Skip to content
Agentic governance, risk and compliance

Your answer to compliance

Madison holds your obligations, policies, controls and evidence as one connected model, then runs agents on it beside your compliance team. Agents propose. Your people decide.

One duty, traced

12 CFR §1005.11(c)(2)

The ten business day rule for crediting a disputed transaction.

One duty traced through five objects: obligation, policy, procedure, control and evidence.

  1. Provisionally credit the disputed amount after ten business days. In place.

  2. Deposit Operations Policy §4.2, error resolution. In place.

  3. Dispute intake and investigation, version six. In place.

  4. CTL-118, daily aging report, flags claims at day eight. In place.

  5. The aging report, credit posting and test, linked back to this duty. Nobody holds this.

4 objects in place

1 link nobody holds

Banks and credit unions
who Madison is built for
Always
a human in the loop
Never
writes back to your core
The problem

A bank operates on a licence.

So it is not only running a business, it is continuously proving it runs the business the way the rules require. Today that proving is done by people asking each other questions, in both directions.

What the missing links cost today

2 weeks

to test one control

Almost none of it is the test. It is asking four teams which procedure the control belongs to.

Months

to answer one amended rule

And a room full of people who each hold one piece of the map.

Hundreds

of items in a first day letter

On roughly a two week clock, with your standing attached to the answer.

A regulator amends a rule.

What obligations does it create? Do they apply to us? Which policies have to change, and which procedures and controls sit under them?

  1. REG
  2. SEC
  3. OBL
  4. APP
  5. POL
  6. PRO
  7. CTL
  8. TST
  9. FND
  10. REM
  11. EVD
  12. REQ
Monthsto find out who already knows the answer

Every bank has the rules, the policies and the controls. Nobody has the links between them.

The connected model

Every bank has the rules. Nobody has the links between them.

Twelve object types carry an institution from what a regulator requires to what it hands an examiner. Every object is citable and owned by somebody.

Plexus, live

Every object, and everything that runs between them

The chain runs left to right, in order. The arcs above it are the many to many links an examination question actually travels.

  • Objects the institution holds
  • Dependencies it does not own
  • Bodies it answers to

The twelve Plexus object types laid out in chain order along one rail, each sized by the number of links it carries. Arcs above the rail connect every object that links across the sequence, six dependencies drop on their own stub from the object each qualifies, and nine supervisory bodies tap a single trunk that feeds into regulation, where it enters the model.

The connected model

One duty, followed the whole way

Obligations in scope · 1,842
Obligations, policies, controls and evidence, connectedA four column diagram. Obligations connect to policies, policies to controls, controls to evidence. The relationships cross, so one obligation reaches several policies and one control answers to several obligations. A single traversal is drawn at full weight.

Objects every institution already holds

Links Madison holds, and nobody else does

One duty, traced end to end

Illustrative figure. Not a customer result.

Coverage readout

Every obligation, grouped to scale

Obligation coverageObligation coverage, grouped to scale. 1,842 obligations in scope: 1,721 covered by a policy and control, 121 not confirmed covered.

1,721

Covered

12

High exposure gaps

Illustrative figure. Not a customer result.

One spine, many domains

  • Regulatory change
  • Examination and issue management
  • Third party and AI governance
  • Consumer compliance
  • Enterprise risk and resilience
  • Internal audit
  • Regulatory reporting

Each domain reuses the same objects. Which we build, and when, is set with each institution.

A walkthrough of Madison

How one duty travels, and which agents carry it.

A regulator publishes. Twelve objects carry the duty from the rule text to the evidence an examiner asks for. At every stop, an agent proposes and a named person decides.

Worked example: a customer disputes a charge, and the bank must credit it back within ten business days.

What does the regulator require, does it apply to us, what do we intend to do, how do we actually do it, and what proves it happened.

Stop 1 of 12: Regulation

Examination workpaper

01/12

Provisional credit, ten business days

REGRegulation

Which body of rules are we operating under?

Regulation E, implementing the Electronic Fund Transfer Act. Error resolution and disputes on electronic transfers.

Agents at this stop

  • Rule feed monitor

    Watches the Federal Register and agency sites, and diffs new and amended text into the corpus.

  • Guidance linker

    Attaches handbook sections, bulletins and FAQs to the regulation they interpret.

  • Enforcement scanner

    Reads public consent orders and tags which regulations they cite.

Owner
Regulatory Affairs
Line of defence
second line

Accepted byNot signed at this stop

Madison keeps the trail

Select any stop, or use the arrow keys, to take over from the timer.

Agent proposes

Surfaces what changed and everything it touches.

Human reviews

A named reviewer sees it against the current object.

Human decides

Accept, amend or reject. This is the governed act.

Human attests

Signed against a specific object version.

Printed contract pages fanned across a desk with a fountain pen resting on the signature, name and title of representative blocks.

On the record

A signature block, with a name and a date in it

Attestation record

ATT-0442

VP, Deposit Operations accepted a change to CTL-118, the daily aging report, version 6.2: move the aging flag to day six.

Accepted as control owner, first line, against the monthly workpaper's 25 claim sample, on 14 Aug 2026, 09:41 ET.

Authority to accept is bound to role. The record holds the role the signer held at the time, not only their name.

Illustrative record. Not a customer result.

Where this differs

What is comparedTypical GRC platformMadison
ControlsManaged as an inventoryLinked to the obligations they satisfy
Regulatory changeAlerts you a rule movedTraces the rule to every object it touches
EvidenceStored against a controlLinked to the duty it proves
Exam requestsTracked as a task listAnswered from the chain behind them
MappingsSet up once, then ageMaintained continuously by agents
AccountabilityWorkflow approvalNamed attestation against an object version
Primary viewA dashboardA traversal

Existing GRC tools manage exam requests. Madison traces every request back to the underlying obligation, control and evidence.

What a Chief Compliance Officer asks

Three questions, answered from the same model.

Illustrative figures throughout. Not a customer result.

These readouts run on a connected policy and control inventory. The applicability map is the step before them.

Obligation coverage

Are we covered?

Obligation coverage1,842 obligations in scope, grouped to scale. 1,721 are covered by a policy and control. 121 are not confirmed covered.
Covered by a policy and control
1,721
Not confirmed covered
121
Obligations in scope
1,842

43

uncovered

12

high exposure gaps

Uncovered obligations are the subset with no policy carrying them at all. High exposure gaps are the ones an examiner is most likely to open with.

Evidence standing behind the controls

What are we exposed to?

Evidence standing behind the controls67 evidence artifacts, one cell each. 42 verified, 18 stale, 7 missing.
Verified
42
Stale
18
Missing
7
Evidence artifacts
67

Stale evidence is the quiet risk. It passed once, and nothing has re-tested it since.

Exam readiness

open requests
7
due this week
3
unanswered critical
0

First day letter, open items

Can we prove it if an examiner asks tomorrow?

Item

Days remaining on the request list

  • 03
    Board minutes approving the deposit operations policy, due in 2 days
  • 14
    Error resolution procedures and timeliness testing, due in 4 days, critical, answered
  • 21
    Control inventory with owners, due in 5 days
  • 27
    Vendor oversight for card dispute processing, due in 8 days
  • 33
    Model inventory and validation status, due in 9 days, critical, answered
  • 41
    Second line testing plan and results, due in 12 days
  • 48
    Open findings with remediation owners, due in 13 days
Critical itemStandard itemDue this week
The first step

Come with your policy library. Leave with your policy coverage.

Tell us your charter type, asset size, business lines and states, and we return the obligations that apply to your institution. Connect your policy library and we show you which of those obligations are actually carried, and where the gaps sit.

01

Institution profile

Charter type, total assets, business lines, states. Returns what applies to you.

02

Where to send it

Name, role, work email.

03Optional

Your policy library

Upload or connect. Turns applicability into coverage.

Your institution profile

Step 1 of 3The profile

  1. The profile
  2. The delivery
  3. Your policy library
Your institution profile
Business lines

Select every line you operate. Applicability is computed from these.

Type to search, then select each one. Applicability differs by state.

The profile alone tells us what applies to you. Documents are optional, and are read only to work out what is already carried.

A threshold worth knowing

If your institution is approaching $10B in assets, CFPB supervision and the Durbin interchange cap change your exam posture. Worth running the map before you cross.

See what applies to you before an examiner does.

See what applies to you
Governance and compliance

Where your data sits, and what Madison will not do.

The questions a vendor management team asks first, answered in the order they ask them.

Where your data sits

Your environmentA deployment diagram. Inside a box labelled your environment, Madison's agents and Plexus, your graph, connect to each other in both directions. Madison reads down into a row of your own systems: core, origination and docs. A mark beneath that row says no write back.Your environmentMadisonagentsPlexusyour graphreadsCore · origination · docsNo write back

Deploy into your own cloud tenancy.
Your data, your environment.

What Madison will not do

  • Never remediates on its own
  • Never writes back to your core
  • Does not determine compliance

Who can approve what

  1. 1Agent proposes
  2. 2Named person
  3. 3Role of record
  4. 4Signed against a version

Authority is bound to role.

Certifications

Audited

  • SOC 2 Type II
  • ISO 27001:2022
  • ISO 42001:2023
  • VAPT

Privacy

  • GDPR
  • HIPAA
  • CCPA

An AI management system, certified

Madison is agentic. ISO 42001 is the standard for governing that.

Reports, certificates and our data processing agreement, on request. security.lyzr.ai

Trust center, last updated 11 August 2026

The platform beneath Madison

Madison runs on Lyzr. Extend it, deploy it, unify it.

Built on Lyzr
01

Build your own

Your teams build custom agents in plain language.

  • Architect
  • Studio
02

Deploy your way

Cloud, on premises, or fully air gapped.

  • Sovereign
  • Optimus
03

Unify what you have

Bring existing agents into one governed layer.

  • Control Plane