OpenAI's Trove Agent Automates Third-Party Risk Analysis

OpenAI unveils Trove, a custom GPT agent that automates third-party risk analysis using web search, Google Drive, and Google Docs.

4 min read
Screenshot of OpenAI's platform showing the creation of the Trove agent for third-party risk analysis.
Image credit: OpenAI· OpenAI Youtube

OpenAI is expanding the capabilities of its custom GPT agents with the introduction of Trove, a specialized tool designed to automate the complex and time-consuming process of third-party risk analysis. Demonstrated by OpenAI's Ho Jun, Trove represents a significant step towards empowering businesses with AI-driven compliance and risk management solutions.

The video showcases how Trove functions as a Third Party Risk Manager agent. It takes vendor details as input, utilizes web search to gather relevant information, and cross-references this with a predefined risk criteria spreadsheet stored in Google Drive. The output is a polished Google Doc report, serving as a comprehensive assessment of the vendor's risk posture.

The full discussion can be found on OpenAI Youtube's YouTube channel.

Workspace agents in ChatGPT: Third-party risk management agent - OpenAI Youtube
Workspace agents in ChatGPT: Third-party risk management agent — from OpenAI Youtube

Building the Trove Agent

Ho Jun walks through the creation of the Trove agent, highlighting the modular approach to building custom GPTs. The process begins by defining the agent's core function: to conduct criterion-based vendor risk assessments. This involves specifying the necessary tools and skills.

Related startups

Trove's workflow is designed to be thorough and efficient. It starts by accessing vendor details and then proceeds to use web search to collect current evidence. This evidence is mapped against the user's risk criteria, which are sourced from a Google Drive spreadsheet. The agent then synthesizes this information to produce a detailed report in Google Docs.

The video demonstrates the agent's ability to integrate with existing business tools. By connecting to Google Drive and Google Docs, Trove can access and generate documents, streamlining the workflow. The agent is also configured to respond to messages within ChatGPT, making it accessible to users familiar with the platform.

Key Capabilities and Workflow

The Trove agent is built with specific capabilities to perform its risk assessment duties effectively:

  • Assess vendor risk: The primary function is to evaluate third-party vendors against established risk criteria.
  • Apply risk criteria: The agent uses a predefined risk framework, often from a Google Drive spreadsheet, to standardize assessments.
  • Draft report docs: Trove generates a polished Google Doc report summarizing findings, risk posture, and recommended next steps.

During the demonstration, the agent is tasked with assessing a hypothetical vendor, "Acme." Trove initiates the process by pulling vendor risk workflow data. It then locates the relevant criteria sheet in Google Drive and begins gathering current evidence from Acme's website and public sources. This evidence is used to populate the risk matrix within the assessment.

The agent's internal thought process is made visible, showing its steps: opening the workflow, searching for the criteria sheet, researching Acme, and finally drafting the Google Doc. This transparency allows users to understand how the agent arrives at its conclusions.

Automating Complex Tasks

The video highlights the potential for Trove and similar agents to automate tasks that are traditionally manual and labor-intensive. Third-party risk assessment involves extensive research, data analysis, and report generation, all of which can be prone to human error and time constraints.

By automating these steps, Trove aims to:

  • Increase efficiency: Significantly reduce the time required for vendor risk assessments.
  • Ensure consistency: Apply risk criteria uniformly across all vendors, eliminating subjective variations.
  • Free up analysts: Allow human analysts to focus on higher-level strategic tasks and complex cases, rather than routine data collection and report drafting.

The demonstration culminates in the generation of a detailed risk assessment report for "Acme." The report includes a risk summary, a detailed risk matrix with criterion ratings and key rationales, and a section for detailed findings. This output mirrors the kind of comprehensive analysis expected from human risk professionals.

Availability and Future Potential

The video concludes by stating that custom GPTs like Trove are available in ChatGPT Business, Enterprise, and Edu versions. This suggests a strategic push by OpenAI to integrate these powerful AI tools into professional workflows across various sectors.

The development of agents like Trove signals a broader trend in AI development: the creation of specialized assistants that can perform complex, domain-specific tasks. This moves beyond general-purpose chatbots towards more targeted solutions that can directly address business needs, such as compliance, financial reporting, and operational efficiency.

The ability to build and deploy custom agents that can interact with various data sources and applications is a key feature of OpenAI's evolving platform. This allows organizations to tailor AI solutions to their unique requirements, potentially transforming how risk management and other critical business functions are performed.

© 2026 StartupHub.ai. All rights reserved. Do not enter, scrape, copy, reproduce, or republish this article in whole or in part. Use as input to AI training, fine-tuning, retrieval-augmented generation, or any machine-learning system is prohibited without written license. Substantially-similar derivative works will be pursued to the fullest extent of applicable copyright, database, and computer-misuse laws. See our terms.