Control plane & evidence · Financial services first · Pre-launch
Show your examiner what your AI agents were authorized to do with money, what they did, and that the record is intact.
Custogent is the control plane an AI agent must pass through to move money, and the tamper-evident, quantum-safe evidence ledger that turns each decision it makes into a record an examiner can verify without trusting you, or us. It shows that every recorded verdict on an agent’s instruction was computed under its named mandate and policy version, from disclosed inputs, and can be recomputed by anyone from the record.
Custogent never holds funds, card numbers or your agents’ private keys, is not a payment processor, and never substitutes its own judgment for yours: every policy verdict is your own policy version applied to your own inputs.
- agent
- ap-settlement-07 · owner: Treasury Ops
- instruction
- transfer 18,400.00 USD → counterparty 4471 · ACH same-day
- mandate
- m_0192 v4 · ceiling 25,000.00 · expires 2026-12-31
- policy
- ps_v17 · 3f9a…c2e1 · agg.spend.day.agent 71,300.00
- verdict
- hold · NOVEL_COUNTERPARTY · 2026-09-04T13:02:11Z
- approval
- approver ≠ mandate issuer · signed hash 8b1e…04d7 · 13:06:40Z
- receipt
- checkpoint #48,211 · RFC 3161 + second anchor · S3 Object Lock
- signatures
- EdDSA ✓ · ML-DSA-65 ✓
Illustrative record. Each verdict records the mandate and policy version it was evaluated under — or that one was missing — the values it evaluated and any approval, and carries a receipt anyone holding the evidence pack, our published keys and the verifier can check. What the record shows an agent did is its signed instruction, the verdict and, where your release point returns one, the release receipt: an allow on its own is not proof that a payment was made.
“Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance.”
Model Risk Management: Revised Guidance · OCC Bulletin 2026-13, issued jointly with the Federal Reserve (SR 26-2) and the FDIC · 17 April 2026
Why now
There is no supervisory rulebook for agents that move money. There is still an examiner.
In April 2026 the banking agencies rescinded SR 11-7 and placed generative and agentic AI outside the replacement guidance. The request for information they promised had still not been published as of mid-September 2026, and the replacement third-party risk guidance the same agencies published for comment on 15 September 2026 does not mention AI. The rest of the rulebook still applies — safety and soundness, third-party risk management, BSA/AML and, for covered entities, NYDFS Part 500 — and sponsor banks are required to obtain evidence from their fintech partners. Institutions have to show it themselves.
The framework excludes agents.
Revised interagency model risk guidance names generative and agentic AI as out of scope, and states that non-compliance will not result in supervisory criticism. It leaves the governance and controls for what it excludes to each bank’s own risk management. The model-risk yardstick no longer covers agents; the exam still does.
OCC Bulletin 2026-13 · FRB SR 26-2 · FDIC FIL-15-2026 · 17 Apr 2026
Autonomy and auditability are named risks.
FINRA’s 2026 oversight report lists “AI agents acting autonomously without human validation and approval” and multi-step reasoning that is “difficult to trace or explain” among the risks of AI agents, and says firms may need supervisory processes specific to the agents they deploy.
FINRA 2026 Annual Regulatory Oversight Report · 9 Dec 2025
Least prepared where it counts.
Asked which part of AI incident response their institution is least prepared for, 72% of US banking professionals picked one of two: reporting an AI failure to a regulator (37.8%) or a model kill-switch protocol (34.4%).
Wolters Kluwer US Banking AI Risk and Governance Index · 28 May 2026 · 230 US banking professionals
Four in five fraud and risk leaders worldwide say their institution has already encountered attacks using agentic AI (BioCatch, 2026 Future of Digital Trust, 10 June 2026; 1,440 leaders, 25 countries). Visa’s rules now require agent platforms in its agentic-commerce program to register, and Mastercard says its agentic tokens are built to register, verify and recognize agentic transactions; American Express says its own agent-registration specification is still under development. The operating rules of the bank rails — ACH, RTP, FedNow — contain no AI-agent provision. No network can tell an institution whether its agents stayed inside the institution’s own policy across all the rails it uses, or hand its examiner that record. That job belongs to the institution.
Product
Three layers. One system of record for agent authority.
A gateway in the path of your agents’ money-moving instructions. A ledger that makes every recorded decision — and every recorded change to who may make one — tamper-evident and verifiable by a stranger. Evidence packs written for the person who has to sign the exam response. The sixth part proposes changes to the control set when the guidance changes underneath it. Everything below describes the product being built; none of it is running for customers yet.
Mandates
A signed grant of authority: this agent may take these actions, on behalf of this principal, within these limits, until this date. Issued by a named person signing with their own credential; revoked at a recorded instant, after which the gateway refuses the next instruction under it and outstanding authorizations stop at verifying release points within their freshness window. The record of authority an examiner is likely to ask for.
Policy and limits, in line
Per-transaction, daily, per-counterparty and fleet limits, novel-counterparty holds, channel restrictions and time windows — evaluated before release — designed for a p99 under fifty milliseconds — with the policy version and every evaluated value recorded in the verdict.
Maker-checker and kill switch
High-risk instructions hold for a qualified human who is shown what the agent proposed and signs over exactly that instruction; the signature does not by itself show what the person read. One switch stops new authorizations for an agent, a class of agents or everything, and records what it refused, when, and what was still outstanding. In enforcement it stops new Custogent authorizations the moment it is recorded, and blocks pending releases at every release point that verifies our token within the freshness window you set; where a release point does not verify tokens, it stops new authorizations only.
Tamper-evident, quantum-safe
Append-only, hash-chained, Merkle-tree records with checkpoints signed twice — classical and post-quantum (ML-DSA) — timestamped by an RFC 3161 authority and a second, separately operated anchor, and kept in retention-locked storage (S3 Object Lock, compliance mode), with a replicated copy in your own account. Verifiable offline by anyone holding the evidence pack, with our published keys, an independent timestamp and the published verifier.
Evidence packs and replay
A signed bundle for a period: a control narrative mapped to named sources, the receipts that support each control assertion, exceptions, approvals, kill-switch tests and disclosed gaps — and replay: would this instruction have been held under the policy in force in March? Mappings are not an examiner’s approval.
Regulatory watch
Guidance, standards and rail rules from named sources held as versioned data. When a watched source changes — the promised interagency request for information included — the change arrives as a proposed difference against your control set, reviewed and approved by a person, with the whole trail on the ledger. It does not promise complete coverage or compliance.
Custogent is not a payment processor, a fraud model, an agent framework or an identity provider. It never screens, and never substitutes its own judgment for yours: every policy verdict is your own policy version applied to your own inputs, and the gateway’s own safety rules produce only a hold. It sits beside all of them and records what they submitted, decided and reported, and under which rules. Every deployment starts in shadow mode — record only, nothing blocked — and moves to enforcement only when the readiness conditions below are met and the institution signs the approval. Where the institution’s own gate enforces, the deployment stays an evidence-only mode, labeled as such.
How it works
One integration in the agent. One chokepoint across the release points you connect. One record the examiner can check alone.
A recorder alone does not block a payment.
The gateway is on the path. A verdict is a decision, not a log entry. In enforcement mode — where your release point verifies our token, or our adapter in your environment does — the agent cannot proceed without it. Where your own gate enforces, we record your gate’s decisions and recompute them against your policy version, and every pack says the gate was yours; where neither, every evidence pack says so. It fails closed: no mandate, no policy snapshot, or no screening result where your policy requires one means hold, never allow.
You do not have to take our word for the calculation.
Every checkpoint is signed with a classical key and a post-quantum key, timestamped by an RFC 3161 authority and a second, separately operated anchor, and kept in retention-locked storage. An examiner holding the evidence pack, our published keys, an independent timestamp and the standalone verifier can check its records without an account, without our systems or yours, and without asking us. The report names what it still depends on: whose keys, whose assertions, which anchors.
The policy that governed a decision is named in the decision.
Each verdict carries the exact policy version and every value it evaluated. A recorded instruction can be re-evaluated under another policy version when the inputs that version needs were recorded; a counterfactual run is labeled as one and states what it assumed — for a dispute, a lookback exam, or to show a proposed change would have caught the case that worried you.
Financial services first, on a core that carries no industry vocabulary.
The definitions of mandates, instructions, verdicts, approvals and receipts do not mention money. The financial-services pack supplies the rails, limits and control mappings; other regulated industries are a design goal on the same core, not an available capability.
Trust
What the record proves, and what it does not.
This is the design being built, stated with its limits, because a security team will find the limits anyway. Nothing here is a certification or an audit opinion.
Integrity and transport, not everything.
Checkpoints are designed to be signed with ML-DSA-65 as well as EdDSA, and the load balancers are specified for hybrid post-quantum key exchange with clients that support it. This is not an end-to-end post-quantum claim. No timestamp authority issues post-quantum tokens today, so time is anchored by an RFC 3161 authority and a second, separately operated anchor; timestamps are renewed while they are still trustworthy, moving to post-quantum authorities as they appear.
What the certificate covers.
Signing keys are to live in AWS KMS hardware validated to FIPS 140-3 Level 3. That module’s current certificate lists neither ML-DSA nor EdDSA among its approved algorithms. We say so because you would find out.
“Valid as of”, never “valid now”.
The verifier reports “valid as of registry version N at checkpoint M”, because an offline verifier cannot know what was revoked after the pack was built. For each thing it reports, it names whose key, whose copy, whose observation or whose authority would have to fail for it to be wrong.
Small enough to check ours.
Policies are written in a small, closed, formally specified rule language, so anyone can write their own interpreter and check ours. A formally specified language is not a formally verified interpreter; that is why the verifier is a separate implementation with a reproducible build.
No recovery path, so every role has two.
Approvers sign with credentials they hold themselves. There is no recovery path, not through us and not through a help desk. Enforcement cannot start without at least two people enrolled for every approving role; a later period in which a role falls to one is flagged in that period’s evidence pack.
No model takes part in a verdict.
Models help draft and classify for Regulatory watch and run Custogent’s own agents. None of them sees your data until you enable it by a signed approval, and every model call is recorded before it is sent.
Where your own gate controls release, the kill switch stops new authorizations where applicable and asks your gate to stop the specified new releases; delivery and effect depend on your gate and are reported separately, an acknowledgement is not independent proof that releases stopped, and nothing already committed is recalled. A checkpoint commits every tenant’s chain head in its cell: the number of entries reveals how many tenants the cell serves, and the published format will state what else checkpoints can reveal.
Who it’s for
Can you show your sponsor bank — or your examiner — every recorded instruction your AI agents submitted last quarter, the authority each acted under, the policy in force at the time, who approved each exception, and show that the record has not been altered since it was committed?
If assembling that answer would take longer than a day, or would rest on “we prompt the model carefully”, that is the conversation. Fintechs and agent builders deploying money-moving agents feel it first, because a sponsor bank is required to obtain evidence from its fintech partners, and asks. Banks feel it next, across their own agents and their partners’.
There is nothing to buy. Thirty minutes on how that question is landing at your institution is worth more to both of us than a demonstration would be, and it is the only thing being asked for.
The functions this usually sits with
- 01Compliance and risk at a fintech deploying agents
- 02Payments or platform engineering — the team that must not be slowed down
- 03Third-party risk and BSA at a sponsor bank
- 04Model risk and AI governance at a bank
Stage
Pre-launch, and saying so.
Custogent is being built now, and is looking for a small number of design partners: regulated institutions willing to argue the control set out against their own examinations and their own sponsor-bank reviews rather than inherit someone else’s.
There is no product to sell you yet. That is the reason to talk early rather than a reason to wait — design partners shape which controls come first, within fixed security boundaries, and the first evidence pack a sponsor bank reviews should be one of theirs.
Before a bank switches to enforcement, it shows us six things: a release point that checks our token, its own continuously replicated copy of the record, a named contact, at least two approvers for every approving role, a rehearsed incident notice, and a verifier it has run on its own pack.
Founder
Sheo Jha
Founder, Custogent. Formerly Risk Officer, U.S. Securities and Exchange Commission, Enforcement Division.
CISSP · CISM · CRISC
BS EE, IIT Kanpur · MBA, The George Washington University
Sheo spent twelve years as a Risk Officer in the U.S. Securities and Exchange Commission’s Enforcement Division, where he built and led its Governance, Risk and Compliance program, leaving in March 2026. He is Chief Innovation Officer at Ankore Consulting, a risk and technology advisory firm he co-founded in 2010.
Custogent exists because the examiner’s questions — who authorized this agent, what could it do, what rule was in force, who approved the exception, and can you prove the record is intact — have no answer yet for an agent that can move money on its own. The answer has to be built into the path the money takes, and it has to be checkable by someone who does not trust the vendor.
Contact
Request access, or just start the conversation.
Access is by request and by conversation — there is no self-service signup, no trial and no login on this site. Tell us who you are and what you are looking at; a person replies.
- Generalinfo@custogent.com
- Security reportssecurity@custogent.com · security.txt
- LocationCharlotte, North Carolina
No contact form by design: nothing is collected on this page, and a form processor would be a subprocessor to disclose on your questionnaire. Requests arrive as ordinary email.