AI Governance with Kyūdō
AI governance means governing the AI your organization deploys: keeping an inventory of AI systems, assessing their risk, collecting evidence of oversight, and assigning accountability for each one. Kyūdō runs all four on the Compliance Graph, the same governed data layer that holds your controls and evidence, so AI governance is part of your compliance program rather than a separate tool.
This page is the short answer. For the architecture, module walkthrough, and deployment detail, explore the full AI governance solution. For how the platform's own AI is governed, see what makes a GRC platform AI-native.
AI system inventory
Governance starts with knowing what you run. Kyūdō inventories AI systems as first-class entities in the Compliance Graph, connected to vendors, data flows, and controls, so the inventory is a working part of your compliance program rather than a static list.
AI systems as graph entities
Each AI system your organization runs is an entity in the Compliance Graph, not a row in a standalone register. It connects to the vendor that supplies it, the data flows it participates in, and the controls that govern it.
Connections stay current
When a vendor relationship, data flow, or control changes, every AI system connected to it reflects the change. The inventory answers from live data instead of a spreadsheet maintained by hand.
Accountability attached
Ownership, risk classification, and oversight obligations attach to each AI system directly, so the question of who is accountable for a given system has one recorded answer.
Vendor and fourth-party AI risk
Most of the AI in your environment arrives through vendors, and behind each vendor sits an AI provider you never contracted with directly. That is fourth-party AI risk: your vendors' model and infrastructure suppliers. Kyūdō maps these chains in the Compliance Graph, vendor to sub-processor to AI provider, so you can see which of your vendors depend on which AI providers and what data reaches them.
Contractual obligations, including AI provider disclosure, are tracked as attributes of the relationship. When a vendor adds or changes an AI provider, the exposure is visible in the same graph that holds your controls and evidence. This runs on Kyūdō's vendor risk management module, so third-party and fourth-party AI risk share one program rather than two.
Map once, prove three times
The three major AI frameworks overlap heavily. Kyūdō unifies them in one set of 156 AI governance controls, so an oversight control implemented once produces evidence that serves the EU AI Act, ISO 42001, and the NIST AI RMF together. See all supported frameworks for how the same crosswalk approach covers your cyber obligations.
EU AI Act
The European Union's risk-based regulation of AI systems. Obligations phase in through August 2026, so the relevant question is how current your evidence is on any given day.
ISO 42001
The international AI management system standard. It defines how an organization sets up and maintains governance over its AI, and certification is assessed by an accredited body.
NIST AI RMF
The NIST AI Risk Management Framework, a voluntary US framework for identifying, measuring, and managing AI risk across the lifecycle of each system.
Governance evidence, not governance intentions
AI governance frameworks ask for proof that oversight happened, not a policy stating that it should. Kyūdō collects that proof continuously and holds it to the same provenance standard as every other artifact on the platform. Unfamiliar terms are defined in the glossary.
Human oversight records
Who reviewed which AI decision, and when. Oversight events are captured as evidence artifacts rather than reconstructed from memory when an assessor asks.
Model documentation
Model cards, intended-use statements, and evaluation results are stored as governed artifacts linked to the AI system they describe.
Audit trail with provenance
Every artifact carries a hash, lineage, and confidence score, so an assessor can verify where a piece of governance evidence came from and that it has not changed.
Put AI governance on the same graph as your controls
Deploy inside your Azure tenant and see your AI systems, vendors, and governance evidence connect from your own signals.
Questions, answered
Kyūdō governs the AI your organization deploys by treating each AI system as an entity in the Compliance Graph, connected to the vendor that supplies it, the data flows it participates in, and the controls that govern it. 156 AI governance controls unify the EU AI Act, ISO 42001, and the NIST AI Risk Management Framework, and governance evidence such as human oversight records and model documentation is collected continuously with a hash, lineage, and confidence score per artifact.
Yes. The EU AI Act is one of the three frameworks unified in Kyūdō's 156 AI governance controls, alongside ISO 42001 and the NIST AI Risk Management Framework. Obligations under the Act phase in through August 2026, and Kyūdō maps them to controls you can evidence continuously inside your own Azure tenant, so readiness is a standing posture rather than a deadline project.
Fourth-party AI risk is the exposure created by your vendors' own AI providers: the model and infrastructure suppliers behind the tools your vendors sell you. Kyūdō maps these relationships in the Compliance Graph, so you can see which vendors depend on which AI providers, track contractual obligations such as AI provider disclosure, and connect that exposure to your own controls and evidence.
Yes. Kyūdō models AI systems as entities in the Compliance Graph, connected to the vendors that supply them, the data flows they touch, and the controls that govern them. Because the inventory lives on the same graph as your evidence, each AI system's governance status is answered from live data rather than a spreadsheet maintained by hand.
Yes. Sensei AI Advisor answers from deterministic Compliance Graph retrieval, cites the specific source nodes behind every answer, and carries a confidence score on every output. Results below the confidence threshold are routed to human review rather than answered speculatively, and AI inference runs inside your own Azure tenant, so prompts and evidence stay in your environment.
Looking for more? See all frequently asked questions.
