SportsFirst

Vendor and regulatory due-diligence briefing agent

AI agentMicro-tool1-2 week prototypeResearchPrototype-ready

Problem

Before signing off a new vendor or system, someone on the IT or security team has to establish what that vendor actually claims about data handling, security certification and accessibility, and none of it lives in one place. They open the vendor's website, hunt for a security or trust page, check whether a data processing agreement is offered at all, and skim a subprocessor list if one exists. Findings get pasted into an email thread or a procurement document, alongside a vendor risk spreadsheet on a shared drive that nobody updates once the deal closes. For a small purchase the research gets skipped entirely because nobody has a day to spend on it, and the next renewal starts from zero again.

Product idea

A research agent that takes a vendor name and product page and works through the organisation's own due-diligence checklist item by item: does the vendor publish a security or trust page, is a data processing agreement offered, is a subprocessor list disclosed, is there an accessibility conformance statement, and what data protection law does the vendor say it aligns with. Each answer carries a link back to where it was found. Anything it cannot verify publicly is marked as not found rather than inferred, with a short list of questions to put to the vendor directly. It does not score the vendor or recommend a decision; it hands the reviewer a briefing to read before that call.

Who it is for

Heads of IT and information security officers preparing for a procurement decision, and data managers who need to know what a vendor claims about data handling before signing. Sponsored by the Head of IT.

Possible first version

A form that takes a vendor name and public website address, checked against a fixed due-diligence checklist covering security certification, data processing agreement availability, subprocessor disclosure and accessibility statements. The agent researches each item from public pages only, produces a briefing document with source links and a list of unanswered questions, and lets the reviewer edit before sharing. Out of scope for version one: no login to vendor security portals behind a non-disclosure agreement (NDA), no scoring or approve/reject workflow, and no write-back into a procurement or vendor risk system.

Build classification
Micro-tool
Rough effort
1-2 week prototype
Roles involved
Head of IT, Information security officer, Data manager
Relevant to
Professional club, League office, Federation / governing body, Venue & stadium operator, Collegiate athletics
Systems in play
Document management and intranets, Service desk and ticketing tools, Spreadsheets
Product framing
Research

Questions we get asked

What do we need to give it before it can produce anything useful?

A vendor name, the product's public website, and your own due-diligence checklist, the list of things you already ask every vendor about security, data handling and accessibility. Most organisations have that checklist somewhere, even if it is a document nobody has opened in a year. The agent works from what is publicly published; it does not need an account with the vendor or a signed non-disclosure agreement (NDA) to start.

Does this replace the vendor risk questionnaire we already send out?

No. The questionnaire you send is answered directly by the vendor and stays the authoritative record. This tool does something earlier: it gathers what the vendor already publishes before anyone sends a questionnaire, so the reviewer walks into that conversation knowing what is already public and what still needs asking. It sits in front of your existing process, not instead of it.

How do we know it isn't inventing a compliance claim to fill a gap?

It only reports what it can point to on a public page, with the link attached, and every item it cannot find is marked as not found rather than guessed. That is a deliberate constraint. A briefing that confidently states a vendor holds a certification it does not have is worse than no briefing at all, so the agent is built to say 'not published' far more often than a polished report would like.

Does it decide whether we should approve the vendor?

No, and it should not. It produces a briefing, not a verdict. The approval decision still runs through whatever committee or sign-off your organisation already uses, and stays with a named person who can be held accountable for it. Version one also does not log into any vendor portal that sits behind a password or an NDA; if the evidence is not public, it goes on the list of questions to ask the vendor directly rather than being retrieved another way.

Is this your workflow?

Tell us one sports workflow that still runs on paper, spreadsheets, WhatsApp or an outdated system. We will map it and show you what a simpler product looks like.

Tell us about it

More in IT, data, compliance & knowledge