Data, AI, and agents · Governed as one

The governance layer for the agentic enterprise.

Every model read and every agent step is checked before it commits, and the proof writes itself. Built for finance. Three planes: know what can act, govern the action, prove it held.

3planes

One governance lifecycle

11surfaces

Each a subproduct

1estate

Data, AI, agents

0blind spots

Nothing acts unseen

The problem, in three parts

AI scaled faster than anyone could govern it. Agents made it autonomous.

01

You cannot see the estate.

No single inventory of the data, models, and agents that can act. You cannot govern what you cannot see.

02

Controls do not reach the action.

Policy lives in binders and pipelines. Agents act outside both, in milliseconds.

03

Findings arrive as surprises.

Evidence is assembled after the fact. The exam finds the problem before you do.

One layer closes all three ↓

Where Fiducia sits

One layer between the estate and everyone it answers to.

Actions flow in from the systems Fiducia reads. Evidence flows out to the people the estate must answer. Nothing commits in between without a check.

Reads from

  • Warehouses and lakes
  • Model and feature registries
  • Agent frameworks and copilots
  • SaaS and core systems
  • Identity and ticketing
  • Third party AI and vendors

The governance layer

Fiducia

The Runtime

DiscoverEnforceAttestProve

Checked before it commits

Answers to

  • The board
  • The regulator
  • Internal and external audit
  • Model risk and compliance
  • Customers and members
  • The public record

Arcade governs the tool call. Redpanda governs the data plane. Fiducia governs the decision, and maps it to the rule it must answer to.

The stance

The controls that made you examinable will not make you governable.

Control has moved through four eras. The first three all assumed a person in the path with time to intervene. Autonomy removes that time, and with it the one assumption every old control was built on.

A control that is not enforced at the moment of action is not a control. It is a record.

The consequence gap · time to intervene

Closing

I
LedgerDays
II
Periodic reviewWeeks to quarters
III
Continuous monitoringMinutes
IV
Autonomous executionNone

Every control built for the first three eras assumed the bar was wide enough for a person to step in. At era IV there is no bar.

I

Ledger

Control by record. The books reconciled after the fact.

II

Periodic review

The model risk world. Validation on a calendar.

III

Continuous monitoring

Observability. Watching in real time, still after the act.

IV

Autonomous execution

Agents act and the person is gone. Control must move into the action.

Know what can act. Govern the action. Prove it held.

Governing autonomy is not one feature. It is a stack. Three planes, read left to right. Eleven surfaces sit across them, and every surface keys off the one before it.

The governed estate

Govern one decision and it is a demo. Govern every decision and it is the product.

Fiducia scores the whole estate continuously. Every row is a model or an agent. Every column is a check. Every cell is current.

The governed estate · live

87Assurance Score · rising

SensQualLineBiasAuthEvid
underwriting_v4
kyc_agent
rebalance_agent
claims_copilot

1 red · kyc_agent authority out of bounds · blocked, routed to owner

Stochastic capability. Deterministic mandate. Both, at once.

Regulators require reproducibility. Fiducia resolves the tension between stochastic models and deterministic mandates by wrapping every governed action in machinery that behaves the same way every time, and writes down what it did.

01

Structured prompt templates

Versioned, audit tracked templates. The same inputs produce the same evaluation pathway, every time.

02

Multi agent consensus

Multiple agents evaluate the same decision independently. Disagreement above threshold routes to a human reviewer.

03

LLM as judge

A separate model instance scores primary outputs against calibrated rubrics. Generator and evaluator are architecturally separated.

04

Compliance as code

Controls expressed as versioned, testable code. A policy change ships like a software release: reviewed, tested, rolled back if it fails.

05

Tiered decision rights

Reversible actions clear at machine speed. Consequential actions route to a named human before commit. The line is codified.

06

Immutable audit log

An append only record of every reasoning step. Not editable, not deletable.

Built for the institution, not the startup.

Tenant isolation

Single tenant deployment options. Your data does not train foundation models.

Data residency

Deployed in your region, your cloud, or your own perimeter.

Certifications

SOC 2 Type II. Zero data retention options. DPA ready.

SOC 2 Type IIZDRDPA ready

Enterprise identity

SSO, SCIM, and role based access mapped to your control functions.

Read only by default

Connectors observe. Enforcement scopes are explicit, granted, and logged.

Examiner ready records

Every governed action leaves an immutable, attributable record built for supervisory review.

Coverage

Every rule you answer to, already mapped to a control.

From SR 11-7 to the EU AI Act, from NYC Local Law 144 to ISO 42001. One control test answers every framework that asks for it.

Explore the Rulebook · 29 frameworks and counting

Map once, prove everywhere

29 in the Rulebook

One test result answers every framework that asks for the same thing. Coverage stops being a per framework project.

Why Fiducia, not the alternatives

Everyone owns a slice. Fiducia owns the seam.

One estate, not three tools

Data, AI, and agents governed as one. Everyone else owns a slice. Fiducia owns the seam.

Enforced at the action

Policy decides before the action commits, not in a review that happens after.

The language of the exam

Written in the regulatory vocabulary finance is examined in, from SR 11-7 to DORA.

Evidence that writes itself

Living Evidence as a byproduct of execution, not a binder you assemble each quarter.

On the roadmap · future tense

Govern what defends. Consume what proves.

Agentic security is coming to Fiducia. Oversight of the agents that run your security operations, and proof from offensive testing turned into evidence the board can read. One estate, one record. This stays future tense until it ships.

Questions, answered.

What is Fiducia?

Fiducia is the governance layer for the agentic enterprise. Its production offering, Assurance, is an AI-native IT risk management and governance platform built for the second and third lines of defense at regulated financial institutions. It ingests your frameworks, policies, and live operational data, maps controls to risks continuously, tests controls across the full population, and generates audit-ready evidence, replacing manual spreadsheets and point-in-time sampling.

Do we have to replace our GRC platform to use Fiducia?

No. Fiducia reads from your GRC platform, ITSM, CMDB, and the rest of the estate through read-only connectors, and produces independent challenge evidence alongside them. Institutions typically run both, with Fiducia as the evidence and assurance layer, and revisit the system-of-record question at their own pace.

How is this different from an AI security tool that blocks agent actions?

A security tool blocks on anomaly, when behavior looks wrong. Fiducia evaluates against institutional authority, so an outcome cites the rule, the control, the appetite clause, and the obligation behind it. Both are useful and neither replaces the other, and security telemetry can be a source into the governance graph. Assurance evaluates and evidences actions today; enforcing at the moment of action is the Runtime plane, which is in development.

Does Fiducia write anything back into our systems?

No. Connections are read-only, and write-capable credentials are rejected at setup. Where an outbound integration creates a ticket or a message in another system, that action runs under credentials you supply for that integration and is subject to that system's permissions.

Is our data used to train models?

No, in any deployment model. The platform documentation sets out the full position, including the terms that apply to model serving.

Can the AI close a finding or change a risk rating on its own?

No. Agents propose, people decide. Every finding arrives with the rule it maps to, its pass or fail, and the evidence behind it, and the decision you record in the review queue is the decision of record.

Will the same question always get the same answer?

The governance outcome is designed to be reproducible: the same control assessed against the same evidence and methodology produces the same result, and the methodology itself is versioned. Authority evaluation is deterministic and involves no model at all.

How do we explain a finding to an examiner?

Open the finding's decision trace and export it. It carries the context, the reasoning, the authority derivation from control to appetite clause to obligation, the evaluation, and the human decision. It is the chain most examiners ask for.

What is the difference between shadow AI autonomy and shadow authority?

Shadow autonomy is the risk that an agent acts beyond its authorized scope. Shadow authority is the measurable instance: an action for which no valid delegation path existed at that moment. The first is a category of concern; the second is a finding you can act on.

The convergence

The agentic enterprise runs on governed data and AI.

Know what can act. Govern the action. Prove it held. Proactive, independent, ready for the regulator, always on.