Cognatum

Resources / Blog

Governed knowledge, in writing.

Written for the people who have to defend an AI answer. Every post cites its primary sources, and lists them at the end.

Everything else.

Everything else we have published.

Compliance officers, regulatory affairs leads, quality teams, and the engineers who build for them.

Life sciences

Inspection readiness never tests the answer

Inspection readiness programs test two things: whether you can produce the document, and whether your people can speak to it. Both assume someone reached for a record. Increasingly, they asked an assistant instead.

Read →

Financial services

Delegation of authority stops before the answer

Your delegation of authority names who may approve what, up to which limit. No line of it covers the answer an AI assistant gives from your own documents, and accountability for that answer never moved anywhere.

Read →

AI governance

AI observability can't see a stale source

A retrieval trace records which document your AI reached for and how relevant the retriever thought it was. It carries no approver, no version and no effective date, so a faithfully grounded answer from a withdrawn policy still scores well.

Read →

Standards

CAPA closes on the document, not the answer

Corrective and preventive action assumes four things: a detected nonconformity, a way to contain it, a traceable cause, and a later effectiveness check. A wrong AI answer offers none of the four.

Read →

Life sciences

GxP scope stops at the systems you classified

GxP compliance begins with a list of systems in scope. An AI answer is assembled across that list, from sources that were never on it, and the classification scheme never sees the answer at all.

Read →

Financial services

Segregation of duties and the unsigned answer

Segregation of duties separates recording, approving, custody and reconciling. A retrieval-based AI assistant quietly occupies three of those four stages and leaves the approving seat empty. Here is where the second signature belongs.

Read →

Standards

Every AI answer is an uncontrolled copy

Document control governs the document. An AI assistant answers from it and produces something with no revision number, no approver and no way back. That is an uncontrolled copy, made at machine speed.

Read →

System of record

Legal hold preserves documents, not answers

A legal hold freezes the documents an AI assistant reads. It does not freeze the answers that assistant already gave, and it will not help you reproduce them.

Read →

Financial services

Three lines of defense, no owner for the answer

The three lines model gives every risk an owner. Ask which line owns the knowledge an AI assistant answers from, and the question tends to go quiet.

Read →

Life sciences

GAMP 5 validates the system, not the answer

GAMP 5 validates the computerized system. It was never written to govern the document an AI assistant retrieved, or the answer it assembled from that document. That gap sits outside every validation package.

Read →

AI governance

Data stewardship stops at the data layer

Data stewards own tables, lineage and quality metrics. The policies, SOPs and memos your AI assistant actually answers from sit outside that remit, with no owner and no review date.

Read →

System of record

Policy management ends at the policy

Policy lifecycles govern the document. They stop short of the sentence an employee is handed when they ask an assistant what the policy says, and that sentence is what people act on.

Read →

System of record

Information silos aren't the problem

Every guide to information silos ends in the same instruction. Break them down, consolidate the tools, migrate everything into one place. That advice has been failing for twenty years, and location was never the real problem.

Read →

AI governance

AI grounding stops where governance starts

Every grounding guide tells you to make sure the model answers from verified source material. Almost none of them say what makes a source verified, who approved it, or what happens when two grounded documents disagree.

Read →

System of record

Why we built Cognatum

Cognatum did not start as a product. It started as an internal fix for thirty years of contracts that nobody could answer for. Here is what that exercise taught us, and what we built because of it.

Read →

Life sciences

ALCOA principles don't cover your AI answers

Your batch records are attributable, legible, contemporaneous, original and accurate. The sentence your AI assistant wrote from them is probably none of those things. Here is how to close the gap.

Read →

Standards

Change control ends where your AI answer begins

Every regulated company controls changes to its documents. Almost none control what happens to the answers already built on the old version. An AI assistant turns that gap into a daily problem.

Read →

System of record

Institutional knowledge: capture is only half the job

Most institutional knowledge programs stop at capture. Writing an expert's method down does not say who approved it, when, or whether it still holds. Once an AI assistant reads it, that gap becomes the answer's problem.

Read →

AI governance

Agentic AI governance covers the agent, not the answer

Every agentic AI governance framework on the first page of Google governs the same thing: what the agent is permitted to do. Almost none of them governs what the agent is acting on: who approved it, and whether it is still current. That is where the expensive failures live.

Read →

AI governance

Shadow AI: a knowledge problem before a security problem

Every definition of shadow AI describes the same behavior and prescribes the same fix: find the unapproved tools and block them. That treats the supply of AI tools as the problem. The demand is what actually needs answering.

Read →

Life sciences

21 CFR Part 11 and AI-generated answers: what an inspector will ask

An inspector who finds an AI assistant answering from controlled documents asks the questions Part 11 has always framed: who approved this, where is the audit trail, was it current. What a defensible answer trail looks like, mechanism by mechanism.

Read →

Standards

ISO 30401 for AI governance: a clause-level walkthrough

ISO 30401:2018 is the certifiable management system standard for knowledge management. Its clauses map onto what a review board asks about AI: who approved this, when, and is it still current. A clause-by-clause walkthrough of what each requires and the evidence that satisfies it.

Read →

Financial services

SEC 17a-4, FINRA supervision, and AI-generated answers

Neither SEC Rule 17a-4 nor FINRA Rule 3110 mentions AI. Both still apply to it. This piece shows where an AI answer creates records and supervision risk, and what an evidence trail looks like: who approved it, when, from what source, at which version, and how long it is kept.

Read →

System of record

What is a knowledge management system of record?

It is the one place that holds the approved version itself, not a link to wherever the file happens to sit. This piece defines the term, shows how it differs from tools that only point at content, and says why AI raises the bar.

Read →

AI governance

Why your AI initiative stalled at governance review

The mandate was real and the pilot worked, yet the deployment stalled the moment governance asked who approved what the assistant says. The objection is to the knowledge it reads, not the model, and it has a mechanical fix.

Read →

Knowledge governed. Intelligence everywhere.

See it on your own content, in your own environment.