Coriqo AI ASSET CONTROL PLANE
A control plane for enterprise AI assets

One source of truth for every model your institution answers for.

Coriqo connects the models scattered across your registries, storage, and pipelines into a single governed asset graph — then answers the questions no individual system can. We start where the pain is sharpest: turning an examiner request into a one-click package instead of a six-week scramble.

Read-only. Sits on top of where your models already live — never a runtime dependency.

First lens maps to SR 11-7OCC 2011-12EU AI ActNCUA / FDIC

Most regulated teams track their model inventory in spreadsheets, SharePoint, and email approval chains. Then the examiner shows up.

InventoryA spreadsheet updated when someone remembersa live registry that's always current
ApprovalsAn email thread you hope you can still findan immutable, signed audit trail
Lineage"Ask the engineer who left last year"version ancestry, data, and code on record
Exam prepSix weeks chasing teams for documentsone button, one dated package
How it's built

Three layers. Connectors ingest. The core records. Lenses ask questions.

Coriqo isn't a compliance app — it's a control plane. Connectors read your existing systems into one asset graph; every lens asks a different question of that same graph. Compliance is the first question we answer. It won't be the last.

Lens layer Swappable applications · one graph underneath
Shipping now

Compliance & audit

Inventory, lineage, approvals, examiner packages

On the roadmap

Cost & FinOps

Spend attributed to model, team, business unit

On the roadmap

Lineage & drift

What changed, what's duplicated, what's diverging

Open API

Your own lens

Query the graph for questions we haven't built yet

each lens reads the same graph
Core platform Built once — the structural layer every lens draws from

Asset graph

Every model, version, owner, and lineage edge — relationships no single registry holds.

Event spine

Every change recorded as an immutable event. This is what makes the audit trail trustworthy.

Identity & policy

Who can view, change, approve, retire — humans, service accounts, time-boxed examiners.

read-only ingest · sources keep ownership
Connector layer Read-only · pluggable · never owns the data
Registries
MLflow · Hugging Face
Storage
S3 · Azure · GCS · NAS
Pipelines
CI/CD · training jobs
Cloud
AWS · GCP · Azure
The first lens · what ships

Compliance, built around how a model risk team actually works.

We lead with the sharpest pain so the platform earns its place before it expands. Engineers register models from their pipelines; validators review them; everything that happens is recorded in a way an examiner can trust.

01 — Register

A living inventory

Every model and version, with owner, risk tier, training run, dataset, and a pointer to wherever the artifact actually lives. No migration, no copies of weights.

02 — Govern

A real approval workflow

Draft → review → validated → approved → in production → retired. A model can't reach production without an independent reviewer — and never the producer.

03 — Attest

An exam-ready trail

Every state change logged immutably: who, when, from what, to what, with notes. Overdue reviews surface on their own. Generate the examiner package on demand.

Live demo · the first lens · sample data

Walk a model from submission to an examiner package.

A working prototype with illustrative data. Click through a model risk team's three core surfaces — the inventory, the governance lifecycle, and the one moment that sells the whole thing.

coriqo.io / org_risk_models / inventory Live
Model inventory
Governance lifecycle
Examiner package
Model inventory14 models · 31 versions · 2 reviews overdue
ModelRisk tierValidation statusOwnerNext review
credit-risk-scorer · v3
High-risk lending model. Each transition is written to the immutable audit trail.
Immutable audit trail
No transitions yet. Advance the model to begin the record.
Generate examiner package

The moment compliance teams care about. Bundle inventory, lineage, and the full access & approval trail for a date range into a single dated document — the kind you hand an examiner.

§

Your generated examiner package will appear here.

Posture

Read-only by design

Coriqo observes and records. It never moves artifacts, never sits in your serving path, never becomes a runtime dependency.

Identity

SSO, RBAC, examiner tokens

OIDC for humans, scoped keys for pipelines, and time-boxed read-only access for examiners — every access itself logged.

Deployment

Runs in your environment

Kubernetes-native and built for air-gapped and on-prem deployment where regulated workloads require it.

Evidence

Immutable audit trail

Every state change is captured as a signed, append-only event — the foundation an examiner can actually trust.