Heritage Community Bank
Governed AI for Regulatory Control Assessment
Prototype Demonstration
Prepared for practitioner review and methodology validation

Enterprise AI should not replace professional judgment — it should make professional judgment transparent, repeatable, and reviewable.

This demonstration showcases the next generation of the CRI Coverage Assessment methodology that began during the Heritage Community Bank engagement. Rather than manually assessing hundreds of controls against security requirements, the CRI Assessor applies a governed, transparent methodology that combines structured profiles, deterministic reasoning, semantic analysis, and human review to produce repeatable coverage assessments.

Every conclusion can be traced back through a Coverage Decision Record, allowing reviewers to understand, validate, and challenge each determination.

Heritage transforms regulatory interpretation from an opaque AI response into a governed, evidence-backed decision process that professionals can review, challenge, and reproduce.

This is not a report generated by AI. It is the output of a governed assessment methodology designed to support professional judgment.

CRI Assessor — Physical Architecture: Secure, Governed, Model-Independent, Client Data Stays Local

The Arthur Knowledge Repository is the platform. CRI v2.2 is the first assessment application — the architecture supports any regulatory framework.

Explore the Methodology
PR
Coverage Assessment Report
Experience the completed assessment, inspect individual coverage decisions, and review the human concurrence workflow
CL
Control Library
Explore the structured control library used throughout the assessment — every report finding links directly to its originating control
DA
Deployment Architecture
How the CRI Assessor uses AI without exposing client data — privacy-first two-component design
TX
Control Profile Taxonomy
The 6-dimension classification vocabulary that powers compatibility reasoning — 568 controls profiled, 318 DS to cover
RM
Research & Publication Roadmap
Five credibility milestones from methodology engineering through ISACA publication — building evidence, not features
F5
External Methodology Review
Fable 5 independent assessment of the Docker client delivery package and MCP Knowledge Server — findings, severity ratings, and action plan
Why This Matters

Organizations spend significant effort manually determining whether existing controls satisfy regulatory and cybersecurity requirements. The CRI Assessor demonstrates a governed, transparent methodology that makes those determinations repeatable, explainable, and reviewable.