Top Rated Solution for Vendor and Contract Lifecycle Management

G2 reviews, 4.5 stars Software Advice, 4.7 stars

“Before Gatekeeper, our contracts were everywhere and nowhere.”

Anastasiia Sergeeva, Legal Operations Manager, BlaBlaCar

“Gatekeeper is that friendly tap on the shoulder, to remind me what needs our attention.”

Donna Roccoforte, Paralegal, Hakkasan Group

“Great System. Vetted over 25 other systems and Gatekeeper rose to the top.”

Randall S. Wood, Associate Corporate Counsel, Cricut

Book your Free Demo of Gatekeeper

GATEKEEPER AI AGENTS

Vendor Risk Tiering Agent

Automatically assign vendors to the right risk tier based on the criticality criteria that matter to your organisation.

The Vendor Risk Tiering Agent assesses vendor intake and questionnaire responses against your criteria, assigns the appropriate risk tier and records the reasoning behind each decision, giving your team a consistent view of vendor criticality.

ESG Review Agent in action.

See how the ESG Review Agent assesses vendor submissions against your sustainability criteria, scores performance and identifies gaps requiring attention.

HOW IT WORKS

How the Vendor Risk Tiering Agent works.

Gather vendor information.

The Agent reviews information submitted through your intake form or vendor questionnaire.

Enrich the assessment.

Where configured, it gathers additional vendor information from the vendor’s website. Missing information is flagged rather than inferred.

Evaluate risk factors.

The Agent assesses factors such as data access, system access, contract value and service type against your configured criteria.

Apply tiering rules.

Tier criteria are evaluated from highest to lowest criticality, ensuring higher-risk criteria take precedence.

Assign the risk tier.

The Agent assigns the appropriate Vendor /Third Party Tier from 1, highest criticality, to 4, lowest criticality.

Record the outcome.

The tier and supporting reasoning are written to the vendor record, with missing information or discrepancies flagged for review.

FAQS

Frequently asked questions.

What does the Vendor Risk Tier Agent review?

The Agent assesses vendor information against the factors your organisation uses to determine criticality, including:

  • Personal or customer data access
  • Production or internal system access
  • Contract value
  • Data handling requirements
  • Service type and business impact
  • Supporting vendor information

Where configured, it can also review information from the vendor’s website, including certifications and company details.

What are the configuration options?

Configure the Agent to match your organisation’s vendor risk tiering methodology, including:

  • Number and definition of risk tiers
  • Tiering criteria
  • Contract value thresholds
  • Data and system access rules
  • Vendor category rules
  • Escalation and uncertainty rules
  • Output and reasoning fields
How does the Agent handle missing or conflicting information?

The Agent does not guess when required information is unavailable. Missing information is left unresolved and flagged for review.

Where website information conflicts with submitted questionnaire or intake data, the submitted response takes precedence and the discrepancy is recorded.

Can the Vendor Risk Tiering Agent make decisions automatically?

Yes. The Agent assesses vendor information against your defined tiering criteria and automatically assigns the appropriate risk tier.

  • Risk factors are assessed against your configured criteria.
  • The highest-severity tier that applies is assigned.
  • Missing information is flagged rather than inferred.
  • The assigned tier and supporting reasoning are recorded in Gatekeeper.
How does Agent automation compare with a manual process?

Without Agent automation, teams manually assess each vendor against criticality criteria.

  • Risk factors require manual cross-checking.
  • Tiering can vary between reviewers.
  • Missing or conflicting information takes additional time to resolve.

With Agent automation, vendors are assessed automatically against your defined criteria.

  • Risk factors are evaluated consistently.
  • The highest applicable risk tier is assigned automatically.
  • Reasoning and discrepancies are recorded for review.
Is there an audit trail?

Every Agent action is recorded in Gatekeeper with a timestamp, including the criteria applied, decision made, supporting evidence and reasoning where applicable.

This creates a searchable record of how each outcome was reached, supporting compliance verification, internal review and audit requirements.

How is my data kept secure and compliant?

Your data stays within Gatekeeper while the Agent performs its work. Actions, decisions and supporting evidence are logged, creating a clear audit trail.

The Agent operates within the permissions, playbooks and authority controls you configure.

Data handling follows Gatekeeper’s enterprise security standards, including SOC 2 Type II compliance and GDPR requirements.

one unified record

Every capability, unified.

One system of truth.

Customer and vendor contracts, obligations, and renewals in one record.

See spend against contract.

Contract value sits next to what is actually being spent.

No single point of failure.

Contract knowledge lives in the platform, so nothing is lost when someone changes role or leaves.

Draft from approved templates.

Every agreement starts from language Legal already trusts.

Keep control of the clause library.

Guard-railed templates keep off-policy wording from going out.

Nothing renews unnoticed.

Every renewal date tracked, with owners and reminders set automatically.

Expert insight & opinion

Related AI agents.

Gatekeeper's agents work as a single, connected team, handing off to one another across the lifecycle rather than running in isolation like bolted-on point tools.