Will AI Agents Make Third-Party Risk Management Smarter, or Just Faster?

ProcessUnity said this week that one early customer, a large global technology and consulting firm, has cut third-party intake cycle time by 54%, improved assessment throughput by 43%, and reduced incomplete inherent-risk questionnaires by 75% since putting AI agents to work. Those are vendor-supplied numbers from a single early adopter and deserve to be read that way. But the size of the numbers is not the story. The story is the kind of work the agents are being allowed to do.

The September 1 launch of ProcessUnity AI Agents for TPRM puts task-specific agents to work across the third-party lifecycle: screening intake, drafting inherent-risk questionnaire responses, flagging duplicate vendors, analyzing SOC 2 reports, scanning contracts, validating certificates of insurance, writing remediation instructions, and preparing executive risk summaries. Every judgment call is routed to a human subject matter expert, and agent activity lands in an audit trail. A no-code Agent Architect lets analysts build their own agents without a development project.

That is a different product category from the copilots and document summarizers that have dominated RiskTech AI announcements for two years. It is also not autonomous risk management, whatever the launch vocabulary implies. Four other developments in the same week explain why the difference matters.

This Is Agentic, Not Autonomous, and the Distinction Matters

Wheelhouse Advisors draws a firm line between the two. An agentic system investigates, drafts, and recommends, then waits for a human to approve before anything changes. An autonomous system detects, decides, acts, and verifies without a handoff. By its own description, ProcessUnity has built the former. The agents do the reading and the drafting, and humans keep the decisions that matter. The line was already needed in May, when IBM, Optro, and ServiceNow each claimed autonomous capability in the same news cycle while describing architecturally different things.

Agentic is the right design for 2026, and it is a meaningful step. Two years of generative AI in GRC produced faster documentation, better search, and suggested controls. Productivity improved. The risk operating model did not change. Agents that carry out defined pieces of the workflow, consume program-specific context, and produce structured, auditable outputs change the operating model itself. AI has moved from helping people do risk work to doing a share of the work.

Hyperproof's 2026 benchmark shows how early that shift still is. Ninety-seven percent of GRC teams use AI somewhere in their workflows. Only 27% have operationalized it for external assurance, the category that includes vendor security questionnaires. Most usage remains internal research and documentation. The lesson is that “we use AI” is about to become a meaningless maturity claim, because nearly everyone will be able to make it. The useful question is what the AI has been authorized to identify, assess, recommend, and do, and under whose authority.

The Program the Agents Are Joining Is Not Integrated

Here is where the ProcessUnity news collides with a much less flattering dataset.

KPMG's 2026 Global Third-Party Risk Management Survey of 851 organizations found that only 18% have fully integrated TPRM with enterprise risk management. Seventy-one percent plan more integration over the next three years, which is another way of saying most have not done it yet. Only 17% describe their TPRM data as fully reliable. Between 50% and 58% already use AI in third-party risk, and only 22% call those implementations very effective.

KPMG's conclusion deserves attention from every buyer evaluating risk agents. The most effective AI implementations connect processes across the end-to-end workflow and keep ownership intact from start to finish. Siloed, single-step agents underperform.

That finding is not really about AI. It is about integration. An agent can analyze a supplier flawlessly and still have no idea how that supplier relates to an important business service, a strategic objective, a technology dependency, a concentration exposure, or the enterprise risk appetite. When the data feeding the agent is reliable in fewer than one program in five, and the connection to ERM exists in fewer still, what has been automated is TPRM. Integrated Risk Management has not been touched.

Faster Silos Are Still Silos

The last decade of RiskTech digitized risk one domain at a time. GRC platforms automated controls and compliance. ERM tools digitized the risk register. TPRM systems automated supplier assessments. Security platforms accumulated exposure data. Continuity tools modeled disruption. Each domain got its own system, its own data model, and its own workflow.

Agents now make each of those systems dramatically more efficient inside its own boundary. Efficiency inside a domain does not produce intelligence across domains. The outcome, absent deliberate design, is an automated silo architecture: hundreds of specialized agents doing local risk work extremely well while nobody, human or machine, can see their collective effect on enterprise objectives.

ProcessUnity's no-code Agent Architect makes this a live concern rather than a hypothetical. The company describes a program's automation footprint expanding “at the speed of its own governance.” That is an honest phrase, and it cuts both ways. Where governance is strong, custom agents will multiply inside a coherent operating model. Where governance is weak, they will multiply anyway. The RiskTech Journal named that pattern agent sprawl in May, and an August survey covered here found that five in six large-company executives with AI governance in place still do not consider their organizations ready to run AI.

The same week offered a glimpse of the alternative. Everbridge's acquisition of Open Measures, announced September 2, folds open-source intelligence from more than 45 digital sources into critical event management, with the stated aim of connecting weak external signals to the specific people, locations, assets, and operations they threaten. That is integration logic: signal, context, prioritization, and response in one chain. Third-party risk agents need the same chain, running through the enterprise rather than stopping at the vendor file.

The Questions Buyers Should Be Asking Now

The question for organizations adopting risk agents is no longer whether AI belongs in TPRM. It does. The harder questions are architectural. What information can the agent see beyond its own domain? Which enterprise objectives and assets give context to its recommendations? What authority has been delegated to it, and which decisions stay with a human? Where is evidence retained, and for how long? How does the organization learn when one agent's action shifts exposure somewhere else? And who, or what, decides when an automated third-party decision has become an enterprise risk decision?

Those questions sit at the boundary between today's GRC platforms and an Autonomous IRM architecture. The IRM Navigator Model treats risk management as an operating model spanning GRC, ERM, technology risk, and operational risk rather than a collection of applications, precisely because that boundary is where value is created or lost. Last week's Risk Wheelhouse episode turned the same boundary into a buyer playbook: action boundaries, policy inheritance, evidence by design, and reversibility.

The workforce implication follows directly. Writing in The Wall Street Journal this week, Optro's Justin Greenberger argues that AI-era audit teams need professionals who combine risk expertise with systems architecture, enterprise data flows, and control-pattern analysis. He calls the role the audit engineer. The same profile is what a risk agent deployment needs on the buyer side: someone who can trace how data, controls, systems, and automated decisions interact before the agents start acting on them.

ProcessUnity's announcement matters for reasons larger than third-party risk. It shows agent-level risk execution moving from concept to shipped product, with human authority and audit evidence designed in. That is the right starting point. Whether it reduces enterprise risk depends on a decision the vendor cannot make for its customers: integrate first and then automate, or automate first and hope integration follows.

An automated silo is still a silo. It simply moves faster.

How security platforms and IRM platforms are converging on the System of Action that would connect those silos is the subject of “The Two Roads to Autonomous IRM,” available exclusively on The RTJ Bridge.

References

1.ProcessUnity, “ProcessUnity Launches AI Agents That Cut Third-Party Risk Busywork,” September 1, 2026. https://www.processunity.com/resources/press-releases/processunity-launches-ai-agents-for-tprm/

2.KPMG, The 2026 KPMG Global Third-Party Risk Management Survey. https://kpmg.com/xx/en/our-insights/risk-and-regulation/the-2026-kpmg-global-third-party-risk-management-survey.html

3.Hyperproof, “GRC Teams Scale AI Governance: Insights from the 2026 IT Risk and Compliance Benchmark,” August 2026. https://hyperproof.io/resource/grc-teams-scale-ai-governance-insights/

4.Everbridge, “Everbridge Acquires Open Measures to Expand Risk Intelligence Capabilities,” September 2, 2026 (Business Wire). https://finance.yahoo.com/technology/ai/articles/everbridge-acquires-open-measures-expand-123000640.html

5.The Wall Street Journal, CFO Journal, “Advice for Auditors in the AI Era,” September 4, 2026. https://www.wsj.com/cfo-journal/advice-for-auditors-in-the-ai-era-30bc6a84

6.Wheelhouse Advisors, “IRM50 OnWatch: The Week that Autonomous IRM Hit the Market,” The RTJ Bridge, May 13, 2026. https://www.wheelhouseadvisors.com/rtj-bridge/irm50-onwatch-the-week-that-autonomous-irm-hit-the-market

7.Wheelhouse Advisors, “The Two Roads to Autonomous IRM,” The RTJ Bridge, September 3, 2026. https://www.wheelhouseadvisors.com/rtj-bridge/the-two-roads-to-autonomous-irm

Ori Wellington

Orion “Ori” Wellington is the lead editor for The RiskTech Journal and The RTJ Bridge, where he helps shape editorial direction, guide strategic narratives, and support media relations across Wheelhouse Advisors. As a digital editorial advisor, Ori synthesizes trends in risk, technology, and governance, drawing from roles modeled on information security, risk analytics, and IT leadership.

Part of Wheelhouse’s AI-augmented research team, Ori works to distill complex signals into actionable intelligence—bridging expertise across domains and elevating the voice of integrated risk thinking.

https://wheelhouseadvisors.com
Next
Next

IRM Market Brief: August 25 to 31, 2026