Skip to main content
Questionnaires in VISO TRUST can be answered in two ways: automatically by Artifact Intelligence using existing documentation, or directly by the vendor through the collection portal. This page covers both paths — including the full vendor experience from receiving a request to submitting a response.

AI-Answered Questionnaires

When a questionnaire is configured with Answer with AI, VISO AI answers each question automatically by reading the full text of the artifacts on the vendor relationship. Artifacts you’ve excluded from the relationship are not used. Each answer comes back with source citations — the specific passages and artifacts it relied on — and a confidence score. This approach:
  • Requires no effort from the vendor
  • Works best when the vendor has submitted high-quality documentation that addresses the questions
Answering starts automatically once the assessment completes and every artifact on the relationship has finished processing. Questionnaires added to the relationship after the assessment completed are not answered automatically. Those show a Pending change prompt in the questionnaire’s section of the risk analysis asking you to run Update assessment, which answers them as part of the update. An update also re-answers completed questionnaires from the vendor’s latest artifacts. A question counts as answered only when the AI backs its answer with cited evidence. If the AI can’t confidently answer a question from available evidence, the question is marked unable to answer, its control domain remains unvalidated, and it may trigger a follow-up to the vendor. If the AI drafts an answer without citing any supporting passage, the question also remains unanswered. Unanswered questions show no answer text in the risk analysis, even when a draft exists. Answers, their citations, and the reasoning behind each one appear in the questionnaire’s section of the risk analysis. See Questionnaires in risk analysis.

Vendor-Answered Questionnaires

When a questionnaire requires direct vendor response, it is included in the collection request sent to the vendor. The vendor completes it through the collection portal — a secure, guided interface they access via email.

The Vendor Experience

1

Receiving the request

The vendor receives an email with a link to the collection portal and a one-time passcode. The email may also include a personal message from your team.
2

Accessing the portal

The vendor enters their passcode and arrives at the portal landing page, which shows:
  • Your organization’s name (and branding, if configured)
  • A summary of what’s being requested
  • Options to get started, request more time, forward the request, or opt out
3

Reviewing the request

The portal clearly distinguishes between:
  • Scope-based requests — standard document types determined by the assessment framework (SOC 2 reports, security policies, etc.)
  • Specific artifact requests — named documents or additional materials your team requested for this relationship
  • Questionnaire questions — written questions requiring direct responses
4

Answering questions

All questionnaires in the request appear on a single page, organized into sections — the standard VISO TRUST questionnaire followed by any supplemental questionnaires. A navigation panel beside the questions lists each section with its answered count and progress, and highlights the section currently in view. Selecting a section jumps directly to it.For each question, the vendor:
  • Selects a response from the available options
  • Adds a description to provide context or clarification
Selecting Continue checks every section for completeness. If any responses are missing, the portal jumps to the first unanswered question so the vendor can fill in the gaps.
5

Submitting

When complete, the vendor reviews and certifies that their responses are accurate, then submits. VISO TRUST immediately begins processing the response.

Forwarding the Request

The vendor contact who received the request may not be the right person to answer, which is common when requests go to a sales contact instead of a security team. In that case, the vendor can forward the request to a colleague directly from the portal. Changing the contact while the request is active sends a new email to the updated recipient.

Opting Out

Vendors can opt out of a collection request from the portal — intended for when they’re no longer doing business with your organization. Opting out ends the assessment and cannot be undone; if it was a mistake, you’ll need to start a new assessment.
This section describes the portal from your side. To send a vendor instructions for their side, share Responding to a VISO TRUST Request: Vendor’s Guide.

Follow-Up Questionnaires

After the initial assessment review, if controls remain unvalidated, VISO TRUST may send a follow-up questionnaire targeted at the specific gaps. This is a shorter, more focused questionnaire than the initial one. Vendors have a configurable window (7 days by default) to respond to a follow-up. The portal experience is the same as the initial collection request.

Answering as a Trust Profile

If your organization has a Trust Profile, Artifact Intelligence can use documents uploaded there to automatically answer questionnaires sent to your organization by VISO TRUST customers — without any manual effort. This is the primary benefit of maintaining a complete Trust Profile: when customers assess you, the AI answers their questionnaires using your pre-uploaded documentation rather than requiring your security team to respond manually to each request.

Tracking Responses

For questionnaires sent to vendors, track response status in the relationship’s Artifacts tab. The questionnaire response appears as a Questionnaire artifact with its analysis status. Once processed, responses are reflected in the risk analysis on the Assessments tab. For follow-up questionnaires, the assessment status changes to Collecting Information while the vendor responds, and returns to Review Started once the response is submitted and processing begins.