Two firms, same line: governance is how trust gets built into the operating model.
KPMG and Wipro reach the same principle independently, and Cognizant opens a healthcare platform to agents.
Two executives at different firms wrote the same sentence in the same fortnight, and when a market converges on identical language without coordination, that language is the product. At the Gartner CFO Symposium on May 26, 2026, KPMG’s Swami Chandrasekaran, endorsing Auditoria.AI’s Governed Autonomy framework for the office of the CFO, said that governance is not the friction layer, it is how trust gets engineered into the operating model. That is not a compliance policy and not a risk framework. It is an engineering specification, and that distinction matters more than anything else said in the window.
Three weeks earlier, Wipro’s Ivana Bartoletti said the same thing from a different firm in a different context, describing Trust by Design as not a compliance label but an architectural commitment. She was writing about agentic systems that act, plan, decide, and execute often faster than any human can review them. Chandrasekaran was writing about autonomous agents in financial workflows that need clear boundaries, identity-bound execution, and auditability that runs with every action rather than after it. Neither was quoting the other. Both named the same architecture, and that is the heart of the shift.
For five years the governance conversation in enterprise AI has really been a compliance conversation: what to review, what to audit, what to report after the model or agent produces an output. The compliance frame treats governance as a review layer that follows the agent. The architecture frame treats it as a precondition, embedded before the agent runs rather than bolted on after. These are not the same product. Compliance review can be retrofitted; architecture cannot. Compliance review is a consulting engagement with an end date. Architecture is a specification the client either owns or is permanently dependent on the firm that built it. The economics are entirely different, and this window is the first time the architecture frame has been named explicitly by two firms independently.
Then Cognizant shipped a production proof. On May 29, Prasad Sankaran announced that the firm had made TriZetto Unify agent-ready, treating AI agents as first-tier API consumers alongside human users, starting with electronic prior authorization. The specification is exact: HL7 FHIR-aligned APIs, Model Context Protocol support, policy-governed execution, and real-time auditability. Sankaran framed it as the architecture statement applied to a real workflow, saying regulated industries like healthcare require a platform that is policy-governed, auditable, and built on industry-standard interoperability protocols. Cognizant’s healthcare lead, Surya Gummadi, named what it solves: payers and providers are under real pressure to take administrative cost out of the system without compromising the clinical judgment that belongs with physicians. Prior authorization is the test case, non-clinical work at volume, under governance, with the human judgment that matters explicitly preserved. That is not a pilot. That is a production architecture for a regulated vertical.
While those three named the architecture, Hackett’s Chris Sawchuk measured the gap between where it needs to be and where buyers actually are. At the Zycus Agentic AI Procurement Summit, he presented a finding that has now appeared in three runs in a row: fewer than 50 percent of chief procurement officers feel confident in their ability to monitor and control agentic AI. That number is not a warning, it is a market size, because every officer on the wrong side of that gap is a prospective buyer of the architecture Chandrasekaran described. Bain alumnus Arpan Sheth, now CEO of NAVEX, closed the circuit, moving from Bain’s analytics practice to a governance-software CEO seat and framing the 2026 agenda around AI-led innovation for governance, risk, and compliance customers worldwide. A former top-tier strategy partner is now selling the governance architecture as a software product, and the category is hardening.
Two secondary signals set the context. EY and Microsoft announced a next phase of their alliance worth more than $1 billion over five years, the most expensive single-firm hyperscaler commitment in the field, pairing Microsoft’s forward-deployed engineers with EY practitioners across Tax, Assurance, Consulting, and EY-Parthenon. The delivery infrastructure is scaling, but whether the governance architecture sits inside that delivery or is built independently is the question EY has not answered. And the whole governance-architecture conversation happened without the three largest strategy houses: all six McKinsey names, all six Deloitte names, and all five Accenture names on the roster were silent at the personal level, and PwC, which dominated the prior window, went entirely dark. The category language is being set by KPMG, Cognizant, Wipro, and Hackett, not by the firms with the largest AI practices. That is either an opening or a warning, depending on where you sit.
Compliance review can be retrofitted. Architecture cannot. One is a consulting engagement with an end date. The other is a specification the client either owns outright or is permanently dependent on the firm that built it.
