IBM watsonx.governance
AI governance toolkit to direct, manage and monitor AI models across their lifecycle
Turn AI policy into enforceable controls across homegrown and third-party AI systems
Our assessment — not a user rating. How we score
Toolglade take: A mature, enterprise-grade AI governance platform that stands out by pushing beyond policy documentation into real runtime enforcement, best suited to large regulated organizations that can absorb custom enterprise pricing.
OneTrust AI Governance helps enterprises discover and inventory AI systems, agents, models, and datasets, then assess risk against the EU AI Act, NIST AI RMF, and ISO 42001. It automates intake, approval, and attestation workflows while generating audit-ready evidence across the AI lifecycle. Runtime capabilities monitor models and agents in production, detect policy violations and sensitive data, and enforce guardrails that can block, redact, route, or escalate actions. It integrates natively with platforms such as Amazon Bedrock, Microsoft Azure AI Foundry, Google Vertex, and Databricks.
OneTrust AI Governance is the AI governance module of the OneTrust trust platform, built to help enterprises inventory AI systems, models, agents, datasets, and vendors, then classify and assess risk against frameworks such as the EU AI Act, the NIST AI Risk Management Framework, and ISO 42001. It centralizes intake, approvals, ownership, and audit-ready evidence in an AI Program Center so governance and security teams gain visibility into what is running and whether it was ever formally reviewed. Beyond documentation, the product extends into runtime enforcement. It monitors model and agent behavior in production across supported platforms, detects policy violations and sensitive data exposure, and applies guardrails that can block, redact, route, or escalate activity where AI actually runs. Capabilities such as AI Policy Manager, Guardrail Enforcement, the AI Guard SDK, Guardian Agents, and MCP governance connect written policy to machine-ready controls.
OneTrust AI Governance is the AI governance module of the OneTrust trust platform, aimed at enterprises that need to inventory, assess, and control AI systems at scale. It aligns to the EU AI Act, NIST AI RMF, and ISO 42001 and centralizes intake, approvals, and audit evidence. What sets it apart is runtime enforcement: monitoring models and agents in production, detecting violations and sensitive data, and applying guardrails where AI runs. It integrates natively with Amazon Bedrock, Microsoft Azure AI Foundry, Google Vertex, and Databricks. Pricing is custom and not publicly disclosed, reflecting its enterprise positioning.
OneTrust is a privately held software company founded in 2016 and headquartered in Atlanta, Georgia. It built its business on privacy management, consent, and cookie compliance, and has expanded into a broader trust platform spanning data use governance, third-party management, tech risk and compliance, and AI governance. The company appointed John Heyman as Chief Executive Officer to drive its AI-ready governance platform strategy.
OneTrust AI Governance sits within this platform and reflects the company push into AI-specific oversight. OneTrust was named a Visionary in the inaugural 2026 Gartner Magic Quadrant for AI Governance Platforms, and it markets a shared operating model connecting governance teams and AI owners across models, datasets, agents, vendors, and platforms.
The product organizes work into managing AI risk, observing AI at runtime, controlling AI actions and use, and proving governance in production. Teams discover and centralize AI systems, agents, models, datasets, and vendors in an AI Program Center, assign ownership, and apply consistent risk evaluation using EU AI Act, NIST AI RMF, and ISO 42001 templates. Automated workflows route intake, approval, attestation, and signoff while tracking lifecycle status, exceptions, and required controls.
Runtime capabilities monitor model and agent behavior across supported platforms such as Amazon Bedrock and Microsoft Azure AI Foundry, surfacing evaluation, usage, and PII signals. AI Policy Manager defines policy intent while Guardrail Enforcement executes technical actions to filter prompts and outputs, and block, redact, route, or escalate activity. The AI Guard SDK, a Python library, detects sensitive data in prompts and responses before a model sees it, and Guardian Agents plus MCP governance controls extend auditable oversight into agentic environments.
OneTrust AI Governance targets large enterprises and regulated organizations that have significant AI adoption and face obligations under the EU AI Act, NIST AI RMF, ISO 42001, and other emerging regulations. Its primary audiences are privacy, compliance, legal, security, and risk teams, as well as data and AI governance councils that need centralized visibility and enforceable controls. It is less suited to small businesses, startups, or individual developers given its enterprise focus and custom pricing.
AI governance managers, privacy analysts, risk and compliance specialists, and security engineers who inventory AI, run assessments, configure workflows, and monitor and remediate runtime risk.
Chief Privacy Officers, Chief Information Security Officers, Chief Compliance Officers, and heads of data and AI governance who own budget and platform selection.
Legal counsel, data science and ML engineering leaders, procurement, internal audit, and AI governance councils that shape requirements and approve controls.
A large or mid-to-large enterprise in a regulated sector with active AI development and third-party AI usage, existing OneTrust or trust-tooling investment, and a mandate to demonstrate compliance and enforce controls across the AI lifecycle.
OneTrust is a private company that, according to third-party trackers, has raised roughly 1.13 billion dollars across multiple rounds from investors including TCV, Insight Partners, Coatue, and Generation Investment Management. Its largest round was a 300 million dollar Series C in December 2020, and a later 150 million dollar round in July 2023 was led by Generation Investment Management at a reported valuation of about 4.5 billion dollars, a decrease from an earlier peak valuation. These figures come from external sources and are not confirmed by OneTrust in official product materials.
It provides built-in assessment templates and controls aligned to the EU AI Act, the NIST AI Risk Management Framework, and ISO 42001, with automated risk tiering by use case and system type.
Yes. It connects to production environments such as Amazon Bedrock and Microsoft Azure AI Foundry, monitors model and agent behavior, detects policy violations and PII, and can block, redact, route, or escalate actions at the point of execution.
OneTrust does not publicly disclose pricing. It uses custom enterprise quotes obtained through a sales conversation, and there is no advertised free plan or self-service trial.
Yes. It registers agents with a defined purpose, enforces permissions and allowed actions, governs multi-agent handoffs, and applies MCP policies with audit logs through capabilities such as Guardian Agents and MCP governance controls.
Side-by-side pages for pricing, features, and best-fit use cases.
AI governance toolkit to direct, manage and monitor AI models across their lifecycle
Enterprise AI observability and security for LLMs, agents, and ML models
Unified AI evaluation, observability, and governance for regulated enterprises
Agentic AI workspace for in-house legal and compliance teams