API 580/581
API 580 / API 581 — Risk-Based Inspection for fixed equipment
2016 · Global
API RP 580 (RBI methodology) + API 581 (RBI quantitative technology) for fixed-equipment inspection planning. KYE Protocol™ governs the authority and evidence of an AI-recommended inspect/repair/replace action and records the inspection-interval + failure-mode reference vocabulary; KYE Protocol™ does not compute RBI risk. Per-requirement bijection at framework-coverage-bijection.
0 Enforced2 Designed0 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| RBI decision documentation + review (contestable) |
Designed |
L2 Designed |
api-580.10.0 |
Evidence Pack™Authority Gate |
| High-consequence action named-engineer sign-off |
Designed |
L2 Designed |
api-581.5.0 |
Authority GateDecision Map™ |
arrow_forward KYE™ framework reference
Australia Group
Australia Group — Biological & Chemical Dual-Use Export Controls
2023 · Global
Australia Group dual-use export-control regime — harmonised control lists for dual-use biological agents, toxins, equipment, and chemical-weapon precursors. KYE Protocol™ governs whether an AI-generated design mapping to a controlled item may proceed to a consequential action — the KYE AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed0 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Dual-use biological control list |
Designed |
L2 Designed |
australia-group.bio-agents, australia-group.bio-equipment |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Dual-use chemical precursor list |
Designed |
L2 Designed |
australia-group.chem-precursors |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Controlled-item action gating |
Designed |
L2 Designed |
australia-group.controlled-item-gate |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
arrow_forward KYE™ framework reference
BCBS 239
BCBS 239 — Risk Data Aggregation & Risk Reporting Principles
BCBS 239 (Principles for effective risk data aggregation and risk reporting, January 2013) · International
BCBS 239 sets the Basel Committee's 14 principles for effective risk data aggregation and risk reporting. KYE Protocol™ governs whether a model-driven output or risk report under it may proceed to a consequential action — only a currently-validated model used within its approved scope, model changes as named-authority decisions with evidence, every consequential decision pinned to model_id + version + validation reference, and every risk report bound to its data-lineage evidence chain, sealed into a signed replay-provable Evidence Pack™. The quantitative model build / validation mathematics / capital computation / portfolio composition stays the bank's own work (honest scope, §0 — not investment advice). All 14 principles are mapped one row each (honest tri-state). Per-requirement bijection at /compliance/bcbs-239.html.
3 Enforced0 Designed3 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Risk-data governance & named authority on the report (P1) |
Enforced |
L3 Enforceable |
bcbs-239.principle1-governance |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Risk-data aggregation lineage, completeness & adaptability (P3 / P4 / P6) |
Enforced |
L3 Enforceable |
bcbs-239.principle3-accuracy-integrity-lineage, bcbs-239.principle4-completeness, bcbs-239.principle6-adaptability |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Risk-report traceability, cadence & distribution evidence (P7 / P10 / P11) |
Enforced |
L3 Enforceable |
bcbs-239.principle7-reporting-accuracy, bcbs-239.principle10-frequency, bcbs-239.principle11-distribution |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Bank data architecture & crisis-timeliness capability (P2 / P5)The data architecture, IT infrastructure, and crisis-timeliness aggregation capability are the bank's own data and technology estate — KYE™ is an AI-authority and evidence layer, not a data platform. |
Out of scope |
L1 Mapped |
bcbs-239.principle2-data-architecture, bcbs-239.principle5-timeliness |
— |
| Report substance — comprehensiveness & clarity (P8 / P9)Judging material-risk coverage and the report's editorial quality is the bank's risk and reporting functions' own work — KYE™ proves what the report aggregated and how, not whether it covered everything that mattered. |
Out of scope |
L1 Mapped |
bcbs-239.principle8-comprehensiveness, bcbs-239.principle9-clarity-usefulness |
— |
| Supervisory review, remedial tools & home/host cooperation (P12–P14)Principles 12–14 are addressed to supervisors — conducting the review, applying supervisory measures, and home/host cooperation are regulator functions; KYE™'s sealed evidence chains support the bank's side of the review but the obligations sit outside an AI-authority-governance protocol. |
Out of scope |
L1 Mapped |
bcbs-239.principle12-supervisory-review, bcbs-239.principle13-remedial-actions, bcbs-239.principle14-home-host-cooperation |
— |
arrow_forward KYE™ framework reference
Colorado SB21-169
Colorado SB21-169 — Insurers' Use of External Consumer Data & AI
Colorado SB21-169 (Restrict Insurers' Use of External Consumer Data; C.R.S. §10-3-1104.9) + Division of Insurance regulations · United States
Colorado SB21-169 restricts insurers' use of external consumer data, algorithms, and predictive models to prevent unfair discrimination, and requires testing, documentation, and consumer adverse-action reasons. KYE Protocol™ governs whether an AI-assisted underwriting or claims decision relying on external data may proceed to a consequential adverse action — under a named authority, with a recorded adverse-action reason-code, with proxy-discrimination / fairness-evidence captured, a signed replay-provable Evidence Pack™ per decision, and an appeal / contestability record. The external-data selection / pricing / methodology design on the merits stays the insurer's own work (honest scope, §0). Per-requirement bijection at /compliance/colorado-sb21-169.html.
3 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Adverse-action reason explainability to the consumer |
Enforced |
L3 Enforceable |
colorado-sb21-169.adverse-action-explainability |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| External-data proxy-discrimination evidence |
Enforced |
L3 Enforceable |
colorado-sb21-169.external-data-discrimination-evidence |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Named-authority on the external-data-driven decision |
Enforced |
L3 Enforceable |
colorado-sb21-169.external-data-decision-authority |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| External data source selection & pricing on the meritsThe external-data selection / pricing / methodology design on the merits is the insurer's own work — KYE™ is an AI-authority and evidence layer, not a pricing or data-selection engine. |
Out of scope |
L1 Mapped |
colorado-sb21-169.external-data-source-selection-pricing |
— |
arrow_forward KYE™ framework reference
COSHH
COSHH — Control of Substances Hazardous to Health Regulations 2002 (UK)
2002 · United Kingdom
UK COSHH 2002 (SI 2002/2677), HSE-enforced. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved COSHH assessments and control instructions — the KYE HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed0 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| COSHH assessment authored under safety floor |
Designed |
L2 Designed |
coshh.reg-6 |
Purpose Permission™Edge Governance Safety Floor |
| Exposure-control measure advisory pending sign-off |
Designed |
L2 Designed |
coshh.reg-7 |
Authority GateDecision Map™ |
| Control-measure instruction contestable + evidenced |
Designed |
L2 Designed |
coshh.reg-8 |
Evidence Pack™Authority Gate |
arrow_forward KYE™ framework reference
CWC / BWC
CWC + BWC — Chemical & Biological Weapons Conventions
1997-2024 · Global
Chemical Weapons Convention (CWC, Schedules 1/2/3) + Biological Weapons Convention (BWC, prohibited bio/toxin agents). KYE Protocol™ governs whether an AI-generated molecule or agent mapping to a scheduled/prohibited item may proceed to a consequential action — a hard stop routed to oversight, the KYE AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed0 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| CWC scheduled chemicals (Schedule 1/2/3) |
Designed |
L2 Designed |
cwc-bwc.cwc-schedule1, cwc-bwc.cwc-schedule2-3 |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| BWC prohibited biological / toxin agents |
Designed |
L2 Designed |
cwc-bwc.bwc-prohibited-agents |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Prohibited-agent action stop |
Designed |
L2 Designed |
cwc-bwc.prohibited-agent-stop |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
arrow_forward KYE™ framework reference
DoD 5015.2
DoD 5015.02-STD — Records Management Application Design Criteria (RMA spine)
2007 · United States
DoD 5015.02-STD records-management-application spine for the KYE Chain of Authority™ for Iron Mountain InSight DXP. KYE Protocol™ overlays the action-boundary access-control + named-authority + governance-decision audit (enforced); the RMA record-declaration / file-plan / disposition criteria are out-of-scope (owned by the records-manager). §0: KYE Protocol™ retains PROOF-OF-GOVERNANCE, not the customer's records.
2 Enforced0 Designed2 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Access-control decision at the action boundary (authority overlay) |
Enforced |
L3 Enforceable |
dod-5015-2.access-control-action-decision, dod-5015-2.named-authority-binding |
Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Audit of the action decision (authority overlay) |
Enforced |
L3 Enforceable |
dod-5015-2.action-decision-audit |
Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Record declaration & categorisation / file plan (RMA criteria) |
Out of scope |
L1 Mapped |
dod-5015-2.record-declaration-file-plan |
— |
| Disposition & transfer (RMA criteria) |
Out of scope |
L1 Mapped |
dod-5015-2.disposition-transfer |
— |
arrow_forward KYE™ framework reference
Dodd-Frank §922
Dodd-Frank §922 + SEC Rule 21F — Whistleblower Programme
Dodd-Frank Act §922 (15 U.S.C. §78u-6) + SEC Rules 21F (whistleblower programme) · United States
Dodd-Frank §922 + SEC Rule 21F — Whistleblower Programme is the US SEC whistleblower programme (confidentiality, anti-retaliation, the Rule 21F-17 anti-impediment prohibition). KYE Protocol™ governs whether an AI-assisted access to a whistleblower's identity or a consequential case action may proceed — on a recorded need-to-know authority, with confidentiality evidence captured, a signed Evidence Pack™, and a contestability record. Assessing the securities-law tip on its merits, awarding the bounty, and adjudicating the §922 / Rule 21F claim stay with the SEC and counsel (honest scope, §0). Per-requirement bijection at /compliance/dodd-frank-whistleblower.html.
2 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Confidentiality & anti-impediment evidence for a whistleblower's identity |
Enforced |
L3 Enforceable |
dodd-frank-whistleblower.confidentiality-evidence |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & reconstruction of the handling / retaliation determination |
Enforced |
L3 Enforceable |
dodd-frank-whistleblower.handling-contestability-reconstruction |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Securities-law merits, bounty award & Rule 21F adjudicationAssessing the tip, awarding the bounty, and adjudicating the §922 / Rule 21F claim is the SEC's and counsel's determination — KYE™ is an AI-authority and evidence layer, not an enforcement engine. |
Out of scope |
L1 Mapped |
dodd-frank-whistleblower.securities-merits-and-award |
— |
arrow_forward KYE™ framework reference
EU AI Act insurance
EU AI Act — Annex III High-Risk Insurance
Regulation (EU) 2024/1689 (EU AI Act) — Annex III high-risk insurance use-cases (life & health risk assessment / pricing) · European Union
The EU AI Act classifies AI used for risk assessment and pricing in life and health insurance as high-risk (Annex III), triggering human-oversight (Art. 14), record-keeping (Art. 12), and transparency obligations. KYE Protocol™ governs whether an AI-assisted insurance decision in scope may proceed to a consequential adverse action — under a named human-oversight authority, with a recorded adverse-action reason-code, fairness-evidence captured, a signed replay-provable Evidence Pack™ (the Art. 12 log) per decision, and an appeal / contestability record. The risk pricing / system build / conformity assessment on the merits stays the provider's own work (honest scope, §0). Per-requirement bijection at /compliance/eu-ai-act-insurance.html.
3 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Human oversight authority over the high-risk decision (Art. 14) |
Enforced |
L3 Enforceable |
eu-ai-act-insurance.annex3-human-oversight |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Record-keeping / logging of the AI decision (Art. 12) |
Enforced |
L3 Enforceable |
eu-ai-act-insurance.annex3-record-keeping-logging |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Transparency & contestability of the decision |
Enforced |
L3 Enforceable |
eu-ai-act-insurance.annex3-transparency-contestability |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Risk pricing, system build & conformity assessment on the meritsThe risk pricing / high-risk system build / Art. 43 conformity assessment on the merits is the provider's own work — KYE™ is an AI-authority and evidence layer at the action boundary, not a system-build, pricing, or conformity-assessment engine. |
Out of scope |
L1 Mapped |
eu-ai-act-insurance.risk-pricing-system-build-conformity |
— |
arrow_forward KYE™ framework reference
EU Evidence Reg
EU Evidence Regulation 2020/1783 + eIDAS — Evidence Authenticity & Transmission
Regulation (EU) 2020/1783 (taking of evidence in civil/commercial matters) + eIDAS Regulation (EU) 910/2014 (electronic evidence integrity) · European Union
EU Evidence Regulation 2020/1783 + eIDAS — Evidence Authenticity & Transmission is the EU cross-border evidence and electronic-integrity framework (Regulation 2020/1783 + eIDAS). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/eu-evidence-regulation.html.
2 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Chain-of-custody & integrity for cross-border evidence transmission |
Enforced |
L3 Enforceable |
eu-evidence-regulation.evidence-authenticity-transmission |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Integrity-bound, contestable Evidence Pack™ (eIDAS-aligned) |
Enforced |
L3 Enforceable |
eu-evidence-regulation.eidas-integrity-evidence-pack |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Member-State admissibility & substantive evidential assessmentThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. |
Out of scope |
L1 Mapped |
eu-evidence-regulation.member-state-admissibility |
— |
arrow_forward KYE™ framework reference
EU Whistleblower Dir.
EU Whistleblower Directive — Directive (EU) 2019/1937
Directive (EU) 2019/1937 (protection of persons who report breaches of Union law) · European Union
EU Whistleblower Directive — Directive (EU) 2019/1937 is the EU whistleblower-protection framework (confidentiality, acknowledgement / feedback clocks, prohibition of retaliation). KYE Protocol™ governs whether an AI-assisted intake-triage decision, an access to a reporter's identity / PII, a case disposition (close / escalate), or an adverse action on a reporter may proceed to a consequential action — under a named handler's authority, on a recorded need-to-know basis, with confidentiality and retaliation-risk evidence captured, a signed replay-provable Evidence Pack™ per consequential action, and a contestability record so any disposition can be reconstructed and challenged. The substantive investigation / allegation merits / remediation decision stays the organisation's own work (honest scope, §0). Per-requirement bijection at /compliance/eu-whistleblower-directive.html.
3 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Confidentiality & need-to-know access to a reporter's identity |
Enforced |
L3 Enforceable |
eu-whistleblower-directive.confidentiality-need-to-know-access |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Named-authority on the case disposition (acknowledgement / feedback clocks) |
Enforced |
L3 Enforceable |
eu-whistleblower-directive.case-disposition-named-authority |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & reconstruction of the handling |
Enforced |
L3 Enforceable |
eu-whistleblower-directive.handling-contestability-reconstruction |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive investigation & whether the breach occurredInvestigating the report on its merits and deciding the remediation is the organisation's own ethics / legal work — KYE™ is an AI-authority and evidence layer, not an investigation or adjudication engine. |
Out of scope |
L1 Mapped |
eu-whistleblower-directive.substantive-investigation |
— |
arrow_forward KYE™ framework reference
Fed SR 11-7
Fed SR 11-7 — Supervisory Guidance on Model Risk Management
SR 11-7 / OCC 2011-12 (Supervisory Guidance on Model Risk Management, April 2011) · United States
Fed SR 11-7 / OCC 2011-12 is the US supervisory guidance on model risk management (development, validation, governance). KYE Protocol™ governs whether a model-driven output or risk report under it may proceed to a consequential action — only a currently-validated model used within its approved scope, model changes as named-authority decisions with evidence, every consequential decision pinned to model_id + version + validation reference, and every risk report bound to its data-lineage evidence chain, sealed into a signed replay-provable Evidence Pack™. The quantitative model build / validation mathematics / capital computation / portfolio composition stays the bank's own work (honest scope, §0 — not investment advice). Per-requirement bijection at /compliance/fed-sr-11-7.html.
4 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Validated-model use authority at the decision boundary |
Enforced |
L3 Enforceable |
fed-sr-11-7.model-use-named-authority |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Model change control as a named-authority decision |
Enforced |
L3 Enforceable |
fed-sr-11-7.model-change-control |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Decision traceability to model version & validation reference |
Enforced |
L3 Enforceable |
fed-sr-11-7.decision-provenance-traceability |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Model inventory & policy controls on model use |
Enforced |
L3 Enforceable |
fed-sr-11-7.inventory-policy-controls |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Quantitative model development, validation & capital mathematicsThe quantitative model build, validation mathematics, and capital & liquidity computation are the bank's own quantitative work — KYE™ is an AI-authority and evidence layer, not a model-validation or capital-calculation engine. |
Out of scope |
L1 Mapped |
fed-sr-11-7.quantitative-development-validation |
— |
arrow_forward KYE™ framework reference
FRCP e-discovery
FRCP e-Discovery — Rules 26 / 34 / 37 + FRE 502 (privilege)
FRCP (2015 e-discovery amendments; Rules 26 / 34 / 37 + FRE 502) · United States
FRCP e-Discovery — Rules 26 / 34 / 37 + FRE 502 (privilege) is the US federal e-discovery and privilege framework (FRCP 26 / 34 / 37 + FRE 502). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/frcp-ediscovery.html.
3 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Named-authority on the privilege / discovery determination |
Enforced |
L3 Enforceable |
frcp-ediscovery.rule26g-discovery-certification |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Discovery chain-of-custody for produced / withheld ESI |
Enforced |
L3 Enforceable |
frcp-ediscovery.rule34-esi-chain-of-custody |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & sanctions-reconstruction of the determination |
Enforced |
L3 Enforceable |
frcp-ediscovery.rule37-sanctions-reconstruction |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive privilege judgment & attorney certification on the meritsThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. |
Out of scope |
L1 Mapped |
frcp-ediscovery.substantive-privilege-judgment |
— |
arrow_forward KYE™ framework reference
FRE 901/902
FRE 901 / 902 — Authentication & Self-Authentication of Evidence
FRE 901 / 902 (Authentication & Self-Authentication; 2017 ESI amendments) · United States
FRE 901 / 902 — Authentication & Self-Authentication of Evidence is the US evidence-authentication framework (FRE 901 / 902). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/fre-authentication.html.
2 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| No-hallucinated-citation provenance pin for AI assertions |
Enforced |
L3 Enforceable |
fre-authentication.rule901-authentication-evidence |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Hash-bound self-authenticating Evidence Pack™ |
Enforced |
L3 Enforceable |
fre-authentication.rule902-self-authenticating-record |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive admissibility, relevance & weight of the evidenceThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. |
Out of scope |
L1 Mapped |
fre-authentication.substantive-admissibility |
— |
arrow_forward KYE™ framework reference
GDPR Whistleblowing
GDPR (Whistleblowing) — Special-Category & Data-Minimisation in Reports
Regulation (EU) 2016/679 (GDPR) — whistleblowing data-protection slice (Art. 5, 6, 9, 15, 21) · European Union
GDPR (Whistleblowing) — Special-Category & Data-Minimisation in Reports is the data-protection slice of whistleblowing (data minimisation, special-category restriction, need-to-know access, data-subject access / objection). KYE Protocol™ governs whether an AI-assisted access to the personal / special-category data in a report may proceed — on a recorded need-to-know authority, with data-minimisation evidence captured, a signed Evidence Pack™, and a contestability record so a data-subject access or objection can be reconstructed. The lawful-basis assessment of the underlying processing, the DPIA, and data-subject adjudication stay with the controller / DPO / supervisory authority (honest scope, §0). Per-requirement bijection at /compliance/gdpr-whistleblower.html.
2 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Need-to-know access & data-minimisation evidence for special-category report data |
Enforced |
L3 Enforceable |
gdpr-whistleblower.special-category-need-to-know-access |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Data-subject contestability (access / objection) reconstruction |
Enforced |
L3 Enforceable |
gdpr-whistleblower.data-subject-contestability |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Lawful-basis assessment, DPIA & data-subject adjudicationThe lawful-basis assessment, the DPIA, and data-subject adjudication is the controller's / DPO's / supervisory authority's determination — KYE™ is an AI-authority and evidence layer, not a data-protection-compliance engine. |
Out of scope |
L1 Mapped |
gdpr-whistleblower.lawful-basis-and-dpia |
— |
arrow_forward KYE™ framework reference
ICH Q1
ICH Q1 — Stability Testing
ICH Q1A(R2) (2003) · International
ICH Q1 — Stability Testing is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q1.html.
0 Enforced1 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Authority over an AI stability summary at the action boundary |
Designed |
L2 Designed |
ich-q1.named-authority |
Purpose Permission™Authority Gate |
| Stability study science & shelf-life determinationThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. |
Out of scope |
L1 Mapped |
ich-q1.science |
— |
arrow_forward KYE™ framework reference
ICH Q10
ICH Q10 — Pharmaceutical Quality System
ICH Q10 (2008) · International
ICH Q10 — Pharmaceutical Quality System is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q10.html.
3 Enforced1 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Management responsibility & named-authority |
Enforced |
L3 Enforceable |
ich-q10.management-responsibility-authority |
Authority GateDecision replayEvidence Pack™ |
| Change-management authority at the action boundary |
Enforced |
L3 Enforceable |
ich-q10.change-management-authority |
Authority GateDecision replayEvidence Pack™ |
| Management review control (sign-off gate) |
Enforced |
L3 Enforceable |
ich-q10.management-review-control |
Authority GateDecision replayEvidence Pack™ |
| Personnel competence recorded before the action |
Designed |
L2 Designed |
ich-q10.personnel-competence |
Purpose Permission™Authority Gate |
| Quality-system substance (CAPA / change science)The scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. |
Out of scope |
L1 Mapped |
ich-q10.quality-system-substance |
— |
arrow_forward KYE™ framework reference
ICH Q2
ICH Q2(R2) — Validation of Analytical Procedures
ICH Q2(R2) (2023) · International
ICH Q2(R2) — Validation of Analytical Procedures is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q2.html.
3 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Validation-package authority at the action boundary |
Enforced |
L3 Enforceable |
ich-q2.validation-package-authority |
Authority GateDecision replayEvidence Pack™ |
| Validation-conclusion justification recorded before the action |
Enforced |
L3 Enforceable |
ich-q2.validation-conclusion-justification |
Authority GateDecision replayEvidence Pack™ |
| Replay-provable validation-package provenance |
Enforced |
L3 Enforceable |
ich-q2.validation-package-provenance |
Authority GateDecision replayEvidence Pack™ |
| Analytical-method science & validation statisticsThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. |
Out of scope |
L1 Mapped |
ich-q2.analytical-method-science |
— |
arrow_forward KYE™ framework reference
ICH Q3
ICH Q3 — Impurities
ICH Q3 family · International
ICH Q3 — Impurities is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q3.html.
0 Enforced1 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Authority over an AI impurity-assessment summary at the action boundary |
Designed |
L2 Designed |
ich-q3.named-authority |
Purpose Permission™Authority Gate |
| Impurity science & threshold determinationThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. |
Out of scope |
L1 Mapped |
ich-q3.science |
— |
arrow_forward KYE™ framework reference
ICH Q5
ICH Q5 — Quality of Biotechnological Products
ICH Q5 family · International
ICH Q5 — Quality of Biotechnological Products is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q5.html.
0 Enforced1 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Authority over an AI biotech-quality summary at the action boundary |
Designed |
L2 Designed |
ich-q5.named-authority |
Purpose Permission™Authority Gate |
| Biotech product science (viral safety / comparability / stability)The scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. |
Out of scope |
L1 Mapped |
ich-q5.science |
— |
arrow_forward KYE™ framework reference
ICH Q6
ICH Q6 — Specifications
ICH Q6 family · International
ICH Q6 — Specifications is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q6.html.
0 Enforced1 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Authority over an AI specification-justification summary at the action boundary |
Designed |
L2 Designed |
ich-q6.named-authority |
Purpose Permission™Authority Gate |
| Specification science & acceptance-criteria settingThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. |
Out of scope |
L1 Mapped |
ich-q6.science |
— |
arrow_forward KYE™ framework reference
ICH Q7
ICH Q7 — GMP for Active Pharmaceutical Ingredients
ICH Q7 (2000) · International
ICH Q7 — GMP for Active Pharmaceutical Ingredients is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q7.html.
4 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Quality-Unit release authority at the action boundary |
Enforced |
L3 Enforceable |
ich-q7.quality-unit-batch-release |
Authority GateDecision replayEvidence Pack™ |
| Records & data integrity (ALCOA+) screened before the action |
Enforced |
L3 Enforceable |
ich-q7.data-integrity-alcoa |
Authority GateDecision replayEvidence Pack™ |
| Replay-provable GMP-record provenance |
Enforced |
L3 Enforceable |
ich-q7.gmp-record-provenance |
Authority GateDecision replayEvidence Pack™ |
| Batch release sign-off gate (§36 two-person) |
Enforced |
L3 Enforceable |
ich-q7.batch-release-signoff |
Authority GateDecision replayEvidence Pack™ |
| Physical API manufacture & analytical testingThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. |
Out of scope |
L1 Mapped |
ich-q7.physical-api-manufacture |
— |
arrow_forward KYE™ framework reference
ICH Q8
ICH Q8(R2) — Pharmaceutical Development
ICH Q8(R2) (2009) · International
ICH Q8(R2) — Pharmaceutical Development is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q8.html.
3 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Development-content authority at the action boundary |
Enforced |
L3 Enforceable |
ich-q8.development-justification-provenance |
Authority GateDecision replayEvidence Pack™ |
| Development justification recorded before the action |
Enforced |
L3 Enforceable |
ich-q8.justification-recorded-before-action |
Authority GateDecision replayEvidence Pack™ |
| Replay-provable development-content provenance |
Enforced |
L3 Enforceable |
ich-q8.development-content-provenance |
Authority GateDecision replayEvidence Pack™ |
| Development science (QbD / design space / control strategy)The scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. |
Out of scope |
L1 Mapped |
ich-q8.development-science |
— |
arrow_forward KYE™ framework reference
ICH Q9
ICH Q9(R1) — Quality Risk Management
ICH Q9(R1) (2023) · International
ICH Q9(R1) — Quality Risk Management is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q9.html.
3 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Risk-based decision authority at the action boundary |
Enforced |
L3 Enforceable |
ich-q9.qrm-decision-authority |
Authority GateDecision replayEvidence Pack™ |
| Risk-decision justification recorded before the action |
Enforced |
L3 Enforceable |
ich-q9.risk-decision-justification |
Authority GateDecision replayEvidence Pack™ |
| Replay-provable QRM provenance |
Enforced |
L3 Enforceable |
ich-q9.qrm-provenance |
Authority GateDecision replayEvidence Pack™ |
| Risk-assessment science & control-strategy selectionThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. |
Out of scope |
L1 Mapped |
ich-q9.risk-assessment-science |
— |
arrow_forward KYE™ framework reference
IEC 61508
IEC 61508:2010 — Functional safety of E/E/PE safety-related systems
2010 · Global
The umbrella functional-safety standard defining Safety Integrity Levels (SIL 1-4) and the safety lifecycle. KYE Protocol™ governs the authority, evidence and finality of an AI-recommended physical-safety action against a SIL-validated model-authority claim; KYE Protocol™ does not perform the SIL determination. Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed0 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| SIL-validated model authority + safety floor |
Designed |
L2 Designed |
iec-61508.part-1.7.6 |
Purpose Permission™Edge Governance Safety Floor |
| Functional-safety decision evidence + named accountability |
Designed |
L2 Designed |
iec-61508.part-1.7.14 |
Evidence Pack™Reporting Engine |
| Contestable verification outcomes |
Designed |
L2 Designed |
iec-61508.part-3.7.9 |
Evidence Pack™Authority Gate |
arrow_forward KYE™ framework reference
IEC 61511
IEC 61511:2016 — Safety instrumented systems for the process industry
2016 · Global
The process-sector application of IEC 61508 defining safety instrumented systems (SIS). KYE Protocol™ governs the authority and finality of an AI-recommended physical-safety action (turbine trip, unit shutdown, derate) under the safety floor. Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed0 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| SIS actuating decision under safety floor |
Designed |
L2 Designed |
iec-61511.clause-11.3 |
Purpose Permission™Edge Governance Safety Floor |
| Operation & maintenance named accountability |
Designed |
L2 Designed |
iec-61511.clause-16.2 |
Authority GateDecision Map™ |
| Contestable / reviewable SIS decisions |
Designed |
L2 Designed |
iec-61511.clause-11.9 |
Evidence Pack™Authority Gate |
arrow_forward KYE™ framework reference
ISO 14001
ISO 14001 — Environmental Management Systems
2015 · Global
ISO 14001:2015 environmental management system. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved environmental HSE instructions that discharge an EMS control — the KYE HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed0 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Environmental operational control under safety floor |
Designed |
L2 Designed |
iso-14001.8.1 |
Purpose Permission™Edge Governance Safety Floor |
| Environmental emergency instruction scope-bound |
Designed |
L2 Designed |
iso-14001.8.2 |
Purpose Permission™Authority Gate |
| Compliance evaluation contestable + evidenced |
Designed |
L2 Designed |
iso-14001.9.1.2 |
Evidence Pack™Authority Gate |
arrow_forward KYE™ framework reference
ISO 15489
ISO 15489-1:2016 — Records Management (records-management spine)
2016 · Global
ISO 15489-1:2016 records-management spine for the KYE Chain of Authority™ for Iron Mountain InSight DXP. Iron Mountain governs INFORMATION (records, custody, retention, classification); KYE Protocol™ governs ACTION — who was authorised to act on a record at the moment it drives a consequential AI action, evidenced, final, revocable. The authentic/reliable-records-at-the-action-boundary requirements are KYE Protocol™'s job (enforced); records storage / capture / retention / disposition are records-management's job (out-of-scope, owned by the records-manager / information-custodian).
2 Enforced0 Designed3 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Records authenticity & reliability (authority overlay) |
Enforced |
L3 Enforceable |
iso-15489.authenticity-authority-binding, iso-15489.reliability-evidence-pin |
Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Records access & permissions (authority overlay) |
Enforced |
L3 Enforceable |
iso-15489.access-permission-overlay |
Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Records creation, capture & metadata (records-management) |
Out of scope |
L1 Mapped |
iso-15489.records-capture-metadata |
— |
| Retention schedule & disposition authority (records-management) |
Out of scope |
L1 Mapped |
iso-15489.retention-disposition-authority |
— |
| Records storage & preservation (records-management) |
Out of scope |
L1 Mapped |
iso-15489.storage-preservation |
— |
arrow_forward KYE™ framework reference
ISO 16175
ISO 16175-1:2020 — Software for Managing Records (digital records spine)
2020 · Global
ISO 16175-1:2020 digital-records-software spine for the KYE Chain of Authority™ for Iron Mountain InSight DXP. KYE Protocol™ overlays the action-boundary access-control decision + the governance-decision audit trail (enforced); the records-software capture / classification / retention functions are out-of-scope (owned by Iron Mountain InSight DXP). §0: Iron Mountain proves where information travelled; KYE Protocol™ proves who was authorised to act on it.
2 Enforced0 Designed2 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Action-decision audit trail (authority overlay) |
Enforced |
L3 Enforceable |
iso-16175.action-audit-trail, iso-16175.replayable-decision-record |
Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Access-control decision at the action boundary (authority overlay) |
Enforced |
L3 Enforceable |
iso-16175.access-control-decision |
Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Capture & classification functional requirements (records-software) |
Out of scope |
L1 Mapped |
iso-16175.capture-classification-functional |
— |
| Retention & disposition functional requirements (records-software) |
Out of scope |
L1 Mapped |
iso-16175.retention-disposition-functional |
— |
arrow_forward KYE™ framework reference
ISO 17025
ISO/IEC 17025:2017 — Competence of testing and calibration laboratories
2017 · International
ISO/IEC 17025:2017 sets the general requirements for the competence, impartiality and consistent operation of testing and calibration laboratories. KYE Protocol™ enforces the §7.11 data-management integrity, §7.5/§7.8 technical-record reproducibility and audit-trail slices where a laboratory uses AI-supported decisioning — metrology, equipment and competence stay the laboratory's technical system. Per-requirement bijection at /compliance/iso-17025.html.
2 Enforced2 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Control of data & information management (7.11) |
Enforced |
L3 Enforceable |
iso-17025.7.11-data-management |
WORM audit hash-chain |
| Technical records & integrity of results (7.5, 7.8) |
Enforced |
L3 Enforceable |
iso-17025.7.5-technical-records |
Decision replayEvidence Pack™ |
| Control of management-system records & audit trail (8.4) |
Designed |
L2 Designed |
iso-17025.8.4-management-records |
WORM audit hash-chain |
| Impartiality & authority over automated decisions (4.1, 6.2) |
Designed |
L2 Designed |
iso-17025.4.1-impartiality-authority |
Purpose Permission™Authority Gate |
| Metrological traceability, measurement uncertainty, equipment & competenceMetrological traceability, measurement uncertainty, equipment calibration and technical competence are the laboratory's own technical/metrology system — out of scope for an AI-authority-governance protocol. |
Out of scope |
L1 Mapped |
iso-17025.6.5-traceability, iso-17025.6.3-equipment-competence |
— |
arrow_forward KYE™ framework reference
ISO/IEC 27035
ISO/IEC 27035 — Incident Management
ISO/IEC 27035 — Information security incident management · International
ISO/IEC 27035 is the international standard for information-security incident management, including careful incident-evidence handling. KYE Protocol™ governs whether an AI-assisted incident decision under it may proceed to a consequential action — under a named accountable officer's authority, with incident-evidence chain-of-custody recorded, the assessment pinned to verifiable signal sources, a signed replay-provable Evidence Pack™ per decision, and a contestability record for the lessons-learned reconstruction. Detection / response tooling / forensic analysis stays the organisation's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/iso-27035.html.
3 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Incident-evidence chain-of-custody (evidence handling) |
Enforced |
L3 Enforceable |
iso-27035.evidence-chain-of-custody |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Named-authority on the assessment-and-decision response |
Enforced |
L3 Enforceable |
iso-27035.assessment-decision-authority |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & lessons-learned reconstruction |
Enforced |
L3 Enforceable |
iso-27035.lessons-learned-reconstruction |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Detection, response tooling & forensic analysisThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. |
Out of scope |
L1 Mapped |
iso-27035.detection-response-forensics |
— |
arrow_forward KYE™ framework reference
ISO 45001
ISO 45001 — Occupational Health & Safety Management Systems
2018 · Global
ISO 45001:2018 occupational health & safety management system. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved safety-critical HSE documents (permits-to-work, risk assessments, method statements) that discharge an OH&S control — the KYE HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.
0 Enforced4 Designed0 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Operational planning & control under safety floor |
Designed |
L2 Designed |
iso-45001.8.1 |
Purpose Permission™Edge Governance Safety Floor |
| Hierarchy-of-controls selection advisory pending sign-off |
Designed |
L2 Designed |
iso-45001.8.1.2 |
Authority GateDecision Map™ |
| Emergency-preparedness instruction scope-bound |
Designed |
L2 Designed |
iso-45001.8.2 |
Purpose Permission™Authority Gate |
| Incident / corrective action contestable + evidenced |
Designed |
L2 Designed |
iso-45001.10.2 |
Evidence Pack™Authority Gate |
arrow_forward KYE™ framework reference
ISO 55000
ISO 55000 / ISO 55001:2014 — Asset management management systems
2014 · Global
ISO 55000/55001 asset-management system requirements. KYE Protocol™ governs the authority, evidence and finality of AI-recommended asset-management actions and the scope of the AI's authority over the asset portfolio. Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed0 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Asset-management objectives + scoped decision authority |
Designed |
L2 Designed |
iso-55001.6.2.1 |
Authority GateDecision Map™ |
| Planned actions — finality + named accountability |
Designed |
L2 Designed |
iso-55001.6.2.2 |
Purpose Permission™Edge Governance Safety Floor |
| Contestable performance review |
Designed |
L2 Designed |
iso-55001.9.1 |
Evidence Pack™Authority Gate |
arrow_forward KYE™ framework reference
Mastercard Disputes
Mastercard Chargeback Standards — Dispute Resolution & Arbitration
Mastercard Chargeback Standards — Dispute Resolution & Arbitration (Chargeback Guide) · Global
The Mastercard Chargeback Standards govern the dispute lifecycle — first chargeback, second presentment with supporting documentation, pre-arbitration, and arbitration on the documented record. KYE Protocol™ governs whether the second presentment / case filing may proceed — under a named owner's recorded authority, with the supporting evidence captured as evidence events at transaction time, and the bundle sealed as a signed, hash-bound, WORM-retained, replay-verifiable Evidence Pack™ so the documented record survives arbitration scrutiny. Whether to fight, the narrative, and the outcome stay the merchant's / network's own (honest scope, §0). Per-requirement bijection at /compliance/mastercard-dispute-rules.html.
3 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Second-presentment evidence captured at transaction time |
Enforced |
L3 Enforceable |
mastercard-dispute-rules.second-presentment-evidence-capture |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Named-authority on the chargeback response |
Enforced |
L3 Enforceable |
mastercard-dispute-rules.chargeback-response-authority |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Arbitration-grade reconstruction of the dispute record |
Enforced |
L3 Enforceable |
mastercard-dispute-rules.arbitration-reconstruction-record |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Dispute merits adjudication & strategyWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. |
Out of scope |
L1 Mapped |
mastercard-dispute-rules.dispute-merits-adjudication |
— |
arrow_forward KYE™ framework reference
MoReq2010
MoReq2010 — Modular Requirements for Records Systems (records-system spine)
2011 · European Union
MoReq2010 records-system spine for the KYE Chain of Authority™ for Iron Mountain InSight DXP. KYE Protocol™ overlays the action-boundary access-control service + entity-event governance-decision audit + custody→authority binding (enforced); the records-system classification / search / retention / disposition core services are out-of-scope (owned by Iron Mountain InSight DXP).
2 Enforced0 Designed2 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Access-control service at the action boundary (authority overlay) |
Enforced |
L3 Enforceable |
moreq-2010.access-control-service-overlay, moreq-2010.custody-to-authority-binding |
Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Entity-event audit of the action decision (authority overlay) |
Enforced |
L3 Enforceable |
moreq-2010.entity-event-action-audit |
Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Classification & search core service (records-system) |
Out of scope |
L1 Mapped |
moreq-2010.classification-search-service |
— |
| Retention & disposition core service (records-system) |
Out of scope |
L1 Mapped |
moreq-2010.retention-disposition-service |
— |
arrow_forward KYE™ framework reference
MSHA
MSHA — Mine Safety and Health Administration standards (30 CFR)
2024 · United States
US MSHA standards under 30 CFR governing surface and underground mine safety. KYE Protocol™ governs the authority, evidence and finality of AI-recommended physical-safety actions on mine equipment (e.g. mine-hoist stop). Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed0 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Mine-equipment actuation under safety floor |
Designed |
L2 Designed |
msha.30-cfr-56.18002 |
Purpose Permission™Edge Governance Safety Floor |
| Hoisting stop named accountability |
Designed |
L2 Designed |
msha.30-cfr-57.19021 |
Authority GateDecision Map™ |
| Contestable equipment-safety decisions |
Designed |
L2 Designed |
msha.30-cfr-75.1725 |
Evidence Pack™Authority Gate |
arrow_forward KYE™ framework reference
NAIC AI Bulletin
NAIC Model Bulletin on the Use of AI by Insurers
NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (adopted December 2023) · United States
The NAIC Model Bulletin on the Use of AI by Insurers is the US insurer-AI governance expectation (written AIS Program, named accountability, documentation, unfair-discrimination testing). KYE Protocol™ governs whether an AI-assisted underwriting or claims decision under it may proceed to a consequential adverse action — under a named underwriter's / adjuster's authority, with a recorded adverse-action reason-code, with proxy-discrimination / fairness-evidence captured, a signed replay-provable Evidence Pack™ per decision, and an appeal / contestability record so any decision can be reconstructed and contested. The actuarial pricing / risk-appetite / model design on the merits stays the insurer's own work (honest scope, §0). Per-requirement bijection at /compliance/naic-model-bulletin-ai.html.
3 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Named accountability & governance of the AI decision |
Enforced |
L3 Enforceable |
naic-model-bulletin-ai.governance-named-accountability |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Adverse-action explainability & documentation |
Enforced |
L3 Enforceable |
naic-model-bulletin-ai.adverse-action-documentation |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Unfair-discrimination testing evidence |
Enforced |
L3 Enforceable |
naic-model-bulletin-ai.unfair-discrimination-testing |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Actuarial pricing, risk appetite & model design on the meritsThe actuarial pricing / risk-appetite / model design on the merits is the insurer's own work — KYE™ is an AI-authority and evidence layer, not a pricing, actuarial, or risk-modelling engine. |
Out of scope |
L1 Mapped |
naic-model-bulletin-ai.actuarial-pricing-model-design |
— |
arrow_forward KYE™ framework reference
NERC CIP
NERC CIP — Critical Infrastructure Protection (bulk electric system)
2024 · United States
NERC CIP reliability standards governing cyber security of the North American bulk electric system. KYE Protocol™ governs the authority, evidence and finality of an AI-recommended physical-safety action on grid assets and the scope boundary of the AI's authority. Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed0 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Controlled actuation of BES assets under safety floor |
Designed |
L2 Designed |
nerc-cip.cip-007-6.r1 |
Purpose Permission™Edge Governance Safety Floor |
| Purpose-scoped authority for grid actions |
Designed |
L2 Designed |
nerc-cip.cip-004-6.r4 |
Authority GateDecision Map™ |
| Contestable + evidenced incident decisions |
Designed |
L2 Designed |
nerc-cip.cip-008-6.r1 |
Evidence Pack™Authority Gate |
arrow_forward KYE™ framework reference
NIS2 Incident
NIS2 Incident Reporting — Article 23 (24h / 72h)
NIS2 — Directive (EU) 2022/2555, Article 23 · European Union
NIS2 Incident Reporting (Directive (EU) 2022/2555, Article 23) is the EU 24-hour / 72-hour staged-notification regime for significant incidents. KYE Protocol™ governs whether an AI-assisted disclosure-timing decision or containment action under it may proceed to a consequential incident action — under a named accountable officer's authority, with chain-of-custody recorded, and a contestability record so the timing decision can be reconstructed and challenged. Incident detection / impact analysis stays the entity's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/nis2-incident.html.
2 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Disclosure-timing authority on the 24h / 72h notification clock |
Enforced |
L3 Enforceable |
nis2-incident.notification-clock-authority |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Incident-evidence chain-of-custody for the notification |
Enforced |
L3 Enforceable |
nis2-incident.notification-evidence-custody |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Incident detection & impact analysisThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. |
Out of scope |
L1 Mapped |
nis2-incident.detection-impact-analysis |
— |
arrow_forward KYE™ framework reference
NIST CSF 2.0 RS/RC
NIST CSF 2.0 — RESPOND & RECOVER
NIST Cybersecurity Framework 2.0 (2024) — RESPOND (RS) + RECOVER (RC) · United States
NIST CSF 2.0 RESPOND & RECOVER is the incident-management, analysis, and recovery half of the NIST Cybersecurity Framework 2.0. KYE Protocol™ governs whether an AI-assisted response / recovery action under it may proceed to a consequential incident action — under a named accountable officer's authority, with the incident analysis pinned to verifiable signal sources, chain-of-custody recorded, a signed replay-provable Evidence Pack™ per decision, and a contestability record. Threat detection (DETECT) / response tooling / recovery execution stays the organisation's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/nist-csf-2-respond-recover.html.
3 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Named-authority on the RESPOND/RECOVER action (RS.MA / RC.RP) |
Enforced |
L3 Enforceable |
nist-csf-2-respond-recover.rs-action-authority |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Incident-analysis source pin (RS.AN) |
Enforced |
L3 Enforceable |
nist-csf-2-respond-recover.rs-incident-evidence |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & post-incident reconstruction (RS.MA / improvement) |
Enforced |
L3 Enforceable |
nist-csf-2-respond-recover.rs-contestability |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Threat detection (DETECT) & recovery execution toolingThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. |
Out of scope |
L1 Mapped |
nist-csf-2-respond-recover.detection-recovery-tooling |
— |
arrow_forward KYE™ framework reference
Synthesis Screening
Nucleic-Acid Synthesis Screening — IBBIS Common Mechanism + IGSC Harmonized Screening Protocol
2023 · Global
Nucleic-acid synthesis screening regime — the IBBIS Common Mechanism and IGSC Harmonized Screening Protocol screen synthesis orders for sequences of concern before synthesis. KYE Protocol™ governs whether an AI-generated nucleic-acid sequence may proceed to a synthesis order, binding the screening result — the KYE AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed0 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Sequence-of-concern screening |
Designed |
L2 Designed |
nucleic-acid-synthesis-screening.soc-screen, nucleic-acid-synthesis-screening.flagged-hold |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Customer / legitimacy screening |
Designed |
L2 Designed |
nucleic-acid-synthesis-screening.customer-screen |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Screening provenance & record-keeping |
Designed |
L2 Designed |
nucleic-acid-synthesis-screening.screening-provenance |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
arrow_forward KYE™ framework reference
NYDFS AI Circular
NYDFS Insurance Circular Letter on AI
NYDFS Insurance Circular Letter No. 7 (2024) — Use of AI Systems and External Consumer Data in Underwriting and Pricing · United States
NYDFS Insurance Circular Letter No. 7 (2024) sets expectations for insurers using AI and external consumer data in underwriting and pricing — senior-management accountability, unfair-discrimination testing, consumer transparency, documentation. KYE Protocol™ governs whether an AI-assisted insurance decision in scope may proceed to a consequential adverse action — under a named accountable authority, with a recorded adverse-action reason-code, proxy-discrimination / fairness-evidence captured, a signed replay-provable Evidence Pack™ per decision, and a consumer appeal / contestability record. The ECDIS selection / pricing / methodology design on the merits stays the insurer's own work (honest scope, §0). Per-requirement bijection at /compliance/nydfs-insurance-circular-ai.html.
3 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Senior-management accountability for the AI decision |
Enforced |
L3 Enforceable |
nydfs-insurance-circular-ai.senior-management-accountability |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Unfair-discrimination testing evidence |
Enforced |
L3 Enforceable |
nydfs-insurance-circular-ai.unfair-discrimination-testing |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Consumer transparency & appeal record |
Enforced |
L3 Enforceable |
nydfs-insurance-circular-ai.consumer-transparency-appeal |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| ECDIS selection, pricing & methodology design on the meritsThe ECDIS selection / pricing / testing-methodology design on the merits is the insurer's own work — KYE™ is an AI-authority and evidence layer, not a data-selection, pricing, or testing-methodology engine. |
Out of scope |
L1 Mapped |
nydfs-insurance-circular-ai.ecdis-selection-pricing-methodology |
— |
arrow_forward KYE™ framework reference
OECD GLP
OECD Good Laboratory Practice (Principles) + FDA 21 CFR Part 58
1998 + 21 CFR 58 · International / US
OECD Principles of Good Laboratory Practice and FDA 21 CFR Part 58 govern the integrity, traceability, audit-trail and archiving of non-clinical safety-study data. KYE Protocol™ enforces the ALCOA+ data-integrity, audit-trail and replay slices where an AI/automated step captures or transforms study data — physical study conduct stays the laboratory's GLP system. Per-requirement bijection at /compliance/oecd-glp.html.
2 Enforced2 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Study data integrity & raw-data traceability (ALCOA+) |
Enforced |
L3 Enforceable |
oecd-glp.data-integrity, oecd-glp.raw-data-traceability |
WORM audit hash-chainDecision replayEvidence Pack™ |
| Audit trail & change control for electronic records (Part 11 overlap) |
Enforced |
L3 Enforceable |
oecd-glp.audit-trail |
WORM audit hash-chain |
| Archive & retention of study records |
Designed |
L2 Designed |
oecd-glp.archive-retention |
WORM audit hash-chain |
| QA & study-director oversight of automated steps |
Designed |
L2 Designed |
oecd-glp.oversight-of-automated-steps |
Purpose Permission™Authority Gate |
| Physical study conduct & facilitiesApparatus calibration, test/reference-item handling and physical SOP execution are the laboratory's own GLP quality system — KYE™ is an AI-authority and evidence layer, not a lab-operations system. |
Out of scope |
L1 Mapped |
oecd-glp.physical-study-conduct |
— |
arrow_forward KYE™ framework reference
OSHA PSM
OSHA PSM — Process Safety Management (29 CFR 1910.119)
1992 · United States
US OSHA Process Safety Management standard for facilities handling highly hazardous chemicals. KYE Protocol™ governs the authority, evidence and finality of AI-recommended physical-safety actions in a PSM-covered process. Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed0 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Mechanical-integrity actuation under safety floor |
Designed |
L2 Designed |
osha-psm.1910.119.j |
Purpose Permission™Edge Governance Safety Floor |
| Operating-procedure named accountability |
Designed |
L2 Designed |
osha-psm.1910.119.f |
Authority GateDecision Map™ |
| Management-of-change contestable + evidenced |
Designed |
L2 Designed |
osha-psm.1910.119.l |
Evidence Pack™Authority Gate |
arrow_forward KYE™ framework reference
Permit to Work
Permit-to-Work Systems (HSE HSG250 guidance)
HSG250 · United Kingdom
Permit-to-work systems per UK HSE HSG250. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved permits-to-work — the KYE HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed0 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Permit advisory pending competent-authoriser sign-off |
Designed |
L2 Designed |
permit-to-work.authorisation |
Authority GateDecision Map™ |
| Permit scope & isolation bounded to authorised work |
Designed |
L2 Designed |
permit-to-work.scope-isolation |
Purpose Permission™Authority Gate |
| Hand-back & audit contestable + evidenced |
Designed |
L2 Designed |
permit-to-work.handback-audit |
Evidence Pack™Authority Gate |
arrow_forward KYE™ framework reference
PRA SS1/23
PRA SS1/23 — Model Risk Management Principles for Banks
PRA SS1/23 (Model risk management principles for banks, May 2023; effective May 2024) · United Kingdom
PRA SS1/23 sets the UK model risk management principles for banks (Principles 1–5, explicitly including AI/ML models). KYE Protocol™ governs whether a model-driven output or risk report under it may proceed to a consequential action — only a currently-validated model used within its approved scope, model changes as named-authority decisions with evidence, every consequential decision pinned to model_id + version + validation reference, and every risk report bound to its data-lineage evidence chain, sealed into a signed replay-provable Evidence Pack™. The quantitative model build / validation mathematics / capital computation / portfolio composition stays the bank's own work (honest scope, §0 — not investment advice). Per-requirement bijection at /compliance/pra-ss1-23.html.
5 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Model identification & inventory resolution (Principle 1) |
Enforced |
L3 Enforceable |
pra-ss1-23.principle1-model-inventory-resolution |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Governance & named SMF accountability (Principle 2) |
Enforced |
L3 Enforceable |
pra-ss1-23.principle2-governance-named-authority |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Model development, implementation & use incl. AI/ML (Principle 3) |
Enforced |
L3 Enforceable |
pra-ss1-23.principle3-development-implementation-use |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Validation-status binding at the moment of use (Principle 4) |
Enforced |
L3 Enforceable |
pra-ss1-23.principle4-validation-status-binding |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Model risk mitigants & restrictions on use (Principle 5) |
Enforced |
L3 Enforceable |
pra-ss1-23.principle5-mitigants-restrictions |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Independent validation judgment & quantitative work on the meritsThe quantitative model build, validation mathematics, and capital & liquidity computation are the bank's own quantitative work — KYE™ is an AI-authority and evidence layer, not a model-validation or capital-calculation engine. |
Out of scope |
L1 Mapped |
pra-ss1-23.independent-validation-judgment |
— |
arrow_forward KYE™ framework reference
PSD2 SCA Disputes
PSD2 SCA & Unauthorised-Transaction Liability (Arts. 72-74, 97)
PSD2 — Directive (EU) 2015/2366, Arts. 72-74 + 97 (SCA & unauthorised-transaction liability) · European Union
PSD2 Arts. 72-74 + 97 govern SCA and unauthorised-transaction liability in the EU — the PSP carries the burden of proof that the transaction was authenticated and accurately recorded. KYE Protocol™ governs whether an unauthorised-transaction refund / liability allocation may proceed — under a named owner's recorded authority, with the SCA / authentication evidence captured as evidence events at transaction time, and the liability-allocation bundle sealed as a signed, hash-bound, replay-provable Evidence Pack™ that meets the Article 72 burden of proof. The substantive fraud / authorisation determination stays the PSP's / merchant's own (honest scope, §0). Per-requirement bijection at /compliance/psd2-sca-disputes.html.
3 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| SCA / authentication evidence captured at transaction time |
Enforced |
L3 Enforceable |
psd2-sca-disputes.sca-evidence-capture |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Named-authority on the unauthorised-transaction refund |
Enforced |
L3 Enforceable |
psd2-sca-disputes.unauthorised-transaction-refund-authority |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Burden-of-proof evidence integrity for liability allocation |
Enforced |
L3 Enforceable |
psd2-sca-disputes.liability-allocation-evidence |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive fraud / authorisation determination on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. |
Out of scope |
L1 Mapped |
psd2-sca-disputes.fraud-determination |
— |
arrow_forward KYE™ framework reference
Reg E
Reg E — EFTA Error Resolution (12 CFR 1005.11)
EFTA / Regulation E — 12 CFR Part 1005 (error resolution, §1005.11) · United States
Reg E (12 CFR 1005.11) is the US error-resolution framework for electronic fund transfers. KYE Protocol™ governs whether a provisional credit, refund, or error determination in the dispute flow may proceed — under a named owner's recorded authority, with the transaction evidence captured as evidence events at transaction time, a signed replay-provable Evidence Pack™, and a recorded contestable determination. The substantive error adjudication stays the institution's / merchant's own (honest scope, §0). Per-requirement bijection at /compliance/reg-e.html.
3 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Named-authority on the provisional credit / refund action |
Enforced |
L3 Enforceable |
reg-e.provisional-credit-authority |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Investigation evidence record captured at transaction time |
Enforced |
L3 Enforceable |
reg-e.investigation-evidence-record |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & written-determination reconstruction |
Enforced |
L3 Enforceable |
reg-e.error-determination-contestability |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive error adjudication on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. |
Out of scope |
L1 Mapped |
reg-e.substantive-error-adjudication |
— |
arrow_forward KYE™ framework reference
Reg Z
Reg Z — TILA Billing-Error Resolution (12 CFR 1026.13)
TILA / Regulation Z — 12 CFR Part 1026 (billing-error resolution, §1026.13) · United States
Reg Z (12 CFR 1026.13) is the US billing-error-resolution framework for credit accounts. KYE Protocol™ governs whether an account correction, credit, or billing-error determination in the dispute flow may proceed — under a named owner's recorded authority, with the transaction evidence captured as evidence events at transaction time, a signed replay-provable Evidence Pack™, and a recorded contestable determination. The substantive billing-error adjudication stays the creditor's / merchant's own (honest scope, §0). Per-requirement bijection at /compliance/reg-z.html.
3 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Named-authority on the account correction / credit action |
Enforced |
L3 Enforceable |
reg-z.billing-error-resolution-record |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Billing-dispute evidence record captured at transaction time |
Enforced |
L3 Enforceable |
reg-z.billing-dispute-evidence-record |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & written-explanation reconstruction |
Enforced |
L3 Enforceable |
reg-z.billing-dispute-contestability |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive billing-error adjudication on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. |
Out of scope |
L1 Mapped |
reg-z.substantive-billing-error-adjudication |
— |
arrow_forward KYE™ framework reference
RIDDOR
RIDDOR — Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013 (UK)
2013 · United Kingdom
UK RIDDOR 2013 (SI 2013/1471), HSE-enforced. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved RIDDOR-reportable incident reports — the KYE HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed0 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Incident report authored under safety floor |
Designed |
L2 Designed |
riddor.reg-4-6 |
Purpose Permission™Edge Governance Safety Floor |
| Reportability determination advisory pending sign-off |
Designed |
L2 Designed |
riddor.reporting-decision |
Authority GateDecision Map™ |
| Incident records contestable + evidenced |
Designed |
L2 Designed |
riddor.reg-12 |
Evidence Pack™Authority Gate |
arrow_forward KYE™ framework reference
SEC Cyber Disclosure
SEC Cyber Disclosure — Item 1.05 (4 business days)
SEC Cybersecurity Disclosure Rules (2023) — Item 1.05 + Item 106 · United States
SEC Cyber Disclosure (Item 1.05) is the US four-business-day material-cybersecurity-incident disclosure regime on Form 8-K. KYE Protocol™ governs whether an AI-assisted disclosure-timing decision under it may proceed to a consequential disclosure action — under a named accountable officer's authority, with incident-evidence chain-of-custody recorded, and a contestability record so the timing decision can be reconstructed and challenged. The substantive materiality determination / 8-K drafting / legal judgment stays the registrant's own work (honest scope, §0/§70). Per-requirement bijection at /compliance/sec-cyber-disclosure.html.
2 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Disclosure-timing authority on the four-business-day clock |
Enforced |
L3 Enforceable |
sec-cyber-disclosure.item105-materiality-disclosure-authority |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability of the timing decision in an SEC / shareholder review |
Enforced |
L3 Enforceable |
sec-cyber-disclosure.item105-timing-contestability |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive materiality determination & 8-K draftingThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. |
Out of scope |
L1 Mapped |
sec-cyber-disclosure.substantive-materiality-drafting |
— |
arrow_forward KYE™ framework reference
Sedona Principles
The Sedona Principles — Best Practices for Electronic Document Production
The Sedona Principles, Third Edition (2018) · United States
The Sedona Principles — Best Practices for Electronic Document Production is the leading US e-discovery best-practice commentary (The Sedona Principles, Third Edition). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/sedona-principles.html.
2 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Defensible, reconstructable AI-review process record |
Enforced |
L3 Enforceable |
sedona-principles.principle6-defensible-process |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Replay-provable evidence of the process when challenged |
Enforced |
L3 Enforceable |
sedona-principles.replay-provable-process-evidence |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Methodology selection & substantive production completenessThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. |
Out of scope |
L1 Mapped |
sedona-principles.methodology-and-completeness |
— |
arrow_forward KYE™ framework reference
SOX §806
SOX §806 — Whistleblower Anti-Retaliation (18 U.S.C. §1514A)
Sarbanes-Oxley Act §806 (18 U.S.C. §1514A) — whistleblower anti-retaliation · United States
SOX §806 — Whistleblower Anti-Retaliation (18 U.S.C. §1514A) is the US public-company anti-retaliation statute (contributing-factor / clear-and-convincing burden). KYE Protocol™ governs whether an AI-assisted adverse HR action that touches a reporter may proceed — only with a recorded retaliation-risk assessment evidence — and binds a contestability record so the employer's burden-of-proof can be reconstructed if a §806 complaint is filed. Whether the action was in fact retaliatory and the §806 adjudication stay with counsel / OSHA / the courts (honest scope, §0). Per-requirement bijection at /compliance/sox-806.html.
2 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Retaliation-risk assessment evidence before an adverse action |
Enforced |
L3 Enforceable |
sox-806.anti-retaliation-risk-record |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & burden-of-proof reconstruction |
Enforced |
L3 Enforceable |
sox-806.contestability-burden-reconstruction |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Whether the action was in fact retaliatory & §806 adjudicationDeciding whether an action was retaliatory and adjudicating the §806 complaint is a legal determination for counsel and the courts — KYE™ is an AI-authority and evidence layer, not an adjudication engine. |
Out of scope |
L1 Mapped |
sox-806.substantive-retaliation-adjudication |
— |
arrow_forward KYE™ framework reference
CPR PD 57AD
UK CPR Part 31 + PD 57AD — Disclosure & the Disclosure Certificate
CPR Part 31 + Practice Direction 57AD (Disclosure in the Business and Property Courts, 2022) · United Kingdom
UK CPR Part 31 + PD 57AD — Disclosure & the Disclosure Certificate is the English civil disclosure framework (CPR Part 31 + Practice Direction 57AD). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/uk-cpr-pd57ad.html.
2 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Named-authority on the disclosure determination & certificate |
Enforced |
L3 Enforceable |
uk-cpr-pd57ad.disclosure-certificate |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & reconstruction of a disclosure challenge |
Enforced |
L3 Enforceable |
uk-cpr-pd57ad.disclosure-challenge-reconstruction |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive disclosure review & adequacy judgmentThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. |
Out of scope |
L1 Mapped |
uk-cpr-pd57ad.substantive-disclosure-review |
— |
arrow_forward KYE™ framework reference
UK PIDA
UK PIDA — Public Interest Disclosure Act 1998 (ERA 1996 Part IVA)
UK Public Interest Disclosure Act 1998 (Employment Rights Act 1996, Part IVA) · United Kingdom
UK PIDA — Public Interest Disclosure Act 1998 (ERA 1996 Part IVA) is the UK protected-disclosure framework (protection from detriment and automatic-unfair dismissal). KYE Protocol™ governs whether an AI-assisted handling of a protected disclosure, or an adverse action on a worker who made one, may proceed — under a named handler's authority, with a recorded detriment / retaliation-risk assessment before adverse action, and a contestability record so a detriment / dismissal claim can be reconstructed. Whether the disclosure qualifies, whether a detriment occurred, and the tribunal adjudication stay with counsel and the tribunal (honest scope, §0). Per-requirement bijection at /compliance/uk-pida.html.
2 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Named-authority on the protected-disclosure handling & detriment-risk record |
Enforced |
L3 Enforceable |
uk-pida.protected-disclosure-handling-authority |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & reconstruction for a detriment / dismissal claim |
Enforced |
L3 Enforceable |
uk-pida.detriment-claim-reconstruction |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Whether the disclosure qualifies & employment-tribunal adjudicationDeciding whether a disclosure qualifies and adjudicating the tribunal claim is a legal determination for counsel and the tribunal — KYE™ is an AI-authority and evidence layer, not an adjudication engine. |
Out of scope |
L1 Mapped |
uk-pida.qualifying-disclosure-and-adjudication |
— |
arrow_forward KYE™ framework reference
Visa CE 3.0
Visa Compelling Evidence 3.0 (CE3.0)
Visa Compelling Evidence 3.0 (CE3.0) — remedied-dispute evidence requirements (Visa Rules, fraud reason code 10.4) · Global
Visa Compelling Evidence 3.0 defines the qualifying evidence set that remedies a card-absent fraud dispute (prior undisputed transactions, matching device / IP / address / account identifiers, delivery evidence). KYE Protocol™ governs whether the representment may proceed — under a named owner's recorded authority, with the qualifying evidence captured as evidence events at transaction time, and the representment bundle sealed as a signed, hash-bound, WORM-retained, replay-verifiable Evidence Pack™ — exactly the provable evidence set CE3.0 representments turn on. Whether to fight, the narrative, and the outcome stay the merchant's / network's own (honest scope, §0). Per-requirement bijection at /compliance/visa-ce30.html.
3 Enforced0 Designed1 Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Qualifying evidence set captured at transaction time |
Enforced |
L3 Enforceable |
visa-ce30.evidence-set-capture |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Representment bundle integrity (signed · hash-bound · WORM) |
Enforced |
L3 Enforceable |
visa-ce30.representment-bundle-integrity |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Named-authority on the representment decision |
Enforced |
L3 Enforceable |
visa-ce30.representment-authority |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Dispute outcome adjudication & narrative on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. |
Out of scope |
L1 Mapped |
visa-ce30.dispute-outcome-adjudication |
— |
arrow_forward KYE™ framework reference