Solutions

Two starting points, one record

Some organisations need an AI governance programme the board and the regulator can rely on. Others need authority over agents that already act. Both work from the same record in Cogna8 One.

Establish an AI governance programme

Inventory, accountable owners, risk tiers, controls and evidence for every AI system, mapped to your regulatory obligations, with no change to how the systems run.

For risk and compliance, technology and internal audit.

Govern agents that act

Agents that pay, send or change records are authorised before each action, against your policy and delegated approval limits, with a record of every decision.

For teams putting agents into production.

Regulated financial services

Built on the obligations you already report against

Regulation
APRA Prudential Standards CPS 230 Operational Risk Management and CPS 234 Information Security, implemented control by control. ASIC and MAS expectations tracked alongside.
Legislation
The Financial Accountability Regime, and Privacy Act reforms that from December 2026 require privacy policies to explain decisions made or substantially supported by automated systems.
Obligations
Each obligation carries its source, its effective date, an accountable executive, and the controls and evidence that satisfy it.

Let's connect

Tell us where your AI programme is today. We scope the first engagement to your own AI estate, and every enquiry is handled in confidence.