Regulatory coverage · honest tri-state map

Every framework. One honest coverage map.

KYE Protocol™ maps to 249 regulatory frameworks, decomposed into 853 requirement groups. 456 are Enforced at runtime, 244 Designed and in build, 153 Out of scope. Every number here is computed from a single schema-backed registry — change the registry, the page regenerates.

How to read this map

Three honest states — no checkbox theatre.

Every requirement group below carries exactly one of these states. A group is only marked Enforced when runtime code and a CI gate back it — so a customer’s audit team can sign with the right residual-risk register.

Enforced

Live runtime code enforces this requirement, and a CI gate verifies it on every release.

Designed

Schema, contract, and acceptance criteria are locked; the runtime implementation is in build and tracked in the implementation plan.

Out of scope

Not discharged by KYE Protocol™ — owned by the customer's own systems, processes, or counsel. KYE™ is an evidence layer, not a replacement for these controls.

The coverage-maturity ladder

How far each control has climbed — mapped to certified.

Tri-state tells you whether KYE Protocol™ owns a control. The maturity ladder tells you how far it has climbed — from merely mapped, through designed and enforceable, to evidence-backed and certified. A row only claims evidence-backed or certified when a real Evidence Pack™ or assessor artefact backs it; a CI gate rejects any inflated claim. This is the per-control axis — orthogonal to where KYE Protocol™ ships SKUs by jurisdiction.

L1 Mapped (156)

KYE Protocol™ has mapped the obligation/control: the framework requirement is decomposed and crosswalked to the KYE Protocol™ control vocabulary, but no design, runtime check, evidence, or certification is asserted at this level.

L2 Designed (238)

KYE Protocol™ has a profile / control design for the obligation: schema, contract, and acceptance criteria are locked and tracked in the implementation plan, but the runtime enforcement is in build.

L3 Enforceable (459)

KYE Protocol™ can enforce the obligation via live runtime checks (a Decision Engine / Authority Gate path or a CI gate that fails closed). A claim at this level must resolve to a real runtime control or gate.

L4 Evidence-backed (0)

KYE Protocol™ generates a signed Evidence Pack™ for the obligation — the enforcement decision is captured as a replayable, third-party-verifiable artefact. A claim at this level must resolve to a real Evidence Pack™ example on disk (honest-floor rule).

L5 Certified (0)

An external KYE Seal™ / accredited-assessor review is available for the obligation. The top of the ladder: a buyer can point at an independent assessment, not just KYE Protocol™'s own evidence. A claim at this level must resolve to a real seal / assessor artefact on disk (honest-floor rule).

Coverage by framework

Every framework, decomposed and marked.

Filter by state to see exactly where KYE Protocol™ enforces today, where it is in build, and where the customer owns the control.

AI governance

Frameworks that govern the lifecycle, oversight, and accountability of AI systems and AI agents.

AI-CAIQ

AI-CAIQ (STAR-for-AI self-assessment)

1.0 · International

The CSA AI Consensus Assessments Initiative Questionnaire is the self-assessment companion to the AICM and the basis for CSA STAR-for-AI listings. KYE™ generates each answer it can satisfy from runtime evidence (a KYE™ artefact + a §0.3 evidence event), and marks questions outside its execution scope as not applicable — never fabricated.

1 Enforced0 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Questionnaire answers generated from replay-provable runtime evidence Enforced L3 Enforceable AI-CAIQ (KYE-resolvable questions)
Evidence Pack™Decision Map™Replay-Proof™
Out-of-scope questions marked not applicableInfrastructure, training-pipeline and internal model-validation questions are not applicable to the KYE™ execution-layer scope. Marked honestly, never fabricated. Out of scope L1 Mapped AI-CAIQ (infrastructure / model-training questions)
arrow_forward KYE™ framework reference
AI Solutions Framework

AI Solutions Framework — Enterprise AI-Adoption Control Framework (IG1–IG3)

1.0 · International

The AI Solutions Framework is an enterprise AI-adoption control framework (~90 safeguards across AI governance & accountability, risk management, AI safety, data privacy/lineage, compliance monitoring, and audit & evidence; IG1–IG3 maturity). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the KYE AI Solutions Framework Authority Pack™ (§70 honesty bar). Frameworks define what should happen; KYE Protocol™ resolves who may make it happen, under what authority, and proves it later. The organisational safeguards (governance board, AI inventory, policy authorship, training, risk committee) and the deploy-time infrastructure-posture / CSPM safeguards (model-logging, encryption, IAM least-privilege, network egress) are honestly out of scope and ceded to their owning roles. KYE Protocol™ complements a deploy-time posture/CSPM layer — coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.

3 Enforced0 Designed2 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
AI governance & accountability — action-boundary authority (enforced) Enforced L3 Enforceable ai-solutions-framework.approval-workflow-authority, ai-solutions-framework.accountability-named-principal
Action Admissibility™ GateAuthority Finality™Evidence Pack™
AI risk management & safety — attestation + human-oversight stage gate (enforced) Enforced L3 Enforceable ai-solutions-framework.attestation-due-diligence-before-action, ai-solutions-framework.human-oversight-stage-gate
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Compliance monitoring & audit/evidence — exception register + provenance pin (enforced) Enforced L3 Enforceable ai-solutions-framework.exception-register, ai-solutions-framework.audit-evidence-provenance-pin
Evidence Pack™Replay-Proof™Audit WORM
Organisational safeguards (out of scope — governance-office / CISO) Out of scope L1 Mapped ai-solutions-framework.ai-governance-board, ai-solutions-framework.ai-system-inventory, ai-solutions-framework.ai-acceptable-use-policy, ai-solutions-framework.ai-workforce-training, ai-solutions-framework.ai-risk-committee-review
Infrastructure posture / CSPM safeguards (out of scope — cloud-platform / devsecops; complemented by KYE Protocol™) Out of scope L1 Mapped ai-solutions-framework.model-inference-logging-enabled, ai-solutions-framework.ai-data-storage-encryption, ai-solutions-framework.ai-iam-least-privilege, ai-solutions-framework.ai-network-egress-posture
arrow_forward KYE™ framework reference
AICM Resolution

CSA AI Controls Matrix (AICM)

1.0 · International

The Cloud Security Alliance AI Controls Matrix defines 243 control objectives across 18 domains. AICM defines the controls. KYE™ operationalises them — proving how each control resolved at the moment a consequential AI action occurred. KYE™ binds the execution-resolvable domains and is honest about the infrastructure and model-training domains it does not touch.

6 Enforced0 Designed1 Out of scope
7 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Identity & access management — authority at the moment of action Enforced L3 Enforceable IAM, AAC
Purpose Permission™Authority GateDelegated-agent binding
Governance, risk & compliance — human oversight + recurring attestation Enforced L3 Enforceable GRC
GovernedUI human-control surface≤90-day compliance attestation
Logging & monitoring — signed evidence + decision map per action Enforced L3 Enforceable LOG
Evidence Pack™Decision Map™WORM audit hash-chain
Model risk & resilience — replay-provable from public keys Enforced L3 Enforceable MRM (action-resolution slice)
Replay-Proof™Context seal
Supply chain & transparency — provenance pinned in evidence Enforced L3 Enforceable STA
Tool-call pinEvidence Pack™
Application-interface + data-lifecycle admissibility at the boundaryThe deny-by-default action-boundary and moment-of-use data admissibility contracts are locked; per-interface and per-asset runtime wiring is in build. Enforced L3 Enforceable AIS, DSP
Policy Enforcement PointData-use PDP stage
Cloud infrastructure security + model-training & internal model validationCloud-fabric hardening is operated by the cloud service provider; training-pipeline security and internal model validation are owned by the model developer. KYE™ governs how a model's actions resolve at run time and records them — it does not operate the infrastructure or train the model. Out of scope L1 Mapped IVS, TVM, MRM (model-internals slice)
arrow_forward KYE™ framework reference
AIDA

AIDA — Artificial Intelligence and Data Act (Bill C-27, federal)

Bill C-27 Part 3 (tabled, lapsed Jan 2025) · Canada

Canada's proposed federal AI law (AIDA, Part 3 of Bill C-27). The bill lapsed on prorogation in January 2025 and is NOT in force — mapped as a forward-looking design anchor (all rows advisory): high-impact assessment, risk mitigation + monitoring, record-keeping, transparency, and serious-harm notification. Per-requirement bijection at /compliance/aida.html.

0 Enforced5 Designed0 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
High-impact system assessment (s.7) Designed L2 Designed s7
Risk Engine
Risk mitigation + monitoring (s.8-9) Designed L2 Designed s8
Drift DetectorRisk Engine
Record-keeping (s.10) Designed L2 Designed s10
WORM audit hash-chain
Transparency / publication (s.11) Designed L2 Designed s11
Reporting Engine
Serious-harm notification (s.12) Designed L2 Designed s12
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
AU AI Guardrails

Australian Government Mandatory AI Guardrails

DISR 2024 (10 guardrails) · Australia

The 10 mandatory AI guardrails proposed by the Department of Industry, Science and Resources (Sept 2024) + the Voluntary AI Safety Standard. Per-requirement bijection at /compliance/au-ai-guardrails.html.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Accountability, risk management & data governance (G1-G3) Enforced L3 Enforceable Guardrail 1, Guardrail 2, Guardrail 3
Purpose Permission™Risk EngineData Classification EngineEvidence Pack™
Testing, human oversight, transparency & contestability (G4-G7) Enforced L3 Enforceable Guardrail 4, Guardrail 5, Guardrail 6, Guardrail 7
Conformance RunnerDrift DetectorGovernedUI™Decision Map™Replay-Proof™
Supply-chain transparency & record-keeping (G8-G9) Enforced L3 Enforceable Guardrail 8, Guardrail 9
Authority RegisterWORM audit hash-chainEvidence Pack™
Stakeholder engagement (G10)Process-and-policy obligation owned by the customer's governance function; KYE™ records that engagement occurred but does not perform it. Out of scope L1 Mapped Guardrail 10
arrow_forward KYE™ framework reference
BSI AIC4

BSI AIC4 — AI Cloud Service Compliance Criteria

2021 · Germany

The German Federal Office for Information Security (BSI) AI Cloud Service Compliance Criteria Catalogue (AIC4) — one of the frameworks the CSA AICM crosswalks to. KYE™ binds the security-and-robustness criteria that resolve at action time and marks the cloud-platform operational criteria out of scope.

2 Enforced0 Designed1 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Security & robustness of AI decisions — evidenced at action time Enforced L3 Enforceable AIC4 Security & Robustness, AIC4 Reliability
Evidence Pack™Replay-Proof™Purpose Permission™
Performance, bias mitigation & explainability of the AI decision recordThe decision-record contract that backs explainability and the action-level audit is locked; the per-criterion runtime surface is in build. Enforced L3 Enforceable AIC4 Performance & Functionality, AIC4 Bias, AIC4 Explainability
Decision Map™
Cloud-platform operations, data centre & training-environment criteriaCloud-platform operations and the model-training environment are operated by the cloud service provider and the model developer, not by KYE™. Out of scope (§0 honest scope). Out of scope L1 Mapped AIC4 Data Management (training), AIC4 Operations
arrow_forward KYE™ framework reference
EC-Council ADG

EC-Council ADG — Adopt · Defend · Govern

2026 · Global

35 requirements across three pillars (Adopt / Defend / Govern), nine governance surfaces, twelve minimum controls (MC-1..MC-12), and three autonomy tiers (HITL / HOTL / HOOTL). Complementary to KYE Protocol™: ADG = operating model, KYE Protocol™ = runtime authority proof.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Pillar 1 — Adopt (10 requirements covering lifecycle, capability, risk, secure deployment, change, evidence, purpose grant, training, acceptable use, assurance baseline) Enforced L3 Enforceable ADG/Adopt
Model capability profileRisk assessmentPurpose Permission™ grant issuanceAdoption evidence packInitial compliance attestation
Pillar 2 — Defend (10 requirements covering threat-model, red-team, runtime monitoring, tool/MCP register, prompt-injection defence, supply chain, incident response, SPOF, federation, continuous attestation) Enforced L3 Enforceable ADG/Defend
KYE Tool & MCP Authority Register™Tool call pin (side-effect binding)Drift signal familyReplay-Proof™ envelopeSPOF registryFederation cross-org delegationCompliance attestation cadence
Pillar 3 — Govern (15 requirements covering authority register, purpose grant, admissibility, evidence pack, decision map, replay-proof, Authority Finality™, human oversight, autonomy tiers, MC-1..MC-12, decision rights, board reporting) Enforced L3 Enforceable ADG/Govern, ADG/MC-1..MC-12
Purpose Permission™Action Admissibility™ GateDecision Map™Evidence Pack™Replay-Proof™Authority Finality™GovernedUI™ critical-point reviewKYE Autonomy Tiers™ (A0-A3)KYE Minimum Authority Controls™ (KAC-1..KAC-12)
arrow_forward KYE™ framework reference
EEOC Uniform Guidelines

EEOC Uniform Guidelines on Employee Selection Procedures

1978 (29 CFR Part 1607) · United States

US federal guidelines defining the four-fifths adverse-impact rule and the validation duty for selection procedures.

1 Enforced1 Designed0 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Four-fifths adverse-impact rule Enforced L3 Enforceable 29 CFR §1607.4(D)
Evidence Pack™Authority Gate
Validation of selection procedures Designed L2 Designed 29 CFR §1607.5
Delegated Auditability Rail
arrow_forward KYE™ framework reference
EU AI Act

EU AI Act — Artificial Intelligence Regulation

Regulation (EU) 2024/1689 · European Union

EU regulation setting lifecycle obligations for high-risk AI systems.

4 Enforced1 Designed1 Out of scope
6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Risk-management system Enforced L3 Enforceable Art. 9
Purpose Permission™Authority Gate
Data & data governance Enforced L3 Enforceable Art. 10
Purpose Permission™WORM audit hash-chain
Record-keeping & traceability Enforced L3 Enforceable Art. 12, Art. 72
WORM audit hash-chainDecision replay
Human oversight Enforced L3 Enforceable Art. 14
WebAuthn step-upAuthority Gate
Transparency & provision of informationTransparency receipts are emitted today; the detached signatures that make them verifiable downstream are in build. Designed L2 Designed Art. 13, Art. 50
Decision Map™ signing (JWS-detached)Evidence Pack™ signing (COSE-Sign1)
Annex IV technical documentationKYE™ produces operational evidence; the static Annex IV technical-documentation file is authored separately. Out of scope L1 Mapped Art. 11
arrow_forward KYE™ framework reference
EU AI Act Art 50

EU AI Act — Article 50 chatbot transparency

2024/1689 · European Union

Article 50 of Regulation (EU) 2024/1689 requires natural persons be informed they are interacting with an AI system, plus related transparency record-keeping. KYE Protocol™ governs the ENFORCEMENT AUTHORITY + EVIDENCE of the Article 50 chatbot disclosure at the action boundary — consumed by the KYE Chatbot Authority Pack™. The broader Regulation is covered by the eu-ai-act registry; this is the narrow chatbot-transparency execution slice. Per-requirement bijection at framework-coverage-bijection.

2 Enforced0 Designed1 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Art 50 — AI-interaction disclosure Enforced L3 Enforceable eu-ai-act-chatbot-transparency.art50-chatbot-disclosure-enforcement
Action Admissibility™ GateAuthority Finality™
Art 50 — transparency record-keeping Enforced L3 Enforceable eu-ai-act-chatbot-transparency.art50-transparency-record-keeping
Evidence Pack™Replay-Proof™WORM Retention
Disclosure UX & AI Act conformity program (out of scope)Model vendor / operator responsibility — disclosure UX/copy and the broader AI Act conformity program. Zero KYE™ controls (complement-not-compete). Out of scope L1 Mapped eu-ai-act-chatbot-transparency.disclosure-ux-and-conformity-program
arrow_forward KYE™ framework reference
FDA / EMA AI

FDA + EMA — AI / Provenance Expectations for AI-Derived Regulated Candidates

2024-2025 · US / EU

FDA + EMA AI / provenance expectations for AI-derived candidates entering regulated drug/device pipelines — documented provenance, reproducibility, and GxP data integrity (ALCOA+). KYE Protocol™ governs whether an AI-derived candidate may proceed to a regulated stage, binding replay-provable provenance — the KYE AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
AI design provenance & reproducibility Designed L2 Designed fda-ema.design-provenance, fda-ema.reproducibility
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
GxP data integrity (ALCOA+) Designed L2 Designed fda-ema.gxp-data-integrity
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Human oversight & accountability Designed L2 Designed fda-ema.human-accountability
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
arrow_forward KYE™ framework reference
OECD AI Principles

OECD AI Principles — Recommendation of the Council on Artificial Intelligence

OECD/LEGAL/0449 (2019, updated 2024) · International

The OECD Recommendation of the Council on Artificial Intelligence (OECD/LEGAL/0449) sets five value-based principles for trustworthy AI — inclusive growth & well-being; human-centred values & fairness; transparency & explainability; robustness, security & safety; and accountability — and is the reference standard behind the G7 Hiroshima Process and many national AI strategies. This framework is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: although several principles crosswalk to existing KYE Protocol™ rails (transparency/explainability → §0.3 evidence & §13 Replay-Proof™; accountability → §21 Audit Pilot™ & §52 agent binding; robustness/safety → §13 Resilience Loop™; human-centred/fairness → §36 GovernedUI™ human-in-the-loop), no requirement has yet been bound at the requirement level. Per the §70 honesty bar, coverage is reported out of scope pending deep mapping rather than claimed as enforced.

0 Enforced0 Designed1 Out of scope
1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): candidate crosswalks to §0.3 / §13 / §21 / §36 / §52 are noted in the summary but NOT yet bound at the requirement level, so coverage stays out of scope until the deep mapping runs through the §70 rail — never inflated to imply enforcement that does not exist. Out of scope L1 Mapped OECD AI Principles (five value-based principles — not yet decomposed into requirement-level mappings)
arrow_forward KYE™ framework reference
IMDA MGF (Agentic AI)

IMDA Model AI Governance Framework for Agentic AI

v1.5 (20 May 2026, updated 5 June 2026) · Singapore

Singapore IMDA's Model AI Governance Framework for Agentic AI (v1.5) sets expectations across four dimensions: (1) assess and bound the risks upfront; (2) make humans meaningfully accountable; (3) implement technical controls and processes; (4) enable end-user responsibility. This framework is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: although every dimension crosswalks cleanly to existing KYE Protocol™ rails (bound risk upfront → entity/principal identity + §52 agent binding + Purpose Permission™ §12; meaningful human accountability → §36 GovernedUI™ approval modes + Finality Gate; technical controls → §13 Evidence Pack™ / Replay-Proof™ + §34 monitoring; end-user responsibility → §17 Directory + §21 Audit Pilot™), no requirement has yet been bound at the requirement level. Per the §70 honesty bar, coverage is reported out of scope pending deep mapping rather than claimed as enforced.

0 Enforced0 Designed1 Out of scope
1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): the four-dimension crosswalk to KYE's entity/§52 / §36 Finality / §13 Evidence+Replay / §17+§21 rails is noted in the summary but NOT yet bound at the requirement level, so coverage stays out of scope until the deep mapping runs through the §70 rail — never inflated to imply enforcement that does not exist. Out of scope L1 Mapped IMDA MGF for Agentic AI — four governance dimensions (not yet decomposed into requirement-level mappings)
arrow_forward KYE™ framework reference
Frontier Bio-Safeguard Eval

Common Standard for Evaluating Frontier AI Safeguards against Biological Misuse

technical report, June 2026 · International

A proposed common standard (GovAI/OpenAI, June 2026) for evaluating frontier-AI safeguards against biological misuse: seven recommendations across four principles (comparability across companies; account for the deployment environment; treat safeguards as dynamic; preserve legitimate scientific use) plus a three-layer safeguard stack — access (who can use the model), inference (how harmful queries are handled), platform (post-hoc misuse detection) — combined into composite safeguard levels calibrated to threat actor. This standard is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: it crosswalks to KYE's genomics-biosecurity Authority Pack™ + Genetic Sequencing Authority Agent™ (action-boundary admissibility + sequence-of-concern screening) and to §52 access controls + §13 Evidence Pack™, but no requirement is bound at the requirement level. Per the §70 honesty bar, coverage is reported out of scope pending deep mapping. NOTE: this standard evaluates MODEL-LEVEL safeguards; KYE governs the ACTION boundary — complementary, not the same control.

0 Enforced0 Designed1 Out of scope
1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): crosswalk to the genomics-biosecurity pack + §52/§13 noted in the summary but NOT requirement-bound. The standard evaluates model-level safeguards; KYE governs the action boundary — coverage stays out of scope until deep mapping, never inflated. Out of scope L1 Mapped Seven recommendations + three-layer safeguard stack (not yet decomposed into requirement-level mappings)
arrow_forward KYE™ framework reference
AI Verify

IMDA AI Verify

AI Verify Foundation · Singapore

IMDA / AI Verify Foundation testing framework — transparency, accountability, human agency & oversight, robustness. Per-requirement bijection at /compliance/imda-ai-verify.html.

2 Enforced0 Designed0 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Transparency + accountability Enforced L3 Enforceable AI Verify — transparency, AI Verify — accountability
Decision Map™Evidence Pack™Purpose Permission™
Human agency & oversight + robustness Enforced L3 Enforceable AI Verify — human agency, AI Verify — robustness
GovernedUI™Authority GateConformance RunnerDrift Detector
arrow_forward KYE™ framework reference
ISO 42001

ISO/IEC 42001 — AI Management System

2023 · International

Management-system standard for the responsible development and use of AI.

3 Enforced1 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
AI policy & objectives Enforced L3 Enforceable Clause 5-6
Purpose Permission™Authority Gate
Operational AI controls & impact assessment Enforced L3 Enforceable Clause 8, Annex A.6
Purpose Permission™WORM audit hash-chain
Performance evaluation & audit trail Enforced L3 Enforceable Clause 9
WORM audit hash-chainDecision replay
Signed AI-system lifecycle evidenceLifecycle events are recorded in the audit chain today; signed lifecycle evidence packs are in build. Designed L2 Designed Annex A.6.2
Evidence Pack™ signing (COSE-Sign1)
arrow_forward KYE™ framework reference
MAS FEAT

MAS FEAT Principles

2018 + Veritas methodology & toolkit · Singapore

MAS Principles to promote Fairness, Ethics, Accountability and Transparency (FEAT) in the use of AI and data analytics in Singapore's financial sector, together with MAS Veritas — the MAS-convened consortium's companion FEAT assessment methodology (phased methodology documents, 2020-2022) and open-source Veritas Toolkit (v2.0, 2023). Veritas is canonicalised inside this framework entry rather than as a standalone framework. Per-requirement bijection at /compliance/mas-feat.html.

2 Enforced0 Designed0 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Fairness + ethics Enforced L3 Enforceable FEAT — fairness, FEAT — ethics
Risk EngineDecision Map™Purpose Permission™Authority Gate
Accountability + transparency Enforced L3 Enforceable FEAT — accountability, FEAT — transparency
Replay-Proof™Regulator Replay agentEvidence Pack™Decision Map™
arrow_forward KYE™ framework reference
MAS MindForge

MAS Project MindForge — AI Risk Management: Operationalisation Handbook

2024 · Singapore

MAS Project MindForge's AI Risk Management: Operationalisation Handbook gives Singapore financial institutions practical guidance for operationalising AI risk management across four blocks (Scope & AI Oversight, AI Risk Management, AI Lifecycle Management, Enablers; 17 considerations). KYE Protocol™ operationalises the action-boundary subset at runtime — it does NOT replace MindForge (§0.25 integrate-not-compete). KYE governs whether a consequential financial AI action is authorised, within the human-oversight mode the FI declared for that use, evidenced, contestable, and final at the moment it happens — and proves the basis, replayable by MAS or internal audit. Honest scope: KYE does not govern the FI's governance operating model, model-development methodology, or the correctness of the AI's output. Per-requirement bijection at /compliance/mas-mindforge.html.

4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Scope & AI oversight (oversight modes machine-enforceable + AI action-authority inventory) Enforced L3 Enforceable mas-mindforge.oversight-modes-machine-enforceable, mas-mindforge.action-authority-inventory
GovernedUI™ approval modesPurpose Permission™Authority GateEntity & Principal Registry
AI risk management (escalation before finality + third-party / vendor AI authority register) Enforced L3 Enforceable mas-mindforge.escalation-before-finality, mas-mindforge.third-party-vendor-authority-register
Authority Gateway (REQUIRE_APPROVAL)Edge Governance Safety FloorAuthority RegisterGovernedUI™ escalation
AI lifecycle management (deployment controls at the Authority Gateway + monitoring/change as replay-provable Evidence Packs)KYE enforces approved deployment conditions + replay-provable monitoring/change evidence at the action boundary; the FI's pre-deployment validation and model-performance monitoring stay the FI's own (honest scope). Enforced L3 Enforceable mas-mindforge.deployment-controls-authority-gateway, mas-mindforge.monitoring-change-evidence-replay
Authority GatewayEvidence Pack™Replay-Proof™WORM audit hash-chain
Enablers (named accountability at the action boundary)KYE binds and proves named accountability at the boundary; staffing and running the three-lines-of-defence operating model stays the FI's own (honest scope). Enforced L3 Enforceable mas-mindforge.enablers-named-accountability
GovernedUI™ named-authority sign-offDelegated Auditability RailAuthority Finality™
arrow_forward KYE™ framework reference
NIST AI RMF

NIST AI Risk Management Framework

1.0 · United States

Voluntary framework for managing AI risk across the Govern, Map, Measure, and Manage functions.

3 Enforced1 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Govern function Enforced L3 Enforceable GOVERN
Purpose Permission™Authority Gate
Map & Measure functions Enforced L3 Enforceable MAP, MEASURE
Purpose Permission™WORM audit hash-chain
Manage function & incident response Enforced L3 Enforceable MANAGE
WORM audit hash-chainDecision replay
Independently verifiable measurement evidenceMeasurement outcomes are recorded today; signed, externally verifiable measurement evidence is in build. Designed L2 Designed MEASURE 2.x
Evidence Pack™ signing (COSE-Sign1)
arrow_forward KYE™ framework reference
NYC Local Law 144

NYC Local Law 144 — Automated Employment Decision Tools

2023 (in force 2023-07-05) · United States (New York City)

NYC law requiring a bias audit before an automated employment decision tool screens a candidate, with candidate notice and published results.

1 Enforced1 Designed0 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
AEDT bias audit Enforced L3 Enforceable NYC Admin Code §20-871
Evidence Pack™Authority Gate
Candidate notice & contestability Designed L2 Designed NYC Admin Code §20-871(b)
Rights-Disputes Rail
arrow_forward KYE™ framework reference
NZ Algorithm Charter

NZ Algorithm Charter for Aotearoa New Zealand

2020 · New Zealand

Algorithm Charter for Aotearoa New Zealand (2020) — transparency, human oversight, and data/bias commitments for government use of algorithms. Per-requirement bijection at /compliance/nz-algorithm-charter.html.

2 Enforced0 Designed0 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Transparency + human oversight Enforced L3 Enforceable Charter — transparency, Charter — human oversight
Decision Map™Evidence Pack™GovernedUI™Replay-Proof™
Data clarity + bias management Enforced L3 Enforceable Charter — data and bias
Data Classification EngineRisk Engine
arrow_forward KYE™ framework reference
TBS ADM Directive

TBS Directive on Automated Decision-Making (Canada federal government)

TBS (amended 2023) · Canada

The Treasury Board Directive on Automated Decision-Making governing Canadian federal-government automated decision systems: the Algorithmic Impact Assessment, transparency notice, meaningful explanation, and quality-assurance + recourse. Per-requirement bijection at /compliance/tbs-directive-adm.html.

4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Algorithmic Impact Assessment Enforced L3 Enforceable aia
Risk Engine
Transparency notice Enforced L3 Enforceable notice
Reporting Engine
Meaningful explanation Enforced L3 Enforceable explanation
Decision Map™Replay-Proof™
Quality assurance + recourse Enforced L3 Enforceable recourse
Reporting EngineWORM audit hash-chain
arrow_forward KYE™ framework reference
UK AI Assurance

UK AI Assurance (DSIT)

Introduction to AI Assurance, Feb 2024 · United Kingdom

The UK government's AI assurance toolkit — the measure / evaluate / communicate loop and the six assurance mechanisms that operationalise the UK AI principles. KYE Protocol™ is itself an assurance mechanism: it measures every governed AI action, evaluates it against purpose admissibility, and communicates it as signed, replayable evidence.

5 Enforced1 Designed1 Out of scope
7 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Measure, evaluate & communicate (the assurance loop)Every governed AI action is measured, evaluated against the purpose grant, and communicated as a signed Evidence Pack™ — assurance as a continuous runtime loop, not a point-in-time review. Enforced L3 Enforceable §4.1
WORM audit hash-chainEvidence Pack™Decision Map™
Risk assessmentEvery agent action is admitted against a risk-scoped purpose grant before it runs; disallowed actions never execute. Enforced L3 Enforceable §4.2, §5.4
Purpose Permission™Authority Gate
Algorithmic impact assessmentEach decision's inputs and downstream effects are recorded in a Decision Map™; a per-deployment aggregate impact view is in build. Designed L2 Designed §4.2, §5.5
Decision Map™Evidence Pack™
Bias auditBias and fairness assessment of model outputs is owned by the customer's model-evaluation process — consistent with the UK AI Framework fairness principle. Out of scope L1 Mapped §4.2, §5.6
Compliance auditAdherence to internal policy and regulation is continuously reviewable against the tamper-evident, append-only audit chain. Enforced L3 Enforceable §4.2, §5.7
WORM audit hash-chainControl mappings
Conformity assessmentThe KYE Conformance Pack™ is the test suite a conformity-assessment body runs; third-party UKAS-accredited certification remains external to the protocol. Enforced L3 Enforceable §4.2, §5.8
Conformance Pack™
Formal verificationReplay-Proof™ is a deterministic, cryptographically-verifiable re-execution — a governed decision can be mathematically re-checked from public keys alone. Enforced L3 Enforceable §4.2, §5.9
Replay-Proof™Decision replay
arrow_forward KYE™ framework reference
UK AI

UK AI Regulatory Framework

2023 white paper · United Kingdom

The UK's pro-innovation AI principles and the DSIT AI assurance toolkit.

3 Enforced1 Designed1 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Safety, security & robustness Enforced L3 Enforceable Principle 1
Purpose Permission™Authority GateWORM audit hash-chain
Appropriate transparency & explainability Enforced L3 Enforceable Principle 2
WORM audit hash-chainDecision replay
Accountability & governance Enforced L3 Enforceable Principle 4
Authority GatePurpose Permission™
Contestability & redress evidenceDecision inputs are replayable today; signed evidence supporting contestability and redress is in build. Designed L2 Designed Principle 5
Evidence Pack™ signing (COSE-Sign1)Decision Map™ signing (JWS-detached)
Fairness assessment of model outputsBias and fairness assessment of model outputs is owned by the customer's model-evaluation process. Out of scope L1 Mapped Principle 3
arrow_forward KYE™ framework reference
UK Equality Act 2010

UK Equality Act 2010

2010 · United Kingdom

UK statute making an automated selection rule that disadvantages a protected group unlawful indirect discrimination unless objectively justified.

1 Enforced1 Designed0 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Indirect discrimination (s.19) Enforced L3 Enforceable Equality Act 2010 s.19
Evidence Pack™Authority Gate
Protected characteristics (s.4) Designed L2 Designed Equality Act 2010 s.4
Data Governance Pack™
arrow_forward KYE™ framework reference
EO 14110

US EO 14110 — Safe, Secure & Trustworthy AI (biosecurity / dual-use)

2023 · United States

US Executive Order 14110 (2023) Safe/Secure/Trustworthy AI — biosecurity, nucleic-acid synthesis screening, and content provenance provisions (rescinded Jan 2025; the dual-use-bio + synthesis-screening + provenance obligation pattern it established remains the de-facto reference set). KYE Protocol™ governs whether an AI-generated sequence/molecule may proceed to a consequential action — the KYE AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Dual-use biology & synthesis screening Designed L2 Designed us-eo-14110.4.4-synthesis-screening, us-eo-14110.4.4-dual-use-bio
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Content provenance & authentication Designed L2 Designed us-eo-14110.4.5-provenance
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Human oversight of consequential AI action Designed L2 Designed us-eo-14110.human-oversight
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
arrow_forward KYE™ framework reference
UNESCO AI Ethics

UNESCO Recommendation on the Ethics of Artificial Intelligence (2021)

2021 · International

The first global normative instrument on AI ethics, adopted (Nov 2021) by all 193 UNESCO member states. KYE Protocol™ operationalises the AI-action authority + evidence boundary of its values & principles — human oversight & determination, transparency & explainability, responsibility & accountability, privacy & data protection, fairness & non-discrimination, safety & security — with named accountability (Authority Finality™), a replay-derivable Evidence Pack™ and Decision Map™. KYE Protocol™ does NOT adjudicate the ethics of the outcome, and the environmental-sustainability and education/public-awareness principles are out-of-scope / customer-owned; coverage is never inflated. Per-requirement bijection at framework-coverage-bijection.

3 Enforced3 Designed0 Out of scope
6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Human oversight & determination Enforced L3 Enforceable unesco-ai-ethics.principle.human-oversight-determination
Purpose Permission™Authority Finality™
Transparency & explainability of AI decisions Enforced L3 Enforceable unesco-ai-ethics.principle.transparency-explainability
Decision Map™Evidence Pack™
Responsibility & accountability — auditable, attributable outcomes Enforced L3 Enforceable unesco-ai-ethics.principle.responsibility-accountability
Authority Finality™Evidence Pack™
Right to privacy & data protection Designed L2 Designed unesco-ai-ethics.principle.privacy-data-protection
Data Purpose Binding™Purpose Permission™
Fairness & non-discrimination (contestability + audit evidence) Designed L2 Designed unesco-ai-ethics.principle.fairness-non-discrimination
Decision Map™Evidence Pack™
Safety & security — action-admissibility safety floor Designed L2 Designed unesco-ai-ethics.principle.safety-security, unesco-ai-ethics.value.human-dignity-rights
Edge Governance Safety FloorPurpose Permission™
arrow_forward KYE™ framework reference
US Chatbot Laws

US State AI-Chatbot Laws — consumer / customer chatbot safeguards

2024-2026 · United States

The wave of US state AI-chatbot statutes (13+ states; 7 with a private right of action at roughly $1,000/violation) — CA SB 243, Utah AI Mental Health Chatbot Act, NY, IL, et al. Four recurring themes: crisis protocols, minor protections, deception/disclosure, liability. KYE Protocol™ governs the AUTHORITY + EVIDENCE of the chatbot safeguard actions at the moment the interaction occurs — the KYE Chatbot Authority Pack™. It does not provide the chatbot/LLM, the clinical crisis content, or the GRC program. Per-requirement bijection at framework-coverage-bijection.

5 Enforced0 Designed2 Out of scope
7 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Jurisdiction-aware safeguard resolution Enforced L3 Enforceable us-state-chatbot-laws.jurisdiction-resolution-applicable-safeguards
Action Admissibility™ GateCross-Jurisdiction Handoff RailAuthority Finality™
Mental-health / crisis protocol Enforced L3 Enforceable us-state-chatbot-laws.crisis-escalation-authority
Action Admissibility™ GateAuthority Finality™Evidence Pack™
Minor protections Enforced L3 Enforceable us-state-chatbot-laws.minor-protection-authority
Action Admissibility™ GateAuthority Finality™
Deception / disclosure / anthropomorphism Enforced L3 Enforceable us-state-chatbot-laws.disclosure-enforcement-authority
Action Admissibility™ GateAuthority Finality™
Liability / private right of action — litigation evidence Enforced L3 Enforceable us-state-chatbot-laws.litigation-evidence-capture
Evidence Pack™Replay-Proof™WORM Retention
Clinical crisis-counselling substance (out of scope)Crisis-service responsibility — clinical crisis content. KYE™ proves the escalation was authorised & triggered, not the content. Zero KYE™ controls (complement-not-compete). Out of scope L1 Mapped us-state-chatbot-laws.clinical-crisis-counselling-substance
Chatbot / model behaviour & UX (out of scope)Model vendor / operator responsibility — the LLM, its outputs, age-estimation, and UX. Zero KYE™ controls (complement-not-compete). Out of scope L1 Mapped us-state-chatbot-laws.chatbot-model-behaviour-and-ux
arrow_forward KYE™ framework reference
Voluntary GenAI Code

Voluntary Code of Conduct — Advanced Generative AI (Canada)

ISED (Sept 2023) · Canada

Canada's voluntary code for advanced generative AI systems (ISED, 2023). Voluntary signatory program — all rows advisory: accountability, transparency, and human oversight + monitoring outcomes anchored to the KYE Protocol™ action-governance layer. Per-requirement bijection at /compliance/voluntary-code-genai.html.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Accountability Designed L2 Designed accountability
Authority GateRisk Engine
Transparency Designed L2 Designed transparency
Decision Map™Reporting Engine
Human oversight + monitoring Designed L2 Designed oversight
Drift DetectorIncident Detector
arrow_forward KYE™ framework reference
ISO 31000

ISO 31000:2018 — Risk management — Guidelines

2018 · International

ISO 31000:2018 risk-management principles, framework and process. KYE Protocol™ governs the authority, evidence and finality of AI-agent actions as a risk-treatment and risk-recording control inside the ISO 31000 process — it does not run the enterprise risk-management system. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Accountability + assigned authority for AI risk Designed L2 Designed iso-31000.5.4.2
Purpose Permission™GovernedUI
Risk identification + treatment at the action boundary Designed L2 Designed iso-31000.6.4.2, iso-31000.6.5.2
Decision Map™Authority Gate
Monitoring/review + replay-derivable recording Designed L2 Designed iso-31000.6.6, iso-31000.6.7
Evidence Pack™Replay Proof™Delegated Auditability
arrow_forward KYE™ framework reference
Three Lines Model

The IIA's Three Lines Model (2020)

2020 · International

The IIA's Three Lines Model (2020). KYE Protocol™ supplies the runtime authority + evidence + assurance primitives the model assumes across first line (operational), second line (risk/compliance) and third line (internal audit) — it does not replace any line's people or mandate. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Governance accountability + governing-body oversight Designed L2 Designed three-lines.principle-1, three-lines.principle-2
Purpose Permission™GovernedUIEvidence Pack™
First/second line authority + third-line assurance Designed L2 Designed three-lines.principle-3, three-lines.principle-4
Decision Map™Delegated Auditability
Independent verification + aligned value protection Designed L2 Designed three-lines.principle-5, three-lines.principle-6
Replay Proof™Evidence Pack™
arrow_forward KYE™ framework reference
MIT AI Risk Repository

MIT AI Risk Repository — Domain Taxonomy

2024 · International

MIT AI Risk Repository (2024) Domain Taxonomy — 7 domains. KYE Protocol™ addresses the 4 action-authority domains (privacy/security access, malicious misuse, human oversight, system-safety traceability/multi-agent) and is HONESTLY out of scope for the 3 content/societal domains (discrimination & toxicity, misinformation, socioeconomic & environmental). Coverage never inflated. Per-requirement bijection at framework-coverage-bijection.

0 Enforced4 Designed3 Out of scope
7 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
D2 Privacy & Security — access bounded by purpose + tenant Designed L2 Designed mit-risk.d2-privacy-security
Purpose Permission™Decision Map™Tenant Isolation
D4 Malicious Actors & Misuse — unauthorised action refused Designed L2 Designed mit-risk.d4-malicious-misuse
Purpose Permission™Authority Gate
D5 Human-Computer Interaction — human oversight Designed L2 Designed mit-risk.d5-human-computer-interaction
GovernedUI
D7 AI System Safety — traceability + multi-agent authority Designed L2 Designed mit-risk.d7-traceability, mit-risk.d7-multi-agent
Evidence Pack™Replay Proof™Delegated Auditability
D1 Discrimination & Toxicity (content/fairness — out of scope)the protocol governs authority of agent ACTIONS, not content truth/fairness or macro-societal outcomes — this MIT domain is honestly out of scope; never inflated. Out of scope L1 Mapped MIT domain (content/societal — outside the authority-of-action scope)
D3 Misinformation (content truth — out of scope)the protocol governs authority of agent ACTIONS, not content truth/fairness or macro-societal outcomes — this MIT domain is honestly out of scope; never inflated. Out of scope L1 Mapped MIT domain (content/societal — outside the authority-of-action scope)
D6 Socioeconomic & Environmental (macro/societal — out of scope)the protocol governs authority of agent ACTIONS, not content truth/fairness or macro-societal outcomes — this MIT domain is honestly out of scope; never inflated. Out of scope L1 Mapped MIT domain (content/societal — outside the authority-of-action scope)
arrow_forward KYE™ framework reference
ATRS

Algorithmic Transparency Recording Standard (ATRS)

ATRS v3.0 (2025) · United Kingdom

The UK Government Algorithmic Transparency Recording Standard — mandatory for central-government departments and arm’s-length bodies publishing algorithmic tools that affect the public. KYE Protocol™ is the evidence source the ATRS record is populated FROM: every governed public-sector AI action emits a signed Evidence Pack™ carrying the tool’s purpose, decision map and capability profile, so the published transparency record is a projection of recorded runtime evidence rather than a hand-authored claim.

2 Enforced1 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Tier 1 + Tier 2 transparency recordMarquee mapping — the Evidence Pack™ populates the ATRS Tier-1 overview and Tier-2 technical record; replay-verifiable from published keys. Enforced L3 Enforceable Tier 1, Tier 2
Evidence Pack™Decision Map™Capability Profile
Senior responsible ownerThe ATRS named owner resolves to the recorded named-authority decision for every consequential action. Enforced L3 Enforceable Owner
Authority RegisterPurpose Permission™
Maintain & re-publish on change§13 drift detection flags the behaviour change that re-opens the published record; the re-publication trigger workflow is in build. Designed L2 Designed Maintenance
Resilience Loop™ drift signal
Public effect & appeal arrangementsThe substantive public-effect judgement and appeal design are the deploying body’s own responsibility; KYE supplies the contestability hooks, not the policy. Out of scope L1 Mapped Impact
arrow_forward KYE™ framework reference
UK Gov AI Playbook

AI Playbook for the UK Government

Feb 2025 · United Kingdom

The UK Government AI Playbook’s ten principles for safe, effective and secure use of AI in government. KYE Protocol™ enforces the governance principles at the action boundary: meaningful named accountability, secure provenance-backed use, and meaningful human control on consequential decisions — each emitting a signed, replay-verifiable Evidence Pack™.

3 Enforced1 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Meaningful accountabilityNamed human accountability recorded before every consequential action; the AI governance board maps to §36 approval modes. Enforced L3 Enforceable Principle: accountability
Authority RegisterPurpose Permission™GovernedUI approval modes
Keeping AI use securePinned provenance + WORM-retained replay-verifiable Evidence Pack™ per action. Enforced L3 Enforceable Principle: security
Replay-Proof™Evidence Pack™WORM audit
Meaningful human controlStaged finality (draft→recommendation→human-reviewed→citizen-facing→final); two-person sign-off on irreversible authorising-official assertions. Enforced L3 Enforceable Principle: human control
GovernedUI sign-offDecision finality states
Lifecycle management & monitoringDrift monitoring + AI/ML systems inventory; the mandated review-cadence workflow is in build. Designed L2 Designed Principle: lifecycle
Resilience Loop™§67 model-governance catalogue
arrow_forward KYE™ framework reference
Orange Book

HMT Orange Book — Management of Risk

2023 · United Kingdom

HM Treasury’s Orange Book is the cross-government standard for risk management. KYE Protocol™ performs the identify-assess-monitor arc at the action boundary: every governed AI action is risk-scored and admitted against a risk-scoped purpose grant before it runs, and behaviour drift is monitored continuously through the Resilience Loop™.

2 Enforced1 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Identify & assess riskRisk-scored admission against a risk-scoped purpose grant before the action runs. Enforced L3 Enforceable Identify, Assess
Risk scorePurpose Permission™Decision Map™
Monitor & respond§13 continuous drift detection + improvement records. Enforced L3 Enforceable Monitor
Resilience Loop™ drift signal
Report & escalate to governance bodyAuthority register + attestations support reporting; the portfolio risk-report rendering is in build. Designed L2 Designed Report
Authority RegisterCompliance attestation
arrow_forward KYE™ framework reference
Magenta Book

HMT Magenta Book — Evaluation Guidance

2020 · United Kingdom

HM Treasury’s Magenta Book is the cross-government standard for evaluation of interventions. KYE Protocol™ supplies the recorded process evidence — what the AI tool actually did, for whom, under whose authority — that a process or impact evaluation of an AI intervention rests on, drawn from runtime Evidence Packs™ rather than reconstructed from scattered logs.

1 Enforced1 Designed1 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Process evaluationRecorded action evidence is the process the evaluator examines. Enforced L3 Enforceable Process eval
Observed ActionEvidence Pack™Decision Map™
Impact evaluationPopulation-impact classification supports impact evaluation; the per-cohort export for a counterfactual study is in build. Designed L2 Designed Impact eval
Consequence Mapping Engine
Value-for-money & evaluation conclusionThe value-for-money judgement and analytical conclusion are the department’s evaluation function’s, not KYE’s. Out of scope L1 Mapped VfM
arrow_forward KYE™ framework reference
ISO 9000

ISO 9000:2015 — Quality management systems

ISO 9000:2015 · International

ISO 9000:2015 defines the quality-management concepts of objective evidence, validation and change control — ‘objective evidence that requirements have been fulfilled’. The KYE Evidence Pack™ IS that objective evidence: a signed, replay-verifiable record that the named-authority, due-diligence and sign-off requirements were fulfilled before an AI-assisted output proceeded.

2 Enforced1 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Objective evidence & verificationSigned replay-verifiable objective evidence that requirements were fulfilled. Enforced L3 Enforceable 3.8.3
Evidence Pack™Replay-Proof™Decision Map™
Validation (fit for intended use)Purpose-scope admission confirms the output fit for its intended public-sector use at the action boundary. Enforced L3 Enforceable 3.8.13
Purpose Permission™Decision Engine
Change control & re-validation§13 drift signal flags the change that ought to trigger re-validation; the re-validation gate workflow is in build. Designed L2 Designed Change control
Resilience Loop™ drift signal
arrow_forward KYE™ framework reference
UK AI Testing & Assurance (Public Sector)

AI Testing and Assurance Framework for the Public Sector

2024 · United Kingdom

The UK Cross-Government Testing Community framework for testing and assuring AI systems used in the public sector, pre-deployment and in-life. KYE Protocol™ runs pre-deployment scenario tests through the Scenario Engine, monitors in-life behaviour through the Resilience Loop™, and reconstructs an assurance record for an oversight reviewer through the §21 audit-replay machinery.

2 Enforced1 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Pre-deployment testingAdversarial/policy scenarios run and risk-scored before admission to a consequential action path. Enforced L3 Enforceable Pre-deployment
Scenario EngineRisk score
In-life assuranceContinuous drift detection + audit-pilot replay for ongoing assurance. Enforced L3 Enforceable In-life
Resilience Loop™Audit Pilot™
Assurance evidence & replayReconstructable assurance record; the Cross-Government-Testing-Community report rendering is in build. Designed L2 Designed Assurance record
Audit-replay orchestratorRegulator-replay agent
arrow_forward KYE™ framework reference
EN 18286

EN 18286:2025 — Quality management system for high-risk AI systems

EN 18286:2025 (E) · European Union

European harmonised standard for the QMS obligation on providers of high-risk AI systems (supporting EU AI Act Article 17). PARTIAL MAPPING — only Clause 5.1 (the six non-delegable top-management duties) is mapped at this edition; the rest of the standard is not yet mapped and is deliberately omitted, not inflated. KYE governs the AUTHORITY, OVERSIGHT, and EVIDENCE dimensions of the QMS; it does not implement the provider's HR/training, compute-procurement, or sustainability program.

4 Enforced2 Designed0 Out of scope
6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Quality policy & measurable objectives from regulatory purpose (5.1.a) Enforced L3 Enforceable EN 18286:2025 Clause 5.1.a + Note 2
Purpose Permission™Authority Register≤90-day attestation
Resources for the QMS — data-lineage/traceability storage over the retention period (5.1.b, lineage sub-duty only)Only the lineage/traceability-retention sub-duty maps to KYE. Compute provisioning, human-capital competence/training, and energy-efficiency sustainability are provider-owned and out of KYE scope (not claimed). Designed L2 Designed EN 18286:2025 Clause 5.1.b
WORM audit hash-chainobject-store immutability retention policy
Effective role responsibilities — human oversight, intervention thresholds, override/intervenability, automation-bias mitigation (5.1.c) Enforced L3 Enforceable EN 18286:2025 Clause 5.1.c
KYE GovernedUI™ approval modesOversight envelope / override interfaceDelegated-authority bindingMeta-governance no-self-grant gate
QMS integrated into the provider's processes across the AI lifecycle — not a separate binder (5.1.d) Enforced L3 Enforceable EN 18286:2025 Clause 5.1.d
Self-governance evidence-event familyCohesion Cascade™
QMS achieves intended results — management review, nonconformity → corrective action (5.1.e) Enforced L3 Enforceable EN 18286:2025 Clause 5.1.e
Reconciliation Engine™ declared-vs-deployed bijection≤90-day attestation
Communication of QMS importance & promotion of a responsible-AI culture (5.1.f + Note 1)KYE supplies the communication/education channel; sustaining a responsible-AI culture amid staff turnover/drift is a provider-owned people obligation and is not claimed as enforced. Designed L2 Designed EN 18286:2025 Clause 5.1.f
Comms Rail · KYE Comms Engine™Learn Rail · KYE Learn™
arrow_forward KYE™ framework reference
MAS AIRG (consultation)

MAS Consultation Paper on Guidelines on Artificial Intelligence Risk Management (AIRG)

consultation-2025-11 (final Guidelines not yet issued as of 2026-07-03) · Singapore

MAS's proposed sector-wide supervisory Guidelines on AI Risk Management (consultation paper published 13 November 2025; comments closed 31 January 2026): supervisory expectations on AI risk oversight, key AI risk-management systems, policies and procedures, AI life-cycle controls, and capabilities/capacity — explicitly covering Generative AI and AI agents, applied proportionately with a proposed 12-month transition after issuance. This instrument is REGISTERED in the §70 Framework Mapping Rail as a MONITORED consultation (the final Guidelines had not been issued at registration; the entry will be re-versioned on publication). It is distinct from MAS Project MindForge, the industry-co-created operationalisation handbook, which is deep-mapped separately. No requirement is bound while the text is non-final, so coverage is honestly reported as out of scope.

0 Enforced0 Designed1 Out of scope
1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail as a monitored consultation instrument; text not yet finalHonest registered state (§70 mapping_state=registered): the consultation crosswalks cleanly to existing KYE Protocol™ rails (AI oversight → §36 GovernedUI™ approval modes + Finality Gate; life-cycle controls → §13 Evidence Pack™ / Replay-Proof™; AI-agent expectations → §52 agent binding + §0.30 agents-as-principals), but the honesty bar forbids binding requirements to a non-final text — deep mapping runs through the §70 rail once MAS issues the Guidelines. Coverage is never inflated. Out of scope L1 Mapped MAS AIRG consultation paper (13 Nov 2025) — proposed expectations on AI oversight, risk-management systems, life-cycle controls, and capabilities; not yet issued as final Guidelines, not yet decomposed into requirement-level mappings
arrow_forward KYE™ framework reference
ISO/IEC 38507

ISO/IEC 38507:2022 — Governance implications of the use of AI by organizations

ISO/IEC 38507:2022 · International (ISO/IEC)

ISO/IEC 38507 gives the governing body guidance on the governance implications of AI, on the Evaluate-Direct-Monitor model. KYE Protocol™ governs the AUTHORITY dimension of that accountability: every AI-agent action is bound to a named accountable Principal under a directed purpose, with substantive human oversight and replay-provable evidence. KYE enforces the authority/evidence/oversight slice mechanically; the board process itself sits outside its scope (honest §70 tri-state).

4 Enforced1 Designed0 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Accountability & the governing body (non-delegable, EDM) Enforced L3 Enforceable iso-iec-38507.governing-body-accountability, iso-iec-38507.accountability-for-outcomes, iso-iec-38507.governance-vs-management
§0.30 accountable Principaldelegation chainAuthority vs execution seamEvidence Pack™
Direct — purpose alignment & acceptable-use policy Enforced L3 Enforceable iso-iec-38507.purpose-alignment, iso-iec-38507.acceptable-use-policy
Purpose Permission™Rules Gateway™Decision Map™
Evaluate — AI-specific considerations (autonomy, risk, data) Designed L3 Enforceable iso-iec-38507.ai-characteristics-consequences, iso-iec-38507.risk-oversight, iso-iec-38507.data-governance-for-ai
bounded agent authorityrisk signals§31 data-use authority
Monitor — human oversight & continuous assurance Enforced L3 Enforceable iso-iec-38507.material-decision-oversight, iso-iec-38507.continuous-monitoring
GovernedUI™ approval modesper-action re-check§34 reconciliation
Transparency, explainability & compliance obligations Enforced L3 Enforceable iso-iec-38507.transparency-explainability, iso-iec-38507.compliance-obligations
Decision Map™ reason codesReplay-Proof™≤90-day attestation§70 mapping
arrow_forward KYE™ framework reference
MOW SOC

MOW Search Only Terms Contract (SOC)

socw/2 (2026) — immutable MOW-stewarded contract URL, robots.txt Terms Document Locator (tdl:) declaration · United Kingdom

Machine-readable standard contract (Movement for an Open Web / Preiskel & Co LLP, July 2026) licensing website access for Search Indexing only and pricing every other Access Event at the contract's default per-Product Access Fee. KYE Protocol™ maps it as publisher-side content-access authority: classify each automated access against the licence at the moment of access, seal Access Events as verifiable evidence, and derive the invoice-ready unlicensed-access schedule. The contract stays MOW's — KYE™ never re-hosts or interprets it: the SOC sets the terms; KYE™ proves the breach.

0 Enforced7 Designed1 Out of scope
8 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Machine-readable terms declaration Designed L2 Designed mow-search-only-contract.terms-document-locator
Purpose Permission™Decision replayEvidence Pack™Replay-Proof™
Purpose-limited licensed access Designed L2 Designed mow-search-only-contract.purpose-limited-index-access
Purpose Permission™Decision replayEvidence Pack™Replay-Proof™
Access-event evidence & records Designed L2 Designed mow-search-only-contract.access-event-evidence
Purpose Permission™Decision replayEvidence Pack™Replay-Proof™
Access-fee accrual & waiver conditions Designed L2 Designed mow-search-only-contract.access-fee-accrual
Purpose Permission™Decision replayEvidence Pack™Replay-Proof™
AI-scraping & dataset prohibition Designed L2 Designed mow-search-only-contract.ai-scraping-prohibition
Purpose Permission™Decision replayEvidence Pack™Replay-Proof™
Database-rights & bulk-extraction restriction Designed L2 Designed mow-search-only-contract.database-rights
Purpose Permission™Decision replayEvidence Pack™Replay-Proof™
Contract formation & court enforcement Out of scope L1 Mapped mow-search-only-contract.legal-formation-and-enforcement
Accessibility & reader carve-out Designed L2 Designed mow-search-only-contract.accessibility-carveout
Purpose Permission™Decision replayEvidence Pack™Replay-Proof™
arrow_forward KYE™ framework reference
EW-AiRM

EW-AiRM — Enterprise-Wide AI Risk Management

EW-AiRM (Human-AI Institute / Markus Krebsz) · International

EW-AiRM is an enterprise-wide AI risk-management framework (Human-AI Institute / Markus Krebsz) that quantifies board risk appetite, assesses AI-necessity and organisational readiness, classifies risk against the MIT AI Risk Repository, sets non-negotiables (named accountability, tested human override, F-Critical no-averaging, named incident route) and an 8-Black-Swan resilience discipline, and produces a HAiPECR pre-deployment record. KYE Protocol™ maps the honest boundary — enterprise AI-risk governance is NOT per-action authority: system approval ≠ action authority. KYE enforces the runtime half (every consequential action admissibility-checked under a named authority, fail-closed, evidenced, replay-provable) and CONSUMES EW-AiRM's residual-risk acceptance and the HAiPECR verdict as an action policy, returning per-action authorised / denied / scope-inflation / expired-authority / revocation evidence. The quantification, readiness/necessity assessment, MIT-taxonomy classification, and Black-Swan scenario planning stay EW-AiRM's own work. From Board Risk Appetite to Runtime Proof. Per-requirement bijection at /compliance/ewairm.html.

3 Enforced5 Designed4 Out of scope
12 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
System approval vs per-action authority (the boundary) Enforced L3 Enforceable ewairm.system-approval-not-action-authority
Authority GatePurpose Permission™Decision replayReplay-Proof™
Non-negotiable — named accountability Enforced L3 Enforceable ewairm.non-negotiable-named-accountability
Named principalAuthority GateEvidence Pack™
Non-negotiable — no score-averaging over a critical failure Enforced L3 Enforceable ewairm.f-critical-no-averaging-override
Fail-closed admissibilityDecision replayReplay-Proof™
Non-negotiable — tested human override Designed L2 Designed ewairm.non-negotiable-tested-human-override
GovernedUI™ HITLKill-switch
Residual-risk acceptance → runtime condition Designed L2 Designed ewairm.residual-risk-acceptance-as-authority-condition
Purpose Permission™Scope condition
HAiPECR record consumption Designed L2 Designed ewairm.documented-haipecr-consumption
Decision replayAction policy
Non-negotiable — named incident route Designed L2 Designed ewairm.non-negotiable-named-incident-route
Contestability routeEvidence Pack™
Black-Swan resilience — runtime evidence Designed L2 Designed ewairm.black-swan-runtime-resilience-evidence
Resilience Loop™No-SPOFReplay-Proof™
Board risk-appetite quantificationQuantifying board-level AI risk appetite is EW-AiRM's enterprise-risk work; KYE consumes an already-decided residual-risk acceptance as a runtime condition but does not quantify appetite. Out of scope L1 Mapped ewairm.board-risk-appetite-quantification
Organisational-readiness assessmentPeople / process / culture / governance-maturity readiness assessment is an organisational-diagnostic activity KYE does not perform or replace. Out of scope L1 Mapped ewairm.organisational-readiness-assessment
AI-necessity assessmentWhether AI should be used at all (necessity / proportionality) is a judgement KYE does not adjudicate; KYE governs the authority of AI actions once AI is deployed. Out of scope L1 Mapped ewairm.ai-necessity-assessment
MIT AI Risk Repository taxonomyClassifying risks against the MIT AI Risk Repository is an analytic activity owned by the enterprise; KYE enforces authority at the action boundary regardless of how a risk is taxonomised. Out of scope L1 Mapped ewairm.mit-risk-taxonomy-classification
arrow_forward KYE™ framework reference
HAiPECR

HAiPECR — Human-AI Pre-deployment Evidence & Certification Record

HAiPECR (Human-AI Institute / Markus Krebsz, OECD-listed Apr 2023) · International

HAiPECR (Human-AI Institute / Markus Krebsz; OECD Catalogue of Tools & Metrics for Trustworthy AI, April 2023) is a pre-deployment evidence-and-certification record across seven dimensions — human oversight, accountability, transparency & explainability, privacy & data, ethics & fairness, compliance & legal, resilience & security — culminating in a deploy / do-not-deploy verdict. KYE Protocol™ CONSUMES the HAiPECR credential/verdict as an action policy and enforces the runtime half: dimensions that resolve to a real KYE runtime artefact are enforced/designed, and a do-not-deploy verdict makes consequential actions inadmissible at the §12 boundary — returning per-action authorised / denied / scope-inflation / expired-authority / revocation evidence. Ethics & fairness SCORING and the authoring of the HAiPECR record itself stay the human-expert's work (KYE proves authority, not model fairness). From Board Risk Appetite to Runtime Proof. Per-requirement bijection at /compliance/haipecr.html.

1 Enforced6 Designed1 Out of scope
8 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Dimension — accountability Enforced L3 Enforceable haipecr.accountability
Named principalAuthority GateEvidence Pack™
Dimension — human oversight Designed L2 Designed haipecr.human-oversight
GovernedUI™ HITLKill-switch
Dimension — transparency & explainability Designed L2 Designed haipecr.transparency-explainability
Decision Map™Evidence Pack™
Dimension — privacy & data Designed L2 Designed haipecr.privacy-data
Data-use admissibilityMemory Authority Rail™
Dimension — compliance & legal Designed L2 Designed haipecr.compliance-legal
Framework Mapping Rail™Decision replay
Dimension — resilience & security Designed L2 Designed haipecr.resilience-security
Resilience Loop™No-SPOFReplay-Proof™
Deploy-gate verdict consumption Designed L2 Designed haipecr.deploy-gate-verdict-consumption
Action policyPurpose Permission™Decision replay
Dimension — ethics & fairnessScoring the ethical acceptability and fairness of model behaviour is a model-evaluation activity owned by the builder and the enterprise's ethics function; KYE proves an action was authorised, evidenced, and replayable, not that the model is fair. Out of scope L1 Mapped haipecr.ethics-fairness
arrow_forward KYE™ framework reference

Data protection

Personal-data regulation covering lawful basis, data-subject rights, and processing accountability.

Alberta PIPA

Alberta PIPA — Personal Information Protection Act (Alberta)

S.A. 2003, c. P-6.5 · Canada

Alberta's private-sector privacy law (PIPA), substantially similar to PIPEDA and the first Canadian private-sector law with mandatory breach notification: consent, protection of personal information, and breach notification. Per-requirement bijection at /compliance/alberta-pipa.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Consent (ss.7-8) Enforced L3 Enforceable s7
Purpose Permission™
Protection of personal information (s.34) Enforced L3 Enforceable s34
Authority Gate
Breach notification (s.34.1) Enforced L3 Enforceable s34.1
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
DSG

Datenschutzgesetz (DSG, BGBl. I Nr. 165/1999, as amended 2018)

2018 (GDPR implementing act) · Austria

DSG is Austria's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Austria-specific national deltas here. Per-requirement bijection at /compliance/at-dsg.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
APPI

APPI — Act on the Protection of Personal Information

Act No. 57 of 2003, as amended (2022) · Japan

Japan's Act on the Protection of Personal Information, supervised by the Personal Information Protection Commission (PPC) — purpose-of-use limitation, security control measures, cross-border transfer, disclosure/access rights and breach reporting. KYE Protocol™ governs the personal-data obligations that bind an AI-supported action; the organisational privacy programme stays out of scope. Per-requirement bijection at /compliance/appi.html.

2 Enforced1 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Purpose-of-use limitation & security control measures Enforced L3 Enforceable APPI Art. 17-18, APPI Art. 23
Purpose Permission™Authority Resolution™Data Classification Engine
Cross-border transfer & disclosure/access rights Enforced L3 Enforceable APPI Art. 28 / 31, APPI Art. 33-35
Cross-Border Evidence agentDecision Map™Replay-Proof™Evidence Pack™
Breach reporting to the PPCKYE™ assembles the PPC notification package from the leakage evidence; the regulator-side delivery channel to the PPC is designed pending the per-jurisdiction reporting connector. Designed L1 Mapped APPI Art. 26
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
BC PIPA

BC PIPA — Personal Information Protection Act (British Columbia)

S.B.C. 2003, c. 63 · Canada

British Columbia's private-sector privacy law (PIPA), substantially similar to PIPEDA: consent, reasonable security, and access/correction. Per-requirement bijection at /compliance/bc-pipa.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Consent (ss.6-8) Enforced L3 Enforceable s6
Purpose Permission™
Reasonable security (s.34) Enforced L3 Enforceable s34
Authority Gate
Access + correction (ss.23-24) Enforced L3 Enforceable s23
Reporting EngineWORM audit hash-chain
arrow_forward KYE™ framework reference
Belgian Data Protection Act 2018

Loi du 30 juillet 2018 — Belgian Data Protection Act

2018 (GDPR implementing act) · Belgium

Belgian Data Protection Act 2018 is Belgium's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Belgium-specific national deltas here. Per-requirement bijection at /compliance/be-dpa-2018.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
Bulgarian Personal Data Protection Act

Personal Data Protection Act (amended 2019 to implement the GDPR)

2018 (GDPR implementing act) · Bulgaria

Bulgarian Personal Data Protection Act is Bulgaria's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Bulgaria-specific national deltas here. Per-requirement bijection at /compliance/bg-pdpa.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
nFADP

nFADP / revDSG — revised Federal Act on Data Protection (in force 1 Sept 2023)

in force 2023 · Switzerland

Switzerland's revised Federal Act on Data Protection (nFADP/revDSG) — a sovereign, GDPR-aligned statute under an EU adequacy decision. this registry maps the Swiss national deltas; AI-system governance defers to the directly-applicable obligations Switzerland references. Per-requirement bijection at /compliance/ch-nfadp.html.

4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
National statute (non-EU, adequacy) — nFADP/revDSG lawful-purpose + accountability Enforced L3 Enforceable nfadp-basis
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
Cross-border transfer / adequacy regime (non-EU) Enforced L3 Enforceable adequacy-cross-border
Authority GateEvidence Pack™
arrow_forward KYE™ framework reference
Law 125(I)/2018

Law 125(I)/2018 (providing for the protection of natural persons with regard to the processing of personal data)

2018 (GDPR implementing act) · Cyprus

Law 125(I)/2018 is Cyprus's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Cyprus-specific national deltas here. Per-requirement bijection at /compliance/cy-law-125-2018.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
Zákon 110/2019

Zákon č. 110/2019 Sb., o zpracování osobních údajů

2018 (GDPR implementing act) · Czech Republic

Zákon 110/2019 is Czech Republic's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Czech Republic-specific national deltas here. Per-requirement bijection at /compliance/cz-zakon-110-2019.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
BDSG

BDSG — Bundesdatenschutzgesetz (Federal Data Protection Act, 2018)

2018 (GDPR implementing act) · Germany

BDSG is Germany's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Germany-specific national deltas here. Per-requirement bijection at /compliance/de-bdsg.html.

4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
Employee-data processing (BDSG §26, works-council co-determination) Enforced L3 Enforceable employee-data-bdsg-26
Purpose Permission™Decision Map™
arrow_forward KYE™ framework reference
Databeskyttelsesloven

Databeskyttelsesloven (Lov nr. 502 af 23. maj 2018)

2018 (GDPR implementing act) · Denmark

Databeskyttelsesloven is Denmark's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Denmark-specific national deltas here. Per-requirement bijection at /compliance/dk-databeskyttelsesloven.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
LOPDGDD

LOPDGDD — Ley Orgánica 3/2018 de Protección de Datos Personales y garantía de los derechos digitales

2018 (GDPR implementing act) · Spain

LOPDGDD is Spain's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Spain-specific national deltas here. Per-requirement bijection at /compliance/es-lopdgdd.html.

4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
LOPDGDD Título X digital rights (disconnection, digital-will, workplace) Enforced L3 Enforceable digital-rights-titulo-x
DSAR AgentEvidence Pack™
arrow_forward KYE™ framework reference
Tietosuojalaki

Tietosuojalaki (1050/2018) — Data Protection Act

2018 (GDPR implementing act) · Finland

Tietosuojalaki is Finland's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Finland-specific national deltas here. Per-requirement bijection at /compliance/fi-tietosuojalaki.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
Loi Informatique et Libertés

Loi Informatique et Libertés (Act No. 78-17, as amended) + CNIL

2018 (GDPR implementing act) · France

Loi Informatique et Libertés is France's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the France-specific national deltas here. Per-requirement bijection at /compliance/fr-lil.html.

4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
Health-data HDS-certified hosting + CNIL reference methodologies Enforced L3 Enforceable health-data-hds
Data Classification EngineAuthority Gate
arrow_forward KYE™ framework reference
CCPA/CPRA

CCPA/CPRA — California Consumer Privacy Act (as amended by the CPRA)

Cal. Civ. Code §1798.100 et seq. (2018, amended by CPRA 2020) · United States

The California Consumer Privacy Act (as amended by the CPRA) grants California consumers rights over their personal information — notice at collection, the right to know/access, delete, correct, opt out of sale/sharing, limit the use of sensitive PI, and non-discrimination for exercising those rights. This framework is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: its consumer-rights structure overlaps heavily with the already-deep-mapped GDPR and crosswalks to existing KYE Protocol™ rails (right to know/delete/correct → §31 Data Governance Pack & the DSAR evidence agent; opt-out of sale/sharing & limit-use → §12 Purpose Permission™; data-as-authority lifecycle → §63 Memory Authority Rail), but no requirement has yet been bound at the requirement level. Per the §70 honesty bar, coverage is reported out of scope pending deep mapping rather than claimed as enforced.

0 Enforced0 Designed1 Out of scope
1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): candidate crosswalks to §31 / §12 / §63 and the existing GDPR deep-map are noted in the summary but NOT yet bound at the requirement level, so coverage stays out of scope until the deep mapping runs through the §70 rail — never inflated to imply enforcement that does not exist. Out of scope L1 Mapped CCPA/CPRA consumer rights (notice, know/access, delete, correct, opt-out of sale/sharing, limit sensitive PI, non-discrimination — not yet decomposed into requirement-level mappings)
arrow_forward KYE™ framework reference
GDPR

GDPR — General Data Protection Regulation

Regulation (EU) 2016/679 · European Union

EU regulation governing the processing of personal data.

4 Enforced1 Designed0 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Lawful basis & purpose limitation Enforced L3 Enforceable Art. 5, Art. 6
Purpose Permission™Authority Gate
Data-subject rights handling Enforced L3 Enforceable Art. 12-22
Purpose Permission™WORM audit hash-chain
Records of processing & accountability Enforced L3 Enforceable Art. 30
WORM audit hash-chainDecision replay
Integrity, confidentiality & signed evidenceAccess to personal data is governed today; signed integrity evidence and automated key rotation are in build. Designed L2 Designed Art. 32
Evidence Pack™ signing (COSE-Sign1)Automated key rotation
International transfers (Chapter V) — Schrems II / SCC / adequacy§72 Jurisdiction & Data-Sovereignty Authority surfaces the GDPR Chapter V cross-border requirements already deep-mapped in internal Each crossing emits a signed kye.cross_border.transfer.v1 carrying the lawful_basis (adequacy / SCC + Transfer Impact Assessment) and the residency_verdict, so the Art. 44-49 transfer-impact assessment is the evidence pack itself. Enforced L3 Enforceable Art. 44, Art. 45, Art. 46, Art. 49
Cross-Border Transfer Record (kye.cross_border.transfer.v1)Jurisdiction Attestation (kye.jurisdiction.attestation.v1)Residency Verdict (§72)
arrow_forward KYE™ framework reference
GDPR Art. 22

GDPR Article 22 — Automated Decision-Making

Regulation (EU) 2016/679 (GDPR) — Article 22 (automated individual decision-making, including profiling) + Articles 13–15 / Recital 71 · European Union

GDPR Article 22 gives data subjects the right not to be subject to solely-automated similarly-significant decisions without safeguards — human intervention, meaningful information about the logic, and the right to contest. KYE Protocol™ governs whether an AI-assisted insurance decision in scope may proceed — under a recorded named-authority (the human-involvement safeguard), with a recorded adverse-action reason-code (meaningful information about the logic), a signed replay-provable Evidence Pack™ per decision, and an appeal / contestability record (the right to contest and to human intervention). The lawful basis / substantive decision / risk pricing on the merits stays the controller's own work (honest scope, §0). Per-requirement bijection at /compliance/gdpr-automated-decision.html.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Human involvement / named-authority safeguard (Art. 22(3)) Enforced L3 Enforceable gdpr-automated-decision.art22-human-involvement-safeguard
Authority GateDecision replayEvidence Pack™Replay-Proof™
Right to contest & human intervention (Recital 71) Enforced L3 Enforceable gdpr-automated-decision.art22-contest-human-intervention
Authority GateDecision replayEvidence Pack™Replay-Proof™
Meaningful information about the logic / adverse-action reason (Art. 13–15) Enforced L3 Enforceable gdpr-automated-decision.art13-15-meaningful-information-logic
Authority GateDecision replayEvidence Pack™Replay-Proof™
Lawful basis, substantive decision & pricing on the meritsThe lawful basis for the processing / the substantive decision / the risk pricing on the merits is the controller's own work — KYE™ is an AI-authority and evidence layer at the action boundary, not a legal-basis, decision, or pricing engine. Out of scope L1 Mapped gdpr-automated-decision.lawful-basis-substantive-decision
arrow_forward KYE™ framework reference
Law 4624/2019

Law 4624/2019 (measures implementing the GDPR)

2018 (GDPR implementing act) · Greece

Law 4624/2019 is Greece's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Greece-specific national deltas here. Per-requirement bijection at /compliance/gr-law-4624-2019.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
Info Act

Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Info Act, GDPR-aligned)

2018 (GDPR implementing act) · Hungary

Info Act is Hungary's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Hungary-specific national deltas here. Per-requirement bijection at /compliance/hu-info-act.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
Data Protection Act 2018

Data Protection Act 2018

2018 (GDPR implementing act) · Ireland

Data Protection Act 2018 is Ireland's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Ireland-specific national deltas here. Per-requirement bijection at /compliance/ie-dpa-2018.html.

4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
One-Stop-Shop lead supervisory authority (DPC) — cross-border accountability Enforced L3 Enforceable lead-supervisory-oss
Evidence Pack™Reporting Engine
arrow_forward KYE™ framework reference
ISO 23081

ISO 23081-1:2017 — Managing Metadata for Records (records-metadata spine)

2017 · Global

ISO 23081-1:2017 records-metadata spine and AUTHORITY ANCHOR for the InSight DXP connector contract. KYE Protocol™ CONSUMES records metadata (agent, classification, event-history) as the input signal at the action boundary (enforced: classification-driven-authority, custody→authority binding, agent→principal binding); records-metadata creation / management is out-of-scope (owned by Iron Mountain InSight DXP).

2 Enforced0 Designed2 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Metadata-driven authority decision (authority overlay) Enforced L3 Enforceable iso-23081.classification-driven-authority, iso-23081.event-history-evidence
Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Agent-metadata binding to a KYE-resolved principal (authority overlay) Enforced L3 Enforceable iso-23081.agent-metadata-principal-binding
Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Metadata creation & capture (records-management) Out of scope L1 Mapped iso-23081.metadata-creation-capture
Metadata management & maintenance (records-management) Out of scope L1 Mapped iso-23081.metadata-management-maintenance
arrow_forward KYE™ framework reference
Codice Privacy

Codice in materia di protezione dei dati personali (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018)

2018 (GDPR implementing act) · Italy

Codice Privacy is Italy's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Italy-specific national deltas here. Per-requirement bijection at /compliance/it-codice-privacy.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
Luxembourg Data Protection Act 2018

Loi du 1er août 2018 portant organisation de la Commission nationale pour la protection des données

2018 (GDPR implementing act) · Luxembourg

Luxembourg Data Protection Act 2018 is Luxembourg's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Luxembourg-specific national deltas here. Per-requirement bijection at /compliance/lu-cnpd.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
UAVG

UAVG — Uitvoeringswet Algemene verordening gegevensbescherming (GDPR Implementation Act, 2018)

2018 (GDPR implementing act) · Netherlands

UAVG is Netherlands's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Netherlands-specific national deltas here. Per-requirement bijection at /compliance/nl-uavg.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
Personopplysningsloven

Personopplysningsloven (LOV-2018-06-15-38) — GDPR incorporated via the EEA Agreement

2018 (GDPR implementing act) · Norway

Personopplysningsloven is Norway's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Norway-specific national deltas here. Per-requirement bijection at /compliance/no-personopplysningsloven.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
NZ Privacy Act 2020

New Zealand Privacy Act 2020

Privacy Act 2020 (NZ) · New Zealand

The NZ Information Privacy Principles + Part 6 notifiable privacy breaches. Per-requirement bijection at /compliance/nz-privacy-act-2020.html.

2 Enforced0 Designed0 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
IPP 5 security, IPP 10 use-limitation, IPP 6 access Enforced L3 Enforceable IPP 5, IPP 10, IPP 6
Authority GatePurpose Permission™DSAR Evidence agentReplay-Proof™
Part 6 notifiable privacy breachDetection + package assembly enforced; delivery channel to the OPC is in build. Enforced L3 Enforceable Privacy Act 2020 Part 6
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
PIPEDA

PIPEDA — Personal Information Protection and Electronic Documents Act

S.C. 2000, c. 5 · Canada

Canada's federal private-sector privacy law (PIPEDA, S.C. 2000, c. 5): the ten Schedule 1 fair-information principles plus mandatory breach-of-security-safeguards reporting (s.10.1). Per-requirement bijection at /compliance/pipeda.html.

6 Enforced0 Designed0 Out of scope
6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Accountability + openness (Sch.1 4.1, 4.8) Enforced L3 Enforceable sch1-4.1
Authority GateReporting Engine
Purpose + consent (Sch.1 4.2-4.3) Enforced L3 Enforceable sch1-4.3
Decision Map™Purpose Permission™
Limiting collection/use/retention (Sch.1 4.4-4.5) Enforced L3 Enforceable sch1-4.5
Authority GatePurpose Permission™
Safeguards (Sch.1 4.7) Enforced L3 Enforceable sch1-4.7
Authority Gate
Individual access (Sch.1 4.9) Enforced L3 Enforceable sch1-4.9
Reporting EngineWORM audit hash-chain
Breach reporting (s.10.1) Enforced L3 Enforceable s10.1
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
UODO

Ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych (Personal Data Protection Act)

2018 (GDPR implementing act) · Poland

UODO is Poland's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Poland-specific national deltas here. Per-requirement bijection at /compliance/pl-uodo.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
Privacy Act 1988

Privacy Act 1988 (Cth) — ADM transparency + APPs

ADM reform (Privacy and Other Legislation Amendment Act 2024) · Australia

The Australian Privacy Principles + the 2024 automated-decision-making transparency reform (ADM provisions commence Dec 2026). Per-requirement bijection at /compliance/privacy-act-1988.html.

2 Enforced0 Designed0 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Automated decision-making transparency Enforced L3 Enforceable Privacy Act 2024 reform — ADM
Decision Map™Evidence Pack™Replay-Proof™
APP 1 open management + APP 11 security of personal information Enforced L3 Enforceable APP 1, APP 11
Authority GatePurpose Permission™Reporting Engine
arrow_forward KYE™ framework reference
Lei 58/2019

Lei n.º 58/2019 (assegura a execução do RGPD)

2018 (GDPR implementing act) · Portugal

Lei 58/2019 is Portugal's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Portugal-specific national deltas here. Per-requirement bijection at /compliance/pt-lei-58-2019.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
Quebec Law 25

Quebec Law 25 — Private Sector personal-information modernisation

S.Q. 2021, c. 25 · Canada

Quebec's modernised private-sector privacy regime (Law 25, fully in force Sept 2024): privacy-impact assessment, automated-decision transparency, confidentiality-incident reporting to the CAI, data portability, and express consent for sensitive information. Per-requirement bijection at /compliance/quebec-law-25.html.

5 Enforced0 Designed0 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Privacy impact assessment (s.3.3) Enforced L3 Enforceable s3.3
Decision Map™Risk Engine
Automated-decision transparency (s.12.1) Enforced L3 Enforceable s12.1
Decision Map™Replay-Proof™
Confidentiality-incident reporting (s.3.5-3.8) Enforced L3 Enforceable s3.5
Incident DetectorReporting Engine
Data portability (s.27) Enforced L3 Enforceable s27
Reporting EngineWORM audit hash-chain
Consent for sensitive information (s.12) Enforced L3 Enforceable s12
Authority GatePurpose Permission™
arrow_forward KYE™ framework reference
Law 190/2018

Law No. 190/2018 (implementing measures for the GDPR)

2018 (GDPR implementing act) · Romania

Law 190/2018 is Romania's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Romania-specific national deltas here. Per-requirement bijection at /compliance/ro-law-190-2018.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
Swedish Data Protection Act

Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning

2018 (GDPR implementing act) · Sweden

Swedish Data Protection Act is Sweden's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Sweden-specific national deltas here. Per-requirement bijection at /compliance/se-dpa.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
Act 18/2018

Act No. 18/2018 Coll. on Personal Data Protection

2018 (GDPR implementing act) · Slovakia

Act 18/2018 is Slovakia's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Slovakia-specific national deltas here. Per-requirement bijection at /compliance/sk-act-18-2018.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registry Enforced L3 Enforceable gdpr-transposition
Purpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing account Enforced L3 Enforceable supervisory-authority
Evidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assembly Enforced L3 Enforceable breach-notification
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
China PIPL

PIPL — Personal Information Protection Law of the People's Republic of China

PIPL (effective 2021-11-01) · China

PIPL governs the processing and cross-border provision of personal information of individuals in the PRC. Chapter III sets the lawful routes for cross-border provision (CAC security assessment, CAC standard contract, or personal-information-protection certification) plus a data-localisation duty for critical-information-infrastructure operators and large processors. This framework is REGISTERED in the §70 Framework Mapping Rail and surfaced by §72 (Jurisdiction & Data-Sovereignty Authority) at the cross-border admissibility boundary; deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.

0 Enforced0 Designed1 Out of scope
1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no PIPL requirement is bound to a KYE Protocol™ artefact yet. The §72 cross-border admissibility binding (kye.cross_border.transfer.v1.residency_verdict) is platform-level and applies across regimes; PIPL-specific deep mapping (CAC routes, localisation duties) is scheduled through the §70 rail. Coverage is never inflated. Out of scope L1 Mapped PIPL Chapter III — cross-border provision of personal information (Arts. 38-43); full text not yet decomposed into requirement-level mappings
arrow_forward KYE™ framework reference
UK IDTA / Data Bridge

UK International Data Transfer regime — IDTA, Addendum and UK Data Bridge

IDTA + International Data Transfer Addendum (in force 2022-03-21) · United Kingdom

The UK regime for restricted international transfers under UK GDPR / DPA 2018 ss.17A-19: the ICO International Data Transfer Agreement (IDTA), the UK Addendum to the EU SCCs, and UK adequacy regulations ('data bridges'). This framework is REGISTERED in the §70 Framework Mapping Rail and surfaced by §72 (Jurisdiction & Data-Sovereignty Authority) at the cross-border admissibility boundary; deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.

0 Enforced0 Designed1 Out of scope
1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no UK-transfer requirement is bound to a KYE Protocol™ artefact yet. The §72 cross-border admissibility binding (kye.cross_border.transfer.v1.residency_verdict) is platform-level; UK-IDTA-specific deep mapping (IDTA clauses, data-bridge adequacy) is scheduled through the §70 rail. Coverage is never inflated. Out of scope L1 Mapped UK GDPR Chapter V + DPA 2018 ss.17A-19; ICO IDTA / Addendum / data-bridge adequacy regulations — full text not yet decomposed into requirement-level mappings
arrow_forward KYE™ framework reference
Singapore PDPA

Singapore Personal Data Protection Act 2012 (PDPA)

PDPA 2012 (No. 26 of 2012), as amended 2020 · Singapore

Singapore's baseline data-protection statute, administered by the Personal Data Protection Commission (PDPC): consent, notification and purpose-limitation obligations, deemed consent by notification, the legitimate-interests exception, mandatory data-breach notification, data portability, and the Do Not Call registry (as amended by the Personal Data Protection (Amendment) Act 2020). This framework is REGISTERED in the §70 Framework Mapping Rail — distinct from Bulgaria's PDPA, which is registered separately — and connects to the §63 Memory Authority Rail, whose four memory-lifecycle schema deltas were validated against Singapore-PDPC guidance. Deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.

0 Enforced0 Designed1 Out of scope
1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no PDPA requirement is bound to a KYE Protocol™ artefact yet. The §63 Memory Authority Rail's Singapore-PDPC-validated schema deltas (ai_specific_notice, withdrawal_route, use_type, use_admissibility_ref) are platform-level and cross-regime; PDPA-specific deep mapping is scheduled through the §70 rail. Coverage is never inflated. Out of scope L1 Mapped PDPA 2012 Parts III-VIA — consent, purpose limitation, notification, access/correction, data-breach notification, data portability; full text not yet decomposed into requirement-level mappings
arrow_forward KYE™ framework reference
DPDP Act 2023

Digital Personal Data Protection Act, 2023

Act No. 22 of 2023 · India

KYE governs the AUTHORITY + EVIDENCE layer of personal-data processing at the action boundary: whether a consequential action against personal data was authorised under a declared purpose (§12), and whether that decision is sealed and replayable (§13/§30). KYE is OUT-OF-SCOPE for the substantive data-governance obligations a Data Fiduciary owes directly — obtaining valid consent from Data Principals, publishing notices, appointing a Data Protection Officer, conducting Data Protection Impact Assessments, and answering the Board. Those are the customer's own systems, processes and counsel; KYE evidences the action, it does not discharge the duty (§70 §4). Deep per-requirement mapping: 8 requirements, 3 enforced by KYE runtime, 5 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.

1 Enforced0 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority + evidence at the action boundary — enforced by KYE runtime and verified by CI Enforced L3 Enforceable dpdp-act-2023.PURPOSE-LIMITATION — Personal data processed only for the purpose for which consent was given, dpdp-act-2023.ACTION-EVIDENCE — Every consequential action on personal data is evidenced and replayable, dpdp-act-2023.ERASURE-ROUTE — Data Principal right to erasure is routed and evidenced
kye.compliance.attestation.v1kye.evidence.decision_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context_seal.v1internalinternalinternal
Obligations owed directly by the regulated entity — NOT discharged by KYEKYE governs the AUTHORITY + EVIDENCE layer of personal-data processing at the action boundary: whether a consequential action against personal data was authorised under a declared purpose (§12), and whether that decision is sealed and replayable (§13/§30). KYE is OUT-OF-SCOPE for the substantive data-governance obligations a Data Fiduciary owes directly — obtaining valid consent from Data Principals, publishing notices, appointing a Data Protection Officer, conducting Data Protection Impact Assessments, and answering the Board. Those are the customer's own systems, processes and counsel; KYE evidences the action, it does not discharge the duty (§70 §4). Out of scope L1 Mapped dpdp-act-2023.NOTICE-CONSENT — Itemised notice and valid consent obtained from the Data Principal, dpdp-act-2023.BREACH-INTIMATION — Personal-data breach intimated to the Board and affected Data Principals, dpdp-act-2023.SDF-OBLIGATIONS — Significant Data Fiduciary duties — DPO, independent audit, DPIA, dpdp-act-2023.CHILDREN-DATA — Verifiable parental consent and no tracking or targeted advertising directed at children, dpdp-act-2023.CROSS-BORDER — Transfer of personal data outside India subject to Government restriction
arrow_forward KYE™ framework reference

Financial-services regulation

Payments and operational-resilience regulation specific to banks, payment institutions, and the EU financial sector.

ECOA / Reg B

ECOA / Regulation B — Equal Credit Opportunity Act

ECOA (15 U.S.C. §1691 et seq.) / Regulation B (12 C.F.R. Part 1002) · United States

ECOA prohibits discrimination in any aspect of a credit transaction and Regulation B operationalises it, including §1002.9 adverse-action notices with a specific statement of reasons. KYE Protocol™ governs whether an AI lending agent's consequential credit decision may proceed — only under a named-authority decision purpose-scoped to the credit transaction, with every adverse action carrying a Decision Map™ (the specific reasons, explainable) bound to a §61 contestability route and sealed into a signed replay-provable Evidence Pack™. The disparate-impact statistics, the credit-scoring feature choice, and the model's fairness validation stay the lender's own quantitative fair-lending work (honest scope, §0). Per-requirement bijection at /compliance/ecoa-reg-b.html.

2 Enforced1 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Credit-decision authority at the action boundary Enforced L3 Enforceable ecoa-reg-b.credit-decision-named-authority
Authority GateDecision replayEvidence Pack™Replay-Proof™
Adverse-action notice with specific reasons Enforced L3 Enforceable ecoa-reg-b.adverse-action-decision-map
Decision Map™Evidence Pack™Contestability routeReplay-Proof™
Prohibited-basis non-discrimination evidence Designed L2 Designed ecoa-reg-b.prohibited-basis-non-discrimination-evidence
Decision Map™Audit WORM
Fair-lending statistical analysis & model fairnessThe disparate-impact regression, less-discriminatory-alternative search, and model-fairness validation are the lender's own quantitative fair-lending work — KYE™ is an AI-authority and evidence layer, not a fair-lending analytics engine. Out of scope L1 Mapped ecoa-reg-b.fair-lending-statistical-analysis
arrow_forward KYE™ framework reference
FCRA

FCRA — Fair Credit Reporting Act

Fair Credit Reporting Act (15 U.S.C. §1681 et seq.) / Regulation V (12 C.F.R. Part 1022) · United States

FCRA §1681m requires a user of a consumer report who takes adverse action based on it to give an adverse-action notice naming the reporting agency and the consumer's rights. KYE Protocol™ governs whether an AI lending agent may act on a consumer report — only under a named-authority decision with a permissible purpose, with every report-driven adverse action carrying a Decision Map™ (the report's contribution + the named reporting agency) bound to a §61 contestability route and sealed into a signed replay-provable Evidence Pack™. The report generation, the scoring of report data, and the accuracy of report contents stay the consumer-reporting agency's and furnisher's work (honest scope, §0). Per-requirement bijection at /compliance/fcra.html.

3 Enforced1 Designed2 Out of scope
6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Credit-report use authority at the decision boundary Enforced L3 Enforceable fcra.credit-report-use-authority
Authority GateDecision replayEvidence Pack™Replay-Proof™
Adverse-action-on-report notice (specific reasons + agency identity) Enforced L3 Enforceable fcra.adverse-action-on-report-notice
Decision Map™Evidence Pack™Contestability route
Consumer-report data accuracy & furnisher disputesReport-content accuracy, the furnisher's §1681s-2 duties, and reinvestigation of disputes are the reporting agency's and furnisher's obligations — KYE™ governs the lending agent's decision, not the report. Out of scope L1 Mapped fcra.report-accuracy-and-furnisher-disputes
Employment / tenant consumer-report use authority Enforced L3 Enforceable fcra.employment-report-permissible-purpose-and-disclosure
Authority GatePurpose Permission™Evidence Pack™
Employment pre-adverse-action two-step notice Designed L2 Designed fcra.pre-adverse-action-notice
Decision Map™Contestability route
Consumer-report data disposalDisposal of the consumer-report copy and underlying data is the user's own data-handling duty over data KYE does not hold — KYE governs the agent's authority-to-act, not the report data. Out of scope L1 Mapped fcra.disposal-of-consumer-report-data
arrow_forward KYE™ framework reference
ICRAA

ICRAA — California Investigative Consumer Reporting Agencies Act

California Investigative Consumer Reporting Agencies Act (ICRAA), Cal. Civ. Code §1786 et seq. · United States

ICRAA is the California-jurisdiction overlay on the federal FCRA for INVESTIGATIVE consumer reports (character / reputation / mode-of-living information gathered through interviews — the bulk of California employment and tenant background screening). It is stricter than FCRA: §1786.16 requires clear-and-conspicuous written notice AND the consumer's written authorization plus a nature-and-scope disclosure before an investigative consumer report is procured; §1786.40 requires an adverse-action notice naming the agency. KYE Protocol™ governs whether an AI agent may PROCEED to procure or act on an investigative consumer report — only under a named-authority decision with a permissible purpose, a recorded written-consent authority, and every adverse action carrying a Decision Map™ + the named agency bound to a §61 contestability route and sealed into a signed replay-provable Evidence Pack™. KYE is NOT a consumer reporting agency: it does not generate the report, conduct the interviews, judge the accuracy of the report contents, or run the reinvestigation (honest scope, §0/§70). Per-requirement bijection at /compliance/icraa.html.

3 Enforced1 Designed1 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Investigative-report use authority at the procurement/decision boundary Enforced L3 Enforceable icraa.investigative-report-use-authority
Authority GatePurpose Permission™Evidence Pack™
California written notice + written authorization + nature-and-scope disclosure Enforced L3 Enforceable icraa.written-consent-and-nature-scope-disclosure
Authority GateDecision Map™Evidence Pack™
Adverse-action-on-investigative-report notice (reasons + agency identity) Enforced L3 Enforceable icraa.adverse-action-notice
Decision Map™Evidence Pack™Contestability route
Consumer copy + dispute / reinvestigation route Designed L2 Designed icraa.consumer-copy-and-dispute-route
Contestability routeDelegated Auditability
Investigative-report content accuracy & agency reinvestigation dutiesReport-content accuracy, the reasonable-procedures duty (§1786.20), and the agency's reinvestigation (§1786.24) are the investigative consumer reporting agency's obligations — KYE governs the user's decision, not the report, and is not a CRA. Out of scope L1 Mapped icraa.report-accuracy-and-agency-reinvestigation
arrow_forward KYE™ framework reference
FCA CONC

FCA CONC — Consumer Credit Sourcebook

FCA Handbook CONC — Consumer Credit Sourcebook · United Kingdom

FCA CONC governs UK consumer-credit conduct, including CONC 5 responsible lending (creditworthiness & affordability) and CONC 7 arrears, default & forbearance. KYE Protocol™ governs whether an AI lending agent's creditworthiness-driven or arrears action may proceed — only under a named-authority decision purpose-scoped to the credit agreement, with the action carrying a Decision Map™ recording that the creditworthiness assessment was relied on, bound to a §61 forbearance/contestability route, and sealed into a signed replay-provable Evidence Pack™. The affordability calculation and credit-policy adequacy stay the lender's own responsible-lending work (honest scope, §0). Per-requirement bijection at /compliance/fca-conc.html.

1 Enforced1 Designed1 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Creditworthiness/arrears action authority at the boundary Enforced L3 Enforceable fca-conc.lending-action-named-authority
Authority GateDecision replayEvidence Pack™Replay-Proof™
Creditworthiness-reliance & forbearance evidence Designed L2 Designed fca-conc.creditworthiness-reliance-evidence
Decision Map™Evidence Pack™Contestability route
Affordability calculation & credit-policy adequacyThe affordability calculation, income/expenditure modelling, and credit-policy adequacy under CONC 5 are the lender's own responsible-lending work — KYE™ governs the agent's action, not the calculation. Out of scope L1 Mapped fca-conc.affordability-calculation-and-policy
arrow_forward KYE™ framework reference
AICPA SSTS

AICPA SSTS — Statements on Standards for Tax Services

2024 · United States

AICPA Statements on Standards for Tax Services (2024) — the enforceable standards for tax-return positions (reasonable basis / disclosure), reasonable inquiry & reliance on data, and the form & content of advice. KYE Protocol™ governs whether an AI-generated tax position / advice may proceed under a named member's authority, with the SSTS standards recorded before the action — the KYE Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Tax-return positions (SSTS No. 1) Designed L2 Designed aicpa-ssts.ssts1-reasonable-basis, aicpa-ssts.ssts1-disclosure
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Data & reasonable inquiry (SSTS No. 3) Designed L2 Designed aicpa-ssts.ssts3-reasonable-inquiry
Evidence Pack™Replay-Proof™Action Admissibility™ Gate
Form & content of advice (SSTS No. 7) Designed L2 Designed aicpa-ssts.ssts7-form-of-advice
Action Admissibility™ GateAuthority Finality™Evidence Pack™
arrow_forward KYE™ framework reference
AIFMD / UCITS

AIFMD / UCITS — Fund Manager Authority, Risk Management & Investment Limits

Directive 2011/61/EU & Directive 2009/65/EC · European Union

AIFMD (Directive 2011/61/EU) and the UCITS Directive (Directive 2009/65/EC) govern EU collective-investment fund management — fund-manager authorisation & conduct, the risk-management function & limits, investment limits & diversification, and recordkeeping / depositary oversight. KYE Protocol™ governs whether an AI-assisted investment decision/action is within the fund's mandate and limits, authorised, evidenced, and final at the action boundary — the KYE Investment Decision Authority Pack™. KYE Protocol™ does not run the risk-management function, judge whether a decision is correct, produce investment intelligence, or act as a fund manager. Per-requirement bijection at framework-coverage-bijection.

4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Fund manager authorisation & conduct Enforced L3 Enforceable aifmd-ucits.fund-manager-authorisation-conduct
Action Admissibility™ GateAuthority Finality™Evidence Pack™
Risk-management function & limits Enforced L3 Enforceable aifmd-ucits.risk-management-function-limits
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Investment limits & diversification Enforced L3 Enforceable aifmd-ucits.investment-limits-diversification
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Recordkeeping & depositary oversight Enforced L3 Enforceable aifmd-ucits.recordkeeping-depositary-oversight
Evidence Pack™Replay-Proof™Action Admissibility™ Gate
arrow_forward KYE™ framework reference
APRA CPS 230

APRA CPS 230 — Operational Risk Management

Effective 1 July 2025 · Australia

APRA Prudential Standard CPS 230 — operational risk management, business continuity and service-provider management for APRA-regulated entities. Per-requirement bijection at /compliance/apra-cps-230.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Operational risk management (paras 13-21) Enforced L3 Enforceable CPS 230 §13, CPS 230 §15, CPS 230 §18
Risk EngineDecision EngineAuthority GatePurpose Permission™Resilience Loop™
Incident notification to APRA (para 20)Detection + package assembly enforced; the regulator-side delivery channel to APRA is in build. Enforced L3 Enforceable CPS 230 §20
Incident DetectorReporting Engine
Business continuity + service-provider management (paras 30-48) Enforced L3 Enforceable CPS 230 §35, CPS 230 §42
Authority RegisterSPoF registryEdge Governance Safety FloorOffline Evidence Log
arrow_forward KYE™ framework reference
FSA AI Guidelines

FSA AI / Model Governance Expectations for Financial Institutions

FSA AI Discussion Paper (June 2024) + Supervision Guidelines · Japan

The Japan Financial Services Agency's AI governance and model-risk expectations for financial institutions — AI governance & accountability, model risk management, human oversight, explainability and operational resilience. KYE Protocol™ evidences the expectations that bind an AI-supported financial action at runtime. Per-requirement bijection at /compliance/fsa-guidelines-ai.html.

2 Enforced1 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
AI governance, accountability & model risk management Enforced L3 Enforceable FSA AI governance expectation, FSA model-risk expectation
Purpose Permission™Risk EngineConformance RunnerDrift Detector
Human oversight & explainability/customer disclosure Enforced L3 Enforceable FSA human-oversight expectation, FSA explainability expectation
GovernedUI™Authority Resolution™Decision Map™Evidence Pack™
Operational resilience & incident reporting to the FSAKYE™ assembles the FSA notification package; the regulator-side delivery channel to the FSA is designed pending the per-jurisdiction reporting connector. Designed L1 Mapped FSA operational-resilience expectation
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
Consumer-Driven Banking

Canada Consumer-Driven Banking Framework (open banking)

Consumer-Driven Banking Act (2024) · Canada

Canada's consumer-driven banking (open banking) framework under the Consumer-Driven Banking Act, 2024 (stood up by the FCAC): accreditation of participants, consumer consent + data-sharing control, a common technical/security standard, and oversight + accountability. Per-requirement bijection at /compliance/canada-cdb.html.

4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Accreditation of participants Enforced L3 Enforceable accreditation
Authority GateRisk Engine
Consumer consent + data-sharing control Enforced L3 Enforceable consent
Authority GatePurpose Permission™
Common technical + security standard Enforced L3 Enforceable technical-standard
Authority Gate
Oversight + accountability Enforced L3 Enforceable oversight
Authority GateReporting Engine
arrow_forward KYE™ framework reference
Companies Act 2006

UK Companies Act 2006 — Accounting Records, True & Fair Accounts & Filing with the Registrar

2006 · United Kingdom

The UK Companies Act 2006 — adequate accounting records (s.386), true and fair view (s.393), director responsibility & board approval (s.414), and filing of the statutory accounts with the Registrar of Companies / Companies House (s.441/s.442). KYE Protocol™ governs whether an AI-generated financial entry / statement / filing may proceed to a consequential action under a named accountant's / director's authority, with §36 two-person sign-off on the irreversible Companies House submission — the KYE Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0 Enforced4 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Adequate accounting records (s.386) Designed L2 Designed companies-act-2006.s386-adequate-records
Evidence Pack™Replay-Proof™Action Admissibility™ Gate
True & fair view (s.393) Designed L2 Designed companies-act-2006.s393-true-and-fair
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Director responsibility & approval (s.414) Designed L2 Designed companies-act-2006.s414-director-responsibility
Action Admissibility™ GateAuthority Finality™Evidence Pack™
Filing with the Registrar / Companies House (s.441/s.442) Designed L2 Designed companies-act-2006.s441-filing-with-registrar, companies-act-2006.s442-filing-deadlines
Action Admissibility™ GateAuthority Finality™Evidence Pack™
arrow_forward KYE™ framework reference
DORA

DORA — Digital Operational Resilience Act

Regulation (EU) 2022/2554 · European Union

EU regulation for the digital operational resilience of the financial sector.

4 Enforced0 Designed1 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
ICT risk-management framework Enforced L3 Enforceable Art. 5-16
Purpose Permission™Authority GateWORM audit hash-chain
ICT incident detection & reconstruction Enforced L3 Enforceable Art. 17-23
WORM audit hash-chainDecision replay
ICT third-party register & concentration analysis Enforced L3 Enforceable Art. 28(3)
Directory tenant proxyWORM audit hash-chain
Tamper-evident resilience evidenceResilience-testing outcomes are recorded today; signed resilience evidence packs are in build. Enforced L3 Enforceable Art. 24-27
Evidence Pack™ signing (COSE-Sign1)
ICT third-party contractual arrangementsExit strategies, audit rights, and termination clauses require contract-management tooling outside KYE™. Out of scope L1 Mapped Art. 15, Art. 28-30
arrow_forward KYE™ framework reference
DORA Incident

DORA ICT Incident Reporting — Article 19 + classification RTS

DORA — Regulation (EU) 2022/2554, Article 19 + classification RTS · European Union

DORA ICT Incident Reporting (Regulation (EU) 2022/2554, Article 19) is the EU financial-sector ICT-incident reporting regime. KYE Protocol™ governs whether an AI-assisted containment action, incident classification, or staged-report timing decision under it may proceed to a consequential incident action — under a named accountable officer's authority, with incident-evidence chain-of-custody recorded, no AI-asserted classification relied on without a pinned signal source, a signed replay-provable Evidence Pack™ per decision, and a contestability record so any decision can be reconstructed and challenged. Threat detection / SIEM-EDR runtime / forensics / remediation stays the entity's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/dora-ict-incident.html.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Named-authority on the containment / response action Enforced L3 Enforceable dora-ict-incident.containment-action-authority
Authority GateDecision replayEvidence Pack™Replay-Proof™
Incident-evidence chain-of-custody & report integrity Enforced L3 Enforceable dora-ict-incident.incident-evidence-integrity
Authority GateDecision replayEvidence Pack™Replay-Proof™
Disclosure-timing authority on the staged reporting clock Enforced L3 Enforceable dora-ict-incident.staged-report-timing-authority
Authority GateDecision replayEvidence Pack™Replay-Proof™
Threat detection, forensics & remediation engineeringThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. Out of scope L1 Mapped dora-ict-incident.threat-detection-forensics-remediation
arrow_forward KYE™ framework reference
EU 6AMLD

EU Sixth Anti-Money Laundering Directive (6AMLD) — Directive (EU) 2018/1673

Directive (EU) 2018/1673 · European Union

The EU Sixth Anti-Money Laundering Directive (Directive (EU) 2018/1673) harmonises money-laundering offences, the 22 predicate offences, aiding/abetting/inciting, and corporate liability across the EU. KYE Protocol™ governs whether an AI agent's AML action may proceed at the action boundary under a named compliance officer's authority, with due diligence before the action and replay-provable provenance. KYE Protocol™ does not run transaction-monitoring models, does not decide whether conduct is criminal money-laundering, and does not replace the institution's AML program or legal advice.

0 Enforced4 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Predicate offences & scope (Art. 2/3) Designed L2 Designed eu-6amld.predicate-offences-scope
Action Admissibility™ GateAuthority Finality™Evidence Pack™
Aiding, abetting & inciting (Art. 4) Designed L2 Designed eu-6amld.aiding-abetting-inciting
Action Admissibility™ GateEvidence Pack™Replay-Proof™
Corporate / legal-person liability (Art. 7/8) Designed L2 Designed eu-6amld.corporate-liability
Action Admissibility™ GateEvidence Pack™Replay-Proof™
Sanctions & competent-authority cooperation (Art. 9-10) Designed L2 Designed eu-6amld.competent-authority-cooperation
Action Admissibility™ GateAuthority Finality™Evidence Pack™
arrow_forward KYE™ framework reference
EU DAC

EU DAC — Directive on Administrative Cooperation (DAC6 + DAC7)

dac6-dac7 · European Union

EU Directive on Administrative Cooperation — DAC6 mandatory disclosure of reportable cross-border arrangements (hallmarks A–E, main-benefit test, 30-day window) and DAC7 platform-operator reporting. KYE Protocol™ governs whether an AI-generated arrangement / advice that may be reportable proceeds only after the hallmark / disclosure screen is recorded — the KYE Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
DAC6 hallmark screening Designed L2 Designed eu-dac.dac6-reportable-arrangement, eu-dac.dac6-main-benefit-test
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
DAC6 disclosure & reporting window Designed L2 Designed eu-dac.dac6-disclosure-window
Action Admissibility™ GateAuthority Finality™Evidence Pack™
DAC7 platform reporting Designed L2 Designed eu-dac.dac7-platform-reporting
Evidence Pack™Replay-Proof™Action Admissibility™ Gate
arrow_forward KYE™ framework reference
FATF 40 Recommendations

FATF 40 Recommendations — International Standards on Combating Money Laundering and the Financing of Terrorism & Proliferation

2012 (as amended) · International

The FATF 40 Recommendations are the global AML/CFT authority anchor — risk-based approach (R.1), customer due diligence & beneficial ownership (R.10), record-keeping (R.11), the Travel Rule (R.16), and suspicious-transaction reporting (R.20). KYE Protocol™ governs whether an AI agent's AML action may proceed at the action boundary (alert triage, sanctions screening, SAR/STR drafting, KYC/CDD) under a named compliance officer's authority, with §36 two-person sign-off on the consequential SAR/STR filing — the KYE AML & Financial-Crimes Governance Pack™. KYE Protocol™ does not run transaction-monitoring models, does not decide whether a transaction is truly money-laundering, and does not replace the institution's AML program.

5 Enforced0 Designed0 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Risk-based approach (R.1) Enforced L3 Enforceable fatf-40-recommendations.r1-risk-based-approach
Action Admissibility™ GateAuthority Finality™Evidence Pack™
Customer due diligence & beneficial ownership (R.10) Enforced L3 Enforceable fatf-40-recommendations.r10-customer-due-diligence
Action Admissibility™ GateEvidence Pack™Replay-Proof™
Record-keeping (R.11) Enforced L3 Enforceable fatf-40-recommendations.r11-record-keeping
Action Admissibility™ GateEvidence Pack™Replay-Proof™
Travel Rule — wire / virtual-asset transfers (R.16) Enforced L3 Enforceable fatf-40-recommendations.r16-travel-rule
Action Admissibility™ GateEvidence Pack™
Suspicious transaction reporting (R.20) Enforced L3 Enforceable fatf-40-recommendations.r20-suspicious-transaction-reporting
Action Admissibility™ GateAuthority Finality™Evidence Pack™
arrow_forward KYE™ framework reference
FCA COBS

FCA COBS — Conduct of Business Sourcebook (UK Investment Conduct)

FCA Handbook COBS · United Kingdom

The FCA Conduct of Business Sourcebook (COBS) governs UK investment business with clients — the client's best interests rule (COBS 2.1.1R), suitability (COBS 9), best execution (COBS 11), and recordkeeping. KYE Protocol™ governs whether an AI-assisted investment decision/action is within mandate, authorised, evidenced, and final at the action boundary — the KYE Investment Decision Authority Pack™. KYE Protocol™ does not perform the suitability assessment, judge whether a recommendation is correct, produce investment intelligence, or act as an investment adviser. Per-requirement bijection at framework-coverage-bijection.

4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Client's best interests rule (COBS 2.1.1R) Enforced L3 Enforceable fca-cobs.client-best-interests-rule
Action Admissibility™ GateAuthority Finality™Evidence Pack™
Suitability (COBS 9 / 9A) Enforced L3 Enforceable fca-cobs.suitability-cobs9
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Best execution (COBS 11.2 / 11.2A) Enforced L3 Enforceable fca-cobs.best-execution-cobs11
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Recordkeeping of advice & orders Enforced L3 Enforceable fca-cobs.recordkeeping-advice-orders
Evidence Pack™Replay-Proof™Action Admissibility™ Gate
arrow_forward KYE™ framework reference
FRC Ethical Standard

FRC Ethical Standard — Integrity, Objectivity & Independence

2024 · United Kingdom

The Financial Reporting Council's Ethical Standard — integrity, objectivity & independence, professional competence & due care, and the threats-and-safeguards framework for auditors and accountants. KYE Protocol™ governs whether an AI-generated entry / statement / conclusion may proceed under a named professional's authority, with the objectivity / independence / competence basis recorded before the action — the KYE Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0 Enforced4 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Integrity Designed L2 Designed frc-ethical-standard.integrity
Action Admissibility™ GateAuthority Finality™Evidence Pack™
Objectivity & independence Designed L2 Designed frc-ethical-standard.objectivity-independence
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Professional competence & due care Designed L2 Designed frc-ethical-standard.professional-competence
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Threats & safeguards framework Designed L2 Designed frc-ethical-standard.threats-safeguards
Action Admissibility™ GateAuthority Finality™Evidence Pack™
arrow_forward KYE™ framework reference
FSB Sound Practices

FSB Sound Practices for the Responsible Adoption of AI in Finance

consultation-2026-06 · International

The Financial Stability Board's Sound Practices for the Responsible Adoption of AI in Finance (consultation, 10 June 2026) sets supervisory expectations for how financial institutions govern AI across model risk, accountability, third-party dependency, and operational resilience. This framework is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped — no requirement has been bound to a KYE Protocol™ artefact, so coverage is honestly reported as out of scope pending deep mapping. The §70 honesty bar forbids claiming enforced/designed coverage before a requirement is bound to a cited artefact. Deep mapping will be scheduled through the §70 rail (by hand, the §59 deterministic pipeline, or the §70 framework-mapping-agent) once the final report text is pinned.

0 Enforced0 Designed1 Out of scope
1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): the framework is declared in framework-registry.json but no requirement has been bound to a KYE Protocol™ artefact yet. Coverage is reported out of scope until the deep mapping runs through the §70 rail — never inflated to imply enforcement that does not exist. Out of scope L1 Mapped FSB Sound Practices (full consultation text — not yet decomposed into requirement-level mappings)
arrow_forward KYE™ framework reference
FCA MCOB

FCA MCOB — Mortgage Conduct of Business (FCA Handbook)

FCA Handbook · United Kingdom

FCA Handbook conduct rules for regulated mortgage advice, pre-contract disclosure and responsible lending. KYE Protocol™ governs the AUTHORITY of an AI agent to take a suitability / disclosure / responsible-lending action and the EVIDENCE / replay of that action, under named accountability; KYE Protocol™ does not perform the affordability calculation, author the advice, or determine the regulatory correctness of the mortgage recommendation. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Suitability / affordability action admissibility Designed L2 Designed fca-mcob.4.7a
Purpose Permission™Authority Gate
Pre-contract disclosure evidence Designed L2 Designed fca-mcob.5.6
Evidence Pack™
Responsible-lending decision record Designed L2 Designed fca-mcob.11.6
Evidence Pack™Authority Gate
The affordability calculation itself Out of scope L1 Mapped fca-mcob.11a.affordability-calc
arrow_forward KYE™ framework reference
FCA Consumer Duty

FCA Consumer Duty (PRIN 2A) — Principle 12 & the four outcomes

PRIN 2A · United Kingdom

FCA Handbook PRIN 2A — the Consumer Duty (Principle 12 + the four outcomes). KYE Protocol™ governs the AUTHORITY of an AI agent to act toward a good retail-customer outcome, the consumer-understanding EVIDENCE, and foreseeable-harm contestability; KYE Protocol™ does not assess price-and-value, author the good-outcome judgement, or determine the firm's Consumer Duty compliance. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Act-to-deliver-good-outcomes authority gate Designed L2 Designed fca-consumer-duty.prin-2a.2
Purpose Permission™Authority Gate
Consumer-understanding evidence Designed L2 Designed fca-consumer-duty.prin-2a.6
Evidence Pack™
Foreseeable-harm contestability Designed L2 Designed fca-consumer-duty.prin-2a.5
Delegated AuditabilityEvidence Pack™
Price-and-value assessment Out of scope L1 Mapped fca-consumer-duty.prin-2a.4
arrow_forward KYE™ framework reference
Investment Mandate / IPS

Investment Mandate / IPS — Investment Policy Statement & Discretionary Mandate Authority

2026 · International

The Investment Policy Statement (IPS) / discretionary investment mandate — the authority anchor for AI-assisted investment decisions. Defines permitted investments, concentration / liquidity limits, prohibited investments, named authority / delegation, and reporting obligations. KYE Protocol™ governs whether an AI-assisted investment decision/action is within the recorded mandate, under whose authority it proceeds, evidenced, contestable, and final at the action boundary — the KYE Investment Decision Authority Pack™. KYE Protocol™ does not produce investment intelligence, judge whether a thesis is correct, or render any view on alpha / returns / suitability of outcome, and is not an investment adviser. Per-requirement bijection at framework-coverage-bijection.

0 Enforced4 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Mandate scope & permitted investments Designed L2 Designed investment-mandate-ips.mandate-scope-permitted-investments
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Constraints, limits & prohibitions Designed L2 Designed investment-mandate-ips.constraints-limits-prohibitions
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Named authority & delegation Designed L2 Designed investment-mandate-ips.named-authority-delegation
Action Admissibility™ GateAuthority Finality™Evidence Pack™
Reporting & evidence obligations Designed L2 Designed investment-mandate-ips.reporting-evidence-obligations
Evidence Pack™Replay-Proof™Action Admissibility™ Gate
arrow_forward KYE™ framework reference
Circular 230

IRS Circular 230 — Regulations Governing Practice before the IRS

2014-rev · United States

Treasury Department Circular No. 230 (31 CFR Part 10) — the standards of practice (due diligence §10.22, competence §10.35, return positions §10.34, written advice §10.37) for practitioners before the IRS. KYE Protocol™ governs whether an AI-generated tax position/filing/advice may proceed to a consequential action under a named preparer's authority — the KYE Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Due diligence & competence Designed L2 Designed irs-circular-230.10.22-due-diligence, irs-circular-230.10.35-competence
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Tax-return positions & written advice Designed L2 Designed irs-circular-230.10.34-positions, irs-circular-230.10.37-written-advice
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Practitioner authority & sign-off Designed L2 Designed irs-circular-230.preparer-signoff
Action Admissibility™ GateAuthority Finality™Evidence Pack™
arrow_forward KYE™ framework reference
ISA (UK)

ISA (UK) — International Standards on Auditing (UK)

2024 · United Kingdom

The International Standards on Auditing (UK) — professional scepticism & reasonable assurance (ISA 200), fraud responsibilities (ISA 240), risk identification & assessment (ISA 315), and forming the opinion & reporting (ISA 700). KYE Protocol™ governs whether an AI-generated audit working-paper / conclusion may proceed under a named auditor's authority, with the ISA (UK) responsibilities recorded before the action — the KYE Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0 Enforced4 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Professional scepticism & reasonable assurance (ISA 200) Designed L2 Designed isa-uk.isa200-professional-scepticism
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Fraud responsibilities (ISA 240) Designed L2 Designed isa-uk.isa240-fraud-responsibilities
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Risk identification & assessment (ISA 315) Designed L2 Designed isa-uk.isa315-risk-assessment
Evidence Pack™Replay-Proof™Action Admissibility™ Gate
Forming the opinion & reporting (ISA 700) Designed L2 Designed isa-uk.isa700-forming-opinion
Action Admissibility™ GateAuthority Finality™Evidence Pack™
arrow_forward KYE™ framework reference
MAS TRM

MAS Technology Risk Management Guidelines

Jan 2021 · Singapore

Monetary Authority of Singapore Technology Risk Management Guidelines — access control, audit logging, IT incident management, third-party risk. Per-requirement bijection at /compliance/mas-trm.html.

2 Enforced0 Designed0 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Access control + tamper-resistant audit logging Enforced L3 Enforceable MAS TRM — access control, MAS TRM — audit logging
Authority GateAuthority Revocation OrchestratorWORM audit hash-chainStreaming Logs Contract™
IT incident management + third-party riskThird-party risk enforced via Authority Register + SPoF; the MAS incident-notification delivery channel is in build. Enforced L3 Enforceable MAS TRM — incident management, MAS TRM — third-party risk
Incident DetectorReporting EngineAuthority RegisterSPoF registry
arrow_forward KYE™ framework reference
MiFID II

MiFID II — Markets in Financial Instruments Directive II (Investment Services Conduct)

Directive 2014/65/EU · European Union

MiFID II (Directive 2014/65/EU) governs the provision of investment services in the EU — acting in the client's best interest (Art. 24), suitability (Art. 25), best execution (Art. 27), and recordkeeping. KYE Protocol™ governs whether an AI-assisted investment decision/action is within mandate, authorised, evidenced, and final at the action boundary — the KYE Investment Decision Authority Pack™. KYE Protocol™ does not perform the suitability assessment, judge whether a recommendation is correct, produce investment intelligence, or act as an investment adviser. Per-requirement bijection at framework-coverage-bijection.

4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Acting in the client's best interest (Art. 24) Enforced L3 Enforceable mifid-ii.art24-best-interest
Action Admissibility™ GateAuthority Finality™Evidence Pack™
Suitability & appropriateness (Art. 25) Enforced L3 Enforceable mifid-ii.art25-suitability
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Best execution (Art. 27) Enforced L3 Enforceable mifid-ii.art27-best-execution
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Recordkeeping & basis of advice Enforced L3 Enforceable mifid-ii.recordkeeping-basis-of-advice
Evidence Pack™Replay-Proof™Action Admissibility™ Gate
arrow_forward KYE™ framework reference
Pillar Two

OECD Pillar Two — GloBE Rules (Global Minimum Tax) & BEPS

2023-globe · International

OECD/G20 Pillar Two GloBE rules — a 15% global minimum effective tax rate (IIR / UTPR) with a per-jurisdiction top-up tax reported in the GloBE Information Return (GIR). KYE Protocol™ governs whether an AI-generated Pillar Two computation may proceed to a filing or a booked liability — the KYE Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GloBE effective-tax-rate & top-up tax Designed L2 Designed oecd-pillar-two.globe-top-up-tax, oecd-pillar-two.effective-tax-rate
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
GloBE Information Return (GIR) Designed L2 Designed oecd-pillar-two.gir-information-return
Evidence Pack™Replay-Proof™Action Admissibility™ Gate
Scope & charging-rule determination Designed L2 Designed oecd-pillar-two.scope-charging-rule
Action Admissibility™ GateAuthority Finality™Evidence Pack™
arrow_forward KYE™ framework reference
OSFI B-10

OSFI Guideline B-10 — Third-Party Risk Management

Effective 1 May 2024 · Canada

OSFI Guideline B-10 — risk-based management of third-party arrangements for federally regulated financial institutions: the arrangement register, criticality-proportionate risk assessment, and ongoing monitoring + concentration risk. Per-requirement bijection at /compliance/osfi-b-10.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Third-party arrangement register Enforced L3 Enforceable register
Authority GateRisk Engine
Risk assessment by criticality Enforced L3 Enforceable risk-assessment
Risk Engine
Ongoing monitoring + concentration risk Enforced L3 Enforceable monitoring
Offline Evidence LogRisk Engine
arrow_forward KYE™ framework reference
OSFI B-13

OSFI Guideline B-13 — Technology & Cyber Risk Management

Effective 1 Jan 2024 · Canada

OSFI Guideline B-13 — technology and cyber risk management for federally regulated financial institutions: governance, technology operations + resilience, and cyber security. Per-requirement bijection at /compliance/osfi-b-13.html.

3 Enforced0 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Governance + risk management (Domain 1) Enforced L3 Enforceable d1
Authority GateRisk Engine
Technology operations + resilience (Domain 2) Enforced L3 Enforceable d2-asset-register, d2-resilience
Authority GateEdge Governance Safety FloorOffline Evidence LogRisk Engine
Cyber security — monitoring + incident (Domain 3) Enforced L3 Enforceable d3
Incident DetectorWORM audit hash-chain
arrow_forward KYE™ framework reference
OSFI E-23

OSFI Guideline E-23 — Model Risk Management

Effective 1 May 2027 · Canada

OSFI Guideline E-23 — enterprise-wide model risk management across the model lifecycle (model definition expanded to AI/ML): inventory + risk rating, independent validation, ongoing monitoring, and accountability. Per-requirement bijection at /compliance/osfi-e-23.html.

3 Enforced1 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Model inventory + risk rating Enforced L3 Enforceable inventory
Authority GateRisk Engine
Development + independent validation Designed L2 Designed validation
Replay-Proof™WORM audit hash-chain
Ongoing monitoring Enforced L3 Enforceable monitoring
Drift DetectorRisk Engine
Roles + accountability Enforced L3 Enforceable accountability
Authority Gate
arrow_forward KYE™ framework reference
PCI DSS

PCI DSS — Payment Card Industry Data Security Standard

4.0 · Global

Security standard for entities that store, process, or transmit cardholder data.

2 Enforced1 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Access control & strong authentication Enforced L3 Enforceable Req 7, Req 8
Authority GateWebAuthn step-upPurpose Permission™
Audit logging & monitoring Enforced L3 Enforceable Req 10
WORM audit hash-chainDecision replay
Stored account-data protection evidenceKYE™ governs access to account data; signed evidence of protection and a FIPS-validated crypto adapter are in build. Designed L2 Designed Req 3
Evidence Pack™ signing (COSE-Sign1)FIPS-validated crypto module
Network security, anti-malware & physical accessNetwork segmentation, TLS termination, endpoint protection, and physical access to cardholder data are operated by the customer. Out of scope L1 Mapped Req 1, Req 4, Req 5, Req 9
arrow_forward KYE™ framework reference
PCMLTFA / FINTRAC

PCMLTFA / FINTRAC — Anti-Money-Laundering & Terrorist-Financing

S.C. 2000, c. 17 · Canada

Canada's anti-money-laundering and terrorist-financing regime (PCMLTFA + Regulations, administered by FINTRAC): client identification + KYC, ongoing monitoring, suspicious-transaction reporting, and record-keeping. Per-requirement bijection at /compliance/pcmltfa-fintrac.html.

4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Client identification + KYC Enforced L3 Enforceable kyc
Authority GateDecision Map™
Ongoing monitoring Enforced L3 Enforceable monitoring
Drift DetectorRisk Engine
Suspicious transaction reporting (s.7) Enforced L3 Enforceable s7-str
Incident DetectorReporting Engine
Record-keeping (s.6) Enforced L3 Enforceable s6-records
WORM audit hash-chain
arrow_forward KYE™ framework reference
PSD2 / PSD3

PSD2 / PSD3 — EU Payment Services Directive

PSD2 2015/2366 · European Union

EU payment-services regulation covering strong customer authentication and third-party access to accounts.

2 Enforced1 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Strong customer authentication Enforced L3 Enforceable RTS Art. 4-9
WebAuthn step-upAuthority Gate
Third-party-provider access governance Enforced L3 Enforceable Art. 66-67
Purpose Permission™Directory tenant proxy
Transaction authorisation evidenceEvery transaction authorisation is recorded today; signed, third-party-verifiable transaction evidence is in build. Designed L2 Designed Art. 97
Evidence Pack™ signing (COSE-Sign1)Decision Map™ signing (JWS-detached)
Liability allocation frameworkKYE™ produces evidence relevant to liability, but the contractual allocation of liability is a legal matter. Out of scope L1 Mapped Art. 97(5)
arrow_forward KYE™ framework reference
RBNZ BS11

RBNZ BS11 — Outsourcing Policy

BS11 Outsourcing Policy · New Zealand

Reserve Bank of New Zealand outsourcing policy — control over outsourced functions, continuity of basic banking functions, continuing compliance evidence. Per-requirement bijection at /compliance/rbnz-bs11.html.

2 Enforced0 Designed0 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Outsourcing register + continuity of basic banking functions Enforced L3 Enforceable BS11 — outsourcing register, BS11 — basic banking functions
Authority RegisterSPoF registryEdge Governance Safety FloorOffline Evidence Log
Continuing compliance evidence to RBNZ Enforced L3 Enforceable BS11 — control evidence
Evidence Pack™Regulator Replay agentWORM audit hash-chain
arrow_forward KYE™ framework reference
SEC IA Fiduciary

SEC Investment Adviser Fiduciary Duty — Advisers Act of 1940 (Duty of Care & Loyalty)

Investment Advisers Act of 1940 · United States

The US Investment Advisers Act of 1940 (s.206) and the SEC's 2019 fiduciary interpretation establish a federal fiduciary duty for registered investment advisers — a duty of care, a duty of loyalty, and the books-and-records rule (204-2). KYE Protocol™ governs whether an AI-assisted investment decision/action is within mandate, authorised, evidenced, and final at the action boundary — the KYE Investment Decision Authority Pack™. KYE Protocol™ does not form the reasonable belief, judge whether advice is correct, produce investment intelligence, or act as an investment adviser. Per-requirement bijection at framework-coverage-bijection.

4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Duty of care — reasonable belief best interest Enforced L3 Enforceable sec-ia-fiduciary.duty-of-care-best-interest
Action Admissibility™ GateAuthority Finality™Evidence Pack™
Duty of loyalty — conflicts & disclosure Enforced L3 Enforceable sec-ia-fiduciary.duty-of-loyalty-conflicts
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Suitability / mandate of advice Enforced L3 Enforceable sec-ia-fiduciary.suitability-mandate-of-advice
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Books & records (Rule 204-2) Enforced L3 Enforceable sec-ia-fiduciary.books-and-records-204-2
Evidence Pack™Replay-Proof™Action Admissibility™ Gate
arrow_forward KYE™ framework reference
SOX 404

SOX §404 — Internal Control over Financial Reporting (tax provision)

2002 · United States

Sarbanes-Oxley §404 — management (and auditor) assessment of internal control over financial reporting (ICFR), with the income-tax provision a recurring material-weakness source requiring review controls, documentation, and data integrity. KYE Protocol™ governs whether an AI-generated tax-provision figure may proceed to being booked under recorded management-review controls with replay-provable provenance — the KYE Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Tax-provision ICFR design Enforced L3 Enforceable sox-404.tax-provision-icfr
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Review & approval controls Enforced L3 Enforceable sox-404.management-review-control
Action Admissibility™ GateAuthority Finality™Evidence Pack™
Documentation & data integrity Enforced L3 Enforceable sox-404.documentation-data-integrity
Evidence Pack™Replay-Proof™Action Admissibility™ Gate
Management attestation Enforced L3 Enforceable sox-404.management-attestation
Action Admissibility™ GateAuthority Finality™Evidence Pack™
arrow_forward KYE™ framework reference
FRS 102

UK GAAP — FRS 102 / FRS 105 Recognition, Measurement & Disclosure

2024 · United Kingdom

FRS 102 / FRS 105 (UK GAAP) — recognition and measurement bases, accounting-policy selection and consistency, disclosure requirements, and the micro-entity regime. KYE Protocol™ governs whether an AI-generated entry / statement may proceed with the FRS 102 / FRS 105 recognition, measurement, and disclosure basis recorded before the action — the KYE Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0 Enforced4 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Recognition & measurement Designed L2 Designed uk-gaap-frs102.frs102-recognition-measurement
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Accounting policies & consistency Designed L2 Designed uk-gaap-frs102.frs102-accounting-policies
Evidence Pack™Replay-Proof™Action Admissibility™ Gate
Disclosure requirements Designed L2 Designed uk-gaap-frs102.frs102-disclosure
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Micro-entity (FRS 105) regime Designed L2 Designed uk-gaap-frs102.frs105-micro-entity
Action Admissibility™ GateAuthority Finality™Evidence Pack™
arrow_forward KYE™ framework reference
UK MTD

UK Making Tax Digital (MTD) — Digital Record-Keeping & API Filing

2024 · United Kingdom

HMRC Making Tax Digital — digital record-keeping, unbroken digital links from source data to submitted figures, and programmatic filing via the MTD API. KYE Protocol™ governs whether an AI-generated MTD figure may proceed to an API submission under a named preparer's authority, preserving the digital link in replay-provable provenance — the KYE Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Digital record-keeping & digital links Designed L2 Designed uk-mtd.digital-record-keeping, uk-mtd.digital-links
Evidence Pack™Replay-Proof™Action Admissibility™ Gate
API filing integrity Designed L2 Designed uk-mtd.api-filing-integrity
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Preparer authority for submission Designed L2 Designed uk-mtd.preparer-authority-submission
Action Admissibility™ GateAuthority Finality™Evidence Pack™
arrow_forward KYE™ framework reference
US BSA / FinCEN

US Bank Secrecy Act / FinCEN — AML Program, CDD & SAR Requirements

31 U.S.C. 5311 et seq.; 31 CFR Chapter X · United States

The US Bank Secrecy Act (31 U.S.C. 5311 et seq.) and FinCEN regulations (31 CFR Chapter X) require a risk-based AML program (5318(h)), customer due diligence & beneficial ownership (CDD Rule), Suspicious Activity Reports (SARs), and record-keeping. KYE Protocol™ governs whether an AI agent's AML action may proceed at the action boundary under a named BSA/AML officer's authority, with §36 two-person sign-off on the consequential SAR filing. KYE Protocol™ does not run transaction-monitoring models, does not decide whether a transaction is truly suspicious, and does not replace the institution's BSA/AML program.

4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
AML program (31 U.S.C. 5318(h)) Enforced L3 Enforceable us-bsa-fincen.aml-program-5318h
Action Admissibility™ GateAuthority Finality™Evidence Pack™
Customer due diligence & beneficial ownership (CDD Rule) Enforced L3 Enforceable us-bsa-fincen.cdd-beneficial-ownership
Action Admissibility™ GateEvidence Pack™Replay-Proof™
Suspicious Activity Reporting (SAR) Enforced L3 Enforceable us-bsa-fincen.sar-filing
Action Admissibility™ GateAuthority Finality™Evidence Pack™
Record-keeping (31 CFR Chapter X) Enforced L3 Enforceable us-bsa-fincen.record-keeping
Action Admissibility™ GateEvidence Pack™Replay-Proof™
arrow_forward KYE™ framework reference
Wolfsberg Principles

Wolfsberg Group AML Principles & Guidance

current · International

The Wolfsberg Group publishes industry AML, sanctions-screening, and correspondent-banking due-diligence standards for global banks. KYE Protocol™ governs whether an AI agent's AML or sanctions-screening action may proceed at the action boundary under a named compliance officer's authority, with due diligence before the action and replay-provable provenance. KYE Protocol™ does not run the screening engine, does not decide whether a name is a true sanctions match, and does not replace the institution's AML / sanctions program.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Risk-based KYC / CDD Designed L2 Designed wolfsberg-principles.risk-based-kyc-cdd
Action Admissibility™ GateEvidence Pack™Replay-Proof™
Sanctions & transaction screening governance Designed L2 Designed wolfsberg-principles.sanctions-screening-governance
Action Admissibility™ GateAuthority Finality™Evidence Pack™
Correspondent-banking due diligence Designed L2 Designed wolfsberg-principles.correspondent-banking-due-diligence
Action Admissibility™ GateAuthority Finality™Evidence Pack™
arrow_forward KYE™ framework reference
ECB AI Supervisory Expectations

ECB Supervisory Expectations on AI-Amplified Cyber and Operational Risk

emerging-2026 · EU

ECB Banking Supervision's emerging expectations on AI-amplified cyber and operational risk for significant institutions (planned 'dear CEO letter', per Reuters 3 June 2026; part of the ECB 2026–2028 supervisory priorities). REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: no formal requirement text has been published, so coverage is honestly reported as out of scope pending deep mapping. The §70 honesty bar forbids claiming enforced/designed coverage before requirements are pinned. The substance — AI-actor authority, privileged-action gating, incident-response authority, replay-derivable evidence — is already covered by KYE Protocol™'s deep-mapped DORA artefacts and the shipped Cyber Resilience & Incident Authority Pack; deep mapping will graft those once the ECB text is final.

0 Enforced0 Designed1 Out of scope
1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no requirement bound to a KYE Protocol™ artefact yet because no formal text is published. Coverage reported out of scope until the ECB requirements are pinned and deep-mapped through the §70 rail — never inflated. The DORA / Cyber Resilience & Incident Authority Pack artefacts already answer the substance and will be grafted on publication. Out of scope L1 Mapped ECB AI supervisory expectations (forthcoming dear-CEO letter — not yet decomposed into requirement-level mappings)
arrow_forward KYE™ framework reference
SM&CR

UK Senior Managers & Certification Regime (SM&CR)

2016 (as amended) · United Kingdom

UK SM&CR accountability regime. KYE Protocol™ governs whether an AI agent's action may proceed under a named Senior Manager's delegated authority, with the responsibility line recorded and replay-provable. Consumed via kye:rule-pack:sm-cr + kye:sector-pack:uk-financial-services-sm-cr (§0: never re-mapped). Per-requirement bijection at framework-coverage-bijection.

0 Enforced2 Designed0 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
SMF responsibility + duty-of-responsibility evidence Designed L2 Designed uk-smcr.smf-responsibility, uk-smcr.duty-of-responsibility
Purpose Permission™Evidence Pack™Replay Proof™
Certification scope + contestable conduct record Designed L2 Designed uk-smcr.certification, uk-smcr.conduct-rules
Purpose Permission™Delegated Auditability
arrow_forward KYE™ framework reference
Failure to Prevent Fraud

UK Failure to Prevent Fraud (ECCTA 2023)

ECCTA 2023 (in force 1 Sep 2025) · United Kingdom

UK ECCTA 2023 corporate 'failure to prevent fraud' offence. KYE Protocol™ turns AI-actor authority into a demonstrable 'reasonable fraud-prevention procedure': AI actions that could facilitate fraud are gated by named authority, evidenced, and contestable. KYE Protocol™ proves the procedure operated; it does not adjudicate the offence. Per-requirement bijection at framework-coverage-bijection.

0 Enforced2 Designed0 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Reasonable procedures (statutory defence) + evidence Designed L2 Designed uk-eccta-ftpf.reasonable-procedures, uk-eccta-ftpf.evidence-of-procedures
Purpose Permission™Evidence Pack™Replay Proof™
Fraud risk assessment + monitoring Designed L2 Designed uk-eccta-ftpf.risk-assessment, uk-eccta-ftpf.monitoring-review
Decision Map™Delegated Auditability
arrow_forward KYE™ framework reference
UK MLR 2017

UK Money Laundering Regulations 2017 (MLR 2017)

SI 2017/692 (as amended) · United Kingdom

UK MLR 2017 AML/CTF obligations. KYE Protocol™ governs whether an AI agent's AML action may proceed under a named compliance officer's authority, with due diligence recorded and replay-provable provenance. Consumed via the aml-financial-crimes spine (§0: never re-mapped). KYE Protocol™ proves the basis; it does not decide whether conduct is money laundering. Per-requirement bijection at framework-coverage-bijection.

0 Enforced2 Designed0 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Risk assessment + customer due diligence Designed L2 Designed uk-mlr-2017.risk-assessment, uk-mlr-2017.cdd
Purpose Permission™Decision Map™
Ongoing monitoring + replay-derivable records Designed L2 Designed uk-mlr-2017.ongoing-monitoring, uk-mlr-2017.record-keeping
Delegated AuditabilityEvidence Pack™Replay Proof™
arrow_forward KYE™ framework reference
MiCA

MiCA — Markets in Crypto-Assets Regulation

Regulation (EU) 2023/1114 · European Union

EU regulation for crypto-asset issuance and crypto-asset service providers (CASPs): custody, conduct, conflicts, complaints, and the Travel Rule overlay. Titles III–IV from Jun 2024; Title V from Dec 2024.

3 Enforced1 Designed1 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Custody & administration of crypto-assets (Art. 70, 75, 76) Enforced L3 Enforceable Art. 75
MiCA custody rule packEvidence Pack™ signingAuthority Gate
CASP conduct & conflict-of-interest screening (Art. 66, 72) Enforced L3 Enforceable Art. 66, Art. 72
Purpose Permission™Decision replay
Complaints handling (Art. 71)Evidenced complaint-handling response is design-locked; a CASP complaint-intake-and-tracking runtime path is not yet wired. Designed L2 Designed Art. 71
Comms Rail (evidenced response)
Travel Rule + AML overlay for crypto-asset transfers Enforced L3 Enforceable Reg (EU) 2023/1113
Travel-Rule rule packAML financial-crimes rule pack
Token white paper, authorisation & reserve of assetsReserve of assets, prudential own-funds, white-paper notification and issuer/CASP authorisation are prudential/licensing obligations of the regulated entity and its competent authority, outside KYE's lane. Out of scope L1 Mapped Art. 16, Art. 36, Art. 54
arrow_forward KYE™ framework reference
GENIUS Act

GENIUS Act — US payment stablecoin law

GENIUS Act (Pub. L. 119-27, 2025) · United States

First US federal law governing payment stablecoins: 1:1 reserve backing, redemption at par, monthly reserve disclosure, BSA/AML obligations, lawful-order (freeze/seize/burn) capability, and marketing restrictions. Prudential rulemaking deadline July 2026.

2 Enforced1 Designed2 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Redemption at par on demand Enforced L3 Enforceable §4
Purpose Permission™Authority Gate
Monthly reserve-composition disclosure (certified)KYE produces a tamper-evident, certify-able evidence pack for the disclosure; the reserve-composition data is the issuer's and the disclosure-assembly flow is design-locked, not yet wired. Designed L2 Designed §4
Evidence Pack™ signingWORM audit hash-chain
BSA / AML program + sanctions / lawful-order capability Enforced L3 Enforceable §4
AML financial-crimes rule packAuthority GateWORM audit hash-chain
1:1 reserve backing & no-yield constraintHolding/investing the 1:1 reserve and the no-yield prohibition are balance-sheet/product obligations of the issuer, outside KYE's lane. Out of scope L1 Mapped §4
Issuer authorisation, charter & prudential supervisionFederal/state issuer authorisation, charter and prudential supervision are licensing/supervision obligations of the issuer and its regulator, outside KYE's lane. Out of scope L1 Mapped §3, §5
arrow_forward KYE™ framework reference
Singapore PS Act

Singapore Payment Services Act 2019 (PS Act)

PS Act 2019 (No. 2 of 2019), as amended · Singapore

Singapore's licensing and conduct regime for payment service providers, administered by MAS: seven regulated activities (account issuance, domestic and cross-border money transfer, merchant acquisition, e-money issuance, digital payment token services, money-changing) across three licence classes, with AML/CFT, technology-risk and user-protection conditions. This framework is REGISTERED in the §70 Framework Mapping Rail following the statute-class precedent of the DORA and PSD2/PSD3 rows; deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.

0 Enforced0 Designed1 Out of scope
1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no PS Act requirement is bound to a KYE Protocol™ artefact yet. The payment-authorization rail's authority controls are platform-level and cross-regime; PS-Act-specific deep mapping (licence-class conditions, DPT-service obligations) is scheduled through the §70 rail. Coverage is never inflated. Out of scope L1 Mapped PS Act 2019 — licensing (Part 2), conduct of business (Part 3), and AML/CFT + technology-risk licence conditions; full text not yet decomposed into requirement-level mappings
arrow_forward KYE™ framework reference
Singapore SFA

Singapore Securities and Futures Act 2001 (SFA)

SFA 2001 (2020 Revised Edition), as amended · Singapore

Singapore's capital-markets statute, administered by MAS: licensing of capital-markets services, regulation of organised markets and clearing facilities, offers of investments and prospectus requirements, market-conduct prohibitions (false trading, market rigging, insider trading), and derivatives-contract regulation. This framework is REGISTERED in the §70 Framework Mapping Rail following the statute-class precedent of the DORA and PSD2/PSD3 rows; deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.

0 Enforced0 Designed1 Out of scope
1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no SFA requirement is bound to a KYE Protocol™ artefact yet. SFA-specific deep mapping (licensing, market-conduct, disclosure obligations) is scheduled through the §70 rail. Coverage is never inflated. Out of scope L1 Mapped SFA 2001 — capital-markets services licensing, market conduct (Part 12), offers of investments (Part 13); full text not yet decomposed into requirement-level mappings
arrow_forward KYE™ framework reference
TARGET2

TARGET2 / T2 RTGS (ECB) — incl. Settlement Finality Directive 98/26/EC

ECB TARGET Guideline (EU) 2022/912 (ECB/2022/8) + Directive 98/26/EC Arts 3 & 5 · European Union

The Eurosystem's real-time gross settlement system settles payment orders in central bank money with finality conferred at the moment of entry under the Settlement Finality Directive — an entered order cannot be unwound. KYE Protocol™ governs the payment-authority dimension: every instruction (human- or AI-agent-originated) must resolve to a live, purpose-scoped mandate of an authorised user of an admitted participant, with the admissibility verdict, sealed decision context and hash-bound Evidence Pack™ complete BEFORE the finality moment, revocation biting on the very next action, and the message's authorisation lineage retained append-only over the record-keeping period. Settlement execution, legal conferral of finality and intraday liquidity/credit stay the Eurosystem's and the participant treasury's own (honest scope, §0). Per-requirement bijection at /compliance/target2-rtgs.html.

4 Enforced1 Designed2 Out of scope
7 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Participation, access criteria & authorised-user binding Enforced L3 Enforceable target2-rtgs.participation-access-authority
Purpose Permission™Authority GateDecision replayEvidence Pack™Replay-Proof™
Settlement finality & the pre-entry authority checkpoint (SFD 98/26/EC) Enforced L3 Enforceable target2-rtgs.pre-settlement-authority-checkpoint
Authority GateContext sealEvidence Pack™Replay-Proof™
Suspension, termination & revocation propagation Enforced L3 Enforceable target2-rtgs.revocation-suspension-propagation
Authority GateAuthority-drift monitoringKill-switch semantics
ISO 20022 messaging integrity & record retention Enforced L3 Enforceable target2-rtgs.message-integrity-records
Evidence Pack™WORM audit hash-chainRetention policy
Operational resilience, self-certification & incident notificationKYE supplies the machine-generated attestation cadence and sealed incident evidence the self-certification and notification duties run on; the participant's BCM programme, endpoint security and the submissions themselves are participant-owned and not claimed as enforced. Designed L2 Designed target2-rtgs.operational-resilience-incident
≤90-day attestationEvidence Pack™
Settlement execution & legal conferral of finalitySettlement in central bank money and the SFD's legal conferral of finality/irrevocability are performed and owned by the Eurosystem as system operator — KYE™ is an AI-authority and evidence layer, not a settlement engine or designated system. Out of scope L1 Mapped target2-rtgs.settlement-finality-execution
Liquidity provision & intraday creditFunding MCAs/DCAs, collateralised intraday credit and liquidity reservations are treasury and central-bank functions — KYE™ is not a liquidity-management or collateral engine. Out of scope L1 Mapped target2-rtgs.liquidity-intraday-credit
arrow_forward KYE™ framework reference
CIPS

CIPS — Cross-Border Interbank Payment System (RMB)

CIPS participant and business rules — direct/indirect participation, ISO 20022 messaging, RTGS + hybrid netting · China

CIPS clears and settles cross-border RMB payments for direct participants (settling on CIPS accounts) and indirect participants routed through sponsoring direct participants, over ISO 20022-based messaging with RTGS and hybrid-netting settlement. KYE Protocol™ governs the payment-authority dimension only: participant mandate binding at the moment of action, the pre-settlement authority checkpoint (verdict + sealed evidence before the instruction is released), message-authorisation lineage retained append-only, and the authority + evidence layer of the participant's OWN financial-crime screening decision under the laws applicable to that participant — KYE takes no position on any jurisdiction's sanctions regime and provides nothing that weakens or routes around a screening obligation. Settlement execution, netting sessions and liquidity funding stay the operator's and participants' own (honest scope, §0). Per-requirement bijection at /compliance/cips-cross-border.html.

3 Enforced2 Designed1 Out of scope
6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Participation & authorised-user binding Enforced L3 Enforceable cips-cross-border.participant-authority
Purpose Permission™Authority GateDecision replayEvidence Pack™Replay-Proof™
Pre-settlement authority checkpoint & irrevocability Enforced L3 Enforceable cips-cross-border.pre-settlement-authority-checkpoint
Authority GateContext sealEvidence Pack™Replay-Proof™
ISO 20022 messaging integrity & record retention Enforced L3 Enforceable cips-cross-border.message-integrity-records
Evidence Pack™WORM audit hash-chainRetention policy
Financial-crime screening authority & evidenceScope-guarded: KYE governs the authority and evidence layer of the participant's own screening decision under the AML/CTF and sanctions laws applicable to that participant. Screening adjudication itself — list management, matching, disposition — is the participant's / their vendor's own and is not claimed. Designed L2 Designed cips-cross-border.financial-crime-screening-authority
Named-authority bindingScreening tool-call evidenceDecision replay
Operational resilience & incident reportingKYE supplies sealed incident evidence and the attestation cadence; availability engineering, contingency arrangements and the incident report to the operator are participant-owned and not claimed as enforced. Designed L2 Designed cips-cross-border.operational-resilience-incident
≤90-day attestationEvidence Pack™
Settlement execution & liquidity provisionClearing and settling RMB payments across CIPS accounts, netting sessions and liquidity funding are owned by the system operator and participant treasuries — KYE™ is an AI-authority and evidence layer, not a clearing, settlement or liquidity engine. Out of scope L1 Mapped cips-cross-border.settlement-execution-liquidity
arrow_forward KYE™ framework reference
UK Faster Payments

UK Faster Payments (FPS)

UK Faster Payment System rules (Pay.UK) + PSR mandatory APP-scam reimbursement for Faster Payments (October 2024) · United Kingdom

Faster Payments processes UK retail payments in near real time — an accepted payment is irrevocable, so there is no recall window to correct an unauthorised agent action. KYE Protocol™ governs the payment-authority dimension: participant and sponsor/aggregator mandate binding at the moment of action, the pre-submission authority checkpoint (verdict + sealed evidence before release), message-authorisation lineage retained append-only over the record-keeping period, and the replay-verifiable authorisation evidence trail an APP-scam reimbursement investigation turns on (who or what authorised, under which mandate, with which fraud-assessment tool-calls). Scheme processing, settlement at the Bank of England, prefunding/net-sender-cap management and the reimbursement adjudication itself stay the scheme's, the Bank's and the PSPs' own (honest scope, §0). Per-requirement bijection at /compliance/uk-fps.html.

3 Enforced2 Designed2 Out of scope
7 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Participation, access criteria & authorised-user binding Enforced L3 Enforceable uk-fps.participant-access-authority
Purpose Permission™Authority GateDecision replayEvidence Pack™Replay-Proof™
Irrevocability & the pre-submission authority checkpoint Enforced L3 Enforceable uk-fps.pre-submission-authority-checkpoint
Authority GateContext sealEvidence Pack™Replay-Proof™
Messaging integrity & record retention Enforced L3 Enforceable uk-fps.message-integrity-records
Evidence Pack™WORM audit hash-chainRetention policy
APP-fraud reimbursement & authorisation evidenceKYE supplies the replay-verifiable record of the authorising principal, mandate, purpose scope and fraud-assessment tool-calls a claim investigation needs; the reimbursement adjudication (gross-negligence assessment, 50:50 split, claim payment) is owned by the PSPs, Pay.UK and the PSR and is not claimed as enforced. Designed L2 Designed uk-fps.app-fraud-reimbursement-evidence
Decision replayEvidence Pack™WORM audit hash-chain
Operational resilience & incident reportingKYE supplies sealed incident evidence and the attestation cadence; availability engineering, contingency arrangements and the notifications themselves are participant-owned and not claimed as enforced. Designed L2 Designed uk-fps.operational-resilience-incident
≤90-day attestationEvidence Pack™
Scheme processing & settlement executionCentral-infrastructure processing, deferred multilateral net settlement at the Bank of England, and the conferral of irrevocability on accepted payments are owned by Pay.UK, the infrastructure provider and the Bank — KYE™ is an AI-authority and evidence layer, not a payment processor. Out of scope L1 Mapped uk-fps.scheme-processing-settlement
Liquidity provision & net sender capsPrefunding the settlement account, sizing/managing the net sender cap and intraday liquidity monitoring are participant treasury functions — KYE™ is not a liquidity-management engine. Out of scope L1 Mapped uk-fps.liquidity-net-sender-caps
arrow_forward KYE™ framework reference
SAFR

SAFR — Safeguards for Agentic Finance at Runtime

SAFR v1.0 (July 2026) · Global (industry reference; MAS Project MindForge lineage)

SAFR is an industry reference framework (BuildFin.AI) for a runtime governance layer over agentic AI in financial services: four components (Agent Identity, Controls Repository, Disposition Engine, Audit Log) exchanging a Governance Envelope, sitting after model guardrails and before execution. KYE Protocol™ maps to SAFR component-for-component at the moment-of-action admissibility check and adds Authority Finality™ — a Replay-Proof™ record verifiable from public keys alone. KYE governs whether the agentic financial action was allowed to become final; the rails execute if and only if approved.

6 Enforced2 Designed0 Out of scope
8 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Runtime governance at the point of action (pre-execution + per-step) Enforced L3 Enforceable safr.pre-execution-governance, safr.per-step-independent-authority
Purpose Permission™Decision Engineper-action admissibility
Agent Identity — verified registered principal (SAFR component 1) Designed L3 Enforceable safr.agent-identity-verification, safr.authoritative-registry-resolution
§0.30 agent-as-principal§52 authority bindingentity hierarchy
Controls Repository & capability-based mandate (SAFR component 2) Enforced L3 Enforceable safr.controls-repository, safr.mandate-capability-authority
Rules Gateway™§52 authority claimDecision Map™
Deterministic disposition — four outcomes, risk-calibrated (SAFR component 3) Designed L3 Enforceable safr.deterministic-disposition, safr.four-outcome-disposition, safr.risk-calibrated-outcome
Decision EngineDecision Map™risk signals
Governance Envelope authenticated to origin Enforced L3 Enforceable safr.governance-envelope-authenticated
Evidence Pack™tool-call pincontext seal
Immutable, tamper-evident audit log (SAFR component 4) Enforced L3 Enforceable safr.immutable-audit-log
§30 WORMReplay-Proof™Authority Finality™
Substantive human escalation (bounded, timeout, real authority) Enforced L3 Enforceable safr.substantive-human-escalation
GovernedUI™ approval modestimeout→block/senior§9 no self-grant
Native + gateway integration and decision-not-settlement boundary Enforced L3 Enforceable safr.native-and-gateway-integration, safr.decision-not-settlement-boundary
PEP (native + gateway)§0.33 Authority Finality™ category
arrow_forward KYE™ framework reference
AAOIFI SS

AAOIFI Shariah Standards

AAOIFI Shariah Standards (as at 2023 compilation) · International

AAOIFI's suite of Shariah Standards on Islamic-finance contracts and instruments — the substantive fiqh rulings adopted by many regulators and institutions.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Standards (substantive contract rulings) Designed L2 Designed AAOIFI SS
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped AAOIFI SS
arrow_forward KYE™ framework reference
AAOIFI GSIFI

AAOIFI Governance Standards (GSIFI)

AAOIFI Governance Standards for Islamic Financial Institutions (GSIFI) · International

AAOIFI's governance standards defining the Shariah supervisory board, review, audit, and governance-committee arrangements for Islamic financial institutions.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Governance Standards (GSIFI) Designed L2 Designed AAOIFI GSIFI
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped AAOIFI GSIFI
arrow_forward KYE™ framework reference
AAOIFI FAS

AAOIFI Financial Accounting Standards (FAS)

AAOIFI Financial Accounting Standards (FAS) · International

AAOIFI's accounting standards for the recognition, measurement and disclosure of Islamic-finance contracts.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Financial Accounting Standards (FAS) Designed L2 Designed AAOIFI FAS
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped AAOIFI FAS
arrow_forward KYE™ framework reference
AAOIFI ASIFI

AAOIFI Auditing Standards (ASIFI)

AAOIFI Auditing Standards for Islamic Financial Institutions (ASIFI) · International

AAOIFI's auditing standards for external and Shariah-compliance audit of Islamic financial institutions.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Auditing Standards (ASIFI) Designed L2 Designed AAOIFI ASIFI
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped AAOIFI ASIFI
arrow_forward KYE™ framework reference
IFSB-10

IFSB-10 — Guiding Principles on Shari'ah Governance Systems

IFSB-10 (2009) · International

IFSB-10 sets guiding principles for the Shariah governance system: competence, independence, confidentiality and consistency of the Shariah board, plus review and audit functions.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance System (IFSB-10 guiding principles) Designed L2 Designed IFSB-10
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped IFSB-10
arrow_forward KYE™ framework reference
IFSB

IFSB Prudential Standards (suite)

IFSB prudential standards suite · International

The IFSB's prudential and disclosure standards for institutions offering Islamic financial services, including corporate governance, core principles, and market-discipline disclosures.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Prudential & governance standards (IFSB suite) Designed L2 Designed IFSB
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped IFSB
arrow_forward KYE™ framework reference
IIFM

IIFM Documentation Standards

IIFM documentation standards · International

IIFM's standardised master agreements and documentation for Islamic hedging, treasury, interbank and sukuk transactions.

1 Enforced0 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Documentation & contract standards (IIFM) Enforced L3 Enforceable IIFM
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped IIFM
arrow_forward KYE™ framework reference
BNM SGF 2019

Bank Negara Malaysia — Shariah Governance Policy Document 2019

BNM/RH/PD 028-100 (2019) · Malaysia

BNM's Shariah Governance Policy Document (2019) sets board oversight, Shariah committee, and Shariah risk/review/audit/research control functions, operating under the binding rulings of BNM's Shariah Advisory Council (SAC).

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (BNM SGF 2019 + SAC/IFSA 2013) Designed L2 Designed BNM SGF 2019
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped BNM SGF 2019
arrow_forward KYE™ framework reference
CBUAE HSA

CBUAE — Higher Shariah Authority and Shariah Governance Standard

CBUAE Shariah Governance Standard (2020) · United Arab Emirates

The CBUAE requires each Islamic financial institution to maintain an Internal Shariah Supervision Committee and Shariah control functions, operating under the binding resolutions of the CBUAE Higher Shariah Authority (HSA).

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (CBUAE HSA Standard) Designed L2 Designed CBUAE HSA
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped CBUAE HSA
arrow_forward KYE™ framework reference
CBB SG Module

Central Bank of Bahrain — Shariah Governance Module

CBB Rulebook — Shariah Governance Module · Bahrain

The CBB Shariah Governance Module mandates AAOIFI standards, an independent Shariah supervisory board, internal Shariah audit and review, and (from 2020) a centralised Shariah board.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (CBB Module) Designed L2 Designed CBB SG Module
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped CBB SG Module
arrow_forward KYE™ framework reference
SAMA SGF

Saudi Central Bank — Shariah Governance Framework

SAMA Shariah Governance Framework (2020) · Saudi Arabia

SAMA's Shariah Governance Framework requires local banks to establish an independent Shariah committee, a Shariah division, and Shariah review and audit functions.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (SAMA Framework) Designed L2 Designed SAMA SGF
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped SAMA SGF
arrow_forward KYE™ framework reference
OJK / DSN-MUI

OJK / DSN-MUI — Indonesian Shariah Governance

OJK Shariah governance regulations + DSN-MUI fatawa · Indonesia

Indonesia operates a two-tier model: DSN-MUI issues national fatawa binding on Islamic financial institutions, while OJK regulates the institution-level Dewan Pengawas Syariah (Shariah Supervisory Board) and compliance functions.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (OJK + DSN-MUI) Designed L2 Designed OJK / DSN-MUI
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped OJK / DSN-MUI
arrow_forward KYE™ framework reference
SBP SGF

State Bank of Pakistan — Shariah Governance Framework

SBP Shariah Governance Framework (2018) · Pakistan

SBP's Shariah Governance Framework mandates a board Shariah committee, a resident Shariah board member, a Shariah compliance department, and internal and external Shariah audit, under the SBP Shariah Advisory Committee's rulings.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (SBP Framework) Designed L2 Designed SBP SGF
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped SBP SGF
arrow_forward KYE™ framework reference
QCB

Qatar Central Bank — Shariah Supervision and Governance

QCB Islamic banking instructions · Qatar

QCB and the QFCRA require Islamic financial institutions to maintain a Shariah supervisory board and Shariah review/audit functions, with broad reference to AAOIFI standards.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (QCB / QFCRA) Designed L2 Designed QCB
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped QCB
arrow_forward KYE™ framework reference
CBK

Central Bank of Kuwait — Shariah Supervisory Governance

CBK Shariah supervisory governance instructions · Kuwait

The CBK requires Islamic banks to maintain an independent Shariah supervisory board and Shariah audit, coordinated with a higher committee for Shariah supervision at the CBK.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (CBK) Designed L2 Designed CBK
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped CBK
arrow_forward KYE™ framework reference
CBO IBRF

Central Bank of Oman — Islamic Banking Regulatory Framework (IBRF)

CBO Islamic Banking Regulatory Framework (2012) · Oman

Oman's IBRF mandates a Shariah Supervisory Board, an internal Shariah reviewer, and Shariah audit for Islamic banks and windows, referencing AAOIFI standards.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (CBO IBRF) Designed L2 Designed CBO IBRF
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped CBO IBRF
arrow_forward KYE™ framework reference
TKBB

TKBB — Participation Banking Standards (Türkiye)

TKBB participation-banking standards + BDDK regulation · Türkiye

In Türkiye, participation (Islamic) banks are supervised by BDDK; the TKBB Central Advisory Board issues participation-banking standards, and each bank maintains an advisory committee.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Participation Banking Governance (TKBB) Designed L2 Designed TKBB
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped TKBB
arrow_forward KYE™ framework reference
CBN NIFI

Central Bank of Nigeria — Non-Interest (Islamic) Financial Institutions

CBN guidelines for non-interest financial institutions · Nigeria

The CBN regulates Non-Interest (Islamic) Financial Institutions; a central Financial Regulation Advisory Council of Experts (FRACE) advises the CBN, and each institution maintains an Advisory Committee of Experts (ACE).

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (CBN NIFI + FRACE) Designed L2 Designed CBN NIFI
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped CBN NIFI
arrow_forward KYE™ framework reference
FCA SSB model

UK FCA — Firm-Level Shariah Supervisory Board Model

FCA/PRA firm-level governance (no separate Shariah regime) · uk

The UK has no separate statutory Shariah regime; Islamic financial institutions operate under the standard FCA/PRA perimeter and appoint their own firm-level Shariah supervisory boards, typically applying AAOIFI standards.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Firm-Level Shariah Governance (UK FCA model) Designed L2 Designed FCA SSB model
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped FCA SSB model
arrow_forward KYE™ framework reference
Brunei SFSB

Brunei — Syariah Financial Supervisory Board and BDCB

Syariah Financial Supervisory Board Order + BDCB regulation · Brunei Darussalam

Brunei's Syariah Financial Supervisory Board (SFSB) is the highest authority on Islamic finance matters; BDCB regulates institution-level Syariah advisory bodies.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (Brunei SFSB) Designed L2 Designed Brunei SFSB
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped Brunei SFSB
arrow_forward KYE™ framework reference
CBJ Islamic

Central Bank of Jordan — Islamic Banking Shariah Governance

CBJ Islamic banking instructions · Jordan

The CBJ regulates Islamic banks under the Banking Law and dedicated instructions requiring a Shariah supervisory board and Shariah audit.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (CBJ) Designed L2 Designed CBJ Islamic
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped CBJ Islamic
arrow_forward KYE™ framework reference
Egypt FRA

Egypt FRA — Islamic Finance Shariah Supervision

FRA Islamic finance regulations (sukuk, takaful) · Egypt

Egypt's FRA regulates non-banking Islamic finance (sukuk, takaful) with a central Shariah supervisory committee; the CBE oversees Islamic banking.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (Egypt FRA) Designed L2 Designed Egypt FRA
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped Egypt FRA
arrow_forward KYE™ framework reference
Sudan HSSB

Central Bank of Sudan — High Shariah Supervisory Board

CBOS High Shariah Supervisory Board framework · Sudan

Sudan operates a fully Islamic banking system; the High Shariah Supervisory Board (HSSB) at the CBOS issues binding rulings, and each bank maintains a Shariah supervisory body.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (Sudan HSSB) Designed L2 Designed Sudan HSSB
Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). Out of scope L1 Mapped Sudan HSSB
arrow_forward KYE™ framework reference
RBI IT Governance MD

RBI IT Governance Master Direction

Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices · India

KYE governs the AUTHORITY + EVIDENCE layer where AI agents take consequential action inside a regulated entity's operations. KYE is OUT-OF-SCOPE for board-level IT governance structures, the entity's information-security programme, business-continuity capability and internal-audit function — those are the regulated entity's own, and RBI supervises them directly (§70 §4). Deep per-requirement mapping: 6 requirements, 2 enforced by KYE runtime, 4 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.

1 Enforced0 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority + evidence at the action boundary — enforced by KYE runtime and verified by CI Enforced L3 Enforceable rbi-master-direction-it.AGENT-ACTION-AUTHORITY — Consequential actions by automated systems resolve to a live delegated authority, rbi-master-direction-it.AUDIT-TRAIL — Tamper-evident audit trail over privileged and consequential operations
kye.compliance.attestation.v1kye.evidence.decision_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context_seal.v1internal
Obligations owed directly by the regulated entity — NOT discharged by KYEKYE governs the AUTHORITY + EVIDENCE layer where AI agents take consequential action inside a regulated entity's operations. KYE is OUT-OF-SCOPE for board-level IT governance structures, the entity's information-security programme, business-continuity capability and internal-audit function — those are the regulated entity's own, and RBI supervises them directly (§70 §4). Out of scope L1 Mapped rbi-master-direction-it.IT-GOVERNANCE-STRUCTURE — Board-level IT strategy committee and defined governance structure, rbi-master-direction-it.INFOSEC-PROGRAMME — Information-security policy, controls and periodic assessment, rbi-master-direction-it.BUSINESS-CONTINUITY — Business continuity and disaster-recovery capability with periodic testing, rbi-master-direction-it.IT-ASSURANCE — Independent assurance and internal audit over IT controls
arrow_forward KYE™ framework reference

Healthcare AI — UK regulatory + clinical research

Frameworks specifically governing AI agents in clinical environments and UK medical-device regulation. Per-requirement bijection maps available at /compliance/<framework>.html.

PMDA SaMD

PMDA Software-as-a-Medical-Device (SaMD) Pathway

PMD Act SaMD pathway + PMDA review framework · Japan

The Pharmaceuticals and Medical Devices Agency's Software-as-a-Medical-Device review pathway under the PMD Act, including the SaMD two-step (DASH) approval scheme and AI/ML change-control expectations. KYE Protocol™ evidences the QMS, clinical-evaluation provenance, change-control, post-market surveillance and human-oversight obligations that bind an AI-supported clinical action; device classification and marketing approval remain the manufacturer's submission. Per-requirement bijection at /compliance/pmda-samd.html.

2 Enforced1 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
QMS evidence & clinical-evaluation provenance Enforced L3 Enforceable PMDA SaMD QMS evidence, PMDA SaMD clinical evaluation
WORM audit hash-chainEvidence Pack™Data Classification Engine
Change control, versioning & human oversight of clinical decisions Enforced L3 Enforceable PMDA SaMD change control, PMDA SaMD human oversight
Conformance RunnerDrift DetectorGovernedUI™Authority Resolution™
Post-market surveillance & incident reporting to the PMDAKYE™ assembles the PMDA adverse-event notification package; the regulator-side delivery channel to the PMDA is designed pending the per-jurisdiction reporting connector. Designed L1 Mapped PMDA SaMD post-market surveillance
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
CLIA

CLIA — Clinical Laboratory Improvement Amendments (42 CFR Part 493)

42 CFR 493 · US

The Clinical Laboratory Improvement Amendments (42 CFR Part 493) set US federal quality standards for testing on human specimens. KYE Protocol™ enforces the test-report integrity and electronic-record audit-trail slices, and governs the authority of AI-supported result generation — testing, proficiency testing and competency stay the laboratory's quality system. Per-requirement bijection at /compliance/clia.html.

3 Enforced1 Designed1 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Test records & result-report integrity (Subpart J, 493.1291) Enforced L3 Enforceable clia.493.1291-report-integrity
Decision replayEvidence Pack™
Audit trail for electronic test records Enforced L3 Enforceable clia.audit-trail
WORM audit hash-chain
Test-record retention (493.1105) Designed L2 Designed clia.493.1105-record-retention
WORM audit hash-chain
Authority & oversight of AI-supported result generation (Subpart M) Enforced L3 Enforceable clia.493.1445-ai-oversight
Purpose Permission™Authority Gate
Analytic-system QC, validation, proficiency testing & competency (Subparts K, H, M)Analytic-system quality control, method validation, proficiency testing and personnel competency are the laboratory's own quality and HR functions — out of scope for an AI-authority-governance protocol. Out of scope L1 Mapped clia.493-subpart-k-analytic-systems, clia.493-pt-competency
arrow_forward KYE™ framework reference
HAARF v1.0

HAARF — Healthcare AI Agents Regulatory Framework

v1.0 (2026) · Global

Comprehensive security and governance standard for autonomous AI agents in clinical environments — 279 requirements across 8 categories.

1 Enforced0 Designed0 Out of scope
1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
279 requirements across 8 categories — risk lifecycle, model passport, cybersecurity, human oversight, agent registration, autonomy governance, bias/equity, tool integration Enforced L3 Enforceable HAARF C1–C8
Decision EngineEvidence EngineGovernedUI approvalEdge Governance modesShadow ModeAgent Tool Pack™
arrow_forward KYE™ framework reference
ISO 15189

ISO 15189:2022 — Medical laboratories: quality and competence

2022 · International

ISO 15189:2022 sets quality and competence requirements for medical laboratories, including patient-safety risk management. KYE Protocol™ enforces the §7.4-7.6 report-integrity, §7.6/§8.4 data-integrity and audit-trail slices where a medical laboratory uses AI-supported decisioning — examination procedures and competence stay the laboratory's quality system. Per-requirement bijection at /compliance/iso-15189.html.

5 Enforced0 Designed1 Out of scope
6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Reporting of results & integrity of the report (7.4-7.6) Enforced L3 Enforceable iso-15189.7.4-report-integrity
Decision replayEvidence Pack™
Control of records & audit trail (8.4) Enforced L3 Enforceable iso-15189.8.4-record-control
WORM audit hash-chain
Information management & data integrity (7.6, 8.4) Enforced L3 Enforceable iso-15189.7.6-data-integrity
Decision replayEvidence Pack™
Impartiality & authorised decision-making (5.1, 6.2) Enforced L3 Enforceable iso-15189.5.1-impartiality-authority
Purpose Permission™Authority Gate
Risk management & patient-safety evidence (8.5) Enforced L3 Enforceable iso-15189.8.5-risk-patient-safety
Resilience Loop™
Examination processes & technical competence (6, 7.3)Validation of examination procedures, reference intervals, equipment/reagents and technical competence are the medical laboratory's own quality system — out of scope for an AI-authority-governance protocol. Out of scope L1 Mapped iso-15189.6-examination-competence
arrow_forward KYE™ framework reference
MHRA MDR 2002

UK Medical Devices Regulations 2002

2002 as amended through 2024 · United Kingdom

UK Statutory Instrument 2002/618 — risk classes, conformity assessment, essential requirements (Annex I regs 7-12), Annex IX classification rules, and post-market vigilance (regs 44-47). 53 requirements.

1 Enforced0 Designed0 Out of scope
1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
53 requirements across risk classes + conformity assessment + essential requirements + classification rules + post-market vigilance Enforced L3 Enforceable SI 2002/618
Profile classificationSector packSigned evidence packTrust-domain UDI
arrow_forward KYE™ framework reference
MHRA PMS 2025

MHRA Post-Market Surveillance Regulations 2025

SI 2024/1368 (effective June 2025) · United Kingdom

Explicit post-market surveillance obligations: PMS plan (Reg 7), post-market clinical follow-up (Reg 8), incident reporting timelines (2/10/15-day), Periodic Safety Update Reports (PSURs), trend reporting. 36 requirements.

1 Enforced0 Designed0 Out of scope
1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
36 requirements across PMS plan, PMCF, incident timelines, PSURs, and trend reporting Enforced L3 Enforceable SI 2024/1368
Resilience-loop registryComms-rail templatesAnalytics-plane eventsGovernedUI two-person sign-off
arrow_forward KYE™ framework reference
MHRA SaMD & AI

MHRA Software and AI as a Medical Device Change Program

2023 Change Program · United Kingdom

41 requirements: 15 original work-packages + 7 PCCP (Predetermined Change Control Plan) obligations + 9 change-class triggers (capability / model_params / training-data / bias drift) + 6 transparency obligations + 4 oversight/bias-mitigation controls.

1 Enforced0 Designed0 Out of scope
1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
41 requirements across SaMD lifecycle, PCCP, change-class triggers, transparency, and oversight Enforced L3 Enforceable MHRA SaMD Program 2023
Canonical change-controlReplay-Proof™ envelopeDecision Map™Evidence Pack™Shadow ModeEdge Governance bundle versioning
arrow_forward KYE™ framework reference
PHIPA Ontario

PHIPA (Ontario) — Personal Health Information Protection Act, 2004

S.O. 2004, c. 3, Sched. A · Canada

Ontario's health-privacy statute (PHIPA, 2004): consent + lawful purpose, circle-of-care implied consent, data minimisation, the electronic audit-log duty, access/correction, and IPC breach notification for personal health information. Per-requirement bijection at /compliance/phipa-ontario.html.

5 Enforced0 Designed0 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Consent + lawful purpose (ss.29-30, 36-38) Enforced L3 Enforceable s29, s38
Authority GateDecision Map™Purpose Permission™
Data minimisation (s.30(2)) Enforced L3 Enforceable s30-2
Purpose Permission™
Electronic audit log + access control (s.10.1, s.12, O.Reg.329/04 s.6.3) Enforced L3 Enforceable s10.1
WORM audit hash-chain
Access + correction (ss.52-55) Enforced L3 Enforceable s52
Reporting EngineWORM audit hash-chain
Breach + IPC notification (s.12(2)-(3)) Enforced L3 Enforceable s12-2
Incident DetectorReporting Engine
arrow_forward KYE™ framework reference
CDSCO MDR 2017

CDSCO Medical Devices Rules 2017

Medical Devices Rules, 2017, as amended · India

Where AI software qualifies as a medical device, KYE governs the AUTHORITY + EVIDENCE layer of clinical actions the software takes or recommends. KYE is OUT-OF-SCOPE for device classification, licensing, manufacturing quality systems and the clinical determination itself — those belong to the manufacturer and CDSCO (§70 §4). Deep per-requirement mapping: 5 requirements, 2 enforced by KYE runtime, 3 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.

1 Enforced0 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority + evidence at the action boundary — enforced by KYE runtime and verified by CI Enforced L3 Enforceable cdsco-medical-devices.CLINICAL-ACTION-AUTHORITY — Clinical actions by software resolve to a live authority and are evidenced, cdsco-medical-devices.POST-MARKET-EVIDENCE — Records supporting post-market surveillance and adverse-event review
kye.compliance.attestation.v1kye.evidence.decision_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context_seal.v1internal
Obligations owed directly by the regulated entity — NOT discharged by KYEWhere AI software qualifies as a medical device, KYE governs the AUTHORITY + EVIDENCE layer of clinical actions the software takes or recommends. KYE is OUT-OF-SCOPE for device classification, licensing, manufacturing quality systems and the clinical determination itself — those belong to the manufacturer and CDSCO (§70 §4). Out of scope L1 Mapped cdsco-medical-devices.DEVICE-CLASSIFICATION — Risk-based classification of the device, cdsco-medical-devices.LICENSING — Manufacturing or import licence obtained and maintained, cdsco-medical-devices.QMS — Quality management system for design and manufacture
arrow_forward KYE™ framework reference

Sectoral frameworks

Domain-specific AI accountability frameworks scoped to a single regulated sector.

API 580/581

API 580 / API 581 — Risk-Based Inspection for fixed equipment

2016 · Global

API RP 580 (RBI methodology) + API 581 (RBI quantitative technology) for fixed-equipment inspection planning. KYE Protocol™ governs the authority and evidence of an AI-recommended inspect/repair/replace action and records the inspection-interval + failure-mode reference vocabulary; KYE Protocol™ does not compute RBI risk. Per-requirement bijection at framework-coverage-bijection.

0 Enforced2 Designed0 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
RBI decision documentation + review (contestable) Designed L2 Designed api-580.10.0
Evidence Pack™Authority Gate
High-consequence action named-engineer sign-off Designed L2 Designed api-581.5.0
Authority GateDecision Map™
arrow_forward KYE™ framework reference
Australia Group

Australia Group — Biological & Chemical Dual-Use Export Controls

2023 · Global

Australia Group dual-use export-control regime — harmonised control lists for dual-use biological agents, toxins, equipment, and chemical-weapon precursors. KYE Protocol™ governs whether an AI-generated design mapping to a controlled item may proceed to a consequential action — the KYE AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Dual-use biological control list Designed L2 Designed australia-group.bio-agents, australia-group.bio-equipment
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Dual-use chemical precursor list Designed L2 Designed australia-group.chem-precursors
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Controlled-item action gating Designed L2 Designed australia-group.controlled-item-gate
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
arrow_forward KYE™ framework reference
BCBS 239

BCBS 239 — Risk Data Aggregation & Risk Reporting Principles

BCBS 239 (Principles for effective risk data aggregation and risk reporting, January 2013) · International

BCBS 239 sets the Basel Committee's 14 principles for effective risk data aggregation and risk reporting. KYE Protocol™ governs whether a model-driven output or risk report under it may proceed to a consequential action — only a currently-validated model used within its approved scope, model changes as named-authority decisions with evidence, every consequential decision pinned to model_id + version + validation reference, and every risk report bound to its data-lineage evidence chain, sealed into a signed replay-provable Evidence Pack™. The quantitative model build / validation mathematics / capital computation / portfolio composition stays the bank's own work (honest scope, §0 — not investment advice). All 14 principles are mapped one row each (honest tri-state). Per-requirement bijection at /compliance/bcbs-239.html.

3 Enforced0 Designed3 Out of scope
6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Risk-data governance & named authority on the report (P1) Enforced L3 Enforceable bcbs-239.principle1-governance
Authority GateDecision replayEvidence Pack™Replay-Proof™
Risk-data aggregation lineage, completeness & adaptability (P3 / P4 / P6) Enforced L3 Enforceable bcbs-239.principle3-accuracy-integrity-lineage, bcbs-239.principle4-completeness, bcbs-239.principle6-adaptability
Authority GateDecision replayEvidence Pack™Replay-Proof™
Risk-report traceability, cadence & distribution evidence (P7 / P10 / P11) Enforced L3 Enforceable bcbs-239.principle7-reporting-accuracy, bcbs-239.principle10-frequency, bcbs-239.principle11-distribution
Authority GateDecision replayEvidence Pack™Replay-Proof™
Bank data architecture & crisis-timeliness capability (P2 / P5)The data architecture, IT infrastructure, and crisis-timeliness aggregation capability are the bank's own data and technology estate — KYE™ is an AI-authority and evidence layer, not a data platform. Out of scope L1 Mapped bcbs-239.principle2-data-architecture, bcbs-239.principle5-timeliness
Report substance — comprehensiveness & clarity (P8 / P9)Judging material-risk coverage and the report's editorial quality is the bank's risk and reporting functions' own work — KYE™ proves what the report aggregated and how, not whether it covered everything that mattered. Out of scope L1 Mapped bcbs-239.principle8-comprehensiveness, bcbs-239.principle9-clarity-usefulness
Supervisory review, remedial tools & home/host cooperation (P12–P14)Principles 12–14 are addressed to supervisors — conducting the review, applying supervisory measures, and home/host cooperation are regulator functions; KYE™'s sealed evidence chains support the bank's side of the review but the obligations sit outside an AI-authority-governance protocol. Out of scope L1 Mapped bcbs-239.principle12-supervisory-review, bcbs-239.principle13-remedial-actions, bcbs-239.principle14-home-host-cooperation
arrow_forward KYE™ framework reference
Colorado SB21-169

Colorado SB21-169 — Insurers' Use of External Consumer Data & AI

Colorado SB21-169 (Restrict Insurers' Use of External Consumer Data; C.R.S. §10-3-1104.9) + Division of Insurance regulations · United States

Colorado SB21-169 restricts insurers' use of external consumer data, algorithms, and predictive models to prevent unfair discrimination, and requires testing, documentation, and consumer adverse-action reasons. KYE Protocol™ governs whether an AI-assisted underwriting or claims decision relying on external data may proceed to a consequential adverse action — under a named authority, with a recorded adverse-action reason-code, with proxy-discrimination / fairness-evidence captured, a signed replay-provable Evidence Pack™ per decision, and an appeal / contestability record. The external-data selection / pricing / methodology design on the merits stays the insurer's own work (honest scope, §0). Per-requirement bijection at /compliance/colorado-sb21-169.html.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Adverse-action reason explainability to the consumer Enforced L3 Enforceable colorado-sb21-169.adverse-action-explainability
Authority GateDecision replayEvidence Pack™Replay-Proof™
External-data proxy-discrimination evidence Enforced L3 Enforceable colorado-sb21-169.external-data-discrimination-evidence
Authority GateDecision replayEvidence Pack™Replay-Proof™
Named-authority on the external-data-driven decision Enforced L3 Enforceable colorado-sb21-169.external-data-decision-authority
Authority GateDecision replayEvidence Pack™Replay-Proof™
External data source selection & pricing on the meritsThe external-data selection / pricing / methodology design on the merits is the insurer's own work — KYE™ is an AI-authority and evidence layer, not a pricing or data-selection engine. Out of scope L1 Mapped colorado-sb21-169.external-data-source-selection-pricing
arrow_forward KYE™ framework reference
COSHH

COSHH — Control of Substances Hazardous to Health Regulations 2002 (UK)

2002 · United Kingdom

UK COSHH 2002 (SI 2002/2677), HSE-enforced. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved COSHH assessments and control instructions — the KYE HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
COSHH assessment authored under safety floor Designed L2 Designed coshh.reg-6
Purpose Permission™Edge Governance Safety Floor
Exposure-control measure advisory pending sign-off Designed L2 Designed coshh.reg-7
Authority GateDecision Map™
Control-measure instruction contestable + evidenced Designed L2 Designed coshh.reg-8
Evidence Pack™Authority Gate
arrow_forward KYE™ framework reference
CWC / BWC

CWC + BWC — Chemical & Biological Weapons Conventions

1997-2024 · Global

Chemical Weapons Convention (CWC, Schedules 1/2/3) + Biological Weapons Convention (BWC, prohibited bio/toxin agents). KYE Protocol™ governs whether an AI-generated molecule or agent mapping to a scheduled/prohibited item may proceed to a consequential action — a hard stop routed to oversight, the KYE AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
CWC scheduled chemicals (Schedule 1/2/3) Designed L2 Designed cwc-bwc.cwc-schedule1, cwc-bwc.cwc-schedule2-3
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
BWC prohibited biological / toxin agents Designed L2 Designed cwc-bwc.bwc-prohibited-agents
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Prohibited-agent action stop Designed L2 Designed cwc-bwc.prohibited-agent-stop
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
arrow_forward KYE™ framework reference
DoD 5015.2

DoD 5015.02-STD — Records Management Application Design Criteria (RMA spine)

2007 · United States

DoD 5015.02-STD records-management-application spine for the KYE Chain of Authority™ for Iron Mountain InSight DXP. KYE Protocol™ overlays the action-boundary access-control + named-authority + governance-decision audit (enforced); the RMA record-declaration / file-plan / disposition criteria are out-of-scope (owned by the records-manager). §0: KYE Protocol™ retains PROOF-OF-GOVERNANCE, not the customer's records.

2 Enforced0 Designed2 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Access-control decision at the action boundary (authority overlay) Enforced L3 Enforceable dod-5015-2.access-control-action-decision, dod-5015-2.named-authority-binding
Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Audit of the action decision (authority overlay) Enforced L3 Enforceable dod-5015-2.action-decision-audit
Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Record declaration & categorisation / file plan (RMA criteria) Out of scope L1 Mapped dod-5015-2.record-declaration-file-plan
Disposition & transfer (RMA criteria) Out of scope L1 Mapped dod-5015-2.disposition-transfer
arrow_forward KYE™ framework reference
Dodd-Frank §922

Dodd-Frank §922 + SEC Rule 21F — Whistleblower Programme

Dodd-Frank Act §922 (15 U.S.C. §78u-6) + SEC Rules 21F (whistleblower programme) · United States

Dodd-Frank §922 + SEC Rule 21F — Whistleblower Programme is the US SEC whistleblower programme (confidentiality, anti-retaliation, the Rule 21F-17 anti-impediment prohibition). KYE Protocol™ governs whether an AI-assisted access to a whistleblower's identity or a consequential case action may proceed — on a recorded need-to-know authority, with confidentiality evidence captured, a signed Evidence Pack™, and a contestability record. Assessing the securities-law tip on its merits, awarding the bounty, and adjudicating the §922 / Rule 21F claim stay with the SEC and counsel (honest scope, §0). Per-requirement bijection at /compliance/dodd-frank-whistleblower.html.

2 Enforced0 Designed1 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Confidentiality & anti-impediment evidence for a whistleblower's identity Enforced L3 Enforceable dodd-frank-whistleblower.confidentiality-evidence
Authority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & reconstruction of the handling / retaliation determination Enforced L3 Enforceable dodd-frank-whistleblower.handling-contestability-reconstruction
Authority GateDecision replayEvidence Pack™Replay-Proof™
Securities-law merits, bounty award & Rule 21F adjudicationAssessing the tip, awarding the bounty, and adjudicating the §922 / Rule 21F claim is the SEC's and counsel's determination — KYE™ is an AI-authority and evidence layer, not an enforcement engine. Out of scope L1 Mapped dodd-frank-whistleblower.securities-merits-and-award
arrow_forward KYE™ framework reference
EU AI Act insurance

EU AI Act — Annex III High-Risk Insurance

Regulation (EU) 2024/1689 (EU AI Act) — Annex III high-risk insurance use-cases (life & health risk assessment / pricing) · European Union

The EU AI Act classifies AI used for risk assessment and pricing in life and health insurance as high-risk (Annex III), triggering human-oversight (Art. 14), record-keeping (Art. 12), and transparency obligations. KYE Protocol™ governs whether an AI-assisted insurance decision in scope may proceed to a consequential adverse action — under a named human-oversight authority, with a recorded adverse-action reason-code, fairness-evidence captured, a signed replay-provable Evidence Pack™ (the Art. 12 log) per decision, and an appeal / contestability record. The risk pricing / system build / conformity assessment on the merits stays the provider's own work (honest scope, §0). Per-requirement bijection at /compliance/eu-ai-act-insurance.html.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Human oversight authority over the high-risk decision (Art. 14) Enforced L3 Enforceable eu-ai-act-insurance.annex3-human-oversight
Authority GateDecision replayEvidence Pack™Replay-Proof™
Record-keeping / logging of the AI decision (Art. 12) Enforced L3 Enforceable eu-ai-act-insurance.annex3-record-keeping-logging
Authority GateDecision replayEvidence Pack™Replay-Proof™
Transparency & contestability of the decision Enforced L3 Enforceable eu-ai-act-insurance.annex3-transparency-contestability
Authority GateDecision replayEvidence Pack™Replay-Proof™
Risk pricing, system build & conformity assessment on the meritsThe risk pricing / high-risk system build / Art. 43 conformity assessment on the merits is the provider's own work — KYE™ is an AI-authority and evidence layer at the action boundary, not a system-build, pricing, or conformity-assessment engine. Out of scope L1 Mapped eu-ai-act-insurance.risk-pricing-system-build-conformity
arrow_forward KYE™ framework reference
EU Evidence Reg

EU Evidence Regulation 2020/1783 + eIDAS — Evidence Authenticity & Transmission

Regulation (EU) 2020/1783 (taking of evidence in civil/commercial matters) + eIDAS Regulation (EU) 910/2014 (electronic evidence integrity) · European Union

EU Evidence Regulation 2020/1783 + eIDAS — Evidence Authenticity & Transmission is the EU cross-border evidence and electronic-integrity framework (Regulation 2020/1783 + eIDAS). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/eu-evidence-regulation.html.

2 Enforced0 Designed1 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Chain-of-custody & integrity for cross-border evidence transmission Enforced L3 Enforceable eu-evidence-regulation.evidence-authenticity-transmission
Authority GateDecision replayEvidence Pack™Replay-Proof™
Integrity-bound, contestable Evidence Pack™ (eIDAS-aligned) Enforced L3 Enforceable eu-evidence-regulation.eidas-integrity-evidence-pack
Authority GateDecision replayEvidence Pack™Replay-Proof™
Member-State admissibility & substantive evidential assessmentThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. Out of scope L1 Mapped eu-evidence-regulation.member-state-admissibility
arrow_forward KYE™ framework reference
EU Whistleblower Dir.

EU Whistleblower Directive — Directive (EU) 2019/1937

Directive (EU) 2019/1937 (protection of persons who report breaches of Union law) · European Union

EU Whistleblower Directive — Directive (EU) 2019/1937 is the EU whistleblower-protection framework (confidentiality, acknowledgement / feedback clocks, prohibition of retaliation). KYE Protocol™ governs whether an AI-assisted intake-triage decision, an access to a reporter's identity / PII, a case disposition (close / escalate), or an adverse action on a reporter may proceed to a consequential action — under a named handler's authority, on a recorded need-to-know basis, with confidentiality and retaliation-risk evidence captured, a signed replay-provable Evidence Pack™ per consequential action, and a contestability record so any disposition can be reconstructed and challenged. The substantive investigation / allegation merits / remediation decision stays the organisation's own work (honest scope, §0). Per-requirement bijection at /compliance/eu-whistleblower-directive.html.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Confidentiality & need-to-know access to a reporter's identity Enforced L3 Enforceable eu-whistleblower-directive.confidentiality-need-to-know-access
Authority GateDecision replayEvidence Pack™Replay-Proof™
Named-authority on the case disposition (acknowledgement / feedback clocks) Enforced L3 Enforceable eu-whistleblower-directive.case-disposition-named-authority
Authority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & reconstruction of the handling Enforced L3 Enforceable eu-whistleblower-directive.handling-contestability-reconstruction
Authority GateDecision replayEvidence Pack™Replay-Proof™
Substantive investigation & whether the breach occurredInvestigating the report on its merits and deciding the remediation is the organisation's own ethics / legal work — KYE™ is an AI-authority and evidence layer, not an investigation or adjudication engine. Out of scope L1 Mapped eu-whistleblower-directive.substantive-investigation
arrow_forward KYE™ framework reference
Fed SR 11-7

Fed SR 11-7 — Supervisory Guidance on Model Risk Management

SR 11-7 / OCC 2011-12 (Supervisory Guidance on Model Risk Management, April 2011) · United States

Fed SR 11-7 / OCC 2011-12 is the US supervisory guidance on model risk management (development, validation, governance). KYE Protocol™ governs whether a model-driven output or risk report under it may proceed to a consequential action — only a currently-validated model used within its approved scope, model changes as named-authority decisions with evidence, every consequential decision pinned to model_id + version + validation reference, and every risk report bound to its data-lineage evidence chain, sealed into a signed replay-provable Evidence Pack™. The quantitative model build / validation mathematics / capital computation / portfolio composition stays the bank's own work (honest scope, §0 — not investment advice). Per-requirement bijection at /compliance/fed-sr-11-7.html.

4 Enforced0 Designed1 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Validated-model use authority at the decision boundary Enforced L3 Enforceable fed-sr-11-7.model-use-named-authority
Authority GateDecision replayEvidence Pack™Replay-Proof™
Model change control as a named-authority decision Enforced L3 Enforceable fed-sr-11-7.model-change-control
Authority GateDecision replayEvidence Pack™Replay-Proof™
Decision traceability to model version & validation reference Enforced L3 Enforceable fed-sr-11-7.decision-provenance-traceability
Authority GateDecision replayEvidence Pack™Replay-Proof™
Model inventory & policy controls on model use Enforced L3 Enforceable fed-sr-11-7.inventory-policy-controls
Authority GateDecision replayEvidence Pack™Replay-Proof™
Quantitative model development, validation & capital mathematicsThe quantitative model build, validation mathematics, and capital & liquidity computation are the bank's own quantitative work — KYE™ is an AI-authority and evidence layer, not a model-validation or capital-calculation engine. Out of scope L1 Mapped fed-sr-11-7.quantitative-development-validation
arrow_forward KYE™ framework reference
OCC AI Supervision

OCC AI Supervisory Expectations — Model Risk · Third-Party Risk · New-Activity / Filing Readiness

2024 · United States

The U.S. Office of the Comptroller of the Currency (OCC) supervises national banks and federal savings associations. Its supervisory expectations for a bank deploying consequential AI draw on OCC Bulletin 2011-12 (model risk management, joint with Fed SR 11-7), OCC Bulletin 2013-29 + the 2023 Interagency Third-Party Risk Management Guidance, OCC heightened standards for risk governance, and the OCC's new-activity / examiner-engagement expectations. KYE Protocol™ governs the action-boundary subset at runtime — only a consequential AI action under its approved use and recorded authority proceeds, out-of-scope actions escalate or are refused, and every action that proceeds is replay-provable to an OCC examiner from public keys alone. KYE operationalises the OCC's expectations — it does NOT replace them (§0.25 integrate-not-compete). Honest scope: KYE does NOT run the bank's MRM program, validate models, make the bank's regulatory filing, or judge whether the AI's output is correct; that work, and the OCC's own supervisory determinations, stay out of scope. Broader, separate spine from the fed-sr-11-7 MRM-only row (references SR 11-7 lineage, does not duplicate it). Per-requirement bijection at /compliance/occ-ai-supervision.html.

4 Enforced0 Designed1 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Model risk management (approved-use authority + model-change as a named-authority decision) Enforced L3 Enforceable occ-ai-supervision.validated-use-authority-at-the-decision-boundary, occ-ai-supervision.model-change-as-named-authority-decision
Purpose Permission™Authority GatewayGovernedUI™ named-authority sign-offEvidence Pack™
Third-party / vendor AI risk (external authority register + escalation before finality)KYE governs what external/vendor AI is authorised to DO inside the bank's action boundary; vendor due-diligence and contract review on the merits stay the bank's own (honest scope). Enforced L3 Enforceable occ-ai-supervision.third-party-ai-authority-register, occ-ai-supervision.out-of-scope-escalation-before-finality
Authority RegisterAuthority Gateway (REQUIRE_APPROVAL)Edge Governance Safety FloorGovernedUI™ escalation
New-activity / filing & examiner readiness (replay-provable Evidence Packs + action-authority inventory)KYE proves to an OCC examiner how each consequential AI action was governed; making the regulatory filing and the OCC's supervisory determinations stay out of scope (honest scope). Enforced L3 Enforceable occ-ai-supervision.new-activity-examiner-replayable-evidence, occ-ai-supervision.action-authority-inventory
Evidence Pack™Replay-Proof™WORM audit hash-chainEntity & Principal Registry
Heightened-standards governance & accountability (named accountability at the action boundary)KYE binds and proves named accountability at the boundary; staffing and running the bank's three-lines-of-defence operating model stays the bank's own (honest scope). Enforced L3 Enforceable occ-ai-supervision.heightened-standards-named-accountability
GovernedUI™ named-authority sign-offDelegated Auditability RailAuthority Finality™
Model development, validation & supervisory determinationsDeveloping and validating the model, running the bank's MRM program, making the regulatory filing, and the OCC's own supervisory determinations / examination ratings are the bank's and the regulator's own work — KYE™ is an AI-authority and evidence layer, not a model-validation engine, a filing service, or a supervisor. Out of scope L1 Mapped occ-ai-supervision.model-development-validation-supervisory-determinations
arrow_forward KYE™ framework reference
FRCP e-discovery

FRCP e-Discovery — Rules 26 / 34 / 37 + FRE 502 (privilege)

FRCP (2015 e-discovery amendments; Rules 26 / 34 / 37 + FRE 502) · United States

FRCP e-Discovery — Rules 26 / 34 / 37 + FRE 502 (privilege) is the US federal e-discovery and privilege framework (FRCP 26 / 34 / 37 + FRE 502). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/frcp-ediscovery.html.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Named-authority on the privilege / discovery determination Enforced L3 Enforceable frcp-ediscovery.rule26g-discovery-certification
Authority GateDecision replayEvidence Pack™Replay-Proof™
Discovery chain-of-custody for produced / withheld ESI Enforced L3 Enforceable frcp-ediscovery.rule34-esi-chain-of-custody
Authority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & sanctions-reconstruction of the determination Enforced L3 Enforceable frcp-ediscovery.rule37-sanctions-reconstruction
Authority GateDecision replayEvidence Pack™Replay-Proof™
Substantive privilege judgment & attorney certification on the meritsThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. Out of scope L1 Mapped frcp-ediscovery.substantive-privilege-judgment
arrow_forward KYE™ framework reference
FRE 901/902

FRE 901 / 902 — Authentication & Self-Authentication of Evidence

FRE 901 / 902 (Authentication & Self-Authentication; 2017 ESI amendments) · United States

FRE 901 / 902 — Authentication & Self-Authentication of Evidence is the US evidence-authentication framework (FRE 901 / 902). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/fre-authentication.html.

2 Enforced0 Designed1 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
No-hallucinated-citation provenance pin for AI assertions Enforced L3 Enforceable fre-authentication.rule901-authentication-evidence
Authority GateDecision replayEvidence Pack™Replay-Proof™
Hash-bound self-authenticating Evidence Pack™ Enforced L3 Enforceable fre-authentication.rule902-self-authenticating-record
Authority GateDecision replayEvidence Pack™Replay-Proof™
Substantive admissibility, relevance & weight of the evidenceThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. Out of scope L1 Mapped fre-authentication.substantive-admissibility
arrow_forward KYE™ framework reference
ABA Model Rules

ABA Model Rules of Professional Conduct (AI-relevant duties)

Rules 1.1 / 1.4 / 1.5 / 1.6 / 5.1 / 5.3 + ABA Formal Opinion 512 (2023) · United States

The ABA Model Rules of Professional Conduct set the US legal profession's core duties — competence (Rule 1.1, incl. technological competence), communication (1.4), reasonable fees (1.5), confidentiality (1.6), and supervision of subordinate lawyers and non-lawyer assistance (5.1 & 5.3) — extended to generative AI by ABA Formal Opinion 512 (2023) and state-bar guidance (California 2023, NYSBA 2024). KYE Protocol™ governs whether an AI-assisted legal action supporting each duty may proceed to a consequential step — under a named lawyer's authority, with the verification, confidentiality-isolation, communication and supervisory-accountability record captured as a signed, replay-provable Evidence Pack™ that predates the incident. Each AI-relevant duty is mapped onto the existing KYE Legal Pack™ (kye:sector-pack:legal) workflows at the requirement level and marked designed (authority boundary bound, no runtime engine wired yet), except the reasonable-fees duty (Rule 1.5), which has no KYE artefact governing legal billing and is honestly out of scope. KYE governs the AUTHORITY BOUNDARY of the AI action — NOT wholesale compliance with a professional-conduct duty, and NOT the practice of law: it does not draft, advise, judge attorney conduct, or render the lawyer's professional judgment. Per-requirement bijection at /compliance/aba-model-rules.html.

0 Enforced5 Designed1 Out of scope
6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Competence — verified AI work product authority (Rule 1.1) Designed L2 Designed aba-model-rules.rule-1-1-competence
Purpose Permission™Authority GateEvidence Pack™
Client communication release authority (Rule 1.4) Designed L2 Designed aba-model-rules.rule-1-4-communication
Purpose Permission™Evidence Pack™
Confidentiality & client-information isolation (Rule 1.6) Designed L2 Designed aba-model-rules.rule-1-6-confidentiality
Authority GateZero Contamination
Supervisory responsibility & firm AI-governance record (Rules 5.1 & 5.3) Designed L2 Designed aba-model-rules.rule-5-1-5-3-supervision
Delegated AuditabilityGovernedUI™Evidence Pack™
Generative-AI use authority boundary (Formal Opinion 512) Designed L2 Designed aba-model-rules.formal-opinion-512-genai
Purpose Permission™Evidence Pack™GovernedUI™
Reasonable fees (Rule 1.5)No KYE artefact governs legal billing or fee reasonableness — the firm's own regulated determination. Honest out-of-scope (§0); coverage never inflated. Out of scope L1 Mapped aba-model-rules.rule-1-5-fees
arrow_forward KYE™ framework reference
GDPR Whistleblowing

GDPR (Whistleblowing) — Special-Category & Data-Minimisation in Reports

Regulation (EU) 2016/679 (GDPR) — whistleblowing data-protection slice (Art. 5, 6, 9, 15, 21) · European Union

GDPR (Whistleblowing) — Special-Category & Data-Minimisation in Reports is the data-protection slice of whistleblowing (data minimisation, special-category restriction, need-to-know access, data-subject access / objection). KYE Protocol™ governs whether an AI-assisted access to the personal / special-category data in a report may proceed — on a recorded need-to-know authority, with data-minimisation evidence captured, a signed Evidence Pack™, and a contestability record so a data-subject access or objection can be reconstructed. The lawful-basis assessment of the underlying processing, the DPIA, and data-subject adjudication stay with the controller / DPO / supervisory authority (honest scope, §0). Per-requirement bijection at /compliance/gdpr-whistleblower.html.

2 Enforced0 Designed1 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Need-to-know access & data-minimisation evidence for special-category report data Enforced L3 Enforceable gdpr-whistleblower.special-category-need-to-know-access
Authority GateDecision replayEvidence Pack™Replay-Proof™
Data-subject contestability (access / objection) reconstruction Enforced L3 Enforceable gdpr-whistleblower.data-subject-contestability
Authority GateDecision replayEvidence Pack™Replay-Proof™
Lawful-basis assessment, DPIA & data-subject adjudicationThe lawful-basis assessment, the DPIA, and data-subject adjudication is the controller's / DPO's / supervisory authority's determination — KYE™ is an AI-authority and evidence layer, not a data-protection-compliance engine. Out of scope L1 Mapped gdpr-whistleblower.lawful-basis-and-dpia
arrow_forward KYE™ framework reference
ICH Q1

ICH Q1 — Stability Testing

ICH Q1A(R2) (2003) · International

ICH Q1 — Stability Testing is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q1.html.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority over an AI stability summary at the action boundary Designed L2 Designed ich-q1.named-authority
Purpose Permission™Authority Gate
Stability study science & shelf-life determinationThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. Out of scope L1 Mapped ich-q1.science
arrow_forward KYE™ framework reference
ICH Q10

ICH Q10 — Pharmaceutical Quality System

ICH Q10 (2008) · International

ICH Q10 — Pharmaceutical Quality System is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q10.html.

3 Enforced1 Designed1 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Management responsibility & named-authority Enforced L3 Enforceable ich-q10.management-responsibility-authority
Authority GateDecision replayEvidence Pack™
Change-management authority at the action boundary Enforced L3 Enforceable ich-q10.change-management-authority
Authority GateDecision replayEvidence Pack™
Management review control (sign-off gate) Enforced L3 Enforceable ich-q10.management-review-control
Authority GateDecision replayEvidence Pack™
Personnel competence recorded before the action Designed L2 Designed ich-q10.personnel-competence
Purpose Permission™Authority Gate
Quality-system substance (CAPA / change science)The scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. Out of scope L1 Mapped ich-q10.quality-system-substance
arrow_forward KYE™ framework reference
ICH Q2

ICH Q2(R2) — Validation of Analytical Procedures

ICH Q2(R2) (2023) · International

ICH Q2(R2) — Validation of Analytical Procedures is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q2.html.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Validation-package authority at the action boundary Enforced L3 Enforceable ich-q2.validation-package-authority
Authority GateDecision replayEvidence Pack™
Validation-conclusion justification recorded before the action Enforced L3 Enforceable ich-q2.validation-conclusion-justification
Authority GateDecision replayEvidence Pack™
Replay-provable validation-package provenance Enforced L3 Enforceable ich-q2.validation-package-provenance
Authority GateDecision replayEvidence Pack™
Analytical-method science & validation statisticsThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. Out of scope L1 Mapped ich-q2.analytical-method-science
arrow_forward KYE™ framework reference
ICH Q3

ICH Q3 — Impurities

ICH Q3 family · International

ICH Q3 — Impurities is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q3.html.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority over an AI impurity-assessment summary at the action boundary Designed L2 Designed ich-q3.named-authority
Purpose Permission™Authority Gate
Impurity science & threshold determinationThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. Out of scope L1 Mapped ich-q3.science
arrow_forward KYE™ framework reference
ICH Q5

ICH Q5 — Quality of Biotechnological Products

ICH Q5 family · International

ICH Q5 — Quality of Biotechnological Products is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q5.html.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority over an AI biotech-quality summary at the action boundary Designed L2 Designed ich-q5.named-authority
Purpose Permission™Authority Gate
Biotech product science (viral safety / comparability / stability)The scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. Out of scope L1 Mapped ich-q5.science
arrow_forward KYE™ framework reference
ICH Q6

ICH Q6 — Specifications

ICH Q6 family · International

ICH Q6 — Specifications is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q6.html.

0 Enforced1 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority over an AI specification-justification summary at the action boundary Designed L2 Designed ich-q6.named-authority
Purpose Permission™Authority Gate
Specification science & acceptance-criteria settingThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. Out of scope L1 Mapped ich-q6.science
arrow_forward KYE™ framework reference
ICH Q7

ICH Q7 — GMP for Active Pharmaceutical Ingredients

ICH Q7 (2000) · International

ICH Q7 — GMP for Active Pharmaceutical Ingredients is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q7.html.

4 Enforced0 Designed1 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Quality-Unit release authority at the action boundary Enforced L3 Enforceable ich-q7.quality-unit-batch-release
Authority GateDecision replayEvidence Pack™
Records & data integrity (ALCOA+) screened before the action Enforced L3 Enforceable ich-q7.data-integrity-alcoa
Authority GateDecision replayEvidence Pack™
Replay-provable GMP-record provenance Enforced L3 Enforceable ich-q7.gmp-record-provenance
Authority GateDecision replayEvidence Pack™
Batch release sign-off gate (§36 two-person) Enforced L3 Enforceable ich-q7.batch-release-signoff
Authority GateDecision replayEvidence Pack™
Physical API manufacture & analytical testingThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. Out of scope L1 Mapped ich-q7.physical-api-manufacture
arrow_forward KYE™ framework reference
ICH Q8

ICH Q8(R2) — Pharmaceutical Development

ICH Q8(R2) (2009) · International

ICH Q8(R2) — Pharmaceutical Development is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q8.html.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Development-content authority at the action boundary Enforced L3 Enforceable ich-q8.development-justification-provenance
Authority GateDecision replayEvidence Pack™
Development justification recorded before the action Enforced L3 Enforceable ich-q8.justification-recorded-before-action
Authority GateDecision replayEvidence Pack™
Replay-provable development-content provenance Enforced L3 Enforceable ich-q8.development-content-provenance
Authority GateDecision replayEvidence Pack™
Development science (QbD / design space / control strategy)The scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. Out of scope L1 Mapped ich-q8.development-science
arrow_forward KYE™ framework reference
ICH Q9

ICH Q9(R1) — Quality Risk Management

ICH Q9(R1) (2023) · International

ICH Q9(R1) — Quality Risk Management is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q9.html.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Risk-based decision authority at the action boundary Enforced L3 Enforceable ich-q9.qrm-decision-authority
Authority GateDecision replayEvidence Pack™
Risk-decision justification recorded before the action Enforced L3 Enforceable ich-q9.risk-decision-justification
Authority GateDecision replayEvidence Pack™
Replay-provable QRM provenance Enforced L3 Enforceable ich-q9.qrm-provenance
Authority GateDecision replayEvidence Pack™
Risk-assessment science & control-strategy selectionThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. Out of scope L1 Mapped ich-q9.risk-assessment-science
arrow_forward KYE™ framework reference
IEC 61508

IEC 61508:2010 — Functional safety of E/E/PE safety-related systems

2010 · Global

The umbrella functional-safety standard defining Safety Integrity Levels (SIL 1-4) and the safety lifecycle. KYE Protocol™ governs the authority, evidence and finality of an AI-recommended physical-safety action against a SIL-validated model-authority claim; KYE Protocol™ does not perform the SIL determination. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
SIL-validated model authority + safety floor Designed L2 Designed iec-61508.part-1.7.6
Purpose Permission™Edge Governance Safety Floor
Functional-safety decision evidence + named accountability Designed L2 Designed iec-61508.part-1.7.14
Evidence Pack™Reporting Engine
Contestable verification outcomes Designed L2 Designed iec-61508.part-3.7.9
Evidence Pack™Authority Gate
arrow_forward KYE™ framework reference
IEC 61511

IEC 61511:2016 — Safety instrumented systems for the process industry

2016 · Global

The process-sector application of IEC 61508 defining safety instrumented systems (SIS). KYE Protocol™ governs the authority and finality of an AI-recommended physical-safety action (turbine trip, unit shutdown, derate) under the safety floor. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
SIS actuating decision under safety floor Designed L2 Designed iec-61511.clause-11.3
Purpose Permission™Edge Governance Safety Floor
Operation & maintenance named accountability Designed L2 Designed iec-61511.clause-16.2
Authority GateDecision Map™
Contestable / reviewable SIS decisions Designed L2 Designed iec-61511.clause-11.9
Evidence Pack™Authority Gate
arrow_forward KYE™ framework reference
ISO 21448

ISO 21448:2022 — Safety Of The Intended Functionality (SOTIF)

2022 · Global

The companion to ISO 26262 governing the residual risk of a fault-free intended function (e.g. an ADAS / autonomous perception or decision function) operating at the edge of, or outside, its specified operating envelope. KYE Protocol™ governs the authority, the operating-envelope (control / safety-floor) admissibility, the evidence and the finality of an AI-recommended action against a declared intended-functionality envelope, with Replay-Proof™ failure-path reconstruction; KYE Protocol™ does not perform the SOTIF hazard analysis, triggering-condition identification, or the model's internal failure-mechanism analysis. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Operating-envelope (control / safety-floor) action admissibility Designed L2 Designed iso-21448.clause-6
Purpose Permission™Edge Governance Safety Floor
Replay-derivable intended-functionality decision evidence Designed L2 Designed iso-21448.clause-10
Evidence Pack™Reporting Engine
Named accountability + contestable outcomes Designed L2 Designed iso-21448.clause-11
Authority GateEvidence Pack™
arrow_forward KYE™ framework reference
Law Society Protocol

Law Society Conveyancing Protocol

Conveyancing Protocol · United Kingdom

The Law Society of England & Wales — Conveyancing Protocol. KYE Protocol™ governs the AUTHORITY of an AI agent to take or finalise a protocol step, the client-due-diligence / source-of-funds EVIDENCE boundary (binding the deep-mapped uk-mlr-2017 store, not re-mapping it), and the replay-derivable transaction file; KYE Protocol™ does not perform the searches, draft the enquiries, or determine the legal correctness of the conveyance. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Protocol-step authority / finality on AI-assisted steps Designed L2 Designed law-society-conveyancing-protocol.step-authority
Purpose Permission™Authority Gate
Client due diligence + source-of-funds evidence Designed L2 Designed law-society-conveyancing-protocol.cdd-source-of-funds
Evidence Pack™
Replay-derivable transaction file Designed L2 Designed law-society-conveyancing-protocol.replay-file
Evidence Pack™Replay-Proof™
Legal correctness of searches / enquiries Out of scope L1 Mapped law-society-conveyancing-protocol.searches-enquiries-correctness
arrow_forward KYE™ framework reference
CLC Code

CLC Code of Conduct — Council for Licensed Conveyancers

Code of Conduct · United Kingdom

Council for Licensed Conveyancers (CLC) — Code of Conduct. KYE Protocol™ governs the AUTHORITY of an AI agent to act in the client's interest, named-accountable conveyancer sign-off, the confidentiality / isolation boundary, and the EVIDENCE boundary around client-money handling; KYE Protocol™ does not reconcile the client account, hold money, or determine CLC compliance. Per-requirement bijection at framework-coverage-bijection.

0 Enforced4 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Act-in-client-best-interest authority Designed L2 Designed clc-code-of-conduct.client-best-interest
Purpose Permission™Authority Gate
Named accountable conveyancer sign-off Designed L2 Designed clc-code-of-conduct.named-conveyancer-signoff
Delegated Auditability
Confidentiality and isolation of client matters Designed L2 Designed clc-code-of-conduct.confidentiality
Authority Gate
Client-money handling evidence boundary Designed L2 Designed clc-code-of-conduct.client-money
Evidence Pack™
arrow_forward KYE™ framework reference
HM Land Registry

HM Land Registry — Registration & Digital Identity Standard (Safe Harbour)

Registration & Digital Identity Standard · United Kingdom

HM Land Registry — registration requirements and the Digital Identity Standard (Safe Harbour). KYE Protocol™ governs the AUTHORITY of an AI agent to take a digital-identity-verification or application-submission action and the Safe Harbour EVIDENCE / replay boundary; KYE Protocol™ does not perform the identity-check determination, run the verification technology, or determine HMLR registration correctness. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Digital-identity verification action admissibility (Safe Harbour) Designed L2 Designed hm-land-registry.digital-identity-admissibility
Purpose Permission™Evidence Pack™
Application-submission authority Designed L2 Designed hm-land-registry.application-submission-authority
Authority Gate
Replay-derivable submission record Designed L2 Designed hm-land-registry.replay-submission-record
Evidence Pack™Replay-Proof™
The conveyancer's identity-check determination Out of scope L1 Mapped hm-land-registry.identity-check-determination
arrow_forward KYE™ framework reference
Homes England CFG

Homes England Capital Funding Guide — Shared Ownership (model lease)

Capital Funding Guide — Shared Ownership · United Kingdom

Homes England — Capital Funding Guide (Shared Ownership + model lease). KYE Protocol™ governs the AUTHORITY of an AI agent to take a shared-ownership eligibility-decision action, the affordability / sustainability EVIDENCE boundary, and named-accountable sign-off / contestability; KYE Protocol™ does not make the eligibility determination, run the affordability assessment, or judge model-lease compliance. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shared-ownership eligibility-decision authority Designed L2 Designed homes-england-cfg.eligibility-authority
Purpose Permission™Authority Gate
Affordability / sustainability evidence Designed L2 Designed homes-england-cfg.affordability-sustainability-evidence
Evidence Pack™
Named-accountable sign-off and contestability Designed L2 Designed homes-england-cfg.named-signoff-contestable
Delegated Auditability
Model-lease compliance determination Out of scope L1 Mapped homes-england-cfg.model-lease-compliance
arrow_forward KYE™ framework reference
ISO 14001

ISO 14001 — Environmental Management Systems

2015 · Global

ISO 14001:2015 environmental management system. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved environmental HSE instructions that discharge an EMS control — the KYE HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Environmental operational control under safety floor Designed L2 Designed iso-14001.8.1
Purpose Permission™Edge Governance Safety Floor
Environmental emergency instruction scope-bound Designed L2 Designed iso-14001.8.2
Purpose Permission™Authority Gate
Compliance evaluation contestable + evidenced Designed L2 Designed iso-14001.9.1.2
Evidence Pack™Authority Gate
arrow_forward KYE™ framework reference
ISO 15489

ISO 15489-1:2016 — Records Management (records-management spine)

2016 · Global

ISO 15489-1:2016 records-management spine for the KYE Chain of Authority™ for Iron Mountain InSight DXP. Iron Mountain governs INFORMATION (records, custody, retention, classification); KYE Protocol™ governs ACTION — who was authorised to act on a record at the moment it drives a consequential AI action, evidenced, final, revocable. The authentic/reliable-records-at-the-action-boundary requirements are KYE Protocol™'s job (enforced); records storage / capture / retention / disposition are records-management's job (out-of-scope, owned by the records-manager / information-custodian).

2 Enforced0 Designed3 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Records authenticity & reliability (authority overlay) Enforced L3 Enforceable iso-15489.authenticity-authority-binding, iso-15489.reliability-evidence-pin
Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Records access & permissions (authority overlay) Enforced L3 Enforceable iso-15489.access-permission-overlay
Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Records creation, capture & metadata (records-management) Out of scope L1 Mapped iso-15489.records-capture-metadata
Retention schedule & disposition authority (records-management) Out of scope L1 Mapped iso-15489.retention-disposition-authority
Records storage & preservation (records-management) Out of scope L1 Mapped iso-15489.storage-preservation
arrow_forward KYE™ framework reference
ISO 16175

ISO 16175-1:2020 — Software for Managing Records (digital records spine)

2020 · Global

ISO 16175-1:2020 digital-records-software spine for the KYE Chain of Authority™ for Iron Mountain InSight DXP. KYE Protocol™ overlays the action-boundary access-control decision + the governance-decision audit trail (enforced); the records-software capture / classification / retention functions are out-of-scope (owned by Iron Mountain InSight DXP). §0: Iron Mountain proves where information travelled; KYE Protocol™ proves who was authorised to act on it.

2 Enforced0 Designed2 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Action-decision audit trail (authority overlay) Enforced L3 Enforceable iso-16175.action-audit-trail, iso-16175.replayable-decision-record
Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Access-control decision at the action boundary (authority overlay) Enforced L3 Enforceable iso-16175.access-control-decision
Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Capture & classification functional requirements (records-software) Out of scope L1 Mapped iso-16175.capture-classification-functional
Retention & disposition functional requirements (records-software) Out of scope L1 Mapped iso-16175.retention-disposition-functional
arrow_forward KYE™ framework reference
ISO 17025

ISO/IEC 17025:2017 — Competence of testing and calibration laboratories

2017 · International

ISO/IEC 17025:2017 sets the general requirements for the competence, impartiality and consistent operation of testing and calibration laboratories. KYE Protocol™ enforces the §7.11 data-management integrity, §7.5/§7.8 technical-record reproducibility and audit-trail slices where a laboratory uses AI-supported decisioning — metrology, equipment and competence stay the laboratory's technical system. Per-requirement bijection at /compliance/iso-17025.html.

3 Enforced1 Designed1 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Control of data & information management (7.11) Enforced L3 Enforceable iso-17025.7.11-data-management
WORM audit hash-chain
Technical records & integrity of results (7.5, 7.8) Enforced L3 Enforceable iso-17025.7.5-technical-records
Decision replayEvidence Pack™
Control of management-system records & audit trail (8.4) Designed L2 Designed iso-17025.8.4-management-records
WORM audit hash-chain
Impartiality & authority over automated decisions (4.1, 6.2) Enforced L3 Enforceable iso-17025.4.1-impartiality-authority
Purpose Permission™Authority Gate
Metrological traceability, measurement uncertainty, equipment & competenceMetrological traceability, measurement uncertainty, equipment calibration and technical competence are the laboratory's own technical/metrology system — out of scope for an AI-authority-governance protocol. Out of scope L1 Mapped iso-17025.6.5-traceability, iso-17025.6.3-equipment-competence
arrow_forward KYE™ framework reference
ISO/IEC 27035

ISO/IEC 27035 — Incident Management

ISO/IEC 27035 — Information security incident management · International

ISO/IEC 27035 is the international standard for information-security incident management, including careful incident-evidence handling. KYE Protocol™ governs whether an AI-assisted incident decision under it may proceed to a consequential action — under a named accountable officer's authority, with incident-evidence chain-of-custody recorded, the assessment pinned to verifiable signal sources, a signed replay-provable Evidence Pack™ per decision, and a contestability record for the lessons-learned reconstruction. Detection / response tooling / forensic analysis stays the organisation's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/iso-27035.html.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Incident-evidence chain-of-custody (evidence handling) Enforced L3 Enforceable iso-27035.evidence-chain-of-custody
Authority GateDecision replayEvidence Pack™Replay-Proof™
Named-authority on the assessment-and-decision response Enforced L3 Enforceable iso-27035.assessment-decision-authority
Authority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & lessons-learned reconstruction Enforced L3 Enforceable iso-27035.lessons-learned-reconstruction
Authority GateDecision replayEvidence Pack™Replay-Proof™
Detection, response tooling & forensic analysisThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. Out of scope L1 Mapped iso-27035.detection-response-forensics
arrow_forward KYE™ framework reference
ISO 45001

ISO 45001 — Occupational Health & Safety Management Systems

2018 · Global

ISO 45001:2018 occupational health & safety management system. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved safety-critical HSE documents (permits-to-work, risk assessments, method statements) that discharge an OH&S control — the KYE HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.

0 Enforced4 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Operational planning & control under safety floor Designed L2 Designed iso-45001.8.1
Purpose Permission™Edge Governance Safety Floor
Hierarchy-of-controls selection advisory pending sign-off Designed L2 Designed iso-45001.8.1.2
Authority GateDecision Map™
Emergency-preparedness instruction scope-bound Designed L2 Designed iso-45001.8.2
Purpose Permission™Authority Gate
Incident / corrective action contestable + evidenced Designed L2 Designed iso-45001.10.2
Evidence Pack™Authority Gate
arrow_forward KYE™ framework reference
ISO 55000

ISO 55000 / ISO 55001:2014 — Asset management management systems

2014 · Global

ISO 55000/55001 asset-management system requirements. KYE Protocol™ governs the authority, evidence and finality of AI-recommended asset-management actions and the scope of the AI's authority over the asset portfolio. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Asset-management objectives + scoped decision authority Designed L2 Designed iso-55001.6.2.1
Authority GateDecision Map™
Planned actions — finality + named accountability Designed L2 Designed iso-55001.6.2.2
Purpose Permission™Edge Governance Safety Floor
Contestable performance review Designed L2 Designed iso-55001.9.1
Evidence Pack™Authority Gate
arrow_forward KYE™ framework reference
Mastercard Disputes

Mastercard Chargeback Standards — Dispute Resolution & Arbitration

Mastercard Chargeback Standards — Dispute Resolution & Arbitration (Chargeback Guide) · Global

The Mastercard Chargeback Standards govern the dispute lifecycle — first chargeback, second presentment with supporting documentation, pre-arbitration, and arbitration on the documented record. KYE Protocol™ governs whether the second presentment / case filing may proceed — under a named owner's recorded authority, with the supporting evidence captured as evidence events at transaction time, and the bundle sealed as a signed, hash-bound, WORM-retained, replay-verifiable Evidence Pack™ so the documented record survives arbitration scrutiny. Whether to fight, the narrative, and the outcome stay the merchant's / network's own (honest scope, §0). Per-requirement bijection at /compliance/mastercard-dispute-rules.html.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Second-presentment evidence captured at transaction time Enforced L3 Enforceable mastercard-dispute-rules.second-presentment-evidence-capture
Authority GateDecision replayEvidence Pack™Replay-Proof™
Named-authority on the chargeback response Enforced L3 Enforceable mastercard-dispute-rules.chargeback-response-authority
Authority GateDecision replayEvidence Pack™Replay-Proof™
Arbitration-grade reconstruction of the dispute record Enforced L3 Enforceable mastercard-dispute-rules.arbitration-reconstruction-record
Authority GateDecision replayEvidence Pack™Replay-Proof™
Dispute merits adjudication & strategyWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. Out of scope L1 Mapped mastercard-dispute-rules.dispute-merits-adjudication
arrow_forward KYE™ framework reference
MoReq2010

MoReq2010 — Modular Requirements for Records Systems (records-system spine)

2011 · European Union

MoReq2010 records-system spine for the KYE Chain of Authority™ for Iron Mountain InSight DXP. KYE Protocol™ overlays the action-boundary access-control service + entity-event governance-decision audit + custody→authority binding (enforced); the records-system classification / search / retention / disposition core services are out-of-scope (owned by Iron Mountain InSight DXP).

2 Enforced0 Designed2 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Access-control service at the action boundary (authority overlay) Enforced L3 Enforceable moreq-2010.access-control-service-overlay, moreq-2010.custody-to-authority-binding
Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Entity-event audit of the action decision (authority overlay) Enforced L3 Enforceable moreq-2010.entity-event-action-audit
Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Classification & search core service (records-system) Out of scope L1 Mapped moreq-2010.classification-search-service
Retention & disposition core service (records-system) Out of scope L1 Mapped moreq-2010.retention-disposition-service
arrow_forward KYE™ framework reference
MSHA

MSHA — Mine Safety and Health Administration standards (30 CFR)

2024 · United States

US MSHA standards under 30 CFR governing surface and underground mine safety. KYE Protocol™ governs the authority, evidence and finality of AI-recommended physical-safety actions on mine equipment (e.g. mine-hoist stop). Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Mine-equipment actuation under safety floor Designed L2 Designed msha.30-cfr-56.18002
Purpose Permission™Edge Governance Safety Floor
Hoisting stop named accountability Designed L2 Designed msha.30-cfr-57.19021
Authority GateDecision Map™
Contestable equipment-safety decisions Designed L2 Designed msha.30-cfr-75.1725
Evidence Pack™Authority Gate
arrow_forward KYE™ framework reference
NAIC AI Bulletin

NAIC Model Bulletin on the Use of AI by Insurers

NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (adopted December 2023) · United States

The NAIC Model Bulletin on the Use of AI by Insurers is the US insurer-AI governance expectation (written AIS Program, named accountability, documentation, unfair-discrimination testing). KYE Protocol™ governs whether an AI-assisted underwriting or claims decision under it may proceed to a consequential adverse action — under a named underwriter's / adjuster's authority, with a recorded adverse-action reason-code, with proxy-discrimination / fairness-evidence captured, a signed replay-provable Evidence Pack™ per decision, and an appeal / contestability record so any decision can be reconstructed and contested. The actuarial pricing / risk-appetite / model design on the merits stays the insurer's own work (honest scope, §0). Per-requirement bijection at /compliance/naic-model-bulletin-ai.html.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Named accountability & governance of the AI decision Enforced L3 Enforceable naic-model-bulletin-ai.governance-named-accountability
Authority GateDecision replayEvidence Pack™Replay-Proof™
Adverse-action explainability & documentation Enforced L3 Enforceable naic-model-bulletin-ai.adverse-action-documentation
Authority GateDecision replayEvidence Pack™Replay-Proof™
Unfair-discrimination testing evidence Enforced L3 Enforceable naic-model-bulletin-ai.unfair-discrimination-testing
Authority GateDecision replayEvidence Pack™Replay-Proof™
Actuarial pricing, risk appetite & model design on the meritsThe actuarial pricing / risk-appetite / model design on the merits is the insurer's own work — KYE™ is an AI-authority and evidence layer, not a pricing, actuarial, or risk-modelling engine. Out of scope L1 Mapped naic-model-bulletin-ai.actuarial-pricing-model-design
arrow_forward KYE™ framework reference
NERC CIP

NERC CIP — Critical Infrastructure Protection (bulk electric system)

2024 · United States

NERC CIP reliability standards governing cyber security of the North American bulk electric system. KYE Protocol™ governs the authority, evidence and finality of an AI-recommended physical-safety action on grid assets and the scope boundary of the AI's authority. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Controlled actuation of BES assets under safety floor Designed L2 Designed nerc-cip.cip-007-6.r1
Purpose Permission™Edge Governance Safety Floor
Purpose-scoped authority for grid actions Designed L2 Designed nerc-cip.cip-004-6.r4
Authority GateDecision Map™
Contestable + evidenced incident decisions Designed L2 Designed nerc-cip.cip-008-6.r1
Evidence Pack™Authority Gate
arrow_forward KYE™ framework reference
NIS2 Incident

NIS2 Incident Reporting — Article 23 (24h / 72h)

NIS2 — Directive (EU) 2022/2555, Article 23 · European Union

NIS2 Incident Reporting (Directive (EU) 2022/2555, Article 23) is the EU 24-hour / 72-hour staged-notification regime for significant incidents. KYE Protocol™ governs whether an AI-assisted disclosure-timing decision or containment action under it may proceed to a consequential incident action — under a named accountable officer's authority, with chain-of-custody recorded, and a contestability record so the timing decision can be reconstructed and challenged. Incident detection / impact analysis stays the entity's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/nis2-incident.html.

2 Enforced0 Designed1 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Disclosure-timing authority on the 24h / 72h notification clock Enforced L3 Enforceable nis2-incident.notification-clock-authority
Authority GateDecision replayEvidence Pack™Replay-Proof™
Incident-evidence chain-of-custody for the notification Enforced L3 Enforceable nis2-incident.notification-evidence-custody
Authority GateDecision replayEvidence Pack™Replay-Proof™
Incident detection & impact analysisThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. Out of scope L1 Mapped nis2-incident.detection-impact-analysis
arrow_forward KYE™ framework reference
NIST CSF 2.0 RS/RC

NIST CSF 2.0 — RESPOND & RECOVER

NIST Cybersecurity Framework 2.0 (2024) — RESPOND (RS) + RECOVER (RC) · United States

NIST CSF 2.0 RESPOND & RECOVER is the incident-management, analysis, and recovery half of the NIST Cybersecurity Framework 2.0. KYE Protocol™ governs whether an AI-assisted response / recovery action under it may proceed to a consequential incident action — under a named accountable officer's authority, with the incident analysis pinned to verifiable signal sources, chain-of-custody recorded, a signed replay-provable Evidence Pack™ per decision, and a contestability record. Threat detection (DETECT) / response tooling / recovery execution stays the organisation's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/nist-csf-2-respond-recover.html.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Named-authority on the RESPOND/RECOVER action (RS.MA / RC.RP) Enforced L3 Enforceable nist-csf-2-respond-recover.rs-action-authority
Authority GateDecision replayEvidence Pack™Replay-Proof™
Incident-analysis source pin (RS.AN) Enforced L3 Enforceable nist-csf-2-respond-recover.rs-incident-evidence
Authority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & post-incident reconstruction (RS.MA / improvement) Enforced L3 Enforceable nist-csf-2-respond-recover.rs-contestability
Authority GateDecision replayEvidence Pack™Replay-Proof™
Threat detection (DETECT) & recovery execution toolingThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. Out of scope L1 Mapped nist-csf-2-respond-recover.detection-recovery-tooling
arrow_forward KYE™ framework reference
Synthesis Screening

Nucleic-Acid Synthesis Screening — IBBIS Common Mechanism + IGSC Harmonized Screening Protocol

2023 · Global

Nucleic-acid synthesis screening regime — the IBBIS Common Mechanism and IGSC Harmonized Screening Protocol screen synthesis orders for sequences of concern before synthesis. KYE Protocol™ governs whether an AI-generated nucleic-acid sequence may proceed to a synthesis order, binding the screening result — the KYE AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Sequence-of-concern screening Designed L2 Designed nucleic-acid-synthesis-screening.soc-screen, nucleic-acid-synthesis-screening.flagged-hold
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Customer / legitimacy screening Designed L2 Designed nucleic-acid-synthesis-screening.customer-screen
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Screening provenance & record-keeping Designed L2 Designed nucleic-acid-synthesis-screening.screening-provenance
Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
arrow_forward KYE™ framework reference
NYDFS AI Circular

NYDFS Insurance Circular Letter on AI

NYDFS Insurance Circular Letter No. 7 (2024) — Use of AI Systems and External Consumer Data in Underwriting and Pricing · United States

NYDFS Insurance Circular Letter No. 7 (2024) sets expectations for insurers using AI and external consumer data in underwriting and pricing — senior-management accountability, unfair-discrimination testing, consumer transparency, documentation. KYE Protocol™ governs whether an AI-assisted insurance decision in scope may proceed to a consequential adverse action — under a named accountable authority, with a recorded adverse-action reason-code, proxy-discrimination / fairness-evidence captured, a signed replay-provable Evidence Pack™ per decision, and a consumer appeal / contestability record. The ECDIS selection / pricing / methodology design on the merits stays the insurer's own work (honest scope, §0). Per-requirement bijection at /compliance/nydfs-insurance-circular-ai.html.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Senior-management accountability for the AI decision Enforced L3 Enforceable nydfs-insurance-circular-ai.senior-management-accountability
Authority GateDecision replayEvidence Pack™Replay-Proof™
Unfair-discrimination testing evidence Enforced L3 Enforceable nydfs-insurance-circular-ai.unfair-discrimination-testing
Authority GateDecision replayEvidence Pack™Replay-Proof™
Consumer transparency & appeal record Enforced L3 Enforceable nydfs-insurance-circular-ai.consumer-transparency-appeal
Authority GateDecision replayEvidence Pack™Replay-Proof™
ECDIS selection, pricing & methodology design on the meritsThe ECDIS selection / pricing / testing-methodology design on the merits is the insurer's own work — KYE™ is an AI-authority and evidence layer, not a data-selection, pricing, or testing-methodology engine. Out of scope L1 Mapped nydfs-insurance-circular-ai.ecdis-selection-pricing-methodology
arrow_forward KYE™ framework reference
OECD GLP

OECD Good Laboratory Practice (Principles) + FDA 21 CFR Part 58

1998 + 21 CFR 58 · International / US

OECD Principles of Good Laboratory Practice and FDA 21 CFR Part 58 govern the integrity, traceability, audit-trail and archiving of non-clinical safety-study data. KYE Protocol™ enforces the ALCOA+ data-integrity, audit-trail and replay slices where an AI/automated step captures or transforms study data — physical study conduct stays the laboratory's GLP system. Per-requirement bijection at /compliance/oecd-glp.html.

3 Enforced1 Designed1 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Study data integrity & raw-data traceability (ALCOA+) Enforced L3 Enforceable oecd-glp.data-integrity, oecd-glp.raw-data-traceability
WORM audit hash-chainDecision replayEvidence Pack™
Audit trail & change control for electronic records (Part 11 overlap) Enforced L3 Enforceable oecd-glp.audit-trail
WORM audit hash-chain
Archive & retention of study records Designed L2 Designed oecd-glp.archive-retention
WORM audit hash-chain
QA & study-director oversight of automated steps Enforced L3 Enforceable oecd-glp.oversight-of-automated-steps
Purpose Permission™Authority Gate
Physical study conduct & facilitiesApparatus calibration, test/reference-item handling and physical SOP execution are the laboratory's own GLP quality system — KYE™ is an AI-authority and evidence layer, not a lab-operations system. Out of scope L1 Mapped oecd-glp.physical-study-conduct
arrow_forward KYE™ framework reference
OSHA PSM

OSHA PSM — Process Safety Management (29 CFR 1910.119)

1992 · United States

US OSHA Process Safety Management standard for facilities handling highly hazardous chemicals. KYE Protocol™ governs the authority, evidence and finality of AI-recommended physical-safety actions in a PSM-covered process. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Mechanical-integrity actuation under safety floor Designed L2 Designed osha-psm.1910.119.j
Purpose Permission™Edge Governance Safety Floor
Operating-procedure named accountability Designed L2 Designed osha-psm.1910.119.f
Authority GateDecision Map™
Management-of-change contestable + evidenced Designed L2 Designed osha-psm.1910.119.l
Evidence Pack™Authority Gate
arrow_forward KYE™ framework reference
Permit to Work

Permit-to-Work Systems (HSE HSG250 guidance)

HSG250 · United Kingdom

Permit-to-work systems per UK HSE HSG250. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved permits-to-work — the KYE HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Permit advisory pending competent-authoriser sign-off Designed L2 Designed permit-to-work.authorisation
Authority GateDecision Map™
Permit scope & isolation bounded to authorised work Designed L2 Designed permit-to-work.scope-isolation
Purpose Permission™Authority Gate
Hand-back & audit contestable + evidenced Designed L2 Designed permit-to-work.handback-audit
Evidence Pack™Authority Gate
arrow_forward KYE™ framework reference
PRA SS1/23

PRA SS1/23 — Model Risk Management Principles for Banks

PRA SS1/23 (Model risk management principles for banks, May 2023; effective May 2024) · United Kingdom

PRA SS1/23 sets the UK model risk management principles for banks (Principles 1–5, explicitly including AI/ML models). KYE Protocol™ governs whether a model-driven output or risk report under it may proceed to a consequential action — only a currently-validated model used within its approved scope, model changes as named-authority decisions with evidence, every consequential decision pinned to model_id + version + validation reference, and every risk report bound to its data-lineage evidence chain, sealed into a signed replay-provable Evidence Pack™. The quantitative model build / validation mathematics / capital computation / portfolio composition stays the bank's own work (honest scope, §0 — not investment advice). Per-requirement bijection at /compliance/pra-ss1-23.html.

5 Enforced0 Designed1 Out of scope
6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Model identification & inventory resolution (Principle 1) Enforced L3 Enforceable pra-ss1-23.principle1-model-inventory-resolution
Authority GateDecision replayEvidence Pack™Replay-Proof™
Governance & named SMF accountability (Principle 2) Enforced L3 Enforceable pra-ss1-23.principle2-governance-named-authority
Authority GateDecision replayEvidence Pack™Replay-Proof™
Model development, implementation & use incl. AI/ML (Principle 3) Enforced L3 Enforceable pra-ss1-23.principle3-development-implementation-use
Authority GateDecision replayEvidence Pack™Replay-Proof™
Validation-status binding at the moment of use (Principle 4) Enforced L3 Enforceable pra-ss1-23.principle4-validation-status-binding
Authority GateDecision replayEvidence Pack™Replay-Proof™
Model risk mitigants & restrictions on use (Principle 5) Enforced L3 Enforceable pra-ss1-23.principle5-mitigants-restrictions
Authority GateDecision replayEvidence Pack™Replay-Proof™
Independent validation judgment & quantitative work on the meritsThe quantitative model build, validation mathematics, and capital & liquidity computation are the bank's own quantitative work — KYE™ is an AI-authority and evidence layer, not a model-validation or capital-calculation engine. Out of scope L1 Mapped pra-ss1-23.independent-validation-judgment
arrow_forward KYE™ framework reference
PSD2 SCA Disputes

PSD2 SCA & Unauthorised-Transaction Liability (Arts. 72-74, 97)

PSD2 — Directive (EU) 2015/2366, Arts. 72-74 + 97 (SCA & unauthorised-transaction liability) · European Union

PSD2 Arts. 72-74 + 97 govern SCA and unauthorised-transaction liability in the EU — the PSP carries the burden of proof that the transaction was authenticated and accurately recorded. KYE Protocol™ governs whether an unauthorised-transaction refund / liability allocation may proceed — under a named owner's recorded authority, with the SCA / authentication evidence captured as evidence events at transaction time, and the liability-allocation bundle sealed as a signed, hash-bound, replay-provable Evidence Pack™ that meets the Article 72 burden of proof. The substantive fraud / authorisation determination stays the PSP's / merchant's own (honest scope, §0). Per-requirement bijection at /compliance/psd2-sca-disputes.html.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
SCA / authentication evidence captured at transaction time Enforced L3 Enforceable psd2-sca-disputes.sca-evidence-capture
Authority GateDecision replayEvidence Pack™Replay-Proof™
Named-authority on the unauthorised-transaction refund Enforced L3 Enforceable psd2-sca-disputes.unauthorised-transaction-refund-authority
Authority GateDecision replayEvidence Pack™Replay-Proof™
Burden-of-proof evidence integrity for liability allocation Enforced L3 Enforceable psd2-sca-disputes.liability-allocation-evidence
Authority GateDecision replayEvidence Pack™Replay-Proof™
Substantive fraud / authorisation determination on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. Out of scope L1 Mapped psd2-sca-disputes.fraud-determination
arrow_forward KYE™ framework reference
Reg E

Reg E — EFTA Error Resolution (12 CFR 1005.11)

EFTA / Regulation E — 12 CFR Part 1005 (error resolution, §1005.11) · United States

Reg E (12 CFR 1005.11) is the US error-resolution framework for electronic fund transfers. KYE Protocol™ governs whether a provisional credit, refund, or error determination in the dispute flow may proceed — under a named owner's recorded authority, with the transaction evidence captured as evidence events at transaction time, a signed replay-provable Evidence Pack™, and a recorded contestable determination. The substantive error adjudication stays the institution's / merchant's own (honest scope, §0). Per-requirement bijection at /compliance/reg-e.html.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Named-authority on the provisional credit / refund action Enforced L3 Enforceable reg-e.provisional-credit-authority
Authority GateDecision replayEvidence Pack™Replay-Proof™
Investigation evidence record captured at transaction time Enforced L3 Enforceable reg-e.investigation-evidence-record
Authority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & written-determination reconstruction Enforced L3 Enforceable reg-e.error-determination-contestability
Authority GateDecision replayEvidence Pack™Replay-Proof™
Substantive error adjudication on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. Out of scope L1 Mapped reg-e.substantive-error-adjudication
arrow_forward KYE™ framework reference
Reg Z

Reg Z — TILA Billing-Error Resolution (12 CFR 1026.13)

TILA / Regulation Z — 12 CFR Part 1026 (billing-error resolution, §1026.13) · United States

Reg Z (12 CFR 1026.13) is the US billing-error-resolution framework for credit accounts. KYE Protocol™ governs whether an account correction, credit, or billing-error determination in the dispute flow may proceed — under a named owner's recorded authority, with the transaction evidence captured as evidence events at transaction time, a signed replay-provable Evidence Pack™, and a recorded contestable determination. The substantive billing-error adjudication stays the creditor's / merchant's own (honest scope, §0). Per-requirement bijection at /compliance/reg-z.html.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Named-authority on the account correction / credit action Enforced L3 Enforceable reg-z.billing-error-resolution-record
Authority GateDecision replayEvidence Pack™Replay-Proof™
Billing-dispute evidence record captured at transaction time Enforced L3 Enforceable reg-z.billing-dispute-evidence-record
Authority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & written-explanation reconstruction Enforced L3 Enforceable reg-z.billing-dispute-contestability
Authority GateDecision replayEvidence Pack™Replay-Proof™
Substantive billing-error adjudication on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. Out of scope L1 Mapped reg-z.substantive-billing-error-adjudication
arrow_forward KYE™ framework reference
RIDDOR

RIDDOR — Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013 (UK)

2013 · United Kingdom

UK RIDDOR 2013 (SI 2013/1471), HSE-enforced. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved RIDDOR-reportable incident reports — the KYE HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Incident report authored under safety floor Designed L2 Designed riddor.reg-4-6
Purpose Permission™Edge Governance Safety Floor
Reportability determination advisory pending sign-off Designed L2 Designed riddor.reporting-decision
Authority GateDecision Map™
Incident records contestable + evidenced Designed L2 Designed riddor.reg-12
Evidence Pack™Authority Gate
arrow_forward KYE™ framework reference
SEC Cyber Disclosure

SEC Cyber Disclosure — Item 1.05 (4 business days)

SEC Cybersecurity Disclosure Rules (2023) — Item 1.05 + Item 106 · United States

SEC Cyber Disclosure (Item 1.05) is the US four-business-day material-cybersecurity-incident disclosure regime on Form 8-K. KYE Protocol™ governs whether an AI-assisted disclosure-timing decision under it may proceed to a consequential disclosure action — under a named accountable officer's authority, with incident-evidence chain-of-custody recorded, and a contestability record so the timing decision can be reconstructed and challenged. The substantive materiality determination / 8-K drafting / legal judgment stays the registrant's own work (honest scope, §0/§70). Per-requirement bijection at /compliance/sec-cyber-disclosure.html.

2 Enforced0 Designed1 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Disclosure-timing authority on the four-business-day clock Enforced L3 Enforceable sec-cyber-disclosure.item105-materiality-disclosure-authority
Authority GateDecision replayEvidence Pack™Replay-Proof™
Contestability of the timing decision in an SEC / shareholder review Enforced L3 Enforceable sec-cyber-disclosure.item105-timing-contestability
Authority GateDecision replayEvidence Pack™Replay-Proof™
Substantive materiality determination & 8-K draftingThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. Out of scope L1 Mapped sec-cyber-disclosure.substantive-materiality-drafting
arrow_forward KYE™ framework reference
Sedona Principles

The Sedona Principles — Best Practices for Electronic Document Production

The Sedona Principles, Third Edition (2018) · United States

The Sedona Principles — Best Practices for Electronic Document Production is the leading US e-discovery best-practice commentary (The Sedona Principles, Third Edition). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/sedona-principles.html.

2 Enforced0 Designed1 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Defensible, reconstructable AI-review process record Enforced L3 Enforceable sedona-principles.principle6-defensible-process
Authority GateDecision replayEvidence Pack™Replay-Proof™
Replay-provable evidence of the process when challenged Enforced L3 Enforceable sedona-principles.replay-provable-process-evidence
Authority GateDecision replayEvidence Pack™Replay-Proof™
Methodology selection & substantive production completenessThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. Out of scope L1 Mapped sedona-principles.methodology-and-completeness
arrow_forward KYE™ framework reference
SOX §806

SOX §806 — Whistleblower Anti-Retaliation (18 U.S.C. §1514A)

Sarbanes-Oxley Act §806 (18 U.S.C. §1514A) — whistleblower anti-retaliation · United States

SOX §806 — Whistleblower Anti-Retaliation (18 U.S.C. §1514A) is the US public-company anti-retaliation statute (contributing-factor / clear-and-convincing burden). KYE Protocol™ governs whether an AI-assisted adverse HR action that touches a reporter may proceed — only with a recorded retaliation-risk assessment evidence — and binds a contestability record so the employer's burden-of-proof can be reconstructed if a §806 complaint is filed. Whether the action was in fact retaliatory and the §806 adjudication stay with counsel / OSHA / the courts (honest scope, §0). Per-requirement bijection at /compliance/sox-806.html.

2 Enforced0 Designed1 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Retaliation-risk assessment evidence before an adverse action Enforced L3 Enforceable sox-806.anti-retaliation-risk-record
Authority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & burden-of-proof reconstruction Enforced L3 Enforceable sox-806.contestability-burden-reconstruction
Authority GateDecision replayEvidence Pack™Replay-Proof™
Whether the action was in fact retaliatory & §806 adjudicationDeciding whether an action was retaliatory and adjudicating the §806 complaint is a legal determination for counsel and the courts — KYE™ is an AI-authority and evidence layer, not an adjudication engine. Out of scope L1 Mapped sox-806.substantive-retaliation-adjudication
arrow_forward KYE™ framework reference
CPR PD 57AD

UK CPR Part 31 + PD 57AD — Disclosure & the Disclosure Certificate

CPR Part 31 + Practice Direction 57AD (Disclosure in the Business and Property Courts, 2022) · United Kingdom

UK CPR Part 31 + PD 57AD — Disclosure & the Disclosure Certificate is the English civil disclosure framework (CPR Part 31 + Practice Direction 57AD). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/uk-cpr-pd57ad.html.

2 Enforced0 Designed1 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Named-authority on the disclosure determination & certificate Enforced L3 Enforceable uk-cpr-pd57ad.disclosure-certificate
Authority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & reconstruction of a disclosure challenge Enforced L3 Enforceable uk-cpr-pd57ad.disclosure-challenge-reconstruction
Authority GateDecision replayEvidence Pack™Replay-Proof™
Substantive disclosure review & adequacy judgmentThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. Out of scope L1 Mapped uk-cpr-pd57ad.substantive-disclosure-review
arrow_forward KYE™ framework reference
UK PIDA

UK PIDA — Public Interest Disclosure Act 1998 (ERA 1996 Part IVA)

UK Public Interest Disclosure Act 1998 (Employment Rights Act 1996, Part IVA) · United Kingdom

UK PIDA — Public Interest Disclosure Act 1998 (ERA 1996 Part IVA) is the UK protected-disclosure framework (protection from detriment and automatic-unfair dismissal). KYE Protocol™ governs whether an AI-assisted handling of a protected disclosure, or an adverse action on a worker who made one, may proceed — under a named handler's authority, with a recorded detriment / retaliation-risk assessment before adverse action, and a contestability record so a detriment / dismissal claim can be reconstructed. Whether the disclosure qualifies, whether a detriment occurred, and the tribunal adjudication stay with counsel and the tribunal (honest scope, §0). Per-requirement bijection at /compliance/uk-pida.html.

2 Enforced0 Designed1 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Named-authority on the protected-disclosure handling & detriment-risk record Enforced L3 Enforceable uk-pida.protected-disclosure-handling-authority
Authority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & reconstruction for a detriment / dismissal claim Enforced L3 Enforceable uk-pida.detriment-claim-reconstruction
Authority GateDecision replayEvidence Pack™Replay-Proof™
Whether the disclosure qualifies & employment-tribunal adjudicationDeciding whether a disclosure qualifies and adjudicating the tribunal claim is a legal determination for counsel and the tribunal — KYE™ is an AI-authority and evidence layer, not an adjudication engine. Out of scope L1 Mapped uk-pida.qualifying-disclosure-and-adjudication
arrow_forward KYE™ framework reference
Visa CE 3.0

Visa Compelling Evidence 3.0 (CE3.0)

Visa Compelling Evidence 3.0 (CE3.0) — remedied-dispute evidence requirements (Visa Rules, fraud reason code 10.4) · Global

Visa Compelling Evidence 3.0 defines the qualifying evidence set that remedies a card-absent fraud dispute (prior undisputed transactions, matching device / IP / address / account identifiers, delivery evidence). KYE Protocol™ governs whether the representment may proceed — under a named owner's recorded authority, with the qualifying evidence captured as evidence events at transaction time, and the representment bundle sealed as a signed, hash-bound, WORM-retained, replay-verifiable Evidence Pack™ — exactly the provable evidence set CE3.0 representments turn on. Whether to fight, the narrative, and the outcome stay the merchant's / network's own (honest scope, §0). Per-requirement bijection at /compliance/visa-ce30.html.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Qualifying evidence set captured at transaction time Enforced L3 Enforceable visa-ce30.evidence-set-capture
Authority GateDecision replayEvidence Pack™Replay-Proof™
Representment bundle integrity (signed · hash-bound · WORM) Enforced L3 Enforceable visa-ce30.representment-bundle-integrity
Authority GateDecision replayEvidence Pack™Replay-Proof™
Named-authority on the representment decision Enforced L3 Enforceable visa-ce30.representment-authority
Authority GateDecision replayEvidence Pack™Replay-Proof™
Dispute outcome adjudication & narrative on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. Out of scope L1 Mapped visa-ce30.dispute-outcome-adjudication
arrow_forward KYE™ framework reference
2 CFR 200 (Uniform Guidance)

US 2 CFR 200 — Uniform Guidance

2 C.F.R. Part 200 (Uniform Guidance) · United States

US federal grants-administration regulation: uniform administrative requirements, cost principles, and audit requirements for federal awards. KYE governs WHETHER a grants-lifecycle action by an AI agent may proceed and proves the basis (via the KYE Governed Grants Agent™); it does not write applications, run a grants-management platform, or move money.

3 Enforced1 Designed1 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Cost principles & allowability of costs (§200.403) Enforced L3 Enforceable 2 C.F.R. §200.403
Governed Grants Agent™ admit→decidePurpose Permission™Evidence Pack™
Internal controls over the federal award (§200.303) Enforced L3 Enforceable 2 C.F.R. §200.303
Replay-Proof™WORM audit hash-chainEvidence Pack™
Pass-through entity / subrecipient monitoring (§200.332) Enforced L3 Enforceable 2 C.F.R. §200.332
Governed Grants Agent™ admit→decideDelegated Auditability
Prior written approval & record retention (§200.407, §200.334) Designed L2 Designed 2 C.F.R. §200.407, 2 C.F.R. §200.334
GovernedUI two-person sign-off (Phase-2)WORM retention policy (Phase-2)
Grantee financial-management system & Single Audit (§200.302, §200.501) Out of scope L1 Mapped 2 C.F.R. §200.302, 2 C.F.R. §200.501
arrow_forward KYE™ framework reference
IT Rules 2021

IT Rules 2021

Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as amended · India

KYE governs whether an AI agent's content-affecting ACTION (publish, remove, restrict, distribute) was authorised and is evidenced. KYE is OUT-OF-SCOPE for the substantive content determination — whether material is unlawful — and for operating grievance-redressal machinery. Those are the intermediary's own obligations (§70 §4). Deep per-requirement mapping: 4 requirements, 1 enforced by KYE runtime, 3 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.

1 Enforced0 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority + evidence at the action boundary — enforced by KYE runtime and verified by CI Enforced L3 Enforceable it-rules-2021.ACTION-AUTHORITY — Content-affecting actions taken under resolved authority and evidenced
kye.compliance.attestation.v1kye.evidence.decision_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context_seal.v1internal
Obligations owed directly by the regulated entity — NOT discharged by KYEKYE governs whether an AI agent's content-affecting ACTION (publish, remove, restrict, distribute) was authorised and is evidenced. KYE is OUT-OF-SCOPE for the substantive content determination — whether material is unlawful — and for operating grievance-redressal machinery. Those are the intermediary's own obligations (§70 §4). Out of scope L1 Mapped it-rules-2021.GRIEVANCE-REDRESSAL — Grievance officer appointed and complaints resolved within prescribed timelines, it-rules-2021.DUE-DILIGENCE — Intermediary due-diligence obligations including publication of rules and privacy policy, it-rules-2021.SYNTHETIC-LABELLING — Identification of artificially generated or modified information
arrow_forward KYE™ framework reference

Security & cyber-resilience

Information-security and operational-resilience frameworks that govern how systems are protected, monitored, and recovered.

ASD Essential Eight

ASD Essential Eight + ASD AI guidance

Nov 2023 maturity model + 2024 AI guidance · Australia

ASD/ACSC Essential Eight mitigation strategies + ASD 'Engaging with Artificial Intelligence' guidance, scoped to the AI-agent action path. Per-requirement bijection at /compliance/asd-essential-eight.html.

2 Enforced0 Designed0 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Restrict administrative privileges + multi-factor authentication Enforced L3 Enforceable E8 — Restrict admin privileges, E8 — MFA
Authority GateAuthority Revocation OrchestratorWebAuthn step-up
Tamper-evident monitoring + AI supply-chain governance Enforced L3 Enforceable E8 — Monitoring, ASD AI guidance — supply chain
WORM audit hash-chainStreaming Logs Contract™Authority Register
arrow_forward KYE™ framework reference
CISA CDM

CISA CDM — Continuous Diagnostics and Mitigation (AI-agent asset accountability)

CDM Program — DEFEND capability areas A–D · United States

CISA's Continuous Diagnostics and Mitigation program, mapped to the agentic-AI asset surface: an AI agent that holds credentials, reaches data, and acts on systems is a reportable cyber asset. KYE™ answers 'what agents exist, who owns them, what do they touch, what can they do, and are they drifting?'

4 Enforced0 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Asset Management — HWAM/SWAM/CSM/VUL (the AI-agent asset inventory + approved-design baseline + drift) Enforced L3 Enforceable HWAM, SWAM, CSM, VUL
§14 Agent Registry (reportable assets)Operating Model™ baselineReality Coupling™ drift
Identity & Access Management — TRUST/CRED/PRIV/BEHAVE Enforced L3 Enforceable TRUST, CRED, PRIV, BEHAVE
Know Your Entity™ resolutionAuthority tokens + revocationPurpose Permission™ least privilege
Network Security Management — BOUND/MNGEVT (tenant isolation + suspend/revoke response) Enforced L3 Enforceable BOUND, MNGEVT
§0.11 tenant isolationSuspend/Revoke/Kill-switchWORM audit
Data Protection Management — DPM (tamper-evident, replayable evidence) Enforced L3 Enforceable DPM
WORM audit hash-chainEvidence Pack™Replay Proof™
arrow_forward KYE™ framework reference
FedRAMP

FedRAMP — Federal Risk and Authorization Management Program

Rev 5 · United States

US federal cloud authorisation program built on the NIST SP 800-53 control baseline.

4 Enforced0 Designed1 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Access Control (AC) family Enforced L3 Enforceable AC
Authority GatePurpose Permission™WebAuthn step-up
Audit & Accountability (AU) family Enforced L3 Enforceable AU
WORM audit hash-chainDecision replay
Identification & Authentication (IA) family Enforced L3 Enforceable IA
WebAuthn step-upAuthority Gate
System & communications protection — cryptographyA FIPS-validated cryptographic adapter and automated key rotation are in build. Enforced L3 Enforceable SC-12, SC-13
FIPS-validated crypto moduleAutomated key rotationEvidence Pack™ signing (COSE-Sign1)
Physical (PE) & Personnel (PS) familiesPhysical and personnel controls are operated by the customer's authorised cloud environment. Out of scope L1 Mapped PE, PS
arrow_forward KYE™ framework reference
Google SRE Change Mgmt

Google SRE — Change Management (progressive rollout & rollback)

SRE Book · International

Google SRE — Change Management (progressive rollout & rollback). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.

1 Enforced0 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Progressive rollout authority & rollback readiness (action-boundary, enforced) Enforced L3 Enforceable google-sre-change-management.progressive-rollout-authority
Action Admissibility™ GateAuthority Finality™Evidence Pack™
Monitoring, canary analysis & rollout-automation tooling (out-of-scope — sre / platform) Out of scope L1 Mapped google-sre-change-management.monitoring-rollout-tooling
arrow_forward KYE™ framework reference
ISO 27001

ISO/IEC 27001 — Information Security Management

2022 · International

Information security management system requirements and the Annex A control set.

3 Enforced1 Designed1 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Organisational & people controls Enforced L3 Enforceable A.5.x, A.6.x
Purpose Permission™Authority Gate
Identity & access management Enforced L3 Enforceable A.5.15-A.5.18, A.8.2-A.8.5
Authority GateWebAuthn step-upPurpose Permission™
Logging, monitoring & event management Enforced L3 Enforceable A.8.15, A.8.16
WORM audit hash-chainDecision replay
Cryptographic controls & key managementEd25519 signing runs in-process today; the KMS/HSM-backed key-rotation and FIPS-validated adapter are in build. Designed L2 Designed A.8.24
Evidence Pack™ signing (COSE-Sign1)Automated key rotationFIPS-validated crypto module
Physical security & training deliveryKYE™ records that training was completed as a capability grant, but does not deliver content or operate physical and environmental controls. Out of scope L1 Mapped A.7.x, A.6.3
arrow_forward KYE™ framework reference
ISO/IEC 20000-1

ISO/IEC 20000-1 — Service Management (change management §8.5.1)

2018 · International

ISO/IEC 20000-1 — Service Management (change management §8.5.1). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.

1 Enforced0 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Change management §8.5.1 — authorization & records (action-boundary, enforced) Enforced L3 Enforceable iso-iec-20000-1.clause8-5-1-change-management
Action Admissibility™ GateAuthority Finality™Evidence Pack™
Service-management system operation, SLAs & continual improvement (out-of-scope — service-management) Out of scope L1 Mapped iso-iec-20000-1.smsystem-operation
arrow_forward KYE™ framework reference
ITIL 4 Change Enablement

ITIL 4 — Change Enablement (change authority & assessment)

4 · International

ITIL 4 — Change Enablement (change authority & assessment). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.

1 Enforced0 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Change authority & assessment (action-boundary, enforced) Enforced L3 Enforceable itil-4-change-enablement.change-authority-assessment
Action Admissibility™ GateAuthority Finality™Evidence Pack™
Technical change evaluation, scheduling & change-model authoring (out-of-scope — change-management) Out of scope L1 Mapped itil-4-change-enablement.change-evaluation-technical
arrow_forward KYE™ framework reference
NIS2

NIS2 — Network and Information Security Directive

Directive (EU) 2022/2555 · European Union

EU cybersecurity directive setting risk-management and incident-reporting duties for essential and important entities.

2 Enforced1 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Cybersecurity risk-management measures Enforced L3 Enforceable Art. 21
Purpose Permission™Authority GateWORM audit hash-chain
Incident handling & reporting evidence Enforced L3 Enforceable Art. 23
WORM audit hash-chainDecision replay
Supply-chain security evidenceSupply-chain federation runs through the Directory tenant proxy today; signed supply-chain evidence packs are in build. Designed L2 Designed Art. 21(2)(d)
Evidence Pack™ signing (COSE-Sign1)Directory tenant proxy
Management-body governance designationDesignation of management-body responsibility for cybersecurity risk is an organisational matter. Out of scope L1 Mapped Art. 20
arrow_forward KYE™ framework reference
NIST 800-207

NIST SP 800-207 — Zero Trust Architecture

1.0 · United States

Reference architecture for zero-trust security: per-request authorisation and continuous evaluation.

3 Enforced0 Designed1 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Policy decision & enforcement point Enforced L3 Enforceable §2, §3.1
Authority GatePurpose Permission™
Continuous evaluation & per-request authorisation Enforced L3 Enforceable §3.2
Purpose Permission™WebAuthn step-up
Audit, telemetry & diagnostics Enforced L3 Enforceable §3.4
WORM audit hash-chainDecision replay
Deployment-topology selectionKYE™ aligns with every zero-trust deployment variant but does not prescribe one; deployment topology is the customer's choice. Out of scope L1 Mapped §3.3
arrow_forward KYE™ framework reference
NIST 800-53 CM

NIST SP 800-53 Rev 5 — Configuration Management (CM) family

Rev 5 · United States

NIST SP 800-53 Rev 5 — Configuration Management (CM) family. KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.

1 Enforced0 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
CM-3 configuration change control — authority & impact analysis (action-boundary, enforced) Enforced L3 Enforceable nist-800-53-cm.cm-3-configuration-change-control
Action Admissibility™ GateAuthority Finality™Evidence Pack™
CM-2 baseline configuration & CM-8 component inventory (out-of-scope — config-management) Out of scope L1 Mapped nist-800-53-cm.cm-2-baseline-inventory
arrow_forward KYE™ framework reference
NIST CSF

NIST Cybersecurity Framework

2.0 · United States

Outcome-based cybersecurity framework organised around the Govern, Identify, Protect, Detect, Respond, and Recover functions.

3 Enforced1 Designed0 Out of scope
4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Govern function Enforced L3 Enforceable GV
Purpose Permission™Authority Gate
Identify & Protect functions Enforced L3 Enforceable ID, PR
Authority GatePurpose Permission™WebAuthn step-up
Detect, Respond & Recover functions Enforced L3 Enforceable DE, RS, RC
WORM audit hash-chainDecision replay
Tamper-evident control evidenceThe append-only audit chain protects evidence integrity today; detached signatures that prove integrity to an external party are in build. Designed L2 Designed PR.DS
Evidence Pack™ signing (COSE-Sign1)
arrow_forward KYE™ framework reference
SOC 2

SOC 2 — Trust Services Criteria

TSC 2017 · Global

AICPA Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy.

4 Enforced1 Designed1 Out of scope
6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Control environment, communication & risk assessment Enforced L3 Enforceable CC1.x, CC2.x, CC3.x
Purpose Permission™Authority GateWORM audit hash-chain
Logical access controls Enforced L3 Enforceable CC6.1-CC6.8
Authority GatePurpose Permission™WebAuthn step-up
System operations, monitoring & change management Enforced L3 Enforceable CC7.x, CC8.1
WORM audit hash-chainDecision replay
Confidentiality, availability & recovery Enforced L3 Enforceable C1.x, A1.2, P4.1
Authority GateWORM audit hash-chain
Independently verifiable transparency receiptsTransparency receipts are emitted today; the detached cryptographic signatures that make them third-party-verifiable are in build. Designed L2 Designed CC2.3
Evidence Pack™ signing (COSE-Sign1)Decision Map™ signing (JWS-detached)
Board oversight & physical securityBoard composition and data-centre physical controls are organisational; KYE™ records the actions of board members but does not establish governance structure. Out of scope L1 Mapped CC1.2
arrow_forward KYE™ framework reference
SOC 2 CC8

Production Action Authority — SOC 2 CC8 Change Management

2017 TSC · United States

SOC 2 — CC8 Change Management (Common Criteria). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.

1 Enforced0 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
CC8.1 change authorization & evidence (action-boundary, enforced) Enforced L3 Enforceable soc2-cc8-change-management.cc8-1-change-authorization
Action Admissibility™ GateAuthority Finality™Evidence Pack™
Change design, development & testing (out-of-scope — engineering / qa) Out of scope L1 Mapped soc2-cc8-change-management.cc8-development-testing
arrow_forward KYE™ framework reference
OWASP Agentic Top 10

OWASP Top 10 for Agentic Applications (Agentic AI Threats and Mitigations)

2025 · International

OWASP's agentic-AI threat taxonomy (2025), crosswalked by AIUC-1. KYE Protocol™ is the runtime authority + evidence + finality substrate each threat class assumes — it gates the agent action, binds agent identity, and seals replay-provable evidence. KYE proves the control operated at the action boundary; it is not an agent scanner. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Tool misuse / privilege / intent — gated by purpose-scope Designed L2 Designed owasp-agentic.t2-tool-misuse, owasp-agentic.t3-privilege-compromise, owasp-agentic.t6-intent-goal-manipulation
Purpose Permission™Decision Map™Authority Gate
Repudiation / spoofing / deception — identity + replay evidence Designed L2 Designed owasp-agentic.t8-repudiation-untraceability, owasp-agentic.t9-identity-spoofing, owasp-agentic.t7-misaligned-deceptive
Evidence Pack™Replay Proof™Delegated Auditability
Memory poisoning / HITL overwhelm — memory authority + approval modes Designed L2 Designed owasp-agentic.t1-memory-poisoning, owasp-agentic.t10-hitl-overwhelm
Memory AuthorityGovernedUI
arrow_forward KYE™ framework reference
SASH Cyber Agents

Singapore SASH — Detecting Offensive Cyber Agents

2026 · Singapore

Singapore SASH 'Detecting Offensive Cyber Agents' defence-in-depth (2026). KYE Protocol™ makes a defending org's own agents first-class identifiable principals with replay-provable actions + a continuous posture signal — complementing the identity, triage and exchange (ACE) layers. KYE is the authority + evidence substrate, not an IDS/honeypot. Per-requirement bijection at framework-coverage-bijection.

0 Enforced3 Designed0 Out of scope
3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Agent identity — first-class bound principals Designed L2 Designed sash.agent-identity
Delegated Agent BindingAgent Identity
Detection & triage — continuous posture signal Designed L2 Designed sash.detection-triage
Posture SignalDelegated Agent Binding
ACE exchange + post-incident replay Designed L2 Designed sash.ace-exchange, sash.evidence-replay
Evidence Pack™Replay Proof™Delegated Auditability
arrow_forward KYE™ framework reference
CRA

EU Cyber Resilience Act (CRA)

Regulation (EU) 2024/2847 · European Union

EU horizontal cybersecurity regulation for products with digital elements; mandatory SBOM, vulnerability handling, security-by-design, and Article 14 vulnerability/incident reporting (24h/72h/14-day). Fully applicable Dec 2027.

3 Enforced1 Designed1 Out of scope
5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Security-by-design essential requirements (Annex I, Part I) Enforced L3 Enforceable Annex I, Part I
Purpose Permission™WORM audit hash-chainSIEM streaming logs
Vulnerability handling + remediation (Annex I, Part II) Enforced L3 Enforceable Annex I, Part II
Cyber-resilience incident rule packDecision replay
SBOM generation & machine-readable bill of materialsKYE does not generate the product SBOM (manufacturer obligation); a manufacturer-supplied SBOM can be cited and pinned as evidence to a governed vulnerability-handling decision. Runtime ingest is designed, not yet wired. Designed L2 Designed Annex I, Part II (1)
Document Intelligence Rail (cite-and-pin)
Article 14 vulnerability & severe-incident reporting (24h/72h/14-day) Enforced L3 Enforceable Art. 14
Incident lifecycleEvidence Pack™ signing
Conformity assessment & CE markingConformity assessment, CE marking and placing-on-the-market are product-certification obligations of the manufacturer and notified body, outside KYE's lane. Out of scope L1 Mapped Art. 32, Annex VIII
arrow_forward KYE™ framework reference
CERT-In Directions

CERT-In Cyber Security Directions

Directions dated 28 April 2022 under s.70B(6), Information Technology Act, 2000 · India

KYE governs the AUTHORITY + EVIDENCE layer of incident response: what was decided, under whose authority, and when — sealed so the sequence is replayable against a statutory clock. KYE is OUT-OF-SCOPE for detecting cyber incidents across the customer's estate, for operating their SOC, and for making the regulatory filing to CERT-In. The six-hour obligation is the customer's; KYE makes the timeline provable (§70 §4). Deep per-requirement mapping: 5 requirements, 2 enforced by KYE runtime, 3 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.

1 Enforced0 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority + evidence at the action boundary — enforced by KYE runtime and verified by CI Enforced L3 Enforceable cert-in-directions-2022.SIX-HOUR-CLOCK — Specified cyber incidents reported to CERT-In within six hours of noticing, cert-in-directions-2022.LOG-RETENTION — ICT system logs maintained securely for a rolling 180-day period within Indian jurisdiction
kye.compliance.attestation.v1kye.evidence.pack.v1kye.replay.context_seal.v1kye.resilience.availability_gap.v1
Obligations owed directly by the regulated entity — NOT discharged by KYEKYE governs the AUTHORITY + EVIDENCE layer of incident response: what was decided, under whose authority, and when — sealed so the sequence is replayable against a statutory clock. KYE is OUT-OF-SCOPE for detecting cyber incidents across the customer's estate, for operating their SOC, and for making the regulatory filing to CERT-In. The six-hour obligation is the customer's; KYE makes the timeline provable (§70 §4). Out of scope L1 Mapped cert-in-directions-2022.TIME-SYNC — System clocks synchronised to NPL or NIC network time, cert-in-directions-2022.INCIDENT-DETECTION — Detection and triage of reportable cyber incidents across the estate, cert-in-directions-2022.REGULATORY-FILING — Submission of the incident report to CERT-In in the prescribed format
arrow_forward KYE™ framework reference
SEBI CSCRF

SEBI CSCRF

Cybersecurity and Cyber Resilience Framework (CSCRF) · India

KYE governs the AUTHORITY + EVIDENCE layer of consequential actions and of incident RESPONSE decisions. KYE is OUT-OF-SCOPE for the identify/protect/detect capabilities themselves — asset inventory, network protection, monitoring — which the regulated entity operates (§70 §4). Deep per-requirement mapping: 6 requirements, 2 enforced by KYE runtime, 4 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.

1 Enforced0 Designed1 Out of scope
2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority + evidence at the action boundary — enforced by KYE runtime and verified by CI Enforced L3 Enforceable sebi-cyber-resilience.RESPOND-AUTHORITY — Incident-response actions taken under resolved authority and sealed, sebi-cyber-resilience.EVIDENCE-RETENTION — Retention of security event records supporting audit and forensic review
kye.compliance.attestation.v1kye.evidence.decision_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context_seal.v1internal
Obligations owed directly by the regulated entity — NOT discharged by KYEKYE governs the AUTHORITY + EVIDENCE layer of consequential actions and of incident RESPONSE decisions. KYE is OUT-OF-SCOPE for the identify/protect/detect capabilities themselves — asset inventory, network protection, monitoring — which the regulated entity operates (§70 §4). Out of scope L1 Mapped sebi-cyber-resilience.IDENTIFY-PROTECT — Asset identification and protective controls across the estate, sebi-cyber-resilience.DETECT-MONITOR — Continuous monitoring and detection of cyber events, sebi-cyber-resilience.INCIDENT-REPORTING — Reporting of cyber incidents to SEBI within prescribed timelines, sebi-cyber-resilience.RECOVER — Recovery and restoration capability with defined objectives
arrow_forward KYE™ framework reference
Methodology

One registry. Zero hand-authored numbers.

This page is generated. The framework roster, every count, and every headline number above are projected from internal — a schema-backed canonical registry validated on every build. The page cannot drift from the registry: a CI gate regenerates it and fails the build on any mismatch.

For the full per-control register — every article and criterion bound to its KYE™ runtime control — see the compliance frameworks reference and the compliance program. KYE Protocol™ is an evidence layer: it is not a certification, and it does not replace the customer’s own controls or an accredited assessment.

See your own coverage map.

Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.