
Anyone who has taken a SaaS product through a serious security review knows the routine. A questionnaire with two to three hundred questions goes to the vendor. Two weeks later it comes back half filled in, with references to a whitepaper and a link to a trust center that you can only open after signing a non-disclosure agreement. Then the ping-pong starts.
The obvious question: why don't vendors simply publish their security documentation in a way that an AI agent can read and check against your internal requirements? All the effort with questionnaires, mapping and follow-up questions would disappear. The idea is right. Today it mostly fails at the customer's end.
Where the time really goes
The expensive part is the translation. You ask questions in your format, along your controls. The vendor answers in its format, along its certification. Someone has to map these two worlds onto each other line by line, spot the gaps and follow up. With twenty critical suppliers a year, that quickly adds up to weeks, spread across people who don't have the time for it.
On the vendor side it looks like a mirror image. A Swiss software company that sells to banks, insurers and hospitals answers the same questions dozens of times a year, each time in a different Excel template. That ties up people in sales and delays deals. After the deal, nobody looks at the answers again.
Europe is making supplier reviews mandatory
The pressure currently comes from European regulators. Since 17 January 2025, the Digital Operational Resilience Act (DORA) has applied in the EU. Financial entities must keep a register of all contractual arrangements with ICT service providers and make it available to supervisors, distinguishing whether a service supports critical functions. NIS2 obliges essential and important entities to actively manage the security of their supply chain.
The Cyber Resilience Act goes one step further towards data. From December 2027, manufacturers of products with digital elements must keep a software bill of materials in a commonly used, machine-readable format in their technical documentation. That also affects Swiss manufacturers as soon as they sell into the EU.
In Switzerland these obligations have existed for longer. FINMA Circular 2018/3 requires banks and insurers to carefully select, instruct and monitor their service providers when outsourcing, including audit and inspection rights. Article 9 of the Data Protection Act requires every company to make sure that its processor can guarantee data security. And Article 9 of the Information Security Act obliges federal authorities to pass their security requirements on to third parties by contract and to verify their implementation.
On the evidence side, the C5 catalogue of the German BSI is already a standard for cloud providers that is used well beyond Germany. An independent auditor attests there that the controls were effective over a period of time. Security evidence is turning into data. An agent compares data faster and more thoroughly than any person with two Excel windows open.
Why the agent alone doesn't solve the problem
A comparison needs two sides. However cleanly the vendor structures its evidence, the agent needs something to check it against. In most Swiss SMEs I know, this second side doesn't exist in usable form. The requirements for suppliers sit in an old questionnaire, in individual contract clauses and above all in the head of the IT manager. An agent that is supposed to check against implicit knowledge delivers either nothing or something arbitrary.
The second problem is more fundamental. Documentation describes an intention. An access control policy says what a vendor intends to do. Whether it actually does it is shown only by independent evidence: a C5 attestation or a comparable audit report that proves effectiveness over a period of time, or an ISO 27001 certificate whose scope covers the service you are buying. An agent that reads marketing-style self-declarations and marks them as fulfilled automates compliance theater instead of ending it.
On top of that comes a risk that is new with agents. Whoever lets an agent read content written by a third party lets that third party have a say. A vendor document can contain wording designed to steer an agent. This type of attack is called prompt injection, and it is still not reliably solved for language models. The very party that is being assessed supplies the material the assessment rests on.
The responsibility stays with the customer. Neither the Data Protection Act nor FINMA nor DORA accepts "the agent checked it" as a justification.
What a model that holds up looks like
I consider a model with four elements realistic. The vendor provides audited evidence in a structured, machine-readable format, cleanly organised along a recognised standard such as ISO 27001 or C5. You keep your own requirements catalogue in the same format: which controls you expect from which type of supplier, graded by criticality. The agent compares the two and marks what is proven, what is only claimed and what is open. And a person decides on the gaps and the residual risk.
In this model the work shrinks from weeks to the points that need a judgement. Follow-up questions become precise, because the agent can name exactly which requirement is missing and which evidence would be needed for it. The recurring reassessment, which many companies simply skip today, becomes almost free.
What this means for Swiss vendors
For software companies and service providers that sell to regulated customers in Switzerland and the EU, this is an opportunity. Whoever provides evidence in a way that lets the customer finish the review in days instead of months shortens their own sales cycle. In tenders with regulated customers that becomes an advantage, because the security review is no longer the step where the schedule breaks.
What counts now
The technology for agent-based supplier reviews is largely there. Whether your vendors provide audited evidence is something you can only influence through your purchasing and your contract clauses. Whether your own requirements are written down clearly enough for a machine to work with is entirely up to you. Whoever tackles that today is ready when the vendors catch up, and usually discovers along the way which suppliers were never properly reviewed.




