Case Study

Custom AI Engineering

03

Engineering Custom AI for C-SCRM:


Piloting a Specialized AI Ecosystem to Slash Risk Reporting Time and Drive Projected Savings of up to $1.7M

Executive Summary


A Federal Agency was bottlenecked by a slow, expensive Department-level enterprise service required to conduct Supply Chain Risk Assessments (SCRAs). To bypass procurement delays and pay-per-request fees, our embedded expert engineered a proprietary suite of Custom AI Assistants—including a specialized Open-Source Intelligence (OSINT) assistant—to automate Publicly Available Information (PAI) reporting and multi-tier analysis for NIST SR-6 compliance. Currently in an advanced SME-led pilot phase, this AI ecosystem has demonstrated the potential to slash report generation from up to 24 days down to just 10 minutes for baseline reporting and 30 minutes for deep-tier analysis, showcasing a viable path to enterprise-wide adoption and up to $1.79 million in projected cost avoidance.

The Challenge

To comply with evolving NIST SP 800-53 Rev 5 mandates (specifically the SR-6 control family), the agency was required to gather and analyze Publicly Available Information (PAI) for comprehensive vendor risk assessments.

However, the agency was heavily dependent on a Department-level enterprise service to perform these searches. This legacy process was highly inefficient: it operated on a pay-per-request model (costing between $5,000 and $14,000 per assessment) that drained budgets and required a convoluted, multi-layered routing and approval process. Securing a single SCRA report required a 7- to 10-day procurement lead time, followed by an additional 7 to 14 days to generate the report, depending on vendor complexity. This financial and bureaucratic gridlock severely hindered the agency’s ability to assess third-party risks at scale.

Client Profile


Client Type:

Federal Scientific Bureau

Mission Domain:

Enterprise Cybersecurity, Applied AI, Supply Chain Visibility, and Cyber Supply Chain Risk Management
(C-SCRM)

The Approach

Recognizing the urgent need for a faster, localized solution, our Subject Matter Expert architected a proprietary ecosystem of prompt-driven, highly specialized AI tools designed specifically for federal C-SCRM compliance.

Methodological Grounding:

Programmed the primary AI Assistant's parameters using Public Law, Executive Orders, federal memos, and NIST publications to ensure all risk scoring aligned strictly with federal methodologies.

Targeted Data
Ingestion:

Engineered the core assistant to ingest and synthesize critical PAI from vetted sources—including Crunchbase, LexisNexis, news outlets, and CVE/KVE databases—evaluating vendors across cybersecurity, financial stability, and adverse media domains.

Custom OSINT
Assistant:

Engineered an additional OSINT AI Assistant designed to ingest the finalized PAI reports and investigate deeper into the vendor ecosystem. This tool illuminates multi-tier (N-tier) supply chain relationships and hidden risks, effectively acting as an internal, highly cost-effective equivalent to enterprise platforms like Interos or Exiger.

Broader AI
Ecosystem:

Beyond SCRA generation, developed multiple specialized AI Assistants to support the broader practice, including a Public Law and Policy Monitor to track federal changes, a Training Assistant, and a Threat Intelligence utility monitoring private sector news for cyber incidents and emerging CVEs/KVEs.

Solution & Execution

Acting as the primary driver for the C-SCRM initiative, our expert rapidly evolved from project management to trusted program leadership, effectively operating as a highly leveraged "one-man army." Key execution milestones included:

SME-Driven Pilot
Phase:

Rather than immediately deploying the raw tools to the broader agency, the AI suite is actively being piloted by our internal SME. This allows us to deliver highly accurate, fully formatted risk reports directly to stakeholders while conducting ongoing testing and training for wider audience adoption.

Rigorous A/B
Testing:

Continuously comparing the AI's outputs against the legacy enterprise reports to identify commonalities, close gaps, and build a comprehensive library of validated reports.

Managing Hallucination Risks:

Acknowledged and actively mitigated AI hallucination risks by restricting the system's knowledge base strictly to published, vetted resources rather than theoretical data.

Human-in-the-Loop (HITL) Verification:

Established a mandatory double- and triple-check review process, ensuring that while data aggregation and initial scoring are accelerated by the AI, final risk determinations are heavily vetted by the human expert before delivery.

Outcomes & Impact

While the overarching enterprise service remains active, the SME-led pilot of this custom AI suite has demonstrated transformative potential for the agency's SCRM operational capabilities:

Massive Cost Avoidance:


Unprecedented Speed:

Crushed the historical
14- to 24-day timeline (lead time + generation time) down to just
10 minutes

to generate the foundational PAI report, and an additional 20 minutes for the specialized OSINT assistant to conduct multi-tier supply chain mapping. This guarantees a comprehensive, deep-tier assessment in just 30 minutes.

Massive Projected Cost Avoidance:

By eliminating the pay-per-request enterprise fees across 128 paid assessments, the AI ecosystem has outlined a clear path to

yielding between $640,000 and $1.79 million in direct savings upon wider adoption.

Deep-Teir Supply Chain Visibility:

By chaining the PAI reports into the specialized OSINT Assistant, the agency

gained the ability to peer deeper into multi-tier vendor relationships to identify hidden supply chain risks

a capability previously out of reach without costly commercial licenses.

Operational Autonomy:

Successfully bypassed the bureaucratic delays of the overarching Department's routing and approval process during the pilot, giving the agency

localized, real-time control over its supply chain risk visibility.

Key Differentiators

AI Engineering & Innovation:

The rare ability to independently architect, train, and pilot a suite of specialized AI Assistants that targets a million-dollar enterprise bottleneck and delivers commercial-grade, multi-tier supply chain visibility internally.

SME-as-a-Service Model:

Leveraging advanced, proprietary technology internally to drastically accelerate deliverable timelines while maintaining expert oversight and client trust during the testing phases.

Responsible AI Governance:

Demonstrated deep maturity in managing AI deployment by implementing strict parameters, transparent source linking, and rigorous human-in-the-loop verification to ensure absolute defensibility and technical accuracy.

See more of our Case studies

Ready to work
with us?

Every engagement starts with a conversation. The right partner should make complex work feel clearer, not heavier. At Qoral, we take the time to understand your goals, constraints, risks, and operating environment before recommending a path forward. Reach out to start a conversation about where you are, what you need, and how we can support your next step. Whether you need strategic guidance, compliance support, or a trusted partner for IT initiatives, Qoral is here to help.