Solutions  /  Financial services and insurance

Secondary discovery

The control changed. Which decisions are now unsupported?

Models inform credit, pricing, claims and surveillance decisions inside obligations that move. When a policy, threshold or regulatory expectation changes, the question is which prior decisions were made under the old rule and whether that matters.

APRA pilot + AWS evidence

Start with one bounded, non-actuating workflow.

EcoKure does not approve credit, move money or replace model validation. The first financial-services path is a draft customer communication: a control pack checks it, a qualified reviewer handles abstentions, and the record remains independently verifiable.

01Bound the workflow

Draft communication only. No payment or credit action.

02Configure the pack

Your risk function owns the policy, citations and thresholds.

03Run in shadow mode

Observe ALLOW, BLOCK and ABSTAIN without changing production.

04Review exceptions

Hardship, vulnerability and other cases go to a named reviewer.

05Export the evidence

Retain the signed decision, reason, control version and sign-off.

Supports evidence for

APRA concern → EcoKure control → customer evidence

OwnershipNamed control owner and reviewerApproval record
Operational resilienceFail-closed behaviour and recovery testRecovery EvidencePack
Change managementVersioned pack and impact analysisAffected-decision report
SecurityTenant boundary, IAM and key custodyAccess and signing evidence
AuditabilitySigned per-decision recordIndependent verification
Target-environment measurement

AWS evidence, clearly bounded

117,290verifications
0recorded errors
19.47 msp95 measured run
128.1/ssoak throughput

KMS signing was independently verified, Terraform-managed PostgreSQL was used, and the evidence chain remained valid after controlled recovery. This is target-environment evidence, not AWS certification, APRA approval or production customer validation.

Customer systemPrivate APIRuntimePostgreSQL + KMSEvidencePack
Run the APRA workflow lab
Enterprise readiness

What the architecture conversation still needs to close.

These are validation items, not hidden claims. The pilot turns them into named decisions, tests and evidence.

TO CLOSE

Company-owned account

Separate organisational ownership from a single personal cloud workspace.

TO VALIDATE

Staging and production

Use separate environments and keep production data out of test.

TO EXECUTE

Key custody

Run the KMS-backed signing-key migration in the real deployment.

PILOT SCOPE

Tenant evidence

Validate per-tenant evidence sets, control packs and database isolation.

AGREE

Service boundary

Set the customer SLO, incident route, retention policy and support model.

DECIDE

Historical records

Document how pre-commitment chain entries are migrated or treated.

The problem

Two responses, both unsatisfying

Attest periodically

Proves the control was designed. It does not prove it operated on any given decision.

Sample and review

Finds patterns. It cannot reconstruct one specific decision two years later.

Operational-risk expectations increasingly ask whether controls were operating rather than merely documented, and model governance functions are being asked to evidence individual decisions rather than aggregate performance.

Who is in the room

What each of them needs to see

RoleWhat they need before this proceeds
Chief risk officerWants failure behaviour, abstention handling and what happens when the checker itself is unavailable.
Model risk and validationWants determinism and replay, because a result that cannot be reproduced cannot be validated.
ComplianceWants a mapping from a lane to a specific obligation, not a general assurance.
Internal auditWants a per-decision record they can test without asking the first line for help.
Behind this page

The gates that do the checking

This page exists because these implementations exist. We do not publish an industry page without gates behind it.

StatsGate

Open source

Detects impossible or internally inconsistent statistics using GRIM and p-value consistency checks.

ClaimGate

Interactive lab

Extracts claims from AI or scientific output and routes each one to the deterministic gate that can settle it.

ClaimLint

Open source

Lints documentation for unsupported AI and science claims. Runs as a CLI or a GitHub Action in CI.

Security Lanes

Open source

Reproducible test cases across CWE and OWASP weakness families with transparent scoring.

ReplayGate

Interactive lab

Re-runs sealed evidence packs to detect verification drift over time.

EU AI Act Profile

Open source

An application profile mapping deterministic lanes and evidence onto specific EU AI Act articles.

Limits

What this is not

  • EcoKure is not a model risk management platform and does not perform model validation.
  • It does not assess creditworthiness, price risk, or make any financial determination.
  • Nothing it produces is financial or legal advice, or a compliance opinion.
  • This is a discovery market. EcoKure has no financial services deployment and says so.

Start with one workflow

The useful first conversation is thirty minutes on a workflow where a change in rules or evidence has already cost you work. Both sides find out quickly whether this is worth pursuing.

Where it sits in what you already run

Nothing is replaced. The runtime deploys in your own account, so the only thing crossing the seam is a decision request one way and a verdict with its evidence coming back.

Your banking stack unchanged, nothing replaced Core banking and the customer channel The model generating the communication Your GRC platform and control library Entra ID or your own directory Operational risk reporting draft communication verdict + evidence no agent installed no data leaves your boundary EcoKure Assurance Runtime deployed in your account · 11 dependencies APRA control pack, owned by your risk function A verdict on every customer communication Signed evidence, reconstructable years later Abstentions routed to a qualified reviewer Board-ready assurance reporting EcoKure never touches • Credit decisions — out of scope for a first pilot • Payments or any movement of money • Your model — model validation stays yours • Customer data — an input digest, never the content
The pilot deliberately starts on a non-actuating workflow. EcoKure does not approve credit, move money or touch a payment rail, and the control pack is authored by your risk function rather than by us — which is the part an APRA reviewer asks about.

What one decision actually does

The same runtime and the same evidence contract as every other pathway. What changes is the control pack and the workflow.

your bank’s own account — nothing leaves it In scope AI-assisted customer communication EcoKure Policy, citation and arithmetic checks Decision ALLOW / BLOCK / ABSTAIN Your rules APRA AI Control Pack — your version binds version + hash entry 412 ABSTAIN signed, append-only evidence chain signs every outcome hardship, vulnerability, Queue Review queue aged, board-reported Person Your qualified reviewer entry 587 BLOCK sign-off — commitment only, no identity references, never rewrites Evidence pack export Independent verifier no EcoKure code runs offline
Mapped to CPS 230, CPS 234 and the April 2026 AI letter. The abstention path is what an APRA reviewer asks about: a communication touching hardship or a deceased estate is not wrong, it is not the machine’s to send — so it abstains rather than blocking, and a named person decides. Both entries reach the board report.
Next · Start a pilot Adoption