System of record
Information silos aren't the problem
Every guide to information silos ends in the same instruction. Break them down, consolidate the tools, migrate everything into one place. That advice has been failing for twenty years, and location was never the real problem.
Cognatum Team · Sep 17, 2026 · 5 min read
Search for advice on information silos and the answer arrives before the question finishes. Break them down. Consolidate the tools. Move everything into one shared space and get the departments talking. It is the most consistent recommendation in enterprise software, and organizations have been acting on it, expensively, for about twenty years.
Cognatum governs the entry
source · version · approver · permissions
The silos are still there. That is worth taking seriously, because a fix that never lands usually means the problem was described wrong.
What the standard advice gets right
The definition is not in dispute. Wikipedia describes an information silo as an insular management system incapable of reciprocal operation with related systems, which is precise and unflattering. Read the entry.
TechTarget's account is the practical one. A data silo is a repository controlled by one department and closed off from the rest of the organization, and the costs are real. Duplicated effort, decisions made on partial information, and people spending the day hunting for something the company already owns. Read the definition.
Where it stops being useful
The prescription that follows is almost always consolidation. Retire the departmental tools, pick one platform, migrate the content, enforce it. Anyone who has run that project knows how it ends. The migration takes three quarters, half the content arrives stripped of its context, and the teams who lost their system quietly keep the files they actually need somewhere else.
There is a line we hear in nearly every demo. My information lives in fifteen different systems and I need fifteen different logins, and the answer is not a sixteenth login.
Regulators did not ask banks to merge their systems
Financial services worked through this in public. The Basel Committee recorded that the crisis beginning in 2007 revealed that many banks, including global systemically important banks, were unable to aggregate risk exposures and identify concentrations fully, quickly and accurately. See the principles.
The remedy was not an instruction to collapse every system into one. It was a requirement to build the capability to aggregate across them, reliably enough to answer under pressure. The architecture was allowed to stay plural. The answer had to be dependable.
Retrieval already crosses the silo
Whatever else has changed, reach is no longer the hard part. A retrieval layer will read a departmental Box folder, a SharePoint site, a Slack channel and a Snowflake table in the same query, then produce one fluent paragraph from all four.
So the silo stopped being a wall and became something harder to see. The material is blended at the moment of the answer, and nothing in that blend records where each piece came from or whether anyone stood behind it.
Three questions the blend cannot answer
- Who approved this passage, by name, for this use?
- Which version of it was in force when the answer was given?
- If two systems disagreed, what happened to the one that lost?
The third should worry a regulated firm most. A survey of knowledge conflicts in large language models names the enterprise case directly as inter context conflict, where two retrieved passages contradict each other and the system settles it without saying so. Read the survey.
Silos make that likelier, not because departments are careless, but because the same policy gets restated in four places and then drifts apart. Showing both passages and routing the disagreement to a person is the honest behavior.
What the instruments assume
The EU AI Act requires high risk systems to allow the automatic recording of events over the lifetime of the system, which presumes there is a record worth keeping. Read Article 12.
NIST's Generative AI Profile treats information integrity as a risk category in its own right, separate from security and privacy. See the profile.
ISO/IEC 42001 applies management system discipline to artificial intelligence, including the evidence an organization is expected to keep. See the standard.
What software can and cannot claim
These instruments describe what an organization has to be able to demonstrate. Software can align with them and produce the evidence a demonstration rests on. No tool confers compliance or certification on the company running it, whatever the brochure says.
Leave the silos where they are
Departmental repositories exist for good reasons. Legal keeps its own folders because legal has its own retention rules and its own reviewers, and the same holds for clinical, for risk, and for whoever maintains pricing. That split is not a defect to be engineered away.
What is missing is anything sitting above them. One layer that reads across every repository, records who approved each entry and when, keeps the version that was live when an answer was given, and serves that to people and to AI systems alike.
Notification, not quiet correction
When a source changes, and that includes a table, a query or a data mart rather than only a document, every entry depending on it is flagged and routed to a named person, who decides what the change means before approving it again. Nothing rewrites itself, and no knowledge base should be sold as always current.
The work consolidation keeps postponing
An APQC survey of 1,000 professionals, sponsored by eGain and published in October 2025, found that 92 percent of organizations do not consistently capture knowledge from soon to be retirees and 85 percent have not operationalized AI to automate knowledge management processes. Read the findings.
Those numbers describe capacity spent in the wrong place. Another consolidation program will not move them, because the constraint was never where the files happen to sit.
Governed where it lives
Breaking down silos treats location as the problem. Governing across them treats accountability as the problem, which is the one a reviewer, an auditor or a customer is actually asking about. The Cognatum Knowledge Loop is built that way, with a named human at the approval gate rather than a model deciding what is true. Your company's knowledge isn't missing. It's unusable. Cognatum changes that.
Sources
- Information silo (wikipedia.org)
- What are data silos and what problems do they cause? (techtarget.com)
- Principles for effective risk data aggregation and risk reporting, Basel Committee (bis.org)
- Knowledge Conflicts for LLMs: A Survey (arxiv.org)
- EU AI Act Article 12: Record-Keeping (artificialintelligenceact.eu)
- Artificial Intelligence Risk Management Framework: Generative AI Profile (nist.gov)
- ISO/IEC 42001:2023 Artificial intelligence, Management system (iso.org)
- APQC study on the Great Retirement, knowledge loss and AI (apqc.org)
- The Cognatum Knowledge Loop (cognatum.ai)
Common questions
Questions this raises.
What is an information silo?
An information silo is a system or repository whose contents are held by one team or department and cannot be reached or used easily by the rest of the organization. Wikipedia describes it as an insular management system incapable of reciprocal operation with related systems. In practice it looks like a departmental drive, a tool one team bought, or a folder only three people know the contents of.
Are information silos always bad?
No. A departmental repository usually exists because that department has its own retention rules, its own reviewers and its own working pace. The split itself is normal. The problem is that nothing sits above those repositories to record who approved each item, which version is current, and what happens to answers drawn from them when the source changes.
How do you fix information silos without migrating everything?
By leaving the content where it lives and adding a governed layer across it. The layer reads from each repository, carries a named approver, a date and a source on every entry, and keeps a point in time record of which version an answer used. Nobody is asked to abandon the system their team already works in, and no migration project is required.
Do information silos still matter if our AI assistant can search everything?
They matter differently. Retrieval crosses repositories easily, so reach is largely solved. What retrieval does not carry across is provenance. Once four sources are blended into one fluent paragraph, the answer no longer shows which passage came from where, who approved it, or whether a second system said something different.
What should happen when two systems give contradictory answers?
The conflict should be surfaced rather than resolved quietly. Research on knowledge conflicts calls this inter context conflict, and the usual model behavior is to prefer whichever passage reads more confidently. The better handling is to present both, state where they disagree, and route the item to a person with the authority to decide which one governs.