GATEKEEPER AI AGENTS
Risk Register Agent.
Turn vendor questionnaire gaps into structured risk register entries without manual extraction.
The Risk Register Agent identifies individual risks, categorises them, assigns severity and captures supporting evidence, so your team can focus on mitigation and vendor remediation.
ESG Review Agent in action.
See how the ESG Review Agent assesses vendor submissions against your sustainability criteria, scores performance and identifies gaps requiring attention.
HOW IT WORKS
How the Risk Register Agent works.
Vendor gaps identified.
The Agent reviews DDQ and SIG Lite questionnaire responses and identifies missing or weak practices as individual risks.
Risks categorised.
Each gap is assigned to the appropriate risk domain: Information Security, Privacy, ESG, Operational or Financial.
Severity assessed.
The Agent assigns a High, Medium or Low severity rating using your configured severity rules.
Supporting details captured.
Relevant questionnaire responses are captured alongside each risk, giving your team context behind the finding.
Register entries created.
Each gap becomes a structured risk entry with its category, severity and business impact, ready for your team to review and address.
Action prioritised.
Structured risk entries give your team a clear view of which vendor risks need attention.
FAQS
Frequently asked questions.
What does the Risk Register Agent review?
The Agent reviews SIG Lite questionnaire responses to identify specific vendor risk gaps.
For each gap, it:
- Identifies the specific risk.
- Assigns the appropriate risk category.
- Assesses severity using your configured rules.
- Captures the supporting questionnaire response.
- Creates a structured entry with the gap, category, severity and business impact.
What are the configuration options?
Configure the Agent around your organisation’s risk framework, including:
- Risk categories: Define the categories relevant to your organisation.
- Severity thresholds: Set rules for High, Medium and Low severity.
- Trigger responses: Define which questionnaire responses create a risk entry.
- Additional data: Choose what supporting information is captured for each risk.
Does the Agent make risk decisions automatically?
The Agent identifies, categorises and assigns severity to risks based on the rules you configure, while your team retains oversight of how those risks are managed.
- Severity follows your defined thresholds.
- Supporting questionnaire responses are captured.
- Each risk is documented with its category and business impact.
- Your team uses the findings to guide mitigation and vendor remediation.
When does the Risk Register Agent create risk entries?
The Agent reviews SIG Lite questionnaires when vendors complete assessments and during periodic re-evaluation cycles.
When questionnaire responses meet your configured criteria, the Agent identifies the gaps and creates structured risk entries.
How does Agent automation compare with a manual process?
Without Agent automation, teams manually extract risks from completed vendor questionnaires.
- Each gap must be identified and entered into the risk register.
- Risk categorisation can vary between reviewers.
- Severity assessments can be inconsistent.
With Agent automation, questionnaire responses are systematically assessed for risk gaps.
- Risks are categorised into the appropriate domains.
- Severity is assigned using your defined criteria.
- Structured risk register entries are created automatically.
Is there an audit trail?
Every Agent action is recorded in Gatekeeper with a timestamp, including the criteria applied, decision made, supporting evidence and reasoning where applicable.
This creates a searchable record of how each outcome was reached, supporting compliance verification, internal review and audit requirements.
How is my data kept secure and compliant?
Your data stays within Gatekeeper while the Agent performs its work. Actions, decisions and supporting evidence are logged, creating a clear audit trail.
The Agent operates within the permissions, playbooks and authority controls you configure.
Data handling follows Gatekeeper’s enterprise security standards, including SOC 2 Type II compliance and GDPR requirements.
one unified record
Every capability, connected.
One system of truth.
Customer and vendor contracts, obligations, and renewals in one record.
See spend against contract.
Contract value sits next to what is actually being spent.
No single point of failure.
Contract knowledge lives in the platform, so nothing is lost when someone changes role or leaves.
Draft from approved templates.
Every agreement starts from language Legal already trusts.
Keep control of the clause library.
Guard-railed templates keep off-policy wording from going out.
Nothing renews unnoticed.
Every renewal date tracked, with owners and reminders set automatically.
Expert insight & opinion
Related AI agents.
Gatekeeper's agents work as a single, connected team, handing off to one another across the lifecycle rather than running in isolation like bolted-on point tools.