OneTrust
OneTrust is a governance platform for privacy, data and AI, sold to privacy teams, security and risk teams, data teams and marketing teams across five solution families. Privacy Automation maintains an automated data and activity map, runs privacy impact assessments and mitigation workflows, assesses vendor privacy risk, manages data processing agreements and transfers, and in its fuller package automates data subject request fulfilment from intake and identity verification through data retrieval, deletion and secure communication, alongside privacy incident and notification management. Consent and Preferences covers consent banners and preference centres across web, mobile and connected TV, backed by a database of categorised cookies and trackers, with a universal consent and preference product for managing consent across the customer journey. AI Governance maintains a register of AI initiatives, models, agents, datasets and vendors, aligns AI risk assessments and tiering to the EU AI Act, NIST and ISO 42001, configures approvals, attestations and evaluation gates before systems reach production, automates model documentation and regulatory reporting, and applies runtime controls across prompts, outputs, data access and permitted AI actions. Tech Risk and Compliance and Third-Party Management complete the set, the latter drawing on Dow Jones ethics and compliance databases for politically exposed person, sanctions and watchlist screening. AI assists inside the platform, with AI-generated risk assessments routed through a review and approval step involving privacy, security and legal reviewers before a use case proceeds. OneTrust reports more than 14,000 customers including Adobe, Samsung, Pfizer, Walgreens, Aetna and Maersk, publishes its Master Terms, Data Processing Addendum and Standard Contractual Clauses openly with full version histories, and operates a trust centre from which its SOC 2 Type II report, ISO certifications and penetration test summaries can be downloaded directly.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
Artificial intelligence is present, shipped and contractually confirmed, and it is a layer on a product whose value stands entirely without it. The core is registry and workflow software: a data and activity map, consent banners and preference centres, data subject request automation, vendor and third-party inventories, assessment templates across more than fifty standards, and policy approval workflows. Remove every model and all of that continues to work, which is the distinction this axis asks about. Where AI appears it accelerates an existing step rather than constituting one, with an AI-assisted risk assessment producing a summary and key findings that then route to human approval. Worth separating two things that are easy to conflate here: OneTrust sells AI governance as a subject matter, maintaining registers of a customer's models, agents and datasets and applying runtime controls to them, and that is the product managing someone else's AI rather than the product being AI. The Master Terms confirm the vendor's own use, answering the question of whether AI is used in the services with a plain yes.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is not asserted loudly and it is not measured either, and the document that would answer it is obtainable rather than published. The AI-assisted assessment shown on the home page produces a risk summary and graded findings across personal data processing, model accuracy and transparency, which is an output a compliance officer will act on, and no accuracy rate, benchmark, test set or error mode for it was located on any public surface. Several limbs of this axis do not bite: the product does not retrieve primary legal authority, so grounding to openable sources and citator checking are not the relevant questions, and the applicable risk is a wrong risk rating rather than a fabricated citation. The AI Systems Transparency Report is the artifact that would carry this and the Master Terms describe it as available upon request, which under the gated-is-not-absent rule is the middle tier rather than an absence, but its contents could not be read on 1 September 2026. Checked the home page, the trust centre, the pricing and packaging page and the published contracting explainer.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A review point is not merely claimed but drawn, with named roles, and the surrounding control structure is incomplete. The AI use case workflow published on the home page runs intake, then AI risk assessment, then a review and approve stage showing three pending reviewers identified as Privacy, Security and Legal, then continuous monitoring described as real-time oversight and alerts after workflow completion. That places the machine output before a human gate and says who holds it, which is more than most vendors in this lane publish. The AI Governance package reinforces it commercially, listing configurable approvals, attestations and evaluation gates before AI systems move to production, and runtime controls across prompts, outputs, data access and allowed AI actions. What is missing is the rest: nothing states what the assessment does unattended, at what confidence it defers, or what happens after it is wrong, and no statement was located about the behaviour of OneTrust's own models as distinct from the governance gates it sells.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
A named customer, a named individual and real figures are published, and nothing carries a date. The GOL customer story quotes Bruna Boccini, Head of Compliance and Data Protection Officer at the airline, and gives specific before-and-after numbers in her own account: vendor approval falling from almost thirty days to between five and zero, and request completion falling from fourteen or fifteen days to a few minutes, against a described estate of seven billion identifiers and thousands of data flows and vendors. A commissioned Forrester Total Economic Impact study adds a 227 per cent three-year return and a seven-month payback, which is a figure attached to a documented methodology a reader can assess. Around those sit a large named logo set including Adobe, Samsung, Pfizer, Walgreens, Aetna, Atlassian, Maersk and Bristol Myers Squibb, and a claim of more than 14,000 customers with more than half the Fortune 500. What holds this below the top band is dating: no located customer story or study carries a date, and the operational figures are the interviewee's own account rather than a measured study.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
The published commitments are substantive and contractual, and the training question is not answered. What a buyer can read before signing: a Data Processing Addendum published openly with version history, purpose limitation providing that personal data is processed only for the limited purposes described in the agreement and that OneTrust will not buy or sell customer personal data, customer retention of ownership of all data input into the services, tenant separation with data held in a logically-separated cloud database and a single production environment per customer, ISO 27701 certification for privacy information management, and deletion or export rights exercisable at any time during the term and for sixty days after it ends. Against that, nothing located states whether customer content is used to train or improve models, which is the first question this axis asks and a conspicuous silence for a company selling AI governance; the position on third-party model providers is equally absent; and privilege and work product are never mentioned, which matters because the platform is sold to privacy counsel and the workflow assigns a legal reviewer.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Nothing located addresses the line between an information tool and legal advice, on a product that produces compliance determinations for a professional audience. The platform assigns risk ratings, generates assessments against named regimes including the EU AI Act, GDPR and US state privacy laws, and routes them to a reviewer identified as Legal, so the output is consumed as a compliance judgement. What is published in its place is a performance commitment rather than an advice-line position: the Master Terms warrant that the cloud services will materially conform to the OneTrust User Guide throughout the subscription term. No statement was located that outputs are not legal advice, that OneTrust is not a law firm, that no professional relationship arises, or that a user should take advice on their own facts, and no jurisdiction limit or supervision and competence discussion appears. **This is the row most likely to move on this record**: the Master Terms PDF itself and the Legal and Compliance Information page were not opened on 1 September 2026, and a disclaimer may sit in either, so the grade rests on the home page, trust centre, pricing page and published contracting explainer.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A governance framework with real substance is published and its results are not. The trust centre states that OneTrust's AI governance programme is managed by an interdisciplinary AI Governance Committee, supported by AI governance processes across the organisation and the AI systems lifecycle, an internal AI use policy and employee training. That is an accountable body, a lifecycle scope and two named instruments rather than a list of adjectives, and it is backed by a dedicated Responsible AI section, a published Journey to AI Governance toolkit and an AI Systems Transparency Report. Two things keep it below the top band. No individual is named as accountable, the committee being identified only by function. And nothing has been disclosed about uneven output: no bias evaluation, no testing regime and no result appears on any public surface, which is a notable gap for a vendor whose own product sells bias and drift monitoring to others. The AI Systems Transparency Report is available on request rather than published, so it sits in the middle disclosure tier and its contents were not read.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Every limb this band names is published, current and specific enough to hold the vendor to, and this is the strongest stewardship record located in the corpus. Retention is customer-configurable rather than merely stated, with services shipping built-in data minimisation functionality including auto-deletion and retention periods, and OneTrust expressly encouraging customers to configure them down. Deletion is contractual and time-bounded: customers may delete or export their data in a structured, commonly used and machine-readable format at any point during the term and for up to sixty days after termination, after which remaining data is deleted under a destruction policy. Access control runs through customer-administered user access plus ISO 27001, 27017 and 27701 certification, with the security obligations set out in Appendix 1 of the published DPA. Subprocessors are maintained on a list with a thirty-day advance notice commitment for changes and a right to object on reasonable data protection grounds, remedied by an alternative provider or termination of the affected subscription. Incident practice is stated: notification without undue delay, continuing updates on material developments, and cooperation with the customer's own reporting obligations. Encryption is given concretely at AES-256 at rest and in backup and a minimum of TLS 1.2 in transit, and the trust centre publishes a 2026 penetration test executive summary alongside disaster recovery and business continuity exercise memos. The one soft edge is that the subprocessor list itself sits on the customer portal rather than the open trust centre.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
What the vendor stands behind is published, specific, versioned and independently assessed, which no other record in this pull matches. The Master Terms of Service are published in full at a dedicated legal centre, currently version 5.1 effective 23 March 2026, with every prior version back to August 2020 downloadable alongside the DPA, Standard Contractual Clauses, Business Associate Agreement and product-specific supplemental terms. The liability position is stated and benchmarked rather than buried: a cap on each party's liability equal to the total annual fees paid or payable in the preceding year, which OneTrust expressly notes is broader than the more common cap tied to fees for the applicable service only, with willful misconduct and intellectual property claims carved out and uncapped. An indemnity with stated scope covers third-party IP infringement claims arising from use of the cloud services, with OneTrust controlling the defence. A warranty a buyer can invoke commits the cloud services to conform materially to the User Guide throughout the term. OneTrust also publishes a plain-language explainer, Contracting with OneTrust, setting all of this out for a reviewer, and states plainly what it will not do, refusing uncapped liability for data breach and giving its reasoning. The Master Terms carry an independent TermScout assessment rating them 70 per cent customer favourable with a perfect score against buy-side deal breakers. What is absent is anything specific to AI output being wrong and any insurance position.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Integration is plainly a real part of the offering and no individual connection could be named from the surfaces read. A dedicated Integrations page sits in the platform navigation and is described as an extensive set of integrations for adding data management to existing workflows, the Third-Party Management package refers to automating vendor assessments with ecosystem integrations, the Consent product is described as scaling through APIs to collect and enforce consent across emerging channels, and some services ship components that a customer implements on its own systems and websites such as cookie consent scripts and data discovery agents. OneTrust is additionally distributed through the Azure Marketplace, which has its own published supplemental terms. What is missing is the naming and the depth: no specific system is identified anywhere on the pages read, no API reference or developer documentation was located, and nothing describes what moves in which direction. **The Integrations page was not opened on 1 September 2026**, so this grade is rebuttable upward on one fetch and is recorded conservatively rather than assumed.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The tenancy model is stated plainly, residency is offered, and the processing question is left open. The published contracting explainer describes cloud services delivered on a shared architecture, codebase and infrastructure, with customer data held in a logically-separated cloud database and each customer receiving a single production tenant environment, with non-production environments included in some subscriptions and further environments purchasable. Residency is a customer choice: customers can select from various geographic hosting locations for their tenant environment. What changes between tiers is also addressed, with HIPAA-compliant and PCI-compliant environments available for customers with specialised requirements, backed by a published PCI attestation of compliance and a HITRUST certification. Two things hold it below the top band. The available regions are referred to collectively rather than enumerated, so a buyer cannot see the list without asking. And where processing happens is nowhere distinguished from where data is stored, which matters for the AI features specifically since no model or provider is identified.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
This is the trust centre the band describes and the first record in this pull to reach the top of this axis. Attestations are current, independent, and downloadable directly as PDFs with no form, no email capture and no NDA click-through: a SOC 2 Type II report, a second SOC 2 Type II for Certification Automation, ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27017 and ISO 9001 certificates, and, decisively for the scope limb, **a published Statement of Applicability** setting out which controls are in scope. Industry and sector records sit alongside them: a PCI DSS attestation of compliance signed November 2025 with a third-party responsibility matrix, a HITRUST certification letter, TISAX, TX-RAMP, the Spanish ENS conformity statement, and a CAIQ v4.0.3 self-assessment lodged on the Cloud Security Alliance STAR registry. Security documentation goes beyond certificates to a 2026 penetration test executive summary, a completed standard SIG questionnaire, a security, privacy and architecture whitepaper, and disaster recovery and business continuity exercise memos, with a live system status page. Under the gated-is-not-absent tiers this is open publication rather than the self-serve request tier, which is what separates it from every other record graded on this axis so far.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
AI use is confirmed and nothing underneath it is identified publicly. The Master Terms answer the question of whether OneTrust uses artificial intelligence in the services with a plain yes, and direct the reader to the AI Systems Transparency Report, described as available upon request. No model, model family, provider or architecture is named on any public surface read on 1 September 2026, and no statement excludes a third-party foundation model either, so a customer cannot tell from published material whose model processes the assessments and documentation it generates. Where inference runs is not addressed separately from where data is stored. No commitment to notify customers when the model set changes was located, though the subprocessor change process does carry a thirty-day notice commitment and would capture a model provider engaged as a subprocessor. This sits above the bottom band because a dedicated transparency artifact exists and is obtainable rather than absent, which is the middle disclosure tier, and below the band above because nothing is actually named where a reader can see it.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The unit and the structure are published in more detail than anywhere else in this corpus, and no figure appears. A dedicated pricing and packaging page sets out nine named packages across five solution families, each with its key capabilities listed so the feature split between base and suite editions is visible, and, unusually, **each with its own charging meter stated explicitly**: AI Governance priced on admin users and AI inventory; the Consent Management Platform on average daily visitors aggregated across channels and properties; Universal Consent and Preference Management on total data subject profiles captured; Privacy Automation on users and privacy asset inventory; Tech Risk and Compliance on admin users and asset inventory; and Third-Party Management on admin users and third-party inventory. Published FAQs explain what a solution package is, that pricing runs on value-based usage meters, and that a tiered model applies with an account executive moving a customer up a tier when usage consistently exceeds limits. What is absent is the number: no rate, band, floor or currency appears anywhere, every package routes to a Get Pricing form, and nothing states what implementation or professional services add.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is described across three deliberate axes with substance behind each, and the boundary is left open. Solutions are organised by function into six families, by role into data, marketing, privacy, and security and risk teams, and by regulation with dedicated pages for GDPR, US privacy law and the EU AI Act plus a wider regulatory index. Practice depth is real: the Tech Risk and Compliance package cites templates and guidance across more than fifty standards, regulations and frameworks, the AI Governance package names the EU AI Act, NIST and ISO 42001 as the frameworks assessments align to, and third-party screening reaches politically exposed persons, sanctions and watchlists through Dow Jones data. The customer base spans regulated industry, retail, pharmaceutical, technology and non-profits on the published logo set. Two gaps keep it here. Nothing states where the product stops, with no statement of organisation size, data volume or the situations it does not fit. And the By Role navigation, which is where a legal buyer would look, offers privacy, security and risk, data and marketing teams and **no page for legal or counsel**, even though the product's own published workflow assigns a legal reviewer.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No located term or policy addresses the question either way.
No located term or policy addresses the question either way, which is the single most surprising gap on this record. OneTrust publishes a Master Terms of Service, a Data Processing Addendum and Standard Contractual Clauses openly with full version histories, confirms in the contracting explainer that artificial intelligence is used in the services, and states that personal data is processed only for the limited purposes described in the agreement and that customer personal data will not be bought or sold. None of that reaches model training. The purpose limitation is the nearest thing and it is a general processing restriction rather than a training prohibition, and it is expressed over personal data rather than over the assessments, policies and inventories a customer builds in the platform. The document that would answer it, the AI Systems Transparency Report, is described as available upon request rather than published. Searched the trust centre, the legal centre including the contracting explainer, the pricing page and the home page on 1 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
The customer controls the retention window, by product configuration or by contractual instruction, but zero retention is not stated as available.
Retention is under the customer's control as a product configuration rather than a contractual instruction, which is rarer than the value name suggests. The published contracting explainer states that some services include built-in functionalities for data minimisation including auto-deletion and retention periods, and that OneTrust encourages customers to configure the services to reduce the amount of personal data held in its environment at any point. Alongside that sits an explicit deletion and portability right: customers may delete or export their data in a structured, commonly used and machine-readable format at any time during the subscription term and for up to sixty days after termination, after which remaining data is deleted under a destruction policy. What is not stated is a zero-retention option, and no separate window is published for AI prompts or generated assessments as distinct from customer records generally.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own permission model, documented, requiring the firm to keep it aligned.
OneTrust operates its own documented permission and separation model, and it is described at the tenant and user level rather than below it. The contracting explainer states that customer data is held in a logically-separated cloud database, that each customer receives a single production tenant environment for all subscribed services, and that the customer's own users control access to the cloud services as well as the volume and types of data submitted, with OneTrust not having specific access to what a customer chooses to submit. ISO 27701 certification covers the privacy information management system around it. What is not addressed is separation inside a single customer account: nothing describes walls between teams, business units or matters, which is a live question because the published workflow routes a single AI use case to privacy, security and legal reviewers who sit in different functions.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Terms commit to notice where lawfully permitted. No transparency report located.
A position is published, a transparency report exists, and the notice limb rests on a document other than the customer agreement. The contracting explainer states that OneTrust does not voluntarily disclose or grant access to any personal data of its customers to government authorities unless required by law, and directs the reader to a published policy and transparency report on government and law enforcement requests. The notice commitment located sits in the Mutual Nondisclosure Agreement, which provides that confidential information may be disclosed as required by law or valid legal order after using reasonable efforts to provide notice of the disclosure; that document governs pre-contract confidential information rather than platform data. The Data Processing Addendum PDF, which is where a notice commitment for customer data would sit, was not opened on 1 September 2026, so this row may move up to notice and report on reading it.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Sources are identified without stating the licence or rights basis.
The product does not retrieve primary law, and the reference datasets it does carry are named, which is more than most vendors manage. Three are identified on the pricing page: a database of more than 45 million categorised cookies and trackers behind the consent product; risk intelligence data on millions of third parties behind third-party management; and, named to its provider, Dow Jones ethics and compliance databases supplying politically exposed person, sanctions and watchlist screening in the Third-Party Management Suite. Regulatory change intelligence is attributed to DataGuidance within Privacy Automation. What is absent is the rights basis: no licence, ownership or public-domain footing is stated for any of them, and no update cadence is published beyond the claim that inventories are evergreen. Checked the pricing and packaging page, the home page and the trust centre on 1 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
No citator applies and the row is recorded rather than skipped. The platform does not return legal authority whose subsequent history could be checked; it maintains registers, runs assessments and enforces controls. The nearest analogue is regulatory currency rather than treatment: Privacy Automation is described as helping customers understand the operational impact of regulatory changes through DataGuidance intelligence, and the AI Governance package aligns assessments to named frameworks including the EU AI Act, NIST and ISO 42001, so the platform tracks whether a requirement has moved without purporting to tell a user whether an authority still stands. Searched the pricing and packaging page, the home page, the trust centre and the published contracting explainer on 1 September 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Nothing located describes what the AI does when it cannot assess reliably. The published workflow shows an AI-assisted assessment returning a risk summary graded medium with findings graded medium and low, so the output carries a severity rating, but a risk grade is a conclusion about the subject rather than a statement of the model's own confidence, and nothing indicates what a user sees when the system cannot reach one. No abstention path, confidence score or coverage indicator is documented. The structural mitigation is the approval gate rather than a model behaviour: every assessment routes to named human reviewers before a use case proceeds, so an uncertain output is caught by process rather than flagged by the system. Searched the home page, the pricing and packaging page, the trust centre and the contracting explainer on 1 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name. No court order, opinion or disciplinary record naming OneTrust was located. This is a statement about the public record rather than a finding about the product. The failure mode this signal tracks fits poorly: the platform's AI output is a risk rating or a piece of model documentation consumed inside a governance workflow and gated by human approval, not a citation to legal authority prepared for filing, so the analogous exposure would be a mis-rated assessment surfacing in a regulatory examination rather than in a court.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
No engagement with professional responsibility or ethics guidance was located, which is worth separating carefully from what OneTrust does publish. The company engages extensively with regulation as subject matter, naming GDPR, US state privacy laws, the EU AI Act, NIST, ISO 42001, DORA and more than fifty standards and frameworks in its packages, and maintains a public glossary of AI governance and privacy terms. None of that is guidance binding the professional who relies on the output. Nothing references ABA Formal Opinion 512, any state bar opinion, Law Society or SRA guidance, or any equivalent addressed to counsel using AI tools, and no general statement that a user's own professional obligations survive use of the platform was found. Searched the home page, the trust centre, the pricing page, the legal centre and the published contracting explainer on 1 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Savings are quantified and billing treatment is never addressed. A commissioned Forrester Total Economic Impact study is promoted with a 227 per cent three-year return on investment and a seven-month payback, and the GOL customer story gives operational time reductions from thirty days to five or fewer for vendor approval and from a fortnight to minutes for request completion. The buyer is an in-house privacy, legal or risk function rather than a firm billing a client, so the fee question lands obliquely, but it is not absent: outside counsel and consultancies use platforms of this kind on client engagements, and nothing published addresses how AI-assisted assessment work should be disclosed or billed where that happens. No per-matter record of AI-assisted work is described for that purpose, as distinct from the audit-ready evidence the product generates about a customer's own AI systems.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
The material exists behind a sales conversation or an executed agreement.
Half of what a client's AI clause asks for is openly published and the half about AI is obtainable rather than public. On the open side, and this is unusually strong: the Data Processing Addendum, the Standard Contractual Clauses and the Master Terms are all downloadable from the legal centre without an agreement in place, with full version histories, which is precisely the forwardable contractual material the signal contemplates. On the gated side, the subprocessor list is maintained on the customer portal rather than the open trust centre, though with a thirty-day advance notice commitment for changes and a right to object on reasonable data protection grounds. And **no model provider is named anywhere**: the AI Systems Transparency Report is described as available upon request. Under the coverage test a firm therefore cannot tell its client which systems see its content without first contracting or requesting, which is what places this at the request tier rather than higher.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
There is an inversion worth naming here: OneTrust sells the capability to produce exactly this record about a customer's own AI, while its own equivalent is available on request. The AI Governance package automates model documentation, audit-ready evidence and regulatory reporting outputs, configures approvals, attestations and evaluation gates, and correlates runtime behaviour with purpose, data sensitivity and regulatory obligations, which is a disclosure record about the customer's systems. For OneTrust's own AI, the published workflow logs a review and approve step naming privacy, security and legal reviewers, so who signed off is captured. What is not established is whether that record identifies which output was machine-generated or which model produced it, and no document-level export covering model, sources and verification is described. OneTrust's own AI Systems Transparency Report is available upon request rather than published.