Agents / Operational & Third-party Risk
Vendor Risk Assessment Agent
Prepares third-party risk assessments for vendor arrangements.
Runs, last 30 days
64
Tools
4
Data scopes
3
Human checkpoints
2
About this agent
Prepares third-party risk assessments for new and renewing vendor arrangements. It reads the contract, the vendor's security questionnaire and certificates, checks them against the BNM Policy Document on Outsourcing and BNM RMiT requirements, and drafts an assessment with gaps and suggested contract clauses for the third-party risk reviewer.
Tools4
- Gemini on Vertex AI (credit-memo-summariser)
- Regulatory clause search (regulatory-clause-retriever)
- Vendor register
- Third-party risk system: assessment writer
Data access scope3
- Read-only: vendor contracts, questionnaires and certificates in the vendor register
- Write: draft assessments to the third-party risk system only
- No access to customer data
Guardrails3
- Material outsourcing decisions always go to a human reviewer
- Every gap cites the requirement it is measured against
- Does not contact vendors directly
Human-in-the-loop2
- Third-party risk reviewer approves every assessment
- Material outsourcing arrangements go to the Outsourcing Committee
Orchestration
Every tool call is scoped by the declared data access above; the orchestrator cannot reach systems outside it. Owning business unit: Group Risk Management.
Ownership and sensitivity
Who approves access
- Owner, Operational & Third-party Risk, Aminah Yusof
- Operational & Third-party Risk, Aminah Yusof
Business-sensitive. Models and data products scoped to named business units.
Entitlement per business unit, approved by the owner; conditions attach.
- Third-party
- Supplied by an approved vendor; outsourcing and third-party risk controls apply.
- GenAI
- Generates text; prompt screening for customer data and output review apply.
Community · 0 threads
Questions, findings and requests from the business units that use this asset. Owners reply here; threads with upvotes surface to the owning team's inbox.
Live demo run
Watch the agent execute a real scenario step by step, every tool call, validation, and human checkpoint is traced and auditable. Typical run: ~10.1s.
Audit
Updated 2026-07-10. Run traces retained 24 months for audit under the platform governance policy.