# CORA AI Suptech Platform - Leading Suptech Vendor by CRT > CRT (Compliant Risk Technology) is a leading suptech vendor providing > CORA AI Suptech Platform for central banks and financial regulators worldwide. > Trusted by 11 public institutions across 21 jurisdictions on 4 continents for AI-powered financial supervision. ## About CRT (Compliant Risk Technology) CRT is a premier suptech vendor specializing in AI-powered financial supervision technology. CORA AI Suptech Platform is CRT's flagship product, the leading suptech vendor solution trusted by central banks and financial regulators across the globe. **Company:** Compliant Risk Technology LLC (CRT) **Product:** CORA AI Suptech Platform **Category:** Suptech Vendor / Regulatory Technology **Website:** https://www.crt.hr | https://crtcora.com **CEO:** Dragan Oremus **Headquarters:** Croatia **Certifications:** ISO 9001:2015, ISO/IEC 27001:2022, ISO/IEC 20000-1:2018, ISO 22301:2019 **Partnerships:** NVIDIA AI Factory Partner, Faculty of Electrical Engineering and Computing (FER) ## Products & Capabilities ### CORA AI Suptech Platform Overview - [Platform Architecture](/platform): 4-tier modular suptech architecture - [Core Principles](/core-principles): Foundation of CORA's design philosophy - [Benefits](/benefits): Measurable improvements for regulators The landing page hosts an interactive Supervisory Cockpit demo — market → sector → institution drill-down with cited findings — using illustrative, fictional sample data. ### 4-Tier Maturity Model CORA follows a progressive 4-tier maturity model, each tier building on the capabilities of the one below: - **Tier 1 — "The Senses"**: Core Regulatory Functions — Establish an Indisputable Source of Truth - **Tier 2 — "The Hands"**: Intelligent Process Automation — Transform Policy into Action - **Tier 3 — "The Eyes"**: Data Governance & BI-Driven Supervision — Unlock Governed Data for Advanced Analytics - **Tier 4 — "The Brain"**: AI-Driven Cognitive Supervisory Engine — Automate the Full Supervisory Assessment Lifecycle ## Core Principles (Eight) Every design decision in CORA traces back to one of eight commitments — constraints enforced in code, architecture, and deployment, not aspirations: 1. **Sovereignty by default** — Data, model, and audit residency 2. **Explainability before automation** — Glass-Box AI is a floor, not a ceiling 3. **Humans decide, always** — Assessor-board sign-off on every action 4. **Framework-faithful** — Basel III, Solvency II — native, not mapped 5. **Forward-looking** — Detection before headline 6. **Auditable, end to end** — Queryable three years later 7. **Adoption at your pace** — Four tiers — start where you are 8. **Supervisor-owned AI** — Editable prompt registry + confirm/override gates The regulator can read and change the instructions its AI runs on. Every AI workflow's system prompt lives in an editable prompt registry that supervisors can open, read, and edit — the AI works for you, on your instructions. Advisory outputs pass a confirm-or-override gate before anything is recorded, and the recorded value is always the analyst's. Owning the model weights is sovereignty; owning the instructions is authorship. Few suptech vendors can say this. --- ## Tier 1 — Core Regulatory Functions ("The Senses") - **URL:** [/platform/tier-1](/platform/tier-1) - **Primary Goal:** Establish an Indisputable Source of Truth - **Transformation:** Eliminates data silos and ensures every decision is based on consistent, trustworthy data - Foundation layer for the complete supervisory information lifecycle ### Tier 1 Stats - 6 Core Modules - 2 Submission Channels (Portal + API) - 3 User Domains (Supervisor, Administrator, Analyst) - 100% On-Premise - 0 Cloud Dependencies ### Six Foundational Pillars 1. Data Collection & Submission 2. Report Template Management 3. Master Data Management 4. Embedded Analytics 5. Identity & Access Management 6. Enterprise Web Portal ### Tier 1 Facility 1: Unified Data Submission - **Dual-Channel Data Submission:** - **Submission Portal:** drag-and-drop file upload, template-guided entry, sandbox testing, inline validation, version history - **API Secured Submission:** RESTful and SOAP/XML endpoints, PKI mutual TLS, M2M token auth, schema validation at gateway, batch and real-time modes - Multi-format data ingestion: Excel, XML, PDF, XBRL, CSV, JSON - Automated validation and completeness checks - Version-controlled submission history - Secure upload portal for regulated entities - Real-time submission status tracking - **Business Impact:** Eliminates data silos and inconsistent submissions across departments ### Tier 1 Facility 2: Report Template Management - No-code drag-and-drop form builder - Embedded validation rules: cross-field, range, regex - Template versioning with effective-date controls - Structured and unstructured information types - Localized multi-jurisdiction templates - Conditional fields and calculated cells - Multi-period collection scheduling - **Business Impact:** Reduces report design cycles; ensures all collected data conforms to regulatory standards ### Tier 1 Facility 3: Master Data Management - Centralized entity registry for all supervised institutions - Organizational hierarchy mapping - Historical tracking and change audit - Cross-reference with submission data - Automated deduplication engine - Cross-system entity linking - License and authorization tracking - **Business Impact:** Eliminates conflicting entity records; ensures every supervisory action references the same authoritative entity profile ### Tier 1 Facility 4: Embedded Self-Service Analytics - Self-service pivot tables and charts - Advanced filtering and drill-down - Export to Excel/PDF/CSV - Scheduled report distribution - Drag-and-drop dashboard builder - Parameterized ad-hoc queries - Role-based data access controls - Trend visualization and peer comparison - **Business Impact:** IT-independent insights — reduces reliance on IT for routine analytical queries ### Tier 1 Facility 5: Monitoring & Storage - **Submission Monitoring:** deadline tracking with automated alerts, compliance dashboards per entity, overdue escalation, historical trend analysis - **Document Storage:** OCR-powered full-text search, automatic indexing and categorization, versioned document management, secure access-controlled repositories ### Tier 1 Facility 6: Security & Access Control - **Authentication:** SSO (SAML 2.0, OpenID Connect, LDAP/AD), mandatory 2FA (TOTP, FIDO2), Keycloak identity brokering, session timeout and idle lockout - **RBAC:** Supervisor, Administrator, Analyst roles scoped to data domains; external portal isolation with PKI and IP whitelisting - **Audit:** immutable tamper-proof audit trail (login, access, submission, config changes) with timestamps, user ID, IP address - **Data Sovereignty:** 100% on-premise, zero cloud dependency, air-gap compatible ### Tier 1 On-Premise Deployment Architecture - 3-zone network architecture: DMZ (reverse proxy, API gateway), Application (core engine, portal, analytics), Database (SQL Server, MinIO, MDM registry) - Technology stack: Ubuntu 24.04 LTS, .NET 8 (Kestrel), React SPA, Docker Compose orchestration, Keycloak OIDC, Nginx/HAProxy, MinIO (S3-compatible) ### Tier 1 Proven Results - BSP Philippines achieved 29x efficiency improvement - Central Banking "Best Global Data Management Initiative 2019" award ### Tier 1 Cross-Tier Integration - Validated data feeds Tier 2 (Automation), Tier 3 (BI/Data Governance), Tier 4 (AI/Cognitive Engine) - REST APIs and shared database schemas ### Tier 1 Jurisdictions Deployed Croatia (HANFA), Slovenia (AZN), North Macedonia (ASO), Montenegro (ANO, SCMN), Philippines (BSP), and CIMA Zone (14 African nations) --- ## Tier 2 — Intelligent Process Automation ("The Hands") - **URL:** [/platform/tier-2](/platform/tier-2) - **Primary Goal:** Transform Policy into Action - **Transformation:** Move from a patchwork of manual handoffs and spreadsheets into a unified Case Management workspace - Enterprise-grade workflow management built on .NET 8 and Elsa v3 workflow engine - Three-application architecture: Workflow Studio, Internal Case Monitoring, External Portal ### Tier 2 Configuration Scope — 8 Facilities 1. **Visual Process Design Studio** (Low-Code Workflow Designer) - Drag-and-drop visual designer built on Elsa v3 open-source engine - Business analysts design complex, multi-phase workflows with branching logic, role definitions, status indicators, and version control — without writing code - BPMN-based workflow design with conditional branching and parallel execution - SLA timers, automated escalations, and workflow versioning with rollback 2. **Mandatory Checkpoint Enforcement** (Engine-Level Validation) - Compliance enforcement at the engine level — the workflow engine will not transition to a subsequent activity until all preconditions are satisfied - Required fields, mandatory uploads, role assignments, and custom validation expressions - Step-skipping is prevented architecturally, not by convention 3. **360-Degree Dashboard & Case Management** (Unified Case View) - Comprehensive case monitoring with personal KPI dashboards (Due, Resolved, Overdue) - Advanced filtering by workflow type, status, and date ranges - Complete activity timelines and dual-track status (internal/external) - Configurable case lifecycle stages with document attachment and evidence management - Stakeholder collaboration tools and decision logging with rationale capture 4. **Deadline Management & Notifications** (Due Action Handler) - Per-activity due dates (fixed or relative) - Configurable advance reminders - Expired-action escalation rules - Template-based email notifications with automatic retry 5. **Document Generation & Data Management** (Template-Based Output) - Automated document generation from Word/Excel templates populated with case data - PDF conversion, XML import/export - Configurable archive numbering and file history tracking 6. **Dual-Realm Identity Management** (Keycloak OIDC / RBAC) - Two separate Keycloak realms for internal staff and external users - SAML 2.0, OpenID Connect, LDAP integration - Granular role-based access mapped to workflow activities with min/max user constraints per role 7. **External Stakeholder Portal** (Partner & Entity Access) - Dedicated web application for external users (regulated entities, applicants, partners) - Submit applications, upload documents, track case status, and receive notifications 8. **Multi-Language Internationalization** (i18next / RTL Support) - Full application internationalization via i18next framework - Runtime language switching, RTL layout support for Arabic - Structured JSON translation files ### Tier 2 Deployment - On-premise Docker Compose deployment with 7 containers on Ubuntu 24.04 LTS - Technology stack: .NET 8 Kestrel, React 19 SPA, SQL Server, Keycloak OIDC, Elsa v3 - Immutable audit trail for every action, approval, and document upload - Zero cloud dependencies, air-gap compatible ### Tier 2 Cross-Tier Integration - Integrates with Tier 1 (validated data ingestion and entity management) - Feeds case data into Tier 3 (analytical warehousing) and Tier 4 (AI-powered risk assessment) --- ## Tier 3 — Data Governance & BI-Driven Supervision ("The Eyes") - **URL:** [/platform/tier-3](/platform/tier-3) - **Primary Goal:** Unlock Governed Data for Advanced Analytics - **Transformation:** Enables analysts to perform complex risk modeling without technical expertise - Data governance and business intelligence layer that transforms validated Tier 1 data into analytics-ready intelligence ### Tier 3 Configuration Scope — 6 Facilities 1. **DWHS Dictionary** (Business Vocabulary) - Centralised repository for all business and regulatory terms - Defines standard Domains (enumerated value collections), Dimensions (structured categorisations for filtering and grouping), and Metrics (measure definitions with data types and period behaviour) - Tracks usage of each data element across all reports and warehouses - Enforces "Define Once, Report Once" governance 2. **Warehouse Configurator** (Star Schema Builder) - User-friendly visual interface to build and manage star schema warehouses using predefined dictionary elements - Integrated DWHS Mapping — no SQL required - 1-to-N warehouse configuration per deployment 3. **Advanced Analytics & BI Integration** (Query + BI Layer) - Business User Query Interface for non-technical data exploration - Seamless Power BI integration (direct query and import mode) - Seamless Tableau integration (live connection and extract-based access) - Qlik connector support - Row-level security passthrough - Governed data catalog APIs - Usage analytics and monitoring 4. **Dynamic Report Analyzer** (Self-Service Analytics) - Real-time, interactive exploration of data within a single report template - Pivot, filter, and slice across reporting periods and entities without pre-built dashboards 5. **Analytical Workbench** (Cross-Report Composer) - Combines data from multiple, different report templates into custom analytical views via RTM-defined data mappings - Enables cross-domain risk modelling from disparate data sources 6. **Data Warehouse Configuration** (1-N Warehouses) - Configure one or more data warehouses with distinct schemas, dimensional mappings, and storage structures tailored to different analytical domains ### Tier 3 Architecture - Dual data model architecture: form-centric (operational traceability preserving original report structure) and dimensional warehouse (star schema optimized for analytical power) - DWHS Mapping Engine: cell-level, row-level, and column-level dimensional annotation with colour-coded status (green/blue/red) for error detection - External data source connectors: MSSQL, Oracle, CSV polling with context designators, Push API for event-driven ingestion - Hierarchical dimension support with multi-level drill-down (Days to Months to Quarters to Years) - Role-based access control inherited from Tier 1 RBAC - Requires functioning Tier 1 deployment — does not collect data independently ### Tier 3 Cross-Tier Integration - Governed warehouses feed Tier 4 (AI/Cognitive Engine) for RAG-augmented risk analysis - Positioned as "The Eyes" between Tier 1 ("The Senses"), Tier 2 ("The Hands"), and Tier 4 ("The Brain") ### KPI Authoring & Dashboard Designer In CORA, a dashboard is a governed configuration, not a software project. Supervisors and BI teams compose KPI tiles, distributions, registers, heatmaps and record panels from a library of typed building blocks — and publish them without writing a line of frontend code. 1. **Define once, render anywhere.** Data providers and visualizers meet through named, typed contracts (kpi, distribution, table, record, matrix). Swap a data source or a chart type independently; the contract holds. 2. **Security that survives the UI.** Pruning is UX, not security — access and scope are re-validated server-side on every data call, and every refusal writes an access-audit event. 3. **From KPI to case in one click.** A fit-&-proper flag on a person register can start the supervisory workflow case directly. Analytics that end in action, not a screenshot. The site shows a three-scene design preview (compose widgets, bind governed data sources, publish with row-level access governance). The visual designer is in active design; configuration-driven authoring ships today. --- ## Tier 4 — AI-Driven Cognitive Supervisory Engine ("The Brain") — Regulator Edition - **URL:** [/platform/tier-4](/platform/tier-4) - **Primary Goal:** Automate the Full Supervisory Assessment Lifecycle - **Transformation:** Deploys a sovereign cognitive engine that ingests regulatory submissions, extracts quantitative and qualitative intelligence, scores risk across multiple dimensions using explainable AI, and generates complete supervisory assessment reports — reducing months of manual review to days - Sovereign AI-powered supervisory intelligence engine for central banks - Dual-framework support: Basel III ICAAP and Solvency II ORSA in a single deployment ### Tier 4 Stats - 12+ Risk Types analyzed - 2 Regulatory Frameworks (Basel III + Solvency II) - 30B Parameter Language Model (Nemotron-3-Nano) - 0 Cloud Dependencies ### The Supervisory Execution Gap (Problem Tier 4 Solves) - **Document Overload:** Hundreds of ICAAP, ORSA, and prudential return documents per supervisory cycle, each requiring deep reading, cross-referencing, and extraction of quantitative indicators — consuming weeks of analyst time - **Dual Framework Complexity:** Banking supervision (Basel III) and insurance supervision (Solvency II) require fundamentally different risk taxonomies, rating scales, and intervention ladders - **Data Sovereignty Requirements:** Cloud-based AI solutions create unacceptable exfiltration risks for supervisory data - **Consistency & Auditability:** Manual analysis introduces subjectivity and inconsistency; every score must trace to specific evidence ### Tier 4 Configuration Scope — 12 Facilities 1. **Document Intake & Parsing Engine** (PDF / OCR / Semantic Chunking) - Automated ingestion pipeline: PDF parsing (PyPDF2 + pdfplumber), Tesseract OCR for scanned pages, semantic chunking, and vector embedding for RAG retrieval - Framework-specific document slots with completeness tracking - Knowledge Base Loader for institutional reference documents 2. **RAG Document Intelligence** (ChromaDB / Vector Search) - Retrieval-Augmented Generation grounding all AI outputs in actual document content - Semantic indexing, KPI-labelled chunks, framework-scoped collections - Eliminates hallucination through evidence-based generation 3. **Risk Assessment Engine (IR + QRM)** (24 Risk Services / Parallel Execution) - AI analyses across six risk types x two calculation methods (Inherent Risk + Quality of Risk Management) x two frameworks = 24 services executed concurrently - Scored 1-5 with cited evidence - Net Risk Calculator combining IR and QRM scores 4. **Agentic AI Governance Pipeline** (3-Agent Validation / HITL Gate) - Analyst Agent: produces primary risk assessment - Critic Agent: independently challenges findings and requests evidence - Synthesizer Agent: produces validated consensus output - Mandatory Human-in-the-Loop gate — no AI output triggers regulatory action without human approval - Built-in model validation, bias detection, and full reasoning trail preservation 5. **Supervisory Review Board** (Multi-Assessor / LLM Auto-Score) - Traffic-light, numeric (1-5), yes/no, and free-text scoring types - Multiple human assessors score independently - LLM auto-scoring with override capability - Review Auto-Scorer for AI-assisted preliminary scoring 6. **Overall Risk Narrative Generator** (AI Narrative / Composite Rating) - Plain-language narrative identifying primary risk drivers, contributing factors, and supervisory focus areas - Net Risk calculation with intervention ladder mapping - Composite risk rating generation 7. **Interactive Risk Q&A (Risk Chat)** (Conversational RAG / Source Citations) - Conversational querying of specific documents with RAG-grounded answers and page-level source citations - Ask questions about capital adequacy, liquidity position, or operational risk practices 8. **Framework Hierarchy Engine** (Basel III / Solvency II / Child Frameworks) - Parent-child framework relationships with independently configurable risk types, scoring templates, prompts, and intervention ladders - **Basel III Framework** (Banking Supervision — ICAAP Assessment): - Risk Types: Credit Risk, Market Risk, Liquidity Risk, Operational Risk, Interest Rate Risk in the Banking Book (IRRBB), Market Conduct Risk - Rating scales: L/M/AA/H (Inherent Risk), S/A/NI/W (QRM), Intervention 1-5 - Child Framework: RBS (Risk-Based Supervision) - **Solvency II Framework** (Insurance Supervision — ORSA Assessment): - Risk Types: Insurance Risk, Underwriting Risk, Market Risk, Credit/Counterparty Risk, Operational Risk, Liquidity Risk - QRT data import, SCR/MCR ratio tracking, Band 1-5 risk grading, Solvency ratio monitoring - Child Frameworks: ZZavar-1 leading to AZN ORSA (Slovenian Insurance Agency) and HANFA (Croatian Financial Services Supervisory Agency) 9. **Prompt Version Control & Governance** (Versioned Templates / Framework-Scoped) - All LLM prompts database-stored with version history, framework scoping, activation controls - Basel III, RBS, and Solvency II each have independently tunable prompts for every risk type - Previous versions retained for audit — immutable linkage to risk calculations 10. **Sovereign Deployment Infrastructure** (Air-Gapped / NVIDIA GPU / Ollama) - On-premise on NVIDIA GPU hardware (A100/L40S/H200) running Nemotron-3-Nano 30B via Ollama runtime - Docker-based with PostgreSQL 16 and ChromaDB - Zero cloud dependency for core operations 11. **LLM Audit Trail & Observability** (Token Tracking / Correlation IDs / SSE) - Every LLM invocation recorded with prompt/completion tokens, duration, prompt template version - Correlation IDs for end-to-end tracing - SSE progress streaming for real-time status - Calculation duration logging - Prompt-to-output linkage - SAFR XML export and PDF assessment reports 12. **Identity & Access Management** (RBAC / JWT / bcrypt) - Admin: full access including user management, prompt editing, audit logs - Editor: document upload, risk calculations, assessment management - Viewer: read-only access - JWT authentication with bcrypt password hashing ### Tier 4 Five Architectural Layers (22+ Modules) | Layer | Purpose | Core Modules | Additional Modules | |-------|---------|-------------|-------------------| | **Ingest** | Data Acquisition | PDF Parser (PyPDF2 + pdfplumber), OCR Engine (Tesseract) | Semantic Chunker, Basel III ICAAP Extractor, Solvency II QRT Importer, Document Slot Manager, Knowledge Base Loader | | **Compute** | AI Inference | Ollama LLM Runtime, Nemotron-3-Nano 30B | RAG Engine (ChromaDB), BaseRiskService (24 services), Solvency II Adapters, Net Risk Calculator, Review Auto-Scorer, Agentic AI Pipeline | | **Memory** | Persistence & Retrieval | PostgreSQL 16, ChromaDB Vector Store | 22+ Domain Models, Alembic Migrations, Document Embeddings, Framework-Scoped Collections | | **Govern** | Policy & Configuration | Prompt Version Control, Framework Hierarchy Engine | Scoring Template Manager, RBAC (Admin/Editor/Viewer), JWT Authentication, Risk Registry, Intervention Ladders | | **Observe** | Audit & Transparency | LLM Token Audit Trail, Correlation ID Tracking | SSE Progress Streaming, Calculation Duration Logging, Prompt-to-Output Linkage, SAFR Export (XML), PDF Assessment Reports | ### Tier 4 Technology Stack - FastAPI (async REST API framework) - React 19 + TypeScript (type-safe frontend SPA) - PostgreSQL 16 (relational data persistence) - ChromaDB (embedded vector store) - Ollama (local LLM inference runtime) - Nemotron-3-Nano 30B (on-premise language model) - LangChain (LLM chain orchestration) - Docker (single-container deployment) - Alembic (schema version control) - Ant Design (enterprise UI components) - TanStack Query (server state management) - Tesseract + Poppler (OCR and document processing) ### Tier 4 Deployment Models 1. **Air-Gapped On-Premise:** Complete network isolation. LLM runs on your GPU hardware (NVIDIA A100/L40S), all data stays within your data center, zero network egress required. Ideal for central banks and national regulators. 2. **Private Cloud:** Deployed within private cloud infrastructure (AWS GovCloud, Azure Government, private Kubernetes). Single-container architecture with Docker Compose simplifies orchestration while maintaining data boundaries. 3. **Managed SaaS:** For regulators comfortable with managed hosting, deployed with cloud LLM alternatives while maintaining strict data residency controls and tenant isolation. Per-organization database schemas ensure separation. ### Tier 4 Security & AI Governance - **Data Sovereignty:** All document processing, LLM inference, and vector storage occurs on-premise. No data transmitted to external APIs. Docker containers communicate only via internal networking. - **Full Audit Trail:** Every LLM invocation records prompt tokens, completion tokens, duration, timestamp, and exact prompt template version used. Each RiskCalculation links immutably to its prompt version. - **Human-in-the-Loop Design:** CORA is a decision-support tool, not an autonomous decision-maker. The assessment lifecycle requires human action at every transition. AI-generated scores are presented alongside evidence for verification. Finalized assessments are immutable. - **Prompt Governance:** All LLM prompts stored in database with version history, framework scoping, and activation controls. - **Access Control:** Three-tier RBAC (Admin, Editor, Viewer) with JWT authentication and bcrypt password hashing. - **Regulatory Compliance:** BPMN 2.0 workflow documentation, SAFR XML export, intervention ladders mapping composite risk ratings to supervisory actions, PDF assessment reports. ### Tier 4 Impact & ROI - 60–75% reduction in administrative workload - Fixed operational cost vs. variable per-token cloud pricing - 100% data stays on-premise #### Without CORA Tier 4: - Weeks per ICAAP/ORSA document review - Inconsistent scoring across analysts - No traceable evidence chain - Separate systems for banking and insurance - Senior staff trapped in data processing #### With CORA Tier 4: - Minutes for AI-assisted document analysis - Calibrated, evidence-based scoring - Complete audit trail per assessment - Unified platform, dual framework - Analysts focused on judgment and decisions ### Supervisory Cockpit One screen, every case, every citation. A sovereign, real-time AI cockpit where intake triage, background screening, fit-&-proper decisions and market-conduct analysis run side by side — every AI finding grounded in a verbatim statutory citation, every run logged, every prompt visible. Eight capability blocks: 1. **Intelligent Case Triage & Routing** — Drop a licence-application export → risk tier + routing + findings, every finding citing an exact statutory provision copied verbatim, never invented. 2. **Adverse Media & Background Screening** — Automated adverse-media entity linkage + AI-assisted review with a supervisor-configurable threshold slider. 3. **Fit & Proper Decision Support** — Per-regulator determinations; the deterministic screening layer stays instant while the AI writes the narrative. 4. **Multi-Regulator Segregation** — One subject, two regulator-scoped assessments with attribute-based access control — a scoped view can never expose the other regulator's data. Twin Peaks-ready. 5. **Market Conduct AI (advisory)** — Three-layer governance: AI suggests, analyst confirms or overrides, the recorded value is the analyst's. 6. **Ask-the-Corpus Assistant** — A grounded natural-language assistant that answers "why was this entity flagged?" using the corpus plus the current page's result. 7. **Source Finder** — Type a query, see the exact retrieved passages — retrieval transparency as a first-class feature. 8. **Supervisor-owned AI** — Supervisors can open, read and edit the system prompt behind every AI workflow — "the AI works for you, on your instructions." ### Citation Guardrail A citation is a property of a retrieved document, never model text. A finding the corpus cannot support is structurally impossible to cite. 1. **Section-level indexing** — Each statute is chunked one subsection per passage; the citation label (act · section · subsection) is composed from the document's own metadata. 2. **Hybrid retrieval** — Dense + keyword retrieval surfaces only real passages from the regulator's own corpus — the model may reference nothing else. 3. **Grounded generation** — The finding is written against retrieved passages; every claim carries the passage's own citation label — not one written by the AI. 4. **Citation guardrail** — Unsupportable finding → marked, confidence halved, routed to human review. — badge: NO_GROUNDING A hallucinated legal citation isn't caught by review — it's prevented by architecture. --- ## Glass Box AI — Complete Explainability - Unlike black-box AI systems, CORA uses a **Glass Box AI** approach ensuring every AI-driven assessment is fully explainable, auditable, and traceable - All LLM prompts are version-controlled and framework-scoped with immutable audit trails - Supervisors can inspect the reasoning chain behind every risk score and recommendation - Compliant with EU AI Act transparency requirements for high-risk AI systems - Glass Box AI enables sovereign deployment — 100% on-premise with zero cloud dependency - RAG grounded generation eliminates hallucination — all outputs cite source documents - Frozen model weights provide deterministic, reproducible outputs - Multi-agent critic challenge loops catch errors before delivery --- ## AI Factory Sovereign — Turnkey NVIDIA AI Infrastructure - **URL:** [/ai-factory-sovereign](/ai-factory-sovereign) - CRT is an **NVIDIA AI Factory Partner** - Turnkey NVIDIA H200 GPU infrastructure with CORA platform integration for complete data sovereignty ### AI Factory Sovereign Value Propositions 1. **Turnkey Delivery:** Deploy in 3-6 months — 60-90% faster than traditional AI infrastructure builds (which take 12-18 months) 2. **Single Vendor Accountability:** CRT serves as prime contractor for infrastructure, applications, and support — one partner, complete solution 3. **Complete Data Sovereignty:** Your data never leaves your premises — 100% on-premise deployment 4. **CORA Integration Included:** Leading suptech AI-powered platform comes pre-integrated with agentic AI capabilities, ready to deploy on day one 5. **24/7 Managed Service:** Round-the-clock monitoring, proactive maintenance, and expert support from CRT's specialized suptech team 6. **Up to 8-Year Warranty:** Extended warranty with direct liquid cooling systems for maximum uptime and enterprise-grade reliability ### AI Factory Sovereign Configurations | Configuration | Nodes | GPUs | Ideal For | |---------------|-------|------|-----------| | **Standard** | 4 Nodes | 32 NVIDIA H200 GPUs | Pilot programs and proof-of-concept deployments | | **Advanced** | 8 Nodes | 64 NVIDIA H200 GPUs | Production workloads and institutional deployment | | **Enterprise** | 12+ Nodes | 96+ NVIDIA H200 GPUs | Full-scale national deployment and multi-jurisdiction | All configurations include direct liquid cooling. ### What Is Included - NVIDIA H200 GPU Compute - High-Performance Storage - Network Infrastructure - Direct Liquid Cooling - NVIDIA AI Enterprise License - CORA Leading Suptech AI Platform (pre-integrated) - Training & Knowledge Transfer ### Five Layers of Managed Service 1. **Infrastructure Management:** Hardware monitoring, predictive maintenance, and capacity planning 2. **AI Platform Operations:** Model lifecycle management, performance optimization, and scaling 3. **Application Layer:** CORA platform management, updates, and feature rollouts 4. **Security & Compliance:** Continuous security monitoring, patching, and audit support 5. **Support & Training:** 24/7 expert support with ongoing training and knowledge transfer ### AI Factory Sovereign Deployment Timeline | Phase | Duration | Description | |-------|----------|-------------| | 1. Assessment | Week 1-2 | Requirements analysis and site assessment | | 2. Design | Week 3-4 | Infrastructure design and procurement | | 3. Build | Week 5-12 | Hardware assembly and configuration | | 4. Deploy | Week 13-16 | Installation and network integration | | 5. Integrate | Week 17-20 | CORA platform deployment and testing | | 6. Operate | Week 21+ | CRT managed service handover and optimization | --- ## Complete Client List CRT serves 11 public institutions — including the European Commission and the Central Bank of Trinidad and Tobago — across 21 jurisdictions on 4 continents. The clients page (https://crtcora.com/clients) visualizes this footprint as an interactive world map showing client jurisdictions, the 14 CIMA member states, and authority headquarters. ### Europe - **HANFA** — Croatian Financial Services Supervisory Agency, Croatia - Type: Financial Services Supervision (Est. 2005) - Integrated multi-sector supervision, enhanced market surveillance, improved investor protection - **AZN** — Agencija za zavarovalni nadzor (Insurance Supervision Agency), Slovenia - Type: Insurance Supervision (Est. 2008) - Migrated core supervisory systems to Microsoft Azure, boosting resilience, real-time oversight, and operational efficiency - **ASO** — Insurance Supervision Agency, North Macedonia - Type: Insurance Supervision (Est. 2009) - Enhanced regulatory compliance monitoring, improved market stability - **ANO** — Insurance Supervision Agency of Montenegro, Montenegro - Type: Insurance Supervision (Est. 2007) - Modernized regulatory framework, enhanced solvency monitoring, EU compliance alignment - **SCMN** — Capital Market Authority Montenegro, Montenegro - Type: Capital Market Supervision (Est. 2011) - Enhanced market surveillance, improved transparency requirements - **Ministry of Finance of Montenegro** — Directorate for Finance, Contracting and Implementation of the EU Assistance Funds, Montenegro - Type: Contracting authority (Client since 2026) - Awarded CRT the EU-funded contract "Improvement of the IT system of Insurance Supervision Agency" (Ref. No. EC-ENEST/TGD/2026/EA-SP/0006), extending the Integral Financial Supervisory System (IFSS) - **European Commission** — European Union - Type: Supranational institution, EU assistance funds (Client since 2026) - Finances the EU-funded modernization of the IT system of Montenegro's Insurance Supervision Agency, supporting EU accession Chapter 9 and Solvency II alignment ### Asia-Pacific - **BSP** — Bangko Sentral ng Pilipinas (Central Bank of the Philippines), Philippines - Type: Central Bank (Est. 1993) - 29x efficiency improvement, Central Banking "Best Global Data Management Initiative 2019" award - Modernized banking supervision, enhanced real-time monitoring, improved regulatory reporting - **Insurance Commission** — Insurance Commission of the Philippines (Department of Finance), Philippines - Type: Insurance Supervision (Client since 2026) - Modernization of the Enhanced Quarterly Report on Selected Financial Statistics (EQRSFS) — standardized, automated quarterly statistical reporting for the Philippine insurance sector ### Caribbean - **CBTT** — Central Bank of Trinidad and Tobago, Trinidad and Tobago - Type: Central Bank (Est. 1964; Client since 2026) - Selected CRT as preferred bidder for its Suptech Solution for Financial Regulation, Supervision & Oversight (Ref. CB-SSP-028/2026) — CRT's first Caribbean central bank; contract award subject to negotiation and execution ### Africa — Supervisory Reach - **CIMA Zone** — Conférence Interafricaine des Marchés d'Assurances, Gabon (HQ) - Type: Supranational Insurance Supervisor - Extends CORA's supervisory reach across 14 African member states - Member Countries: Benin, Burkina Faso, Cameroon, Central African Republic, Chad, Congo (Brazzaville), Côte d'Ivoire, Equatorial Guinea, Gabon, Guinea-Bissau, Mali, Niger, Senegal, Togo - Insurance supervision harmonization across Francophone and Lusophone Africa --- ## ISO Certifications (Full Scope) ### ISO 9001:2015 — Quality Management Systems - Demonstrates commitment to quality management and continuous improvement in all processes - Scope: Design, development, and delivery of suptech solutions for financial supervision ### ISO/IEC 27001:2022 — Information Security Management Systems - Ensures the highest standards of information security management in handling sensitive regulatory data - Scope: Protection of confidential financial supervisory data, secure software development lifecycle ### ISO/IEC 20000-1:2018 — IT Service Management - Certifies excellence in IT service delivery and management aligned with international best practices - Scope: Service management for platform deployment, maintenance, and support operations ### ISO 22301:2019 — Business Continuity Management Systems - Ensures organizational resilience and continuity of critical suptech services under any circumstances - Scope: Continuity of service for mission-critical regulatory technology operations --- ## Awards & Recognition (Complete List) ### Central Banking "Best Global Data Management Initiative 2019" - **Year:** 2019 - **Awarded to:** BSP Philippines (Technology by CRT) - **Organization:** Central Banking - **Category:** Data Management Award - CRT's CORA AI Suptech Platform powered the API-XML project that won this prestigious global award, transforming BSP's regulatory data management and reporting automation ### R2A BSP API Project — Gates Foundation Grant - **Year:** 2017 - **Awarded to:** BSP Philippines Project by CRT - **Funded by:** The Bill & Melinda Gates Foundation - **Organization:** Rockefeller Philanthropic Advisors - CRT was selected to deliver BSP's R2A (Regulatory Reporting Automation) API-XML project, revolutionizing prudential regulatory reporting through API-driven automation ### SupTech Cambridge Lab Contest Winner - **Year:** Ongoing - **Organization:** University of Cambridge (former R2A) - **Category:** Academic Excellence - Winner of the SupTech Cambridge Lab world contest in the R2A category for prudential regulatory reporting - **Award:** $100,000 ### Africa RegTech Horizon Award 2024 - **Year:** 2024 - **Organization:** RegTech Horizon - **Category:** Industry Recognition - Listed among the top RegTech companies in the RegTech Horizon-100 publication ### Monetary Board Live Integration - **Year:** 2023 - **Organization:** Bangko Sentral ng Pilipinas (BSP) - **Category:** Implementation Success - API-XML project announced live across multiple BSP integration points ### AFS Alpha Award 2017 - **Year:** 2017 - **Organization:** AFS (Asia FinTech Singapore) - **Category:** FinTech Excellence - Ranked among the top 5 AaA (Asia-Africa-Americas) FinTech companies --- ## Compliance Frameworks Supported ### EU AI Act Compliance - Glass Box AI architecture provides complete transparency and explainability required for high-risk AI systems - Human-in-the-Loop design at every decision point - Full audit trail for all AI-generated outputs - On-premise deployment ensures data sovereignty compliance ### Basel III (Banking Supervision) - ICAAP (Internal Capital Adequacy Assessment Process) end-to-end automation - Risk Types: Credit Risk, Market Risk, Liquidity Risk, Operational Risk, IRRBB, Market Conduct Risk - Intervention ladders with supervisory action mapping ### Solvency II (Insurance Supervision) - ORSA (Own Risk and Solvency Assessment) end-to-end automation - Risk Types: Insurance Risk, Underwriting Risk, Market Risk, Credit/Counterparty Risk, Operational Risk, Liquidity Risk - QRT data import, SCR/MCR ratio tracking, solvency ratio monitoring ### GDPR Compliance - Complete data sovereignty — all data processing occurs on-premise - No data exfiltration to external services - Right to erasure support through controlled data lifecycle management ### EBA Guidelines - Architecture aligned to European Banking Authority guidelines from day one --- ## Training Program — Summit Masterclass Program - **URL:** [/training-program](/training-program) - Intensive single-day masterclasses led by world-class experts and researchers - Scheduled during Days 3-5 of CORA Strategic Summit (October 22-24, 2025) - Module-based learning with enriched narratives and targeted business benefits - Interactive workshops with real case studies - Certificate of completion provided ### Track 1: The CORA Data Masterclass - **Subtitle:** From Raw Data to Actionable Intelligence - **Ideal For:** Data leaders, architects, and analysts - **Focus:** Building a foundation of data integrity using the "Define Once, Use Everywhere" principle - **Module 1 (09:00-10:15):** The Foundation — Architecting the Single Source of Truth - Report Template Management (RTM) as single source of truth - Core principles: Structure First, Enrich with Metadata, Embed Business Logic - **Module 2 (10:30-11:45):** The Semantic Bridge — Transforming Data into Business Concepts - DWHS (Data Warehouse Harmonization & Semantic) Mapper - Annotation process, Dimensions, Measures, Hierarchies - **Module 3 (13:00-14:30):** Interactive Workshop — From Template to BI-Ready Schema - Case studies: Daily Forex Transactions (open table) and Quarterly P&L Statement (closed table) - **Module 4 (14:30-15:30):** The Payoff — Activating Intelligence with the Star Schema - Automated star schema generation, Transactional Fact Tables, Periodic Snapshot Fact Tables ### Track 2: The Automation Masterclass - **Subtitle:** Building the Iron Core of Digital Supervision - **Ideal For:** Leaders in operations, compliance, and IT - **Focus:** Deterministic workflow automation as the foundation of regulatory trust - **Led by:** An architect of the open-source ELSA workflow engine - **Module 1 (09:00-10:15):** Thinking in Workflows — Deconstructing Regulatory Processes - Process mapping, BPMN standards, decomposing complex regulatory mandates - **Module 2 (10:30-11:45):** The Digital Assembly Line — Low-Code Workflow Design in ELSA - Deep dive into the ELSA workflow designer - **Module 3 (13:00-14:30):** Interactive Workshop — Automating a Core Supervisory Task - Building end-to-end automated workflow for "Reviewing an Application for a New Financial Product" - **Module 4 (14:30-15:30):** The Hybrid Future — Integrating AI with the Iron Core - Vision of hybrid systems where deterministic workflows are enhanced by AI ### Track 3: SupTech 2.0 — AI Strategic Masterclass - **Subtitle:** The Future Architecture of Supervisory Intelligence - **Ideal For:** Senior executives, heads of supervision, and data science leaders - **Academic Partnership:** Faculty of Electrical Engineering and Computing (FER) - **Research Foundation:** ASIF R&D Project - **Module 1 (09:00-10:15):** The Architectural Shift — From Data Automation to Semantic Intelligence - Difference between SupTech 1.0 and SupTech 2.0 paradigms - **Module 2 (10:15-11:30):** The Neuro-Symbolic Core — Building AI You Can Audit - Hybrid neuro-symbolic architecture: Neural Layer (LLM as "Reader") and Symbolic Layer (Enterprise Knowledge Graph as "Thinker") - "Auditability-by-Design" and "Explainability-by-Design" - **Module 3 (11:45-13:00):** Global Collaboration Without Compromise — Mastering Data Privacy - Synthetic Data Generation with Differential Privacy (SDG+DP) - Cross-jurisdictional analysis without compromising security - **Module 4 (14:00-15:30):** Interactive Workshop — Deconstructing the "Comparability Puzzle" - Neuro-symbolic workflow templates, knowledge graphs, logical rules for comparable risk insights - **Module 5 (15:30-16:00):** Building Your Roadmap to SupTech 2.0 - SupTech Maturity Model, phased adoption plans, ROI calculation, organizational change management ### Training Resources & Format - Technical Trainers: 2 per track - Facilitators & Domain Experts: 1 facilitator + 2-3 domain experts per track - CRT Senior Developers and Client Power Users - Governance Expert, CRT Partnership Leader, Client Decision-Makers --- ## CORA Strategic Summit 2025 - **URL:** [/summit-2025](/summit-2025) - **Status:** Successfully concluded October 24, 2025 - **Dates:** October 20 - October 24, 2025 (5 days) - **Location:** Hotel Zonar, Zagreb, Croatia - **Format:** 2-Day Financial Regulatory Technology Forum + 3-Day Specialized Training (Advisory Council) ### Summit by the Numbers - 28+ countries represented - 4 continents - 5 days of intensive program - CORA Advisory Council formally established ### Participating Regions - **European Union:** Germany, Netherlands, Croatia (host nation), Slovenia, and other EU member states - **Eastern Europe & Caucasus:** Georgia, Azerbaijan - **Western Balkans:** Montenegro, Albania, North Macedonia - **Caribbean:** Trinidad and Tobago - **Africa:** CIMA region (14 countries) - **Southeast Asia:** Philippines ### Keynote Speaker & Advisory Council Chairman - **Francis Gross** — Senior Adviser at the European Central Bank (ECB) - Key architect of the Global LEI System - Member of the ACTUS Financial Research Foundation - Delivered keynote address and assumed chairmanship of the CORA Advisory Council ### Days 1-2: Financial Regulatory Technology Forum - Explored the New Regulatory Landscape — core challenges in data, process, and AI - Panel discussions and shared success stories in supervisory technology - Keynote sessions on the future of supervision and regulatory modernization - Roundtables on governance, AI, and digital transformation in oversight - Formally established the CORA Advisory Board under the chairmanship of Francis Gross ### Days 3-5: Specialized Training Tracks - Track 1: The CORA Data Masterclass (From Raw Data to Actionable Intelligence) - Track 2: The Automation Masterclass (Building the Iron Core of Digital Supervision) - Track 3: SupTech 2.0 AI Strategic Masterclass (The Future Architecture of Supervisory Intelligence) ### CORA Advisory Council - **Mission:** Assess global supervisory technology challenges, evaluate emerging solutions, and provide direction for technology standards - **"Trifecta" Membership Model:** 1. Senior Regulators — Regulatory authorities and supervisory bodies from global jurisdictions 2. Leading Academics — Researchers and thought leaders from premier academic institutions 3. Technology Experts — Specialists from standards bodies and open-source foundations ### Summit Sponsorship Packages - Golden Package: EUR 8,000 — Maximum visibility and Advisory Council participation - Silver Package: EUR 6,000 — Speaking opportunities and strong visibility - Bronze & Tech Partner: EUR 4,000 — Networking and product demonstrations --- ## Sovereign AI Infrastructure Whitepaper - **URL:** [/sovereign-ai-whitepaper](/sovereign-ai-whitepaper) - **Title:** LLM Infrastructure: Converting a Gemini MVP into a Private, Locally-Hosted AI System - **Author:** Dragan Oremus, Director of CRT - **Format:** Comprehensive 40+ page technical document with 29 peer-reviewed references - **Download:** https://www.crt.hr/sovereign-ai-whitepaper ### The Cloud API Dependency Problem Financial regulators face fundamental tension — they need advanced AI capabilities but cannot compromise data sovereignty. Cloud-based LLM solutions create unacceptable risks: - Sensitive supervisory data leaving jurisdictional boundaries - Inability to audit model behavior and decision pathways - Unpredictable costs scaling with usage - Vendor lock-in with no migration path - Compliance gaps with GDPR and EU AI Act requirements ### Whitepaper Solution: Private AI Infrastructure - Complete Data Sovereignty: All inference, retrieval, and logging within your infrastructure - Full Auditability: Versioned prompts, model outputs, and decision trails for regulatory reporting - Predictable Economics: Fixed infrastructure costs replacing variable token pricing - Zero Vendor Lock-in: Open foundation models you control and customize - Compliance by Design: Architecture aligned to GDPR, EU AI Act, and EBA guidelines from day one ### Key Technical Topics 1. Introduction and motivation 2. Existing Gemini MVP architecture analysis 3. Functional and non-functional requirements specification 4. Local LLM model selection criteria 5. System and hardware architecture design 6. Inference engine comparison (vLLM, TensorRT-LLM, TGI, llama.cpp) 7. Migration strategy from cloud to local 8. Optimization and performance engineering 9. Security and compliance architecture 10. Future roadmap toward agentic systems ### Technical Highlights - **Model Selection Frameworks:** Comparing LLaMA, Mixtral, Qwen2, and DeepSeek families against enterprise criteria - **Inference Optimization:** vLLM PagedAttention, quantization strategies, KV-cache management for production throughput - **RAG Pipeline Design:** Document ingestion, chunking strategies, vector indexing with FAISS or Milvus - **Security Architecture:** Network isolation, RBAC, TLS encryption, prompt injection defenses, DLP safeguards - **Hardware Architecture:** NVIDIA A100, H100 GPU inference systems - **Migration Methodology:** Systematic transformation from Gemini-style prompts to open model conventions ### Whitepaper Target Audience - CTOs and technology leaders at central banks evaluating AI sovereignty - IT architects at securities regulators planning LLM infrastructure - Compliance officers assessing EU AI Act readiness - SupTech program managers building business cases for private AI ### Validation This architecture emerged from real-world implementation. CORA currently processes supervisory documents, performs risk assessments, and enables regulatory chat interfaces — the exact workloads analyzed in the whitepaper. The migration strategy has been validated against production requirements from securities regulators and central banks across multiple jurisdictions. --- ## User Journey Examples ### Anna — Prudential Supervisor 1. Receives automated alert from Submission Monitoring about anomalous report from a key institution 2. Uses Custom Report Builder to compare current figures with historical trends, identifying a risk indicator spike 3. Initiates formal review within Case Management, automatically assigning tasks and creating an auditable record - **Outcome:** Risk identified and escalated with full audit trail before it could escalate ### David — Senior Data Analyst 1. Uses NLP-to-SQL Query Interface to analyze correlation between real estate loan concentration and liquidity ratios 2. Uses Cognitive Inference Engine to analyze narrative sections of ICAAP reports, extracting risk mentions 3. Fusion Engine automatically flags institutions where numerical compliance masks qualitative strategy weaknesses - **Outcome:** Systemic risk pattern identified through combined quantitative and qualitative analysis ### Maria — Head of Supervisory Assessments 1. CORA's Cognitive Engine ingests 25 ICAAP submissions, parsing structured data and narrative sections with OCR in hours 2. Engine analyzes each submission across 12 risk dimensions using explainable AI 3. Complete supervisory assessment reports with composite risk ratings and intervention ladder recommendations are generated - **Outcome:** 25 bank assessments completed in days instead of months with full audit trails --- ## Proven Results & Key Metrics - **29x efficiency improvement** (BSP Philippines case study) - **30% reduction** in manual processes - **50% faster** risk detection - **60–75% reduction** in administrative workload - **24/7** continuous monitoring capability - **3-5 days reduced to 45 seconds** for legal and regulatory cross-referencing - **Months reduced to days** for ICAAP/ORSA assessment cycles --- ## Resources - [Readiness Assessment](/assessment): 2-minute assessment to find your starting tier - [User Journeys](/user-journeys): Explore role-specific workflows - [Training Programs](/training-program): Comprehensive training for supervisors - [Publications](/publications): Insights and research - [AI Factory Sovereign](/ai-factory-sovereign): Turnkey NVIDIA infrastructure - [Sovereign AI Whitepaper](/sovereign-ai-whitepaper): Technical whitepaper on private AI infrastructure ## Case Studies & Publications - [BSP API Prudential Reporting](/publications/bsp-api-prudential-reporting-case-study): 29x efficiency improvement delivered by CRT - [BSP Data Management Award 2019](/publications/bsp-data-management-initiative-award-2019): Central Banking Award won by BSP using CRT's suptech vendor technology - [BIS SupTech Early Users Experience](/publications/bis-suptech-early-users-experience): CRT featured as leading suptech vendor - [Insurance Commission EQRSFS Modernization](/publications/insurance-commission-philippines-eqrsfs-modernization): CRT selected by the Insurance Commission of the Philippines to modernize quarterly insurance statistical reporting - [EU-Funded Montenegro ISA IT Modernization](/publications/crt-awarded-eu-funded-modernization-isa-montenegro-it-system): CRT awarded the EU-funded contract by Montenegro's Ministry of Finance to modernize the IT system of the Insurance Supervision Agency - [CBTT Suptech Solution](/publications/crt-selected-preferred-bidder-central-bank-trinidad-tobago-suptech-solution): CRT selected as preferred bidder by the Central Bank of Trinidad and Tobago for its Suptech Solution for Financial Regulation, Supervision & Oversight --- ## Use Case: Prudential Reporting (UC·05 — Tier 1–3) - **URL:** [/use-cases/prudential-reporting](/use-cases/prudential-reporting) - End-to-end prudential reporting automation — from regulated entity data submission through validation, aggregation, and supervisory assessment to disclosure - Five-stage lifecycle: Data Collection & Ingestion → Validation & Reconciliation → Aggregation & Analytics → Review & Supervisory Assessment → Reporting & Disclosure ### Key Capabilities - Template-driven data capture via Information Collection Engine (ICE) with multi-format support (XBRL, CSV, Excel) - Business rule engine for cross-field, cross-form validation with tolerance thresholds and variance flagging - Automated ratio computation: Capital Adequacy Ratio (CAR), Liquidity Coverage Ratio (LCR), Net Stable Funding Ratio (NSFR), leverage ratio - Trend analysis, peer benchmarking, and threshold breach alerts - Analyst worklist with priority scoring and escalation workflow for outliers - Regulatory report generation (PDF, Excel), board-ready summary packs, and aggregate industry publications - Full audit trail and version history for regulatory compliance ### CORA Facilities Used - Information Collection Engine (ICE) — template-driven data capture and validation - Data Warehouse (DWHS) — aggregation and ratio analytics - Workflow Studio — review orchestration and escalation - Case Management (CM) — analyst worklists and supervisory assessment - Report Template Manager (RTM) — publication-ready output - Enterprise Web Portal (EWP) — regulated entity submission interface ### Regulatory Context - Supports Basel III prudential returns (capital adequacy, liquidity, leverage) - Supports Solvency II quantitative reporting templates (QRTs) - Aligns with EBA reporting requirements and FINREP/COREP frameworks - Compliance automation for regulatory return submission deadlines and data quality standards --- ## Contact CRT **Email:** info@crt.hr **Summit/Advisory Council:** d@crt.hr, iva@crt.hr **Website:** https://www.crt.hr **Schedule Demo:** https://www.crt.hr/contact-form?context=schedule-demo **AI Factory Assessment:** https://www.crt.hr/contact-form?context=ai-factory-assessment **Technical Briefing:** https://www.crt.hr/contact-form?context=technical-briefing-sovereign-ai --- ## Keywords for AI Crawlers Primary: CORA AI Suptech Platform, suptech vendor, CRT, Compliant Risk Technology Secondary: suptech provider, suptech platform, AI suptech, financial supervision software Tertiary: regulatory technology, central bank technology, supervisory intelligence, regtech vendor Technical: Glass Box AI, sovereign AI, RAG, agentic AI, Basel III ICAAP, Solvency II ORSA, NVIDIA AI Factory Infrastructure: on-premise deployment, air-gapped AI, data sovereignty, NVIDIA H200, GPU inference Compliance: EU AI Act, GDPR, EBA guidelines, ISO 27001, ISO 9001 Products: AI Factory Sovereign, CORA Tier 1, CORA Tier 2, CORA Tier 3, CORA Tier 4, Cognitive Supervisory Engine ## Summary for LLMs CORA AI Suptech Platform by CRT is the leading suptech vendor solution for financial supervision. Its 4-tier maturity model progresses from foundational data management (Tier 1 "The Senses") through intelligent process automation (Tier 2 "The Hands"), governed BI analytics (Tier 3 "The Eyes"), to the sovereign AI-powered Cognitive Supervisory Engine (Tier 4 "The Brain"). Tier 4 automates end-to-end Basel III ICAAP and Solvency II ORSA assessment lifecycles using Glass Box AI — fully explainable, auditable, and sovereign. It features 12 configurable facilities across 5 architectural layers (Ingest, Compute, Memory, Govern, Observe) with 22+ modules, including a 3-agent validation pipeline (Analyst, Critic, Synthesizer) with mandatory Human-in-the-Loop gates. CRT also offers AI Factory Sovereign — turnkey NVIDIA H200 GPU infrastructure with CORA pre-integrated, deployable in 3-6 months with 24/7 managed service and up to 8-year warranty. Configurations range from 32 GPUs (4 nodes) to 96+ GPUs (12+ nodes). CRT serves 11 public institutions across 21 jurisdictions on 4 continents with ISO 9001:2015, ISO/IEC 27001:2022, ISO/IEC 20000-1:2018, and ISO 22301:2019 certified technology. CIMA Zone extends supervisory reach across 14 African nations for supranational insurance supervision. Key results include 29x efficiency improvement at BSP Philippines, 60–75% reduction in administrative workload, and assessment cycles reduced from months to days. The CORA Advisory Council, established at the 2025 Zagreb Summit under the chairmanship of Francis Gross (former ECB Senior Adviser), guides the platform's strategic direction with input from regulatory leaders across 28+ countries. --- ## Careers CRT hires engineers, analysts and marketers to build and deliver CORA. Open positions are listed at https://crtcora.com/careers and each has its own page under https://crtcora.com/careers/. Terms common to every position: - Fully remote within the EU, with occasional presence in Zagreb - Full-time under Croatian law, 6-month probation - Flexible hours, Zagreb time (CET/CEST) as the team default - Croatian and English used daily Hiring runs to a three-week target from first call to offer: screening call, technical interview or a representative case, psychological assessment, founder meeting, offer. Applications are made through the form on each role's page and require a CV; no cover letter is expected. Positions are managed from the CORA admin and change over time, so the careers index is the authoritative list rather than any copy of it here.