Kyūdō
Reference

GRC and AI Governance Glossary

This glossary defines 17 terms used across governance, risk, and compliance and AI governance, in plain language. Each entry gives a one-sentence definition, why the concept matters, a concrete example, and how Kyūdō addresses it.

AI-native GRC

AI-native GRC is a governance, risk, and compliance architecture in which AI reasons over governed, connected compliance data as the platform's operating substrate rather than as a chat feature added to static records.

Why it matters

It determines whether AI output can be trusted for audit work. AI retrofitted onto disconnected records cannot trace its answers to verifiable sources.

Example

An analyst asks which frameworks are affected by a failed access control and receives an answer that cites the specific control, evidence artifact, and framework mappings behind it.

How Kyūdō addresses it

Kyūdō implements this with Sensei AI Advisor, which retrieves deterministically from the Compliance Graph and cites its source nodes.

Microsoft-native GRC

Microsoft-native GRC is a compliance platform approach that reads signals directly from Microsoft security services such as Defender XDR, Sentinel, Purview, Entra ID, and Azure Policy rather than through generic third-party connectors.

Why it matters

Evidence quality depends on signal fidelity. Reading the primary source removes the lag and loss that generic connectors introduce.

Example

A conditional access policy change in Entra ID appears as refreshed control evidence without anyone exporting a report.

How Kyūdō addresses it

Kyūdō converts Defender XDR, Sentinel, Purview, Entra ID, and Azure Policy signals into scored evidence, and also ingests AWS, Google Cloud, and Oracle Cloud signals.

Sovereign GRC

Sovereign GRC is a deployment model that keeps the compliance platform, its data, and its AI processing entirely inside infrastructure the customer owns and controls.

Why it matters

Compliance data describes an organization's weakest points. Regulated entities increasingly require that this data never sit in another company's cloud.

Example

A defense contractor runs its full GRC stack inside its own Azure tenant, so no external party ever holds a copy of its control evidence.

How Kyūdō addresses it

Kyūdō deploys via Azure Managed Applications inside the customer's Azure tenant with no cross-tenant data plane and AI inference on in-tenant Azure OpenAI Service.

Customer-hosted GRC

Customer-hosted GRC is a model in which the GRC application runs inside the customer's own cloud tenant instead of the vendor's multi-tenant SaaS environment.

Why it matters

It changes who holds the data and who sets the security boundary. The customer's existing identity, network, and monitoring controls apply directly to the platform.

Example

A bank deploys its GRC platform into its own subscription, puts it behind private endpoints, and audits it with the same tooling as any internal system.

How Kyūdō addresses it

Kyūdō ships as an Azure Managed Application that installs into the customer's tenant with private endpoints only.

Continuous controls monitoring

Continuous controls monitoring (CCM) evaluates control effectiveness automatically and repeatedly from live system signals instead of through periodic manual testing.

Why it matters

Point-in-time testing leaves long blind windows between assessments. Continuous evaluation shows posture as it is now, not as it was at the last audit.

Example

An encryption control flips to failing within hours of a storage account being misconfigured, rather than surfacing months later during audit preparation.

How Kyūdō addresses it

Kyūdō recalculates control status as Microsoft Defender XDR, Sentinel, Purview, Entra ID, and Azure Policy signals arrive.

Compliance evidence automation

Compliance evidence automation is the practice of collecting, refreshing, and attaching audit evidence from source systems automatically rather than by manual export and upload.

Why it matters

Manual evidence gathering is the largest recurring cost in most compliance programs, and hand-collected artifacts go stale immediately.

Example

Instead of screenshotting an MFA configuration each quarter, the platform pulls the setting from the identity provider and records it with a timestamp.

How Kyūdō addresses it

Kyūdō converts Microsoft security signals into evidence artifacts that each carry a hash, lineage, and confidence score.

Audit-ready evidence

Audit-ready evidence is compliance evidence that carries verifiable provenance, including origin, collection time, integrity hash, and lineage, so an assessor can rely on it without rework.

Why it matters

Assessors discount evidence they cannot verify. Provenance turns a screenshot-grade artifact into a defensible record.

Example

An access review artifact shows the exact query that produced it, when it ran, and a hash proving it has not been altered since collection.

How Kyūdō addresses it

Every artifact in Kyūdō carries a hash, lineage, and confidence score from the moment it is created.

Compliance graph

A compliance graph is a connected data model that represents controls, risks, policies, vendors, evidence, frameworks, and AI systems as linked entities rather than rows in separate tables.

Why it matters

Compliance questions are relationship questions: which risks does this control treat, which frameworks does this evidence satisfy. A graph answers them directly.

Example

When a control fails, the graph immediately shows the affected risks, framework obligations, and vendor relationships connected to it.

How Kyūdō addresses it

Kyūdō's Compliance Graph is the substrate Sensei AI Advisor retrieves from, which is what lets its answers cite source nodes.

Vendor risk management

Vendor risk management (VRM) is the discipline of assessing, monitoring, and treating the risks an organization inherits from the vendors it buys products and services from.

Why it matters

A vendor's security failure becomes your incident. Regulators and customers increasingly hold organizations accountable for their supply chain.

Example

Before renewing a payroll provider, the security team reviews its assessment responses, certifications, and open findings in one place.

How Kyūdō addresses it

Kyūdō scores vendors on the same Compliance Graph as internal controls, so a vendor's weakness maps to the specific obligations it threatens.

Third-party risk management

Third-party risk management (TPRM) extends vendor risk management to every external party with access to an organization's data, systems, or processes, including partners, contractors, and service providers.

Why it matters

Risk enters through any connected party, not only paid vendors. TPRM widens the assessment boundary to match the real attack and compliance surface.

Example

A marketing agency with access to the customer database is assessed with the same rigor as a software vendor, because the exposure is equivalent.

How Kyūdō addresses it

Kyūdō models all external parties as entities in the Compliance Graph, linked to the systems and data they touch.

Fourth-party AI risk

Fourth-party AI risk is the exposure created when your vendors embed AI systems, often from their own suppliers, into products your organization depends on.

Why it matters

Your data may be processed by AI models you never evaluated and never contracted with. Standard vendor questionnaires rarely surface this layer.

Example

A CRM vendor adds an AI assistant built on a third-party model, and customer records begin flowing to a model provider you have no agreement with.

How Kyūdō addresses it

Kyūdō's vendor assessments capture embedded AI usage and link it to the platform's AI governance controls in the Compliance Graph.

AI governance

AI governance is the set of policies, controls, and oversight processes that keep an organization's use of AI lawful, documented, and aligned with frameworks such as the EU AI Act, ISO 42001, and the NIST AI RMF.

Why it matters

AI obligations are now dated regulatory requirements, with EU AI Act obligations applying from August 2026. Organizations need an inventory of AI systems and evidence of the controls around them.

Example

A company classifies an internal hiring screener as high risk under the EU AI Act and documents the human oversight and logging controls attached to it.

How Kyūdō addresses it

Kyūdō ships 156 AI governance controls covering the EU AI Act, ISO 42001, and the NIST AI RMF, with AI systems as first-class entities in the Compliance Graph.

Control inheritance

Control inheritance is the reuse of a control that is implemented and evidenced once to satisfy obligations in multiple frameworks, systems, or organizational units without duplicate work.

Why it matters

Most frameworks overlap heavily. Without inheritance, teams re-implement and re-evidence the same safeguard for every new obligation.

Example

One MFA implementation, evidenced once, satisfies related requirements in SOC 2, ISO 27001, and CMMC simultaneously.

How Kyūdō addresses it

Kyūdō's unified catalog of 1,400+ controls maps each implementation across 80+ frameworks through the SCF crosswalk.

Framework crosswalk mapping

Framework crosswalk mapping is the practice of relating the requirements of one compliance framework to equivalent requirements in others through a common control taxonomy.

Why it matters

It converts multi-framework compliance from parallel projects into one program. The quality of the mapping determines how much work is actually saved.

Example

A crosswalk shows that an access control requirement in ISO 27001 corresponds to specific requirements in SOC 2 and NIST 800-171, so one implementation covers all three.

How Kyūdō addresses it

Kyūdō uses the Secure Controls Framework crosswalk with STRM semantic mapping (NIST IR 8477) to relate 1,400+ controls across 80+ frameworks.

Assessment-objective coverage

Assessment-objective coverage measures compliance at the level of the individual objectives an assessor tests, rather than at the coarser level of whole controls.

Why it matters

A control can look implemented while individual objectives inside it fail. Objective-level tracking shows readiness the way the assessor will actually score it.

Example

A CMMC practice with five assessment objectives shows four met and one open, instead of a single misleading green checkmark on the practice.

How Kyūdō addresses it

Kyūdō tracks evidence against individual assessment objectives in the Compliance Graph, with CMMC Phase 2 enforcement beginning November 10, 2026 as a common planning anchor.

Trust center

A trust center is a portal where an organization shares its security and compliance posture, certifications, and documentation with customers and prospects.

Why it matters

Security questionnaires stall deals. A current, self-serve posture page answers most diligence questions before they are asked.

Example

A prospect reviews a vendor's control summaries and subprocessor list in its trust center and skips forty questionnaire items.

How Kyūdō addresses it

Kyūdō's Trust Center publishes posture drawn from the same live Compliance Graph that drives internal monitoring, so the public page and the internal state cannot diverge.

Policy lifecycle management

Policy lifecycle management is the governed process of drafting, approving, publishing, attesting to, reviewing, and retiring organizational policies.

Why it matters

Auditors test whether policies are current, approved, and acknowledged. An unmanaged policy set fails all three quietly.

Example

An acceptable use policy moves through review and approval, employees attest to it, and the system schedules its next review date automatically.

How Kyūdō addresses it

Kyūdō's Policy Center links each policy to the controls it mandates in the Compliance Graph, so a policy change surfaces the controls it affects.

From definitions to working proof

The fastest way to understand these concepts is to watch them run against your own Azure tenant. Common questions are answered in the FAQ.