Brex’s Journey with Drata’s TPRM Agent: Turning Evidence Overload into an Advantage

Overview
Brex is a fast-growing financial technology company operating in a highly regulated environment where customer trust depends on rigorous security, compliance, and risk management.
Its Trust and GRC teams manage third-party risk across a complex ecosystem of vendors and subprocessors, all while staying lean and audit-ready. Priyanka Chaudhary, Head of GRC, describes third-party risk management as one of GRC’s more mature programs, built to support intensive external audits and a constantly evolving vendor landscape.
To keep scaling that maturity, Brex joined Drata’s design partner program for Drata’s TPRM Agent, an AI-powered capability within Drata’s Third-Party Risk Management product. Working closely with Drata’s product team, they are shaping a criteria-driven, evidence-first model for third-party risk.
Both Priyanka and Allan Silva, Senior GRC Lead, bring strategic and practitioner perspectives to this journey, helping ensure the agent reflects real-world TPRM realities rather than a theoretical ideal.
For Brex, this work is also part of a broader move toward continuous, integrated trust on Drata’s Agentic Trust Management Platform, where agentic AI handles repeatable evidence work so human experts can focus on higher-value decisions.
The Reality of Modern Third-Party Risk at Brex
For Brex, third-party risk management is a core element for how the company supports growth and innovation while maintaining trust. As Brex expands its ecosystem of vendors and technologies, the program is continuously evolving to a more scalable model that can keep pace with the speed of the business.
That evolution amplifies two ongoing priorities for the GRC team:
Maintaining clear, end-to-end visibility into how third parties are used across the business as vendors are added, changed, and retired.
Scaling reviews so the team can quickly sift through growing volumes of third-party information and focus effort where it matters most, without slowing down the business.
As Priyanka puts it, the hardest part is sustaining that end-to-end visibility and focus:
“The biggest challenge we’re seeing with third-party risk management is maintaining visibility over all vendors across their lifecycle and making sure teams are prioritizing risk management efforts appropriately.”
Brex’s GRC function is intentionally lean, so every hour spent scrolling through reports is an hour not spent on strategic, business-aligned risk decisions. The team wants to focus on how vendors are actually used in Brex’s environment, data in scope, roles and access, integration patterns, and then right-size risk management without sacrificing rigor across their third-party ecosystem.
Inside Drata’s Design Partnership with Brex on the TPRM Agent
Brex was already using Drata in a meaningful way for its third-party risk management program when the opportunity arose to join the TPRM Agent design partner program.
That decision was driven by two key factors:
A strong existing relationship and trust in Drata’s team.
A desire to help shape what the next generation of TPRM looks like in practice, informed by Brex’s day-to-day experience with vendor risk.
What stood out about Drata's team was their eagerness to listen, iterate quickly, and stay ahead of where TPRM is heading. This is a collaboration style that matches how Brex itself approaches problem-solving.
From Brex’s side, the goal is not to fix a broken program, but to bring a mature, criteria-based practice into the product design process so that new capabilities scale best practices and help address the most painful parts of the job.
As a design partner, Brex works closely with Drata on specific TPRM use cases and workflows, using real vendor scenarios to shape how the product evolves.
Inside Brex's Work with Drata's TPRM Agent
Criteria-Driven, Evidence-First Assessments
Before the TPRM Agent, Brex had already moved toward a criteria-based model for third-party reviews. The team maintained a matrix describing what to collect and review based on the type of SaaS tool, the data in scope, and how the vendor would be used in Brex’s environment.
Applying that model at scale meant gathering documents, reviewing them line by line, and reconciling findings across standards. This is a volume challenge that even the most mature program faces as vendor ecosystems grow.
With Drata’s TPRM Agent, Brex is defining how automation can scale that model:
Define what matters to Brex first—its own criteria, risk thresholds, and documentation expectations.
Ingest large volumes of vendor documentation (questionnaires, SOC 2s, pen tests, and more) for any given vendor.
Map specific citations from those documents back to Brex’s criteria and highlight where requirements are Met, Partially Met, Not Met, or Inconclusive, including suggested follow-ups for gaps.
Allan sees particular value in this model because every company has a different risk profile. The traditional one-size-fits-all approach to vendor review doesn’t work when risk context varies so widely. With this criteria-driven, evidence-first model, Brex can go deeper across more vendors, while reducing the cognitive load of reading long sequences of documents and risking human error.
Priyanka emphasizes that this is about using criteria and evidence to focus the team’s time where it really counts:
“In order to not waste your team’s time and not miss critical risks, you do have to have that criteria-based approach.”
For Brex, the promise of AI in TPRM is not to replace judgment, but to automate repetitive, volume-heavy work like copying, pasting, and scanning multi-page reports, so the team can focus on truly assessing risk in the context of how each tool will be used.
Reimagining Review Workflows with Automation
Brex’s business teams are constantly exploring new tools and vendors, especially as AI capabilities accelerate.
That creates pressure on the GRC team to keep vendor onboarding fast but extremely reliable.
In the design partner program, Brex is exploring how the TPRM Agent can:
Streamline vendor onboarding workflows and centralize document collection.
Apply Brex’s assessment criteria to vendor evidence in a consistent, repeatable way.
Surface the right findings and evidence so GRC practitioners can quickly decide where to go deeper.
By having the agent handle the first pass on documentation and criteria mapping, Priyanka’s team can spend more time on what only humans can do: contextualizing risk with legal, privacy, AppSec, IT, procurement, and business stakeholders; deciding where contractual protections or compensating controls are needed; and ensuring vendors are used in lower-risk ways, for example, right-sizing access and making sure data is deleted and access removed during offboarding.
For Allan, who works closely with auditors, another benefit is the potential improvement in the quality of evidence and artifacts the team can generate, which helps increase productivity day to day and facilitates better preparation for external audits.
Early Signals and Executive Perspective
Working with Drata on the TPRM Agent, Brex is already seeing concrete results. Automated, criteria-driven, evidence-first analysis is helping the team:
Reduce manual review time by scoping and organizing the most relevant information for each vendor.
Improve consistency and reliability in how criteria are applied across different engagements.
Free up capacity in a lean GRC team to focus on higher-impact risk work.
From a leadership perspective, Priyanka sees this as a way to raise the bar on Brex’s security risk management program without simply adding more headcount. By automating the groundwork of evidence review, the team can better support the business as it experiments with new technologies, onboards vendors faster, and navigates an expanding attack surface tied to third, fourth, and even fifth parties.
Framing both the early impact and the potential ahead, she sums it up this way:
“Drata’s TPRM Agent allows us to level up our security risk management program across the board by reducing manual work and letting us focus on the risks that matter.”
Allan puts it plainly:
“Drata’s TPRM Agent made us a lot more productive while also improving the quality of our reviews.”
Together, these perspectives highlight a design partnership where Brex is a mature, forward-looking team co-shaping a new way to handle third-party risk at scale.
Practitioner Perspective: Reducing Friction and Refocusing on Risk
On the practitioner side, Allan and the team are living the realities of third-party risk management every day: collecting security questionnaires, reading long SOC 2 and pen test reports, and synthesizing findings into a coherent risk picture.
This is where automation has the most immediate impact.
Instead of spending hours scrolling through documents and copying information into systems of record, practitioners can:
Enable agents to analyze large document sets, extract what matters, and surface criteria-based findings and follow-up recommendations.
Focus their time on interpreting those findings, understanding how a vendor will integrate into Brex’s environment, and determining the right controls and follow-up actions.
Work more closely with business partners to ensure vendors are used safely and deprovisioned cleanly when no longer needed.
Priyanka also sees the agent as a way to elevate newer practitioners. With a strong criteria framework and agent-generated summaries in place, junior team members have a clearer starting point for contributing to vendor reviews, learning how to assess vendor risk, and expanding coverage across more vendors without overwhelming the core GRC team.
For both Priyanka and Allan, the shift is from “reading documents” to “making decisions.” Instead of drowning in data, the team can focus their expertise on contextualizing vendor risks, aligning with legal and technical stakeholders, and making sure Brex’s use of each tool truly makes sense for the business.
Where Brex and Drata Are Headed
Brex and Drata are pushing the boundaries of what AI can do in third-party risk management. As a design partner, Brex is helping define what comes next — expanding the criteria-driven, evidence-first model into new workflows, deeper integrations, and more continuous forms of vendor oversight.
Priyanka and Allan see third-party risk management evolving toward something far more dynamic: continuous, cross-functional, and context-aware — where automation handles the heavy lifting and human experts focus on the decisions that truly require their judgment.
For Brex, the goal is to stay ahead of an expanding vendor ecosystem, matching the speed at which the business adopts new technologies with equally advanced risk management capabilities. That means going beyond point-in-time assessments and toward a model where third-party risk is monitored, prioritized, and acted on continuously.
Chart Your Course
Navigate to new worlds of trust with Drata.
Chart Your Course
Navigate to new worlds of trust with Drata.