← All flagship engagements
Enterprise Automation

Vendor & Third-Party AI Risk Review

Model approval registry, prompt-injection detection, PII leak scanning — gating what data and models touch a workflow before they run.

Start this engagement Read the Reverse SLA

"Every new model or vendor integration your teams adopt is a new surface for prompt injection, PII leakage, and silent model drift — and vendor risk assessments are stale the day they're signed off. Vouchstone puts a standing agent team on model and vendor risk instead of a point-in-time questionnaire."

The reality

What you are actually dealing with

  • Vendor risk assessments are stale the day they are completed — no continuous monitoring
  • Prompt injection, PII leakage, and model drift risks grow with every new AI deployment
  • No central registry of which models are approved for which data classification
  • Vendor questionnaires are a one-time PDF, not a living record that updates when the vendor changes
  • New model rollouts ship without a gate checking what data they are allowed to see
Vouchstone countermove

How we ship it

  • Model approval registry: every model mapped to the data classifications it is cleared to touch
  • Continuous vendor risk agents re-check vendor posture on a schedule, not just at onboarding
  • Prompt-injection detection agents scan inputs before they reach a model
  • PII leak scanning (Presidio) gates outputs before they leave a workflow
  • Data classification gating blocks a workflow from routing regulated data to an unapproved model
  • Every gate decision signed to an immutable audit ledger — reviewable evidence, not a point-in-time PDF
Reverse SLA

What we owe you when we miss

Most SI contracts only penalise you for falling behind on payment. Our Reverse SLA flips that - when we miss a named milestone, parity threshold, or budget band, we owe you in credits or refund.

Coverage

Named vendors and models in scope for continuous monitoring, not a one-time review

Detection

Vendor risk and posture changes detected within 4 hours

Gating

Every model call checked against the approval registry before it runs — no silent exceptions

What you walk away with

Vendor & Model Risk Registry

Model approval registry mapped to data classifications, continuous vendor risk dashboard, prompt-injection and PII-leak scan logs, and a signed audit trail of every gating decision.

Side-by-side

Big SI playbook vs. Vouchstone

Big SI

Annual vendor questionnaire PDF — stale the day it is signed, no continuous monitoring

Vouchstone

Standing agent team on model and vendor risk, continuous re-checks, real-time gating on every model call

Compliance evidence auto-generated

Domains your audit + compliance teams care about

Every action signed to the ledger; every signed action chained into a regulator-ready evidence pack matched to the framework controls below. One-click export, OCSF-formatted for your SIEM.

SOC 2 Type 2GDPREU AI ActNIST CSF

Ready to start?

Five-minute intake. Sixty-second response with a named lead, a draft scope, and a price band. No sales call needed before you see what we propose.