Organization
The Organization section provides a centralized space to manage organizational information, policies, and vendors. It supports governance workflows by allowing different roles to contribute based on their responsibilities, including policy management and vendor risk assessment.
Profile
Section titled “Profile”The Organization Profile captures key details about the organization and is managed primarily by the Governance Officer.
Other users can view this information but cannot modify it unless permitted.
Create and Update Profile
Section titled “Create and Update Profile”- Navigate to Organization → Profile
- Click Create Profile
- Provide:
- Organization Name
- Description
- Contact Details
- Relevant links (e.g., company website)

Once created, the Governance Officer can update the profile at any time by selecting Edit and maintaining current information.
Policies
Section titled “Policies”The Policies section allows organizations to manage internal governance policies in a structured and version-controlled manner.
A Policy Manager is responsible for creating and updating policies, while the Governance Officer reviews and approves them.
Create a Policy
Section titled “Create a Policy”- Navigate to Organization → Policies
- Click Add Policy
- Provide:
- Policy Name
- Category
- Visibility (Public or Private)
After creation, policy documents can be added as versions.
Manage Policy Versions
Section titled “Manage Policy Versions”Each policy can have multiple versions to track updates over time.
- Add a new version by selecting Add Policy Version
- Upload supporting documents (PDF, DOCX, Markdown)
- Provide version details

Once added, the policy version is submitted for review.
Policy Review Workflow
Section titled “Policy Review Workflow”- Submitted policies move to In Review status
- The Governance Officer can:
- Approve the policy
- Reject the policy
- Add comments or feedback

This ensures that all policies go through a formal approval process before being finalized.
Vendors
Section titled “Vendors”The Vendors section allows organizations to manage third-party vendors and perform AI-assisted Vendor Risk Assessments (VRA).
Create and Manage Vendors
Section titled “Create and Manage Vendors”- Navigate to Organization → Vendors
- Click Create
- Provide:
- Vendor name and details
- Contact information
- Associated systems
- Internal owner(s)

Once created, vendors are listed on the Vendors page, where users can:
- View vendor details
- Sort and filter by name, risk level, status, or creation date
- Update vendor information
Vendor Contracts
Section titled “Vendor Contracts”Each vendor can have associated contracts that serve as the basis for risk assessment.
- Open a vendor profile
- Add contracts using the Upload option
- View and manage uploaded documents
- Attach additional supporting evidence if needed

Vendor Risk Assessment (VRA)
Section titled “Vendor Risk Assessment (VRA)”Pacific AI provides AI-assisted Vendor Risk Assessment based on uploaded contracts.
To initiate an assessment:
-
Navigate to the Risk section within a vendor
-
Click Create Assessment
-
Select one or more assessment categories:
- Data Governance & Privacy (DGP)
- Generative AI & Agentic Systems (GAAS)
- Business Continuity & Ethics (BCE)
- Regulatory & Compliance (RC)
- Cybersecurity & Infrastructure (CSI)
- Model Performance, Safety, & Bias (MPSB)
Perform Assessment
Section titled “Perform Assessment”Users can complete assessments in two ways:
Manual Assessment
Section titled “Manual Assessment”- Click Review
- Answer questions for each category
- Confirm responses

AI-Assisted Assessment
Section titled “AI-Assisted Assessment”- Click Run AI
- The system generates responses based on uploaded contracts
- Review and adjust responses if needed
- Confirm final answers

Assessment Insights
Section titled “Assessment Insights”- Once at least three categories are completed, analytics become available
- Users can review overall vendor risk insights and assessment summaries

The Organization module ensures structured management of internal policies, vendor relationships, and associated risks, enabling better oversight and informed decision-making.