Collecting Artifacts Isn't The Same As Analyzing Them
About the Company
CrestaCresta unlocks the true potential of the contact center, turning every customer conversation into a competitive advantage.
- Headquarters:Sunnyvale, California
- Company Size:501-1,000
- Industry:Software Development
Cresta is an enterprise AI platform for the contact center, built to turn every customer conversation into a competitive advantage. Founded in 2017 out of the Stanford AI Lab, it serves Fortune 500 enterprises across telecommunications, financial services, and hospitality.
Ryan Mathew leads GRC at Cresta, a remit that spans customer-facing security, compliance, and third-party risk. On the vendor side, he kept running into the same problem every security team does. Vendor risk has become an exercise in collection, not analysis.
"A lot of time was spent just getting the information and initiating the process, and almost no time was spent in actual analysis and review."
Why most vendor reviews skip the review
Ryan has run vendor risk programs before, on the workflow-heavy platforms that dominate the category. He knows what those tools are good at, and where they stop.
"What vendor risk management has become is just this big information gathering, but no review of the information."
His read is that the category optimized for the wrong thing. The established platforms built more and more elaborate approval chains, routing a document from one reviewer to the next until someone clicks approve. The workflow kept getting heavier while the analysis went missing. More routing never meant more review.
"They collect everything and then they say, now it's up to you to click a button."
A vendor comes in on a deadline, the documents and the questionnaire take time to land, and by the time everything is in hand there is no room left to actually read it. The review becomes a record that a review happened.
What the team cut
The old model put the questionnaire at the front door. Ryan moved it to the back. The vendor's documents go in first, Lema analyzes them and maps the findings against the controls that matter, and the questions come after that, targeted only at the gaps the artifacts leave open. The questionnaire he inherited was long, a trimmed version of a standard industry set. What replaced it is a shorter more focused set of questions, "I wanted to get away from the questionnaire piece and completely rely on Lema's analysis."
Where the review time goes
With the collection step compressed, the team's time moves to the part that was missing. Lema reads the vendor's documentation and returns the findings and gaps in a form a person can work through in minutes.
"It does the analysis and the review piece. That's the important part in vendor risk management, which is completely lost, forgotten."
That changes what Ryan spends his attention on. Instead of chasing every policy, he works the gaps Lema surfaces and follows up on the ones that matter for Cresta. Two come up consistently: a vendor's breach notification SLA, and how a vendor uses Cresta's data for model training.
"Within the 5 to 10 minute decision time I have to make a decision about this vendor, I'm actually focusing on important things."
A review you can stand behind
Ryan puts the difference in one line.
"It's actual vendor risk management, compared to the checkbox exercise."
What he values is not a faster clock. It is that a genuine review now happens, instead of an approval resting on the fact that a vendor has a SOC 2 report. Lema does the reading a person would do, if a person had the time.