Kyūdō
Third-Party and Vendor Risk

Vendor Risk Management

Kyūdō manages vendor risk on the same Compliance Graph as your controls and evidence. Vendors, contracts, certifications, and sub-processors are connected entities, so risk scores reflect live control evidence rather than a static annual questionnaire, and Sensei AI Advisor drafts questionnaire responses from evidence you already hold, with citations a reviewer can verify.

Vendor Risk
Vendor risk management dashboard with scored vendor register
Key Capabilities

Built for how compliance actually works.

Vendors as Compliance Graph entities

Every vendor is inventoried as an entity connected to the controls it affects, the contracts and certifications that cover it, and the evidence behind each assessment. One record, fully connected.

Questionnaires, inbound and outbound

Sensei AI Advisor drafts responses to inbound security questionnaires from your existing control evidence, with per-answer citations. Outbound questionnaires to your vendors run through the same workflow.

Sub-processor and fourth-party mapping

Map who your vendors depend on, including their AI providers, so exposure two steps down the chain is visible in the same graph as your own controls.

Certifications and contracts as evidence

A vendor's SOC 2 report, ISO certificate, or data processing agreement is stored as an evidence object with hash, lineage, and expiry, linked to the assessments it supports.

AI provider disclosure

Track which vendors use which AI providers and what disclosure their contracts require, so vendor AI exposure is recorded rather than assumed.

Continuous monitoring

Vendors are reassessed when the signals or artifacts connected to them change, such as an expiring certification or a lapsed contract term, not on a fixed annual calendar.

01

Sensei Drafts Questionnaire Responses From Evidence You Already Hold

Answering the same security questionnaire for every prospect is repeated work over evidence that already exists. Sensei AI Advisor retrieves from the Compliance Graph, drafts each response from your live control evidence, and cites the specific nodes it drew from, so a reviewer verifies sources instead of rewriting answers. Responses below the confidence threshold are routed to human review before anything is sent.

Questionnaire Response
Questionnaire response drafting view with cited evidence
02

Risk Scoring Connected to Live Control Evidence

A vendor score derived from last year's questionnaire describes last year's vendor. In Kyūdō, each vendor's risk score is computed from what is currently connected to it in the Compliance Graph: control status, certifications and their expiry, contract terms, and assessment responses. When any of those change, the score is reassessed, so the register your team and your auditors read reflects the present.

Vendor Assessment
Vendor assessment scoring view
Related

Where vendor risk connects

AI governance

Govern the AI your vendors supply and the AI you deploy directly in one program.

Trust Center

Answer the questionnaires pointed at you by publishing live posture to customers.

Platform overview

See how vendor risk connects to controls, evidence, and risk on one graph.

Glossary

Definitions for fourth-party risk, sub-processor, evidence provenance, and more.

Frequently Asked

Questions, answered

Looking for more? See all frequently asked questions.