Kyūdō
AI Governance

AI Governance with Kyūdō

AI governance means governing the AI your organization deploys: keeping an inventory of AI systems, assessing their risk, collecting evidence of oversight, and assigning accountability for each one. Kyūdō runs all four on the Compliance Graph, the same governed data layer that holds your controls and evidence, so AI governance is part of your compliance program rather than a separate tool.

This page is the short answer. For the architecture, module walkthrough, and deployment detail, explore the full AI governance solution. For how the platform's own AI is governed, see what makes a GRC platform AI-native.

Book a Deployment Workshop Explore the Full AI Governance Solution
Inventory

AI system inventory

Governance starts with knowing what you run. Kyūdō inventories AI systems as first-class entities in the Compliance Graph, connected to vendors, data flows, and controls, so the inventory is a working part of your compliance program rather than a static list.

AI systems as graph entities

Each AI system your organization runs is an entity in the Compliance Graph, not a row in a standalone register. It connects to the vendor that supplies it, the data flows it participates in, and the controls that govern it.

Connections stay current

When a vendor relationship, data flow, or control changes, every AI system connected to it reflects the change. The inventory answers from live data instead of a spreadsheet maintained by hand.

Accountability attached

Ownership, risk classification, and oversight obligations attach to each AI system directly, so the question of who is accountable for a given system has one recorded answer.

Vendor AI

Vendor and fourth-party AI risk

Most of the AI in your environment arrives through vendors, and behind each vendor sits an AI provider you never contracted with directly. That is fourth-party AI risk: your vendors' model and infrastructure suppliers. Kyūdō maps these chains in the Compliance Graph, vendor to sub-processor to AI provider, so you can see which of your vendors depend on which AI providers and what data reaches them.

Contractual obligations, including AI provider disclosure, are tracked as attributes of the relationship. When a vendor adds or changes an AI provider, the exposure is visible in the same graph that holds your controls and evidence. This runs on Kyūdō's vendor risk management module, so third-party and fourth-party AI risk share one program rather than two.

Framework Readiness

Map once, prove three times

The three major AI frameworks overlap heavily. Kyūdō unifies them in one set of 156 AI governance controls, so an oversight control implemented once produces evidence that serves the EU AI Act, ISO 42001, and the NIST AI RMF together. See all supported frameworks for how the same crosswalk approach covers your cyber obligations.

EU AI Act

The European Union's risk-based regulation of AI systems. Obligations phase in through August 2026, so the relevant question is how current your evidence is on any given day.

ISO 42001

The international AI management system standard. It defines how an organization sets up and maintains governance over its AI, and certification is assessed by an accredited body.

NIST AI RMF

The NIST AI Risk Management Framework, a voluntary US framework for identifying, measuring, and managing AI risk across the lifecycle of each system.

Evidence

Governance evidence, not governance intentions

AI governance frameworks ask for proof that oversight happened, not a policy stating that it should. Kyūdō collects that proof continuously and holds it to the same provenance standard as every other artifact on the platform. Unfamiliar terms are defined in the glossary.

Human oversight records

Who reviewed which AI decision, and when. Oversight events are captured as evidence artifacts rather than reconstructed from memory when an assessor asks.

Model documentation

Model cards, intended-use statements, and evaluation results are stored as governed artifacts linked to the AI system they describe.

Audit trail with provenance

Every artifact carries a hash, lineage, and confidence score, so an assessor can verify where a piece of governance evidence came from and that it has not changed.

Put AI governance on the same graph as your controls

Deploy inside your Azure tenant and see your AI systems, vendors, and governance evidence connect from your own signals.

Frequently Asked

Questions, answered

Looking for more? See all frequently asked questions.