Drata launches standalone third-party risk tool for vendors
Fri, 2nd Oct 2026 (Today)
Drata has launched its Third-Party Risk Management product as a standalone offering designed to help organisations assess vendors across their portfolios through automated, evidence-based reviews.
The release marks a shift for the software group's third-party risk tool, which previously sat within its broader platform. The standalone version is built around an assessment engine that continuously reviews vendor information rather than relying on periodic questionnaires and point-in-time scoring.
Third-party risk management has become more prominent as companies rely on a growing number of external technology suppliers, including providers of artificial intelligence tools. Drata cited research showing that 75% of governance, risk and compliance leaders believe AI adoption is moving faster than their teams' ability to vet third parties properly.
It argues that this gap leaves many suppliers subject to limited scrutiny. Detailed manual reviews can absorb hundreds of staff hours, often leading businesses to reserve deeper checks for only 10% to 20% of their most critical vendors while the rest of the portfolio receives less rigorous assessment.
Drata also pointed to findings from an upcoming report showing that 76% of organisations reassess third-party partners and vendors no more than once a year. That pattern can leave businesses relying on outdated views of supplier risk.
How it works
According to Drata, the standalone product automates vendor reviews from initial assessment through residual risk evaluation. Each result includes the reasoning and evidence behind the assessment, giving compliance and security teams material they can use when auditors or internal stakeholders question a decision.
The system also applies the same standards across a full vendor base, aiming to reduce differences between reviewers and shifts in judgement over time. It can perform an inherent risk assessment for all vendors and charges only when a supplier requires a full security review.
Drata contrasted the product with older third-party risk approaches that rely heavily on binary responses, checkbox questionnaires, or static scorecards. Its assessment process uses customer-defined standards expressed in natural language and weighs multiple factors in context, rather than reducing a vendor's profile to a simple yes-or-no outcome.
For residual risk analysis, the product evaluates evidence and questionnaire responses against those standards, then returns cited evidence, assessment results, and a calculated risk score. Drata presented this as an alternative to tools that generate questionnaire answers without a way to validate them.
Customer response
Two users cited by Drata said the product had reduced manual effort and improved the review process.
"Drata's TPRM Agent allows us to level up our security risk management program across the board by reducing manual work and letting us focus on the risks that matter," said Priyanka Chaudhary, Head of GRC at Brex.
Silva said the product had made the team "a lot more productive while also improving the quality of our reviews."
Market pressure
The launch comes as software suppliers and governance providers try to address the strain on internal risk teams caused by larger supplier estates and the spread of AI services. Security and compliance functions have long had to balance the need for close review against limited staffing, and vendors in the sector are increasingly framing automation as a way to expand coverage.
Drata's case is that businesses should move away from annual or occasional reviews and adopt a more continuous model. That position reflects a broader shift in the compliance market, where customers are asking not only for a risk score but also for a documented rationale that can stand up to regulatory, audit, and procurement scrutiny.
"The pace of AI adoption today means organizations must abandon the antiquated notion of periodic check-ins, and quickly implement continuous judgement applied at scale," said Adam Markowitz, Co-founder and CEO of Drata. "Facing a colossal tech stack with insufficient hours or headcount for rigorous vetting, we built agentic TPRM to remove these trade-offs, giving every vendor the same depth of scrutiny without sacrificing rigor or accuracy."