System of record
Where the approved answer lives.
A system of record stores the approved answer itself. Search points at a file wherever it happens to sit, and cannot vouch for it.
Who asks
Cognatum, the governed layer
approved · versioned · permissioned
Where the work already happens
The problem
Nobody approved that answer.
An AI system does not go live until a review board signs it off.
Regulated enterprises are deploying AI assistants and agents they cannot prove are answering correctly, and their AI initiatives are stalling at governance review because of it.
The stall has a specific cause. When a reviewer asks who approved the answer an assistant just gave, the honest reply in most deployments is that nobody did. The retrieval layer was never built to hold an approval.
The word for that record is provenance: who approved an entry, when, from what source, and at which version.
Search was never asked to vouch for anything
Enterprises solved findability years ago and are now discovering that findability and defensibility are different problems. A search box that returns the right document is a good search box. An AI answering from that document, in a regulated workflow, needs something the search box never had to supply: a person who stands behind it.
A system of record for knowledge stores the canonical, approved, versioned entry. Index-in-place tools point at content wherever it happens to live, which means they cannot version it, approve it, or attest to it.
- Answer Approved
Which retention period applies to client trade communications?
ComplianceRecords - Decision Approved
Standardise retention schedules on the records policy
LegalCompliance - Procedure Approved
Applying a legal hold to a retention schedule
LegalRecords - Answer In review
How long are supervisory review records kept?
ComplianceSupervision - Note Draft
Retention questions raised in the Q3 examination
Compliance
The choice
Three ways to feed AI.
Three architectures now compete to feed enterprise AI. They differ in the one dimension that decides governance review: whether anyone can attest to what gets served.
Architecture 01
Index in place
Leave content where it lives, crawl it, and rank it. Nothing to author, and nothing to approve.
Architecture 02
Verification workflow
Add a person who confirms on a cadence that a card is still accurate. A real improvement, and still not a record.
Architecture 03
A governed record
Store the approved entry itself and govern it, so the approval, the date, and the version belong to the answer.
The first one
What an index cannot know.
An index does not know which of the six copies of a policy is current, whether the page it just retrieved was superseded last quarter, or whether anyone with authority ever reviewed the words it hands to a model. It can point to content. It cannot vouch for it. The limit is structural, not a roadmap gap: you cannot version, approve, or attest to content you merely point at.
Where this stalls
For an unregulated workload, that trade is often acceptable. For disclosure language at a broker-dealer or a medical information response at a pharmaceutical company, it is the exact point where the AI initiative stalls: the reviewer asks who approved what the assistant said, and an index has no answer, because holding answers was never its job. The trail ends at a URL, and a URL is not an approval.
Source A · Retention policy v7
Supervisory records are kept for six years.
Source B · Supervisory procedures v3
Supervisory records are kept for five years.
Conflict held apart · routed to Records Management to resolve, not averaged.
The second one
A check is not a record.
The second architecture adds a human check. This is the ground verification-workflow tools such as Guru occupy: a designated verifier confirms on a review cadence that a card of content is still accurate, and unverified cards get flagged. It is a real improvement over pointing. Someone is at least looking.
It still stops short of a governed system of record, in three specific ways.
- No answer-level provenance chain. A verified card says the card was reviewed. It does not say who stands behind the specific answer an AI assembled from it, at which version, from which source.
- No sovereign deployment. The knowledge and its history run where the vendor runs, not necessarily where a regulated customer needs them to.
- No AI running the maintenance loop. Deduplication, reconciliation, and archiving still depend on the sustained human diligence whose lapse left the knowledge ungoverned in the first place.
Use disclosure D-214 rev 6. It supersedes rev 5 for all retail communications and carries the current market-risk language.
No source · no approver · no date
Last checked 2026-05-02, by nobody in particular.
The third one
Four facts on every answer.
The third architecture stores the canonical entry itself, and governs it. In Cognatum, AI runs the eight-step Knowledge Loop: it captures knowledge from the systems where work happens, structures and cleans it, enriches and improves it, deploys it once approved, and watches how it performs in use. Humans concentrate at the one step where judgment is irreplaceable, the Approve gate. Nothing goes live until a named person signs off, and the sign-off is recorded.
The result is that every live entry carries provenance, four facts an assistant inherits every time it answers from the record.
- A named approver: a person with authority put their name on this entry.
- A timestamp: when the approval happened, not when someone last happened to look.
- A source: the document or system the entry derives from.
- A version: which iteration the approval attaches to, with the history retained.
Use disclosure D-214 rev 6. It supersedes rev 5 for all retail communications and carries the current market-risk language. SOP-4471 v3
The chain
What an auditor walks.
The chip is a summary. Behind it is a chain, and the chain is what an auditor actually walks. Each link names the one below it, so a served answer leads back to a dated decision a person made, rather than to a URL.
Superseded versions are retained rather than overwritten. That is the part that matters after the fact: the question is rarely what the entry says today, it is what it said on the day the answer went out, and who had signed off on that.
What this is not
None of this makes an organization compliant with ISO 30401, the EU AI Act, NIST AI RMF, or any regulator's rules, and we do not claim it does. Standards and regulations assess organizations, not software. What the chip represents is evidence supplied toward the customer's own obligations: who approved this answer, when, and from what source.
Connected
Four flows, both directions.
Four flows connect them.
- Ingest, from source systems into Cognatum over a plain API and over MCP, the open standard AI assistants use to reach outside data: raw knowledge enters from wherever work happens.
- Serve, from Cognatum to consumers over MCP and API: governed, approved entries reach people and AI.
- Write-back, from Cognatum to the source systems: corrections propagate to the place the error came from, so people stop finding the stale version.
- Usage signals, from consumers back into Cognatum: what gets used, questioned, and contradicted feeds the next cycle of the loop.
What never moves
A system of record can sound like a silo. It is the opposite of one. MCP and API connections run in both directions: sources feed in, consumers draw out, and write-back carries corrections from Cognatum to the systems the errors came from. An agent queries governed knowledge over MCP. A workflow reads and writes over the REST API. A fix made once in the knowledge base propagates to the SharePoint page where people would otherwise keep finding the old answer.
What never moves is where the truth lives. The canonical, approved, versioned entry lives in Cognatum. Other systems can reference it, cache it, or sync from it, but exactly one entry carries the approval, and every consumer, human or machine, answers from that one.
Cognatum governs the entry
source · version · approver · permissions
Where it lives
And you decide where.
A governed home raises one more question: where does that home live, and who gets to connect to it? That is what Sovrinty is for. Sovrinty is the control layer on top of Cognatum, and it becomes available once your knowledge lives in Cognatum, because control needs something real to hold.
It is a separate product and this page does not sell it. What is worth knowing here is the shape of the choice it gives you, because it is the question a security review reaches within about ten minutes.
- Your hardware. The knowledge base runs in your own environment rather than ours.
- Another country. The same knowledge base, in a jurisdiction you choose.
- Another vendor. Which systems and which model providers connect to it stays your decision.
Common questions
What people ask here.
What is a knowledge management system of record?
It is the store that holds the approved answer itself, versioned, with a record of who approved it and when. A search index points at content wherever it happens to sit, which is why it cannot version that content, approve it, or say who stood behind it.
We already have enterprise search. Why is this different?
Search solves finding. This solves defending. A search box that returns the right document is a good search box, and it was never asked to vouch for what it returns.
What does an answer carry?
Four facts: the person who approved the entry, the date they approved it, the document it came from, and which version the approval attaches to. Superseded versions are kept, so what an answer said on a date in March is a lookup.
Do we have to move our content?
No. Source systems keep their content and feed in. What moves is where the approved version lives: exactly one entry carries the approval, and every reader, human or machine, answers from that one.
Does this make us compliant with anything?
No. Standards and regulations assess organizations, not software. What you get is evidence toward duties you already carry: an approver, a date, a source, and a version on every answer served.
Knowledge governed. Intelligence everywhere.
See it on your own content, in your own environment.