Skip to content
← All AI assets

Autonomous compliance agent · AI risk governance

AI Vendor Risk Assessment Agent

An autonomous compliance agent built with Rovo Architect that independently investigates third-party AI vendors across internal tickets, policies, DPAs, and web docs to generate evidence-backed risk scores and publish-ready Confluence assessments in minutes.

My role
Sole designer & AI architect
Tools
Atlassian Rovo, Confluence API, Jira API, MX AI Risk Rubric, Web Investigation
Who it helps
IT Security, Procurement, AI Governance leads, and technical leaders evaluating third-party AI tools and vendor integrations for enterprise adoption.
How it works
Takes a 4-item minimal intake (vendor/tool, URL, MX use case, data sent), autonomously searches Confluence, Jira, vendor DPAs, security trust portals, and web sources, calculates weighted scores across 5 risk clusters, and formats a publish-ready Confluence page.
My contribution
Designed, prompted, and calibrated the agent using Rovo Architect; implemented MX's 5-cluster AI Risk Scoring Rubric, conservative-by-default scoring logic, and automated Confluence publishing pipeline.
Why it’s valuable
Reduced vendor AI risk assessments from hours or up to a week of manual security/procurement review down to minutes, while eliminating undocumented scoring assumptions and enforcing 100% evidence attribution.

Approach

  1. Built the agent using Rovo Architect to enforce conservative-by-default evaluation rules and auditable evidence standards.
  2. Designed a 4-item minimal intake protocol (vendor/tool, product URL, specific MX use case, data classification touchpoints) that prevents user interrogation while capturing critical context.
  3. Implemented automated multi-channel research across internal Confluence/Jira spaces, vendor DPAs/whitepapers, SOC 2/ISO certifications, model cards, and web databases.
  4. Configured the 5-cluster weighted scoring engine covering Inherent System Risk, Performance & Reliability, Security & Compliance, Data Risk, and Operational Modifiers.
  5. Engineered strict evidence rules: mandatory citations, 'Insufficient Evidence — Assumed High' defaults, and explicit human confirmation before creating Confluence pages.
  6. Demonstrated the agent to the Head of IT, validating its end-to-end evidence gathering and rubric scoring against production vendor evaluations.

Outcomes

  • Cut vendor risk assessment turnaround time from hours or up to a week down to a few minutes.
  • Demonstrated to the Head of IT, receiving immediate validation for speed, rigor, and publish-ready depth.
  • Enforced 100% evidence attribution on all scored indicators, eliminating unverified assumptions in vendor onboarding.
  • Standardized multi-tier risk scoring (Low, Medium, High, Critical) directly linked to required governance controls (monitoring, audit logs, kill-switches).

What I learned

  • An AI compliance agent must be conservative by default: when evidence is missing or ambiguous, assuming high risk protects the organization and flags gaps immediately.
  • The agent must act as an independent analyst, not a form: finding public vendor DPAs, SOC 2 data, and sub-processor lists is the agent's job, not the user's.
  • Presenting clear modifier dynamics (human oversight, criticality of decision) helps teams understand how their specific implementation changes the vendor's net risk profile.

Overview

As enterprise teams adopt generative AI and specialized AI vendors, evaluating third-party AI risk becomes a severe operational bottleneck. Evaluating a single vendor’s AI capabilities, training data handling, sub-processors, security certifications, and model governance typically required:

  • Days of back-and-forth between procurement, security, and the requesting team.
  • Manual searches across vendor Trust Centers, Data Processing Addenda (DPAs), SOC 2 reports, and internal Jira security review tickets.
  • Subjective risk scoring prone to inconsistent human interpretation.

Built with Rovo Architect, the AI Vendor Risk Assessment Agent acts as an autonomous compliance analyst. Given only the vendor name, product link, intended use case, and data exposure profile, the agent executes an exhaustive internal and external investigation, scores the tool against MX’s formal AI Risk Scoring Rubric, and formats a complete, publish-ready Confluence evaluation in minutes.


Core Operating Principles

The agent operates under strict governance rules to ensure enterprise-grade reliability:

  1. Research First, Ask Second: The user is never treated like a search engine. The agent asks only for internal context (the intended MX use case and data classification); all vendor documentation, DPAs, certifications, and model cards are investigated autonomously.
  2. Conservative by Default: If evidence is ambiguous, the agent assigns the higher-risk score. If evidence cannot be found after exhausting internal and external channels, it assigns Insufficient Evidence — Assumed High to highlight the gap.
  3. 100% Evidence Attribution: Every scored indicator must cite a specific source (document name, URL, Jira ticket, or Confluence page) with a one-sentence justification.
  4. Present Findings, Don’t Make Procurement Decisions: The agent calculates risk scores, identifies risk tiers, and specifies required controls per policy. Humans retain final approval authority.
  5. Human Gate Before Publishing: The agent generates a complete in-chat preview for review and only publishes to Confluence upon explicit human confirmation.

The 5-Cluster Risk Scoring Framework

The agent evaluates third-party AI tools across five weighted clusters, producing an objective composite score mapped directly to required operational controls:

┌─────────────────────────────────────────────────────────────┐
│              AI VENDOR RISK SCORING ENGINE                  │
├──────────────────────────────┬──────────────────────────────┤
│ 1. Inherent System Risk      │ Interpretability, Generative │
│    (Range: 3 – 21)           │ Capacity, Agentic Autonomy   │
├──────────────────────────────┼──────────────────────────────┤
│ 2. Performance & Reliability │ Benchmarks, Bias, Fairness,  │
│    (Range: 1 – 13)           │ Robustness, Explainability   │
├──────────────────────────────┼──────────────────────────────┤
│ 3. Security & Compliance     │ Surface, Posture, 4th Party, │
│    (Range: 1 – 11)           │ Adversarial Risk, Certs      │
├──────────────────────────────┼──────────────────────────────┤
│ 4. Data Risk                 │ Training on MX Data, Memory, │
│    (Range: 0 – 16)           │ Filtering, PII Classification│
├──────────────────────────────┼──────────────────────────────┤
│ 5. Operational Modifiers     │ Human Oversight Level,       │
│    (Range: -7 to +5)         │ Decision-Critical Use Impact │
└──────────────────────────────┴──────────────────────────────┘
                               │ Sum

┌─────────────────────────────────────────────────────────────┐
│                  GOVERNED RISK TIERS                        │
│  • Low (-2 to 20): Internal docs & basic model card         │
│  • Medium (21 to 45): Human-in-the-loop review in SOP/tool  │
│  • High (46 to 55): Periodic audit & escalation pathways    │
│  • Critical (56 to 66): Exec review, red-teaming, kill-switch│
└─────────────────────────────────────────────────────────────┘

Risk Indicators Breakdown

ClusterIndicatorEvaluated Risk States
Inherent System RiskInterpretability LevelTransparent (1) · Partially Interpretable (4) · Opaque/Black Box (7)
Generative CapacityNone (1) · Template-Based (4) · Context-Limited (4) · Open-Ended (7)
Agentic ProfileNone (1) · Limited Autonomy (4) · Fully Autonomous (7)
Performance & ReliabilityPerformance MetricsHigh (0) · Medium (1) · Low (2) · Not Available (3)
Bias AssessmentComplete (1) · Partial (2) · None (3)
Robustness & FairnessFormally Tested (0) · None (2)
Explainability MethodSHAP/LIME/Other (0) · None (2)
Security & ComplianceAccess SurfaceInternal (1) · External API (2) · Public (3)
Security PostureHardened (0) · Baseline (1) · Unverified (2)
4th Party AI RiskNone (0) · Moderate (1) · High (2)
CertificationsNIST / ISO 27001 / SOC 2 (0) · Other (1) · None (2)
Data RiskMX Data in LLM TrainingRetained for Model Training (2) · Zero Data Retention (0)
Input/Output FilteringActive Guardrails (0) · None / Unverified (2)
Data ClassificationPublic (-3) · Internal/NPI (0) · PII/Financial (3)
Persistent MemorySession Only (0) · Cross-Session Retention (2)
Operational ModifiersHuman Oversight LevelStrict Human-in-the-Loop (-7) · Partial (-4) · None (0)
Decision CriticalityLow Workflow Impact (0) · Influences Decisions (+3) · Critical (+5)

Investigation & Publishing Workflow

[Phase 1: Minimal Intake]
  │ • Vendor/Tool Name & URL
  │ • MX Specific Use Case
  │ • Data Classification & Touchpoints

[Phase 2: Multi-Channel Autonomous Research]
  │ • Internal: Confluence spaces, Jira security & procurement tickets
  │ • Vendor: DPAs, Trust Portals, Sub-processor lists, Model Cards
  │ • Independent: SOC 2, ISO certifications, CVE / breach history

[Phase 3: Conservative-by-Default Rubric Scoring]
  │ • Map evidence to indicators with mandatory citations
  │ • Auto-assign 'Insufficient Evidence — Assumed High' on gaps
  │ • Calculate composite score and map to Risk Tier & Controls

[Phase 4: Human Gate & Confluence Page Publishing]
  │ • Present complete formatted draft in chat
  │ • Await explicit human confirmation & target space/parent
  │ • Publish structured Markdown page via Confluence API

Operational Architecture & Safety Controls

The agent’s operational architecture ensures high analytical rigor without requiring human operators to manually audit every underlying document:

1. Minimal Intake vs. Autonomous Depth

The agent limits human input to essential internal context that cannot be inferred externally:

  • Product target: Vendor name, tool name, and specific product URL.
  • Workflow context: The exact MX team, workflow, and operational touchpoint.
  • Data exposure: Integration type (API, browser extension, SSO, native client), specific data fields passed, and data classification levels (Public, Internal/NPI, PII, Financial).

All subsequent investigation—including retrieving Data Processing Addenda (DPAs), SOC 2 compliance, sub-processor disclosures, and training data policies—is conducted autonomously across internal databases and external trust centers.

2. Conservative Scoring & Evidence Attribution

To protect against model hallucinations and unverified vendor marketing claims:

  • Mandatory sourcing: Every indicator score requires an explicit, auditable citation and a one-sentence factual justification.
  • Conservative ambiguity resolution: If documentation is unclear or conflicting, the agent defaults to the higher-risk score.
  • Explicit gap flagging: If evidence cannot be found after exhausting all channels, the indicator is marked Insufficient Evidence — Assumed High. This makes data gaps immediately visible on the final scorecard.

3. Separation of Evaluation from Procurement

The agent is explicitly designed as an analyst, not a decision-maker. It calculates composite scores, maps scores to required governance controls (such as executive review, kill-switch readiness, or mandatory human verification), and generates a publish-ready Confluence report. The final procurement decision remains strictly in human hands.

Email copied: mitchellgdyer@gmail.com