Summary
- Drata's agentic TPRM product automates vendor intake, risk tiering, evidence collection, assessment, residual-risk evaluation, and decision tracking.
- The system cites supporting evidence for findings and applies customer-defined assessment criteria rather than relying solely on questionnaire scores.
- Drata began offering TPRM independently on 1 September, so the current announcement expands an existing commercial launch rather than introducing the underlying capability for the first time.
Third-party risk management is becoming another test case for agentic enterprise software, with Drata making its automated vendor-assessment system available as a standalone product and trying to replace periodic questionnaire scoring with decisions tied directly to supporting evidence.
Drata says its TPRM product can handle vendor intake, inherent-risk classification, evidence collection, criteria-based assessment, residual-risk calculation, reporting, and decision tracking in a single workflow. Reviewers remain responsible for evaluating the findings and making the final vendor decision.
The underlying agentic capability was publicly documented before this week’s announcement. Drata published it as a major product release on 9 September, while its own guidance says the product became available independently of the wider compliance platform on 1 September. The current announcement is therefore a broader commercial push around standalone availability rather than the first introduction of Drata’s third-party risk technology.
The underlying workload is substantial. Security and governance teams can accumulate hundreds or thousands of software suppliers, cloud services, processors, contractors, and other external relationships, while detailed reviews remain labour-intensive enough that organisations routinely divide vendors into those receiving close scrutiny and those receiving a lighter process.
The agent reads before the reviewer does
Traditional vendor assessment often starts with a questionnaire asking a supplier whether specified controls exist, producing a score that helps the customer decide whether further investigation is necessary. Drata is attempting to reverse more of that process by collecting evidence first and evaluating it against criteria defined by the customer.
The product can ingest documentation from public or private Trust Centers, uploaded files, or requests sent to suppliers. Its agent then evaluates evidence against assessment criteria and provides supporting citations for individual findings, allowing the reviewer to inspect the material behind a result rather than accept an unexplained score.
Inherent risk is treated separately from residual risk. The first stage asks how consequential a vendor relationship would be before considering its controls, using the customer’s own rules and contextual information to determine the depth of review. Residual risk is assessed after evidence about the supplier’s security posture has been considered.
That structure is familiar to risk practitioners, although automating the judgement changes where effort is spent. Instead of manually reading every security report or questionnaire before forming an opinion, a reviewer is being asked to inspect an AI-produced assessment and decide whether the evidence and reasoning support it.
The productivity argument depends heavily on that verification step. If reviewers routinely have to reread every document in full because they cannot trust the agent’s interpretation, much of the labour saving disappears. If they accept results too readily, an automated assessment can turn an error into a consistent process applied across hundreds of suppliers.
Drata therefore emphasises traceability and human oversight rather than presenting the product as an autonomous approval engine. Its September product documentation states that reviewers remain responsible for evaluating findings and making final vendor decisions.
European rules raise the evidence requirement
Although Drata is headquartered in the United States, the product has a direct European market because supplier oversight is embedded in several regulatory regimes. The Digital Operational Resilience Act requires financial organisations to manage ICT third-party risk, while NIS2 includes supply-chain security within broader cybersecurity risk-management requirements.
Drata already markets control and evidence workflows for DORA and NIS2, and its TPRM system is positioned as a way to assess suppliers against those wider governance obligations. Neither regulation prescribes Drata’s product or requires the use of agentic AI, but both increase the value of being able to show how a vendor was assessed and what evidence supported the decision.
Auditability becomes particularly important where security teams are automating professional judgement rather than repetitive data entry. A regulator, auditor, or internal risk committee may be less interested in the numerical score assigned to a supplier than in why a control was considered adequate, what documentation was reviewed, and whether the assessment was current when the contract was approved.
Drata’s approach addresses that requirement by retaining an evidence chain behind findings, although the system still depends on the quality and completeness of the documents it receives. A polished assessment cannot identify a control failure that a supplier’s evidence does not reveal, while reports such as SOC 2 documents remain bounded by their audit scope and period.
The company is also responding to AI itself as a supplier-risk problem. Its State of GRC research says 75% of IT and security professionals believe AI adoption is moving faster than their ability to vet third parties properly. As suppliers add models, AI features, subprocessors, and external services, customers have more questions to ask about data use, governance, and the systems sitting behind a nominally familiar software product.
Automation can broaden the percentage of a vendor portfolio receiving structured review, but coverage and depth are not the same thing. Assessing every supplier with the same workflow may improve consistency while still producing weak decisions if criteria are poorly written, evidence is incomplete, or reviewers lack the expertise to challenge the agent’s output.
The more interesting change is therefore not that a GRC platform now contains AI. Drata is putting the model into the judgement layer of a process whose output can determine whether another company is trusted with systems or data.
A vendor-risk decision may have to survive questions from an auditor, regulator, security leader, or procurement team months after the original assessment. Drata’s commercial proposition is that an agent can do enough collection and analysis to expand coverage while preserving the evidential trail needed for a human to defend the final decision.












