RiskHeatMap.aiGoverned demo

Incident Detail

Explainable by design

Vendor access review evidence overdue

Review the agent-generated root cause analysis, issue framing, control posture, risks, and actions before final approval.

Human approval remains required before controls, risks, and actions are finalised.

Incident

The source event that triggered downstream agent work.

System
Third-party Assurance
Reported
Jul 11, 2026, 1:30 AM
Severity
Medium
Status
Open

Quarterly access certification evidence for a conveyancing data provider was not supplied before the assurance deadline.

Issue

Human-reviewable issue statement generated from the RCA.

P2Approved

Third-party assurance evidence is not continuously tracked

Manual collection and escalation create avoidable gaps in vendor control assurance.

Owner: Vendor Risk

Root Cause Analysis

Mock AI-generated narrative based on deterministic rules.

Ai Generated79 Confidence

Trigger

Quarterly vendor evidence deadline passed without an accepted submission.

Summary

The assurance workflow relied on manual evidence reminders and did not escalate the missed certification deadline early enough.

Contributing factors

  • Evidence collection remained email-driven.
  • No automated escalation was tied to the assurance due date.
  • Vendor ownership changed during the review cycle.

Risks

Inherent and residual risk posture tied to this incident.

Third-party assurance coverage risk

ResidualMediumApproved

Missing evidence reduces confidence that vendor access controls continue to operate effectively.

Third PartyScore 51

Data classification

Deterministic P0–P4 classification over the incident, issue, and RCA text.

P3Standard

Standard internal business content was detected.

Reasons

Contains standard internal business process content.

Matched signals

workflow

Recent audit events

Key system events for this incident package.

Human Reviewer

Jul 11, 2026, 2:10 AM

Review Approved

issue issue-vendor-003

Evidence Monitor

Jul 11, 2026, 1:30 AM

Evidence Overdue

evidence evidence-access-review

Controls

Control posture classified as effective, weakness, or gap.

Vendor evidence due-date monitoring

WeaknessApproved

Assurance evidence is tracked against owners, due dates, reminders, and escalation thresholds.

Owner: Vendor Risk

Actions

Recommended remediation work generated from the simulated agents.

Automate vendor evidence escalation

OpenApproved

Create evidence reminders and owner escalation seven days before each due date.

Vendor RiskDue Jul 25, 2026