Standards
The ISO 30401 crosswalk.
ISO 30401 is the management system standard for knowledge management. This page maps each step of the loop to the clause it operationalizes.
-
01
Capture
Ingest from every source.
-
02
Structure
Normalize the format.
-
03
Clean
Update, deduplicate, reconcile, archive.
-
04
Enrich
Add context and tags.
-
05
Improve
Refine clarity, usability.
-
06
Approve
Human sign-off, audited.
A person holds this step
-
07
Integrate/Deploy
Push live everywhere.
-
08
Reuse
Serve people and AI.
The standard
What ISO 30401 is.
ISO 30401:2018 is a management system standard. The International Organization for Standardization published it in November 2018 (https://www.iso.org/standard/68683.html). It sets out what an organization must do to run a knowledge management system: set one up, operate it, keep it, review it, and improve it.
It uses the same structure as ISO 9001 for quality and ISO 27001 for information security. If your organization has been through either audit, the shape of a 30401 audit will already be familiar.
What certifiable means, and what it does not
An accredited body can audit an organization against the standard and issue a certificate. What gets certified is always the organization and its management system. Never a piece of software. That distinction shapes every sentence on this page.
Clause 4.4 is the operational core. Clause 4.4.2 covers knowledge development: acquiring new knowledge, applying it, retaining it, and handling knowledge that is out of date or invalid. Clause 4.4.3 covers how knowledge moves, through interaction, representation, combination, and internalization. Clause 4.4.4 names the enablers the system rests on.
Why this page
What your reviewer asks.
An AI system does not go live until a review board signs it off.
Regulated enterprises are deploying AI assistants and agents they cannot prove are answering correctly, and their AI initiatives are stalling at governance review because of it.
The standard gives your governance team a recognized way to ask what it is already asking: is the knowledge this AI answers from under control? The crosswalk below maps each step of the loop to the clause it operationalizes.
One note on reading it. The clause texts belong to ISO and are sold by ISO. This page cites clause numbers and paraphrases what each one asks for. The published standard is the authority.
“I do not need the AI to be clever. I need to know who approved what it just said.”
The short definition
ISO 30401:2018 is a certifiable management system standard for knowledge management, in the same family as ISO 9001 and ISO 27001. Cognatum is designed to operationalize its requirements and to supply evidence toward a customer pursuing conformity.
The crosswalk
Clause by clause, seven ways.
Each step of the loop against the clause it operationalizes, and the evidence it leaves behind. The word for that record is provenance: who approved an entry, when, from what source, and at which version.
Clause 4.4.2(a)
Capture: acquiring new knowledge
Clause 4.4.2(a) requires an organization to show that it acquires new knowledge systematically: creation, discovery, lessons learned, and acquisition from outside. An auditor reading it looks for a mechanism, not for effort.
Capture is that mechanism. It ingests from the systems where knowledge is actually made: documents, shared drives, the chat threads where decisions land, resolved tickets, CRM records, and experts themselves. It runs continuously, rather than waiting for someone to remember to submit something.
The evidence: every entry carries a source lineage showing which system it came from and when. Acquisition stops being a claim and becomes a record an auditor can sample.
Clauses 4.4.3(b) and (c)
Structure and Enrich: representation and combination
Clause 4.4.3 covers how knowledge is conveyed and transformed. Subclause (b), representation, covers codifying it so it is documented, reachable, and usable in a consistent form. Subclause (c), combination, covers classifying, tagging and synthesizing, so related knowledge is found together instead of scattered.
Two steps carry this. Structure normalizes whatever arrives, a policy PDF, a ticket resolution, a decision buried in a thread, into one entry format. Enrich adds the tags and relationships that connect an entry to the products, policies and situations it applies to.
The evidence: one schema and a working taxonomy. Ask where the entries about a given obligation live and the answer is a query rather than a dig.
Clause 4.4.2(d)
Clean: outdated or invalid knowledge
Clause 4.4.2(d) requires the organization to handle outdated or invalid knowledge: deletion, curation, archiving, and updating. Of every clause in the standard this is the one organizations struggle hardest to evidence, because the work it describes was never anybody's job.
Clean is a near-verbatim match. Its four sub-steps, update, deduplicate, remove contradictions, archive, are the clause's requirements restated as continuous work the AI does. The standard asks for a practice. Most organizations can show a content review that happened once.
The evidence: a change history on every entry, showing what changed, which duplicates merged, which contradictions were resolved, and what was archived.
Clause 10.2
Improve: continual improvement
Clause 10.2 requires continual improvement of the suitability, adequacy, and effectiveness of the knowledge management system: a recurring activity, not a one-time implementation.
Improve, step five, refines the clarity and usability of entries based on how they actually perform in use. Because consumption signals flow back into the loop, improvement is driven by evidence of what readers and AI systems struggled with, not by a calendar reminder.
The evidence: version histories showing successive refinement tied to usage, which is exactly the record a clause built on the word continual is asking for.
Clauses 5.3, 7.5.2 to 7.5.3
Approve: roles, review, and control
Clause 5.3 requires top management to assign roles, responsibilities and authorities for the knowledge management system: someone must be answerable, by name. Clauses 7.5.2 and 7.5.3 govern documented information: review and approval on creation and update, then protection, distribution control, version control and retention.
Approve is the human gate in an otherwise AI-run loop, and it satisfies both at once. An entry goes live only when a named approver with assigned authority signs off, and the sign-off is timestamped, versioned and recorded.
The evidence is that record: who approved this, in what role, on what date, at what version, from what source. The chip shown here is illustrative.
Clause 4.4.2(b)
Integrate and Deploy: applying current knowledge
Clause 4.4.2(b) requires that current knowledge is applied: transferred, shared and usable inside the flow of work, rather than sitting in a repository nobody opens.
Integrate and Deploy push an approved entry to every channel at once, over MCP, the open standard AI assistants use to reach outside data, and a plain API: assistants and agents, proposal tools, internal search and chat, and portals.
The evidence: deployment state per entry per channel, so a reviewer can confirm not only that knowledge was approved but where it was in force, and when.
Clause 4.4.3(d)
Reuse: internalization and learning
Clause 4.4.3(d) covers internalization and learning: knowledge being searched for, taken in, and put into practice. It is the clause that asks whether the system is actually used.
Reuse is where both kinds of reader draw on the governed entries: people searching and asking, and AI systems retrieving over MCP. A machine internalizes nothing. It answers from whatever it retrieves. So for AI the standard's intent is met only if what it reads from is the governed set.
The evidence: reuse records showing that knowledge is consumed, by whom and by what, and that what gets consumed shapes the next revision.
The enablers
What the standard expects.
Clause 4.4.4 names the enablers a knowledge management system depends on: human capital, processes, technology and infrastructure, and governance. The standard expects an organization to manage all four. Cognatum supplies some directly and structures the rest, and the honest split matters.
- Human capital. The people who hold the knowledge, and the named owners who approve it.
- Processes. The loop itself: capture, clean, enrich, improve, approve, deploy, reuse.
- Technology and infrastructure. Where the entries live, and what may connect to them.
- Governance. Who decides, on what authority, and what record that decision leaves.
The operative word in the clause is current
Every channel serves from the same governed core. Supersede an entry and it is superseded everywhere, in the same moment. There is no window in which one channel is still handing out the old version while another has the new one.
Beyond ISO 30401
Two other frameworks.
Two other frameworks turn up in governance reviews of enterprise AI, and the same machinery produces evidence for both.
Regulation (EU) 2024/1689
The EU AI Act
The EU AI Act is Regulation (EU) 2024/1689, published on EUR-Lex (https://eur-lex.europa.eu/eli/reg/2024/1689/oj). Its obligations for high-risk AI systems began applying to new systems on August 2, 2026.
For systems in scope it sets requirements including data and data governance (Article 10), record-keeping (Article 12), transparency and provision of information to deployers (Article 13), and human oversight (Article 14).
In practice
Where those requirements reach you
Where a system answers from your own knowledge, those requirements reach the knowledge itself. What did it answer from? Who approved that, when, and in what version? Was a person accountable?
Our answer is the provenance record on every live entry. Whether a given system is high-risk is a legal call you make with your own counsel.
Voluntary framework
NIST AI RMF
The NIST AI Risk Management Framework is voluntary, published by the U.S. National Institute of Standards and Technology (https://www.nist.gov/itl/ai-risk-management-framework). It is built around four functions: govern, map, measure and manage, and it is increasingly written into procurement questionnaires and vendor AI audits.
When a review built on it asks how you govern the knowledge your AI draws on, the loop's records are the documentary answer: provenance, approval, change history and deployment state. In both reviews the pattern is the same. Here is where an unapproved answer costs you, and here is the trail: approver, timestamp, source and version on every entry the AI reads.
The guardrail
Standards assess organizations.
No software product can be certified to ISO 30401, and no purchase makes an organization compliant with the EU AI Act or aligned to NIST AI RMF. Certification assesses an organization and its management system. Regulation governs an organization and its AI systems in context. Saying the software itself is certified is a category error under the standard.
Cognatum operationalizes ISO 30401's lifecycle requirements. It is designed to align with the standard's structure. It supports a customer pursuing conformity, by running the process and supplying the evidence a conformity assessment asks for.
If you hear stronger verbs than those, from us or from anyone, ask what exactly was assessed, and of whom.
Common questions
What reviewers ask.
Is Cognatum ISO 30401 certified?
No, and no software can be. ISO 30401 certification assesses an organization and its knowledge management system, not a product. Cognatum operationalizes the standard's lifecycle requirements, is designed to align with its structure, and supports a customer pursuing conformity. The crosswalk on this page shows the clause-level mapping.
Does deploying Cognatum make an organization compliant with ISO 30401 or the EU AI Act?
No. ISO 30401 requires organizational commitments no software can carry: leadership (clause 5.1), a knowledge management policy (clause 5.2), internal audit (clause 9.2), and management review (clause 9.3). The EU AI Act governs organizations and the AI systems they place on the market or put into service. Cognatum supplies process, technology, and an evidence trail toward the customer's obligations.
Who gets certified under ISO 30401, and by whom?
The organization. An accredited certification body audits the organization's knowledge management system against the standard's requirements and issues the certificate, the same model as ISO 9001 and ISO 27001. A software vendor can support that audit with mechanisms and records, which is the role Cognatum plays.
What evidence does Cognatum produce for an auditor or a governance review?
Per entry: the source it was captured from, its change history through cleaning and improvement, the named approver and their role, the approval timestamp, the version identifier, and its deployment state per channel. Across the library: which duplicates were merged, which contradictions were resolved, and what was archived. These records exist as a by-product of the loop running, not as a document prepared for the audit.
What happened on August 2, 2026 under the EU AI Act?
Under Regulation (EU) 2024/1689 (https://eur-lex.europa.eu/eli/reg/2024/1689/oj), obligations for high-risk AI systems began applying to new systems on that date. Organizations whose AI deployments fall in scope face requirements including record-keeping, data governance, and human oversight. Cognatum supplies evidence toward those obligations: who approved each piece of knowledge an AI system answers from, when, at what version, and from what source. It does not determine whether a system is high-risk and it does not confer compliance.
Is Cognatum a KCS® product?
No. Cognatum is informed by industry practice in knowledge-centered service, including the work of the Consortium for Service Innovation, and it differs by design: AI runs the eight-step loop while humans concentrate at the Approve gate, knowledge is captured from every system where it is created rather than primarily from support interactions, and every live entry carries provenance for audit. For certification questions the relevant instrument is ISO 30401, which is why this page maps the loop to its clauses.
Where can I read the standards and regulations this page references?
ISO 30401:2018 is available from the International Organization for Standardization (https://www.iso.org/standard/68683.html). The EU AI Act, Regulation (EU) 2024/1689, is published on EUR-Lex (https://eur-lex.europa.eu/eli/reg/2024/1689/oj). The NIST AI Risk Management Framework is published by NIST (https://www.nist.gov/itl/ai-risk-management-framework). This page paraphrases clause requirements; the published texts are authoritative.
Knowledge governed. Intelligence everywhere.
See it on your own content, in your own environment.
KCS® is a service mark of the Consortium for Service Innovation.