Technical evaluation

vCISO Lite versus OneTrust

OneTrust AI Governance is the AI-Gov arm of a 14,000-customer privacy / TPRM / GRC platform — Visionary in the June 2026 Gartner MQ, one named AI-Gov reference customer on their solution pages today. vCISO Lite ships Trustworthy Autonomy + Evidence Graph + APRI + services bundled at $8,500/mo flat Enterprise MSRP.

Prepared
Method
Capability walk against OneTrust’s published product surface (onetrust.com/solutions/ai-governance/, onetrust.com/solutions/data-teams/, developer.onetrust.com AI Guard docs) and vCISO Lite’s live platform. Both vendors’ Gartner MQ pages consulted for 2026 placement.
Sources
onetrust.com/solutions/ai-governance/, onetrust.com/solutions/data-teams/, developer.onetrust.com/onetrust/docs/ai-guard-faq, onetrust.com/pricing/, vcisolite.com product surfaces, and Regulation (EU) 2024/1689 (Articles 12, 99). See §10.
Corrections
Both vendors invited to review. Send corrections to /contact; the “Prepared” date above is bumped on any material update.
On this page · 10 sections

TL;DR

Findings§1

Where OneTrust leads

  • 2026 Gartner MQ Visionary. Same quadrant as Credo AI, ModelOp, Airia, Monitaur; IBM/ServiceNow/Truyo are Leaders.[6] vCISO Lite is not on the quadrant.
  • 14,000-customer privacy / TPRM / GRC platform underneath. If {company} already runs OneTrust for privacy or TPRM, extending "one shared data model" to AI Gov is genuinely lower-friction than swapping platforms.[1]
  • Native hyperscaler ML connectors. Bedrock, SageMaker, Foundry, Vertex, Databricks (Unity Catalog), Snowflake; Winter ‘26 added Agent Detection for Bedrock/Foundry/Vertex.[4]
  • 300+ AI Guard classification profiles. Large prompt/response content-classification library out of the box.[3] vCISO Lite doesn’t ship an equivalent library.
  • ISO 42001 partnership with AWS.[7] Real value if {company}’s primary framework is 42001 and the production stack is AWS-native.

Where vCISO Lite leads

  • A knowable Enterprise-tier number. $8,500/mo flat MSRP bundles Trustworthy Autonomy + Evidence Graph + APRI. OneTrust is contact-sales; third-party aggregators put minimum ACV ~$10K and real enterprise deals $50K–$300K+/yr.[2]
  • Runtime enforcement OneTrust’s own docs don’t recommend. Verbatim from their developer FAQ: “It is optimized for development and testing workloads. As of this release, it is not recommended for large classification volumes generally seen in externally facing AI applications or agents.”[3] Custom classification profiles also not supported. Trustworthy Autonomy runs in production; public beta 2026-07-07 with a published evaluation harness.
  • APRI vs OneTrust workflow-embedded AI assist — same category, more shipped. APRI (our MCP tool graph + evidence-backed answer surface) adds end-to-end vendor questionnaires with cited evidence, board packs, Linear-ticket remediation plans, SOC 2 readiness PDFs, vendor risk re-scoring, M&A data rooms. Caller-entitlement scoped, complete tool-call audit trail, observe-first with confirmation gates. Live MCP endpoint at mcp.vcisolite.com for Claude + Cursor.
  • Evidence Graph — externally-anchored. Per-event Ed25519 signing + RFC-3161 external anchor + transparency log live prod 2026-08-20. Auditor re-derives without trusting the platform. OneTrust’s "comprehensive records" are platform-internal.
  • Evidence Graph SDK is licensable. Embed the same integrity in a partner product, internal system, or insurance pipeline. Optionality OneTrust doesn’t offer.
  • 250+ SCF-cross-mapped frameworks on the same SKU. One vendor for AI-Gov + SOC 2/ISO 27001/HIPAA/PCI DSS/DORA/NYDFS/CMMC/FedRAMP. OneTrust AI Governance is a separate SKU from OneTrust Privacy, TPRM, GRC.[5]
  • Founder-direct. [email protected] reaches the founder, not an enterprise SDR queue.

Scope & evaluation criteria

Boundaries§2

In scope

Buyer profile
SMB and mid-market operators (25–1,500 employees) evaluating a purpose-built AI governance platform to cover agent inventory, policy enforcement, framework-mapped evidence, and runtime autonomous operations — without an existing OneTrust privacy / TPRM / GRC estate underneath. Fortune-500 CIO evaluations with a mature OneTrust footprint are OneTrust’s home turf and are noted where relevant; they are not the buyer this page is written for.
Evaluation frame
Ten capability categories the SMB and mid-market buyer is evaluating BOTH tools for. Not: everything each product does.
Comparison basis
Published product documentation, live product surfaces, developer FAQs (verbatim quoted where it matters), vendor recognition pages, and Gartner primary press notice. Not: analyst reports behind Gartner’s paywall, vendor-sponsored bakeoffs, or internal-only NDA material.

Out of scope

OneTrust Privacy / TPRM / GRC merits
OneTrust’s 14,000-customer privacy platform and its Forrester Wave Q4 2025 Leader placement for Privacy Management Software are earned and defensible. This page does not litigate whether OneTrust is the right choice for that market; it is. AI Governance is a separate SKU inside that platform and is compared here on its own AI-Gov merits.
Guardian Agents concept
Guardian Agents is not a shipped OneTrust product; it’s a Gartner AI TRiSM pattern OneTrust markets around. Compared here as a positioning claim, not a shipped SKU.
Roadmap
Only shipped, generally-available or public-beta capability is compared. Private-preview capabilities are footnoted where public.

Capability coverage

Ten capabilities§3

Amber = OneTrust ships it. Teal = vCISO Lite ships it. Split = both ship it (weighted when one is materially stronger). Hover a hex for the mechanism detail.

Capability deep-dives

How each side implements it§4

Five capabilities, one spec-card per side. Same slots on both cards so the reader can eye-compare row by row. Framework decomposition lives in §5.

Workflow-embedded AI assistWinter ‘26: AI Inventory Analysis · AI Evidence AnalysisGuardrail Enforcementwire policies to Bedrock / Foundry / Vertex eventsAI Policy Managerintent · scope · applicability · required controlsAI Guard SDKPython only · 300+ classifiers · “dev/testing scope”not for prod agents (their FAQ)AI Registry · Discover the AI EstateWinter ‘26 adds Agent Detection for Bedrock / Foundry / VertexAI Governance Cloud · platform-internal audit trailOneTrust Platform · ONE SHARED DATA MODELPrivacy · TPRM · GRC · Consent · DSAR · AI Governance all reference the same records14,000-customer privacy heritage · 200+ platform connectors · ~75% of the Fortune 100
OneTrust AI Governance sits on the privacy platform. The core structural point is at the base: Privacy, TPRM, GRC, Consent, DSAR, and AI Governance all reference the same records. AI Governance is a standalone SKU per their pricing page, but architecturally it’s continuous with the privacy platform — the “one shared data model” positioning per onetrust.com/platform/is what “one platform” means. Also visible: AI Guard SDK sits at layer 4 as the runtime piece, with the dev/testing scope caveat their own developer FAQ writes.
CUSTOMER’S CLOUD ACCOUNTSAWS Bedrock · SageMakerAzure AI FoundryGoogle Vertex AIDatabricks · SnowflakeOAuthConnectorread model + agent inventoryHTTPSOneTrust SaaS backendAI Registry · Discover the AI EstateWinter ’26: Agent Detection forBedrock · Foundry · Vertexrecords live in AI Governance CloudOff-cloud models · embedded code · agents deployed outside these services stay invisible until AI Guard SDK is added inside the app process.
Discovery = “inventory of what the cloud services see.” OneTrust’s AI Registry is fed by cloud-account connectors to Bedrock, Foundry, Vertex, Databricks, and Snowflake. That covers a lot of production AI workloads — but only what the cloud service itself catalogs. Models deployed off-cloud, embedded in application code, or agents wired through frameworks outside the AI Guard SDK’s Python-only surface are not visible until instrumented. Compare to Credo AI, whose LangChain / CrewAI / AutoGen SDK-callback pattern is on-process (see /vs/credo-ai §4).
§4.1

AI Registry & agent discovery

Both platforms ship model + agent inventory. The difference is what the inventory reaches and how the record is evidence-anchored.

OneTrust AI Governance

Cloud-account connectors to Amazon Bedrock, SageMaker, Azure AI Foundry, Vertex AI, Databricks (with Unity Catalog), Snowflake. Winter '26 release added Agent Detection for Bedrock / Foundry / Vertex. AI Guard SDK (Python) fills in-process instrumentation.

Inputs
Cloud-service inventories, model deployments, dataset registrations, SDK-instrumented agent traces.
Outputs
Live AI inventory · agent detection · policy inheritance · governance workflows.
Evidence
Platform-internal record; OneTrust proprietary logging.
Fails when
Auditor asks to independently verify the discovery record without trusting OneTrust's logs.
vCISO Lite

Model + agent inventory with policy binding and every registered asset bound to the Evidence Graph.

Inputs
Integration events, discovery scans, policy state, framework mappings.
Outputs
Live inventory · policy binding · framework-control mapping · signed record per registered asset.
Evidence
Hash-chained record anchored to RFC-3161 external timestamp authority; re-derivable by an auditor who does not trust vCISO Lite.
Fails when
Native cloud-service connector coverage doesn't match OneTrust's Bedrock / Foundry / Vertex / Databricks / Snowflake for buyers whose entire AI workload lives inside those services.
§4.2

Policy engine & framework mapping

Both platforms map policy to framework controls. The decisive difference is how many frameworks — and which.

OneTrust AI Governance

AI Policy Manager — define policy intent, scope, applicability, required controls. Guardrail Enforcement wires policies against Bedrock / Foundry / Vertex events. Framework mapping covers EU AI Act, NIST AI RMF, ISO 42001, and OECD AI Principles.

Inputs
Regulatory content, cloud-service events, agent traces, dataset registrations.
Outputs
Policy binding · framework mapping · guardrail enforcement · workflow automation.
Evidence
Compliance dashboards + platform-internal audit trail.
Fails when
Buyer's program has to cover HIPAA, PCI DSS, DORA, NYDFS Part 500, FedRAMP, CMMC, SOC 2, or ISO 27001 alongside AI governance — OneTrust AI Governance's framework list is four AI-specific frameworks; broader coverage requires the OneTrust GRC SKU (separate SKU, separate line item).
vCISO Lite

Policy engine mapped across 250+ SCF-cross-mapped frameworks (1,468 universal controls) — every framework the mid-market buyer's program actually touches — inside the same $8,500/mo Enterprise tier that includes Trustworthy Autonomy and the Evidence Graph.

Inputs
SCF-mapped control matrix, evidence chain data, live system state.
Outputs
Policy binding · framework mapping · evidence-chain anchoring.
Evidence
Signed chain per policy decision · re-derivable framework-mapping trace.
Fails when
Buyer specifically needs OECD AI Principles as a first-class published framework — vCISO Lite maps OECD through NIST AI RMF and ISO 42001 alignment, not as a standalone framework pack.
ONETRUST AI GUARD SDKPython 3.13+ only · Docker or K8s on-prem300+ system profiles · no custom classifiersDev / testing scopeper OneTrust developer FAQProduction agent workload?“not recommended” (their words)Optimized for development and testing workloads.Externally-facing prod = documented gap.vCISO LITE · TRUSTWORTHY AUTONOMYAutonomous operations layer of vCISO LitePublic beta since 2026-07-07Production runtimeevery autonomous action signed to Evidence GraphPublished evaluation harnesspass rates by task category, visible pre-purchaseRuns where production agents run.Buyer sees pass rates before signing.
OneTrust’s own docs are the source. The runtime piece — the moment the platform actually intervenes on an AI action in production — is where the shipped-state gap is honest. Verbatim from OneTrust’s developer FAQ: “It is optimized for development and testing workloads. As of this release, it is not recommended for large classification volumes generally seen in externally facing AI applications or agents.” That is not a criticism; it is what their own engineering team publishes. Trustworthy Autonomy is scoped for production and published its evaluation harness so the buyer sees agent behavior before purchase.
§4.3

Autonomous operations layer / runtime enforcement

Both platforms are working toward the same thing: a governed layer where AI agents actually run real work on the buyer's behalf. The difference is what's already shipped for production.

OneTrust AI Governance

AI Guard SDK (Python-only, Docker / K8s on-prem) + AI Policy Manager + Guardrail Enforcement. Positioned as extending the OneTrust control plane into AI workloads and MCP environments.

Inputs
Prompts, responses, model outputs, agent traces via AI Guard's 300+ system-defined classification profiles.
Outputs
Classification labels · policy violation events · aggregated metrics to OneTrust AI Governance Cloud.
Evidence
Platform-internal record; aggregated metrics only leave customer environment.
Fails when
OneTrust's own developer FAQ verbatim: "It is optimized for development and testing workloads. As of this release, it is not recommended for large classification volumes generally seen in externally facing AI applications or agents." Custom classification profiles are also not supported.
vCISO Lite

Trustworthy Autonomy — the autonomous operations layer of vCISO Lite, running on the Evidence Graph substrate. Public beta since 2026-07-07.

Inputs
Agent action requests · policy state · framework-control mapping · evidence chain state.
Outputs
Signed authorization decision per action · agent execution · evidence-chain record before AND after the action.
Evidence
Every autonomous action recorded to the Evidence Graph; published evaluation harness grades the agent by task category with pass rates + failure cases visible pre-purchase.
Fails when
Buyer needs GA (not public-beta) autonomous action at trust-ladder rung 2 (scoped autonomy) or rung 3 (goal-oriented) today — those reach GA H1 2027 and H2 2027+ respectively. OneTrust's Guardian Agents concept is also not GA today (it's not a shipped SKU).
§4.4

Evidence chain & audit-trail integrity

The question an auditor / insurer / regulator will ask about the AI agent’s actions after the fact. The chain that answers it has to be re-derivable without trusting the platform that produced it.

OneTrust AI Governance

"Comprehensive records of AI-related decisions" — platform-internal audit trail inside the OneTrust AI Governance Cloud. Exportable.

Inputs
AI Registry events, policy violation events, workflow signoff records, AI Guard classification metrics.
Outputs
Audit dashboards · exportable log · compliance evidence generation.
Evidence
Log entries in a proprietary store; verification requires trusting OneTrust's reporting.
Fails when
Adversarial auditor asks to verify the chain independently without relying on OneTrust's attestation.
vCISO Lite

Evidence Graph — hash-chained records anchored to an external RFC-3161 timestamp authority. Per-event Ed25519 signing shipped 2026-08-16; transparency log + receipts live in production since 2026-08-20. Independent verifier cron.

Inputs
Every agent action, evidence artifact, policy decision, and framework mapping.
Outputs
Sealed evidence chain · external timestamp attestation · re-derivable proof.
Evidence
Auditor re-derives the chain against the RFC-3161 attestation record; verification does not depend on trusting vCISO Lite.
Fails when
Buyer's existing audit tooling has not been briefed on RFC-3161 verification; onboarding the audit firm to the RFC-3161 verification pattern takes one call.
ONETRUSTAgent action + evidencewriteAI Governance CloudOneTrust proprietary audit trailexportAuditor reads logVerification requires trusting OneTrust.vCISO LITE · EVIDENCE GRAPHAgent action + evidencehash + chainHash-chained recordevery block links to the prior hashRFC-3161 anchorre-deriveAuditor verifies chainagainst external anchor recordVerification does not require trusting vCISO Lite.
OneTrust stores; the Evidence Graph proves.Both platforms record what the agent did. Only one produces a record that a party who distrusts the platform can independently verify. This is an architectural difference — not a capability list. Same shape as the Credo AI architectural contrast, because both incumbents keep the audit trail proprietary; vCISO Lite’s Evidence Graph is the one integrity primitive the buyer can license out to a partner, an internal system, or an insurance carrier for the same guarantee.
§4.5

Integrity substrate as licensable SDK

Whether the audit-trail primitive is only usable inside the vendor’s product or can also be embedded elsewhere.

OneTrust AI Governance

Not offered. Audit trail is a proprietary OneTrust capability inside the AI Governance Cloud.

Inputs
N/A
Outputs
N/A
Evidence
N/A
Fails when
Buyer wants to embed the same integrity substrate in a partner product, an internal system, or an insurance-carrier reporting pipeline.
vCISO Lite

Evidence Graph SDK — Library / Hosted / Enterprise / Charter tiers. Same primitive vCISO Lite uses internally, packaged for embedding. Licensable since 2026-08-15.

Inputs
Partner platform events, internal-system records, third-party reporting.
Outputs
Signed, externally-anchored, re-derivable evidence chain.
Evidence
The SDK produces the same signed evidence chain the product uses internally; consumers verify against the same RFC-3161 attestation record.
Fails when
Buyer's use case is only vCISO Lite's own product surface; SDK licensing is unnecessary optionality.

Framework & control coverage

Framework depth§5

OneTrust AI Governance publishes 4 AI-specific frameworks on its product page (EU AI Act, NIST AI RMF, ISO 42001, OECD AI Principles). vCISO Lite covers three of those four (OECD is mapped through NIST AI RMF and ISO 42001 alignment) plus 250+ SCF-cross-mapped frameworks (1,468 universal controls)that most mid-market compliance programs actually touch. The gap-fill frameworks vCISO Lite covers natively (and OneTrust AI Governance doesn’t publish on the AI Governance surface) are highlighted below.

OneTrust AI Governance[8]

EU AI Act
NIST AI RMF
ISO 42001
OECD AI

vCISO Lite

EU AI Act
NIST AI RMF
ISO 42001
SOC 2
DORA
NYDFS 500
HIPAA
PCI DSS
GDPR
NIST 800-53
NIST 800-171
FedRAMP
CMMC L1
CMMC L2
CMMC L3
ISO 27001
NIST CSF 2.0
ISO 27002
ISO 27701
ISO 22301
HITRUST
SOC 1
SOC 3
CCPA / CPRA
GLBA
CJIS
StateRAMP
TX-RAMP
CIS Controls
CIS Benchmarks
MITRE ATT&CK
NIST 800-63
NIST 800-172
FFIEC CAT
SWIFT CSCF
NIS 2
LGPD
PIPEDA

Pricing & sales motion

How each is bought§6

Two facing pricing stacks — the way a CFO reads a comparison. Amber column is OneTrust AI Governance; teal column is vCISO Lite.

OneTrust AI Governance

Contact sales

Not published · pricing meter is admin users + AI inventory[2]

Sales channel
Direct enterprise sales
Direct end-buyer access
Yes, at enterprise scale · self-serve tier not offered
Product SKUs
AI Governance is a standalone package; broader OneTrust modules (Privacy, TPRM, GRC) are separate SKUs[5]
Pricing model
Enterprise annual contract · admin users + AI inventory metering · third-party aggregators put minimum ACV ~$10K and enterprise deals $50K–$300K+/yr[2]
Named AI-Gov reference customers
1 (Blackbaud)[9] · platform-wide roster is privacy-management heritage
Contract length
Annual minimum · enterprise multi-year typical
Runtime enforcement
AI Guard SDK is dev/testing scope (their FAQ)[3]
Broader-compliance coverage on same SKU
No · buyer pairs with OneTrust GRC (separate SKU) or a third-party GRC tool
Sales cycle
Book demo → Enterprise procurement → 3–6 weeks to number
vCISO Lite

$0 / mo

Enterprise tier · bundles Trustworthy Autonomy + Evidence Graph + APRI

Sales channel
Direct · founder-accessible
Direct end-buyer access
Yes · Enterprise via /pricing Contact Sales
Product SKUs
Enterprise $8,500/mo bundles Trustworthy Autonomy + Evidence Graph + APRI · lower tiers $299–$1,499/mo do not include AI-governance features
Pricing model
Flat monthly Enterprise number · framework coverage + evaluation harness included · Trustworthy Autonomy per-action pricing pending (expected ~$1.50–$2 per resolved action, not enforced during public beta)
Customer segment
SMB · mid-market · lean security teams · AI-native shops
Contract length
Annual or monthly · no multi-year lock required
Runtime enforcement
Trustworthy Autonomy production runtime (public beta 2026-07-07) · published eval harness
Broader-compliance coverage on same SKU
250+ SCF-cross-mapped frameworks (1,468 universal controls) · one platform
Sales cycle
Enterprise: one call · flat MSRP on file (no 3–6 week discovery)

Integration surface

Native connectors§7

OneTrust’s AI Governance integrations skew toward hyperscaler model-hosting services (Bedrock, SageMaker, Azure AI Foundry, Vertex AI, Databricks with Unity Catalog, Snowflake); vCISO Lite’s toward the compliance / risk / diligence stack a mid-market operator actually runs. See vCISO Lite’s full catalog on /features/integrations.

IntegrationOneTrustvCISO Lite
AWSNativeNative
AzureNativeNative
GCPNativeNative
AWS BedrockNative
AWS SageMakerNative
Azure AI FoundryNative
Google Vertex AINative
DatabricksNative
SnowflakeNativeNative
JiraNativeNative
SlackNative
ServiceNowNative
Palo Alto NetworksNative
OktaNative
Google WorkspaceNative
Microsoft 365Native
GitHubNative
GitLabNative
Integration count published?No · 200+ referenced platform-wide, not AI-Gov-specificNo

Deployment, data, extensibility

Platform architecture§8
AttributeOneTrust AI GovernancevCISO Lite
Service modelSaaS (AI Governance Cloud) · AI Guard SDK runs on-prem in customer infra (Docker / K8s)SaaS multitenant · Enterprise-tier options for isolated deployments on request
Data residencyNot publicly specified on Platform Overview or AI Governance solution pageUS (primary)
Tenant isolationNot publicly disclosedLogical (row-level org scoping)
Public APIPlatform APIs referenced; AI Guard has a REST API for non-Python callers · full specification not publicly disclosed for AI GovernanceREST + MCP (Model Context Protocol) tool graph · OpenAPI 3.0
SSO / SCIMAvailable across the OneTrust platform (privacy heritage); AI-Gov-specific SSO/SCIM details not publicly disclosedSAML 2.0 · OIDC · SCIM 2.0
Audit-trail modelPlatform-internal audit trail in AI Governance Cloud · exportable · OneTrust proprietary loggingEvidence Graph · hash-chained per-event · RFC 3161 external timestamp anchor · SDK-licensable
Runtime SDKAI Guard SDK · Python 3.13+ only · custom classifiers not supported · “not recommended for large classification volumes generally seen in externally facing AI applications or agents” per their FAQ[3]Trustworthy Autonomy (public beta 2026-07-07) · production runtime · published evaluation harness · graduated trust ladder
Conversational LLM surfaceAI Policy Manager + workflow-embedded AI assist (Winter ‘26: AI Inventory Analysis, AI Evidence Analysis) · no standalone MCP endpoint disclosedAPRI (AI-Powered Risk Intelligence) · MCP tool graph · answers cite evidence chain · caller-entitlement scoped
Own complianceSOC 2, ISO 27001 available platform-wide (privacy heritage); AI-Gov-specific certifications not publicly disclosedSOC 2 Type II · ISO 27001 (in progress) · runs on itself
Positioning relative to broader platform“One shared data model” with Privacy, TPRM, GRC · AI Governance is a standalone SKU but leans on the platform-wide pitchAI-Gov + broader compliance program on the same Enterprise SKU · no assumed prior footprint

Business-case briefing

For a budget request§9

Personalized briefing

Make the case for vCISO Lite over OneTrust AI Governance

A PDF business case, personalized to your company, that lays out the three options, the cost math, and the honest tradeoffs — the argument you need to attach to a budget request or take into a vendor-selection meeting.

View pricing

Notes & sources

Provenance§10
  1. [1] OneTrust platform positioning (“one shared data model,” ~14,000 customers, ~75% of Fortune 100 across the trust platform) from onetrust.com/platform/ and onetrust.com/ (accessed 2026-09-14). AI Governance product surface, module list, and integration list from onetrust.com/solutions/ai-governance/ and onetrust.com/solutions/data-teams/.
  2. [2] OneTrust pricing page routes every prospect to a sales call and describes the AI Governance meter as admin users + AI inventory: onetrust.com/pricing/(accessed 2026-09-14). Third-party aggregators (Vendr aggregate across ~280 OneTrust deals: median $10,514, range $1,394–$42,533 platform-wide; Sprinto’s OneTrust review and multiple 2026 buyer reviews report minimum ACV ~$10K and enterprise-grade deployments $50K–$300K+/yr) are directional and not OneTrust-sourced.
  3. [3] OneTrust AI Guard SDK developer FAQ, verbatim: “It is optimized for development and testing workloads. As of this release, it is not recommended for large classification volumes generally seen in externally facing AI applications or agents.” Custom classification profiles not supported. Python 3.13+ required. Runs on-prem in customer infra (Docker container or Kubernetes pod on OneTrust Light Worker Node). Source: developer.onetrust.com/onetrust/docs/ai-guard-faq (accessed 2026-09-14).
  4. [4] OneTrust AI Governance native integrations (Amazon Bedrock, SageMaker, Azure AI Foundry, Google Vertex AI, Databricks with Unity Catalog, Snowflake, Jira, Palo Alto Networks) from onetrust.com/solutions/ai-governance/ and onetrust.com/solutions/data-teams/ (accessed 2026-09-14). Winter ‘26 release Agent Detection for Bedrock / Foundry / Vertex per onetrust.com/blog/evolving-privacy-programs-with-ai-whats-new-in-the-onetrust-winter-26-release/. LangChain, CrewAI, and AutoGen not named as first-class integrations on any OneTrust page fetched today.
  5. [5] OneTrust AI Governance is a standalone SKU per onetrust.com/pricing/; broader OneTrust modules (Privacy, TPRM, GRC) are separate SKUs. The “one shared data model” positioning per onetrust.com/platform/ works for prospects who buy multiple SKUs; a greenfield buyer of AI Governance alone gets less of the “unified platform” pitch. vCISO Lite’s 250+ SCF-cross-mapped frameworks (1,468 universal controls) from the Secure Controls Framework crosswalk on /features/compliance.
  6. [6] Inaugural 2026 Gartner Magic Quadrant for AI Governance Platforms, published June 16, 2026; OneTrust placed as Visionary. Reprint page: onetrust.com/resources/gartner-magic-quadrant-for-ai-governance-platforms-2026-report/. OneTrust’s own commentary: onetrust.com/blog/onetrust-debuts-as-a-visionary-in-the-2026-gartner-magic-quadrant-for-ai-governance-platforms-heres-why-it-matters/. Leaders: IBM, ServiceNow, Truyo. Visionaries: OneTrust, ModelOp, Airia, Credo AI, Monitaur. Challenger: Holistic AI. Niche Players: SAP, Reliance AI, Cranium AI, Saidot.
  7. [7] OneTrust + AWS ISO 42001 readiness co-marketed accelerator: onetrust.com/blog/scale-ai-responsibly-through-iso-42001-readiness-with-onetrust-and-aws/ (accessed 2026-09-14).
  8. [8] OneTrust AI Governance published framework coverage (EU AI Act, NIST AI RMF, ISO 42001, OECD AI Principles) from onetrust.com/solutions/ai-governance/ (accessed 2026-09-14). NYC Local Law 144, Colorado AI Act, and other jurisdictional AI-specific frameworks were not confirmed on OneTrust pages fetched today.
  9. [9] The single named AI Governance reference customer on OneTrust’s solution pages today is Blackbaud. Quote from Ren Nunes (Senior Manager, Data & AI Governance): “With OneTrust, our AI governance council has a technology-driven process to review projects, assess data needs, and uphold compliance. The customizable workflows, integrations with other platforms we utilize, and alignment with NIST’s AI Risk Management Framework have accelerated our approvals and helped embed oversight at every phase of the AI lifecycle.”Blackbaud’s own testimonial traces the journey from CCPA privacy work in 2018 into AI governance on the same platform. Other logos on the /solutions/data-teams/ page (Iberia, Amplifon, Boehringer Ingelheim, BT Group, Copeland) are not labeled AI Governance customers on any OneTrust page fetched today.
  10. EU AI Act citations to Regulation (EU) 2024/1689 — Article 12 (automatic-logging mandate for high-risk AI systems, 6-month minimum audit-log retention) and Article 99 (max fines of €35M or 7% of global turnover).
  11. All product capability claims for both platforms are current as of the “Prepared” date at the top of this page. OneTrust’s product surface evolves quarterly (Winter ‘26 release cadence); capabilities may have shipped since. Corrections: /contact.
  12. This page does not compare against IBM watsonx.governance, ServiceNow AI Control Tower, Credo AI, Holistic AI, or the other 2026 Gartner MQ vendors on their own merits — each has its own head-to-head brief under /compare. For the broader category framing and where vCISO Lite sits, see /blog/best-ai-governance-platforms-2026; for the underlying Evidence Graph, see /evidence-graph.