Diligent is pushing automation deeper into governance, risk, and compliance workflows. Its latest agentic AI strategy aims to reduce slow manual work across audit, cyber risk, third-party reviews, compliance, and board reporting.
The headline claim is bold. Diligent says Cyber Risk Management can reduce six weeks of cyber risk assessment work to hours. For security and communications leaders, that promise matters. Risk reviews often slow down technology rollouts, supplier approvals, and compliance reporting.
However, the claim still needs clearer proof. Diligent has not published the customer, assessment scope, sample size, or calculation behind it. Buyers need to know what “hours” includes. It could mean AI processing time only. It may not include data cleanup, staff review, corrections, and approval.
Still, the product direction looks significant. Diligent does not appear to be building isolated assistants. Instead, it wants one connected GRC environment. That environment links evidence, approvals, reporting, and audit trails inside Diligent One.
This shared model could help large enterprises. Many organizations still run risk, audit, compliance, and security in separate tools. Diligent Institute research found only 19% of surveyed legal leaders had fully integrated GRC systems. Another 65% described their systems as only somewhat integrated.
In practice, Diligent’s agents can prepare assessments, request evidence, create records, and move approved work forward. They can also map cyber findings to assets, controls, business processes, and remediation owners. Yet humans still approve risk acceptance, budget decisions, and formal governance actions.
That boundary is important. AI can speed preparation and coordination. It should not replace executive judgment. In regulated sectors, including telecoms, accountability remains with people.
Diligent’s Risk Maestro shows this approach clearly. It can create audit files, draft objectives, and connect risks with controls. A practitioner must review changes before the platform writes them back. The system also keeps a traceable link for audit purposes.
Cyber Risk Management supports control mapping against NIST CSF, ISO 27001, SOC 2, and FedRAMP. It can also use external security insights from providers such as Bitsight and SecurityScorecard.
This could make board reporting more useful. Directors rarely act on vulnerability scores alone. They need to understand business impact, ownership, required action, and remaining exposure.
The challenge is measurement. Faster reports do not always mean lower risk. Organizations should measure time to remediation, residual risk, and decision quality. They should also track rework and human review effort.
Independent analysis adds caution. Forrester named Diligent a Leader in its Q2 2026 GRC platform evaluation. The firm also noted that AI still delivers limited customer value across parts of the GRC market.
Diligent’s strategy may reset expectations for automated risk management. But the six-weeks-to-hours claim needs production evidence. A named customer and transparent benchmark would give buyers real confidence.
For now, Diligent offers a compelling direction. It connects technical findings to business decisions more directly. That alone could help security, compliance, and telecom operations teams move faster.

