Third-Party and Vendor Risk Agent
The Third-Party and Vendor Risk Agent analyses SOC 2 and ISO 27001 reports, security questionnaires, POPIA operator agreements and compliance documents. It flags control gaps, reviews data residency and compares responses with your standards and the FSCA and PA Joint Standards, so your risk team can focus on decisions.
Ideal forRisk teams
The difference
From 3-5 days per vendor to 30-45 minutes
Your risk team clears vendor backlogs, keeps assessments current and spends its expertise on the vendors that matter most.
Done by hand
3-5 days per vendor
With the Vanine agent
30-45 minutes
Time returned to your team
90%
Indicative figures. We measure your own baseline in the first fortnight so the numbers you see are yours.
Joint Standard requirements met
Joint Standard 2 of 2024 and the direction set by Joint Communication 2 of 2025 on cloud and data offshoring require documented third-party assessments. The agent produces them consistently for every vendor.
POPIA and offshoring clarity
The agent checks operator agreements for security safeguards and breach notification and flags where personal information leaves South Africa, so you can assess section 72 obligations early.
Days of work reduced to minutes
Reading assurance reports and questionnaires by hand takes days per vendor. The agent completes the analysis quickly and uniformly, so onboarding is not held up.
Capabilities
Consistent, evidence-backed vendor assessments in under an hour.
Built for risk, IT security and procurement teams at SA banks, insurers, asset managers and large corporates.
Automated control gap detection
Analyses assurance reports and questionnaires to find missing or weak controls, comparing responses with your security baseline and Joint Standard 2 of 2024 on cybersecurity and cyber resilience.
Compliance mapping and verification
Maps certifications such as ISO 27001 and SOC 2 Type II to your framework, and checks that POPIA operator agreements cover security safeguards and breach notification.
Data residency and cloud review
Flags where personal information is processed or stored outside South Africa, so you can assess section 72 of POPIA and your cloud and data offshoring obligations.
Risk scoring and prioritisation
Scores vendors on control gaps, severity and business impact, and can include commercial checks such as B-BBEE status and Tax Compliance Status in your onboarding criteria.
Bulk and consistent assessment
Processes many vendor assessments at once using uniform criteria, so results are consistent regardless of who reviews them.
Auditable assessment records
Links every finding to the exact section of the vendor's documentation, giving defensible evidence for the board, regulators and internal audit.
How it works
From your systems to a result you sign off
Vendor approval and risk acceptance remain with your risk and procurement owners. Assessments land ready for their review and sign-off.
Connect the places your vendor assessments already live.
Assurance reports, questionnaires and operator agreements from your procurement system (SAP Ariba or Coupa), questionnaire portals, SharePoint and your GRC platform. Already use something else? We connect that too.
- OpenAI Frontier
- Microsoft 365 (SharePoint, Teams, Outlook)
- Copilot Studio
- SAP Ariba, Coupa
- GRC platforms and ServiceNow
- Vendor questionnaire portals
- Central Supplier Database (CSD) reports
- Your own AI platform or models
Triggers when a vendor enters onboarding or is due for review, or on request in Teams or OpenAI Frontier.
A scored assessment with cited findings and remediation points, written back to your GRC platform or ServiceNow and filed in SharePoint.
Step by step
- 01
A vendor enters onboarding or reaches its periodic review date.
- 02
The agent gathers assurance reports, questionnaires and contracts.
- 03
It tests controls against your baseline and the Joint Standards and checks POPIA and data residency terms.
- 04
It scores the vendor and produces a cited assessment report.
- 05
Your risk owner reviews the findings and approves, conditions or declines the vendor.
Deployment
Runs inside the tools your team already uses
The same agent and the same cited output, delivered three ways: through the AI assistant you have rolled out, on a model you host yourself, or inside your own software.
In the frontier assistant you already pay for
We publish the agent as an MCP server. Add it as a connector and your team calls it from the chat they use every day, with no new tool to learn.
"What control gaps are in the PayCo SOC 2?"
- vendor
- PayCo (Pty) Ltd
- tier
- Critical
On a model you host yourself
Run the agent on open-weight models in your data centre or private cloud. Your vendor assessments never leave your network, which keeps POPIA and data residency straightforward.
- Llama
- Mistral
- Ollama
- or any OpenAI-compatible endpoint
Inside your own software
Trigger a run from your own workflows, and push the finished output into your ERP, GRC or reporting systems. We build the integration with your team.
- REST API
- Webhooks
- Batch jobs
- Embeddable review panel
Governed the same way, every route
Whichever way your team reaches the agent, identity, permissions and audit stay with your existing controls.
- Single sign-on through Entra ID, Okta or Google Workspace
- Reads only the documents each user is already allowed to open
- Every tool call written to an audit log you can export
How we deliver it
One agent, three ways to hold it
Start where your team already works, then take it as far into your systems as the value justifies.
DATA SECURITY & PRIVACY
Your vendor assessments stay yours.
The agent runs inside your tenancy, reads only what each task needs, and never trains on your vendor assessments. Every step is logged so your auditors can see exactly what it touched.
Built for regulated work.
+YOUR VENDOR ASSESSMENTS NEVER LEAVE YOUR ENVIRONMENT
More agents
More agents we build for South African enterprises
Each one is built on the same foundation: your documents, your rules, and your people signing off.
Precision AI for Institutional Workflows


