The OneTrust Platform
OneTrust is now introducing the evolution of its platform—designed to enable governance at AI speed and enterprise scale while keeping people in control. Combining CORIE, the AI Control Plane, and the Governance Command Center, the OneTrust Platform gives governance teams the shared intelligence, workflow connectivity, and controls to put AI to work at scale while managing risk. This safeguards AI transformation initiatives, increases operational efficiency, and empowers teams to make better risk decisions. Organizations can also extend the platform as their needs evolve, adding the policies, controls, workflows, and decision logic their business requires across industry-specific domains.
OneTrust CORIE: The Shared Intelligence Layer Across the OneTrust Platform: CORIE connects context and decisions across privacy, consent, technology risk, third-party management, and AI risk, drawing on a pre-built understanding of an organization’s environment and rules. It automates risk decisions with business teams’ oversight and provides the proof behind the decisions made and policies applied, saving teams time without sacrificing safety.
- Trust Graph: Maps AI systems and models alongside enterprise data, vendors and identities, connecting them with consent signals and applicable governance requirements.
- Reasoning Engine: Uses policies, prior assessments, and governance decisions to drive consistent, context-aware decisions across connected programs.
- Evidence Ledger: Captures what was considered, which policy or control applied, and what action was taken, creating an auditable record throughout the flow of work.
This intelligence powers the agent interactions across the platform. Whether using OneTrust’s native agents, customer-built agents, or third-party agents, CORIE provides the shared context, reasoning, and evidence needed to ensure actions are informed, governed, and explainable.
The AI Control Plane brings CORIE’s intelligence into AI workflows at runtime, establishing separation of duties for the AI era—through architecture rather than organizational boundaries. Acting as an independent control layer between AI agents and enterprise systems, it evaluates actions as they occur and applies or orchestrates the policies, guardrails, and controls that determine whether an action proceeds, is blocked, or requires human approval.
Headless Experience Via MCP Gateway: OneTrust is extending integrations beyond APIs to provide a headless experience via MCP Gateway, enabling AI-native integrations to applications such as ChatGPT, Claude, Copilot, and Glean. This brings governance context, intelligence, and workflows into the AI tools teams already use and build with. Reduces custom integrations and streamlines collaboration across a range of use cases spanning assessments, agent development, and more. Private preview in Fall.
Governance Command Center - Your Team’s Central Control Hub: Offers a holistic view of risk posture and governance activity, decisions, and exceptions. Teams can manage policies and controls across privacy, consent, technology risk, third-party management, and AI governance in one place, and intervene when human judgment is required.
“Across the business, new uses of AI are improving how we operate and serve our customers. Our role in governance is to help bring those ideas into production with a clear understanding of the risks, confidence that our policies will hold, and evidence of what AI does. OneTrust’s vision connects those requirements to the way work actually happens, enabling teams like ours to govern AI at scale and support the pace of innovation that moves our business forward.” - Kelly Thewes, Global Head of Data Privacy Compliance & Chief Data Ethics & Privacy Officer at Fiserv