QFX (Questionnaire, Framework, eXecution) has no hardcoded assumptions about what's being assessed. Vendors, employees, M&A targets, insurance applicants, supply chain partners — same engine, same scoring, same audit trail.
VendorOrg, InternalOrg, Individual Employee, InsuranceApplicant, MergerTarget, SupplyChainPartner, SubContractor, PublicSectorBody, plus tenant-defined CustomEntityType.
Conditional branching, auto-scoring, finding generation, task assignment — all configurable per rule with full audit trail.
Respondent provides a legally significant attestation at submission. Signed responses are immutable evidence.
SIG Lite/Core/Full, CAIQ, NIST CSF, ISO 27001, HITRUST, plus custom framework support.
QFX is a configurable, rules-driven assessment engine with a subject-type layer — a vendor, a merger target, an employee, an internal system are all first-class subjects with their own branding, scoring and audit trail.
Import SIG Lite/Core/Full, CAIQ, HITRUST and more as starting libraries, or author from a one-line description — the engine renders, scores and maps to frameworks regardless of source.
Responses are scored by a rule engine, not read by hand — consistent, explainable, and mapped to the control framework behind the question.
Questions branch on prior answers, so respondents only see what applies — designed to be completed, not abandoned.
Replace paper underwriting questionnaires with a scored, conditional digital workflow whose risk weights map directly to underwriting decisions.
A structured, signed, timestamped diligence workflow with maturity-graded scoring — defensible where email-and-spreadsheet diligence is not.
HITRUST, ISO or NIST self-assessments run on the same engine, auto-scored and mapped, with evidence reusable across frameworks.
BIRAs, DPIA surveys and policy attestations delivered to employees through an SSO-authenticated portal, scored the same way.
Verisq's QFX Assessment Engine is part of the Trust Operations Platform — one data model, one audit trail, one auditor seat.