GRC Data & AI Summit 2026
First look · Jaimin Shah, Global CISO, APEX Fintech Solutions · Roi Amior, CPO & Co-Founder, Anecdotes
Jaimin Shah names three pain points that will sound familiar. Manual work everywhere, from classifying vendors to chasing SOC 2 reports and DPAs, and then doing all of it again next cycle. No single source of truth, with vendor information scattered across email threads, Slack, spreadsheets, and trust portals. And the trust gap: risk does not stay still, but the assessment does. It is accurate the day you capture it and stale every day after. Roi Amior then gives the first look at agentic TPRM from Anecdotes: plugins discovering vendors across ERP, identity, finance, and procurement systems, agents tiering each vendor against your own classification criteria, and document agents assessing pen test reports, SOC 2s, and AI policies against your controls. You set where approval is required. Every agent decision is traceable and yours to override.
What you'll take away