What Diligent actually launched
Based on the available description, this is not just a chatbot layer added on top of a GRC platform. Diligent is positioning the release around orchestration agents and specialised AI agents that can coordinate work across audit and risk workflows.
The main pieces include:
- An orchestration agent that accepts natural language instructions
- Specialised agents for different risk and audit tasks
- Live-data reporting for board-ready outputs
- Continuous oversight features tied to risk and controls activity
- A connected intelligence layer that links GRC context across the platform
That matters because GRC work is often less about answering a question and more about moving a process forward: assigning tasks, following up overdue actions, gathering evidence, checking controls, and escalating issues when needed.
The practical shift: from point-in-time reporting to ongoing oversight
The core promise here is straightforward. Instead of waiting for periodic reviews, Diligent wants teams to work from a more continuous monitoring view of changing risk conditions.
In enterprise risk management, the new agentic layer is described as supporting tasks such as:
- Monitoring risk data
- Cleaning and maintaining records
- Coordinating assessments
- Following up on overdue actions
- Escalating issues
- Identifying emerging risks
In internal audit, the tooling appears designed to help teams:
- Identify relevant risks
- Map those risks to audit objectives
- Link existing controls
- Support evidence collection
- Assist with testing and findings development
This is where the launch becomes more interesting than a generic “AI for compliance” announcement. Diligent is targeting routine coordination work that consumes time but still depends heavily on context.
Why orchestration matters more than Q&A
A standard AI assistant can answer prompts. An orchestration agent is meant to do more than that.
Diligent says its orchestration agent can route tasks to specialised agents across different parts of the audit and risk process. That suggests a workflow model where the AI is not only retrieving information, but also coordinating steps and approvals.
For GRC teams, that is a meaningful distinction. The bottleneck is often not finding a policy or summarising a control. It is making sure the right work gets triggered, assigned, reviewed, and documented with enough traceability to stand up to scrutiny later.
If Diligent’s implementation works as intended, the value will likely come from reduced coordination drag rather than from flashy AI interactions.
The data layer is the real product story
Agentic AI in regulated workflows only becomes useful when it has domain context. Diligent’s answer to that is what it calls a connected intelligence layer, described as a “GRC brain” linking regulations, obligations, policies, controls, risks, evidence, and actions across the organisation.
That is a more serious proposition than letting a general-purpose model generate summaries from isolated documents. In risk and audit, disconnected answers are often worse than no answer at all. They can sound convincing while missing the control history, ownership chain, or underlying obligation.
The description suggests Diligent is trying to ground agent behaviour in the organisation’s actual governance and risk structure. That is the right direction for this category.
Board-ready reporting from live data
Diligent also introduced AI reporting features that can generate reports from live risk and controls data, using either conversational prompts or templates. The reports are described as including source citations.
This part of the launch may end up being one of the most immediately valuable features for many teams. Reporting is one of the most visible pain points in GRC: slow to assemble, manually updated, and often dependent on stitching together information from multiple owners.
If report generation is tied closely enough to current risk and control data, teams could spend less time formatting updates and more time checking whether the content reflects the real risk picture.
For boards and executives, the appeal is obvious: faster reporting with clearer traceability. For practitioners, the upside is less repetitive reporting work and fewer last-minute document drills.
Where this could fit best
This launch appears best suited to organisations that already have meaningful GRC processes and enough data inside Diligent One for the agents to work with context.
The strongest fit is likely:
- Risk teams managing frequent assessment cycles
- Internal audit teams with recurring evidence and testing workflows
- Governance teams preparing board-facing reports
- Organisations trying to move from periodic reviews to continuous monitoring
The weaker fit may be teams looking for a quick AI overlay without structured underlying data. Agentic workflow tools tend to perform best when the process, ownership, and records are already reasonably mature.
Tradeoffs to watch
The promise of “continuous oversight” sounds attractive, but it introduces practical questions.
First, more automation can create more noise if escalation rules and task routing are not tuned carefully. A system that flags everything quickly can still slow teams down.
Second, board-ready reporting generated from live data is only as reliable as the source systems and governance behind them. If controls data is incomplete or stale, AI will not fix that on its own.
Third, Diligent itself appears careful to frame this as decision support rather than decision replacement. That is the right posture for audit and risk functions, where accountability, professional judgement, and approval trails still matter more than speed alone. For related governance concerns, see oversight.
Why this launch is worth watching
There are many AI tool announcements in compliance and risk, but a large share still focus on drafting, summarising, or search. Diligent’s update stands out because it is framed around workflow execution inside an established GRC environment.
That makes the product direction more concrete. The company is not just saying “ask AI about risk.” It is saying AI should help monitor changes, coordinate actions, support audit work, and produce reporting tied to live operational context.
For buyers evaluating AI in GRC, that is the more useful question to ask: not whether a model can answer policy questions, but whether it can reduce the real friction in risk and audit operations without weakening oversight.
Availability signal
Diligent said the connected intelligence layer at the centre of this update will become available in select solutions in October. That timing matters because the effectiveness of the broader agentic approach seems closely tied to that shared context layer.
Teams considering the launch should pay close attention to which parts of Diligent One receive the connected layer first, and how much of their existing workflow can actually be grounded in it.
The takeaway
Diligent’s launch is a pragmatic bet on where AI can earn its place in GRC: not by replacing judgement, but by reducing manual coordination, tightening follow-up, and speeding reporting from live data. If your risk or audit team is stuck in spreadsheet-heavy, point-in-time workflows, this is the kind of product move worth watching closely.
The real test will be simple: whether these agents can help teams act faster without making governance looser. In GRC, that balance is the whole product.
Comments (0) No comments yet
Want to join this discussion? Login or Register.
No comments yet. Be the first to share your thoughts!