Vendor Risk Management
Kyūdō manages vendor risk on the same Compliance Graph as your controls and evidence. Vendors, contracts, certifications, and sub-processors are connected entities, so risk scores reflect live control evidence rather than a static annual questionnaire, and Sensei AI Advisor drafts questionnaire responses from evidence you already hold, with citations a reviewer can verify.

Built for how compliance actually works.
Vendors as Compliance Graph entities
Every vendor is inventoried as an entity connected to the controls it affects, the contracts and certifications that cover it, and the evidence behind each assessment. One record, fully connected.
Questionnaires, inbound and outbound
Sensei AI Advisor drafts responses to inbound security questionnaires from your existing control evidence, with per-answer citations. Outbound questionnaires to your vendors run through the same workflow.
Sub-processor and fourth-party mapping
Map who your vendors depend on, including their AI providers, so exposure two steps down the chain is visible in the same graph as your own controls.
Certifications and contracts as evidence
A vendor's SOC 2 report, ISO certificate, or data processing agreement is stored as an evidence object with hash, lineage, and expiry, linked to the assessments it supports.
AI provider disclosure
Track which vendors use which AI providers and what disclosure their contracts require, so vendor AI exposure is recorded rather than assumed.
Continuous monitoring
Vendors are reassessed when the signals or artifacts connected to them change, such as an expiring certification or a lapsed contract term, not on a fixed annual calendar.
Sensei Drafts Questionnaire Responses From Evidence You Already Hold
Answering the same security questionnaire for every prospect is repeated work over evidence that already exists. Sensei AI Advisor retrieves from the Compliance Graph, drafts each response from your live control evidence, and cites the specific nodes it drew from, so a reviewer verifies sources instead of rewriting answers. Responses below the confidence threshold are routed to human review before anything is sent.

Risk Scoring Connected to Live Control Evidence
A vendor score derived from last year's questionnaire describes last year's vendor. In Kyūdō, each vendor's risk score is computed from what is currently connected to it in the Compliance Graph: control status, certifications and their expiry, contract terms, and assessment responses. When any of those change, the score is reassessed, so the register your team and your auditors read reflects the present.

Where vendor risk connects
Questions, answered
Kyūdō manages vendor risk on the same Compliance Graph as your controls and evidence. Vendors are entities connected to the controls they affect, the contracts and certifications that cover them, and the evidence that supports each assessment, so vendor risk reflects your live posture rather than a binder assembled once a year. Sensei AI Advisor drafts questionnaire responses from existing control evidence, with citations a reviewer can verify.
Yes. Beyond your direct vendors, Kyūdō maps the sub-processors your vendors depend on, including their AI providers. These relationships are modeled in the Compliance Graph, so you can trace which data reaches which fourth party, track contractual obligations such as AI provider disclosure, and see the exposure alongside the controls and evidence it touches.
Yes. When a customer or prospect sends a security questionnaire, Sensei AI Advisor drafts responses from the control evidence you already hold, citing the specific Compliance Graph nodes each answer draws from. A person reviews and approves the draft before it goes out, and low-confidence answers are routed to human review rather than sent speculatively. The same mechanism supports outbound questionnaires to your own vendors.
Vendor risk scores in Kyūdō are connected to live control evidence, not a static annual questionnaire. Each vendor's score reflects the current state of the controls, certifications, contracts, and assessment responses linked to it in the Compliance Graph, and reassessment is triggered when the underlying signals or artifacts change. The score you see describes the vendor as it is now, not as it was at the last review cycle.
Yes. AI provider relationships are modeled as part of each vendor's entry in the Compliance Graph: which AI providers a vendor depends on, what disclosure the contract requires, and which of your data flows are exposed. This connects vendor risk management to AI governance, so the AI your vendors deploy is governed in the same program as the AI you deploy directly.
Looking for more? See all frequently asked questions.
