AI for third-party risk, starting in the UK
From vendor evidence to findings your team can close
regAIx reads vendor evidence such as SOC 2 reports and security questionnaires, proposes a risk tier, drafts findings with owners and due dates, and follows each one through to closure, so analysts can spend their time on judgement.
SOC 2 Type II report Page 47
Testing of user access reviews identified two exceptions in the period, where reviews of privileged accounts were completed late. Backups are encrypted at rest, and restoration testing was not performed during the period. Controls operated by the hosting provider are excluded from the scope of this report.
Draft findings Inherent risk: High
-
HighAccess managementLate reviews of privileged access mean inappropriate access may go undetected.
-
MediumResilienceBackup restoration was not tested, so recovery from data loss is unproven.
-
MediumScopeHosting controls are outside this report, so assurance over the underlying provider needs a separate review.
How it works
From documents to a tracked list of findings in three steps.
-
Add the vendor's evidence
Assurance reports, certificates, questionnaires and the relevant contract terms.
-
regAIx drafts the assessment
It proposes a tier, maps the evidence to controls and drafts findings, each linked to its source passage.
-
Your analyst decides
Accepted findings get an owner and due date, then reminders and escalation follow.
Nothing sits open unnoticed
- One register for every vendor finding, owner and due date.
- Reminders and escalation when items stall.
- Residual risk updated as findings close.
| Finding | Owner | Due | Status |
|---|---|---|---|
| Privileged access reviews | Security lead | 12 Nov | Closed |
| Backup restoration test | Operations lead | 10 Dec | In progress |
| Hosting provider assurance | TPRM analyst | 15 Jan | Scheduled |
| Exit plan for key supplier | Vendor owner | 28 Oct | Escalated |
What we are building
Everything between receiving a vendor's report and closing the last finding.
Inherent risk and tiering
A proposed tier based on the data the vendor handles, the systems it supports and how hard it is to replace.
Controls and evidence review
SOC 2 reports, ISO 27001 certificates and questionnaires compared with your controls, with gaps flagged.
Findings and residual risk
Clear risk statements with a proposed owner and due date, and a residual risk view to accept or change.
Issue management
Every accepted finding tracked through to closure.
Exit and resilience checks
Exit terms reviewed, with a note wherever a vendor has no practical fallback.
Audit-ready trail
Every decision recorded with the evidence behind it.
How we are building it
Founder-led, based in London, and shaped by experience in regulation, supervision and third-party risk.
People decide, regAIx drafts
Risk judgement stays with the analyst. The tool saves reading and drafting time, not sign-off.
Every finding points to its evidence
A finding that cannot be traced to its source is not worth acting on.
For any team that depends on vendors
Cloud, software and data suppliers raise the same questions in every sector.
Tell us where vendor reviews slow down
If you run or support a third-party risk programme, we would like to hear where assessments and follow-up take your team the longest.
Email hello@regaix.ai