Vendor Due Diligence Agent
Coordinates third-party due diligence and risk assessment.
Collects and reads the security questionnaires, financials, certifications and adverse media on a prospective vendor, runs sanctions screening on the entity, and assembles a risk-rated diligence file with evidence and rationale. High-risk ratings route through the third-party-risk oversight agent, which re-derives as a check, before the accountable third-party-risk officer approves engagement.
Authority
Recommend for approval
Team role
Coordinates the work
Handoffs
Named collaborators
The role
What it owns and where its authority ends
Desk
Procurement & Vendor Management
Desk workflow
Sourcing, then vendor due diligence, then contract negotiation, then onboarding, then ongoing monitoring and renewal. High-risk vendor ratings route through the third-party-risk oversight agent's re-derivation to the accountable third-party-risk officer; an accountable attorney approves every execution on the legal-review judge's check.
Collaboration
Coordinates specialist contributions
Decision boundary
An accountable reviewer commits the decision or action.
Systems and capabilities involved
Vendor risk management platform
Document intake + OCR
Adverse media + financial-health screening
Vendor portal
legacy questionnaire systems
Sanctions / entity screening
Handoffs
What this role gives and receives
Capabilities offered
The handoffs name the next owner or specialist and the work that moves between them.
Handoff to
External handoff
Risk's operational and third-party risk desk for oversight
Context
What the role needs to do the work
- Current work
- The vendor file being assembled and the outstanding checklist.
- Prior interactions
- Prior diligence on the same or related vendors.
- Policies and reference
- Third-party-risk framework, control requirements by service tier.
- Working method
- Document-extraction playbooks per questionnaire and certification type.
Illustrative workflow
How the work moves
Starting point
A new cloud-infrastructure vendor enters the onboarding pipeline.
- 01
Collect the security questionnaire, SOC 2, and financials via the vendor portal.
- 02
Screen the entity for sanctions and adverse media through the screening agents.
- 03
Assess controls against the third-party-risk framework; compute a risk rating.
- 04
Assemble the diligence file with evidence and a rating rationale.
Result
A risk-rated diligence file with evidence and rationale; flags a concentration-risk concern to the third-party-risk oversight agent, which re-derives as a check before the accountable third-party-risk officer approves engagement.
Checks and boundaries
What must be tested or reviewed
- 01Four-eyes: high-risk vendor ratings require the third-party-risk oversight agent to re-derive as a check and the accountable third-party-risk officer to approve before engagement.
- 02Completeness check against the third-party-risk control set before sign-off.
- 03Agent-as-judge review of the risk-rating rationale.
- 04Immutable audit log for regulatory third-party-risk exam.
Human authority
An accountable reviewer commits the decision or action.
Keep exploring