ethira
Resources

TPRM

The vendor is the agent.

18 June 2026 · 6 min read

Third parties now act through agents. TPRM that stops at the vendor row misses the new entity.

Third-party risk management was built for a company. You onboard a legal entity. You file the DPA. You score the questionnaire. You put a row in the inventory. When something goes wrong, you write to a named contact and you hope the contract has teeth.

That model assumed the third party waited to be asked.

It no longer does.

Vendors now ship agents: bots in Slack, copilots in the IDE, assistants in the CRM, tools that call your APIs with a key issued for “integration.” Those agents do not sit in the vendor row. They sit in your estate. They hold credentials. They see tickets, code, customer records, and the contents of a channel that was never classified. They take steps: file a change, summarise a case, fetch a document, on a schedule you do not control.

If your TPRM programme stops at the legal entity, you have a list of companies and a blind spot the size of everything those companies can now do inside your walls.

The new entity is the actor

The unit of risk is no longer only who you pay. It is what acts. A vendor can be assessed, certified, and still introduce an agent that reaches data the questionnaire never mentioned. A model provider can be on the approved list while an unapproved wrapper: a browser plugin, a local tool, a shadow workspace: is the thing actually calling it.

That wrapper is a system. The caller is an agent. The path is a data flow. None of those are the vendor row.

Security sees this as access: keys, scopes, identity. Legal sees this as processing: who is the processor when an agent summarises a customer file? GRC sees this as an ICT third-party arrangement that was never declared because nobody thought a chatbot counted. They are looking at the same object. They need the same graph.

Agent governance, in this light, is not a new product. It is TPRM that finally includes the actors the vendor deployed, and ICT governance that finally includes the actors your own teams stood up. Same picture. Different cut.

Stop scoring the logo

A living graph treats the vendor, the system, the agent, and the data flow as first-class. When a third party ships an agent, it lands as a node with an owner, a path to data, and a contract that does or does not cover that path. When an internal team connects that agent to a production database, the edge appears without a campaign. Findings evaluate the live arrangement, not last year’s score for the logo.

You still need the legal entity. You still need the DPA, the DORA fields, the offboarding. Those remain views. What you cannot do is pretend the entity is the only thing that acts.

The organisations that get this will stop asking “is this vendor approved” as the last question. They will ask what the vendor’s agents can reach, what they can write, and who owns that reach today. That is the same question they should already ask of their own systems. AI did not invent it. AI made it impossible to ignore.

Get started

See past the vendor row.

Map every third party through the systems and agents that actually act, and the data they can reach.

All notes