What a record your reviewer can verify without trusting you looks like in practice.
Nine scenarios, five in banking and four in healthcare — from consolidating a fragmented inventory ahead of an OCC exam, to a clinical AI vendor clearing hospital AI-governance review, to a health plan evidencing that a licensed human made the denial. Switch between the two below. Each shows the problem, how Coriqo is used, and the kind of outcome to expect.
These are illustrative sample scenarios composited from the problems Coriqo is built to solve, consistent with the illustrative sample data used in our demo. The organization profiles and figures below are examples for explanation, not claims about named customers or guaranteed results. Coriqo has no named healthcare customer yet — the healthcare scenarios describe workflows the shipped healthcare rulepack supports, not deals that happened.
Consolidating a fragmented model inventory ahead of an OCC exam
$40B regional bank · 120+ models across 6 business linesThe challenge
Model risk lived in at least four spreadsheets that disagreed with each other. Credit, treasury, BSA/AML, and finance each kept their own list, and no single record could answer "how many models do we run, who owns each, and what state is validation in." With an OCC exam scheduled, leadership could not confidently produce a complete inventory — the first document the request list always asks for.
How Coriqo is used
The team imported each business line's spreadsheet through Coriqo's dry-run-then-commit CSV workflow with four-eyes approval, reconciling duplicates and orphaned models into one authoritative inventory. Every model was tiered, assigned a named owner, and mapped for dependencies, so the impact of any one model could be traced downstream.
Vendor and end-user-computing models that had never been formally tracked were pulled into scope as first-class inventory records.
Illustrative outcomes
Proving effective challenge on credit and underwriting models
Mid-size lender · $9B in assets · 30+ credit and pricing modelsThe challenge
The lender validated its models, but the record showed only conclusions — not the substance of the challenge SR 26-2 expects. Examiners had previously questioned whether reviews were genuinely independent, since the same analysts who built models also appeared to sign them off, and the reasoning behind each approval lived in email threads that were hard to reconstruct.
How Coriqo is used
Coriqo enforces segregation of duties by role: a model's owner can never be recorded as its independent approver, and self-approval is blocked outright. Each validation captures what was challenged, the limitations identified, the conditions attached to approval, and the named, independent person who signed off.
The full challenge history is written to an append-only record, so the reasoning behind every approval is evidence rather than recollection.
Illustrative outcomes
Standing up model risk management from spreadsheets with a two-person team
Credit union · $3B in assets · 2-person risk functionThe challenge
The credit union's entire model risk function was two people holding the title alongside other jobs. Examiner expectations — an inventory, a validation cadence proportional to risk, documented approvals, ongoing monitoring — hadn't gone away, but hiring a validation department was never on the table. They needed the structural rigor of a large program without the headcount.
How Coriqo is used
Coriqo gives the two-person team one lifecycle state machine (draft → submitted → validated → approved → production → retired) so a model's state always reflects reality. Tiering drives a proportional validation cadence automatically, so low-risk calculators don't get the same depth as material models.
For the highest-risk models where internal independence is hard, the workflow supports engaging an external validator and recording that review in the same trail.
Illustrative outcomes
Capturing model-governance decisions from Teams and email as sealed evidence
$22B commercial bank · Microsoft 365 · Teams-first cultureThe challenge
The decisions that mattered — "the recalibration looks fine, ship it" — happened in Teams channels and email threads, then vanished from the governance record, which kept only the conclusion. When an examiner asked who decided a model was acceptable despite back-testing drift and on what basis, the honest answer was a reconstruction, not evidence.
How Coriqo is used
Coriqo captures Microsoft Teams communications as governed, approvable evidence: a named person reviews and approves a thread into the record, attaches it to the relevant model or governance event, and it is sealed into the same tamper-evident examiner package as everything else.
Capture never auto-decides. Attribution follows the human who approves, not the chat message and never an AI summary — the conversation becomes visible evidence behind a human sign-off.
Illustrative outcomes
Passing an exam with an independently verifiable, tamper-evident audit trail
$15B regional bank · preparing for a supervisory model risk reviewThe challenge
The bank's records were coherent, but every claim rested on "trust our database." An examiner had no way to confirm a validation record hadn't been edited after the fact, or that an approval was as old as it appeared. The team wanted evidence an examiner could confirm independently, rather than assurances the examiner had to take on faith.
How Coriqo is used
Every governance event — approvals, validations, monitoring breaches, findings — is appended to a SHA-256 hash chain, sealed into Merkle checkpoints, and signed with Ed25519. The examiner downloads an inclusion proof and verifies a single event offline, with the public key alone, no Coriqo server involved.
A one-button examiner package assembles the dated, self-contained, independently checkable record for the full review.
Illustrative outcomes
Clearing hospital AI-governance review without rebuilding the evidence pack each time
Clinical AI vendor · one deployed model, deals pending at 9 health systemsThe challenge
The model was not the obstacle. Every health system's AI-governance committee asked for a different slice of the same evidence — one wanted the bias-management approach, the next demographic representativeness of the training data, a third the retirement and change-management policy. Each request was answered by hand from slides and a shared drive, and the answers drifted between deals.
The harder question came from counsel: the vendor's own deck reported a clinician override rate, and nobody could say who computed it or whether it could have been edited since.
How Coriqo is used
The vendor runs the healthcare rulepack — the Joint Commission's RUAIH certification domains, cross-referenced to the ONC HTI-1 predictive DSI source attributes. Each requirement resolves to records already in the chain rather than a document reassembled per deal, so a committee asking about bias management and one asking about lifecycle policy are answered from the same sealed record.
Human review of the model's recommendations is recorded as it happens: time on each decision, agreement with the model, volume, and reviewer. The vendor's medical director sets the threshold at which that pattern opens a tracked finding — Coriqo reports the number and never renders a judgment about a named clinician.
Each committee gets time-boxed, read-only access to the record and verifies the chain against a public key instead of accepting the vendor's summary.
Illustrative outcomes
Evidencing that a licensed human, not the model, made the denial
Regional health plan · utilization management · 2026 state AI statutes in scopeThe challenge
Every 2026 state statute on AI in utilization management says the same thing: a licensed clinician, not an algorithm, has to make an adverse determination. The plan believed it complied. It could not show it.
The figure that defined this whole problem publicly — roughly a second per claim — came from journalism and discovery, not from any system a plan could produce on request. When the state regulator asked how long the plan's own reviewers spent, the honest answer was that nobody was measuring.
How Coriqo is used
Each determination records who reviewed it, how long they spent, and whether they departed from the model's recommendation, sealed into the same append-only chain as everything else. The plan cannot revise the figure after the fact, which is the property that makes it worth producing.
The medical director sets the thresholds. When dwell time or concordance crosses one on a class of determinations, Coriqo opens a tracked finding with an owner and a due date — a fact routed to a human, never a verdict about a named reviewer.
External review organizations and state regulators get time-boxed, read-only access and verify the record against a public key.
Illustrative outcomes
Telling nine health systems what changed when the model is retrained
Clinical AI vendor · quarterly retraining cadence · 9 deployed customersThe challenge
The model improves every quarter, which is the point of the product and the source of the problem. Each retrain invalidates part of the documentation every customer holds, and each customer's AI committee had approved a specific version under specific claims about its data and performance.
Nobody could answer, per customer, which version they were running, which validation evidence applied to it, or whether they had been told about the last change. RUAIH asks for lifecycle policy covering change management and retirement, not just the initial validation — and this was the gap.
How Coriqo is used
Every retrain is a new sealed version with its own lineage: the training data description, the demographic representativeness, the external validation, and the bias-management approach that belong to that version specifically, not to the product in general.
Because the requirement checks resolve to records rather than documents, each customer's package regenerates against the version that customer actually runs. A committee reviewing v4 sees v4's evidence, and the fact that v3 was superseded on a dated, sealed event.
Retirement of an old version is a recorded governance event rather than an email nobody kept.
Illustrative outcomes
One approval authorized 4,000 agent actions — showing what it actually covered
Clinical AI vendor · agentic prior-authorization workflow · mandate-scoped agentThe challenge
The product stopped scoring and started acting. A clinician approves a mandate — what the agent is permitted to do, on which cases, within which bounds — and the agent then works through thousands of items under that single authorization.
Override rate stops being a meaningful number when almost nothing reaches a human individually. The committee's question became sharper and harder: how much action did one signature cover, and did the person signing see anything representative of what they were authorizing?
How Coriqo is used
The mandate is a governed, versioned record, and a material change to it is a new version requiring fresh approval rather than an edit. Every action the agent takes is sealed as a decision trace anchored to the mandate version it ran under.
That makes the ratio answerable from the record instead of estimated: this approval, this mandate version, this many sealed actions, over this window, with these escalations back to a human. A committee can sample the traces rather than accept a summary.
Actions falling outside the mandate's scope are recorded as such, so the boundary is evidenced rather than asserted.
Illustrative outcomes
Want to walk through a scenario like yours?
Tell us about your institution — asset size, model count, and where your current MRM process hurts — and we'll show you the workflow against your own situation, not a canned demo.