AI That Actually Helps TPRM with Brian Shaw
Third Party Threat Hunting
0:00 / 0:00
AI That Actually Helps TPRM with Brian Shaw
87 просмотров · 8 дн. назад
Third Party Threat Hunting
59 подписчиков
87 просмотров · 8 дн. назад
“100% automated vendor risk assessments” sounds seductive right up until you are staring at unstructured SOC 2 reports, mismatched ISO certificates, and a queue you cannot clear. Greg sits down with Brian Shaw, a long-time third-party risk and compliance leader, to talk about what AI can realistically do in third-party risk management today, and what it absolutely should not do yet.
We start with a blunt warning: do not automate a broken process. If a question does not change a risk decision, answering it faster does not improve your TPRM program. From there, we get practical about the best use case most teams feel immediately, evidence collection and normalization. Brian explains how AI and natural language processing can extract risk signals from SOC reports, contracts, and policies, then compare sources to flag contradictions with citations so a human can make a defensible call. We also dig into the human side: analysts are not getting replaced if they build strength in materiality, investigation, mitigation, and relationship management.
Then we zoom out to modern vendor risk architecture: annual assessments as a photograph, risk as a movie. We talk continuous monitoring, material events, and why context must stay connected from intake through renewal. Finally, we tackle fourth-party and concentration risk, including the uncomfortable truth that “vendor diversity” can collapse into one shared cloud or model provider dependency, and how risk graphs can help you see the real blast radius.
Subscribe for more practitioner-level conversations, share this with your risk team, and leave a review with the one TPRM workflow you would automate first.
00:00 Welcome And Guest Background
01:20 Five Fast Questions On AI
04:15 AI Hype Versus Real Bottlenecks
08:16 NLP For SOC 2 And ISO Evidence
10:39 Augmenting Analysts Not Replacing Them
13:16 Trustworthy AI With Audit Trails
14:52 Continuous Monitoring Beyond Annual Reviews
17:16 Fourth Party Concentration Risk Graphs
19:54 Agentic AI Governance And Guardrails
22:26 A Safe Pilot Plan And Closing