ECOA / Reg B
ECOA / Regulation B — Equal Credit Opportunity Act
ECOA (15 U.S.C. §1691 et seq.) / Regulation B (12 C.F.R. Part 1002) · United States
ECOA prohibits discrimination in any aspect of a credit transaction and Regulation B operationalises it, including §1002.9 adverse-action notices with a specific statement of reasons. KYE Protocol™ governs whether an AI lending agent's consequential credit decision may proceed — only under a named-authority decision purpose-scoped to the credit transaction, with every adverse action carrying a Decision Map™ (the specific reasons, explainable) bound to a §61 contestability route and sealed into a signed replay-provable Evidence Pack™. The disparate-impact statistics, the credit-scoring feature choice, and the model's fairness validation stay the lender's own quantitative fair-lending work (honest scope, §0). Per-requirement bijection at /compliance/ecoa-reg-b.html.
2 Enforced1 Designed1 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Credit-decision authority at the action boundary |
Enforced |
L3 Enforceable |
ecoa-reg-b.credit-decision-named-authority |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Adverse-action notice with specific reasons |
Enforced |
L3 Enforceable |
ecoa-reg-b.adverse-action-decision-map |
Decision Map™Evidence Pack™Contestability routeReplay-Proof™ |
| Prohibited-basis non-discrimination evidence |
Designed |
L2 Designed |
ecoa-reg-b.prohibited-basis-non-discrimination-evidence |
Decision Map™Audit WORM |
| Fair-lending statistical analysis & model fairnessThe disparate-impact regression, less-discriminatory-alternative search, and model-fairness validation are the lender's own quantitative fair-lending work — KYE™ is an AI-authority and evidence layer, not a fair-lending analytics engine. |
Out of scope |
L1 Mapped |
ecoa-reg-b.fair-lending-statistical-analysis |
— |
arrow_forward KYE™ framework reference
FCRA
FCRA — Fair Credit Reporting Act
Fair Credit Reporting Act (15 U.S.C. §1681 et seq.) / Regulation V (12 C.F.R. Part 1022) · United States
FCRA §1681m requires a user of a consumer report who takes adverse action based on it to give an adverse-action notice naming the reporting agency and the consumer's rights. KYE Protocol™ governs whether an AI lending agent may act on a consumer report — only under a named-authority decision with a permissible purpose, with every report-driven adverse action carrying a Decision Map™ (the report's contribution + the named reporting agency) bound to a §61 contestability route and sealed into a signed replay-provable Evidence Pack™. The report generation, the scoring of report data, and the accuracy of report contents stay the consumer-reporting agency's and furnisher's work (honest scope, §0). Per-requirement bijection at /compliance/fcra.html.
3 Enforced1 Designed2 Out of scope
6 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Credit-report use authority at the decision boundary |
Enforced |
L3 Enforceable |
fcra.credit-report-use-authority |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Adverse-action-on-report notice (specific reasons + agency identity) |
Enforced |
L3 Enforceable |
fcra.adverse-action-on-report-notice |
Decision Map™Evidence Pack™Contestability route |
| Consumer-report data accuracy & furnisher disputesReport-content accuracy, the furnisher's §1681s-2 duties, and reinvestigation of disputes are the reporting agency's and furnisher's obligations — KYE™ governs the lending agent's decision, not the report. |
Out of scope |
L1 Mapped |
fcra.report-accuracy-and-furnisher-disputes |
— |
| Employment / tenant consumer-report use authority |
Enforced |
L3 Enforceable |
fcra.employment-report-permissible-purpose-and-disclosure |
Authority GatePurpose Permission™Evidence Pack™ |
| Employment pre-adverse-action two-step notice |
Designed |
L2 Designed |
fcra.pre-adverse-action-notice |
Decision Map™Contestability route |
| Consumer-report data disposalDisposal of the consumer-report copy and underlying data is the user's own data-handling duty over data KYE™ does not hold — KYE™ governs the agent's authority-to-act, not the report data. |
Out of scope |
L1 Mapped |
fcra.disposal-of-consumer-report-data |
— |
arrow_forward KYE™ framework reference
ICRAA
ICRAA — California Investigative Consumer Reporting Agencies Act
California Investigative Consumer Reporting Agencies Act (ICRAA), Cal. Civ. Code §1786 et seq. · United States
ICRAA is the California-jurisdiction overlay on the federal FCRA for INVESTIGATIVE consumer reports (character / reputation / mode-of-living information gathered through interviews — the bulk of California employment and tenant background screening). It is stricter than FCRA: §1786.16 requires clear-and-conspicuous written notice AND the consumer's written authorization plus a nature-and-scope disclosure before an investigative consumer report is procured; §1786.40 requires an adverse-action notice naming the agency. KYE Protocol™ governs whether an AI agent may PROCEED to procure or act on an investigative consumer report — only under a named-authority decision with a permissible purpose, a recorded written-consent authority, and every adverse action carrying a Decision Map™ + the named agency bound to a §61 contestability route and sealed into a signed replay-provable Evidence Pack™. KYE™ is NOT a consumer reporting agency: it does not generate the report, conduct the interviews, judge the accuracy of the report contents, or run the reinvestigation (honest scope, §0/§70). Per-requirement bijection at /compliance/icraa.html.
3 Enforced1 Designed1 Out of scope
5 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Investigative-report use authority at the procurement/decision boundary |
Enforced |
L3 Enforceable |
icraa.investigative-report-use-authority |
Authority GatePurpose Permission™Evidence Pack™ |
| California written notice + written authorization + nature-and-scope disclosure |
Enforced |
L3 Enforceable |
icraa.written-consent-and-nature-scope-disclosure |
Authority GateDecision Map™Evidence Pack™ |
| Adverse-action-on-investigative-report notice (reasons + agency identity) |
Enforced |
L3 Enforceable |
icraa.adverse-action-notice |
Decision Map™Evidence Pack™Contestability route |
| Consumer copy + dispute / reinvestigation route |
Designed |
L2 Designed |
icraa.consumer-copy-and-dispute-route |
Contestability routeDelegated Auditability |
| Investigative-report content accuracy & agency reinvestigation dutiesReport-content accuracy, the reasonable-procedures duty (§1786.20), and the agency's reinvestigation (§1786.24) are the investigative consumer reporting agency's obligations — KYE™ governs the user's decision, not the report, and is not a CRA. |
Out of scope |
L1 Mapped |
icraa.report-accuracy-and-agency-reinvestigation |
— |
arrow_forward KYE™ framework reference
FCA CONC
FCA CONC — Consumer Credit Sourcebook
FCA Handbook CONC — Consumer Credit Sourcebook · United Kingdom
FCA CONC governs UK consumer-credit conduct, including CONC 5 responsible lending (creditworthiness & affordability) and CONC 7 arrears, default & forbearance. KYE Protocol™ governs whether an AI lending agent's creditworthiness-driven or arrears action may proceed — only under a named-authority decision purpose-scoped to the credit agreement, with the action carrying a Decision Map™ recording that the creditworthiness assessment was relied on, bound to a §61 forbearance/contestability route, and sealed into a signed replay-provable Evidence Pack™. The affordability calculation and credit-policy adequacy stay the lender's own responsible-lending work (honest scope, §0). Per-requirement bijection at /compliance/fca-conc.html.
1 Enforced1 Designed1 Out of scope
3 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Creditworthiness/arrears action authority at the boundary |
Enforced |
L3 Enforceable |
fca-conc.lending-action-named-authority |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Creditworthiness-reliance & forbearance evidence |
Designed |
L2 Designed |
fca-conc.creditworthiness-reliance-evidence |
Decision Map™Evidence Pack™Contestability route |
| Affordability calculation & credit-policy adequacyThe affordability calculation, income/expenditure modelling, and credit-policy adequacy under CONC 5 are the lender's own responsible-lending work — KYE™ governs the agent's action, not the calculation. |
Out of scope |
L1 Mapped |
fca-conc.affordability-calculation-and-policy |
— |
arrow_forward KYE™ framework reference
AICPA SSTS
AICPA SSTS — Statements on Standards for Tax Services
2024 · United States
AICPA Statements on Standards for Tax Services (2024) — the enforceable standards for tax-return positions (reasonable basis / disclosure), reasonable inquiry & reliance on data, and the form & content of advice. KYE Protocol™ governs whether an AI-generated tax position / advice may proceed under a named member's authority, with the SSTS standards recorded before the action — the KYE Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Tax-return positions (SSTS No. 1) |
Designed |
L2 Designed |
aicpa-ssts.ssts1-reasonable-basis, aicpa-ssts.ssts1-disclosure |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Data & reasonable inquiry (SSTS No. 3) |
Designed |
L2 Designed |
aicpa-ssts.ssts3-reasonable-inquiry |
Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| Form & content of advice (SSTS No. 7) |
Designed |
L2 Designed |
aicpa-ssts.ssts7-form-of-advice |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
arrow_forward KYE™ framework reference
AIFMD / UCITS
AIFMD / UCITS — Fund Manager Authority, Risk Management & Investment Limits
Directive 2011/61/EU & Directive 2009/65/EC · European Union
AIFMD (Directive 2011/61/EU) and the UCITS Directive (Directive 2009/65/EC) govern EU collective-investment fund management — fund-manager authorisation & conduct, the risk-management function & limits, investment limits & diversification, and recordkeeping / depositary oversight. KYE Protocol™ governs whether an AI-assisted investment decision/action is within the fund's mandate and limits, authorised, evidenced, and final at the action boundary — the KYE Investment Decision Authority Pack™. KYE Protocol™ does not run the risk-management function, judge whether a decision is correct, produce investment intelligence, or act as a fund manager. Per-requirement bijection at framework-coverage-bijection.
4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Fund manager authorisation & conduct |
Enforced |
L3 Enforceable |
aifmd-ucits.fund-manager-authorisation-conduct |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Risk-management function & limits |
Enforced |
L3 Enforceable |
aifmd-ucits.risk-management-function-limits |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Investment limits & diversification |
Enforced |
L3 Enforceable |
aifmd-ucits.investment-limits-diversification |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Recordkeeping & depositary oversight |
Enforced |
L3 Enforceable |
aifmd-ucits.recordkeeping-depositary-oversight |
Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
arrow_forward KYE™ framework reference
APRA CPS 230
APRA CPS 230 — Operational Risk Management
Effective 1 July 2025 · Australia
APRA Prudential Standard CPS 230 — operational risk management, business continuity and service-provider management for APRA-regulated entities. Per-requirement bijection at /compliance/apra-cps-230.html.
3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Operational risk management (paras 13-21) |
Enforced |
L3 Enforceable |
CPS 230 §13, CPS 230 §15, CPS 230 §18 |
Risk EngineDecision EngineAuthority GatePurpose Permission™Resilience Loop™ |
| Incident notification to APRA (para 20)Detection + package assembly enforced; the regulator-side delivery channel to APRA is in build. |
Enforced |
L3 Enforceable |
CPS 230 §20 |
Incident DetectorReporting Engine |
| Business continuity + service-provider management (paras 30-48) |
Enforced |
L3 Enforceable |
CPS 230 §35, CPS 230 §42 |
Authority RegisterSPoF registryEdge Governance Safety FloorOffline Evidence Log |
arrow_forward KYE™ framework reference
FSA AI Guidelines
FSA AI / Model Governance Expectations for Financial Institutions
FSA AI Discussion Paper (June 2024) + Supervision Guidelines · Japan
The Japan Financial Services Agency's AI governance and model-risk expectations for financial institutions — AI governance & accountability, model risk management, human oversight, explainability and operational resilience. KYE Protocol™ evidences the expectations that bind an AI-supported financial action at runtime. Per-requirement bijection at /compliance/fsa-guidelines-ai.html.
2 Enforced1 Designed0 Out of scope
3 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| AI governance, accountability & model risk management |
Enforced |
L3 Enforceable |
FSA AI governance expectation, FSA model-risk expectation |
Purpose Permission™Risk EngineConformance RunnerDrift Detector |
| Human oversight & explainability/customer disclosure |
Enforced |
L3 Enforceable |
FSA human-oversight expectation, FSA explainability expectation |
GovernedUI™Authority Resolution™Decision Map™Evidence Pack™ |
| Operational resilience & incident reporting to the FSAKYE™ assembles the FSA notification package; the regulator-side delivery channel to the FSA is designed pending the per-jurisdiction reporting connector. |
Designed |
L1 Mapped |
FSA operational-resilience expectation |
Incident DetectorReporting Engine |
arrow_forward KYE™ framework reference
Consumer-Driven Banking
Canada Consumer-Driven Banking Framework (open banking)
Consumer-Driven Banking Act (2024) · Canada
Canada's consumer-driven banking (open banking) framework under the Consumer-Driven Banking Act, 2024 (stood up by the FCAC): accreditation of participants, consumer consent + data-sharing control, a common technical/security standard, and oversight + accountability. Per-requirement bijection at /compliance/canada-cdb.html.
4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Accreditation of participants |
Enforced |
L3 Enforceable |
accreditation |
Authority GateRisk Engine |
| Consumer consent + data-sharing control |
Enforced |
L3 Enforceable |
consent |
Authority GatePurpose Permission™ |
| Common technical + security standard |
Enforced |
L3 Enforceable |
technical-standard |
Authority Gate |
| Oversight + accountability |
Enforced |
L3 Enforceable |
oversight |
Authority GateReporting Engine |
arrow_forward KYE™ framework reference
Companies Act 2006
UK Companies Act 2006 — Accounting Records, True & Fair Accounts & Filing with the Registrar
2006 · United Kingdom
The UK Companies Act 2006 — adequate accounting records (s.386), true and fair view (s.393), director responsibility & board approval (s.414), and filing of the statutory accounts with the Registrar of Companies / Companies House (s.441/s.442). KYE Protocol™ governs whether an AI-generated financial entry / statement / filing may proceed to a consequential action under a named accountant's / director's authority, with §36 two-person sign-off on the irreversible Companies House submission — the KYE Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
0 Enforced4 Designed0 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Adequate accounting records (s.386) |
Designed |
L2 Designed |
companies-act-2006.s386-adequate-records |
Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| True & fair view (s.393) |
Designed |
L2 Designed |
companies-act-2006.s393-true-and-fair |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Director responsibility & approval (s.414) |
Designed |
L2 Designed |
companies-act-2006.s414-director-responsibility |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Filing with the Registrar / Companies House (s.441/s.442) |
Designed |
L2 Designed |
companies-act-2006.s441-filing-with-registrar, companies-act-2006.s442-filing-deadlines |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
arrow_forward KYE™ framework reference
DORA
DORA — Digital Operational Resilience Act
Regulation (EU) 2022/2554 · European Union
EU regulation for the digital operational resilience of the financial sector.
4 Enforced0 Designed1 Out of scope
5 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| ICT risk-management framework |
Enforced |
L3 Enforceable |
Art. 5-16 |
Purpose Permission™Authority GateWORM audit hash-chain |
| ICT incident detection & reconstruction |
Enforced |
L3 Enforceable |
Art. 17-23 |
WORM audit hash-chainDecision replay |
| ICT third-party register & concentration analysis |
Enforced |
L3 Enforceable |
Art. 28(3) |
Directory tenant proxyWORM audit hash-chain |
| Tamper-evident resilience evidenceResilience-testing outcomes are recorded today; signed resilience evidence packs are in build. |
Enforced |
L3 Enforceable |
Art. 24-27 |
Evidence Pack™ signing (COSE-Sign1) |
| ICT third-party contractual arrangementsExit strategies, audit rights, and termination clauses require contract-management tooling outside KYE™. |
Out of scope |
L1 Mapped |
Art. 15, Art. 28-30 |
— |
arrow_forward KYE™ framework reference
DORA Incident
DORA ICT Incident Reporting — Article 19 + classification RTS
DORA — Regulation (EU) 2022/2554, Article 19 + classification RTS · European Union
DORA ICT Incident Reporting (Regulation (EU) 2022/2554, Article 19) is the EU financial-sector ICT-incident reporting regime. KYE Protocol™ governs whether an AI-assisted containment action, incident classification, or staged-report timing decision under it may proceed to a consequential incident action — under a named accountable officer's authority, with incident-evidence chain-of-custody recorded, no AI-asserted classification relied on without a pinned signal source, a signed replay-provable Evidence Pack™ per decision, and a contestability record so any decision can be reconstructed and challenged. Threat detection / SIEM-EDR runtime / forensics / remediation stays the entity's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/dora-ict-incident.html.
3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Named-authority on the containment / response action |
Enforced |
L3 Enforceable |
dora-ict-incident.containment-action-authority |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Incident-evidence chain-of-custody & report integrity |
Enforced |
L3 Enforceable |
dora-ict-incident.incident-evidence-integrity |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Disclosure-timing authority on the staged reporting clock |
Enforced |
L3 Enforceable |
dora-ict-incident.staged-report-timing-authority |
Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Threat detection, forensics & remediation engineeringThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. |
Out of scope |
L1 Mapped |
dora-ict-incident.threat-detection-forensics-remediation |
— |
arrow_forward KYE™ framework reference
EU 6AMLD
EU Sixth Anti-Money Laundering Directive (6AMLD) — Directive (EU) 2018/1673
Directive (EU) 2018/1673 · European Union
The EU Sixth Anti-Money Laundering Directive (Directive (EU) 2018/1673) harmonises money-laundering offences, the 22 predicate offences, aiding/abetting/inciting, and corporate liability across the EU. KYE Protocol™ governs whether an AI agent's AML action may proceed at the action boundary under a named compliance officer's authority, with due diligence before the action and replay-provable provenance. KYE Protocol™ does not run transaction-monitoring models, does not decide whether conduct is criminal money-laundering, and does not replace the institution's AML program or legal advice.
0 Enforced4 Designed0 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Predicate offences & scope (Art. 2/3) |
Designed |
L2 Designed |
eu-6amld.predicate-offences-scope |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Aiding, abetting & inciting (Art. 4) |
Designed |
L2 Designed |
eu-6amld.aiding-abetting-inciting |
Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
| Corporate / legal-person liability (Art. 7/8) |
Designed |
L2 Designed |
eu-6amld.corporate-liability |
Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
| Sanctions & competent-authority cooperation (Art. 9-10) |
Designed |
L2 Designed |
eu-6amld.competent-authority-cooperation |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
arrow_forward KYE™ framework reference
EU DAC
EU DAC — Directive on Administrative Cooperation (DAC6 + DAC7)
dac6-dac7 · European Union
EU Directive on Administrative Cooperation — DAC6 mandatory disclosure of reportable cross-border arrangements (hallmarks A–E, main-benefit test, 30-day window) and DAC7 platform-operator reporting. KYE Protocol™ governs whether an AI-generated arrangement / advice that may be reportable proceeds only after the hallmark / disclosure screen is recorded — the KYE Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| DAC6 hallmark screening |
Designed |
L2 Designed |
eu-dac.dac6-reportable-arrangement, eu-dac.dac6-main-benefit-test |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| DAC6 disclosure & reporting window |
Designed |
L2 Designed |
eu-dac.dac6-disclosure-window |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| DAC7 platform reporting |
Designed |
L2 Designed |
eu-dac.dac7-platform-reporting |
Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
arrow_forward KYE™ framework reference
FATF 40 Recommendations
FATF 40 Recommendations — International Standards on Combating Money Laundering and the Financing of Terrorism & Proliferation
2012 (as amended) · International
The FATF 40 Recommendations are the global AML/CFT authority anchor — risk-based approach (R.1), customer due diligence & beneficial ownership (R.10), record-keeping (R.11), the Travel Rule (R.16), and suspicious-transaction reporting (R.20). KYE Protocol™ governs whether an AI agent's AML action may proceed at the action boundary (alert triage, sanctions screening, SAR/STR drafting, KYC/CDD) under a named compliance officer's authority, with §36 two-person sign-off on the consequential SAR/STR filing — the KYE AML & Financial-Crimes Governance Pack™. KYE Prot™ocol™ does not run transaction-monitoring models, does not decide whether a transaction is truly money-laundering, and does not replace the institution's AML program.
5 Enforced0 Designed0 Out of scope
5 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Risk-based approach (R.1) |
Enforced |
L3 Enforceable |
fatf-40-recommendations.r1-risk-based-approach |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Customer due diligence & beneficial ownership (R.10) |
Enforced |
L3 Enforceable |
fatf-40-recommendations.r10-customer-due-diligence |
Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
| Record-keeping (R.11) |
Enforced |
L3 Enforceable |
fatf-40-recommendations.r11-record-keeping |
Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
| Travel Rule — wire / virtual-asset transfers (R.16) |
Enforced |
L3 Enforceable |
fatf-40-recommendations.r16-travel-rule |
Action Admissibility™ GateEvidence Pack™ |
| Suspicious transaction reporting (R.20) |
Enforced |
L3 Enforceable |
fatf-40-recommendations.r20-suspicious-transaction-reporting |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
arrow_forward KYE™ framework reference
FCA COBS
FCA COBS — Conduct of Business Sourcebook (UK Investment Conduct)
FCA Handbook COBS · United Kingdom
The FCA Conduct of Business Sourcebook (COBS) governs UK investment business with clients — the client's best interests rule (COBS 2.1.1R), suitability (COBS 9), best execution (COBS 11), and recordkeeping. KYE Protocol™ governs whether an AI-assisted investment decision/action is within mandate, authorised, evidenced, and final at the action boundary — the KYE Investment Decision Authority Pack™. KYE Protocol™ does not perform the suitability assessment, judge whether a recommendation is correct, produce investment intelligence, or act as an investment adviser. Per-requirement bijection at framework-coverage-bijection.
4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Client's best interests rule (COBS 2.1.1R) |
Enforced |
L3 Enforceable |
fca-cobs.client-best-interests-rule |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Suitability (COBS 9 / 9A) |
Enforced |
L3 Enforceable |
fca-cobs.suitability-cobs9 |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Best execution (COBS 11.2 / 11.2A) |
Enforced |
L3 Enforceable |
fca-cobs.best-execution-cobs11 |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Recordkeeping of advice & orders |
Enforced |
L3 Enforceable |
fca-cobs.recordkeeping-advice-orders |
Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
arrow_forward KYE™ framework reference
FRC Ethical Standard
FRC Ethical Standard — Integrity, Objectivity & Independence
2024 · United Kingdom
The Financial Reporting Council's Ethical Standard — integrity, objectivity & independence, professional competence & due care, and the threats-and-safeguards framework for auditors and accountants. KYE Protocol™ governs whether an AI-generated entry / statement / conclusion may proceed under a named professional's authority, with the objectivity / independence / competence basis recorded before the action — the KYE Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
0 Enforced4 Designed0 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Integrity |
Designed |
L2 Designed |
frc-ethical-standard.integrity |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Objectivity & independence |
Designed |
L2 Designed |
frc-ethical-standard.objectivity-independence |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Professional competence & due care |
Designed |
L2 Designed |
frc-ethical-standard.professional-competence |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Threats & safeguards framework |
Designed |
L2 Designed |
frc-ethical-standard.threats-safeguards |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
arrow_forward KYE™ framework reference
FSB Sound Practices
FSB Sound Practices for the Responsible Adoption of AI in Finance
consultation-2026-06 · International
The Financial Stability Board's Sound Practices for the Responsible Adoption of AI in Finance (consultation, 10 June 2026) sets supervisory expectations for how financial institutions govern AI across model risk, accountability, third-party dependency, and operational resilience. This framework is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped — no requirement has been bound to a KYE Protocol™ artefact, so coverage is honestly reported as out of scope pending deep mapping. The §70 honesty bar forbids claiming enforced/designed coverage before a requirement is bound to a cited artefact. Deep mapping will be scheduled through the §70 rail (by hand, the §59 deterministic pipeline, or the §70 framework-mapping-agent) once the final report text is pinned.
0 Enforced0 Designed1 Out of scope
1 requirement group — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): the framework is declared in framework-registry.json but no requirement has been bound to a KYE Protocol™ artefact yet. Coverage is reported out of scope until the deep mapping runs through the §70 rail — never inflated to imply enforcement that does not exist. |
Out of scope |
L1 Mapped |
FSB Sound Practices (full consultation text — not yet decomposed into requirement-level mappings) |
— |
arrow_forward KYE™ framework reference
FCA MCOB
FCA MCOB — Mortgage Conduct of Business (FCA Handbook)
FCA Handbook · United Kingdom
FCA Handbook conduct rules for regulated mortgage advice, pre-contract disclosure and responsible lending. KYE Protocol™ governs the AUTHORITY of an AI agent to take a suitability / disclosure / responsible-lending action and the EVIDENCE / replay of that action, under named accountability; KYE Protocol™ does not perform the affordability calculation, author the advice, or determine the regulatory correctness of the mortgage recommendation. Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed1 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Suitability / affordability action admissibility |
Designed |
L2 Designed |
fca-mcob.4.7a |
Purpose Permission™Authority Gate |
| Pre-contract disclosure evidence |
Designed |
L2 Designed |
fca-mcob.5.6 |
Evidence Pack™ |
| Responsible-lending decision record |
Designed |
L2 Designed |
fca-mcob.11.6 |
Evidence Pack™Authority Gate |
| The affordability calculation itself |
Out of scope |
L1 Mapped |
fca-mcob.11a.affordability-calc |
— |
arrow_forward KYE™ framework reference
FCA Consumer Duty
FCA Consumer Duty (PRIN 2A) — Principle 12 & the four outcomes
PRIN 2A · United Kingdom
FCA Handbook PRIN 2A — the Consumer Duty (Principle 12 + the four outcomes). KYE Protocol™ governs the AUTHORITY of an AI agent to act toward a good retail-customer outcome, the consumer-understanding EVIDENCE, and foreseeable-harm contestability; KYE Protocol™ does not assess price-and-value, author the good-outcome judgement, or determine the firm's Consumer Duty compliance. Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed1 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Act-to-deliver-good-outcomes authority gate |
Designed |
L2 Designed |
fca-consumer-duty.prin-2a.2 |
Purpose Permission™Authority Gate |
| Consumer-understanding evidence |
Designed |
L2 Designed |
fca-consumer-duty.prin-2a.6 |
Evidence Pack™ |
| Foreseeable-harm contestability |
Designed |
L2 Designed |
fca-consumer-duty.prin-2a.5 |
Delegated AuditabilityEvidence Pack™ |
| Price-and-value assessment |
Out of scope |
L1 Mapped |
fca-consumer-duty.prin-2a.4 |
— |
arrow_forward KYE™ framework reference
Investment Mandate / IPS
Investment Mandate / IPS — Investment Policy Statement & Discretionary Mandate Authority
2026 · International
The Investment Policy Statement (IPS) / discretionary investment mandate — the authority anchor for AI-assisted investment decisions. Defines permitted investments, concentration / liquidity limits, prohibited investments, named authority / delegation, and reporting obligations. KYE Protocol™ governs whether an AI-assisted investment decision/action is within the recorded mandate, under whose authority it proceeds, evidenced, contestable, and final at the action boundary — the KYE Investment Decision Authority Pack™. KYE Protocol™ does not produce investment intelligence, judge whether a thesis is correct, or render any view on alpha / returns / suitability of outcome, and is not an investment adviser. Per-requirement bijection at framework-coverage-bijection.
0 Enforced4 Designed0 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Mandate scope & permitted investments |
Designed |
L2 Designed |
investment-mandate-ips.mandate-scope-permitted-investments |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Constraints, limits & prohibitions |
Designed |
L2 Designed |
investment-mandate-ips.constraints-limits-prohibitions |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Named authority & delegation |
Designed |
L2 Designed |
investment-mandate-ips.named-authority-delegation |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Reporting & evidence obligations |
Designed |
L2 Designed |
investment-mandate-ips.reporting-evidence-obligations |
Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
arrow_forward KYE™ framework reference
Circular 230
IRS Circular 230 — Regulations Governing Practice before the IRS
2014-rev · United States
Treasury Department Circular No. 230 (31 CFR Part 10) — the standards of practice (due diligence §10.22, competence §10.35, return positions §10.34, written advice §10.37) for practitioners before the IRS. KYE Protocol™ governs whether an AI-generated tax position/filing/advice may proceed to a consequential action under a named preparer's authority — the KYE Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Due diligence & competence |
Designed |
L2 Designed |
irs-circular-230.10.22-due-diligence, irs-circular-230.10.35-competence |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Tax-return positions & written advice |
Designed |
L2 Designed |
irs-circular-230.10.34-positions, irs-circular-230.10.37-written-advice |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Practitioner authority & sign-off |
Designed |
L2 Designed |
irs-circular-230.preparer-signoff |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
arrow_forward KYE™ framework reference
ISA (UK)
ISA (UK) — International Standards on Auditing (UK)
2024 · United Kingdom
The International Standards on Auditing (UK) — professional scepticism & reasonable assurance (ISA 200), fraud responsibilities (ISA 240), risk identification & assessment (ISA 315), and forming the opinion & reporting (ISA 700). KYE Protocol™ governs whether an AI-generated audit working-paper / conclusion may proceed under a named auditor's authority, with the ISA (UK) responsibilities recorded before the action — the KYE Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
0 Enforced4 Designed0 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Professional scepticism & reasonable assurance (ISA 200) |
Designed |
L2 Designed |
isa-uk.isa200-professional-scepticism |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Fraud responsibilities (ISA 240) |
Designed |
L2 Designed |
isa-uk.isa240-fraud-responsibilities |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Risk identification & assessment (ISA 315) |
Designed |
L2 Designed |
isa-uk.isa315-risk-assessment |
Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| Forming the opinion & reporting (ISA 700) |
Designed |
L2 Designed |
isa-uk.isa700-forming-opinion |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
arrow_forward KYE™ framework reference
MAS TRM
MAS Technology Risk Management Guidelines
Jan 2021 · Singapore
Monetary Authority of Singapore Technology Risk Management Guidelines — access control, audit logging, IT incident management, third-party risk. Per-requirement bijection at /compliance/mas-trm.html.
2 Enforced0 Designed0 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Access control + tamper-resistant audit logging |
Enforced |
L3 Enforceable |
MAS TRM — access control, MAS TRM — audit logging |
Authority GateAuthority Revocation OrchestratorWORM audit hash-chainStreaming Logs Contract™ |
| IT incident management + third-party riskThird-party risk enforced via Authority Register + SPoF; the MAS incident-notification delivery channel is in build. |
Enforced |
L3 Enforceable |
MAS TRM — incident management, MAS TRM — third-party risk |
Incident DetectorReporting EngineAuthority RegisterSPoF registry |
arrow_forward KYE™ framework reference
MiFID II
MiFID II — Markets in Financial Instruments Directive II (Investment Services Conduct)
Directive 2014/65/EU · European Union
MiFID II (Directive 2014/65/EU) governs the provision of investment services in the EU — acting in the client's best interest (Art. 24), suitability (Art. 25), best execution (Art. 27), and recordkeeping. KYE Protocol™ governs whether an AI-assisted investment decision/action is within mandate, authorised, evidenced, and final at the action boundary — the KYE Investment Decision Authority Pack™. KYE Protocol™ does not perform the suitability assessment, judge whether a recommendation is correct, produce investment intelligence, or act as an investment adviser. Per-requirement bijection at framework-coverage-bijection.
4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Acting in the client's best interest (Art. 24) |
Enforced |
L3 Enforceable |
mifid-ii.art24-best-interest |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Suitability & appropriateness (Art. 25) |
Enforced |
L3 Enforceable |
mifid-ii.art25-suitability |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Best execution (Art. 27) |
Enforced |
L3 Enforceable |
mifid-ii.art27-best-execution |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Recordkeeping & basis of advice |
Enforced |
L3 Enforceable |
mifid-ii.recordkeeping-basis-of-advice |
Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
arrow_forward KYE™ framework reference
Pillar Two
OECD Pillar Two — GloBE Rules (Global Minimum Tax) & BEPS
2023-globe · International
OECD/G20 Pillar Two GloBE rules — a 15% global minimum effective tax rate (IIR / UTPR) with a per-jurisdiction top-up tax reported in the GloBE Information Return (GIR). KYE Protocol™ governs whether an AI-generated Pillar Two computation may proceed to a filing or a booked liability — the KYE Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| GloBE effective-tax-rate & top-up tax |
Designed |
L2 Designed |
oecd-pillar-two.globe-top-up-tax, oecd-pillar-two.effective-tax-rate |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| GloBE Information Return (GIR) |
Designed |
L2 Designed |
oecd-pillar-two.gir-information-return |
Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| Scope & charging-rule determination |
Designed |
L2 Designed |
oecd-pillar-two.scope-charging-rule |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
arrow_forward KYE™ framework reference
OSFI B-10
OSFI Guideline B-10 — Third-Party Risk Management
Effective 1 May 2024 · Canada
OSFI Guideline B-10 — risk-based management of third-party arrangements for federally regulated financial institutions: the arrangement register, criticality-proportionate risk assessment, and ongoing monitoring + concentration risk. Per-requirement bijection at /compliance/osfi-b-10.html.
3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Third-party arrangement register |
Enforced |
L3 Enforceable |
register |
Authority GateRisk Engine |
| Risk assessment by criticality |
Enforced |
L3 Enforceable |
risk-assessment |
Risk Engine |
| Ongoing monitoring + concentration risk |
Enforced |
L3 Enforceable |
monitoring |
Offline Evidence LogRisk Engine |
arrow_forward KYE™ framework reference
OSFI B-13
OSFI Guideline B-13 — Technology & Cyber Risk Management
Effective 1 Jan 2024 · Canada
OSFI Guideline B-13 — technology and cyber risk management for federally regulated financial institutions: governance, technology operations + resilience, and cyber security. Per-requirement bijection at /compliance/osfi-b-13.html.
3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Governance + risk management (Domain 1) |
Enforced |
L3 Enforceable |
d1 |
Authority GateRisk Engine |
| Technology operations + resilience (Domain 2) |
Enforced |
L3 Enforceable |
d2-asset-register, d2-resilience |
Authority GateEdge Governance Safety FloorOffline Evidence LogRisk Engine |
| Cyber security — monitoring + incident (Domain 3) |
Enforced |
L3 Enforceable |
d3 |
Incident DetectorWORM audit hash-chain |
arrow_forward KYE™ framework reference
OSFI E-23
OSFI Guideline E-23 — Model Risk Management
Effective 1 May 2027 · Canada
OSFI Guideline E-23 — enterprise-wide model risk management across the model lifecycle (model definition expanded to AI/ML): inventory + risk rating, independent validation, ongoing monitoring, and accountability. Per-requirement bijection at /compliance/osfi-e-23.html.
3 Enforced1 Designed0 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Model inventory + risk rating |
Enforced |
L3 Enforceable |
inventory |
Authority GateRisk Engine |
| Development + independent validation |
Designed |
L2 Designed |
validation |
Replay-Proof™WORM audit hash-chain |
| Ongoing monitoring |
Enforced |
L3 Enforceable |
monitoring |
Drift DetectorRisk Engine |
| Roles + accountability |
Enforced |
L3 Enforceable |
accountability |
Authority Gate |
arrow_forward KYE™ framework reference
PCI DSS
PCI DSS — Payment Card Industry Data Security Standard
4.0 · Global
Security standard for entities that store, process, or transmit cardholder data.
2 Enforced1 Designed1 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Access control & strong authentication |
Enforced |
L3 Enforceable |
Req 7, Req 8 |
Authority GateWebAuthn step-upPurpose Permission™ |
| Audit logging & monitoring |
Enforced |
L3 Enforceable |
Req 10 |
WORM audit hash-chainDecision replay |
| Stored account-data protection evidenceKYE™ governs access to account data; signed evidence of protection and a FIPS-validated crypto adapter are in build. |
Designed |
L2 Designed |
Req 3 |
Evidence Pack™ signing (COSE-Sign1)FIPS-validated crypto module |
| Network security, anti-malware & physical accessNetwork segmentation, TLS termination, endpoint protection, and physical access to cardholder data are operated by the customer. |
Out of scope |
L1 Mapped |
Req 1, Req 4, Req 5, Req 9 |
— |
arrow_forward KYE™ framework reference
PCMLTFA / FINTRAC
PCMLTFA / FINTRAC — Anti-Money-Laundering & Terrorist-Financing
S.C. 2000, c. 17 · Canada
Canada's anti-money-laundering and terrorist-financing regime (PCMLTFA + Regulations, administered by FINTRAC): client identification + KYC, ongoing monitoring, suspicious-transaction reporting, and record-keeping. Per-requirement bijection at /compliance/pcmltfa-fintrac.html.
4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Client identification + KYC |
Enforced |
L3 Enforceable |
kyc |
Authority GateDecision Map™ |
| Ongoing monitoring |
Enforced |
L3 Enforceable |
monitoring |
Drift DetectorRisk Engine |
| Suspicious transaction reporting (s.7) |
Enforced |
L3 Enforceable |
s7-str |
Incident DetectorReporting Engine |
| Record-keeping (s.6) |
Enforced |
L3 Enforceable |
s6-records |
WORM audit hash-chain |
arrow_forward KYE™ framework reference
PSD2 / PSD3
PSD2 / PSD3 — EU Payment Services Directive
PSD2 2015/2366 · European Union
EU payment-services regulation covering strong customer authentication and third-party access to accounts.
2 Enforced1 Designed1 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Strong customer authentication |
Enforced |
L3 Enforceable |
RTS Art. 4-9 |
WebAuthn step-upAuthority Gate |
| Third-party-provider access governance |
Enforced |
L3 Enforceable |
Art. 66-67 |
Purpose Permission™Directory tenant proxy |
| Transaction authorisation evidenceEvery transaction authorisation is recorded today; signed, third-party-verifiable transaction evidence is in build. |
Designed |
L2 Designed |
Art. 97 |
Evidence Pack™ signing (COSE-Sign1)Decision Map™ signing (JWS-detached) |
| Liability allocation frameworkKYE™ produces evidence relevant to liability, but the contractual allocation of liability is a legal matter. |
Out of scope |
L1 Mapped |
Art. 97(5) |
— |
arrow_forward KYE™ framework reference
RBNZ BS11
RBNZ BS11 — Outsourcing Policy
BS11 Outsourcing Policy · New Zealand
Reserve Bank of New Zealand outsourcing policy — control over outsourced functions, continuity of basic banking functions, continuing compliance evidence. Per-requirement bijection at /compliance/rbnz-bs11.html.
2 Enforced0 Designed0 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Outsourcing register + continuity of basic banking functions |
Enforced |
L3 Enforceable |
BS11 — outsourcing register, BS11 — basic banking functions |
Authority RegisterSPoF registryEdge Governance Safety FloorOffline Evidence Log |
| Continuing compliance evidence to RBNZ |
Enforced |
L3 Enforceable |
BS11 — control evidence |
Evidence Pack™Regulator Replay agentWORM audit hash-chain |
arrow_forward KYE™ framework reference
SEC IA Fiduciary
SEC Investment Adviser Fiduciary Duty — Advisers Act of 1940 (Duty of Care & Loyalty)
Investment Advisers Act of 1940 · United States
The US Investment Advisers Act of 1940 (s.206) and the SEC's 2019 fiduciary interpretation establish a federal fiduciary duty for registered investment advisers — a duty of care, a duty of loyalty, and the books-and-records rule (204-2). KYE Protocol™ governs whether an AI-assisted investment decision/action is within mandate, authorised, evidenced, and final at the action boundary — the KYE Investment Decision Authority Pack™. KYE Protocol™ does not form the reasonable belief, judge whether advice is correct, produce investment intelligence, or act as an investment adviser. Per-requirement bijection at framework-coverage-bijection.
4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Duty of care — reasonable belief best interest |
Enforced |
L3 Enforceable |
sec-ia-fiduciary.duty-of-care-best-interest |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Duty of loyalty — conflicts & disclosure |
Enforced |
L3 Enforceable |
sec-ia-fiduciary.duty-of-loyalty-conflicts |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Suitability / mandate of advice |
Enforced |
L3 Enforceable |
sec-ia-fiduciary.suitability-mandate-of-advice |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Books & records (Rule 204-2) |
Enforced |
L3 Enforceable |
sec-ia-fiduciary.books-and-records-204-2 |
Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
arrow_forward KYE™ framework reference
SOX 404
SOX §404 — Internal Control over Financial Reporting (tax provision)
2002 · United States
Sarbanes-Oxley §404 — management (and auditor) assessment of internal control over financial reporting (ICFR), with the income-tax provision a recurring material-weakness source requiring review controls, documentation, and data integrity. KYE Protocol™ governs whether an AI-generated tax-provision figure may proceed to being booked under recorded management-review controls with replay-provable provenance — the KYE Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Tax-provision ICFR design |
Enforced |
L3 Enforceable |
sox-404.tax-provision-icfr |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Review & approval controls |
Enforced |
L3 Enforceable |
sox-404.management-review-control |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Documentation & data integrity |
Enforced |
L3 Enforceable |
sox-404.documentation-data-integrity |
Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| Management attestation |
Enforced |
L3 Enforceable |
sox-404.management-attestation |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
arrow_forward KYE™ framework reference
FRS 102
UK GAAP — FRS 102 / FRS 105 Recognition, Measurement & Disclosure
2024 · United Kingdom
FRS 102 / FRS 105 (UK GAAP) — recognition and measurement bases, accounting-policy selection and consistency, disclosure requirements, and the micro-entity regime. KYE Protocol™ governs whether an AI-generated entry / statement may proceed with the FRS 102 / FRS 105 recognition, measurement, and disclosure basis recorded before the action — the KYE Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
0 Enforced4 Designed0 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Recognition & measurement |
Designed |
L2 Designed |
uk-gaap-frs102.frs102-recognition-measurement |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Accounting policies & consistency |
Designed |
L2 Designed |
uk-gaap-frs102.frs102-accounting-policies |
Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| Disclosure requirements |
Designed |
L2 Designed |
uk-gaap-frs102.frs102-disclosure |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Micro-entity (FRS 105) regime |
Designed |
L2 Designed |
uk-gaap-frs102.frs105-micro-entity |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
arrow_forward KYE™ framework reference
UK MTD
UK Making Tax Digital (MTD) — Digital Record-Keeping & API Filing
2024 · United Kingdom
HMRC Making Tax Digital — digital record-keeping, unbroken digital links from source data to submitted figures, and programmatic filing via the MTD API. KYE Protocol™ governs whether an AI-generated MTD figure may proceed to an API submission under a named preparer's authority, preserving the digital link in replay-provable provenance — the KYE Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Digital record-keeping & digital links |
Designed |
L2 Designed |
uk-mtd.digital-record-keeping, uk-mtd.digital-links |
Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| API filing integrity |
Designed |
L2 Designed |
uk-mtd.api-filing-integrity |
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Preparer authority for submission |
Designed |
L2 Designed |
uk-mtd.preparer-authority-submission |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
arrow_forward KYE™ framework reference
US BSA / FinCEN
US Bank Secrecy Act / FinCEN — AML Program, CDD & SAR Requirements
31 U.S.C. 5311 et seq.; 31 CFR Chapter X · United States
The US Bank Secrecy Act (31 U.S.C. 5311 et seq.) and FinCEN regulations (31 CFR Chapter X) require a risk-based AML program (5318(h)), customer due diligence & beneficial ownership (CDD Rule), Suspicious Activity Reports (SARs), and record-keeping. KYE Protocol™ governs whether an AI agent's AML action may proceed at the action boundary under a named BSA/AML officer's authority, with §36 two-person sign-off on the consequential SAR filing. KYE Protocol™ does not run transaction-monitoring models, does not decide whether a transaction is truly suspicious, and does not replace the institution's BSA/AML program.
4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| AML program (31 U.S.C. 5318(h)) |
Enforced |
L3 Enforceable |
us-bsa-fincen.aml-program-5318h |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Customer due diligence & beneficial ownership (CDD Rule) |
Enforced |
L3 Enforceable |
us-bsa-fincen.cdd-beneficial-ownership |
Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
| Suspicious Activity Reporting (SAR) |
Enforced |
L3 Enforceable |
us-bsa-fincen.sar-filing |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Record-keeping (31 CFR Chapter X) |
Enforced |
L3 Enforceable |
us-bsa-fincen.record-keeping |
Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
arrow_forward KYE™ framework reference
Wolfsberg Principles
Wolfsberg Group AML Principles & Guidance
current · International
The Wolfsberg Group publishes industry AML, sanctions-screening, and correspondent-banking due-diligence standards for global banks. KYE Protocol™ governs whether an AI agent's AML or sanctions-screening action may proceed at the action boundary under a named compliance officer's authority, with due diligence before the action and replay-provable provenance. KYE Protocol™ does not run the screening engine, does not decide whether a name is a true sanctions match, and does not replace the institution's AML / sanctions program.
0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Risk-based KYC / CDD |
Designed |
L2 Designed |
wolfsberg-principles.risk-based-kyc-cdd |
Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
| Sanctions & transaction screening governance |
Designed |
L2 Designed |
wolfsberg-principles.sanctions-screening-governance |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Correspondent-banking due diligence |
Designed |
L2 Designed |
wolfsberg-principles.correspondent-banking-due-diligence |
Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
arrow_forward KYE™ framework reference
ECB AI Supervisory Expectations
ECB Supervisory Expectations on AI-Amplified Cyber and Operational Risk
emerging-2026 · EU
ECB Banking Supervision's emerging expectations on AI-amplified cyber and operational risk for significant institutions (planned 'dear CEO letter', per Reuters 3 June 2026; part of the ECB 2026–2028 supervisory priorities). REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: no formal requirement text has been published, so coverage is honestly reported as out of scope pending deep mapping. The §70 honesty bar forbids claiming enforced/designed coverage before requirements are pinned. The substance — AI-actor authority, privileged-action gating, incident-response authority, replay-derivable evidence — is already covered by KYE Protocol™'s deep-mapped DORA artefacts and the shipped Cyber Resilience & Incident Authority Pack; deep mapping will graft those once the ECB text is final.
0 Enforced0 Designed1 Out of scope
1 requirement group — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no requirement bound to a KYE Protocol™ artefact yet because no formal text is published. Coverage reported out of scope until the ECB requirements are pinned and deep-mapped through the §70 rail — never inflated. The DORA / Cyber Resilience & Incident Authority Pack artefacts already answer the substance and will be grafted on publication. |
Out of scope |
L1 Mapped |
ECB AI supervisory expectations (forthcoming dear-CEO letter — not yet decomposed into requirement-level mappings) |
— |
arrow_forward KYE™ framework reference
SM&CR
UK Senior Managers & Certification Regime (SM&CR)
2016 (as amended) · United Kingdom
UK SM&CR accountability regime. KYE Protocol™ governs whether an AI agent's action may proceed under a named Senior Manager's delegated authority, with the responsibility line recorded and replay-provable. Consumed via kye:rule-pack:sm-cr + kye:sector-pack:uk-financial-services-sm-cr (§0: never re-mapped). Per-requirement bijection at framework-coverage-bijection.
0 Enforced2 Designed0 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| SMF responsibility + duty-of-responsibility evidence |
Designed |
L2 Designed |
uk-smcr.smf-responsibility, uk-smcr.duty-of-responsibility |
Purpose Permission™Evidence Pack™Replay Proof™ |
| Certification scope + contestable conduct record |
Designed |
L2 Designed |
uk-smcr.certification, uk-smcr.conduct-rules |
Purpose Permission™Delegated Auditability |
arrow_forward KYE™ framework reference
Failure to Prevent Fraud
UK Failure to Prevent Fraud (ECCTA 2023)
ECCTA 2023 (in force 1 Sep 2025) · United Kingdom
UK ECCTA 2023 corporate 'failure to prevent fraud' offence. KYE Protocol™ turns AI-actor authority into a demonstrable 'reasonable fraud-prevention procedure': AI actions that could facilitate fraud are gated by named authority, evidenced, and contestable. KYE Protocol™ proves the procedure operated; it does not adjudicate the offence. Per-requirement bijection at framework-coverage-bijection.
0 Enforced2 Designed0 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Reasonable procedures (statutory defence) + evidence |
Designed |
L2 Designed |
uk-eccta-ftpf.reasonable-procedures, uk-eccta-ftpf.evidence-of-procedures |
Purpose Permission™Evidence Pack™Replay Proof™ |
| Fraud risk assessment + monitoring |
Designed |
L2 Designed |
uk-eccta-ftpf.risk-assessment, uk-eccta-ftpf.monitoring-review |
Decision Map™Delegated Auditability |
arrow_forward KYE™ framework reference
UK MLR 2017
UK Money Laundering Regulations 2017 (MLR 2017)
SI 2017/692 (as amended) · United Kingdom
UK MLR 2017 AML/CTF obligations. KYE Protocol™ governs whether an AI agent's AML action may proceed under a named compliance officer's authority, with due diligence recorded and replay-provable provenance. Consumed via the aml-financial-crimes spine (§0: never re-mapped). KYE Protocol™ proves the basis; it does not decide whether conduct is money laundering. Per-requirement bijection at framework-coverage-bijection.
0 Enforced2 Designed0 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Risk assessment + customer due diligence |
Designed |
L2 Designed |
uk-mlr-2017.risk-assessment, uk-mlr-2017.cdd |
Purpose Permission™Decision Map™ |
| Ongoing monitoring + replay-derivable records |
Designed |
L2 Designed |
uk-mlr-2017.ongoing-monitoring, uk-mlr-2017.record-keeping |
Delegated AuditabilityEvidence Pack™Replay Proof™ |
arrow_forward KYE™ framework reference
MiCA
MiCA — Markets in Crypto-Assets Regulation
Regulation (EU) 2023/1114 · European Union
EU regulation for crypto-asset issuance and crypto-asset service providers (CASPs): custody, conduct, conflicts, complaints, and the Travel Rule overlay. Titles III–IV from Jun 2024; Title V from Dec 2024.
3 Enforced1 Designed1 Out of scope
5 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Custody & administration of crypto-assets (Art. 70, 75, 76) |
Enforced |
L3 Enforceable |
Art. 75 |
MiCA custody rule packEvidence Pack™ signingAuthority Gate |
| CASP conduct & conflict-of-interest screening (Art. 66, 72) |
Enforced |
L3 Enforceable |
Art. 66, Art. 72 |
Purpose Permission™Decision replay |
| Complaints handling (Art. 71)Evidenced complaint-handling response is design-locked; a CASP complaint-intake-and-tracking runtime path is not yet wired. |
Designed |
L2 Designed |
Art. 71 |
Comms Rail (evidenced response) |
| Travel Rule + AML overlay for crypto-asset transfers |
Enforced |
L3 Enforceable |
Reg (EU) 2023/1113 |
Travel-Rule rule packAML financial-crimes rule pack |
| Token white paper, authorisation & reserve of assetsReserve of assets, prudential own-funds, white-paper notification and issuer/CASP authorisation are prudential/licensing obligations of the regulated entity and its competent authority, outside KYE™'s lane. |
Out of scope |
L1 Mapped |
Art. 16, Art. 36, Art. 54 |
— |
arrow_forward KYE™ framework reference
GENIUS Act
GENIUS Act — US payment stablecoin law
GENIUS Act (Pub. L. 119-27, 2025) · United States
First US federal law governing payment stablecoins: 1:1 reserve backing, redemption at par, monthly reserve disclosure, BSA/AML obligations, lawful-order (freeze/seize/burn) capability, and marketing restrictions. Prudential rulemaking deadline July 2026.
2 Enforced1 Designed2 Out of scope
5 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Redemption at par on demand |
Enforced |
L3 Enforceable |
§4 |
Purpose Permission™Authority Gate |
| Monthly reserve-composition disclosure (certified)KYE™ produces a tamper-evident, certify-able evidence pack for the disclosure; the reserve-composition data is the issuer's and the disclosure-assembly flow is design-locked, not yet wired. |
Designed |
L2 Designed |
§4 |
Evidence Pack™ signingWORM audit hash-chain |
| BSA / AML program + sanctions / lawful-order capability |
Enforced |
L3 Enforceable |
§4 |
AML financial-crimes rule packAuthority GateWORM audit hash-chain |
| 1:1 reserve backing & no-yield constraintHolding/investing the 1:1 reserve and the no-yield prohibition are balance-sheet/product obligations of the issuer, outside KYE™'s lane. |
Out of scope |
L1 Mapped |
§4 |
— |
| Issuer authorisation, charter & prudential supervisionFederal/state issuer authorisation, charter and prudential supervision are licensing/supervision obligations of the issuer and its regulator, outside KYE™'s lane. |
Out of scope |
L1 Mapped |
§3, §5 |
— |
arrow_forward KYE™ framework reference
Singapore PS Act
Singapore Payment Services Act 2019 (PS Act)
PS Act 2019 (No. 2 of 2019), as amended · Singapore
Singapore's licensing and conduct regime for payment service providers, administered by MAS: seven regulated activities (account issuance, domestic and cross-border money transfer, merchant acquisition, e-money issuance, digital payment token services, money-changing) across three licence classes, with AML/CFT, technology-risk and user-protection conditions. This framework is REGISTERED in the §70 Framework Mapping Rail following the statute-class precedent of the DORA and PSD2/PSD3 rows; deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.
0 Enforced0 Designed1 Out of scope
1 requirement group — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no PS Act requirement is bound to a KYE Protocol™ artefact yet. The payment-authorization rail's authority controls are platform-level and cross-regime; PS-Act-specific deep mapping (licence-class conditions, DPT-service obligations) is scheduled through the §70 rail. Coverage is never inflated. |
Out of scope |
L1 Mapped |
PS Act 2019 — licensing (Part 2), conduct of business (Part 3), and AML/CFT + technology-risk licence conditions; full text not yet decomposed into requirement-level mappings |
— |
arrow_forward KYE™ framework reference
Singapore SFA
Singapore Securities and Futures Act 2001 (SFA)
SFA 2001 (2020 Revised Edition), as amended · Singapore
Singapore's capital-markets statute, administered by MAS: licensing of capital-markets services, regulation of organised markets and clearing facilities, offers of investments and prospectus requirements, market-conduct prohibitions (false trading, market rigging, insider trading), and derivatives-contract regulation. This framework is REGISTERED in the §70 Framework Mapping Rail following the statute-class precedent of the DORA and PSD2/PSD3 rows; deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.
0 Enforced0 Designed1 Out of scope
1 requirement group — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no SFA requirement is bound to a KYE Protocol™ artefact yet. SFA-specific deep mapping (licensing, market-conduct, disclosure obligations) is scheduled through the §70 rail. Coverage is never inflated. |
Out of scope |
L1 Mapped |
SFA 2001 — capital-markets services licensing, market conduct (Part 12), offers of investments (Part 13); full text not yet decomposed into requirement-level mappings |
— |
arrow_forward KYE™ framework reference
TARGET2
TARGET2 / T2 RTGS (ECB) — incl. Settlement Finality Directive 98/26/EC
ECB TARGET Guideline (EU) 2022/912 (ECB/2022/8) + Directive 98/26/EC Arts 3 & 5 · European Union
The Eurosystem's real-time gross settlement system settles payment orders in central bank money with finality conferred at the moment of entry under the Settlement Finality Directive — an entered order cannot be unwound. KYE Protocol™ governs the payment-authority dimension: every instruction (human- or AI-agent-originated) must resolve to a live, purpose-scoped mandate of an authorised user of an admitted participant, with the admissibility verdict, sealed decision context and hash-bound Evidence Pack™ complete BEFORE the finality moment, revocation biting on the very next action, and the message's authorisation lineage retained append-only over the record-keeping period. Settlement execution, legal conferral of finality and intraday liquidity/credit stay the Eurosystem's and the participant treasury's own (honest scope, §0). Per-requirement bijection at /compliance/target2-rtgs.html.
4 Enforced1 Designed2 Out of scope
7 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Participation, access criteria & authorised-user binding |
Enforced |
L3 Enforceable |
target2-rtgs.participation-access-authority |
Purpose Permission™Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Settlement finality & the pre-entry authority checkpoint (SFD 98/26/EC) |
Enforced |
L3 Enforceable |
target2-rtgs.pre-settlement-authority-checkpoint |
Authority GateContext sealEvidence Pack™Replay-Proof™ |
| Suspension, termination & revocation propagation |
Enforced |
L3 Enforceable |
target2-rtgs.revocation-suspension-propagation |
Authority GateAuthority-drift monitoringKill-switch semantics |
| ISO 20022 messaging integrity & record retention |
Enforced |
L3 Enforceable |
target2-rtgs.message-integrity-records |
Evidence Pack™WORM audit hash-chainRetention policy |
| Operational resilience, self-certification & incident notificationKYE™ supplies the machine-generated attestation cadence and sealed incident evidence the self-certification and notification duties run on; the participant's BCM programme, endpoint security and the submissions themselves are participant-owned and not claimed as enforced. |
Designed |
L2 Designed |
target2-rtgs.operational-resilience-incident |
≤90-day attestationEvidence Pack™ |
| Settlement execution & legal conferral of finalitySettlement in central bank money and the SFD's legal conferral of finality/irrevocability are performed and owned by the Eurosystem as system operator — KYE™ is an AI-authority and evidence layer, not a settlement engine or designated system. |
Out of scope |
L1 Mapped |
target2-rtgs.settlement-finality-execution |
— |
| Liquidity provision & intraday creditFunding MCAs/DCAs, collateralised intraday credit and liquidity reservations are treasury and central-bank functions — KYE™ is not a liquidity-management or collateral engine. |
Out of scope |
L1 Mapped |
target2-rtgs.liquidity-intraday-credit |
— |
arrow_forward KYE™ framework reference
CIPS
CIPS — Cross-Border Interbank Payment System (RMB)
CIPS participant and business rules — direct/indirect participation, ISO 20022 messaging, RTGS + hybrid netting · China
CIPS clears and settles cross-border RMB payments for direct participants (settling on CIPS accounts) and indirect participants routed through sponsoring direct participants, over ISO 20022-based messaging with RTGS and hybrid-netting settlement. KYE Protocol™ governs the payment-authority dimension only: participant mandate binding at the moment of action, the pre-settlement authority checkpoint (verdict + sealed evidence before the instruction is released), message-authorisation lineage retained append-only, and the authority + evidence layer of the participant's OWN financial-crime screening decision under the laws applicable to that participant — KYE™ takes no position on any jurisdiction's sanctions regime and provides nothing that weakens or routes around a screening obligation. Settlement execution, netting sessions and liquidity funding stay the operator's and participants' own (honest scope, §0). Per-requirement bijection at /compliance/cips-cross-border.html.
3 Enforced2 Designed1 Out of scope
6 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Participation & authorised-user binding |
Enforced |
L3 Enforceable |
cips-cross-border.participant-authority |
Purpose Permission™Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Pre-settlement authority checkpoint & irrevocability |
Enforced |
L3 Enforceable |
cips-cross-border.pre-settlement-authority-checkpoint |
Authority GateContext sealEvidence Pack™Replay-Proof™ |
| ISO 20022 messaging integrity & record retention |
Enforced |
L3 Enforceable |
cips-cross-border.message-integrity-records |
Evidence Pack™WORM audit hash-chainRetention policy |
| Financial-crime screening authority & evidenceScope-guarded: KYE™ governs the authority and evidence layer of the participant's own screening decision under the AML/CTF and sanctions laws applicable to that participant. Screening adjudication itself — list management, matching, disposition — is the participant's / their vendor's own and is not claimed. |
Designed |
L2 Designed |
cips-cross-border.financial-crime-screening-authority |
Named-authority bindingScreening tool-call evidenceDecision replay |
| Operational resilience & incident reportingKYE™ supplies sealed incident evidence and the attestation cadence; availability engineering, contingency arrangements and the incident report to the operator are participant-owned and not claimed as enforced. |
Designed |
L2 Designed |
cips-cross-border.operational-resilience-incident |
≤90-day attestationEvidence Pack™ |
| Settlement execution & liquidity provisionClearing and settling RMB payments across CIPS accounts, netting sessions and liquidity funding are owned by the system operator and participant treasuries — KYE™ is an AI-authority and evidence layer, not a clearing, settlement or liquidity engine. |
Out of scope |
L1 Mapped |
cips-cross-border.settlement-execution-liquidity |
— |
arrow_forward KYE™ framework reference
UK Faster Payments
UK Faster Payments (FPS)
UK Faster Payment System rules (Pay.UK) + PSR mandatory APP-scam reimbursement for Faster Payments (October 2024) · United Kingdom
Faster Payments processes UK retail payments in near real time — an accepted payment is irrevocable, so there is no recall window to correct an unauthorised agent action. KYE Protocol™ governs the payment-authority dimension: participant and sponsor/aggregator mandate binding at the moment of action, the pre-submission authority checkpoint (verdict + sealed evidence before release), message-authorisation lineage retained append-only over the record-keeping period, and the replay-verifiable authorisation evidence trail an APP-scam reimbursement investigation turns on (who or what authorised, under which mandate, with which fraud-assessment tool-calls). Scheme processing, settlement at the Bank of England, prefunding/net-sender-cap management and the reimbursement adjudication itself stay the scheme's, the Bank's and the PSPs' own (honest scope, §0). Per-requirement bijection at /compliance/uk-fps.html.
3 Enforced2 Designed2 Out of scope
7 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Participation, access criteria & authorised-user binding |
Enforced |
L3 Enforceable |
uk-fps.participant-access-authority |
Purpose Permission™Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Irrevocability & the pre-submission authority checkpoint |
Enforced |
L3 Enforceable |
uk-fps.pre-submission-authority-checkpoint |
Authority GateContext sealEvidence Pack™Replay-Proof™ |
| Messaging integrity & record retention |
Enforced |
L3 Enforceable |
uk-fps.message-integrity-records |
Evidence Pack™WORM audit hash-chainRetention policy |
| APP-fraud reimbursement & authorisation evidenceKYE™ supplies the replay-verifiable record of the authorising principal, mandate, purpose scope and fraud-assessment tool-calls a claim investigation needs; the reimbursement adjudication (gross-negligence assessment, 50:50 split, claim payment) is owned by the PSPs, Pay.UK and the PSR and is not claimed as enforced. |
Designed |
L2 Designed |
uk-fps.app-fraud-reimbursement-evidence |
Decision replayEvidence Pack™WORM audit hash-chain |
| Operational resilience & incident reportingKYE™ supplies sealed incident evidence and the attestation cadence; availability engineering, contingency arrangements and the notifications themselves are participant-owned and not claimed as enforced. |
Designed |
L2 Designed |
uk-fps.operational-resilience-incident |
≤90-day attestationEvidence Pack™ |
| Scheme processing & settlement executionCentral-infrastructure processing, deferred multilateral net settlement at the Bank of England, and the conferral of irrevocability on accepted payments are owned by Pay.UK, the infrastructure provider and the Bank — KYE™ is an AI-authority and evidence layer, not a payment processor. |
Out of scope |
L1 Mapped |
uk-fps.scheme-processing-settlement |
— |
| Liquidity provision & net sender capsPrefunding the settlement account, sizing/managing the net sender cap and intraday liquidity monitoring are participant treasury functions — KYE™ is not a liquidity-management engine. |
Out of scope |
L1 Mapped |
uk-fps.liquidity-net-sender-caps |
— |
arrow_forward KYE™ framework reference
SAFR
SAFR — Safeguards for Agentic Finance at Runtime
SAFR v1.0 (July 2026) · Global (industry reference; MAS Project MindForge lineage)
SAFR is an industry reference framework (BuildFin.AI) for a runtime governance layer over agentic AI in financial services: four components (Agent Identity, Controls Repository, Disposition Engine, Audit Log) exchanging a Governance Envelope, sitting after model guardrails and before execution. KYE Protocol™ maps to SAFR component-for-component at the moment-of-action admissibility check and adds Authority Finality™ — a Replay-Proof™ record verifiable from public keys alone. KYE™ governs whether the agentic financial action was allowed to become final; the rails execute if and only if approved.
6 Enforced2 Designed0 Out of scope
8 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Runtime governance at the point of action (pre-execution + per-step) |
Enforced |
L3 Enforceable |
safr.pre-execution-governance, safr.per-step-independent-authority |
Purpose Permission™Decision Engineper-action admissibility |
| Agent Identity — verified registered principal (SAFR component 1) |
Designed |
L3 Enforceable |
safr.agent-identity-verification, safr.authoritative-registry-resolution |
§0.30 agent-as-principal§52 authority bindingentity hierarchy |
| Controls Repository & capability-based mandate (SAFR component 2) |
Enforced |
L3 Enforceable |
safr.controls-repository, safr.mandate-capability-authority |
Rules Gateway™§52 authority claimDecision Map™ |
| Deterministic disposition — four outcomes, risk-calibrated (SAFR component 3) |
Designed |
L3 Enforceable |
safr.deterministic-disposition, safr.four-outcome-disposition, safr.risk-calibrated-outcome |
Decision EngineDecision Map™risk signals |
| Governance Envelope authenticated to origin |
Enforced |
L3 Enforceable |
safr.governance-envelope-authenticated |
Evidence Pack™tool-call pincontext seal |
| Immutable, tamper-evident audit log (SAFR component 4) |
Enforced |
L3 Enforceable |
safr.immutable-audit-log |
§30 WORMReplay-Proof™Authority Finality™ |
| Substantive human escalation (bounded, timeout, real authority) |
Enforced |
L3 Enforceable |
safr.substantive-human-escalation |
GovernedUI™ approval modestimeout→block/senior§9 no self-grant |
| Native + gateway integration and decision-not-settlement boundary |
Enforced |
L3 Enforceable |
safr.native-and-gateway-integration, safr.decision-not-settlement-boundary |
PEP (native + gateway)§0.33 Authority Finality™ category |
arrow_forward KYE™ framework reference
AAOIFI SS
AAOIFI Shariah Standards
AAOIFI Shariah Standards (as at 2023 compilation) · International
AAOIFI's suite of Shariah Standards on Islamic-finance contracts and instruments — the substantive fiqh rulings adopted by many regulators and institutions.
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Shariah Standards (substantive contract rulings) |
Designed |
L2 Designed |
AAOIFI SS |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
AAOIFI SS |
— |
arrow_forward KYE™ framework reference
AAOIFI GSIFI
AAOIFI Governance Standards (GSIFI)
AAOIFI Governance Standards for Islamic Financial Institutions (GSIFI) · International
AAOIFI's governance standards defining the Shariah supervisory board, review, audit, and governance-committee arrangements for Islamic financial institutions.
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Governance Standards (GSIFI) |
Designed |
L2 Designed |
AAOIFI GSIFI |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
AAOIFI GSIFI |
— |
arrow_forward KYE™ framework reference
AAOIFI FAS
AAOIFI Financial Accounting Standards (FAS)
AAOIFI Financial Accounting Standards (FAS) · International
AAOIFI's accounting standards for the recognition, measurement and disclosure of Islamic-finance contracts.
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Financial Accounting Standards (FAS) |
Designed |
L2 Designed |
AAOIFI FAS |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
AAOIFI FAS |
— |
arrow_forward KYE™ framework reference
AAOIFI ASIFI
AAOIFI Auditing Standards (ASIFI)
AAOIFI Auditing Standards for Islamic Financial Institutions (ASIFI) · International
AAOIFI's auditing standards for external and Shariah-compliance audit of Islamic financial institutions.
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Auditing Standards (ASIFI) |
Designed |
L2 Designed |
AAOIFI ASIFI |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
AAOIFI ASIFI |
— |
arrow_forward KYE™ framework reference
IFSB-10
IFSB-10 — Guiding Principles on Shari'ah Governance Systems
IFSB-10 (2009) · International
IFSB-10 sets guiding principles for the Shariah governance system: competence, independence, confidentiality and consistency of the Shariah board, plus review and audit functions.
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Shariah Governance System (IFSB-10 guiding principles) |
Designed |
L2 Designed |
IFSB-10 |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
IFSB-10 |
— |
arrow_forward KYE™ framework reference
IFSB
IFSB Prudential Standards (suite)
IFSB prudential standards suite · International
The IFSB's prudential and disclosure standards for institutions offering Islamic financial services, including corporate governance, core principles, and market-discipline disclosures.
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Prudential & governance standards (IFSB suite) |
Designed |
L2 Designed |
IFSB |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
IFSB |
— |
arrow_forward KYE™ framework reference
IIFM
IIFM Documentation Standards
IIFM documentation standards · International
IIFM's standardised master agreements and documentation for Islamic hedging, treasury, interbank and sukuk transactions.
1 Enforced0 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Documentation & contract standards (IIFM) |
Enforced |
L3 Enforceable |
IIFM |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
IIFM |
— |
arrow_forward KYE™ framework reference
BNM SGF 2019
Bank Negara Malaysia — Shariah Governance Policy Document 2019
BNM/RH/PD 028-100 (2019) · Malaysia
BNM's Shariah Governance Policy Document (2019) sets board oversight, Shariah committee, and Shariah risk/review/audit/research control functions, operating under the binding rulings of BNM's Shariah Advisory Council (SAC).
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Shariah Governance (BNM SGF 2019 + SAC/IFSA 2013) |
Designed |
L2 Designed |
BNM SGF 2019 |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
BNM SGF 2019 |
— |
arrow_forward KYE™ framework reference
CBUAE HSA
CBUAE — Higher Shariah Authority and Shariah Governance Standard
CBUAE Shariah Governance Standard (2020) · United Arab Emirates
The CBUAE requires each Islamic financial institution to maintain an Internal Shariah Supervision Committee and Shariah control functions, operating under the binding resolutions of the CBUAE Higher Shariah Authority (HSA).
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Shariah Governance (CBUAE HSA Standard) |
Designed |
L2 Designed |
CBUAE HSA |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
CBUAE HSA |
— |
arrow_forward KYE™ framework reference
CBB SG Module
Central Bank of Bahrain — Shariah Governance Module
CBB Rulebook — Shariah Governance Module · Bahrain
The CBB Shariah Governance Module mandates AAOIFI standards, an independent Shariah supervisory board, internal Shariah audit and review, and (from 2020) a centralised Shariah board.
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Shariah Governance (CBB Module) |
Designed |
L2 Designed |
CBB SG Module |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
CBB SG Module |
— |
arrow_forward KYE™ framework reference
SAMA SGF
Saudi Central Bank — Shariah Governance Framework
SAMA Shariah Governance Framework (2020) · Saudi Arabia
SAMA's Shariah Governance Framework requires local banks to establish an independent Shariah committee, a Shariah division, and Shariah review and audit functions.
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Shariah Governance (SAMA Framework) |
Designed |
L2 Designed |
SAMA SGF |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
SAMA SGF |
— |
arrow_forward KYE™ framework reference
OJK / DSN-MUI
OJK / DSN-MUI — Indonesian Shariah Governance
OJK Shariah governance regulations + DSN-MUI fatawa · Indonesia
Indonesia operates a two-tier model: DSN-MUI issues national fatawa binding on Islamic financial institutions, while OJK regulates the institution-level Dewan Pengawas Syariah (Shariah Supervisory Board) and compliance functions.
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Shariah Governance (OJK + DSN-MUI) |
Designed |
L2 Designed |
OJK / DSN-MUI |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
OJK / DSN-MUI |
— |
arrow_forward KYE™ framework reference
SBP SGF
State Bank of Pakistan — Shariah Governance Framework
SBP Shariah Governance Framework (2018) · Pakistan
SBP's Shariah Governance Framework mandates a board Shariah committee, a resident Shariah board member, a Shariah compliance department, and internal and external Shariah audit, under the SBP Shariah Advisory Committee's rulings.
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Shariah Governance (SBP Framework) |
Designed |
L2 Designed |
SBP SGF |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
SBP SGF |
— |
arrow_forward KYE™ framework reference
QCB
Qatar Central Bank — Shariah Supervision and Governance
QCB Islamic banking instructions · Qatar
QCB and the QFCRA require Islamic financial institutions to maintain a Shariah supervisory board and Shariah review/audit functions, with broad reference to AAOIFI standards.
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Shariah Governance (QCB / QFCRA) |
Designed |
L2 Designed |
QCB |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
QCB |
— |
arrow_forward KYE™ framework reference
CBK
Central Bank of Kuwait — Shariah Supervisory Governance
CBK Shariah supervisory governance instructions · Kuwait
The CBK requires Islamic banks to maintain an independent Shariah supervisory board and Shariah audit, coordinated with a higher committee for Shariah supervision at the CBK.
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Shariah Governance (CBK) |
Designed |
L2 Designed |
CBK |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
CBK |
— |
arrow_forward KYE™ framework reference
CBO IBRF
Central Bank of Oman — Islamic Banking Regulatory Framework (IBRF)
CBO Islamic Banking Regulatory Framework (2012) · Oman
Oman's IBRF mandates a Shariah Supervisory Board, an internal Shariah reviewer, and Shariah audit for Islamic banks and windows, referencing AAOIFI standards.
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Shariah Governance (CBO IBRF) |
Designed |
L2 Designed |
CBO IBRF |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
CBO IBRF |
— |
arrow_forward KYE™ framework reference
TKBB
TKBB — Participation Banking Standards (Türkiye)
TKBB participation-banking standards + BDDK regulation · Türkiye
In Türkiye, participation (Islamic) banks are supervised by BDDK; the TKBB Central Advisory Board issues participation-banking standards, and each bank maintains an advisory committee.
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Participation Banking Governance (TKBB) |
Designed |
L2 Designed |
TKBB |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
TKBB |
— |
arrow_forward KYE™ framework reference
CBN NIFI
Central Bank of Nigeria — Non-Interest (Islamic) Financial Institutions
CBN guidelines for non-interest financial institutions · Nigeria
The CBN regulates Non-Interest (Islamic) Financial Institutions; a central Financial Regulation Advisory Council of Experts (FRACE) advises the CBN, and each institution maintains an Advisory Committee of Experts (ACE).
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Shariah Governance (CBN NIFI + FRACE) |
Designed |
L2 Designed |
CBN NIFI |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
CBN NIFI |
— |
arrow_forward KYE™ framework reference
FCA SSB model
UK FCA — Firm-Level Shariah Supervisory Board Model
FCA/PRA firm-level governance (no separate Shariah regime) · uk
The UK has no separate statutory Shariah regime; Islamic financial institutions operate under the standard FCA/PRA perimeter and appoint their own firm-level Shariah supervisory boards, typically applying AAOIFI standards.
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Firm-Level Shariah Governance (UK FCA model) |
Designed |
L2 Designed |
FCA SSB model |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
FCA SSB model |
— |
arrow_forward KYE™ framework reference
Brunei SFSB
Brunei — Syariah Financial Supervisory Board and BDCB
Syariah Financial Supervisory Board Order + BDCB regulation · Brunei Darussalam
Brunei's Syariah Financial Supervisory Board (SFSB) is the highest authority on Islamic finance matters; BDCB regulates institution-level Syariah advisory bodies.
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Shariah Governance (Brunei SFSB) |
Designed |
L2 Designed |
Brunei SFSB |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
Brunei SFSB |
— |
arrow_forward KYE™ framework reference
CBJ Islamic
Central Bank of Jordan — Islamic Banking Shariah Governance
CBJ Islamic banking instructions · Jordan
The CBJ regulates Islamic banks under the Banking Law and dedicated instructions requiring a Shariah supervisory board and Shariah audit.
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Shariah Governance (CBJ) |
Designed |
L2 Designed |
CBJ Islamic |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
CBJ Islamic |
— |
arrow_forward KYE™ framework reference
Egypt FRA
Egypt FRA — Islamic Finance Shariah Supervision
FRA Islamic finance regulations (sukuk, takaful) · Egypt
Egypt's FRA regulates non-banking Islamic finance (sukuk, takaful) with a central Shariah supervisory committee; the CBE oversees Islamic banking.
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Shariah Governance (Egypt FRA) |
Designed |
L2 Designed |
Egypt FRA |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
Egypt FRA |
— |
arrow_forward KYE™ framework reference
Sudan HSSB
Central Bank of Sudan — High Shariah Supervisory Board
CBOS High Shariah Supervisory Board framework · Sudan
Sudan operates a fully Islamic banking system; the High Shariah Supervisory Board (HSSB) at the CBOS issues binding rulings, and each bank maintains a Shariah supervisory body.
0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Shariah Governance (Sudan HSSB) |
Designed |
L2 Designed |
Sudan HSSB |
Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). |
Out of scope |
L1 Mapped |
Sudan HSSB |
— |
arrow_forward KYE™ framework reference
RBI IT Governance MD
RBI IT Governance Master Direction
Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices · India
KYE™ governs the AUTHORITY + EVIDENCE layer where AI agents take consequential action inside a regulated entity's operations. KYE™ is OUT-OF-SCOPE for board-level IT governance structures, the entity's information-security programme, business-continuity capability and internal-audit function — those are the regulated entity's own, and RBI supervises them directly (§70 §4). Deep per-requirement mapping: 6 requirements, 2 enforced by KYE™ runtime, 4 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.
1 Enforced0 Designed1 Out of scope
2 requirement groups — view detail
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| Authority + evidence at the action boundary — enforced by KYE™ runtime and verified by CI |
Enforced |
L3 Enforceable |
rbi-master-direction-it.AGENT-ACTION-AUTHORITY — Consequential actions by automated systems resolve to a live delegated authority, rbi-master-direction-it.AUDIT-TRAIL — Tamper-evident audit trail over privileged and consequential operations |
kye.compliance.attestation.v1kye.evidence.decision_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context_seal.v1internal |
| Obligations owed directly by the regulated entity — NOT discharged by KYE™KYE™ governs the AUTHORITY + EVIDENCE layer where AI agents take consequential action inside a regulated entity's operations. KYE™ is OUT-OF-SCOPE for board-level IT governance structures, the entity's information-security programme, business-continuity capability and internal-audit function — those are the regulated entity's own, and RBI supervises them directly (§70 §4). |
Out of scope |
L1 Mapped |
rbi-master-direction-it.IT-GOVERNANCE-STRUCTURE — Board-level IT strategy committee and defined governance structure, rbi-master-direction-it.INFOSEC-PROGRAMME — Information-security policy, controls and periodic assessment, rbi-master-direction-it.BUSINESS-CONTINUITY — Business continuity and disaster-recovery capability with periodic testing, rbi-master-direction-it.IT-ASSURANCE — Independent assurance and internal audit over IT controls |
— |
arrow_forward KYE™ framework reference