How The Agency works, where your data lives, what we cover for compliance, how to try it before buying — and a few other things we get asked a lot.
About RiskXchange
What the company is, what it costs, and how it compares.
RiskXchange is a third-party risk management platform. It rates the security posture of an organisation and its vendors from the outside in, combines that with the evidence vendors supply themselves — questionnaires, certifications, policies, trust-centre data — and keeps both under continuous monitoring. The outside-in network covers more than five million companies. On top of the platform sits The Agency, a workforce of AI agents that runs the assessment, chasing, remediation and reporting work a TPRM team would otherwise do by hand.
The practice of identifying and controlling the risk an organisation takes on when it depends on someone else — vendors, suppliers, service providers, and the parties behind them. It exists because of a structural asymmetry: outsourcing a function transfers the work and the control, but not the accountability to your regulator or your customers. It covers more than security, taking in concentration and resilience, financial stability, sanctions exposure and data protection. Our full explainer covers the lifecycle, what a framework contains, and where programmes fail.
The platform is sold as three annual tiers, and the prices are published rather than gated. Essentials is £14,900 a year (50 vendors), Professional £31,500 (150 vendors), and Enterprise starts at £75,000, quoted against portfolio size, regulatory load and rollout pace. All tiers include unlimited user seats and carry no setup fee. Full feature comparison on the platform pricing page; the main pricing page covers advisory engagements and the managed programme.
The security-ratings and TPRM market includes Bitsight, SecurityScorecard, UpGuard, Panorays and Prevalent, among others. Most of them are strong at one of the two signals: either outside-in scanning or questionnaire and evidence management. RiskXchange's argument is that the two together are what produce a defensible view — a rating tells you what an attacker can see, evidence tells you what the vendor claims, and the gap between them is the finding. The second difference is that the assessment work runs on agents rather than on headcount. We publish a platform comparison with pricing attributed to named, dated sources, and a ranked review that says where RiskXchange is not the right fit.
Founded in 2020. Headquarters in London, with offices in Austin, Texas and Dubai. The company began as a conventional TPRM platform built on a continuously growing network of monitored companies; the shift to an agent-based model came in 2024, after customers kept hitting the same headcount ceiling — more vendors to assess than analysts to assess them. More on the about page.
RiskXchange was named a Gartner Cool Vendor in third-party risk management, selected for its agentic approach to TPRM and the depth of its outside-in data. Customer reviews are published on Gartner Peer Insights. For security and compliance credentials — ISO 27001, SOC 2 Type II, data residency and sub-processors — see the Data & Security section below and the trust centre.
Mostly regulated mid-market and enterprise organisations with vendor portfolios large enough that manual assessment has stopped scaling — commonly financial services, insurance, healthcare, technology and retail. The common trigger is regulatory: DORA, NIS2, ISO 27001 surveillance or a supervisory review that asks for evidence a spreadsheet cannot produce.
The Agency
How the AI workforce works, what makes it different, and how you stay in control.
The Agency is RiskXchange's AI workforce — five lead agents and twenty-seven specialists, each one trained for a single part of the third-party risk lifecycle. Together they cover vendor onboarding, evidence assessment, continuous monitoring, remediation and regulatory reporting end to end.
They're not chatbots. Each agent is a purpose-built workflow that does specific jobs — drafting and chasing vendor questionnaires, parsing trust centre evidence, running outside-in scans, generating regulatory reports. They have memory across interactions, structured handoffs to other agents, and produce auditable output.
Yes — within boundaries. ARIA reads vendor evidence and hands findings to TARA for tiering. REX detects a breach and notifies NOVA so the relationship is updated. VANCE composes board reports from intelligence the others produced. The handoffs are structured and logged so you can audit who did what.
Three modes, set per vendor: Manual (no agent involvement), Assisted (agents draft, humans approve every action), and Autonomous (end-to-end execution, humans notified rather than blocking). You set the mode on each supplier, so a critical vendor can require sign-off on every action while a low-risk one runs hands-off.
Correct. NOVA is the only agent that communicates with vendors directly — across email, WhatsApp and in-app chat. Every other agent works on the platform side. Your vendors see one consistent face for the whole relationship.
Vendors & onboarding
How vendors get added, what NOVA asks them for, and how the workflow handles real-world edge cases.
You add a vendor manually or via CSV, and NOVA's intake pipeline takes over — firmographic enrichment runs first, then NOVA reaches out to the vendor through their preferred channel and starts evidence collection. ARIA pre-populates whatever it can from documents the vendor has already shared on their trust centre or in previous engagements.
Email, WhatsApp and in-app chat. NOVA picks the channel based on your customer preferences and what the vendor has previously responded to. You can be looped into any conversation NOVA is already having — multi-party threads work across all three channels.
NOVA detects bounced emails, out-of-office replies and explicit handoff signals, then re-routes the workflow to a new point of contact — either one you nominate or one NOVA discovers from the vendor's public org chart and verifies before engaging.
Yes. You can pause NOVA on a per-vendor basis at any time. Useful for sensitive commercial conversations or when a relationship is being renegotiated and you want human-only contact during that window.
Data & security
Where your data lives, who can see it, and the controls we have around it.
We run regional environments in the UK, EU and US. Your tenant data stays in the region you select at onboarding and is not replicated outside it without your explicit instruction. Talk to sales for specific data-residency requirements.
Only your authorised users and the platform itself. RiskXchange staff don't access tenant data except via explicit, time-bound, audit-logged support sessions you've approved.
ISO 27001, SOC 2 Type II, and we're aligned to NIST CSF and DORA's operational resilience requirements. Full certification documents and our SIG questionnaire are available on request from sales.
We maintain a public sub-processor list and notify customers in advance of any additions. Tenants can pin to a specific sub-processor list at onboarding for regulatory requirements.
Tenant data is retained for 90 days after termination by default, then permanently deleted with a verifiable destruction record. Custom retention windows are available on Enterprise.
Compliance frameworks
Which frameworks the platform covers and what TARA and VANCE produce for each.
DORA, NIS2, ISO 27001, NIST CSF, PCI DSS, APRA CPS 230, ADHICS (UAE) and GDPR. We add new frameworks as customer demand and regulatory clarity drive them.
TARA continuously assesses each vendor's posture against the framework requirements you've assigned to them. Gaps are surfaced as ranked findings with suggested treatment paths and SLAs. You don't run gap-analysis projects any more — TARA does it on the rolling basis the regulators actually expect.
VANCE composes regulator-aligned reports (DORA Article 28 reports, NIS2 incident packs, etc.), audit-ready evidence trails for internal and external audit, and board-pack summaries that surface portfolio-wide patterns. The output is generated from live data, not hand-assembled by an analyst.
Audit-ready out of the box — formatted templates per regulator, with linked evidence, agent attribution, and a tamper-evident audit trail of who and what produced each output. Most customers send VANCE's output directly to their auditors with light review.
Platform & integrations
How the platform fits into your existing stack — identity, ticketing, GRC, and APIs.
Yes — SAML 2.0 and OIDC. Native integrations for Azure AD / Entra ID and Okta ship on Enterprise. Other identity providers via SAML on request.
Out of the box: Jira, ServiceNow, Archer, OneTrust, Slack, Microsoft Teams. Custom integrations available on Enterprise via our API.
Yes — full REST API access on Professional and Enterprise. Webhooks for event-driven workflows. We publish the OpenAPI spec and provide sandbox tenants for integration development.
Pricing & trials
How to get started without a procurement cycle.
Yes. Run a free SnapShot — pick a live vendor and we'll have NOVA, ARIA and REX produce a complete posture report within 24 hours. No procurement, no commitment.
On the platform pricing page. Three tiers — Essentials, Professional, Enterprise — with the full feature comparison and a tier-specific FAQ. The main pricing page covers the fixed-price advisory engagements and the managed programme.
Essentials goes live the same day. Professional typically takes one to two weeks with the dedicated CSM. Enterprise white-glove onboarding runs to whatever rollout schedule you set — often four to eight weeks for multi-region deployments.
Still have questions?
Book a 30-minute call with the team and we'll work through the details specific to your portfolio, your frameworks, and your rollout. No procurement detour required.