Machine Insights, Human Decisions: How AI Is Changing Third Party Risk Assessment
Third Party Therapy Podcast — featuring Aki Eldar, co-founder of Mirato
Artificial intelligence is either the biggest opportunity or the biggest risk in third party risk management (TPRM), depending on who you ask. In this episode of Third Party Therapy, host Mike Day speaks with Aki Eldar, entrepreneur and co-founder of Mirato, about where AI genuinely moves the needle in TPRM today — and where the industry needs to temper its expectations.
From Data Protection to TPRM
Aki's route into TPRM AI is not a straight line. He founded his first company, Secure Islands, in 2006, focused on classifying and protecting unstructured data — years before the concept of protecting the data itself, rather than the network perimeter, became mainstream. Secure Islands was acquired by Microsoft, and its technology now underpins what is broadly known as Microsoft's information protection capability. Five and a half years ago, Aki and co-founder Itay Hochman founded Mirato, bringing that same data and AI background to a discipline he describes as still "stuck ten years ago" — a world where workflow has been automated, but the actual work of assessment has not.
Where AI Fits Today: Subjective and Objective Data
Aki frames Mirato's value proposition around two categories of data:
• Subjective data — the evidence documents a third party supplies, sometimes running to thousands of pages, which must be manually mined for evidence against hundreds of controls.
• Objective data — external data sources (some paid, some free) that enrich and cross-check what the third party has provided.
Rather than requiring organisations to hire more assessors to increase either the volume or quality of assessment, Mirato's model trains the technology once and then scales it indefinitely — reading documents automatically, finding supporting evidence for controls, and pulling in external data sources without needing to add subject-matter experts for every domain.
The accuracy claim is notable: Aki cites Mirato's own accuracy at "a little bit more than 90%", against what he says published studies put human assessor accuracy at around 60%. He is careful to frame this as augmentation, not replacement, of human judgement — Mirato's slogan is "machine insights, human decision."
Editorial note: the specific accuracy figures cited above are Aki Eldar's own claims made on the podcast and have not been independently verified — readers should treat them as one vendor's stated position rather than a confirmed industry benchmark.
Killing the Questionnaire
One of the more concrete products discussed is MQK — Mirato Questionnaire Killer — which flips the traditional due diligence questionnaire on its head. Instead of a vendor manually answering hundreds of questions, they upload their evidence documents and the system answers the majority of the questions automatically, based on what's actually written in that evidence. The vendor still attests to the answers, preserving accountability, and can request clarifications where needed.
Both this tool and Mirato's core control-assessment product provide a full audit trail: every finding links back to the specific document, page and highlighted paragraph that supports it.
Why Auditability Matters More in TPRM Than Almost Anywhere Else
Auditability isn't a nice-to-have here — it's existential. Aki is direct about the risk of "black box" AI in a regulated space: if you can't explain why a decision was reached, neither can the regulator, and that is simply unacceptable in most TPRM contexts. This is also Mirato's answer to one of generative AI's best-known weaknesses — hallucination and inconsistency. Because Mirato's assessments are fully explainable and evidence-linked rather than generative, Aki says the same inputs reliably produce the same outputs, run after run — something he notes is not guaranteed with off-the-shelf generative AI, and is often not true of human assessors either.
Beyond Assessment: Aggregation, Fourth Parties and Continuous Assessment
The conversation moves into territory relevant to concentration risk and extended supply chain visibility, an increasingly urgent regulatory concern under frameworks like DORA. Aki describes a "risk hunter" capability that automatically maps relationships between products, software packages, locations and departments to expose cascading and aggregation risk — including fourth parties.
He also draws a sharp and useful distinction between two terms often used interchangeably:
• Continuous monitoring — data changes continuously, but still requires a human to review it before it can be acted on.
• Continuous assessment — the system itself detects when a change crosses a meaningful threshold and alerts the organisation automatically.
Aki is candid that true predictive capability — anticipating incidents before they happen — isn't realistic yet. His view is deliberately incremental: get the assessment fast and accurate first, then build continuous assessment, and only then start thinking about prediction. "I don't believe in revolutions," he says, "I believe it's incremental."
The Risk of AI Assessing AI-Generated Data
Mike raises a sharper question: as AI-generated content proliferates, is there a risk that the data organisations feed into AI-driven assessment tools is itself increasingly AI-generated — creating a feedback loop that erodes reliability over time? Aki's answer circles back to design principles: as long as a system remains fully explainable and provides a complete audit trail, the ability to control and interrogate outputs is retained regardless of the provenance of the underlying data.
The Two Warnings for TPRM Leaders Considering AI
Asked what mistakes he's already seeing, Aki offers two clear warnings:
1. Don't try to solve everything at once. Bring value quickly with a narrow, well-defined use case, then expand — the classic minimum viable product approach.
2. Don't build AI capability in-house just because it's fashionable. TPRM, in Aki's view, is not the most strategic function in which to build proprietary AI, because the resulting models don't transfer to other parts of the business — you'd be paying, by his estimate, roughly ten times more to build and retrain a capability that specialist vendors already offer.
Practical First Steps
For any organisation starting this journey, the recommended approach is: define a specific use case with real value, define clear success metrics and KPIs, compare a small number of vendors solving a similar problem rather than chasing "best overall", start with a narrow scope (one or two risk domains, not the entire assessment), and start standalone before integrating into your broader IRM and workflow stack.
The direction of travel Aki describes mirrors the automotive industry's own evolution — from fully manual assembly to a process still run on the same workflow "assembly line," but where machines now do roughly 80% of the work, freeing people to focus on judgement rather than administration. His ambition for TPRM: flip today's roughly 80% data administration / 20% risk and mitigation split into its inverse.
Listen to the full episode of Third Party Therapy, produced in association with CeFPro, on Apple Podcasts, Spotify, Amazon Music, Audacy and YouTube, or visit thirdpartytherapy.com to subscribe to the mailing list.
Tags
#ThirdPartyTherapy #TPRM #ArtificialIntelligence #AIinTPRM #VendorRiskManagement #DueDiligence #ContinuousMonitoring #ContinuousAssessment #RegTech #ThirdPartyRisk #GenerativeAI #ExplainableAI #DORA #FourthPartyRisk #RiskManagementPodcast #HowIsAIUsedInThirdPartyRiskManagement #AIVendorDueDiligence #TPRMPodcast


