Third-Party and Vendor Risk Agent

The Third-Party and Vendor Risk Agent analyses SOC 2 and ISO 27001 reports, security questionnaires, POPIA operator agreements and compliance documents. It flags control gaps, reviews data residency and compares responses with your standards and the FSCA and PA Joint Standards, so your risk team can focus on decisions.

Ideal forRisk teams

The difference

From 3-5 days per vendor to 30-45 minutes

Your risk team clears vendor backlogs, keeps assessments current and spends its expertise on the vendors that matter most.

Done by hand

3-5 days per vendor

With the Vanine agent

30-45 minutes

Time returned to your team

90%

Indicative figures. We measure your own baseline in the first fortnight so the numbers you see are yours.

Joint Standard requirements met

Joint Standard 2 of 2024 and the direction set by Joint Communication 2 of 2025 on cloud and data offshoring require documented third-party assessments. The agent produces them consistently for every vendor.

POPIA and offshoring clarity

The agent checks operator agreements for security safeguards and breach notification and flags where personal information leaves South Africa, so you can assess section 72 obligations early.

Days of work reduced to minutes

Reading assurance reports and questionnaires by hand takes days per vendor. The agent completes the analysis quickly and uniformly, so onboarding is not held up.

Capabilities

Consistent, evidence-backed vendor assessments in under an hour.

Built for risk, IT security and procurement teams at SA banks, insurers, asset managers and large corporates.

Automated control gap detection

Analyses assurance reports and questionnaires to find missing or weak controls, comparing responses with your security baseline and Joint Standard 2 of 2024 on cybersecurity and cyber resilience.

Compliance mapping and verification

Maps certifications such as ISO 27001 and SOC 2 Type II to your framework, and checks that POPIA operator agreements cover security safeguards and breach notification.

Data residency and cloud review

Flags where personal information is processed or stored outside South Africa, so you can assess section 72 of POPIA and your cloud and data offshoring obligations.

Risk scoring and prioritisation

Scores vendors on control gaps, severity and business impact, and can include commercial checks such as B-BBEE status and Tax Compliance Status in your onboarding criteria.

Bulk and consistent assessment

Processes many vendor assessments at once using uniform criteria, so results are consistent regardless of who reviews them.

Auditable assessment records

Links every finding to the exact section of the vendor's documentation, giving defensible evidence for the board, regulators and internal audit.

How it works

From your systems to a result you sign off

Vendor approval and risk acceptance remain with your risk and procurement owners. Assessments land ready for their review and sign-off.

SAPSharePointOutlookTeamsExcel
Any system you use
Connects

Connect the places your vendor assessments already live.

Assurance reports, questionnaires and operator agreements from your procurement system (SAP Ariba or Coupa), questionnaire portals, SharePoint and your GRC platform. Already use something else? We connect that too.

  • OpenAI Frontier
  • Microsoft 365 (SharePoint, Teams, Outlook)
  • Copilot Studio
  • SAP Ariba, Coupa
  • GRC platforms and ServiceNow
  • Vendor questionnaire portals
  • Central Supplier Database (CSD) reports
  • Your own AI platform or models
Works in

Triggers when a vendor enters onboarding or is due for review, or on request in Teams or OpenAI Frontier.

Automated control gap detection
Compliance mapping and verification
Data residency and cloud review
Risk scoring and prioritisation
Bulk and consistent assessment
Auditable assessment records
Delivers to

A scored assessment with cited findings and remediation points, written back to your GRC platform or ServiceNow and filed in SharePoint.

Step by step

  1. 01

    A vendor enters onboarding or reaches its periodic review date.

  2. 02

    The agent gathers assurance reports, questionnaires and contracts.

  3. 03

    It tests controls against your baseline and the Joint Standards and checks POPIA and data residency terms.

  4. 04

    It scores the vendor and produces a cited assessment report.

  5. 05

    Your risk owner reviews the findings and approves, conditions or declines the vendor.

Deployment

Runs inside the tools your team already uses

The same agent and the same cited output, delivered three ways: through the AI assistant you have rolled out, on a model you host yourself, or inside your own software.

Model Context Protocol

In the frontier assistant you already pay for

We publish the agent as an MCP server. Add it as a connector and your team calls it from the chat they use every day, with no new tool to learn.

Adopting frontier AI across your teams
Called from ClaudeMCP connected

"What control gaps are in the PayCo SOC 2?"

Toolthird_party_and_vendor_risk.detect_control_gaps
vendor
PayCo (Pty) Ltd
tier
Critical
Returned2 gaps, 1 qualified controlEvery finding linked to its source document
Self-hosted

On a model you host yourself

Run the agent on open-weight models in your data centre or private cloud. Your vendor assessments never leave your network, which keeps POPIA and data residency straightforward.

  • Llama
  • Mistral
  • Ollama
  • or any OpenAI-compatible endpoint
Sovereign AI on your infrastructure
Bespoke systems

Inside your own software

Trigger a run from your own workflows, and push the finished output into your ERP, GRC or reporting systems. We build the integration with your team.

  • REST API
  • Webhooks
  • Batch jobs
  • Embeddable review panel
Custom integrations from our software factory
Governance

Governed the same way, every route

Whichever way your team reaches the agent, identity, permissions and audit stay with your existing controls.

  • Single sign-on through Entra ID, Okta or Google Workspace
  • Reads only the documents each user is already allowed to open
  • Every tool call written to an audit log you can export
How your data is handled

DATA SECURITY & PRIVACY

Your vendor assessments stay yours.

The agent runs inside your tenancy, reads only what each task needs, and never trains on your vendor assessments. Every step is logged so your auditors can see exactly what it touched.

Built for regulated work.

+
WHAT THE AGENT KEEPSONLY THE OUTPUTENCRYPTED AT REST0 BIT AES0% DELETABLE0 TRAINING RUNS

YOUR VENDOR ASSESSMENTS NEVER LEAVE YOUR ENVIRONMENT

Precision AI for Institutional Workflows

Build once.Deploy across teams.Improve over time.