The living register the automated-AML mandate demands.

The CBN's 2026 Baseline Standards for Automated AML/CFT/CPF require a “glass box”: model ownership, independent validation, change control, explainability and demonstrable effectiveness, and the institution is responsible regardless of vendor. Model Governance turns that into a system of record.

Three pillars the guidance mandates, mapped to the module.

Defensibility

A change log and immutable audit trail give you the traceability and explainability a supervisor asks for, who changed what, when, and why.

Governance

Model ownership, independent validation and change control, with validation that can't be signed off by the model's own owner or developer.

Demonstrable effectiveness

Validation outcomes and review cadence on the record, so effectiveness is something you show, not assert.

From a PDF you update yearly to a register that governs itself.

Model inventory

Register each model with purpose, provider (in-house or vendor), version, criticality, owner and lifecycle status. The static PDF becomes a living register.

Independent validation

Record validations with an outcome (validated / conditional / rejected), stamp the last-validated date, and advance the next due date by cadence. The validator is never the owner, independence by construction.

Change-control-as-control

Every material change, a retrain, a threshold tweak, a data or version change, a decommission, is logged with who and when. That log is the trail an examiner asks for.

Overdue, surfaced automatically

A scheduled sweep flags models whose validation is overdue, so nothing quietly drifts out of governance.

The home for your AI governance, too.

The same register is where ISO/IEC 42001 AI-management controls live. As you deploy AI across the business, “GRC that also governs your models” stops being a separate problem, it's one inventory, one validation lifecycle, one trail.

How ISO 42001 is modelled
Who leans on it

The sectors and seats it serves.

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.