Enforced
Live runtime code enforces this requirement, and a CI gate verifies it on every release.
Regulatory coverage
KYE Protocol™ maps to 249 regulatory frameworks, decomposed into 853 requirement groups. 446 are Enforced at runtime, 254 Designed and in build, 153 Out of scope. Every number here is computed from a single schema-backed registry — change the registry, the page regenerates.
You learn: Where KYE™ coverage is active, staged or planned. You can: Pick a stage.
| Global / jurisdiction-neutral · 5 frameworks | ✓ | — | — |
|---|---|---|---|
| International (ISO / IEC) · 5 frameworks | ✓ | — | — |
| United Kingdom · 19 frameworks | ✓ | — | — |
| United States · 17 frameworks | ✓ | — | — |
| European Union · 9 frameworks | ✓ | — | — |
| Gulf region (GCC) · 4 frameworks | ✓ | — | — |
| Public sector (cross-jurisdiction) · 4 frameworks | ✓ | — | — |
| Canada · 16 frameworks | ✓ | — | — |
| Australia · 4 frameworks | ✓ | — | — |
| New Zealand · 3 frameworks | ✓ | — | — |
| Singapore · 3 frameworks | ✓ | — | — |
| Japan · 3 frameworks | ✓ | — | — |
| India · 6 frameworks | — | ✓ | — |
| Brazil | — | — | ✓ |
| China (PRC) · 1 frameworks | — | — | ✓ |
| Switzerland · 1 frameworks | ✓ | — | — |
| Hong Kong | — | — | ✓ |
| Germany · 5 frameworks | ✓ | — | — |
| France · 5 frameworks | ✓ | — | — |
| Italy · 5 frameworks | ✓ | — | — |
| Spain · 5 frameworks | ✓ | — | — |
| Netherlands · 5 frameworks | ✓ | — | — |
| Belgium · 5 frameworks | ✓ | — | — |
| Luxembourg · 5 frameworks | ✓ | — | — |
| Poland · 5 frameworks | ✓ | — | — |
| Sweden · 5 frameworks | ✓ | — | — |
| Norway · 5 frameworks | ✓ | — | — |
| Denmark · 5 frameworks | ✓ | — | — |
| Finland · 5 frameworks | ✓ | — | — |
| Austria · 5 frameworks | ✓ | — | — |
| Ireland · 5 frameworks | ✓ | — | — |
| Portugal · 5 frameworks | ✓ | — | — |
| Greece · 5 frameworks | ✓ | — | — |
| Czech Republic · 5 frameworks | ✓ | — | — |
| Hungary · 5 frameworks | ✓ | — | — |
| Romania · 5 frameworks | ✓ | — | — |
| Slovakia · 5 frameworks | ✓ | — | — |
| Bulgaria · 5 frameworks | ✓ | — | — |
| Cyprus · 5 frameworks | ✓ | — | — |
| Malaysia · 1 frameworks | — | ✓ | — |
| United Arab Emirates · 1 frameworks | — | ✓ | — |
| Bahrain · 1 frameworks | — | ✓ | — |
| Saudi Arabia · 1 frameworks | — | ✓ | — |
| Indonesia · 1 frameworks | — | ✓ | — |
| Pakistan · 1 frameworks | — | ✓ | — |
| Qatar · 1 frameworks | — | ✓ | — |
| Kuwait · 1 frameworks | — | ✓ | — |
| Oman · 1 frameworks | — | ✓ | — |
| Türkiye · 1 frameworks | — | ✓ | — |
| Nigeria · 1 frameworks | — | ✓ | — |
| Brunei Darussalam · 1 frameworks | — | ✓ | — |
| Jordan · 1 frameworks | — | ✓ | — |
| Egypt · 1 frameworks | — | ✓ | — |
| Sudan · 1 frameworks | — | ✓ | — |
| Thailand | — | — | ✓ |
How to read this map
Every requirement group below carries exactly one of these states. A group is only marked Enforced when runtime code and a CI gate back it — so a customer’s audit team can sign with the right residual-risk register.
Live runtime code enforces this requirement, and a CI gate verifies it on every release.
Schema, contract, and acceptance criteria are locked; the runtime implementation is in build and tracked in the implementation plan.
Not discharged by KYE Protocol™ — owned by the customer's own systems, processes, or counsel. KYE™ is an evidence layer, not a replacement for these controls.
The coverage-maturity ladder
Tri-state tells you whether KYE Protocol™ owns a control. The maturity ladder tells you how far it has climbed — from merely mapped, through designed and enforceable, to evidence-backed and certified. A row only claims evidence-backed or certified when a real Evidence Pack™ or assessor artefact backs it; a CI gate rejects any inflated claim. This is the per-control axis — orthogonal to where KYE Protocol™ ships SKUs by jurisdiction.
KYE Protocol™ has mapped the obligation/control: the framework requirement is decomposed and crosswalked to the KYE Protocol™ control vocabulary, but no design, runtime check, evidence, or certification is asserted at this level.
KYE Protocol™ has a profile / control design for the obligation: schema, contract, and acceptance criteria are locked and tracked in the implementation plan, but the runtime enforcement is in build.
KYE Protocol™ can enforce the obligation via live runtime checks (a Decision Engine / Authority Gate path or a CI gate that fails closed). A claim at this level must resolve to a real runtime control or gate.
KYE Protocol™ generates a signed Evidence Pack™ for the obligation — the enforcement decision is captured as a replayable, third-party-verifiable artefact. A claim at this level must resolve to a real Evidence Pack™ example on disk (honest-floor rule).
An external KYE™ Seal™ / accredited-assessor review is available for the obligation. The top of the ladder: a buyer can point at an independent assessment, not just KYE Protocol™'s own evidence. A claim at this level must resolve to a real seal / assessor artefact on disk (honest-floor rule).
Coverage by framework
Filter by state to see exactly where KYE Protocol™ enforces today, where it is in build, and where the customer owns the control.
Frameworks that govern the lifecycle, oversight, and accountability of AI systems and AI agents.
AI-CAIQ
1.0 · International
The CSA AI Consensus Assessments Initiative Questionnaire is the self-assessment companion to the AICM and the basis for CSA STAR-for-AI listings. KYE™ generates each answer it can satisfy from runtime evidence (a KYE™ artefact + a §0.3 evidence event), and marks questions outside its execution scope as not applicable — never fabricated.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Questionnaire answers generated from replay-provable runtime evidence | Enforced | L3 Enforceable | AI-CAIQ (KYE-resolvable questions) | Evidence Pack™Decision Map™Replay-Proof™ |
| Out-of-scope questions marked not applicableInfrastructure, training-pipeline and internal model-validation questions are not applicable to the KYE™ execution-layer scope. Marked honestly, never fabricated. | Out of scope | L1 Mapped | AI-CAIQ (infrastructure / model-training questions) | — |
AI Solutions Framework
1.0 · International
The AI Solutions Framework is an enterprise AI-adoption control framework (~90 safeguards across AI governance & accountability, risk management, AI safety, data privacy/lineage, compliance monitoring, and audit & evidence; IG1–IG3 maturity). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the KYE™ AI Solutions Framework Authority Pack™ (§70 honesty bar). Frameworks define what should happen; KYE Protocol™ resolves who may make it happen, under what authority, and proves it later. The organisational safeguards (governance board, AI inventory, policy authorship, training, risk committee) and the deploy-time infrastructure-posture / CSPM safeguards (model-logging, encryption, IAM least-privilege, network egress) are honestly out of scope and ceded to their owning roles. KYE Protocol™ complements a deploy-time posture/CSPM layer — coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| AI governance & accountability — action-boundary authority (enforced) | Enforced | L3 Enforceable | ai-solutions-framework.approval-workflow-authority, ai-solutions-framework.accountability-named-principal | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| AI risk management & safety — attestation + human-oversight stage gate (enforced) | Enforced | L3 Enforceable | ai-solutions-framework.attestation-due-diligence-before-action, ai-solutions-framework.human-oversight-stage-gate | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Compliance monitoring & audit/evidence — exception register + provenance pin (enforced) | Enforced | L3 Enforceable | ai-solutions-framework.exception-register, ai-solutions-framework.audit-evidence-provenance-pin | Evidence Pack™Replay-Proof™Audit WORM |
| Organisational safeguards (out of scope — governance-office / CISO) | Out of scope | L1 Mapped | ai-solutions-framework.ai-governance-board, ai-solutions-framework.ai-system-inventory, ai-solutions-framework.ai-acceptable-use-policy, ai-solutions-framework.ai-workforce-training, ai-solutions-framework.ai-risk-committee-review | — |
| Infrastructure posture / CSPM safeguards (out of scope — cloud-platform / devsecops; complemented by KYE Protocol™) | Out of scope | L1 Mapped | ai-solutions-framework.model-inference-logging-enabled, ai-solutions-framework.ai-data-storage-encryption, ai-solutions-framework.ai-iam-least-privilege, ai-solutions-framework.ai-network-egress-posture | — |
AICM Resolution
1.0 · International
The Cloud Security Alliance AI Controls Matrix defines 243 control objectives across 18 domains. AICM defines the controls. KYE™ operationalises them — proving how each control resolved at the moment a consequential AI action occurred. KYE™ binds the execution-resolvable domains and is honest about the infrastructure and model-training domains it does not touch.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Identity & access management — authority at the moment of action | Enforced | L3 Enforceable | IAM, AAC | Purpose Permission™Authority GateDelegated-agent binding |
| Governance, risk & compliance — human oversight + recurring attestation | Enforced | L3 Enforceable | GRC | GovernedUI human-control surface≤90-day compliance attestation |
| Logging & monitoring — signed evidence + decision map per action | Enforced | L3 Enforceable | LOG | Evidence Pack™Decision Map™WORM audit hash-chain |
| Model risk & resilience — replay-provable from public keys | Enforced | L3 Enforceable | MRM (action-resolution slice) | Replay-Proof™Context seal |
| Supply chain & transparency — provenance pinned in evidence | Enforced | L3 Enforceable | STA | Tool-call pinEvidence Pack™ |
| Application-interface + data-lifecycle admissibility at the boundaryThe deny-by-default action-boundary and moment-of-use data admissibility contracts are locked; per-interface and per-asset runtime wiring is in build. | Enforced | L3 Enforceable | AIS, DSP | Policy Enforcement PointData-use PDP stage |
| Cloud infrastructure security + model-training & internal model validationCloud-fabric hardening is operated by the cloud service provider; training-pipeline security and internal model validation are owned by the model developer. KYE™ governs how a model's actions resolve at run time and records them — it does not operate the infrastructure or train the model. | Out of scope | L1 Mapped | IVS, TVM, MRM (model-internals slice) | — |
AIDA
Bill C-27 Part 3 (tabled, lapsed Jan 2025) · Canada
Canada's proposed federal AI law (AIDA, Part 3 of Bill C-27). The bill lapsed on prorogation in January 2025 and is NOT in force — mapped as a forward-looking design anchor (all rows advisory): high-impact assessment, risk mitigation + monitoring, record-keeping, transparency, and serious-harm notification. Per-requirement bijection at /compliance/aida.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| High-impact system assessment (s.7) | Designed | L2 Designed | s7 | Risk Engine |
| Risk mitigation + monitoring (s.8-9) | Designed | L2 Designed | s8 | Drift DetectorRisk Engine |
| Record-keeping (s.10) | Designed | L2 Designed | s10 | WORM audit hash-chain |
| Transparency / publication (s.11) | Designed | L2 Designed | s11 | Reporting Engine |
| Serious-harm notification (s.12) | Designed | L2 Designed | s12 | Incident DetectorReporting Engine |
AU AI Guardrails
DISR 2024 (10 guardrails) · Australia
The 10 mandatory AI guardrails proposed by the Department of Industry, Science and Resources (Sept 2024) + the Voluntary AI Safety Standard. Per-requirement bijection at /compliance/au-ai-guardrails.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Accountability, risk management & data governance (G1-G3) | Enforced | L3 Enforceable | Guardrail 1, Guardrail 2, Guardrail 3 | Purpose Permission™Risk EngineData Classification EngineEvidence Pack™ |
| Testing, human oversight, transparency & contestability (G4-G7) | Enforced | L3 Enforceable | Guardrail 4, Guardrail 5, Guardrail 6, Guardrail 7 | Conformance RunnerDrift DetectorGovernedUI™Decision Map™Replay-Proof™ |
| Supply-chain transparency & record-keeping (G8-G9) | Enforced | L3 Enforceable | Guardrail 8, Guardrail 9 | Authority RegisterWORM audit hash-chainEvidence Pack™ |
| Stakeholder engagement (G10)Process-and-policy obligation owned by the customer's governance function; KYE™ records that engagement occurred but does not perform it. | Out of scope | L1 Mapped | Guardrail 10 | — |
BSI AIC4
2021 · Germany
The German Federal Office for Information Security (BSI) AI Cloud Service Compliance Criteria Catalogue (AIC4) — one of the frameworks the CSA AICM crosswalks to. KYE™ binds the security-and-robustness criteria that resolve at action time and marks the cloud-platform operational criteria out of scope.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Security & robustness of AI decisions — evidenced at action time | Enforced | L3 Enforceable | AIC4 Security & Robustness, AIC4 Reliability | Evidence Pack™Replay-Proof™Purpose Permission™ |
| Performance, bias mitigation & explainability of the AI decision recordThe decision-record contract that backs explainability and the action-level audit is locked; the per-criterion runtime surface is in build. | Enforced | L3 Enforceable | AIC4 Performance & Functionality, AIC4 Bias, AIC4 Explainability | Decision Map™ |
| Cloud-platform operations, data centre & training-environment criteriaCloud-platform operations and the model-training environment are operated by the cloud service provider and the model developer, not by KYE™. Out of scope (§0 honest scope). | Out of scope | L1 Mapped | AIC4 Data Management (training), AIC4 Operations | — |
EC-Council ADG
2026 · Global
35 requirements across three pillars (Adopt / Defend / Govern), nine governance surfaces, twelve minimum controls (MC-1..MC-12), and three autonomy tiers (HITL / HOTL / HOOTL). Complementary to KYE Protocol™: ADG = operating model, KYE Protocol™ = runtime authority proof.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Pillar 1 — Adopt (10 requirements covering lifecycle, capability, risk, secure deployment, change, evidence, purpose grant, training, acceptable use, assurance baseline) | Enforced | L3 Enforceable | ADG/Adopt | Model capability profileRisk assessmentPurpose Permission™ grant issuanceAdoption evidence packInitial compliance attestation |
| Pillar 2 — Defend (10 requirements covering threat-model, red-team, runtime monitoring, tool/MCP register, prompt-injection defence, supply chain, incident response, SPOF, federation, continuous attestation) | Enforced | L3 Enforceable | ADG/Defend | KYE™ Tool & MCP Authority Register™Tool call pin (side-effect binding)Drift signal familyReplay-Proof™ envelopeSPOF registryFederation cross-org delegationCompliance attestation cadence |
| Pillar 3 — Govern (15 requirements covering authority register, purpose grant, admissibility, evidence pack, decision map, replay-proof, Authority Finality™, human oversight, autonomy tiers, MC-1..MC-12, decision rights, board reporting) | Enforced | L3 Enforceable | ADG/Govern, ADG/MC-1..MC-12 | Purpose Permission™Action Admissibility™ GateDecision Map™Evidence Pack™Replay-Proof™Authority Finality™GovernedUI™ critical-point reviewKYE Autonomy Tiers™ (A0-A3)KYE™ Minimum Authority Controls™ (KAC-1..KAC-12) |
EEOC Uniform Guidelines
1978 (29 CFR Part 1607) · United States
US federal guidelines defining the four-fifths adverse-impact rule and the validation duty for selection procedures.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Four-fifths adverse-impact rule | Enforced | L3 Enforceable | 29 CFR §1607.4(D) | Evidence Pack™Authority Gate |
| Validation of selection procedures | Designed | L2 Designed | 29 CFR §1607.5 | Delegated Auditability Rail |
EU AI Act
Regulation (EU) 2024/1689 · European Union
EU regulation setting lifecycle obligations for high-risk AI systems.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Risk-management system | Enforced | L3 Enforceable | Art. 9 | Purpose Permission™Authority Gate |
| Data & data governance | Enforced | L3 Enforceable | Art. 10 | Purpose Permission™WORM audit hash-chain |
| Record-keeping & traceability | Enforced | L3 Enforceable | Art. 12, Art. 72 | WORM audit hash-chainDecision replay |
| Human oversight | Enforced | L3 Enforceable | Art. 14 | WebAuthn step-upAuthority Gate |
| Transparency & provision of informationTransparency receipts are emitted today; the detached signatures that make them verifiable downstream are in build. | Designed | L2 Designed | Art. 13, Art. 50 | Decision Map™ signing (JWS-detached)Evidence Pack™ signing (COSE-Sign1) |
| Annex IV technical documentationKYE™ produces operational evidence; the static Annex IV technical-documentation file is authored separately. | Out of scope | L1 Mapped | Art. 11 | — |
EU AI Act Art 50
2024/1689 · European Union
Article 50 of Regulation (EU) 2024/1689 requires natural persons be informed they are interacting with an AI system, plus related transparency record-keeping. KYE Protocol™ governs the ENFORCEMENT AUTHORITY + EVIDENCE of the Article 50 chatbot disclosure at the action boundary — consumed by the KYE™ Chatbot Authority Pack™. The broader Regulation is covered by the eu-ai-act registry; this is the narrow chatbot-transparency execution slice. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Art 50 — AI-interaction disclosure | Enforced | L3 Enforceable | eu-ai-act-chatbot-transparency.art50-chatbot-disclosure-enforcement | Action Admissibility™ GateAuthority Finality™ |
| Art 50 — transparency record-keeping | Enforced | L3 Enforceable | eu-ai-act-chatbot-transparency.art50-transparency-record-keeping | Evidence Pack™Replay-Proof™WORM Retention |
| Disclosure UX & AI Act conformity program (out of scope)Model vendor / operator responsibility — disclosure UX/copy and the broader AI Act conformity program. Zero KYE™ controls (complement-not-compete). | Out of scope | L1 Mapped | eu-ai-act-chatbot-transparency.disclosure-ux-and-conformity-program | — |
FDA / EMA AI
2024-2025 · US / EU
FDA + EMA AI / provenance expectations for AI-derived candidates entering regulated drug/device pipelines — documented provenance, reproducibility, and GxP data integrity (ALCOA+). KYE Protocol™ governs whether an AI-derived candidate may proceed to a regulated stage, binding replay-provable provenance — the KYE™ AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| AI design provenance & reproducibility | Designed | L2 Designed | fda-ema.design-provenance, fda-ema.reproducibility | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| GxP data integrity (ALCOA+) | Designed | L2 Designed | fda-ema.gxp-data-integrity | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Human oversight & accountability | Designed | L2 Designed | fda-ema.human-accountability | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
OECD AI Principles
OECD/LEGAL/0449 (2019, updated 2024) · International
The OECD Recommendation of the Council on Artificial Intelligence (OECD/LEGAL/0449) sets five value-based principles for trustworthy AI — inclusive growth & well-being; human-centred values & fairness; transparency & explainability; robustness, security & safety; and accountability — and is the reference standard behind the G7 Hiroshima Process and many national AI strategies. This framework is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: although several principles crosswalk to existing KYE Protocol™ rails (transparency/explainability → §0.3 evidence & §13 Replay-Proof™; accountability → §21 Audit Pilot™ & §52 agent binding; robustness/safety → §13 Resilience Loop™; human-centred/fairness → §36 GovernedUI™ human-in-the-loop), no requirement has yet been bound at the requirement level. Per the §70 honesty bar, coverage is reported out of scope pending deep mapping rather than claimed as enforced.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): candidate crosswalks to §0.3 / §13 / §21 / §36 / §52 are noted in the summary but NOT yet bound at the requirement level, so coverage stays out of scope until the deep mapping runs through the §70 rail — never inflated to imply enforcement that does not exist. | Out of scope | L1 Mapped | OECD AI Principles (five value-based principles — not yet decomposed into requirement-level mappings) | — |
IMDA MGF (Agentic AI)
v1.5 (20 May 2026, updated 5 June 2026) · Singapore
Singapore IMDA's Model AI Governance Framework for Agentic AI (v1.5) sets expectations across four dimensions: (1) assess and bound the risks upfront; (2) make humans meaningfully accountable; (3) implement technical controls and processes; (4) enable end-user responsibility. This framework is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: although every dimension crosswalks cleanly to existing KYE Protocol™ rails (bound risk upfront → entity/principal identity + §52 agent binding + Purpose Permission™ §12; meaningful human accountability → §36 GovernedUI™ approval modes + Finality Gate; technical controls → §13 Evidence Pack™ / Replay-Proof™ + §34 monitoring; end-user responsibility → §17 Directory + §21 Audit Pilot™), no requirement has yet been bound at the requirement level. Per the §70 honesty bar, coverage is reported out of scope pending deep mapping rather than claimed as enforced.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): the four-dimension crosswalk to KYE™'s entity/§52 / §36 Finality / §13 Evidence+Replay / §17+§21 rails is noted in the summary but NOT yet bound at the requirement level, so coverage stays out of scope until the deep mapping runs through the §70 rail — never inflated to imply enforcement that does not exist. | Out of scope | L1 Mapped | IMDA MGF for Agentic AI — four governance dimensions (not yet decomposed into requirement-level mappings) | — |
Frontier Bio-Safeguard Eval
technical report, June 2026 · International
A proposed common standard (GovAI/OpenAI, June 2026) for evaluating frontier-AI safeguards against biological misuse: seven recommendations across four principles (comparability across companies; account for the deployment environment; treat safeguards as dynamic; preserve legitimate scientific use) plus a three-layer safeguard stack — access (who can use the model), inference (how harmful queries are handled), platform (post-hoc misuse detection) — combined into composite safeguard levels calibrated to threat actor. This standard is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: it crosswalks to KYE™'s genomics-biosecurity Authority Pack™ + Genetic Sequencing Authority Agent™ (action-boundary admissibility + sequence-of-concern screening) and to §52 access controls + §13 Evidence Pack™, but no requirement is bound at the requirement level. Per the §70 honesty bar, coverage is reported out of scope pending deep mapping. NOTE: this standard evaluates MODEL-LEVEL safeguards; KYE™ governs the ACTION boundary — complementary, not the same control.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): crosswalk to the genomics-biosecurity pack + §52/§13 noted in the summary but NOT requirement-bound. The standard evaluates model-level safeguards; KYE™ governs the action boundary — coverage stays out of scope until deep mapping, never inflated. | Out of scope | L1 Mapped | Seven recommendations + three-layer safeguard stack (not yet decomposed into requirement-level mappings) | — |
AI Verify
AI Verify Foundation · Singapore
IMDA / AI Verify Foundation testing framework — transparency, accountability, human agency & oversight, robustness. Per-requirement bijection at /compliance/imda-ai-verify.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Transparency + accountability | Enforced | L3 Enforceable | AI Verify — transparency, AI Verify — accountability | Decision Map™Evidence Pack™Purpose Permission™ |
| Human agency & oversight + robustness | Enforced | L3 Enforceable | AI Verify — human agency, AI Verify — robustness | GovernedUI™Authority GateConformance RunnerDrift Detector |
ISO 42001
2023 · International
Management-system standard for the responsible development and use of AI.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| AI policy & objectives | Enforced | L3 Enforceable | Clause 5-6 | Purpose Permission™Authority Gate |
| Operational AI controls & impact assessment | Enforced | L3 Enforceable | Clause 8, Annex A.6 | Purpose Permission™WORM audit hash-chain |
| Performance evaluation & audit trail | Enforced | L3 Enforceable | Clause 9 | WORM audit hash-chainDecision replay |
| Signed AI-system lifecycle evidenceLifecycle events are recorded in the audit chain today; signed lifecycle evidence packs are in build. | Designed | L2 Designed | Annex A.6.2 | Evidence Pack™ signing (COSE-Sign1) |
MAS FEAT
2018 + Veritas methodology & toolkit · Singapore
MAS Principles to promote Fairness, Ethics, Accountability and Transparency (FEAT) in the use of AI and data analytics in Singapore's financial sector, together with MAS Veritas — the MAS-convened consortium's companion FEAT assessment methodology (phased methodology documents, 2020-2022) and open-source Veritas Toolkit (v2.0, 2023). Veritas is canonicalised inside this framework entry rather than as a standalone framework. Per-requirement bijection at /compliance/mas-feat.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Fairness + ethics | Enforced | L3 Enforceable | FEAT — fairness, FEAT — ethics | Risk EngineDecision Map™Purpose Permission™Authority Gate |
| Accountability + transparency | Enforced | L3 Enforceable | FEAT — accountability, FEAT — transparency | Replay-Proof™Regulator Replay agentEvidence Pack™Decision Map™ |
MAS MindForge
2024 · Singapore
MAS Project MindForge's AI Risk Management: Operationalisation Handbook gives Singapore financial institutions practical guidance for operationalising AI risk management across four blocks (Scope & AI Oversight, AI Risk Management, AI Lifecycle Management, Enablers; 17 considerations). KYE Protocol™ operationalises the action-boundary subset at runtime — it does NOT replace MindForge (§0.25 integrate-not-compete). KYE™ governs whether a consequential financial AI action is authorised, within the human-oversight mode the FI declared for that use, evidenced, contestable, and final at the moment it happens — and proves the basis, replayable by MAS or internal audit. Honest scope: KYE™ does not govern the FI's governance operating model, model-development methodology, or the correctness of the AI's output. Per-requirement bijection at /compliance/mas-mindforge.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Scope & AI oversight (oversight modes machine-enforceable + AI action-authority inventory)Downgraded 2026-09-03 (§70 honesty bar): every per-requirement control mapped for this framework is still Designed, not Enforced, so an 'enforced' group status was a hand-authored claim no control verifies. Restored to 'enforced' only when the deep-store rollup earns it. | Designed | L2 Designed | mas-mindforge.oversight-modes-machine-enforceable, mas-mindforge.action-authority-inventory | GovernedUI™ approval modesPurpose Permission™Authority GateEntity & Principal Registry |
| AI risk management (escalation before finality + third-party / vendor AI authority register)Downgraded 2026-09-03 (§70 honesty bar): every per-requirement control mapped for this framework is still Designed, not Enforced, so an 'enforced' group status was a hand-authored claim no control verifies. Restored to 'enforced' only when the deep-store rollup earns it. | Designed | L2 Designed | mas-mindforge.escalation-before-finality, mas-mindforge.third-party-vendor-authority-register | Authority Gateway (REQUIRE_APPROVAL)Edge Governance Safety FloorAuthority RegisterGovernedUI™ escalation |
| AI lifecycle management (deployment controls at the Authority Gateway + monitoring/change as replay-provable Evidence Packs)KYE™ enforces approved deployment conditions + replay-provable monitoring/change evidence at the action boundary; the FI's pre-deployment validation and model-performance monitoring stay the FI's own (honest scope). Downgraded 2026-09-03 (§70 honesty bar): every per-requirement control mapped for this framework is still Designed, not Enforced, so an 'enforced' group status was a hand-authored claim no control verifies. Restored to 'enforced' only when the deep-store rollup earns it. | Designed | L2 Designed | mas-mindforge.deployment-controls-authority-gateway, mas-mindforge.monitoring-change-evidence-replay | Authority GatewayEvidence Pack™Replay-Proof™WORM audit hash-chain |
| Enablers (named accountability at the action boundary)KYE™ binds and proves named accountability at the boundary; staffing and running the three-lines-of-defence operating model stays the FI's own (honest scope). Downgraded 2026-09-03 (§70 honesty bar): every per-requirement control mapped for this framework is still Designed, not Enforced, so an 'enforced' group status was a hand-authored claim no control verifies. Restored to 'enforced' only when the deep-store rollup earns it. | Designed | L2 Designed | mas-mindforge.enablers-named-accountability | GovernedUI™ named-authority sign-offDelegated Auditability RailAuthority Finality™ |
NIST AI RMF
1.0 · United States
Voluntary framework for managing AI risk across the Govern, Map, Measure, and Manage functions.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Govern function | Enforced | L3 Enforceable | GOVERN | Purpose Permission™Authority Gate |
| Map & Measure functions | Enforced | L3 Enforceable | MAP, MEASURE | Purpose Permission™WORM audit hash-chain |
| Manage function & incident response | Enforced | L3 Enforceable | MANAGE | WORM audit hash-chainDecision replay |
| Independently verifiable measurement evidenceMeasurement outcomes are recorded today; signed, externally verifiable measurement evidence is in build. | Designed | L2 Designed | MEASURE 2.x | Evidence Pack™ signing (COSE-Sign1) |
NYC Local Law 144
2023 (in force 2023-07-05) · United States (New York City)
NYC law requiring a bias audit before an automated employment decision tool screens a candidate, with candidate notice and published results.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| AEDT bias audit | Enforced | L3 Enforceable | NYC Admin Code §20-871 | Evidence Pack™Authority Gate |
| Candidate notice & contestability | Designed | L2 Designed | NYC Admin Code §20-871(b) | Rights-Disputes Rail |
NZ Algorithm Charter
2020 · New Zealand
Algorithm Charter for Aotearoa New Zealand (2020) — transparency, human oversight, and data/bias commitments for government use of algorithms. Per-requirement bijection at /compliance/nz-algorithm-charter.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Transparency + human oversight | Enforced | L3 Enforceable | Charter — transparency, Charter — human oversight | Decision Map™Evidence Pack™GovernedUI™Replay-Proof™ |
| Data clarity + bias management | Enforced | L3 Enforceable | Charter — data and bias | Data Classification EngineRisk Engine |
TBS ADM Directive
TBS (amended 2023) · Canada
The Treasury Board Directive on Automated Decision-Making governing Canadian federal-government automated decision systems: the Algorithmic Impact Assessment, transparency notice, meaningful explanation, and quality-assurance + recourse. Per-requirement bijection at /compliance/tbs-directive-adm.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Algorithmic Impact Assessment | Enforced | L3 Enforceable | aia | Risk Engine |
| Transparency notice | Enforced | L3 Enforceable | notice | Reporting Engine |
| Meaningful explanation | Enforced | L3 Enforceable | explanation | Decision Map™Replay-Proof™ |
| Quality assurance + recourse | Enforced | L3 Enforceable | recourse | Reporting EngineWORM audit hash-chain |
UK AI Assurance
Introduction to AI Assurance, Feb 2024 · United Kingdom
The UK government's AI assurance toolkit — the measure / evaluate / communicate loop and the six assurance mechanisms that operationalise the UK AI principles. KYE Protocol™ is itself an assurance mechanism: it measures every governed AI action, evaluates it against purpose admissibility, and communicates it as signed, replayable evidence.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Measure, evaluate & communicate (the assurance loop)Every governed AI action is measured, evaluated against the purpose grant, and communicated as a signed Evidence Pack™ — assurance as a continuous runtime loop, not a point-in-time review. | Enforced | L3 Enforceable | §4.1 | WORM audit hash-chainEvidence Pack™Decision Map™ |
| Risk assessmentEvery agent action is admitted against a risk-scoped purpose grant before it runs; disallowed actions never execute. | Enforced | L3 Enforceable | §4.2, §5.4 | Purpose Permission™Authority Gate |
| Algorithmic impact assessmentEach decision's inputs and downstream effects are recorded in a Decision Map™; a per-deployment aggregate impact view is in build. | Designed | L2 Designed | §4.2, §5.5 | Decision Map™Evidence Pack™ |
| Bias auditBias and fairness assessment of model outputs is owned by the customer's model-evaluation process — consistent with the UK AI Framework fairness principle. | Out of scope | L1 Mapped | §4.2, §5.6 | — |
| Compliance auditAdherence to internal policy and regulation is continuously reviewable against the tamper-evident, append-only audit chain. | Enforced | L3 Enforceable | §4.2, §5.7 | WORM audit hash-chainControl mappings |
| Conformity assessmentThe KYE™ Conformance Pack™ is the test suite a conformity-assessment body runs; third-party UKAS-accredited certification remains external to the protocol. | Enforced | L3 Enforceable | §4.2, §5.8 | Conformance Pack™ |
| Formal verificationReplay-Proof™ is a deterministic, cryptographically-verifiable re-execution — a governed decision can be mathematically re-checked from public keys alone. | Enforced | L3 Enforceable | §4.2, §5.9 | Replay-Proof™Decision replay |
UK AI
2023 white paper · United Kingdom
The UK's pro-innovation AI principles and the DSIT AI assurance toolkit.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Safety, security & robustness | Enforced | L3 Enforceable | Principle 1 | Purpose Permission™Authority GateWORM audit hash-chain |
| Appropriate transparency & explainability | Enforced | L3 Enforceable | Principle 2 | WORM audit hash-chainDecision replay |
| Accountability & governance | Enforced | L3 Enforceable | Principle 4 | Authority GatePurpose Permission™ |
| Contestability & redress evidenceDecision inputs are replayable today; signed evidence supporting contestability and redress is in build. | Designed | L2 Designed | Principle 5 | Evidence Pack™ signing (COSE-Sign1)Decision Map™ signing (JWS-detached) |
| Fairness assessment of model outputsBias and fairness assessment of model outputs is owned by the customer's model-evaluation process. | Out of scope | L1 Mapped | Principle 3 | — |
UK Equality Act 2010
2010 · United Kingdom
UK statute making an automated selection rule that disadvantages a protected group unlawful indirect discrimination unless objectively justified.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Indirect discrimination (s.19) | Enforced | L3 Enforceable | Equality Act 2010 s.19 | Evidence Pack™Authority Gate |
| Protected characteristics (s.4) | Designed | L2 Designed | Equality Act 2010 s.4 | Data Governance Pack™ |
EO 14110
2023 · United States
US Executive Order 14110 (2023) Safe/Secure/Trustworthy AI — biosecurity, nucleic-acid synthesis screening, and content provenance provisions (rescinded Jan 2025; the dual-use-bio + synthesis-screening + provenance obligation pattern it established remains the de-facto reference set). KYE Protocol™ governs whether an AI-generated sequence/molecule may proceed to a consequential action — the KYE™ AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Dual-use biology & synthesis screening | Designed | L2 Designed | us-eo-14110.4.4-synthesis-screening, us-eo-14110.4.4-dual-use-bio | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Content provenance & authentication | Designed | L2 Designed | us-eo-14110.4.5-provenance | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Human oversight of consequential AI action | Designed | L2 Designed | us-eo-14110.human-oversight | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
UNESCO AI Ethics
2021 · International
The first global normative instrument on AI ethics, adopted (Nov 2021) by all 193 UNESCO member states. KYE Protocol™ operationalises the AI-action authority + evidence boundary of its values & principles — human oversight & determination, transparency & explainability, responsibility & accountability, privacy & data protection, fairness & non-discrimination, safety & security — with named accountability (Authority Finality™), a replay-derivable Evidence Pack™ and Decision Map™. KYE Protocol™ does NOT adjudicate the ethics of the outcome, and the environmental-sustainability and education/public-awareness principles are out-of-scope / customer-owned; coverage is never inflated. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Human oversight & determination | Enforced | L3 Enforceable | unesco-ai-ethics.principle.human-oversight-determination | Purpose Permission™Authority Finality™ |
| Transparency & explainability of AI decisions | Enforced | L3 Enforceable | unesco-ai-ethics.principle.transparency-explainability | Decision Map™Evidence Pack™ |
| Responsibility & accountability — auditable, attributable outcomes | Enforced | L3 Enforceable | unesco-ai-ethics.principle.responsibility-accountability | Authority Finality™Evidence Pack™ |
| Right to privacy & data protection | Designed | L2 Designed | unesco-ai-ethics.principle.privacy-data-protection | Data Purpose Binding™Purpose Permission™ |
| Fairness & non-discrimination (contestability + audit evidence) | Designed | L2 Designed | unesco-ai-ethics.principle.fairness-non-discrimination | Decision Map™Evidence Pack™ |
| Safety & security — action-admissibility safety floor | Designed | L2 Designed | unesco-ai-ethics.principle.safety-security, unesco-ai-ethics.value.human-dignity-rights | Edge Governance Safety FloorPurpose Permission™ |
US Chatbot Laws
2024-2026 · United States
The wave of US state AI-chatbot statutes (13+ states; 7 with a private right of action at roughly $1,000/violation) — CA SB 243, Utah AI Mental Health Chatbot Act, NY, IL, et al. Four recurring themes: crisis protocols, minor protections, deception/disclosure, liability. KYE Protocol™ governs the AUTHORITY + EVIDENCE of the chatbot safeguard actions at the moment the interaction occurs — the KYE™ Chatbot Authority Pack™. It does not provide the chatbot/LLM, the clinical crisis content, or the GRC program. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Jurisdiction-aware safeguard resolution | Enforced | L3 Enforceable | us-state-chatbot-laws.jurisdiction-resolution-applicable-safeguards | Action Admissibility™ GateCross-Jurisdiction Handoff RailAuthority Finality™ |
| Mental-health / crisis protocol | Enforced | L3 Enforceable | us-state-chatbot-laws.crisis-escalation-authority | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Minor protections | Enforced | L3 Enforceable | us-state-chatbot-laws.minor-protection-authority | Action Admissibility™ GateAuthority Finality™ |
| Deception / disclosure / anthropomorphism | Enforced | L3 Enforceable | us-state-chatbot-laws.disclosure-enforcement-authority | Action Admissibility™ GateAuthority Finality™ |
| Liability / private right of action — litigation evidence | Enforced | L3 Enforceable | us-state-chatbot-laws.litigation-evidence-capture | Evidence Pack™Replay-Proof™WORM Retention |
| Clinical crisis-counselling substance (out of scope)Crisis-service responsibility — clinical crisis content. KYE™ proves the escalation was authorised & triggered, not the content. Zero KYE™ controls (complement-not-compete). | Out of scope | L1 Mapped | us-state-chatbot-laws.clinical-crisis-counselling-substance | — |
| Chatbot / model behaviour & UX (out of scope)Model vendor / operator responsibility — the LLM, its outputs, age-estimation, and UX. Zero KYE™ controls (complement-not-compete). | Out of scope | L1 Mapped | us-state-chatbot-laws.chatbot-model-behaviour-and-ux | — |
Voluntary GenAI Code
ISED (Sept 2023) · Canada
Canada's voluntary code for advanced generative AI systems (ISED, 2023). Voluntary signatory program — all rows advisory: accountability, transparency, and human oversight + monitoring outcomes anchored to the KYE Protocol™ action-governance layer. Per-requirement bijection at /compliance/voluntary-code-genai.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Accountability | Designed | L2 Designed | accountability | Authority GateRisk Engine |
| Transparency | Designed | L2 Designed | transparency | Decision Map™Reporting Engine |
| Human oversight + monitoring | Designed | L2 Designed | oversight | Drift DetectorIncident Detector |
ISO 31000
2018 · International
ISO 31000:2018 risk-management principles, framework and process. KYE Protocol™ governs the authority, evidence and finality of AI-agent actions as a risk-treatment and risk-recording control inside the ISO 31000 process — it does not run the enterprise risk-management system. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Accountability + assigned authority for AI risk | Designed | L2 Designed | iso-31000.5.4.2 | Purpose Permission™GovernedUI |
| Risk identification + treatment at the action boundary | Designed | L2 Designed | iso-31000.6.4.2, iso-31000.6.5.2 | Decision Map™Authority Gate |
| Monitoring/review + replay-derivable recording | Designed | L2 Designed | iso-31000.6.6, iso-31000.6.7 | Evidence Pack™Replay Proof™Delegated Auditability |
Three Lines Model
2020 · International
The IIA's Three Lines Model (2020). KYE Protocol™ supplies the runtime authority + evidence + assurance primitives the model assumes across first line (operational), second line (risk/compliance) and third line (internal audit) — it does not replace any line's people or mandate. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Governance accountability + governing-body oversight | Designed | L2 Designed | three-lines.principle-1, three-lines.principle-2 | Purpose Permission™GovernedUIEvidence Pack™ |
| First/second line authority + third-line assurance | Designed | L2 Designed | three-lines.principle-3, three-lines.principle-4 | Decision Map™Delegated Auditability |
| Independent verification + aligned value protection | Designed | L2 Designed | three-lines.principle-5, three-lines.principle-6 | Replay Proof™Evidence Pack™ |
MIT AI Risk Repository
2024 · International
MIT AI Risk Repository (2024) Domain Taxonomy — 7 domains. KYE Protocol™ addresses the 4 action-authority domains (privacy/security access, malicious misuse, human oversight, system-safety traceability/multi-agent) and is HONESTLY out of scope for the 3 content/societal domains (discrimination & toxicity, misinformation, socioeconomic & environmental). Coverage never inflated. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| D2 Privacy & Security — access bounded by purpose + tenant | Designed | L2 Designed | mit-risk.d2-privacy-security | Purpose Permission™Decision Map™Tenant Isolation |
| D4 Malicious Actors & Misuse — unauthorised action refused | Designed | L2 Designed | mit-risk.d4-malicious-misuse | Purpose Permission™Authority Gate |
| D5 Human-Computer Interaction — human oversight | Designed | L2 Designed | mit-risk.d5-human-computer-interaction | GovernedUI |
| D7 AI System Safety — traceability + multi-agent authority | Designed | L2 Designed | mit-risk.d7-traceability, mit-risk.d7-multi-agent | Evidence Pack™Replay Proof™Delegated Auditability |
| D1 Discrimination & Toxicity (content/fairness — out of scope)the protocol governs authority of agent ACTIONS, not content truth/fairness or macro-societal outcomes — this MIT domain is honestly out of scope; never inflated. | Out of scope | L1 Mapped | MIT domain (content/societal — outside the authority-of-action scope) | — |
| D3 Misinformation (content truth — out of scope)the protocol governs authority of agent ACTIONS, not content truth/fairness or macro-societal outcomes — this MIT domain is honestly out of scope; never inflated. | Out of scope | L1 Mapped | MIT domain (content/societal — outside the authority-of-action scope) | — |
| D6 Socioeconomic & Environmental (macro/societal — out of scope)the protocol governs authority of agent ACTIONS, not content truth/fairness or macro-societal outcomes — this MIT domain is honestly out of scope; never inflated. | Out of scope | L1 Mapped | MIT domain (content/societal — outside the authority-of-action scope) | — |
ATRS
ATRS v3.0 (2025) · United Kingdom
The UK Government Algorithmic Transparency Recording Standard — mandatory for central-government departments and arm’s-length bodies publishing algorithmic tools that affect the public. KYE Protocol™ is the evidence source the ATRS record is populated FROM: every governed public-sector AI action emits a signed Evidence Pack™ carrying the tool’s purpose, decision map and capability profile, so the published transparency record is a projection of recorded runtime evidence rather than a hand-authored claim.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Tier 1 + Tier 2 transparency recordMarquee mapping — the Evidence Pack™ populates the ATRS Tier-1 overview and Tier-2 technical record; replay-verifiable from published keys. | Enforced | L3 Enforceable | Tier 1, Tier 2 | Evidence Pack™Decision Map™Capability Profile |
| Senior responsible ownerThe ATRS named owner resolves to the recorded named-authority decision for every consequential action. | Enforced | L3 Enforceable | Owner | Authority RegisterPurpose Permission™ |
| Maintain & re-publish on change§13 drift detection flags the behaviour change that re-opens the published record; the re-publication trigger workflow is in build. | Designed | L2 Designed | Maintenance | Resilience Loop™ drift signal |
| Public effect & appeal arrangementsThe substantive public-effect judgement and appeal design are the deploying body’s own responsibility; KYE™ supplies the contestability hooks, not the policy. | Out of scope | L1 Mapped | Impact | — |
UK Gov AI Playbook
Feb 2025 · United Kingdom
The UK Government AI Playbook’s ten principles for safe, effective and secure use of AI in government. KYE Protocol™ enforces the governance principles at the action boundary: meaningful named accountability, secure provenance-backed use, and meaningful human control on consequential decisions — each emitting a signed, replay-verifiable Evidence Pack™.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Meaningful accountabilityNamed human accountability recorded before every consequential action; the AI governance board maps to §36 approval modes. | Enforced | L3 Enforceable | Principle: accountability | Authority RegisterPurpose Permission™GovernedUI approval modes |
| Keeping AI use securePinned provenance + WORM-retained replay-verifiable Evidence Pack™ per action. | Enforced | L3 Enforceable | Principle: security | Replay-Proof™Evidence Pack™WORM audit |
| Meaningful human controlStaged finality (draft→recommendation→human-reviewed→citizen-facing→final); two-person sign-off on irreversible authorising-official assertions. | Enforced | L3 Enforceable | Principle: human control | GovernedUI sign-offDecision finality states |
| Lifecycle management & monitoringDrift monitoring + AI/ML systems inventory; the mandated review-cadence workflow is in build. | Designed | L2 Designed | Principle: lifecycle | Resilience Loop™§67 model-governance catalogue |
Orange Book
2023 · United Kingdom
HM Treasury’s Orange Book is the cross-government standard for risk management. KYE Protocol™ performs the identify-assess-monitor arc at the action boundary: every governed AI action is risk-scored and admitted against a risk-scoped purpose grant before it runs, and behaviour drift is monitored continuously through the Resilience Loop™.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Identify & assess riskRisk-scored admission against a risk-scoped purpose grant before the action runs. | Enforced | L3 Enforceable | Identify, Assess | Risk scorePurpose Permission™Decision Map™ |
| Monitor & respond§13 continuous drift detection + improvement records. | Enforced | L3 Enforceable | Monitor | Resilience Loop™ drift signal |
| Report & escalate to governance bodyAuthority register + attestations support reporting; the portfolio risk-report rendering is in build. | Designed | L2 Designed | Report | Authority RegisterCompliance attestation |
Magenta Book
2020 · United Kingdom
HM Treasury’s Magenta Book is the cross-government standard for evaluation of interventions. KYE Protocol™ supplies the recorded process evidence — what the AI tool actually did, for whom, under whose authority — that a process or impact evaluation of an AI intervention rests on, drawn from runtime Evidence Packs™ rather than reconstructed from scattered logs.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Process evaluationRecorded action evidence is the process the evaluator examines. | Enforced | L3 Enforceable | Process eval | Observed ActionEvidence Pack™Decision Map™ |
| Impact evaluationPopulation-impact classification supports impact evaluation; the per-cohort export for a counterfactual study is in build. | Designed | L2 Designed | Impact eval | Consequence Mapping Engine |
| Value-for-money & evaluation conclusionThe value-for-money judgement and analytical conclusion are the department’s evaluation function’s, not KYE™’s. | Out of scope | L1 Mapped | VfM | — |
ISO 9000
ISO 9000:2015 · International
ISO 9000:2015 defines the quality-management concepts of objective evidence, validation and change control — ‘objective evidence that requirements have been fulfilled’. The KYE™ Evidence Pack™ IS that objective evidence: a signed, replay-verifiable record that the named-authority, due-diligence and sign-off requirements were fulfilled before an AI-assisted output proceeded.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Objective evidence & verificationSigned replay-verifiable objective evidence that requirements were fulfilled. | Enforced | L3 Enforceable | 3.8.3 | Evidence Pack™Replay-Proof™Decision Map™ |
| Validation (fit for intended use)Purpose-scope admission confirms the output fit for its intended public-sector use at the action boundary. | Enforced | L3 Enforceable | 3.8.13 | Purpose Permission™Decision Engine |
| Change control & re-validation§13 drift signal flags the change that ought to trigger re-validation; the re-validation gate workflow is in build. | Designed | L2 Designed | Change control | Resilience Loop™ drift signal |
UK AI Testing & Assurance (Public Sector)
2024 · United Kingdom
The UK Cross-Government Testing Community framework for testing and assuring AI systems used in the public sector, pre-deployment and in-life. KYE Protocol™ runs pre-deployment scenario tests through the Scenario Engine, monitors in-life behaviour through the Resilience Loop™, and reconstructs an assurance record for an oversight reviewer through the §21 audit-replay machinery.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Pre-deployment testingAdversarial/policy scenarios run and risk-scored before admission to a consequential action path. | Enforced | L3 Enforceable | Pre-deployment | Scenario EngineRisk score |
| In-life assuranceContinuous drift detection + audit-pilot replay for ongoing assurance. | Enforced | L3 Enforceable | In-life | Resilience Loop™Audit Pilot™ |
| Assurance evidence & replayReconstructable assurance record; the Cross-Government-Testing-Community report rendering is in build. | Designed | L2 Designed | Assurance record | Audit-replay orchestratorRegulator-replay agent |
EN 18286
EN 18286:2025 (E) · European Union
European harmonised standard for the QMS obligation on providers of high-risk AI systems (supporting EU AI Act Article 17). PARTIAL MAPPING — only Clause 5.1 (the six non-delegable top-management duties) is mapped at this edition; the rest of the standard is not yet mapped and is deliberately omitted, not inflated. KYE™ governs the AUTHORITY, OVERSIGHT, and EVIDENCE dimensions of the QMS; it does not implement the provider's HR/training, compute-procurement, or sustainability program.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Quality policy & measurable objectives from regulatory purpose (5.1.a) | Enforced | L3 Enforceable | EN 18286:2025 Clause 5.1.a + Note 2 | Purpose Permission™Authority Register≤90-day attestation |
| Resources for the QMS — data-lineage/traceability storage over the retention period (5.1.b, lineage sub-duty only)Only the lineage/traceability-retention sub-duty maps to KYE™. Compute provisioning, human-capital competence/training, and energy-efficiency sustainability are provider-owned and out of KYE™ scope (not claimed). | Designed | L2 Designed | EN 18286:2025 Clause 5.1.b | WORM audit hash-chainobject-store immutability retention policy |
| Effective role responsibilities — human oversight, intervention thresholds, override/intervenability, automation-bias mitigation (5.1.c) | Enforced | L3 Enforceable | EN 18286:2025 Clause 5.1.c | KYE™ GovernedUI™ approval modesOversight envelope / override interfaceDelegated-authority bindingMeta-governance no-self-grant gate |
| QMS integrated into the provider's processes across the AI lifecycle — not a separate binder (5.1.d) | Enforced | L3 Enforceable | EN 18286:2025 Clause 5.1.d | Self-governance evidence-event familyCohesion Cascade™ |
| QMS achieves intended results — management review, nonconformity → corrective action (5.1.e) | Enforced | L3 Enforceable | EN 18286:2025 Clause 5.1.e | Reconciliation Engine™ declared-vs-deployed bijection≤90-day attestation |
| Communication of QMS importance & promotion of a responsible-AI culture (5.1.f + Note 1)KYE™ supplies the communication/education channel; sustaining a responsible-AI culture amid staff turnover/drift is a provider-owned people obligation and is not claimed as enforced. | Designed | L2 Designed | EN 18286:2025 Clause 5.1.f | Comms Rail · KYE™ Comms Engine™Learn Rail · KYE™ Learn™ |
MAS AIRG (consultation)
consultation-2025-11 (final Guidelines not yet issued as of 2026-07-03) · Singapore
MAS's proposed sector-wide supervisory Guidelines on AI Risk Management (consultation paper published 13 November 2025; comments closed 31 January 2026): supervisory expectations on AI risk oversight, key AI risk-management systems, policies and procedures, AI life-cycle controls, and capabilities/capacity — explicitly covering Generative AI and AI agents, applied proportionately with a proposed 12-month transition after issuance. This instrument is REGISTERED in the §70 Framework Mapping Rail as a MONITORED consultation (the final Guidelines had not been issued at registration; the entry will be re-versioned on publication). It is distinct from MAS Project MindForge, the industry-co-created operationalisation handbook, which is deep-mapped separately. No requirement is bound while the text is non-final, so coverage is honestly reported as out of scope.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Registered in the §70 rail as a monitored consultation instrument; text not yet finalHonest registered state (§70 mapping_state=registered): the consultation crosswalks cleanly to existing KYE Protocol™ rails (AI oversight → §36 GovernedUI™ approval modes + Finality Gate; life-cycle controls → §13 Evidence Pack™ / Replay-Proof™; AI-agent expectations → §52 agent binding + §0.30 agents-as-principals), but the honesty bar forbids binding requirements to a non-final text — deep mapping runs through the §70 rail once MAS issues the Guidelines. Coverage is never inflated. | Out of scope | L1 Mapped | MAS AIRG consultation paper (13 Nov 2025) — proposed expectations on AI oversight, risk-management systems, life-cycle controls, and capabilities; not yet issued as final Guidelines, not yet decomposed into requirement-level mappings | — |
ISO/IEC 38507
ISO/IEC 38507:2022 · International (ISO/IEC)
ISO/IEC 38507 gives the governing body guidance on the governance implications of AI, on the Evaluate-Direct-Monitor model. KYE Protocol™ governs the AUTHORITY dimension of that accountability: every AI-agent action is bound to a named accountable Principal under a directed purpose, with substantive human oversight and replay-provable evidence. KYE™ enforces the authority/evidence/oversight slice mechanically; the board process itself sits outside its scope (honest §70 tri-state).
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Accountability & the governing body (non-delegable, EDM) | Enforced | L3 Enforceable | iso-iec-38507.governing-body-accountability, iso-iec-38507.accountability-for-outcomes, iso-iec-38507.governance-vs-management | §0.30 accountable Principaldelegation chainAuthority vs execution seamEvidence Pack™ |
| Direct — purpose alignment & acceptable-use policy | Enforced | L3 Enforceable | iso-iec-38507.purpose-alignment, iso-iec-38507.acceptable-use-policy | Purpose Permission™Rules Gateway™Decision Map™ |
| Evaluate — AI-specific considerations (autonomy, risk, data) | Designed | L3 Enforceable | iso-iec-38507.ai-characteristics-consequences, iso-iec-38507.risk-oversight, iso-iec-38507.data-governance-for-ai | bounded agent authorityrisk signals§31 data-use authority |
| Monitor — human oversight & continuous assurance | Enforced | L3 Enforceable | iso-iec-38507.material-decision-oversight, iso-iec-38507.continuous-monitoring | GovernedUI™ approval modesper-action re-check§34 reconciliation |
| Transparency, explainability & compliance obligations | Enforced | L3 Enforceable | iso-iec-38507.transparency-explainability, iso-iec-38507.compliance-obligations | Decision Map™ reason codesReplay-Proof™≤90-day attestation§70 mapping |
MOW SOC
socw/2 (2026) — immutable MOW-stewarded contract URL, robots.txt Terms Document Locator (tdl:) declaration · United Kingdom
Machine-readable standard contract (Movement for an Open Web / Preiskel & Co LLP, July 2026) licensing website access for Search Indexing only and pricing every other Access Event at the contract's default per-Product Access Fee. KYE Protocol™ maps it as publisher-side content-access authority: classify each automated access against the licence at the moment of access, seal Access Events as verifiable evidence, and derive the invoice-ready unlicensed-access schedule. The contract stays MOW's — KYE™ never re-hosts or interprets it: the SOC sets the terms; KYE™ proves the breach.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Machine-readable terms declaration | Designed | L2 Designed | mow-search-only-contract.terms-document-locator | Purpose Permission™Decision replayEvidence Pack™Replay-Proof™ |
| Purpose-limited licensed access | Designed | L2 Designed | mow-search-only-contract.purpose-limited-index-access | Purpose Permission™Decision replayEvidence Pack™Replay-Proof™ |
| Access-event evidence & records | Designed | L2 Designed | mow-search-only-contract.access-event-evidence | Purpose Permission™Decision replayEvidence Pack™Replay-Proof™ |
| Access-fee accrual & waiver conditions | Designed | L2 Designed | mow-search-only-contract.access-fee-accrual | Purpose Permission™Decision replayEvidence Pack™Replay-Proof™ |
| AI-scraping & dataset prohibition | Designed | L2 Designed | mow-search-only-contract.ai-scraping-prohibition | Purpose Permission™Decision replayEvidence Pack™Replay-Proof™ |
| Database-rights & bulk-extraction restriction | Designed | L2 Designed | mow-search-only-contract.database-rights | Purpose Permission™Decision replayEvidence Pack™Replay-Proof™ |
| Contract formation & court enforcement | Out of scope | L1 Mapped | mow-search-only-contract.legal-formation-and-enforcement | — |
| Accessibility & reader carve-out | Designed | L2 Designed | mow-search-only-contract.accessibility-carveout | Purpose Permission™Decision replayEvidence Pack™Replay-Proof™ |
EW-AiRM
EW-AiRM (Human-AI Institute / Markus Krebsz) · International
EW-AiRM is an enterprise-wide AI risk-management framework (Human-AI Institute / Markus Krebsz) that quantifies board risk appetite, assesses AI-necessity and organisational readiness, classifies risk against the MIT AI Risk Repository, sets non-negotiables (named accountability, tested human override, F-Critical no-averaging, named incident route) and an 8-Black-Swan resilience discipline, and produces a HAiPECR pre-deployment record. KYE Protocol™ maps the honest boundary — enterprise AI-risk governance is NOT per-action authority: system approval ≠ action authority. KYE™ enforces the runtime half (every consequential action admissibility-checked under a named authority, fail-closed, evidenced, replay-provable) and CONSUMES EW-AiRM's residual-risk acceptance and the HAiPECR verdict as an action policy, returning per-action authorised / denied / scope-inflation / expired-authority / revocation evidence. The quantification, readiness/necessity assessment, MIT-taxonomy classification, and Black-Swan scenario planning stay EW-AiRM's own work. From Board Risk Appetite to Runtime Proof. Per-requirement bijection at /compliance/ewairm.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| System approval vs per-action authority (the boundary) | Enforced | L3 Enforceable | ewairm.system-approval-not-action-authority | Authority GatePurpose Permission™Decision replayReplay-Proof™ |
| Non-negotiable — named accountability | Enforced | L3 Enforceable | ewairm.non-negotiable-named-accountability | Named principalAuthority GateEvidence Pack™ |
| Non-negotiable — no score-averaging over a critical failure | Enforced | L3 Enforceable | ewairm.f-critical-no-averaging-override | Fail-closed admissibilityDecision replayReplay-Proof™ |
| Non-negotiable — tested human override | Designed | L2 Designed | ewairm.non-negotiable-tested-human-override | GovernedUI™ HITLKill-switch |
| Residual-risk acceptance → runtime condition | Designed | L2 Designed | ewairm.residual-risk-acceptance-as-authority-condition | Purpose Permission™Scope condition |
| HAiPECR record consumption | Designed | L2 Designed | ewairm.documented-haipecr-consumption | Decision replayAction policy |
| Non-negotiable — named incident route | Designed | L2 Designed | ewairm.non-negotiable-named-incident-route | Contestability routeEvidence Pack™ |
| Black-Swan resilience — runtime evidence | Designed | L2 Designed | ewairm.black-swan-runtime-resilience-evidence | Resilience Loop™No-SPOFReplay-Proof™ |
| Board risk-appetite quantificationQuantifying board-level AI risk appetite is EW-AiRM's enterprise-risk work; KYE™ consumes an already-decided residual-risk acceptance as a runtime condition but does not quantify appetite. | Out of scope | L1 Mapped | ewairm.board-risk-appetite-quantification | — |
| Organisational-readiness assessmentPeople / process / culture / governance-maturity readiness assessment is an organisational-diagnostic activity KYE™ does not perform or replace. | Out of scope | L1 Mapped | ewairm.organisational-readiness-assessment | — |
| AI-necessity assessmentWhether AI should be used at all (necessity / proportionality) is a judgement KYE™ does not adjudicate; KYE™ governs the authority of AI actions once AI is deployed. | Out of scope | L1 Mapped | ewairm.ai-necessity-assessment | — |
| MIT AI Risk Repository taxonomyClassifying risks against the MIT AI Risk Repository is an analytic activity owned by the enterprise; KYE™ enforces authority at the action boundary regardless of how a risk is taxonomised. | Out of scope | L1 Mapped | ewairm.mit-risk-taxonomy-classification | — |
HAiPECR
HAiPECR (Human-AI Institute / Markus Krebsz, OECD-listed Apr 2023) · International
HAiPECR (Human-AI Institute / Markus Krebsz; OECD Catalogue of Tools & Metrics for Trustworthy AI, April 2023) is a pre-deployment evidence-and-certification record across seven dimensions — human oversight, accountability, transparency & explainability, privacy & data, ethics & fairness, compliance & legal, resilience & security — culminating in a deploy / do-not-deploy verdict. KYE Protocol™ CONSUMES the HAiPECR credential/verdict as an action policy and enforces the runtime half: dimensions that resolve to a real KYE™ runtime artefact are enforced/designed, and a do-not-deploy verdict makes consequential actions inadmissible at the §12 boundary — returning per-action authorised / denied / scope-inflation / expired-authority / revocation evidence. Ethics & fairness SCORING and the authoring of the HAiPECR record itself stay the human-expert's work (KYE™ proves authority, not model fairness). From Board Risk Appetite to Runtime Proof. Per-requirement bijection at /compliance/haipecr.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Dimension — accountability | Enforced | L3 Enforceable | haipecr.accountability | Named principalAuthority GateEvidence Pack™ |
| Dimension — human oversight | Designed | L2 Designed | haipecr.human-oversight | GovernedUI™ HITLKill-switch |
| Dimension — transparency & explainability | Designed | L2 Designed | haipecr.transparency-explainability | Decision Map™Evidence Pack™ |
| Dimension — privacy & data | Designed | L2 Designed | haipecr.privacy-data | Data-use admissibilityMemory Authority Rail™ |
| Dimension — compliance & legal | Designed | L2 Designed | haipecr.compliance-legal | Framework Mapping Rail™Decision replay |
| Dimension — resilience & security | Designed | L2 Designed | haipecr.resilience-security | Resilience Loop™No-SPOFReplay-Proof™ |
| Deploy-gate verdict consumption | Designed | L2 Designed | haipecr.deploy-gate-verdict-consumption | Action policyPurpose Permission™Decision replay |
| Dimension — ethics & fairnessScoring the ethical acceptability and fairness of model behaviour is a model-evaluation activity owned by the builder and the enterprise's ethics function; KYE™ proves an action was authorised, evidenced, and replayable, not that the model is fair. | Out of scope | L1 Mapped | haipecr.ethics-fairness | — |
Personal-data regulation covering lawful basis, data-subject rights, and processing accountability.
Alberta PIPA
S.A. 2003, c. P-6.5 · Canada
Alberta's private-sector privacy law (PIPA), substantially similar to PIPEDA and the first Canadian private-sector law with mandatory breach notification: consent, protection of personal information, and breach notification. Per-requirement bijection at /compliance/alberta-pipa.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Consent (ss.7-8) | Enforced | L3 Enforceable | s7 | Purpose Permission™ |
| Protection of personal information (s.34) | Enforced | L3 Enforceable | s34 | Authority Gate |
| Breach notification (s.34.1) | Designed | L2 Designed | s34.1 | Incident DetectorReporting Engine |
DSG
2018 (GDPR implementing act) · Austria
DSG is Austria's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Austria-specific national deltas here. Per-requirement bijection at /compliance/at-dsg.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
APPI
Act No. 57 of 2003, as amended (2022) · Japan
Japan's Act on the Protection of Personal Information, supervised by the Personal Information Protection Commission (PPC) — purpose-of-use limitation, security control measures, cross-border transfer, disclosure/access rights and breach reporting. KYE Protocol™ governs the personal-data obligations that bind an AI-supported action; the organisational privacy programme stays out of scope. Per-requirement bijection at /compliance/appi.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Purpose-of-use limitation & security control measures | Enforced | L3 Enforceable | APPI Art. 17-18, APPI Art. 23 | Purpose Permission™Authority Resolution™Data Classification Engine |
| Cross-border transfer & disclosure/access rights | Enforced | L3 Enforceable | APPI Art. 28 / 31, APPI Art. 33-35 | Cross-Border Evidence agentDecision Map™Replay-Proof™Evidence Pack™ |
| Breach reporting to the PPCKYE™ assembles the PPC notification package from the leakage evidence; the regulator-side delivery channel to the PPC is designed pending the per-jurisdiction reporting connector. | Designed | L1 Mapped | APPI Art. 26 | Incident DetectorReporting Engine |
BC PIPA
S.B.C. 2003, c. 63 · Canada
British Columbia's private-sector privacy law (PIPA), substantially similar to PIPEDA: consent, reasonable security, and access/correction. Per-requirement bijection at /compliance/bc-pipa.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Consent (ss.6-8) | Enforced | L3 Enforceable | s6 | Purpose Permission™ |
| Reasonable security (s.34) | Enforced | L3 Enforceable | s34 | Authority Gate |
| Access + correction (ss.23-24) | Enforced | L3 Enforceable | s23 | Reporting EngineWORM audit hash-chain |
Belgian Data Protection Act 2018
2018 (GDPR implementing act) · Belgium
Belgian Data Protection Act 2018 is Belgium's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Belgium-specific national deltas here. Per-requirement bijection at /compliance/be-dpa-2018.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
Bulgarian Personal Data Protection Act
2018 (GDPR implementing act) · Bulgaria
Bulgarian Personal Data Protection Act is Bulgaria's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Bulgaria-specific national deltas here. Per-requirement bijection at /compliance/bg-pdpa.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
nFADP
in force 2023 · Switzerland
Switzerland's revised Federal Act on Data Protection (nFADP/revDSG) — a sovereign, GDPR-aligned statute under an EU adequacy decision. this registry maps the Swiss national deltas; AI-system governance defers to the directly-applicable obligations Switzerland references. Per-requirement bijection at /compliance/ch-nfadp.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| National statute (non-EU, adequacy) — nFADP/revDSG lawful-purpose + accountability | Enforced | L3 Enforceable | nfadp-basis | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
| Cross-border transfer / adequacy regime (non-EU) | Enforced | L3 Enforceable | adequacy-cross-border | Authority GateEvidence Pack™ |
Law 125(I)/2018
2018 (GDPR implementing act) · Cyprus
Law 125(I)/2018 is Cyprus's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Cyprus-specific national deltas here. Per-requirement bijection at /compliance/cy-law-125-2018.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
Zákon 110/2019
2018 (GDPR implementing act) · Czech Republic
Zákon 110/2019 is Czech Republic's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Czech Republic-specific national deltas here. Per-requirement bijection at /compliance/cz-zakon-110-2019.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
BDSG
2018 (GDPR implementing act) · Germany
BDSG is Germany's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Germany-specific national deltas here. Per-requirement bijection at /compliance/de-bdsg.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
| Employee-data processing (BDSG §26, works-council co-determination) | Enforced | L3 Enforceable | employee-data-bdsg-26 | Purpose Permission™Decision Map™ |
Databeskyttelsesloven
2018 (GDPR implementing act) · Denmark
Databeskyttelsesloven is Denmark's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Denmark-specific national deltas here. Per-requirement bijection at /compliance/dk-databeskyttelsesloven.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
LOPDGDD
2018 (GDPR implementing act) · Spain
LOPDGDD is Spain's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Spain-specific national deltas here. Per-requirement bijection at /compliance/es-lopdgdd.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
| LOPDGDD Título X digital rights (disconnection, digital-will, workplace) | Enforced | L3 Enforceable | digital-rights-titulo-x | DSAR AgentEvidence Pack™ |
Tietosuojalaki
2018 (GDPR implementing act) · Finland
Tietosuojalaki is Finland's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Finland-specific national deltas here. Per-requirement bijection at /compliance/fi-tietosuojalaki.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
Loi Informatique et Libertés
2018 (GDPR implementing act) · France
Loi Informatique et Libertés is France's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the France-specific national deltas here. Per-requirement bijection at /compliance/fr-lil.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
| Health-data HDS-certified hosting + CNIL reference methodologies | Enforced | L3 Enforceable | health-data-hds | Data Classification EngineAuthority Gate |
CCPA/CPRA
Cal. Civ. Code §1798.100 et seq. (2018, amended by CPRA 2020) · United States
The California Consumer Privacy Act (as amended by the CPRA) grants California consumers rights over their personal information — notice at collection, the right to know/access, delete, correct, opt out of sale/sharing, limit the use of sensitive PI, and non-discrimination for exercising those rights. This framework is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: its consumer-rights structure overlaps heavily with the already-deep-mapped GDPR and crosswalks to existing KYE Protocol™ rails (right to know/delete/correct → §31 Data Governance Pack & the DSAR evidence agent; opt-out of sale/sharing & limit-use → §12 Purpose Permission™; data-as-authority lifecycle → §63 Memory Authority Rail), but no requirement has yet been bound at the requirement level. Per the §70 honesty bar, coverage is reported out of scope pending deep mapping rather than claimed as enforced.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): candidate crosswalks to §31 / §12 / §63 and the existing GDPR deep-map are noted in the summary but NOT yet bound at the requirement level, so coverage stays out of scope until the deep mapping runs through the §70 rail — never inflated to imply enforcement that does not exist. | Out of scope | L1 Mapped | CCPA/CPRA consumer rights (notice, know/access, delete, correct, opt-out of sale/sharing, limit sensitive PI, non-discrimination — not yet decomposed into requirement-level mappings) | — |
GDPR
Regulation (EU) 2016/679 · European Union
EU regulation governing the processing of personal data.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Lawful basis & purpose limitation | Enforced | L3 Enforceable | Art. 5, Art. 6 | Purpose Permission™Authority Gate |
| Data-subject rights handling | Enforced | L3 Enforceable | Art. 12-22 | Purpose Permission™WORM audit hash-chain |
| Records of processing & accountability | Enforced | L3 Enforceable | Art. 30 | WORM audit hash-chainDecision replay |
| Integrity, confidentiality & signed evidenceAccess to personal data is governed today; signed integrity evidence and automated key rotation are in build. | Designed | L2 Designed | Art. 32 | Evidence Pack™ signing (COSE-Sign1)Automated key rotation |
| International transfers (Chapter V) — Schrems II / SCC / adequacy§72 Jurisdiction & Data-Sovereignty Authority surfaces the GDPR Chapter V cross-border requirements already deep-mapped in internal Each crossing emits a signed kye.cross_border.transfer.v1 carrying the lawful_basis (adequacy / SCC + Transfer Impact Assessment) and the residency_verdict, so the Art. 44-49 transfer-impact assessment is the evidence pack itself. | Enforced | L3 Enforceable | Art. 44, Art. 45, Art. 46, Art. 49 | Cross-Border Transfer Record (kye.cross_border.transfer.v1)Jurisdiction Attestation (kye.jurisdiction.attestation.v1)Residency Verdict (§72) |
GDPR Art. 22
Regulation (EU) 2016/679 (GDPR) — Article 22 (automated individual decision-making, including profiling) + Articles 13–15 / Recital 71 · European Union
GDPR Article 22 gives data subjects the right not to be subject to solely-automated similarly-significant decisions without safeguards — human intervention, meaningful information about the logic, and the right to contest. KYE Protocol™ governs whether an AI-assisted insurance decision in scope may proceed — under a recorded named-authority (the human-involvement safeguard), with a recorded adverse-action reason-code (meaningful information about the logic), a signed replay-provable Evidence Pack™ per decision, and an appeal / contestability record (the right to contest and to human intervention). The lawful basis / substantive decision / risk pricing on the merits stays the controller's own work (honest scope, §0). Per-requirement bijection at /compliance/gdpr-automated-decision.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Human involvement / named-authority safeguard (Art. 22(3)) | Enforced | L3 Enforceable | gdpr-automated-decision.art22-human-involvement-safeguard | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Right to contest & human intervention (Recital 71) | Enforced | L3 Enforceable | gdpr-automated-decision.art22-contest-human-intervention | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Meaningful information about the logic / adverse-action reason (Art. 13–15) | Enforced | L3 Enforceable | gdpr-automated-decision.art13-15-meaningful-information-logic | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Lawful basis, substantive decision & pricing on the meritsThe lawful basis for the processing / the substantive decision / the risk pricing on the merits is the controller's own work — KYE™ is an AI-authority and evidence layer at the action boundary, not a legal-basis, decision, or pricing engine. | Out of scope | L1 Mapped | gdpr-automated-decision.lawful-basis-substantive-decision | — |
Law 4624/2019
2018 (GDPR implementing act) · Greece
Law 4624/2019 is Greece's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Greece-specific national deltas here. Per-requirement bijection at /compliance/gr-law-4624-2019.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
Info Act
2018 (GDPR implementing act) · Hungary
Info Act is Hungary's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Hungary-specific national deltas here. Per-requirement bijection at /compliance/hu-info-act.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
Data Protection Act 2018
2018 (GDPR implementing act) · Ireland
Data Protection Act 2018 is Ireland's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Ireland-specific national deltas here. Per-requirement bijection at /compliance/ie-dpa-2018.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
| One-Stop-Shop lead supervisory authority (DPC) — cross-border accountability | Enforced | L3 Enforceable | lead-supervisory-oss | Evidence Pack™Reporting Engine |
ISO 23081
2017 · Global
ISO 23081-1:2017 records-metadata spine and AUTHORITY ANCHOR for the InSight DXP connector contract. KYE Protocol™ CONSUMES records metadata (agent, classification, event-history) as the input signal at the action boundary (enforced: classification-driven-authority, custody→authority binding, agent→principal binding); records-metadata creation / management is out-of-scope (owned by Iron Mountain InSight DXP).
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Metadata-driven authority decision (authority overlay) | Enforced | L3 Enforceable | iso-23081.classification-driven-authority, iso-23081.event-history-evidence | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Agent-metadata binding to a KYE-resolved principal (authority overlay) | Enforced | L3 Enforceable | iso-23081.agent-metadata-principal-binding | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Metadata creation & capture (records-management) | Out of scope | L1 Mapped | iso-23081.metadata-creation-capture | — |
| Metadata management & maintenance (records-management) | Out of scope | L1 Mapped | iso-23081.metadata-management-maintenance | — |
Codice Privacy
2018 (GDPR implementing act) · Italy
Codice Privacy is Italy's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Italy-specific national deltas here. Per-requirement bijection at /compliance/it-codice-privacy.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
Luxembourg Data Protection Act 2018
2018 (GDPR implementing act) · Luxembourg
Luxembourg Data Protection Act 2018 is Luxembourg's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Luxembourg-specific national deltas here. Per-requirement bijection at /compliance/lu-cnpd.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
UAVG
2018 (GDPR implementing act) · Netherlands
UAVG is Netherlands's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Netherlands-specific national deltas here. Per-requirement bijection at /compliance/nl-uavg.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
Personopplysningsloven
2018 (GDPR implementing act) · Norway
Personopplysningsloven is Norway's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Norway-specific national deltas here. Per-requirement bijection at /compliance/no-personopplysningsloven.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
NZ Privacy Act 2020
Privacy Act 2020 (NZ) · New Zealand
The NZ Information Privacy Principles + Part 6 notifiable privacy breaches. Per-requirement bijection at /compliance/nz-privacy-act-2020.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| IPP 5 security, IPP 10 use-limitation, IPP 6 access | Enforced | L3 Enforceable | IPP 5, IPP 10, IPP 6 | Authority GatePurpose Permission™DSAR Evidence agentReplay-Proof™ |
| Part 6 notifiable privacy breachDetection + package assembly enforced; delivery channel to the OPC is in build. | Enforced | L3 Enforceable | Privacy Act 2020 Part 6 | Incident DetectorReporting Engine |
PIPEDA
S.C. 2000, c. 5 · Canada
Canada's federal private-sector privacy law (PIPEDA, S.C. 2000, c. 5): the ten Schedule 1 fair-information principles plus mandatory breach-of-security-safeguards reporting (s.10.1). Per-requirement bijection at /compliance/pipeda.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Accountability + openness (Sch.1 4.1, 4.8) | Enforced | L3 Enforceable | sch1-4.1 | Authority GateReporting Engine |
| Purpose + consent (Sch.1 4.2-4.3) | Enforced | L3 Enforceable | sch1-4.3 | Decision Map™Purpose Permission™ |
| Limiting collection/use/retention (Sch.1 4.4-4.5) | Enforced | L3 Enforceable | sch1-4.5 | Authority GatePurpose Permission™ |
| Safeguards (Sch.1 4.7) | Enforced | L3 Enforceable | sch1-4.7 | Authority Gate |
| Individual access (Sch.1 4.9) | Enforced | L3 Enforceable | sch1-4.9 | Reporting EngineWORM audit hash-chain |
| Breach reporting (s.10.1) | Designed | L2 Designed | s10.1 | Incident DetectorReporting Engine |
UODO
2018 (GDPR implementing act) · Poland
UODO is Poland's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Poland-specific national deltas here. Per-requirement bijection at /compliance/pl-uodo.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
Privacy Act 1988
ADM reform (Privacy and Other Legislation Amendment Act 2024) · Australia
The Australian Privacy Principles + the 2024 automated-decision-making transparency reform (ADM provisions commence Dec 2026). Per-requirement bijection at /compliance/privacy-act-1988.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Automated decision-making transparency | Enforced | L3 Enforceable | Privacy Act 2024 reform — ADM | Decision Map™Evidence Pack™Replay-Proof™ |
| APP 1 open management + APP 11 security of personal information | Enforced | L3 Enforceable | APP 1, APP 11 | Authority GatePurpose Permission™Reporting Engine |
Lei 58/2019
2018 (GDPR implementing act) · Portugal
Lei 58/2019 is Portugal's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Portugal-specific national deltas here. Per-requirement bijection at /compliance/pt-lei-58-2019.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
Quebec Law 25
S.Q. 2021, c. 25 · Canada
Quebec's modernised private-sector privacy regime (Law 25, fully in force Sept 2024): privacy-impact assessment, automated-decision transparency, confidentiality-incident reporting to the CAI, data portability, and express consent for sensitive information. Per-requirement bijection at /compliance/quebec-law-25.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Privacy impact assessment (s.3.3) | Enforced | L3 Enforceable | s3.3 | Decision Map™Risk Engine |
| Automated-decision transparency (s.12.1) | Enforced | L3 Enforceable | s12.1 | Decision Map™Replay-Proof™ |
| Confidentiality-incident reporting (s.3.5-3.8) | Designed | L2 Designed | s3.5 | Incident DetectorReporting Engine |
| Data portability (s.27) | Designed | L2 Designed | s27 | Reporting EngineWORM audit hash-chain |
| Consent for sensitive information (s.12) | Enforced | L3 Enforceable | s12 | Authority GatePurpose Permission™ |
Law 190/2018
2018 (GDPR implementing act) · Romania
Law 190/2018 is Romania's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Romania-specific national deltas here. Per-requirement bijection at /compliance/ro-law-190-2018.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
Swedish Data Protection Act
2018 (GDPR implementing act) · Sweden
Swedish Data Protection Act is Sweden's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Sweden-specific national deltas here. Per-requirement bijection at /compliance/se-dpa.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
Act 18/2018
2018 (GDPR implementing act) · Slovakia
Act 18/2018 is Slovakia's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Slovakia-specific national deltas here. Per-requirement bijection at /compliance/sk-act-18-2018.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
China PIPL
PIPL (effective 2021-11-01) · China
PIPL governs the processing and cross-border provision of personal information of individuals in the PRC. Chapter III sets the lawful routes for cross-border provision (CAC security assessment, CAC standard contract, or personal-information-protection certification) plus a data-localisation duty for critical-information-infrastructure operators and large processors. This framework is REGISTERED in the §70 Framework Mapping Rail and surfaced by §72 (Jurisdiction & Data-Sovereignty Authority) at the cross-border admissibility boundary; deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no PIPL requirement is bound to a KYE Protocol™ artefact yet. The §72 cross-border admissibility binding (kye.cross_border.transfer.v1.residency_verdict) is platform-level and applies across regimes; PIPL-specific deep mapping (CAC routes, localisation duties) is scheduled through the §70 rail. Coverage is never inflated. | Out of scope | L1 Mapped | PIPL Chapter III — cross-border provision of personal information (Arts. 38-43); full text not yet decomposed into requirement-level mappings | — |
UK IDTA / Data Bridge
IDTA + International Data Transfer Addendum (in force 2022-03-21) · United Kingdom
The UK regime for restricted international transfers under UK GDPR / DPA 2018 ss.17A-19: the ICO International Data Transfer Agreement (IDTA), the UK Addendum to the EU SCCs, and UK adequacy regulations ('data bridges'). This framework is REGISTERED in the §70 Framework Mapping Rail and surfaced by §72 (Jurisdiction & Data-Sovereignty Authority) at the cross-border admissibility boundary; deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no UK-transfer requirement is bound to a KYE Protocol™ artefact yet. The §72 cross-border admissibility binding (kye.cross_border.transfer.v1.residency_verdict) is platform-level; UK-IDTA-specific deep mapping (IDTA clauses, data-bridge adequacy) is scheduled through the §70 rail. Coverage is never inflated. | Out of scope | L1 Mapped | UK GDPR Chapter V + DPA 2018 ss.17A-19; ICO IDTA / Addendum / data-bridge adequacy regulations — full text not yet decomposed into requirement-level mappings | — |
Singapore PDPA
PDPA 2012 (No. 26 of 2012), as amended 2020 · Singapore
Singapore's baseline data-protection statute, administered by the Personal Data Protection Commission (PDPC): consent, notification and purpose-limitation obligations, deemed consent by notification, the legitimate-interests exception, mandatory data-breach notification, data portability, and the Do Not Call registry (as amended by the Personal Data Protection (Amendment) Act 2020). This framework is REGISTERED in the §70 Framework Mapping Rail — distinct from Bulgaria's PDPA, which is registered separately — and connects to the §63 Memory Authority Rail, whose four memory-lifecycle schema deltas were validated against Singapore-PDPC guidance. Deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no PDPA requirement is bound to a KYE Protocol™ artefact yet. The §63 Memory Authority Rail's Singapore-PDPC-validated schema deltas (ai_specific_notice, withdrawal_route, use_type, use_admissibility_ref) are platform-level and cross-regime; PDPA-specific deep mapping is scheduled through the §70 rail. Coverage is never inflated. | Out of scope | L1 Mapped | PDPA 2012 Parts III-VIA — consent, purpose limitation, notification, access/correction, data-breach notification, data portability; full text not yet decomposed into requirement-level mappings | — |
DPDP Act 2023
Act No. 22 of 2023 · India
KYE™ governs the AUTHORITY + EVIDENCE layer of personal-data processing at the action boundary: whether a consequential action against personal data was authorised under a declared purpose (§12), and whether that decision is sealed and replayable (§13/§30). KYE™ is OUT-OF-SCOPE for the substantive data-governance obligations a Data Fiduciary owes directly — obtaining valid consent from Data Principals, publishing notices, appointing a Data Protection Officer, conducting Data Protection Impact Assessments, and answering the Board. Those are the customer's own systems, processes and counsel; KYE™ evidences the action, it does not discharge the duty (§70 §4). Deep per-requirement mapping: 8 requirements, 3 enforced by KYE™ runtime, 5 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Authority + evidence at the action boundary — enforced by KYE™ runtime and verified by CI | Enforced | L3 Enforceable | dpdp-act-2023.PURPOSE-LIMITATION — Personal data processed only for the purpose for which consent was given, dpdp-act-2023.ACTION-EVIDENCE — Every consequential action on personal data is evidenced and replayable, dpdp-act-2023.ERASURE-ROUTE — Data Principal right to erasure is routed and evidenced | kye.compliance.attestation.v1kye.evidence.decision_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context_seal.v1internalinternalinternal |
| Obligations owed directly by the regulated entity — NOT discharged by KYE™KYE™ governs the AUTHORITY + EVIDENCE layer of personal-data processing at the action boundary: whether a consequential action against personal data was authorised under a declared purpose (§12), and whether that decision is sealed and replayable (§13/§30). KYE™ is OUT-OF-SCOPE for the substantive data-governance obligations a Data Fiduciary owes directly — obtaining valid consent from Data Principals, publishing notices, appointing a Data Protection Officer, conducting Data Protection Impact Assessments, and answering the Board. Those are the customer's own systems, processes and counsel; KYE™ evidences the action, it does not discharge the duty (§70 §4). | Out of scope | L1 Mapped | dpdp-act-2023.NOTICE-CONSENT — Itemised notice and valid consent obtained from the Data Principal, dpdp-act-2023.BREACH-INTIMATION — Personal-data breach intimated to the Board and affected Data Principals, dpdp-act-2023.SDF-OBLIGATIONS — Significant Data Fiduciary duties — DPO, independent audit, DPIA, dpdp-act-2023.CHILDREN-DATA — Verifiable parental consent and no tracking or targeted advertising directed at children, dpdp-act-2023.CROSS-BORDER — Transfer of personal data outside India subject to Government restriction | — |
Payments and operational-resilience regulation specific to banks, payment institutions, and the EU financial sector.
ECOA / Reg B
ECOA (15 U.S.C. §1691 et seq.) / Regulation B (12 C.F.R. Part 1002) · United States
ECOA prohibits discrimination in any aspect of a credit transaction and Regulation B operationalises it, including §1002.9 adverse-action notices with a specific statement of reasons. KYE Protocol™ governs whether an AI lending agent's consequential credit decision may proceed — only under a named-authority decision purpose-scoped to the credit transaction, with every adverse action carrying a Decision Map™ (the specific reasons, explainable) bound to a §61 contestability route and sealed into a signed replay-provable Evidence Pack™. The disparate-impact statistics, the credit-scoring feature choice, and the model's fairness validation stay the lender's own quantitative fair-lending work (honest scope, §0). Per-requirement bijection at /compliance/ecoa-reg-b.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Credit-decision authority at the action boundary | Enforced | L3 Enforceable | ecoa-reg-b.credit-decision-named-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Adverse-action notice with specific reasons | Enforced | L3 Enforceable | ecoa-reg-b.adverse-action-decision-map | Decision Map™Evidence Pack™Contestability routeReplay-Proof™ |
| Prohibited-basis non-discrimination evidence | Designed | L2 Designed | ecoa-reg-b.prohibited-basis-non-discrimination-evidence | Decision Map™Audit WORM |
| Fair-lending statistical analysis & model fairnessThe disparate-impact regression, less-discriminatory-alternative search, and model-fairness validation are the lender's own quantitative fair-lending work — KYE™ is an AI-authority and evidence layer, not a fair-lending analytics engine. | Out of scope | L1 Mapped | ecoa-reg-b.fair-lending-statistical-analysis | — |
FCRA
Fair Credit Reporting Act (15 U.S.C. §1681 et seq.) / Regulation V (12 C.F.R. Part 1022) · United States
FCRA §1681m requires a user of a consumer report who takes adverse action based on it to give an adverse-action notice naming the reporting agency and the consumer's rights. KYE Protocol™ governs whether an AI lending agent may act on a consumer report — only under a named-authority decision with a permissible purpose, with every report-driven adverse action carrying a Decision Map™ (the report's contribution + the named reporting agency) bound to a §61 contestability route and sealed into a signed replay-provable Evidence Pack™. The report generation, the scoring of report data, and the accuracy of report contents stay the consumer-reporting agency's and furnisher's work (honest scope, §0). Per-requirement bijection at /compliance/fcra.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Credit-report use authority at the decision boundary | Enforced | L3 Enforceable | fcra.credit-report-use-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Adverse-action-on-report notice (specific reasons + agency identity) | Enforced | L3 Enforceable | fcra.adverse-action-on-report-notice | Decision Map™Evidence Pack™Contestability route |
| Consumer-report data accuracy & furnisher disputesReport-content accuracy, the furnisher's §1681s-2 duties, and reinvestigation of disputes are the reporting agency's and furnisher's obligations — KYE™ governs the lending agent's decision, not the report. | Out of scope | L1 Mapped | fcra.report-accuracy-and-furnisher-disputes | — |
| Employment / tenant consumer-report use authority | Enforced | L3 Enforceable | fcra.employment-report-permissible-purpose-and-disclosure | Authority GatePurpose Permission™Evidence Pack™ |
| Employment pre-adverse-action two-step notice | Designed | L2 Designed | fcra.pre-adverse-action-notice | Decision Map™Contestability route |
| Consumer-report data disposalDisposal of the consumer-report copy and underlying data is the user's own data-handling duty over data KYE™ does not hold — KYE™ governs the agent's authority-to-act, not the report data. | Out of scope | L1 Mapped | fcra.disposal-of-consumer-report-data | — |
ICRAA
California Investigative Consumer Reporting Agencies Act (ICRAA), Cal. Civ. Code §1786 et seq. · United States
ICRAA is the California-jurisdiction overlay on the federal FCRA for INVESTIGATIVE consumer reports (character / reputation / mode-of-living information gathered through interviews — the bulk of California employment and tenant background screening). It is stricter than FCRA: §1786.16 requires clear-and-conspicuous written notice AND the consumer's written authorization plus a nature-and-scope disclosure before an investigative consumer report is procured; §1786.40 requires an adverse-action notice naming the agency. KYE Protocol™ governs whether an AI agent may PROCEED to procure or act on an investigative consumer report — only under a named-authority decision with a permissible purpose, a recorded written-consent authority, and every adverse action carrying a Decision Map™ + the named agency bound to a §61 contestability route and sealed into a signed replay-provable Evidence Pack™. KYE™ is NOT a consumer reporting agency: it does not generate the report, conduct the interviews, judge the accuracy of the report contents, or run the reinvestigation (honest scope, §0/§70). Per-requirement bijection at /compliance/icraa.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Investigative-report use authority at the procurement/decision boundary | Enforced | L3 Enforceable | icraa.investigative-report-use-authority | Authority GatePurpose Permission™Evidence Pack™ |
| California written notice + written authorization + nature-and-scope disclosure | Enforced | L3 Enforceable | icraa.written-consent-and-nature-scope-disclosure | Authority GateDecision Map™Evidence Pack™ |
| Adverse-action-on-investigative-report notice (reasons + agency identity) | Enforced | L3 Enforceable | icraa.adverse-action-notice | Decision Map™Evidence Pack™Contestability route |
| Consumer copy + dispute / reinvestigation route | Designed | L2 Designed | icraa.consumer-copy-and-dispute-route | Contestability routeDelegated Auditability |
| Investigative-report content accuracy & agency reinvestigation dutiesReport-content accuracy, the reasonable-procedures duty (§1786.20), and the agency's reinvestigation (§1786.24) are the investigative consumer reporting agency's obligations — KYE™ governs the user's decision, not the report, and is not a CRA. | Out of scope | L1 Mapped | icraa.report-accuracy-and-agency-reinvestigation | — |
FCA CONC
FCA Handbook CONC — Consumer Credit Sourcebook · United Kingdom
FCA CONC governs UK consumer-credit conduct, including CONC 5 responsible lending (creditworthiness & affordability) and CONC 7 arrears, default & forbearance. KYE Protocol™ governs whether an AI lending agent's creditworthiness-driven or arrears action may proceed — only under a named-authority decision purpose-scoped to the credit agreement, with the action carrying a Decision Map™ recording that the creditworthiness assessment was relied on, bound to a §61 forbearance/contestability route, and sealed into a signed replay-provable Evidence Pack™. The affordability calculation and credit-policy adequacy stay the lender's own responsible-lending work (honest scope, §0). Per-requirement bijection at /compliance/fca-conc.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Creditworthiness/arrears action authority at the boundary | Enforced | L3 Enforceable | fca-conc.lending-action-named-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Creditworthiness-reliance & forbearance evidence | Designed | L2 Designed | fca-conc.creditworthiness-reliance-evidence | Decision Map™Evidence Pack™Contestability route |
| Affordability calculation & credit-policy adequacyThe affordability calculation, income/expenditure modelling, and credit-policy adequacy under CONC 5 are the lender's own responsible-lending work — KYE™ governs the agent's action, not the calculation. | Out of scope | L1 Mapped | fca-conc.affordability-calculation-and-policy | — |
AICPA SSTS
2024 · United States
AICPA Statements on Standards for Tax Services (2024) — the enforceable standards for tax-return positions (reasonable basis / disclosure), reasonable inquiry & reliance on data, and the form & content of advice. KYE Protocol™ governs whether an AI-generated tax position / advice may proceed under a named member's authority, with the SSTS standards recorded before the action — the KYE™ Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Tax-return positions (SSTS No. 1) | Designed | L2 Designed | aicpa-ssts.ssts1-reasonable-basis, aicpa-ssts.ssts1-disclosure | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Data & reasonable inquiry (SSTS No. 3) | Designed | L2 Designed | aicpa-ssts.ssts3-reasonable-inquiry | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| Form & content of advice (SSTS No. 7) | Designed | L2 Designed | aicpa-ssts.ssts7-form-of-advice | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
AIFMD / UCITS
Directive 2011/61/EU & Directive 2009/65/EC · European Union
AIFMD (Directive 2011/61/EU) and the UCITS Directive (Directive 2009/65/EC) govern EU collective-investment fund management — fund-manager authorisation & conduct, the risk-management function & limits, investment limits & diversification, and recordkeeping / depositary oversight. KYE Protocol™ governs whether an AI-assisted investment decision/action is within the fund's mandate and limits, authorised, evidenced, and final at the action boundary — the KYE™ Investment Decision Authority Pack™. KYE Protocol™ does not run the risk-management function, judge whether a decision is correct, produce investment intelligence, or act as a fund manager. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Fund manager authorisation & conduct | Enforced | L3 Enforceable | aifmd-ucits.fund-manager-authorisation-conduct | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Risk-management function & limits | Enforced | L3 Enforceable | aifmd-ucits.risk-management-function-limits | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Investment limits & diversification | Enforced | L3 Enforceable | aifmd-ucits.investment-limits-diversification | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Recordkeeping & depositary oversight | Enforced | L3 Enforceable | aifmd-ucits.recordkeeping-depositary-oversight | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
APRA CPS 230
Effective 1 July 2025 · Australia
APRA Prudential Standard CPS 230 — operational risk management, business continuity and service-provider management for APRA-regulated entities. Per-requirement bijection at /compliance/apra-cps-230.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Operational risk management (paras 13-21) | Enforced | L3 Enforceable | CPS 230 §13, CPS 230 §15, CPS 230 §18 | Risk EngineDecision EngineAuthority GatePurpose Permission™Resilience Loop™ |
| Incident notification to APRA (para 20)Detection + package assembly enforced; the regulator-side delivery channel to APRA is in build. | Enforced | L3 Enforceable | CPS 230 §20 | Incident DetectorReporting Engine |
| Business continuity + service-provider management (paras 30-48) | Enforced | L3 Enforceable | CPS 230 §35, CPS 230 §42 | Authority RegisterSPoF registryEdge Governance Safety FloorOffline Evidence Log |
FSA AI Guidelines
FSA AI Discussion Paper (June 2024) + Supervision Guidelines · Japan
The Japan Financial Services Agency's AI governance and model-risk expectations for financial institutions — AI governance & accountability, model risk management, human oversight, explainability and operational resilience. KYE Protocol™ evidences the expectations that bind an AI-supported financial action at runtime. Per-requirement bijection at /compliance/fsa-guidelines-ai.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| AI governance, accountability & model risk management | Enforced | L3 Enforceable | FSA AI governance expectation, FSA model-risk expectation | Purpose Permission™Risk EngineConformance RunnerDrift Detector |
| Human oversight & explainability/customer disclosure | Enforced | L3 Enforceable | FSA human-oversight expectation, FSA explainability expectation | GovernedUI™Authority Resolution™Decision Map™Evidence Pack™ |
| Operational resilience & incident reporting to the FSAKYE™ assembles the FSA notification package; the regulator-side delivery channel to the FSA is designed pending the per-jurisdiction reporting connector. | Designed | L1 Mapped | FSA operational-resilience expectation | Incident DetectorReporting Engine |
Consumer-Driven Banking
Consumer-Driven Banking Act (2024) · Canada
Canada's consumer-driven banking (open banking) framework under the Consumer-Driven Banking Act, 2024 (stood up by the FCAC): accreditation of participants, consumer consent + data-sharing control, a common technical/security standard, and oversight + accountability. Per-requirement bijection at /compliance/canada-cdb.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Accreditation of participants | Enforced | L3 Enforceable | accreditation | Authority GateRisk Engine |
| Consumer consent + data-sharing control | Enforced | L3 Enforceable | consent | Authority GatePurpose Permission™ |
| Common technical + security standard | Enforced | L3 Enforceable | technical-standard | Authority Gate |
| Oversight + accountability | Enforced | L3 Enforceable | oversight | Authority GateReporting Engine |
Companies Act 2006
2006 · United Kingdom
The UK Companies Act 2006 — adequate accounting records (s.386), true and fair view (s.393), director responsibility & board approval (s.414), and filing of the statutory accounts with the Registrar of Companies / Companies House (s.441/s.442). KYE Protocol™ governs whether an AI-generated financial entry / statement / filing may proceed to a consequential action under a named accountant's / director's authority, with §36 two-person sign-off on the irreversible Companies House submission — the KYE™ Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Adequate accounting records (s.386) | Designed | L2 Designed | companies-act-2006.s386-adequate-records | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| True & fair view (s.393) | Designed | L2 Designed | companies-act-2006.s393-true-and-fair | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Director responsibility & approval (s.414) | Designed | L2 Designed | companies-act-2006.s414-director-responsibility | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Filing with the Registrar / Companies House (s.441/s.442) | Designed | L2 Designed | companies-act-2006.s441-filing-with-registrar, companies-act-2006.s442-filing-deadlines | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
DORA
Regulation (EU) 2022/2554 · European Union
EU regulation for the digital operational resilience of the financial sector.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| ICT risk-management framework | Enforced | L3 Enforceable | Art. 5-16 | Purpose Permission™Authority GateWORM audit hash-chain |
| ICT incident detection & reconstruction | Enforced | L3 Enforceable | Art. 17-23 | WORM audit hash-chainDecision replay |
| ICT third-party register & concentration analysis | Enforced | L3 Enforceable | Art. 28(3) | Directory tenant proxyWORM audit hash-chain |
| Tamper-evident resilience evidenceResilience-testing outcomes are recorded today; signed resilience evidence packs are in build. | Enforced | L3 Enforceable | Art. 24-27 | Evidence Pack™ signing (COSE-Sign1) |
| ICT third-party contractual arrangementsExit strategies, audit rights, and termination clauses require contract-management tooling outside KYE™. | Out of scope | L1 Mapped | Art. 15, Art. 28-30 | — |
DORA Incident
DORA — Regulation (EU) 2022/2554, Article 19 + classification RTS · European Union
DORA ICT Incident Reporting (Regulation (EU) 2022/2554, Article 19) is the EU financial-sector ICT-incident reporting regime. KYE Protocol™ governs whether an AI-assisted containment action, incident classification, or staged-report timing decision under it may proceed to a consequential incident action — under a named accountable officer's authority, with incident-evidence chain-of-custody recorded, no AI-asserted classification relied on without a pinned signal source, a signed replay-provable Evidence Pack™ per decision, and a contestability record so any decision can be reconstructed and challenged. Threat detection / SIEM-EDR runtime / forensics / remediation stays the entity's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/dora-ict-incident.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Named-authority on the containment / response action | Enforced | L3 Enforceable | dora-ict-incident.containment-action-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Incident-evidence chain-of-custody & report integrity | Enforced | L3 Enforceable | dora-ict-incident.incident-evidence-integrity | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Disclosure-timing authority on the staged reporting clock | Enforced | L3 Enforceable | dora-ict-incident.staged-report-timing-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Threat detection, forensics & remediation engineeringThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. | Out of scope | L1 Mapped | dora-ict-incident.threat-detection-forensics-remediation | — |
EU 6AMLD
Directive (EU) 2018/1673 · European Union
The EU Sixth Anti-Money Laundering Directive (Directive (EU) 2018/1673) harmonises money-laundering offences, the 22 predicate offences, aiding/abetting/inciting, and corporate liability across the EU. KYE Protocol™ governs whether an AI agent's AML action may proceed at the action boundary under a named compliance officer's authority, with due diligence before the action and replay-provable provenance. KYE Protocol™ does not run transaction-monitoring models, does not decide whether conduct is criminal money-laundering, and does not replace the institution's AML program or legal advice.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Predicate offences & scope (Art. 2/3) | Designed | L2 Designed | eu-6amld.predicate-offences-scope | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Aiding, abetting & inciting (Art. 4) | Designed | L2 Designed | eu-6amld.aiding-abetting-inciting | Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
| Corporate / legal-person liability (Art. 7/8) | Designed | L2 Designed | eu-6amld.corporate-liability | Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
| Sanctions & competent-authority cooperation (Art. 9-10) | Designed | L2 Designed | eu-6amld.competent-authority-cooperation | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
EU DAC
dac6-dac7 · European Union
EU Directive on Administrative Cooperation — DAC6 mandatory disclosure of reportable cross-border arrangements (hallmarks A–E, main-benefit test, 30-day window) and DAC7 platform-operator reporting. KYE Protocol™ governs whether an AI-generated arrangement / advice that may be reportable proceeds only after the hallmark / disclosure screen is recorded — the KYE™ Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| DAC6 hallmark screening | Designed | L2 Designed | eu-dac.dac6-reportable-arrangement, eu-dac.dac6-main-benefit-test | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| DAC6 disclosure & reporting window | Designed | L2 Designed | eu-dac.dac6-disclosure-window | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| DAC7 platform reporting | Designed | L2 Designed | eu-dac.dac7-platform-reporting | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
FATF 40 Recommendations
2012 (as amended) · International
The FATF 40 Recommendations are the global AML/CFT authority anchor — risk-based approach (R.1), customer due diligence & beneficial ownership (R.10), record-keeping (R.11), the Travel Rule (R.16), and suspicious-transaction reporting (R.20). KYE Protocol™ governs whether an AI agent's AML action may proceed at the action boundary (alert triage, sanctions screening, SAR/STR drafting, KYC/CDD) under a named compliance officer's authority, with §36 two-person sign-off on the consequential SAR/STR filing — the KYE™ AML & Financial-Crimes Governance Pack™. KYE™ Prot™ocol™ does not run transaction-monitoring models, does not decide whether a transaction is truly money-laundering, and does not replace the institution's AML program.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Risk-based approach (R.1) | Enforced | L3 Enforceable | fatf-40-recommendations.r1-risk-based-approach | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Customer due diligence & beneficial ownership (R.10) | Enforced | L3 Enforceable | fatf-40-recommendations.r10-customer-due-diligence | Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
| Record-keeping (R.11) | Enforced | L3 Enforceable | fatf-40-recommendations.r11-record-keeping | Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
| Travel Rule — wire / virtual-asset transfers (R.16) | Enforced | L3 Enforceable | fatf-40-recommendations.r16-travel-rule | Action Admissibility™ GateEvidence Pack™ |
| Suspicious transaction reporting (R.20) | Enforced | L3 Enforceable | fatf-40-recommendations.r20-suspicious-transaction-reporting | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
FCA COBS
FCA Handbook COBS · United Kingdom
The FCA Conduct of Business Sourcebook (COBS) governs UK investment business with clients — the client's best interests rule (COBS 2.1.1R), suitability (COBS 9), best execution (COBS 11), and recordkeeping. KYE Protocol™ governs whether an AI-assisted investment decision/action is within mandate, authorised, evidenced, and final at the action boundary — the KYE™ Investment Decision Authority Pack™. KYE Protocol™ does not perform the suitability assessment, judge whether a recommendation is correct, produce investment intelligence, or act as an investment adviser. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Client's best interests rule (COBS 2.1.1R) | Enforced | L3 Enforceable | fca-cobs.client-best-interests-rule | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Suitability (COBS 9 / 9A) | Enforced | L3 Enforceable | fca-cobs.suitability-cobs9 | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Best execution (COBS 11.2 / 11.2A) | Enforced | L3 Enforceable | fca-cobs.best-execution-cobs11 | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Recordkeeping of advice & orders | Enforced | L3 Enforceable | fca-cobs.recordkeeping-advice-orders | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
FRC Ethical Standard
2024 · United Kingdom
The Financial Reporting Council's Ethical Standard — integrity, objectivity & independence, professional competence & due care, and the threats-and-safeguards framework for auditors and accountants. KYE Protocol™ governs whether an AI-generated entry / statement / conclusion may proceed under a named professional's authority, with the objectivity / independence / competence basis recorded before the action — the KYE™ Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Integrity | Designed | L2 Designed | frc-ethical-standard.integrity | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Objectivity & independence | Designed | L2 Designed | frc-ethical-standard.objectivity-independence | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Professional competence & due care | Designed | L2 Designed | frc-ethical-standard.professional-competence | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Threats & safeguards framework | Designed | L2 Designed | frc-ethical-standard.threats-safeguards | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
FSB Sound Practices
consultation-2026-06 · International
The Financial Stability Board's Sound Practices for the Responsible Adoption of AI in Finance (consultation, 10 June 2026) sets supervisory expectations for how financial institutions govern AI across model risk, accountability, third-party dependency, and operational resilience. This framework is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped — no requirement has been bound to a KYE Protocol™ artefact, so coverage is honestly reported as out of scope pending deep mapping. The §70 honesty bar forbids claiming enforced/designed coverage before a requirement is bound to a cited artefact. Deep mapping will be scheduled through the §70 rail (by hand, the §59 deterministic pipeline, or the §70 framework-mapping-agent) once the final report text is pinned.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): the framework is declared in framework-registry.json but no requirement has been bound to a KYE Protocol™ artefact yet. Coverage is reported out of scope until the deep mapping runs through the §70 rail — never inflated to imply enforcement that does not exist. | Out of scope | L1 Mapped | FSB Sound Practices (full consultation text — not yet decomposed into requirement-level mappings) | — |
FCA MCOB
FCA Handbook · United Kingdom
FCA Handbook conduct rules for regulated mortgage advice, pre-contract disclosure and responsible lending. KYE Protocol™ governs the AUTHORITY of an AI agent to take a suitability / disclosure / responsible-lending action and the EVIDENCE / replay of that action, under named accountability; KYE Protocol™ does not perform the affordability calculation, author the advice, or determine the regulatory correctness of the mortgage recommendation. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Suitability / affordability action admissibility | Designed | L2 Designed | fca-mcob.4.7a | Purpose Permission™Authority Gate |
| Pre-contract disclosure evidence | Designed | L2 Designed | fca-mcob.5.6 | Evidence Pack™ |
| Responsible-lending decision record | Designed | L2 Designed | fca-mcob.11.6 | Evidence Pack™Authority Gate |
| The affordability calculation itself | Out of scope | L1 Mapped | fca-mcob.11a.affordability-calc | — |
FCA Consumer Duty
PRIN 2A · United Kingdom
FCA Handbook PRIN 2A — the Consumer Duty (Principle 12 + the four outcomes). KYE Protocol™ governs the AUTHORITY of an AI agent to act toward a good retail-customer outcome, the consumer-understanding EVIDENCE, and foreseeable-harm contestability; KYE Protocol™ does not assess price-and-value, author the good-outcome judgement, or determine the firm's Consumer Duty compliance. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Act-to-deliver-good-outcomes authority gate | Designed | L2 Designed | fca-consumer-duty.prin-2a.2 | Purpose Permission™Authority Gate |
| Consumer-understanding evidence | Designed | L2 Designed | fca-consumer-duty.prin-2a.6 | Evidence Pack™ |
| Foreseeable-harm contestability | Designed | L2 Designed | fca-consumer-duty.prin-2a.5 | Delegated AuditabilityEvidence Pack™ |
| Price-and-value assessment | Out of scope | L1 Mapped | fca-consumer-duty.prin-2a.4 | — |
Investment Mandate / IPS
2026 · International
The Investment Policy Statement (IPS) / discretionary investment mandate — the authority anchor for AI-assisted investment decisions. Defines permitted investments, concentration / liquidity limits, prohibited investments, named authority / delegation, and reporting obligations. KYE Protocol™ governs whether an AI-assisted investment decision/action is within the recorded mandate, under whose authority it proceeds, evidenced, contestable, and final at the action boundary — the KYE™ Investment Decision Authority Pack™. KYE Protocol™ does not produce investment intelligence, judge whether a thesis is correct, or render any view on alpha / returns / suitability of outcome, and is not an investment adviser. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Mandate scope & permitted investments | Designed | L2 Designed | investment-mandate-ips.mandate-scope-permitted-investments | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Constraints, limits & prohibitions | Designed | L2 Designed | investment-mandate-ips.constraints-limits-prohibitions | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Named authority & delegation | Designed | L2 Designed | investment-mandate-ips.named-authority-delegation | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Reporting & evidence obligations | Designed | L2 Designed | investment-mandate-ips.reporting-evidence-obligations | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
Circular 230
2014-rev · United States
Treasury Department Circular No. 230 (31 CFR Part 10) — the standards of practice (due diligence §10.22, competence §10.35, return positions §10.34, written advice §10.37) for practitioners before the IRS. KYE Protocol™ governs whether an AI-generated tax position/filing/advice may proceed to a consequential action under a named preparer's authority — the KYE™ Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Due diligence & competence | Designed | L2 Designed | irs-circular-230.10.22-due-diligence, irs-circular-230.10.35-competence | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Tax-return positions & written advice | Designed | L2 Designed | irs-circular-230.10.34-positions, irs-circular-230.10.37-written-advice | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Practitioner authority & sign-off | Designed | L2 Designed | irs-circular-230.preparer-signoff | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
ISA (UK)
2024 · United Kingdom
The International Standards on Auditing (UK) — professional scepticism & reasonable assurance (ISA 200), fraud responsibilities (ISA 240), risk identification & assessment (ISA 315), and forming the opinion & reporting (ISA 700). KYE Protocol™ governs whether an AI-generated audit working-paper / conclusion may proceed under a named auditor's authority, with the ISA (UK) responsibilities recorded before the action — the KYE™ Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Professional scepticism & reasonable assurance (ISA 200) | Designed | L2 Designed | isa-uk.isa200-professional-scepticism | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Fraud responsibilities (ISA 240) | Designed | L2 Designed | isa-uk.isa240-fraud-responsibilities | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Risk identification & assessment (ISA 315) | Designed | L2 Designed | isa-uk.isa315-risk-assessment | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| Forming the opinion & reporting (ISA 700) | Designed | L2 Designed | isa-uk.isa700-forming-opinion | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
MAS TRM
Jan 2021 · Singapore
Monetary Authority of Singapore Technology Risk Management Guidelines — access control, audit logging, IT incident management, third-party risk. Per-requirement bijection at /compliance/mas-trm.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Access control + tamper-resistant audit logging | Enforced | L3 Enforceable | MAS TRM — access control, MAS TRM — audit logging | Authority GateAuthority Revocation OrchestratorWORM audit hash-chainStreaming Logs Contract™ |
| IT incident management + third-party riskThird-party risk enforced via Authority Register + SPoF; the MAS incident-notification delivery channel is in build. | Enforced | L3 Enforceable | MAS TRM — incident management, MAS TRM — third-party risk | Incident DetectorReporting EngineAuthority RegisterSPoF registry |
MiFID II
Directive 2014/65/EU · European Union
MiFID II (Directive 2014/65/EU) governs the provision of investment services in the EU — acting in the client's best interest (Art. 24), suitability (Art. 25), best execution (Art. 27), and recordkeeping. KYE Protocol™ governs whether an AI-assisted investment decision/action is within mandate, authorised, evidenced, and final at the action boundary — the KYE™ Investment Decision Authority Pack™. KYE Protocol™ does not perform the suitability assessment, judge whether a recommendation is correct, produce investment intelligence, or act as an investment adviser. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Acting in the client's best interest (Art. 24) | Enforced | L3 Enforceable | mifid-ii.art24-best-interest | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Suitability & appropriateness (Art. 25) | Enforced | L3 Enforceable | mifid-ii.art25-suitability | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Best execution (Art. 27) | Enforced | L3 Enforceable | mifid-ii.art27-best-execution | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Recordkeeping & basis of advice | Enforced | L3 Enforceable | mifid-ii.recordkeeping-basis-of-advice | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
Pillar Two
2023-globe · International
OECD/G20 Pillar Two GloBE rules — a 15% global minimum effective tax rate (IIR / UTPR) with a per-jurisdiction top-up tax reported in the GloBE Information Return (GIR). KYE Protocol™ governs whether an AI-generated Pillar Two computation may proceed to a filing or a booked liability — the KYE™ Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| GloBE effective-tax-rate & top-up tax | Designed | L2 Designed | oecd-pillar-two.globe-top-up-tax, oecd-pillar-two.effective-tax-rate | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| GloBE Information Return (GIR) | Designed | L2 Designed | oecd-pillar-two.gir-information-return | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| Scope & charging-rule determination | Designed | L2 Designed | oecd-pillar-two.scope-charging-rule | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
OSFI B-10
Effective 1 May 2024 · Canada
OSFI Guideline B-10 — risk-based management of third-party arrangements for federally regulated financial institutions: the arrangement register, criticality-proportionate risk assessment, and ongoing monitoring + concentration risk. Per-requirement bijection at /compliance/osfi-b-10.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Third-party arrangement register | Enforced | L3 Enforceable | register | Authority GateRisk Engine |
| Risk assessment by criticality | Enforced | L3 Enforceable | risk-assessment | Risk Engine |
| Ongoing monitoring + concentration risk | Enforced | L3 Enforceable | monitoring | Offline Evidence LogRisk Engine |
OSFI B-13
Effective 1 Jan 2024 · Canada
OSFI Guideline B-13 — technology and cyber risk management for federally regulated financial institutions: governance, technology operations + resilience, and cyber security. Per-requirement bijection at /compliance/osfi-b-13.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Governance + risk management (Domain 1) | Enforced | L3 Enforceable | d1 | Authority GateRisk Engine |
| Technology operations + resilience (Domain 2) | Enforced | L3 Enforceable | d2-asset-register, d2-resilience | Authority GateEdge Governance Safety FloorOffline Evidence LogRisk Engine |
| Cyber security — monitoring + incident (Domain 3) | Enforced | L3 Enforceable | d3 | Incident DetectorWORM audit hash-chain |
OSFI E-23
Effective 1 May 2027 · Canada
OSFI Guideline E-23 — enterprise-wide model risk management across the model lifecycle (model definition expanded to AI/ML): inventory + risk rating, independent validation, ongoing monitoring, and accountability. Per-requirement bijection at /compliance/osfi-e-23.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Model inventory + risk rating | Enforced | L3 Enforceable | inventory | Authority GateRisk Engine |
| Development + independent validation | Designed | L2 Designed | validation | Replay-Proof™WORM audit hash-chain |
| Ongoing monitoring | Enforced | L3 Enforceable | monitoring | Drift DetectorRisk Engine |
| Roles + accountability | Enforced | L3 Enforceable | accountability | Authority Gate |
PCI DSS
4.0 · Global
Security standard for entities that store, process, or transmit cardholder data.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Access control & strong authentication | Enforced | L3 Enforceable | Req 7, Req 8 | Authority GateWebAuthn step-upPurpose Permission™ |
| Audit logging & monitoring | Enforced | L3 Enforceable | Req 10 | WORM audit hash-chainDecision replay |
| Stored account-data protection evidenceKYE™ governs access to account data; signed evidence of protection and a FIPS-validated crypto adapter are in build. | Designed | L2 Designed | Req 3 | Evidence Pack™ signing (COSE-Sign1)FIPS-validated crypto module |
| Network security, anti-malware & physical accessNetwork segmentation, TLS termination, endpoint protection, and physical access to cardholder data are operated by the customer. | Out of scope | L1 Mapped | Req 1, Req 4, Req 5, Req 9 | — |
PCMLTFA / FINTRAC
S.C. 2000, c. 17 · Canada
Canada's anti-money-laundering and terrorist-financing regime (PCMLTFA + Regulations, administered by FINTRAC): client identification + KYC, ongoing monitoring, suspicious-transaction reporting, and record-keeping. Per-requirement bijection at /compliance/pcmltfa-fintrac.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Client identification + KYC | Enforced | L3 Enforceable | kyc | Authority GateDecision Map™ |
| Ongoing monitoring | Enforced | L3 Enforceable | monitoring | Drift DetectorRisk Engine |
| Suspicious transaction reporting (s.7) | Designed | L2 Designed | s7-str | Incident DetectorReporting Engine |
| Record-keeping (s.6) | Enforced | L3 Enforceable | s6-records | WORM audit hash-chain |
PSD2 / PSD3
PSD2 2015/2366 · European Union
EU payment-services regulation covering strong customer authentication and third-party access to accounts.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Strong customer authentication | Enforced | L3 Enforceable | RTS Art. 4-9 | WebAuthn step-upAuthority Gate |
| Third-party-provider access governance | Enforced | L3 Enforceable | Art. 66-67 | Purpose Permission™Directory tenant proxy |
| Transaction authorisation evidenceEvery transaction authorisation is recorded today; signed, third-party-verifiable transaction evidence is in build. | Designed | L2 Designed | Art. 97 | Evidence Pack™ signing (COSE-Sign1)Decision Map™ signing (JWS-detached) |
| Liability allocation frameworkKYE™ produces evidence relevant to liability, but the contractual allocation of liability is a legal matter. | Out of scope | L1 Mapped | Art. 97(5) | — |
RBNZ BS11
BS11 Outsourcing Policy · New Zealand
Reserve Bank of New Zealand outsourcing policy — control over outsourced functions, continuity of basic banking functions, continuing compliance evidence. Per-requirement bijection at /compliance/rbnz-bs11.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Outsourcing register + continuity of basic banking functions | Enforced | L3 Enforceable | BS11 — outsourcing register, BS11 — basic banking functions | Authority RegisterSPoF registryEdge Governance Safety FloorOffline Evidence Log |
| Continuing compliance evidence to RBNZ | Enforced | L3 Enforceable | BS11 — control evidence | Evidence Pack™Regulator Replay agentWORM audit hash-chain |
SEC IA Fiduciary
Investment Advisers Act of 1940 · United States
The US Investment Advisers Act of 1940 (s.206) and the SEC's 2019 fiduciary interpretation establish a federal fiduciary duty for registered investment advisers — a duty of care, a duty of loyalty, and the books-and-records rule (204-2). KYE Protocol™ governs whether an AI-assisted investment decision/action is within mandate, authorised, evidenced, and final at the action boundary — the KYE™ Investment Decision Authority Pack™. KYE Protocol™ does not form the reasonable belief, judge whether advice is correct, produce investment intelligence, or act as an investment adviser. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Duty of care — reasonable belief best interest | Enforced | L3 Enforceable | sec-ia-fiduciary.duty-of-care-best-interest | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Duty of loyalty — conflicts & disclosure | Enforced | L3 Enforceable | sec-ia-fiduciary.duty-of-loyalty-conflicts | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Suitability / mandate of advice | Enforced | L3 Enforceable | sec-ia-fiduciary.suitability-mandate-of-advice | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Books & records (Rule 204-2) | Enforced | L3 Enforceable | sec-ia-fiduciary.books-and-records-204-2 | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
SOX 404
2002 · United States
Sarbanes-Oxley §404 — management (and auditor) assessment of internal control over financial reporting (ICFR), with the income-tax provision a recurring material-weakness source requiring review controls, documentation, and data integrity. KYE Protocol™ governs whether an AI-generated tax-provision figure may proceed to being booked under recorded management-review controls with replay-provable provenance — the KYE™ Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Tax-provision ICFR design | Enforced | L3 Enforceable | sox-404.tax-provision-icfr | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Review & approval controls | Enforced | L3 Enforceable | sox-404.management-review-control | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Documentation & data integrity | Enforced | L3 Enforceable | sox-404.documentation-data-integrity | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| Management attestation | Enforced | L3 Enforceable | sox-404.management-attestation | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
FRS 102
2024 · United Kingdom
FRS 102 / FRS 105 (UK GAAP) — recognition and measurement bases, accounting-policy selection and consistency, disclosure requirements, and the micro-entity regime. KYE Protocol™ governs whether an AI-generated entry / statement may proceed with the FRS 102 / FRS 105 recognition, measurement, and disclosure basis recorded before the action — the KYE™ Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Recognition & measurement | Designed | L2 Designed | uk-gaap-frs102.frs102-recognition-measurement | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Accounting policies & consistency | Designed | L2 Designed | uk-gaap-frs102.frs102-accounting-policies | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| Disclosure requirements | Designed | L2 Designed | uk-gaap-frs102.frs102-disclosure | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Micro-entity (FRS 105) regime | Designed | L2 Designed | uk-gaap-frs102.frs105-micro-entity | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
UK MTD
2024 · United Kingdom
HMRC Making Tax Digital — digital record-keeping, unbroken digital links from source data to submitted figures, and programmatic filing via the MTD API. KYE Protocol™ governs whether an AI-generated MTD figure may proceed to an API submission under a named preparer's authority, preserving the digital link in replay-provable provenance — the KYE™ Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Digital record-keeping & digital links | Designed | L2 Designed | uk-mtd.digital-record-keeping, uk-mtd.digital-links | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| API filing integrity | Designed | L2 Designed | uk-mtd.api-filing-integrity | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Preparer authority for submission | Designed | L2 Designed | uk-mtd.preparer-authority-submission | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
US BSA / FinCEN
31 U.S.C. 5311 et seq.; 31 CFR Chapter X · United States
The US Bank Secrecy Act (31 U.S.C. 5311 et seq.) and FinCEN regulations (31 CFR Chapter X) require a risk-based AML program (5318(h)), customer due diligence & beneficial ownership (CDD Rule), Suspicious Activity Reports (SARs), and record-keeping. KYE Protocol™ governs whether an AI agent's AML action may proceed at the action boundary under a named BSA/AML officer's authority, with §36 two-person sign-off on the consequential SAR filing. KYE Protocol™ does not run transaction-monitoring models, does not decide whether a transaction is truly suspicious, and does not replace the institution's BSA/AML program.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| AML program (31 U.S.C. 5318(h)) | Enforced | L3 Enforceable | us-bsa-fincen.aml-program-5318h | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Customer due diligence & beneficial ownership (CDD Rule) | Enforced | L3 Enforceable | us-bsa-fincen.cdd-beneficial-ownership | Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
| Suspicious Activity Reporting (SAR) | Enforced | L3 Enforceable | us-bsa-fincen.sar-filing | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Record-keeping (31 CFR Chapter X) | Enforced | L3 Enforceable | us-bsa-fincen.record-keeping | Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
Wolfsberg Principles
current · International
The Wolfsberg Group publishes industry AML, sanctions-screening, and correspondent-banking due-diligence standards for global banks. KYE Protocol™ governs whether an AI agent's AML or sanctions-screening action may proceed at the action boundary under a named compliance officer's authority, with due diligence before the action and replay-provable provenance. KYE Protocol™ does not run the screening engine, does not decide whether a name is a true sanctions match, and does not replace the institution's AML / sanctions program.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Risk-based KYC / CDD | Designed | L2 Designed | wolfsberg-principles.risk-based-kyc-cdd | Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
| Sanctions & transaction screening governance | Designed | L2 Designed | wolfsberg-principles.sanctions-screening-governance | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Correspondent-banking due diligence | Designed | L2 Designed | wolfsberg-principles.correspondent-banking-due-diligence | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
ECB AI Supervisory Expectations
emerging-2026 · EU
ECB Banking Supervision's emerging expectations on AI-amplified cyber and operational risk for significant institutions (planned 'dear CEO letter', per Reuters 3 June 2026; part of the ECB 2026–2028 supervisory priorities). REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: no formal requirement text has been published, so coverage is honestly reported as out of scope pending deep mapping. The §70 honesty bar forbids claiming enforced/designed coverage before requirements are pinned. The substance — AI-actor authority, privileged-action gating, incident-response authority, replay-derivable evidence — is already covered by KYE Protocol™'s deep-mapped DORA artefacts and the shipped Cyber Resilience & Incident Authority Pack; deep mapping will graft those once the ECB text is final.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no requirement bound to a KYE Protocol™ artefact yet because no formal text is published. Coverage reported out of scope until the ECB requirements are pinned and deep-mapped through the §70 rail — never inflated. The DORA / Cyber Resilience & Incident Authority Pack artefacts already answer the substance and will be grafted on publication. | Out of scope | L1 Mapped | ECB AI supervisory expectations (forthcoming dear-CEO letter — not yet decomposed into requirement-level mappings) | — |
SM&CR
2016 (as amended) · United Kingdom
UK SM&CR accountability regime. KYE Protocol™ governs whether an AI agent's action may proceed under a named Senior Manager's delegated authority, with the responsibility line recorded and replay-provable. Consumed via kye:rule-pack:sm-cr + kye:sector-pack:uk-financial-services-sm-cr (§0: never re-mapped). Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| SMF responsibility + duty-of-responsibility evidence | Designed | L2 Designed | uk-smcr.smf-responsibility, uk-smcr.duty-of-responsibility | Purpose Permission™Evidence Pack™Replay Proof™ |
| Certification scope + contestable conduct record | Designed | L2 Designed | uk-smcr.certification, uk-smcr.conduct-rules | Purpose Permission™Delegated Auditability |
Failure to Prevent Fraud
ECCTA 2023 (in force 1 Sep 2025) · United Kingdom
UK ECCTA 2023 corporate 'failure to prevent fraud' offence. KYE Protocol™ turns AI-actor authority into a demonstrable 'reasonable fraud-prevention procedure': AI actions that could facilitate fraud are gated by named authority, evidenced, and contestable. KYE Protocol™ proves the procedure operated; it does not adjudicate the offence. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Reasonable procedures (statutory defence) + evidence | Designed | L2 Designed | uk-eccta-ftpf.reasonable-procedures, uk-eccta-ftpf.evidence-of-procedures | Purpose Permission™Evidence Pack™Replay Proof™ |
| Fraud risk assessment + monitoring | Designed | L2 Designed | uk-eccta-ftpf.risk-assessment, uk-eccta-ftpf.monitoring-review | Decision Map™Delegated Auditability |
UK MLR 2017
SI 2017/692 (as amended) · United Kingdom
UK MLR 2017 AML/CTF obligations. KYE Protocol™ governs whether an AI agent's AML action may proceed under a named compliance officer's authority, with due diligence recorded and replay-provable provenance. Consumed via the aml-financial-crimes spine (§0: never re-mapped). KYE Protocol™ proves the basis; it does not decide whether conduct is money laundering. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Risk assessment + customer due diligence | Designed | L2 Designed | uk-mlr-2017.risk-assessment, uk-mlr-2017.cdd | Purpose Permission™Decision Map™ |
| Ongoing monitoring + replay-derivable records | Designed | L2 Designed | uk-mlr-2017.ongoing-monitoring, uk-mlr-2017.record-keeping | Delegated AuditabilityEvidence Pack™Replay Proof™ |
MiCA
Regulation (EU) 2023/1114 · European Union
EU regulation for crypto-asset issuance and crypto-asset service providers (CASPs): custody, conduct, conflicts, complaints, and the Travel Rule overlay. Titles III–IV from Jun 2024; Title V from Dec 2024.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Custody & administration of crypto-assets (Art. 70, 75, 76) | Enforced | L3 Enforceable | Art. 75 | MiCA custody rule packEvidence Pack™ signingAuthority Gate |
| CASP conduct & conflict-of-interest screening (Art. 66, 72) | Enforced | L3 Enforceable | Art. 66, Art. 72 | Purpose Permission™Decision replay |
| Complaints handling (Art. 71)Evidenced complaint-handling response is design-locked; a CASP complaint-intake-and-tracking runtime path is not yet wired. | Designed | L2 Designed | Art. 71 | Comms Rail (evidenced response) |
| Travel Rule + AML overlay for crypto-asset transfers | Enforced | L3 Enforceable | Reg (EU) 2023/1113 | Travel-Rule rule packAML financial-crimes rule pack |
| Token white paper, authorisation & reserve of assetsReserve of assets, prudential own-funds, white-paper notification and issuer/CASP authorisation are prudential/licensing obligations of the regulated entity and its competent authority, outside KYE™'s lane. | Out of scope | L1 Mapped | Art. 16, Art. 36, Art. 54 | — |
GENIUS Act
GENIUS Act (Pub. L. 119-27, 2025) · United States
First US federal law governing payment stablecoins: 1:1 reserve backing, redemption at par, monthly reserve disclosure, BSA/AML obligations, lawful-order (freeze/seize/burn) capability, and marketing restrictions. Prudential rulemaking deadline July 2026.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Redemption at par on demand | Enforced | L3 Enforceable | §4 | Purpose Permission™Authority Gate |
| Monthly reserve-composition disclosure (certified)KYE™ produces a tamper-evident, certify-able evidence pack for the disclosure; the reserve-composition data is the issuer's and the disclosure-assembly flow is design-locked, not yet wired. | Designed | L2 Designed | §4 | Evidence Pack™ signingWORM audit hash-chain |
| BSA / AML program + sanctions / lawful-order capability | Enforced | L3 Enforceable | §4 | AML financial-crimes rule packAuthority GateWORM audit hash-chain |
| 1:1 reserve backing & no-yield constraintHolding/investing the 1:1 reserve and the no-yield prohibition are balance-sheet/product obligations of the issuer, outside KYE™'s lane. | Out of scope | L1 Mapped | §4 | — |
| Issuer authorisation, charter & prudential supervisionFederal/state issuer authorisation, charter and prudential supervision are licensing/supervision obligations of the issuer and its regulator, outside KYE™'s lane. | Out of scope | L1 Mapped | §3, §5 | — |
Singapore PS Act
PS Act 2019 (No. 2 of 2019), as amended · Singapore
Singapore's licensing and conduct regime for payment service providers, administered by MAS: seven regulated activities (account issuance, domestic and cross-border money transfer, merchant acquisition, e-money issuance, digital payment token services, money-changing) across three licence classes, with AML/CFT, technology-risk and user-protection conditions. This framework is REGISTERED in the §70 Framework Mapping Rail following the statute-class precedent of the DORA and PSD2/PSD3 rows; deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no PS Act requirement is bound to a KYE Protocol™ artefact yet. The payment-authorization rail's authority controls are platform-level and cross-regime; PS-Act-specific deep mapping (licence-class conditions, DPT-service obligations) is scheduled through the §70 rail. Coverage is never inflated. | Out of scope | L1 Mapped | PS Act 2019 — licensing (Part 2), conduct of business (Part 3), and AML/CFT + technology-risk licence conditions; full text not yet decomposed into requirement-level mappings | — |
Singapore SFA
SFA 2001 (2020 Revised Edition), as amended · Singapore
Singapore's capital-markets statute, administered by MAS: licensing of capital-markets services, regulation of organised markets and clearing facilities, offers of investments and prospectus requirements, market-conduct prohibitions (false trading, market rigging, insider trading), and derivatives-contract regulation. This framework is REGISTERED in the §70 Framework Mapping Rail following the statute-class precedent of the DORA and PSD2/PSD3 rows; deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping_state=registered): declared in framework-registry.json but no SFA requirement is bound to a KYE Protocol™ artefact yet. SFA-specific deep mapping (licensing, market-conduct, disclosure obligations) is scheduled through the §70 rail. Coverage is never inflated. | Out of scope | L1 Mapped | SFA 2001 — capital-markets services licensing, market conduct (Part 12), offers of investments (Part 13); full text not yet decomposed into requirement-level mappings | — |
TARGET2
ECB TARGET Guideline (EU) 2022/912 (ECB/2022/8) + Directive 98/26/EC Arts 3 & 5 · European Union
The Eurosystem's real-time gross settlement system settles payment orders in central bank money with finality conferred at the moment of entry under the Settlement Finality Directive — an entered order cannot be unwound. KYE Protocol™ governs the payment-authority dimension: every instruction (human- or AI-agent-originated) must resolve to a live, purpose-scoped mandate of an authorised user of an admitted participant, with the admissibility verdict, sealed decision context and hash-bound Evidence Pack™ complete BEFORE the finality moment, revocation biting on the very next action, and the message's authorisation lineage retained append-only over the record-keeping period. Settlement execution, legal conferral of finality and intraday liquidity/credit stay the Eurosystem's and the participant treasury's own (honest scope, §0). Per-requirement bijection at /compliance/target2-rtgs.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Participation, access criteria & authorised-user binding | Enforced | L3 Enforceable | target2-rtgs.participation-access-authority | Purpose Permission™Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Settlement finality & the pre-entry authority checkpoint (SFD 98/26/EC) | Enforced | L3 Enforceable | target2-rtgs.pre-settlement-authority-checkpoint | Authority GateContext sealEvidence Pack™Replay-Proof™ |
| Suspension, termination & revocation propagation | Enforced | L3 Enforceable | target2-rtgs.revocation-suspension-propagation | Authority GateAuthority-drift monitoringKill-switch semantics |
| ISO 20022 messaging integrity & record retention | Enforced | L3 Enforceable | target2-rtgs.message-integrity-records | Evidence Pack™WORM audit hash-chainRetention policy |
| Operational resilience, self-certification & incident notificationKYE™ supplies the machine-generated attestation cadence and sealed incident evidence the self-certification and notification duties run on; the participant's BCM programme, endpoint security and the submissions themselves are participant-owned and not claimed as enforced. | Designed | L2 Designed | target2-rtgs.operational-resilience-incident | ≤90-day attestationEvidence Pack™ |
| Settlement execution & legal conferral of finalitySettlement in central bank money and the SFD's legal conferral of finality/irrevocability are performed and owned by the Eurosystem as system operator — KYE™ is an AI-authority and evidence layer, not a settlement engine or designated system. | Out of scope | L1 Mapped | target2-rtgs.settlement-finality-execution | — |
| Liquidity provision & intraday creditFunding MCAs/DCAs, collateralised intraday credit and liquidity reservations are treasury and central-bank functions — KYE™ is not a liquidity-management or collateral engine. | Out of scope | L1 Mapped | target2-rtgs.liquidity-intraday-credit | — |
CIPS
CIPS participant and business rules — direct/indirect participation, ISO 20022 messaging, RTGS + hybrid netting · China
CIPS clears and settles cross-border RMB payments for direct participants (settling on CIPS accounts) and indirect participants routed through sponsoring direct participants, over ISO 20022-based messaging with RTGS and hybrid-netting settlement. KYE Protocol™ governs the payment-authority dimension only: participant mandate binding at the moment of action, the pre-settlement authority checkpoint (verdict + sealed evidence before the instruction is released), message-authorisation lineage retained append-only, and the authority + evidence layer of the participant's OWN financial-crime screening decision under the laws applicable to that participant — KYE™ takes no position on any jurisdiction's sanctions regime and provides nothing that weakens or routes around a screening obligation. Settlement execution, netting sessions and liquidity funding stay the operator's and participants' own (honest scope, §0). Per-requirement bijection at /compliance/cips-cross-border.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Participation & authorised-user binding | Enforced | L3 Enforceable | cips-cross-border.participant-authority | Purpose Permission™Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Pre-settlement authority checkpoint & irrevocability | Enforced | L3 Enforceable | cips-cross-border.pre-settlement-authority-checkpoint | Authority GateContext sealEvidence Pack™Replay-Proof™ |
| ISO 20022 messaging integrity & record retention | Enforced | L3 Enforceable | cips-cross-border.message-integrity-records | Evidence Pack™WORM audit hash-chainRetention policy |
| Financial-crime screening authority & evidenceScope-guarded: KYE™ governs the authority and evidence layer of the participant's own screening decision under the AML/CTF and sanctions laws applicable to that participant. Screening adjudication itself — list management, matching, disposition — is the participant's / their vendor's own and is not claimed. | Designed | L2 Designed | cips-cross-border.financial-crime-screening-authority | Named-authority bindingScreening tool-call evidenceDecision replay |
| Operational resilience & incident reportingKYE™ supplies sealed incident evidence and the attestation cadence; availability engineering, contingency arrangements and the incident report to the operator are participant-owned and not claimed as enforced. | Designed | L2 Designed | cips-cross-border.operational-resilience-incident | ≤90-day attestationEvidence Pack™ |
| Settlement execution & liquidity provisionClearing and settling RMB payments across CIPS accounts, netting sessions and liquidity funding are owned by the system operator and participant treasuries — KYE™ is an AI-authority and evidence layer, not a clearing, settlement or liquidity engine. | Out of scope | L1 Mapped | cips-cross-border.settlement-execution-liquidity | — |
UK Faster Payments
UK Faster Payment System rules (Pay.UK) + PSR mandatory APP-scam reimbursement for Faster Payments (October 2024) · United Kingdom
Faster Payments processes UK retail payments in near real time — an accepted payment is irrevocable, so there is no recall window to correct an unauthorised agent action. KYE Protocol™ governs the payment-authority dimension: participant and sponsor/aggregator mandate binding at the moment of action, the pre-submission authority checkpoint (verdict + sealed evidence before release), message-authorisation lineage retained append-only over the record-keeping period, and the replay-verifiable authorisation evidence trail an APP-scam reimbursement investigation turns on (who or what authorised, under which mandate, with which fraud-assessment tool-calls). Scheme processing, settlement at the Bank of England, prefunding/net-sender-cap management and the reimbursement adjudication itself stay the scheme's, the Bank's and the PSPs' own (honest scope, §0). Per-requirement bijection at /compliance/uk-fps.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Participation, access criteria & authorised-user binding | Enforced | L3 Enforceable | uk-fps.participant-access-authority | Purpose Permission™Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Irrevocability & the pre-submission authority checkpoint | Enforced | L3 Enforceable | uk-fps.pre-submission-authority-checkpoint | Authority GateContext sealEvidence Pack™Replay-Proof™ |
| Messaging integrity & record retention | Enforced | L3 Enforceable | uk-fps.message-integrity-records | Evidence Pack™WORM audit hash-chainRetention policy |
| APP-fraud reimbursement & authorisation evidenceKYE™ supplies the replay-verifiable record of the authorising principal, mandate, purpose scope and fraud-assessment tool-calls a claim investigation needs; the reimbursement adjudication (gross-negligence assessment, 50:50 split, claim payment) is owned by the PSPs, Pay.UK and the PSR and is not claimed as enforced. | Designed | L2 Designed | uk-fps.app-fraud-reimbursement-evidence | Decision replayEvidence Pack™WORM audit hash-chain |
| Operational resilience & incident reportingKYE™ supplies sealed incident evidence and the attestation cadence; availability engineering, contingency arrangements and the notifications themselves are participant-owned and not claimed as enforced. | Designed | L2 Designed | uk-fps.operational-resilience-incident | ≤90-day attestationEvidence Pack™ |
| Scheme processing & settlement executionCentral-infrastructure processing, deferred multilateral net settlement at the Bank of England, and the conferral of irrevocability on accepted payments are owned by Pay.UK, the infrastructure provider and the Bank — KYE™ is an AI-authority and evidence layer, not a payment processor. | Out of scope | L1 Mapped | uk-fps.scheme-processing-settlement | — |
| Liquidity provision & net sender capsPrefunding the settlement account, sizing/managing the net sender cap and intraday liquidity monitoring are participant treasury functions — KYE™ is not a liquidity-management engine. | Out of scope | L1 Mapped | uk-fps.liquidity-net-sender-caps | — |
SAFR
SAFR v1.0 (July 2026) · Global (industry reference; MAS Project MindForge lineage)
SAFR is an industry reference framework (BuildFin.AI) for a runtime governance layer over agentic AI in financial services: four components (Agent Identity, Controls Repository, Disposition Engine, Audit Log) exchanging a Governance Envelope, sitting after model guardrails and before execution. KYE Protocol™ maps to SAFR component-for-component at the moment-of-action admissibility check and adds Authority Finality™ — a Replay-Proof™ record verifiable from public keys alone. KYE™ governs whether the agentic financial action was allowed to become final; the rails execute if and only if approved.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Runtime governance at the point of action (pre-execution + per-step) | Enforced | L3 Enforceable | safr.pre-execution-governance, safr.per-step-independent-authority | Purpose Permission™Decision Engineper-action admissibility |
| Agent Identity — verified registered principal (SAFR component 1) | Designed | L3 Enforceable | safr.agent-identity-verification, safr.authoritative-registry-resolution | §0.30 agent-as-principal§52 authority bindingentity hierarchy |
| Controls Repository & capability-based mandate (SAFR component 2) | Enforced | L3 Enforceable | safr.controls-repository, safr.mandate-capability-authority | Rules Gateway™§52 authority claimDecision Map™ |
| Deterministic disposition — four outcomes, risk-calibrated (SAFR component 3) | Designed | L3 Enforceable | safr.deterministic-disposition, safr.four-outcome-disposition, safr.risk-calibrated-outcome | Decision EngineDecision Map™risk signals |
| Governance Envelope authenticated to origin | Enforced | L3 Enforceable | safr.governance-envelope-authenticated | Evidence Pack™tool-call pincontext seal |
| Immutable, tamper-evident audit log (SAFR component 4) | Enforced | L3 Enforceable | safr.immutable-audit-log | §30 WORMReplay-Proof™Authority Finality™ |
| Substantive human escalation (bounded, timeout, real authority) | Enforced | L3 Enforceable | safr.substantive-human-escalation | GovernedUI™ approval modestimeout→block/senior§9 no self-grant |
| Native + gateway integration and decision-not-settlement boundary | Enforced | L3 Enforceable | safr.native-and-gateway-integration, safr.decision-not-settlement-boundary | PEP (native + gateway)§0.33 Authority Finality™ category |
AAOIFI SS
AAOIFI Shariah Standards (as at 2023 compilation) · International
AAOIFI's suite of Shariah Standards on Islamic-finance contracts and instruments — the substantive fiqh rulings adopted by many regulators and institutions.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Shariah Standards (substantive contract rulings) | Designed | L2 Designed | AAOIFI SS | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | AAOIFI SS | — |
AAOIFI GSIFI
AAOIFI Governance Standards for Islamic Financial Institutions (GSIFI) · International
AAOIFI's governance standards defining the Shariah supervisory board, review, audit, and governance-committee arrangements for Islamic financial institutions.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Governance Standards (GSIFI) | Designed | L2 Designed | AAOIFI GSIFI | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | AAOIFI GSIFI | — |
AAOIFI FAS
AAOIFI Financial Accounting Standards (FAS) · International
AAOIFI's accounting standards for the recognition, measurement and disclosure of Islamic-finance contracts.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Financial Accounting Standards (FAS) | Designed | L2 Designed | AAOIFI FAS | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | AAOIFI FAS | — |
AAOIFI ASIFI
AAOIFI Auditing Standards for Islamic Financial Institutions (ASIFI) · International
AAOIFI's auditing standards for external and Shariah-compliance audit of Islamic financial institutions.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Auditing Standards (ASIFI) | Designed | L2 Designed | AAOIFI ASIFI | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | AAOIFI ASIFI | — |
IFSB-10
IFSB-10 (2009) · International
IFSB-10 sets guiding principles for the Shariah governance system: competence, independence, confidentiality and consistency of the Shariah board, plus review and audit functions.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Shariah Governance System (IFSB-10 guiding principles) | Designed | L2 Designed | IFSB-10 | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | IFSB-10 | — |
IFSB
IFSB prudential standards suite · International
The IFSB's prudential and disclosure standards for institutions offering Islamic financial services, including corporate governance, core principles, and market-discipline disclosures.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Prudential & governance standards (IFSB suite) | Designed | L2 Designed | IFSB | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | IFSB | — |
IIFM
IIFM documentation standards · International
IIFM's standardised master agreements and documentation for Islamic hedging, treasury, interbank and sukuk transactions.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Documentation & contract standards (IIFM) | Enforced | L3 Enforceable | IIFM | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | IIFM | — |
BNM SGF 2019
BNM/RH/PD 028-100 (2019) · Malaysia
BNM's Shariah Governance Policy Document (2019) sets board oversight, Shariah committee, and Shariah risk/review/audit/research control functions, operating under the binding rulings of BNM's Shariah Advisory Council (SAC).
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Shariah Governance (BNM SGF 2019 + SAC/IFSA 2013) | Designed | L2 Designed | BNM SGF 2019 | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | BNM SGF 2019 | — |
CBUAE HSA
CBUAE Shariah Governance Standard (2020) · United Arab Emirates
The CBUAE requires each Islamic financial institution to maintain an Internal Shariah Supervision Committee and Shariah control functions, operating under the binding resolutions of the CBUAE Higher Shariah Authority (HSA).
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Shariah Governance (CBUAE HSA Standard) | Designed | L2 Designed | CBUAE HSA | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | CBUAE HSA | — |
CBB SG Module
CBB Rulebook — Shariah Governance Module · Bahrain
The CBB Shariah Governance Module mandates AAOIFI standards, an independent Shariah supervisory board, internal Shariah audit and review, and (from 2020) a centralised Shariah board.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Shariah Governance (CBB Module) | Designed | L2 Designed | CBB SG Module | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | CBB SG Module | — |
SAMA SGF
SAMA Shariah Governance Framework (2020) · Saudi Arabia
SAMA's Shariah Governance Framework requires local banks to establish an independent Shariah committee, a Shariah division, and Shariah review and audit functions.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Shariah Governance (SAMA Framework) | Designed | L2 Designed | SAMA SGF | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | SAMA SGF | — |
OJK / DSN-MUI
OJK Shariah governance regulations + DSN-MUI fatawa · Indonesia
Indonesia operates a two-tier model: DSN-MUI issues national fatawa binding on Islamic financial institutions, while OJK regulates the institution-level Dewan Pengawas Syariah (Shariah Supervisory Board) and compliance functions.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Shariah Governance (OJK + DSN-MUI) | Designed | L2 Designed | OJK / DSN-MUI | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | OJK / DSN-MUI | — |
SBP SGF
SBP Shariah Governance Framework (2018) · Pakistan
SBP's Shariah Governance Framework mandates a board Shariah committee, a resident Shariah board member, a Shariah compliance department, and internal and external Shariah audit, under the SBP Shariah Advisory Committee's rulings.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Shariah Governance (SBP Framework) | Designed | L2 Designed | SBP SGF | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | SBP SGF | — |
QCB
QCB Islamic banking instructions · Qatar
QCB and the QFCRA require Islamic financial institutions to maintain a Shariah supervisory board and Shariah review/audit functions, with broad reference to AAOIFI standards.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Shariah Governance (QCB / QFCRA) | Designed | L2 Designed | QCB | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | QCB | — |
CBK
CBK Shariah supervisory governance instructions · Kuwait
The CBK requires Islamic banks to maintain an independent Shariah supervisory board and Shariah audit, coordinated with a higher committee for Shariah supervision at the CBK.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Shariah Governance (CBK) | Designed | L2 Designed | CBK | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | CBK | — |
CBO IBRF
CBO Islamic Banking Regulatory Framework (2012) · Oman
Oman's IBRF mandates a Shariah Supervisory Board, an internal Shariah reviewer, and Shariah audit for Islamic banks and windows, referencing AAOIFI standards.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Shariah Governance (CBO IBRF) | Designed | L2 Designed | CBO IBRF | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | CBO IBRF | — |
TKBB
TKBB participation-banking standards + BDDK regulation · Türkiye
In Türkiye, participation (Islamic) banks are supervised by BDDK; the TKBB Central Advisory Board issues participation-banking standards, and each bank maintains an advisory committee.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Participation Banking Governance (TKBB) | Designed | L2 Designed | TKBB | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | TKBB | — |
CBN NIFI
CBN guidelines for non-interest financial institutions · Nigeria
The CBN regulates Non-Interest (Islamic) Financial Institutions; a central Financial Regulation Advisory Council of Experts (FRACE) advises the CBN, and each institution maintains an Advisory Committee of Experts (ACE).
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Shariah Governance (CBN NIFI + FRACE) | Designed | L2 Designed | CBN NIFI | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | CBN NIFI | — |
FCA SSB model
FCA/PRA firm-level governance (no separate Shariah regime) · uk
The UK has no separate statutory Shariah regime; Islamic financial institutions operate under the standard FCA/PRA perimeter and appoint their own firm-level Shariah supervisory boards, typically applying AAOIFI standards.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Firm-Level Shariah Governance (UK FCA model) | Designed | L2 Designed | FCA SSB model | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | FCA SSB model | — |
Brunei SFSB
Syariah Financial Supervisory Board Order + BDCB regulation · Brunei Darussalam
Brunei's Syariah Financial Supervisory Board (SFSB) is the highest authority on Islamic finance matters; BDCB regulates institution-level Syariah advisory bodies.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Shariah Governance (Brunei SFSB) | Designed | L2 Designed | Brunei SFSB | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | Brunei SFSB | — |
CBJ Islamic
CBJ Islamic banking instructions · Jordan
The CBJ regulates Islamic banks under the Banking Law and dedicated instructions requiring a Shariah supervisory board and Shariah audit.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Shariah Governance (CBJ) | Designed | L2 Designed | CBJ Islamic | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | CBJ Islamic | — |
Egypt FRA
FRA Islamic finance regulations (sukuk, takaful) · Egypt
Egypt's FRA regulates non-banking Islamic finance (sukuk, takaful) with a central Shariah supervisory committee; the CBE oversees Islamic banking.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Shariah Governance (Egypt FRA) | Designed | L2 Designed | Egypt FRA | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | Egypt FRA | — |
Sudan HSSB
CBOS High Shariah Supervisory Board framework · Sudan
Sudan operates a fully Islamic banking system; the High Shariah Supervisory Board (HSSB) at the CBOS issues binding rulings, and each bank maintains a Shariah supervisory body.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Shariah Governance (Sudan HSSB) | Designed | L2 Designed | Sudan HSSB | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | Sudan HSSB | — |
RBI IT Governance MD
Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices · India
KYE™ governs the AUTHORITY + EVIDENCE layer where AI agents take consequential action inside a regulated entity's operations. KYE™ is OUT-OF-SCOPE for board-level IT governance structures, the entity's information-security programme, business-continuity capability and internal-audit function — those are the regulated entity's own, and RBI supervises them directly (§70 §4). Deep per-requirement mapping: 6 requirements, 2 enforced by KYE™ runtime, 4 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Authority + evidence at the action boundary — enforced by KYE™ runtime and verified by CI | Enforced | L3 Enforceable | rbi-master-direction-it.AGENT-ACTION-AUTHORITY — Consequential actions by automated systems resolve to a live delegated authority, rbi-master-direction-it.AUDIT-TRAIL — Tamper-evident audit trail over privileged and consequential operations | kye.compliance.attestation.v1kye.evidence.decision_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context_seal.v1internal |
| Obligations owed directly by the regulated entity — NOT discharged by KYE™KYE™ governs the AUTHORITY + EVIDENCE layer where AI agents take consequential action inside a regulated entity's operations. KYE™ is OUT-OF-SCOPE for board-level IT governance structures, the entity's information-security programme, business-continuity capability and internal-audit function — those are the regulated entity's own, and RBI supervises them directly (§70 §4). | Out of scope | L1 Mapped | rbi-master-direction-it.IT-GOVERNANCE-STRUCTURE — Board-level IT strategy committee and defined governance structure, rbi-master-direction-it.INFOSEC-PROGRAMME — Information-security policy, controls and periodic assessment, rbi-master-direction-it.BUSINESS-CONTINUITY — Business continuity and disaster-recovery capability with periodic testing, rbi-master-direction-it.IT-ASSURANCE — Independent assurance and internal audit over IT controls | — |
Frameworks specifically governing AI agents in clinical environments and UK medical-device regulation. Per-requirement bijection maps available at /compliance/<framework>.html.
PMDA SaMD
PMD Act SaMD pathway + PMDA review framework · Japan
The Pharmaceuticals and Medical Devices Agency's Software-as-a-Medical-Device review pathway under the PMD Act, including the SaMD two-step (DASH) approval scheme and AI/ML change-control expectations. KYE Protocol™ evidences the QMS, clinical-evaluation provenance, change-control, post-market surveillance and human-oversight obligations that bind an AI-supported clinical action; device classification and marketing approval remain the manufacturer's submission. Per-requirement bijection at /compliance/pmda-samd.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| QMS evidence & clinical-evaluation provenance | Enforced | L3 Enforceable | PMDA SaMD QMS evidence, PMDA SaMD clinical evaluation | WORM audit hash-chainEvidence Pack™Data Classification Engine |
| Change control, versioning & human oversight of clinical decisions | Enforced | L3 Enforceable | PMDA SaMD change control, PMDA SaMD human oversight | Conformance RunnerDrift DetectorGovernedUI™Authority Resolution™ |
| Post-market surveillance & incident reporting to the PMDAKYE™ assembles the PMDA adverse-event notification package; the regulator-side delivery channel to the PMDA is designed pending the per-jurisdiction reporting connector. | Designed | L1 Mapped | PMDA SaMD post-market surveillance | Incident DetectorReporting Engine |
CLIA
42 CFR 493 · US
The Clinical Laboratory Improvement Amendments (42 CFR Part 493) set US federal quality standards for testing on human specimens. KYE Protocol™ enforces the test-report integrity and electronic-record audit-trail slices, and governs the authority of AI-supported result generation — testing, proficiency testing and competency stay the laboratory's quality system. Per-requirement bijection at /compliance/clia.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Test records & result-report integrity (Subpart J, 493.1291) | Enforced | L3 Enforceable | clia.493.1291-report-integrity | Decision replayEvidence Pack™ |
| Audit trail for electronic test records | Enforced | L3 Enforceable | clia.audit-trail | WORM audit hash-chain |
| Test-record retention (493.1105) | Designed | L2 Designed | clia.493.1105-record-retention | WORM audit hash-chain |
| Authority & oversight of AI-supported result generation (Subpart M) | Enforced | L3 Enforceable | clia.493.1445-ai-oversight | Purpose Permission™Authority Gate |
| Analytic-system QC, validation, proficiency testing & competency (Subparts K, H, M)Analytic-system quality control, method validation, proficiency testing and personnel competency are the laboratory's own quality and HR functions — out of scope for an AI-authority-governance protocol. | Out of scope | L1 Mapped | clia.493-subpart-k-analytic-systems, clia.493-pt-competency | — |
HAARF v1.0
v1.0 (2026) · Global
Comprehensive security and governance standard for autonomous AI agents in clinical environments — 279 requirements across 8 categories.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| 279 requirements across 8 categories — risk lifecycle, model passport, cybersecurity, human oversight, agent registration, autonomy governance, bias/equity, tool integration | Enforced | L3 Enforceable | HAARF C1–C8 | Decision EngineEvidence EngineGovernedUI approvalEdge Governance modesShadow ModeAgent Tool Pack™ |
ISO 15189
2022 · International
ISO 15189:2022 sets quality and competence requirements for medical laboratories, including patient-safety risk management. KYE Protocol™ enforces the §7.4-7.6 report-integrity, §7.6/§8.4 data-integrity and audit-trail slices where a medical laboratory uses AI-supported decisioning — examination procedures and competence stay the laboratory's quality system. Per-requirement bijection at /compliance/iso-15189.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Reporting of results & integrity of the report (7.4-7.6) | Enforced | L3 Enforceable | iso-15189.7.4-report-integrity | Decision replayEvidence Pack™ |
| Control of records & audit trail (8.4) | Enforced | L3 Enforceable | iso-15189.8.4-record-control | WORM audit hash-chain |
| Information management & data integrity (7.6, 8.4) | Enforced | L3 Enforceable | iso-15189.7.6-data-integrity | Decision replayEvidence Pack™ |
| Impartiality & authorised decision-making (5.1, 6.2) | Enforced | L3 Enforceable | iso-15189.5.1-impartiality-authority | Purpose Permission™Authority Gate |
| Risk management & patient-safety evidence (8.5) | Enforced | L3 Enforceable | iso-15189.8.5-risk-patient-safety | Resilience Loop™ |
| Examination processes & technical competence (6, 7.3)Validation of examination procedures, reference intervals, equipment/reagents and technical competence are the medical laboratory's own quality system — out of scope for an AI-authority-governance protocol. | Out of scope | L1 Mapped | iso-15189.6-examination-competence | — |
MHRA MDR 2002
2002 as amended through 2024 · United Kingdom
UK Statutory Instrument 2002/618 — risk classes, conformity assessment, essential requirements (Annex I regs 7-12), Annex IX classification rules, and post-market vigilance (regs 44-47). 53 requirements.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| 53 requirements across risk classes + conformity assessment + essential requirements + classification rules + post-market vigilance | Enforced | L3 Enforceable | SI 2002/618 | Profile classificationSector packSigned evidence packTrust-domain UDI |
MHRA PMS 2025
SI 2024/1368 (effective June 2025) · United Kingdom
Explicit post-market surveillance obligations: PMS plan (Reg 7), post-market clinical follow-up (Reg 8), incident reporting timelines (2/10/15-day), Periodic Safety Update Reports (PSURs), trend reporting. 36 requirements.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| 36 requirements across PMS plan, PMCF, incident timelines, PSURs, and trend reporting | Enforced | L3 Enforceable | SI 2024/1368 | Resilience-loop registryComms-rail templatesAnalytics-plane eventsGovernedUI two-person sign-off |
MHRA SaMD & AI
2023 Change Program · United Kingdom
41 requirements: 15 original work-packages + 7 PCCP (Predetermined Change Control Plan) obligations + 9 change-class triggers (capability / model_params / training-data / bias drift) + 6 transparency obligations + 4 oversight/bias-mitigation controls.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| 41 requirements across SaMD lifecycle, PCCP, change-class triggers, transparency, and oversight | Enforced | L3 Enforceable | MHRA SaMD Program 2023 | Canonical change-controlReplay-Proof™ envelopeDecision Map™Evidence Pack™Shadow ModeEdge Governance bundle versioning |
PHIPA Ontario
S.O. 2004, c. 3, Sched. A · Canada
Ontario's health-privacy statute (PHIPA, 2004): consent + lawful purpose, circle-of-care implied consent, data minimisation, the electronic audit-log duty, access/correction, and IPC breach notification for personal health information. Per-requirement bijection at /compliance/phipa-ontario.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Consent + lawful purpose (ss.29-30, 36-38) | Enforced | L3 Enforceable | s29, s38 | Authority GateDecision Map™Purpose Permission™ |
| Data minimisation (s.30(2)) | Enforced | L3 Enforceable | s30-2 | Purpose Permission™ |
| Electronic audit log + access control (s.10.1, s.12, O.Reg.329/04 s.6.3) | Enforced | L3 Enforceable | s10.1 | WORM audit hash-chain |
| Access + correction (ss.52-55) | Enforced | L3 Enforceable | s52 | Reporting EngineWORM audit hash-chain |
| Breach + IPC notification (s.12(2)-(3)) | Designed | L2 Designed | s12-2 | Incident DetectorReporting Engine |
CDSCO MDR 2017
Medical Devices Rules, 2017, as amended · India
Where AI software qualifies as a medical device, KYE™ governs the AUTHORITY + EVIDENCE layer of clinical actions the software takes or recommends. KYE™ is OUT-OF-SCOPE for device classification, licensing, manufacturing quality systems and the clinical determination itself — those belong to the manufacturer and CDSCO (§70 §4). Deep per-requirement mapping: 5 requirements, 2 enforced by KYE™ runtime, 3 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Authority + evidence at the action boundary — enforced by KYE™ runtime and verified by CI | Enforced | L3 Enforceable | cdsco-medical-devices.CLINICAL-ACTION-AUTHORITY — Clinical actions by software resolve to a live authority and are evidenced, cdsco-medical-devices.POST-MARKET-EVIDENCE — Records supporting post-market surveillance and adverse-event review | kye.compliance.attestation.v1kye.evidence.decision_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context_seal.v1internal |
| Obligations owed directly by the regulated entity — NOT discharged by KYE™Where AI software qualifies as a medical device, KYE™ governs the AUTHORITY + EVIDENCE layer of clinical actions the software takes or recommends. KYE™ is OUT-OF-SCOPE for device classification, licensing, manufacturing quality systems and the clinical determination itself — those belong to the manufacturer and CDSCO (§70 §4). | Out of scope | L1 Mapped | cdsco-medical-devices.DEVICE-CLASSIFICATION — Risk-based classification of the device, cdsco-medical-devices.LICENSING — Manufacturing or import licence obtained and maintained, cdsco-medical-devices.QMS — Quality management system for design and manufacture | — |
Domain-specific AI accountability frameworks scoped to a single regulated sector.
API 580/581
2016 · Global
API RP 580 (RBI methodology) + API 581 (RBI quantitative technology) for fixed-equipment inspection planning. KYE Protocol™ governs the authority and evidence of an AI-recommended inspect/repair/replace action and records the inspection-interval + failure-mode reference vocabulary; KYE Protocol™ does not compute RBI risk. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| RBI decision documentation + review (contestable) | Designed | L2 Designed | api-580.10.0 | Evidence Pack™Authority Gate |
| High-consequence action named-engineer sign-off | Designed | L2 Designed | api-581.5.0 | Authority GateDecision Map™ |
Australia Group
2023 · Global
Australia Group dual-use export-control regime — harmonised control lists for dual-use biological agents, toxins, equipment, and chemical-weapon precursors. KYE Protocol™ governs whether an AI-generated design mapping to a controlled item may proceed to a consequential action — the KYE™ AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Dual-use biological control list | Designed | L2 Designed | australia-group.bio-agents, australia-group.bio-equipment | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Dual-use chemical precursor list | Designed | L2 Designed | australia-group.chem-precursors | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Controlled-item action gating | Designed | L2 Designed | australia-group.controlled-item-gate | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
BCBS 239
BCBS 239 (Principles for effective risk data aggregation and risk reporting, January 2013) · International
BCBS 239 sets the Basel Committee's 14 principles for effective risk data aggregation and risk reporting. KYE Protocol™ governs whether a model-driven output or risk report under it may proceed to a consequential action — only a currently-validated model used within its approved scope, model changes as named-authority decisions with evidence, every consequential decision pinned to model_id + version + validation reference, and every risk report bound to its data-lineage evidence chain, sealed into a signed replay-provable Evidence Pack™. The quantitative model build / validation mathematics / capital computation / portfolio composition stays the bank's own work (honest scope, §0 — not investment advice). All 14 principles are mapped one row each (honest tri-state). Per-requirement bijection at /compliance/bcbs-239.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Risk-data governance & named authority on the report (P1) | Enforced | L3 Enforceable | bcbs-239.principle1-governance | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Risk-data aggregation lineage, completeness & adaptability (P3 / P4 / P6) | Enforced | L3 Enforceable | bcbs-239.principle3-accuracy-integrity-lineage, bcbs-239.principle4-completeness, bcbs-239.principle6-adaptability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Risk-report traceability, cadence & distribution evidence (P7 / P10 / P11) | Enforced | L3 Enforceable | bcbs-239.principle7-reporting-accuracy, bcbs-239.principle10-frequency, bcbs-239.principle11-distribution | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Bank data architecture & crisis-timeliness capability (P2 / P5)The data architecture, IT infrastructure, and crisis-timeliness aggregation capability are the bank's own data and technology estate — KYE™ is an AI-authority and evidence layer, not a data platform. | Out of scope | L1 Mapped | bcbs-239.principle2-data-architecture, bcbs-239.principle5-timeliness | — |
| Report substance — comprehensiveness & clarity (P8 / P9)Judging material-risk coverage and the report's editorial quality is the bank's risk and reporting functions' own work — KYE™ proves what the report aggregated and how, not whether it covered everything that mattered. | Out of scope | L1 Mapped | bcbs-239.principle8-comprehensiveness, bcbs-239.principle9-clarity-usefulness | — |
| Supervisory review, remedial tools & home/host cooperation (P12–P14)Principles 12–14 are addressed to supervisors — conducting the review, applying supervisory measures, and home/host cooperation are regulator functions; KYE™'s sealed evidence chains support the bank's side of the review but the obligations sit outside an AI-authority-governance protocol. | Out of scope | L1 Mapped | bcbs-239.principle12-supervisory-review, bcbs-239.principle13-remedial-actions, bcbs-239.principle14-home-host-cooperation | — |
Colorado SB21-169
Colorado SB21-169 (Restrict Insurers' Use of External Consumer Data; C.R.S. §10-3-1104.9) + Division of Insurance regulations · United States
Colorado SB21-169 restricts insurers' use of external consumer data, algorithms, and predictive models to prevent unfair discrimination, and requires testing, documentation, and consumer adverse-action reasons. KYE Protocol™ governs whether an AI-assisted underwriting or claims decision relying on external data may proceed to a consequential adverse action — under a named authority, with a recorded adverse-action reason-code, with proxy-discrimination / fairness-evidence captured, a signed replay-provable Evidence Pack™ per decision, and an appeal / contestability record. The external-data selection / pricing / methodology design on the merits stays the insurer's own work (honest scope, §0). Per-requirement bijection at /compliance/colorado-sb21-169.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Adverse-action reason explainability to the consumer | Enforced | L3 Enforceable | colorado-sb21-169.adverse-action-explainability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| External-data proxy-discrimination evidence | Enforced | L3 Enforceable | colorado-sb21-169.external-data-discrimination-evidence | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Named-authority on the external-data-driven decision | Enforced | L3 Enforceable | colorado-sb21-169.external-data-decision-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| External data source selection & pricing on the meritsThe external-data selection / pricing / methodology design on the merits is the insurer's own work — KYE™ is an AI-authority and evidence layer, not a pricing or data-selection engine. | Out of scope | L1 Mapped | colorado-sb21-169.external-data-source-selection-pricing | — |
COSHH
2002 · United Kingdom
UK COSHH 2002 (SI 2002/2677), HSE-enforced. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved COSHH assessments and control instructions — the KYE™ HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| COSHH assessment authored under safety floor | Designed | L2 Designed | coshh.reg-6 | Purpose Permission™Edge Governance Safety Floor |
| Exposure-control measure advisory pending sign-off | Designed | L2 Designed | coshh.reg-7 | Authority GateDecision Map™ |
| Control-measure instruction contestable + evidenced | Designed | L2 Designed | coshh.reg-8 | Evidence Pack™Authority Gate |
CWC / BWC
1997-2024 · Global
Chemical Weapons Convention (CWC, Schedules 1/2/3) + Biological Weapons Convention (BWC, prohibited bio/toxin agents). KYE Protocol™ governs whether an AI-generated molecule or agent mapping to a scheduled/prohibited item may proceed to a consequential action — a hard stop routed to oversight, the KYE™ AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| CWC scheduled chemicals (Schedule 1/2/3) | Designed | L2 Designed | cwc-bwc.cwc-schedule1, cwc-bwc.cwc-schedule2-3 | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| BWC prohibited biological / toxin agents | Designed | L2 Designed | cwc-bwc.bwc-prohibited-agents | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Prohibited-agent action stop | Designed | L2 Designed | cwc-bwc.prohibited-agent-stop | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
DoD 5015.2
2007 · United States
DoD 5015.02-STD records-management-application spine for the KYE™ Chain of Authority™ for Iron Mountain InSight DXP. KYE Protocol™ overlays the action-boundary access-control + named-authority + governance-decision audit (enforced); the RMA record-declaration / file-plan / disposition criteria are out-of-scope (owned by the records-manager). §0: KYE Protocol™ retains PROOF-OF-GOVERNANCE, not the customer's records.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Access-control decision at the action boundary (authority overlay) | Enforced | L3 Enforceable | dod-5015-2.access-control-action-decision, dod-5015-2.named-authority-binding | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Audit of the action decision (authority overlay) | Enforced | L3 Enforceable | dod-5015-2.action-decision-audit | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Record declaration & categorisation / file plan (RMA criteria) | Out of scope | L1 Mapped | dod-5015-2.record-declaration-file-plan | — |
| Disposition & transfer (RMA criteria) | Out of scope | L1 Mapped | dod-5015-2.disposition-transfer | — |
Dodd-Frank §922
Dodd-Frank Act §922 (15 U.S.C. §78u-6) + SEC Rules 21F (whistleblower programme) · United States
Dodd-Frank §922 + SEC Rule 21F — Whistleblower Programme is the US SEC whistleblower programme (confidentiality, anti-retaliation, the Rule 21F-17 anti-impediment prohibition). KYE Protocol™ governs whether an AI-assisted access to a whistleblower's identity or a consequential case action may proceed — on a recorded need-to-know authority, with confidentiality evidence captured, a signed Evidence Pack™, and a contestability record. Assessing the securities-law tip on its merits, awarding the bounty, and adjudicating the §922 / Rule 21F claim stay with the SEC and counsel (honest scope, §0). Per-requirement bijection at /compliance/dodd-frank-whistleblower.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Confidentiality & anti-impediment evidence for a whistleblower's identity | Enforced | L3 Enforceable | dodd-frank-whistleblower.confidentiality-evidence | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & reconstruction of the handling / retaliation determination | Enforced | L3 Enforceable | dodd-frank-whistleblower.handling-contestability-reconstruction | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Securities-law merits, bounty award & Rule 21F adjudicationAssessing the tip, awarding the bounty, and adjudicating the §922 / Rule 21F claim is the SEC's and counsel's determination — KYE™ is an AI-authority and evidence layer, not an enforcement engine. | Out of scope | L1 Mapped | dodd-frank-whistleblower.securities-merits-and-award | — |
EU AI Act insurance
Regulation (EU) 2024/1689 (EU AI Act) — Annex III high-risk insurance use-cases (life & health risk assessment / pricing) · European Union
The EU AI Act classifies AI used for risk assessment and pricing in life and health insurance as high-risk (Annex III), triggering human-oversight (Art. 14), record-keeping (Art. 12), and transparency obligations. KYE Protocol™ governs whether an AI-assisted insurance decision in scope may proceed to a consequential adverse action — under a named human-oversight authority, with a recorded adverse-action reason-code, fairness-evidence captured, a signed replay-provable Evidence Pack™ (the Art. 12 log) per decision, and an appeal / contestability record. The risk pricing / system build / conformity assessment on the merits stays the provider's own work (honest scope, §0). Per-requirement bijection at /compliance/eu-ai-act-insurance.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Human oversight authority over the high-risk decision (Art. 14) | Enforced | L3 Enforceable | eu-ai-act-insurance.annex3-human-oversight | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Record-keeping / logging of the AI decision (Art. 12) | Enforced | L3 Enforceable | eu-ai-act-insurance.annex3-record-keeping-logging | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Transparency & contestability of the decision | Enforced | L3 Enforceable | eu-ai-act-insurance.annex3-transparency-contestability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Risk pricing, system build & conformity assessment on the meritsThe risk pricing / high-risk system build / Art. 43 conformity assessment on the merits is the provider's own work — KYE™ is an AI-authority and evidence layer at the action boundary, not a system-build, pricing, or conformity-assessment engine. | Out of scope | L1 Mapped | eu-ai-act-insurance.risk-pricing-system-build-conformity | — |
EU Evidence Reg
Regulation (EU) 2020/1783 (taking of evidence in civil/commercial matters) + eIDAS Regulation (EU) 910/2014 (electronic evidence integrity) · European Union
EU Evidence Regulation 2020/1783 + eIDAS — Evidence Authenticity & Transmission is the EU cross-border evidence and electronic-integrity framework (Regulation 2020/1783 + eIDAS). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/eu-evidence-regulation.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Chain-of-custody & integrity for cross-border evidence transmission | Enforced | L3 Enforceable | eu-evidence-regulation.evidence-authenticity-transmission | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Integrity-bound, contestable Evidence Pack™ (eIDAS-aligned) | Enforced | L3 Enforceable | eu-evidence-regulation.eidas-integrity-evidence-pack | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Member-State admissibility & substantive evidential assessmentThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. | Out of scope | L1 Mapped | eu-evidence-regulation.member-state-admissibility | — |
EU Whistleblower Dir.
Directive (EU) 2019/1937 (protection of persons who report breaches of Union law) · European Union
EU Whistleblower Directive — Directive (EU) 2019/1937 is the EU whistleblower-protection framework (confidentiality, acknowledgement / feedback clocks, prohibition of retaliation). KYE Protocol™ governs whether an AI-assisted intake-triage decision, an access to a reporter's identity / PII, a case disposition (close / escalate), or an adverse action on a reporter may proceed to a consequential action — under a named handler's authority, on a recorded need-to-know basis, with confidentiality and retaliation-risk evidence captured, a signed replay-provable Evidence Pack™ per consequential action, and a contestability record so any disposition can be reconstructed and challenged. The substantive investigation / allegation merits / remediation decision stays the organisation's own work (honest scope, §0). Per-requirement bijection at /compliance/eu-whistleblower-directive.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Confidentiality & need-to-know access to a reporter's identity | Enforced | L3 Enforceable | eu-whistleblower-directive.confidentiality-need-to-know-access | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Named-authority on the case disposition (acknowledgement / feedback clocks) | Enforced | L3 Enforceable | eu-whistleblower-directive.case-disposition-named-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & reconstruction of the handling | Enforced | L3 Enforceable | eu-whistleblower-directive.handling-contestability-reconstruction | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive investigation & whether the breach occurredInvestigating the report on its merits and deciding the remediation is the organisation's own ethics / legal work — KYE™ is an AI-authority and evidence layer, not an investigation or adjudication engine. | Out of scope | L1 Mapped | eu-whistleblower-directive.substantive-investigation | — |
Fed SR 11-7
SR 11-7 / OCC 2011-12 (Supervisory Guidance on Model Risk Management, April 2011) · United States
Fed SR 11-7 / OCC 2011-12 is the US supervisory guidance on model risk management (development, validation, governance). KYE Protocol™ governs whether a model-driven output or risk report under it may proceed to a consequential action — only a currently-validated model used within its approved scope, model changes as named-authority decisions with evidence, every consequential decision pinned to model_id + version + validation reference, and every risk report bound to its data-lineage evidence chain, sealed into a signed replay-provable Evidence Pack™. The quantitative model build / validation mathematics / capital computation / portfolio composition stays the bank's own work (honest scope, §0 — not investment advice). Per-requirement bijection at /compliance/fed-sr-11-7.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Validated-model use authority at the decision boundary | Enforced | L3 Enforceable | fed-sr-11-7.model-use-named-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Model change control as a named-authority decision | Enforced | L3 Enforceable | fed-sr-11-7.model-change-control | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Decision traceability to model version & validation reference | Enforced | L3 Enforceable | fed-sr-11-7.decision-provenance-traceability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Model inventory & policy controls on model use | Enforced | L3 Enforceable | fed-sr-11-7.inventory-policy-controls | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Quantitative model development, validation & capital mathematicsThe quantitative model build, validation mathematics, and capital & liquidity computation are the bank's own quantitative work — KYE™ is an AI-authority and evidence layer, not a model-validation or capital-calculation engine. | Out of scope | L1 Mapped | fed-sr-11-7.quantitative-development-validation | — |
OCC AI Supervision
2024 · United States
The U.S. Office of the Comptroller of the Currency (OCC) supervises national banks and federal savings associations. Its supervisory expectations for a bank deploying consequential AI draw on OCC Bulletin 2011-12 (model risk management, joint with Fed SR 11-7), OCC Bulletin 2013-29 + the 2023 Interagency Third-Party Risk Management Guidance, OCC heightened standards for risk governance, and the OCC's new-activity / examiner-engagement expectations. KYE Protocol™ governs the action-boundary subset at runtime — only a consequential AI action under its approved use and recorded authority proceeds, out-of-scope actions escalate or are refused, and every action that proceeds is replay-provable to an OCC examiner from public keys alone. KYE™ operationalises the OCC's expectations — it does NOT replace them (§0.25 integrate-not-compete). Honest scope: KYE™ does NOT run the bank's MRM program, validate models, make the bank's regulatory filing, or judge whether the AI's output is correct; that work, and the OCC's own supervisory determinations, stay out of scope. Broader, separate spine from the fed-sr-11-7 MRM-only row (references SR 11-7 lineage, does not duplicate it). Per-requirement bijection at /compliance/occ-ai-supervision.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Model risk management (approved-use authority + model-change as a named-authority decision) | Enforced | L3 Enforceable | occ-ai-supervision.validated-use-authority-at-the-decision-boundary, occ-ai-supervision.model-change-as-named-authority-decision | Purpose Permission™Authority GatewayGovernedUI™ named-authority sign-offEvidence Pack™ |
| Third-party / vendor AI risk (external authority register + escalation before finality)KYE™ governs what external/vendor AI is authorised to DO inside the bank's action boundary; vendor due-diligence and contract review on the merits stay the bank's own (honest scope). | Enforced | L3 Enforceable | occ-ai-supervision.third-party-ai-authority-register, occ-ai-supervision.out-of-scope-escalation-before-finality | Authority RegisterAuthority Gateway (REQUIRE_APPROVAL)Edge Governance Safety FloorGovernedUI™ escalation |
| New-activity / filing & examiner readiness (replay-provable Evidence Packs + action-authority inventory)KYE™ proves to an OCC examiner how each consequential AI action was governed; making the regulatory filing and the OCC's supervisory determinations stay out of scope (honest scope). | Enforced | L3 Enforceable | occ-ai-supervision.new-activity-examiner-replayable-evidence, occ-ai-supervision.action-authority-inventory | Evidence Pack™Replay-Proof™WORM audit hash-chainEntity & Principal Registry |
| Heightened-standards governance & accountability (named accountability at the action boundary)KYE™ binds and proves named accountability at the boundary; staffing and running the bank's three-lines-of-defence operating model stays the bank's own (honest scope). | Enforced | L3 Enforceable | occ-ai-supervision.heightened-standards-named-accountability | GovernedUI™ named-authority sign-offDelegated Auditability RailAuthority Finality™ |
| Model development, validation & supervisory determinationsDeveloping and validating the model, running the bank's MRM program, making the regulatory filing, and the OCC's own supervisory determinations / examination ratings are the bank's and the regulator's own work — KYE™ is an AI-authority and evidence layer, not a model-validation engine, a filing service, or a supervisor. | Out of scope | L1 Mapped | occ-ai-supervision.model-development-validation-supervisory-determinations | — |
FRCP e-discovery
FRCP (2015 e-discovery amendments; Rules 26 / 34 / 37 + FRE 502) · United States
FRCP e-Discovery — Rules 26 / 34 / 37 + FRE 502 (privilege) is the US federal e-discovery and privilege framework (FRCP 26 / 34 / 37 + FRE 502). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/frcp-ediscovery.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Named-authority on the privilege / discovery determination | Enforced | L3 Enforceable | frcp-ediscovery.rule26g-discovery-certification | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Discovery chain-of-custody for produced / withheld ESI | Enforced | L3 Enforceable | frcp-ediscovery.rule34-esi-chain-of-custody | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & sanctions-reconstruction of the determination | Enforced | L3 Enforceable | frcp-ediscovery.rule37-sanctions-reconstruction | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive privilege judgment & attorney certification on the meritsThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. | Out of scope | L1 Mapped | frcp-ediscovery.substantive-privilege-judgment | — |
FRE 901/902
FRE 901 / 902 (Authentication & Self-Authentication; 2017 ESI amendments) · United States
FRE 901 / 902 — Authentication & Self-Authentication of Evidence is the US evidence-authentication framework (FRE 901 / 902). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/fre-authentication.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| No-hallucinated-citation provenance pin for AI assertions | Enforced | L3 Enforceable | fre-authentication.rule901-authentication-evidence | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Hash-bound self-authenticating Evidence Pack™ | Enforced | L3 Enforceable | fre-authentication.rule902-self-authenticating-record | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive admissibility, relevance & weight of the evidenceThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. | Out of scope | L1 Mapped | fre-authentication.substantive-admissibility | — |
ABA Model Rules
Rules 1.1 / 1.4 / 1.5 / 1.6 / 5.1 / 5.3 + ABA Formal Opinion 512 (2023) · United States
The ABA Model Rules of Professional Conduct set the US legal profession's core duties — competence (Rule 1.1, incl. technological competence), communication (1.4), reasonable fees (1.5), confidentiality (1.6), and supervision of subordinate lawyers and non-lawyer assistance (5.1 & 5.3) — extended to generative AI by ABA Formal Opinion 512 (2023) and state-bar guidance (California 2023, NYSBA 2024). KYE Protocol™ governs whether an AI-assisted legal action supporting each duty may proceed to a consequential step — under a named lawyer's authority, with the verification, confidentiality-isolation, communication and supervisory-accountability record captured as a signed, replay-provable Evidence Pack™ that predates the incident. Each AI-relevant duty is mapped onto the existing KYE™ Legal Pack™ (kye:sector-pack:legal) workflows at the requirement level and marked designed (authority boundary bound, no runtime engine wired yet), except the reasonable-fees duty (Rule 1.5), which has no KYE™ artefact governing legal billing and is honestly out of scope. KYE™ governs the AUTHORITY BOUNDARY of the AI action — NOT wholesale compliance with a professional-conduct duty, and NOT the practice of law: it does not draft, advise, judge attorney conduct, or render the lawyer's professional judgment. Per-requirement bijection at /compliance/aba-model-rules.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Competence — verified AI work product authority (Rule 1.1) | Designed | L2 Designed | aba-model-rules.rule-1-1-competence | Purpose Permission™Authority GateEvidence Pack™ |
| Client communication release authority (Rule 1.4) | Designed | L2 Designed | aba-model-rules.rule-1-4-communication | Purpose Permission™Evidence Pack™ |
| Confidentiality & client-information isolation (Rule 1.6) | Designed | L2 Designed | aba-model-rules.rule-1-6-confidentiality | Authority GateZero Contamination |
| Supervisory responsibility & firm AI-governance record (Rules 5.1 & 5.3) | Designed | L2 Designed | aba-model-rules.rule-5-1-5-3-supervision | Delegated AuditabilityGovernedUI™Evidence Pack™ |
| Generative-AI use authority boundary (Formal Opinion 512) | Designed | L2 Designed | aba-model-rules.formal-opinion-512-genai | Purpose Permission™Evidence Pack™GovernedUI™ |
| Reasonable fees (Rule 1.5)No KYE™ artefact governs legal billing or fee reasonableness — the firm's own regulated determination. Honest out-of-scope (§0); coverage never inflated. | Out of scope | L1 Mapped | aba-model-rules.rule-1-5-fees | — |
GDPR Whistleblowing
Regulation (EU) 2016/679 (GDPR) — whistleblowing data-protection slice (Art. 5, 6, 9, 15, 21) · European Union
GDPR (Whistleblowing) — Special-Category & Data-Minimisation in Reports is the data-protection slice of whistleblowing (data minimisation, special-category restriction, need-to-know access, data-subject access / objection). KYE Protocol™ governs whether an AI-assisted access to the personal / special-category data in a report may proceed — on a recorded need-to-know authority, with data-minimisation evidence captured, a signed Evidence Pack™, and a contestability record so a data-subject access or objection can be reconstructed. The lawful-basis assessment of the underlying processing, the DPIA, and data-subject adjudication stay with the controller / DPO / supervisory authority (honest scope, §0). Per-requirement bijection at /compliance/gdpr-whistleblower.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Need-to-know access & data-minimisation evidence for special-category report data | Enforced | L3 Enforceable | gdpr-whistleblower.special-category-need-to-know-access | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Data-subject contestability (access / objection) reconstruction | Enforced | L3 Enforceable | gdpr-whistleblower.data-subject-contestability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Lawful-basis assessment, DPIA & data-subject adjudicationThe lawful-basis assessment, the DPIA, and data-subject adjudication is the controller's / DPO's / supervisory authority's determination — KYE™ is an AI-authority and evidence layer, not a data-protection-compliance engine. | Out of scope | L1 Mapped | gdpr-whistleblower.lawful-basis-and-dpia | — |
ICH Q1
ICH Q1A(R2) (2003) · International
ICH Q1 — Stability Testing is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q1.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Authority over an AI stability summary at the action boundary | Designed | L2 Designed | ich-q1.named-authority | Purpose Permission™Authority Gate |
| Stability study science & shelf-life determinationThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. | Out of scope | L1 Mapped | ich-q1.science | — |
ICH Q10
ICH Q10 (2008) · International
ICH Q10 — Pharmaceutical Quality System is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q10.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Management responsibility & named-authority | Enforced | L3 Enforceable | ich-q10.management-responsibility-authority | Authority GateDecision replayEvidence Pack™ |
| Change-management authority at the action boundary | Enforced | L3 Enforceable | ich-q10.change-management-authority | Authority GateDecision replayEvidence Pack™ |
| Management review control (sign-off gate) | Enforced | L3 Enforceable | ich-q10.management-review-control | Authority GateDecision replayEvidence Pack™ |
| Personnel competence recorded before the action | Designed | L2 Designed | ich-q10.personnel-competence | Purpose Permission™Authority Gate |
| Quality-system substance (CAPA / change science)The scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. | Out of scope | L1 Mapped | ich-q10.quality-system-substance | — |
ICH Q2
ICH Q2(R2) (2023) · International
ICH Q2(R2) — Validation of Analytical Procedures is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q2.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Validation-package authority at the action boundary | Enforced | L3 Enforceable | ich-q2.validation-package-authority | Authority GateDecision replayEvidence Pack™ |
| Validation-conclusion justification recorded before the action | Enforced | L3 Enforceable | ich-q2.validation-conclusion-justification | Authority GateDecision replayEvidence Pack™ |
| Replay-provable validation-package provenance | Enforced | L3 Enforceable | ich-q2.validation-package-provenance | Authority GateDecision replayEvidence Pack™ |
| Analytical-method science & validation statisticsThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. | Out of scope | L1 Mapped | ich-q2.analytical-method-science | — |
ICH Q3
ICH Q3 family · International
ICH Q3 — Impurities is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q3.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Authority over an AI impurity-assessment summary at the action boundary | Designed | L2 Designed | ich-q3.named-authority | Purpose Permission™Authority Gate |
| Impurity science & threshold determinationThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. | Out of scope | L1 Mapped | ich-q3.science | — |
ICH Q5
ICH Q5 family · International
ICH Q5 — Quality of Biotechnological Products is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q5.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Authority over an AI biotech-quality summary at the action boundary | Designed | L2 Designed | ich-q5.named-authority | Purpose Permission™Authority Gate |
| Biotech product science (viral safety / comparability / stability)The scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. | Out of scope | L1 Mapped | ich-q5.science | — |
ICH Q6
ICH Q6 family · International
ICH Q6 — Specifications is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q6.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Authority over an AI specification-justification summary at the action boundary | Designed | L2 Designed | ich-q6.named-authority | Purpose Permission™Authority Gate |
| Specification science & acceptance-criteria settingThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. | Out of scope | L1 Mapped | ich-q6.science | — |
ICH Q7
ICH Q7 (2000) · International
ICH Q7 — GMP for Active Pharmaceutical Ingredients is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q7.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Quality-Unit release authority at the action boundary | Enforced | L3 Enforceable | ich-q7.quality-unit-batch-release | Authority GateDecision replayEvidence Pack™ |
| Records & data integrity (ALCOA+) screened before the action | Enforced | L3 Enforceable | ich-q7.data-integrity-alcoa | Authority GateDecision replayEvidence Pack™ |
| Replay-provable GMP-record provenance | Enforced | L3 Enforceable | ich-q7.gmp-record-provenance | Authority GateDecision replayEvidence Pack™ |
| Batch release sign-off gate (§36 two-person) | Enforced | L3 Enforceable | ich-q7.batch-release-signoff | Authority GateDecision replayEvidence Pack™ |
| Physical API manufacture & analytical testingThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. | Out of scope | L1 Mapped | ich-q7.physical-api-manufacture | — |
ICH Q8
ICH Q8(R2) (2009) · International
ICH Q8(R2) — Pharmaceutical Development is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q8.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Development-content authority at the action boundary | Enforced | L3 Enforceable | ich-q8.development-justification-provenance | Authority GateDecision replayEvidence Pack™ |
| Development justification recorded before the action | Enforced | L3 Enforceable | ich-q8.justification-recorded-before-action | Authority GateDecision replayEvidence Pack™ |
| Replay-provable development-content provenance | Enforced | L3 Enforceable | ich-q8.development-content-provenance | Authority GateDecision replayEvidence Pack™ |
| Development science (QbD / design space / control strategy)The scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. | Out of scope | L1 Mapped | ich-q8.development-science | — |
ICH Q9
ICH Q9(R1) (2023) · International
ICH Q9(R1) — Quality Risk Management is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q9.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Risk-based decision authority at the action boundary | Enforced | L3 Enforceable | ich-q9.qrm-decision-authority | Authority GateDecision replayEvidence Pack™ |
| Risk-decision justification recorded before the action | Enforced | L3 Enforceable | ich-q9.risk-decision-justification | Authority GateDecision replayEvidence Pack™ |
| Replay-provable QRM provenance | Enforced | L3 Enforceable | ich-q9.qrm-provenance | Authority GateDecision replayEvidence Pack™ |
| Risk-assessment science & control-strategy selectionThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. | Out of scope | L1 Mapped | ich-q9.risk-assessment-science | — |
IEC 61508
2010 · Global
The umbrella functional-safety standard defining Safety Integrity Levels (SIL 1-4) and the safety lifecycle. KYE Protocol™ governs the authority, evidence and finality of an AI-recommended physical-safety action against a SIL-validated model-authority claim; KYE Protocol™ does not perform the SIL determination. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| SIL-validated model authority + safety floor | Designed | L2 Designed | iec-61508.part-1.7.6 | Purpose Permission™Edge Governance Safety Floor |
| Functional-safety decision evidence + named accountability | Designed | L2 Designed | iec-61508.part-1.7.14 | Evidence Pack™Reporting Engine |
| Contestable verification outcomes | Designed | L2 Designed | iec-61508.part-3.7.9 | Evidence Pack™Authority Gate |
IEC 61511
2016 · Global
The process-sector application of IEC 61508 defining safety instrumented systems (SIS). KYE Protocol™ governs the authority and finality of an AI-recommended physical-safety action (turbine trip, unit shutdown, derate) under the safety floor. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| SIS actuating decision under safety floor | Designed | L2 Designed | iec-61511.clause-11.3 | Purpose Permission™Edge Governance Safety Floor |
| Operation & maintenance named accountability | Designed | L2 Designed | iec-61511.clause-16.2 | Authority GateDecision Map™ |
| Contestable / reviewable SIS decisions | Designed | L2 Designed | iec-61511.clause-11.9 | Evidence Pack™Authority Gate |
ISO 21448
2022 · Global
The companion to ISO 26262 governing the residual risk of a fault-free intended function (e.g. an ADAS / autonomous perception or decision function) operating at the edge of, or outside, its specified operating envelope. KYE Protocol™ governs the authority, the operating-envelope (control / safety-floor) admissibility, the evidence and the finality of an AI-recommended action against a declared intended-functionality envelope, with Replay-Proof™ failure-path reconstruction; KYE Protocol™ does not perform the SOTIF hazard analysis, triggering-condition identification, or the model's internal failure-mechanism analysis. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Operating-envelope (control / safety-floor) action admissibility | Designed | L2 Designed | iso-21448.clause-6 | Purpose Permission™Edge Governance Safety Floor |
| Replay-derivable intended-functionality decision evidence | Designed | L2 Designed | iso-21448.clause-10 | Evidence Pack™Reporting Engine |
| Named accountability + contestable outcomes | Designed | L2 Designed | iso-21448.clause-11 | Authority GateEvidence Pack™ |
Law Society Protocol
Conveyancing Protocol · United Kingdom
The Law Society of England & Wales — Conveyancing Protocol. KYE Protocol™ governs the AUTHORITY of an AI agent to take or finalise a protocol step, the client-due-diligence / source-of-funds EVIDENCE boundary (binding the deep-mapped uk-mlr-2017 store, not re-mapping it), and the replay-derivable transaction file; KYE Protocol™ does not perform the searches, draft the enquiries, or determine the legal correctness of the conveyance. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Protocol-step authority / finality on AI-assisted steps | Designed | L2 Designed | law-society-conveyancing-protocol.step-authority | Purpose Permission™Authority Gate |
| Client due diligence + source-of-funds evidence | Designed | L2 Designed | law-society-conveyancing-protocol.cdd-source-of-funds | Evidence Pack™ |
| Replay-derivable transaction file | Designed | L2 Designed | law-society-conveyancing-protocol.replay-file | Evidence Pack™Replay-Proof™ |
| Legal correctness of searches / enquiries | Out of scope | L1 Mapped | law-society-conveyancing-protocol.searches-enquiries-correctness | — |
CLC Code
Code of Conduct · United Kingdom
Council for Licensed Conveyancers (CLC) — Code of Conduct. KYE Protocol™ governs the AUTHORITY of an AI agent to act in the client's interest, named-accountable conveyancer sign-off, the confidentiality / isolation boundary, and the EVIDENCE boundary around client-money handling; KYE Protocol™ does not reconcile the client account, hold money, or determine CLC compliance. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Act-in-client-best-interest authority | Designed | L2 Designed | clc-code-of-conduct.client-best-interest | Purpose Permission™Authority Gate |
| Named accountable conveyancer sign-off | Designed | L2 Designed | clc-code-of-conduct.named-conveyancer-signoff | Delegated Auditability |
| Confidentiality and isolation of client matters | Designed | L2 Designed | clc-code-of-conduct.confidentiality | Authority Gate |
| Client-money handling evidence boundary | Designed | L2 Designed | clc-code-of-conduct.client-money | Evidence Pack™ |
HM Land Registry
Registration & Digital Identity Standard · United Kingdom
HM Land Registry — registration requirements and the Digital Identity Standard (Safe Harbour). KYE Protocol™ governs the AUTHORITY of an AI agent to take a digital-identity-verification or application-submission action and the Safe Harbour EVIDENCE / replay boundary; KYE Protocol™ does not perform the identity-check determination, run the verification technology, or determine HMLR registration correctness. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Digital-identity verification action admissibility (Safe Harbour) | Designed | L2 Designed | hm-land-registry.digital-identity-admissibility | Purpose Permission™Evidence Pack™ |
| Application-submission authority | Designed | L2 Designed | hm-land-registry.application-submission-authority | Authority Gate |
| Replay-derivable submission record | Designed | L2 Designed | hm-land-registry.replay-submission-record | Evidence Pack™Replay-Proof™ |
| The conveyancer's identity-check determination | Out of scope | L1 Mapped | hm-land-registry.identity-check-determination | — |
Homes England CFG
Capital Funding Guide — Shared Ownership · United Kingdom
Homes England — Capital Funding Guide (Shared Ownership + model lease). KYE Protocol™ governs the AUTHORITY of an AI agent to take a shared-ownership eligibility-decision action, the affordability / sustainability EVIDENCE boundary, and named-accountable sign-off / contestability; KYE Protocol™ does not make the eligibility determination, run the affordability assessment, or judge model-lease compliance. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Shared-ownership eligibility-decision authority | Designed | L2 Designed | homes-england-cfg.eligibility-authority | Purpose Permission™Authority Gate |
| Affordability / sustainability evidence | Designed | L2 Designed | homes-england-cfg.affordability-sustainability-evidence | Evidence Pack™ |
| Named-accountable sign-off and contestability | Designed | L2 Designed | homes-england-cfg.named-signoff-contestable | Delegated Auditability |
| Model-lease compliance determination | Out of scope | L1 Mapped | homes-england-cfg.model-lease-compliance | — |
ISO 14001
2015 · Global
ISO 14001:2015 environmental management system. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved environmental HSE instructions that discharge an EMS control — the KYE™ HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Environmental operational control under safety floor | Designed | L2 Designed | iso-14001.8.1 | Purpose Permission™Edge Governance Safety Floor |
| Environmental emergency instruction scope-bound | Designed | L2 Designed | iso-14001.8.2 | Purpose Permission™Authority Gate |
| Compliance evaluation contestable + evidenced | Designed | L2 Designed | iso-14001.9.1.2 | Evidence Pack™Authority Gate |
ISO 15489
2016 · Global
ISO 15489-1:2016 records-management spine for the KYE™ Chain of Authority™ for Iron Mountain InSight DXP. Iron Mountain governs INFORMATION (records, custody, retention, classification); KYE Protocol™ governs ACTION — who was authorised to act on a record at the moment it drives a consequential AI action, evidenced, final, revocable. The authentic/reliable-records-at-the-action-boundary requirements are KYE Protocol™'s job (enforced); records storage / capture / retention / disposition are records-management's job (out-of-scope, owned by the records-manager / information-custodian).
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Records authenticity & reliability (authority overlay) | Enforced | L3 Enforceable | iso-15489.authenticity-authority-binding, iso-15489.reliability-evidence-pin | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Records access & permissions (authority overlay) | Enforced | L3 Enforceable | iso-15489.access-permission-overlay | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Records creation, capture & metadata (records-management) | Out of scope | L1 Mapped | iso-15489.records-capture-metadata | — |
| Retention schedule & disposition authority (records-management) | Out of scope | L1 Mapped | iso-15489.retention-disposition-authority | — |
| Records storage & preservation (records-management) | Out of scope | L1 Mapped | iso-15489.storage-preservation | — |
ISO 16175
2020 · Global
ISO 16175-1:2020 digital-records-software spine for the KYE™ Chain of Authority™ for Iron Mountain InSight DXP. KYE Protocol™ overlays the action-boundary access-control decision + the governance-decision audit trail (enforced); the records-software capture / classification / retention functions are out-of-scope (owned by Iron Mountain InSight DXP). §0: Iron Mountain proves where information travelled; KYE Protocol™ proves who was authorised to act on it.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Action-decision audit trail (authority overlay) | Enforced | L3 Enforceable | iso-16175.action-audit-trail, iso-16175.replayable-decision-record | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Access-control decision at the action boundary (authority overlay) | Enforced | L3 Enforceable | iso-16175.access-control-decision | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Capture & classification functional requirements (records-software) | Out of scope | L1 Mapped | iso-16175.capture-classification-functional | — |
| Retention & disposition functional requirements (records-software) | Out of scope | L1 Mapped | iso-16175.retention-disposition-functional | — |
ISO 17025
2017 · International
ISO/IEC 17025:2017 sets the general requirements for the competence, impartiality and consistent operation of testing and calibration laboratories. KYE Protocol™ enforces the §7.11 data-management integrity, §7.5/§7.8 technical-record reproducibility and audit-trail slices where a laboratory uses AI-supported decisioning — metrology, equipment and competence stay the laboratory's technical system. Per-requirement bijection at /compliance/iso-17025.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Control of data & information management (7.11) | Enforced | L3 Enforceable | iso-17025.7.11-data-management | WORM audit hash-chain |
| Technical records & integrity of results (7.5, 7.8) | Enforced | L3 Enforceable | iso-17025.7.5-technical-records | Decision replayEvidence Pack™ |
| Control of management-system records & audit trail (8.4) | Designed | L2 Designed | iso-17025.8.4-management-records | WORM audit hash-chain |
| Impartiality & authority over automated decisions (4.1, 6.2) | Enforced | L3 Enforceable | iso-17025.4.1-impartiality-authority | Purpose Permission™Authority Gate |
| Metrological traceability, measurement uncertainty, equipment & competenceMetrological traceability, measurement uncertainty, equipment calibration and technical competence are the laboratory's own technical/metrology system — out of scope for an AI-authority-governance protocol. | Out of scope | L1 Mapped | iso-17025.6.5-traceability, iso-17025.6.3-equipment-competence | — |
ISO/IEC 27035
ISO/IEC 27035 — Information security incident management · International
ISO/IEC 27035 is the international standard for information-security incident management, including careful incident-evidence handling. KYE Protocol™ governs whether an AI-assisted incident decision under it may proceed to a consequential action — under a named accountable officer's authority, with incident-evidence chain-of-custody recorded, the assessment pinned to verifiable signal sources, a signed replay-provable Evidence Pack™ per decision, and a contestability record for the lessons-learned reconstruction. Detection / response tooling / forensic analysis stays the organisation's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/iso-27035.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Incident-evidence chain-of-custody (evidence handling) | Enforced | L3 Enforceable | iso-27035.evidence-chain-of-custody | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Named-authority on the assessment-and-decision response | Enforced | L3 Enforceable | iso-27035.assessment-decision-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & lessons-learned reconstruction | Enforced | L3 Enforceable | iso-27035.lessons-learned-reconstruction | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Detection, response tooling & forensic analysisThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. | Out of scope | L1 Mapped | iso-27035.detection-response-forensics | — |
ISO 45001
2018 · Global
ISO 45001:2018 occupational health & safety management system. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved safety-critical HSE documents (permits-to-work, risk assessments, method statements) that discharge an OH&S control — the KYE™ HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Operational planning & control under safety floor | Designed | L2 Designed | iso-45001.8.1 | Purpose Permission™Edge Governance Safety Floor |
| Hierarchy-of-controls selection advisory pending sign-off | Designed | L2 Designed | iso-45001.8.1.2 | Authority GateDecision Map™ |
| Emergency-preparedness instruction scope-bound | Designed | L2 Designed | iso-45001.8.2 | Purpose Permission™Authority Gate |
| Incident / corrective action contestable + evidenced | Designed | L2 Designed | iso-45001.10.2 | Evidence Pack™Authority Gate |
ISO 55000
2014 · Global
ISO 55000/55001 asset-management system requirements. KYE Protocol™ governs the authority, evidence and finality of AI-recommended asset-management actions and the scope of the AI's authority over the asset portfolio. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Asset-management objectives + scoped decision authority | Designed | L2 Designed | iso-55001.6.2.1 | Authority GateDecision Map™ |
| Planned actions — finality + named accountability | Designed | L2 Designed | iso-55001.6.2.2 | Purpose Permission™Edge Governance Safety Floor |
| Contestable performance review | Designed | L2 Designed | iso-55001.9.1 | Evidence Pack™Authority Gate |
Mastercard Disputes
Mastercard Chargeback Standards — Dispute Resolution & Arbitration (Chargeback Guide) · Global
The Mastercard Chargeback Standards govern the dispute lifecycle — first chargeback, second presentment with supporting documentation, pre-arbitration, and arbitration on the documented record. KYE Protocol™ governs whether the second presentment / case filing may proceed — under a named owner's recorded authority, with the supporting evidence captured as evidence events at transaction time, and the bundle sealed as a signed, hash-bound, WORM-retained, replay-verifiable Evidence Pack™ so the documented record survives arbitration scrutiny. Whether to fight, the narrative, and the outcome stay the merchant's / network's own (honest scope, §0). Per-requirement bijection at /compliance/mastercard-dispute-rules.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Second-presentment evidence captured at transaction time | Enforced | L3 Enforceable | mastercard-dispute-rules.second-presentment-evidence-capture | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Named-authority on the chargeback response | Enforced | L3 Enforceable | mastercard-dispute-rules.chargeback-response-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Arbitration-grade reconstruction of the dispute record | Enforced | L3 Enforceable | mastercard-dispute-rules.arbitration-reconstruction-record | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Dispute merits adjudication & strategyWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. | Out of scope | L1 Mapped | mastercard-dispute-rules.dispute-merits-adjudication | — |
MoReq2010
2011 · European Union
MoReq2010 records-system spine for the KYE™ Chain of Authority™ for Iron Mountain InSight DXP. KYE Protocol™ overlays the action-boundary access-control service + entity-event governance-decision audit + custody→authority binding (enforced); the records-system classification / search / retention / disposition core services are out-of-scope (owned by Iron Mountain InSight DXP).
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Access-control service at the action boundary (authority overlay) | Enforced | L3 Enforceable | moreq-2010.access-control-service-overlay, moreq-2010.custody-to-authority-binding | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Entity-event audit of the action decision (authority overlay) | Enforced | L3 Enforceable | moreq-2010.entity-event-action-audit | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Classification & search core service (records-system) | Out of scope | L1 Mapped | moreq-2010.classification-search-service | — |
| Retention & disposition core service (records-system) | Out of scope | L1 Mapped | moreq-2010.retention-disposition-service | — |
MSHA
2024 · United States
US MSHA standards under 30 CFR governing surface and underground mine safety. KYE Protocol™ governs the authority, evidence and finality of AI-recommended physical-safety actions on mine equipment (e.g. mine-hoist stop). Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Mine-equipment actuation under safety floor | Designed | L2 Designed | msha.30-cfr-56.18002 | Purpose Permission™Edge Governance Safety Floor |
| Hoisting stop named accountability | Designed | L2 Designed | msha.30-cfr-57.19021 | Authority GateDecision Map™ |
| Contestable equipment-safety decisions | Designed | L2 Designed | msha.30-cfr-75.1725 | Evidence Pack™Authority Gate |
NAIC AI Bulletin
NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (adopted December 2023) · United States
The NAIC Model Bulletin on the Use of AI by Insurers is the US insurer-AI governance expectation (written AIS Program, named accountability, documentation, unfair-discrimination testing). KYE Protocol™ governs whether an AI-assisted underwriting or claims decision under it may proceed to a consequential adverse action — under a named underwriter's / adjuster's authority, with a recorded adverse-action reason-code, with proxy-discrimination / fairness-evidence captured, a signed replay-provable Evidence Pack™ per decision, and an appeal / contestability record so any decision can be reconstructed and contested. The actuarial pricing / risk-appetite / model design on the merits stays the insurer's own work (honest scope, §0). Per-requirement bijection at /compliance/naic-model-bulletin-ai.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Named accountability & governance of the AI decision | Enforced | L3 Enforceable | naic-model-bulletin-ai.governance-named-accountability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Adverse-action explainability & documentation | Enforced | L3 Enforceable | naic-model-bulletin-ai.adverse-action-documentation | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Unfair-discrimination testing evidence | Enforced | L3 Enforceable | naic-model-bulletin-ai.unfair-discrimination-testing | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Actuarial pricing, risk appetite & model design on the meritsThe actuarial pricing / risk-appetite / model design on the merits is the insurer's own work — KYE™ is an AI-authority and evidence layer, not a pricing, actuarial, or risk-modelling engine. | Out of scope | L1 Mapped | naic-model-bulletin-ai.actuarial-pricing-model-design | — |
NERC CIP
2024 · United States
NERC CIP reliability standards governing cyber security of the North American bulk electric system. KYE Protocol™ governs the authority, evidence and finality of an AI-recommended physical-safety action on grid assets and the scope boundary of the AI's authority. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Controlled actuation of BES assets under safety floor | Designed | L2 Designed | nerc-cip.cip-007-6.r1 | Purpose Permission™Edge Governance Safety Floor |
| Purpose-scoped authority for grid actions | Designed | L2 Designed | nerc-cip.cip-004-6.r4 | Authority GateDecision Map™ |
| Contestable + evidenced incident decisions | Designed | L2 Designed | nerc-cip.cip-008-6.r1 | Evidence Pack™Authority Gate |
NIS2 Incident
NIS2 — Directive (EU) 2022/2555, Article 23 · European Union
NIS2 Incident Reporting (Directive (EU) 2022/2555, Article 23) is the EU 24-hour / 72-hour staged-notification regime for significant incidents. KYE Protocol™ governs whether an AI-assisted disclosure-timing decision or containment action under it may proceed to a consequential incident action — under a named accountable officer's authority, with chain-of-custody recorded, and a contestability record so the timing decision can be reconstructed and challenged. Incident detection / impact analysis stays the entity's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/nis2-incident.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Disclosure-timing authority on the 24h / 72h notification clock | Enforced | L3 Enforceable | nis2-incident.notification-clock-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Incident-evidence chain-of-custody for the notification | Enforced | L3 Enforceable | nis2-incident.notification-evidence-custody | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Incident detection & impact analysisThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. | Out of scope | L1 Mapped | nis2-incident.detection-impact-analysis | — |
NIST CSF 2.0 RS/RC
NIST Cybersecurity Framework 2.0 (2024) — RESPOND (RS) + RECOVER (RC) · United States
NIST CSF 2.0 RESPOND & RECOVER is the incident-management, analysis, and recovery half of the NIST Cybersecurity Framework 2.0. KYE Protocol™ governs whether an AI-assisted response / recovery action under it may proceed to a consequential incident action — under a named accountable officer's authority, with the incident analysis pinned to verifiable signal sources, chain-of-custody recorded, a signed replay-provable Evidence Pack™ per decision, and a contestability record. Threat detection (DETECT) / response tooling / recovery execution stays the organisation's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/nist-csf-2-respond-recover.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Named-authority on the RESPOND/RECOVER action (RS.MA / RC.RP) | Enforced | L3 Enforceable | nist-csf-2-respond-recover.rs-action-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Incident-analysis source pin (RS.AN) | Enforced | L3 Enforceable | nist-csf-2-respond-recover.rs-incident-evidence | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & post-incident reconstruction (RS.MA / improvement) | Enforced | L3 Enforceable | nist-csf-2-respond-recover.rs-contestability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Threat detection (DETECT) & recovery execution toolingThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. | Out of scope | L1 Mapped | nist-csf-2-respond-recover.detection-recovery-tooling | — |
Synthesis Screening
2023 · Global
Nucleic-acid synthesis screening regime — the IBBIS Common Mechanism and IGSC Harmonized Screening Protocol screen synthesis orders for sequences of concern before synthesis. KYE Protocol™ governs whether an AI-generated nucleic-acid sequence may proceed to a synthesis order, binding the screening result — the KYE™ AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Sequence-of-concern screening | Designed | L2 Designed | nucleic-acid-synthesis-screening.soc-screen, nucleic-acid-synthesis-screening.flagged-hold | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Customer / legitimacy screening | Designed | L2 Designed | nucleic-acid-synthesis-screening.customer-screen | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Screening provenance & record-keeping | Designed | L2 Designed | nucleic-acid-synthesis-screening.screening-provenance | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
NYDFS AI Circular
NYDFS Insurance Circular Letter No. 7 (2024) — Use of AI Systems and External Consumer Data in Underwriting and Pricing · United States
NYDFS Insurance Circular Letter No. 7 (2024) sets expectations for insurers using AI and external consumer data in underwriting and pricing — senior-management accountability, unfair-discrimination testing, consumer transparency, documentation. KYE Protocol™ governs whether an AI-assisted insurance decision in scope may proceed to a consequential adverse action — under a named accountable authority, with a recorded adverse-action reason-code, proxy-discrimination / fairness-evidence captured, a signed replay-provable Evidence Pack™ per decision, and a consumer appeal / contestability record. The ECDIS selection / pricing / methodology design on the merits stays the insurer's own work (honest scope, §0). Per-requirement bijection at /compliance/nydfs-insurance-circular-ai.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Senior-management accountability for the AI decision | Enforced | L3 Enforceable | nydfs-insurance-circular-ai.senior-management-accountability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Unfair-discrimination testing evidence | Enforced | L3 Enforceable | nydfs-insurance-circular-ai.unfair-discrimination-testing | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Consumer transparency & appeal record | Enforced | L3 Enforceable | nydfs-insurance-circular-ai.consumer-transparency-appeal | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| ECDIS selection, pricing & methodology design on the meritsThe ECDIS selection / pricing / testing-methodology design on the merits is the insurer's own work — KYE™ is an AI-authority and evidence layer, not a data-selection, pricing, or testing-methodology engine. | Out of scope | L1 Mapped | nydfs-insurance-circular-ai.ecdis-selection-pricing-methodology | — |
OECD GLP
1998 + 21 CFR 58 · International / US
OECD Principles of Good Laboratory Practice and FDA 21 CFR Part 58 govern the integrity, traceability, audit-trail and archiving of non-clinical safety-study data. KYE Protocol™ enforces the ALCOA+ data-integrity, audit-trail and replay slices where an AI/automated step captures or transforms study data — physical study conduct stays the laboratory's GLP system. Per-requirement bijection at /compliance/oecd-glp.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Study data integrity & raw-data traceability (ALCOA+) | Enforced | L3 Enforceable | oecd-glp.data-integrity, oecd-glp.raw-data-traceability | WORM audit hash-chainDecision replayEvidence Pack™ |
| Audit trail & change control for electronic records (Part 11 overlap) | Enforced | L3 Enforceable | oecd-glp.audit-trail | WORM audit hash-chain |
| Archive & retention of study records | Designed | L2 Designed | oecd-glp.archive-retention | WORM audit hash-chain |
| QA & study-director oversight of automated steps | Enforced | L3 Enforceable | oecd-glp.oversight-of-automated-steps | Purpose Permission™Authority Gate |
| Physical study conduct & facilitiesApparatus calibration, test/reference-item handling and physical SOP execution are the laboratory's own GLP quality system — KYE™ is an AI-authority and evidence layer, not a lab-operations system. | Out of scope | L1 Mapped | oecd-glp.physical-study-conduct | — |
OSHA PSM
1992 · United States
US OSHA Process Safety Management standard for facilities handling highly hazardous chemicals. KYE Protocol™ governs the authority, evidence and finality of AI-recommended physical-safety actions in a PSM-covered process. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Mechanical-integrity actuation under safety floor | Designed | L2 Designed | osha-psm.1910.119.j | Purpose Permission™Edge Governance Safety Floor |
| Operating-procedure named accountability | Designed | L2 Designed | osha-psm.1910.119.f | Authority GateDecision Map™ |
| Management-of-change contestable + evidenced | Designed | L2 Designed | osha-psm.1910.119.l | Evidence Pack™Authority Gate |
Permit to Work
HSG250 · United Kingdom
Permit-to-work systems per UK HSE HSG250. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved permits-to-work — the KYE™ HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Permit advisory pending competent-authoriser sign-off | Designed | L2 Designed | permit-to-work.authorisation | Authority GateDecision Map™ |
| Permit scope & isolation bounded to authorised work | Designed | L2 Designed | permit-to-work.scope-isolation | Purpose Permission™Authority Gate |
| Hand-back & audit contestable + evidenced | Designed | L2 Designed | permit-to-work.handback-audit | Evidence Pack™Authority Gate |
PRA SS1/23
PRA SS1/23 (Model risk management principles for banks, May 2023; effective May 2024) · United Kingdom
PRA SS1/23 sets the UK model risk management principles for banks (Principles 1–5, explicitly including AI/ML models). KYE Protocol™ governs whether a model-driven output or risk report under it may proceed to a consequential action — only a currently-validated model used within its approved scope, model changes as named-authority decisions with evidence, every consequential decision pinned to model_id + version + validation reference, and every risk report bound to its data-lineage evidence chain, sealed into a signed replay-provable Evidence Pack™. The quantitative model build / validation mathematics / capital computation / portfolio composition stays the bank's own work (honest scope, §0 — not investment advice). Per-requirement bijection at /compliance/pra-ss1-23.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Model identification & inventory resolution (Principle 1) | Enforced | L3 Enforceable | pra-ss1-23.principle1-model-inventory-resolution | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Governance & named SMF accountability (Principle 2) | Enforced | L3 Enforceable | pra-ss1-23.principle2-governance-named-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Model development, implementation & use incl. AI/ML (Principle 3) | Enforced | L3 Enforceable | pra-ss1-23.principle3-development-implementation-use | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Validation-status binding at the moment of use (Principle 4) | Enforced | L3 Enforceable | pra-ss1-23.principle4-validation-status-binding | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Model risk mitigants & restrictions on use (Principle 5) | Enforced | L3 Enforceable | pra-ss1-23.principle5-mitigants-restrictions | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Independent validation judgment & quantitative work on the meritsThe quantitative model build, validation mathematics, and capital & liquidity computation are the bank's own quantitative work — KYE™ is an AI-authority and evidence layer, not a model-validation or capital-calculation engine. | Out of scope | L1 Mapped | pra-ss1-23.independent-validation-judgment | — |
PSD2 SCA Disputes
PSD2 — Directive (EU) 2015/2366, Arts. 72-74 + 97 (SCA & unauthorised-transaction liability) · European Union
PSD2 Arts. 72-74 + 97 govern SCA and unauthorised-transaction liability in the EU — the PSP carries the burden of proof that the transaction was authenticated and accurately recorded. KYE Protocol™ governs whether an unauthorised-transaction refund / liability allocation may proceed — under a named owner's recorded authority, with the SCA / authentication evidence captured as evidence events at transaction time, and the liability-allocation bundle sealed as a signed, hash-bound, replay-provable Evidence Pack™ that meets the Article 72 burden of proof. The substantive fraud / authorisation determination stays the PSP's / merchant's own (honest scope, §0). Per-requirement bijection at /compliance/psd2-sca-disputes.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| SCA / authentication evidence captured at transaction time | Enforced | L3 Enforceable | psd2-sca-disputes.sca-evidence-capture | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Named-authority on the unauthorised-transaction refund | Enforced | L3 Enforceable | psd2-sca-disputes.unauthorised-transaction-refund-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Burden-of-proof evidence integrity for liability allocation | Enforced | L3 Enforceable | psd2-sca-disputes.liability-allocation-evidence | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive fraud / authorisation determination on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. | Out of scope | L1 Mapped | psd2-sca-disputes.fraud-determination | — |
Reg E
EFTA / Regulation E — 12 CFR Part 1005 (error resolution, §1005.11) · United States
Reg E (12 CFR 1005.11) is the US error-resolution framework for electronic fund transfers. KYE Protocol™ governs whether a provisional credit, refund, or error determination in the dispute flow may proceed — under a named owner's recorded authority, with the transaction evidence captured as evidence events at transaction time, a signed replay-provable Evidence Pack™, and a recorded contestable determination. The substantive error adjudication stays the institution's / merchant's own (honest scope, §0). Per-requirement bijection at /compliance/reg-e.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Named-authority on the provisional credit / refund action | Enforced | L3 Enforceable | reg-e.provisional-credit-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Investigation evidence record captured at transaction time | Enforced | L3 Enforceable | reg-e.investigation-evidence-record | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & written-determination reconstruction | Enforced | L3 Enforceable | reg-e.error-determination-contestability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive error adjudication on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. | Out of scope | L1 Mapped | reg-e.substantive-error-adjudication | — |
Reg Z
TILA / Regulation Z — 12 CFR Part 1026 (billing-error resolution, §1026.13) · United States
Reg Z (12 CFR 1026.13) is the US billing-error-resolution framework for credit accounts. KYE Protocol™ governs whether an account correction, credit, or billing-error determination in the dispute flow may proceed — under a named owner's recorded authority, with the transaction evidence captured as evidence events at transaction time, a signed replay-provable Evidence Pack™, and a recorded contestable determination. The substantive billing-error adjudication stays the creditor's / merchant's own (honest scope, §0). Per-requirement bijection at /compliance/reg-z.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Named-authority on the account correction / credit action | Enforced | L3 Enforceable | reg-z.billing-error-resolution-record | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Billing-dispute evidence record captured at transaction time | Enforced | L3 Enforceable | reg-z.billing-dispute-evidence-record | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & written-explanation reconstruction | Enforced | L3 Enforceable | reg-z.billing-dispute-contestability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive billing-error adjudication on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. | Out of scope | L1 Mapped | reg-z.substantive-billing-error-adjudication | — |
RIDDOR
2013 · United Kingdom
UK RIDDOR 2013 (SI 2013/1471), HSE-enforced. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved RIDDOR-reportable incident reports — the KYE™ HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Incident report authored under safety floor | Designed | L2 Designed | riddor.reg-4-6 | Purpose Permission™Edge Governance Safety Floor |
| Reportability determination advisory pending sign-off | Designed | L2 Designed | riddor.reporting-decision | Authority GateDecision Map™ |
| Incident records contestable + evidenced | Designed | L2 Designed | riddor.reg-12 | Evidence Pack™Authority Gate |
SEC Cyber Disclosure
SEC Cybersecurity Disclosure Rules (2023) — Item 1.05 + Item 106 · United States
SEC Cyber Disclosure (Item 1.05) is the US four-business-day material-cybersecurity-incident disclosure regime on Form 8-K. KYE Protocol™ governs whether an AI-assisted disclosure-timing decision under it may proceed to a consequential disclosure action — under a named accountable officer's authority, with incident-evidence chain-of-custody recorded, and a contestability record so the timing decision can be reconstructed and challenged. The substantive materiality determination / 8-K drafting / legal judgment stays the registrant's own work (honest scope, §0/§70). Per-requirement bijection at /compliance/sec-cyber-disclosure.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Disclosure-timing authority on the four-business-day clock | Enforced | L3 Enforceable | sec-cyber-disclosure.item105-materiality-disclosure-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability of the timing decision in an SEC / shareholder review | Enforced | L3 Enforceable | sec-cyber-disclosure.item105-timing-contestability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive materiality determination & 8-K draftingThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. | Out of scope | L1 Mapped | sec-cyber-disclosure.substantive-materiality-drafting | — |
Sedona Principles
The Sedona Principles, Third Edition (2018) · United States
The Sedona Principles — Best Practices for Electronic Document Production is the leading US e-discovery best-practice commentary (The Sedona Principles, Third Edition). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/sedona-principles.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Defensible, reconstructable AI-review process record | Enforced | L3 Enforceable | sedona-principles.principle6-defensible-process | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Replay-provable evidence of the process when challenged | Enforced | L3 Enforceable | sedona-principles.replay-provable-process-evidence | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Methodology selection & substantive production completenessThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. | Out of scope | L1 Mapped | sedona-principles.methodology-and-completeness | — |
SOX §806
Sarbanes-Oxley Act §806 (18 U.S.C. §1514A) — whistleblower anti-retaliation · United States
SOX §806 — Whistleblower Anti-Retaliation (18 U.S.C. §1514A) is the US public-company anti-retaliation statute (contributing-factor / clear-and-convincing burden). KYE Protocol™ governs whether an AI-assisted adverse HR action that touches a reporter may proceed — only with a recorded retaliation-risk assessment evidence — and binds a contestability record so the employer's burden-of-proof can be reconstructed if a §806 complaint is filed. Whether the action was in fact retaliatory and the §806 adjudication stay with counsel / OSHA / the courts (honest scope, §0). Per-requirement bijection at /compliance/sox-806.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Retaliation-risk assessment evidence before an adverse action | Enforced | L3 Enforceable | sox-806.anti-retaliation-risk-record | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & burden-of-proof reconstruction | Enforced | L3 Enforceable | sox-806.contestability-burden-reconstruction | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Whether the action was in fact retaliatory & §806 adjudicationDeciding whether an action was retaliatory and adjudicating the §806 complaint is a legal determination for counsel and the courts — KYE™ is an AI-authority and evidence layer, not an adjudication engine. | Out of scope | L1 Mapped | sox-806.substantive-retaliation-adjudication | — |
CPR PD 57AD
CPR Part 31 + Practice Direction 57AD (Disclosure in the Business and Property Courts, 2022) · United Kingdom
UK CPR Part 31 + PD 57AD — Disclosure & the Disclosure Certificate is the English civil disclosure framework (CPR Part 31 + Practice Direction 57AD). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/uk-cpr-pd57ad.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Named-authority on the disclosure determination & certificate | Enforced | L3 Enforceable | uk-cpr-pd57ad.disclosure-certificate | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & reconstruction of a disclosure challenge | Enforced | L3 Enforceable | uk-cpr-pd57ad.disclosure-challenge-reconstruction | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive disclosure review & adequacy judgmentThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. | Out of scope | L1 Mapped | uk-cpr-pd57ad.substantive-disclosure-review | — |
UK PIDA
UK Public Interest Disclosure Act 1998 (Employment Rights Act 1996, Part IVA) · United Kingdom
UK PIDA — Public Interest Disclosure Act 1998 (ERA 1996 Part IVA) is the UK protected-disclosure framework (protection from detriment and automatic-unfair dismissal). KYE Protocol™ governs whether an AI-assisted handling of a protected disclosure, or an adverse action on a worker who made one, may proceed — under a named handler's authority, with a recorded detriment / retaliation-risk assessment before adverse action, and a contestability record so a detriment / dismissal claim can be reconstructed. Whether the disclosure qualifies, whether a detriment occurred, and the tribunal adjudication stay with counsel and the tribunal (honest scope, §0). Per-requirement bijection at /compliance/uk-pida.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Named-authority on the protected-disclosure handling & detriment-risk record | Enforced | L3 Enforceable | uk-pida.protected-disclosure-handling-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & reconstruction for a detriment / dismissal claim | Enforced | L3 Enforceable | uk-pida.detriment-claim-reconstruction | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Whether the disclosure qualifies & employment-tribunal adjudicationDeciding whether a disclosure qualifies and adjudicating the tribunal claim is a legal determination for counsel and the tribunal — KYE™ is an AI-authority and evidence layer, not an adjudication engine. | Out of scope | L1 Mapped | uk-pida.qualifying-disclosure-and-adjudication | — |
Visa CE 3.0
Visa Compelling Evidence 3.0 (CE3.0) — remedied-dispute evidence requirements (Visa Rules, fraud reason code 10.4) · Global
Visa Compelling Evidence 3.0 defines the qualifying evidence set that remedies a card-absent fraud dispute (prior undisputed transactions, matching device / IP / address / account identifiers, delivery evidence). KYE Protocol™ governs whether the representment may proceed — under a named owner's recorded authority, with the qualifying evidence captured as evidence events at transaction time, and the representment bundle sealed as a signed, hash-bound, WORM-retained, replay-verifiable Evidence Pack™ — exactly the provable evidence set CE3.0 representments turn on. Whether to fight, the narrative, and the outcome stay the merchant's / network's own (honest scope, §0). Per-requirement bijection at /compliance/visa-ce30.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Qualifying evidence set captured at transaction time | Enforced | L3 Enforceable | visa-ce30.evidence-set-capture | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Representment bundle integrity (signed · hash-bound · WORM) | Enforced | L3 Enforceable | visa-ce30.representment-bundle-integrity | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Named-authority on the representment decision | Enforced | L3 Enforceable | visa-ce30.representment-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Dispute outcome adjudication & narrative on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. | Out of scope | L1 Mapped | visa-ce30.dispute-outcome-adjudication | — |
2 CFR 200 (Uniform Guidance)
2 C.F.R. Part 200 (Uniform Guidance) · United States
US federal grants-administration regulation: uniform administrative requirements, cost principles, and audit requirements for federal awards. KYE™ governs WHETHER a grants-lifecycle action by an AI agent may proceed and proves the basis (via the KYE™ Governed Grants Agent™); it does not write applications, run a grants-management platform, or move money.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Cost principles & allowability of costs (§200.403) | Enforced | L3 Enforceable | 2 C.F.R. §200.403 | Governed Grants Agent™ admit→decidePurpose Permission™Evidence Pack™ |
| Internal controls over the federal award (§200.303) | Enforced | L3 Enforceable | 2 C.F.R. §200.303 | Replay-Proof™WORM audit hash-chainEvidence Pack™ |
| Pass-through entity / subrecipient monitoring (§200.332) | Enforced | L3 Enforceable | 2 C.F.R. §200.332 | Governed Grants Agent™ admit→decideDelegated Auditability |
| Prior written approval & record retention (§200.407, §200.334) | Designed | L2 Designed | 2 C.F.R. §200.407, 2 C.F.R. §200.334 | GovernedUI two-person sign-off (Phase-2)WORM retention policy (Phase-2) |
| Grantee financial-management system & Single Audit (§200.302, §200.501) | Out of scope | L1 Mapped | 2 C.F.R. §200.302, 2 C.F.R. §200.501 | — |
IT Rules 2021
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as amended · India
KYE™ governs whether an AI agent's content-affecting ACTION (publish, remove, restrict, distribute) was authorised and is evidenced. KYE™ is OUT-OF-SCOPE for the substantive content determination — whether material is unlawful — and for operating grievance-redressal machinery. Those are the intermediary's own obligations (§70 §4). Deep per-requirement mapping: 4 requirements, 1 enforced by KYE™ runtime, 3 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Authority + evidence at the action boundary — enforced by KYE™ runtime and verified by CI | Enforced | L3 Enforceable | it-rules-2021.ACTION-AUTHORITY — Content-affecting actions taken under resolved authority and evidenced | kye.compliance.attestation.v1kye.evidence.decision_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context_seal.v1internal |
| Obligations owed directly by the regulated entity — NOT discharged by KYE™KYE™ governs whether an AI agent's content-affecting ACTION (publish, remove, restrict, distribute) was authorised and is evidenced. KYE™ is OUT-OF-SCOPE for the substantive content determination — whether material is unlawful — and for operating grievance-redressal machinery. Those are the intermediary's own obligations (§70 §4). | Out of scope | L1 Mapped | it-rules-2021.GRIEVANCE-REDRESSAL — Grievance officer appointed and complaints resolved within prescribed timelines, it-rules-2021.DUE-DILIGENCE — Intermediary due-diligence obligations including publication of rules and privacy policy, it-rules-2021.SYNTHETIC-LABELLING — Identification of artificially generated or modified information | — |
Information-security and operational-resilience frameworks that govern how systems are protected, monitored, and recovered.
ASD Essential Eight
Nov 2023 maturity model + 2024 AI guidance · Australia
ASD/ACSC Essential Eight mitigation strategies + ASD 'Engaging with Artificial Intelligence' guidance, scoped to the AI-agent action path. Per-requirement bijection at /compliance/asd-essential-eight.html.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Restrict administrative privileges + multi-factor authentication | Enforced | L3 Enforceable | E8 — Restrict admin privileges, E8 — MFA | Authority GateAuthority Revocation OrchestratorWebAuthn step-up |
| Tamper-evident monitoring + AI supply-chain governance | Enforced | L3 Enforceable | E8 — Monitoring, ASD AI guidance — supply chain | WORM audit hash-chainStreaming Logs Contract™Authority Register |
CISA CDM
CDM Program — DEFEND capability areas A–D · United States
CISA's Continuous Diagnostics and Mitigation program, mapped to the agentic-AI asset surface: an AI agent that holds credentials, reaches data, and acts on systems is a reportable cyber asset. KYE™ answers 'what agents exist, who owns them, what do they touch, what can they do, and are they drifting?'
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Asset Management — HWAM/SWAM/CSM/VUL (the AI-agent asset inventory + approved-design baseline + drift) | Enforced | L3 Enforceable | HWAM, SWAM, CSM, VUL | §14 Agent Registry (reportable assets)Operating Model™ baselineReality Coupling™ drift |
| Identity & Access Management — TRUST/CRED/PRIV/BEHAVE | Enforced | L3 Enforceable | TRUST, CRED, PRIV, BEHAVE | Know Your Entity™ resolutionAuthority tokens + revocationPurpose Permission™ least privilege |
| Network Security Management — BOUND/MNGEVT (tenant isolation + suspend/revoke response) | Enforced | L3 Enforceable | BOUND, MNGEVT | §0.11 tenant isolationSuspend/Revoke/Kill-switchWORM audit |
| Data Protection Management — DPM (tamper-evident, replayable evidence) | Enforced | L3 Enforceable | DPM | WORM audit hash-chainEvidence Pack™Replay Proof™ |
FedRAMP
Rev 5 · United States
US federal cloud authorisation program built on the NIST SP 800-53 control baseline.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Access Control (AC) family | Enforced | L3 Enforceable | AC | Authority GatePurpose Permission™WebAuthn step-up |
| Audit & Accountability (AU) family | Enforced | L3 Enforceable | AU | WORM audit hash-chainDecision replay |
| Identification & Authentication (IA) family | Enforced | L3 Enforceable | IA | WebAuthn step-upAuthority Gate |
| System & communications protection — cryptographyA FIPS-validated cryptographic adapter and automated key rotation are in build. | Enforced | L3 Enforceable | SC-12, SC-13 | FIPS-validated crypto moduleAutomated key rotationEvidence Pack™ signing (COSE-Sign1) |
| Physical (PE) & Personnel (PS) familiesPhysical and personnel controls are operated by the customer's authorised cloud environment. | Out of scope | L1 Mapped | PE, PS | — |
Google SRE Change Mgmt
SRE Book · International
Google SRE — Change Management (progressive rollout & rollback). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE™ Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Progressive rollout authority & rollback readiness (action-boundary, enforced) | Enforced | L3 Enforceable | google-sre-change-management.progressive-rollout-authority | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Monitoring, canary analysis & rollout-automation tooling (out-of-scope — sre / platform) | Out of scope | L1 Mapped | google-sre-change-management.monitoring-rollout-tooling | — |
ISO 27001
2022 · International
Information security management system requirements and the Annex A control set.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Organisational & people controls | Enforced | L3 Enforceable | A.5.x, A.6.x | Purpose Permission™Authority Gate |
| Identity & access management | Enforced | L3 Enforceable | A.5.15-A.5.18, A.8.2-A.8.5 | Authority GateWebAuthn step-upPurpose Permission™ |
| Logging, monitoring & event management | Enforced | L3 Enforceable | A.8.15, A.8.16 | WORM audit hash-chainDecision replay |
| Cryptographic controls & key managementEd25519 signing runs in-process today; the KMS/HSM-backed key-rotation and FIPS-validated adapter are in build. | Designed | L2 Designed | A.8.24 | Evidence Pack™ signing (COSE-Sign1)Automated key rotationFIPS-validated crypto module |
| Physical security & training deliveryKYE™ records that training was completed as a capability grant, but does not deliver content or operate physical and environmental controls. | Out of scope | L1 Mapped | A.7.x, A.6.3 | — |
ISO/IEC 20000-1
2018 · International
ISO/IEC 20000-1 — Service Management (change management §8.5.1). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE™ Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Change management §8.5.1 — authorization & records (action-boundary, enforced) | Enforced | L3 Enforceable | iso-iec-20000-1.clause8-5-1-change-management | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Service-management system operation, SLAs & continual improvement (out-of-scope — service-management) | Out of scope | L1 Mapped | iso-iec-20000-1.smsystem-operation | — |
ITIL 4 Change Enablement
4 · International
ITIL 4 — Change Enablement (change authority & assessment). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE™ Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Change authority & assessment (action-boundary, enforced) | Enforced | L3 Enforceable | itil-4-change-enablement.change-authority-assessment | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Technical change evaluation, scheduling & change-model authoring (out-of-scope — change-management) | Out of scope | L1 Mapped | itil-4-change-enablement.change-evaluation-technical | — |
NIS2
Directive (EU) 2022/2555 · European Union
EU cybersecurity directive setting risk-management and incident-reporting duties for essential and important entities.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Cybersecurity risk-management measures | Enforced | L3 Enforceable | Art. 21 | Purpose Permission™Authority GateWORM audit hash-chain |
| Incident handling & reporting evidence | Enforced | L3 Enforceable | Art. 23 | WORM audit hash-chainDecision replay |
| Supply-chain security evidenceSupply-chain federation runs through the Directory tenant proxy today; signed supply-chain evidence packs are in build. | Designed | L2 Designed | Art. 21(2)(d) | Evidence Pack™ signing (COSE-Sign1)Directory tenant proxy |
| Management-body governance designationDesignation of management-body responsibility for cybersecurity risk is an organisational matter. | Out of scope | L1 Mapped | Art. 20 | — |
NIST 800-207
1.0 · United States
Reference architecture for zero-trust security: per-request authorisation and continuous evaluation.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Policy decision & enforcement point | Enforced | L3 Enforceable | §2, §3.1 | Authority GatePurpose Permission™ |
| Continuous evaluation & per-request authorisation | Enforced | L3 Enforceable | §3.2 | Purpose Permission™WebAuthn step-up |
| Audit, telemetry & diagnostics | Enforced | L3 Enforceable | §3.4 | WORM audit hash-chainDecision replay |
| Deployment-topology selectionKYE™ aligns with every zero-trust deployment variant but does not prescribe one; deployment topology is the customer's choice. | Out of scope | L1 Mapped | §3.3 | — |
NIST 800-53 CM
Rev 5 · United States
NIST SP 800-53 Rev 5 — Configuration Management (CM) family. KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE™ Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| CM-3 configuration change control — authority & impact analysis (action-boundary, enforced) | Enforced | L3 Enforceable | nist-800-53-cm.cm-3-configuration-change-control | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| CM-2 baseline configuration & CM-8 component inventory (out-of-scope — config-management) | Out of scope | L1 Mapped | nist-800-53-cm.cm-2-baseline-inventory | — |
NIST CSF
2.0 · United States
Outcome-based cybersecurity framework organised around the Govern, Identify, Protect, Detect, Respond, and Recover functions.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Govern function | Enforced | L3 Enforceable | GV | Purpose Permission™Authority Gate |
| Identify & Protect functions | Enforced | L3 Enforceable | ID, PR | Authority GatePurpose Permission™WebAuthn step-up |
| Detect, Respond & Recover functions | Enforced | L3 Enforceable | DE, RS, RC | WORM audit hash-chainDecision replay |
| Tamper-evident control evidenceThe append-only audit chain protects evidence integrity today; detached signatures that prove integrity to an external party are in build. | Designed | L2 Designed | PR.DS | Evidence Pack™ signing (COSE-Sign1) |
SOC 2
TSC 2017 · Global
AICPA Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Control environment, communication & risk assessment | Enforced | L3 Enforceable | CC1.x, CC2.x, CC3.x | Purpose Permission™Authority GateWORM audit hash-chain |
| Logical access controls | Enforced | L3 Enforceable | CC6.1-CC6.8 | Authority GatePurpose Permission™WebAuthn step-up |
| System operations, monitoring & change management | Enforced | L3 Enforceable | CC7.x, CC8.1 | WORM audit hash-chainDecision replay |
| Confidentiality, availability & recovery | Enforced | L3 Enforceable | C1.x, A1.2, P4.1 | Authority GateWORM audit hash-chain |
| Independently verifiable transparency receiptsTransparency receipts are emitted today; the detached cryptographic signatures that make them third-party-verifiable are in build. | Designed | L2 Designed | CC2.3 | Evidence Pack™ signing (COSE-Sign1)Decision Map™ signing (JWS-detached) |
| Board oversight & physical securityBoard composition and data-centre physical controls are organisational; KYE™ records the actions of board members but does not establish governance structure. | Out of scope | L1 Mapped | CC1.2 | — |
SOC 2 CC8
2017 TSC · United States
SOC 2 — CC8 Change Management (Common Criteria). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE™ Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| CC8.1 change authorization & evidence (action-boundary, enforced) | Enforced | L3 Enforceable | soc2-cc8-change-management.cc8-1-change-authorization | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Change design, development & testing (out-of-scope — engineering / qa) | Out of scope | L1 Mapped | soc2-cc8-change-management.cc8-development-testing | — |
OWASP Agentic Top 10
2025 · International
OWASP's agentic-AI threat taxonomy (2025), crosswalked by AIUC-1. KYE Protocol™ is the runtime authority + evidence + finality substrate each threat class assumes — it gates the agent action, binds agent identity, and seals replay-provable evidence. KYE™ proves the control operated at the action boundary; it is not an agent scanner. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Tool misuse / privilege / intent — gated by purpose-scope | Designed | L2 Designed | owasp-agentic.t2-tool-misuse, owasp-agentic.t3-privilege-compromise, owasp-agentic.t6-intent-goal-manipulation | Purpose Permission™Decision Map™Authority Gate |
| Repudiation / spoofing / deception — identity + replay evidence | Designed | L2 Designed | owasp-agentic.t8-repudiation-untraceability, owasp-agentic.t9-identity-spoofing, owasp-agentic.t7-misaligned-deceptive | Evidence Pack™Replay Proof™Delegated Auditability |
| Memory poisoning / HITL overwhelm — memory authority + approval modes | Designed | L2 Designed | owasp-agentic.t1-memory-poisoning, owasp-agentic.t10-hitl-overwhelm | Memory AuthorityGovernedUI |
SASH Cyber Agents
2026 · Singapore
Singapore SASH 'Detecting Offensive Cyber Agents' defence-in-depth (2026). KYE Protocol™ makes a defending org's own agents first-class identifiable principals with replay-provable actions + a continuous posture signal — complementing the identity, triage and exchange (ACE) layers. KYE™ is the authority + evidence substrate, not an IDS/honeypot. Per-requirement bijection at framework-coverage-bijection.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Agent identity — first-class bound principals | Designed | L2 Designed | sash.agent-identity | Delegated Agent BindingAgent Identity |
| Detection & triage — continuous posture signal | Designed | L2 Designed | sash.detection-triage | Posture SignalDelegated Agent Binding |
| ACE exchange + post-incident replay | Designed | L2 Designed | sash.ace-exchange, sash.evidence-replay | Evidence Pack™Replay Proof™Delegated Auditability |
CRA
Regulation (EU) 2024/2847 · European Union
EU horizontal cybersecurity regulation for products with digital elements; mandatory SBOM, vulnerability handling, security-by-design, and Article 14 vulnerability/incident reporting (24h/72h/14-day). Fully applicable Dec 2027.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Security-by-design essential requirements (Annex I, Part I) | Enforced | L3 Enforceable | Annex I, Part I | Purpose Permission™WORM audit hash-chainSIEM streaming logs |
| Vulnerability handling + remediation (Annex I, Part II) | Enforced | L3 Enforceable | Annex I, Part II | Cyber-resilience incident rule packDecision replay |
| SBOM generation & machine-readable bill of materialsKYE™ does not generate the product SBOM (manufacturer obligation); a manufacturer-supplied SBOM can be cited and pinned as evidence to a governed vulnerability-handling decision. Runtime ingest is designed, not yet wired. | Designed | L2 Designed | Annex I, Part II (1) | Document Intelligence Rail (cite-and-pin) |
| Article 14 vulnerability & severe-incident reporting (24h/72h/14-day) | Enforced | L3 Enforceable | Art. 14 | Incident lifecycleEvidence Pack™ signing |
| Conformity assessment & CE markingConformity assessment, CE marking and placing-on-the-market are product-certification obligations of the manufacturer and notified body, outside KYE™'s lane. | Out of scope | L1 Mapped | Art. 32, Annex VIII | — |
CERT-In Directions
Directions dated 28 April 2022 under s.70B(6), Information Technology Act, 2000 · India
KYE™ governs the AUTHORITY + EVIDENCE layer of incident response: what was decided, under whose authority, and when — sealed so the sequence is replayable against a statutory clock. KYE™ is OUT-OF-SCOPE for detecting cyber incidents across the customer's estate, for operating their SOC, and for making the regulatory filing to CERT-In. The six-hour obligation is the customer's; KYE™ makes the timeline provable (§70 §4). Deep per-requirement mapping: 5 requirements, 2 enforced by KYE™ runtime, 3 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Authority + evidence at the action boundary — enforced by KYE™ runtime and verified by CI | Enforced | L3 Enforceable | cert-in-directions-2022.SIX-HOUR-CLOCK — Specified cyber incidents reported to CERT-In within six hours of noticing, cert-in-directions-2022.LOG-RETENTION — ICT system logs maintained securely for a rolling 180-day period within Indian jurisdiction | kye.compliance.attestation.v1kye.evidence.pack.v1kye.replay.context_seal.v1kye.resilience.availability_gap.v1 |
| Obligations owed directly by the regulated entity — NOT discharged by KYE™KYE™ governs the AUTHORITY + EVIDENCE layer of incident response: what was decided, under whose authority, and when — sealed so the sequence is replayable against a statutory clock. KYE™ is OUT-OF-SCOPE for detecting cyber incidents across the customer's estate, for operating their SOC, and for making the regulatory filing to CERT-In. The six-hour obligation is the customer's; KYE™ makes the timeline provable (§70 §4). | Out of scope | L1 Mapped | cert-in-directions-2022.TIME-SYNC — System clocks synchronised to NPL or NIC network time, cert-in-directions-2022.INCIDENT-DETECTION — Detection and triage of reportable cyber incidents across the estate, cert-in-directions-2022.REGULATORY-FILING — Submission of the incident report to CERT-In in the prescribed format | — |
SEBI CSCRF
Cybersecurity and Cyber Resilience Framework (CSCRF) · India
KYE™ governs the AUTHORITY + EVIDENCE layer of consequential actions and of incident RESPONSE decisions. KYE™ is OUT-OF-SCOPE for the identify/protect/detect capabilities themselves — asset inventory, network protection, monitoring — which the regulated entity operates (§70 §4). Deep per-requirement mapping: 6 requirements, 2 enforced by KYE™ runtime, 4 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.
Enforced
Designed
Out of scope
| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
|---|---|---|---|---|
| Authority + evidence at the action boundary — enforced by KYE™ runtime and verified by CI | Enforced | L3 Enforceable | sebi-cyber-resilience.RESPOND-AUTHORITY — Incident-response actions taken under resolved authority and sealed, sebi-cyber-resilience.EVIDENCE-RETENTION — Retention of security event records supporting audit and forensic review | kye.compliance.attestation.v1kye.evidence.decision_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context_seal.v1internal |
| Obligations owed directly by the regulated entity — NOT discharged by KYE™KYE™ governs the AUTHORITY + EVIDENCE layer of consequential actions and of incident RESPONSE decisions. KYE™ is OUT-OF-SCOPE for the identify/protect/detect capabilities themselves — asset inventory, network protection, monitoring — which the regulated entity operates (§70 §4). | Out of scope | L1 Mapped | sebi-cyber-resilience.IDENTIFY-PROTECT — Asset identification and protective controls across the estate, sebi-cyber-resilience.DETECT-MONITOR — Continuous monitoring and detection of cyber events, sebi-cyber-resilience.INCIDENT-REPORTING — Reporting of cyber incidents to SEBI within prescribed timelines, sebi-cyber-resilience.RECOVER — Recovery and restoration capability with defined objectives | — |
Methodology
This page is generated. The framework roster, every count, and every headline number above are projected from internal — a schema-backed canonical registry validated on every build. The page cannot drift from the registry: a CI gate regenerates it and fails the build on any mismatch.
For the full per-control register — every article and criterion bound to its KYE™ runtime control — see the compliance frameworks reference and the compliance program. KYE Protocol™ is an evidence layer: it is not a certification, and it does not replace the customer’s own controls or an accredited assessment.
Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.
Canonical KYE™ surfaces referenced on this page: Audit Pilot · Cohesion Cascade · Delegated Auditability · Evidence Pack™ · KYE™ Comms Engine · KYE™ Production Action Authority™ · KYE Protocol™ · KYE™ Reconciliation Engine · Purpose Permission · Resilience Loop · Self-Governance.