Regulatory coverage

Every framework. One honest coverage map.

KYE Protocol™ maps to 249 regulatory frameworks, decomposed into 853 requirement groups. 446 are Enforced at runtime, 254 Designed and in build, 153 Out of scope. Every number here is computed from a single schema-backed registry — change the registry, the page regenerates.

Coverage by jurisdiction

Demo data

You learn: Where KYE™ coverage is active, staged or planned. You can: Pick a stage.

Global / jurisdiction-neutral · 5 frameworks✓——
International (ISO / IEC) · 5 frameworks✓——
United Kingdom · 19 frameworks✓——
United States · 17 frameworks✓——
European Union · 9 frameworks✓——
Gulf region (GCC) · 4 frameworks✓——
Public sector (cross-jurisdiction) · 4 frameworks✓——
Canada · 16 frameworks✓——
Australia · 4 frameworks✓——
New Zealand · 3 frameworks✓——
Singapore · 3 frameworks✓——
Japan · 3 frameworks✓——
India · 6 frameworks—✓—
Brazil——✓
China (PRC) · 1 frameworks——✓
Switzerland · 1 frameworks✓——
Hong Kong——✓
Germany · 5 frameworks✓——
France · 5 frameworks✓——
Italy · 5 frameworks✓——
Spain · 5 frameworks✓——
Netherlands · 5 frameworks✓——
Belgium · 5 frameworks✓——
Luxembourg · 5 frameworks✓——
Poland · 5 frameworks✓——
Sweden · 5 frameworks✓——
Norway · 5 frameworks✓——
Denmark · 5 frameworks✓——
Finland · 5 frameworks✓——
Austria · 5 frameworks✓——
Ireland · 5 frameworks✓——
Portugal · 5 frameworks✓——
Greece · 5 frameworks✓——
Czech Republic · 5 frameworks✓——
Hungary · 5 frameworks✓——
Romania · 5 frameworks✓——
Slovakia · 5 frameworks✓——
Bulgaria · 5 frameworks✓——
Cyprus · 5 frameworks✓——
Malaysia · 1 frameworks—✓—
United Arab Emirates · 1 frameworks—✓—
Bahrain · 1 frameworks—✓—
Saudi Arabia · 1 frameworks—✓—
Indonesia · 1 frameworks—✓—
Pakistan · 1 frameworks—✓—
Qatar · 1 frameworks—✓—
Kuwait · 1 frameworks—✓—
Oman · 1 frameworks—✓—
Türkiye · 1 frameworks—✓—
Nigeria · 1 frameworks—✓—
Brunei Darussalam · 1 frameworks—✓—
Jordan · 1 frameworks—✓—
Egypt · 1 frameworks—✓—
Sudan · 1 frameworks—✓—
Thailand——✓
How this widget is built
Demonstrates
Coverage Atlas
Components
  • Jurisdiction dictionary (stages)
  • Framework registry
Flow
Jurisdiction → stage → frameworks. Architecture diagram
Used on

How to read this map

Three honest states — no checkbox theatre.

Every requirement group below carries exactly one of these states. A group is only marked Enforced when runtime code and a CI gate back it — so a customer’s audit team can sign with the right residual-risk register.

Enforced

Live runtime code enforces this requirement, and a CI gate verifies it on every release.

Designed

Schema, contract, and acceptance criteria are locked; the runtime implementation is in build and tracked in the implementation plan.

Out of scope

Not discharged by KYE Protocol™ — owned by the customer's own systems, processes, or counsel. KYE™ is an evidence layer, not a replacement for these controls.

The coverage-maturity ladder

How far each control has climbed — mapped to certified.

Tri-state tells you whether KYE Protocol™ owns a control. The maturity ladder tells you how far it has climbed — from merely mapped, through designed and enforceable, to evidence-backed and certified. A row only claims evidence-backed or certified when a real Evidence Pack™ or assessor artefact backs it; a CI gate rejects any inflated claim. This is the per-control axis — orthogonal to where KYE Protocol™ ships SKUs by jurisdiction.

L1 Mapped (156)

KYE Protocol™ has mapped the obligation/control: the framework requirement is decomposed and crosswalked to the KYE Protocol™ control vocabulary, but no design, runtime check, evidence, or certification is asserted at this level.

L2 Designed (248)

KYE Protocol™ has a profile / control design for the obligation: schema, contract, and acceptance criteria are locked and tracked in the implementation plan, but the runtime enforcement is in build.

L3 Enforceable (449)

KYE Protocol™ can enforce the obligation via live runtime checks (a Decision Engine / Authority Gate path or a CI gate that fails closed). A claim at this level must resolve to a real runtime control or gate.

L4 Evidence-backed (0)

KYE Protocol™ generates a signed Evidence Pack™ for the obligation — the enforcement decision is captured as a replayable, third-party-verifiable artefact. A claim at this level must resolve to a real Evidence Pack™ example on disk (honest-floor rule).

L5 Certified (0)

An external KYE™ Seal™ / accredited-assessor review is available for the obligation. The top of the ladder: a buyer can point at an independent assessment, not just KYE Protocol™'s own evidence. A claim at this level must resolve to a real seal / assessor artefact on disk (honest-floor rule).

Coverage by framework

Every framework, decomposed and marked.

Filter by state to see exactly where KYE Protocol™ enforces today, where it is in build, and where the customer owns the control.

AI governance

Frameworks that govern the lifecycle, oversight, and accountability of AI systems and AI agents.

AI-CAIQ

AI-CAIQ (STAR-for-AI self-assessment)

1.0 · International

The CSA AI Consensus Assessments Initiative Questionnaire is the self-assessment companion to the AICM and the basis for CSA STAR-for-AI listings. KYE™ generates each answer it can satisfy from runtime evidence (a KYE™ artefact + a §0.3 evidence event), and marks questions outside its execution scope as not applicable — never fabricated.

1

Enforced

0

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Questionnaire answers generated from replay-provable runtime evidenceEnforcedL3 EnforceableAI-CAIQ (KYE-resolvable questions)Evidence Pack™Decision Map™Replay-Proof™
Out-of-scope questions marked not applicableInfrastructure, training-pipeline and internal model-validation questions are not applicable to the KYE™ execution-layer scope. Marked honestly, never fabricated.Out of scopeL1 MappedAI-CAIQ (infrastructure / model-training questions)—

AI Solutions Framework

AI Solutions Framework — Enterprise AI-Adoption Control Framework (IG1–IG3)

1.0 · International

The AI Solutions Framework is an enterprise AI-adoption control framework (~90 safeguards across AI governance & accountability, risk management, AI safety, data privacy/lineage, compliance monitoring, and audit & evidence; IG1–IG3 maturity). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the KYE™ AI Solutions Framework Authority Pack™ (§70 honesty bar). Frameworks define what should happen; KYE Protocol™ resolves who may make it happen, under what authority, and proves it later. The organisational safeguards (governance board, AI inventory, policy authorship, training, risk committee) and the deploy-time infrastructure-posture / CSPM safeguards (model-logging, encryption, IAM least-privilege, network egress) are honestly out of scope and ceded to their owning roles. KYE Protocol™ complements a deploy-time posture/CSPM layer — coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.

3

Enforced

0

Designed

2

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
AI governance & accountability — action-boundary authority (enforced)EnforcedL3 Enforceableai-solutions-framework.approval-workflow-authority, ai-solutions-framework.accountability-named-principalAction Admissibility™ GateAuthority Finality™Evidence Pack™
AI risk management & safety — attestation + human-oversight stage gate (enforced)EnforcedL3 Enforceableai-solutions-framework.attestation-due-diligence-before-action, ai-solutions-framework.human-oversight-stage-gateAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Compliance monitoring & audit/evidence — exception register + provenance pin (enforced)EnforcedL3 Enforceableai-solutions-framework.exception-register, ai-solutions-framework.audit-evidence-provenance-pinEvidence Pack™Replay-Proof™Audit WORM
Organisational safeguards (out of scope — governance-office / CISO)Out of scopeL1 Mappedai-solutions-framework.ai-governance-board, ai-solutions-framework.ai-system-inventory, ai-solutions-framework.ai-acceptable-use-policy, ai-solutions-framework.ai-workforce-training, ai-solutions-framework.ai-risk-committee-review—
Infrastructure posture / CSPM safeguards (out of scope — cloud-platform / devsecops; complemented by KYE Protocol™)Out of scopeL1 Mappedai-solutions-framework.model-inference-logging-enabled, ai-solutions-framework.ai-data-storage-encryption, ai-solutions-framework.ai-iam-least-privilege, ai-solutions-framework.ai-network-egress-posture—

AICM Resolution

CSA AI Controls Matrix (AICM)

1.0 · International

The Cloud Security Alliance AI Controls Matrix defines 243 control objectives across 18 domains. AICM defines the controls. KYE™ operationalises them — proving how each control resolved at the moment a consequential AI action occurred. KYE™ binds the execution-resolvable domains and is honest about the infrastructure and model-training domains it does not touch.

6

Enforced

0

Designed

1

Out of scope

7 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Identity & access management — authority at the moment of actionEnforcedL3 EnforceableIAM, AACPurpose Permission™Authority GateDelegated-agent binding
Governance, risk & compliance — human oversight + recurring attestationEnforcedL3 EnforceableGRCGovernedUI human-control surface≤90-day compliance attestation
Logging & monitoring — signed evidence + decision map per actionEnforcedL3 EnforceableLOGEvidence Pack™Decision Map™WORM audit hash-chain
Model risk & resilience — replay-provable from public keysEnforcedL3 EnforceableMRM (action-resolution slice)Replay-Proof™Context seal
Supply chain & transparency — provenance pinned in evidenceEnforcedL3 EnforceableSTATool-call pinEvidence Pack™
Application-interface + data-lifecycle admissibility at the boundaryThe deny-by-default action-boundary and moment-of-use data admissibility contracts are locked; per-interface and per-asset runtime wiring is in build.EnforcedL3 EnforceableAIS, DSPPolicy Enforcement PointData-use PDP stage
Cloud infrastructure security + model-training & internal model validationCloud-fabric hardening is operated by the cloud service provider; training-pipeline security and internal model validation are owned by the model developer. KYE™ governs how a model's actions resolve at run time and records them — it does not operate the infrastructure or train the model.Out of scopeL1 MappedIVS, TVM, MRM (model-internals slice)—

AIDA

AIDA — Artificial Intelligence and Data Act (Bill C-27, federal)

Bill C-27 Part 3 (tabled, lapsed Jan 2025) · Canada

Canada's proposed federal AI law (AIDA, Part 3 of Bill C-27). The bill lapsed on prorogation in January 2025 and is NOT in force — mapped as a forward-looking design anchor (all rows advisory): high-impact assessment, risk mitigation + monitoring, record-keeping, transparency, and serious-harm notification. Per-requirement bijection at /compliance/aida.html.

0

Enforced

5

Designed

0

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
High-impact system assessment (s.7)DesignedL2 Designeds7Risk Engine
Risk mitigation + monitoring (s.8-9)DesignedL2 Designeds8Drift DetectorRisk Engine
Record-keeping (s.10)DesignedL2 Designeds10WORM audit hash-chain
Transparency / publication (s.11)DesignedL2 Designeds11Reporting Engine
Serious-harm notification (s.12)DesignedL2 Designeds12Incident DetectorReporting Engine

AU AI Guardrails

Australian Government Mandatory AI Guardrails

DISR 2024 (10 guardrails) · Australia

The 10 mandatory AI guardrails proposed by the Department of Industry, Science and Resources (Sept 2024) + the Voluntary AI Safety Standard. Per-requirement bijection at /compliance/au-ai-guardrails.html.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Accountability, risk management & data governance (G1-G3)EnforcedL3 EnforceableGuardrail 1, Guardrail 2, Guardrail 3Purpose Permission™Risk EngineData Classification EngineEvidence Pack™
Testing, human oversight, transparency & contestability (G4-G7)EnforcedL3 EnforceableGuardrail 4, Guardrail 5, Guardrail 6, Guardrail 7Conformance RunnerDrift DetectorGovernedUI™Decision Map™Replay-Proof™
Supply-chain transparency & record-keeping (G8-G9)EnforcedL3 EnforceableGuardrail 8, Guardrail 9Authority RegisterWORM audit hash-chainEvidence Pack™
Stakeholder engagement (G10)Process-and-policy obligation owned by the customer's governance function; KYE™ records that engagement occurred but does not perform it.Out of scopeL1 MappedGuardrail 10—

BSI AIC4

BSI AIC4 — AI Cloud Service Compliance Criteria

2021 · Germany

The German Federal Office for Information Security (BSI) AI Cloud Service Compliance Criteria Catalogue (AIC4) — one of the frameworks the CSA AICM crosswalks to. KYE™ binds the security-and-robustness criteria that resolve at action time and marks the cloud-platform operational criteria out of scope.

2

Enforced

0

Designed

1

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Security & robustness of AI decisions — evidenced at action timeEnforcedL3 EnforceableAIC4 Security & Robustness, AIC4 ReliabilityEvidence Pack™Replay-Proof™Purpose Permission™
Performance, bias mitigation & explainability of the AI decision recordThe decision-record contract that backs explainability and the action-level audit is locked; the per-criterion runtime surface is in build.EnforcedL3 EnforceableAIC4 Performance & Functionality, AIC4 Bias, AIC4 ExplainabilityDecision Map™
Cloud-platform operations, data centre & training-environment criteriaCloud-platform operations and the model-training environment are operated by the cloud service provider and the model developer, not by KYE™. Out of scope (§0 honest scope).Out of scopeL1 MappedAIC4 Data Management (training), AIC4 Operations—

EC-Council ADG

EC-Council ADG — Adopt · Defend · Govern

2026 · Global

35 requirements across three pillars (Adopt / Defend / Govern), nine governance surfaces, twelve minimum controls (MC-1..MC-12), and three autonomy tiers (HITL / HOTL / HOOTL). Complementary to KYE Protocol™: ADG = operating model, KYE Protocol™ = runtime authority proof.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Pillar 1 — Adopt (10 requirements covering lifecycle, capability, risk, secure deployment, change, evidence, purpose grant, training, acceptable use, assurance baseline)EnforcedL3 EnforceableADG/AdoptModel capability profileRisk assessmentPurpose Permission™ grant issuanceAdoption evidence packInitial compliance attestation
Pillar 2 — Defend (10 requirements covering threat-model, red-team, runtime monitoring, tool/MCP register, prompt-injection defence, supply chain, incident response, SPOF, federation, continuous attestation)EnforcedL3 EnforceableADG/DefendKYE™ Tool & MCP Authority Register™Tool call pin (side-effect binding)Drift signal familyReplay-Proof™ envelopeSPOF registryFederation cross-org delegationCompliance attestation cadence
Pillar 3 — Govern (15 requirements covering authority register, purpose grant, admissibility, evidence pack, decision map, replay-proof, Authority Finality™, human oversight, autonomy tiers, MC-1..MC-12, decision rights, board reporting)EnforcedL3 EnforceableADG/Govern, ADG/MC-1..MC-12Purpose Permission™Action Admissibility™ GateDecision Map™Evidence Pack™Replay-Proof™Authority Finality™GovernedUI™ critical-point reviewKYE Autonomy Tiers™ (A0-A3)KYE™ Minimum Authority Controls™ (KAC-1..KAC-12)

EEOC Uniform Guidelines

EEOC Uniform Guidelines on Employee Selection Procedures

1978 (29 CFR Part 1607) · United States

US federal guidelines defining the four-fifths adverse-impact rule and the validation duty for selection procedures.

1

Enforced

1

Designed

0

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Four-fifths adverse-impact ruleEnforcedL3 Enforceable29 CFR §1607.4(D)Evidence Pack™Authority Gate
Validation of selection proceduresDesignedL2 Designed29 CFR §1607.5Delegated Auditability Rail

EU AI Act

EU AI Act — Artificial Intelligence Regulation

Regulation (EU) 2024/1689 · European Union

EU regulation setting lifecycle obligations for high-risk AI systems.

4

Enforced

1

Designed

1

Out of scope

6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Risk-management systemEnforcedL3 EnforceableArt. 9Purpose Permission™Authority Gate
Data & data governanceEnforcedL3 EnforceableArt. 10Purpose Permission™WORM audit hash-chain
Record-keeping & traceabilityEnforcedL3 EnforceableArt. 12, Art. 72WORM audit hash-chainDecision replay
Human oversightEnforcedL3 EnforceableArt. 14WebAuthn step-upAuthority Gate
Transparency & provision of informationTransparency receipts are emitted today; the detached signatures that make them verifiable downstream are in build.DesignedL2 DesignedArt. 13, Art. 50Decision Map™ signing (JWS-detached)Evidence Pack™ signing (COSE-Sign1)
Annex IV technical documentationKYE™ produces operational evidence; the static Annex IV technical-documentation file is authored separately.Out of scopeL1 MappedArt. 11—

EU AI Act Art 50

EU AI Act — Article 50 chatbot transparency

2024/1689 · European Union

Article 50 of Regulation (EU) 2024/1689 requires natural persons be informed they are interacting with an AI system, plus related transparency record-keeping. KYE Protocol™ governs the ENFORCEMENT AUTHORITY + EVIDENCE of the Article 50 chatbot disclosure at the action boundary — consumed by the KYE™ Chatbot Authority Pack™. The broader Regulation is covered by the eu-ai-act registry; this is the narrow chatbot-transparency execution slice. Per-requirement bijection at framework-coverage-bijection.

2

Enforced

0

Designed

1

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Art 50 — AI-interaction disclosureEnforcedL3 Enforceableeu-ai-act-chatbot-transparency.art50-chatbot-disclosure-enforcementAction Admissibility™ GateAuthority Finality™
Art 50 — transparency record-keepingEnforcedL3 Enforceableeu-ai-act-chatbot-transparency.art50-transparency-record-keepingEvidence Pack™Replay-Proof™WORM Retention
Disclosure UX & AI Act conformity program (out of scope)Model vendor / operator responsibility — disclosure UX/copy and the broader AI Act conformity program. Zero KYE™ controls (complement-not-compete).Out of scopeL1 Mappedeu-ai-act-chatbot-transparency.disclosure-ux-and-conformity-program—

FDA / EMA AI

FDA + EMA — AI / Provenance Expectations for AI-Derived Regulated Candidates

2024-2025 · US / EU

FDA + EMA AI / provenance expectations for AI-derived candidates entering regulated drug/device pipelines — documented provenance, reproducibility, and GxP data integrity (ALCOA+). KYE Protocol™ governs whether an AI-derived candidate may proceed to a regulated stage, binding replay-provable provenance — the KYE™ AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
AI design provenance & reproducibilityDesignedL2 Designedfda-ema.design-provenance, fda-ema.reproducibilityAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
GxP data integrity (ALCOA+)DesignedL2 Designedfda-ema.gxp-data-integrityAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Human oversight & accountabilityDesignedL2 Designedfda-ema.human-accountabilityAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™

OECD AI Principles

OECD AI Principles — Recommendation of the Council on Artificial Intelligence

OECD/LEGAL/0449 (2019, updated 2024) · International

The OECD Recommendation of the Council on Artificial Intelligence (OECD/LEGAL/0449) sets five value-based principles for trustworthy AI — inclusive growth & well-being; human-centred values & fairness; transparency & explainability; robustness, security & safety; and accountability — and is the reference standard behind the G7 Hiroshima Process and many national AI strategies. This framework is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: although several principles crosswalk to existing KYE Protocol™ rails (transparency/explainability → §0.3 evidence & §13 Replay-Proof™; accountability → §21 Audit Pilot™ & §52 agent binding; robustness/safety → §13 Resilience Loop™; human-centred/fairness → §36 GovernedUI™ human-in-the-loop), no requirement has yet been bound at the requirement level. Per the §70 honesty bar, coverage is reported out of scope pending deep mapping rather than claimed as enforced.

0

Enforced

0

Designed

1

Out of scope

1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): candidate crosswalks to §0.3 / §13 / §21 / §36 / §52 are noted in the summary but NOT yet bound at the requirement level, so coverage stays out of scope until the deep mapping runs through the §70 rail — never inflated to imply enforcement that does not exist.Out of scopeL1 MappedOECD AI Principles (five value-based principles — not yet decomposed into requirement-level mappings)—

IMDA MGF (Agentic AI)

IMDA Model AI Governance Framework for Agentic AI

v1.5 (20 May 2026, updated 5 June 2026) · Singapore

Singapore IMDA's Model AI Governance Framework for Agentic AI (v1.5) sets expectations across four dimensions: (1) assess and bound the risks upfront; (2) make humans meaningfully accountable; (3) implement technical controls and processes; (4) enable end-user responsibility. This framework is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: although every dimension crosswalks cleanly to existing KYE Protocol™ rails (bound risk upfront → entity/principal identity + §52 agent binding + Purpose Permission™ §12; meaningful human accountability → §36 GovernedUI™ approval modes + Finality Gate; technical controls → §13 Evidence Pack™ / Replay-Proof™ + §34 monitoring; end-user responsibility → §17 Directory + §21 Audit Pilot™), no requirement has yet been bound at the requirement level. Per the §70 honesty bar, coverage is reported out of scope pending deep mapping rather than claimed as enforced.

0

Enforced

0

Designed

1

Out of scope

1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): the four-dimension crosswalk to KYE™'s entity/§52 / §36 Finality / §13 Evidence+Replay / §17+§21 rails is noted in the summary but NOT yet bound at the requirement level, so coverage stays out of scope until the deep mapping runs through the §70 rail — never inflated to imply enforcement that does not exist.Out of scopeL1 MappedIMDA MGF for Agentic AI — four governance dimensions (not yet decomposed into requirement-level mappings)—

Frontier Bio-Safeguard Eval

Common Standard for Evaluating Frontier AI Safeguards against Biological Misuse

technical report, June 2026 · International

A proposed common standard (GovAI/OpenAI, June 2026) for evaluating frontier-AI safeguards against biological misuse: seven recommendations across four principles (comparability across companies; account for the deployment environment; treat safeguards as dynamic; preserve legitimate scientific use) plus a three-layer safeguard stack — access (who can use the model), inference (how harmful queries are handled), platform (post-hoc misuse detection) — combined into composite safeguard levels calibrated to threat actor. This standard is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: it crosswalks to KYE™'s genomics-biosecurity Authority Pack™ + Genetic Sequencing Authority Agent™ (action-boundary admissibility + sequence-of-concern screening) and to §52 access controls + §13 Evidence Pack™, but no requirement is bound at the requirement level. Per the §70 honesty bar, coverage is reported out of scope pending deep mapping. NOTE: this standard evaluates MODEL-LEVEL safeguards; KYE™ governs the ACTION boundary — complementary, not the same control.

0

Enforced

0

Designed

1

Out of scope

1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): crosswalk to the genomics-biosecurity pack + §52/§13 noted in the summary but NOT requirement-bound. The standard evaluates model-level safeguards; KYE™ governs the action boundary — coverage stays out of scope until deep mapping, never inflated.Out of scopeL1 MappedSeven recommendations + three-layer safeguard stack (not yet decomposed into requirement-level mappings)—

AI Verify

IMDA AI Verify

AI Verify Foundation · Singapore

IMDA / AI Verify Foundation testing framework — transparency, accountability, human agency & oversight, robustness. Per-requirement bijection at /compliance/imda-ai-verify.html.

2

Enforced

0

Designed

0

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Transparency + accountabilityEnforcedL3 EnforceableAI Verify — transparency, AI Verify — accountabilityDecision Map™Evidence Pack™Purpose Permission™
Human agency & oversight + robustnessEnforcedL3 EnforceableAI Verify — human agency, AI Verify — robustnessGovernedUI™Authority GateConformance RunnerDrift Detector

ISO 42001

ISO/IEC 42001 — AI Management System

2023 · International

Management-system standard for the responsible development and use of AI.

3

Enforced

1

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
AI policy & objectivesEnforcedL3 EnforceableClause 5-6Purpose Permission™Authority Gate
Operational AI controls & impact assessmentEnforcedL3 EnforceableClause 8, Annex A.6Purpose Permission™WORM audit hash-chain
Performance evaluation & audit trailEnforcedL3 EnforceableClause 9WORM audit hash-chainDecision replay
Signed AI-system lifecycle evidenceLifecycle events are recorded in the audit chain today; signed lifecycle evidence packs are in build.DesignedL2 DesignedAnnex A.6.2Evidence Pack™ signing (COSE-Sign1)

MAS FEAT

MAS FEAT Principles

2018 + Veritas methodology & toolkit · Singapore

MAS Principles to promote Fairness, Ethics, Accountability and Transparency (FEAT) in the use of AI and data analytics in Singapore's financial sector, together with MAS Veritas — the MAS-convened consortium's companion FEAT assessment methodology (phased methodology documents, 2020-2022) and open-source Veritas Toolkit (v2.0, 2023). Veritas is canonicalised inside this framework entry rather than as a standalone framework. Per-requirement bijection at /compliance/mas-feat.html.

2

Enforced

0

Designed

0

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Fairness + ethicsEnforcedL3 EnforceableFEAT — fairness, FEAT — ethicsRisk EngineDecision Map™Purpose Permission™Authority Gate
Accountability + transparencyEnforcedL3 EnforceableFEAT — accountability, FEAT — transparencyReplay-Proof™Regulator Replay agentEvidence Pack™Decision Map™

MAS MindForge

MAS Project MindForge — AI Risk Management: Operationalisation Handbook

2024 · Singapore

MAS Project MindForge's AI Risk Management: Operationalisation Handbook gives Singapore financial institutions practical guidance for operationalising AI risk management across four blocks (Scope & AI Oversight, AI Risk Management, AI Lifecycle Management, Enablers; 17 considerations). KYE Protocol™ operationalises the action-boundary subset at runtime — it does NOT replace MindForge (§0.25 integrate-not-compete). KYE™ governs whether a consequential financial AI action is authorised, within the human-oversight mode the FI declared for that use, evidenced, contestable, and final at the moment it happens — and proves the basis, replayable by MAS or internal audit. Honest scope: KYE™ does not govern the FI's governance operating model, model-development methodology, or the correctness of the AI's output. Per-requirement bijection at /compliance/mas-mindforge.html.

0

Enforced

4

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Scope & AI oversight (oversight modes machine-enforceable + AI action-authority inventory)Downgraded 2026-09-03 (§70 honesty bar): every per-requirement control mapped for this framework is still Designed, not Enforced, so an 'enforced' group status was a hand-authored claim no control verifies. Restored to 'enforced' only when the deep-store rollup earns it.DesignedL2 Designedmas-mindforge.oversight-modes-machine-enforceable, mas-mindforge.action-authority-inventoryGovernedUI™ approval modesPurpose Permission™Authority GateEntity & Principal Registry
AI risk management (escalation before finality + third-party / vendor AI authority register)Downgraded 2026-09-03 (§70 honesty bar): every per-requirement control mapped for this framework is still Designed, not Enforced, so an 'enforced' group status was a hand-authored claim no control verifies. Restored to 'enforced' only when the deep-store rollup earns it.DesignedL2 Designedmas-mindforge.escalation-before-finality, mas-mindforge.third-party-vendor-authority-registerAuthority Gateway (REQUIRE_APPROVAL)Edge Governance Safety FloorAuthority RegisterGovernedUI™ escalation
AI lifecycle management (deployment controls at the Authority Gateway + monitoring/change as replay-provable Evidence Packs)KYE™ enforces approved deployment conditions + replay-provable monitoring/change evidence at the action boundary; the FI's pre-deployment validation and model-performance monitoring stay the FI's own (honest scope). Downgraded 2026-09-03 (§70 honesty bar): every per-requirement control mapped for this framework is still Designed, not Enforced, so an 'enforced' group status was a hand-authored claim no control verifies. Restored to 'enforced' only when the deep-store rollup earns it.DesignedL2 Designedmas-mindforge.deployment-controls-authority-gateway, mas-mindforge.monitoring-change-evidence-replayAuthority GatewayEvidence Pack™Replay-Proof™WORM audit hash-chain
Enablers (named accountability at the action boundary)KYE™ binds and proves named accountability at the boundary; staffing and running the three-lines-of-defence operating model stays the FI's own (honest scope). Downgraded 2026-09-03 (§70 honesty bar): every per-requirement control mapped for this framework is still Designed, not Enforced, so an 'enforced' group status was a hand-authored claim no control verifies. Restored to 'enforced' only when the deep-store rollup earns it.DesignedL2 Designedmas-mindforge.enablers-named-accountabilityGovernedUI™ named-authority sign-offDelegated Auditability RailAuthority Finality™

NIST AI RMF

NIST AI Risk Management Framework

1.0 · United States

Voluntary framework for managing AI risk across the Govern, Map, Measure, and Manage functions.

3

Enforced

1

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Govern functionEnforcedL3 EnforceableGOVERNPurpose Permission™Authority Gate
Map & Measure functionsEnforcedL3 EnforceableMAP, MEASUREPurpose Permission™WORM audit hash-chain
Manage function & incident responseEnforcedL3 EnforceableMANAGEWORM audit hash-chainDecision replay
Independently verifiable measurement evidenceMeasurement outcomes are recorded today; signed, externally verifiable measurement evidence is in build.DesignedL2 DesignedMEASURE 2.xEvidence Pack™ signing (COSE-Sign1)

NYC Local Law 144

NYC Local Law 144 — Automated Employment Decision Tools

2023 (in force 2023-07-05) · United States (New York City)

NYC law requiring a bias audit before an automated employment decision tool screens a candidate, with candidate notice and published results.

1

Enforced

1

Designed

0

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
AEDT bias auditEnforcedL3 EnforceableNYC Admin Code §20-871Evidence Pack™Authority Gate
Candidate notice & contestabilityDesignedL2 DesignedNYC Admin Code §20-871(b)Rights-Disputes Rail

NZ Algorithm Charter

NZ Algorithm Charter for Aotearoa New Zealand

2020 · New Zealand

Algorithm Charter for Aotearoa New Zealand (2020) — transparency, human oversight, and data/bias commitments for government use of algorithms. Per-requirement bijection at /compliance/nz-algorithm-charter.html.

2

Enforced

0

Designed

0

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Transparency + human oversightEnforcedL3 EnforceableCharter — transparency, Charter — human oversightDecision Map™Evidence Pack™GovernedUI™Replay-Proof™
Data clarity + bias managementEnforcedL3 EnforceableCharter — data and biasData Classification EngineRisk Engine

TBS ADM Directive

TBS Directive on Automated Decision-Making (Canada federal government)

TBS (amended 2023) · Canada

The Treasury Board Directive on Automated Decision-Making governing Canadian federal-government automated decision systems: the Algorithmic Impact Assessment, transparency notice, meaningful explanation, and quality-assurance + recourse. Per-requirement bijection at /compliance/tbs-directive-adm.html.

4

Enforced

0

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Algorithmic Impact AssessmentEnforcedL3 EnforceableaiaRisk Engine
Transparency noticeEnforcedL3 EnforceablenoticeReporting Engine
Meaningful explanationEnforcedL3 EnforceableexplanationDecision Map™Replay-Proof™
Quality assurance + recourseEnforcedL3 EnforceablerecourseReporting EngineWORM audit hash-chain

UK AI Assurance

UK AI Assurance (DSIT)

Introduction to AI Assurance, Feb 2024 · United Kingdom

The UK government's AI assurance toolkit — the measure / evaluate / communicate loop and the six assurance mechanisms that operationalise the UK AI principles. KYE Protocol™ is itself an assurance mechanism: it measures every governed AI action, evaluates it against purpose admissibility, and communicates it as signed, replayable evidence.

5

Enforced

1

Designed

1

Out of scope

7 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Measure, evaluate & communicate (the assurance loop)Every governed AI action is measured, evaluated against the purpose grant, and communicated as a signed Evidence Pack™ — assurance as a continuous runtime loop, not a point-in-time review.EnforcedL3 Enforceable§4.1WORM audit hash-chainEvidence Pack™Decision Map™
Risk assessmentEvery agent action is admitted against a risk-scoped purpose grant before it runs; disallowed actions never execute.EnforcedL3 Enforceable§4.2, §5.4Purpose Permission™Authority Gate
Algorithmic impact assessmentEach decision's inputs and downstream effects are recorded in a Decision Map™; a per-deployment aggregate impact view is in build.DesignedL2 Designed§4.2, §5.5Decision Map™Evidence Pack™
Bias auditBias and fairness assessment of model outputs is owned by the customer's model-evaluation process — consistent with the UK AI Framework fairness principle.Out of scopeL1 Mapped§4.2, §5.6—
Compliance auditAdherence to internal policy and regulation is continuously reviewable against the tamper-evident, append-only audit chain.EnforcedL3 Enforceable§4.2, §5.7WORM audit hash-chainControl mappings
Conformity assessmentThe KYE™ Conformance Pack™ is the test suite a conformity-assessment body runs; third-party UKAS-accredited certification remains external to the protocol.EnforcedL3 Enforceable§4.2, §5.8Conformance Pack™
Formal verificationReplay-Proof™ is a deterministic, cryptographically-verifiable re-execution — a governed decision can be mathematically re-checked from public keys alone.EnforcedL3 Enforceable§4.2, §5.9Replay-Proof™Decision replay

UK AI

UK AI Regulatory Framework

2023 white paper · United Kingdom

The UK's pro-innovation AI principles and the DSIT AI assurance toolkit.

3

Enforced

1

Designed

1

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Safety, security & robustnessEnforcedL3 EnforceablePrinciple 1Purpose Permission™Authority GateWORM audit hash-chain
Appropriate transparency & explainabilityEnforcedL3 EnforceablePrinciple 2WORM audit hash-chainDecision replay
Accountability & governanceEnforcedL3 EnforceablePrinciple 4Authority GatePurpose Permission™
Contestability & redress evidenceDecision inputs are replayable today; signed evidence supporting contestability and redress is in build.DesignedL2 DesignedPrinciple 5Evidence Pack™ signing (COSE-Sign1)Decision Map™ signing (JWS-detached)
Fairness assessment of model outputsBias and fairness assessment of model outputs is owned by the customer's model-evaluation process.Out of scopeL1 MappedPrinciple 3—

UK Equality Act 2010

UK Equality Act 2010

2010 · United Kingdom

UK statute making an automated selection rule that disadvantages a protected group unlawful indirect discrimination unless objectively justified.

1

Enforced

1

Designed

0

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Indirect discrimination (s.19)EnforcedL3 EnforceableEquality Act 2010 s.19Evidence Pack™Authority Gate
Protected characteristics (s.4)DesignedL2 DesignedEquality Act 2010 s.4Data Governance Pack™

EO 14110

US EO 14110 — Safe, Secure & Trustworthy AI (biosecurity / dual-use)

2023 · United States

US Executive Order 14110 (2023) Safe/Secure/Trustworthy AI — biosecurity, nucleic-acid synthesis screening, and content provenance provisions (rescinded Jan 2025; the dual-use-bio + synthesis-screening + provenance obligation pattern it established remains the de-facto reference set). KYE Protocol™ governs whether an AI-generated sequence/molecule may proceed to a consequential action — the KYE™ AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Dual-use biology & synthesis screeningDesignedL2 Designedus-eo-14110.4.4-synthesis-screening, us-eo-14110.4.4-dual-use-bioAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Content provenance & authenticationDesignedL2 Designedus-eo-14110.4.5-provenanceAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Human oversight of consequential AI actionDesignedL2 Designedus-eo-14110.human-oversightAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™

UNESCO AI Ethics

UNESCO Recommendation on the Ethics of Artificial Intelligence (2021)

2021 · International

The first global normative instrument on AI ethics, adopted (Nov 2021) by all 193 UNESCO member states. KYE Protocol™ operationalises the AI-action authority + evidence boundary of its values & principles — human oversight & determination, transparency & explainability, responsibility & accountability, privacy & data protection, fairness & non-discrimination, safety & security — with named accountability (Authority Finality™), a replay-derivable Evidence Pack™ and Decision Map™. KYE Protocol™ does NOT adjudicate the ethics of the outcome, and the environmental-sustainability and education/public-awareness principles are out-of-scope / customer-owned; coverage is never inflated. Per-requirement bijection at framework-coverage-bijection.

3

Enforced

3

Designed

0

Out of scope

6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Human oversight & determinationEnforcedL3 Enforceableunesco-ai-ethics.principle.human-oversight-determinationPurpose Permission™Authority Finality™
Transparency & explainability of AI decisionsEnforcedL3 Enforceableunesco-ai-ethics.principle.transparency-explainabilityDecision Map™Evidence Pack™
Responsibility & accountability — auditable, attributable outcomesEnforcedL3 Enforceableunesco-ai-ethics.principle.responsibility-accountabilityAuthority Finality™Evidence Pack™
Right to privacy & data protectionDesignedL2 Designedunesco-ai-ethics.principle.privacy-data-protectionData Purpose Binding™Purpose Permission™
Fairness & non-discrimination (contestability + audit evidence)DesignedL2 Designedunesco-ai-ethics.principle.fairness-non-discriminationDecision Map™Evidence Pack™
Safety & security — action-admissibility safety floorDesignedL2 Designedunesco-ai-ethics.principle.safety-security, unesco-ai-ethics.value.human-dignity-rightsEdge Governance Safety FloorPurpose Permission™

US Chatbot Laws

US State AI-Chatbot Laws — consumer / customer chatbot safeguards

2024-2026 · United States

The wave of US state AI-chatbot statutes (13+ states; 7 with a private right of action at roughly $1,000/violation) — CA SB 243, Utah AI Mental Health Chatbot Act, NY, IL, et al. Four recurring themes: crisis protocols, minor protections, deception/disclosure, liability. KYE Protocol™ governs the AUTHORITY + EVIDENCE of the chatbot safeguard actions at the moment the interaction occurs — the KYE™ Chatbot Authority Pack™. It does not provide the chatbot/LLM, the clinical crisis content, or the GRC program. Per-requirement bijection at framework-coverage-bijection.

5

Enforced

0

Designed

2

Out of scope

7 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Jurisdiction-aware safeguard resolutionEnforcedL3 Enforceableus-state-chatbot-laws.jurisdiction-resolution-applicable-safeguardsAction Admissibility™ GateCross-Jurisdiction Handoff RailAuthority Finality™
Mental-health / crisis protocolEnforcedL3 Enforceableus-state-chatbot-laws.crisis-escalation-authorityAction Admissibility™ GateAuthority Finality™Evidence Pack™
Minor protectionsEnforcedL3 Enforceableus-state-chatbot-laws.minor-protection-authorityAction Admissibility™ GateAuthority Finality™
Deception / disclosure / anthropomorphismEnforcedL3 Enforceableus-state-chatbot-laws.disclosure-enforcement-authorityAction Admissibility™ GateAuthority Finality™
Liability / private right of action — litigation evidenceEnforcedL3 Enforceableus-state-chatbot-laws.litigation-evidence-captureEvidence Pack™Replay-Proof™WORM Retention
Clinical crisis-counselling substance (out of scope)Crisis-service responsibility — clinical crisis content. KYE™ proves the escalation was authorised & triggered, not the content. Zero KYE™ controls (complement-not-compete).Out of scopeL1 Mappedus-state-chatbot-laws.clinical-crisis-counselling-substance—
Chatbot / model behaviour & UX (out of scope)Model vendor / operator responsibility — the LLM, its outputs, age-estimation, and UX. Zero KYE™ controls (complement-not-compete).Out of scopeL1 Mappedus-state-chatbot-laws.chatbot-model-behaviour-and-ux—

Voluntary GenAI Code

Voluntary Code of Conduct — Advanced Generative AI (Canada)

ISED (Sept 2023) · Canada

Canada's voluntary code for advanced generative AI systems (ISED, 2023). Voluntary signatory program — all rows advisory: accountability, transparency, and human oversight + monitoring outcomes anchored to the KYE Protocol™ action-governance layer. Per-requirement bijection at /compliance/voluntary-code-genai.html.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
AccountabilityDesignedL2 DesignedaccountabilityAuthority GateRisk Engine
TransparencyDesignedL2 DesignedtransparencyDecision Map™Reporting Engine
Human oversight + monitoringDesignedL2 DesignedoversightDrift DetectorIncident Detector

ISO 31000

ISO 31000:2018 — Risk management — Guidelines

2018 · International

ISO 31000:2018 risk-management principles, framework and process. KYE Protocol™ governs the authority, evidence and finality of AI-agent actions as a risk-treatment and risk-recording control inside the ISO 31000 process — it does not run the enterprise risk-management system. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Accountability + assigned authority for AI riskDesignedL2 Designediso-31000.5.4.2Purpose Permission™GovernedUI
Risk identification + treatment at the action boundaryDesignedL2 Designediso-31000.6.4.2, iso-31000.6.5.2Decision Map™Authority Gate
Monitoring/review + replay-derivable recordingDesignedL2 Designediso-31000.6.6, iso-31000.6.7Evidence Pack™Replay Proof™Delegated Auditability

Three Lines Model

The IIA's Three Lines Model (2020)

2020 · International

The IIA's Three Lines Model (2020). KYE Protocol™ supplies the runtime authority + evidence + assurance primitives the model assumes across first line (operational), second line (risk/compliance) and third line (internal audit) — it does not replace any line's people or mandate. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Governance accountability + governing-body oversightDesignedL2 Designedthree-lines.principle-1, three-lines.principle-2Purpose Permission™GovernedUIEvidence Pack™
First/second line authority + third-line assuranceDesignedL2 Designedthree-lines.principle-3, three-lines.principle-4Decision Map™Delegated Auditability
Independent verification + aligned value protectionDesignedL2 Designedthree-lines.principle-5, three-lines.principle-6Replay Proof™Evidence Pack™

MIT AI Risk Repository

MIT AI Risk Repository — Domain Taxonomy

2024 · International

MIT AI Risk Repository (2024) Domain Taxonomy — 7 domains. KYE Protocol™ addresses the 4 action-authority domains (privacy/security access, malicious misuse, human oversight, system-safety traceability/multi-agent) and is HONESTLY out of scope for the 3 content/societal domains (discrimination & toxicity, misinformation, socioeconomic & environmental). Coverage never inflated. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

4

Designed

3

Out of scope

7 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
D2 Privacy & Security — access bounded by purpose + tenantDesignedL2 Designedmit-risk.d2-privacy-securityPurpose Permission™Decision Map™Tenant Isolation
D4 Malicious Actors & Misuse — unauthorised action refusedDesignedL2 Designedmit-risk.d4-malicious-misusePurpose Permission™Authority Gate
D5 Human-Computer Interaction — human oversightDesignedL2 Designedmit-risk.d5-human-computer-interactionGovernedUI
D7 AI System Safety — traceability + multi-agent authorityDesignedL2 Designedmit-risk.d7-traceability, mit-risk.d7-multi-agentEvidence Pack™Replay Proof™Delegated Auditability
D1 Discrimination & Toxicity (content/fairness — out of scope)the protocol governs authority of agent ACTIONS, not content truth/fairness or macro-societal outcomes — this MIT domain is honestly out of scope; never inflated.Out of scopeL1 MappedMIT domain (content/societal — outside the authority-of-action scope)—
D3 Misinformation (content truth — out of scope)the protocol governs authority of agent ACTIONS, not content truth/fairness or macro-societal outcomes — this MIT domain is honestly out of scope; never inflated.Out of scopeL1 MappedMIT domain (content/societal — outside the authority-of-action scope)—
D6 Socioeconomic & Environmental (macro/societal — out of scope)the protocol governs authority of agent ACTIONS, not content truth/fairness or macro-societal outcomes — this MIT domain is honestly out of scope; never inflated.Out of scopeL1 MappedMIT domain (content/societal — outside the authority-of-action scope)—

ATRS

Algorithmic Transparency Recording Standard (ATRS)

ATRS v3.0 (2025) · United Kingdom

The UK Government Algorithmic Transparency Recording Standard — mandatory for central-government departments and arm’s-length bodies publishing algorithmic tools that affect the public. KYE Protocol™ is the evidence source the ATRS record is populated FROM: every governed public-sector AI action emits a signed Evidence Pack™ carrying the tool’s purpose, decision map and capability profile, so the published transparency record is a projection of recorded runtime evidence rather than a hand-authored claim.

2

Enforced

1

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Tier 1 + Tier 2 transparency recordMarquee mapping — the Evidence Pack™ populates the ATRS Tier-1 overview and Tier-2 technical record; replay-verifiable from published keys.EnforcedL3 EnforceableTier 1, Tier 2Evidence Pack™Decision Map™Capability Profile
Senior responsible ownerThe ATRS named owner resolves to the recorded named-authority decision for every consequential action.EnforcedL3 EnforceableOwnerAuthority RegisterPurpose Permission™
Maintain & re-publish on change§13 drift detection flags the behaviour change that re-opens the published record; the re-publication trigger workflow is in build.DesignedL2 DesignedMaintenanceResilience Loop™ drift signal
Public effect & appeal arrangementsThe substantive public-effect judgement and appeal design are the deploying body’s own responsibility; KYE™ supplies the contestability hooks, not the policy.Out of scopeL1 MappedImpact—

UK Gov AI Playbook

AI Playbook for the UK Government

Feb 2025 · United Kingdom

The UK Government AI Playbook’s ten principles for safe, effective and secure use of AI in government. KYE Protocol™ enforces the governance principles at the action boundary: meaningful named accountability, secure provenance-backed use, and meaningful human control on consequential decisions — each emitting a signed, replay-verifiable Evidence Pack™.

3

Enforced

1

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Meaningful accountabilityNamed human accountability recorded before every consequential action; the AI governance board maps to §36 approval modes.EnforcedL3 EnforceablePrinciple: accountabilityAuthority RegisterPurpose Permission™GovernedUI approval modes
Keeping AI use securePinned provenance + WORM-retained replay-verifiable Evidence Pack™ per action.EnforcedL3 EnforceablePrinciple: securityReplay-Proof™Evidence Pack™WORM audit
Meaningful human controlStaged finality (draft→recommendation→human-reviewed→citizen-facing→final); two-person sign-off on irreversible authorising-official assertions.EnforcedL3 EnforceablePrinciple: human controlGovernedUI sign-offDecision finality states
Lifecycle management & monitoringDrift monitoring + AI/ML systems inventory; the mandated review-cadence workflow is in build.DesignedL2 DesignedPrinciple: lifecycleResilience Loop™§67 model-governance catalogue

Orange Book

HMT Orange Book — Management of Risk

2023 · United Kingdom

HM Treasury’s Orange Book is the cross-government standard for risk management. KYE Protocol™ performs the identify-assess-monitor arc at the action boundary: every governed AI action is risk-scored and admitted against a risk-scoped purpose grant before it runs, and behaviour drift is monitored continuously through the Resilience Loop™.

2

Enforced

1

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Identify & assess riskRisk-scored admission against a risk-scoped purpose grant before the action runs.EnforcedL3 EnforceableIdentify, AssessRisk scorePurpose Permission™Decision Map™
Monitor & respond§13 continuous drift detection + improvement records.EnforcedL3 EnforceableMonitorResilience Loop™ drift signal
Report & escalate to governance bodyAuthority register + attestations support reporting; the portfolio risk-report rendering is in build.DesignedL2 DesignedReportAuthority RegisterCompliance attestation

Magenta Book

HMT Magenta Book — Evaluation Guidance

2020 · United Kingdom

HM Treasury’s Magenta Book is the cross-government standard for evaluation of interventions. KYE Protocol™ supplies the recorded process evidence — what the AI tool actually did, for whom, under whose authority — that a process or impact evaluation of an AI intervention rests on, drawn from runtime Evidence Packs™ rather than reconstructed from scattered logs.

1

Enforced

1

Designed

1

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Process evaluationRecorded action evidence is the process the evaluator examines.EnforcedL3 EnforceableProcess evalObserved ActionEvidence Pack™Decision Map™
Impact evaluationPopulation-impact classification supports impact evaluation; the per-cohort export for a counterfactual study is in build.DesignedL2 DesignedImpact evalConsequence Mapping Engine
Value-for-money & evaluation conclusionThe value-for-money judgement and analytical conclusion are the department’s evaluation function’s, not KYE™’s.Out of scopeL1 MappedVfM—

ISO 9000

ISO 9000:2015 — Quality management systems

ISO 9000:2015 · International

ISO 9000:2015 defines the quality-management concepts of objective evidence, validation and change control — ‘objective evidence that requirements have been fulfilled’. The KYE™ Evidence Pack™ IS that objective evidence: a signed, replay-verifiable record that the named-authority, due-diligence and sign-off requirements were fulfilled before an AI-assisted output proceeded.

2

Enforced

1

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Objective evidence & verificationSigned replay-verifiable objective evidence that requirements were fulfilled.EnforcedL3 Enforceable3.8.3Evidence Pack™Replay-Proof™Decision Map™
Validation (fit for intended use)Purpose-scope admission confirms the output fit for its intended public-sector use at the action boundary.EnforcedL3 Enforceable3.8.13Purpose Permission™Decision Engine
Change control & re-validation§13 drift signal flags the change that ought to trigger re-validation; the re-validation gate workflow is in build.DesignedL2 DesignedChange controlResilience Loop™ drift signal

UK AI Testing & Assurance (Public Sector)

AI Testing and Assurance Framework for the Public Sector

2024 · United Kingdom

The UK Cross-Government Testing Community framework for testing and assuring AI systems used in the public sector, pre-deployment and in-life. KYE Protocol™ runs pre-deployment scenario tests through the Scenario Engine, monitors in-life behaviour through the Resilience Loop™, and reconstructs an assurance record for an oversight reviewer through the §21 audit-replay machinery.

2

Enforced

1

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Pre-deployment testingAdversarial/policy scenarios run and risk-scored before admission to a consequential action path.EnforcedL3 EnforceablePre-deploymentScenario EngineRisk score
In-life assuranceContinuous drift detection + audit-pilot replay for ongoing assurance.EnforcedL3 EnforceableIn-lifeResilience Loop™Audit Pilot™
Assurance evidence & replayReconstructable assurance record; the Cross-Government-Testing-Community report rendering is in build.DesignedL2 DesignedAssurance recordAudit-replay orchestratorRegulator-replay agent

EN 18286

EN 18286:2025 — Quality management system for high-risk AI systems

EN 18286:2025 (E) · European Union

European harmonised standard for the QMS obligation on providers of high-risk AI systems (supporting EU AI Act Article 17). PARTIAL MAPPING — only Clause 5.1 (the six non-delegable top-management duties) is mapped at this edition; the rest of the standard is not yet mapped and is deliberately omitted, not inflated. KYE™ governs the AUTHORITY, OVERSIGHT, and EVIDENCE dimensions of the QMS; it does not implement the provider's HR/training, compute-procurement, or sustainability program.

4

Enforced

2

Designed

0

Out of scope

6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Quality policy & measurable objectives from regulatory purpose (5.1.a)EnforcedL3 EnforceableEN 18286:2025 Clause 5.1.a + Note 2Purpose Permission™Authority Register≤90-day attestation
Resources for the QMS — data-lineage/traceability storage over the retention period (5.1.b, lineage sub-duty only)Only the lineage/traceability-retention sub-duty maps to KYE™. Compute provisioning, human-capital competence/training, and energy-efficiency sustainability are provider-owned and out of KYE™ scope (not claimed).DesignedL2 DesignedEN 18286:2025 Clause 5.1.bWORM audit hash-chainobject-store immutability retention policy
Effective role responsibilities — human oversight, intervention thresholds, override/intervenability, automation-bias mitigation (5.1.c)EnforcedL3 EnforceableEN 18286:2025 Clause 5.1.cKYE™ GovernedUI™ approval modesOversight envelope / override interfaceDelegated-authority bindingMeta-governance no-self-grant gate
QMS integrated into the provider's processes across the AI lifecycle — not a separate binder (5.1.d)EnforcedL3 EnforceableEN 18286:2025 Clause 5.1.dSelf-governance evidence-event familyCohesion Cascade™
QMS achieves intended results — management review, nonconformity → corrective action (5.1.e)EnforcedL3 EnforceableEN 18286:2025 Clause 5.1.eReconciliation Engine™ declared-vs-deployed bijection≤90-day attestation
Communication of QMS importance & promotion of a responsible-AI culture (5.1.f + Note 1)KYE™ supplies the communication/education channel; sustaining a responsible-AI culture amid staff turnover/drift is a provider-owned people obligation and is not claimed as enforced.DesignedL2 DesignedEN 18286:2025 Clause 5.1.fComms Rail · KYE™ Comms Engine™Learn Rail · KYE™ Learn™

MAS AIRG (consultation)

MAS Consultation Paper on Guidelines on Artificial Intelligence Risk Management (AIRG)

consultation-2025-11 (final Guidelines not yet issued as of 2026-07-03) · Singapore

MAS's proposed sector-wide supervisory Guidelines on AI Risk Management (consultation paper published 13 November 2025; comments closed 31 January 2026): supervisory expectations on AI risk oversight, key AI risk-management systems, policies and procedures, AI life-cycle controls, and capabilities/capacity — explicitly covering Generative AI and AI agents, applied proportionately with a proposed 12-month transition after issuance. This instrument is REGISTERED in the §70 Framework Mapping Rail as a MONITORED consultation (the final Guidelines had not been issued at registration; the entry will be re-versioned on publication). It is distinct from MAS Project MindForge, the industry-co-created operationalisation handbook, which is deep-mapped separately. No requirement is bound while the text is non-final, so coverage is honestly reported as out of scope.

0

Enforced

0

Designed

1

Out of scope

1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail as a monitored consultation instrument; text not yet finalHonest registered state (§70 mapping_state=registered): the consultation crosswalks cleanly to existing KYE Protocol™ rails (AI oversight → §36 GovernedUI™ approval modes + Finality Gate; life-cycle controls → §13 Evidence Pack™ / Replay-Proof™; AI-agent expectations → §52 agent binding + §0.30 agents-as-principals), but the honesty bar forbids binding requirements to a non-final text — deep mapping runs through the §70 rail once MAS issues the Guidelines. Coverage is never inflated.Out of scopeL1 MappedMAS AIRG consultation paper (13 Nov 2025) — proposed expectations on AI oversight, risk-management systems, life-cycle controls, and capabilities; not yet issued as final Guidelines, not yet decomposed into requirement-level mappings—

ISO/IEC 38507

ISO/IEC 38507:2022 — Governance implications of the use of AI by organizations

ISO/IEC 38507:2022 · International (ISO/IEC)

ISO/IEC 38507 gives the governing body guidance on the governance implications of AI, on the Evaluate-Direct-Monitor model. KYE Protocol™ governs the AUTHORITY dimension of that accountability: every AI-agent action is bound to a named accountable Principal under a directed purpose, with substantive human oversight and replay-provable evidence. KYE™ enforces the authority/evidence/oversight slice mechanically; the board process itself sits outside its scope (honest §70 tri-state).

4

Enforced

1

Designed

0

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Accountability & the governing body (non-delegable, EDM)EnforcedL3 Enforceableiso-iec-38507.governing-body-accountability, iso-iec-38507.accountability-for-outcomes, iso-iec-38507.governance-vs-management§0.30 accountable Principaldelegation chainAuthority vs execution seamEvidence Pack™
Direct — purpose alignment & acceptable-use policyEnforcedL3 Enforceableiso-iec-38507.purpose-alignment, iso-iec-38507.acceptable-use-policyPurpose Permission™Rules Gateway™Decision Map™
Evaluate — AI-specific considerations (autonomy, risk, data)DesignedL3 Enforceableiso-iec-38507.ai-characteristics-consequences, iso-iec-38507.risk-oversight, iso-iec-38507.data-governance-for-aibounded agent authorityrisk signals§31 data-use authority
Monitor — human oversight & continuous assuranceEnforcedL3 Enforceableiso-iec-38507.material-decision-oversight, iso-iec-38507.continuous-monitoringGovernedUI™ approval modesper-action re-check§34 reconciliation
Transparency, explainability & compliance obligationsEnforcedL3 Enforceableiso-iec-38507.transparency-explainability, iso-iec-38507.compliance-obligationsDecision Map™ reason codesReplay-Proof™≤90-day attestation§70 mapping

MOW SOC

MOW Search Only Terms Contract (SOC)

socw/2 (2026) — immutable MOW-stewarded contract URL, robots.txt Terms Document Locator (tdl:) declaration · United Kingdom

Machine-readable standard contract (Movement for an Open Web / Preiskel & Co LLP, July 2026) licensing website access for Search Indexing only and pricing every other Access Event at the contract's default per-Product Access Fee. KYE Protocol™ maps it as publisher-side content-access authority: classify each automated access against the licence at the moment of access, seal Access Events as verifiable evidence, and derive the invoice-ready unlicensed-access schedule. The contract stays MOW's — KYE™ never re-hosts or interprets it: the SOC sets the terms; KYE™ proves the breach.

0

Enforced

7

Designed

1

Out of scope

8 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Machine-readable terms declarationDesignedL2 Designedmow-search-only-contract.terms-document-locatorPurpose Permission™Decision replayEvidence Pack™Replay-Proof™
Purpose-limited licensed accessDesignedL2 Designedmow-search-only-contract.purpose-limited-index-accessPurpose Permission™Decision replayEvidence Pack™Replay-Proof™
Access-event evidence & recordsDesignedL2 Designedmow-search-only-contract.access-event-evidencePurpose Permission™Decision replayEvidence Pack™Replay-Proof™
Access-fee accrual & waiver conditionsDesignedL2 Designedmow-search-only-contract.access-fee-accrualPurpose Permission™Decision replayEvidence Pack™Replay-Proof™
AI-scraping & dataset prohibitionDesignedL2 Designedmow-search-only-contract.ai-scraping-prohibitionPurpose Permission™Decision replayEvidence Pack™Replay-Proof™
Database-rights & bulk-extraction restrictionDesignedL2 Designedmow-search-only-contract.database-rightsPurpose Permission™Decision replayEvidence Pack™Replay-Proof™
Contract formation & court enforcementOut of scopeL1 Mappedmow-search-only-contract.legal-formation-and-enforcement—
Accessibility & reader carve-outDesignedL2 Designedmow-search-only-contract.accessibility-carveoutPurpose Permission™Decision replayEvidence Pack™Replay-Proof™

EW-AiRM

EW-AiRM — Enterprise-Wide AI Risk Management

EW-AiRM (Human-AI Institute / Markus Krebsz) · International

EW-AiRM is an enterprise-wide AI risk-management framework (Human-AI Institute / Markus Krebsz) that quantifies board risk appetite, assesses AI-necessity and organisational readiness, classifies risk against the MIT AI Risk Repository, sets non-negotiables (named accountability, tested human override, F-Critical no-averaging, named incident route) and an 8-Black-Swan resilience discipline, and produces a HAiPECR pre-deployment record. KYE Protocol™ maps the honest boundary — enterprise AI-risk governance is NOT per-action authority: system approval ≠ action authority. KYE™ enforces the runtime half (every consequential action admissibility-checked under a named authority, fail-closed, evidenced, replay-provable) and CONSUMES EW-AiRM's residual-risk acceptance and the HAiPECR verdict as an action policy, returning per-action authorised / denied / scope-inflation / expired-authority / revocation evidence. The quantification, readiness/necessity assessment, MIT-taxonomy classification, and Black-Swan scenario planning stay EW-AiRM's own work. From Board Risk Appetite to Runtime Proof. Per-requirement bijection at /compliance/ewairm.html.

3

Enforced

5

Designed

4

Out of scope

12 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
System approval vs per-action authority (the boundary)EnforcedL3 Enforceableewairm.system-approval-not-action-authorityAuthority GatePurpose Permission™Decision replayReplay-Proof™
Non-negotiable — named accountabilityEnforcedL3 Enforceableewairm.non-negotiable-named-accountabilityNamed principalAuthority GateEvidence Pack™
Non-negotiable — no score-averaging over a critical failureEnforcedL3 Enforceableewairm.f-critical-no-averaging-overrideFail-closed admissibilityDecision replayReplay-Proof™
Non-negotiable — tested human overrideDesignedL2 Designedewairm.non-negotiable-tested-human-overrideGovernedUI™ HITLKill-switch
Residual-risk acceptance → runtime conditionDesignedL2 Designedewairm.residual-risk-acceptance-as-authority-conditionPurpose Permission™Scope condition
HAiPECR record consumptionDesignedL2 Designedewairm.documented-haipecr-consumptionDecision replayAction policy
Non-negotiable — named incident routeDesignedL2 Designedewairm.non-negotiable-named-incident-routeContestability routeEvidence Pack™
Black-Swan resilience — runtime evidenceDesignedL2 Designedewairm.black-swan-runtime-resilience-evidenceResilience Loop™No-SPOFReplay-Proof™
Board risk-appetite quantificationQuantifying board-level AI risk appetite is EW-AiRM's enterprise-risk work; KYE™ consumes an already-decided residual-risk acceptance as a runtime condition but does not quantify appetite.Out of scopeL1 Mappedewairm.board-risk-appetite-quantification—
Organisational-readiness assessmentPeople / process / culture / governance-maturity readiness assessment is an organisational-diagnostic activity KYE™ does not perform or replace.Out of scopeL1 Mappedewairm.organisational-readiness-assessment—
AI-necessity assessmentWhether AI should be used at all (necessity / proportionality) is a judgement KYE™ does not adjudicate; KYE™ governs the authority of AI actions once AI is deployed.Out of scopeL1 Mappedewairm.ai-necessity-assessment—
MIT AI Risk Repository taxonomyClassifying risks against the MIT AI Risk Repository is an analytic activity owned by the enterprise; KYE™ enforces authority at the action boundary regardless of how a risk is taxonomised.Out of scopeL1 Mappedewairm.mit-risk-taxonomy-classification—

HAiPECR

HAiPECR — Human-AI Pre-deployment Evidence & Certification Record

HAiPECR (Human-AI Institute / Markus Krebsz, OECD-listed Apr 2023) · International

HAiPECR (Human-AI Institute / Markus Krebsz; OECD Catalogue of Tools & Metrics for Trustworthy AI, April 2023) is a pre-deployment evidence-and-certification record across seven dimensions — human oversight, accountability, transparency & explainability, privacy & data, ethics & fairness, compliance & legal, resilience & security — culminating in a deploy / do-not-deploy verdict. KYE Protocol™ CONSUMES the HAiPECR credential/verdict as an action policy and enforces the runtime half: dimensions that resolve to a real KYE™ runtime artefact are enforced/designed, and a do-not-deploy verdict makes consequential actions inadmissible at the §12 boundary — returning per-action authorised / denied / scope-inflation / expired-authority / revocation evidence. Ethics & fairness SCORING and the authoring of the HAiPECR record itself stay the human-expert's work (KYE™ proves authority, not model fairness). From Board Risk Appetite to Runtime Proof. Per-requirement bijection at /compliance/haipecr.html.

1

Enforced

6

Designed

1

Out of scope

8 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Dimension — accountabilityEnforcedL3 Enforceablehaipecr.accountabilityNamed principalAuthority GateEvidence Pack™
Dimension — human oversightDesignedL2 Designedhaipecr.human-oversightGovernedUI™ HITLKill-switch
Dimension — transparency & explainabilityDesignedL2 Designedhaipecr.transparency-explainabilityDecision Map™Evidence Pack™
Dimension — privacy & dataDesignedL2 Designedhaipecr.privacy-dataData-use admissibilityMemory Authority Rail™
Dimension — compliance & legalDesignedL2 Designedhaipecr.compliance-legalFramework Mapping Rail™Decision replay
Dimension — resilience & securityDesignedL2 Designedhaipecr.resilience-securityResilience Loop™No-SPOFReplay-Proof™
Deploy-gate verdict consumptionDesignedL2 Designedhaipecr.deploy-gate-verdict-consumptionAction policyPurpose Permission™Decision replay
Dimension — ethics & fairnessScoring the ethical acceptability and fairness of model behaviour is a model-evaluation activity owned by the builder and the enterprise's ethics function; KYE™ proves an action was authorised, evidenced, and replayable, not that the model is fair.Out of scopeL1 Mappedhaipecr.ethics-fairness—

Data protection

Personal-data regulation covering lawful basis, data-subject rights, and processing accountability.

Alberta PIPA

Alberta PIPA — Personal Information Protection Act (Alberta)

S.A. 2003, c. P-6.5 · Canada

Alberta's private-sector privacy law (PIPA), substantially similar to PIPEDA and the first Canadian private-sector law with mandatory breach notification: consent, protection of personal information, and breach notification. Per-requirement bijection at /compliance/alberta-pipa.html.

2

Enforced

1

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Consent (ss.7-8)EnforcedL3 Enforceables7Purpose Permission™
Protection of personal information (s.34)EnforcedL3 Enforceables34Authority Gate
Breach notification (s.34.1)DesignedL2 Designeds34.1Incident DetectorReporting Engine

DSG

Datenschutzgesetz (DSG, BGBl. I Nr. 165/1999, as amended 2018)

2018 (GDPR implementing act) · Austria

DSG is Austria's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Austria-specific national deltas here. Per-requirement bijection at /compliance/at-dsg.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine

APPI

APPI — Act on the Protection of Personal Information

Act No. 57 of 2003, as amended (2022) · Japan

Japan's Act on the Protection of Personal Information, supervised by the Personal Information Protection Commission (PPC) — purpose-of-use limitation, security control measures, cross-border transfer, disclosure/access rights and breach reporting. KYE Protocol™ governs the personal-data obligations that bind an AI-supported action; the organisational privacy programme stays out of scope. Per-requirement bijection at /compliance/appi.html.

2

Enforced

1

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Purpose-of-use limitation & security control measuresEnforcedL3 EnforceableAPPI Art. 17-18, APPI Art. 23Purpose Permission™Authority Resolution™Data Classification Engine
Cross-border transfer & disclosure/access rightsEnforcedL3 EnforceableAPPI Art. 28 / 31, APPI Art. 33-35Cross-Border Evidence agentDecision Map™Replay-Proof™Evidence Pack™
Breach reporting to the PPCKYE™ assembles the PPC notification package from the leakage evidence; the regulator-side delivery channel to the PPC is designed pending the per-jurisdiction reporting connector.DesignedL1 MappedAPPI Art. 26Incident DetectorReporting Engine

BC PIPA

BC PIPA — Personal Information Protection Act (British Columbia)

S.B.C. 2003, c. 63 · Canada

British Columbia's private-sector privacy law (PIPA), substantially similar to PIPEDA: consent, reasonable security, and access/correction. Per-requirement bijection at /compliance/bc-pipa.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Consent (ss.6-8)EnforcedL3 Enforceables6Purpose Permission™
Reasonable security (s.34)EnforcedL3 Enforceables34Authority Gate
Access + correction (ss.23-24)EnforcedL3 Enforceables23Reporting EngineWORM audit hash-chain

Belgian Data Protection Act 2018

Loi du 30 juillet 2018 — Belgian Data Protection Act

2018 (GDPR implementing act) · Belgium

Belgian Data Protection Act 2018 is Belgium's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Belgium-specific national deltas here. Per-requirement bijection at /compliance/be-dpa-2018.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine

Bulgarian Personal Data Protection Act

Personal Data Protection Act (amended 2019 to implement the GDPR)

2018 (GDPR implementing act) · Bulgaria

Bulgarian Personal Data Protection Act is Bulgaria's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Bulgaria-specific national deltas here. Per-requirement bijection at /compliance/bg-pdpa.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine

nFADP

nFADP / revDSG — revised Federal Act on Data Protection (in force 1 Sept 2023)

in force 2023 · Switzerland

Switzerland's revised Federal Act on Data Protection (nFADP/revDSG) — a sovereign, GDPR-aligned statute under an EU adequacy decision. this registry maps the Swiss national deltas; AI-system governance defers to the directly-applicable obligations Switzerland references. Per-requirement bijection at /compliance/ch-nfadp.html.

4

Enforced

0

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
National statute (non-EU, adequacy) — nFADP/revDSG lawful-purpose + accountabilityEnforcedL3 Enforceablenfadp-basisPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine
Cross-border transfer / adequacy regime (non-EU)EnforcedL3 Enforceableadequacy-cross-borderAuthority GateEvidence Pack™

Law 125(I)/2018

Law 125(I)/2018 (providing for the protection of natural persons with regard to the processing of personal data)

2018 (GDPR implementing act) · Cyprus

Law 125(I)/2018 is Cyprus's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Cyprus-specific national deltas here. Per-requirement bijection at /compliance/cy-law-125-2018.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine

Zákon 110/2019

Zákon č. 110/2019 Sb., o zpracování osobních údajů

2018 (GDPR implementing act) · Czech Republic

Zákon 110/2019 is Czech Republic's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Czech Republic-specific national deltas here. Per-requirement bijection at /compliance/cz-zakon-110-2019.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine

BDSG

BDSG — Bundesdatenschutzgesetz (Federal Data Protection Act, 2018)

2018 (GDPR implementing act) · Germany

BDSG is Germany's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Germany-specific national deltas here. Per-requirement bijection at /compliance/de-bdsg.html.

4

Enforced

0

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine
Employee-data processing (BDSG §26, works-council co-determination)EnforcedL3 Enforceableemployee-data-bdsg-26Purpose Permission™Decision Map™

Databeskyttelsesloven

Databeskyttelsesloven (Lov nr. 502 af 23. maj 2018)

2018 (GDPR implementing act) · Denmark

Databeskyttelsesloven is Denmark's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Denmark-specific national deltas here. Per-requirement bijection at /compliance/dk-databeskyttelsesloven.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine

LOPDGDD

LOPDGDD — Ley Orgánica 3/2018 de Protección de Datos Personales y garantía de los derechos digitales

2018 (GDPR implementing act) · Spain

LOPDGDD is Spain's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Spain-specific national deltas here. Per-requirement bijection at /compliance/es-lopdgdd.html.

4

Enforced

0

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine
LOPDGDD Título X digital rights (disconnection, digital-will, workplace)EnforcedL3 Enforceabledigital-rights-titulo-xDSAR AgentEvidence Pack™

Tietosuojalaki

Tietosuojalaki (1050/2018) — Data Protection Act

2018 (GDPR implementing act) · Finland

Tietosuojalaki is Finland's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Finland-specific national deltas here. Per-requirement bijection at /compliance/fi-tietosuojalaki.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine

Loi Informatique et Libertés

Loi Informatique et Libertés (Act No. 78-17, as amended) + CNIL

2018 (GDPR implementing act) · France

Loi Informatique et Libertés is France's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the France-specific national deltas here. Per-requirement bijection at /compliance/fr-lil.html.

4

Enforced

0

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine
Health-data HDS-certified hosting + CNIL reference methodologiesEnforcedL3 Enforceablehealth-data-hdsData Classification EngineAuthority Gate

CCPA/CPRA

CCPA/CPRA — California Consumer Privacy Act (as amended by the CPRA)

Cal. Civ. Code §1798.100 et seq. (2018, amended by CPRA 2020) · United States

The California Consumer Privacy Act (as amended by the CPRA) grants California consumers rights over their personal information — notice at collection, the right to know/access, delete, correct, opt out of sale/sharing, limit the use of sensitive PI, and non-discrimination for exercising those rights. This framework is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: its consumer-rights structure overlaps heavily with the already-deep-mapped GDPR and crosswalks to existing KYE Protocol™ rails (right to know/delete/correct → §31 Data Governance Pack & the DSAR evidence agent; opt-out of sale/sharing & limit-use → §12 Purpose Permission™; data-as-authority lifecycle → §63 Memory Authority Rail), but no requirement has yet been bound at the requirement level. Per the §70 honesty bar, coverage is reported out of scope pending deep mapping rather than claimed as enforced.

0

Enforced

0

Designed

1

Out of scope

1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): candidate crosswalks to §31 / §12 / §63 and the existing GDPR deep-map are noted in the summary but NOT yet bound at the requirement level, so coverage stays out of scope until the deep mapping runs through the §70 rail — never inflated to imply enforcement that does not exist.Out of scopeL1 MappedCCPA/CPRA consumer rights (notice, know/access, delete, correct, opt-out of sale/sharing, limit sensitive PI, non-discrimination — not yet decomposed into requirement-level mappings)—

GDPR

GDPR — General Data Protection Regulation

Regulation (EU) 2016/679 · European Union

EU regulation governing the processing of personal data.

4

Enforced

1

Designed

0

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Lawful basis & purpose limitationEnforcedL3 EnforceableArt. 5, Art. 6Purpose Permission™Authority Gate
Data-subject rights handlingEnforcedL3 EnforceableArt. 12-22Purpose Permission™WORM audit hash-chain
Records of processing & accountabilityEnforcedL3 EnforceableArt. 30WORM audit hash-chainDecision replay
Integrity, confidentiality & signed evidenceAccess to personal data is governed today; signed integrity evidence and automated key rotation are in build.DesignedL2 DesignedArt. 32Evidence Pack™ signing (COSE-Sign1)Automated key rotation
International transfers (Chapter V) — Schrems II / SCC / adequacy§72 Jurisdiction & Data-Sovereignty Authority surfaces the GDPR Chapter V cross-border requirements already deep-mapped in internal Each crossing emits a signed kye.cross_border.transfer.v1 carrying the lawful_basis (adequacy / SCC + Transfer Impact Assessment) and the residency_verdict, so the Art. 44-49 transfer-impact assessment is the evidence pack itself.EnforcedL3 EnforceableArt. 44, Art. 45, Art. 46, Art. 49Cross-Border Transfer Record (kye.cross_border.transfer.v1)Jurisdiction Attestation (kye.jurisdiction.attestation.v1)Residency Verdict (§72)

GDPR Art. 22

GDPR Article 22 — Automated Decision-Making

Regulation (EU) 2016/679 (GDPR) — Article 22 (automated individual decision-making, including profiling) + Articles 13–15 / Recital 71 · European Union

GDPR Article 22 gives data subjects the right not to be subject to solely-automated similarly-significant decisions without safeguards — human intervention, meaningful information about the logic, and the right to contest. KYE Protocol™ governs whether an AI-assisted insurance decision in scope may proceed — under a recorded named-authority (the human-involvement safeguard), with a recorded adverse-action reason-code (meaningful information about the logic), a signed replay-provable Evidence Pack™ per decision, and an appeal / contestability record (the right to contest and to human intervention). The lawful basis / substantive decision / risk pricing on the merits stays the controller's own work (honest scope, §0). Per-requirement bijection at /compliance/gdpr-automated-decision.html.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Human involvement / named-authority safeguard (Art. 22(3))EnforcedL3 Enforceablegdpr-automated-decision.art22-human-involvement-safeguardAuthority GateDecision replayEvidence Pack™Replay-Proof™
Right to contest & human intervention (Recital 71)EnforcedL3 Enforceablegdpr-automated-decision.art22-contest-human-interventionAuthority GateDecision replayEvidence Pack™Replay-Proof™
Meaningful information about the logic / adverse-action reason (Art. 13–15)EnforcedL3 Enforceablegdpr-automated-decision.art13-15-meaningful-information-logicAuthority GateDecision replayEvidence Pack™Replay-Proof™
Lawful basis, substantive decision & pricing on the meritsThe lawful basis for the processing / the substantive decision / the risk pricing on the merits is the controller's own work — KYE™ is an AI-authority and evidence layer at the action boundary, not a legal-basis, decision, or pricing engine.Out of scopeL1 Mappedgdpr-automated-decision.lawful-basis-substantive-decision—

Law 4624/2019

Law 4624/2019 (measures implementing the GDPR)

2018 (GDPR implementing act) · Greece

Law 4624/2019 is Greece's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Greece-specific national deltas here. Per-requirement bijection at /compliance/gr-law-4624-2019.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine

Info Act

Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Info Act, GDPR-aligned)

2018 (GDPR implementing act) · Hungary

Info Act is Hungary's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Hungary-specific national deltas here. Per-requirement bijection at /compliance/hu-info-act.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine

Data Protection Act 2018

Data Protection Act 2018

2018 (GDPR implementing act) · Ireland

Data Protection Act 2018 is Ireland's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Ireland-specific national deltas here. Per-requirement bijection at /compliance/ie-dpa-2018.html.

4

Enforced

0

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine
One-Stop-Shop lead supervisory authority (DPC) — cross-border accountabilityEnforcedL3 Enforceablelead-supervisory-ossEvidence Pack™Reporting Engine

ISO 23081

ISO 23081-1:2017 — Managing Metadata for Records (records-metadata spine)

2017 · Global

ISO 23081-1:2017 records-metadata spine and AUTHORITY ANCHOR for the InSight DXP connector contract. KYE Protocol™ CONSUMES records metadata (agent, classification, event-history) as the input signal at the action boundary (enforced: classification-driven-authority, custody→authority binding, agent→principal binding); records-metadata creation / management is out-of-scope (owned by Iron Mountain InSight DXP).

2

Enforced

0

Designed

2

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Metadata-driven authority decision (authority overlay)EnforcedL3 Enforceableiso-23081.classification-driven-authority, iso-23081.event-history-evidenceAction Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Agent-metadata binding to a KYE-resolved principal (authority overlay)EnforcedL3 Enforceableiso-23081.agent-metadata-principal-bindingAction Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Metadata creation & capture (records-management)Out of scopeL1 Mappediso-23081.metadata-creation-capture—
Metadata management & maintenance (records-management)Out of scopeL1 Mappediso-23081.metadata-management-maintenance—

Codice Privacy

Codice in materia di protezione dei dati personali (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018)

2018 (GDPR implementing act) · Italy

Codice Privacy is Italy's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Italy-specific national deltas here. Per-requirement bijection at /compliance/it-codice-privacy.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine

Luxembourg Data Protection Act 2018

Loi du 1er août 2018 portant organisation de la Commission nationale pour la protection des données

2018 (GDPR implementing act) · Luxembourg

Luxembourg Data Protection Act 2018 is Luxembourg's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Luxembourg-specific national deltas here. Per-requirement bijection at /compliance/lu-cnpd.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine

UAVG

UAVG — Uitvoeringswet Algemene verordening gegevensbescherming (GDPR Implementation Act, 2018)

2018 (GDPR implementing act) · Netherlands

UAVG is Netherlands's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Netherlands-specific national deltas here. Per-requirement bijection at /compliance/nl-uavg.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine

Personopplysningsloven

Personopplysningsloven (LOV-2018-06-15-38) — GDPR incorporated via the EEA Agreement

2018 (GDPR implementing act) · Norway

Personopplysningsloven is Norway's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Norway-specific national deltas here. Per-requirement bijection at /compliance/no-personopplysningsloven.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine

NZ Privacy Act 2020

New Zealand Privacy Act 2020

Privacy Act 2020 (NZ) · New Zealand

The NZ Information Privacy Principles + Part 6 notifiable privacy breaches. Per-requirement bijection at /compliance/nz-privacy-act-2020.html.

2

Enforced

0

Designed

0

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
IPP 5 security, IPP 10 use-limitation, IPP 6 accessEnforcedL3 EnforceableIPP 5, IPP 10, IPP 6Authority GatePurpose Permission™DSAR Evidence agentReplay-Proof™
Part 6 notifiable privacy breachDetection + package assembly enforced; delivery channel to the OPC is in build.EnforcedL3 EnforceablePrivacy Act 2020 Part 6Incident DetectorReporting Engine

PIPEDA

PIPEDA — Personal Information Protection and Electronic Documents Act

S.C. 2000, c. 5 · Canada

Canada's federal private-sector privacy law (PIPEDA, S.C. 2000, c. 5): the ten Schedule 1 fair-information principles plus mandatory breach-of-security-safeguards reporting (s.10.1). Per-requirement bijection at /compliance/pipeda.html.

5

Enforced

1

Designed

0

Out of scope

6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Accountability + openness (Sch.1 4.1, 4.8)EnforcedL3 Enforceablesch1-4.1Authority GateReporting Engine
Purpose + consent (Sch.1 4.2-4.3)EnforcedL3 Enforceablesch1-4.3Decision Map™Purpose Permission™
Limiting collection/use/retention (Sch.1 4.4-4.5)EnforcedL3 Enforceablesch1-4.5Authority GatePurpose Permission™
Safeguards (Sch.1 4.7)EnforcedL3 Enforceablesch1-4.7Authority Gate
Individual access (Sch.1 4.9)EnforcedL3 Enforceablesch1-4.9Reporting EngineWORM audit hash-chain
Breach reporting (s.10.1)DesignedL2 Designeds10.1Incident DetectorReporting Engine

UODO

Ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych (Personal Data Protection Act)

2018 (GDPR implementing act) · Poland

UODO is Poland's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Poland-specific national deltas here. Per-requirement bijection at /compliance/pl-uodo.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine

Privacy Act 1988

Privacy Act 1988 (Cth) — ADM transparency + APPs

ADM reform (Privacy and Other Legislation Amendment Act 2024) · Australia

The Australian Privacy Principles + the 2024 automated-decision-making transparency reform (ADM provisions commence Dec 2026). Per-requirement bijection at /compliance/privacy-act-1988.html.

2

Enforced

0

Designed

0

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Automated decision-making transparencyEnforcedL3 EnforceablePrivacy Act 2024 reform — ADMDecision Map™Evidence Pack™Replay-Proof™
APP 1 open management + APP 11 security of personal informationEnforcedL3 EnforceableAPP 1, APP 11Authority GatePurpose Permission™Reporting Engine

Lei 58/2019

Lei n.º 58/2019 (assegura a execução do RGPD)

2018 (GDPR implementing act) · Portugal

Lei 58/2019 is Portugal's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Portugal-specific national deltas here. Per-requirement bijection at /compliance/pt-lei-58-2019.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine

Quebec Law 25

Quebec Law 25 — Private Sector personal-information modernisation

S.Q. 2021, c. 25 · Canada

Quebec's modernised private-sector privacy regime (Law 25, fully in force Sept 2024): privacy-impact assessment, automated-decision transparency, confidentiality-incident reporting to the CAI, data portability, and express consent for sensitive information. Per-requirement bijection at /compliance/quebec-law-25.html.

3

Enforced

2

Designed

0

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Privacy impact assessment (s.3.3)EnforcedL3 Enforceables3.3Decision Map™Risk Engine
Automated-decision transparency (s.12.1)EnforcedL3 Enforceables12.1Decision Map™Replay-Proof™
Confidentiality-incident reporting (s.3.5-3.8)DesignedL2 Designeds3.5Incident DetectorReporting Engine
Data portability (s.27)DesignedL2 Designeds27Reporting EngineWORM audit hash-chain
Consent for sensitive information (s.12)EnforcedL3 Enforceables12Authority GatePurpose Permission™

Law 190/2018

Law No. 190/2018 (implementing measures for the GDPR)

2018 (GDPR implementing act) · Romania

Law 190/2018 is Romania's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Romania-specific national deltas here. Per-requirement bijection at /compliance/ro-law-190-2018.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine

Swedish Data Protection Act

Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning

2018 (GDPR implementing act) · Sweden

Swedish Data Protection Act is Sweden's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Sweden-specific national deltas here. Per-requirement bijection at /compliance/se-dpa.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine

Act 18/2018

Act No. 18/2018 Coll. on Personal Data Protection

2018 (GDPR implementing act) · Slovakia

Act 18/2018 is Slovakia's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Slovakia-specific national deltas here. Per-requirement bijection at /compliance/sk-act-18-2018.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GDPR transposition (national basis) — substantive obligations reuse the GDPR registryEnforcedL3 Enforceablegdpr-transpositionPurpose Permission™Decision Map™
Supervisory authority + accountability — disclosable processing accountEnforcedL3 Enforceablesupervisory-authorityEvidence Pack™Reporting Engine
Breach notification (national channel) — Art. 33/34 record assemblyEnforcedL3 Enforceablebreach-notificationIncident DetectorReporting Engine

China PIPL

PIPL — Personal Information Protection Law of the People's Republic of China

PIPL (effective 2021-11-01) · China

PIPL governs the processing and cross-border provision of personal information of individuals in the PRC. Chapter III sets the lawful routes for cross-border provision (CAC security assessment, CAC standard contract, or personal-information-protection certification) plus a data-localisation duty for critical-information-infrastructure operators and large processors. This framework is REGISTERED in the §70 Framework Mapping Rail and surfaced by §72 (Jurisdiction & Data-Sovereignty Authority) at the cross-border admissibility boundary; deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.

0

Enforced

0

Designed

1

Out of scope

1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no PIPL requirement is bound to a KYE Protocol™ artefact yet. The §72 cross-border admissibility binding (kye.cross_border.transfer.v1.residency_verdict) is platform-level and applies across regimes; PIPL-specific deep mapping (CAC routes, localisation duties) is scheduled through the §70 rail. Coverage is never inflated.Out of scopeL1 MappedPIPL Chapter III — cross-border provision of personal information (Arts. 38-43); full text not yet decomposed into requirement-level mappings—

UK IDTA / Data Bridge

UK International Data Transfer regime — IDTA, Addendum and UK Data Bridge

IDTA + International Data Transfer Addendum (in force 2022-03-21) · United Kingdom

The UK regime for restricted international transfers under UK GDPR / DPA 2018 ss.17A-19: the ICO International Data Transfer Agreement (IDTA), the UK Addendum to the EU SCCs, and UK adequacy regulations ('data bridges'). This framework is REGISTERED in the §70 Framework Mapping Rail and surfaced by §72 (Jurisdiction & Data-Sovereignty Authority) at the cross-border admissibility boundary; deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.

0

Enforced

0

Designed

1

Out of scope

1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no UK-transfer requirement is bound to a KYE Protocol™ artefact yet. The §72 cross-border admissibility binding (kye.cross_border.transfer.v1.residency_verdict) is platform-level; UK-IDTA-specific deep mapping (IDTA clauses, data-bridge adequacy) is scheduled through the §70 rail. Coverage is never inflated.Out of scopeL1 MappedUK GDPR Chapter V + DPA 2018 ss.17A-19; ICO IDTA / Addendum / data-bridge adequacy regulations — full text not yet decomposed into requirement-level mappings—

Singapore PDPA

Singapore Personal Data Protection Act 2012 (PDPA)

PDPA 2012 (No. 26 of 2012), as amended 2020 · Singapore

Singapore's baseline data-protection statute, administered by the Personal Data Protection Commission (PDPC): consent, notification and purpose-limitation obligations, deemed consent by notification, the legitimate-interests exception, mandatory data-breach notification, data portability, and the Do Not Call registry (as amended by the Personal Data Protection (Amendment) Act 2020). This framework is REGISTERED in the §70 Framework Mapping Rail — distinct from Bulgaria's PDPA, which is registered separately — and connects to the §63 Memory Authority Rail, whose four memory-lifecycle schema deltas were validated against Singapore-PDPC guidance. Deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.

0

Enforced

0

Designed

1

Out of scope

1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no PDPA requirement is bound to a KYE Protocol™ artefact yet. The §63 Memory Authority Rail's Singapore-PDPC-validated schema deltas (ai_specific_notice, withdrawal_route, use_type, use_admissibility_ref) are platform-level and cross-regime; PDPA-specific deep mapping is scheduled through the §70 rail. Coverage is never inflated.Out of scopeL1 MappedPDPA 2012 Parts III-VIA — consent, purpose limitation, notification, access/correction, data-breach notification, data portability; full text not yet decomposed into requirement-level mappings—

DPDP Act 2023

Digital Personal Data Protection Act, 2023

Act No. 22 of 2023 · India

KYE™ governs the AUTHORITY + EVIDENCE layer of personal-data processing at the action boundary: whether a consequential action against personal data was authorised under a declared purpose (§12), and whether that decision is sealed and replayable (§13/§30). KYE™ is OUT-OF-SCOPE for the substantive data-governance obligations a Data Fiduciary owes directly — obtaining valid consent from Data Principals, publishing notices, appointing a Data Protection Officer, conducting Data Protection Impact Assessments, and answering the Board. Those are the customer's own systems, processes and counsel; KYE™ evidences the action, it does not discharge the duty (§70 §4). Deep per-requirement mapping: 8 requirements, 3 enforced by KYE™ runtime, 5 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.

1

Enforced

0

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority + evidence at the action boundary — enforced by KYE™ runtime and verified by CIEnforcedL3 Enforceabledpdp-act-2023.PURPOSE-LIMITATION — Personal data processed only for the purpose for which consent was given, dpdp-act-2023.ACTION-EVIDENCE — Every consequential action on personal data is evidenced and replayable, dpdp-act-2023.ERASURE-ROUTE — Data Principal right to erasure is routed and evidencedkye.compliance.attestation.v1kye.evidence.decision_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context_seal.v1internalinternalinternal
Obligations owed directly by the regulated entity — NOT discharged by KYE™KYE™ governs the AUTHORITY + EVIDENCE layer of personal-data processing at the action boundary: whether a consequential action against personal data was authorised under a declared purpose (§12), and whether that decision is sealed and replayable (§13/§30). KYE™ is OUT-OF-SCOPE for the substantive data-governance obligations a Data Fiduciary owes directly — obtaining valid consent from Data Principals, publishing notices, appointing a Data Protection Officer, conducting Data Protection Impact Assessments, and answering the Board. Those are the customer's own systems, processes and counsel; KYE™ evidences the action, it does not discharge the duty (§70 §4).Out of scopeL1 Mappeddpdp-act-2023.NOTICE-CONSENT — Itemised notice and valid consent obtained from the Data Principal, dpdp-act-2023.BREACH-INTIMATION — Personal-data breach intimated to the Board and affected Data Principals, dpdp-act-2023.SDF-OBLIGATIONS — Significant Data Fiduciary duties — DPO, independent audit, DPIA, dpdp-act-2023.CHILDREN-DATA — Verifiable parental consent and no tracking or targeted advertising directed at children, dpdp-act-2023.CROSS-BORDER — Transfer of personal data outside India subject to Government restriction—

Financial-services regulation

Payments and operational-resilience regulation specific to banks, payment institutions, and the EU financial sector.

ECOA / Reg B

ECOA / Regulation B — Equal Credit Opportunity Act

ECOA (15 U.S.C. §1691 et seq.) / Regulation B (12 C.F.R. Part 1002) · United States

ECOA prohibits discrimination in any aspect of a credit transaction and Regulation B operationalises it, including §1002.9 adverse-action notices with a specific statement of reasons. KYE Protocol™ governs whether an AI lending agent's consequential credit decision may proceed — only under a named-authority decision purpose-scoped to the credit transaction, with every adverse action carrying a Decision Map™ (the specific reasons, explainable) bound to a §61 contestability route and sealed into a signed replay-provable Evidence Pack™. The disparate-impact statistics, the credit-scoring feature choice, and the model's fairness validation stay the lender's own quantitative fair-lending work (honest scope, §0). Per-requirement bijection at /compliance/ecoa-reg-b.html.

2

Enforced

1

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Credit-decision authority at the action boundaryEnforcedL3 Enforceableecoa-reg-b.credit-decision-named-authorityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Adverse-action notice with specific reasonsEnforcedL3 Enforceableecoa-reg-b.adverse-action-decision-mapDecision Map™Evidence Pack™Contestability routeReplay-Proof™
Prohibited-basis non-discrimination evidenceDesignedL2 Designedecoa-reg-b.prohibited-basis-non-discrimination-evidenceDecision Map™Audit WORM
Fair-lending statistical analysis & model fairnessThe disparate-impact regression, less-discriminatory-alternative search, and model-fairness validation are the lender's own quantitative fair-lending work — KYE™ is an AI-authority and evidence layer, not a fair-lending analytics engine.Out of scopeL1 Mappedecoa-reg-b.fair-lending-statistical-analysis—

FCRA

FCRA — Fair Credit Reporting Act

Fair Credit Reporting Act (15 U.S.C. §1681 et seq.) / Regulation V (12 C.F.R. Part 1022) · United States

FCRA §1681m requires a user of a consumer report who takes adverse action based on it to give an adverse-action notice naming the reporting agency and the consumer's rights. KYE Protocol™ governs whether an AI lending agent may act on a consumer report — only under a named-authority decision with a permissible purpose, with every report-driven adverse action carrying a Decision Map™ (the report's contribution + the named reporting agency) bound to a §61 contestability route and sealed into a signed replay-provable Evidence Pack™. The report generation, the scoring of report data, and the accuracy of report contents stay the consumer-reporting agency's and furnisher's work (honest scope, §0). Per-requirement bijection at /compliance/fcra.html.

3

Enforced

1

Designed

2

Out of scope

6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Credit-report use authority at the decision boundaryEnforcedL3 Enforceablefcra.credit-report-use-authorityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Adverse-action-on-report notice (specific reasons + agency identity)EnforcedL3 Enforceablefcra.adverse-action-on-report-noticeDecision Map™Evidence Pack™Contestability route
Consumer-report data accuracy & furnisher disputesReport-content accuracy, the furnisher's §1681s-2 duties, and reinvestigation of disputes are the reporting agency's and furnisher's obligations — KYE™ governs the lending agent's decision, not the report.Out of scopeL1 Mappedfcra.report-accuracy-and-furnisher-disputes—
Employment / tenant consumer-report use authorityEnforcedL3 Enforceablefcra.employment-report-permissible-purpose-and-disclosureAuthority GatePurpose Permission™Evidence Pack™
Employment pre-adverse-action two-step noticeDesignedL2 Designedfcra.pre-adverse-action-noticeDecision Map™Contestability route
Consumer-report data disposalDisposal of the consumer-report copy and underlying data is the user's own data-handling duty over data KYE™ does not hold — KYE™ governs the agent's authority-to-act, not the report data.Out of scopeL1 Mappedfcra.disposal-of-consumer-report-data—

ICRAA

ICRAA — California Investigative Consumer Reporting Agencies Act

California Investigative Consumer Reporting Agencies Act (ICRAA), Cal. Civ. Code §1786 et seq. · United States

ICRAA is the California-jurisdiction overlay on the federal FCRA for INVESTIGATIVE consumer reports (character / reputation / mode-of-living information gathered through interviews — the bulk of California employment and tenant background screening). It is stricter than FCRA: §1786.16 requires clear-and-conspicuous written notice AND the consumer's written authorization plus a nature-and-scope disclosure before an investigative consumer report is procured; §1786.40 requires an adverse-action notice naming the agency. KYE Protocol™ governs whether an AI agent may PROCEED to procure or act on an investigative consumer report — only under a named-authority decision with a permissible purpose, a recorded written-consent authority, and every adverse action carrying a Decision Map™ + the named agency bound to a §61 contestability route and sealed into a signed replay-provable Evidence Pack™. KYE™ is NOT a consumer reporting agency: it does not generate the report, conduct the interviews, judge the accuracy of the report contents, or run the reinvestigation (honest scope, §0/§70). Per-requirement bijection at /compliance/icraa.html.

3

Enforced

1

Designed

1

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Investigative-report use authority at the procurement/decision boundaryEnforcedL3 Enforceableicraa.investigative-report-use-authorityAuthority GatePurpose Permission™Evidence Pack™
California written notice + written authorization + nature-and-scope disclosureEnforcedL3 Enforceableicraa.written-consent-and-nature-scope-disclosureAuthority GateDecision Map™Evidence Pack™
Adverse-action-on-investigative-report notice (reasons + agency identity)EnforcedL3 Enforceableicraa.adverse-action-noticeDecision Map™Evidence Pack™Contestability route
Consumer copy + dispute / reinvestigation routeDesignedL2 Designedicraa.consumer-copy-and-dispute-routeContestability routeDelegated Auditability
Investigative-report content accuracy & agency reinvestigation dutiesReport-content accuracy, the reasonable-procedures duty (§1786.20), and the agency's reinvestigation (§1786.24) are the investigative consumer reporting agency's obligations — KYE™ governs the user's decision, not the report, and is not a CRA.Out of scopeL1 Mappedicraa.report-accuracy-and-agency-reinvestigation—

FCA CONC

FCA CONC — Consumer Credit Sourcebook

FCA Handbook CONC — Consumer Credit Sourcebook · United Kingdom

FCA CONC governs UK consumer-credit conduct, including CONC 5 responsible lending (creditworthiness & affordability) and CONC 7 arrears, default & forbearance. KYE Protocol™ governs whether an AI lending agent's creditworthiness-driven or arrears action may proceed — only under a named-authority decision purpose-scoped to the credit agreement, with the action carrying a Decision Map™ recording that the creditworthiness assessment was relied on, bound to a §61 forbearance/contestability route, and sealed into a signed replay-provable Evidence Pack™. The affordability calculation and credit-policy adequacy stay the lender's own responsible-lending work (honest scope, §0). Per-requirement bijection at /compliance/fca-conc.html.

1

Enforced

1

Designed

1

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Creditworthiness/arrears action authority at the boundaryEnforcedL3 Enforceablefca-conc.lending-action-named-authorityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Creditworthiness-reliance & forbearance evidenceDesignedL2 Designedfca-conc.creditworthiness-reliance-evidenceDecision Map™Evidence Pack™Contestability route
Affordability calculation & credit-policy adequacyThe affordability calculation, income/expenditure modelling, and credit-policy adequacy under CONC 5 are the lender's own responsible-lending work — KYE™ governs the agent's action, not the calculation.Out of scopeL1 Mappedfca-conc.affordability-calculation-and-policy—

AICPA SSTS

AICPA SSTS — Statements on Standards for Tax Services

2024 · United States

AICPA Statements on Standards for Tax Services (2024) — the enforceable standards for tax-return positions (reasonable basis / disclosure), reasonable inquiry & reliance on data, and the form & content of advice. KYE Protocol™ governs whether an AI-generated tax position / advice may proceed under a named member's authority, with the SSTS standards recorded before the action — the KYE™ Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Tax-return positions (SSTS No. 1)DesignedL2 Designedaicpa-ssts.ssts1-reasonable-basis, aicpa-ssts.ssts1-disclosureAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Data & reasonable inquiry (SSTS No. 3)DesignedL2 Designedaicpa-ssts.ssts3-reasonable-inquiryEvidence Pack™Replay-Proof™Action Admissibility™ Gate
Form & content of advice (SSTS No. 7)DesignedL2 Designedaicpa-ssts.ssts7-form-of-adviceAction Admissibility™ GateAuthority Finality™Evidence Pack™

AIFMD / UCITS

AIFMD / UCITS — Fund Manager Authority, Risk Management & Investment Limits

Directive 2011/61/EU & Directive 2009/65/EC · European Union

AIFMD (Directive 2011/61/EU) and the UCITS Directive (Directive 2009/65/EC) govern EU collective-investment fund management — fund-manager authorisation & conduct, the risk-management function & limits, investment limits & diversification, and recordkeeping / depositary oversight. KYE Protocol™ governs whether an AI-assisted investment decision/action is within the fund's mandate and limits, authorised, evidenced, and final at the action boundary — the KYE™ Investment Decision Authority Pack™. KYE Protocol™ does not run the risk-management function, judge whether a decision is correct, produce investment intelligence, or act as a fund manager. Per-requirement bijection at framework-coverage-bijection.

4

Enforced

0

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Fund manager authorisation & conductEnforcedL3 Enforceableaifmd-ucits.fund-manager-authorisation-conductAction Admissibility™ GateAuthority Finality™Evidence Pack™
Risk-management function & limitsEnforcedL3 Enforceableaifmd-ucits.risk-management-function-limitsAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Investment limits & diversificationEnforcedL3 Enforceableaifmd-ucits.investment-limits-diversificationAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Recordkeeping & depositary oversightEnforcedL3 Enforceableaifmd-ucits.recordkeeping-depositary-oversightEvidence Pack™Replay-Proof™Action Admissibility™ Gate

APRA CPS 230

APRA CPS 230 — Operational Risk Management

Effective 1 July 2025 · Australia

APRA Prudential Standard CPS 230 — operational risk management, business continuity and service-provider management for APRA-regulated entities. Per-requirement bijection at /compliance/apra-cps-230.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Operational risk management (paras 13-21)EnforcedL3 EnforceableCPS 230 §13, CPS 230 §15, CPS 230 §18Risk EngineDecision EngineAuthority GatePurpose Permission™Resilience Loop™
Incident notification to APRA (para 20)Detection + package assembly enforced; the regulator-side delivery channel to APRA is in build.EnforcedL3 EnforceableCPS 230 §20Incident DetectorReporting Engine
Business continuity + service-provider management (paras 30-48)EnforcedL3 EnforceableCPS 230 §35, CPS 230 §42Authority RegisterSPoF registryEdge Governance Safety FloorOffline Evidence Log

FSA AI Guidelines

FSA AI / Model Governance Expectations for Financial Institutions

FSA AI Discussion Paper (June 2024) + Supervision Guidelines · Japan

The Japan Financial Services Agency's AI governance and model-risk expectations for financial institutions — AI governance & accountability, model risk management, human oversight, explainability and operational resilience. KYE Protocol™ evidences the expectations that bind an AI-supported financial action at runtime. Per-requirement bijection at /compliance/fsa-guidelines-ai.html.

2

Enforced

1

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
AI governance, accountability & model risk managementEnforcedL3 EnforceableFSA AI governance expectation, FSA model-risk expectationPurpose Permission™Risk EngineConformance RunnerDrift Detector
Human oversight & explainability/customer disclosureEnforcedL3 EnforceableFSA human-oversight expectation, FSA explainability expectationGovernedUI™Authority Resolution™Decision Map™Evidence Pack™
Operational resilience & incident reporting to the FSAKYE™ assembles the FSA notification package; the regulator-side delivery channel to the FSA is designed pending the per-jurisdiction reporting connector.DesignedL1 MappedFSA operational-resilience expectationIncident DetectorReporting Engine

Consumer-Driven Banking

Canada Consumer-Driven Banking Framework (open banking)

Consumer-Driven Banking Act (2024) · Canada

Canada's consumer-driven banking (open banking) framework under the Consumer-Driven Banking Act, 2024 (stood up by the FCAC): accreditation of participants, consumer consent + data-sharing control, a common technical/security standard, and oversight + accountability. Per-requirement bijection at /compliance/canada-cdb.html.

4

Enforced

0

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Accreditation of participantsEnforcedL3 EnforceableaccreditationAuthority GateRisk Engine
Consumer consent + data-sharing controlEnforcedL3 EnforceableconsentAuthority GatePurpose Permission™
Common technical + security standardEnforcedL3 Enforceabletechnical-standardAuthority Gate
Oversight + accountabilityEnforcedL3 EnforceableoversightAuthority GateReporting Engine

Companies Act 2006

UK Companies Act 2006 — Accounting Records, True & Fair Accounts & Filing with the Registrar

2006 · United Kingdom

The UK Companies Act 2006 — adequate accounting records (s.386), true and fair view (s.393), director responsibility & board approval (s.414), and filing of the statutory accounts with the Registrar of Companies / Companies House (s.441/s.442). KYE Protocol™ governs whether an AI-generated financial entry / statement / filing may proceed to a consequential action under a named accountant's / director's authority, with §36 two-person sign-off on the irreversible Companies House submission — the KYE™ Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

4

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Adequate accounting records (s.386)DesignedL2 Designedcompanies-act-2006.s386-adequate-recordsEvidence Pack™Replay-Proof™Action Admissibility™ Gate
True & fair view (s.393)DesignedL2 Designedcompanies-act-2006.s393-true-and-fairAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Director responsibility & approval (s.414)DesignedL2 Designedcompanies-act-2006.s414-director-responsibilityAction Admissibility™ GateAuthority Finality™Evidence Pack™
Filing with the Registrar / Companies House (s.441/s.442)DesignedL2 Designedcompanies-act-2006.s441-filing-with-registrar, companies-act-2006.s442-filing-deadlinesAction Admissibility™ GateAuthority Finality™Evidence Pack™

DORA

DORA — Digital Operational Resilience Act

Regulation (EU) 2022/2554 · European Union

EU regulation for the digital operational resilience of the financial sector.

4

Enforced

0

Designed

1

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
ICT risk-management frameworkEnforcedL3 EnforceableArt. 5-16Purpose Permission™Authority GateWORM audit hash-chain
ICT incident detection & reconstructionEnforcedL3 EnforceableArt. 17-23WORM audit hash-chainDecision replay
ICT third-party register & concentration analysisEnforcedL3 EnforceableArt. 28(3)Directory tenant proxyWORM audit hash-chain
Tamper-evident resilience evidenceResilience-testing outcomes are recorded today; signed resilience evidence packs are in build.EnforcedL3 EnforceableArt. 24-27Evidence Pack™ signing (COSE-Sign1)
ICT third-party contractual arrangementsExit strategies, audit rights, and termination clauses require contract-management tooling outside KYE™.Out of scopeL1 MappedArt. 15, Art. 28-30—

DORA Incident

DORA ICT Incident Reporting — Article 19 + classification RTS

DORA — Regulation (EU) 2022/2554, Article 19 + classification RTS · European Union

DORA ICT Incident Reporting (Regulation (EU) 2022/2554, Article 19) is the EU financial-sector ICT-incident reporting regime. KYE Protocol™ governs whether an AI-assisted containment action, incident classification, or staged-report timing decision under it may proceed to a consequential incident action — under a named accountable officer's authority, with incident-evidence chain-of-custody recorded, no AI-asserted classification relied on without a pinned signal source, a signed replay-provable Evidence Pack™ per decision, and a contestability record so any decision can be reconstructed and challenged. Threat detection / SIEM-EDR runtime / forensics / remediation stays the entity's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/dora-ict-incident.html.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Named-authority on the containment / response actionEnforcedL3 Enforceabledora-ict-incident.containment-action-authorityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Incident-evidence chain-of-custody & report integrityEnforcedL3 Enforceabledora-ict-incident.incident-evidence-integrityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Disclosure-timing authority on the staged reporting clockEnforcedL3 Enforceabledora-ict-incident.staged-report-timing-authorityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Threat detection, forensics & remediation engineeringThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine.Out of scopeL1 Mappeddora-ict-incident.threat-detection-forensics-remediation—

EU 6AMLD

EU Sixth Anti-Money Laundering Directive (6AMLD) — Directive (EU) 2018/1673

Directive (EU) 2018/1673 · European Union

The EU Sixth Anti-Money Laundering Directive (Directive (EU) 2018/1673) harmonises money-laundering offences, the 22 predicate offences, aiding/abetting/inciting, and corporate liability across the EU. KYE Protocol™ governs whether an AI agent's AML action may proceed at the action boundary under a named compliance officer's authority, with due diligence before the action and replay-provable provenance. KYE Protocol™ does not run transaction-monitoring models, does not decide whether conduct is criminal money-laundering, and does not replace the institution's AML program or legal advice.

0

Enforced

4

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Predicate offences & scope (Art. 2/3)DesignedL2 Designedeu-6amld.predicate-offences-scopeAction Admissibility™ GateAuthority Finality™Evidence Pack™
Aiding, abetting & inciting (Art. 4)DesignedL2 Designedeu-6amld.aiding-abetting-incitingAction Admissibility™ GateEvidence Pack™Replay-Proof™
Corporate / legal-person liability (Art. 7/8)DesignedL2 Designedeu-6amld.corporate-liabilityAction Admissibility™ GateEvidence Pack™Replay-Proof™
Sanctions & competent-authority cooperation (Art. 9-10)DesignedL2 Designedeu-6amld.competent-authority-cooperationAction Admissibility™ GateAuthority Finality™Evidence Pack™

EU DAC

EU DAC — Directive on Administrative Cooperation (DAC6 + DAC7)

dac6-dac7 · European Union

EU Directive on Administrative Cooperation — DAC6 mandatory disclosure of reportable cross-border arrangements (hallmarks A–E, main-benefit test, 30-day window) and DAC7 platform-operator reporting. KYE Protocol™ governs whether an AI-generated arrangement / advice that may be reportable proceeds only after the hallmark / disclosure screen is recorded — the KYE™ Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
DAC6 hallmark screeningDesignedL2 Designedeu-dac.dac6-reportable-arrangement, eu-dac.dac6-main-benefit-testAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
DAC6 disclosure & reporting windowDesignedL2 Designedeu-dac.dac6-disclosure-windowAction Admissibility™ GateAuthority Finality™Evidence Pack™
DAC7 platform reportingDesignedL2 Designedeu-dac.dac7-platform-reportingEvidence Pack™Replay-Proof™Action Admissibility™ Gate

FATF 40 Recommendations

FATF 40 Recommendations — International Standards on Combating Money Laundering and the Financing of Terrorism & Proliferation

2012 (as amended) · International

The FATF 40 Recommendations are the global AML/CFT authority anchor — risk-based approach (R.1), customer due diligence & beneficial ownership (R.10), record-keeping (R.11), the Travel Rule (R.16), and suspicious-transaction reporting (R.20). KYE Protocol™ governs whether an AI agent's AML action may proceed at the action boundary (alert triage, sanctions screening, SAR/STR drafting, KYC/CDD) under a named compliance officer's authority, with §36 two-person sign-off on the consequential SAR/STR filing — the KYE™ AML & Financial-Crimes Governance Pack™. KYE™ Prot™ocol™ does not run transaction-monitoring models, does not decide whether a transaction is truly money-laundering, and does not replace the institution's AML program.

5

Enforced

0

Designed

0

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Risk-based approach (R.1)EnforcedL3 Enforceablefatf-40-recommendations.r1-risk-based-approachAction Admissibility™ GateAuthority Finality™Evidence Pack™
Customer due diligence & beneficial ownership (R.10)EnforcedL3 Enforceablefatf-40-recommendations.r10-customer-due-diligenceAction Admissibility™ GateEvidence Pack™Replay-Proof™
Record-keeping (R.11)EnforcedL3 Enforceablefatf-40-recommendations.r11-record-keepingAction Admissibility™ GateEvidence Pack™Replay-Proof™
Travel Rule — wire / virtual-asset transfers (R.16)EnforcedL3 Enforceablefatf-40-recommendations.r16-travel-ruleAction Admissibility™ GateEvidence Pack™
Suspicious transaction reporting (R.20)EnforcedL3 Enforceablefatf-40-recommendations.r20-suspicious-transaction-reportingAction Admissibility™ GateAuthority Finality™Evidence Pack™

FCA COBS

FCA COBS — Conduct of Business Sourcebook (UK Investment Conduct)

FCA Handbook COBS · United Kingdom

The FCA Conduct of Business Sourcebook (COBS) governs UK investment business with clients — the client's best interests rule (COBS 2.1.1R), suitability (COBS 9), best execution (COBS 11), and recordkeeping. KYE Protocol™ governs whether an AI-assisted investment decision/action is within mandate, authorised, evidenced, and final at the action boundary — the KYE™ Investment Decision Authority Pack™. KYE Protocol™ does not perform the suitability assessment, judge whether a recommendation is correct, produce investment intelligence, or act as an investment adviser. Per-requirement bijection at framework-coverage-bijection.

4

Enforced

0

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Client's best interests rule (COBS 2.1.1R)EnforcedL3 Enforceablefca-cobs.client-best-interests-ruleAction Admissibility™ GateAuthority Finality™Evidence Pack™
Suitability (COBS 9 / 9A)EnforcedL3 Enforceablefca-cobs.suitability-cobs9Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Best execution (COBS 11.2 / 11.2A)EnforcedL3 Enforceablefca-cobs.best-execution-cobs11Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Recordkeeping of advice & ordersEnforcedL3 Enforceablefca-cobs.recordkeeping-advice-ordersEvidence Pack™Replay-Proof™Action Admissibility™ Gate

FRC Ethical Standard

FRC Ethical Standard — Integrity, Objectivity & Independence

2024 · United Kingdom

The Financial Reporting Council's Ethical Standard — integrity, objectivity & independence, professional competence & due care, and the threats-and-safeguards framework for auditors and accountants. KYE Protocol™ governs whether an AI-generated entry / statement / conclusion may proceed under a named professional's authority, with the objectivity / independence / competence basis recorded before the action — the KYE™ Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

4

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
IntegrityDesignedL2 Designedfrc-ethical-standard.integrityAction Admissibility™ GateAuthority Finality™Evidence Pack™
Objectivity & independenceDesignedL2 Designedfrc-ethical-standard.objectivity-independenceAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Professional competence & due careDesignedL2 Designedfrc-ethical-standard.professional-competenceAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Threats & safeguards frameworkDesignedL2 Designedfrc-ethical-standard.threats-safeguardsAction Admissibility™ GateAuthority Finality™Evidence Pack™

FSB Sound Practices

FSB Sound Practices for the Responsible Adoption of AI in Finance

consultation-2026-06 · International

The Financial Stability Board's Sound Practices for the Responsible Adoption of AI in Finance (consultation, 10 June 2026) sets supervisory expectations for how financial institutions govern AI across model risk, accountability, third-party dependency, and operational resilience. This framework is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped — no requirement has been bound to a KYE Protocol™ artefact, so coverage is honestly reported as out of scope pending deep mapping. The §70 honesty bar forbids claiming enforced/designed coverage before a requirement is bound to a cited artefact. Deep mapping will be scheduled through the §70 rail (by hand, the §59 deterministic pipeline, or the §70 framework-mapping-agent) once the final report text is pinned.

0

Enforced

0

Designed

1

Out of scope

1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): the framework is declared in framework-registry.json but no requirement has been bound to a KYE Protocol™ artefact yet. Coverage is reported out of scope until the deep mapping runs through the §70 rail — never inflated to imply enforcement that does not exist.Out of scopeL1 MappedFSB Sound Practices (full consultation text — not yet decomposed into requirement-level mappings)—

FCA MCOB

FCA MCOB — Mortgage Conduct of Business (FCA Handbook)

FCA Handbook · United Kingdom

FCA Handbook conduct rules for regulated mortgage advice, pre-contract disclosure and responsible lending. KYE Protocol™ governs the AUTHORITY of an AI agent to take a suitability / disclosure / responsible-lending action and the EVIDENCE / replay of that action, under named accountability; KYE Protocol™ does not perform the affordability calculation, author the advice, or determine the regulatory correctness of the mortgage recommendation. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Suitability / affordability action admissibilityDesignedL2 Designedfca-mcob.4.7aPurpose Permission™Authority Gate
Pre-contract disclosure evidenceDesignedL2 Designedfca-mcob.5.6Evidence Pack™
Responsible-lending decision recordDesignedL2 Designedfca-mcob.11.6Evidence Pack™Authority Gate
The affordability calculation itselfOut of scopeL1 Mappedfca-mcob.11a.affordability-calc—

FCA Consumer Duty

FCA Consumer Duty (PRIN 2A) — Principle 12 & the four outcomes

PRIN 2A · United Kingdom

FCA Handbook PRIN 2A — the Consumer Duty (Principle 12 + the four outcomes). KYE Protocol™ governs the AUTHORITY of an AI agent to act toward a good retail-customer outcome, the consumer-understanding EVIDENCE, and foreseeable-harm contestability; KYE Protocol™ does not assess price-and-value, author the good-outcome judgement, or determine the firm's Consumer Duty compliance. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Act-to-deliver-good-outcomes authority gateDesignedL2 Designedfca-consumer-duty.prin-2a.2Purpose Permission™Authority Gate
Consumer-understanding evidenceDesignedL2 Designedfca-consumer-duty.prin-2a.6Evidence Pack™
Foreseeable-harm contestabilityDesignedL2 Designedfca-consumer-duty.prin-2a.5Delegated AuditabilityEvidence Pack™
Price-and-value assessmentOut of scopeL1 Mappedfca-consumer-duty.prin-2a.4—

Investment Mandate / IPS

Investment Mandate / IPS — Investment Policy Statement & Discretionary Mandate Authority

2026 · International

The Investment Policy Statement (IPS) / discretionary investment mandate — the authority anchor for AI-assisted investment decisions. Defines permitted investments, concentration / liquidity limits, prohibited investments, named authority / delegation, and reporting obligations. KYE Protocol™ governs whether an AI-assisted investment decision/action is within the recorded mandate, under whose authority it proceeds, evidenced, contestable, and final at the action boundary — the KYE™ Investment Decision Authority Pack™. KYE Protocol™ does not produce investment intelligence, judge whether a thesis is correct, or render any view on alpha / returns / suitability of outcome, and is not an investment adviser. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

4

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Mandate scope & permitted investmentsDesignedL2 Designedinvestment-mandate-ips.mandate-scope-permitted-investmentsAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Constraints, limits & prohibitionsDesignedL2 Designedinvestment-mandate-ips.constraints-limits-prohibitionsAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Named authority & delegationDesignedL2 Designedinvestment-mandate-ips.named-authority-delegationAction Admissibility™ GateAuthority Finality™Evidence Pack™
Reporting & evidence obligationsDesignedL2 Designedinvestment-mandate-ips.reporting-evidence-obligationsEvidence Pack™Replay-Proof™Action Admissibility™ Gate

Circular 230

IRS Circular 230 — Regulations Governing Practice before the IRS

2014-rev · United States

Treasury Department Circular No. 230 (31 CFR Part 10) — the standards of practice (due diligence §10.22, competence §10.35, return positions §10.34, written advice §10.37) for practitioners before the IRS. KYE Protocol™ governs whether an AI-generated tax position/filing/advice may proceed to a consequential action under a named preparer's authority — the KYE™ Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Due diligence & competenceDesignedL2 Designedirs-circular-230.10.22-due-diligence, irs-circular-230.10.35-competenceAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Tax-return positions & written adviceDesignedL2 Designedirs-circular-230.10.34-positions, irs-circular-230.10.37-written-adviceAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Practitioner authority & sign-offDesignedL2 Designedirs-circular-230.preparer-signoffAction Admissibility™ GateAuthority Finality™Evidence Pack™

ISA (UK)

ISA (UK) — International Standards on Auditing (UK)

2024 · United Kingdom

The International Standards on Auditing (UK) — professional scepticism & reasonable assurance (ISA 200), fraud responsibilities (ISA 240), risk identification & assessment (ISA 315), and forming the opinion & reporting (ISA 700). KYE Protocol™ governs whether an AI-generated audit working-paper / conclusion may proceed under a named auditor's authority, with the ISA (UK) responsibilities recorded before the action — the KYE™ Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

4

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Professional scepticism & reasonable assurance (ISA 200)DesignedL2 Designedisa-uk.isa200-professional-scepticismAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Fraud responsibilities (ISA 240)DesignedL2 Designedisa-uk.isa240-fraud-responsibilitiesAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Risk identification & assessment (ISA 315)DesignedL2 Designedisa-uk.isa315-risk-assessmentEvidence Pack™Replay-Proof™Action Admissibility™ Gate
Forming the opinion & reporting (ISA 700)DesignedL2 Designedisa-uk.isa700-forming-opinionAction Admissibility™ GateAuthority Finality™Evidence Pack™

MAS TRM

MAS Technology Risk Management Guidelines

Jan 2021 · Singapore

Monetary Authority of Singapore Technology Risk Management Guidelines — access control, audit logging, IT incident management, third-party risk. Per-requirement bijection at /compliance/mas-trm.html.

2

Enforced

0

Designed

0

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Access control + tamper-resistant audit loggingEnforcedL3 EnforceableMAS TRM — access control, MAS TRM — audit loggingAuthority GateAuthority Revocation OrchestratorWORM audit hash-chainStreaming Logs Contract™
IT incident management + third-party riskThird-party risk enforced via Authority Register + SPoF; the MAS incident-notification delivery channel is in build.EnforcedL3 EnforceableMAS TRM — incident management, MAS TRM — third-party riskIncident DetectorReporting EngineAuthority RegisterSPoF registry

MiFID II

MiFID II — Markets in Financial Instruments Directive II (Investment Services Conduct)

Directive 2014/65/EU · European Union

MiFID II (Directive 2014/65/EU) governs the provision of investment services in the EU — acting in the client's best interest (Art. 24), suitability (Art. 25), best execution (Art. 27), and recordkeeping. KYE Protocol™ governs whether an AI-assisted investment decision/action is within mandate, authorised, evidenced, and final at the action boundary — the KYE™ Investment Decision Authority Pack™. KYE Protocol™ does not perform the suitability assessment, judge whether a recommendation is correct, produce investment intelligence, or act as an investment adviser. Per-requirement bijection at framework-coverage-bijection.

4

Enforced

0

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Acting in the client's best interest (Art. 24)EnforcedL3 Enforceablemifid-ii.art24-best-interestAction Admissibility™ GateAuthority Finality™Evidence Pack™
Suitability & appropriateness (Art. 25)EnforcedL3 Enforceablemifid-ii.art25-suitabilityAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Best execution (Art. 27)EnforcedL3 Enforceablemifid-ii.art27-best-executionAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Recordkeeping & basis of adviceEnforcedL3 Enforceablemifid-ii.recordkeeping-basis-of-adviceEvidence Pack™Replay-Proof™Action Admissibility™ Gate

Pillar Two

OECD Pillar Two — GloBE Rules (Global Minimum Tax) & BEPS

2023-globe · International

OECD/G20 Pillar Two GloBE rules — a 15% global minimum effective tax rate (IIR / UTPR) with a per-jurisdiction top-up tax reported in the GloBE Information Return (GIR). KYE Protocol™ governs whether an AI-generated Pillar Two computation may proceed to a filing or a booked liability — the KYE™ Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
GloBE effective-tax-rate & top-up taxDesignedL2 Designedoecd-pillar-two.globe-top-up-tax, oecd-pillar-two.effective-tax-rateAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
GloBE Information Return (GIR)DesignedL2 Designedoecd-pillar-two.gir-information-returnEvidence Pack™Replay-Proof™Action Admissibility™ Gate
Scope & charging-rule determinationDesignedL2 Designedoecd-pillar-two.scope-charging-ruleAction Admissibility™ GateAuthority Finality™Evidence Pack™

OSFI B-10

OSFI Guideline B-10 — Third-Party Risk Management

Effective 1 May 2024 · Canada

OSFI Guideline B-10 — risk-based management of third-party arrangements for federally regulated financial institutions: the arrangement register, criticality-proportionate risk assessment, and ongoing monitoring + concentration risk. Per-requirement bijection at /compliance/osfi-b-10.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Third-party arrangement registerEnforcedL3 EnforceableregisterAuthority GateRisk Engine
Risk assessment by criticalityEnforcedL3 Enforceablerisk-assessmentRisk Engine
Ongoing monitoring + concentration riskEnforcedL3 EnforceablemonitoringOffline Evidence LogRisk Engine

OSFI B-13

OSFI Guideline B-13 — Technology & Cyber Risk Management

Effective 1 Jan 2024 · Canada

OSFI Guideline B-13 — technology and cyber risk management for federally regulated financial institutions: governance, technology operations + resilience, and cyber security. Per-requirement bijection at /compliance/osfi-b-13.html.

3

Enforced

0

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Governance + risk management (Domain 1)EnforcedL3 Enforceabled1Authority GateRisk Engine
Technology operations + resilience (Domain 2)EnforcedL3 Enforceabled2-asset-register, d2-resilienceAuthority GateEdge Governance Safety FloorOffline Evidence LogRisk Engine
Cyber security — monitoring + incident (Domain 3)EnforcedL3 Enforceabled3Incident DetectorWORM audit hash-chain

OSFI E-23

OSFI Guideline E-23 — Model Risk Management

Effective 1 May 2027 · Canada

OSFI Guideline E-23 — enterprise-wide model risk management across the model lifecycle (model definition expanded to AI/ML): inventory + risk rating, independent validation, ongoing monitoring, and accountability. Per-requirement bijection at /compliance/osfi-e-23.html.

3

Enforced

1

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Model inventory + risk ratingEnforcedL3 EnforceableinventoryAuthority GateRisk Engine
Development + independent validationDesignedL2 DesignedvalidationReplay-Proof™WORM audit hash-chain
Ongoing monitoringEnforcedL3 EnforceablemonitoringDrift DetectorRisk Engine
Roles + accountabilityEnforcedL3 EnforceableaccountabilityAuthority Gate

PCI DSS

PCI DSS — Payment Card Industry Data Security Standard

4.0 · Global

Security standard for entities that store, process, or transmit cardholder data.

2

Enforced

1

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Access control & strong authenticationEnforcedL3 EnforceableReq 7, Req 8Authority GateWebAuthn step-upPurpose Permission™
Audit logging & monitoringEnforcedL3 EnforceableReq 10WORM audit hash-chainDecision replay
Stored account-data protection evidenceKYE™ governs access to account data; signed evidence of protection and a FIPS-validated crypto adapter are in build.DesignedL2 DesignedReq 3Evidence Pack™ signing (COSE-Sign1)FIPS-validated crypto module
Network security, anti-malware & physical accessNetwork segmentation, TLS termination, endpoint protection, and physical access to cardholder data are operated by the customer.Out of scopeL1 MappedReq 1, Req 4, Req 5, Req 9—

PCMLTFA / FINTRAC

PCMLTFA / FINTRAC — Anti-Money-Laundering & Terrorist-Financing

S.C. 2000, c. 17 · Canada

Canada's anti-money-laundering and terrorist-financing regime (PCMLTFA + Regulations, administered by FINTRAC): client identification + KYC, ongoing monitoring, suspicious-transaction reporting, and record-keeping. Per-requirement bijection at /compliance/pcmltfa-fintrac.html.

3

Enforced

1

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Client identification + KYCEnforcedL3 EnforceablekycAuthority GateDecision Map™
Ongoing monitoringEnforcedL3 EnforceablemonitoringDrift DetectorRisk Engine
Suspicious transaction reporting (s.7)DesignedL2 Designeds7-strIncident DetectorReporting Engine
Record-keeping (s.6)EnforcedL3 Enforceables6-recordsWORM audit hash-chain

PSD2 / PSD3

PSD2 / PSD3 — EU Payment Services Directive

PSD2 2015/2366 · European Union

EU payment-services regulation covering strong customer authentication and third-party access to accounts.

2

Enforced

1

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Strong customer authenticationEnforcedL3 EnforceableRTS Art. 4-9WebAuthn step-upAuthority Gate
Third-party-provider access governanceEnforcedL3 EnforceableArt. 66-67Purpose Permission™Directory tenant proxy
Transaction authorisation evidenceEvery transaction authorisation is recorded today; signed, third-party-verifiable transaction evidence is in build.DesignedL2 DesignedArt. 97Evidence Pack™ signing (COSE-Sign1)Decision Map™ signing (JWS-detached)
Liability allocation frameworkKYE™ produces evidence relevant to liability, but the contractual allocation of liability is a legal matter.Out of scopeL1 MappedArt. 97(5)—

RBNZ BS11

RBNZ BS11 — Outsourcing Policy

BS11 Outsourcing Policy · New Zealand

Reserve Bank of New Zealand outsourcing policy — control over outsourced functions, continuity of basic banking functions, continuing compliance evidence. Per-requirement bijection at /compliance/rbnz-bs11.html.

2

Enforced

0

Designed

0

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Outsourcing register + continuity of basic banking functionsEnforcedL3 EnforceableBS11 — outsourcing register, BS11 — basic banking functionsAuthority RegisterSPoF registryEdge Governance Safety FloorOffline Evidence Log
Continuing compliance evidence to RBNZEnforcedL3 EnforceableBS11 — control evidenceEvidence Pack™Regulator Replay agentWORM audit hash-chain

SEC IA Fiduciary

SEC Investment Adviser Fiduciary Duty — Advisers Act of 1940 (Duty of Care & Loyalty)

Investment Advisers Act of 1940 · United States

The US Investment Advisers Act of 1940 (s.206) and the SEC's 2019 fiduciary interpretation establish a federal fiduciary duty for registered investment advisers — a duty of care, a duty of loyalty, and the books-and-records rule (204-2). KYE Protocol™ governs whether an AI-assisted investment decision/action is within mandate, authorised, evidenced, and final at the action boundary — the KYE™ Investment Decision Authority Pack™. KYE Protocol™ does not form the reasonable belief, judge whether advice is correct, produce investment intelligence, or act as an investment adviser. Per-requirement bijection at framework-coverage-bijection.

4

Enforced

0

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Duty of care — reasonable belief best interestEnforcedL3 Enforceablesec-ia-fiduciary.duty-of-care-best-interestAction Admissibility™ GateAuthority Finality™Evidence Pack™
Duty of loyalty — conflicts & disclosureEnforcedL3 Enforceablesec-ia-fiduciary.duty-of-loyalty-conflictsAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Suitability / mandate of adviceEnforcedL3 Enforceablesec-ia-fiduciary.suitability-mandate-of-adviceAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Books & records (Rule 204-2)EnforcedL3 Enforceablesec-ia-fiduciary.books-and-records-204-2Evidence Pack™Replay-Proof™Action Admissibility™ Gate

SOX 404

SOX §404 — Internal Control over Financial Reporting (tax provision)

2002 · United States

Sarbanes-Oxley §404 — management (and auditor) assessment of internal control over financial reporting (ICFR), with the income-tax provision a recurring material-weakness source requiring review controls, documentation, and data integrity. KYE Protocol™ governs whether an AI-generated tax-provision figure may proceed to being booked under recorded management-review controls with replay-provable provenance — the KYE™ Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

4

Enforced

0

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Tax-provision ICFR designEnforcedL3 Enforceablesox-404.tax-provision-icfrAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Review & approval controlsEnforcedL3 Enforceablesox-404.management-review-controlAction Admissibility™ GateAuthority Finality™Evidence Pack™
Documentation & data integrityEnforcedL3 Enforceablesox-404.documentation-data-integrityEvidence Pack™Replay-Proof™Action Admissibility™ Gate
Management attestationEnforcedL3 Enforceablesox-404.management-attestationAction Admissibility™ GateAuthority Finality™Evidence Pack™

FRS 102

UK GAAP — FRS 102 / FRS 105 Recognition, Measurement & Disclosure

2024 · United Kingdom

FRS 102 / FRS 105 (UK GAAP) — recognition and measurement bases, accounting-policy selection and consistency, disclosure requirements, and the micro-entity regime. KYE Protocol™ governs whether an AI-generated entry / statement may proceed with the FRS 102 / FRS 105 recognition, measurement, and disclosure basis recorded before the action — the KYE™ Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

4

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Recognition & measurementDesignedL2 Designeduk-gaap-frs102.frs102-recognition-measurementAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Accounting policies & consistencyDesignedL2 Designeduk-gaap-frs102.frs102-accounting-policiesEvidence Pack™Replay-Proof™Action Admissibility™ Gate
Disclosure requirementsDesignedL2 Designeduk-gaap-frs102.frs102-disclosureAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Micro-entity (FRS 105) regimeDesignedL2 Designeduk-gaap-frs102.frs105-micro-entityAction Admissibility™ GateAuthority Finality™Evidence Pack™

UK MTD

UK Making Tax Digital (MTD) — Digital Record-Keeping & API Filing

2024 · United Kingdom

HMRC Making Tax Digital — digital record-keeping, unbroken digital links from source data to submitted figures, and programmatic filing via the MTD API. KYE Protocol™ governs whether an AI-generated MTD figure may proceed to an API submission under a named preparer's authority, preserving the digital link in replay-provable provenance — the KYE™ Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Digital record-keeping & digital linksDesignedL2 Designeduk-mtd.digital-record-keeping, uk-mtd.digital-linksEvidence Pack™Replay-Proof™Action Admissibility™ Gate
API filing integrityDesignedL2 Designeduk-mtd.api-filing-integrityAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Preparer authority for submissionDesignedL2 Designeduk-mtd.preparer-authority-submissionAction Admissibility™ GateAuthority Finality™Evidence Pack™

US BSA / FinCEN

US Bank Secrecy Act / FinCEN — AML Program, CDD & SAR Requirements

31 U.S.C. 5311 et seq.; 31 CFR Chapter X · United States

The US Bank Secrecy Act (31 U.S.C. 5311 et seq.) and FinCEN regulations (31 CFR Chapter X) require a risk-based AML program (5318(h)), customer due diligence & beneficial ownership (CDD Rule), Suspicious Activity Reports (SARs), and record-keeping. KYE Protocol™ governs whether an AI agent's AML action may proceed at the action boundary under a named BSA/AML officer's authority, with §36 two-person sign-off on the consequential SAR filing. KYE Protocol™ does not run transaction-monitoring models, does not decide whether a transaction is truly suspicious, and does not replace the institution's BSA/AML program.

4

Enforced

0

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
AML program (31 U.S.C. 5318(h))EnforcedL3 Enforceableus-bsa-fincen.aml-program-5318hAction Admissibility™ GateAuthority Finality™Evidence Pack™
Customer due diligence & beneficial ownership (CDD Rule)EnforcedL3 Enforceableus-bsa-fincen.cdd-beneficial-ownershipAction Admissibility™ GateEvidence Pack™Replay-Proof™
Suspicious Activity Reporting (SAR)EnforcedL3 Enforceableus-bsa-fincen.sar-filingAction Admissibility™ GateAuthority Finality™Evidence Pack™
Record-keeping (31 CFR Chapter X)EnforcedL3 Enforceableus-bsa-fincen.record-keepingAction Admissibility™ GateEvidence Pack™Replay-Proof™

Wolfsberg Principles

Wolfsberg Group AML Principles & Guidance

current · International

The Wolfsberg Group publishes industry AML, sanctions-screening, and correspondent-banking due-diligence standards for global banks. KYE Protocol™ governs whether an AI agent's AML or sanctions-screening action may proceed at the action boundary under a named compliance officer's authority, with due diligence before the action and replay-provable provenance. KYE Protocol™ does not run the screening engine, does not decide whether a name is a true sanctions match, and does not replace the institution's AML / sanctions program.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Risk-based KYC / CDDDesignedL2 Designedwolfsberg-principles.risk-based-kyc-cddAction Admissibility™ GateEvidence Pack™Replay-Proof™
Sanctions & transaction screening governanceDesignedL2 Designedwolfsberg-principles.sanctions-screening-governanceAction Admissibility™ GateAuthority Finality™Evidence Pack™
Correspondent-banking due diligenceDesignedL2 Designedwolfsberg-principles.correspondent-banking-due-diligenceAction Admissibility™ GateAuthority Finality™Evidence Pack™

ECB AI Supervisory Expectations

ECB Supervisory Expectations on AI-Amplified Cyber and Operational Risk

emerging-2026 · EU

ECB Banking Supervision's emerging expectations on AI-amplified cyber and operational risk for significant institutions (planned 'dear CEO letter', per Reuters 3 June 2026; part of the ECB 2026–2028 supervisory priorities). REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: no formal requirement text has been published, so coverage is honestly reported as out of scope pending deep mapping. The §70 honesty bar forbids claiming enforced/designed coverage before requirements are pinned. The substance — AI-actor authority, privileged-action gating, incident-response authority, replay-derivable evidence — is already covered by KYE Protocol™'s deep-mapped DORA artefacts and the shipped Cyber Resilience & Incident Authority Pack; deep mapping will graft those once the ECB text is final.

0

Enforced

0

Designed

1

Out of scope

1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no requirement bound to a KYE Protocol™ artefact yet because no formal text is published. Coverage reported out of scope until the ECB requirements are pinned and deep-mapped through the §70 rail — never inflated. The DORA / Cyber Resilience & Incident Authority Pack artefacts already answer the substance and will be grafted on publication.Out of scopeL1 MappedECB AI supervisory expectations (forthcoming dear-CEO letter — not yet decomposed into requirement-level mappings)—

SM&CR

UK Senior Managers & Certification Regime (SM&CR)

2016 (as amended) · United Kingdom

UK SM&CR accountability regime. KYE Protocol™ governs whether an AI agent's action may proceed under a named Senior Manager's delegated authority, with the responsibility line recorded and replay-provable. Consumed via kye:rule-pack:sm-cr + kye:sector-pack:uk-financial-services-sm-cr (§0: never re-mapped). Per-requirement bijection at framework-coverage-bijection.

0

Enforced

2

Designed

0

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
SMF responsibility + duty-of-responsibility evidenceDesignedL2 Designeduk-smcr.smf-responsibility, uk-smcr.duty-of-responsibilityPurpose Permission™Evidence Pack™Replay Proof™
Certification scope + contestable conduct recordDesignedL2 Designeduk-smcr.certification, uk-smcr.conduct-rulesPurpose Permission™Delegated Auditability

Failure to Prevent Fraud

UK Failure to Prevent Fraud (ECCTA 2023)

ECCTA 2023 (in force 1 Sep 2025) · United Kingdom

UK ECCTA 2023 corporate 'failure to prevent fraud' offence. KYE Protocol™ turns AI-actor authority into a demonstrable 'reasonable fraud-prevention procedure': AI actions that could facilitate fraud are gated by named authority, evidenced, and contestable. KYE Protocol™ proves the procedure operated; it does not adjudicate the offence. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

2

Designed

0

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Reasonable procedures (statutory defence) + evidenceDesignedL2 Designeduk-eccta-ftpf.reasonable-procedures, uk-eccta-ftpf.evidence-of-proceduresPurpose Permission™Evidence Pack™Replay Proof™
Fraud risk assessment + monitoringDesignedL2 Designeduk-eccta-ftpf.risk-assessment, uk-eccta-ftpf.monitoring-reviewDecision Map™Delegated Auditability

UK MLR 2017

UK Money Laundering Regulations 2017 (MLR 2017)

SI 2017/692 (as amended) · United Kingdom

UK MLR 2017 AML/CTF obligations. KYE Protocol™ governs whether an AI agent's AML action may proceed under a named compliance officer's authority, with due diligence recorded and replay-provable provenance. Consumed via the aml-financial-crimes spine (§0: never re-mapped). KYE Protocol™ proves the basis; it does not decide whether conduct is money laundering. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

2

Designed

0

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Risk assessment + customer due diligenceDesignedL2 Designeduk-mlr-2017.risk-assessment, uk-mlr-2017.cddPurpose Permission™Decision Map™
Ongoing monitoring + replay-derivable recordsDesignedL2 Designeduk-mlr-2017.ongoing-monitoring, uk-mlr-2017.record-keepingDelegated AuditabilityEvidence Pack™Replay Proof™

MiCA

MiCA — Markets in Crypto-Assets Regulation

Regulation (EU) 2023/1114 · European Union

EU regulation for crypto-asset issuance and crypto-asset service providers (CASPs): custody, conduct, conflicts, complaints, and the Travel Rule overlay. Titles III–IV from Jun 2024; Title V from Dec 2024.

3

Enforced

1

Designed

1

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Custody & administration of crypto-assets (Art. 70, 75, 76)EnforcedL3 EnforceableArt. 75MiCA custody rule packEvidence Pack™ signingAuthority Gate
CASP conduct & conflict-of-interest screening (Art. 66, 72)EnforcedL3 EnforceableArt. 66, Art. 72Purpose Permission™Decision replay
Complaints handling (Art. 71)Evidenced complaint-handling response is design-locked; a CASP complaint-intake-and-tracking runtime path is not yet wired.DesignedL2 DesignedArt. 71Comms Rail (evidenced response)
Travel Rule + AML overlay for crypto-asset transfersEnforcedL3 EnforceableReg (EU) 2023/1113Travel-Rule rule packAML financial-crimes rule pack
Token white paper, authorisation & reserve of assetsReserve of assets, prudential own-funds, white-paper notification and issuer/CASP authorisation are prudential/licensing obligations of the regulated entity and its competent authority, outside KYE™'s lane.Out of scopeL1 MappedArt. 16, Art. 36, Art. 54—

GENIUS Act

GENIUS Act — US payment stablecoin law

GENIUS Act (Pub. L. 119-27, 2025) · United States

First US federal law governing payment stablecoins: 1:1 reserve backing, redemption at par, monthly reserve disclosure, BSA/AML obligations, lawful-order (freeze/seize/burn) capability, and marketing restrictions. Prudential rulemaking deadline July 2026.

2

Enforced

1

Designed

2

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Redemption at par on demandEnforcedL3 Enforceable§4Purpose Permission™Authority Gate
Monthly reserve-composition disclosure (certified)KYE™ produces a tamper-evident, certify-able evidence pack for the disclosure; the reserve-composition data is the issuer's and the disclosure-assembly flow is design-locked, not yet wired.DesignedL2 Designed§4Evidence Pack™ signingWORM audit hash-chain
BSA / AML program + sanctions / lawful-order capabilityEnforcedL3 Enforceable§4AML financial-crimes rule packAuthority GateWORM audit hash-chain
1:1 reserve backing & no-yield constraintHolding/investing the 1:1 reserve and the no-yield prohibition are balance-sheet/product obligations of the issuer, outside KYE™'s lane.Out of scopeL1 Mapped§4—
Issuer authorisation, charter & prudential supervisionFederal/state issuer authorisation, charter and prudential supervision are licensing/supervision obligations of the issuer and its regulator, outside KYE™'s lane.Out of scopeL1 Mapped§3, §5—

Singapore PS Act

Singapore Payment Services Act 2019 (PS Act)

PS Act 2019 (No. 2 of 2019), as amended · Singapore

Singapore's licensing and conduct regime for payment service providers, administered by MAS: seven regulated activities (account issuance, domestic and cross-border money transfer, merchant acquisition, e-money issuance, digital payment token services, money-changing) across three licence classes, with AML/CFT, technology-risk and user-protection conditions. This framework is REGISTERED in the §70 Framework Mapping Rail following the statute-class precedent of the DORA and PSD2/PSD3 rows; deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.

0

Enforced

0

Designed

1

Out of scope

1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no PS Act requirement is bound to a KYE Protocol™ artefact yet. The payment-authorization rail's authority controls are platform-level and cross-regime; PS-Act-specific deep mapping (licence-class conditions, DPT-service obligations) is scheduled through the §70 rail. Coverage is never inflated.Out of scopeL1 MappedPS Act 2019 — licensing (Part 2), conduct of business (Part 3), and AML/CFT + technology-risk licence conditions; full text not yet decomposed into requirement-level mappings—

Singapore SFA

Singapore Securities and Futures Act 2001 (SFA)

SFA 2001 (2020 Revised Edition), as amended · Singapore

Singapore's capital-markets statute, administered by MAS: licensing of capital-markets services, regulation of organised markets and clearing facilities, offers of investments and prospectus requirements, market-conduct prohibitions (false trading, market rigging, insider trading), and derivatives-contract regulation. This framework is REGISTERED in the §70 Framework Mapping Rail following the statute-class precedent of the DORA and PSD2/PSD3 rows; deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.

0

Enforced

0

Designed

1

Out of scope

1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no SFA requirement is bound to a KYE Protocol™ artefact yet. SFA-specific deep mapping (licensing, market-conduct, disclosure obligations) is scheduled through the §70 rail. Coverage is never inflated.Out of scopeL1 MappedSFA 2001 — capital-markets services licensing, market conduct (Part 12), offers of investments (Part 13); full text not yet decomposed into requirement-level mappings—

TARGET2

TARGET2 / T2 RTGS (ECB) — incl. Settlement Finality Directive 98/26/EC

ECB TARGET Guideline (EU) 2022/912 (ECB/2022/8) + Directive 98/26/EC Arts 3 & 5 · European Union

The Eurosystem's real-time gross settlement system settles payment orders in central bank money with finality conferred at the moment of entry under the Settlement Finality Directive — an entered order cannot be unwound. KYE Protocol™ governs the payment-authority dimension: every instruction (human- or AI-agent-originated) must resolve to a live, purpose-scoped mandate of an authorised user of an admitted participant, with the admissibility verdict, sealed decision context and hash-bound Evidence Pack™ complete BEFORE the finality moment, revocation biting on the very next action, and the message's authorisation lineage retained append-only over the record-keeping period. Settlement execution, legal conferral of finality and intraday liquidity/credit stay the Eurosystem's and the participant treasury's own (honest scope, §0). Per-requirement bijection at /compliance/target2-rtgs.html.

4

Enforced

1

Designed

2

Out of scope

7 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Participation, access criteria & authorised-user bindingEnforcedL3 Enforceabletarget2-rtgs.participation-access-authorityPurpose Permission™Authority GateDecision replayEvidence Pack™Replay-Proof™
Settlement finality & the pre-entry authority checkpoint (SFD 98/26/EC)EnforcedL3 Enforceabletarget2-rtgs.pre-settlement-authority-checkpointAuthority GateContext sealEvidence Pack™Replay-Proof™
Suspension, termination & revocation propagationEnforcedL3 Enforceabletarget2-rtgs.revocation-suspension-propagationAuthority GateAuthority-drift monitoringKill-switch semantics
ISO 20022 messaging integrity & record retentionEnforcedL3 Enforceabletarget2-rtgs.message-integrity-recordsEvidence Pack™WORM audit hash-chainRetention policy
Operational resilience, self-certification & incident notificationKYE™ supplies the machine-generated attestation cadence and sealed incident evidence the self-certification and notification duties run on; the participant's BCM programme, endpoint security and the submissions themselves are participant-owned and not claimed as enforced.DesignedL2 Designedtarget2-rtgs.operational-resilience-incident≤90-day attestationEvidence Pack™
Settlement execution & legal conferral of finalitySettlement in central bank money and the SFD's legal conferral of finality/irrevocability are performed and owned by the Eurosystem as system operator — KYE™ is an AI-authority and evidence layer, not a settlement engine or designated system.Out of scopeL1 Mappedtarget2-rtgs.settlement-finality-execution—
Liquidity provision & intraday creditFunding MCAs/DCAs, collateralised intraday credit and liquidity reservations are treasury and central-bank functions — KYE™ is not a liquidity-management or collateral engine.Out of scopeL1 Mappedtarget2-rtgs.liquidity-intraday-credit—

CIPS

CIPS — Cross-Border Interbank Payment System (RMB)

CIPS participant and business rules — direct/indirect participation, ISO 20022 messaging, RTGS + hybrid netting · China

CIPS clears and settles cross-border RMB payments for direct participants (settling on CIPS accounts) and indirect participants routed through sponsoring direct participants, over ISO 20022-based messaging with RTGS and hybrid-netting settlement. KYE Protocol™ governs the payment-authority dimension only: participant mandate binding at the moment of action, the pre-settlement authority checkpoint (verdict + sealed evidence before the instruction is released), message-authorisation lineage retained append-only, and the authority + evidence layer of the participant's OWN financial-crime screening decision under the laws applicable to that participant — KYE™ takes no position on any jurisdiction's sanctions regime and provides nothing that weakens or routes around a screening obligation. Settlement execution, netting sessions and liquidity funding stay the operator's and participants' own (honest scope, §0). Per-requirement bijection at /compliance/cips-cross-border.html.

3

Enforced

2

Designed

1

Out of scope

6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Participation & authorised-user bindingEnforcedL3 Enforceablecips-cross-border.participant-authorityPurpose Permission™Authority GateDecision replayEvidence Pack™Replay-Proof™
Pre-settlement authority checkpoint & irrevocabilityEnforcedL3 Enforceablecips-cross-border.pre-settlement-authority-checkpointAuthority GateContext sealEvidence Pack™Replay-Proof™
ISO 20022 messaging integrity & record retentionEnforcedL3 Enforceablecips-cross-border.message-integrity-recordsEvidence Pack™WORM audit hash-chainRetention policy
Financial-crime screening authority & evidenceScope-guarded: KYE™ governs the authority and evidence layer of the participant's own screening decision under the AML/CTF and sanctions laws applicable to that participant. Screening adjudication itself — list management, matching, disposition — is the participant's / their vendor's own and is not claimed.DesignedL2 Designedcips-cross-border.financial-crime-screening-authorityNamed-authority bindingScreening tool-call evidenceDecision replay
Operational resilience & incident reportingKYE™ supplies sealed incident evidence and the attestation cadence; availability engineering, contingency arrangements and the incident report to the operator are participant-owned and not claimed as enforced.DesignedL2 Designedcips-cross-border.operational-resilience-incident≤90-day attestationEvidence Pack™
Settlement execution & liquidity provisionClearing and settling RMB payments across CIPS accounts, netting sessions and liquidity funding are owned by the system operator and participant treasuries — KYE™ is an AI-authority and evidence layer, not a clearing, settlement or liquidity engine.Out of scopeL1 Mappedcips-cross-border.settlement-execution-liquidity—

UK Faster Payments

UK Faster Payments (FPS)

UK Faster Payment System rules (Pay.UK) + PSR mandatory APP-scam reimbursement for Faster Payments (October 2024) · United Kingdom

Faster Payments processes UK retail payments in near real time — an accepted payment is irrevocable, so there is no recall window to correct an unauthorised agent action. KYE Protocol™ governs the payment-authority dimension: participant and sponsor/aggregator mandate binding at the moment of action, the pre-submission authority checkpoint (verdict + sealed evidence before release), message-authorisation lineage retained append-only over the record-keeping period, and the replay-verifiable authorisation evidence trail an APP-scam reimbursement investigation turns on (who or what authorised, under which mandate, with which fraud-assessment tool-calls). Scheme processing, settlement at the Bank of England, prefunding/net-sender-cap management and the reimbursement adjudication itself stay the scheme's, the Bank's and the PSPs' own (honest scope, §0). Per-requirement bijection at /compliance/uk-fps.html.

3

Enforced

2

Designed

2

Out of scope

7 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Participation, access criteria & authorised-user bindingEnforcedL3 Enforceableuk-fps.participant-access-authorityPurpose Permission™Authority GateDecision replayEvidence Pack™Replay-Proof™
Irrevocability & the pre-submission authority checkpointEnforcedL3 Enforceableuk-fps.pre-submission-authority-checkpointAuthority GateContext sealEvidence Pack™Replay-Proof™
Messaging integrity & record retentionEnforcedL3 Enforceableuk-fps.message-integrity-recordsEvidence Pack™WORM audit hash-chainRetention policy
APP-fraud reimbursement & authorisation evidenceKYE™ supplies the replay-verifiable record of the authorising principal, mandate, purpose scope and fraud-assessment tool-calls a claim investigation needs; the reimbursement adjudication (gross-negligence assessment, 50:50 split, claim payment) is owned by the PSPs, Pay.UK and the PSR and is not claimed as enforced.DesignedL2 Designeduk-fps.app-fraud-reimbursement-evidenceDecision replayEvidence Pack™WORM audit hash-chain
Operational resilience & incident reportingKYE™ supplies sealed incident evidence and the attestation cadence; availability engineering, contingency arrangements and the notifications themselves are participant-owned and not claimed as enforced.DesignedL2 Designeduk-fps.operational-resilience-incident≤90-day attestationEvidence Pack™
Scheme processing & settlement executionCentral-infrastructure processing, deferred multilateral net settlement at the Bank of England, and the conferral of irrevocability on accepted payments are owned by Pay.UK, the infrastructure provider and the Bank — KYE™ is an AI-authority and evidence layer, not a payment processor.Out of scopeL1 Mappeduk-fps.scheme-processing-settlement—
Liquidity provision & net sender capsPrefunding the settlement account, sizing/managing the net sender cap and intraday liquidity monitoring are participant treasury functions — KYE™ is not a liquidity-management engine.Out of scopeL1 Mappeduk-fps.liquidity-net-sender-caps—

SAFR

SAFR — Safeguards for Agentic Finance at Runtime

SAFR v1.0 (July 2026) · Global (industry reference; MAS Project MindForge lineage)

SAFR is an industry reference framework (BuildFin.AI) for a runtime governance layer over agentic AI in financial services: four components (Agent Identity, Controls Repository, Disposition Engine, Audit Log) exchanging a Governance Envelope, sitting after model guardrails and before execution. KYE Protocol™ maps to SAFR component-for-component at the moment-of-action admissibility check and adds Authority Finality™ — a Replay-Proof™ record verifiable from public keys alone. KYE™ governs whether the agentic financial action was allowed to become final; the rails execute if and only if approved.

6

Enforced

2

Designed

0

Out of scope

8 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Runtime governance at the point of action (pre-execution + per-step)EnforcedL3 Enforceablesafr.pre-execution-governance, safr.per-step-independent-authorityPurpose Permission™Decision Engineper-action admissibility
Agent Identity — verified registered principal (SAFR component 1)DesignedL3 Enforceablesafr.agent-identity-verification, safr.authoritative-registry-resolution§0.30 agent-as-principal§52 authority bindingentity hierarchy
Controls Repository & capability-based mandate (SAFR component 2)EnforcedL3 Enforceablesafr.controls-repository, safr.mandate-capability-authorityRules Gateway™§52 authority claimDecision Map™
Deterministic disposition — four outcomes, risk-calibrated (SAFR component 3)DesignedL3 Enforceablesafr.deterministic-disposition, safr.four-outcome-disposition, safr.risk-calibrated-outcomeDecision EngineDecision Map™risk signals
Governance Envelope authenticated to originEnforcedL3 Enforceablesafr.governance-envelope-authenticatedEvidence Pack™tool-call pincontext seal
Immutable, tamper-evident audit log (SAFR component 4)EnforcedL3 Enforceablesafr.immutable-audit-log§30 WORMReplay-Proof™Authority Finality™
Substantive human escalation (bounded, timeout, real authority)EnforcedL3 Enforceablesafr.substantive-human-escalationGovernedUI™ approval modestimeout→block/senior§9 no self-grant
Native + gateway integration and decision-not-settlement boundaryEnforcedL3 Enforceablesafr.native-and-gateway-integration, safr.decision-not-settlement-boundaryPEP (native + gateway)§0.33 Authority Finality™ category

AAOIFI SS

AAOIFI Shariah Standards

AAOIFI Shariah Standards (as at 2023 compilation) · International

AAOIFI's suite of Shariah Standards on Islamic-finance contracts and instruments — the substantive fiqh rulings adopted by many regulators and institutions.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Standards (substantive contract rulings)DesignedL2 DesignedAAOIFI SSPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedAAOIFI SS—

AAOIFI GSIFI

AAOIFI Governance Standards (GSIFI)

AAOIFI Governance Standards for Islamic Financial Institutions (GSIFI) · International

AAOIFI's governance standards defining the Shariah supervisory board, review, audit, and governance-committee arrangements for Islamic financial institutions.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Governance Standards (GSIFI)DesignedL2 DesignedAAOIFI GSIFIPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedAAOIFI GSIFI—

AAOIFI FAS

AAOIFI Financial Accounting Standards (FAS)

AAOIFI Financial Accounting Standards (FAS) · International

AAOIFI's accounting standards for the recognition, measurement and disclosure of Islamic-finance contracts.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Financial Accounting Standards (FAS)DesignedL2 DesignedAAOIFI FASPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedAAOIFI FAS—

AAOIFI ASIFI

AAOIFI Auditing Standards (ASIFI)

AAOIFI Auditing Standards for Islamic Financial Institutions (ASIFI) · International

AAOIFI's auditing standards for external and Shariah-compliance audit of Islamic financial institutions.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Auditing Standards (ASIFI)DesignedL2 DesignedAAOIFI ASIFIPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedAAOIFI ASIFI—

IFSB-10

IFSB-10 — Guiding Principles on Shari'ah Governance Systems

IFSB-10 (2009) · International

IFSB-10 sets guiding principles for the Shariah governance system: competence, independence, confidentiality and consistency of the Shariah board, plus review and audit functions.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance System (IFSB-10 guiding principles)DesignedL2 DesignedIFSB-10Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedIFSB-10—

IFSB

IFSB Prudential Standards (suite)

IFSB prudential standards suite · International

The IFSB's prudential and disclosure standards for institutions offering Islamic financial services, including corporate governance, core principles, and market-discipline disclosures.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Prudential & governance standards (IFSB suite)DesignedL2 DesignedIFSBPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedIFSB—

IIFM

IIFM Documentation Standards

IIFM documentation standards · International

IIFM's standardised master agreements and documentation for Islamic hedging, treasury, interbank and sukuk transactions.

1

Enforced

0

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Documentation & contract standards (IIFM)EnforcedL3 EnforceableIIFMPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedIIFM—

BNM SGF 2019

Bank Negara Malaysia — Shariah Governance Policy Document 2019

BNM/RH/PD 028-100 (2019) · Malaysia

BNM's Shariah Governance Policy Document (2019) sets board oversight, Shariah committee, and Shariah risk/review/audit/research control functions, operating under the binding rulings of BNM's Shariah Advisory Council (SAC).

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (BNM SGF 2019 + SAC/IFSA 2013)DesignedL2 DesignedBNM SGF 2019Purpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedBNM SGF 2019—

CBUAE HSA

CBUAE — Higher Shariah Authority and Shariah Governance Standard

CBUAE Shariah Governance Standard (2020) · United Arab Emirates

The CBUAE requires each Islamic financial institution to maintain an Internal Shariah Supervision Committee and Shariah control functions, operating under the binding resolutions of the CBUAE Higher Shariah Authority (HSA).

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (CBUAE HSA Standard)DesignedL2 DesignedCBUAE HSAPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedCBUAE HSA—

CBB SG Module

Central Bank of Bahrain — Shariah Governance Module

CBB Rulebook — Shariah Governance Module · Bahrain

The CBB Shariah Governance Module mandates AAOIFI standards, an independent Shariah supervisory board, internal Shariah audit and review, and (from 2020) a centralised Shariah board.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (CBB Module)DesignedL2 DesignedCBB SG ModulePurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedCBB SG Module—

SAMA SGF

Saudi Central Bank — Shariah Governance Framework

SAMA Shariah Governance Framework (2020) · Saudi Arabia

SAMA's Shariah Governance Framework requires local banks to establish an independent Shariah committee, a Shariah division, and Shariah review and audit functions.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (SAMA Framework)DesignedL2 DesignedSAMA SGFPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedSAMA SGF—

OJK / DSN-MUI

OJK / DSN-MUI — Indonesian Shariah Governance

OJK Shariah governance regulations + DSN-MUI fatawa · Indonesia

Indonesia operates a two-tier model: DSN-MUI issues national fatawa binding on Islamic financial institutions, while OJK regulates the institution-level Dewan Pengawas Syariah (Shariah Supervisory Board) and compliance functions.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (OJK + DSN-MUI)DesignedL2 DesignedOJK / DSN-MUIPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedOJK / DSN-MUI—

SBP SGF

State Bank of Pakistan — Shariah Governance Framework

SBP Shariah Governance Framework (2018) · Pakistan

SBP's Shariah Governance Framework mandates a board Shariah committee, a resident Shariah board member, a Shariah compliance department, and internal and external Shariah audit, under the SBP Shariah Advisory Committee's rulings.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (SBP Framework)DesignedL2 DesignedSBP SGFPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedSBP SGF—

QCB

Qatar Central Bank — Shariah Supervision and Governance

QCB Islamic banking instructions · Qatar

QCB and the QFCRA require Islamic financial institutions to maintain a Shariah supervisory board and Shariah review/audit functions, with broad reference to AAOIFI standards.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (QCB / QFCRA)DesignedL2 DesignedQCBPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedQCB—

CBK

Central Bank of Kuwait — Shariah Supervisory Governance

CBK Shariah supervisory governance instructions · Kuwait

The CBK requires Islamic banks to maintain an independent Shariah supervisory board and Shariah audit, coordinated with a higher committee for Shariah supervision at the CBK.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (CBK)DesignedL2 DesignedCBKPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedCBK—

CBO IBRF

Central Bank of Oman — Islamic Banking Regulatory Framework (IBRF)

CBO Islamic Banking Regulatory Framework (2012) · Oman

Oman's IBRF mandates a Shariah Supervisory Board, an internal Shariah reviewer, and Shariah audit for Islamic banks and windows, referencing AAOIFI standards.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (CBO IBRF)DesignedL2 DesignedCBO IBRFPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedCBO IBRF—

TKBB

TKBB — Participation Banking Standards (Türkiye)

TKBB participation-banking standards + BDDK regulation · Türkiye

In Türkiye, participation (Islamic) banks are supervised by BDDK; the TKBB Central Advisory Board issues participation-banking standards, and each bank maintains an advisory committee.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Participation Banking Governance (TKBB)DesignedL2 DesignedTKBBPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedTKBB—

CBN NIFI

Central Bank of Nigeria — Non-Interest (Islamic) Financial Institutions

CBN guidelines for non-interest financial institutions · Nigeria

The CBN regulates Non-Interest (Islamic) Financial Institutions; a central Financial Regulation Advisory Council of Experts (FRACE) advises the CBN, and each institution maintains an Advisory Committee of Experts (ACE).

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (CBN NIFI + FRACE)DesignedL2 DesignedCBN NIFIPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedCBN NIFI—

FCA SSB model

UK FCA — Firm-Level Shariah Supervisory Board Model

FCA/PRA firm-level governance (no separate Shariah regime) · uk

The UK has no separate statutory Shariah regime; Islamic financial institutions operate under the standard FCA/PRA perimeter and appoint their own firm-level Shariah supervisory boards, typically applying AAOIFI standards.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Firm-Level Shariah Governance (UK FCA model)DesignedL2 DesignedFCA SSB modelPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedFCA SSB model—

Brunei SFSB

Brunei — Syariah Financial Supervisory Board and BDCB

Syariah Financial Supervisory Board Order + BDCB regulation · Brunei Darussalam

Brunei's Syariah Financial Supervisory Board (SFSB) is the highest authority on Islamic finance matters; BDCB regulates institution-level Syariah advisory bodies.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (Brunei SFSB)DesignedL2 DesignedBrunei SFSBPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedBrunei SFSB—

CBJ Islamic

Central Bank of Jordan — Islamic Banking Shariah Governance

CBJ Islamic banking instructions · Jordan

The CBJ regulates Islamic banks under the Banking Law and dedicated instructions requiring a Shariah supervisory board and Shariah audit.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (CBJ)DesignedL2 DesignedCBJ IslamicPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedCBJ Islamic—

Egypt FRA

Egypt FRA — Islamic Finance Shariah Supervision

FRA Islamic finance regulations (sukuk, takaful) · Egypt

Egypt's FRA regulates non-banking Islamic finance (sukuk, takaful) with a central Shariah supervisory committee; the CBE oversees Islamic banking.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (Egypt FRA)DesignedL2 DesignedEgypt FRAPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedEgypt FRA—

Sudan HSSB

Central Bank of Sudan — High Shariah Supervisory Board

CBOS High Shariah Supervisory Board framework · Sudan

Sudan operates a fully Islamic banking system; the High Shariah Supervisory Board (HSSB) at the CBOS issues binding rulings, and each bank maintains a Shariah supervisory body.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shariah Governance (Sudan HSSB)DesignedL2 DesignedSudan HSSBPurpose Permission™Authority bindingWORM evidence chain
Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4).Out of scopeL1 MappedSudan HSSB—

RBI IT Governance MD

RBI IT Governance Master Direction

Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices · India

KYE™ governs the AUTHORITY + EVIDENCE layer where AI agents take consequential action inside a regulated entity's operations. KYE™ is OUT-OF-SCOPE for board-level IT governance structures, the entity's information-security programme, business-continuity capability and internal-audit function — those are the regulated entity's own, and RBI supervises them directly (§70 §4). Deep per-requirement mapping: 6 requirements, 2 enforced by KYE™ runtime, 4 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.

1

Enforced

0

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority + evidence at the action boundary — enforced by KYE™ runtime and verified by CIEnforcedL3 Enforceablerbi-master-direction-it.AGENT-ACTION-AUTHORITY — Consequential actions by automated systems resolve to a live delegated authority, rbi-master-direction-it.AUDIT-TRAIL — Tamper-evident audit trail over privileged and consequential operationskye.compliance.attestation.v1kye.evidence.decision_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context_seal.v1internal
Obligations owed directly by the regulated entity — NOT discharged by KYE™KYE™ governs the AUTHORITY + EVIDENCE layer where AI agents take consequential action inside a regulated entity's operations. KYE™ is OUT-OF-SCOPE for board-level IT governance structures, the entity's information-security programme, business-continuity capability and internal-audit function — those are the regulated entity's own, and RBI supervises them directly (§70 §4).Out of scopeL1 Mappedrbi-master-direction-it.IT-GOVERNANCE-STRUCTURE — Board-level IT strategy committee and defined governance structure, rbi-master-direction-it.INFOSEC-PROGRAMME — Information-security policy, controls and periodic assessment, rbi-master-direction-it.BUSINESS-CONTINUITY — Business continuity and disaster-recovery capability with periodic testing, rbi-master-direction-it.IT-ASSURANCE — Independent assurance and internal audit over IT controls—

Healthcare AI — UK regulatory + clinical research

Frameworks specifically governing AI agents in clinical environments and UK medical-device regulation. Per-requirement bijection maps available at /compliance/<framework>.html.

PMDA SaMD

PMDA Software-as-a-Medical-Device (SaMD) Pathway

PMD Act SaMD pathway + PMDA review framework · Japan

The Pharmaceuticals and Medical Devices Agency's Software-as-a-Medical-Device review pathway under the PMD Act, including the SaMD two-step (DASH) approval scheme and AI/ML change-control expectations. KYE Protocol™ evidences the QMS, clinical-evaluation provenance, change-control, post-market surveillance and human-oversight obligations that bind an AI-supported clinical action; device classification and marketing approval remain the manufacturer's submission. Per-requirement bijection at /compliance/pmda-samd.html.

2

Enforced

1

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
QMS evidence & clinical-evaluation provenanceEnforcedL3 EnforceablePMDA SaMD QMS evidence, PMDA SaMD clinical evaluationWORM audit hash-chainEvidence Pack™Data Classification Engine
Change control, versioning & human oversight of clinical decisionsEnforcedL3 EnforceablePMDA SaMD change control, PMDA SaMD human oversightConformance RunnerDrift DetectorGovernedUI™Authority Resolution™
Post-market surveillance & incident reporting to the PMDAKYE™ assembles the PMDA adverse-event notification package; the regulator-side delivery channel to the PMDA is designed pending the per-jurisdiction reporting connector.DesignedL1 MappedPMDA SaMD post-market surveillanceIncident DetectorReporting Engine

CLIA

CLIA — Clinical Laboratory Improvement Amendments (42 CFR Part 493)

42 CFR 493 · US

The Clinical Laboratory Improvement Amendments (42 CFR Part 493) set US federal quality standards for testing on human specimens. KYE Protocol™ enforces the test-report integrity and electronic-record audit-trail slices, and governs the authority of AI-supported result generation — testing, proficiency testing and competency stay the laboratory's quality system. Per-requirement bijection at /compliance/clia.html.

3

Enforced

1

Designed

1

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Test records & result-report integrity (Subpart J, 493.1291)EnforcedL3 Enforceableclia.493.1291-report-integrityDecision replayEvidence Pack™
Audit trail for electronic test recordsEnforcedL3 Enforceableclia.audit-trailWORM audit hash-chain
Test-record retention (493.1105)DesignedL2 Designedclia.493.1105-record-retentionWORM audit hash-chain
Authority & oversight of AI-supported result generation (Subpart M)EnforcedL3 Enforceableclia.493.1445-ai-oversightPurpose Permission™Authority Gate
Analytic-system QC, validation, proficiency testing & competency (Subparts K, H, M)Analytic-system quality control, method validation, proficiency testing and personnel competency are the laboratory's own quality and HR functions — out of scope for an AI-authority-governance protocol.Out of scopeL1 Mappedclia.493-subpart-k-analytic-systems, clia.493-pt-competency—

HAARF v1.0

HAARF — Healthcare AI Agents Regulatory Framework

v1.0 (2026) · Global

Comprehensive security and governance standard for autonomous AI agents in clinical environments — 279 requirements across 8 categories.

1

Enforced

0

Designed

0

Out of scope

1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
279 requirements across 8 categories — risk lifecycle, model passport, cybersecurity, human oversight, agent registration, autonomy governance, bias/equity, tool integrationEnforcedL3 EnforceableHAARF C1–C8Decision EngineEvidence EngineGovernedUI approvalEdge Governance modesShadow ModeAgent Tool Pack™

ISO 15189

ISO 15189:2022 — Medical laboratories: quality and competence

2022 · International

ISO 15189:2022 sets quality and competence requirements for medical laboratories, including patient-safety risk management. KYE Protocol™ enforces the §7.4-7.6 report-integrity, §7.6/§8.4 data-integrity and audit-trail slices where a medical laboratory uses AI-supported decisioning — examination procedures and competence stay the laboratory's quality system. Per-requirement bijection at /compliance/iso-15189.html.

5

Enforced

0

Designed

1

Out of scope

6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Reporting of results & integrity of the report (7.4-7.6)EnforcedL3 Enforceableiso-15189.7.4-report-integrityDecision replayEvidence Pack™
Control of records & audit trail (8.4)EnforcedL3 Enforceableiso-15189.8.4-record-controlWORM audit hash-chain
Information management & data integrity (7.6, 8.4)EnforcedL3 Enforceableiso-15189.7.6-data-integrityDecision replayEvidence Pack™
Impartiality & authorised decision-making (5.1, 6.2)EnforcedL3 Enforceableiso-15189.5.1-impartiality-authorityPurpose Permission™Authority Gate
Risk management & patient-safety evidence (8.5)EnforcedL3 Enforceableiso-15189.8.5-risk-patient-safetyResilience Loop™
Examination processes & technical competence (6, 7.3)Validation of examination procedures, reference intervals, equipment/reagents and technical competence are the medical laboratory's own quality system — out of scope for an AI-authority-governance protocol.Out of scopeL1 Mappediso-15189.6-examination-competence—

MHRA MDR 2002

UK Medical Devices Regulations 2002

2002 as amended through 2024 · United Kingdom

UK Statutory Instrument 2002/618 — risk classes, conformity assessment, essential requirements (Annex I regs 7-12), Annex IX classification rules, and post-market vigilance (regs 44-47). 53 requirements.

1

Enforced

0

Designed

0

Out of scope

1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
53 requirements across risk classes + conformity assessment + essential requirements + classification rules + post-market vigilanceEnforcedL3 EnforceableSI 2002/618Profile classificationSector packSigned evidence packTrust-domain UDI

MHRA PMS 2025

MHRA Post-Market Surveillance Regulations 2025

SI 2024/1368 (effective June 2025) · United Kingdom

Explicit post-market surveillance obligations: PMS plan (Reg 7), post-market clinical follow-up (Reg 8), incident reporting timelines (2/10/15-day), Periodic Safety Update Reports (PSURs), trend reporting. 36 requirements.

1

Enforced

0

Designed

0

Out of scope

1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
36 requirements across PMS plan, PMCF, incident timelines, PSURs, and trend reportingEnforcedL3 EnforceableSI 2024/1368Resilience-loop registryComms-rail templatesAnalytics-plane eventsGovernedUI two-person sign-off

MHRA SaMD & AI

MHRA Software and AI as a Medical Device Change Program

2023 Change Program · United Kingdom

41 requirements: 15 original work-packages + 7 PCCP (Predetermined Change Control Plan) obligations + 9 change-class triggers (capability / model_params / training-data / bias drift) + 6 transparency obligations + 4 oversight/bias-mitigation controls.

1

Enforced

0

Designed

0

Out of scope

1 requirement group — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
41 requirements across SaMD lifecycle, PCCP, change-class triggers, transparency, and oversightEnforcedL3 EnforceableMHRA SaMD Program 2023Canonical change-controlReplay-Proof™ envelopeDecision Map™Evidence Pack™Shadow ModeEdge Governance bundle versioning

PHIPA Ontario

PHIPA (Ontario) — Personal Health Information Protection Act, 2004

S.O. 2004, c. 3, Sched. A · Canada

Ontario's health-privacy statute (PHIPA, 2004): consent + lawful purpose, circle-of-care implied consent, data minimisation, the electronic audit-log duty, access/correction, and IPC breach notification for personal health information. Per-requirement bijection at /compliance/phipa-ontario.html.

4

Enforced

1

Designed

0

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Consent + lawful purpose (ss.29-30, 36-38)EnforcedL3 Enforceables29, s38Authority GateDecision Map™Purpose Permission™
Data minimisation (s.30(2))EnforcedL3 Enforceables30-2Purpose Permission™
Electronic audit log + access control (s.10.1, s.12, O.Reg.329/04 s.6.3)EnforcedL3 Enforceables10.1WORM audit hash-chain
Access + correction (ss.52-55)EnforcedL3 Enforceables52Reporting EngineWORM audit hash-chain
Breach + IPC notification (s.12(2)-(3))DesignedL2 Designeds12-2Incident DetectorReporting Engine

CDSCO MDR 2017

CDSCO Medical Devices Rules 2017

Medical Devices Rules, 2017, as amended · India

Where AI software qualifies as a medical device, KYE™ governs the AUTHORITY + EVIDENCE layer of clinical actions the software takes or recommends. KYE™ is OUT-OF-SCOPE for device classification, licensing, manufacturing quality systems and the clinical determination itself — those belong to the manufacturer and CDSCO (§70 §4). Deep per-requirement mapping: 5 requirements, 2 enforced by KYE™ runtime, 3 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.

1

Enforced

0

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority + evidence at the action boundary — enforced by KYE™ runtime and verified by CIEnforcedL3 Enforceablecdsco-medical-devices.CLINICAL-ACTION-AUTHORITY — Clinical actions by software resolve to a live authority and are evidenced, cdsco-medical-devices.POST-MARKET-EVIDENCE — Records supporting post-market surveillance and adverse-event reviewkye.compliance.attestation.v1kye.evidence.decision_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context_seal.v1internal
Obligations owed directly by the regulated entity — NOT discharged by KYE™Where AI software qualifies as a medical device, KYE™ governs the AUTHORITY + EVIDENCE layer of clinical actions the software takes or recommends. KYE™ is OUT-OF-SCOPE for device classification, licensing, manufacturing quality systems and the clinical determination itself — those belong to the manufacturer and CDSCO (§70 §4).Out of scopeL1 Mappedcdsco-medical-devices.DEVICE-CLASSIFICATION — Risk-based classification of the device, cdsco-medical-devices.LICENSING — Manufacturing or import licence obtained and maintained, cdsco-medical-devices.QMS — Quality management system for design and manufacture—

Sectoral frameworks

Domain-specific AI accountability frameworks scoped to a single regulated sector.

API 580/581

API 580 / API 581 — Risk-Based Inspection for fixed equipment

2016 · Global

API RP 580 (RBI methodology) + API 581 (RBI quantitative technology) for fixed-equipment inspection planning. KYE Protocol™ governs the authority and evidence of an AI-recommended inspect/repair/replace action and records the inspection-interval + failure-mode reference vocabulary; KYE Protocol™ does not compute RBI risk. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

2

Designed

0

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
RBI decision documentation + review (contestable)DesignedL2 Designedapi-580.10.0Evidence Pack™Authority Gate
High-consequence action named-engineer sign-offDesignedL2 Designedapi-581.5.0Authority GateDecision Map™

Australia Group

Australia Group — Biological & Chemical Dual-Use Export Controls

2023 · Global

Australia Group dual-use export-control regime — harmonised control lists for dual-use biological agents, toxins, equipment, and chemical-weapon precursors. KYE Protocol™ governs whether an AI-generated design mapping to a controlled item may proceed to a consequential action — the KYE™ AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Dual-use biological control listDesignedL2 Designedaustralia-group.bio-agents, australia-group.bio-equipmentAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Dual-use chemical precursor listDesignedL2 Designedaustralia-group.chem-precursorsAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Controlled-item action gatingDesignedL2 Designedaustralia-group.controlled-item-gateAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™

BCBS 239

BCBS 239 — Risk Data Aggregation & Risk Reporting Principles

BCBS 239 (Principles for effective risk data aggregation and risk reporting, January 2013) · International

BCBS 239 sets the Basel Committee's 14 principles for effective risk data aggregation and risk reporting. KYE Protocol™ governs whether a model-driven output or risk report under it may proceed to a consequential action — only a currently-validated model used within its approved scope, model changes as named-authority decisions with evidence, every consequential decision pinned to model_id + version + validation reference, and every risk report bound to its data-lineage evidence chain, sealed into a signed replay-provable Evidence Pack™. The quantitative model build / validation mathematics / capital computation / portfolio composition stays the bank's own work (honest scope, §0 — not investment advice). All 14 principles are mapped one row each (honest tri-state). Per-requirement bijection at /compliance/bcbs-239.html.

3

Enforced

0

Designed

3

Out of scope

6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Risk-data governance & named authority on the report (P1)EnforcedL3 Enforceablebcbs-239.principle1-governanceAuthority GateDecision replayEvidence Pack™Replay-Proof™
Risk-data aggregation lineage, completeness & adaptability (P3 / P4 / P6)EnforcedL3 Enforceablebcbs-239.principle3-accuracy-integrity-lineage, bcbs-239.principle4-completeness, bcbs-239.principle6-adaptabilityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Risk-report traceability, cadence & distribution evidence (P7 / P10 / P11)EnforcedL3 Enforceablebcbs-239.principle7-reporting-accuracy, bcbs-239.principle10-frequency, bcbs-239.principle11-distributionAuthority GateDecision replayEvidence Pack™Replay-Proof™
Bank data architecture & crisis-timeliness capability (P2 / P5)The data architecture, IT infrastructure, and crisis-timeliness aggregation capability are the bank's own data and technology estate — KYE™ is an AI-authority and evidence layer, not a data platform.Out of scopeL1 Mappedbcbs-239.principle2-data-architecture, bcbs-239.principle5-timeliness—
Report substance — comprehensiveness & clarity (P8 / P9)Judging material-risk coverage and the report's editorial quality is the bank's risk and reporting functions' own work — KYE™ proves what the report aggregated and how, not whether it covered everything that mattered.Out of scopeL1 Mappedbcbs-239.principle8-comprehensiveness, bcbs-239.principle9-clarity-usefulness—
Supervisory review, remedial tools & home/host cooperation (P12–P14)Principles 12–14 are addressed to supervisors — conducting the review, applying supervisory measures, and home/host cooperation are regulator functions; KYE™'s sealed evidence chains support the bank's side of the review but the obligations sit outside an AI-authority-governance protocol.Out of scopeL1 Mappedbcbs-239.principle12-supervisory-review, bcbs-239.principle13-remedial-actions, bcbs-239.principle14-home-host-cooperation—

Colorado SB21-169

Colorado SB21-169 — Insurers' Use of External Consumer Data & AI

Colorado SB21-169 (Restrict Insurers' Use of External Consumer Data; C.R.S. §10-3-1104.9) + Division of Insurance regulations · United States

Colorado SB21-169 restricts insurers' use of external consumer data, algorithms, and predictive models to prevent unfair discrimination, and requires testing, documentation, and consumer adverse-action reasons. KYE Protocol™ governs whether an AI-assisted underwriting or claims decision relying on external data may proceed to a consequential adverse action — under a named authority, with a recorded adverse-action reason-code, with proxy-discrimination / fairness-evidence captured, a signed replay-provable Evidence Pack™ per decision, and an appeal / contestability record. The external-data selection / pricing / methodology design on the merits stays the insurer's own work (honest scope, §0). Per-requirement bijection at /compliance/colorado-sb21-169.html.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Adverse-action reason explainability to the consumerEnforcedL3 Enforceablecolorado-sb21-169.adverse-action-explainabilityAuthority GateDecision replayEvidence Pack™Replay-Proof™
External-data proxy-discrimination evidenceEnforcedL3 Enforceablecolorado-sb21-169.external-data-discrimination-evidenceAuthority GateDecision replayEvidence Pack™Replay-Proof™
Named-authority on the external-data-driven decisionEnforcedL3 Enforceablecolorado-sb21-169.external-data-decision-authorityAuthority GateDecision replayEvidence Pack™Replay-Proof™
External data source selection & pricing on the meritsThe external-data selection / pricing / methodology design on the merits is the insurer's own work — KYE™ is an AI-authority and evidence layer, not a pricing or data-selection engine.Out of scopeL1 Mappedcolorado-sb21-169.external-data-source-selection-pricing—

COSHH

COSHH — Control of Substances Hazardous to Health Regulations 2002 (UK)

2002 · United Kingdom

UK COSHH 2002 (SI 2002/2677), HSE-enforced. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved COSHH assessments and control instructions — the KYE™ HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
COSHH assessment authored under safety floorDesignedL2 Designedcoshh.reg-6Purpose Permission™Edge Governance Safety Floor
Exposure-control measure advisory pending sign-offDesignedL2 Designedcoshh.reg-7Authority GateDecision Map™
Control-measure instruction contestable + evidencedDesignedL2 Designedcoshh.reg-8Evidence Pack™Authority Gate

CWC / BWC

CWC + BWC — Chemical & Biological Weapons Conventions

1997-2024 · Global

Chemical Weapons Convention (CWC, Schedules 1/2/3) + Biological Weapons Convention (BWC, prohibited bio/toxin agents). KYE Protocol™ governs whether an AI-generated molecule or agent mapping to a scheduled/prohibited item may proceed to a consequential action — a hard stop routed to oversight, the KYE™ AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
CWC scheduled chemicals (Schedule 1/2/3)DesignedL2 Designedcwc-bwc.cwc-schedule1, cwc-bwc.cwc-schedule2-3Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
BWC prohibited biological / toxin agentsDesignedL2 Designedcwc-bwc.bwc-prohibited-agentsAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Prohibited-agent action stopDesignedL2 Designedcwc-bwc.prohibited-agent-stopAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™

DoD 5015.2

DoD 5015.02-STD — Records Management Application Design Criteria (RMA spine)

2007 · United States

DoD 5015.02-STD records-management-application spine for the KYE™ Chain of Authority™ for Iron Mountain InSight DXP. KYE Protocol™ overlays the action-boundary access-control + named-authority + governance-decision audit (enforced); the RMA record-declaration / file-plan / disposition criteria are out-of-scope (owned by the records-manager). §0: KYE Protocol™ retains PROOF-OF-GOVERNANCE, not the customer's records.

2

Enforced

0

Designed

2

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Access-control decision at the action boundary (authority overlay)EnforcedL3 Enforceabledod-5015-2.access-control-action-decision, dod-5015-2.named-authority-bindingAction Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Audit of the action decision (authority overlay)EnforcedL3 Enforceabledod-5015-2.action-decision-auditAction Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Record declaration & categorisation / file plan (RMA criteria)Out of scopeL1 Mappeddod-5015-2.record-declaration-file-plan—
Disposition & transfer (RMA criteria)Out of scopeL1 Mappeddod-5015-2.disposition-transfer—

Dodd-Frank §922

Dodd-Frank §922 + SEC Rule 21F — Whistleblower Programme

Dodd-Frank Act §922 (15 U.S.C. §78u-6) + SEC Rules 21F (whistleblower programme) · United States

Dodd-Frank §922 + SEC Rule 21F — Whistleblower Programme is the US SEC whistleblower programme (confidentiality, anti-retaliation, the Rule 21F-17 anti-impediment prohibition). KYE Protocol™ governs whether an AI-assisted access to a whistleblower's identity or a consequential case action may proceed — on a recorded need-to-know authority, with confidentiality evidence captured, a signed Evidence Pack™, and a contestability record. Assessing the securities-law tip on its merits, awarding the bounty, and adjudicating the §922 / Rule 21F claim stay with the SEC and counsel (honest scope, §0). Per-requirement bijection at /compliance/dodd-frank-whistleblower.html.

2

Enforced

0

Designed

1

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Confidentiality & anti-impediment evidence for a whistleblower's identityEnforcedL3 Enforceabledodd-frank-whistleblower.confidentiality-evidenceAuthority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & reconstruction of the handling / retaliation determinationEnforcedL3 Enforceabledodd-frank-whistleblower.handling-contestability-reconstructionAuthority GateDecision replayEvidence Pack™Replay-Proof™
Securities-law merits, bounty award & Rule 21F adjudicationAssessing the tip, awarding the bounty, and adjudicating the §922 / Rule 21F claim is the SEC's and counsel's determination — KYE™ is an AI-authority and evidence layer, not an enforcement engine.Out of scopeL1 Mappeddodd-frank-whistleblower.securities-merits-and-award—

EU AI Act insurance

EU AI Act — Annex III High-Risk Insurance

Regulation (EU) 2024/1689 (EU AI Act) — Annex III high-risk insurance use-cases (life & health risk assessment / pricing) · European Union

The EU AI Act classifies AI used for risk assessment and pricing in life and health insurance as high-risk (Annex III), triggering human-oversight (Art. 14), record-keeping (Art. 12), and transparency obligations. KYE Protocol™ governs whether an AI-assisted insurance decision in scope may proceed to a consequential adverse action — under a named human-oversight authority, with a recorded adverse-action reason-code, fairness-evidence captured, a signed replay-provable Evidence Pack™ (the Art. 12 log) per decision, and an appeal / contestability record. The risk pricing / system build / conformity assessment on the merits stays the provider's own work (honest scope, §0). Per-requirement bijection at /compliance/eu-ai-act-insurance.html.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Human oversight authority over the high-risk decision (Art. 14)EnforcedL3 Enforceableeu-ai-act-insurance.annex3-human-oversightAuthority GateDecision replayEvidence Pack™Replay-Proof™
Record-keeping / logging of the AI decision (Art. 12)EnforcedL3 Enforceableeu-ai-act-insurance.annex3-record-keeping-loggingAuthority GateDecision replayEvidence Pack™Replay-Proof™
Transparency & contestability of the decisionEnforcedL3 Enforceableeu-ai-act-insurance.annex3-transparency-contestabilityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Risk pricing, system build & conformity assessment on the meritsThe risk pricing / high-risk system build / Art. 43 conformity assessment on the merits is the provider's own work — KYE™ is an AI-authority and evidence layer at the action boundary, not a system-build, pricing, or conformity-assessment engine.Out of scopeL1 Mappedeu-ai-act-insurance.risk-pricing-system-build-conformity—

EU Evidence Reg

EU Evidence Regulation 2020/1783 + eIDAS — Evidence Authenticity & Transmission

Regulation (EU) 2020/1783 (taking of evidence in civil/commercial matters) + eIDAS Regulation (EU) 910/2014 (electronic evidence integrity) · European Union

EU Evidence Regulation 2020/1783 + eIDAS — Evidence Authenticity & Transmission is the EU cross-border evidence and electronic-integrity framework (Regulation 2020/1783 + eIDAS). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/eu-evidence-regulation.html.

2

Enforced

0

Designed

1

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Chain-of-custody & integrity for cross-border evidence transmissionEnforcedL3 Enforceableeu-evidence-regulation.evidence-authenticity-transmissionAuthority GateDecision replayEvidence Pack™Replay-Proof™
Integrity-bound, contestable Evidence Pack™ (eIDAS-aligned)EnforcedL3 Enforceableeu-evidence-regulation.eidas-integrity-evidence-packAuthority GateDecision replayEvidence Pack™Replay-Proof™
Member-State admissibility & substantive evidential assessmentThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine.Out of scopeL1 Mappedeu-evidence-regulation.member-state-admissibility—

EU Whistleblower Dir.

EU Whistleblower Directive — Directive (EU) 2019/1937

Directive (EU) 2019/1937 (protection of persons who report breaches of Union law) · European Union

EU Whistleblower Directive — Directive (EU) 2019/1937 is the EU whistleblower-protection framework (confidentiality, acknowledgement / feedback clocks, prohibition of retaliation). KYE Protocol™ governs whether an AI-assisted intake-triage decision, an access to a reporter's identity / PII, a case disposition (close / escalate), or an adverse action on a reporter may proceed to a consequential action — under a named handler's authority, on a recorded need-to-know basis, with confidentiality and retaliation-risk evidence captured, a signed replay-provable Evidence Pack™ per consequential action, and a contestability record so any disposition can be reconstructed and challenged. The substantive investigation / allegation merits / remediation decision stays the organisation's own work (honest scope, §0). Per-requirement bijection at /compliance/eu-whistleblower-directive.html.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Confidentiality & need-to-know access to a reporter's identityEnforcedL3 Enforceableeu-whistleblower-directive.confidentiality-need-to-know-accessAuthority GateDecision replayEvidence Pack™Replay-Proof™
Named-authority on the case disposition (acknowledgement / feedback clocks)EnforcedL3 Enforceableeu-whistleblower-directive.case-disposition-named-authorityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & reconstruction of the handlingEnforcedL3 Enforceableeu-whistleblower-directive.handling-contestability-reconstructionAuthority GateDecision replayEvidence Pack™Replay-Proof™
Substantive investigation & whether the breach occurredInvestigating the report on its merits and deciding the remediation is the organisation's own ethics / legal work — KYE™ is an AI-authority and evidence layer, not an investigation or adjudication engine.Out of scopeL1 Mappedeu-whistleblower-directive.substantive-investigation—

Fed SR 11-7

Fed SR 11-7 — Supervisory Guidance on Model Risk Management

SR 11-7 / OCC 2011-12 (Supervisory Guidance on Model Risk Management, April 2011) · United States

Fed SR 11-7 / OCC 2011-12 is the US supervisory guidance on model risk management (development, validation, governance). KYE Protocol™ governs whether a model-driven output or risk report under it may proceed to a consequential action — only a currently-validated model used within its approved scope, model changes as named-authority decisions with evidence, every consequential decision pinned to model_id + version + validation reference, and every risk report bound to its data-lineage evidence chain, sealed into a signed replay-provable Evidence Pack™. The quantitative model build / validation mathematics / capital computation / portfolio composition stays the bank's own work (honest scope, §0 — not investment advice). Per-requirement bijection at /compliance/fed-sr-11-7.html.

4

Enforced

0

Designed

1

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Validated-model use authority at the decision boundaryEnforcedL3 Enforceablefed-sr-11-7.model-use-named-authorityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Model change control as a named-authority decisionEnforcedL3 Enforceablefed-sr-11-7.model-change-controlAuthority GateDecision replayEvidence Pack™Replay-Proof™
Decision traceability to model version & validation referenceEnforcedL3 Enforceablefed-sr-11-7.decision-provenance-traceabilityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Model inventory & policy controls on model useEnforcedL3 Enforceablefed-sr-11-7.inventory-policy-controlsAuthority GateDecision replayEvidence Pack™Replay-Proof™
Quantitative model development, validation & capital mathematicsThe quantitative model build, validation mathematics, and capital & liquidity computation are the bank's own quantitative work — KYE™ is an AI-authority and evidence layer, not a model-validation or capital-calculation engine.Out of scopeL1 Mappedfed-sr-11-7.quantitative-development-validation—

OCC AI Supervision

OCC AI Supervisory Expectations — Model Risk · Third-Party Risk · New-Activity / Filing Readiness

2024 · United States

The U.S. Office of the Comptroller of the Currency (OCC) supervises national banks and federal savings associations. Its supervisory expectations for a bank deploying consequential AI draw on OCC Bulletin 2011-12 (model risk management, joint with Fed SR 11-7), OCC Bulletin 2013-29 + the 2023 Interagency Third-Party Risk Management Guidance, OCC heightened standards for risk governance, and the OCC's new-activity / examiner-engagement expectations. KYE Protocol™ governs the action-boundary subset at runtime — only a consequential AI action under its approved use and recorded authority proceeds, out-of-scope actions escalate or are refused, and every action that proceeds is replay-provable to an OCC examiner from public keys alone. KYE™ operationalises the OCC's expectations — it does NOT replace them (§0.25 integrate-not-compete). Honest scope: KYE™ does NOT run the bank's MRM program, validate models, make the bank's regulatory filing, or judge whether the AI's output is correct; that work, and the OCC's own supervisory determinations, stay out of scope. Broader, separate spine from the fed-sr-11-7 MRM-only row (references SR 11-7 lineage, does not duplicate it). Per-requirement bijection at /compliance/occ-ai-supervision.html.

4

Enforced

0

Designed

1

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Model risk management (approved-use authority + model-change as a named-authority decision)EnforcedL3 Enforceableocc-ai-supervision.validated-use-authority-at-the-decision-boundary, occ-ai-supervision.model-change-as-named-authority-decisionPurpose Permission™Authority GatewayGovernedUI™ named-authority sign-offEvidence Pack™
Third-party / vendor AI risk (external authority register + escalation before finality)KYE™ governs what external/vendor AI is authorised to DO inside the bank's action boundary; vendor due-diligence and contract review on the merits stay the bank's own (honest scope).EnforcedL3 Enforceableocc-ai-supervision.third-party-ai-authority-register, occ-ai-supervision.out-of-scope-escalation-before-finalityAuthority RegisterAuthority Gateway (REQUIRE_APPROVAL)Edge Governance Safety FloorGovernedUI™ escalation
New-activity / filing & examiner readiness (replay-provable Evidence Packs + action-authority inventory)KYE™ proves to an OCC examiner how each consequential AI action was governed; making the regulatory filing and the OCC's supervisory determinations stay out of scope (honest scope).EnforcedL3 Enforceableocc-ai-supervision.new-activity-examiner-replayable-evidence, occ-ai-supervision.action-authority-inventoryEvidence Pack™Replay-Proof™WORM audit hash-chainEntity & Principal Registry
Heightened-standards governance & accountability (named accountability at the action boundary)KYE™ binds and proves named accountability at the boundary; staffing and running the bank's three-lines-of-defence operating model stays the bank's own (honest scope).EnforcedL3 Enforceableocc-ai-supervision.heightened-standards-named-accountabilityGovernedUI™ named-authority sign-offDelegated Auditability RailAuthority Finality™
Model development, validation & supervisory determinationsDeveloping and validating the model, running the bank's MRM program, making the regulatory filing, and the OCC's own supervisory determinations / examination ratings are the bank's and the regulator's own work — KYE™ is an AI-authority and evidence layer, not a model-validation engine, a filing service, or a supervisor.Out of scopeL1 Mappedocc-ai-supervision.model-development-validation-supervisory-determinations—

FRCP e-discovery

FRCP e-Discovery — Rules 26 / 34 / 37 + FRE 502 (privilege)

FRCP (2015 e-discovery amendments; Rules 26 / 34 / 37 + FRE 502) · United States

FRCP e-Discovery — Rules 26 / 34 / 37 + FRE 502 (privilege) is the US federal e-discovery and privilege framework (FRCP 26 / 34 / 37 + FRE 502). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/frcp-ediscovery.html.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Named-authority on the privilege / discovery determinationEnforcedL3 Enforceablefrcp-ediscovery.rule26g-discovery-certificationAuthority GateDecision replayEvidence Pack™Replay-Proof™
Discovery chain-of-custody for produced / withheld ESIEnforcedL3 Enforceablefrcp-ediscovery.rule34-esi-chain-of-custodyAuthority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & sanctions-reconstruction of the determinationEnforcedL3 Enforceablefrcp-ediscovery.rule37-sanctions-reconstructionAuthority GateDecision replayEvidence Pack™Replay-Proof™
Substantive privilege judgment & attorney certification on the meritsThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine.Out of scopeL1 Mappedfrcp-ediscovery.substantive-privilege-judgment—

FRE 901/902

FRE 901 / 902 — Authentication & Self-Authentication of Evidence

FRE 901 / 902 (Authentication & Self-Authentication; 2017 ESI amendments) · United States

FRE 901 / 902 — Authentication & Self-Authentication of Evidence is the US evidence-authentication framework (FRE 901 / 902). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/fre-authentication.html.

2

Enforced

0

Designed

1

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
No-hallucinated-citation provenance pin for AI assertionsEnforcedL3 Enforceablefre-authentication.rule901-authentication-evidenceAuthority GateDecision replayEvidence Pack™Replay-Proof™
Hash-bound self-authenticating Evidence Pack™EnforcedL3 Enforceablefre-authentication.rule902-self-authenticating-recordAuthority GateDecision replayEvidence Pack™Replay-Proof™
Substantive admissibility, relevance & weight of the evidenceThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine.Out of scopeL1 Mappedfre-authentication.substantive-admissibility—

ABA Model Rules

ABA Model Rules of Professional Conduct (AI-relevant duties)

Rules 1.1 / 1.4 / 1.5 / 1.6 / 5.1 / 5.3 + ABA Formal Opinion 512 (2023) · United States

The ABA Model Rules of Professional Conduct set the US legal profession's core duties — competence (Rule 1.1, incl. technological competence), communication (1.4), reasonable fees (1.5), confidentiality (1.6), and supervision of subordinate lawyers and non-lawyer assistance (5.1 & 5.3) — extended to generative AI by ABA Formal Opinion 512 (2023) and state-bar guidance (California 2023, NYSBA 2024). KYE Protocol™ governs whether an AI-assisted legal action supporting each duty may proceed to a consequential step — under a named lawyer's authority, with the verification, confidentiality-isolation, communication and supervisory-accountability record captured as a signed, replay-provable Evidence Pack™ that predates the incident. Each AI-relevant duty is mapped onto the existing KYE™ Legal Pack™ (kye:sector-pack:legal) workflows at the requirement level and marked designed (authority boundary bound, no runtime engine wired yet), except the reasonable-fees duty (Rule 1.5), which has no KYE™ artefact governing legal billing and is honestly out of scope. KYE™ governs the AUTHORITY BOUNDARY of the AI action — NOT wholesale compliance with a professional-conduct duty, and NOT the practice of law: it does not draft, advise, judge attorney conduct, or render the lawyer's professional judgment. Per-requirement bijection at /compliance/aba-model-rules.html.

0

Enforced

5

Designed

1

Out of scope

6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Competence — verified AI work product authority (Rule 1.1)DesignedL2 Designedaba-model-rules.rule-1-1-competencePurpose Permission™Authority GateEvidence Pack™
Client communication release authority (Rule 1.4)DesignedL2 Designedaba-model-rules.rule-1-4-communicationPurpose Permission™Evidence Pack™
Confidentiality & client-information isolation (Rule 1.6)DesignedL2 Designedaba-model-rules.rule-1-6-confidentialityAuthority GateZero Contamination
Supervisory responsibility & firm AI-governance record (Rules 5.1 & 5.3)DesignedL2 Designedaba-model-rules.rule-5-1-5-3-supervisionDelegated AuditabilityGovernedUI™Evidence Pack™
Generative-AI use authority boundary (Formal Opinion 512)DesignedL2 Designedaba-model-rules.formal-opinion-512-genaiPurpose Permission™Evidence Pack™GovernedUI™
Reasonable fees (Rule 1.5)No KYE™ artefact governs legal billing or fee reasonableness — the firm's own regulated determination. Honest out-of-scope (§0); coverage never inflated.Out of scopeL1 Mappedaba-model-rules.rule-1-5-fees—

GDPR Whistleblowing

GDPR (Whistleblowing) — Special-Category & Data-Minimisation in Reports

Regulation (EU) 2016/679 (GDPR) — whistleblowing data-protection slice (Art. 5, 6, 9, 15, 21) · European Union

GDPR (Whistleblowing) — Special-Category & Data-Minimisation in Reports is the data-protection slice of whistleblowing (data minimisation, special-category restriction, need-to-know access, data-subject access / objection). KYE Protocol™ governs whether an AI-assisted access to the personal / special-category data in a report may proceed — on a recorded need-to-know authority, with data-minimisation evidence captured, a signed Evidence Pack™, and a contestability record so a data-subject access or objection can be reconstructed. The lawful-basis assessment of the underlying processing, the DPIA, and data-subject adjudication stay with the controller / DPO / supervisory authority (honest scope, §0). Per-requirement bijection at /compliance/gdpr-whistleblower.html.

2

Enforced

0

Designed

1

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Need-to-know access & data-minimisation evidence for special-category report dataEnforcedL3 Enforceablegdpr-whistleblower.special-category-need-to-know-accessAuthority GateDecision replayEvidence Pack™Replay-Proof™
Data-subject contestability (access / objection) reconstructionEnforcedL3 Enforceablegdpr-whistleblower.data-subject-contestabilityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Lawful-basis assessment, DPIA & data-subject adjudicationThe lawful-basis assessment, the DPIA, and data-subject adjudication is the controller's / DPO's / supervisory authority's determination — KYE™ is an AI-authority and evidence layer, not a data-protection-compliance engine.Out of scopeL1 Mappedgdpr-whistleblower.lawful-basis-and-dpia—

ICH Q1

ICH Q1 — Stability Testing

ICH Q1A(R2) (2003) · International

ICH Q1 — Stability Testing is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q1.html.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority over an AI stability summary at the action boundaryDesignedL2 Designedich-q1.named-authorityPurpose Permission™Authority Gate
Stability study science & shelf-life determinationThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine.Out of scopeL1 Mappedich-q1.science—

ICH Q10

ICH Q10 — Pharmaceutical Quality System

ICH Q10 (2008) · International

ICH Q10 — Pharmaceutical Quality System is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q10.html.

3

Enforced

1

Designed

1

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Management responsibility & named-authorityEnforcedL3 Enforceableich-q10.management-responsibility-authorityAuthority GateDecision replayEvidence Pack™
Change-management authority at the action boundaryEnforcedL3 Enforceableich-q10.change-management-authorityAuthority GateDecision replayEvidence Pack™
Management review control (sign-off gate)EnforcedL3 Enforceableich-q10.management-review-controlAuthority GateDecision replayEvidence Pack™
Personnel competence recorded before the actionDesignedL2 Designedich-q10.personnel-competencePurpose Permission™Authority Gate
Quality-system substance (CAPA / change science)The scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine.Out of scopeL1 Mappedich-q10.quality-system-substance—

ICH Q2

ICH Q2(R2) — Validation of Analytical Procedures

ICH Q2(R2) (2023) · International

ICH Q2(R2) — Validation of Analytical Procedures is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q2.html.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Validation-package authority at the action boundaryEnforcedL3 Enforceableich-q2.validation-package-authorityAuthority GateDecision replayEvidence Pack™
Validation-conclusion justification recorded before the actionEnforcedL3 Enforceableich-q2.validation-conclusion-justificationAuthority GateDecision replayEvidence Pack™
Replay-provable validation-package provenanceEnforcedL3 Enforceableich-q2.validation-package-provenanceAuthority GateDecision replayEvidence Pack™
Analytical-method science & validation statisticsThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine.Out of scopeL1 Mappedich-q2.analytical-method-science—

ICH Q3

ICH Q3 — Impurities

ICH Q3 family · International

ICH Q3 — Impurities is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q3.html.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority over an AI impurity-assessment summary at the action boundaryDesignedL2 Designedich-q3.named-authorityPurpose Permission™Authority Gate
Impurity science & threshold determinationThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine.Out of scopeL1 Mappedich-q3.science—

ICH Q5

ICH Q5 — Quality of Biotechnological Products

ICH Q5 family · International

ICH Q5 — Quality of Biotechnological Products is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q5.html.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority over an AI biotech-quality summary at the action boundaryDesignedL2 Designedich-q5.named-authorityPurpose Permission™Authority Gate
Biotech product science (viral safety / comparability / stability)The scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine.Out of scopeL1 Mappedich-q5.science—

ICH Q6

ICH Q6 — Specifications

ICH Q6 family · International

ICH Q6 — Specifications is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q6.html.

0

Enforced

1

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority over an AI specification-justification summary at the action boundaryDesignedL2 Designedich-q6.named-authorityPurpose Permission™Authority Gate
Specification science & acceptance-criteria settingThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine.Out of scopeL1 Mappedich-q6.science—

ICH Q7

ICH Q7 — GMP for Active Pharmaceutical Ingredients

ICH Q7 (2000) · International

ICH Q7 — GMP for Active Pharmaceutical Ingredients is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q7.html.

4

Enforced

0

Designed

1

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Quality-Unit release authority at the action boundaryEnforcedL3 Enforceableich-q7.quality-unit-batch-releaseAuthority GateDecision replayEvidence Pack™
Records & data integrity (ALCOA+) screened before the actionEnforcedL3 Enforceableich-q7.data-integrity-alcoaAuthority GateDecision replayEvidence Pack™
Replay-provable GMP-record provenanceEnforcedL3 Enforceableich-q7.gmp-record-provenanceAuthority GateDecision replayEvidence Pack™
Batch release sign-off gate (§36 two-person)EnforcedL3 Enforceableich-q7.batch-release-signoffAuthority GateDecision replayEvidence Pack™
Physical API manufacture & analytical testingThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine.Out of scopeL1 Mappedich-q7.physical-api-manufacture—

ICH Q8

ICH Q8(R2) — Pharmaceutical Development

ICH Q8(R2) (2009) · International

ICH Q8(R2) — Pharmaceutical Development is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q8.html.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Development-content authority at the action boundaryEnforcedL3 Enforceableich-q8.development-justification-provenanceAuthority GateDecision replayEvidence Pack™
Development justification recorded before the actionEnforcedL3 Enforceableich-q8.justification-recorded-before-actionAuthority GateDecision replayEvidence Pack™
Replay-provable development-content provenanceEnforcedL3 Enforceableich-q8.development-content-provenanceAuthority GateDecision replayEvidence Pack™
Development science (QbD / design space / control strategy)The scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine.Out of scopeL1 Mappedich-q8.development-science—

ICH Q9

ICH Q9(R1) — Quality Risk Management

ICH Q9(R1) (2023) · International

ICH Q9(R1) — Quality Risk Management is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q9.html.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Risk-based decision authority at the action boundaryEnforcedL3 Enforceableich-q9.qrm-decision-authorityAuthority GateDecision replayEvidence Pack™
Risk-decision justification recorded before the actionEnforcedL3 Enforceableich-q9.risk-decision-justificationAuthority GateDecision replayEvidence Pack™
Replay-provable QRM provenanceEnforcedL3 Enforceableich-q9.qrm-provenanceAuthority GateDecision replayEvidence Pack™
Risk-assessment science & control-strategy selectionThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine.Out of scopeL1 Mappedich-q9.risk-assessment-science—

IEC 61508

2010 · Global

The umbrella functional-safety standard defining Safety Integrity Levels (SIL 1-4) and the safety lifecycle. KYE Protocol™ governs the authority, evidence and finality of an AI-recommended physical-safety action against a SIL-validated model-authority claim; KYE Protocol™ does not perform the SIL determination. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
SIL-validated model authority + safety floorDesignedL2 Designediec-61508.part-1.7.6Purpose Permission™Edge Governance Safety Floor
Functional-safety decision evidence + named accountabilityDesignedL2 Designediec-61508.part-1.7.14Evidence Pack™Reporting Engine
Contestable verification outcomesDesignedL2 Designediec-61508.part-3.7.9Evidence Pack™Authority Gate

IEC 61511

IEC 61511:2016 — Safety instrumented systems for the process industry

2016 · Global

The process-sector application of IEC 61508 defining safety instrumented systems (SIS). KYE Protocol™ governs the authority and finality of an AI-recommended physical-safety action (turbine trip, unit shutdown, derate) under the safety floor. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
SIS actuating decision under safety floorDesignedL2 Designediec-61511.clause-11.3Purpose Permission™Edge Governance Safety Floor
Operation & maintenance named accountabilityDesignedL2 Designediec-61511.clause-16.2Authority GateDecision Map™
Contestable / reviewable SIS decisionsDesignedL2 Designediec-61511.clause-11.9Evidence Pack™Authority Gate

ISO 21448

ISO 21448:2022 — Safety Of The Intended Functionality (SOTIF)

2022 · Global

The companion to ISO 26262 governing the residual risk of a fault-free intended function (e.g. an ADAS / autonomous perception or decision function) operating at the edge of, or outside, its specified operating envelope. KYE Protocol™ governs the authority, the operating-envelope (control / safety-floor) admissibility, the evidence and the finality of an AI-recommended action against a declared intended-functionality envelope, with Replay-Proof™ failure-path reconstruction; KYE Protocol™ does not perform the SOTIF hazard analysis, triggering-condition identification, or the model's internal failure-mechanism analysis. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Operating-envelope (control / safety-floor) action admissibilityDesignedL2 Designediso-21448.clause-6Purpose Permission™Edge Governance Safety Floor
Replay-derivable intended-functionality decision evidenceDesignedL2 Designediso-21448.clause-10Evidence Pack™Reporting Engine
Named accountability + contestable outcomesDesignedL2 Designediso-21448.clause-11Authority GateEvidence Pack™

Law Society Protocol

Law Society Conveyancing Protocol

Conveyancing Protocol · United Kingdom

The Law Society of England & Wales — Conveyancing Protocol. KYE Protocol™ governs the AUTHORITY of an AI agent to take or finalise a protocol step, the client-due-diligence / source-of-funds EVIDENCE boundary (binding the deep-mapped uk-mlr-2017 store, not re-mapping it), and the replay-derivable transaction file; KYE Protocol™ does not perform the searches, draft the enquiries, or determine the legal correctness of the conveyance. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Protocol-step authority / finality on AI-assisted stepsDesignedL2 Designedlaw-society-conveyancing-protocol.step-authorityPurpose Permission™Authority Gate
Client due diligence + source-of-funds evidenceDesignedL2 Designedlaw-society-conveyancing-protocol.cdd-source-of-fundsEvidence Pack™
Replay-derivable transaction fileDesignedL2 Designedlaw-society-conveyancing-protocol.replay-fileEvidence Pack™Replay-Proof™
Legal correctness of searches / enquiriesOut of scopeL1 Mappedlaw-society-conveyancing-protocol.searches-enquiries-correctness—

CLC Code

CLC Code of Conduct — Council for Licensed Conveyancers

Code of Conduct · United Kingdom

Council for Licensed Conveyancers (CLC) — Code of Conduct. KYE Protocol™ governs the AUTHORITY of an AI agent to act in the client's interest, named-accountable conveyancer sign-off, the confidentiality / isolation boundary, and the EVIDENCE boundary around client-money handling; KYE Protocol™ does not reconcile the client account, hold money, or determine CLC compliance. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

4

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Act-in-client-best-interest authorityDesignedL2 Designedclc-code-of-conduct.client-best-interestPurpose Permission™Authority Gate
Named accountable conveyancer sign-offDesignedL2 Designedclc-code-of-conduct.named-conveyancer-signoffDelegated Auditability
Confidentiality and isolation of client mattersDesignedL2 Designedclc-code-of-conduct.confidentialityAuthority Gate
Client-money handling evidence boundaryDesignedL2 Designedclc-code-of-conduct.client-moneyEvidence Pack™

HM Land Registry

HM Land Registry — Registration & Digital Identity Standard (Safe Harbour)

Registration & Digital Identity Standard · United Kingdom

HM Land Registry — registration requirements and the Digital Identity Standard (Safe Harbour). KYE Protocol™ governs the AUTHORITY of an AI agent to take a digital-identity-verification or application-submission action and the Safe Harbour EVIDENCE / replay boundary; KYE Protocol™ does not perform the identity-check determination, run the verification technology, or determine HMLR registration correctness. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Digital-identity verification action admissibility (Safe Harbour)DesignedL2 Designedhm-land-registry.digital-identity-admissibilityPurpose Permission™Evidence Pack™
Application-submission authorityDesignedL2 Designedhm-land-registry.application-submission-authorityAuthority Gate
Replay-derivable submission recordDesignedL2 Designedhm-land-registry.replay-submission-recordEvidence Pack™Replay-Proof™
The conveyancer's identity-check determinationOut of scopeL1 Mappedhm-land-registry.identity-check-determination—

Homes England CFG

Homes England Capital Funding Guide — Shared Ownership (model lease)

Capital Funding Guide — Shared Ownership · United Kingdom

Homes England — Capital Funding Guide (Shared Ownership + model lease). KYE Protocol™ governs the AUTHORITY of an AI agent to take a shared-ownership eligibility-decision action, the affordability / sustainability EVIDENCE boundary, and named-accountable sign-off / contestability; KYE Protocol™ does not make the eligibility determination, run the affordability assessment, or judge model-lease compliance. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Shared-ownership eligibility-decision authorityDesignedL2 Designedhomes-england-cfg.eligibility-authorityPurpose Permission™Authority Gate
Affordability / sustainability evidenceDesignedL2 Designedhomes-england-cfg.affordability-sustainability-evidenceEvidence Pack™
Named-accountable sign-off and contestabilityDesignedL2 Designedhomes-england-cfg.named-signoff-contestableDelegated Auditability
Model-lease compliance determinationOut of scopeL1 Mappedhomes-england-cfg.model-lease-compliance—

ISO 14001

ISO 14001 — Environmental Management Systems

2015 · Global

ISO 14001:2015 environmental management system. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved environmental HSE instructions that discharge an EMS control — the KYE™ HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Environmental operational control under safety floorDesignedL2 Designediso-14001.8.1Purpose Permission™Edge Governance Safety Floor
Environmental emergency instruction scope-boundDesignedL2 Designediso-14001.8.2Purpose Permission™Authority Gate
Compliance evaluation contestable + evidencedDesignedL2 Designediso-14001.9.1.2Evidence Pack™Authority Gate

ISO 15489

ISO 15489-1:2016 — Records Management (records-management spine)

2016 · Global

ISO 15489-1:2016 records-management spine for the KYE™ Chain of Authority™ for Iron Mountain InSight DXP. Iron Mountain governs INFORMATION (records, custody, retention, classification); KYE Protocol™ governs ACTION — who was authorised to act on a record at the moment it drives a consequential AI action, evidenced, final, revocable. The authentic/reliable-records-at-the-action-boundary requirements are KYE Protocol™'s job (enforced); records storage / capture / retention / disposition are records-management's job (out-of-scope, owned by the records-manager / information-custodian).

2

Enforced

0

Designed

3

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Records authenticity & reliability (authority overlay)EnforcedL3 Enforceableiso-15489.authenticity-authority-binding, iso-15489.reliability-evidence-pinAction Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Records access & permissions (authority overlay)EnforcedL3 Enforceableiso-15489.access-permission-overlayAction Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Records creation, capture & metadata (records-management)Out of scopeL1 Mappediso-15489.records-capture-metadata—
Retention schedule & disposition authority (records-management)Out of scopeL1 Mappediso-15489.retention-disposition-authority—
Records storage & preservation (records-management)Out of scopeL1 Mappediso-15489.storage-preservation—

ISO 16175

ISO 16175-1:2020 — Software for Managing Records (digital records spine)

2020 · Global

ISO 16175-1:2020 digital-records-software spine for the KYE™ Chain of Authority™ for Iron Mountain InSight DXP. KYE Protocol™ overlays the action-boundary access-control decision + the governance-decision audit trail (enforced); the records-software capture / classification / retention functions are out-of-scope (owned by Iron Mountain InSight DXP). §0: Iron Mountain proves where information travelled; KYE Protocol™ proves who was authorised to act on it.

2

Enforced

0

Designed

2

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Action-decision audit trail (authority overlay)EnforcedL3 Enforceableiso-16175.action-audit-trail, iso-16175.replayable-decision-recordAction Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Access-control decision at the action boundary (authority overlay)EnforcedL3 Enforceableiso-16175.access-control-decisionAction Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Capture & classification functional requirements (records-software)Out of scopeL1 Mappediso-16175.capture-classification-functional—
Retention & disposition functional requirements (records-software)Out of scopeL1 Mappediso-16175.retention-disposition-functional—

ISO 17025

ISO/IEC 17025:2017 — Competence of testing and calibration laboratories

2017 · International

ISO/IEC 17025:2017 sets the general requirements for the competence, impartiality and consistent operation of testing and calibration laboratories. KYE Protocol™ enforces the §7.11 data-management integrity, §7.5/§7.8 technical-record reproducibility and audit-trail slices where a laboratory uses AI-supported decisioning — metrology, equipment and competence stay the laboratory's technical system. Per-requirement bijection at /compliance/iso-17025.html.

3

Enforced

1

Designed

1

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Control of data & information management (7.11)EnforcedL3 Enforceableiso-17025.7.11-data-managementWORM audit hash-chain
Technical records & integrity of results (7.5, 7.8)EnforcedL3 Enforceableiso-17025.7.5-technical-recordsDecision replayEvidence Pack™
Control of management-system records & audit trail (8.4)DesignedL2 Designediso-17025.8.4-management-recordsWORM audit hash-chain
Impartiality & authority over automated decisions (4.1, 6.2)EnforcedL3 Enforceableiso-17025.4.1-impartiality-authorityPurpose Permission™Authority Gate
Metrological traceability, measurement uncertainty, equipment & competenceMetrological traceability, measurement uncertainty, equipment calibration and technical competence are the laboratory's own technical/metrology system — out of scope for an AI-authority-governance protocol.Out of scopeL1 Mappediso-17025.6.5-traceability, iso-17025.6.3-equipment-competence—

ISO/IEC 27035

ISO/IEC 27035 — Incident Management

ISO/IEC 27035 — Information security incident management · International

ISO/IEC 27035 is the international standard for information-security incident management, including careful incident-evidence handling. KYE Protocol™ governs whether an AI-assisted incident decision under it may proceed to a consequential action — under a named accountable officer's authority, with incident-evidence chain-of-custody recorded, the assessment pinned to verifiable signal sources, a signed replay-provable Evidence Pack™ per decision, and a contestability record for the lessons-learned reconstruction. Detection / response tooling / forensic analysis stays the organisation's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/iso-27035.html.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Incident-evidence chain-of-custody (evidence handling)EnforcedL3 Enforceableiso-27035.evidence-chain-of-custodyAuthority GateDecision replayEvidence Pack™Replay-Proof™
Named-authority on the assessment-and-decision responseEnforcedL3 Enforceableiso-27035.assessment-decision-authorityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & lessons-learned reconstructionEnforcedL3 Enforceableiso-27035.lessons-learned-reconstructionAuthority GateDecision replayEvidence Pack™Replay-Proof™
Detection, response tooling & forensic analysisThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine.Out of scopeL1 Mappediso-27035.detection-response-forensics—

ISO 45001

ISO 45001 — Occupational Health & Safety Management Systems

2018 · Global

ISO 45001:2018 occupational health & safety management system. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved safety-critical HSE documents (permits-to-work, risk assessments, method statements) that discharge an OH&S control — the KYE™ HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

4

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Operational planning & control under safety floorDesignedL2 Designediso-45001.8.1Purpose Permission™Edge Governance Safety Floor
Hierarchy-of-controls selection advisory pending sign-offDesignedL2 Designediso-45001.8.1.2Authority GateDecision Map™
Emergency-preparedness instruction scope-boundDesignedL2 Designediso-45001.8.2Purpose Permission™Authority Gate
Incident / corrective action contestable + evidencedDesignedL2 Designediso-45001.10.2Evidence Pack™Authority Gate

ISO 55000

ISO 55000 / ISO 55001:2014 — Asset management management systems

2014 · Global

ISO 55000/55001 asset-management system requirements. KYE Protocol™ governs the authority, evidence and finality of AI-recommended asset-management actions and the scope of the AI's authority over the asset portfolio. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Asset-management objectives + scoped decision authorityDesignedL2 Designediso-55001.6.2.1Authority GateDecision Map™
Planned actions — finality + named accountabilityDesignedL2 Designediso-55001.6.2.2Purpose Permission™Edge Governance Safety Floor
Contestable performance reviewDesignedL2 Designediso-55001.9.1Evidence Pack™Authority Gate

Mastercard Disputes

Mastercard Chargeback Standards — Dispute Resolution & Arbitration

Mastercard Chargeback Standards — Dispute Resolution & Arbitration (Chargeback Guide) · Global

The Mastercard Chargeback Standards govern the dispute lifecycle — first chargeback, second presentment with supporting documentation, pre-arbitration, and arbitration on the documented record. KYE Protocol™ governs whether the second presentment / case filing may proceed — under a named owner's recorded authority, with the supporting evidence captured as evidence events at transaction time, and the bundle sealed as a signed, hash-bound, WORM-retained, replay-verifiable Evidence Pack™ so the documented record survives arbitration scrutiny. Whether to fight, the narrative, and the outcome stay the merchant's / network's own (honest scope, §0). Per-requirement bijection at /compliance/mastercard-dispute-rules.html.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Second-presentment evidence captured at transaction timeEnforcedL3 Enforceablemastercard-dispute-rules.second-presentment-evidence-captureAuthority GateDecision replayEvidence Pack™Replay-Proof™
Named-authority on the chargeback responseEnforcedL3 Enforceablemastercard-dispute-rules.chargeback-response-authorityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Arbitration-grade reconstruction of the dispute recordEnforcedL3 Enforceablemastercard-dispute-rules.arbitration-reconstruction-recordAuthority GateDecision replayEvidence Pack™Replay-Proof™
Dispute merits adjudication & strategyWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine.Out of scopeL1 Mappedmastercard-dispute-rules.dispute-merits-adjudication—

MoReq2010

MoReq2010 — Modular Requirements for Records Systems (records-system spine)

2011 · European Union

MoReq2010 records-system spine for the KYE™ Chain of Authority™ for Iron Mountain InSight DXP. KYE Protocol™ overlays the action-boundary access-control service + entity-event governance-decision audit + custody→authority binding (enforced); the records-system classification / search / retention / disposition core services are out-of-scope (owned by Iron Mountain InSight DXP).

2

Enforced

0

Designed

2

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Access-control service at the action boundary (authority overlay)EnforcedL3 Enforceablemoreq-2010.access-control-service-overlay, moreq-2010.custody-to-authority-bindingAction Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Entity-event audit of the action decision (authority overlay)EnforcedL3 Enforceablemoreq-2010.entity-event-action-auditAction Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™
Classification & search core service (records-system)Out of scopeL1 Mappedmoreq-2010.classification-search-service—
Retention & disposition core service (records-system)Out of scopeL1 Mappedmoreq-2010.retention-disposition-service—

MSHA

MSHA — Mine Safety and Health Administration standards (30 CFR)

2024 · United States

US MSHA standards under 30 CFR governing surface and underground mine safety. KYE Protocol™ governs the authority, evidence and finality of AI-recommended physical-safety actions on mine equipment (e.g. mine-hoist stop). Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Mine-equipment actuation under safety floorDesignedL2 Designedmsha.30-cfr-56.18002Purpose Permission™Edge Governance Safety Floor
Hoisting stop named accountabilityDesignedL2 Designedmsha.30-cfr-57.19021Authority GateDecision Map™
Contestable equipment-safety decisionsDesignedL2 Designedmsha.30-cfr-75.1725Evidence Pack™Authority Gate

NAIC AI Bulletin

NAIC Model Bulletin on the Use of AI by Insurers

NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (adopted December 2023) · United States

The NAIC Model Bulletin on the Use of AI by Insurers is the US insurer-AI governance expectation (written AIS Program, named accountability, documentation, unfair-discrimination testing). KYE Protocol™ governs whether an AI-assisted underwriting or claims decision under it may proceed to a consequential adverse action — under a named underwriter's / adjuster's authority, with a recorded adverse-action reason-code, with proxy-discrimination / fairness-evidence captured, a signed replay-provable Evidence Pack™ per decision, and an appeal / contestability record so any decision can be reconstructed and contested. The actuarial pricing / risk-appetite / model design on the merits stays the insurer's own work (honest scope, §0). Per-requirement bijection at /compliance/naic-model-bulletin-ai.html.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Named accountability & governance of the AI decisionEnforcedL3 Enforceablenaic-model-bulletin-ai.governance-named-accountabilityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Adverse-action explainability & documentationEnforcedL3 Enforceablenaic-model-bulletin-ai.adverse-action-documentationAuthority GateDecision replayEvidence Pack™Replay-Proof™
Unfair-discrimination testing evidenceEnforcedL3 Enforceablenaic-model-bulletin-ai.unfair-discrimination-testingAuthority GateDecision replayEvidence Pack™Replay-Proof™
Actuarial pricing, risk appetite & model design on the meritsThe actuarial pricing / risk-appetite / model design on the merits is the insurer's own work — KYE™ is an AI-authority and evidence layer, not a pricing, actuarial, or risk-modelling engine.Out of scopeL1 Mappednaic-model-bulletin-ai.actuarial-pricing-model-design—

NERC CIP

NERC CIP — Critical Infrastructure Protection (bulk electric system)

2024 · United States

NERC CIP reliability standards governing cyber security of the North American bulk electric system. KYE Protocol™ governs the authority, evidence and finality of an AI-recommended physical-safety action on grid assets and the scope boundary of the AI's authority. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Controlled actuation of BES assets under safety floorDesignedL2 Designednerc-cip.cip-007-6.r1Purpose Permission™Edge Governance Safety Floor
Purpose-scoped authority for grid actionsDesignedL2 Designednerc-cip.cip-004-6.r4Authority GateDecision Map™
Contestable + evidenced incident decisionsDesignedL2 Designednerc-cip.cip-008-6.r1Evidence Pack™Authority Gate

NIS2 Incident

NIS2 Incident Reporting — Article 23 (24h / 72h)

NIS2 — Directive (EU) 2022/2555, Article 23 · European Union

NIS2 Incident Reporting (Directive (EU) 2022/2555, Article 23) is the EU 24-hour / 72-hour staged-notification regime for significant incidents. KYE Protocol™ governs whether an AI-assisted disclosure-timing decision or containment action under it may proceed to a consequential incident action — under a named accountable officer's authority, with chain-of-custody recorded, and a contestability record so the timing decision can be reconstructed and challenged. Incident detection / impact analysis stays the entity's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/nis2-incident.html.

2

Enforced

0

Designed

1

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Disclosure-timing authority on the 24h / 72h notification clockEnforcedL3 Enforceablenis2-incident.notification-clock-authorityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Incident-evidence chain-of-custody for the notificationEnforcedL3 Enforceablenis2-incident.notification-evidence-custodyAuthority GateDecision replayEvidence Pack™Replay-Proof™
Incident detection & impact analysisThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine.Out of scopeL1 Mappednis2-incident.detection-impact-analysis—

NIST CSF 2.0 RS/RC

NIST CSF 2.0 — RESPOND & RECOVER

NIST Cybersecurity Framework 2.0 (2024) — RESPOND (RS) + RECOVER (RC) · United States

NIST CSF 2.0 RESPOND & RECOVER is the incident-management, analysis, and recovery half of the NIST Cybersecurity Framework 2.0. KYE Protocol™ governs whether an AI-assisted response / recovery action under it may proceed to a consequential incident action — under a named accountable officer's authority, with the incident analysis pinned to verifiable signal sources, chain-of-custody recorded, a signed replay-provable Evidence Pack™ per decision, and a contestability record. Threat detection (DETECT) / response tooling / recovery execution stays the organisation's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/nist-csf-2-respond-recover.html.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Named-authority on the RESPOND/RECOVER action (RS.MA / RC.RP)EnforcedL3 Enforceablenist-csf-2-respond-recover.rs-action-authorityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Incident-analysis source pin (RS.AN)EnforcedL3 Enforceablenist-csf-2-respond-recover.rs-incident-evidenceAuthority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & post-incident reconstruction (RS.MA / improvement)EnforcedL3 Enforceablenist-csf-2-respond-recover.rs-contestabilityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Threat detection (DETECT) & recovery execution toolingThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine.Out of scopeL1 Mappednist-csf-2-respond-recover.detection-recovery-tooling—

Synthesis Screening

Nucleic-Acid Synthesis Screening — IBBIS Common Mechanism + IGSC Harmonized Screening Protocol

2023 · Global

Nucleic-acid synthesis screening regime — the IBBIS Common Mechanism and IGSC Harmonized Screening Protocol screen synthesis orders for sequences of concern before synthesis. KYE Protocol™ governs whether an AI-generated nucleic-acid sequence may proceed to a synthesis order, binding the screening result — the KYE™ AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Sequence-of-concern screeningDesignedL2 Designednucleic-acid-synthesis-screening.soc-screen, nucleic-acid-synthesis-screening.flagged-holdAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Customer / legitimacy screeningDesignedL2 Designednucleic-acid-synthesis-screening.customer-screenAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™
Screening provenance & record-keepingDesignedL2 Designednucleic-acid-synthesis-screening.screening-provenanceAction Admissibility™ GateEdge Governance Safety FloorEvidence Pack™

NYDFS AI Circular

NYDFS Insurance Circular Letter on AI

NYDFS Insurance Circular Letter No. 7 (2024) — Use of AI Systems and External Consumer Data in Underwriting and Pricing · United States

NYDFS Insurance Circular Letter No. 7 (2024) sets expectations for insurers using AI and external consumer data in underwriting and pricing — senior-management accountability, unfair-discrimination testing, consumer transparency, documentation. KYE Protocol™ governs whether an AI-assisted insurance decision in scope may proceed to a consequential adverse action — under a named accountable authority, with a recorded adverse-action reason-code, proxy-discrimination / fairness-evidence captured, a signed replay-provable Evidence Pack™ per decision, and a consumer appeal / contestability record. The ECDIS selection / pricing / methodology design on the merits stays the insurer's own work (honest scope, §0). Per-requirement bijection at /compliance/nydfs-insurance-circular-ai.html.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Senior-management accountability for the AI decisionEnforcedL3 Enforceablenydfs-insurance-circular-ai.senior-management-accountabilityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Unfair-discrimination testing evidenceEnforcedL3 Enforceablenydfs-insurance-circular-ai.unfair-discrimination-testingAuthority GateDecision replayEvidence Pack™Replay-Proof™
Consumer transparency & appeal recordEnforcedL3 Enforceablenydfs-insurance-circular-ai.consumer-transparency-appealAuthority GateDecision replayEvidence Pack™Replay-Proof™
ECDIS selection, pricing & methodology design on the meritsThe ECDIS selection / pricing / testing-methodology design on the merits is the insurer's own work — KYE™ is an AI-authority and evidence layer, not a data-selection, pricing, or testing-methodology engine.Out of scopeL1 Mappednydfs-insurance-circular-ai.ecdis-selection-pricing-methodology—

OECD GLP

OECD Good Laboratory Practice (Principles) + FDA 21 CFR Part 58

1998 + 21 CFR 58 · International / US

OECD Principles of Good Laboratory Practice and FDA 21 CFR Part 58 govern the integrity, traceability, audit-trail and archiving of non-clinical safety-study data. KYE Protocol™ enforces the ALCOA+ data-integrity, audit-trail and replay slices where an AI/automated step captures or transforms study data — physical study conduct stays the laboratory's GLP system. Per-requirement bijection at /compliance/oecd-glp.html.

3

Enforced

1

Designed

1

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Study data integrity & raw-data traceability (ALCOA+)EnforcedL3 Enforceableoecd-glp.data-integrity, oecd-glp.raw-data-traceabilityWORM audit hash-chainDecision replayEvidence Pack™
Audit trail & change control for electronic records (Part 11 overlap)EnforcedL3 Enforceableoecd-glp.audit-trailWORM audit hash-chain
Archive & retention of study recordsDesignedL2 Designedoecd-glp.archive-retentionWORM audit hash-chain
QA & study-director oversight of automated stepsEnforcedL3 Enforceableoecd-glp.oversight-of-automated-stepsPurpose Permission™Authority Gate
Physical study conduct & facilitiesApparatus calibration, test/reference-item handling and physical SOP execution are the laboratory's own GLP quality system — KYE™ is an AI-authority and evidence layer, not a lab-operations system.Out of scopeL1 Mappedoecd-glp.physical-study-conduct—

OSHA PSM

OSHA PSM — Process Safety Management (29 CFR 1910.119)

1992 · United States

US OSHA Process Safety Management standard for facilities handling highly hazardous chemicals. KYE Protocol™ governs the authority, evidence and finality of AI-recommended physical-safety actions in a PSM-covered process. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Mechanical-integrity actuation under safety floorDesignedL2 Designedosha-psm.1910.119.jPurpose Permission™Edge Governance Safety Floor
Operating-procedure named accountabilityDesignedL2 Designedosha-psm.1910.119.fAuthority GateDecision Map™
Management-of-change contestable + evidencedDesignedL2 Designedosha-psm.1910.119.lEvidence Pack™Authority Gate

Permit to Work

Permit-to-Work Systems (HSE HSG250 guidance)

HSG250 · United Kingdom

Permit-to-work systems per UK HSE HSG250. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved permits-to-work — the KYE™ HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Permit advisory pending competent-authoriser sign-offDesignedL2 Designedpermit-to-work.authorisationAuthority GateDecision Map™
Permit scope & isolation bounded to authorised workDesignedL2 Designedpermit-to-work.scope-isolationPurpose Permission™Authority Gate
Hand-back & audit contestable + evidencedDesignedL2 Designedpermit-to-work.handback-auditEvidence Pack™Authority Gate

PRA SS1/23

PRA SS1/23 — Model Risk Management Principles for Banks

PRA SS1/23 (Model risk management principles for banks, May 2023; effective May 2024) · United Kingdom

PRA SS1/23 sets the UK model risk management principles for banks (Principles 1–5, explicitly including AI/ML models). KYE Protocol™ governs whether a model-driven output or risk report under it may proceed to a consequential action — only a currently-validated model used within its approved scope, model changes as named-authority decisions with evidence, every consequential decision pinned to model_id + version + validation reference, and every risk report bound to its data-lineage evidence chain, sealed into a signed replay-provable Evidence Pack™. The quantitative model build / validation mathematics / capital computation / portfolio composition stays the bank's own work (honest scope, §0 — not investment advice). Per-requirement bijection at /compliance/pra-ss1-23.html.

5

Enforced

0

Designed

1

Out of scope

6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Model identification & inventory resolution (Principle 1)EnforcedL3 Enforceablepra-ss1-23.principle1-model-inventory-resolutionAuthority GateDecision replayEvidence Pack™Replay-Proof™
Governance & named SMF accountability (Principle 2)EnforcedL3 Enforceablepra-ss1-23.principle2-governance-named-authorityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Model development, implementation & use incl. AI/ML (Principle 3)EnforcedL3 Enforceablepra-ss1-23.principle3-development-implementation-useAuthority GateDecision replayEvidence Pack™Replay-Proof™
Validation-status binding at the moment of use (Principle 4)EnforcedL3 Enforceablepra-ss1-23.principle4-validation-status-bindingAuthority GateDecision replayEvidence Pack™Replay-Proof™
Model risk mitigants & restrictions on use (Principle 5)EnforcedL3 Enforceablepra-ss1-23.principle5-mitigants-restrictionsAuthority GateDecision replayEvidence Pack™Replay-Proof™
Independent validation judgment & quantitative work on the meritsThe quantitative model build, validation mathematics, and capital & liquidity computation are the bank's own quantitative work — KYE™ is an AI-authority and evidence layer, not a model-validation or capital-calculation engine.Out of scopeL1 Mappedpra-ss1-23.independent-validation-judgment—

PSD2 SCA Disputes

PSD2 SCA & Unauthorised-Transaction Liability (Arts. 72-74, 97)

PSD2 — Directive (EU) 2015/2366, Arts. 72-74 + 97 (SCA & unauthorised-transaction liability) · European Union

PSD2 Arts. 72-74 + 97 govern SCA and unauthorised-transaction liability in the EU — the PSP carries the burden of proof that the transaction was authenticated and accurately recorded. KYE Protocol™ governs whether an unauthorised-transaction refund / liability allocation may proceed — under a named owner's recorded authority, with the SCA / authentication evidence captured as evidence events at transaction time, and the liability-allocation bundle sealed as a signed, hash-bound, replay-provable Evidence Pack™ that meets the Article 72 burden of proof. The substantive fraud / authorisation determination stays the PSP's / merchant's own (honest scope, §0). Per-requirement bijection at /compliance/psd2-sca-disputes.html.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
SCA / authentication evidence captured at transaction timeEnforcedL3 Enforceablepsd2-sca-disputes.sca-evidence-captureAuthority GateDecision replayEvidence Pack™Replay-Proof™
Named-authority on the unauthorised-transaction refundEnforcedL3 Enforceablepsd2-sca-disputes.unauthorised-transaction-refund-authorityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Burden-of-proof evidence integrity for liability allocationEnforcedL3 Enforceablepsd2-sca-disputes.liability-allocation-evidenceAuthority GateDecision replayEvidence Pack™Replay-Proof™
Substantive fraud / authorisation determination on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine.Out of scopeL1 Mappedpsd2-sca-disputes.fraud-determination—

Reg E

Reg E — EFTA Error Resolution (12 CFR 1005.11)

EFTA / Regulation E — 12 CFR Part 1005 (error resolution, §1005.11) · United States

Reg E (12 CFR 1005.11) is the US error-resolution framework for electronic fund transfers. KYE Protocol™ governs whether a provisional credit, refund, or error determination in the dispute flow may proceed — under a named owner's recorded authority, with the transaction evidence captured as evidence events at transaction time, a signed replay-provable Evidence Pack™, and a recorded contestable determination. The substantive error adjudication stays the institution's / merchant's own (honest scope, §0). Per-requirement bijection at /compliance/reg-e.html.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Named-authority on the provisional credit / refund actionEnforcedL3 Enforceablereg-e.provisional-credit-authorityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Investigation evidence record captured at transaction timeEnforcedL3 Enforceablereg-e.investigation-evidence-recordAuthority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & written-determination reconstructionEnforcedL3 Enforceablereg-e.error-determination-contestabilityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Substantive error adjudication on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine.Out of scopeL1 Mappedreg-e.substantive-error-adjudication—

Reg Z

Reg Z — TILA Billing-Error Resolution (12 CFR 1026.13)

TILA / Regulation Z — 12 CFR Part 1026 (billing-error resolution, §1026.13) · United States

Reg Z (12 CFR 1026.13) is the US billing-error-resolution framework for credit accounts. KYE Protocol™ governs whether an account correction, credit, or billing-error determination in the dispute flow may proceed — under a named owner's recorded authority, with the transaction evidence captured as evidence events at transaction time, a signed replay-provable Evidence Pack™, and a recorded contestable determination. The substantive billing-error adjudication stays the creditor's / merchant's own (honest scope, §0). Per-requirement bijection at /compliance/reg-z.html.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Named-authority on the account correction / credit actionEnforcedL3 Enforceablereg-z.billing-error-resolution-recordAuthority GateDecision replayEvidence Pack™Replay-Proof™
Billing-dispute evidence record captured at transaction timeEnforcedL3 Enforceablereg-z.billing-dispute-evidence-recordAuthority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & written-explanation reconstructionEnforcedL3 Enforceablereg-z.billing-dispute-contestabilityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Substantive billing-error adjudication on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine.Out of scopeL1 Mappedreg-z.substantive-billing-error-adjudication—

RIDDOR

RIDDOR — Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013 (UK)

2013 · United Kingdom

UK RIDDOR 2013 (SI 2013/1471), HSE-enforced. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved RIDDOR-reportable incident reports — the KYE™ HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Incident report authored under safety floorDesignedL2 Designedriddor.reg-4-6Purpose Permission™Edge Governance Safety Floor
Reportability determination advisory pending sign-offDesignedL2 Designedriddor.reporting-decisionAuthority GateDecision Map™
Incident records contestable + evidencedDesignedL2 Designedriddor.reg-12Evidence Pack™Authority Gate

SEC Cyber Disclosure

SEC Cyber Disclosure — Item 1.05 (4 business days)

SEC Cybersecurity Disclosure Rules (2023) — Item 1.05 + Item 106 · United States

SEC Cyber Disclosure (Item 1.05) is the US four-business-day material-cybersecurity-incident disclosure regime on Form 8-K. KYE Protocol™ governs whether an AI-assisted disclosure-timing decision under it may proceed to a consequential disclosure action — under a named accountable officer's authority, with incident-evidence chain-of-custody recorded, and a contestability record so the timing decision can be reconstructed and challenged. The substantive materiality determination / 8-K drafting / legal judgment stays the registrant's own work (honest scope, §0/§70). Per-requirement bijection at /compliance/sec-cyber-disclosure.html.

2

Enforced

0

Designed

1

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Disclosure-timing authority on the four-business-day clockEnforcedL3 Enforceablesec-cyber-disclosure.item105-materiality-disclosure-authorityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Contestability of the timing decision in an SEC / shareholder reviewEnforcedL3 Enforceablesec-cyber-disclosure.item105-timing-contestabilityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Substantive materiality determination & 8-K draftingThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine.Out of scopeL1 Mappedsec-cyber-disclosure.substantive-materiality-drafting—

Sedona Principles

The Sedona Principles — Best Practices for Electronic Document Production

The Sedona Principles, Third Edition (2018) · United States

The Sedona Principles — Best Practices for Electronic Document Production is the leading US e-discovery best-practice commentary (The Sedona Principles, Third Edition). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/sedona-principles.html.

2

Enforced

0

Designed

1

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Defensible, reconstructable AI-review process recordEnforcedL3 Enforceablesedona-principles.principle6-defensible-processAuthority GateDecision replayEvidence Pack™Replay-Proof™
Replay-provable evidence of the process when challengedEnforcedL3 Enforceablesedona-principles.replay-provable-process-evidenceAuthority GateDecision replayEvidence Pack™Replay-Proof™
Methodology selection & substantive production completenessThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine.Out of scopeL1 Mappedsedona-principles.methodology-and-completeness—

SOX §806

SOX §806 — Whistleblower Anti-Retaliation (18 U.S.C. §1514A)

Sarbanes-Oxley Act §806 (18 U.S.C. §1514A) — whistleblower anti-retaliation · United States

SOX §806 — Whistleblower Anti-Retaliation (18 U.S.C. §1514A) is the US public-company anti-retaliation statute (contributing-factor / clear-and-convincing burden). KYE Protocol™ governs whether an AI-assisted adverse HR action that touches a reporter may proceed — only with a recorded retaliation-risk assessment evidence — and binds a contestability record so the employer's burden-of-proof can be reconstructed if a §806 complaint is filed. Whether the action was in fact retaliatory and the §806 adjudication stay with counsel / OSHA / the courts (honest scope, §0). Per-requirement bijection at /compliance/sox-806.html.

2

Enforced

0

Designed

1

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Retaliation-risk assessment evidence before an adverse actionEnforcedL3 Enforceablesox-806.anti-retaliation-risk-recordAuthority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & burden-of-proof reconstructionEnforcedL3 Enforceablesox-806.contestability-burden-reconstructionAuthority GateDecision replayEvidence Pack™Replay-Proof™
Whether the action was in fact retaliatory & §806 adjudicationDeciding whether an action was retaliatory and adjudicating the §806 complaint is a legal determination for counsel and the courts — KYE™ is an AI-authority and evidence layer, not an adjudication engine.Out of scopeL1 Mappedsox-806.substantive-retaliation-adjudication—

CPR PD 57AD

UK CPR Part 31 + PD 57AD — Disclosure & the Disclosure Certificate

CPR Part 31 + Practice Direction 57AD (Disclosure in the Business and Property Courts, 2022) · United Kingdom

UK CPR Part 31 + PD 57AD — Disclosure & the Disclosure Certificate is the English civil disclosure framework (CPR Part 31 + Practice Direction 57AD). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/uk-cpr-pd57ad.html.

2

Enforced

0

Designed

1

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Named-authority on the disclosure determination & certificateEnforcedL3 Enforceableuk-cpr-pd57ad.disclosure-certificateAuthority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & reconstruction of a disclosure challengeEnforcedL3 Enforceableuk-cpr-pd57ad.disclosure-challenge-reconstructionAuthority GateDecision replayEvidence Pack™Replay-Proof™
Substantive disclosure review & adequacy judgmentThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine.Out of scopeL1 Mappeduk-cpr-pd57ad.substantive-disclosure-review—

UK PIDA

UK PIDA — Public Interest Disclosure Act 1998 (ERA 1996 Part IVA)

UK Public Interest Disclosure Act 1998 (Employment Rights Act 1996, Part IVA) · United Kingdom

UK PIDA — Public Interest Disclosure Act 1998 (ERA 1996 Part IVA) is the UK protected-disclosure framework (protection from detriment and automatic-unfair dismissal). KYE Protocol™ governs whether an AI-assisted handling of a protected disclosure, or an adverse action on a worker who made one, may proceed — under a named handler's authority, with a recorded detriment / retaliation-risk assessment before adverse action, and a contestability record so a detriment / dismissal claim can be reconstructed. Whether the disclosure qualifies, whether a detriment occurred, and the tribunal adjudication stay with counsel and the tribunal (honest scope, §0). Per-requirement bijection at /compliance/uk-pida.html.

2

Enforced

0

Designed

1

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Named-authority on the protected-disclosure handling & detriment-risk recordEnforcedL3 Enforceableuk-pida.protected-disclosure-handling-authorityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Contestability & reconstruction for a detriment / dismissal claimEnforcedL3 Enforceableuk-pida.detriment-claim-reconstructionAuthority GateDecision replayEvidence Pack™Replay-Proof™
Whether the disclosure qualifies & employment-tribunal adjudicationDeciding whether a disclosure qualifies and adjudicating the tribunal claim is a legal determination for counsel and the tribunal — KYE™ is an AI-authority and evidence layer, not an adjudication engine.Out of scopeL1 Mappeduk-pida.qualifying-disclosure-and-adjudication—

Visa CE 3.0

Visa Compelling Evidence 3.0 (CE3.0)

Visa Compelling Evidence 3.0 (CE3.0) — remedied-dispute evidence requirements (Visa Rules, fraud reason code 10.4) · Global

Visa Compelling Evidence 3.0 defines the qualifying evidence set that remedies a card-absent fraud dispute (prior undisputed transactions, matching device / IP / address / account identifiers, delivery evidence). KYE Protocol™ governs whether the representment may proceed — under a named owner's recorded authority, with the qualifying evidence captured as evidence events at transaction time, and the representment bundle sealed as a signed, hash-bound, WORM-retained, replay-verifiable Evidence Pack™ — exactly the provable evidence set CE3.0 representments turn on. Whether to fight, the narrative, and the outcome stay the merchant's / network's own (honest scope, §0). Per-requirement bijection at /compliance/visa-ce30.html.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Qualifying evidence set captured at transaction timeEnforcedL3 Enforceablevisa-ce30.evidence-set-captureAuthority GateDecision replayEvidence Pack™Replay-Proof™
Representment bundle integrity (signed · hash-bound · WORM)EnforcedL3 Enforceablevisa-ce30.representment-bundle-integrityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Named-authority on the representment decisionEnforcedL3 Enforceablevisa-ce30.representment-authorityAuthority GateDecision replayEvidence Pack™Replay-Proof™
Dispute outcome adjudication & narrative on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine.Out of scopeL1 Mappedvisa-ce30.dispute-outcome-adjudication—

2 CFR 200 (Uniform Guidance)

US 2 CFR 200 — Uniform Guidance

2 C.F.R. Part 200 (Uniform Guidance) · United States

US federal grants-administration regulation: uniform administrative requirements, cost principles, and audit requirements for federal awards. KYE™ governs WHETHER a grants-lifecycle action by an AI agent may proceed and proves the basis (via the KYE™ Governed Grants Agent™); it does not write applications, run a grants-management platform, or move money.

3

Enforced

1

Designed

1

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Cost principles & allowability of costs (§200.403)EnforcedL3 Enforceable2 C.F.R. §200.403Governed Grants Agent™ admit→decidePurpose Permission™Evidence Pack™
Internal controls over the federal award (§200.303)EnforcedL3 Enforceable2 C.F.R. §200.303Replay-Proof™WORM audit hash-chainEvidence Pack™
Pass-through entity / subrecipient monitoring (§200.332)EnforcedL3 Enforceable2 C.F.R. §200.332Governed Grants Agent™ admit→decideDelegated Auditability
Prior written approval & record retention (§200.407, §200.334)DesignedL2 Designed2 C.F.R. §200.407, 2 C.F.R. §200.334GovernedUI two-person sign-off (Phase-2)WORM retention policy (Phase-2)
Grantee financial-management system & Single Audit (§200.302, §200.501)Out of scopeL1 Mapped2 C.F.R. §200.302, 2 C.F.R. §200.501—

IT Rules 2021

IT Rules 2021

Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as amended · India

KYE™ governs whether an AI agent's content-affecting ACTION (publish, remove, restrict, distribute) was authorised and is evidenced. KYE™ is OUT-OF-SCOPE for the substantive content determination — whether material is unlawful — and for operating grievance-redressal machinery. Those are the intermediary's own obligations (§70 §4). Deep per-requirement mapping: 4 requirements, 1 enforced by KYE™ runtime, 3 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.

1

Enforced

0

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority + evidence at the action boundary — enforced by KYE™ runtime and verified by CIEnforcedL3 Enforceableit-rules-2021.ACTION-AUTHORITY — Content-affecting actions taken under resolved authority and evidencedkye.compliance.attestation.v1kye.evidence.decision_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context_seal.v1internal
Obligations owed directly by the regulated entity — NOT discharged by KYE™KYE™ governs whether an AI agent's content-affecting ACTION (publish, remove, restrict, distribute) was authorised and is evidenced. KYE™ is OUT-OF-SCOPE for the substantive content determination — whether material is unlawful — and for operating grievance-redressal machinery. Those are the intermediary's own obligations (§70 §4).Out of scopeL1 Mappedit-rules-2021.GRIEVANCE-REDRESSAL — Grievance officer appointed and complaints resolved within prescribed timelines, it-rules-2021.DUE-DILIGENCE — Intermediary due-diligence obligations including publication of rules and privacy policy, it-rules-2021.SYNTHETIC-LABELLING — Identification of artificially generated or modified information—

Security & cyber-resilience

Information-security and operational-resilience frameworks that govern how systems are protected, monitored, and recovered.

ASD Essential Eight

ASD Essential Eight + ASD AI guidance

Nov 2023 maturity model + 2024 AI guidance · Australia

ASD/ACSC Essential Eight mitigation strategies + ASD 'Engaging with Artificial Intelligence' guidance, scoped to the AI-agent action path. Per-requirement bijection at /compliance/asd-essential-eight.html.

2

Enforced

0

Designed

0

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Restrict administrative privileges + multi-factor authenticationEnforcedL3 EnforceableE8 — Restrict admin privileges, E8 — MFAAuthority GateAuthority Revocation OrchestratorWebAuthn step-up
Tamper-evident monitoring + AI supply-chain governanceEnforcedL3 EnforceableE8 — Monitoring, ASD AI guidance — supply chainWORM audit hash-chainStreaming Logs Contract™Authority Register

CISA CDM

CISA CDM — Continuous Diagnostics and Mitigation (AI-agent asset accountability)

CDM Program — DEFEND capability areas A–D · United States

CISA's Continuous Diagnostics and Mitigation program, mapped to the agentic-AI asset surface: an AI agent that holds credentials, reaches data, and acts on systems is a reportable cyber asset. KYE™ answers 'what agents exist, who owns them, what do they touch, what can they do, and are they drifting?'

4

Enforced

0

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Asset Management — HWAM/SWAM/CSM/VUL (the AI-agent asset inventory + approved-design baseline + drift)EnforcedL3 EnforceableHWAM, SWAM, CSM, VUL§14 Agent Registry (reportable assets)Operating Model™ baselineReality Coupling™ drift
Identity & Access Management — TRUST/CRED/PRIV/BEHAVEEnforcedL3 EnforceableTRUST, CRED, PRIV, BEHAVEKnow Your Entity™ resolutionAuthority tokens + revocationPurpose Permission™ least privilege
Network Security Management — BOUND/MNGEVT (tenant isolation + suspend/revoke response)EnforcedL3 EnforceableBOUND, MNGEVT§0.11 tenant isolationSuspend/Revoke/Kill-switchWORM audit
Data Protection Management — DPM (tamper-evident, replayable evidence)EnforcedL3 EnforceableDPMWORM audit hash-chainEvidence Pack™Replay Proof™

FedRAMP

FedRAMP — Federal Risk and Authorization Management Program

Rev 5 · United States

US federal cloud authorisation program built on the NIST SP 800-53 control baseline.

4

Enforced

0

Designed

1

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Access Control (AC) familyEnforcedL3 EnforceableACAuthority GatePurpose Permission™WebAuthn step-up
Audit & Accountability (AU) familyEnforcedL3 EnforceableAUWORM audit hash-chainDecision replay
Identification & Authentication (IA) familyEnforcedL3 EnforceableIAWebAuthn step-upAuthority Gate
System & communications protection — cryptographyA FIPS-validated cryptographic adapter and automated key rotation are in build.EnforcedL3 EnforceableSC-12, SC-13FIPS-validated crypto moduleAutomated key rotationEvidence Pack™ signing (COSE-Sign1)
Physical (PE) & Personnel (PS) familiesPhysical and personnel controls are operated by the customer's authorised cloud environment.Out of scopeL1 MappedPE, PS—

Google SRE Change Mgmt

Google SRE — Change Management (progressive rollout & rollback)

SRE Book · International

Google SRE — Change Management (progressive rollout & rollback). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE™ Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.

1

Enforced

0

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Progressive rollout authority & rollback readiness (action-boundary, enforced)EnforcedL3 Enforceablegoogle-sre-change-management.progressive-rollout-authorityAction Admissibility™ GateAuthority Finality™Evidence Pack™
Monitoring, canary analysis & rollout-automation tooling (out-of-scope — sre / platform)Out of scopeL1 Mappedgoogle-sre-change-management.monitoring-rollout-tooling—

ISO 27001

ISO/IEC 27001 — Information Security Management

2022 · International

Information security management system requirements and the Annex A control set.

3

Enforced

1

Designed

1

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Organisational & people controlsEnforcedL3 EnforceableA.5.x, A.6.xPurpose Permission™Authority Gate
Identity & access managementEnforcedL3 EnforceableA.5.15-A.5.18, A.8.2-A.8.5Authority GateWebAuthn step-upPurpose Permission™
Logging, monitoring & event managementEnforcedL3 EnforceableA.8.15, A.8.16WORM audit hash-chainDecision replay
Cryptographic controls & key managementEd25519 signing runs in-process today; the KMS/HSM-backed key-rotation and FIPS-validated adapter are in build.DesignedL2 DesignedA.8.24Evidence Pack™ signing (COSE-Sign1)Automated key rotationFIPS-validated crypto module
Physical security & training deliveryKYE™ records that training was completed as a capability grant, but does not deliver content or operate physical and environmental controls.Out of scopeL1 MappedA.7.x, A.6.3—

ISO/IEC 20000-1

ISO/IEC 20000-1 — Service Management (change management §8.5.1)

2018 · International

ISO/IEC 20000-1 — Service Management (change management §8.5.1). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE™ Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.

1

Enforced

0

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Change management §8.5.1 — authorization & records (action-boundary, enforced)EnforcedL3 Enforceableiso-iec-20000-1.clause8-5-1-change-managementAction Admissibility™ GateAuthority Finality™Evidence Pack™
Service-management system operation, SLAs & continual improvement (out-of-scope — service-management)Out of scopeL1 Mappediso-iec-20000-1.smsystem-operation—

ITIL 4 Change Enablement

ITIL 4 — Change Enablement (change authority & assessment)

4 · International

ITIL 4 — Change Enablement (change authority & assessment). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE™ Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.

1

Enforced

0

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Change authority & assessment (action-boundary, enforced)EnforcedL3 Enforceableitil-4-change-enablement.change-authority-assessmentAction Admissibility™ GateAuthority Finality™Evidence Pack™
Technical change evaluation, scheduling & change-model authoring (out-of-scope — change-management)Out of scopeL1 Mappeditil-4-change-enablement.change-evaluation-technical—

NIS2

NIS2 — Network and Information Security Directive

Directive (EU) 2022/2555 · European Union

EU cybersecurity directive setting risk-management and incident-reporting duties for essential and important entities.

2

Enforced

1

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Cybersecurity risk-management measuresEnforcedL3 EnforceableArt. 21Purpose Permission™Authority GateWORM audit hash-chain
Incident handling & reporting evidenceEnforcedL3 EnforceableArt. 23WORM audit hash-chainDecision replay
Supply-chain security evidenceSupply-chain federation runs through the Directory tenant proxy today; signed supply-chain evidence packs are in build.DesignedL2 DesignedArt. 21(2)(d)Evidence Pack™ signing (COSE-Sign1)Directory tenant proxy
Management-body governance designationDesignation of management-body responsibility for cybersecurity risk is an organisational matter.Out of scopeL1 MappedArt. 20—

NIST 800-207

NIST SP 800-207 — Zero Trust Architecture

1.0 · United States

Reference architecture for zero-trust security: per-request authorisation and continuous evaluation.

3

Enforced

0

Designed

1

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Policy decision & enforcement pointEnforcedL3 Enforceable§2, §3.1Authority GatePurpose Permission™
Continuous evaluation & per-request authorisationEnforcedL3 Enforceable§3.2Purpose Permission™WebAuthn step-up
Audit, telemetry & diagnosticsEnforcedL3 Enforceable§3.4WORM audit hash-chainDecision replay
Deployment-topology selectionKYE™ aligns with every zero-trust deployment variant but does not prescribe one; deployment topology is the customer's choice.Out of scopeL1 Mapped§3.3—

NIST 800-53 CM

NIST SP 800-53 Rev 5 — Configuration Management (CM) family

Rev 5 · United States

NIST SP 800-53 Rev 5 — Configuration Management (CM) family. KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE™ Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.

1

Enforced

0

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
CM-3 configuration change control — authority & impact analysis (action-boundary, enforced)EnforcedL3 Enforceablenist-800-53-cm.cm-3-configuration-change-controlAction Admissibility™ GateAuthority Finality™Evidence Pack™
CM-2 baseline configuration & CM-8 component inventory (out-of-scope — config-management)Out of scopeL1 Mappednist-800-53-cm.cm-2-baseline-inventory—

NIST CSF

NIST Cybersecurity Framework

2.0 · United States

Outcome-based cybersecurity framework organised around the Govern, Identify, Protect, Detect, Respond, and Recover functions.

3

Enforced

1

Designed

0

Out of scope

4 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Govern functionEnforcedL3 EnforceableGVPurpose Permission™Authority Gate
Identify & Protect functionsEnforcedL3 EnforceableID, PRAuthority GatePurpose Permission™WebAuthn step-up
Detect, Respond & Recover functionsEnforcedL3 EnforceableDE, RS, RCWORM audit hash-chainDecision replay
Tamper-evident control evidenceThe append-only audit chain protects evidence integrity today; detached signatures that prove integrity to an external party are in build.DesignedL2 DesignedPR.DSEvidence Pack™ signing (COSE-Sign1)

SOC 2

SOC 2 — Trust Services Criteria

TSC 2017 · Global

AICPA Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy.

4

Enforced

1

Designed

1

Out of scope

6 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Control environment, communication & risk assessmentEnforcedL3 EnforceableCC1.x, CC2.x, CC3.xPurpose Permission™Authority GateWORM audit hash-chain
Logical access controlsEnforcedL3 EnforceableCC6.1-CC6.8Authority GatePurpose Permission™WebAuthn step-up
System operations, monitoring & change managementEnforcedL3 EnforceableCC7.x, CC8.1WORM audit hash-chainDecision replay
Confidentiality, availability & recoveryEnforcedL3 EnforceableC1.x, A1.2, P4.1Authority GateWORM audit hash-chain
Independently verifiable transparency receiptsTransparency receipts are emitted today; the detached cryptographic signatures that make them third-party-verifiable are in build.DesignedL2 DesignedCC2.3Evidence Pack™ signing (COSE-Sign1)Decision Map™ signing (JWS-detached)
Board oversight & physical securityBoard composition and data-centre physical controls are organisational; KYE™ records the actions of board members but does not establish governance structure.Out of scopeL1 MappedCC1.2—

SOC 2 CC8

Production Action Authority — SOC 2 CC8 Change Management

2017 TSC · United States

SOC 2 — CC8 Change Management (Common Criteria). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE™ Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.

1

Enforced

0

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
CC8.1 change authorization & evidence (action-boundary, enforced)EnforcedL3 Enforceablesoc2-cc8-change-management.cc8-1-change-authorizationAction Admissibility™ GateAuthority Finality™Evidence Pack™
Change design, development & testing (out-of-scope — engineering / qa)Out of scopeL1 Mappedsoc2-cc8-change-management.cc8-development-testing—

OWASP Agentic Top 10

OWASP Top 10 for Agentic Applications (Agentic AI Threats and Mitigations)

2025 · International

OWASP's agentic-AI threat taxonomy (2025), crosswalked by AIUC-1. KYE Protocol™ is the runtime authority + evidence + finality substrate each threat class assumes — it gates the agent action, binds agent identity, and seals replay-provable evidence. KYE™ proves the control operated at the action boundary; it is not an agent scanner. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Tool misuse / privilege / intent — gated by purpose-scopeDesignedL2 Designedowasp-agentic.t2-tool-misuse, owasp-agentic.t3-privilege-compromise, owasp-agentic.t6-intent-goal-manipulationPurpose Permission™Decision Map™Authority Gate
Repudiation / spoofing / deception — identity + replay evidenceDesignedL2 Designedowasp-agentic.t8-repudiation-untraceability, owasp-agentic.t9-identity-spoofing, owasp-agentic.t7-misaligned-deceptiveEvidence Pack™Replay Proof™Delegated Auditability
Memory poisoning / HITL overwhelm — memory authority + approval modesDesignedL2 Designedowasp-agentic.t1-memory-poisoning, owasp-agentic.t10-hitl-overwhelmMemory AuthorityGovernedUI

SASH Cyber Agents

Singapore SASH — Detecting Offensive Cyber Agents

2026 · Singapore

Singapore SASH 'Detecting Offensive Cyber Agents' defence-in-depth (2026). KYE Protocol™ makes a defending org's own agents first-class identifiable principals with replay-provable actions + a continuous posture signal — complementing the identity, triage and exchange (ACE) layers. KYE™ is the authority + evidence substrate, not an IDS/honeypot. Per-requirement bijection at framework-coverage-bijection.

0

Enforced

3

Designed

0

Out of scope

3 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Agent identity — first-class bound principalsDesignedL2 Designedsash.agent-identityDelegated Agent BindingAgent Identity
Detection & triage — continuous posture signalDesignedL2 Designedsash.detection-triagePosture SignalDelegated Agent Binding
ACE exchange + post-incident replayDesignedL2 Designedsash.ace-exchange, sash.evidence-replayEvidence Pack™Replay Proof™Delegated Auditability

CRA

EU Cyber Resilience Act (CRA)

Regulation (EU) 2024/2847 · European Union

EU horizontal cybersecurity regulation for products with digital elements; mandatory SBOM, vulnerability handling, security-by-design, and Article 14 vulnerability/incident reporting (24h/72h/14-day). Fully applicable Dec 2027.

3

Enforced

1

Designed

1

Out of scope

5 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Security-by-design essential requirements (Annex I, Part I)EnforcedL3 EnforceableAnnex I, Part IPurpose Permission™WORM audit hash-chainSIEM streaming logs
Vulnerability handling + remediation (Annex I, Part II)EnforcedL3 EnforceableAnnex I, Part IICyber-resilience incident rule packDecision replay
SBOM generation & machine-readable bill of materialsKYE™ does not generate the product SBOM (manufacturer obligation); a manufacturer-supplied SBOM can be cited and pinned as evidence to a governed vulnerability-handling decision. Runtime ingest is designed, not yet wired.DesignedL2 DesignedAnnex I, Part II (1)Document Intelligence Rail (cite-and-pin)
Article 14 vulnerability & severe-incident reporting (24h/72h/14-day)EnforcedL3 EnforceableArt. 14Incident lifecycleEvidence Pack™ signing
Conformity assessment & CE markingConformity assessment, CE marking and placing-on-the-market are product-certification obligations of the manufacturer and notified body, outside KYE™'s lane.Out of scopeL1 MappedArt. 32, Annex VIII—

CERT-In Directions

CERT-In Cyber Security Directions

Directions dated 28 April 2022 under s.70B(6), Information Technology Act, 2000 · India

KYE™ governs the AUTHORITY + EVIDENCE layer of incident response: what was decided, under whose authority, and when — sealed so the sequence is replayable against a statutory clock. KYE™ is OUT-OF-SCOPE for detecting cyber incidents across the customer's estate, for operating their SOC, and for making the regulatory filing to CERT-In. The six-hour obligation is the customer's; KYE™ makes the timeline provable (§70 §4). Deep per-requirement mapping: 5 requirements, 2 enforced by KYE™ runtime, 3 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.

1

Enforced

0

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority + evidence at the action boundary — enforced by KYE™ runtime and verified by CIEnforcedL3 Enforceablecert-in-directions-2022.SIX-HOUR-CLOCK — Specified cyber incidents reported to CERT-In within six hours of noticing, cert-in-directions-2022.LOG-RETENTION — ICT system logs maintained securely for a rolling 180-day period within Indian jurisdictionkye.compliance.attestation.v1kye.evidence.pack.v1kye.replay.context_seal.v1kye.resilience.availability_gap.v1
Obligations owed directly by the regulated entity — NOT discharged by KYE™KYE™ governs the AUTHORITY + EVIDENCE layer of incident response: what was decided, under whose authority, and when — sealed so the sequence is replayable against a statutory clock. KYE™ is OUT-OF-SCOPE for detecting cyber incidents across the customer's estate, for operating their SOC, and for making the regulatory filing to CERT-In. The six-hour obligation is the customer's; KYE™ makes the timeline provable (§70 §4).Out of scopeL1 Mappedcert-in-directions-2022.TIME-SYNC — System clocks synchronised to NPL or NIC network time, cert-in-directions-2022.INCIDENT-DETECTION — Detection and triage of reportable cyber incidents across the estate, cert-in-directions-2022.REGULATORY-FILING — Submission of the incident report to CERT-In in the prescribed format—

SEBI CSCRF

SEBI CSCRF

Cybersecurity and Cyber Resilience Framework (CSCRF) · India

KYE™ governs the AUTHORITY + EVIDENCE layer of consequential actions and of incident RESPONSE decisions. KYE™ is OUT-OF-SCOPE for the identify/protect/detect capabilities themselves — asset inventory, network protection, monitoring — which the regulated entity operates (§70 §4). Deep per-requirement mapping: 6 requirements, 2 enforced by KYE™ runtime, 4 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.

1

Enforced

0

Designed

1

Out of scope

2 requirement groups — view detail
Requirement groupStatusMaturityFramework refsKYE™ controls
Authority + evidence at the action boundary — enforced by KYE™ runtime and verified by CIEnforcedL3 Enforceablesebi-cyber-resilience.RESPOND-AUTHORITY — Incident-response actions taken under resolved authority and sealed, sebi-cyber-resilience.EVIDENCE-RETENTION — Retention of security event records supporting audit and forensic reviewkye.compliance.attestation.v1kye.evidence.decision_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context_seal.v1internal
Obligations owed directly by the regulated entity — NOT discharged by KYE™KYE™ governs the AUTHORITY + EVIDENCE layer of consequential actions and of incident RESPONSE decisions. KYE™ is OUT-OF-SCOPE for the identify/protect/detect capabilities themselves — asset inventory, network protection, monitoring — which the regulated entity operates (§70 §4).Out of scopeL1 Mappedsebi-cyber-resilience.IDENTIFY-PROTECT — Asset identification and protective controls across the estate, sebi-cyber-resilience.DETECT-MONITOR — Continuous monitoring and detection of cyber events, sebi-cyber-resilience.INCIDENT-REPORTING — Reporting of cyber incidents to SEBI within prescribed timelines, sebi-cyber-resilience.RECOVER — Recovery and restoration capability with defined objectives—

Methodology

One registry. Zero hand-authored numbers.

This page is generated. The framework roster, every count, and every headline number above are projected from internal — a schema-backed canonical registry validated on every build. The page cannot drift from the registry: a CI gate regenerates it and fails the build on any mismatch.

For the full per-control register — every article and criterion bound to its KYE™ runtime control — see the compliance frameworks reference and the compliance program. KYE Protocol™ is an evidence layer: it is not a certification, and it does not replace the customer’s own controls or an accredited assessment.

See your own coverage map.

Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.