Define the organization and the purpose first
A first assessment is most useful when everyone understands what it covers. Decide which organization you are answering for, which business activity matters and who can confirm the answers. If you support several companies, do not combine their practices into a single optimistic response. An access process used by one organization may not exist at another.
RiskSensai’s Digital Trust Assessment is an informational, self-reported readiness workflow. It helps surface questions across security governance, access and identity, infrastructure and data, privacy, AI governance, vendor risk and incident readiness. It does not independently inspect your environment or turn an answer into proof of a working control.1
Before opening the form, write a one-sentence purpose: “We want to identify the most important questions before our next customer security discussion.” That purpose helps you interpret the result without assuming the exercise produces formal assurance.
Enter through the real assessment route
Open the assessment entry page and read its scope. Follow the existing sign-in requirements, then use the organization selection step. Continue only after the selected organization is the one you intend to assess. Access to another organization does not authorize combining its information with this assessment.
The current organization assessment interface offers two modes:
| Mode | Current questionnaire size | Practical use |
|---|---|---|
| Quick check | 21 core questions, approximately seven minutes | An initial discussion and a short list of follow-up questions |
| Full assessment | 97 questions, approximately 30–40 minutes | A broader self-reported picture when you have time and appropriate input |
These are interface estimates, not a promise that a business can verify its practices in seven minutes. If you need to ask a system owner for an answer, take that time. Speed is less valuable than identifying uncertainty correctly.
Answer what exists today
Read each question and its available answers carefully. Select the answer that best matches current practice, not a policy that is being drafted or a process that one team hopes to introduce. Where a question is unclear, note what information would resolve it rather than silently interpreting it in the most favorable way.
Suppose you know that employees use multi-factor authentication for one application, but you do not know whether privileged administrator access follows the same rule. A broad assertion that “all access is protected” would exceed what you know. Keep the uncertainty explicit and ask the appropriate owner to confirm scope.
For questions about repeatable practices, distinguish three things: a written intention, a configured setting and a record that the practice operated. The questionnaire may ask about one of these. Do not use the existence of another as an automatic substitute.
Work through one domain at a time
Use the assessment’s existing navigation and review the saved state presented by the interface. The organization workflow preserves access requirements: a read-only reviewer does not gain assessment-writing permission simply by opening the route. If an action is unavailable, resolve your role with the organization owner rather than using another person’s account.
Keep supporting notes outside the answers if the questionnaire does not offer a relevant field. A short working list can contain the question, the selected response, the person who can confirm it and the record you expect to find. Do not paste passwords, confidential customer data or unrelated exports into a readiness answer.
If a save reports an error or leaves you uncertain whether it completed, inspect the current saved state before trying again. Do not assume a missing success message means that nothing was written. Honest uncertainty is preferable to creating competing versions of the same assessment.
Interpret the result as a set of hypotheses
The result is derived from the answers. A strong score can reflect strong self-reported practices; it cannot establish that those practices have been independently examined. A lower result can help identify where questions or improvements deserve attention. Neither should be used as a certification label.12
NIST’s small-business CSF guidance provides context for prioritizing cybersecurity work around organizational needs.3 Apply that principle when choosing follow-ups: which unanswered question affects an important system, decision or obligation? A visually prominent gap is not automatically the most consequential gap for your business.
Worked example: access-review ownership
Imagine that your responses indicate an inconsistent access-review process. Turn that into a small investigation:
| Follow-up question | Useful evidence | Decision it supports |
|---|---|---|
| Who owns the review? | Named responsibility and approval record | Whether someone can be accountable for the next review |
| Which systems were included? | System list and review period | Whether the scope covers the systems that matter |
| Were exceptions resolved? | Dated exception notes and follow-up records | Whether remediation still needs ownership |
This is an illustrative investigation, not an assertion that RiskSensai automatically collected those records or created findings. Gathering evidence and creating remediation work remain separate actions with their own boundaries.
Save a follow-up plan that someone can use
Choose a manageable number of priorities. For each, name the question to resolve, the responsible person, the relevant record and a sensible review date. Avoid assigning a deadline until the person understands the work. The first useful improvement may be clarifying ownership rather than introducing a new tool.
Keep the distinction between assessment mode and scope. A framework or industry guide can supply context, but it does not change the questionnaire bank into a separate certification audit. Do not present a general self-assessment result as confirmation that every requirement of a selected framework was satisfied.
Reopen before comparing
After saving, use the assessment’s run history to reopen the result. Check the organization, mode and date before discussing it with colleagues. If you later run another assessment, comparison depends on compatible mode and question-bank information. An absent comparison does not mean zero change; it can mean that the records are not comparable.
Your first assessment is complete when the saved result accurately represents the answers you intended to give and you understand its limits. The next useful step is a focused investigation of those answers—not a claim that the organization has passed an independent audit.
Sources and references
-
RiskSensai. Free Digital Trust Assessment. Explains self-reported scope and authenticated assessment entry. ↩ ↩2
-
RiskSensai. RiskSensai Security. Describes current evidence and access-control limits. ↩
-
NIST. Cybersecurity Framework 2.0: Small Business Quick-Start Guide (2024-02). Supports practical risk-prioritization context. ↩

