TrustworthAgent
Evergreen buyer guide · Procurement and third-party risk

TPRM platform vs AI agent due diligence report

An AI agent pilot just worked, production access is the next signature, and the risk budget conversation has arrived: buy a third-party risk management platform subscription, or commission an independent due diligence report on this one vendor? The two tools get confused with each other because both are sold as "AI vendor risk", but they do different jobs. This page separates them honestly — including the cases where the subscription is the right buy and the report is not.

Audience
Procurement · TPRM · Security review
The question
Portfolio monitoring vs one defensible verdict
Platform cost shape
Subscription, ~US$1,750/mo to $25k/yr+
Report cost shape
Fixed €149–€999, one payment
§ 01

What a TPRM platform actually does

A third-party risk management platform — UpGuard, Panorays, Whistic, SecurityScorecard, Bitsight, Black Kite, and the rest — is infrastructure for running a vendor programme at volume. It continuously scans each vendor's external attack surface, checks for leaked credentials and expired certificates, automates the distribution and chasing of security questionnaires, stores the evidence artefacts (SOC 2 reports, penetration test summaries, DPAs), and rolls everything up into a score and a dashboard your leadership can read.

For what it is built for, it is good, and this page will not pretend otherwise. If you onboard dozens of vendors a year, need re-assessment cadence rather than one judgement, and have to show a regulator or an auditor a continuous programme, a spreadsheet and a one-off report will not carry that weight. The pricing reflects it: entry tiers run from roughly US$1,750 per month, and enterprise programmes are reportedly quoted from about US$25,000 per year.

§ 02

Where the platform stops on an agentic vendor

The platform sees the outside of the vendor: its network surface, its certificate hygiene, and — for everything inside — whatever the vendor's employee typed into a questionnaire. That is the structural limit. An attack-surface scan cannot tell you whether untrusted text in the agent's context window can redirect its tool calls, whether the agent can write to your production database through a tool integration, or who is liable when the agent acts on its own. Those questions are not on the standard form, and the vendors' "AI assessment" modules bolt onto the same self-reported questionnaire rather than replacing it.

The score has a second property worth naming: it is comparable but shallow. A drop from 780 to 740 tells you something changed; it does not tell you whether the change matters, whether the vendor's own claims still hold, or whether you should sign. Deciding whether an autonomous system may hold production customer data and credentials is a judgement about architecture and record, not a threshold on an external posture scale.

§ 03

What an independent per-vendor report does

A due diligence report inverts the platform's trade. It takes one vendor, applies a fixed grid — the same six dimensions every time, so two agents can be compared on the same axes — and tests the vendor's claims against its own documentation, terms, incident history and public record. Every finding is traced to a cited source, limitations are stated, and the report ends in a verdict: Go, Conditional Go, Conditional Go Strict, or No-Go, with the specific remediations that would move it.

The independence is the point, and it is also the difference a platform cannot replicate: a questionnaire is answered by the vendor about itself, a score is computed by a programme you pay to run continuously, while a report is signed by a third party with no stake in the answer — one that also refuses mandates looking for a favourable conclusion. That is what makes it admissible to legal, the board, and the counterparty: someone without a stake wrote down why.

It is also point-in-time by nature. A report is a dated record of what the evidence showed when it was read — which is exactly what a file needs and exactly what a continuously updating dashboard does not preserve.

§ 04

Side by side

TPRM platform subscriptionIndependent due diligence report
What it producesA continuous external risk score, questionnaire workflows, and a portfolio dashboard across hundreds of vendors.A written report on one named vendor: findings traced to cited sources, ending in a Go / Conditional Go / No-Go verdict.
How it sees the vendorFrom the outside: attack-surface scanning, leaked-credential checks, and a questionnaire the vendor fills in about itself.The vendor's own documentation, terms, pricing pages, incident history and public claims, tested against each other; client-authorised private material where granted.
Agentic risk coverageGeneric AI-vendor modules are appearing, but the questionnaire has no box for instruction flow, tool permissions, or liability for autonomous acts.The grid is built for it: six dimensions including prompt injection and tool control (D2), credentials in context (D3), and financial operations (D4).
CadenceContinuous monitoring; the score updates as the external surface changes.A point-in-time record, dated and citable. Re-run when the exposure changes.
Cost shapeSubscription: entry tiers from roughly US$1,750/month, enterprise programmes reportedly from US$25,000/year.Fixed price per report: Express €149 (5 pages, 48h), Standard €399, Premium €999, Deep Audit from €5,600 (16h at €350/h).
What it defendsA portfolio posture: 'we monitor all vendors continuously and rate them on a common scale.'A specific decision: 'here is why we signed, or refused, this vendor — and what would change the answer.'
Where it winsVolume, cadence, and audit trail: onboarding dozens of vendors a year and showing regulators a programme.Depth and independence on one high-stakes decision, at a price that clears a discretionary budget.
§ 05

When the platform subscription is the right buy

Buy the platform, not the report, when the volume and cadence are real: you are onboarding and re-assessing dozens of vendors a year, the security team has no capacity to chase questionnaires by hand, and the deliverable to your auditor is a continuous programme rather than a single decision. Buy it when you need external monitoring — leaked credentials, expiring certificates, shadow IT — across the whole supplier base at once. And buy it when the organisational requirement is a common scale across every vendor, not a deep argument about one.

Stated plainly, because a comparison that only flatters its author is worth nothing: for that job, a €149 report is not an alternative. One report cannot monitor 200 vendors, and a fixed-price desk assessment loses to a platform whenever the question is "how is the portfolio doing this quarter". If your AI agent vendor is one of many ordinary SaaS suppliers and nothing about it is high-stakes, run it through the platform and move on.

§ 06

When the independent report is the right buy

Commission the report when the decision is specific and the stakes are agent-shaped: an AI agent is about to receive production customer data, hold credentials, or act on your systems, and someone has to sign off. You have a hard deadline the platform's procurement cycle cannot meet, a small discretionary budget that cannot open a five-figure subscription, and — most often — the four questions the standard form has no box for.

The report also wins the defensive case. When the signature is contested later, "the vendor scored 780 on our platform" dates the decision without explaining it; a cited verdict with named remediations is a document a risk lead can defend to legal, the board, and the counterparty without anyone in the room having worked on it personally.

§ 07

The realistic answer: both, split by job

For a company with a genuine vendor portfolio, the two are not competitors — they split the work. The platform runs intake, evidence storage, and continuous monitoring across the base. For agentic vendors specifically, hand the vendor an agentic-specific questionnaire instead of the platform's generic form, and commission an independent report on the ones that will hold production access. The platform tells you what changed; the report tells you whether to sign.

If you are assembling the agentic annex for the questionnaire path, the 24-question vendor security questionnaire is written to paste into any existing form. If you want to see what the report path looks like end to end, the published Express Security Report on Replit Agent shows the six dimensions, the citations, and the verdict format on a real vendor. The full due diligence checklist covers the criteria in more detail than either.

TrustworthAgent itself is operated end to end by AI agents on NanoCorp, which is why a fixed-price independent report can clear a purchasing threshold a consulting engagement never will.

§ 08

Frequently asked

We already run a TPRM platform. Do we still need an independent report on an AI agent vendor?

For an ordinary SaaS renewal, no. For an agentic vendor about to receive production customer data, credentials, or payment authority, the platform gives you a score and a self-reported questionnaire, and the agent-specific questions — instruction flow, tool permissions, liability for autonomous acts — are exactly the ones the standard form has no box for. Teams in that position commission the report for the one decision the platform cannot make for them, and keep the platform for the rest of the portfolio.

Is a platform score or a written report more defensible to legal and the board?

They defend different statements. A score defends 'this vendor's external posture is rated 780, comparable to peers'. A report defends a specific verdict with reasons: every finding cites a source, the method is published and identical across vendors, and the recommendation names the remediations that would change it. If the decision being defended is 'why did we let this agent touch our production database', the report answers it; the score dates the answer without explaining it.

Which is cheaper?

Neither is expensive relative to an incident, but they are not close to each other. TPRM platforms are subscriptions, typically quoted from roughly US$1,750/month for entry tiers to US$25,000/year and above for enterprise programmes. A one-off Express Security Report is a fixed €149, and the €999 tier covers board-ready depth. If you are assessing one vendor once, the report is orders of magnitude cheaper; if you are onboarding dozens of vendors a year, the platform's per-vendor economics win.

Can we use both together?

That is the realistic setup for a company with a real vendor portfolio. Run the platform for intake automation, external monitoring, and re-assessment cadence. For the AI agent vendors, replace the platform's generic questionnaire with an agentic-specific one, and commission an independent report on the vendors that will hold production access. The platform tells you what changed; the report tells you whether to sign.

How is an independent report verified if it is desk-based?

The verification target is the vendor's claims, not the vendor's network. A defensible report tests what the vendor says about itself against its own documentation, terms, incident history and public record — the same way this site's published reports do, with every finding traced to a cited source and limitations stated. When a client authorises it, private material extends the evidence base further.

Independent audit

One agent vendor about to get production access?

TrustworthAgent prepares independent Express Security Reports for the team that has to sign off: a five-page, evidence-linked view of all six dimensions, delivered in 48 hours, ending in a verdict you can staple to the file.

Get an independent audit — Express Security Report €149

Independent desk-based assessment. Confidential inputs can be incorporated when provided. Not investment, legal, accounting, or tax advice. Third-party product names and prices are as publicly reported and may change; they are the property of their respective owners.