Every organisation has a sixty-item checklist somewhere that only three people truly understand. Our approach at greenstar technology turns that buried expertise into a library of AI agent skills: small, focused, version-controlled packages of instructions, reference documents, and decision logic that an AI assistant loads on demand. On a recent engagement we distilled a complex third-party assurance regime into nine specialist skills covering everything from supplier onboarding to regulatory applicability tests to pre-signature contract review. New staff get expert-level guidance from day one, and when the process changes, the skill is updated once and everyone benefits immediately.
We call the result the Compliance Assurance Agent. This is the story of how it was built, and of the approach we bring to every real-world AI engagement.
The business problem: a compliance maze
Our client’s service owners are accountable for third-party supplier contracts in a regulated environment. Regulators increasingly require firms to actively assure the operations of their third-party suppliers: contract amendments, security tiering, ongoing service reviews, and evidence of oversight. On paper, the process lived in a sixty-plus-item checklist spread across multiple spreadsheet tabs.
In practice, it was a maze. There were four distinct procurement paths, each running six to twenty-five weeks, each with different prerequisites, gates, and workstreams. The right steps depended on answers to questions that were never asked anywhere in the existing toolset. Miss a step and the contract is delayed; skip a required approval and the firm carries a compliance risk. Service owners were expected to read the manual to do their jobs, and the manual was not built for reading.
Start with the process, not the model
We don’t begin an AI engagement by asking which model to use. We begin by mapping the business process: every path, prerequisite, approval gate, and regulatory obligation. Only once the process was fully mapped did we decide which parts needed AI judgment, which needed deterministic software, and which needed a human signature. The result is a solution that fits the organisation rather than forcing the organisation to fit the tool.
Deterministic where possible, AI where it counts
Not every problem needs a language model. The Compliance Assurance Agent pairs a conventional browser dashboard — a live contract register, expiry tracking, and stage-by-stage checklists — with a set of AI agent skills reserved for the questions software alone can’t answer: does this operational-resilience regulation apply to this contract, what security tier does this supplier fall into, is this draft agreement ready for sign-off? Routing, tracking, and state live in ordinary, testable code; the AI is deployed precisely where expert judgment used to be the bottleneck. That division of labour is deliberate, and it is why the solution is trusted in a regulated environment.
Three questions instead of a sixty-page manual
Good AI solutions remove the need for training rather than adding to it. The router at the heart of the agent asks a service owner just three diagnostic questions, and from those answers identifies which of the four procurement paths applies and pre-loads the right checklist, contacts, and timeline. What used to require reading a multi-tab spreadsheet and knowing who to ask now takes under a minute. We design every solution around the same principle: the user should never need to understand the whole system to do their part of it correctly.
Human-in-the-loop by design, not as an afterthought
In regulated industries, the most expensive mistakes happen when a required approval is skipped. So we build hard stops into our AI workflows: human-in-the-loop gates that highlight exactly which sign-offs are required — a countersignature, a security clearance, a regulatory addendum — and refuse to let the process advance until a named human confirms each one. The AI accelerates everything around the gate, but the gate itself belongs to people. The client’s compliance team doesn’t have to take the AI’s word for anything; the audit trail shows a person approved every step that mattered.
Grounded in live data, not general knowledge
An AI assistant is only as useful as the facts it can see. The agent’s skills cross-reference the client’s live contract data — real expiry dates, real status fields, real ownership records — before answering. Ask when to start a renewal and you get a concrete start-by date calculated from the actual contract, plus flags on anomalies a human might miss, such as a superseded agreement still sitting in the register. We treat data grounding as a hard requirement: no generic answers, no hallucinated dates, and every recommendation traceable back to a record the client owns.
Compliance as a feature, not a constraint
Frameworks like the EU’s Digital Operational Resilience Act (DORA) and the oversight expectations of financial regulators are reshaping how firms manage third-party suppliers. We build those obligations directly into the workflow: applicability tests run against the specific contract, required clauses surfaced before signature, review cadences and evidence requirements tracked as first-class checklist items, and mandatory AI-governance reviews built into every new contract and renewal. Regulatory change stops being a scramble and becomes a versioned update to a skill.
How we delivered it
Meet users where they already work
The Compliance Assurance Agent shipped as two front doors to the same brain: a zero-install browser dashboard for everyday routing and progress tracking, and a set of AI skills for the terminal-based assistant that power users already run. Nobody was forced to adopt a new platform, sit through training, or wait for an integration project. That’s a pattern we repeat everywhere — deliver AI inside the tools people already have open, and adoption takes care of itself.
Start small, prove value, then integrate
The first release required no APIs, no new infrastructure, and no security review of external connections. It ran on exported data and local tooling, and it was useful on day one. That’s intentional. We sequence every AI engagement so the client sees working value before committing to deeper integration, then layer in live connections once the workflow has proven itself. Real-world AI adoption is won in weeks, not roadmaps.
Built to hand over, not to rent
Everything we build is designed for the client to own and evolve: skills as readable documents their own teams can edit, dashboards on standard open tooling, decision logic written down rather than locked in a vendor’s black box. When the process changes — and in regulated procurement it always does — the client can update the solution themselves. We measure success not by how much our clients depend on us, but by how confidently they run what we built.
The takeaway
The Compliance Assurance Agent started as a business problem: skilled people losing weeks to a process nobody could hold in their head, in an environment where skipping a step carries regulatory consequences. It became a working AI solution by following a few principles we apply on every engagement — map the process first, package institutional knowledge as agent skills, keep humans in the loop at the moments that matter, ground every answer in the client’s own data, and deliver inside the tools people already use.
If your organisation has its own version of the sixty-item checklist — a process that lives in three people’s heads and a spreadsheet nobody wants to open — that is exactly the kind of problem we like to start with. Talk to greenstar technology about turning it into a solution your team actually uses.