Vendor and regulatory due-diligence briefing agent
Problem
Before signing off a new vendor or system, someone on the IT or security team has to establish what that vendor actually claims about data handling, security certification and accessibility, and none of it lives in one place. They open the vendor's website, hunt for a security or trust page, check whether a data processing agreement is offered at all, and skim a subprocessor list if one exists. Findings get pasted into an email thread or a procurement document, alongside a vendor risk spreadsheet on a shared drive that nobody updates once the deal closes. For a small purchase the research gets skipped entirely because nobody has a day to spend on it, and the next renewal starts from zero again.
Product idea
A research agent that takes a vendor name and product page and works through the organisation's own due-diligence checklist item by item: does the vendor publish a security or trust page, is a data processing agreement offered, is a subprocessor list disclosed, is there an accessibility conformance statement, and what data protection law does the vendor say it aligns with. Each answer carries a link back to where it was found. Anything it cannot verify publicly is marked as not found rather than inferred, with a short list of questions to put to the vendor directly. It does not score the vendor or recommend a decision; it hands the reviewer a briefing to read before that call.
Who it is for
Heads of IT and information security officers preparing for a procurement decision, and data managers who need to know what a vendor claims about data handling before signing. Sponsored by the Head of IT.
Possible first version
A form that takes a vendor name and public website address, checked against a fixed due-diligence checklist covering security certification, data processing agreement availability, subprocessor disclosure and accessibility statements. The agent researches each item from public pages only, produces a briefing document with source links and a list of unanswered questions, and lets the reviewer edit before sharing. Out of scope for version one: no login to vendor security portals behind a non-disclosure agreement (NDA), no scoring or approve/reject workflow, and no write-back into a procurement or vendor risk system.
- Build classification
- Micro-tool
- Rough effort
- 1-2 week prototype
- Roles involved
- Head of IT, Information security officer, Data manager
- Relevant to
- Professional club, League office, Federation / governing body, Venue & stadium operator, Collegiate athletics
- Systems in play
- Document management and intranets, Service desk and ticketing tools, Spreadsheets
- Product framing
- Research
Questions we get asked
What do we need to give it before it can produce anything useful?
A vendor name, the product's public website, and your own due-diligence checklist, the list of things you already ask every vendor about security, data handling and accessibility. Most organisations have that checklist somewhere, even if it is a document nobody has opened in a year. The agent works from what is publicly published; it does not need an account with the vendor or a signed non-disclosure agreement (NDA) to start.
Does this replace the vendor risk questionnaire we already send out?
No. The questionnaire you send is answered directly by the vendor and stays the authoritative record. This tool does something earlier: it gathers what the vendor already publishes before anyone sends a questionnaire, so the reviewer walks into that conversation knowing what is already public and what still needs asking. It sits in front of your existing process, not instead of it.
How do we know it isn't inventing a compliance claim to fill a gap?
It only reports what it can point to on a public page, with the link attached, and every item it cannot find is marked as not found rather than guessed. That is a deliberate constraint. A briefing that confidently states a vendor holds a certification it does not have is worse than no briefing at all, so the agent is built to say 'not published' far more often than a polished report would like.
Does it decide whether we should approve the vendor?
No, and it should not. It produces a briefing, not a verdict. The approval decision still runs through whatever committee or sign-off your organisation already uses, and stays with a named person who can be held accountable for it. Version one also does not log into any vendor portal that sits behind a password or an NDA; if the evidence is not public, it goes on the list of questions to ask the vendor directly rather than being retrieved another way.
Is this your workflow?
Tell us one sports workflow that still runs on paper, spreadsheets, WhatsApp or an outdated system. We will map it and show you what a simpler product looks like.
Tell us about itMore in IT, data, compliance & knowledge
- Access review attestation trackerReplaces the emailed access-review spreadsheet with a per-user confirm-or-revoke task for each system owner, producing a timestamped attestation record for audit.
- Certificate and domain renewal obligation registerA register of every TLS certificate and domain name renewal date across the technology estate, with a named owner and escalation before one lapses and takes a service down.
- Data retention and deletion obligation registerA register that tracks retention deadlines for datasets holding personal data across the technology estate and escalates to a named owner before deletion or review falls overdue.