Перейти к содержимому

AI That Actually Helps TPRM with Brian Shaw

Third Party Threat Hunting

0:00 / 0:00

AI That Actually Helps TPRM with Brian Shaw

87 просмотров · 8 дн. назад
Third Party Threat Hunting
59 подписчиков
87 просмотров · 8 дн. назад
“100% automated vendor risk assessments” sounds seductive right up until you are staring at unstructured SOC 2 reports, mismatched ISO certificates, and a queue you cannot clear. Greg sits down with Brian Shaw, a long-time third-party risk and compliance leader, to talk about what AI can realistically do in third-party risk management today, and what it absolutely should not do yet. We start with a blunt warning: do not automate a broken process. If a question does not change a risk decision, answering it faster does not improve your TPRM program. From there, we get practical about the best use case most teams feel immediately, evidence collection and normalization. Brian explains how AI and natural language processing can extract risk signals from SOC reports, contracts, and policies, then compare sources to flag contradictions with citations so a human can make a defensible call. We also dig into the human side: analysts are not getting replaced if they build strength in materiality, investigation, mitigation, and relationship management. Then we zoom out to modern vendor risk architecture: annual assessments as a photograph, risk as a movie. We talk continuous monitoring, material events, and why context must stay connected from intake through renewal. Finally, we tackle fourth-party and concentration risk, including the uncomfortable truth that “vendor diversity” can collapse into one shared cloud or model provider dependency, and how risk graphs can help you see the real blast radius. Subscribe for more practitioner-level conversations, share this with your risk team, and leave a review with the one TPRM workflow you would automate first. 00:00 Welcome And Guest Background 01:20 Five Fast Questions On AI 04:15 AI Hype Versus Real Bottlenecks 08:16 NLP For SOC 2 And ISO Evidence 10:39 Augmenting Analysts Not Replacing Them 13:16 Trustworthy AI With Audit Trails 14:52 Continuous Monitoring Beyond Annual Reviews 17:16 Fourth Party Concentration Risk Graphs 19:54 Agentic AI Governance And Guardrails 22:26 A Safe Pilot Plan And Closing