The KYE Protocol™ core is the same shape everywhere — Tenant · Workspace · Project · State Registry™ · PDP. Click a sector to see your entities and your state machines light up, pulled live from the open State Library™.
One protocol, every sector: the State Library™
Demo data
You learn: Which regulated lifecycle KYE™ already models for your sector, and what each state obliges you to evidence. You can: Switch sectors, pick a lifecycle, play it.
AI Inference Run Lifecycle NIST-AI-RMF-MEASURE · EU-AI-Act-Art-14 · EU-AI-Act-Art-15 · ISO-IEC-42001 · Apache-2.0
Lifecycle of a single (or batched) AI inference run with drift + safety controls. Aligned with NIST AI RMF MEASURE function and EU AI Act Art 14 (human oversight).
Queued
Inference request queued.
Capture input provenance + prompt envelope.
Executing
Model execution in progress.
Capture model id, version, inputs hash.
Quarantined
Output withheld pending human review.
Hand off to human reviewer.
Completed
Output delivered; logged for audit.
Persist output + safety classifier result.
Drift flagged
Drift / OOD detected; under review.
Record drift signal + window.
Replayed
Replayed on a corrected model / inputs.
Link to original run.
9 transitions
queued→executing · Execute
queued→quarantined · Hold output
executing→completed · Deliver output
executing→drift_flagged · Queue review
executing→quarantined · Hold output
drift_flagged→completed · Release output
drift_flagged→quarantined · Hold output
quarantined→replayed · Re execute
completed→replayed · Re execute
EU AI Act High-Risk System Lifecycle EU-AI-Act-Reg-2024-1689 · EU-AI-Act-Art-16 · EU-AI-Act-Art-17 · EU-AI-Act-Art-43 · Apache-2.0
Lifecycle of a High-Risk AI System under the EU AI Act. Covers design, conformity assessment, CE marking, market surveillance, recall and withdrawal. Aligned with Articles 16-29.
Design
System in design / development.
Operate Quality Management System per Art 17.
Risk management system per Art 9.
Data governance + bias controls per Art 10.
Conformity assessment
Conformity assessment in progress (internal or notified body).
conformity_assessment→design · Return for remediation
ce_marked→in_market · Go live
in_market→recall · Initiate recall
recall→in_market · Restore service
recall→withdrawn · Withdraw from market
in_market→withdrawn · Withdraw from market
AI Model Evaluation Lifecycle NIST-AI-RMF-1.0 · ISO-IEC-42001 · ISO-IEC-23894 · UK-AI-Safety-Institute-Approach · Apache-2.0
Lifecycle of an AI model evaluation against safety + capability benchmarks. Aligned with NIST AI RMF 1.0, ISO/IEC 42001, and emerging UK AISI / US AISI evaluation practice.
Proposed
Evaluation scope drafted.
Define benchmarks + threat model + success criteria.
Lifecycle of a confirmed prompt-injection / model-manipulation incident. Aligned with OWASP LLM Top-10 (LLM01), MITRE ATLAS, and EU AI Act Art 15 (cybersecurity).
Lifecycle for a corporate revolving / term credit facility. Covers proposal, underwriting, activation, drawdown, repayment, and exit paths including default and renegotiation. References Basel III…
Proposed
Facility term sheet drafted with borrower.
Capture indicative term sheet + pricing.
Underwriting
Credit committee underwriting in progress.
Compile credit memo with IFRS 9 staging.
Independent collateral valuation if secured.
Active
Facility live; commitment fee accruing on undrawn portion.
Monitor financial covenants quarterly.
Drawn
Facility partially or fully drawn.
Accrue interest + monitor LTV.
Repaid
Facility fully repaid + closed.
Renegotiated
Facility amended / restated.
Capture amendment + restatement docs.
Defaulted
Covenant breach or payment default; recovery handed off.
Lifecycle of a per-customer KYC check across CDD and EDD pathways. Aligned with US BSA, EU 5AMLD, and JMLSG guidance. Covers periodic refresh and triggered re-screen.
Pending
KYC initiated; documents requested from subject.
Issue document checklist (ID, proof of address, source of funds).
In progress
CDD running: ID verification + sanctions/PEP screen.
Lifecycle for onboarding a merchant onto an acquirer / payment processor. Covers KYB, MCC classification, underwriting, activation, and offboarding. Aligned with PSD2, scheme rules (Visa/Mastercard)…
Lifecycle of a patient consent record for processing of special-category health data. Aligned with HIPAA authorisation requirements and GDPR Art 9(2)(a) explicit consent.
Requested
Consent request issued to patient.
Issue consent form with purpose, retention, recipients.
Lifecycle of an electronic prescription from clinician order through administration. Aligned with HIPAA, GDPR Art 9 (special category data), and NHS Digital DCB0129/0160 clinical safety standards.
Lifecycle of a payer prior-authorisation request for a treatment / device. Aligned with CMS Interoperability and Prior Authorization rule (CMS-0057-F) and HIPAA X12 278.
Requested
PA request submitted by provider.
Persist 278 submission + clinical attachment.
Reviewing
Medical reviewer assessing necessity.
Apply InterQual / MCG criteria; document outcome.
Denied
PA denied; appeal rights communicated.
Issue denial with reason + appeal route.
Approved
PA approved for stated period / units.
Issue approval with authorisation number + expiry.
End-to-end insurance claim from FNOL through adjudication and payout. Covers triage, investigation, fraud detection, payment, and litigation pathways. Aligned with FCA ICOBS and EIOPA conduct…
Reported
First Notification of Loss (FNOL) received.
Capture FNOL with date, peril, policy ref.
Triage
Coverage + initial fraud screen.
Verify coverage in force at loss date.
Run anti-fraud scoring.
Investigation
Loss adjuster / SIU investigation.
Field adjuster report.
Photos, statements, police reports.
Denied
Claim denied; reason + appeal rights communicated.
Document denial reason + appeal route.
Fraud flagged
Fraud confirmed; referred to law enforcement / IFB.
Adjudicated
Claim decision recorded.
Issue ICOBS-compliant decision letter.
Litigation
Matter in litigation; reserves under Solvency II.
Hold IBNR / litigation reserve.
Paid
Indemnity settled to policyholder / third party.
12 transitions
reported→triage · Open claim case
triage→investigation · Assign adjuster
triage→denied · Issue denial
triage→fraud_flagged · Escalate to siu
investigation→adjudicated · Record decision
investigation→fraud_flagged · Refer law enforcement
Lifecycle of an insurance underwriting case from submission through decision. Aligned with EIOPA POG (Product Oversight Governance) and Solvency II risk classification.
Submitted
Submission received from broker / direct.
Persist submission + scheme classification.
Reviewing
Underwriter assessing risk + pricing.
Document risk factors + scoring.
Log referrals to senior underwriting if exceeds authority.
Approved
Risk accepted; quote issued.
Declined
Risk declined; reason recorded.
Document decline reason (EIOPA POG).
Referred
Referred to senior / reinsurer.
Capture reinsurer query + response if required.
6 transitions
submitted→reviewing · Assign underwriter
reviewing→approved · Issue quote
reviewing→declined · Issue decline
reviewing→referred · Refer to senior
referred→approved · Issue quote
referred→declined · Issue decline
Bill of Lading Lifecycle (UCP 600) ICC-UCP-600 · ICC-eUCP-2.1 · UNCITRAL-MLETR · Hague-Visby-Rules · Apache-2.0
Lifecycle of a (potentially electronic) bill of lading from issuance through endorsement and consumption under letters of credit. Aligned with UCP 600, eUCP, and MLETR.
Lifecycle for an outbound payout to a beneficiary bank account. Covers queueing, execution against rail (SEPA / FPS / ACH / SWIFT), settlement, and return paths.
Lifecycle of an Individual Case Safety Report (ICSR) from intake through regulator submission. Aligned with ICH E2B(R3), EMA EudraVigilance, and FDA FAERS.
Lifecycle of a manufactured pharmaceutical batch from production through dispense / recall. Aligned with EU/US GMP, FDA 21 CFR Part 11 electronic records, FMD serialisation.
Manufactured
Batch produced; awaiting QC release.
Compile executed batch record per 21 CFR 211.188.
Qc passed
QP / QA certified release.
QP signature releasing the batch.
Serialise to FMD / DSCSA pack level.
Quarantined
Batch held pending investigation.
Document quarantine trigger.
Shipped
In transit through supply chain.
Monitor cold-chain excursions.
Recalled
Batch recalled by manufacturer / authority.
Execute recall notice + reverse logistics.
Disposed
Batch destroyed per controlled-substance / hazardous-waste rules.
Capture destruction certificate.
Received
Received at wholesaler / pharmacy.
Verify FMD/DSCSA pack-level scan on receipt.
Dispensed
Dispensed to patient; decommissioned in EMVS / DSCSA.
Lifecycle of a Suspicious Transaction / Activity Report from internal alert through FIU submission. Aligned with EU 5AMLD/6AMLD and FATF Recommendation 20.
Flagged
Internal alert raised by monitoring / staff.
Persist alert with model id + features.
Reviewing
MLRO / financial intelligence team reviewing.
Document investigation steps + rationale.
Reported to fiu
STR/SAR filed with FIU; tipping-off rules applied.
Lifecycle of an ICT third-party provider under EU DORA. Covers onboarding, criticality assessment, ongoing monitoring, and exit. Aligned with DORA Art 28-30 and the RTS on register of information.
Onboarded
Provider contracted; register entry created.
Populate Register of Information per RTS.
Assessed
Risk + concentration assessment in progress.
Pre-contract risk assessment per Art 28(4).
Tier classified
Classified as supporting critical / important function (CIF) or not.
Document CIF classification.
Monitored
Ongoing monitoring + testing in place.
Track service KRIs.
Participate in TLPT for CIF providers ≥ threshold.
Lifecycle of a significant cyber incident under EU NIS2. Covers detection, early warning, intermediate + final report to CSIRT/CA, containment, and post-mortem.