In development, starting in the UK
From vendor evidence to findings your team can close
regAIx is building AI for third-party risk teams. It reads vendor evidence such as SOC 2 reports and security questionnaires, proposes a risk tier, drafts findings with owners and due dates, and follows each one through to closure, so analysts can spend their time on judgement.
Email usIllustrative example: excerpt from a vendor assurance report
Testing of user access reviews identified two exceptions in the period, where reviews of privileged accounts were completed late. Backups are encrypted at rest, and restoration testing was not performed during the period. Controls operated by the hosting provider are excluded from the scope of this report.
Drafted findings, for review
- Late reviews of privileged access mean inappropriate access may go undetected. Proposed owner: vendor security lead. Proposed due date: 30 days after acceptance. Source: exception 1.
- Backup restoration was not tested, so recovery from data loss is unproven. Proposed owner: vendor operations lead. Proposed due date: 60 days after acceptance. Source: backup testing.
- Hosting controls are outside this report, so assurance over the underlying provider needs a separate review. Proposed owner: TPRM analyst. Proposed due date: next assessment cycle. Source: scope exclusion.
The excerpt is invented for illustration. It is not taken from any real report or vendor.
How it works
From documents to a tracked list of findings in three steps.
-
1
Add the vendor's evidence
Assurance reports, certificates, questionnaires and the relevant contract terms.
-
2
regAIx drafts the assessment
It proposes a tier, maps the evidence to controls, and drafts findings, each linked to the passage it came from.
-
3
Your analyst decides and tracks to closure
Each finding is accepted, changed or rejected by a person. Accepted findings get an owner and due date, then reminders and escalation follow.
What we are building
Everything a third-party risk team does between receiving a report and closing the last finding.
- Inherent risk and tiering
- A proposed tier based on what the vendor does for you: the data it handles, the systems it supports and how hard it would be to replace.
- Review of controls and evidence
- SOC 2 reports, ISO 27001 certificates and questionnaire answers read and compared with the controls you care about, with exceptions, scope exclusions and gaps flagged.
- Findings and residual risk
- Clear risk statements, a proposed owner and due date for each, and a residual risk view for the analyst to accept or change.
- Issue management through to closure
- Every accepted finding tracked, owners reminded, and stalled items escalated, so nothing sits open without someone knowing.
- Exit and resilience checks
- Termination and exit terms reviewed, with a note wherever a vendor has no practical fallback.
How we are building it
Founder-led, based in London, and shaped by experience in regulation, supervision and third-party risk.
People decide, regAIx drafts
Risk judgement stays with the analyst. The tool exists to save reading and drafting time, not to replace sign-off.
Every finding points to its evidence
A finding that cannot be traced to the source document is not worth acting on, so traceability is designed in from the start.
For any team that depends on vendors
Cloud, software and data suppliers create the same questions in every sector.
Tell us where vendor reviews slow down
If you run or support a third-party risk programme, we would like to hear where assessments and follow-up take your team the longest.
Email hello@regaix.ai