OneTrust Is the Most-Named Third-Party Risk Vendor. No AI Engine Names It First.
TL;DR
- We put 10,000 enterprise buyer-intent queries about third-party risk management to six AI engines in five markets and read the 300,000 answers that came back. OneTrust drew more mentions than any other vendor, 205,000, and was the first vendor named in none of the six engines. Bitsight, third on mentions, opened the answer in three. Nine of the 72 brand strings recorded were named by every engine, yet the engines shared a mean Jaccard overlap of only 0.19 across their cited domains, where 1 means identical, and 52.2% of the 1,551,000 pages they cited sit on a vendor's own site. Being in the answer, being named first, and being named most are three different results, and this category shows a vendor can hold one without the others.
Picture a head of security at a company with 400 suppliers. Her board has asked for a continuous monitoring program by year end, and the spreadsheet questionnaires are not going to survive that. She opens Microsoft Copilot and types the question she would otherwise have put to an analyst: which third-party risk platforms handle continuous monitoring and questionnaire automation at scale, in 2026? A list comes back with Bitsight first. She asks Gemini the same thing and gets ServiceNow first. In ChatGPT it is Whistic. OneTrust is on all three lists, and it is never the name she reads first.
That is the shape of the shortlist now. The AI answer is built before a vendor hears about the deal, so we wanted to measure what the engines put in it for one category, at a scale where the pattern is the finding rather than the anecdote.
Key Takeaways
- OneTrust recorded 205,000 mentions and was the first-mention vendor in no engine. Bitsight recorded 161,000 and was the first-mention vendor in three.
- Nine of the 72 brand strings recorded were named by all six engines. The five leading brands took 54.1% of all mentions.
- The engines spread OneTrust across nine product entries. At product level, "Bitsight" at 146,000 and "UpGuard" at 134,000 both outrank "OneTrust" at 127,000.
- Mean cited-domain overlap between engines was 0.19 as a Jaccard coefficient, where 0 is disjoint and 1 is identical. The only pairs above 0.22 were engines run by the same parent.
- 52.2% of all cited pages sit on a vendor's own site, a majority in ChatGPT and Perplexity and a minority in the other four.
- Only 0.2% of cited pages were dead.
- OneTrust led all five markets; only the second and third positions moved.
How We Ran the Study
We issued 10,000 enterprise buyer-intent queries about third-party risk management, vendor risk monitoring and questionnaire automation to six AI engines: ChatGPT, Microsoft Copilot, Gemini, Google AI Mode, Google AI Overview and Perplexity. Every query ran in five markets (United States, Canada, Germany, India, Australia), giving 50,000 responses per engine and 300,000 in total, collected in August 2026.
For each response we recorded its length, every cited URL, the type of site it sits on and whether it still resolved, every brand named, the order in which brands were named, and which brand the engine put first. The corpus held 1,551,000 cited sources, 72 brand strings, and 127 distinct product entries after plan, edition and category-noun spellings of one product were merged.
The engines are commercial services with no pinned model versions, and the query set is purposive rather than sampled, so we report descriptive figures only and claim no statistical significance. The full method, the per-engine tables and the validity limits are in the complete benchmark report. One disclosure: GrackerAI sells AI search visibility measurement for the category this study covers. The study measured how the engines describe vendors, not the vendors' products, and no vendor paid for or saw any part of it.
The Most-Mentioned Vendor Is Not the One Named First
OneTrust recorded 205,000 mentions across the study, ahead of UpGuard at 165,000 and Bitsight at 161,000. It was also the most-mentioned brand inside three individual engines, ChatGPT, Gemini and Google AI Mode, and tied for first in Microsoft Copilot.
It was the first-mention vendor in none of them.
| AI engine | First-mention vendor | Its mean position | OneTrust's mean position |
|---|---|---|---|
| ChatGPT | Whistic | 1.9 | 3.2 |
| Microsoft Copilot | Bitsight | 3.3 | 3.2 |
| Gemini | ServiceNow | 4.8 | 3.6 |
| Google AI Mode | UpGuard | 1.7 | 3.4 |
| Google AI Overview | Bitsight | 2.7 | 3.3 |
| Perplexity | Bitsight | 3.3 | 2.8 |
Mean position counts named vendors from one; lower is earlier. n = 50,000 responses per engine. Source: GrackerAI AI Search Visibility Benchmark Series, August 2026.
Bitsight held the opening position in Microsoft Copilot, Google AI Overview and Perplexity. Whistic, ServiceNow and UpGuard took it in one engine each. OneTrust's mean ordinal position, the place in the list where an engine names it, sat between 2.8 and 3.6 in every engine: on average the third or fourth name.
Whistic makes the point from the other direction. In ChatGPT it recorded 20,000 mentions, fewer than half of OneTrust's 43,000 in the same engine, and it opened the answer with a mean position of 1.9. A vendor named half as often can still be the one the buyer reads first. Gemini shows the opposite split: ServiceNow opens its answers most often, yet averages position 4.8 there, which fits an engine that names a vendor first in some responses and near the end in others.
Our finding: Mention volume, first-mention frequency and mean position are three separate quantities. In this category the vendor that leads on the first leads on neither of the other two: UpGuard and Bitsight each sat earlier than OneTrust on average in four of the six engines.
We saw the same separation in attack surface management, where the most-mentioned vendor opened three engines and the runner-up was still read earlier on average in four, in a study of the same six engines across four markets rather than five. Two categories, same protocol, same split. If your visibility dashboard reports one number per vendor, it is hiding two of the three things that matter.
Nine Vendors Every Engine Names
The core of this category is settled and it is wide. Nine of the 72 brand strings recorded were named by all six engines: OneTrust, UpGuard, Bitsight, SecurityScorecard, ProcessUnity, Panorays, ServiceNow, Vanta and Riskonnect. Eight more were named by five.
The five leading brands took 54.1% of all brand mentions. Below ProcessUnity in fifth place at 132,000 the counts fall away: Panorays 104,000, ServiceNow 102,000, and no brand outside the seven most-mentioned exceeds 59,000. This is a broad leading group with a steep drop behind it, not a single leader.
The tail is where the engines part company. 38 of the 72 brand strings were named by exactly one engine, none of them above 10,000 mentions. Whistic, MetricStream, Drata and Aravo did not appear in Perplexity at all. Venminder was absent from ChatGPT and Gemini. Black Kite was absent from both Google surfaces. A brand in that tail is being recommended by some engines and is simply not present in others.
Concentration into a reused core is the recurring pattern in this series. Our analysis of why AI engines pick the same three DSPM vendors found it too.
OneTrust Is Nine Products to the Engines
The brand ranking and the product ranking disagree, and the reason is naming.
The engines produced 127 distinct product entries across the study, even after we merged plan, edition and category-noun spellings of one product. Counted by product entry, the most-mentioned is the bare name "Bitsight" at 146,000, then "UpGuard" at 134,000. "OneTrust" is third at 127,000. The brand that leads on total mentions drops to third the moment you count product entries, because the engines wrote OneTrust's products nine different ways: "OneTrust Third-Party Risk Management", "OneTrust Vendor Risk Management", "OneTrust Third-Party Management", "OneTrust Vendorpedia" and five more.
ServiceNow is the next case, with eight separate entries for what a buyer would treat as one or two products. Bitsight and UpGuard were mostly named by their bare brand, which is why they lead the product table.
Our finding: 81 of the 127 product entries were named by exactly one engine, and 61 of them recorded exactly 1,000 mentions. The tail is mostly single-engine: a product that one engine names and the other five do not. Microsoft Copilot alone accounts for 28 of those entries.
Any visibility tool that counts exact product strings will show OneTrust as one 127,000-mention entry plus eight fragments, and Bitsight as one 146,000-mention entry plus five that barely register. That is a measurement artifact, and it is one the vendor can remove. Publish one canonical product name and use it everywhere the engines are likely to read.
Same Shortlist, Different Web
The engines agree on who is in the category. They do not agree on where to read about it.
We measured overlap between each pair of engines' cited domains with a Jaccard coefficient, where 1 means identical source sets and 0 means none shared. The mean across all 15 engine pairs was 0.19. The highest value was 0.40, between Google AI Mode and Google AI Overview, and the next two highest, 0.30 and 0.28, both involved Gemini with one of those two. All three top values sit inside the same parent company. No pair from different parents exceeded 0.22.
Microsoft Copilot was the most isolated engine, the lowest-overlap partner for four of the other five, with values between 0.09 and 0.15. Its most-cited domain was a statistics aggregator that appeared in no other engine's top three sources. ChatGPT's most-cited domain was a questionnaire-automation vendor's own site, Gemini's was the site of a security vendor outside the leading group, Google AI Mode's was an analyst firm, and Google AI Overview's and Perplexity's were two different leading vendors' own sites. Six engines, six different top sources, and no engine's most-cited domain was the most-cited domain of any other.
What the engines do share is a class of source. 52.2% of the 1,551,000 cited pages sit on a domain belonging to a vendor named in the answer. But that is a majority only in ChatGPT, at 72.3%, and Perplexity, at 54.5%. Gemini stood at 42.0%, Google AI Overview at 41.0%, Microsoft Copilot at 39.9% and Google AI Mode at 36.5%, and for those four the largest class was the residual one, pages outside every type we track. Analyst and review sites carried 8.6% of the corpus.
How each engine builds that source list is a question about retrieval rather than about vendors, and we take it apart in how the major AI engines choose which sources to cite.
The consequence for a vendor is direct. A citation earned on a domain that ChatGPT reads is not evidence of anything in Microsoft Copilot. Six engines need six measurements.
The Sources Are Almost All Still There
Of the 1,551,000 URLs the engines attached to their answers, 3,290 did not resolve when we tested them. That is 0.2% of the evidence base.
Four engines recorded no dead links at all: Microsoft Copilot, Gemini, Google AI Overview and Perplexity. Google AI Mode stood at 0.6% and ChatGPT at 0.4%. ChatGPT also cited the most sources, 567,000 or 36.6% of the corpus, so it accounts for 69.0% of the dead links on its own.
The definition matters. Many vendor sites answer an automated request with a 403 because the page sits behind a bot wall. The page exists; the crawler was turned away. Count those as dead and the rate balloons, which is what the first edition of this study did. We now count a page as dead only when it returns not-found, gone or a server error, or its host cannot be reached after a retry. On that definition, the pages these engines lean on are almost all there.
No engine cited its own parent's properties at a measurable rate, and no engine refused a single query. For a vendor, link decay is not the lever in this category. Working out which of your own URLs each engine cites is still a useful per-engine tracking workflow, but the fix at the end of it is rarely a redirect.
Five Markets, One Leader
We expected the shortlist to move between markets, because third-party risk obligations genuinely differ between Germany, Australia and the United States. It did not.
| Market | First | Second | Third |
|---|---|---|---|
| United States | OneTrust | UpGuard | Bitsight |
| Canada | OneTrust | Bitsight | UpGuard |
| Germany | OneTrust | Bitsight | UpGuard |
| India | OneTrust | Bitsight | UpGuard |
| Australia | OneTrust | UpGuard | SecurityScorecard |
Brands ranked by mentions within each market; n = 60,000 responses per market. Source: GrackerAI AI Search Visibility Benchmark Series, August 2026.
OneTrust led every market. UpGuard was second in the United States and Australia, Bitsight in the other three, and the third position rotated among the same group. 27 of the 127 product entries were recorded in all five markets, and every one of the ten most-mentioned entries was among them. The engines draw the same list everywhere and vary only the order behind the leader.
Our network security analysis found recommendations diverging by region, across seven engines and ten markets, so this may be a category where the engines reorder rather than a category where they localize. For a vendor the reading is the same either way. If you are absent from the shortlist in one of these five markets, you are absent in all of them. A localized landing page changes nothing about that.
Where the Engines Argue: Questionnaire Automation
The engines disagreed on one requirement. Asked how to cut questionnaire workload, ChatGPT returned AI-assisted evidence extraction in the form Whistic offers. Gemini more often returned native workflow orchestration inside ServiceNow. Asked which platform suits a program onboarding more than 200 vendors a year, ChatGPT most often named Whistic or ProcessUnity first, while Google AI Overview led with UpGuard or Bitsight, on the strength of combining security ratings with questionnaire workflows. That is the same split as the first-mention table: Whistic opens ChatGPT, Bitsight opens Google AI Overview.
The disagreement is about a category boundary. Dedicated questionnaire-and-evidence platforms on one side, ratings-led platforms with a questionnaire module on the other, and each engine placing the buyer's question on a different side of the line.
Six Engines, Six Shapes of Answer
The engines also answered in different shapes. Mean response length ran from 211.0 words in Google AI Overview to 520.0 in ChatGPT. Microsoft Copilot anchored 67% of its responses to an explicit date, more than any other engine, while Gemini anchored none. Four of the six engines cut off before finishing at some rate, from 2% in Google AI Mode up to 91% in ChatGPT, whose answers were the longest. That figure comes from a terminal-character test, which cannot separate a genuine cut-off from a response that simply ends without punctuation, so read the 91% as an upper bound. If truncation removes vendors, it removes the ones named last.
What a Third-Party Risk Vendor Should Do
Work out which of three problems you have. Outside the nine-brand core, you have an inclusion problem, and ordering does not apply yet. Inside it, you may have an ordering problem, and OneTrust shows that the most-mentioned vendor can have one. Track mentions, first-mention frequency and mean position separately; the components of an AI share of voice score are exactly those three.
Pick one product name and never vary it. Nine OneTrust entries and eight ServiceNow entries are splitting those vendors' own share of voice. Use the canonical string in documentation, pricing and analyst material, so the engines have nothing else to copy.
Take a position on questionnaire automation. It is the one requirement the engines argue about, and a vendor with a clear statement of AI-assisted evidence handling, automated questionnaire completion and shared vendor profiles is giving the engines something to quote. Structuring that kind of content so engines can extract it is the subject of our GRC content strategy for AI search.
Expect your own site to carry about half of the evidence. 52.2% of citations sit on vendor sites, and for four of the six engines the largest class is pages outside every type we track. Documentation, product and integration pages are what ChatGPT and Perplexity read; the other four read a web you do not control, so analyst coverage and third-party comparisons matter more there.
Measure six engines, not one. With a mean source overlap of 0.19, a single-engine reading tells you about that engine. If you are choosing instrumentation for a GRC or risk product, we compared the GEO tools built for GRC and compliance vendors.
Stop budgeting for link decay here. 0.2% of cited URLs were dead, and four engines recorded none. The inclusion problem is where the effort belongs.
Frequently Asked Questions
Which third-party risk management vendor do AI engines mention most?
OneTrust, with 205,000 mentions across 300,000 responses, ahead of UpGuard at 165,000 and Bitsight at 161,000. OneTrust was not the first vendor named in any of the six engines tested; Bitsight was, in three of them.
How many AI responses were analyzed for this third-party risk study?
300,000 responses, from 10,000 buyer-intent queries issued to six AI engines across five markets in August 2026. The responses contained 1,551,000 cited sources and 127 distinct product entries.
Do ChatGPT, Gemini and Copilot recommend the same third-party risk platforms?
Largely yes on the shortlist: nine of the 72 brand strings recorded were named by all six engines. They differ on who comes first, with Whistic opening ChatGPT, ServiceNow opening Gemini and Bitsight opening Microsoft Copilot, and they cite largely different sources, with a mean cited-domain overlap of 0.19.
What share of the sources AI engines cite for TPRM software no longer work?
0.2% of the 1,551,000 cited URLs did not resolve when tested. Four engines recorded no dead links, and no engine exceeded 0.6%.
Do AI recommendations for third-party risk tools change by country?
Not the leader. OneTrust led in all five markets. UpGuard was second in the United States and Australia and Bitsight in Canada, Germany and India, and all ten most-mentioned product entries appeared in all five markets.
Three Numbers, Three Different Leaders
Three numbers describe a vendor's standing in an AI answer, and this category shows how far apart they can sit. OneTrust leads on mentions, holds no first-mention position, and is on average the third or fourth name in every engine. Bitsight is third on mentions and first in three engines. Whistic is ninth on mentions and first in the engine with the longest answers. Nine brands are named by every engine, dozens are not, and the engines producing those answers agreed on the names while sharing roughly a fifth of their cited domains.
If you sell into this category, the question is no longer whether the engines know your name. For nine vendors they do. The question is what they do with it, engine by engine, and whether they are even spelling your product the same way twice.
The per-engine tables, the full product list and the validity limits are in the complete benchmark report.