OneTrust Is the Most-Named Third-Party Risk Vendor. No AI Engine Names It First.

third-party risk management AI search visibility vendor risk management generative engine optimization
Govind Kumar
Govind Kumar

Co-founder/CPO

 
August 30, 2026
16 min read
OneTrust Is the Most-Named Third-Party Risk Vendor. No AI Engine Names It First.

TL;DR

  • We put 10,000 enterprise buyer-intent queries about third-party risk management to six AI engines in five markets and read the 300,000 answers that came back. OneTrust drew more mentions than any other vendor, 205,000, and was the first vendor named in none of the six engines. Bitsight, third on mentions, opened the answer in three. Nine of the 72 brand strings recorded were named by every engine, yet the engines shared a mean Jaccard overlap of only 0.19 across their cited domains, where 1 means identical, and 52.2% of the 1,551,000 pages they cited sit on a vendor's own site. Being in the answer, being named first, and being named most are three different results, and this category shows a vendor can hold one without the others.

Picture a head of security at a company with 400 suppliers. Her board has asked for a continuous monitoring program by year end, and the spreadsheet questionnaires are not going to survive that. She opens Microsoft Copilot and types the question she would otherwise have put to an analyst: which third-party risk platforms handle continuous monitoring and questionnaire automation at scale, in 2026? A list comes back with Bitsight first. She asks Gemini the same thing and gets ServiceNow first. In ChatGPT it is Whistic. OneTrust is on all three lists, and it is never the name she reads first.

That is the shape of the shortlist now. The AI answer is built before a vendor hears about the deal, so we wanted to measure what the engines put in it for one category, at a scale where the pattern is the finding rather than the anecdote.

Key Takeaways

  • OneTrust recorded 205,000 mentions and was the first-mention vendor in no engine. Bitsight recorded 161,000 and was the first-mention vendor in three.
  • Nine of the 72 brand strings recorded were named by all six engines. The five leading brands took 54.1% of all mentions.
  • The engines spread OneTrust across nine product entries. At product level, "Bitsight" at 146,000 and "UpGuard" at 134,000 both outrank "OneTrust" at 127,000.
  • Mean cited-domain overlap between engines was 0.19 as a Jaccard coefficient, where 0 is disjoint and 1 is identical. The only pairs above 0.22 were engines run by the same parent.
  • 52.2% of all cited pages sit on a vendor's own site, a majority in ChatGPT and Perplexity and a minority in the other four.
  • Only 0.2% of cited pages were dead.
  • OneTrust led all five markets; only the second and third positions moved.

How We Ran the Study

We issued 10,000 enterprise buyer-intent queries about third-party risk management, vendor risk monitoring and questionnaire automation to six AI engines: ChatGPT, Microsoft Copilot, Gemini, Google AI Mode, Google AI Overview and Perplexity. Every query ran in five markets (United States, Canada, Germany, India, Australia), giving 50,000 responses per engine and 300,000 in total, collected in August 2026.

For each response we recorded its length, every cited URL, the type of site it sits on and whether it still resolved, every brand named, the order in which brands were named, and which brand the engine put first. The corpus held 1,551,000 cited sources, 72 brand strings, and 127 distinct product entries after plan, edition and category-noun spellings of one product were merged.

The engines are commercial services with no pinned model versions, and the query set is purposive rather than sampled, so we report descriptive figures only and claim no statistical significance. The full method, the per-engine tables and the validity limits are in the complete benchmark report. One disclosure: GrackerAI sells AI search visibility measurement for the category this study covers. The study measured how the engines describe vendors, not the vendors' products, and no vendor paid for or saw any part of it.

The Most-Mentioned Vendor Is Not the One Named First

OneTrust recorded 205,000 mentions across the study, ahead of UpGuard at 165,000 and Bitsight at 161,000. It was also the most-mentioned brand inside three individual engines, ChatGPT, Gemini and Google AI Mode, and tied for first in Microsoft Copilot.

It was the first-mention vendor in none of them.

AI engine First-mention vendor Its mean position OneTrust's mean position
ChatGPT Whistic 1.9 3.2
Microsoft Copilot Bitsight 3.3 3.2
Gemini ServiceNow 4.8 3.6
Google AI Mode UpGuard 1.7 3.4
Google AI Overview Bitsight 2.7 3.3
Perplexity Bitsight 3.3 2.8

Mean position counts named vendors from one; lower is earlier. n = 50,000 responses per engine. Source: GrackerAI AI Search Visibility Benchmark Series, August 2026.

Bitsight held the opening position in Microsoft Copilot, Google AI Overview and Perplexity. Whistic, ServiceNow and UpGuard took it in one engine each. OneTrust's mean ordinal position, the place in the list where an engine names it, sat between 2.8 and 3.6 in every engine: on average the third or fourth name.

Figure 1. Mean ordinal position of OneTrust and Bitsight by AI engine Mean ordinal position of OneTrust and Bitsight by AI engine. ChatGPT: OneTrust 3.2, Bitsight 2.8; Microsoft Copilot: OneTrust 3.2, Bitsight 3.3; Gemini: OneTrust 3.6, Bitsight 2.5; Google AI Mode: OneTrust 3.4, Bitsight 2.5; Google AI Overview: OneTrust 3.3, Bitsight 2.7; Perplexity: OneTrust 2.8, Bitsight 3.3. OneTrust Bitsight 1 2 3 4 5 ChatGPT 2.8 3.2 Microsoft Copilot 3.3 3.2 Gemini 2.5 3.6 Google AI Mode 2.5 3.4 Google AI Overview 2.7 3.3 Perplexity 3.3 2.8 Mean ordinal position (1 = named first)
Figure 1. Mean ordinal position of OneTrust and Bitsight by AI engine. Where in the list each brand is named, counting from one; lower is earlier. n = 50,000 responses per engine. Source: GrackerAI AI Search Visibility Benchmark Series, August 2026.

Whistic makes the point from the other direction. In ChatGPT it recorded 20,000 mentions, fewer than half of OneTrust's 43,000 in the same engine, and it opened the answer with a mean position of 1.9. A vendor named half as often can still be the one the buyer reads first. Gemini shows the opposite split: ServiceNow opens its answers most often, yet averages position 4.8 there, which fits an engine that names a vendor first in some responses and near the end in others.

Our finding: Mention volume, first-mention frequency and mean position are three separate quantities. In this category the vendor that leads on the first leads on neither of the other two: UpGuard and Bitsight each sat earlier than OneTrust on average in four of the six engines.

We saw the same separation in attack surface management, where the most-mentioned vendor opened three engines and the runner-up was still read earlier on average in four, in a study of the same six engines across four markets rather than five. Two categories, same protocol, same split. If your visibility dashboard reports one number per vendor, it is hiding two of the three things that matter.

Nine Vendors Every Engine Names

The core of this category is settled and it is wide. Nine of the 72 brand strings recorded were named by all six engines: OneTrust, UpGuard, Bitsight, SecurityScorecard, ProcessUnity, Panorays, ServiceNow, Vanta and Riskonnect. Eight more were named by five.

Figure 2. AI engine mentions by third-party risk brand AI engine mentions by third-party risk brand. OneTrust 205,000; UpGuard 165,000; Bitsight 161,000; SecurityScorecard 146,000; ProcessUnity 132,000; Panorays 104,000; ServiceNow 102,000; Vanta 59,000; Whistic 51,000; MetricStream 34,000; Drata 29,000; Riskonnect 27,000. 0 50,000 100,000 150,000 200,000 250,000 OneTrust 205,000 UpGuard 165,000 Bitsight 161,000 SecurityScorecard 146,000 ProcessUnity 132,000 Panorays 104,000 ServiceNow 102,000 Vanta 59,000 Whistic 51,000 MetricStream 34,000 Drata 29,000 Riskonnect 27,000 Brand mentions
Figure 2. AI engine mentions by third-party risk brand. The 12 most-mentioned of 72 brand strings recorded; n = 300,000 responses. Source: GrackerAI AI Search Visibility Benchmark Series, August 2026.

The five leading brands took 54.1% of all brand mentions. Below ProcessUnity in fifth place at 132,000 the counts fall away: Panorays 104,000, ServiceNow 102,000, and no brand outside the seven most-mentioned exceeds 59,000. This is a broad leading group with a steep drop behind it, not a single leader.

The tail is where the engines part company. 38 of the 72 brand strings were named by exactly one engine, none of them above 10,000 mentions. Whistic, MetricStream, Drata and Aravo did not appear in Perplexity at all. Venminder was absent from ChatGPT and Gemini. Black Kite was absent from both Google surfaces. A brand in that tail is being recommended by some engines and is simply not present in others.

Concentration into a reused core is the recurring pattern in this series. Our analysis of why AI engines pick the same three DSPM vendors found it too.

OneTrust Is Nine Products to the Engines

The brand ranking and the product ranking disagree, and the reason is naming.

The engines produced 127 distinct product entries across the study, even after we merged plan, edition and category-noun spellings of one product. Counted by product entry, the most-mentioned is the bare name "Bitsight" at 146,000, then "UpGuard" at 134,000. "OneTrust" is third at 127,000. The brand that leads on total mentions drops to third the moment you count product entries, because the engines wrote OneTrust's products nine different ways: "OneTrust Third-Party Risk Management", "OneTrust Vendor Risk Management", "OneTrust Third-Party Management", "OneTrust Vendorpedia" and five more.

ServiceNow is the next case, with eight separate entries for what a buyer would treat as one or two products. Bitsight and UpGuard were mostly named by their bare brand, which is why they lead the product table.

Our finding: 81 of the 127 product entries were named by exactly one engine, and 61 of them recorded exactly 1,000 mentions. The tail is mostly single-engine: a product that one engine names and the other five do not. Microsoft Copilot alone accounts for 28 of those entries.

Any visibility tool that counts exact product strings will show OneTrust as one 127,000-mention entry plus eight fragments, and Bitsight as one 146,000-mention entry plus five that barely register. That is a measurement artifact, and it is one the vendor can remove. Publish one canonical product name and use it everywhere the engines are likely to read.

Same Shortlist, Different Web

The engines agree on who is in the category. They do not agree on where to read about it.

We measured overlap between each pair of engines' cited domains with a Jaccard coefficient, where 1 means identical source sets and 0 means none shared. The mean across all 15 engine pairs was 0.19. The highest value was 0.40, between Google AI Mode and Google AI Overview, and the next two highest, 0.30 and 0.28, both involved Gemini with one of those two. All three top values sit inside the same parent company. No pair from different parents exceeded 0.22.

Microsoft Copilot was the most isolated engine, the lowest-overlap partner for four of the other five, with values between 0.09 and 0.15. Its most-cited domain was a statistics aggregator that appeared in no other engine's top three sources. ChatGPT's most-cited domain was a questionnaire-automation vendor's own site, Gemini's was the site of a security vendor outside the leading group, Google AI Mode's was an analyst firm, and Google AI Overview's and Perplexity's were two different leading vendors' own sites. Six engines, six different top sources, and no engine's most-cited domain was the most-cited domain of any other.

Figure 3. Share of each engine's citations that point to a vendor's own site Share of each engine's citations that point to a vendor's own site. ChatGPT 72.3%; Perplexity 54.5%; Gemini 42.0%; Google AI Overview 41.0%; Microsoft Copilot 39.9%; Google AI Mode 36.5%. 0% 20% 40% 60% 80% ChatGPT 72.3% Perplexity 54.5% Gemini 42.0% Google AI Overview 41.0% Microsoft Copilot 39.9% Google AI Mode 36.5% Vendor-site share (% of cited sources)
Figure 3. Share of each engine's citations that point to a vendor's own site. Cited pages on a domain belonging to a vendor named in the response, as a share of that engine's own cited sources; n = 1,551,000 cited sources. Source: GrackerAI AI Search Visibility Benchmark Series, August 2026.

What the engines do share is a class of source. 52.2% of the 1,551,000 cited pages sit on a domain belonging to a vendor named in the answer. But that is a majority only in ChatGPT, at 72.3%, and Perplexity, at 54.5%. Gemini stood at 42.0%, Google AI Overview at 41.0%, Microsoft Copilot at 39.9% and Google AI Mode at 36.5%, and for those four the largest class was the residual one, pages outside every type we track. Analyst and review sites carried 8.6% of the corpus.

How each engine builds that source list is a question about retrieval rather than about vendors, and we take it apart in how the major AI engines choose which sources to cite.

The consequence for a vendor is direct. A citation earned on a domain that ChatGPT reads is not evidence of anything in Microsoft Copilot. Six engines need six measurements.

The Sources Are Almost All Still There

Of the 1,551,000 URLs the engines attached to their answers, 3,290 did not resolve when we tested them. That is 0.2% of the evidence base.

Four engines recorded no dead links at all: Microsoft Copilot, Gemini, Google AI Overview and Perplexity. Google AI Mode stood at 0.6% and ChatGPT at 0.4%. ChatGPT also cited the most sources, 567,000 or 36.6% of the corpus, so it accounts for 69.0% of the dead links on its own.

The definition matters. Many vendor sites answer an automated request with a 403 because the page sits behind a bot wall. The page exists; the crawler was turned away. Count those as dead and the rate balloons, which is what the first edition of this study did. We now count a page as dead only when it returns not-found, gone or a server error, or its host cannot be reached after a retry. On that definition, the pages these engines lean on are almost all there.

No engine cited its own parent's properties at a measurable rate, and no engine refused a single query. For a vendor, link decay is not the lever in this category. Working out which of your own URLs each engine cites is still a useful per-engine tracking workflow, but the fix at the end of it is rarely a redirect.

Five Markets, One Leader

We expected the shortlist to move between markets, because third-party risk obligations genuinely differ between Germany, Australia and the United States. It did not.

Market First Second Third
United States OneTrust UpGuard Bitsight
Canada OneTrust Bitsight UpGuard
Germany OneTrust Bitsight UpGuard
India OneTrust Bitsight UpGuard
Australia OneTrust UpGuard SecurityScorecard

Brands ranked by mentions within each market; n = 60,000 responses per market. Source: GrackerAI AI Search Visibility Benchmark Series, August 2026.

OneTrust led every market. UpGuard was second in the United States and Australia, Bitsight in the other three, and the third position rotated among the same group. 27 of the 127 product entries were recorded in all five markets, and every one of the ten most-mentioned entries was among them. The engines draw the same list everywhere and vary only the order behind the leader.

Our network security analysis found recommendations diverging by region, across seven engines and ten markets, so this may be a category where the engines reorder rather than a category where they localize. For a vendor the reading is the same either way. If you are absent from the shortlist in one of these five markets, you are absent in all of them. A localized landing page changes nothing about that.

Where the Engines Argue: Questionnaire Automation

The engines disagreed on one requirement. Asked how to cut questionnaire workload, ChatGPT returned AI-assisted evidence extraction in the form Whistic offers. Gemini more often returned native workflow orchestration inside ServiceNow. Asked which platform suits a program onboarding more than 200 vendors a year, ChatGPT most often named Whistic or ProcessUnity first, while Google AI Overview led with UpGuard or Bitsight, on the strength of combining security ratings with questionnaire workflows. That is the same split as the first-mention table: Whistic opens ChatGPT, Bitsight opens Google AI Overview.

The disagreement is about a category boundary. Dedicated questionnaire-and-evidence platforms on one side, ratings-led platforms with a questionnaire module on the other, and each engine placing the buyer's question on a different side of the line.

Six Engines, Six Shapes of Answer

The engines also answered in different shapes. Mean response length ran from 211.0 words in Google AI Overview to 520.0 in ChatGPT. Microsoft Copilot anchored 67% of its responses to an explicit date, more than any other engine, while Gemini anchored none. Four of the six engines cut off before finishing at some rate, from 2% in Google AI Mode up to 91% in ChatGPT, whose answers were the longest. That figure comes from a terminal-character test, which cannot separate a genuine cut-off from a response that simply ends without punctuation, so read the 91% as an upper bound. If truncation removes vendors, it removes the ones named last.

What a Third-Party Risk Vendor Should Do

Work out which of three problems you have. Outside the nine-brand core, you have an inclusion problem, and ordering does not apply yet. Inside it, you may have an ordering problem, and OneTrust shows that the most-mentioned vendor can have one. Track mentions, first-mention frequency and mean position separately; the components of an AI share of voice score are exactly those three.

Pick one product name and never vary it. Nine OneTrust entries and eight ServiceNow entries are splitting those vendors' own share of voice. Use the canonical string in documentation, pricing and analyst material, so the engines have nothing else to copy.

Take a position on questionnaire automation. It is the one requirement the engines argue about, and a vendor with a clear statement of AI-assisted evidence handling, automated questionnaire completion and shared vendor profiles is giving the engines something to quote. Structuring that kind of content so engines can extract it is the subject of our GRC content strategy for AI search.

Expect your own site to carry about half of the evidence. 52.2% of citations sit on vendor sites, and for four of the six engines the largest class is pages outside every type we track. Documentation, product and integration pages are what ChatGPT and Perplexity read; the other four read a web you do not control, so analyst coverage and third-party comparisons matter more there.

Measure six engines, not one. With a mean source overlap of 0.19, a single-engine reading tells you about that engine. If you are choosing instrumentation for a GRC or risk product, we compared the GEO tools built for GRC and compliance vendors.

Stop budgeting for link decay here. 0.2% of cited URLs were dead, and four engines recorded none. The inclusion problem is where the effort belongs.

Frequently Asked Questions

Which third-party risk management vendor do AI engines mention most?

OneTrust, with 205,000 mentions across 300,000 responses, ahead of UpGuard at 165,000 and Bitsight at 161,000. OneTrust was not the first vendor named in any of the six engines tested; Bitsight was, in three of them.

How many AI responses were analyzed for this third-party risk study?

300,000 responses, from 10,000 buyer-intent queries issued to six AI engines across five markets in August 2026. The responses contained 1,551,000 cited sources and 127 distinct product entries.

Do ChatGPT, Gemini and Copilot recommend the same third-party risk platforms?

Largely yes on the shortlist: nine of the 72 brand strings recorded were named by all six engines. They differ on who comes first, with Whistic opening ChatGPT, ServiceNow opening Gemini and Bitsight opening Microsoft Copilot, and they cite largely different sources, with a mean cited-domain overlap of 0.19.

What share of the sources AI engines cite for TPRM software no longer work?

0.2% of the 1,551,000 cited URLs did not resolve when tested. Four engines recorded no dead links, and no engine exceeded 0.6%.

Do AI recommendations for third-party risk tools change by country?

Not the leader. OneTrust led in all five markets. UpGuard was second in the United States and Australia and Bitsight in Canada, Germany and India, and all ten most-mentioned product entries appeared in all five markets.

Three Numbers, Three Different Leaders

Three numbers describe a vendor's standing in an AI answer, and this category shows how far apart they can sit. OneTrust leads on mentions, holds no first-mention position, and is on average the third or fourth name in every engine. Bitsight is third on mentions and first in three engines. Whistic is ninth on mentions and first in the engine with the longest answers. Nine brands are named by every engine, dozens are not, and the engines producing those answers agreed on the names while sharing roughly a fifth of their cited domains.

If you sell into this category, the question is no longer whether the engines know your name. For nine vendors they do. The question is what they do with it, engine by engine, and whether they are even spelling your product the same way twice.

The per-engine tables, the full product list and the validity limits are in the complete benchmark report.

Govind Kumar
Govind Kumar

Co-founder/CPO

 

Govind Kumar is a product and technology leader with hands-on experience in identity platforms, secure system design, and enterprise-grade software architecture. His background spans CIAM technologies and modern authentication protocols. At Gracker, he focuses on building AI-driven systems that help technical and security-focused teams work more efficiently, with an emphasis on clarity, correctness, and long-term system reliability.

Related Articles

Which Attack Surface Management Platforms AI Engines Recommend: A 240,000-Response Study
attack surface management

Which Attack Surface Management Platforms AI Engines Recommend: A 240,000-Response Study

Original study of 240,000 AI engine responses on attack surface management: vendor share of voice, cited sources, dead-link rates, and engine variance.

By Deepak Gupta August 27, 2026 14 min read
common.read_full_article
AI Detection in B2B Content: A Practical QA Workflow for Cybersecurity Teams
AI Detection

AI Detection in B2B Content: A Practical QA Workflow for Cybersecurity Teams

Learn a practical QA workflow for detecting AI-generated B2B content in cybersecurity to protect clients, data, and brand reputation.

By Vijay Shekhawat September 4, 2026 5 min read
common.read_full_article
All Six AI Engines Name the Same Ten Bot Management Vendors. Only ChatGPT Puts DataDome First.
bot management

All Six AI Engines Name the Same Ten Bot Management Vendors. Only ChatGPT Puts DataDome First.

Cloudflare tops 240,000 AI engine answers on bot management and opens five of six engines, but ChatGPT names DataDome first. Full per-engine data inside.

By Govind Kumar August 25, 2026 15 min read
common.read_full_article
AI Engines Mention Bitwarden Most for Enterprise Password Managers. Four of Six Name 1Password First.
enterprise password manager

AI Engines Mention Bitwarden Most for Enterprise Password Managers. Four of Six Name 1Password First.

Bitwarden tops 240,000 AI engine responses on enterprise password managers, 1Password opens four of six engines, and Keeper is second on mentions yet never first.

By Deepak Gupta August 22, 2026 15 min read
common.read_full_article