Types of Attestations in VISO TRUST
Submission Certification
At the end of every vendor collection request, the vendor certifies that the information they submitted is accurate and complete before submitting. This certification is recorded and included in the assessment’s audit trail. It doesn’t affect the risk score directly, but it establishes a formal declaration of accuracy from the vendor.Compliance Attestations
When a vendor publicly claims a compliance certification (e.g., displays a SOC 2, ISO 27001, or PCI DSS badge on their website or trust page) but hasn’t provided the full audit report, VISO TRUST records this as a compliance attestation — a lower-confidence signal that the vendor likely meets the relevant controls. Compliance attestations are treated differently from validated artifacts:- They generate partial credit toward control coverage
- They carry lower assurance than a reviewed audit report
- They remain visible in the Artifacts tab with their source marked as Publicly Collected
Questionnaire Attestations
When vendors respond to questionnaires — either supplemental questionnaires sent during an assessment or follow-up questionnaires targeting control gaps — their written responses are a form of self-attestation. The vendor is asserting, in writing, that they have or don’t have specific controls in place. Questionnaire responses are stored as artifacts and carry Limited assurance — self-attested, not independently verified. Where possible, supplement questionnaire responses with documentary evidence to increase confidence.Managing Attestations
All attestations are visible in the Artifacts tab of a relationship. You can filter by source to see what’s publicly collected vs. submitted by the vendor vs. uploaded by your team. Key actions:- Request the full document — for any publicly claimed certification, send a collection request to get the actual report
- Review the audit trail — the Activity tab records when attestations were received and what decisions were made based on them
- Override assurance — Org Admins can adjust how compliance certifications influence residual risk at the org level in Settings → Risk Model
Attestations and Residual Risk
The influence of attestations on residual risk depends on your organization’s configuration:- By default, publicly claimed compliance certifications reduce residual risk slightly — even without the full report
- You can disable this so certifications only count when the actual document is submitted and analyzed
- Questionnaire response attestations always contribute to control coverage, but at the Limited assurance level