Testing across the population instead of a sample
Controls, transactions and policy exceptions are examined in full rather than in a five-percent extract, which surfaces the repeating pattern that a sample is statistically likely to miss entirely.
Test controls against the evidence rather than the attestation, keep a risk register that reflects what the business actually reported, assess a vendor from the documents they sent, and find the privacy gap before a regulator does.
Assurance functions are small by design and are asked to form a view on everything the rest of the organisation does. The result is coverage by sampling: five percent of transactions tested, a risk register refreshed twice a year from a workshop, vendor questionnaires read once and filed, and a privacy position that was accurate when it was written. VDF risk agents change the arithmetic by reading the whole population, and they hand every finding to a named owner with the document it came from attached.
Controls, transactions and policy exceptions are examined in full rather than in a five-percent extract, which surfaces the repeating pattern that a sample is statistically likely to miss entirely.
Risks are drawn from incidents, audit findings, assessments and business documents as they arrive, so the register describes the current position rather than the last workshop.
Vendor and privacy reviews report the evidence that was not supplied as clearly as the evidence that was, because an unanswered question is the finding that matters most.
Open any agent to see how teams use it, what it produces, how it stays compliant, and the questions buyers ask most — plus related tools to go further.
Test the whole population, evidence every exception, and draft the workpaper.
Explore agent Tier 2Keep a risk register drawn from real signals and scored by your own methodology.
Explore agent Tier 2Assess a vendor from the documents they sent, and name the evidence they did not.
Explore agent Tier 2Map processing to requirements, and keep the law separate from your own policy.
Explore agentAll four agents follow the same shape and it is deliberately unglamorous: read the documents and data you already hold, test them against criteria you configured, and produce findings that carry their evidence. None of them accepts a risk, signs an assessment or approves a vendor.
Audit programmes, risk scoring methodology, vendor requirements and privacy obligations are taken from your own documents, because a finding measured against a generic benchmark is not one your committee can act on.
Transactions, contracts, questionnaires, policies, incident records and processing activities are examined in full, with the extraction confidence recorded wherever a document was read from an image.
Each item is graded against the criteria, and every exception carries the clause, control or requirement it fails together with the passage in the source document that establishes it.
Findings are grouped by the person who owns the control, the risk or the relationship, and the decisions that follow — accept, remediate, escalate, approve — remain theirs to make and to sign.
An assurance function whose evidence cannot be re-examined has simply moved the problem. These agents keep the link from every finding back to the passage that produced it, record the criteria version applied, and never change the underlying records — so a conclusion reached in March can be tested in November against exactly what was read at the time.
They are specialised agents for the assurance functions: internal audit fieldwork and workpapers, enterprise risk register maintenance, third-party vendor risk assessment, and privacy and data-protection analysis — each working from your own criteria and evidence.
Those govern AI systems under one specific regulation. These serve general enterprise assurance across any subject matter: controls, transactions, suppliers, processing activities. An organisation with no AI estate still needs these four.
No. Agents produce findings, scores and recommendations with the evidence attached. Accepting a risk, signing an assessment and approving a supplier are decisions with named accountability, and they stay with the owner.
See these agents applied to your operations — governed, on-premise, and orchestrated together.