Managing third-party cyber risk has become one of the biggest challenges facing modern enterprises as organisations rely on an expanding ecosystem of cloud providers, software vendors and technology partners. Commugen’s launch of specialised AI agents for Third-Party Risk Management reflects a broader shift towards automating what has traditionally been a labour-intensive compliance process. By continuously analysing vendor security posture, gathering cyber threat intelligence and identifying external vulnerabilities, the new platform aims to help security teams move beyond periodic assessments towards real-time, data-driven risk management. The launch underscores how AI is increasingly being applied to strengthen governance, compliance and operational resilience rather than simply improving productivity.
Cybersecurity and compliance automation provider Commugen has announced the commercial launch of three specialised artificial intelligence agents purpose-built for Third-Party Risk Management (TPRM) and integrated natively into Commugen’s overarching Cyber GRC platform. The newly deployed autonomous agents are engineered to automate vendor security reviews, open-source cyber threat intelligence gathering, and non-intrusive external vulnerability scanning. The release marks a significant operational shift for information security teams, transitioning vendor diligence from highly manual, point-in-time checkouts into an ongoing, scalable risk-monitoring environment.
The deployment targets an increasingly severe landscape of supply chain vulnerabilities. Modern enterprise organisations routinely rely on hundreds or thousands of external vendors, software-as-a-service providers, and contractors, each creating secondary entry points into internal production networks and proprietary customer data pools. This interconnected architecture has made third-party infrastructure a primary vector for sophisticated ransomware groups and corporate threat actors seeking a backdoor into larger enterprises. Concurrently, strict regional regulatory mandates, such as Europe’s Digital Operational Resilience Act (DORA), the NIS2 directive, and standardised SOC 2 or ISO 27001 audit frameworks, increasingly require chief information security officers (CISOs) to demonstrate continuous, audit-ready oversight of their entire software and partner supply chain.
Despite these heightened macro risks, traditional vendor risk evaluation remains heavily dependent on spreadsheets and long-form compliance questionnaires. Security analysts frequently spend days manually cross-referencing vendor self-disclosures against independent penetration test summaries, business continuity plans, and structural network certificates. Commugen’s new AI operating layer replaces this slow manual process with three distinct, task-oriented agents that operate sequentially within the organisation’s existing risk workflows.
The first node, the AI Evidence Analysis agent, systematically digests completed vendor questionnaires alongside attached certifications. Instead of simply highlighting blank fields, the agent extracts semantic meaning to detect internal discrepancies, flag expired compliance documents, identify weak operational controls, and mathematically map structural deficiencies back to the client’s internal risk taxonomy. Initial platform implementation telemetry indicates that automating these administrative reviews reduces the raw evidence-processing overhead for security teams by up to 70 per cent.
The second node, the AI Cyber Threat Intelligence agent, mitigates the inherent risk of vendor self-reporting bias by executing continuous open-source intelligence research. By simply querying a partner’s legal entity name, the agent scans public incident databases, dark web credential dumps, security blogs, and corporate breach disclosures to compile an objective, historical risk dossier, complete with verifiable references. This intelligence layer is augmented by the third node, the AI External Vulnerability Scanning agent, which evaluates a supplier’s internet-facing digital footprint to isolate active CVEs, outdated cryptographic protocols, exposed server endpoints, and localised SSL/TLS configuration errors, synthesising the aggregate technical risk into an actionable security score. The rollout follows Commugen’s recent expansion of its governance platform, which already includes domain-specific agents for automated policy generation, mitigation workflow planning, and plain-language risk quantification reports.
What it means for the industry
- Third-party risk management is evolving from periodic compliance exercises into continuous, AI-driven monitoring of supplier security and resilience.
- Organisations are increasingly using AI agents to automate repetitive governance and compliance tasks, allowing security teams to focus on higher-value risk analysis.
- Growing regulatory requirements such as DORA, NIS2 and global cybersecurity standards are accelerating investment in automated governance and risk management platforms.
- Vendor security is becoming a board-level priority as software supply chains continue to expand the potential attack surface for enterprises.
- AI-powered threat intelligence and external vulnerability monitoring provide organisations with a more objective view of supplier risk than self-reported questionnaires alone.
- Governance, Risk and Compliance (GRC) platforms are rapidly evolving into intelligent decision-support systems that continuously assess, prioritise and respond to cyber risk across the enterprise.
Image Source: Pexels.com

