) but hasn’t provided the full audit report, VISO TRUST records this as a compliance attestation — a lower-confidence signal that the vendor likely meets the relevant controls. Compliance attestations are treated differently from validated artifacts:
  • They generate partial credit toward control coverage
  • They carry lower assurance than a reviewed audit report
  • They remain visible in the Artifacts tab with their source marked as Publicly Collected
To upgrade from a compliance attestation to full credit, request the actual certification report through a collection request. Once the report is submitted and analyzed, it replaces the attestation with validated evidence.

Questionnaire Attestations

When vendors respond to questionnaires — either supplemental questionnaires sent during an assessment or follow-up questionnaires targeting control gaps — their written responses are a form of self-attestation. The vendor is asserting, in writing, that they have or don’t have specific controls in place. Questionnaire responses are stored as artifacts and carry Limited assurance — self-attested, not independently verified. Where possible, supplement questionnaire responses with documentary evidence to increase confidence.

Managing Attestations

All attestations are visible in the Artifacts tab of a relationship. You can filter by source to see what’s publicly collected vs. submitted by the vendor vs. uploaded by your team. Key actions:
  • Request the full document — for any publicly claimed certification, send a collection request to get the actual report
  • Review the audit trail — the Activity tab records when attestations were received and what decisions were made based on them
  • Override assurance — Org Admins can adjust how compliance certifications influence residual risk at the org level in Settings → Risk Model

Attestations and Residual Risk

The influence of attestations on residual risk depends on your organization’s configuration:
  • By default, publicly claimed compliance certifications reduce residual risk slightly — even without the full report
  • You can disable this so certifications only count when the actual document is submitted and analyzed
  • Questionnaire response attestations always contribute to control coverage, but at the Limited assurance level
See Your Risk Model for information on configuring how attestations influence scoring.

Requesting Specific Attestations

During a collection request, you can ask for specific attestations by selecting Request specific artifacts and choosing the relevant artifact types. For example, if you need a vendor to confirm their penetration testing cadence but they don’t have a formal report, you can request a written attestation of their testing schedule as part of the assessment scope. Vendors can respond with a document or a written statement — both are captured and analyzed by Artifact Intelligence.