Coriqo
Services · three fixed-scope engagements

Most teams that need this are short a person, not short a tool.

Buying the platform still leaves someone to populate the inventory, chase the documents, and assemble the pack before the exam. In a two-person risk function that someone does not exist. These three engagements do that work with you, on your data, in your Coriqo instance — fixed scope, fixed fee, and a boundary we state before you ask.

The line we don't cross

We assemble and seal the evidence. We never sign the validation opinion. SR 26-2 expects validation to be independent of the model owner, and a vendor that sold you the evidence platform is in no position to also render the conclusion stored inside it. Our work stops at readiness: your second line, or an independent validator you choose, makes the call. If you would rather we did both, we will refer you to a firm that can do the second half.

Why we started offering this

Software that nobody has time to fill in is a shelf-ware risk, and we would rather say so.

Two findings shaped this decision, and both cut against selling a licence and walking away.

Pilots that went nowhere
95% showed no measurable P&L impact

Across roughly 300 deployments, the projects that worked were the ones somebody embedded in; the ones that failed were generic tools handed over at the contract signing.

MIT NANDA, The GenAI Divide, August 2025
Projects being cancelled
Over 40% of agentic AI projects, by end-2027

The reasons given are cost, unclear value, and inadequate risk controls. The third one is the part we can actually fix, and it is easier to fix with someone in the room.

Gartner forecast
The three engagements

Each one ends in something sealed, dated, and checkable by someone outside your company.

Every engagement runs inside your own Coriqo instance and requires an active subscription. We scope on a call and quote a fixed fee; there is no hourly rate and no open-ended retainer. We price per artifact delivered, and the artifact is countable on your own hash chain, so afterwards you can point at what you paid for.

S1
Getting governed
Fixed fee · scoped on a call
You have models in spreadsheets, documents in SharePoint, and no single list anyone trusts. We build the list and turn it into a record.
You end up with
Your full model and AI inventory imported and reconciled, including the vendor models you did not build
Existing documentation ingested and attached to the specific version it covers
Cloud discovery connected, Azure first, so shadow AI shows up next to what you declared
Your first sealed governance chain, verifiable offline with a public key
Scope an S1
S2
Evidence packs
Fixed fee per pack · or fleet coverage
For each model or agent, the evidence a validator will ask for, gathered and sealed before they ask. Per pack, or standing coverage across the fleet.
You end up with
The readiness checklist satisfied, with every open item named and assigned rather than quietly skipped
An assumption register seeded from the documentation, with drift detection running against it
A sealed evidence pack per model, hash-bound to the version it describes
A written list of what is missing and who owns it, because a pack that hides gaps is worse than no pack
Scope an S2
S3
Exam preparation
Fixed fee per exam or milestone
You have a date. A regulatory package for that named exam, or for an EU AI Act conformity milestone, drafted and sealed against it.
You end up with
A regulatory package taken from draft through review to sealed, scoped to the exam actually coming
Gaps raised as tracked corrective actions, each with an owner and a due date
The examiner portal set up so a reviewer can verify the package without a Coriqo account
A dry run against the questions in our regulatory corpus, so the obvious ones have answers before the day
Scope an S3
What we will turn down

Four things we don't sell, and the reason for each.

A short list is more useful to you than a long one, and it tells you what we are before the third call.

The validation opinion

Independence. We prepare the evidence; somebody else concludes on it. This is the boundary at the top of the page and it does not move per engagement.

Bodies by the month

Staff augmentation turns into a headcount line that never ends and a product that stops improving. Every engagement here has a defined end.

Open-ended advisory

We are not a consulting firm and are not trying to become one. Services stay a minority of revenue on purpose, so the platform keeps getting built.

A promised outcome with your regulator

Nobody can sell you a passed exam. We can get the evidence into a state where the questions have answers, which is a different claim and an honest one.

Questions we get

Asked by risk officers, procurement, and the firm that already does your validation.

It feeds them. An S2 pack is the input an independent validator has to assemble by hand today — inventory, versioned documentation, assumptions, chain of approvals, arriving already gathered and hash-bound. That collection has to finish before any judgment can start, and none of it needs the validator's expertise. We take that half; they keep the judgment, which is what they are paid for.
Today, the founder, with a cap of two engagements running at once. That is a real constraint and we would rather name it than take a booking we cannot staff. If the calendar is full we will tell you the date we can start rather than starting badly. As the runbooks harden, the manual steps in them become product features — which is the point of doing this work ourselves rather than hiring a delivery team first.
No. Every deliverable here is a sealed artifact in a Coriqo instance — a pack that leaves as a PDF loses the thing that makes it worth having, which is that a reviewer can verify it later against a public key without trusting either of us. A consultancy can hand you a document; only the platform can hand you a document that is still checkable in three years.
A fixed fee per engagement, quoted after a scoping call, on the same basis as the rest of our packaging. We are not publishing a rate card for the same reason we do not publish a licence price list: we are early, the numbers would be invented, and a bank that catches a vendor inventing numbers is right to stop reading. Ask, and you will get a real one for your scope.
Only what the engagement needs, inside your own tenant, under the same schema isolation and zero-retention terms as ordinary platform use — your data is never used to train a model. Access is scoped to named people for the length of the engagement and revoked at the end, and every action we take lands in your audit trail attributed to us by name rather than to "the vendor". You can read what we did afterwards, which is the same standard we ask of everyone else on the record.
Yes, with the framework swapped. S1 and S2 run the same way against the healthcare rulepack, and S3 targets a Joint Commission RUAIH or ONC HTI-1 review, or a health system's AI governance committee, in place of a bank exam. The artifact both buyers want turns out to be the same one: a sealed package somebody outside your company can check.