Govern AI, from inventory to trusted action.

The active governance engine for every AI asset, risk and control in regulated financial services. Cogna8 gets AI into production faster, and ready for regulators.

See Cogna8 One
Northwind MutualAI governance overviewUpdated 2 minutes ago.
AI systems148+5 this week
High risk232 without an owner
Controls evidenced43 of 81+6 this month
Decisions today3,91237 blocked
Needs attention7
Unknown gpt-4o caller in Finance has no ownerHigh, 12m
Control test failed: claims payment thresholdHigh, 3h
Underwriting risk summariser review due in 3 daysMedium, 1h
Regulated financial services

Built on the obligations you already report against

Regulation
APRA Prudential Standards CPS 230 Operational Risk Management and CPS 234 Information Security, implemented control by control. ASIC and MAS expectations tracked alongside.
Legislation
The Financial Accountability Regime, and Privacy Act reforms that from December 2026 require privacy policies to explain decisions made or substantially supported by automated systems.
Obligations
Each obligation carries its source, its effective date, an accountable executive, and the controls and evidence that satisfy it.

Standards and guidance referenced in the platform design: MAS AIRG, IMDA Agentic AI, ISO 42001, EU AI Act, NIST AI RMF.

The platform

Cogna8 One, AI governance from visibility to authority

Start with what AI you run and who owns it. Carry the same record through controls and evidence to the moment an agent acts.

Discover · Assess

Know what you run

One inventory of models, agents, copilots and MCP servers, each with an owner, a risk tier and the controls it needs.

Claims assistant
OwnerHead of Claims
Risk tierHigh
Required controls7 of 9 in place
Control · Assure

Govern with evidence

Obligations become owned controls in a versioned registry. Each one rises from declared to effective only as evidence supports it.

Large payments need a manager's approval
FrameworkAPRA CPS 230
AssuranceEffective
Latest evidence12 Sep 2026
Authorise

Decide before it acts

For consequential actions, Cogna8 checks the facts, policy and approvals, then allows, routes or blocks, and keeps the receipt.

Claims assistant asks to pay a claim
AmountA$48,200
DecisionNeeds approval
Routed toClaims manager

Start with visibility. Add authority where consequence begins.

See every screen in Cogna8 One
Questions that matter

What your AI governance should answer

  1. Which AI systems and agents are operating across the organisation?

    They arrive through every team and vendor. Most organisations cannot list them all.

  2. Who owns each one, what risk does it carry, and which controls apply?

    Ownership, risk and obligations belong on one record, not in separate registers.

  3. Which controls are evidenced and effective?

    A control on paper is a claim. Dated evidence is what an auditor accepts.

  4. Where are the gaps, exceptions and unresolved risks?

    Missing controls, stale evidence and open exceptions, found before a regulator asks.

  5. When an agent acts, can you prove why it was allowed?

    The facts, policy and approval behind each decision, kept as a receipt.

Action authorisation

AI proposes. Cogna8 decides whether it may act.

Access controls decide what an agent can reach. Cogna8 decides whether this action is authorised now, against current facts, your controls and any approval required.

Proposed by the agent
Claims assistant asks to
Pay A$3,900
Home contents claim, Northwind Mutual
  • Allowed to make paymentsThe claims assistant may pay claims
  • The facts agreeClaim and payment systems both show A$3,900
  • Within the limitPayments under A$10,000 need no approval
Executed
Allowed

The facts agree and the amount is within the assistant's limit. The payment goes ahead.

Decision receiptAsked: pay A$3,900 on a home contents claimWhat was known: Claim and payment systems agreed on A$3,900Rule applied: Payments under A$10,000 need no approvalDecision: Allowed, 5 Oct 2026, 10:42 am

Every decision leaves a receipt: what was proposed, what was known, which policy applied and why.

Who it is for

One record, three teams

Risk and compliance

Which high-risk AI do we run, and is it controlled?

A current view of AI risk, tied to the obligations you report on.

Technology and AI

What do I need before this agent goes live?

Register once, ship with controls defined, connect to the gate when authority is needed.

Internal audit

Can we show this control worked last quarter?

Dated evidence and receipts, with a clear line between declared and proven.

Start with visibility

Scoped to your own AI estate, with runtime authority added only where an agent needs it.

Contact us