When APRA asks for the operational-risk control trail under CPS 230, when the AI Guardrails ask who was accountable and how a decision was reached, when the OAIC asks about an automated decision under the Privacy Act 1988 — KYE Protocol™ answers from a record sealed at the moment of action. Replayable from the publishing tenant's JWKS alone. No vendor dependency in the audit path.
Prudential Standard CPS 230 — Operational Risk Management (effective 1 July 2025). The Risk Engine + Decision Engine bind each governed action to a contemporaneous risk assessment, and the Resilience Loop™ replays the life cycle of every operation an AI agent performed — the operational-risk control trail APRA wants.
Mandatory AI Guardrails (DISR 2024)
The 10 mandatory AI guardrails for high-risk settings. Guardrails 1-9 map directly to KYE™ primitives: accountability (Purpose Permission™), human oversight (GovernedUI™), transparency (Decision Map™), contestability (Replay-Proof™) and record-keeping (WORM audit). Each guardrail is a per-requirement bijection row.
Privacy Act 1988 — ADM reform
The 2024 automated-decision-making transparency reform plus Australian Privacy Principles 1 and 11. The Decision Map™ records the kinds of personal information used in a substantially automated decision, and Replay-Proof™ reconstructs the explanation the reform contemplates.
ASD Essential Eight + ASD AI guidance
Restrict-administrative-privileges and MFA map to Authority Resolution™ + WebAuthn step-up; tamper-evident monitoring maps to the Streaming Logs Contract™ + WORM audit. ASD's 'Engaging with Artificial Intelligence' supply-chain guidance maps to the Authority Register.
AUSTRAC · TGA (acknowledged)
AUSTRAC AML/CTF obligations and TGA medical-device regulation are acknowledged Australian regulators on the coverage registry; their per-requirement bijection maps are staged for the next coverage wave alongside the active four above.
Australian-sovereign deployment
Australian data, Australian keys, Australian control.
Data residency — deploy to Australian-region edge runtime resources; per-tenant configurable; structured datastore + object store pinned to Australia.
Customer KMS — signing keys live in the customer's HSM or sovereign-cloud KMS; KYE™ never has access to the private key material.
Open verifier — APRA examiners, the OAIC, AUSTRAC and the customer's own auditors can replay an Evidence Pack™ using only the publisher's JWKS. No vendor dependency in the audit path.
Apache 2.0 schemas + vocabulary — the contracts the customer relies on are open. The patent-track runtime construction is paid; the proof formats are not.
Australian pilot · 6 weeks
KYE Australian Readiness Pilot™.
Australian banks, insurers, superannuation trustees and AI-deploying enterprises: a 6-week shadow-mode engagement producing APRA CPS 230 operational-risk control mapping per assertion, AI Guardrails accountability coverage, signed Evidence Packs™ per decision, and an APRA-ready executive summary with a residual-risk register.
Independent — no government affiliation. KYE Protocol™ is an independent protocol and is not affiliated with, endorsed by, or part of any government, regulator, or official “Sovereign AI” programme. References to regulators and frameworks describe the requirements KYE™ helps you evidence — not any official relationship.