Trustero TPRM uses AI to review vendor risk documents

Trustero TPRM uses AI to review vendor risk documents

Trustero has launched Trustero Third-Party Risk Management (TPRM), a product that applies the company's AI engine to the vendors and partners an organization relies on, not only to its own compliance program. Security and compliance teams no longer collect and read vendor documentation themselves. They get a recommended risk determination, which they then review and approve.

The launch targets a part of security work that many teams see as tedious. Every new supplier, SaaS provider or service partner brings attestations, questionnaires and reports, and someone has to read them.

A logistics problem more than an analysis problem

Trustero describes vendor risk management as mostly a matter of logistics. Teams spend their time chasing attestations, keeping track of who owns which vendor, and working through questionnaires and audit reports.

According to the company, most organizations still do this in spreadsheets, single-purpose tools, or systems that don't talk to each other. That slows down deals that depend on a vendor being approved, and it leaves gaps where nobody has a clear view of a supplier's risk.

TPRM combines an agentic orchestrator with the AI engine Trustero already uses to automate evidence collection and control monitoring inside its platform. The orchestrator handles the workflow, and the AI engine handles the reading and the first assessment.

How the product works

The company lists four main capabilities.

Risk tiering. Customers set their own tiers, and each tier decides how deep an assessment goes. Vendors considered low risk go through minimal vetting. Vendors in the highest tier are asked for ISO 27001 certifications (ISO 27001 is the international standard for information security management systems), proof of insurance, details on their funding status, and answers to questions specific to cloud services.

AI first-pass evaluation. Trustero compares attestations, security questionnaires and other vendor material against the customer's own risk policies. The result is a risk determination that the team reviews instead of building it from scratch.

Orchestrated requests. The orchestrator tracks changes and pushes each assessment forward without manual prompting. When a step needs a person or an external system, it becomes a tracked request with an assigned owner and an escalation path. Trustero gives examples such as pulling information from a vendor's trust portal, getting a third-party risk score, or obtaining sign-off from finance or legal.

Unified platform. TPRM runs on the same platform as the customer's existing compliance program. Vendor risk data stays next to the rest of the compliance data and does not sit in a separate tool.

Humans keep the final say

Trustero is clear that the AI makes recommendations and does not make decisions. A person reviews and approves every conclusion.

"Most vendor risk tools hand a team a score or a stack of documents and call it done," said David Marsyla, VP of Engineering at Trustero. "We wanted TPRM to work the way the rest of Trustero does: the AI does the reading and the first-pass judgment, and the team's time goes to the approval decision, not the analysis."

Cybersecurity leader Chris Oshaben said the product is meant to fit into existing processes. "Trustero isn't asking you to rip out your vendor management workflow," he said. "It sits at the checkpoints where assessors lose the most time and speeds them up, with a human reviewing every conclusion. That's the kind of AI security leaders can actually adopt today."

The pitch rests on that point. Trustero is not replacing the vendor review process. It is speeding up the stages where assessors lose the most time, which are reading documents, chasing missing evidence and keeping track of who still owes what.

Our Take

Third-party risk is a familiar weak spot. Organizations depend on more suppliers than ever, and every supplier adds attack surface. Many vendor reviews still come down to someone skimming a questionnaire at the end of a long week. Tools that take over the reading and the follow-ups could make thorough reviews realistic for teams that currently only do a fraction of them.

Trustero's emphasis on human approval fits a wider pattern in security products this year, where AI ranks or drafts and a person decides. Sophos' AI-driven prioritization of security fixes takes a similar approach. That model is easier to defend to auditors and boards than fully autonomous decisions.

The key questions are about accuracy and accountability. A first-pass determination is only as good as the policies it is checked against and the documents vendors provide. Approvers will need to resist signing off by default. It is also worth watching how agentic orchestrators handle access to trust portals and other external systems, given recent findings that AI agents can keep data access after tasks end. Readers evaluating such tools should ask how the AI's reasoning is documented and how much of it a reviewer can actually check.