Resources / Blog
Governed knowledge, in writing.
Written for the people who have to defend an AI answer. Every post cites its primary sources, and lists them at the end.
The most recent piece.
Your acceptable use policy stops at the prompt
Ask most companies how they govern AI and you get the acceptable use policy. It is a conduct document: it binds the user and the tool, and it never asks whether the knowledge behind the answer was approved, current or contradicted.
AI governance ยท 6 min read
Read the piece →Everything else.
Everything else we have published.
Compliance officers, regulatory affairs leads, quality teams, and the engineers who build for them.
Life sciences
Inspection readiness never tests the answer
Inspection readiness programs test two things: whether you can produce the document, and whether your people can speak to it. Both assume someone reached for a record. Increasingly, they asked an assistant instead.
Read →Financial services
Delegation of authority stops before the answer
Your delegation of authority names who may approve what, up to which limit. No line of it covers the answer an AI assistant gives from your own documents, and accountability for that answer never moved anywhere.
Read →AI governance
AI observability can't see a stale source
A retrieval trace records which document your AI reached for and how relevant the retriever thought it was. It carries no approver, no version and no effective date, so a faithfully grounded answer from a withdrawn policy still scores well.
Read →Standards
CAPA closes on the document, not the answer
Corrective and preventive action assumes four things: a detected nonconformity, a way to contain it, a traceable cause, and a later effectiveness check. A wrong AI answer offers none of the four.
Read →Life sciences
GxP scope stops at the systems you classified
GxP compliance begins with a list of systems in scope. An AI answer is assembled across that list, from sources that were never on it, and the classification scheme never sees the answer at all.
Read →Financial services
Segregation of duties and the unsigned answer
Segregation of duties separates recording, approving, custody and reconciling. A retrieval-based AI assistant quietly occupies three of those four stages and leaves the approving seat empty. Here is where the second signature belongs.
Read →Standards
Every AI answer is an uncontrolled copy
Document control governs the document. An AI assistant answers from it and produces something with no revision number, no approver and no way back. That is an uncontrolled copy, made at machine speed.
Read →System of record
Legal hold preserves documents, not answers
A legal hold freezes the documents an AI assistant reads. It does not freeze the answers that assistant already gave, and it will not help you reproduce them.
Read →Financial services
Three lines of defense, no owner for the answer
The three lines model gives every risk an owner. Ask which line owns the knowledge an AI assistant answers from, and the question tends to go quiet.
Read →Life sciences
GAMP 5 validates the system, not the answer
GAMP 5 validates the computerized system. It was never written to govern the document an AI assistant retrieved, or the answer it assembled from that document. That gap sits outside every validation package.
Read →AI governance
Data stewardship stops at the data layer
Data stewards own tables, lineage and quality metrics. The policies, SOPs and memos your AI assistant actually answers from sit outside that remit, with no owner and no review date.
Read →System of record
Policy management ends at the policy
Policy lifecycles govern the document. They stop short of the sentence an employee is handed when they ask an assistant what the policy says, and that sentence is what people act on.
Read →System of record
Information silos aren't the problem
Every guide to information silos ends in the same instruction. Break them down, consolidate the tools, migrate everything into one place. That advice has been failing for twenty years, and location was never the real problem.
Read →AI governance
AI grounding stops where governance starts
Every grounding guide tells you to make sure the model answers from verified source material. Almost none of them say what makes a source verified, who approved it, or what happens when two grounded documents disagree.
Read →System of record
Why we built Cognatum
Cognatum did not start as a product. It started as an internal fix for thirty years of contracts that nobody could answer for. Here is what that exercise taught us, and what we built because of it.
Read →Life sciences
ALCOA principles don't cover your AI answers
Your batch records are attributable, legible, contemporaneous, original and accurate. The sentence your AI assistant wrote from them is probably none of those things. Here is how to close the gap.
Read →Standards
Change control ends where your AI answer begins
Every regulated company controls changes to its documents. Almost none control what happens to the answers already built on the old version. An AI assistant turns that gap into a daily problem.
Read →System of record
Institutional knowledge: capture is only half the job
Most institutional knowledge programs stop at capture. Writing an expert's method down does not say who approved it, when, or whether it still holds. Once an AI assistant reads it, that gap becomes the answer's problem.
Read →AI governance
Agentic AI governance covers the agent, not the answer
Every agentic AI governance framework on the first page of Google governs the same thing: what the agent is permitted to do. Almost none of them governs what the agent is acting on: who approved it, and whether it is still current. That is where the expensive failures live.
Read →AI governance
Shadow AI: a knowledge problem before a security problem
Every definition of shadow AI describes the same behavior and prescribes the same fix: find the unapproved tools and block them. That treats the supply of AI tools as the problem. The demand is what actually needs answering.
Read →Life sciences
21 CFR Part 11 and AI-generated answers: what an inspector will ask
An inspector who finds an AI assistant answering from controlled documents asks the questions Part 11 has always framed: who approved this, where is the audit trail, was it current. What a defensible answer trail looks like, mechanism by mechanism.
Read →Standards
ISO 30401 for AI governance: a clause-level walkthrough
ISO 30401:2018 is the certifiable management system standard for knowledge management. Its clauses map onto what a review board asks about AI: who approved this, when, and is it still current. A clause-by-clause walkthrough of what each requires and the evidence that satisfies it.
Read →Financial services
SEC 17a-4, FINRA supervision, and AI-generated answers
Neither SEC Rule 17a-4 nor FINRA Rule 3110 mentions AI. Both still apply to it. This piece shows where an AI answer creates records and supervision risk, and what an evidence trail looks like: who approved it, when, from what source, at which version, and how long it is kept.
Read →System of record
What is a knowledge management system of record?
It is the one place that holds the approved version itself, not a link to wherever the file happens to sit. This piece defines the term, shows how it differs from tools that only point at content, and says why AI raises the bar.
Read →AI governance
Why your AI initiative stalled at governance review
The mandate was real and the pilot worked, yet the deployment stalled the moment governance asked who approved what the assistant says. The objection is to the knowledge it reads, not the model, and it has a mechanical fix.
Read →Knowledge governed. Intelligence everywhere.
See it on your own content, in your own environment.