Company

The AI intelligence layer for third-party risk

ThirdPartyIQ is an agentic AI platform that gathers the evidence, senses risk continuously, and delivers a cited recommendation when something changes.

  • Evidence-first
  • Decision-driven
  • Always-on
Why we exist

Continuous oversight, running on a periodic process

Regulated organizations are expected to monitor their third parties continuously. Yet the tools most teams use still run on periodic questionnaires that are labor-intensive for both sides and out of date the moment they are completed. The effort is enormous, the coverage is thin between cycles, and the answer arrives after it would have mattered.

We built ThirdPartyIQ to close that gap: automatically gathering the evidence, continuously sensing risk signals, reasoning across financial, cybersecurity, sanctions and watchlists, legal, reputational, and regulatory data, and delivering a specific, cited recommendation when risk emerges, instead of waiting for someone to catch it in a dashboard or at the next annual review.

What we do

Four things the platform does, end to end

01

Automated evidence collection

Getting the documents is the hardest part of third-party diligence, and it is almost entirely manual today. ThirdPartyIQ retrieves third-party documentation on our customers' behalf, on their authority, then keeps it current as new versions are published. SOC 2 reports and bridge letters, security and privacy attestations, business continuity and disaster recovery plans, insurance certificates, financial statements, and policy documents arrive without anyone sending an email or chasing a contact.

02

Document intelligence

Collecting the documents is only half the work. Our AI reads what risk teams read by hand today, extracts controls, exceptions, subservice organizations, coverage dates, and version changes, and turns static reports into structured evidence that can be compared, monitored, and reused across every assessment.

03

Continuous monitoring and agentic reasoning

Always-on AI agents ingest signals across six risk domains, detect meaningful change, correlate signals against the evidence already on file, separate noise from real risk, and reach conclusions supported by cited evidence.

04

Proactive action

Insight becomes action. The platform initiates workflows, triggers escalations, and orchestrates responses before risk events become risk incidents.

Six risk domains

What our agents watch

Signals in one domain rarely mean much on their own. The platform correlates across all six, and against the evidence already on file for that third party.

  • Financial health
  • Cybersecurity
  • Sanctions & watchlists
  • Legal
  • Reputational
  • Regulatory
Our approach

What makes this different

We collect the evidence, not just the data

Most platforms hand you feeds and scores. We go get the source documents, keep them current, and read them.

Evidence first

We assemble what is independently knowable about a third party before anyone is asked to fill out a form, then use assessments only where evidence cannot answer the question.

What is reported versus what is verifiable

Existing systems capture what a third party says about itself. We assemble what can be independently corroborated, and reconcile the two.

Decisions, not dashboards

Risk data already exists. What is missing is the reasoning between the signal and the action.

Additive by design

We work alongside the GRC, third-party risk, and procurement systems organizations already have, and we work just as well for teams running on spreadsheets and email. Nothing to rip out.

Built to the exam

Regulatory examination procedures are our product specification.

Our governing principle

AI recommends. Humans approve.

Every recommendation is evidence-cited. Every decision is logged. The full record of what triggered an action is exportable for regulatory examination. The reasoning is ours to show. The decision stays with the institution.

Who we serve

Organizations that have to stand behind their third parties

Banks, credit unions and other regulated organizations accountable for the external relationships they depend on. We use "third parties" as our default term, covering vendors, suppliers, partners, commercial counterparties, and other external relationships.

Our team

A team that has done this before

ThirdPartyIQ was founded by the leadership team behind a GRC platform for regulated financial institutions. Nine years building together. Two operators who know the buyers, the regulations, and the problems regulated organizations have in managing their third-parties.

Carl McCauley

CEO and Co-Founder

Nine years as CEO of 360factors, a governance, risk, and compliance software company serving regulated financial institutions. Prior executive roles at Zycus in procurement, AFS Technologies in supply chain, MetricStream in governance, risk, and compliance. Deep domain expertise in third-party risk, GRC, and the regulatory compliance buyer.

Chris Duden

CTO and Co-Founder

CTO of 360factors from day one, building the full platform stack from pre-product through enterprise deployment at regulated financial institutions. More than 15 years building AI technology, from early natural language processing and machine learning through predictive analytics and modern large language models. Architect of the GRC and agentic compliance platforms he built there.

What we learned

What running a third-party risk program actually teaches you

The hardest part of third-party risk management is not understanding the risk. It is the volume, and the fact that the standard approach starts from zero every time. A questionnaire with hundreds of questions goes to every third party, regardless of what is already independently verifiable. Third parties receiving hundreds of these a year deprioritize the smaller requesters. Coverage lapses. The same risk that should have been visible months earlier surfaces in an examination finding.

Most available tools were built to digitize the questionnaire workflow: better tracking, cleaner documentation, faster routing. That is an improvement. It is not a transformation. The manual work stays. The annual cycle stays. The gaps between reviews stay.

ThirdPartyIQ starts from a different premise. Collect the evidence first. Read it. Monitor it continuously. Ask a third party only what the evidence cannot answer. That is not a workflow efficiency. It is a structural change in how third-party risk gets done.

How we build

Four things that don't change

Evidence over assertion

If we cannot cite it, we do not claim it. Every finding in the platform traces back to a source document or a monitored signal, and that citation travels with the finding into the file.

The human decides

AI does the reasoning and shows its work. The platform reaches a conclusion, presents the evidence behind it, and waits. The institution owns the decision and the record of who made it.

Additive, not disruptive

We make the systems our customers already own more valuable. ThirdPartyIQ runs standalone for teams on spreadsheets and email, and as an intelligence layer above the GRC, third-party risk, and procurement systems already in place.

Built for the examiner in the room

Not just the user at the desk. Every capability is judged against a single question: when this output appears in a file review, does it satisfy guidance or create a finding?

Talk to the people building it

We take calls from third-party risk, procurement, compliance, and credit teams. Tell us where your program stands today, and we will tell you where ThirdPartyIQ fits.

Get in touch

ThirdPartyIQ. Austin, Texas.