Cognatum

System of record

Institutional knowledge: capture is only half the job

Most institutional knowledge programs stop at capture. Writing an expert's method down does not say who approved it, when, or whether it still holds. Once an AI assistant reads it, that gap becomes the answer's problem.

Cognatum Team · Sep 13, 2026 · 5 min read

Institutional knowledge is the working memory of a company. It is the reason a system was built the way it was, the exception that applies to one client, the step that never made it into the manual. Most of it sits with people. Some of it is written down. Very little of it carries a name and a date.

Served to one approved entry
AI assistants & agents
Proposal tools
Internal search & chat
Customer portals
Compliance & audit

Cognatum governs the entry

source · version · approver · permissions

Every guide on the subject gives the same advice: capture it before the person leaves. That advice is sound, and it is incomplete. Capture is where the work starts.

What institutional knowledge is, and what it is not

Institutional knowledge is the mix of documented procedure and undocumented judgment a company actually runs on. Some of it lives in files. Some lives in habit. The line that matters is not written against unwritten. It is governed against ungoverned.

An ungoverned document is one nobody owns. No approver, no review date, no link back to the source it came from. It may well be correct. The point is that you cannot tell, and neither can anything reading it on your behalf.

The capture wave is real, and it has been measured

The numbers behind the current interest are not vague. APQC surveyed 1,000 organizations in a study sponsored by eGain and found that 92 percent do not consistently capture knowledge from soon to be retirees, and that 85 percent have not operationalized AI to automate knowledge management work. APQC also found that 58 percent of C suite respondents were very worried about the loss. See the survey summary.

Deloitte frames the same shift demographically. More than 30 million Americans will turn 65 within four years, and average job tenure has fallen from 4.6 years to 3.9 over the past decade. Read the analysis. Deep organizational memory is being drawn down faster than it is being rebuilt.

Capture is where most programs stop

A capture program produces artifacts. Interview transcripts. Process write ups. Recorded walkthroughs. A folder that did not exist last quarter, filling steadily.

None of that answers the questions a reviewer asks. Who signed off on this. Which version of the source did it come from. Has anything changed underneath it since. An artifact missing those fields is a record of what one person said once, and it ages without telling anyone.

This is the quiet failure mode of a successful capture push. The program hits its target, the documents exist, and the organization is now carrying a larger body of material that nobody has attested to.

Regulators have always asked more of written knowledge

This standard was not invented for AI. The MHRA's guidance on GxP data integrity expects records to be attributable, legible, contemporaneous, original and accurate, which is another way of saying that a document is worth only as much as the name, date and source attached to it. See the guidance.

Regulated industries have applied that test to procedures, batch records and training files for decades. Nothing about it softens when the reader is a model rather than a person.

What changes when an AI assistant reads it

An assistant does not weigh a document's credibility. It retrieves what matches the question and writes fluent prose around it. A superseded procedure and the current one look much alike to a retrieval system. Whichever it reaches first becomes the answer.

So the weakness in a capture only program does not stay contained in a folder. It gets restated, in confident language, to whoever asked, and now it is an answer your organization gave.

What the instruments actually require

Regulators are describing the same concern from the system side. The EU AI Act sets data governance expectations for high risk systems in Article 10 and requires automatic logging across a system's lifetime in Article 12. Article 10 and Article 12 are both short and worth reading in full.

NIST's Generative AI Profile goes further and names information integrity as a risk category in its own right, distinct from privacy or security. See the profile.

A note on what software can and cannot claim

These instruments describe what an organization has to be able to demonstrate. Software can align with them and supply the evidence that supports a demonstration. No product, this one included, confers compliance on the company using it, and any vendor saying otherwise is selling you a sentence rather than a control.

What usable institutional knowledge carries

The difference between a captured document and a usable one is a small set of fields, applied consistently.

  • An approver. A named person who signed off, not a team inbox or a shared drive.
  • A date. When it was approved, and when it next falls due for review.
  • A source. The document, system or conversation the entry was drawn from.
  • A version. Which one the answer drew on at the moment the answer was given.
  • A signal when that source moves, so a person can decide what the change means.

The last one deserves care. A governed knowledge base should tell you when something it depends on has changed. It should not quietly rewrite itself and present the result as current. A system that edits without telling you has removed the one thing the approver was there to provide, which is a person standing behind the wording.

That is the shape of the Cognatum Knowledge Loop, where AI does the maintenance work across eight steps and a named human still approves what goes out.

Where to start

Start narrow. Deloitte's recommendation is to resist documenting everything and instead find the areas that are both mission critical and poorly documented, then work those first. Their five step process is a reasonable map.

Apply the fields above to that narrow set before widening it. A small governed knowledge base is more useful to an AI assistant than a large ungoverned one, because the assistant can say where the answer came from and who stands behind it.

Capturing institutional knowledge keeps it from walking out the door. Governing it is what makes it answer for itself. Knowledge governed. Intelligence everywhere.

Common questions

Questions this raises.

What is the difference between institutional knowledge and tribal knowledge?

They overlap heavily and are often used interchangeably. Tribal knowledge usually emphasizes the undocumented, informally shared part: what a team knows without writing it down. Institutional knowledge is the broader term, covering both the undocumented judgment and the documented procedure a company runs on. For governance purposes the more useful split is not documented against undocumented, but governed against ungoverned: whether an entry carries an approver, a date and a source.

Is capturing knowledge from retiring employees enough?

It is necessary and it is not sufficient. Capture produces documents. It does not establish who approved them, when they were last reviewed, or which source they came from. Without those fields the organization has traded one risk, knowledge leaving with a person, for another, an expanding body of material nobody has attested to.

How does an AI assistant make ungoverned knowledge riskier?

A retrieval system cannot tell a superseded procedure from a current one if neither carries a status, an approval or a date. It surfaces whatever matches the question and renders it in confident prose. The result is that a stale document stops being a file sitting in a folder and becomes an answer your organization has given to someone who asked.

Does a governed knowledge base keep itself up to date automatically?

It should not. Change a source and every entry that depends on it is flagged and routed for re-check, so a person can decide what the change means. It does not silently rewrite approved wording, and no knowledge base should be described as always current. Approval is a human step by design.

What evidence do reviewers usually ask for?

Consistently the same four things: who approved this, when, from what source, and at which version. Instruments like the EU AI Act's record keeping requirements and NIST's treatment of information integrity describe what must be demonstrable rather than prescribing a product. The practical answer is a knowledge layer where those fields exist on every entry rather than being reconstructed after the fact.

Knowledge governed. Intelligence everywhere.

See it on your own content, in your own environment.