Cognatum

Platform / Standards

The ISO 30401 crosswalk.

ISO 30401 is the management system standard for knowledge management. Below maps each step of the loop to the standard.

  1. 01

    Capture

    Ingest from every source.

  2. 02

    Structure

    Normalize the format.

  3. 03

    Clean

    Update, deduplicate, reconcile, archive.

  4. 04

    Enrich

    Add context and tags.

  5. 05

    Improve

    Refine clarity, usability.

  6. 06

    Approve

    Human sign-off, audited.

    A person handles this step

  7. 07

    Integrate/Deploy

    Push live everywhere.

  8. 08

    Reuse

    Serve people and AI.

The standard

What ISO 30401 is.

ISO 30401:2018 is a management system standard for knowledge management, published by ISO in November 2018 (https://www.iso.org/standard/68683.html). It sets out what an organization must do to run one: set it up, operate it, keep it, review it, improve it.

It uses the same structure as ISO 9001 for quality and ISO 27001 for information security. If your organization has been through either audit, the shape of this one is already familiar.

An accredited body can audit an organization against the standard and issue a certificate. What gets certified is always the organization and its management system. Never a piece of software.

Why this page

What your reviewer asks.

An AI system does not go live until a review board signs off on it.

Regulated enterprises are deploying AI assistants and agents they cannot prove are answering correctly, and their AI initiatives are stalling at governance review because of it.

The standard gives your governance team a recognized way to ask what it is already asking: is the knowledge this AI answers from under control?

“I do not need the AI to be clever. I need to know who approved what it just said.”

Head of AI Governance

ISO 30401:2018 is a certifiable management system standard for knowledge management, in the same family as ISO 9001 and ISO 27001. Cognatum is designed to operationalize its requirements and to supply evidence toward a customer pursuing conformity.

app.example-cognatum.internal
Ask Approver D. Whitfield
Related Knowledge Approved knowledge related to your question was found, but no single item was a confident direct match, review the cited sources before relying on this answer.
Retrieval strength Show breakdown
47%

Based on similarity of matched sources, not a correctness guarantee

Mean of 10 retrieved source scores

  • 75%
  • 60%
  • 61%
  • 56%
  • 52%
  • 35%
  • 32%
  • 41%
  • 35%
  • 24%

The crosswalk

Clause by clause, seven ways.

Each step of the loop against the clause it operationalizes, and the record it leaves. That record is provenance: who approved an entry, when, from what source, at which version.

The answer, as served

Six years, the first two in an easily accessible place, on non-rewriteable, non-erasable media.

Asked: Which retention period applies to client trade communications?

names

The entry and version it came from

Version v7, in force

v6 and v5 superseded and retained

names

The source that version derives from

Records Retention Policy 4.2

What version v7 was drafted from

names

The decision that put it in force

Approved by M. Alvarez, Compliance

2026-06-18 · version v7, against Records Retention Policy 4.2

APPROVED
Clause What it asks The step The record
4.4.2(a)That new knowledge is acquired systematically, not when someone remembers to submit itCaptureSource lineage on every entry: which system it came from, and when
4.4.3(b), (c)That knowledge is codified in a consistent form, and classified so related knowledge is found togetherStructure, EnrichOne schema and a working taxonomy. Where entries on an obligation live is a query, not a dig
4.4.2(d)That outdated or invalid knowledge is deleted, curated, archived or updatedCleanA change history: what changed, which duplicates merged, which contradictions resolved, what was archived
10.2Continual improvement of the system's suitability and effectivenessImproveVersion histories tied to usage, not to a calendar reminder
5.3, 7.5.2, 7.5.3That roles and authorities are assigned by name, and documented information is reviewed, approved, version controlled and retainedApproveWho approved this, in what role, on what date, at what version, from what source
4.4.2(b)That current knowledge is applied inside the flow of workIntegrate, DeployDeployment state per entry per channel: where it was in force, and when
4.4.3(d)That knowledge is searched for, taken in, and put into practiceReuseReuse records: what is consumed, by whom, by what, and how that shapes the next revision

Two clauses are worth a note. 4.4.2(d) is the one organizations struggle hardest to evidence, because the work it describes was never anybody's job. Clean is a near-verbatim match for it. And 4.4.3(d) asks whether the system is actually used. A machine internalizes nothing, so for AI the intent is met only if what it reads from is the governed set.

The enablers

What the standard expects.

Clause 4.4.4 names the enablers a knowledge management system depends on: human capital, processes, technology and infrastructure, and governance. The standard expects an organization to manage all four. Cognatum supplies some directly and structures the rest, and the honest split matters.

  • Human capital. The people who hold the knowledge, and the named owners who approve it.
  • Processes. The loop itself: capture, clean, enrich, improve, approve, deploy, reuse.
  • Technology and infrastructure. Where the entries live, and what may connect to them.
  • Governance. Who decides, on what authority, and what record that decision leaves.

Beyond ISO 30401

Two other frameworks.

Two other frameworks turn up in governance reviews of enterprise AI, and the same machinery produces evidence for both.

Regulation (EU) 2024/1689

The EU AI Act

Regulation (EU) 2024/1689 (https://eur-lex.europa.eu/eli/reg/2024/1689/oj). Its transparency rules and enforcement regime took effect on 2 August 2026. Obligations for high-risk systems come later: 2 December 2027 for standalone systems in Annex III, 2 August 2028 for AI built into products already regulated under Annex I, set by Regulation (EU) 2026/1744 (https://eur-lex.europa.eu/eli/reg/2026/1744/oj).

Where a system answers from your own knowledge, its requirements for data governance, record-keeping and human oversight reach the knowledge itself. Whether a given system is high-risk is a legal call you make with your own counsel.

Voluntary framework

NIST AI RMF

Voluntary, published by NIST (https://www.nist.gov/itl/ai-risk-management-framework), built around govern, map, measure and manage, and increasingly written into procurement questionnaires and vendor AI audits. When a review built on it asks how you govern the knowledge your AI draws on, the loop's records answer it.

Which retention period applies to client trade communications? Ask
Approved answer APPROVED

Six years, the first two in an easily accessible place, on non-rewriteable, non-erasable media. Records Retention Policy 4.2 v7

Approved by M. Alvarez, Compliance 2026-06-18

The guardrail

Standards assess organizations.

No software can be certified to ISO 30401, and no purchase makes an organization compliant with the EU AI Act. Certification assesses an organization and its management system. Cognatum operationalizes the standard's requirements, is designed to align with its structure, and supports a customer pursuing conformity.

If you hear stronger verbs than those, from us or from anyone, ask what exactly was assessed, and of whom.

Common questions

What reviewers ask.

Is Cognatum ISO 30401 certified?

No, and no software can be. ISO 30401 certification assesses an organization and its knowledge management system, not a product. Cognatum operationalizes the standard's lifecycle requirements, is designed to align with its structure, and supports a customer pursuing conformity. The crosswalk on this page shows the clause-level mapping.

Does deploying Cognatum make an organization compliant with ISO 30401 or the EU AI Act?

No. ISO 30401 requires organizational commitments no software can carry: leadership (clause 5.1), a knowledge management policy (clause 5.2), internal audit (clause 9.2), and management review (clause 9.3). The EU AI Act governs organizations and the AI systems they place on the market or put into service. Cognatum supplies process, technology, and an evidence trail toward the customer's obligations.

What evidence does Cognatum produce for an auditor or a governance review?

Per entry: the source it was captured from, its change history through cleaning and improvement, the named approver and their role, the approval timestamp, the version identifier, and its deployment state per channel. Across the library: which duplicates were merged, which contradictions were resolved, and what was archived. These records exist as a by-product of the loop running, not as a document prepared for the audit.

What applies under the EU AI Act, and from when?

Regulation (EU) 2024/1689 applies in stages. Its prohibitions and AI literacy provisions took effect in February 2025, its rules for general-purpose AI models in August 2025, and its transparency obligations and enforcement regime on 2 August 2026. The high-risk obligations come later, on the two dates Regulation (EU) 2026/1744 set in July 2026; Beyond ISO 30401 above gives them. Cognatum does not determine whether a system is high-risk and does not confer compliance.

Is Cognatum a KCS® product?

No. Cognatum is informed by industry practice in knowledge-centered service, including the work of the Consortium for Service Innovation, and it differs by design: AI runs the eight-step loop while humans concentrate at the Approve gate, knowledge is captured from every system where it is created rather than primarily from support interactions, and every live entry carries provenance for audit. For certification questions the relevant instrument is ISO 30401, which is why this page maps the loop to its clauses.

Knowledge governed. Intelligence everywhere.

See it on your own content, in your own environment.

KCS® is a service mark of the Consortium for Service Innovation.