Skip to content

Whistic Launches Automation Orchestrator, Handing Vendor Assessments to a Coordinated Team of Four AI Agents

Roughly 90% of legacy TPRM effort goes to workflow administration. AutoAssess hands that work to the agents and keeps every risk decision human.

SAN DIEGO, Calif., Aug. 18, 2026 — Whistic, the Agentic Risk Operations Platform, today announced the general availability of Automation Orchestrator, a unified hub for configuring and coordinating AI agents across the Whistic platform. Its first workflow, AutoAssess, assigns four specialized agents to the vendor assessment lifecycle. The Initiator starts assessments on the cadence and risk or vendor criteria a team configures. The Collector gathers evidence from Trust Centers, the web, and existing vendor records, as well as sends new requests for documents and questionnaires. The Analyst reviews the evidence and generates findings with confidence scores and cited sources. The Reporter compiles a decision-ready executive summary and notifies the team.

Enabled together as Full AutoAssess, the agents move an assessment from trigger to executive summary with zero routine touchpoints. A person reviews the findings, makes the risk decision, and closes every assessment. Teams can also run agents individually, set pause points, and step in manually at any moment, with every agent action recorded in an activity log and reporting via notifications.

A manual vendor assessment takes 12 to 15 hours, and roughly 90% of legacy third-party risk management effort goes to workflow administration. Automation Orchestrator hands the administration to the agents and returns the time to risk decisions.

“Most assessment work is chasing documents, reading evidence, and rebuilding the same summaries over and over,” said Juan Rodriguez, CEO of Whistic. “Automation Orchestrator gives that work to agents built on Whistic AI that has run in Assess for more than two years, with 96% accuracy, confidence scores, and source citations. Nothing about review, approval, or the final risk judgment changes. Your team automates the assessment and owns the decision.”

Orchestrator is built as a general agent hub for risk operations, and vendor assessments are the first workflow it automates. The roadmap extends the same architecture to vendor intake, issue management, agent metrics, and agentic reassessments that surface what changed with a vendor since the last review.

“Source gathering used to eat the front half of every assessment,” said the head of third-party risk at an enterprise healthcare company that ran Orchestrator during early access. “Now the file is waiting for us. Evidence collected, analysis run, summary written. We open it, weigh the findings, and make the call. That is the job we were hired to do.”

Automation Orchestrator is generally available today to every Whistic Assess customer with Whistic AI enabled, with no separate purchase or add-on. Whistic is demonstrating Orchestrator live this week at the ISACA + IIA GRC Conference in San Diego, August 17 to 19. For a full walkthrough of how the agents run an assessment end to end, read the launch article.

Additional Resources

•      Read the launch article: Introducing Automation Orchestrator

•      Watch the on-demand launch webinar: lp.whistic.com/automation-orchestrator-recording

•      Explore the Automation Orchestrator platform page

•      See the updated Whistic Assess page

About Whistic

Whistic is the Agentic Risk Operations Platform built for the teams making the calls. Agentic AI assesses vendors, monitors public, dark web, and SEC sources around the clock, tests internal controls with automatic evidence capture, and shares security posture through a Trust Center network of thousands of vendor profiles. Every alert, response, and test is logged with timestamps. Security and risk teams scale their programs, take action in one workflow, and stay audit-ready by default. Software does the work so humans can make the calls. Learn more at whistic.com.

Media Contact

Wade Tibke, VP of Marketing, Whistic | press@whistic.com

###

Certifications and Security Partnerships

Iso 27001 Iso 42001 Nist Gdpr compliant Shared assessments Aicpa soc2 Start level one Tx ramp