> ## Documentation Index
> Fetch the complete documentation index at: https://docs.visotrust.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Questionnaires

> Build, configure, and send questionnaires in VISO TRUST to collect structured written responses from vendors as part of a security assessment.

**Questionnaires** let you collect structured written responses from vendors — asking specific questions about their security program, controls, or practices. Unlike artifact collection (which relies on documents), questionnaires put questions directly to the vendor and capture their answers as a response artifact.

Questionnaires are managed in **Settings → Questionnaires**. Creating and editing questionnaires requires Admin or Program Manager access.

## When to Use Questionnaires

Questionnaires are useful when:

* A vendor doesn't have formal audit reports and needs to self-attest to their security practices
* You want to ask specific questions not covered by standard artifact types
* Controls remain unvalidated after artifact review and you need targeted clarification
* Your compliance program requires vendors to answer specific questions in writing

## Creating a Questionnaire

<Steps>
  <Step title="Navigate to Settings → Questionnaires">
    Click **Add questionnaire** to create a new one.
  </Step>

  <Step title="Choose how to build it">
    * **Import** — use the provided CSV template to define questions in bulk
    * **Create** — build the questionnaire question by question in the interface
  </Step>

  <Step title="Name it">
    Use a descriptive name — this is visible to vendors when they receive an assessment request containing the questionnaire.
  </Step>

  <Step title="Configure the response method">
    Choose how responses will be collected:

    **Answer with AI** — Artifact Intelligence will attempt to answer the questions automatically using available documents and vendor artifacts. Faster, no vendor effort required. You can still follow up with the vendor if clarification is needed.

    **Require vendor response** — questions are sent directly to the vendor during interactive assessments. The vendor answers in writing through the collection portal.
  </Step>

  <Step title="Set the default scope (optional)">
    Toggle **Enable for every relationship** to apply the questionnaire to all vendor relationships by default. This default can be overridden at the relationship level.
  </Step>
</Steps>

## Managing Questionnaire Scope

### Organization Level

Questionnaires enabled at the org level apply to all new assessments by default. Go to **Settings → Questionnaires** to enable, disable, or edit questionnaires globally.

### Relationship Level

To include or exclude a questionnaire for a specific vendor:

1. Open the vendor relationship
2. Open the **Relationship configuration** dialog (gear icon) and go to **Context → Supplemental questionnaires**
3. Use the slide toggles to turn individual questionnaires on or off
4. Use **Restore organization defaults** to revert to org-level settings

Removing a questionnaire from a relationship excludes it from future assessments and hides responses in the Risk Analysis tab. Previously collected responses are retained.

## Questionnaire Results in Assessments

When a vendor responds to a questionnaire, the response is:

* Stored as a **Questionnaire artifact** in the Artifacts tab
* Displayed in the **Risk Analysis tab** as a new risk dimension alongside your existing control domains
* Analyzed by Artifact Intelligence to map answers to controls where applicable

Questionnaire responses carry **Limited assurance** — they're self-attested by the vendor. For high-risk controls, validate questionnaire responses against documentary evidence where possible.

## Follow-Up Questionnaires

**Follow-up questionnaires** are automatically generated when controls remain unvalidated after artifact review. They target the specific gaps identified in the assessment rather than being a general questionnaire.

You can configure follow-up behavior at three levels:

* **Always ask before following up** — VISO TRUST prompts you to review and decide whether to send a follow-up
* **Conditional based on residual risk** — automatically send a follow-up when residual risk is at or above a threshold (e.g., Medium)
* **Use assessment concierge service** — VISO TRUST manages the follow-up on your behalf

The follow-up response window is configurable (7, 14, 30, 60, or 90 days; 7 by default). VISO TRUST auditors validate the responses (when the AI Assessment + Auditor Review method is configured) and update the assessment findings.

See [Assessment Settings](/third-parties/advanced/assessment-settings) to configure follow-up defaults.

## One-Off Questionnaires

You can send a questionnaire as part of any individual collection request, even if it isn't configured as a default. When starting a collection request, select **Request manual response** and choose the questionnaire to include.

This lets you send targeted questionnaires to specific vendors without changing org or relationship defaults.
