Model-risk attestation with evidence from the run, not the memo.

Govern the workflows where AI influences a decision, and produce the documented, replayable record that model-risk attestation asks for.

A risk analyst reviewing a bound model documentation report beside a laptop, its charts softly out of focus in a quiet office.
§ 01 · How it works

One run, end to end.

Kora governs the workflows where a model or agent influences a decision and captures the run-time evidence model-risk attestation needs: a hash-chained, replayable record of inputs, model outputs, approvals, and outcomes, shaped for SR 26-2 and EU AI Act Article 12 record-keeping.

  1. Run

    A decision enters the workflow

    The run starts under a released process version, and the model version in play is part of the record.

  2. Model output

    The model proposes

    Inputs and outputs are captured as the model or agent shapes the recommendation.

  3. Review

    A person decides

    The reviewer sees the inputs, the output, and the context, and approves or overrides.

  4. Record

    Evidence for attestation

    What the model saw, what it produced, and who decided land in the append-only record.

Attestation draws on facts captured at execution, not a memo written afterwards. Hash-chained, replayable.

§ 02 · The approach

Model-risk attestation

What you get

  • Attestations built from the run

  • Every change under release control

  • Evidence ready when it is asked for

01

Evidence for every model-influenced decision

Each run where a model shapes an outcome leaves a record of what the model saw, what it produced, who reviewed it, and what was decided.

02

Under release control

Which model version and which process version ran is part of the record, so an attestation refers to a specific, frozen release rather than a moving target.

03

Shaped for what examiners expect

The run-time evidence is shaped for SR 26-2 and EU AI Act Article 12 record-keeping, so attestation draws on facts captured at execution, not a document written afterwards.

§ 03 · FAQ

Questions, answered.

What teams ask when they evaluate Kora for this problem.

No. Kora governs the workflows where models and agents act and produces the run-time evidence attestation relies on. It complements a model-risk framework by giving it a hash-chained, replayable record of what actually happened in production.

Inputs, model and agent outputs, the human reviews and approvals, the process and release version, and the outcome, all hash-chained and replayable per run.

The evidence is shaped for the record-keeping expectations of SR 26-2, the interagency model risk guidance that superseded SR 11-7 in April 2026, and EU AI Act Article 12. The same record supports DORA operational-resilience evidence.

No. SR 26-2 explicitly excludes generative and agentic AI models from its scope because they are novel and rapidly evolving. Kora's run-time evidence can still support a firm's broader internal AI-governance and model-risk program by recording what a model or agent did inside the workflow, who reviewed it, and what was decided.
§ 04 · Next step

Bring one model-influenced decision.

In a demo, bring a workflow where a model or agent shapes the outcome. We will run it governed and show the run-time record your next attestation can draw on.