Prove the consequential action was authorised.
Under the UK ECCTA Failure to Prevent Fraud offence — enforcement from 2027 — the statutory defence is reasonable procedures. For your counsel and your CISO, that defence is only as good as the evidence behind it. KYE Protocol™ proves who authorised the block, the warning or the reimbursement, that it was in scope, and that a regulator can replay it from public keys alone — cutting exam-prep from days to minutes.
Three UK pressures, one answer
Each new duty asks the same question of your firm: when an automated or agent process acted, who authorised it? KYE™ governs the authority over that intervention and proves it.
- Failure to Prevent Fraud (ECCTA, 2027) — corporate criminal liability with a reasonable-procedures defence. KYE™ turns each intervention into a signed, scoped, replay-provable record your counsel can put in front of the Serious Fraud Office. The defence, in evidence.
- APP reimbursement (PSR mandatory reimbursement) — for an Authorised Push Payment case, KYE™ proves who authorised the block, the warning or the reimbursement decision and lets the regulator replay it. Every reimbursement decision, accountable.
- Digital-identity abuse (the No.1 NRA emerging risk) — when an automated or agent process acts on a verified identity, KYE™ records on whose authority and within what scope. The action behind the identity, governed.
KYE Protocol™ governs the response, not the detection
For a head of financial crime, the gap is rarely the alert — it is proving the firm's response was authorised and defensible. KYE™ consumes the signals your existing tools produce and proves what your firm did next.
| Your fraud and identity stack does | KYE Protocol™ proves |
|---|---|
| Verifies identity and screens for fraud signals | That the firm's response to the signal was authorised by a named person, within scope, at the moment it happened |
| Flags an Authorised Push Payment as suspicious | Who authorised the block, warn or reimburse — and a Replay-Proof™ record a regulator verifies without trusting any vendor |
| Returns an IDV or fraud-intel score | That the consequential action taken on that score met the EU 6AMLD™ corporate-liability and FCA conduct duties, tied to the artefact that enforces each |
| Produces logs for an audit | The reasonable-procedures defence as replay-verifiable evidence — exam-prep measured in minutes, not days |
Boundary: KYE Protocol™ does not verify identity or detect fraud. Identity-verification and APP-fraud-intelligence vendors are adjacent layers KYE™ consumes — the way it already consumes Weights & Biases provenance — and turns into a governed, replay-provable record of the firm's authorised response. The intervention decision is what KYE™ governs.
Why authority, not another report
A reasonable-procedures defence built from screenshots and spreadsheets is argued; one built from signed evidence is proven. KYE™ puts the proof where it cannot be disputed.
- The defence binds to the action: the same sealed evidence serves the incident responder today and the regulator in 2027.
- Each intervention carries its named authoriser, its scope and its cited basis — the EU 6AMLD™ corporate-liability requirement met per action, not in an annual review.
- The authority record and its public-key proof do not depend on which IDV or fraud-intel vendor produced the signal that triggered it.