A supplier you onboarded three years ago just had its cloud provider breached. You would not know for weeks. The questionnaire they filled in at onboarding is in a folder, marked green, and nobody has looked at it since. Their ISO certificate expired in March. Their credit rating slipped two notches in the spring. A subsidiary appeared on a sanctions list last month. None of that is in your risk register, because your register captures a moment - the moment they answered the questionnaire - and the world has moved on every day since.
This is the structural flaw in how most companies run third-party risk: an annual, self-reported questionnaire treated as if it were a live picture. Third parties are now involved in roughly one in three breaches, double the rate of a year earlier, and the teams meant to watch them are usually one or two people covering hundreds of vendors. The work of watching every supplier every day is not judgement work. It is intake checks, signal monitoring, questionnaire chasing, evidence collection, and re-assessment triggers - routine that runs on rules and memory, and exactly what an AI employee takes over end to end.
This is not a buyer guide to TPRM platforms. It is the story of an AI employee that owns the routine vendor-risk work, grounded in the systems you already run and in a Company Brain that keeps how your company assesses suppliers and what it decided last time. It is written for the head of procurement, the risk manager, or the compliance lead who wants the mechanism, the numbers, and the honest limits before the next third party turns into an incident.
TL;DR
The annual questionnaire is a stale snapshot - it captures what a vendor says on the day they answer, and drifts out of date within weeks as certificates expire, owners change, and new threats emerge.
Third-party risk has become a live discipline - third parties are involved in about one in three breaches, supply-chain compromises cost an average of 4.91 million dollars, and 63 percent of programmes are held back by understaffing.
Continuous monitoring is the shift - Gartner expects half of third-party cyber-risk programmes to focus on continuous monitoring by 2028, watching financial, security, sanctions and news signals between assessments.
The AI employee owns the routine - intake and onboarding checks, continuous monitoring, questionnaire chasing, evidence collection and re-assessment triggers, routing the real decisions to a human.
It complements your TPRM tool, it does not replace it - OneTrust, ProcessUnity, Prevalent, UpGuard and Venminder are the system of record; the AI employee does the work inside it, held together by a Company Brain that keeps your method when the risk manager leaves.
The Questionnaire That Went Stale: What Vendor Risk Actually Is
Third-party risk management looks like one task, deciding whether a supplier is safe to work with, but it is a chain of small, repeated tasks that never really ends. Almost every link in that chain is rule-based and recurring, which is precisely why it fits an AI employee rather than another software licence.
- Intake and onboarding checks - screening a new supplier before the first contract: identity, beneficial ownership, sanctions and watchlists, financial health, security posture, and the certificates that back their claims.
- Tiering and scoping - deciding how critical a vendor is by data access, spend, and business dependency, so the depth of due diligence matches the risk instead of treating every supplier the same.
- Questionnaire chasing and evidence collection - sending the security questionnaire, chasing the three follow-ups, collecting the SOC 2 report and the ISO certificate, and filing it all where it can be found.
- Continuous monitoring - watching the financial, security, sanctions and news signals that move between assessments, because the questionnaire is stale the moment it is filed3,10.
- Re-assessment triggers - re-scoring a vendor when a signal crosses a threshold: a breach, a downgrade, an expired certificate, a new owner, or a sanctions listing.
- Routing the decision - handing a human the accept, reject, or exit decision with the evidence and reasoning attached, so the judgement is fast and well-informed.
The Core Idea
Most of vendor risk is collection plus vigilance: gather the evidence, watch the signals, notice what changed, and re-score against your criteria. That is the part an AI employee owns. The genuine judgement - is this residual risk acceptable, do we trust this vendor with critical data, is it time to exit - is where a person belongs. Automating vendor risk is not about removing the risk manager; it is about removing the chasing and the watching so the risk manager makes the calls that matter, on every vendor, not just the critical few.
The reason this matters is where the time goes and where the coverage fails. The routine tasks are the ones that get skipped when a two-person team is covering hundreds of suppliers.
| Vendor-Risk Task | What It Really Involves | Routine or Judgement |
|---|---|---|
| Intake and onboarding checks | Screen identity, ownership, sanctions, security | Routine |
| Questionnaire chasing | Send, chase, collect, file the evidence | Routine |
| Continuous monitoring | Watch financial, security, sanctions, news signals | Routine |
| Re-assessment triggers | Re-score when a signal crosses a threshold | Routine, learned |
| Tiering and scoping | Rate criticality by data, spend, dependency | Mostly routine, some judgement |
| Accept, reject, or exit | Decide whether to trust or leave a vendor | Judgement |
Once you see vendor risk as a continuous routine with a thin layer of judgement on top, the automation question stops being if and becomes which tasks and how far.
What a Stale Vendor File Actually Costs
The cost of a stale vendor file is easy to underestimate because it sits quiet until a third party fails, and then it arrives as a breach, a supply disruption, or a regulatory finding. The benchmark data pulls it into focus, and the gap between a watched and an unwatched vendor base is not marginal.
- Third parties are now in one in three breaches - Verizon found third-party involvement in breaches doubled from 15 to 30 percent in a single year1,2,3.
- Supply-chain breaches are the expensive, slow ones - IBM puts supply-chain compromise at 15 percent of breaches, an average cost of 4.91 million dollars, and 267 days to detect and contain, the longest of any vector4,5.
- Almost everyone got hit through a partner - one analysis found 97 percent of organisations experienced a supply-chain-related breach in 202512.
- The teams are far too small - most organisations run their whole programme with one or two dedicated people, and 73 percent of financial institutions have one to two staff overseeing more than 300 vendors6,7.
- Understaffing is the number-one obstacle - 63 percent of programmes named understaffing as the biggest barrier to safeguarding the organisation, and the average team said it needs to double6,7.
- The vendor base keeps growing - a rising share of organisations now manage more than 1,000 third parties, well beyond what any small team can watch by hand6.
Key Data Point
A supply-chain compromise costs an average of 4.91 million dollars and takes 267 days to detect and contain, because a breach that comes through a trusted vendor hides inside a relationship you were not watching4,5. Meanwhile the team meant to watch that vendor is one or two people covering hundreds of suppliers6. The annual questionnaire is not a control against this; it is a snapshot that was out of date before the next quarter began.
The deeper cost sits underneath the numbers: coverage collapses to the critical few. A two-person team triages its most important vendors and lets the long tail go dark, and that long tail is where the forgotten supplier with the expired certificate lives.
| Cost or Risk | Annual Questionnaire | AI Employee |
|---|---|---|
| Picture of the vendor | Point-in-time snapshot10 | Live, re-scored on change |
| Coverage | Critical few, long tail goes dark | Whole inventory, every day |
| Time to notice a breach signal | Next annual review, if ever | Within a day of the signal |
| Evidence chasing | Manual, weeks of email | Chased and collected automatically |
| Scaling with vendor count | Add people you cannot hire | Absorb volume without hiring |
The people problem makes the coverage gap permanent: a team that needs to double, in a market where it cannot fill the roles it already has, will never watch the whole base by hand6,7. A programme that depends on more headcount does not scale.
“We all do business with third parties, but again this interconnectedness is being exploited more and more as we try to do our business and are rudely interrupted by incidents and breaches.”
- Alex Pinto, Associate Director of Threat Intelligence, Verizon3
Why 2026 Is the Tipping Point for Vendor-Risk Automation
Vendor risk has been a manual discipline for years, so why now. Several forces converged, and procurement, risk and compliance teams feel them at the same time.
- The threat moved to the supply chain - third-party involvement in breaches doubled to 30 percent in a year, and 91 percent of CISOs report rising third-party incidents with 95 percent expecting the surge to continue1,11.
- The questionnaire model broke in public - Gartner describes third-party questionnaires as point-in-time, self-reported snapshots that miss how a vendor's posture drifts after onboarding, and expects half of third-party cyber-risk programmes to focus on continuous monitoring by 20289,10.
- Regulation turned due diligence into an ongoing duty - the German LkSG requires regular, evidenced risk analysis of suppliers, with penalties up to 2 percent of annual turnover enforced by BAFA13,14,15.
- AI itself became a vendor-risk category - vendor AI risk now ranks as the second-highest concern in third-party risk programmes, adding a whole new class of supplier to assess7.
- The staffing maths does not work - programmes are held back most by understaffing, the average team needs to double, and the vendor count keeps rising, so the base can only be covered by automation6,7.
The Gap Between Intent and Coverage
Most programmes have matured on paper - more of them run a dedicated TPRM platform than a year ago, and manual spreadsheets are on the way out6. But the tool is a system of record, not a worker, and the teams behind it are still one or two people. The gap is not the software; it is the labour to run it against a growing vendor base every day. That gap is the whole opportunity: the register exists, the criteria exist, but nobody has the hours to keep it current. The companies that close the gap first stop being surprised by their own suppliers.
The capability jump and the coverage gap arrive together, which is rare. The monitoring is finally cheap and continuous exactly when the manual model has run out of people.
| Force | What Changed | Source |
|---|---|---|
| Third-party breaches | Doubled to 30% in a year | Verizon DBIR1 |
| Continuous monitoring | Half of programmes to focus on it by 2028 | Gartner10 |
| Regulatory duty | LkSG: regular risk analysis, up to 2% turnover | LkSG / BAFA13,14 |
| Rising incidents | 91% of CISOs report more third-party incidents | Panorays11 |
| Staffing shortfall | 63% blocked by understaffing, teams need to double | Venminder6 |
What the AI Employee Owns, End to End
The difference between a TPRM tool and an AI employee is ownership. A platform stores the vendor inventory and hands each task to a person. An AI employee does the routine work itself and only stops when it hits something a human should decide. Here is the flow it owns across the vendor lifecycle.
The end-to-end vendor-risk flow
- It runs intake - when procurement adds a supplier, it screens identity, beneficial ownership, sanctions, financial health, and security posture before the first contract, and drafts the tier.
- It chases and collects - it sends the security questionnaire, chases the follow-ups over email and Teams, and collects the SOC 2, the ISO certificate, and the insurance evidence without a person nagging.
- It scores against your criteria - it applies your scoring model and residual-risk logic, not a generic template, and shows its reasoning.
- It monitors continuously - it watches financial, security, sanctions and adverse-media signals across the whole inventory every day, so the picture stays live between assessments10.
- It triggers re-assessment - when a signal crosses a threshold you set - a breach, a downgrade, an expired certificate, a new owner - it re-scores the vendor and pulls a fresh questionnaire only if the change warrants one.
- It routes the decision - it hands the risk manager, procurement lead or compliance officer the accept, reject or exit decision with the evidence and reasoning attached, and writes the outcome back to the register.
This is where the honest distinction from TPRM point tools matters. Those platforms are valuable, but they do a different job.
TPRM Platform vs AI Employee
AI Employee owns
- ✓ The chasing and collecting - it gathers the evidence itself
- ✓ The daily monitoring - it watches every vendor, every day
- ✓ The first-pass scoring - it drafts the assessment
- ✓ Learning from decisions - your method compounds
TPRM platform gives you
- ✗ The inventory - the register and vendor records
- ✗ The questionnaire library - templates and workflow
- ✗ The scoring model - you configure and maintain it
- ✗ The person still does the work - inside the tool
Tools like OneTrust, ProcessUnity, Prevalent, UpGuard, SecurityScorecard and Venminder govern the programme: they give you the inventory, the questionnaire library, the risk register and the workflow18,20. The AI employee performs the routine inside that structure, and the two work together rather than competing.
Where the Human Stays
The decision to onboard a critical supplier, to accept a documented residual risk, to trust a vendor with regulated data, or to exit a relationship all stay with people. The AI employee prepares everything so the human decision is fast and well-evidenced, but it never accepts a critical risk on its own. Control does not weaken; it gets a live, well-documented feed behind it instead of a stale folder.
Stop being surprised by your own suppliers
Book a 30-minute call. We will map how your vendor-risk process runs today and where an AI employee can own the routine.

Intake and Continuous Monitoring, Signal by Signal
Two parts of vendor risk carry most of the value: getting the intake right so a bad supplier never gets through, and watching the signals so a good supplier that turns bad gets caught. These are the tasks where an AI employee earns its keep, because both are collection-and-vigilance work rather than judgement.
How the AI runs intake
- It pulls the vendor from procurement - reading the new supplier from your ERP or procurement system the moment it is created, without waiting for a person to start a case.
- It screens the hard checks - identity, beneficial ownership, sanctions and watchlists, politically exposed persons, and adverse media, flagging a hit rather than a blank pass.
- It assesses financial and security posture - credit health, insolvency signals, external security ratings, and the presence and validity of ISO 27001 or SOC 2.
- It drafts the tier - rating criticality by data access, spend, and dependency, so the depth of due diligence matches the risk instead of one process for all.
- It learns from every override - a tier you adjust or a risk you accept is remembered and applied to the next similar vendor, so the same call is not re-made from scratch.
How the AI monitors between assessments
- Security signals - it watches breach disclosures, exposed credentials, expiring certificates, and external security-rating changes across the whole base, every day10,20.
- Financial signals - it tracks credit-rating moves, insolvency filings, and distress indicators that threaten continuity of supply.
- Compliance signals - it screens sanctions, watchlists, ownership changes, and adverse media on human rights or environmental issues relevant to the LkSG13,16.
- Re-assessment on trigger - when a signal crosses your threshold, it re-scores the vendor and drafts the change, pulling a fresh questionnaire only when the change warrants it.
- Register updated and routed - every change is written back to the TPRM tool with the evidence linked, and the material ones route to a human.
| Scenario | Annual Questionnaire | AI Employee |
|---|---|---|
| Vendor's cloud provider is breached | Unknown until next review | Flagged within a day, re-scored |
| ISO 27001 certificate expires | Green in the folder for another year | Gap caught, evidence chased |
| Subsidiary added to a sanctions list | Missed entirely | Screened continuously, routed at once |
| Credit rating slips two notches | No trigger, no comment | Continuity risk flagged for review |
| New supplier onboarded | Questionnaire sent, weeks of chasing | Screened and scored, evidence collected |
The payoff of getting these two tasks right is a vendor base that is watched in full, so the forgotten supplier stops being the blind spot. For the neighbouring functions, see our pieces on AI procurement tools and the AI employee in contract management.
“The 2025 survey results underscore the complexities of third-party risk management and the increasing sophistication of TPRM programs.”
- Michael Berman, Founder and CEO of Ncontracts8
The Company Brain: How the AI Learns Your Method
A generic risk model knows security and compliance in general. It does not know that your company accepts a missing SOC 2 from a vendor with strong compensating controls, that any supplier touching customer data is automatically tier one, or that you exited a logistics partner last year for exactly the distress signal now showing on another. That company-specific knowledge is what the Company Brain holds, and it is what makes the automation durable instead of brittle.
- It holds your risk tiers and criteria - how you rate criticality and score residual risk, so assessments follow your logic, not a vendor-supplied template.
- It knows your mandatory controls - which controls are non-negotiable for a critical vendor and which can be compensated, so the AI applies your bar, not a generic checklist.
- It carries your thresholds - what size of signal triggers a re-assessment and what escalates to a human, so monitoring matches how your team actually decides.
- It remembers what you decided last time - the risks you accepted, the exceptions you granted, and the vendors you exited, so a similar case is handled consistently instead of from scratch.
- It improves from every override - each score a risk manager corrects or exception they grant teaches the AI, so accuracy climbs vendor over vendor rather than staying flat.
- It survives turnover - when the risk manager who just knows the vendors leaves, the method and the decisions stay in the Company Brain instead of walking out the door.
Why This Is the Load-Bearing Wall
The reason so many vendor-risk programmes are fragile is that the method lives in people, not systems. When the risk manager who has assessed suppliers for a decade leaves, the reasoning behind each accepted risk, the unwritten bar for a critical vendor, and the memory of who was exited and why all leave with them, and the next hire re-invents it. A Company Brain flips that: how your company assesses suppliers and what it decided last time is captured as the AI works, improves through daily feedback, and becomes a company asset that does not depend on one head. That is the difference between a one-off clean-up and a compounding advantage.
| Situation | Without a Company Brain | With a Company Brain |
|---|---|---|
| Risk manager leaves | Method and decisions lost | Criteria and precedents retained |
| Similar vendor appears | Assessed from scratch, inconsistently | Handled like the last one, consistently |
| Policy or threshold changes | Retrain each assessor individually | Update once, applied to every vendor |
| Auditor asks why a risk was accepted | Reasoning is in someone's head | Decision and evidence on record |
For a deeper look at this knowledge layer and what its absence costs, see our companion pieces on what no Company Brain really costs and institutional amnesia.
The 90-Day Playbook for a Vendor-Risk AI Employee
You do not flip a switch and hope. You measure, connect, run in parallel on a slice of the portfolio, and only widen the scope and raise autonomy once accuracy is proven on your real vendors. Here is the sequence.
Phase 1: Baseline and map (Weeks 1-4)
- Week 1: Map the process - the intake steps, the tiers, the scoring criteria, the mandatory controls, and the undocumented judgement calls nobody wrote down.
- Week 2: Measure the baseline - how many vendors are overdue for review, how long onboarding takes, how many hours go into chasing, and how much of the base is monitored at all.
- Week 3: Confirm the systems - the GRC or TPRM platform, the procurement or ERP system, email and Teams, and the external feeds for security, financial and sanctions signals.
- Week 4: Set the autonomy rules - which tiers can be onboarded within rules, which always need a human, and the thresholds that trigger a re-assessment.
Phase 2: Connect and prove (Weeks 5-8)
- Week 5-6: Connect the AI employee - integrate it with the TPRM tool, procurement, email and the feeds, seeding it with your tiers, criteria, mandatory controls and past decisions.
- Week 7: Run a slice in parallel - point it at one category or one tier; it screens, monitors, chases and scores while people review and correct, and the Company Brain learns.
- Week 8: Measure against baseline - compare scoring accuracy, coverage, and hours saved, and confirm the assessments genuinely match your method before widening scope.
Phase 3: Scale and control (Weeks 9-12)
- Week 9: Raise the autonomy threshold - let low-risk, clean-signal vendors onboard within rules now that accuracy is proven on your data.
- Week 10-11: Extend the scope - bring the whole vendor base under continuous monitoring, keeping human review on critical tiers and accepted risks.
- Week 12: Report and harden controls - present the coverage gained and hours freed, and lock in the audit trail and the LkSG evidence record as standing practice.
Vendor-Risk AI Readiness Checklist
- You have a baseline for overdue reviews, onboarding time, and coverage of the base
- The process is mapped, including the undocumented tiering and acceptance calls
- Your tiers, scoring criteria, mandatory controls and past decisions are available to seed the AI
- The TPRM tool, procurement system, email and external feeds allow read and write access
- Autonomy thresholds and re-assessment triggers are agreed with risk and procurement
- Review ownership is clear: who signs off on critical vendors and accepted risks
- The LkSG and DSGVO evidence requirements are defined up front
- Success criteria are measurable and agreed before go-live
For the wider view of putting an AI employee on the compliance side of the house, our guides on the AI compliance assistant and NIS2 and AI agents cover the neighbouring obligations.
Where Vendor-Risk Automation Breaks, and How to Avoid It
Vendor-risk automation fails in predictable ways, and Gartner expects over 40 percent of agentic AI projects to be cancelled by the end of 2027, usually on cost and unclear value rather than the model itself21. The failure modes are avoidable if you know them.
- Automating a broken process - if the tiers, criteria and register are a mess, automating them just makes the mess faster. Map and clean first.
- Signal without judgement - a wall of alerts nobody triages is worse than none. Set thresholds so only real changes route to a human, and tune them as you learn.
- Raising autonomy too early - let the AI onboard critical vendors before accuracy is proven and you approve risk at speed. Prove on a low-risk slice first.
- Treating monitoring as the whole job - continuous monitoring surfaces the change; someone still has to decide. Staff the judgement layer or the alerts pile up.
- No audit trail - the LkSG and your auditors need the risk analysis evidenced and the decisions documented. Build the trail in from day one, not after13,14.
- Framing it as a headcount cut - if the team sees only job loss, your best people leave and take the method with them.
“Before asking for more headcount and resources, teams must demonstrate why they cannot get what they want done using AI.”
- Tobi Lütke, CEO of Shopify22
Disciplined Rollout vs Rushed Rollout
Disciplined
- ✓ Baseline first - the coverage gain is provable
- ✓ Parallel slice - accuracy proven before autonomy
- ✓ Tuned thresholds - only real changes route
- ✓ Team redeployed - assessors become deciders
Rushed
- ✗ No baseline - value cannot be shown
- ✗ Full autonomy day one - fast risk acceptance
- ✗ Alert flood - nobody triages it
- ✗ Framed as cuts - method walks out
The pattern is consistent with what we see across compliance automation projects, which we cover in the most common AI implementation mistakes.
How Superkind Fits
Superkind builds AI employees for the Mittelstand and enterprise: agents that take over routine work, connect to the systems you already run, and get better through daily feedback. In vendor risk that means an AI employee that owns intake checks, continuous monitoring, questionnaire chasing, evidence collection and first-draft scoring, and hands your risk manager a decision instead of a backlog.
- An AI employee, not another dashboard - it does the screening, chasing and monitoring end to end rather than showing you who still has to do it.
- Connects to your existing systems - email, Teams, procurement or ERP such as SAP, your GRC or TPRM platform, and the external feeds for security, financial and sanctions signals. No rip-and-replace.
- Complements your TPRM tool - it works alongside OneTrust, ProcessUnity, Prevalent, UpGuard, SecurityScorecard or Venminder, performing the routine inside the register and workflow they provide.
- Learns how you assess suppliers - it applies your tiers, criteria and mandatory controls, and improves from every override, not a generic template.
- Keeps what you decided last time - accepted risks, exceptions and exits stay in the Company Brain, so similar vendors are handled consistently.
- Covers the whole base - it monitors every vendor every day, so the long tail stops being a blind spot for a two-person team.
- Human-in-the-loop by design - people keep the accept, reject and exit decisions; the AI never accepts a critical risk on its own.
- Audit and LkSG ready - every check, signal and decision is logged and evidenced, which suits the LkSG risk-analysis duty and makes the auditor's job easier, not harder13,14.
- Outcomes, not licences - pricing is tied to the measurable result per use case, not per seat, so the ROI is defined before the build starts.
| Approach | TPRM Platform | Superkind AI Employee |
|---|---|---|
| What it does | Stores the inventory, scores, workflow | Does the screening, chasing and monitoring |
| Monitoring | Feeds you data to interpret | Watches and re-scores the whole base |
| Questionnaires | You send and chase | AI chases and collects the evidence |
| Method and decisions | Live in people, leave with them | Captured in the Company Brain |
| Pricing | Per seat, per year | Per outcome, per use case |
Superkind
Pros
- ✓ Owns the routine - screening, chasing, monitoring done
- ✓ Learns your method - accuracy compounds
- ✓ Works on your stack - GRC, SAP, email, feeds
- ✓ LkSG-ready trail - evidenced by design
- ✓ Outcome-based pricing - pay for results
Cons
- ✗ Not a self-serve app - it needs engagement with our team
- ✗ Needs process access - we map your real process first
- ✗ Not instant - proof takes a slice of the portfolio, by design
- ✗ Not a TPRM replacement - it complements your platform
To compare the broader tool landscape before deciding, our guides on AI procurement tools and procurement software versus an AI agent cover the buyer view; this article is about the AI taking over the work.
Decision Framework: Is Your Vendor-Risk Programme Ready?
An AI employee in vendor risk is not right for every company on day one. Use these signals to decide where and whether to start.
| Signal | What It Means | Action |
|---|---|---|
| Most vendors are overdue for review | Coverage has collapsed to the critical few | Put the whole base under continuous monitoring |
| A two-person team covers hundreds of vendors | A capacity problem AI can absorb | Pilot an AI employee before the next hire |
| Onboarding takes weeks of chasing | The intake bottleneck is manual | Let the AI screen, chase and score |
| Your method lives in one person's head | Knowledge risk if they leave | Capture it in a Company Brain now |
| You already run a TPRM platform | The register exists, the work does not get done | Add an AI employee to run the routine inside it |
| You fall under the LkSG | Risk analysis must be regular and evidenced | Automate the monitoring and the evidence trail |
Start Now vs Wait
Start Now
- ✓ Capture the method - while experienced staff are still here
- ✓ Cover the whole base - no more dark long tail
- ✓ Catch signals early - before they become incidents
- ✓ Evidence for the LkSG - continuous, timestamped record
Waiting
- ✗ The long tail stays dark - a forgotten vendor is the breach
- ✗ Files keep going stale - the snapshot ages daily
- ✗ Method keeps leaking - each departure is unrecoverable
- ✗ The gap widens - continuous programmes pull ahead
“Understaffing was the biggest obstacle to safeguarding organisations from third-party breaches, with the average respondent saying they need to double their current team.”
- State of Third-Party Risk Management 2025, Venminder (Ncontracts)6,7
Frequently Asked Questions
AI vendor risk management is an AI employee that does the routine third-party-risk work itself: it runs intake and onboarding checks on a new supplier, monitors financial, security, sanctions and news signals continuously, chases questionnaires and collects evidence, triggers re-assessments when something changes, and routes the real decisions to a human. A TPRM platform such as OneTrust, ProcessUnity, Prevalent or Venminder is the system of record - it stores the vendor inventory, the questionnaires, the risk scores and the workflow. The AI employee performs the work inside that structure rather than replacing it, so the two are complementary: the platform governs the programme, the AI employee runs it.
A human signs off on the decisions that matter. The AI employee does the legwork - collecting evidence, scoring against your criteria, flagging what changed, and drafting a recommendation with its reasoning - but the approval to onboard a critical supplier, accept a risk, or exit a relationship stays with your risk manager, procurement lead or compliance officer. You set the autonomy per tier: a low-risk, low-spend vendor with clean signals can be onboarded within rules you define, while a critical or high-risk vendor always routes to a person. The AI removes the chasing and the collating, not the judgement.
The annual questionnaire is a point-in-time, self-reported snapshot: it captures what a vendor says about itself on the day they fill it in, and it is stale within weeks as controls drift, certificates expire, owners change and new threats emerge. Continuous monitoring watches the signals that move between assessments - a credit downgrade, an expired ISO or SOC certificate, a fresh breach disclosure, a new sanctions listing, adverse news - and re-scores the vendor the moment something changes. Gartner expects half of third-party cyber-risk programmes to focus on continuous monitoring by 2028 for exactly this reason. The AI employee runs the monitoring every day and only pulls in a fresh questionnaire when a real change warrants it.
Yes. The AI employee connects to the systems the vendor-risk process already touches rather than replacing them: your email and Microsoft Teams for chasing evidence, your procurement or ERP system such as SAP for the supplier master and spend, your GRC or TPRM platform for the risk register and workflow, and the external feeds for security ratings, financial health, sanctions and adverse media. It reads the vendor inventory, writes updates back to the register, files evidence with the right metadata, and sends the chase emails itself. There is no rip-and-replace and nothing new for the risk team to learn.
It learns your method from your history and your corrections, and holds it in a Company Brain. It knows your risk tiers, your scoring criteria, which controls are mandatory for a critical vendor versus a marginal one, and how your team handled a similar supplier before. When a risk manager overrides a score, accepts a documented risk, or decides a control is good enough, that decision is remembered and applied to the next vendor without being re-explained. The point is that the reasoning behind each assessment stays in the company, so it does not walk out the door when the risk manager who just knows the vendors leaves.
A back-office assistant that monitors suppliers and drafts assessments under human oversight sits in the limited-risk or minimal-risk tier of the EU AI Act, which carries light transparency obligations rather than the heavy conformity assessment reserved for high-risk uses. Under the DSGVO you keep the processing of any personal data - beneficial-owner or director checks, for instance - lawful and documented, which a logged, auditable AI trail supports. For the German LkSG, the AI employee strengthens compliance because supplier due diligence and risk analysis have to be regular and evidenced, and a continuous, timestamped monitoring record is exactly what the Bundesamt für Wirtschaft und Ausfuhrkontrolle expects to see.
The economics are the whole point. Venminder found most organisations run their entire third-party-risk programme with just one or two dedicated people, and 73 percent of financial institutions have one to two staff overseeing more than 300 vendors, while a growing share manage over 1,000. A human team cannot monitor that population continuously - they triage the critical few and let the long tail go stale. An AI employee monitors the whole inventory every day, so the vendors nobody has looked at since onboarding stop being blind spots, and the human team spends its scarce hours on the decisions the monitoring surfaces.
It watches the signals that actually move a vendor risk score and that a person cannot check daily across hundreds of suppliers. On the security side that means breach disclosures, exposed credentials, expiring or missing ISO 27001 and SOC 2 certificates, and external security ratings. On the financial side it watches credit-rating changes, insolvency filings and signs of distress that threaten continuity. On the compliance side it screens sanctions and watchlists, politically exposed persons, beneficial ownership, and adverse media on human rights or environmental issues relevant to the LkSG. When a signal crosses a threshold you set, it re-scores the vendor and routes the change.
Because the tool is a system of record, not a worker. OneTrust, ProcessUnity, Prevalent, UpGuard, SecurityScorecard and Venminder give you the inventory, the questionnaire library, the scoring model and the workflow, and they do that well. What they do not do is the labour: someone still has to chase the vendor for the evidence, read the SOC 2 report, interpret the adverse-media hit, decide whether a certificate gap matters, and update the register. The AI employee does that routine work inside your existing platform, so you get more coverage from the same tool without hiring, and the register stays current instead of drifting.
Weeks, not months. The first phase maps how your vendor-risk process actually runs - the intake steps, the tiers, the scoring criteria, and the undocumented judgement calls - and measures the baseline: how many vendors are overdue for review, how long onboarding takes, and how many hours go into chasing. Then the AI employee is connected to your GRC tool, email, procurement system and the external feeds, and it runs in parallel on a slice of the portfolio while the team reviews and corrects it. Once its scoring and drafts prove reliable on your real vendors, you widen the scope and raise the autonomy. A single quarter is enough to show a measurable gain.
The return comes from three places: coverage you could never staff, breaches and disruptions avoided, and hours given back to a chronically understaffed team. Third parties are now involved in roughly one in three breaches, supply-chain compromises cost an average of 4.91 million dollars and take 267 days to contain, and 63 percent of programmes name understaffing as their biggest obstacle. An AI employee that monitors the whole vendor base continuously catches the credit downgrade, the expired certificate or the sanctions hit before it becomes an incident, and it does the chasing and collating that eats the team. Because Superkind prices on the outcome per use case rather than per seat, the return is defined before the build starts.
No. The goal is leverage, not headcount reduction. Vendor-risk teams are already too small for the population they cover, so the realistic outcome is that the same people finally get full coverage instead of triaging the critical few. The AI employee takes the repetitive work - intake checks, monitoring, questionnaire chasing, evidence collection and first-draft scoring - and the risk manager, procurement lead and compliance officer keep the judgement: which risks to accept, which vendors to trust with critical data, and when to exit a relationship. The people move from collecting information to acting on it.
Sources
- Verizon - 2025 Data Breach Investigations Report: Third-Party Involvement Doubled to 30%
- Verizon - 2025 Data Breach Investigations Report (full report)
- ASIS International - Verizon 2025 DBIR: Third-Party Involvement in Confirmed Breaches Doubled
- IBM - Cost of a Data Breach 2025
- IBM - 2025 Cost of a Data Breach: Navigating the AI Rush Without Sidelining Security
- Venminder (Ncontracts) - State of Third-Party Risk Management 2025
- Venminder - Highlights from the State of Third-Party Risk Management 2025 Survey
- Business Wire - Ncontracts Releases the 2025 Venminder State of Third-Party Risk Management Survey
- Gartner - Third-Party Risk Management (TPRM): A Complete Guide
- RiskRecon - 5 Key Takeaways From Gartner Predicts 2026 on Third-Party Cyber Risk
- Panorays - 2025 CISO Survey: 91% Report Rising Third-Party Incidents
- Deepstrike - Supply Chain Attack Statistics 2025
- EcoVadis - German Supply Chain Due Diligence Act (LkSG)
- CSR in Deutschland (BMAS) - The German Supply Chain Act
- Cleary Gottlieb - Supply Chain Due Diligence Obligations in Germany, France and the EU
- Circularise - German Supply Chain Act (LkSG): Due Diligence Obligations Explained
- European Commission - Regulatory Framework for AI (EU AI Act)
- Atlas Systems - Third-Party Risk Management Statistics
- Compyl - Third-Party Risk Management for Mid-Market Companies: Beyond Vendor Questionnaires
- UpGuard - Third-Party Risk Management Guide for 2026
- Gartner - Over 40% of Agentic AI Projects Will Be Canceled by End of 2027
- CNBC - Shopify CEO: Prove AI Can’t Do the Job Before Asking for More Headcount (2025)
Ready to watch every vendor, not just the critical few?
Book a 30-minute call with Henri. We will map how your vendor-risk process runs today and where an AI employee can own the monitoring and the chasing - no commitment, no sales pitch.
Book a Demo →
