All resources
AI Review7 min read

Where AI belongs in third-party risk, and where it does not

The time cost in third-party risk is concentrated in reading: hundreds of questionnaire answers, dozens of contracts, a pile of certificates. That is exactly the work assisted review is good at, and exactly why the boundary needs to be explicit.

Claire Bouchard · Legal Counsel, Outsourcing

Good uses: extraction, comparison, first-pass triage

Pulling the expiry date and scope out of a certificate, locating candidate clauses per Article 30 area, flagging answers that contradict previous submissions, and grouping the responses that clearly need a human eye. Each of these produces a suggestion with a source reference.

Bad uses: deciding risk, accepting evidence, closing findings

A risk rating, an evidence acceptance and a contract sign-off are accountable decisions. They belong to a named person with the authority to make them, and the record should show who decided, when and on what basis.

Make the workflow enforce the boundary

In practice this means every generated output lands in a review state, carries a confidence indicator and a link to the source passage, and cannot change a record until a reviewer accepts it. Dismissals are recorded too, because a rejected suggestion is also evidence of review.

  • Every suggestion starts in needs-review state
  • Source passage and confidence are always shown
  • Acceptance and dismissal are both logged with the user
  • No generated value writes to the Register without approval

See how this works in the product.

See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.