Financial services
Segregation of duties and the unsigned answer
Segregation of duties separates recording, approving, custody and reconciling. A retrieval-based AI assistant quietly occupies three of those four stages and leaves the approving seat empty. Here is where the second signature belongs.
Cognatum Team · Sep 28, 2026 · 5 min read
Every regulated firm can name the person who approves a payment. It can name the different person who records it. That split is old, tested, and in places written into law. Now ask the same firm a second question. Who approved the answer its AI assistant gave a member of staff this morning? That one tends to land in silence.
Cognatum governs the entry
source · version · approver · permissions
What segregation of duties actually separates
Segregation of duties splits a task so that no one person runs it end to end. At least two people hold the parts. Cornell University's internal controls guidance lists the stages plainly. Recording covers initiate, submit and process. Approving covers pre-approval and post-entry review. Then comes custody, and then reconciling. The rule itself is one sentence. No one person should initiate, authorize, record, and reconcile a transaction.
One control, three rulebooks
The same control turns up wherever the stakes were high enough to write a rule. Sarbanes-Oxley makes management assess how well its internal control over financial reporting works. NIST SP 800-53 lists separation of duties as a control in its own right, AC-5. The Basel Committee revised its principles for sound operational risk management in 2021. Three domains, one shared instinct. The person who does the work should not be the only person who signs it off.
An AI answer travels the same stages
Now trace an AI assistant answering a question about your own policies. It searches the repositories. It reads several documents. It decides which one is current. It writes a sentence and hands it to a member of staff, who acts on it. Set that against the four stages. Something is missing.
Recording is covered. The index is a record of what the company is taken to know. Custody is covered too, since the documents still sit in the systems that own them. Reconciling is covered, and that is the uncomfortable part. Approving is not covered at all.
The reconciliation nobody assigned
When two documents disagree, something has to choose. In a retrieval pipeline that choice is made by the same part of the system that then writes the answer. It reconciles and records in one motion. Nothing separates the two steps, and no person sits in either seat. A reviewer looking at the same setup in a payment process would flag it in a morning.
A second model checking the first is not the fix. Two models from one vendor, trained the same way, reading the same index, are not two people. They are one pair of hands in two gloves.
Regulators have already written down this use case
FINRA's Regulatory Notice 24-09 is worth reading closely here. It names the scenario outright. Generative AI tools, it says, may let an associated person easily locate and query a member firm's policies and procedures or forms. Where a firm uses such tools inside its supervisory system, the notice adds, its policies and procedures should address technology governance, including model risk management, data privacy and integrity, reliability and accuracy of the AI model.
Read that list again. Every item on it governs the tool. None of them governs the policy document the tool just quoted. None asks who approved that document, or when, or whether a newer version has replaced it.
Where the law reached for a second person
Article 14 of the EU AI Act says high-risk systems must be built so that people can oversee them properly. Those people also have to stay alert to the pull of over-relying on AI output, which the Act calls automation bias. For one narrow category, remote biometric identification, Article 14(5) goes further. No action may follow an identification unless at least two people with the right competence, training and authority have checked it separately.
That clause covers biometrics, not your internal knowledge base. It is quoted here for the instinct behind it, not its reach. Where lawmakers judged a wrong output most costly, they reached for a second person.
Grounding is not approval
The common answer is that retrieval already solves this, because the answer rests on real documents. The first preregistered study of commercial legal research tools put that claim to the test. Products from LexisNexis and Thomson Reuters made things up between 17 and 33 percent of the time, despite vendor language about eliminating hallucinations. Grounding narrows the error rate. It does not put a signature on anything.
Put the second signature on the knowledge
Answers are written on demand, one per question, in the thousands. No firm is going to have a person read each one. So the approval has to move upstream, onto the knowledge the answers come from, before any answer exists.
That is how the Cognatum Knowledge Loop is built. There are eight steps, and AI runs seven of them. It finds the material, structures it, cleans it, enriches it, improves it, integrates it, and puts it back to work. Approve is the step it does not run. A named person decides what is true, reworks the wording where it needs work, and signs. The entry then carries that approver, the date, and the source it came from.
Conflicts get surfaced, not settled
Where two documents disagree, Cognatum shows both and points at the disagreement rather than picking a winner. Two divisions with two different policies is a real conflict to link, not an error to retire quietly. And when a source changes, whether a document, a table or a stored procedure, Cognatum tells the people whose approved entries now rest on stale material. It does not rewrite them on its own.
What an outside party can see
Cornell's guidance adds one more line that carries straight over. It should be possible to demonstrate segregation of duties to an outside party. An examiner cannot audit an intention. What an examiner can audit is a record: which person approved this piece of knowledge, on what date, from which source, and what that source said at the moment the answer was given.
Your company's knowledge isn't missing. It's unusable. Cognatum changes that. The eight steps and the one human gate are set out at cognatum.ai/the-loop.
Sources
- What Is Segregation of Duties (SoD)? (techtarget.com)
- Segregation of Duties, Division of Financial Services (cornell.edu)
- 15 U.S. Code 7262, Management assessment of internal controls (law.cornell.edu)
- Security and Privacy Controls for Information Systems and Organizations, SP 800-53 Rev. 5 (nvlpubs.nist.gov)
- Revisions to the Principles for the Sound Management of Operational Risk (bis.org)
- Regulatory Notice 24-09, Generative AI and Large Language Models (finra.org)
- EU AI Act Article 14, Human oversight (europa.eu)
- Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools (arxiv.org)
- The Cognatum Knowledge Loop (cognatum.ai)
Common questions
Questions this raises.
What is segregation of duties?
Segregation of duties is an internal control that splits a task so at least two people are responsible for its separate parts, and no single person controls a process from start to finish. The classic stages are recording, approving, custody and reconciling. It appears in financial reporting controls, in information security control catalogues such as NIST SP 800-53, and in banking operational risk guidance.
Does segregation of duties apply to AI-generated answers?
The control was written for transactions, so most policies do not mention answers at all. The exposure is real even so. A retrieval-based assistant records what the company is understood to know, reconciles documents that disagree, and delivers the result, while nobody occupies the approving seat. That is three of the four stages in one set of hands.
Can a second AI model provide the separation?
Not in any sense a controls reviewer would accept. Two models from the same vendor, trained on similar data and reading the same index, share the same blind spots. Separation of duties assumes independent judgment, and independence is the property that two components of one pipeline do not have.
Does retrieval or grounding fix the problem?
It reduces error without supplying authorization. The first preregistered evaluation of commercial legal research tools found that retrieval-based products from LexisNexis and Thomson Reuters hallucinated between 17 and 33 percent of the time, despite vendor claims about eliminating hallucinations. Grounding tells you where text came from, not who stood behind it.
How can knowledge be approved without reviewing every answer?
Move the approval upstream. Rather than reviewing answers after the fact, a named person approves the underlying knowledge entry once, and every answer drawn from it inherits that approver, the date and the source. In the Cognatum Knowledge Loop, AI runs seven of the eight steps and Approve is the one it does not, which is why a human sits in exactly one place instead of everywhere.