regAIx Contact

AI for third-party risk, starting in the UK

From vendor evidence to findings your team can close

regAIx reads vendor evidence such as SOC 2 reports and security questionnaires, proposes a risk tier, drafts findings with owners and due dates, and follows each one through to closure, so analysts can spend their time on judgement.

Email us

Vendor review: Northwind Cloud Sample data

SOC 2 Type II report Page 47

Testing of user access reviews identified two exceptions in the period, where reviews of privileged accounts were completed late. Backups are encrypted at rest, and restoration testing was not performed during the period. Controls operated by the hosting provider are excluded from the scope of this report.

Draft findings Inherent risk: High

  • HighAccess management
    Late reviews of privileged access mean inappropriate access may go undetected.
    Vendor security leadDue in 30 daysAcceptChangeReject
  • MediumResilience
    Backup restoration was not tested, so recovery from data loss is unproven.
    Vendor operations leadDue in 60 daysAcceptChangeReject
  • MediumScope
    Hosting controls are outside this report, so assurance over the underlying provider needs a separate review.
    TPRM analystNext assessment cycleAcceptChangeReject
People decideEvery finding is accepted, changed or rejected by an analyst.
Traced to evidenceEach finding links to the passage it came from.
Tracked to closureOwners reminded, stalled items escalated.

How it works

From documents to a tracked list of findings in three steps.

  1. Add the vendor's evidence

    Assurance reports, certificates, questionnaires and the relevant contract terms.

  2. regAIx drafts the assessment

    It proposes a tier, maps the evidence to controls and drafts findings, each linked to its source passage.

  3. Your analyst decides

    Accepted findings get an owner and due date, then reminders and escalation follow.

Nothing sits open unnoticed

  • One register for every vendor finding, owner and due date.
  • Reminders and escalation when items stall.
  • Residual risk updated as findings close.
Findings registerSample data
Findings closed6 of 9
FindingOwnerDueStatus
Privileged access reviewsSecurity lead12 NovClosed
Backup restoration testOperations lead10 DecIn progress
Hosting provider assuranceTPRM analyst15 JanScheduled
Exit plan for key supplierVendor owner28 OctEscalated

What we are building

Everything between receiving a vendor's report and closing the last finding.

Inherent risk and tiering

A proposed tier based on the data the vendor handles, the systems it supports and how hard it is to replace.

Controls and evidence review

SOC 2 reports, ISO 27001 certificates and questionnaires compared with your controls, with gaps flagged.

Findings and residual risk

Clear risk statements with a proposed owner and due date, and a residual risk view to accept or change.

Issue management

Every accepted finding tracked through to closure.

Exit and resilience checks

Exit terms reviewed, with a note wherever a vendor has no practical fallback.

Audit-ready trail

Every decision recorded with the evidence behind it.

How we are building it

Founder-led, based in London, and shaped by experience in regulation, supervision and third-party risk.

People decide, regAIx drafts

Risk judgement stays with the analyst. The tool saves reading and drafting time, not sign-off.

Every finding points to its evidence

A finding that cannot be traced to its source is not worth acting on.

For any team that depends on vendors

Cloud, software and data suppliers raise the same questions in every sector.

Tell us where vendor reviews slow down

If you run or support a third-party risk programme, we would like to hear where assessments and follow-up take your team the longest.

Email hello@regaix.ai