---
title: "KYE Protocol™ — Regulatory coverage · 249 frameworks, 446/853 requirement groups Enforced"
description: "KYE Protocol™ regulatory coverage: 249 frameworks decomposed into 853 requirement groups, each marked Enforced, Designed, or Out of scope — generated from a single schema-backed registry."
url: https://kyeprotocol.com/regulatory-coverage/
lang: en
source: "KYE Protocol"
---

> KYE Protocol™ regulatory coverage: 249 frameworks decomposed into 853 requirement groups, each marked Enforced, Designed, or Out of scope — generated from a single schema-backed registry.

Regulatory coverage

# Every framework. One honest coverage map.

KYE Protocol™ maps to **249 regulatory frameworks**, decomposed into **853 requirement groups**. **446 are Enforced** at runtime, 254 Designed and in build, 153 Out of scope. Every number here is computed from a single schema-backed registry — change the registry, the page regenerates.

How to read this map

## Three honest states — no checkbox theatre.

Every requirement group below carries exactly one of these states. A group is only marked **Enforced** when runtime code and a CI gate back it — so a customer’s audit team can sign with the right residual-risk register.

### Enforced

Live runtime code enforces this requirement, and a CI gate verifies it on every release.

### Designed

Schema, contract, and acceptance criteria are locked; the runtime implementation is in build and tracked in the implementation plan.

### Out of scope

Not discharged by KYE Protocol™ — owned by the customer's own systems, processes, or counsel. KYE™ is an evidence layer, not a replacement for these controls.

The coverage-maturity ladder

## How far each control has climbed — mapped to certified.

Tri-state tells you whether KYE Protocol™ owns a control. The **maturity ladder** tells you _how far it has climbed_ — from merely mapped, through designed and enforceable, to evidence-backed and certified. A row only claims **evidence-backed** or **certified** when a real Evidence Pack™ or assessor artefact backs it; a CI gate rejects any inflated claim. This is the per-control axis — orthogonal to where KYE Protocol™ ships SKUs by jurisdiction.

### L1 Mapped (156)

KYE Protocol™ has mapped the obligation/control: the framework requirement is decomposed and crosswalked to the KYE Protocol™ control vocabulary, but no design, runtime check, evidence, or certification is asserted at this level.

### L2 Designed (248)

KYE Protocol™ has a profile / control design for the obligation: schema, contract, and acceptance criteria are locked and tracked in the implementation plan, but the runtime enforcement is in build.

### L3 Enforceable (449)

KYE Protocol™ can enforce the obligation via live runtime checks (a Decision Engine / Authority Gate path or a CI gate that fails closed). A claim at this level must resolve to a real runtime control or gate.

### L4 Evidence-backed (0)

KYE Protocol™ generates a signed Evidence Pack™ for the obligation — the enforcement decision is captured as a replayable, third-party-verifiable artefact. A claim at this level must resolve to a real Evidence Pack™ example on disk (honest-floor rule).

### L5 Certified (0)

An external KYE™ Seal™ / accredited-assessor review is available for the obligation. The top of the ladder: a buyer can point at an independent assessment, not just KYE Protocol™'s own evidence. A claim at this level must resolve to a real seal / assessor artefact on disk (honest-floor rule).

Coverage by framework

## Every framework, decomposed and marked.

Filter by state to see exactly where KYE Protocol™ enforces today, where it is in build, and where the customer owns the control.

### AI governance

Frameworks that govern the lifecycle, oversight, and accountability of AI systems and AI agents.

AI-CAIQ

#### AI-CAIQ (STAR-for-AI self-assessment)

1.0 · International

The CSA AI Consensus Assessments Initiative Questionnaire is the self-assessment companion to the AICM and the basis for CSA STAR-for-AI listings. KYE™ generates each answer it can satisfy from runtime evidence (a KYE™ artefact + a §0.3 evidence event), and marks questions outside its execution scope as not applicable — never fabricated.

### 1

Enforced

### 0

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Questionnaire answers generated from replay-provable runtime evidence | Enforced | L3 Enforceable | AI-CAIQ (KYE-resolvable questions) | Evidence Pack™Decision Map™Replay-Proof™ |
| Out-of-scope questions marked not applicableInfrastructure, training-pipeline and internal model-validation questions are not applicable to the KYE™ execution-layer scope. Marked honestly, never fabricated. | Out of scope | L1 Mapped | AI-CAIQ (infrastructure / model-training questions) | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

AI Solutions Framework

#### AI Solutions Framework — Enterprise AI-Adoption Control Framework (IG1–IG3)

1.0 · International

The AI Solutions Framework is an enterprise AI-adoption control framework (~90 safeguards across AI governance & accountability, risk management, AI safety, data privacy/lineage, compliance monitoring, and audit & evidence; IG1–IG3 maturity). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the KYE™ AI Solutions Framework Authority Pack™ (§70 honesty bar). Frameworks define what should happen; KYE Protocol™ resolves who may make it happen, under what authority, and proves it later. The organisational safeguards (governance board, AI inventory, policy authorship, training, risk committee) and the deploy-time infrastructure-posture / CSPM safeguards (model-logging, encryption, IAM least-privilege, network egress) are honestly out of scope and ceded to their owning roles. KYE Protocol™ complements a deploy-time posture/CSPM layer — coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.

### 3

Enforced

### 0

Designed

### 2

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| AI governance & accountability — action-boundary authority (enforced) | Enforced | L3 Enforceable | ai-solutions-framework.approval-workflow-authority, ai-solutions-framework.accountability-named-principal | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| AI risk management & safety — attestation + human-oversight stage gate (enforced) | Enforced | L3 Enforceable | ai-solutions-framework.attestation-due-diligence-before-action, ai-solutions-framework.human-oversight-stage-gate | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Compliance monitoring & audit/evidence — exception register + provenance pin (enforced) | Enforced | L3 Enforceable | ai-solutions-framework.exception-register, ai-solutions-framework.audit-evidence-provenance-pin | Evidence Pack™Replay-Proof™Audit WORM |
| Organisational safeguards (out of scope — governance-office / CISO) | Out of scope | L1 Mapped | ai-solutions-framework.ai-governance-board, ai-solutions-framework.ai-system-inventory, ai-solutions-framework.ai-acceptable-use-policy, ai-solutions-framework.ai-workforce-training, ai-solutions-framework.ai-risk-committee-review | — |
| Infrastructure posture / CSPM safeguards (out of scope — cloud-platform / devsecops; complemented by KYE Protocol™) | Out of scope | L1 Mapped | ai-solutions-framework.model-inference-logging-enabled, ai-solutions-framework.ai-data-storage-encryption, ai-solutions-framework.ai-iam-least-privilege, ai-solutions-framework.ai-network-egress-posture | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

AICM Resolution

#### CSA AI Controls Matrix (AICM)

1.0 · International

The Cloud Security Alliance AI Controls Matrix defines 243 control objectives across 18 domains. AICM defines the controls. KYE™ operationalises them — proving how each control resolved at the moment a consequential AI action occurred. KYE™ binds the execution-resolvable domains and is honest about the infrastructure and model-training domains it does not touch.

### 6

Enforced

### 0

Designed

### 1

Out of scope

7 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Identity & access management — authority at the moment of action | Enforced | L3 Enforceable | IAM, AAC | Purpose Permission™Authority GateDelegated-agent binding |
| Governance, risk & compliance — human oversight + recurring attestation | Enforced | L3 Enforceable | GRC | GovernedUI human-control surface≤90-day compliance attestation |
| Logging & monitoring — signed evidence + decision map per action | Enforced | L3 Enforceable | LOG | Evidence Pack™Decision Map™WORM audit hash-chain |
| Model risk & resilience — replay-provable from public keys | Enforced | L3 Enforceable | MRM (action-resolution slice) | Replay-Proof™Context seal |
| Supply chain & transparency — provenance pinned in evidence | Enforced | L3 Enforceable | STA | Tool-call pinEvidence Pack™ |
| Application-interface + data-lifecycle admissibility at the boundaryThe deny-by-default action-boundary and moment-of-use data admissibility contracts are locked; per-interface and per-asset runtime wiring is in build. | Enforced | L3 Enforceable | AIS, DSP | Policy Enforcement PointData-use PDP stage |
| Cloud infrastructure security + model-training & internal model validationCloud-fabric hardening is operated by the cloud service provider; training-pipeline security and internal model validation are owned by the model developer. KYE™ governs how a model's actions resolve at run time and records them — it does not operate the infrastructure or train the model. | Out of scope | L1 Mapped | IVS, TVM, MRM (model-internals slice) | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

AIDA

#### AIDA — Artificial Intelligence and Data Act (Bill C-27, federal)

Bill C-27 Part 3 (tabled, lapsed Jan 2025) · Canada

Canada's proposed federal AI law (AIDA, Part 3 of Bill C-27). The bill lapsed on prorogation in January 2025 and is NOT in force — mapped as a forward-looking design anchor (all rows advisory): high-impact assessment, risk mitigation + monitoring, record-keeping, transparency, and serious-harm notification. Per-requirement bijection at /compliance/aida.html.

### 0

Enforced

### 5

Designed

### 0

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| High-impact system assessment (s.7) | Designed | L2 Designed | s7 | Risk Engine |
| Risk mitigation + monitoring (s.8-9) | Designed | L2 Designed | s8 | Drift DetectorRisk Engine |
| Record-keeping (s.10) | Designed | L2 Designed | s10 | WORM audit hash-chain |
| Transparency / publication (s.11) | Designed | L2 Designed | s11 | Reporting Engine |
| Serious-harm notification (s.12) | Designed | L2 Designed | s12 | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

AU AI Guardrails

#### Australian Government Mandatory AI Guardrails

DISR 2024 (10 guardrails) · Australia

The 10 mandatory AI guardrails proposed by the Department of Industry, Science and Resources (Sept 2024) + the Voluntary AI Safety Standard. Per-requirement bijection at /compliance/au-ai-guardrails.html.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Accountability, risk management & data governance (G1-G3) | Enforced | L3 Enforceable | Guardrail 1, Guardrail 2, Guardrail 3 | Purpose Permission™Risk EngineData Classification EngineEvidence Pack™ |
| Testing, human oversight, transparency & contestability (G4-G7) | Enforced | L3 Enforceable | Guardrail 4, Guardrail 5, Guardrail 6, Guardrail 7 | Conformance RunnerDrift DetectorGovernedUI™Decision Map™Replay-Proof™ |
| Supply-chain transparency & record-keeping (G8-G9) | Enforced | L3 Enforceable | Guardrail 8, Guardrail 9 | Authority RegisterWORM audit hash-chainEvidence Pack™ |
| Stakeholder engagement (G10)Process-and-policy obligation owned by the customer's governance function; KYE™ records that engagement occurred but does not perform it. | Out of scope | L1 Mapped | Guardrail 10 | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

BSI AIC4

#### BSI AIC4 — AI Cloud Service Compliance Criteria

2021 · Germany

The German Federal Office for Information Security (BSI) AI Cloud Service Compliance Criteria Catalogue (AIC4) — one of the frameworks the CSA AICM crosswalks to. KYE™ binds the security-and-robustness criteria that resolve at action time and marks the cloud-platform operational criteria out of scope.

### 2

Enforced

### 0

Designed

### 1

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Security & robustness of AI decisions — evidenced at action time | Enforced | L3 Enforceable | AIC4 Security & Robustness, AIC4 Reliability | Evidence Pack™Replay-Proof™Purpose Permission™ |
| Performance, bias mitigation & explainability of the AI decision recordThe decision-record contract that backs explainability and the action-level audit is locked; the per-criterion runtime surface is in build. | Enforced | L3 Enforceable | AIC4 Performance & Functionality, AIC4 Bias, AIC4 Explainability | Decision Map™ |
| Cloud-platform operations, data centre & training-environment criteriaCloud-platform operations and the model-training environment are operated by the cloud service provider and the model developer, not by KYE™. Out of scope (§0 honest scope). | Out of scope | L1 Mapped | AIC4 Data Management (training), AIC4 Operations | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

EC-Council ADG

#### EC-Council ADG — Adopt · Defend · Govern

2026 · Global

35 requirements across three pillars (Adopt / Defend / Govern), nine governance surfaces, twelve minimum controls (MC-1..MC-12), and three autonomy tiers (HITL / HOTL / HOOTL). Complementary to KYE Protocol™: ADG = operating model, KYE Protocol™ = runtime authority proof.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Pillar 1 — Adopt (10 requirements covering lifecycle, capability, risk, secure deployment, change, evidence, purpose grant, training, acceptable use, assurance baseline) | Enforced | L3 Enforceable | ADG/Adopt | Model capability profileRisk assessmentPurpose Permission™ grant issuanceAdoption evidence packInitial compliance attestation |
| Pillar 2 — Defend (10 requirements covering threat-model, red-team, runtime monitoring, tool/MCP register, prompt-injection defence, supply chain, incident response, SPOF, federation, continuous attestation) | Enforced | L3 Enforceable | ADG/Defend | KYE™ Tool & MCP Authority Register™Tool call pin (side-effect binding)Drift signal familyReplay-Proof™ envelopeSPOF registryFederation cross-org delegationCompliance attestation cadence |
| Pillar 3 — Govern (15 requirements covering authority register, purpose grant, admissibility, evidence pack, decision map, replay-proof, Authority Finality™, human oversight, autonomy tiers, MC-1..MC-12, decision rights, board reporting) | Enforced | L3 Enforceable | ADG/Govern, ADG/MC-1..MC-12 | Purpose Permission™Action Admissibility™ GateDecision Map™Evidence Pack™Replay-Proof™Authority Finality™GovernedUI™ critical-point reviewKYE Autonomy Tiers™ (A0-A3)KYE™ Minimum Authority Controls™ (KAC-1..KAC-12) |

[KYE™ framework reference](https://kyeprotocol.com/compliance/ec-council-adg/)

EEOC Uniform Guidelines

#### EEOC Uniform Guidelines on Employee Selection Procedures

1978 (29 CFR Part 1607) · United States

US federal guidelines defining the four-fifths adverse-impact rule and the validation duty for selection procedures.

### 1

Enforced

### 1

Designed

### 0

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Four-fifths adverse-impact rule | Enforced | L3 Enforceable | 29 CFR §1607.4(D) | Evidence Pack™Authority Gate |
| Validation of selection procedures | Designed | L2 Designed | 29 CFR §1607.5 | Delegated Auditability Rail |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

EU AI Act

#### EU AI Act — Artificial Intelligence Regulation

Regulation (EU) 2024/1689 · European Union

EU regulation setting lifecycle obligations for high-risk AI systems.

### 4

Enforced

### 1

Designed

### 1

Out of scope

6 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Risk-management system | Enforced | L3 Enforceable | Art. 9 | Purpose Permission™Authority Gate |
| Data & data governance | Enforced | L3 Enforceable | Art. 10 | Purpose Permission™WORM audit hash-chain |
| Record-keeping & traceability | Enforced | L3 Enforceable | Art. 12, Art. 72 | WORM audit hash-chainDecision replay |
| Human oversight | Enforced | L3 Enforceable | Art. 14 | WebAuthn step-upAuthority Gate |
| Transparency & provision of informationTransparency receipts are emitted today; the detached signatures that make them verifiable downstream are in build. | Designed | L2 Designed | Art. 13, Art. 50 | Decision Map™ signing (JWS-detached)Evidence Pack™ signing (COSE-Sign1) |
| Annex IV technical documentationKYE™ produces operational evidence; the static Annex IV technical-documentation file is authored separately. | Out of scope | L1 Mapped | Art. 11 | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/eu-ai-act/)

EU AI Act Art 50

#### EU AI Act — Article 50 chatbot transparency

2024/1689 · European Union

Article 50 of Regulation (EU) 2024/1689 requires natural persons be informed they are interacting with an AI system, plus related transparency record-keeping. KYE Protocol™ governs the ENFORCEMENT AUTHORITY + EVIDENCE of the Article 50 chatbot disclosure at the action boundary — consumed by the KYE™ Chatbot Authority Pack™. The broader Regulation is covered by the eu-ai-act registry; this is the narrow chatbot-transparency execution slice. Per-requirement bijection at framework-coverage-bijection.

### 2

Enforced

### 0

Designed

### 1

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Art 50 — AI-interaction disclosure | Enforced | L3 Enforceable | eu-ai-act-chatbot-transparency.art50-chatbot-disclosure-enforcement | Action Admissibility™ GateAuthority Finality™ |
| Art 50 — transparency record-keeping | Enforced | L3 Enforceable | eu-ai-act-chatbot-transparency.art50-transparency-record-keeping | Evidence Pack™Replay-Proof™WORM Retention |
| Disclosure UX & AI Act conformity program (out of scope)Model vendor / operator responsibility — disclosure UX/copy and the broader AI Act conformity program. Zero KYE™ controls (complement-not-compete). | Out of scope | L1 Mapped | eu-ai-act-chatbot-transparency.disclosure-ux-and-conformity-program | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

FDA / EMA AI

#### FDA + EMA — AI / Provenance Expectations for AI-Derived Regulated Candidates

2024-2025 · US / EU

FDA + EMA AI / provenance expectations for AI-derived candidates entering regulated drug/device pipelines — documented provenance, reproducibility, and GxP data integrity (ALCOA+). KYE Protocol™ governs whether an AI-derived candidate may proceed to a regulated stage, binding replay-provable provenance — the KYE™ AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| AI design provenance & reproducibility | Designed | L2 Designed | fda-ema.design-provenance, fda-ema.reproducibility | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| GxP data integrity (ALCOA+) | Designed | L2 Designed | fda-ema.gxp-data-integrity | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Human oversight & accountability | Designed | L2 Designed | fda-ema.human-accountability | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

OECD AI Principles

#### OECD AI Principles — Recommendation of the Council on Artificial Intelligence

OECD/LEGAL/0449 (2019, updated 2024) · International

The OECD Recommendation of the Council on Artificial Intelligence (OECD/LEGAL/0449) sets five value-based principles for trustworthy AI — inclusive growth & well-being; human-centred values & fairness; transparency & explainability; robustness, security & safety; and accountability — and is the reference standard behind the G7 Hiroshima Process and many national AI strategies. This framework is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: although several principles crosswalk to existing KYE Protocol™ rails (transparency/explainability → §0.3 evidence & §13 Replay-Proof™; accountability → §21 Audit Pilot™ & §52 agent binding; robustness/safety → §13 Resilience Loop™; human-centred/fairness → §36 GovernedUI™ human-in-the-loop), no requirement has yet been bound at the requirement level. Per the §70 honesty bar, coverage is reported out of scope pending deep mapping rather than claimed as enforced.

### 0

Enforced

### 0

Designed

### 1

Out of scope

1 requirement group — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping\_state=registered): candidate crosswalks to §0.3 / §13 / §21 / §36 / §52 are noted in the summary but NOT yet bound at the requirement level, so coverage stays out of scope until the deep mapping runs through the §70 rail — never inflated to imply enforcement that does not exist. | Out of scope | L1 Mapped | OECD AI Principles (five value-based principles — not yet decomposed into requirement-level mappings) | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

IMDA MGF (Agentic AI)

#### IMDA Model AI Governance Framework for Agentic AI

v1.5 (20 May 2026, updated 5 June 2026) · Singapore

Singapore IMDA's Model AI Governance Framework for Agentic AI (v1.5) sets expectations across four dimensions: (1) assess and bound the risks upfront; (2) make humans meaningfully accountable; (3) implement technical controls and processes; (4) enable end-user responsibility. This framework is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: although every dimension crosswalks cleanly to existing KYE Protocol™ rails (bound risk upfront → entity/principal identity + §52 agent binding + Purpose Permission™ §12; meaningful human accountability → §36 GovernedUI™ approval modes + Finality Gate; technical controls → §13 Evidence Pack™ / Replay-Proof™ + §34 monitoring; end-user responsibility → §17 Directory + §21 Audit Pilot™), no requirement has yet been bound at the requirement level. Per the §70 honesty bar, coverage is reported out of scope pending deep mapping rather than claimed as enforced.

### 0

Enforced

### 0

Designed

### 1

Out of scope

1 requirement group — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping\_state=registered): the four-dimension crosswalk to KYE™'s entity/§52 / §36 Finality / §13 Evidence+Replay / §17+§21 rails is noted in the summary but NOT yet bound at the requirement level, so coverage stays out of scope until the deep mapping runs through the §70 rail — never inflated to imply enforcement that does not exist. | Out of scope | L1 Mapped | IMDA MGF for Agentic AI — four governance dimensions (not yet decomposed into requirement-level mappings) | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Frontier Bio-Safeguard Eval

#### Common Standard for Evaluating Frontier AI Safeguards against Biological Misuse

technical report, June 2026 · International

A proposed common standard (GovAI/OpenAI, June 2026) for evaluating frontier-AI safeguards against biological misuse: seven recommendations across four principles (comparability across companies; account for the deployment environment; treat safeguards as dynamic; preserve legitimate scientific use) plus a three-layer safeguard stack — access (who can use the model), inference (how harmful queries are handled), platform (post-hoc misuse detection) — combined into composite safeguard levels calibrated to threat actor. This standard is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: it crosswalks to KYE™'s genomics-biosecurity Authority Pack™ + Genetic Sequencing Authority Agent™ (action-boundary admissibility + sequence-of-concern screening) and to §52 access controls + §13 Evidence Pack™, but no requirement is bound at the requirement level. Per the §70 honesty bar, coverage is reported out of scope pending deep mapping. NOTE: this standard evaluates MODEL-LEVEL safeguards; KYE™ governs the ACTION boundary — complementary, not the same control.

### 0

Enforced

### 0

Designed

### 1

Out of scope

1 requirement group — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping\_state=registered): crosswalk to the genomics-biosecurity pack + §52/§13 noted in the summary but NOT requirement-bound. The standard evaluates model-level safeguards; KYE™ governs the action boundary — coverage stays out of scope until deep mapping, never inflated. | Out of scope | L1 Mapped | Seven recommendations + three-layer safeguard stack (not yet decomposed into requirement-level mappings) | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

AI Verify

#### IMDA AI Verify

AI Verify Foundation · Singapore

IMDA / AI Verify Foundation testing framework — transparency, accountability, human agency & oversight, robustness. Per-requirement bijection at /compliance/imda-ai-verify.html.

### 2

Enforced

### 0

Designed

### 0

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Transparency + accountability | Enforced | L3 Enforceable | AI Verify — transparency, AI Verify — accountability | Decision Map™Evidence Pack™Purpose Permission™ |
| Human agency & oversight + robustness | Enforced | L3 Enforceable | AI Verify — human agency, AI Verify — robustness | GovernedUI™Authority GateConformance RunnerDrift Detector |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ISO 42001

#### ISO/IEC 42001 — AI Management System

2023 · International

Management-system standard for the responsible development and use of AI.

### 3

Enforced

### 1

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| AI policy & objectives | Enforced | L3 Enforceable | Clause 5-6 | Purpose Permission™Authority Gate |
| Operational AI controls & impact assessment | Enforced | L3 Enforceable | Clause 8, Annex A.6 | Purpose Permission™WORM audit hash-chain |
| Performance evaluation & audit trail | Enforced | L3 Enforceable | Clause 9 | WORM audit hash-chainDecision replay |
| Signed AI-system lifecycle evidenceLifecycle events are recorded in the audit chain today; signed lifecycle evidence packs are in build. | Designed | L2 Designed | Annex A.6.2 | Evidence Pack™ signing (COSE-Sign1) |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/iso-42001/)

MAS FEAT

#### MAS FEAT Principles

2018 + Veritas methodology & toolkit · Singapore

MAS Principles to promote Fairness, Ethics, Accountability and Transparency (FEAT) in the use of AI and data analytics in Singapore's financial sector, together with MAS Veritas — the MAS-convened consortium's companion FEAT assessment methodology (phased methodology documents, 2020-2022) and open-source Veritas Toolkit (v2.0, 2023). Veritas is canonicalised inside this framework entry rather than as a standalone framework. Per-requirement bijection at /compliance/mas-feat.html.

### 2

Enforced

### 0

Designed

### 0

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Fairness + ethics | Enforced | L3 Enforceable | FEAT — fairness, FEAT — ethics | Risk EngineDecision Map™Purpose Permission™Authority Gate |
| Accountability + transparency | Enforced | L3 Enforceable | FEAT — accountability, FEAT — transparency | Replay-Proof™Regulator Replay agentEvidence Pack™Decision Map™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

MAS MindForge

#### MAS Project MindForge — AI Risk Management: Operationalisation Handbook

2024 · Singapore

MAS Project MindForge's AI Risk Management: Operationalisation Handbook gives Singapore financial institutions practical guidance for operationalising AI risk management across four blocks (Scope & AI Oversight, AI Risk Management, AI Lifecycle Management, Enablers; 17 considerations). KYE Protocol™ operationalises the action-boundary subset at runtime — it does NOT replace MindForge (§0.25 integrate-not-compete). KYE™ governs whether a consequential financial AI action is authorised, within the human-oversight mode the FI declared for that use, evidenced, contestable, and final at the moment it happens — and proves the basis, replayable by MAS or internal audit. Honest scope: KYE™ does not govern the FI's governance operating model, model-development methodology, or the correctness of the AI's output. Per-requirement bijection at /compliance/mas-mindforge.html.

### 0

Enforced

### 4

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Scope & AI oversight (oversight modes machine-enforceable + AI action-authority inventory)Downgraded 2026-09-03 (§70 honesty bar): every per-requirement control mapped for this framework is still Designed, not Enforced, so an 'enforced' group status was a hand-authored claim no control verifies. Restored to 'enforced' only when the deep-store rollup earns it. | Designed | L2 Designed | mas-mindforge.oversight-modes-machine-enforceable, mas-mindforge.action-authority-inventory | GovernedUI™ approval modesPurpose Permission™Authority GateEntity & Principal Registry |
| AI risk management (escalation before finality + third-party / vendor AI authority register)Downgraded 2026-09-03 (§70 honesty bar): every per-requirement control mapped for this framework is still Designed, not Enforced, so an 'enforced' group status was a hand-authored claim no control verifies. Restored to 'enforced' only when the deep-store rollup earns it. | Designed | L2 Designed | mas-mindforge.escalation-before-finality, mas-mindforge.third-party-vendor-authority-register | Authority Gateway (REQUIRE\_APPROVAL)Edge Governance Safety FloorAuthority RegisterGovernedUI™ escalation |
| AI lifecycle management (deployment controls at the Authority Gateway + monitoring/change as replay-provable Evidence Packs)KYE™ enforces approved deployment conditions + replay-provable monitoring/change evidence at the action boundary; the FI's pre-deployment validation and model-performance monitoring stay the FI's own (honest scope). Downgraded 2026-09-03 (§70 honesty bar): every per-requirement control mapped for this framework is still Designed, not Enforced, so an 'enforced' group status was a hand-authored claim no control verifies. Restored to 'enforced' only when the deep-store rollup earns it. | Designed | L2 Designed | mas-mindforge.deployment-controls-authority-gateway, mas-mindforge.monitoring-change-evidence-replay | Authority GatewayEvidence Pack™Replay-Proof™WORM audit hash-chain |
| Enablers (named accountability at the action boundary)KYE™ binds and proves named accountability at the boundary; staffing and running the three-lines-of-defence operating model stays the FI's own (honest scope). Downgraded 2026-09-03 (§70 honesty bar): every per-requirement control mapped for this framework is still Designed, not Enforced, so an 'enforced' group status was a hand-authored claim no control verifies. Restored to 'enforced' only when the deep-store rollup earns it. | Designed | L2 Designed | mas-mindforge.enablers-named-accountability | GovernedUI™ named-authority sign-offDelegated Auditability RailAuthority Finality™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

NIST AI RMF

#### NIST AI Risk Management Framework

1.0 · United States

Voluntary framework for managing AI risk across the Govern, Map, Measure, and Manage functions.

### 3

Enforced

### 1

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Govern function | Enforced | L3 Enforceable | GOVERN | Purpose Permission™Authority Gate |
| Map & Measure functions | Enforced | L3 Enforceable | MAP, MEASURE | Purpose Permission™WORM audit hash-chain |
| Manage function & incident response | Enforced | L3 Enforceable | MANAGE | WORM audit hash-chainDecision replay |
| Independently verifiable measurement evidenceMeasurement outcomes are recorded today; signed, externally verifiable measurement evidence is in build. | Designed | L2 Designed | MEASURE 2.x | Evidence Pack™ signing (COSE-Sign1) |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

NYC Local Law 144

#### NYC Local Law 144 — Automated Employment Decision Tools

2023 (in force 2023-07-05) · United States (New York City)

NYC law requiring a bias audit before an automated employment decision tool screens a candidate, with candidate notice and published results.

### 1

Enforced

### 1

Designed

### 0

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| AEDT bias audit | Enforced | L3 Enforceable | NYC Admin Code §20-871 | Evidence Pack™Authority Gate |
| Candidate notice & contestability | Designed | L2 Designed | NYC Admin Code §20-871(b) | Rights-Disputes Rail |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

NZ Algorithm Charter

#### NZ Algorithm Charter for Aotearoa New Zealand

2020 · New Zealand

Algorithm Charter for Aotearoa New Zealand (2020) — transparency, human oversight, and data/bias commitments for government use of algorithms. Per-requirement bijection at /compliance/nz-algorithm-charter.html.

### 2

Enforced

### 0

Designed

### 0

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Transparency + human oversight | Enforced | L3 Enforceable | Charter — transparency, Charter — human oversight | Decision Map™Evidence Pack™GovernedUI™Replay-Proof™ |
| Data clarity + bias management | Enforced | L3 Enforceable | Charter — data and bias | Data Classification EngineRisk Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

TBS ADM Directive

#### TBS Directive on Automated Decision-Making (Canada federal government)

TBS (amended 2023) · Canada

The Treasury Board Directive on Automated Decision-Making governing Canadian federal-government automated decision systems: the Algorithmic Impact Assessment, transparency notice, meaningful explanation, and quality-assurance + recourse. Per-requirement bijection at /compliance/tbs-directive-adm.html.

### 4

Enforced

### 0

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Algorithmic Impact Assessment | Enforced | L3 Enforceable | aia | Risk Engine |
| Transparency notice | Enforced | L3 Enforceable | notice | Reporting Engine |
| Meaningful explanation | Enforced | L3 Enforceable | explanation | Decision Map™Replay-Proof™ |
| Quality assurance + recourse | Enforced | L3 Enforceable | recourse | Reporting EngineWORM audit hash-chain |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

UK AI Assurance

#### UK AI Assurance (DSIT)

Introduction to AI Assurance, Feb 2024 · United Kingdom

The UK government's AI assurance toolkit — the measure / evaluate / communicate loop and the six assurance mechanisms that operationalise the UK AI principles. KYE Protocol™ is itself an assurance mechanism: it measures every governed AI action, evaluates it against purpose admissibility, and communicates it as signed, replayable evidence.

### 5

Enforced

### 1

Designed

### 1

Out of scope

7 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Measure, evaluate & communicate (the assurance loop)Every governed AI action is measured, evaluated against the purpose grant, and communicated as a signed Evidence Pack™ — assurance as a continuous runtime loop, not a point-in-time review. | Enforced | L3 Enforceable | §4.1 | WORM audit hash-chainEvidence Pack™Decision Map™ |
| Risk assessmentEvery agent action is admitted against a risk-scoped purpose grant before it runs; disallowed actions never execute. | Enforced | L3 Enforceable | §4.2, §5.4 | Purpose Permission™Authority Gate |
| Algorithmic impact assessmentEach decision's inputs and downstream effects are recorded in a Decision Map™; a per-deployment aggregate impact view is in build. | Designed | L2 Designed | §4.2, §5.5 | Decision Map™Evidence Pack™ |
| Bias auditBias and fairness assessment of model outputs is owned by the customer's model-evaluation process — consistent with the UK AI Framework fairness principle. | Out of scope | L1 Mapped | §4.2, §5.6 | — |
| Compliance auditAdherence to internal policy and regulation is continuously reviewable against the tamper-evident, append-only audit chain. | Enforced | L3 Enforceable | §4.2, §5.7 | WORM audit hash-chainControl mappings |
| Conformity assessmentThe KYE™ Conformance Pack™ is the test suite a conformity-assessment body runs; third-party UKAS-accredited certification remains external to the protocol. | Enforced | L3 Enforceable | §4.2, §5.8 | Conformance Pack™ |
| Formal verificationReplay-Proof™ is a deterministic, cryptographically-verifiable re-execution — a governed decision can be mathematically re-checked from public keys alone. | Enforced | L3 Enforceable | §4.2, §5.9 | Replay-Proof™Decision replay |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

UK AI

#### UK AI Regulatory Framework

2023 white paper · United Kingdom

The UK's pro-innovation AI principles and the DSIT AI assurance toolkit.

### 3

Enforced

### 1

Designed

### 1

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Safety, security & robustness | Enforced | L3 Enforceable | Principle 1 | Purpose Permission™Authority GateWORM audit hash-chain |
| Appropriate transparency & explainability | Enforced | L3 Enforceable | Principle 2 | WORM audit hash-chainDecision replay |
| Accountability & governance | Enforced | L3 Enforceable | Principle 4 | Authority GatePurpose Permission™ |
| Contestability & redress evidenceDecision inputs are replayable today; signed evidence supporting contestability and redress is in build. | Designed | L2 Designed | Principle 5 | Evidence Pack™ signing (COSE-Sign1)Decision Map™ signing (JWS-detached) |
| Fairness assessment of model outputsBias and fairness assessment of model outputs is owned by the customer's model-evaluation process. | Out of scope | L1 Mapped | Principle 3 | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

UK Equality Act 2010

#### UK Equality Act 2010

2010 · United Kingdom

UK statute making an automated selection rule that disadvantages a protected group unlawful indirect discrimination unless objectively justified.

### 1

Enforced

### 1

Designed

### 0

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Indirect discrimination (s.19) | Enforced | L3 Enforceable | Equality Act 2010 s.19 | Evidence Pack™Authority Gate |
| Protected characteristics (s.4) | Designed | L2 Designed | Equality Act 2010 s.4 | Data Governance Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

EO 14110

#### US EO 14110 — Safe, Secure & Trustworthy AI (biosecurity / dual-use)

2023 · United States

US Executive Order 14110 (2023) Safe/Secure/Trustworthy AI — biosecurity, nucleic-acid synthesis screening, and content provenance provisions (rescinded Jan 2025; the dual-use-bio + synthesis-screening + provenance obligation pattern it established remains the de-facto reference set). KYE Protocol™ governs whether an AI-generated sequence/molecule may proceed to a consequential action — the KYE™ AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Dual-use biology & synthesis screening | Designed | L2 Designed | us-eo-14110.4.4-synthesis-screening, us-eo-14110.4.4-dual-use-bio | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Content provenance & authentication | Designed | L2 Designed | us-eo-14110.4.5-provenance | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Human oversight of consequential AI action | Designed | L2 Designed | us-eo-14110.human-oversight | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

UNESCO AI Ethics

#### UNESCO Recommendation on the Ethics of Artificial Intelligence (2021)

2021 · International

The first global normative instrument on AI ethics, adopted (Nov 2021) by all 193 UNESCO member states. KYE Protocol™ operationalises the AI-action authority + evidence boundary of its values & principles — human oversight & determination, transparency & explainability, responsibility & accountability, privacy & data protection, fairness & non-discrimination, safety & security — with named accountability (Authority Finality™), a replay-derivable Evidence Pack™ and Decision Map™. KYE Protocol™ does NOT adjudicate the ethics of the outcome, and the environmental-sustainability and education/public-awareness principles are out-of-scope / customer-owned; coverage is never inflated. Per-requirement bijection at framework-coverage-bijection.

### 3

Enforced

### 3

Designed

### 0

Out of scope

6 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Human oversight & determination | Enforced | L3 Enforceable | unesco-ai-ethics.principle.human-oversight-determination | Purpose Permission™Authority Finality™ |
| Transparency & explainability of AI decisions | Enforced | L3 Enforceable | unesco-ai-ethics.principle.transparency-explainability | Decision Map™Evidence Pack™ |
| Responsibility & accountability — auditable, attributable outcomes | Enforced | L3 Enforceable | unesco-ai-ethics.principle.responsibility-accountability | Authority Finality™Evidence Pack™ |
| Right to privacy & data protection | Designed | L2 Designed | unesco-ai-ethics.principle.privacy-data-protection | Data Purpose Binding™Purpose Permission™ |
| Fairness & non-discrimination (contestability + audit evidence) | Designed | L2 Designed | unesco-ai-ethics.principle.fairness-non-discrimination | Decision Map™Evidence Pack™ |
| Safety & security — action-admissibility safety floor | Designed | L2 Designed | unesco-ai-ethics.principle.safety-security, unesco-ai-ethics.value.human-dignity-rights | Edge Governance Safety FloorPurpose Permission™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

US Chatbot Laws

#### US State AI-Chatbot Laws — consumer / customer chatbot safeguards

2024-2026 · United States

The wave of US state AI-chatbot statutes (13+ states; 7 with a private right of action at roughly $1,000/violation) — CA SB 243, Utah AI Mental Health Chatbot Act, NY, IL, et al. Four recurring themes: crisis protocols, minor protections, deception/disclosure, liability. KYE Protocol™ governs the AUTHORITY + EVIDENCE of the chatbot safeguard actions at the moment the interaction occurs — the KYE™ Chatbot Authority Pack™. It does not provide the chatbot/LLM, the clinical crisis content, or the GRC program. Per-requirement bijection at framework-coverage-bijection.

### 5

Enforced

### 0

Designed

### 2

Out of scope

7 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Jurisdiction-aware safeguard resolution | Enforced | L3 Enforceable | us-state-chatbot-laws.jurisdiction-resolution-applicable-safeguards | Action Admissibility™ GateCross-Jurisdiction Handoff RailAuthority Finality™ |
| Mental-health / crisis protocol | Enforced | L3 Enforceable | us-state-chatbot-laws.crisis-escalation-authority | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Minor protections | Enforced | L3 Enforceable | us-state-chatbot-laws.minor-protection-authority | Action Admissibility™ GateAuthority Finality™ |
| Deception / disclosure / anthropomorphism | Enforced | L3 Enforceable | us-state-chatbot-laws.disclosure-enforcement-authority | Action Admissibility™ GateAuthority Finality™ |
| Liability / private right of action — litigation evidence | Enforced | L3 Enforceable | us-state-chatbot-laws.litigation-evidence-capture | Evidence Pack™Replay-Proof™WORM Retention |
| Clinical crisis-counselling substance (out of scope)Crisis-service responsibility — clinical crisis content. KYE™ proves the escalation was authorised & triggered, not the content. Zero KYE™ controls (complement-not-compete). | Out of scope | L1 Mapped | us-state-chatbot-laws.clinical-crisis-counselling-substance | — |
| Chatbot / model behaviour & UX (out of scope)Model vendor / operator responsibility — the LLM, its outputs, age-estimation, and UX. Zero KYE™ controls (complement-not-compete). | Out of scope | L1 Mapped | us-state-chatbot-laws.chatbot-model-behaviour-and-ux | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Voluntary GenAI Code

#### Voluntary Code of Conduct — Advanced Generative AI (Canada)

ISED (Sept 2023) · Canada

Canada's voluntary code for advanced generative AI systems (ISED, 2023). Voluntary signatory program — all rows advisory: accountability, transparency, and human oversight + monitoring outcomes anchored to the KYE Protocol™ action-governance layer. Per-requirement bijection at /compliance/voluntary-code-genai.html.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Accountability | Designed | L2 Designed | accountability | Authority GateRisk Engine |
| Transparency | Designed | L2 Designed | transparency | Decision Map™Reporting Engine |
| Human oversight + monitoring | Designed | L2 Designed | oversight | Drift DetectorIncident Detector |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ISO 31000

#### ISO 31000:2018 — Risk management — Guidelines

2018 · International

ISO 31000:2018 risk-management principles, framework and process. KYE Protocol™ governs the authority, evidence and finality of AI-agent actions as a risk-treatment and risk-recording control inside the ISO 31000 process — it does not run the enterprise risk-management system. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Accountability + assigned authority for AI risk | Designed | L2 Designed | iso-31000.5.4.2 | Purpose Permission™GovernedUI |
| Risk identification + treatment at the action boundary | Designed | L2 Designed | iso-31000.6.4.2, iso-31000.6.5.2 | Decision Map™Authority Gate |
| Monitoring/review + replay-derivable recording | Designed | L2 Designed | iso-31000.6.6, iso-31000.6.7 | Evidence Pack™Replay Proof™Delegated Auditability |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Three Lines Model

#### The IIA's Three Lines Model (2020)

2020 · International

The IIA's Three Lines Model (2020). KYE Protocol™ supplies the runtime authority + evidence + assurance primitives the model assumes across first line (operational), second line (risk/compliance) and third line (internal audit) — it does not replace any line's people or mandate. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Governance accountability + governing-body oversight | Designed | L2 Designed | three-lines.principle-1, three-lines.principle-2 | Purpose Permission™GovernedUIEvidence Pack™ |
| First/second line authority + third-line assurance | Designed | L2 Designed | three-lines.principle-3, three-lines.principle-4 | Decision Map™Delegated Auditability |
| Independent verification + aligned value protection | Designed | L2 Designed | three-lines.principle-5, three-lines.principle-6 | Replay Proof™Evidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

MIT AI Risk Repository

#### MIT AI Risk Repository — Domain Taxonomy

2024 · International

MIT AI Risk Repository (2024) Domain Taxonomy — 7 domains. KYE Protocol™ addresses the 4 action-authority domains (privacy/security access, malicious misuse, human oversight, system-safety traceability/multi-agent) and is HONESTLY out of scope for the 3 content/societal domains (discrimination & toxicity, misinformation, socioeconomic & environmental). Coverage never inflated. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 4

Designed

### 3

Out of scope

7 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| D2 Privacy & Security — access bounded by purpose + tenant | Designed | L2 Designed | mit-risk.d2-privacy-security | Purpose Permission™Decision Map™Tenant Isolation |
| D4 Malicious Actors & Misuse — unauthorised action refused | Designed | L2 Designed | mit-risk.d4-malicious-misuse | Purpose Permission™Authority Gate |
| D5 Human-Computer Interaction — human oversight | Designed | L2 Designed | mit-risk.d5-human-computer-interaction | GovernedUI |
| D7 AI System Safety — traceability + multi-agent authority | Designed | L2 Designed | mit-risk.d7-traceability, mit-risk.d7-multi-agent | Evidence Pack™Replay Proof™Delegated Auditability |
| D1 Discrimination & Toxicity (content/fairness — out of scope)the protocol governs authority of agent ACTIONS, not content truth/fairness or macro-societal outcomes — this MIT domain is honestly out of scope; never inflated. | Out of scope | L1 Mapped | MIT domain (content/societal — outside the authority-of-action scope) | — |
| D3 Misinformation (content truth — out of scope)the protocol governs authority of agent ACTIONS, not content truth/fairness or macro-societal outcomes — this MIT domain is honestly out of scope; never inflated. | Out of scope | L1 Mapped | MIT domain (content/societal — outside the authority-of-action scope) | — |
| D6 Socioeconomic & Environmental (macro/societal — out of scope)the protocol governs authority of agent ACTIONS, not content truth/fairness or macro-societal outcomes — this MIT domain is honestly out of scope; never inflated. | Out of scope | L1 Mapped | MIT domain (content/societal — outside the authority-of-action scope) | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ATRS

#### Algorithmic Transparency Recording Standard (ATRS)

ATRS v3.0 (2025) · United Kingdom

The UK Government Algorithmic Transparency Recording Standard — mandatory for central-government departments and arm’s-length bodies publishing algorithmic tools that affect the public. KYE Protocol™ is the evidence source the ATRS record is populated FROM: every governed public-sector AI action emits a signed Evidence Pack™ carrying the tool’s purpose, decision map and capability profile, so the published transparency record is a projection of recorded runtime evidence rather than a hand-authored claim.

### 2

Enforced

### 1

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Tier 1 + Tier 2 transparency recordMarquee mapping — the Evidence Pack™ populates the ATRS Tier-1 overview and Tier-2 technical record; replay-verifiable from published keys. | Enforced | L3 Enforceable | Tier 1, Tier 2 | Evidence Pack™Decision Map™Capability Profile |
| Senior responsible ownerThe ATRS named owner resolves to the recorded named-authority decision for every consequential action. | Enforced | L3 Enforceable | Owner | Authority RegisterPurpose Permission™ |
| Maintain & re-publish on change§13 drift detection flags the behaviour change that re-opens the published record; the re-publication trigger workflow is in build. | Designed | L2 Designed | Maintenance | Resilience Loop™ drift signal |
| Public effect & appeal arrangementsThe substantive public-effect judgement and appeal design are the deploying body’s own responsibility; KYE™ supplies the contestability hooks, not the policy. | Out of scope | L1 Mapped | Impact | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

UK Gov AI Playbook

#### AI Playbook for the UK Government

Feb 2025 · United Kingdom

The UK Government AI Playbook’s ten principles for safe, effective and secure use of AI in government. KYE Protocol™ enforces the governance principles at the action boundary: meaningful named accountability, secure provenance-backed use, and meaningful human control on consequential decisions — each emitting a signed, replay-verifiable Evidence Pack™.

### 3

Enforced

### 1

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Meaningful accountabilityNamed human accountability recorded before every consequential action; the AI governance board maps to §36 approval modes. | Enforced | L3 Enforceable | Principle: accountability | Authority RegisterPurpose Permission™GovernedUI approval modes |
| Keeping AI use securePinned provenance + WORM-retained replay-verifiable Evidence Pack™ per action. | Enforced | L3 Enforceable | Principle: security | Replay-Proof™Evidence Pack™WORM audit |
| Meaningful human controlStaged finality (draft→recommendation→human-reviewed→citizen-facing→final); two-person sign-off on irreversible authorising-official assertions. | Enforced | L3 Enforceable | Principle: human control | GovernedUI sign-offDecision finality states |
| Lifecycle management & monitoringDrift monitoring + AI/ML systems inventory; the mandated review-cadence workflow is in build. | Designed | L2 Designed | Principle: lifecycle | Resilience Loop™§67 model-governance catalogue |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Orange Book

#### HMT Orange Book — Management of Risk

2023 · United Kingdom

HM Treasury’s Orange Book is the cross-government standard for risk management. KYE Protocol™ performs the identify-assess-monitor arc at the action boundary: every governed AI action is risk-scored and admitted against a risk-scoped purpose grant before it runs, and behaviour drift is monitored continuously through the Resilience Loop™.

### 2

Enforced

### 1

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Identify & assess riskRisk-scored admission against a risk-scoped purpose grant before the action runs. | Enforced | L3 Enforceable | Identify, Assess | Risk scorePurpose Permission™Decision Map™ |
| Monitor & respond§13 continuous drift detection + improvement records. | Enforced | L3 Enforceable | Monitor | Resilience Loop™ drift signal |
| Report & escalate to governance bodyAuthority register + attestations support reporting; the portfolio risk-report rendering is in build. | Designed | L2 Designed | Report | Authority RegisterCompliance attestation |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Magenta Book

#### HMT Magenta Book — Evaluation Guidance

2020 · United Kingdom

HM Treasury’s Magenta Book is the cross-government standard for evaluation of interventions. KYE Protocol™ supplies the recorded process evidence — what the AI tool actually did, for whom, under whose authority — that a process or impact evaluation of an AI intervention rests on, drawn from runtime Evidence Packs™ rather than reconstructed from scattered logs.

### 1

Enforced

### 1

Designed

### 1

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Process evaluationRecorded action evidence is the process the evaluator examines. | Enforced | L3 Enforceable | Process eval | Observed ActionEvidence Pack™Decision Map™ |
| Impact evaluationPopulation-impact classification supports impact evaluation; the per-cohort export for a counterfactual study is in build. | Designed | L2 Designed | Impact eval | Consequence Mapping Engine |
| Value-for-money & evaluation conclusionThe value-for-money judgement and analytical conclusion are the department’s evaluation function’s, not KYE™’s. | Out of scope | L1 Mapped | VfM | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ISO 9000

#### ISO 9000:2015 — Quality management systems

ISO 9000:2015 · International

ISO 9000:2015 defines the quality-management concepts of objective evidence, validation and change control — ‘objective evidence that requirements have been fulfilled’. The KYE™ Evidence Pack™ IS that objective evidence: a signed, replay-verifiable record that the named-authority, due-diligence and sign-off requirements were fulfilled before an AI-assisted output proceeded.

### 2

Enforced

### 1

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Objective evidence & verificationSigned replay-verifiable objective evidence that requirements were fulfilled. | Enforced | L3 Enforceable | 3.8.3 | Evidence Pack™Replay-Proof™Decision Map™ |
| Validation (fit for intended use)Purpose-scope admission confirms the output fit for its intended public-sector use at the action boundary. | Enforced | L3 Enforceable | 3.8.13 | Purpose Permission™Decision Engine |
| Change control & re-validation§13 drift signal flags the change that ought to trigger re-validation; the re-validation gate workflow is in build. | Designed | L2 Designed | Change control | Resilience Loop™ drift signal |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

UK AI Testing & Assurance (Public Sector)

#### AI Testing and Assurance Framework for the Public Sector

2024 · United Kingdom

The UK Cross-Government Testing Community framework for testing and assuring AI systems used in the public sector, pre-deployment and in-life. KYE Protocol™ runs pre-deployment scenario tests through the Scenario Engine, monitors in-life behaviour through the Resilience Loop™, and reconstructs an assurance record for an oversight reviewer through the §21 audit-replay machinery.

### 2

Enforced

### 1

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Pre-deployment testingAdversarial/policy scenarios run and risk-scored before admission to a consequential action path. | Enforced | L3 Enforceable | Pre-deployment | Scenario EngineRisk score |
| In-life assuranceContinuous drift detection + audit-pilot replay for ongoing assurance. | Enforced | L3 Enforceable | In-life | Resilience Loop™Audit Pilot™ |
| Assurance evidence & replayReconstructable assurance record; the Cross-Government-Testing-Community report rendering is in build. | Designed | L2 Designed | Assurance record | Audit-replay orchestratorRegulator-replay agent |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

EN 18286

#### EN 18286:2025 — Quality management system for high-risk AI systems

EN 18286:2025 (E) · European Union

European harmonised standard for the QMS obligation on providers of high-risk AI systems (supporting EU AI Act Article 17). PARTIAL MAPPING — only Clause 5.1 (the six non-delegable top-management duties) is mapped at this edition; the rest of the standard is not yet mapped and is deliberately omitted, not inflated. KYE™ governs the AUTHORITY, OVERSIGHT, and EVIDENCE dimensions of the QMS; it does not implement the provider's HR/training, compute-procurement, or sustainability program.

### 4

Enforced

### 2

Designed

### 0

Out of scope

6 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Quality policy & measurable objectives from regulatory purpose (5.1.a) | Enforced | L3 Enforceable | EN 18286:2025 Clause 5.1.a + Note 2 | Purpose Permission™Authority Register≤90-day attestation |
| Resources for the QMS — data-lineage/traceability storage over the retention period (5.1.b, lineage sub-duty only)Only the lineage/traceability-retention sub-duty maps to KYE™. Compute provisioning, human-capital competence/training, and energy-efficiency sustainability are provider-owned and out of KYE™ scope (not claimed). | Designed | L2 Designed | EN 18286:2025 Clause 5.1.b | WORM audit hash-chainobject-store immutability retention policy |
| Effective role responsibilities — human oversight, intervention thresholds, override/intervenability, automation-bias mitigation (5.1.c) | Enforced | L3 Enforceable | EN 18286:2025 Clause 5.1.c | KYE™ GovernedUI™ approval modesOversight envelope / override interfaceDelegated-authority bindingMeta-governance no-self-grant gate |
| QMS integrated into the provider's processes across the AI lifecycle — not a separate binder (5.1.d) | Enforced | L3 Enforceable | EN 18286:2025 Clause 5.1.d | Self-governance evidence-event familyCohesion Cascade™ |
| QMS achieves intended results — management review, nonconformity → corrective action (5.1.e) | Enforced | L3 Enforceable | EN 18286:2025 Clause 5.1.e | Reconciliation Engine™ declared-vs-deployed bijection≤90-day attestation |
| Communication of QMS importance & promotion of a responsible-AI culture (5.1.f + Note 1)KYE™ supplies the communication/education channel; sustaining a responsible-AI culture amid staff turnover/drift is a provider-owned people obligation and is not claimed as enforced. | Designed | L2 Designed | EN 18286:2025 Clause 5.1.f | Comms Rail · KYE™ Comms Engine™Learn Rail · KYE™ Learn™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

MAS AIRG (consultation)

#### MAS Consultation Paper on Guidelines on Artificial Intelligence Risk Management (AIRG)

consultation-2025-11 (final Guidelines not yet issued as of 2026-07-03) · Singapore

MAS's proposed sector-wide supervisory Guidelines on AI Risk Management (consultation paper published 13 November 2025; comments closed 31 January 2026): supervisory expectations on AI risk oversight, key AI risk-management systems, policies and procedures, AI life-cycle controls, and capabilities/capacity — explicitly covering Generative AI and AI agents, applied proportionately with a proposed 12-month transition after issuance. This instrument is REGISTERED in the §70 Framework Mapping Rail as a MONITORED consultation (the final Guidelines had not been issued at registration; the entry will be re-versioned on publication). It is distinct from MAS Project MindForge, the industry-co-created operationalisation handbook, which is deep-mapped separately. No requirement is bound while the text is non-final, so coverage is honestly reported as out of scope.

### 0

Enforced

### 0

Designed

### 1

Out of scope

1 requirement group — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Registered in the §70 rail as a monitored consultation instrument; text not yet finalHonest registered state (§70 mapping\_state=registered): the consultation crosswalks cleanly to existing KYE Protocol™ rails (AI oversight → §36 GovernedUI™ approval modes + Finality Gate; life-cycle controls → §13 Evidence Pack™ / Replay-Proof™; AI-agent expectations → §52 agent binding + §0.30 agents-as-principals), but the honesty bar forbids binding requirements to a non-final text — deep mapping runs through the §70 rail once MAS issues the Guidelines. Coverage is never inflated. | Out of scope | L1 Mapped | MAS AIRG consultation paper (13 Nov 2025) — proposed expectations on AI oversight, risk-management systems, life-cycle controls, and capabilities; not yet issued as final Guidelines, not yet decomposed into requirement-level mappings | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ISO/IEC 38507

#### ISO/IEC 38507:2022 — Governance implications of the use of AI by organizations

ISO/IEC 38507:2022 · International (ISO/IEC)

ISO/IEC 38507 gives the governing body guidance on the governance implications of AI, on the Evaluate-Direct-Monitor model. KYE Protocol™ governs the AUTHORITY dimension of that accountability: every AI-agent action is bound to a named accountable Principal under a directed purpose, with substantive human oversight and replay-provable evidence. KYE™ enforces the authority/evidence/oversight slice mechanically; the board process itself sits outside its scope (honest §70 tri-state).

### 4

Enforced

### 1

Designed

### 0

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Accountability & the governing body (non-delegable, EDM) | Enforced | L3 Enforceable | iso-iec-38507.governing-body-accountability, iso-iec-38507.accountability-for-outcomes, iso-iec-38507.governance-vs-management | §0.30 accountable Principaldelegation chainAuthority vs execution seamEvidence Pack™ |
| Direct — purpose alignment & acceptable-use policy | Enforced | L3 Enforceable | iso-iec-38507.purpose-alignment, iso-iec-38507.acceptable-use-policy | Purpose Permission™Rules Gateway™Decision Map™ |
| Evaluate — AI-specific considerations (autonomy, risk, data) | Designed | L3 Enforceable | iso-iec-38507.ai-characteristics-consequences, iso-iec-38507.risk-oversight, iso-iec-38507.data-governance-for-ai | bounded agent authorityrisk signals§31 data-use authority |
| Monitor — human oversight & continuous assurance | Enforced | L3 Enforceable | iso-iec-38507.material-decision-oversight, iso-iec-38507.continuous-monitoring | GovernedUI™ approval modesper-action re-check§34 reconciliation |
| Transparency, explainability & compliance obligations | Enforced | L3 Enforceable | iso-iec-38507.transparency-explainability, iso-iec-38507.compliance-obligations | Decision Map™ reason codesReplay-Proof™≤90-day attestation§70 mapping |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

MOW SOC

#### MOW Search Only Terms Contract (SOC)

socw/2 (2026) — immutable MOW-stewarded contract URL, robots.txt Terms Document Locator (tdl:) declaration · United Kingdom

Machine-readable standard contract (Movement for an Open Web / Preiskel & Co LLP, July 2026) licensing website access for Search Indexing only and pricing every other Access Event at the contract's default per-Product Access Fee. KYE Protocol™ maps it as publisher-side content-access authority: classify each automated access against the licence at the moment of access, seal Access Events as verifiable evidence, and derive the invoice-ready unlicensed-access schedule. The contract stays MOW's — KYE™ never re-hosts or interprets it: the SOC sets the terms; KYE™ proves the breach.

### 0

Enforced

### 7

Designed

### 1

Out of scope

8 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Machine-readable terms declaration | Designed | L2 Designed | mow-search-only-contract.terms-document-locator | Purpose Permission™Decision replayEvidence Pack™Replay-Proof™ |
| Purpose-limited licensed access | Designed | L2 Designed | mow-search-only-contract.purpose-limited-index-access | Purpose Permission™Decision replayEvidence Pack™Replay-Proof™ |
| Access-event evidence & records | Designed | L2 Designed | mow-search-only-contract.access-event-evidence | Purpose Permission™Decision replayEvidence Pack™Replay-Proof™ |
| Access-fee accrual & waiver conditions | Designed | L2 Designed | mow-search-only-contract.access-fee-accrual | Purpose Permission™Decision replayEvidence Pack™Replay-Proof™ |
| AI-scraping & dataset prohibition | Designed | L2 Designed | mow-search-only-contract.ai-scraping-prohibition | Purpose Permission™Decision replayEvidence Pack™Replay-Proof™ |
| Database-rights & bulk-extraction restriction | Designed | L2 Designed | mow-search-only-contract.database-rights | Purpose Permission™Decision replayEvidence Pack™Replay-Proof™ |
| Contract formation & court enforcement | Out of scope | L1 Mapped | mow-search-only-contract.legal-formation-and-enforcement | — |
| Accessibility & reader carve-out | Designed | L2 Designed | mow-search-only-contract.accessibility-carveout | Purpose Permission™Decision replayEvidence Pack™Replay-Proof™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

EW-AiRM

#### EW-AiRM — Enterprise-Wide AI Risk Management

EW-AiRM (Human-AI Institute / Markus Krebsz) · International

EW-AiRM is an enterprise-wide AI risk-management framework (Human-AI Institute / Markus Krebsz) that quantifies board risk appetite, assesses AI-necessity and organisational readiness, classifies risk against the MIT AI Risk Repository, sets non-negotiables (named accountability, tested human override, F-Critical no-averaging, named incident route) and an 8-Black-Swan resilience discipline, and produces a HAiPECR pre-deployment record. KYE Protocol™ maps the honest boundary — enterprise AI-risk governance is NOT per-action authority: system approval ≠ action authority. KYE™ enforces the runtime half (every consequential action admissibility-checked under a named authority, fail-closed, evidenced, replay-provable) and CONSUMES EW-AiRM's residual-risk acceptance and the HAiPECR verdict as an action policy, returning per-action authorised / denied / scope-inflation / expired-authority / revocation evidence. The quantification, readiness/necessity assessment, MIT-taxonomy classification, and Black-Swan scenario planning stay EW-AiRM's own work. From Board Risk Appetite to Runtime Proof. Per-requirement bijection at /compliance/ewairm.html.

### 3

Enforced

### 5

Designed

### 4

Out of scope

12 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| System approval vs per-action authority (the boundary) | Enforced | L3 Enforceable | ewairm.system-approval-not-action-authority | Authority GatePurpose Permission™Decision replayReplay-Proof™ |
| Non-negotiable — named accountability | Enforced | L3 Enforceable | ewairm.non-negotiable-named-accountability | Named principalAuthority GateEvidence Pack™ |
| Non-negotiable — no score-averaging over a critical failure | Enforced | L3 Enforceable | ewairm.f-critical-no-averaging-override | Fail-closed admissibilityDecision replayReplay-Proof™ |
| Non-negotiable — tested human override | Designed | L2 Designed | ewairm.non-negotiable-tested-human-override | GovernedUI™ HITLKill-switch |
| Residual-risk acceptance → runtime condition | Designed | L2 Designed | ewairm.residual-risk-acceptance-as-authority-condition | Purpose Permission™Scope condition |
| HAiPECR record consumption | Designed | L2 Designed | ewairm.documented-haipecr-consumption | Decision replayAction policy |
| Non-negotiable — named incident route | Designed | L2 Designed | ewairm.non-negotiable-named-incident-route | Contestability routeEvidence Pack™ |
| Black-Swan resilience — runtime evidence | Designed | L2 Designed | ewairm.black-swan-runtime-resilience-evidence | Resilience Loop™No-SPOFReplay-Proof™ |
| Board risk-appetite quantificationQuantifying board-level AI risk appetite is EW-AiRM's enterprise-risk work; KYE™ consumes an already-decided residual-risk acceptance as a runtime condition but does not quantify appetite. | Out of scope | L1 Mapped | ewairm.board-risk-appetite-quantification | — |
| Organisational-readiness assessmentPeople / process / culture / governance-maturity readiness assessment is an organisational-diagnostic activity KYE™ does not perform or replace. | Out of scope | L1 Mapped | ewairm.organisational-readiness-assessment | — |
| AI-necessity assessmentWhether AI should be used at all (necessity / proportionality) is a judgement KYE™ does not adjudicate; KYE™ governs the authority of AI actions once AI is deployed. | Out of scope | L1 Mapped | ewairm.ai-necessity-assessment | — |
| MIT AI Risk Repository taxonomyClassifying risks against the MIT AI Risk Repository is an analytic activity owned by the enterprise; KYE™ enforces authority at the action boundary regardless of how a risk is taxonomised. | Out of scope | L1 Mapped | ewairm.mit-risk-taxonomy-classification | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

HAiPECR

#### HAiPECR — Human-AI Pre-deployment Evidence & Certification Record

HAiPECR (Human-AI Institute / Markus Krebsz, OECD-listed Apr 2023) · International

HAiPECR (Human-AI Institute / Markus Krebsz; OECD Catalogue of Tools & Metrics for Trustworthy AI, April 2023) is a pre-deployment evidence-and-certification record across seven dimensions — human oversight, accountability, transparency & explainability, privacy & data, ethics & fairness, compliance & legal, resilience & security — culminating in a deploy / do-not-deploy verdict. KYE Protocol™ CONSUMES the HAiPECR credential/verdict as an action policy and enforces the runtime half: dimensions that resolve to a real KYE™ runtime artefact are enforced/designed, and a do-not-deploy verdict makes consequential actions inadmissible at the §12 boundary — returning per-action authorised / denied / scope-inflation / expired-authority / revocation evidence. Ethics & fairness SCORING and the authoring of the HAiPECR record itself stay the human-expert's work (KYE™ proves authority, not model fairness). From Board Risk Appetite to Runtime Proof. Per-requirement bijection at /compliance/haipecr.html.

### 1

Enforced

### 6

Designed

### 1

Out of scope

8 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Dimension — accountability | Enforced | L3 Enforceable | haipecr.accountability | Named principalAuthority GateEvidence Pack™ |
| Dimension — human oversight | Designed | L2 Designed | haipecr.human-oversight | GovernedUI™ HITLKill-switch |
| Dimension — transparency & explainability | Designed | L2 Designed | haipecr.transparency-explainability | Decision Map™Evidence Pack™ |
| Dimension — privacy & data | Designed | L2 Designed | haipecr.privacy-data | Data-use admissibilityMemory Authority Rail™ |
| Dimension — compliance & legal | Designed | L2 Designed | haipecr.compliance-legal | Framework Mapping Rail™Decision replay |
| Dimension — resilience & security | Designed | L2 Designed | haipecr.resilience-security | Resilience Loop™No-SPOFReplay-Proof™ |
| Deploy-gate verdict consumption | Designed | L2 Designed | haipecr.deploy-gate-verdict-consumption | Action policyPurpose Permission™Decision replay |
| Dimension — ethics & fairnessScoring the ethical acceptability and fairness of model behaviour is a model-evaluation activity owned by the builder and the enterprise's ethics function; KYE™ proves an action was authorised, evidenced, and replayable, not that the model is fair. | Out of scope | L1 Mapped | haipecr.ethics-fairness | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

### Data protection

Personal-data regulation covering lawful basis, data-subject rights, and processing accountability.

Alberta PIPA

#### Alberta PIPA — Personal Information Protection Act (Alberta)

S.A. 2003, c. P-6.5 · Canada

Alberta's private-sector privacy law (PIPA), substantially similar to PIPEDA and the first Canadian private-sector law with mandatory breach notification: consent, protection of personal information, and breach notification. Per-requirement bijection at /compliance/alberta-pipa.html.

### 2

Enforced

### 1

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Consent (ss.7-8) | Enforced | L3 Enforceable | s7 | Purpose Permission™ |
| Protection of personal information (s.34) | Enforced | L3 Enforceable | s34 | Authority Gate |
| Breach notification (s.34.1) | Designed | L2 Designed | s34.1 | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

DSG

#### Datenschutzgesetz (DSG, BGBl. I Nr. 165/1999, as amended 2018)

2018 (GDPR implementing act) · Austria

DSG is Austria's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Austria-specific national deltas here. Per-requirement bijection at /compliance/at-dsg.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

APPI

#### APPI — Act on the Protection of Personal Information

Act No. 57 of 2003, as amended (2022) · Japan

Japan's Act on the Protection of Personal Information, supervised by the Personal Information Protection Commission (PPC) — purpose-of-use limitation, security control measures, cross-border transfer, disclosure/access rights and breach reporting. KYE Protocol™ governs the personal-data obligations that bind an AI-supported action; the organisational privacy programme stays out of scope. Per-requirement bijection at /compliance/appi.html.

### 2

Enforced

### 1

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Purpose-of-use limitation & security control measures | Enforced | L3 Enforceable | APPI Art. 17-18, APPI Art. 23 | Purpose Permission™Authority Resolution™Data Classification Engine |
| Cross-border transfer & disclosure/access rights | Enforced | L3 Enforceable | APPI Art. 28 / 31, APPI Art. 33-35 | Cross-Border Evidence agentDecision Map™Replay-Proof™Evidence Pack™ |
| Breach reporting to the PPCKYE™ assembles the PPC notification package from the leakage evidence; the regulator-side delivery channel to the PPC is designed pending the per-jurisdiction reporting connector. | Designed | L1 Mapped | APPI Art. 26 | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

BC PIPA

#### BC PIPA — Personal Information Protection Act (British Columbia)

S.B.C. 2003, c. 63 · Canada

British Columbia's private-sector privacy law (PIPA), substantially similar to PIPEDA: consent, reasonable security, and access/correction. Per-requirement bijection at /compliance/bc-pipa.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Consent (ss.6-8) | Enforced | L3 Enforceable | s6 | Purpose Permission™ |
| Reasonable security (s.34) | Enforced | L3 Enforceable | s34 | Authority Gate |
| Access + correction (ss.23-24) | Enforced | L3 Enforceable | s23 | Reporting EngineWORM audit hash-chain |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Belgian Data Protection Act 2018

#### Loi du 30 juillet 2018 — Belgian Data Protection Act

2018 (GDPR implementing act) · Belgium

Belgian Data Protection Act 2018 is Belgium's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Belgium-specific national deltas here. Per-requirement bijection at /compliance/be-dpa-2018.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Bulgarian Personal Data Protection Act

#### Personal Data Protection Act (amended 2019 to implement the GDPR)

2018 (GDPR implementing act) · Bulgaria

Bulgarian Personal Data Protection Act is Bulgaria's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Bulgaria-specific national deltas here. Per-requirement bijection at /compliance/bg-pdpa.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

nFADP

#### nFADP / revDSG — revised Federal Act on Data Protection (in force 1 Sept 2023)

in force 2023 · Switzerland

Switzerland's revised Federal Act on Data Protection (nFADP/revDSG) — a sovereign, GDPR-aligned statute under an EU adequacy decision. this registry maps the Swiss national deltas; AI-system governance defers to the directly-applicable obligations Switzerland references. Per-requirement bijection at /compliance/ch-nfadp.html.

### 4

Enforced

### 0

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| National statute (non-EU, adequacy) — nFADP/revDSG lawful-purpose + accountability | Enforced | L3 Enforceable | nfadp-basis | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
| Cross-border transfer / adequacy regime (non-EU) | Enforced | L3 Enforceable | adequacy-cross-border | Authority GateEvidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Law 125(I)/2018

#### Law 125(I)/2018 (providing for the protection of natural persons with regard to the processing of personal data)

2018 (GDPR implementing act) · Cyprus

Law 125(I)/2018 is Cyprus's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Cyprus-specific national deltas here. Per-requirement bijection at /compliance/cy-law-125-2018.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Zákon 110/2019

#### Zákon č. 110/2019 Sb., o zpracování osobních údajů

2018 (GDPR implementing act) · Czech Republic

Zákon 110/2019 is Czech Republic's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Czech Republic-specific national deltas here. Per-requirement bijection at /compliance/cz-zakon-110-2019.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

BDSG

#### BDSG — Bundesdatenschutzgesetz (Federal Data Protection Act, 2018)

2018 (GDPR implementing act) · Germany

BDSG is Germany's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Germany-specific national deltas here. Per-requirement bijection at /compliance/de-bdsg.html.

### 4

Enforced

### 0

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
| Employee-data processing (BDSG §26, works-council co-determination) | Enforced | L3 Enforceable | employee-data-bdsg-26 | Purpose Permission™Decision Map™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Databeskyttelsesloven

#### Databeskyttelsesloven (Lov nr. 502 af 23. maj 2018)

2018 (GDPR implementing act) · Denmark

Databeskyttelsesloven is Denmark's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Denmark-specific national deltas here. Per-requirement bijection at /compliance/dk-databeskyttelsesloven.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

LOPDGDD

#### LOPDGDD — Ley Orgánica 3/2018 de Protección de Datos Personales y garantía de los derechos digitales

2018 (GDPR implementing act) · Spain

LOPDGDD is Spain's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Spain-specific national deltas here. Per-requirement bijection at /compliance/es-lopdgdd.html.

### 4

Enforced

### 0

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
| LOPDGDD Título X digital rights (disconnection, digital-will, workplace) | Enforced | L3 Enforceable | digital-rights-titulo-x | DSAR AgentEvidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Tietosuojalaki

#### Tietosuojalaki (1050/2018) — Data Protection Act

2018 (GDPR implementing act) · Finland

Tietosuojalaki is Finland's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Finland-specific national deltas here. Per-requirement bijection at /compliance/fi-tietosuojalaki.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Loi Informatique et Libertés

#### Loi Informatique et Libertés (Act No. 78-17, as amended) + CNIL

2018 (GDPR implementing act) · France

Loi Informatique et Libertés is France's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the France-specific national deltas here. Per-requirement bijection at /compliance/fr-lil.html.

### 4

Enforced

### 0

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
| Health-data HDS-certified hosting + CNIL reference methodologies | Enforced | L3 Enforceable | health-data-hds | Data Classification EngineAuthority Gate |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

CCPA/CPRA

#### CCPA/CPRA — California Consumer Privacy Act (as amended by the CPRA)

Cal. Civ. Code §1798.100 et seq. (2018, amended by CPRA 2020) · United States

The California Consumer Privacy Act (as amended by the CPRA) grants California consumers rights over their personal information — notice at collection, the right to know/access, delete, correct, opt out of sale/sharing, limit the use of sensitive PI, and non-discrimination for exercising those rights. This framework is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: its consumer-rights structure overlaps heavily with the already-deep-mapped GDPR and crosswalks to existing KYE Protocol™ rails (right to know/delete/correct → §31 Data Governance Pack & the DSAR evidence agent; opt-out of sale/sharing & limit-use → §12 Purpose Permission™; data-as-authority lifecycle → §63 Memory Authority Rail), but no requirement has yet been bound at the requirement level. Per the §70 honesty bar, coverage is reported out of scope pending deep mapping rather than claimed as enforced.

### 0

Enforced

### 0

Designed

### 1

Out of scope

1 requirement group — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping\_state=registered): candidate crosswalks to §31 / §12 / §63 and the existing GDPR deep-map are noted in the summary but NOT yet bound at the requirement level, so coverage stays out of scope until the deep mapping runs through the §70 rail — never inflated to imply enforcement that does not exist. | Out of scope | L1 Mapped | CCPA/CPRA consumer rights (notice, know/access, delete, correct, opt-out of sale/sharing, limit sensitive PI, non-discrimination — not yet decomposed into requirement-level mappings) | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

GDPR

#### GDPR — General Data Protection Regulation

Regulation (EU) 2016/679 · European Union

EU regulation governing the processing of personal data.

### 4

Enforced

### 1

Designed

### 0

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Lawful basis & purpose limitation | Enforced | L3 Enforceable | Art. 5, Art. 6 | Purpose Permission™Authority Gate |
| Data-subject rights handling | Enforced | L3 Enforceable | Art. 12-22 | Purpose Permission™WORM audit hash-chain |
| Records of processing & accountability | Enforced | L3 Enforceable | Art. 30 | WORM audit hash-chainDecision replay |
| Integrity, confidentiality & signed evidenceAccess to personal data is governed today; signed integrity evidence and automated key rotation are in build. | Designed | L2 Designed | Art. 32 | Evidence Pack™ signing (COSE-Sign1)Automated key rotation |
| International transfers (Chapter V) — Schrems II / SCC / adequacy§72 Jurisdiction & Data-Sovereignty Authority surfaces the GDPR Chapter V cross-border requirements already deep-mapped in internal Each crossing emits a signed kye.cross\_border.transfer.v1 carrying the lawful\_basis (adequacy / SCC + Transfer Impact Assessment) and the residency\_verdict, so the Art. 44-49 transfer-impact assessment is the evidence pack itself. | Enforced | L3 Enforceable | Art. 44, Art. 45, Art. 46, Art. 49 | Cross-Border Transfer Record (kye.cross\_border.transfer.v1)Jurisdiction Attestation (kye.jurisdiction.attestation.v1)Residency Verdict (§72) |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

GDPR Art. 22

#### GDPR Article 22 — Automated Decision-Making

Regulation (EU) 2016/679 (GDPR) — Article 22 (automated individual decision-making, including profiling) + Articles 13–15 / Recital 71 · European Union

GDPR Article 22 gives data subjects the right not to be subject to solely-automated similarly-significant decisions without safeguards — human intervention, meaningful information about the logic, and the right to contest. KYE Protocol™ governs whether an AI-assisted insurance decision in scope may proceed — under a recorded named-authority (the human-involvement safeguard), with a recorded adverse-action reason-code (meaningful information about the logic), a signed replay-provable Evidence Pack™ per decision, and an appeal / contestability record (the right to contest and to human intervention). The lawful basis / substantive decision / risk pricing on the merits stays the controller's own work (honest scope, §0). Per-requirement bijection at /compliance/gdpr-automated-decision.html.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Human involvement / named-authority safeguard (Art. 22(3)) | Enforced | L3 Enforceable | gdpr-automated-decision.art22-human-involvement-safeguard | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Right to contest & human intervention (Recital 71) | Enforced | L3 Enforceable | gdpr-automated-decision.art22-contest-human-intervention | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Meaningful information about the logic / adverse-action reason (Art. 13–15) | Enforced | L3 Enforceable | gdpr-automated-decision.art13-15-meaningful-information-logic | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Lawful basis, substantive decision & pricing on the meritsThe lawful basis for the processing / the substantive decision / the risk pricing on the merits is the controller's own work — KYE™ is an AI-authority and evidence layer at the action boundary, not a legal-basis, decision, or pricing engine. | Out of scope | L1 Mapped | gdpr-automated-decision.lawful-basis-substantive-decision | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Law 4624/2019

#### Law 4624/2019 (measures implementing the GDPR)

2018 (GDPR implementing act) · Greece

Law 4624/2019 is Greece's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Greece-specific national deltas here. Per-requirement bijection at /compliance/gr-law-4624-2019.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Info Act

#### Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Info Act, GDPR-aligned)

2018 (GDPR implementing act) · Hungary

Info Act is Hungary's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Hungary-specific national deltas here. Per-requirement bijection at /compliance/hu-info-act.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Data Protection Act 2018

#### Data Protection Act 2018

2018 (GDPR implementing act) · Ireland

Data Protection Act 2018 is Ireland's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Ireland-specific national deltas here. Per-requirement bijection at /compliance/ie-dpa-2018.html.

### 4

Enforced

### 0

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |
| One-Stop-Shop lead supervisory authority (DPC) — cross-border accountability | Enforced | L3 Enforceable | lead-supervisory-oss | Evidence Pack™Reporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ISO 23081

#### ISO 23081-1:2017 — Managing Metadata for Records (records-metadata spine)

2017 · Global

ISO 23081-1:2017 records-metadata spine and AUTHORITY ANCHOR for the InSight DXP connector contract. KYE Protocol™ CONSUMES records metadata (agent, classification, event-history) as the input signal at the action boundary (enforced: classification-driven-authority, custody→authority binding, agent→principal binding); records-metadata creation / management is out-of-scope (owned by Iron Mountain InSight DXP).

### 2

Enforced

### 0

Designed

### 2

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Metadata-driven authority decision (authority overlay) | Enforced | L3 Enforceable | iso-23081.classification-driven-authority, iso-23081.event-history-evidence | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Agent-metadata binding to a KYE-resolved principal (authority overlay) | Enforced | L3 Enforceable | iso-23081.agent-metadata-principal-binding | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Metadata creation & capture (records-management) | Out of scope | L1 Mapped | iso-23081.metadata-creation-capture | — |
| Metadata management & maintenance (records-management) | Out of scope | L1 Mapped | iso-23081.metadata-management-maintenance | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Codice Privacy

#### Codice in materia di protezione dei dati personali (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018)

2018 (GDPR implementing act) · Italy

Codice Privacy is Italy's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Italy-specific national deltas here. Per-requirement bijection at /compliance/it-codice-privacy.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Luxembourg Data Protection Act 2018

#### Loi du 1er août 2018 portant organisation de la Commission nationale pour la protection des données

2018 (GDPR implementing act) · Luxembourg

Luxembourg Data Protection Act 2018 is Luxembourg's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Luxembourg-specific national deltas here. Per-requirement bijection at /compliance/lu-cnpd.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

UAVG

#### UAVG — Uitvoeringswet Algemene verordening gegevensbescherming (GDPR Implementation Act, 2018)

2018 (GDPR implementing act) · Netherlands

UAVG is Netherlands's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Netherlands-specific national deltas here. Per-requirement bijection at /compliance/nl-uavg.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Personopplysningsloven

#### Personopplysningsloven (LOV-2018-06-15-38) — GDPR incorporated via the EEA Agreement

2018 (GDPR implementing act) · Norway

Personopplysningsloven is Norway's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Norway-specific national deltas here. Per-requirement bijection at /compliance/no-personopplysningsloven.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

NZ Privacy Act 2020

#### New Zealand Privacy Act 2020

Privacy Act 2020 (NZ) · New Zealand

The NZ Information Privacy Principles + Part 6 notifiable privacy breaches. Per-requirement bijection at /compliance/nz-privacy-act-2020.html.

### 2

Enforced

### 0

Designed

### 0

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| IPP 5 security, IPP 10 use-limitation, IPP 6 access | Enforced | L3 Enforceable | IPP 5, IPP 10, IPP 6 | Authority GatePurpose Permission™DSAR Evidence agentReplay-Proof™ |
| Part 6 notifiable privacy breachDetection + package assembly enforced; delivery channel to the OPC is in build. | Enforced | L3 Enforceable | Privacy Act 2020 Part 6 | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

PIPEDA

#### PIPEDA — Personal Information Protection and Electronic Documents Act

S.C. 2000, c. 5 · Canada

Canada's federal private-sector privacy law (PIPEDA, S.C. 2000, c. 5): the ten Schedule 1 fair-information principles plus mandatory breach-of-security-safeguards reporting (s.10.1). Per-requirement bijection at /compliance/pipeda.html.

### 5

Enforced

### 1

Designed

### 0

Out of scope

6 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Accountability + openness (Sch.1 4.1, 4.8) | Enforced | L3 Enforceable | sch1-4.1 | Authority GateReporting Engine |
| Purpose + consent (Sch.1 4.2-4.3) | Enforced | L3 Enforceable | sch1-4.3 | Decision Map™Purpose Permission™ |
| Limiting collection/use/retention (Sch.1 4.4-4.5) | Enforced | L3 Enforceable | sch1-4.5 | Authority GatePurpose Permission™ |
| Safeguards (Sch.1 4.7) | Enforced | L3 Enforceable | sch1-4.7 | Authority Gate |
| Individual access (Sch.1 4.9) | Enforced | L3 Enforceable | sch1-4.9 | Reporting EngineWORM audit hash-chain |
| Breach reporting (s.10.1) | Designed | L2 Designed | s10.1 | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

UODO

#### Ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych (Personal Data Protection Act)

2018 (GDPR implementing act) · Poland

UODO is Poland's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Poland-specific national deltas here. Per-requirement bijection at /compliance/pl-uodo.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Privacy Act 1988

#### Privacy Act 1988 (Cth) — ADM transparency + APPs

ADM reform (Privacy and Other Legislation Amendment Act 2024) · Australia

The Australian Privacy Principles + the 2024 automated-decision-making transparency reform (ADM provisions commence Dec 2026). Per-requirement bijection at /compliance/privacy-act-1988.html.

### 2

Enforced

### 0

Designed

### 0

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Automated decision-making transparency | Enforced | L3 Enforceable | Privacy Act 2024 reform — ADM | Decision Map™Evidence Pack™Replay-Proof™ |
| APP 1 open management + APP 11 security of personal information | Enforced | L3 Enforceable | APP 1, APP 11 | Authority GatePurpose Permission™Reporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Lei 58/2019

#### Lei n.º 58/2019 (assegura a execução do RGPD)

2018 (GDPR implementing act) · Portugal

Lei 58/2019 is Portugal's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Portugal-specific national deltas here. Per-requirement bijection at /compliance/pt-lei-58-2019.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Quebec Law 25

#### Quebec Law 25 — Private Sector personal-information modernisation

S.Q. 2021, c. 25 · Canada

Quebec's modernised private-sector privacy regime (Law 25, fully in force Sept 2024): privacy-impact assessment, automated-decision transparency, confidentiality-incident reporting to the CAI, data portability, and express consent for sensitive information. Per-requirement bijection at /compliance/quebec-law-25.html.

### 3

Enforced

### 2

Designed

### 0

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Privacy impact assessment (s.3.3) | Enforced | L3 Enforceable | s3.3 | Decision Map™Risk Engine |
| Automated-decision transparency (s.12.1) | Enforced | L3 Enforceable | s12.1 | Decision Map™Replay-Proof™ |
| Confidentiality-incident reporting (s.3.5-3.8) | Designed | L2 Designed | s3.5 | Incident DetectorReporting Engine |
| Data portability (s.27) | Designed | L2 Designed | s27 | Reporting EngineWORM audit hash-chain |
| Consent for sensitive information (s.12) | Enforced | L3 Enforceable | s12 | Authority GatePurpose Permission™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Law 190/2018

#### Law No. 190/2018 (implementing measures for the GDPR)

2018 (GDPR implementing act) · Romania

Law 190/2018 is Romania's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Romania-specific national deltas here. Per-requirement bijection at /compliance/ro-law-190-2018.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Swedish Data Protection Act

#### Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning

2018 (GDPR implementing act) · Sweden

Swedish Data Protection Act is Sweden's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Sweden-specific national deltas here. Per-requirement bijection at /compliance/se-dpa.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Act 18/2018

#### Act No. 18/2018 Coll. on Personal Data Protection

2018 (GDPR implementing act) · Slovakia

Act 18/2018 is Slovakia's national statute implementing/supplementing the GDPR. Substantive obligations reuse the deep GDPR per-article registry (edged via framework↔jurisdiction); this registry maps only the Slovakia-specific national deltas here. Per-requirement bijection at /compliance/sk-act-18-2018.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GDPR transposition (national basis) — substantive obligations reuse the GDPR registry | Enforced | L3 Enforceable | gdpr-transposition | Purpose Permission™Decision Map™ |
| Supervisory authority + accountability — disclosable processing account | Enforced | L3 Enforceable | supervisory-authority | Evidence Pack™Reporting Engine |
| Breach notification (national channel) — Art. 33/34 record assembly | Enforced | L3 Enforceable | breach-notification | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

China PIPL

#### PIPL — Personal Information Protection Law of the People's Republic of China

PIPL (effective 2021-11-01) · China

PIPL governs the processing and cross-border provision of personal information of individuals in the PRC. Chapter III sets the lawful routes for cross-border provision (CAC security assessment, CAC standard contract, or personal-information-protection certification) plus a data-localisation duty for critical-information-infrastructure operators and large processors. This framework is REGISTERED in the §70 Framework Mapping Rail and surfaced by §72 (Jurisdiction & Data-Sovereignty Authority) at the cross-border admissibility boundary; deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.

### 0

Enforced

### 0

Designed

### 1

Out of scope

1 requirement group — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping\_state=registered): declared in framework-registry.json but no PIPL requirement is bound to a KYE Protocol™ artefact yet. The §72 cross-border admissibility binding (kye.cross\_border.transfer.v1.residency\_verdict) is platform-level and applies across regimes; PIPL-specific deep mapping (CAC routes, localisation duties) is scheduled through the §70 rail. Coverage is never inflated. | Out of scope | L1 Mapped | PIPL Chapter III — cross-border provision of personal information (Arts. 38-43); full text not yet decomposed into requirement-level mappings | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

UK IDTA / Data Bridge

#### UK International Data Transfer regime — IDTA, Addendum and UK Data Bridge

IDTA + International Data Transfer Addendum (in force 2022-03-21) · United Kingdom

The UK regime for restricted international transfers under UK GDPR / DPA 2018 ss.17A-19: the ICO International Data Transfer Agreement (IDTA), the UK Addendum to the EU SCCs, and UK adequacy regulations ('data bridges'). This framework is REGISTERED in the §70 Framework Mapping Rail and surfaced by §72 (Jurisdiction & Data-Sovereignty Authority) at the cross-border admissibility boundary; deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.

### 0

Enforced

### 0

Designed

### 1

Out of scope

1 requirement group — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping\_state=registered): declared in framework-registry.json but no UK-transfer requirement is bound to a KYE Protocol™ artefact yet. The §72 cross-border admissibility binding (kye.cross\_border.transfer.v1.residency\_verdict) is platform-level; UK-IDTA-specific deep mapping (IDTA clauses, data-bridge adequacy) is scheduled through the §70 rail. Coverage is never inflated. | Out of scope | L1 Mapped | UK GDPR Chapter V + DPA 2018 ss.17A-19; ICO IDTA / Addendum / data-bridge adequacy regulations — full text not yet decomposed into requirement-level mappings | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Singapore PDPA

#### Singapore Personal Data Protection Act 2012 (PDPA)

PDPA 2012 (No. 26 of 2012), as amended 2020 · Singapore

Singapore's baseline data-protection statute, administered by the Personal Data Protection Commission (PDPC): consent, notification and purpose-limitation obligations, deemed consent by notification, the legitimate-interests exception, mandatory data-breach notification, data portability, and the Do Not Call registry (as amended by the Personal Data Protection (Amendment) Act 2020). This framework is REGISTERED in the §70 Framework Mapping Rail — distinct from Bulgaria's PDPA, which is registered separately — and connects to the §63 Memory Authority Rail, whose four memory-lifecycle schema deltas were validated against Singapore-PDPC guidance. Deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.

### 0

Enforced

### 0

Designed

### 1

Out of scope

1 requirement group — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping\_state=registered): declared in framework-registry.json but no PDPA requirement is bound to a KYE Protocol™ artefact yet. The §63 Memory Authority Rail's Singapore-PDPC-validated schema deltas (ai\_specific\_notice, withdrawal\_route, use\_type, use\_admissibility\_ref) are platform-level and cross-regime; PDPA-specific deep mapping is scheduled through the §70 rail. Coverage is never inflated. | Out of scope | L1 Mapped | PDPA 2012 Parts III-VIA — consent, purpose limitation, notification, access/correction, data-breach notification, data portability; full text not yet decomposed into requirement-level mappings | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

DPDP Act 2023

#### Digital Personal Data Protection Act, 2023

Act No. 22 of 2023 · India

KYE™ governs the AUTHORITY + EVIDENCE layer of personal-data processing at the action boundary: whether a consequential action against personal data was authorised under a declared purpose (§12), and whether that decision is sealed and replayable (§13/§30). KYE™ is OUT-OF-SCOPE for the substantive data-governance obligations a Data Fiduciary owes directly — obtaining valid consent from Data Principals, publishing notices, appointing a Data Protection Officer, conducting Data Protection Impact Assessments, and answering the Board. Those are the customer's own systems, processes and counsel; KYE™ evidences the action, it does not discharge the duty (§70 §4). Deep per-requirement mapping: 8 requirements, 3 enforced by KYE™ runtime, 5 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.

### 1

Enforced

### 0

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Authority + evidence at the action boundary — enforced by KYE™ runtime and verified by CI | Enforced | L3 Enforceable | dpdp-act-2023.PURPOSE-LIMITATION — Personal data processed only for the purpose for which consent was given, dpdp-act-2023.ACTION-EVIDENCE — Every consequential action on personal data is evidenced and replayable, dpdp-act-2023.ERASURE-ROUTE — Data Principal right to erasure is routed and evidenced | kye.compliance.attestation.v1kye.evidence.decision\_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context\_seal.v1internalinternalinternal |
| Obligations owed directly by the regulated entity — NOT discharged by KYE™KYE™ governs the AUTHORITY + EVIDENCE layer of personal-data processing at the action boundary: whether a consequential action against personal data was authorised under a declared purpose (§12), and whether that decision is sealed and replayable (§13/§30). KYE™ is OUT-OF-SCOPE for the substantive data-governance obligations a Data Fiduciary owes directly — obtaining valid consent from Data Principals, publishing notices, appointing a Data Protection Officer, conducting Data Protection Impact Assessments, and answering the Board. Those are the customer's own systems, processes and counsel; KYE™ evidences the action, it does not discharge the duty (§70 §4). | Out of scope | L1 Mapped | dpdp-act-2023.NOTICE-CONSENT — Itemised notice and valid consent obtained from the Data Principal, dpdp-act-2023.BREACH-INTIMATION — Personal-data breach intimated to the Board and affected Data Principals, dpdp-act-2023.SDF-OBLIGATIONS — Significant Data Fiduciary duties — DPO, independent audit, DPIA, dpdp-act-2023.CHILDREN-DATA — Verifiable parental consent and no tracking or targeted advertising directed at children, dpdp-act-2023.CROSS-BORDER — Transfer of personal data outside India subject to Government restriction | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

### Financial-services regulation

Payments and operational-resilience regulation specific to banks, payment institutions, and the EU financial sector.

ECOA / Reg B

#### ECOA / Regulation B — Equal Credit Opportunity Act

ECOA (15 U.S.C. §1691 et seq.) / Regulation B (12 C.F.R. Part 1002) · United States

ECOA prohibits discrimination in any aspect of a credit transaction and Regulation B operationalises it, including §1002.9 adverse-action notices with a specific statement of reasons. KYE Protocol™ governs whether an AI lending agent's consequential credit decision may proceed — only under a named-authority decision purpose-scoped to the credit transaction, with every adverse action carrying a Decision Map™ (the specific reasons, explainable) bound to a §61 contestability route and sealed into a signed replay-provable Evidence Pack™. The disparate-impact statistics, the credit-scoring feature choice, and the model's fairness validation stay the lender's own quantitative fair-lending work (honest scope, §0). Per-requirement bijection at /compliance/ecoa-reg-b.html.

### 2

Enforced

### 1

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Credit-decision authority at the action boundary | Enforced | L3 Enforceable | ecoa-reg-b.credit-decision-named-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Adverse-action notice with specific reasons | Enforced | L3 Enforceable | ecoa-reg-b.adverse-action-decision-map | Decision Map™Evidence Pack™Contestability routeReplay-Proof™ |
| Prohibited-basis non-discrimination evidence | Designed | L2 Designed | ecoa-reg-b.prohibited-basis-non-discrimination-evidence | Decision Map™Audit WORM |
| Fair-lending statistical analysis & model fairnessThe disparate-impact regression, less-discriminatory-alternative search, and model-fairness validation are the lender's own quantitative fair-lending work — KYE™ is an AI-authority and evidence layer, not a fair-lending analytics engine. | Out of scope | L1 Mapped | ecoa-reg-b.fair-lending-statistical-analysis | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

FCRA

#### FCRA — Fair Credit Reporting Act

Fair Credit Reporting Act (15 U.S.C. §1681 et seq.) / Regulation V (12 C.F.R. Part 1022) · United States

FCRA §1681m requires a user of a consumer report who takes adverse action based on it to give an adverse-action notice naming the reporting agency and the consumer's rights. KYE Protocol™ governs whether an AI lending agent may act on a consumer report — only under a named-authority decision with a permissible purpose, with every report-driven adverse action carrying a Decision Map™ (the report's contribution + the named reporting agency) bound to a §61 contestability route and sealed into a signed replay-provable Evidence Pack™. The report generation, the scoring of report data, and the accuracy of report contents stay the consumer-reporting agency's and furnisher's work (honest scope, §0). Per-requirement bijection at /compliance/fcra.html.

### 3

Enforced

### 1

Designed

### 2

Out of scope

6 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Credit-report use authority at the decision boundary | Enforced | L3 Enforceable | fcra.credit-report-use-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Adverse-action-on-report notice (specific reasons + agency identity) | Enforced | L3 Enforceable | fcra.adverse-action-on-report-notice | Decision Map™Evidence Pack™Contestability route |
| Consumer-report data accuracy & furnisher disputesReport-content accuracy, the furnisher's §1681s-2 duties, and reinvestigation of disputes are the reporting agency's and furnisher's obligations — KYE™ governs the lending agent's decision, not the report. | Out of scope | L1 Mapped | fcra.report-accuracy-and-furnisher-disputes | — |
| Employment / tenant consumer-report use authority | Enforced | L3 Enforceable | fcra.employment-report-permissible-purpose-and-disclosure | Authority GatePurpose Permission™Evidence Pack™ |
| Employment pre-adverse-action two-step notice | Designed | L2 Designed | fcra.pre-adverse-action-notice | Decision Map™Contestability route |
| Consumer-report data disposalDisposal of the consumer-report copy and underlying data is the user's own data-handling duty over data KYE™ does not hold — KYE™ governs the agent's authority-to-act, not the report data. | Out of scope | L1 Mapped | fcra.disposal-of-consumer-report-data | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ICRAA

#### ICRAA — California Investigative Consumer Reporting Agencies Act

California Investigative Consumer Reporting Agencies Act (ICRAA), Cal. Civ. Code §1786 et seq. · United States

ICRAA is the California-jurisdiction overlay on the federal FCRA for INVESTIGATIVE consumer reports (character / reputation / mode-of-living information gathered through interviews — the bulk of California employment and tenant background screening). It is stricter than FCRA: §1786.16 requires clear-and-conspicuous written notice AND the consumer's written authorization plus a nature-and-scope disclosure before an investigative consumer report is procured; §1786.40 requires an adverse-action notice naming the agency. KYE Protocol™ governs whether an AI agent may PROCEED to procure or act on an investigative consumer report — only under a named-authority decision with a permissible purpose, a recorded written-consent authority, and every adverse action carrying a Decision Map™ + the named agency bound to a §61 contestability route and sealed into a signed replay-provable Evidence Pack™. KYE™ is NOT a consumer reporting agency: it does not generate the report, conduct the interviews, judge the accuracy of the report contents, or run the reinvestigation (honest scope, §0/§70). Per-requirement bijection at /compliance/icraa.html.

### 3

Enforced

### 1

Designed

### 1

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Investigative-report use authority at the procurement/decision boundary | Enforced | L3 Enforceable | icraa.investigative-report-use-authority | Authority GatePurpose Permission™Evidence Pack™ |
| California written notice + written authorization + nature-and-scope disclosure | Enforced | L3 Enforceable | icraa.written-consent-and-nature-scope-disclosure | Authority GateDecision Map™Evidence Pack™ |
| Adverse-action-on-investigative-report notice (reasons + agency identity) | Enforced | L3 Enforceable | icraa.adverse-action-notice | Decision Map™Evidence Pack™Contestability route |
| Consumer copy + dispute / reinvestigation route | Designed | L2 Designed | icraa.consumer-copy-and-dispute-route | Contestability routeDelegated Auditability |
| Investigative-report content accuracy & agency reinvestigation dutiesReport-content accuracy, the reasonable-procedures duty (§1786.20), and the agency's reinvestigation (§1786.24) are the investigative consumer reporting agency's obligations — KYE™ governs the user's decision, not the report, and is not a CRA. | Out of scope | L1 Mapped | icraa.report-accuracy-and-agency-reinvestigation | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

FCA CONC

#### FCA CONC — Consumer Credit Sourcebook

FCA Handbook CONC — Consumer Credit Sourcebook · United Kingdom

FCA CONC governs UK consumer-credit conduct, including CONC 5 responsible lending (creditworthiness & affordability) and CONC 7 arrears, default & forbearance. KYE Protocol™ governs whether an AI lending agent's creditworthiness-driven or arrears action may proceed — only under a named-authority decision purpose-scoped to the credit agreement, with the action carrying a Decision Map™ recording that the creditworthiness assessment was relied on, bound to a §61 forbearance/contestability route, and sealed into a signed replay-provable Evidence Pack™. The affordability calculation and credit-policy adequacy stay the lender's own responsible-lending work (honest scope, §0). Per-requirement bijection at /compliance/fca-conc.html.

### 1

Enforced

### 1

Designed

### 1

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Creditworthiness/arrears action authority at the boundary | Enforced | L3 Enforceable | fca-conc.lending-action-named-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Creditworthiness-reliance & forbearance evidence | Designed | L2 Designed | fca-conc.creditworthiness-reliance-evidence | Decision Map™Evidence Pack™Contestability route |
| Affordability calculation & credit-policy adequacyThe affordability calculation, income/expenditure modelling, and credit-policy adequacy under CONC 5 are the lender's own responsible-lending work — KYE™ governs the agent's action, not the calculation. | Out of scope | L1 Mapped | fca-conc.affordability-calculation-and-policy | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

AICPA SSTS

#### AICPA SSTS — Statements on Standards for Tax Services

2024 · United States

AICPA Statements on Standards for Tax Services (2024) — the enforceable standards for tax-return positions (reasonable basis / disclosure), reasonable inquiry & reliance on data, and the form & content of advice. KYE Protocol™ governs whether an AI-generated tax position / advice may proceed under a named member's authority, with the SSTS standards recorded before the action — the KYE™ Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Tax-return positions (SSTS No. 1) | Designed | L2 Designed | aicpa-ssts.ssts1-reasonable-basis, aicpa-ssts.ssts1-disclosure | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Data & reasonable inquiry (SSTS No. 3) | Designed | L2 Designed | aicpa-ssts.ssts3-reasonable-inquiry | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| Form & content of advice (SSTS No. 7) | Designed | L2 Designed | aicpa-ssts.ssts7-form-of-advice | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

AIFMD / UCITS

#### AIFMD / UCITS — Fund Manager Authority, Risk Management & Investment Limits

Directive 2011/61/EU & Directive 2009/65/EC · European Union

AIFMD (Directive 2011/61/EU) and the UCITS Directive (Directive 2009/65/EC) govern EU collective-investment fund management — fund-manager authorisation & conduct, the risk-management function & limits, investment limits & diversification, and recordkeeping / depositary oversight. KYE Protocol™ governs whether an AI-assisted investment decision/action is within the fund's mandate and limits, authorised, evidenced, and final at the action boundary — the KYE™ Investment Decision Authority Pack™. KYE Protocol™ does not run the risk-management function, judge whether a decision is correct, produce investment intelligence, or act as a fund manager. Per-requirement bijection at framework-coverage-bijection.

### 4

Enforced

### 0

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Fund manager authorisation & conduct | Enforced | L3 Enforceable | aifmd-ucits.fund-manager-authorisation-conduct | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Risk-management function & limits | Enforced | L3 Enforceable | aifmd-ucits.risk-management-function-limits | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Investment limits & diversification | Enforced | L3 Enforceable | aifmd-ucits.investment-limits-diversification | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Recordkeeping & depositary oversight | Enforced | L3 Enforceable | aifmd-ucits.recordkeeping-depositary-oversight | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

APRA CPS 230

#### APRA CPS 230 — Operational Risk Management

Effective 1 July 2025 · Australia

APRA Prudential Standard CPS 230 — operational risk management, business continuity and service-provider management for APRA-regulated entities. Per-requirement bijection at /compliance/apra-cps-230.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Operational risk management (paras 13-21) | Enforced | L3 Enforceable | CPS 230 §13, CPS 230 §15, CPS 230 §18 | Risk EngineDecision EngineAuthority GatePurpose Permission™Resilience Loop™ |
| Incident notification to APRA (para 20)Detection + package assembly enforced; the regulator-side delivery channel to APRA is in build. | Enforced | L3 Enforceable | CPS 230 §20 | Incident DetectorReporting Engine |
| Business continuity + service-provider management (paras 30-48) | Enforced | L3 Enforceable | CPS 230 §35, CPS 230 §42 | Authority RegisterSPoF registryEdge Governance Safety FloorOffline Evidence Log |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

FSA AI Guidelines

#### FSA AI / Model Governance Expectations for Financial Institutions

FSA AI Discussion Paper (June 2024) + Supervision Guidelines · Japan

The Japan Financial Services Agency's AI governance and model-risk expectations for financial institutions — AI governance & accountability, model risk management, human oversight, explainability and operational resilience. KYE Protocol™ evidences the expectations that bind an AI-supported financial action at runtime. Per-requirement bijection at /compliance/fsa-guidelines-ai.html.

### 2

Enforced

### 1

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| AI governance, accountability & model risk management | Enforced | L3 Enforceable | FSA AI governance expectation, FSA model-risk expectation | Purpose Permission™Risk EngineConformance RunnerDrift Detector |
| Human oversight & explainability/customer disclosure | Enforced | L3 Enforceable | FSA human-oversight expectation, FSA explainability expectation | GovernedUI™Authority Resolution™Decision Map™Evidence Pack™ |
| Operational resilience & incident reporting to the FSAKYE™ assembles the FSA notification package; the regulator-side delivery channel to the FSA is designed pending the per-jurisdiction reporting connector. | Designed | L1 Mapped | FSA operational-resilience expectation | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Consumer-Driven Banking

#### Canada Consumer-Driven Banking Framework (open banking)

Consumer-Driven Banking Act (2024) · Canada

Canada's consumer-driven banking (open banking) framework under the Consumer-Driven Banking Act, 2024 (stood up by the FCAC): accreditation of participants, consumer consent + data-sharing control, a common technical/security standard, and oversight + accountability. Per-requirement bijection at /compliance/canada-cdb.html.

### 4

Enforced

### 0

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Accreditation of participants | Enforced | L3 Enforceable | accreditation | Authority GateRisk Engine |
| Consumer consent + data-sharing control | Enforced | L3 Enforceable | consent | Authority GatePurpose Permission™ |
| Common technical + security standard | Enforced | L3 Enforceable | technical-standard | Authority Gate |
| Oversight + accountability | Enforced | L3 Enforceable | oversight | Authority GateReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Companies Act 2006

#### UK Companies Act 2006 — Accounting Records, True & Fair Accounts & Filing with the Registrar

2006 · United Kingdom

The UK Companies Act 2006 — adequate accounting records (s.386), true and fair view (s.393), director responsibility & board approval (s.414), and filing of the statutory accounts with the Registrar of Companies / Companies House (s.441/s.442). KYE Protocol™ governs whether an AI-generated financial entry / statement / filing may proceed to a consequential action under a named accountant's / director's authority, with §36 two-person sign-off on the irreversible Companies House submission — the KYE™ Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 4

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Adequate accounting records (s.386) | Designed | L2 Designed | companies-act-2006.s386-adequate-records | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| True & fair view (s.393) | Designed | L2 Designed | companies-act-2006.s393-true-and-fair | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Director responsibility & approval (s.414) | Designed | L2 Designed | companies-act-2006.s414-director-responsibility | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Filing with the Registrar / Companies House (s.441/s.442) | Designed | L2 Designed | companies-act-2006.s441-filing-with-registrar, companies-act-2006.s442-filing-deadlines | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

DORA

#### DORA — Digital Operational Resilience Act

Regulation (EU) 2022/2554 · European Union

EU regulation for the digital operational resilience of the financial sector.

### 4

Enforced

### 0

Designed

### 1

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| ICT risk-management framework | Enforced | L3 Enforceable | Art. 5-16 | Purpose Permission™Authority GateWORM audit hash-chain |
| ICT incident detection & reconstruction | Enforced | L3 Enforceable | Art. 17-23 | WORM audit hash-chainDecision replay |
| ICT third-party register & concentration analysis | Enforced | L3 Enforceable | Art. 28(3) | Directory tenant proxyWORM audit hash-chain |
| Tamper-evident resilience evidenceResilience-testing outcomes are recorded today; signed resilience evidence packs are in build. | Enforced | L3 Enforceable | Art. 24-27 | Evidence Pack™ signing (COSE-Sign1) |
| ICT third-party contractual arrangementsExit strategies, audit rights, and termination clauses require contract-management tooling outside KYE™. | Out of scope | L1 Mapped | Art. 15, Art. 28-30 | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/dora/)

DORA Incident

#### DORA ICT Incident Reporting — Article 19 + classification RTS

DORA — Regulation (EU) 2022/2554, Article 19 + classification RTS · European Union

DORA ICT Incident Reporting (Regulation (EU) 2022/2554, Article 19) is the EU financial-sector ICT-incident reporting regime. KYE Protocol™ governs whether an AI-assisted containment action, incident classification, or staged-report timing decision under it may proceed to a consequential incident action — under a named accountable officer's authority, with incident-evidence chain-of-custody recorded, no AI-asserted classification relied on without a pinned signal source, a signed replay-provable Evidence Pack™ per decision, and a contestability record so any decision can be reconstructed and challenged. Threat detection / SIEM-EDR runtime / forensics / remediation stays the entity's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/dora-ict-incident.html.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Named-authority on the containment / response action | Enforced | L3 Enforceable | dora-ict-incident.containment-action-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Incident-evidence chain-of-custody & report integrity | Enforced | L3 Enforceable | dora-ict-incident.incident-evidence-integrity | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Disclosure-timing authority on the staged reporting clock | Enforced | L3 Enforceable | dora-ict-incident.staged-report-timing-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Threat detection, forensics & remediation engineeringThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. | Out of scope | L1 Mapped | dora-ict-incident.threat-detection-forensics-remediation | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

EU 6AMLD

#### EU Sixth Anti-Money Laundering Directive (6AMLD) — Directive (EU) 2018/1673

Directive (EU) 2018/1673 · European Union

The EU Sixth Anti-Money Laundering Directive (Directive (EU) 2018/1673) harmonises money-laundering offences, the 22 predicate offences, aiding/abetting/inciting, and corporate liability across the EU. KYE Protocol™ governs whether an AI agent's AML action may proceed at the action boundary under a named compliance officer's authority, with due diligence before the action and replay-provable provenance. KYE Protocol™ does not run transaction-monitoring models, does not decide whether conduct is criminal money-laundering, and does not replace the institution's AML program or legal advice.

### 0

Enforced

### 4

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Predicate offences & scope (Art. 2/3) | Designed | L2 Designed | eu-6amld.predicate-offences-scope | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Aiding, abetting & inciting (Art. 4) | Designed | L2 Designed | eu-6amld.aiding-abetting-inciting | Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
| Corporate / legal-person liability (Art. 7/8) | Designed | L2 Designed | eu-6amld.corporate-liability | Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
| Sanctions & competent-authority cooperation (Art. 9-10) | Designed | L2 Designed | eu-6amld.competent-authority-cooperation | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

EU DAC

#### EU DAC — Directive on Administrative Cooperation (DAC6 + DAC7)

dac6-dac7 · European Union

EU Directive on Administrative Cooperation — DAC6 mandatory disclosure of reportable cross-border arrangements (hallmarks A–E, main-benefit test, 30-day window) and DAC7 platform-operator reporting. KYE Protocol™ governs whether an AI-generated arrangement / advice that may be reportable proceeds only after the hallmark / disclosure screen is recorded — the KYE™ Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| DAC6 hallmark screening | Designed | L2 Designed | eu-dac.dac6-reportable-arrangement, eu-dac.dac6-main-benefit-test | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| DAC6 disclosure & reporting window | Designed | L2 Designed | eu-dac.dac6-disclosure-window | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| DAC7 platform reporting | Designed | L2 Designed | eu-dac.dac7-platform-reporting | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

FATF 40 Recommendations

#### FATF 40 Recommendations — International Standards on Combating Money Laundering and the Financing of Terrorism & Proliferation

2012 (as amended) · International

The FATF 40 Recommendations are the global AML/CFT authority anchor — risk-based approach (R.1), customer due diligence & beneficial ownership (R.10), record-keeping (R.11), the Travel Rule (R.16), and suspicious-transaction reporting (R.20). KYE Protocol™ governs whether an AI agent's AML action may proceed at the action boundary (alert triage, sanctions screening, SAR/STR drafting, KYC/CDD) under a named compliance officer's authority, with §36 two-person sign-off on the consequential SAR/STR filing — the KYE™ AML & Financial-Crimes Governance Pack™. KYE™ Prot™ocol™ does not run transaction-monitoring models, does not decide whether a transaction is truly money-laundering, and does not replace the institution's AML program.

### 5

Enforced

### 0

Designed

### 0

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Risk-based approach (R.1) | Enforced | L3 Enforceable | fatf-40-recommendations.r1-risk-based-approach | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Customer due diligence & beneficial ownership (R.10) | Enforced | L3 Enforceable | fatf-40-recommendations.r10-customer-due-diligence | Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
| Record-keeping (R.11) | Enforced | L3 Enforceable | fatf-40-recommendations.r11-record-keeping | Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
| Travel Rule — wire / virtual-asset transfers (R.16) | Enforced | L3 Enforceable | fatf-40-recommendations.r16-travel-rule | Action Admissibility™ GateEvidence Pack™ |
| Suspicious transaction reporting (R.20) | Enforced | L3 Enforceable | fatf-40-recommendations.r20-suspicious-transaction-reporting | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

FCA COBS

#### FCA COBS — Conduct of Business Sourcebook (UK Investment Conduct)

FCA Handbook COBS · United Kingdom

The FCA Conduct of Business Sourcebook (COBS) governs UK investment business with clients — the client's best interests rule (COBS 2.1.1R), suitability (COBS 9), best execution (COBS 11), and recordkeeping. KYE Protocol™ governs whether an AI-assisted investment decision/action is within mandate, authorised, evidenced, and final at the action boundary — the KYE™ Investment Decision Authority Pack™. KYE Protocol™ does not perform the suitability assessment, judge whether a recommendation is correct, produce investment intelligence, or act as an investment adviser. Per-requirement bijection at framework-coverage-bijection.

### 4

Enforced

### 0

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Client's best interests rule (COBS 2.1.1R) | Enforced | L3 Enforceable | fca-cobs.client-best-interests-rule | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Suitability (COBS 9 / 9A) | Enforced | L3 Enforceable | fca-cobs.suitability-cobs9 | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Best execution (COBS 11.2 / 11.2A) | Enforced | L3 Enforceable | fca-cobs.best-execution-cobs11 | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Recordkeeping of advice & orders | Enforced | L3 Enforceable | fca-cobs.recordkeeping-advice-orders | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

FRC Ethical Standard

#### FRC Ethical Standard — Integrity, Objectivity & Independence

2024 · United Kingdom

The Financial Reporting Council's Ethical Standard — integrity, objectivity & independence, professional competence & due care, and the threats-and-safeguards framework for auditors and accountants. KYE Protocol™ governs whether an AI-generated entry / statement / conclusion may proceed under a named professional's authority, with the objectivity / independence / competence basis recorded before the action — the KYE™ Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 4

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Integrity | Designed | L2 Designed | frc-ethical-standard.integrity | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Objectivity & independence | Designed | L2 Designed | frc-ethical-standard.objectivity-independence | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Professional competence & due care | Designed | L2 Designed | frc-ethical-standard.professional-competence | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Threats & safeguards framework | Designed | L2 Designed | frc-ethical-standard.threats-safeguards | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

FSB Sound Practices

#### FSB Sound Practices for the Responsible Adoption of AI in Finance

consultation-2026-06 · International

The Financial Stability Board's Sound Practices for the Responsible Adoption of AI in Finance (consultation, 10 June 2026) sets supervisory expectations for how financial institutions govern AI across model risk, accountability, third-party dependency, and operational resilience. This framework is REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped — no requirement has been bound to a KYE Protocol™ artefact, so coverage is honestly reported as out of scope pending deep mapping. The §70 honesty bar forbids claiming enforced/designed coverage before a requirement is bound to a cited artefact. Deep mapping will be scheduled through the §70 rail (by hand, the §59 deterministic pipeline, or the §70 framework-mapping-agent) once the final report text is pinned.

### 0

Enforced

### 0

Designed

### 1

Out of scope

1 requirement group — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping\_state=registered): the framework is declared in framework-registry.json but no requirement has been bound to a KYE Protocol™ artefact yet. Coverage is reported out of scope until the deep mapping runs through the §70 rail — never inflated to imply enforcement that does not exist. | Out of scope | L1 Mapped | FSB Sound Practices (full consultation text — not yet decomposed into requirement-level mappings) | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

FCA MCOB

#### FCA MCOB — Mortgage Conduct of Business (FCA Handbook)

FCA Handbook · United Kingdom

FCA Handbook conduct rules for regulated mortgage advice, pre-contract disclosure and responsible lending. KYE Protocol™ governs the AUTHORITY of an AI agent to take a suitability / disclosure / responsible-lending action and the EVIDENCE / replay of that action, under named accountability; KYE Protocol™ does not perform the affordability calculation, author the advice, or determine the regulatory correctness of the mortgage recommendation. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Suitability / affordability action admissibility | Designed | L2 Designed | fca-mcob.4.7a | Purpose Permission™Authority Gate |
| Pre-contract disclosure evidence | Designed | L2 Designed | fca-mcob.5.6 | Evidence Pack™ |
| Responsible-lending decision record | Designed | L2 Designed | fca-mcob.11.6 | Evidence Pack™Authority Gate |
| The affordability calculation itself | Out of scope | L1 Mapped | fca-mcob.11a.affordability-calc | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

FCA Consumer Duty

#### FCA Consumer Duty (PRIN 2A) — Principle 12 & the four outcomes

PRIN 2A · United Kingdom

FCA Handbook PRIN 2A — the Consumer Duty (Principle 12 + the four outcomes). KYE Protocol™ governs the AUTHORITY of an AI agent to act toward a good retail-customer outcome, the consumer-understanding EVIDENCE, and foreseeable-harm contestability; KYE Protocol™ does not assess price-and-value, author the good-outcome judgement, or determine the firm's Consumer Duty compliance. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Act-to-deliver-good-outcomes authority gate | Designed | L2 Designed | fca-consumer-duty.prin-2a.2 | Purpose Permission™Authority Gate |
| Consumer-understanding evidence | Designed | L2 Designed | fca-consumer-duty.prin-2a.6 | Evidence Pack™ |
| Foreseeable-harm contestability | Designed | L2 Designed | fca-consumer-duty.prin-2a.5 | Delegated AuditabilityEvidence Pack™ |
| Price-and-value assessment | Out of scope | L1 Mapped | fca-consumer-duty.prin-2a.4 | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Investment Mandate / IPS

#### Investment Mandate / IPS — Investment Policy Statement & Discretionary Mandate Authority

2026 · International

The Investment Policy Statement (IPS) / discretionary investment mandate — the authority anchor for AI-assisted investment decisions. Defines permitted investments, concentration / liquidity limits, prohibited investments, named authority / delegation, and reporting obligations. KYE Protocol™ governs whether an AI-assisted investment decision/action is within the recorded mandate, under whose authority it proceeds, evidenced, contestable, and final at the action boundary — the KYE™ Investment Decision Authority Pack™. KYE Protocol™ does not produce investment intelligence, judge whether a thesis is correct, or render any view on alpha / returns / suitability of outcome, and is not an investment adviser. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 4

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Mandate scope & permitted investments | Designed | L2 Designed | investment-mandate-ips.mandate-scope-permitted-investments | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Constraints, limits & prohibitions | Designed | L2 Designed | investment-mandate-ips.constraints-limits-prohibitions | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Named authority & delegation | Designed | L2 Designed | investment-mandate-ips.named-authority-delegation | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Reporting & evidence obligations | Designed | L2 Designed | investment-mandate-ips.reporting-evidence-obligations | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Circular 230

#### IRS Circular 230 — Regulations Governing Practice before the IRS

2014-rev · United States

Treasury Department Circular No. 230 (31 CFR Part 10) — the standards of practice (due diligence §10.22, competence §10.35, return positions §10.34, written advice §10.37) for practitioners before the IRS. KYE Protocol™ governs whether an AI-generated tax position/filing/advice may proceed to a consequential action under a named preparer's authority — the KYE™ Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Due diligence & competence | Designed | L2 Designed | irs-circular-230.10.22-due-diligence, irs-circular-230.10.35-competence | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Tax-return positions & written advice | Designed | L2 Designed | irs-circular-230.10.34-positions, irs-circular-230.10.37-written-advice | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Practitioner authority & sign-off | Designed | L2 Designed | irs-circular-230.preparer-signoff | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ISA (UK)

#### ISA (UK) — International Standards on Auditing (UK)

2024 · United Kingdom

The International Standards on Auditing (UK) — professional scepticism & reasonable assurance (ISA 200), fraud responsibilities (ISA 240), risk identification & assessment (ISA 315), and forming the opinion & reporting (ISA 700). KYE Protocol™ governs whether an AI-generated audit working-paper / conclusion may proceed under a named auditor's authority, with the ISA (UK) responsibilities recorded before the action — the KYE™ Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 4

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Professional scepticism & reasonable assurance (ISA 200) | Designed | L2 Designed | isa-uk.isa200-professional-scepticism | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Fraud responsibilities (ISA 240) | Designed | L2 Designed | isa-uk.isa240-fraud-responsibilities | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Risk identification & assessment (ISA 315) | Designed | L2 Designed | isa-uk.isa315-risk-assessment | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| Forming the opinion & reporting (ISA 700) | Designed | L2 Designed | isa-uk.isa700-forming-opinion | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

MAS TRM

#### MAS Technology Risk Management Guidelines

Jan 2021 · Singapore

Monetary Authority of Singapore Technology Risk Management Guidelines — access control, audit logging, IT incident management, third-party risk. Per-requirement bijection at /compliance/mas-trm.html.

### 2

Enforced

### 0

Designed

### 0

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Access control + tamper-resistant audit logging | Enforced | L3 Enforceable | MAS TRM — access control, MAS TRM — audit logging | Authority GateAuthority Revocation OrchestratorWORM audit hash-chainStreaming Logs Contract™ |
| IT incident management + third-party riskThird-party risk enforced via Authority Register + SPoF; the MAS incident-notification delivery channel is in build. | Enforced | L3 Enforceable | MAS TRM — incident management, MAS TRM — third-party risk | Incident DetectorReporting EngineAuthority RegisterSPoF registry |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

MiFID II

#### MiFID II — Markets in Financial Instruments Directive II (Investment Services Conduct)

Directive 2014/65/EU · European Union

MiFID II (Directive 2014/65/EU) governs the provision of investment services in the EU — acting in the client's best interest (Art. 24), suitability (Art. 25), best execution (Art. 27), and recordkeeping. KYE Protocol™ governs whether an AI-assisted investment decision/action is within mandate, authorised, evidenced, and final at the action boundary — the KYE™ Investment Decision Authority Pack™. KYE Protocol™ does not perform the suitability assessment, judge whether a recommendation is correct, produce investment intelligence, or act as an investment adviser. Per-requirement bijection at framework-coverage-bijection.

### 4

Enforced

### 0

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Acting in the client's best interest (Art. 24) | Enforced | L3 Enforceable | mifid-ii.art24-best-interest | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Suitability & appropriateness (Art. 25) | Enforced | L3 Enforceable | mifid-ii.art25-suitability | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Best execution (Art. 27) | Enforced | L3 Enforceable | mifid-ii.art27-best-execution | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Recordkeeping & basis of advice | Enforced | L3 Enforceable | mifid-ii.recordkeeping-basis-of-advice | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Pillar Two

#### OECD Pillar Two — GloBE Rules (Global Minimum Tax) & BEPS

2023-globe · International

OECD/G20 Pillar Two GloBE rules — a 15% global minimum effective tax rate (IIR / UTPR) with a per-jurisdiction top-up tax reported in the GloBE Information Return (GIR). KYE Protocol™ governs whether an AI-generated Pillar Two computation may proceed to a filing or a booked liability — the KYE™ Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| GloBE effective-tax-rate & top-up tax | Designed | L2 Designed | oecd-pillar-two.globe-top-up-tax, oecd-pillar-two.effective-tax-rate | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| GloBE Information Return (GIR) | Designed | L2 Designed | oecd-pillar-two.gir-information-return | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| Scope & charging-rule determination | Designed | L2 Designed | oecd-pillar-two.scope-charging-rule | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

OSFI B-10

#### OSFI Guideline B-10 — Third-Party Risk Management

Effective 1 May 2024 · Canada

OSFI Guideline B-10 — risk-based management of third-party arrangements for federally regulated financial institutions: the arrangement register, criticality-proportionate risk assessment, and ongoing monitoring + concentration risk. Per-requirement bijection at /compliance/osfi-b-10.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Third-party arrangement register | Enforced | L3 Enforceable | register | Authority GateRisk Engine |
| Risk assessment by criticality | Enforced | L3 Enforceable | risk-assessment | Risk Engine |
| Ongoing monitoring + concentration risk | Enforced | L3 Enforceable | monitoring | Offline Evidence LogRisk Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

OSFI B-13

#### OSFI Guideline B-13 — Technology & Cyber Risk Management

Effective 1 Jan 2024 · Canada

OSFI Guideline B-13 — technology and cyber risk management for federally regulated financial institutions: governance, technology operations + resilience, and cyber security. Per-requirement bijection at /compliance/osfi-b-13.html.

### 3

Enforced

### 0

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Governance + risk management (Domain 1) | Enforced | L3 Enforceable | d1 | Authority GateRisk Engine |
| Technology operations + resilience (Domain 2) | Enforced | L3 Enforceable | d2-asset-register, d2-resilience | Authority GateEdge Governance Safety FloorOffline Evidence LogRisk Engine |
| Cyber security — monitoring + incident (Domain 3) | Enforced | L3 Enforceable | d3 | Incident DetectorWORM audit hash-chain |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

OSFI E-23

#### OSFI Guideline E-23 — Model Risk Management

Effective 1 May 2027 · Canada

OSFI Guideline E-23 — enterprise-wide model risk management across the model lifecycle (model definition expanded to AI/ML): inventory + risk rating, independent validation, ongoing monitoring, and accountability. Per-requirement bijection at /compliance/osfi-e-23.html.

### 3

Enforced

### 1

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Model inventory + risk rating | Enforced | L3 Enforceable | inventory | Authority GateRisk Engine |
| Development + independent validation | Designed | L2 Designed | validation | Replay-Proof™WORM audit hash-chain |
| Ongoing monitoring | Enforced | L3 Enforceable | monitoring | Drift DetectorRisk Engine |
| Roles + accountability | Enforced | L3 Enforceable | accountability | Authority Gate |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

PCI DSS

#### PCI DSS — Payment Card Industry Data Security Standard

4.0 · Global

Security standard for entities that store, process, or transmit cardholder data.

### 2

Enforced

### 1

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Access control & strong authentication | Enforced | L3 Enforceable | Req 7, Req 8 | Authority GateWebAuthn step-upPurpose Permission™ |
| Audit logging & monitoring | Enforced | L3 Enforceable | Req 10 | WORM audit hash-chainDecision replay |
| Stored account-data protection evidenceKYE™ governs access to account data; signed evidence of protection and a FIPS-validated crypto adapter are in build. | Designed | L2 Designed | Req 3 | Evidence Pack™ signing (COSE-Sign1)FIPS-validated crypto module |
| Network security, anti-malware & physical accessNetwork segmentation, TLS termination, endpoint protection, and physical access to cardholder data are operated by the customer. | Out of scope | L1 Mapped | Req 1, Req 4, Req 5, Req 9 | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/pci-dss/)

PCMLTFA / FINTRAC

#### PCMLTFA / FINTRAC — Anti-Money-Laundering & Terrorist-Financing

S.C. 2000, c. 17 · Canada

Canada's anti-money-laundering and terrorist-financing regime (PCMLTFA + Regulations, administered by FINTRAC): client identification + KYC, ongoing monitoring, suspicious-transaction reporting, and record-keeping. Per-requirement bijection at /compliance/pcmltfa-fintrac.html.

### 3

Enforced

### 1

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Client identification + KYC | Enforced | L3 Enforceable | kyc | Authority GateDecision Map™ |
| Ongoing monitoring | Enforced | L3 Enforceable | monitoring | Drift DetectorRisk Engine |
| Suspicious transaction reporting (s.7) | Designed | L2 Designed | s7-str | Incident DetectorReporting Engine |
| Record-keeping (s.6) | Enforced | L3 Enforceable | s6-records | WORM audit hash-chain |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

PSD2 / PSD3

#### PSD2 / PSD3 — EU Payment Services Directive

PSD2 2015/2366 · European Union

EU payment-services regulation covering strong customer authentication and third-party access to accounts.

### 2

Enforced

### 1

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Strong customer authentication | Enforced | L3 Enforceable | RTS Art. 4-9 | WebAuthn step-upAuthority Gate |
| Third-party-provider access governance | Enforced | L3 Enforceable | Art. 66-67 | Purpose Permission™Directory tenant proxy |
| Transaction authorisation evidenceEvery transaction authorisation is recorded today; signed, third-party-verifiable transaction evidence is in build. | Designed | L2 Designed | Art. 97 | Evidence Pack™ signing (COSE-Sign1)Decision Map™ signing (JWS-detached) |
| Liability allocation frameworkKYE™ produces evidence relevant to liability, but the contractual allocation of liability is a legal matter. | Out of scope | L1 Mapped | Art. 97(5) | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

RBNZ BS11

#### RBNZ BS11 — Outsourcing Policy

BS11 Outsourcing Policy · New Zealand

Reserve Bank of New Zealand outsourcing policy — control over outsourced functions, continuity of basic banking functions, continuing compliance evidence. Per-requirement bijection at /compliance/rbnz-bs11.html.

### 2

Enforced

### 0

Designed

### 0

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Outsourcing register + continuity of basic banking functions | Enforced | L3 Enforceable | BS11 — outsourcing register, BS11 — basic banking functions | Authority RegisterSPoF registryEdge Governance Safety FloorOffline Evidence Log |
| Continuing compliance evidence to RBNZ | Enforced | L3 Enforceable | BS11 — control evidence | Evidence Pack™Regulator Replay agentWORM audit hash-chain |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

SEC IA Fiduciary

#### SEC Investment Adviser Fiduciary Duty — Advisers Act of 1940 (Duty of Care & Loyalty)

Investment Advisers Act of 1940 · United States

The US Investment Advisers Act of 1940 (s.206) and the SEC's 2019 fiduciary interpretation establish a federal fiduciary duty for registered investment advisers — a duty of care, a duty of loyalty, and the books-and-records rule (204-2). KYE Protocol™ governs whether an AI-assisted investment decision/action is within mandate, authorised, evidenced, and final at the action boundary — the KYE™ Investment Decision Authority Pack™. KYE Protocol™ does not form the reasonable belief, judge whether advice is correct, produce investment intelligence, or act as an investment adviser. Per-requirement bijection at framework-coverage-bijection.

### 4

Enforced

### 0

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Duty of care — reasonable belief best interest | Enforced | L3 Enforceable | sec-ia-fiduciary.duty-of-care-best-interest | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Duty of loyalty — conflicts & disclosure | Enforced | L3 Enforceable | sec-ia-fiduciary.duty-of-loyalty-conflicts | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Suitability / mandate of advice | Enforced | L3 Enforceable | sec-ia-fiduciary.suitability-mandate-of-advice | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Books & records (Rule 204-2) | Enforced | L3 Enforceable | sec-ia-fiduciary.books-and-records-204-2 | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

SOX 404

#### SOX §404 — Internal Control over Financial Reporting (tax provision)

2002 · United States

Sarbanes-Oxley §404 — management (and auditor) assessment of internal control over financial reporting (ICFR), with the income-tax provision a recurring material-weakness source requiring review controls, documentation, and data integrity. KYE Protocol™ governs whether an AI-generated tax-provision figure may proceed to being booked under recorded management-review controls with replay-provable provenance — the KYE™ Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

### 4

Enforced

### 0

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Tax-provision ICFR design | Enforced | L3 Enforceable | sox-404.tax-provision-icfr | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Review & approval controls | Enforced | L3 Enforceable | sox-404.management-review-control | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Documentation & data integrity | Enforced | L3 Enforceable | sox-404.documentation-data-integrity | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| Management attestation | Enforced | L3 Enforceable | sox-404.management-attestation | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

FRS 102

#### UK GAAP — FRS 102 / FRS 105 Recognition, Measurement & Disclosure

2024 · United Kingdom

FRS 102 / FRS 105 (UK GAAP) — recognition and measurement bases, accounting-policy selection and consistency, disclosure requirements, and the micro-entity regime. KYE Protocol™ governs whether an AI-generated entry / statement may proceed with the FRS 102 / FRS 105 recognition, measurement, and disclosure basis recorded before the action — the KYE™ Accounting Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 4

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Recognition & measurement | Designed | L2 Designed | uk-gaap-frs102.frs102-recognition-measurement | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Accounting policies & consistency | Designed | L2 Designed | uk-gaap-frs102.frs102-accounting-policies | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| Disclosure requirements | Designed | L2 Designed | uk-gaap-frs102.frs102-disclosure | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Micro-entity (FRS 105) regime | Designed | L2 Designed | uk-gaap-frs102.frs105-micro-entity | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

UK MTD

#### UK Making Tax Digital (MTD) — Digital Record-Keeping & API Filing

2024 · United Kingdom

HMRC Making Tax Digital — digital record-keeping, unbroken digital links from source data to submitted figures, and programmatic filing via the MTD API. KYE Protocol™ governs whether an AI-generated MTD figure may proceed to an API submission under a named preparer's authority, preserving the digital link in replay-provable provenance — the KYE™ Tax Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Digital record-keeping & digital links | Designed | L2 Designed | uk-mtd.digital-record-keeping, uk-mtd.digital-links | Evidence Pack™Replay-Proof™Action Admissibility™ Gate |
| API filing integrity | Designed | L2 Designed | uk-mtd.api-filing-integrity | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Preparer authority for submission | Designed | L2 Designed | uk-mtd.preparer-authority-submission | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

US BSA / FinCEN

#### US Bank Secrecy Act / FinCEN — AML Program, CDD & SAR Requirements

31 U.S.C. 5311 et seq.; 31 CFR Chapter X · United States

The US Bank Secrecy Act (31 U.S.C. 5311 et seq.) and FinCEN regulations (31 CFR Chapter X) require a risk-based AML program (5318(h)), customer due diligence & beneficial ownership (CDD Rule), Suspicious Activity Reports (SARs), and record-keeping. KYE Protocol™ governs whether an AI agent's AML action may proceed at the action boundary under a named BSA/AML officer's authority, with §36 two-person sign-off on the consequential SAR filing. KYE Protocol™ does not run transaction-monitoring models, does not decide whether a transaction is truly suspicious, and does not replace the institution's BSA/AML program.

### 4

Enforced

### 0

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| AML program (31 U.S.C. 5318(h)) | Enforced | L3 Enforceable | us-bsa-fincen.aml-program-5318h | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Customer due diligence & beneficial ownership (CDD Rule) | Enforced | L3 Enforceable | us-bsa-fincen.cdd-beneficial-ownership | Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
| Suspicious Activity Reporting (SAR) | Enforced | L3 Enforceable | us-bsa-fincen.sar-filing | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Record-keeping (31 CFR Chapter X) | Enforced | L3 Enforceable | us-bsa-fincen.record-keeping | Action Admissibility™ GateEvidence Pack™Replay-Proof™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Wolfsberg Principles

#### Wolfsberg Group AML Principles & Guidance

current · International

The Wolfsberg Group publishes industry AML, sanctions-screening, and correspondent-banking due-diligence standards for global banks. KYE Protocol™ governs whether an AI agent's AML or sanctions-screening action may proceed at the action boundary under a named compliance officer's authority, with due diligence before the action and replay-provable provenance. KYE Protocol™ does not run the screening engine, does not decide whether a name is a true sanctions match, and does not replace the institution's AML / sanctions program.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Risk-based KYC / CDD | Designed | L2 Designed | wolfsberg-principles.risk-based-kyc-cdd | Action Admissibility™ GateEvidence Pack™Replay-Proof™ |
| Sanctions & transaction screening governance | Designed | L2 Designed | wolfsberg-principles.sanctions-screening-governance | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Correspondent-banking due diligence | Designed | L2 Designed | wolfsberg-principles.correspondent-banking-due-diligence | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ECB AI Supervisory Expectations

#### ECB Supervisory Expectations on AI-Amplified Cyber and Operational Risk

emerging-2026 · EU

ECB Banking Supervision's emerging expectations on AI-amplified cyber and operational risk for significant institutions (planned 'dear CEO letter', per Reuters 3 June 2026; part of the ECB 2026–2028 supervisory priorities). REGISTERED in the §70 Framework Mapping Rail but NOT yet deep-mapped: no formal requirement text has been published, so coverage is honestly reported as out of scope pending deep mapping. The §70 honesty bar forbids claiming enforced/designed coverage before requirements are pinned. The substance — AI-actor authority, privileged-action gating, incident-response authority, replay-derivable evidence — is already covered by KYE Protocol™'s deep-mapped DORA artefacts and the shipped Cyber Resilience & Incident Authority Pack; deep mapping will graft those once the ECB text is final.

### 0

Enforced

### 0

Designed

### 1

Out of scope

1 requirement group — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping\_state=registered): declared in framework-registry.json but no requirement bound to a KYE Protocol™ artefact yet because no formal text is published. Coverage reported out of scope until the ECB requirements are pinned and deep-mapped through the §70 rail — never inflated. The DORA / Cyber Resilience & Incident Authority Pack artefacts already answer the substance and will be grafted on publication. | Out of scope | L1 Mapped | ECB AI supervisory expectations (forthcoming dear-CEO letter — not yet decomposed into requirement-level mappings) | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

SM&CR

#### UK Senior Managers & Certification Regime (SM&CR)

2016 (as amended) · United Kingdom

UK SM&CR accountability regime. KYE Protocol™ governs whether an AI agent's action may proceed under a named Senior Manager's delegated authority, with the responsibility line recorded and replay-provable. Consumed via kye:rule-pack:sm-cr + kye:sector-pack:uk-financial-services-sm-cr (§0: never re-mapped). Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 2

Designed

### 0

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| SMF responsibility + duty-of-responsibility evidence | Designed | L2 Designed | uk-smcr.smf-responsibility, uk-smcr.duty-of-responsibility | Purpose Permission™Evidence Pack™Replay Proof™ |
| Certification scope + contestable conduct record | Designed | L2 Designed | uk-smcr.certification, uk-smcr.conduct-rules | Purpose Permission™Delegated Auditability |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Failure to Prevent Fraud

#### UK Failure to Prevent Fraud (ECCTA 2023)

ECCTA 2023 (in force 1 Sep 2025) · United Kingdom

UK ECCTA 2023 corporate 'failure to prevent fraud' offence. KYE Protocol™ turns AI-actor authority into a demonstrable 'reasonable fraud-prevention procedure': AI actions that could facilitate fraud are gated by named authority, evidenced, and contestable. KYE Protocol™ proves the procedure operated; it does not adjudicate the offence. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 2

Designed

### 0

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Reasonable procedures (statutory defence) + evidence | Designed | L2 Designed | uk-eccta-ftpf.reasonable-procedures, uk-eccta-ftpf.evidence-of-procedures | Purpose Permission™Evidence Pack™Replay Proof™ |
| Fraud risk assessment + monitoring | Designed | L2 Designed | uk-eccta-ftpf.risk-assessment, uk-eccta-ftpf.monitoring-review | Decision Map™Delegated Auditability |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

UK MLR 2017

#### UK Money Laundering Regulations 2017 (MLR 2017)

SI 2017/692 (as amended) · United Kingdom

UK MLR 2017 AML/CTF obligations. KYE Protocol™ governs whether an AI agent's AML action may proceed under a named compliance officer's authority, with due diligence recorded and replay-provable provenance. Consumed via the aml-financial-crimes spine (§0: never re-mapped). KYE Protocol™ proves the basis; it does not decide whether conduct is money laundering. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 2

Designed

### 0

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Risk assessment + customer due diligence | Designed | L2 Designed | uk-mlr-2017.risk-assessment, uk-mlr-2017.cdd | Purpose Permission™Decision Map™ |
| Ongoing monitoring + replay-derivable records | Designed | L2 Designed | uk-mlr-2017.ongoing-monitoring, uk-mlr-2017.record-keeping | Delegated AuditabilityEvidence Pack™Replay Proof™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

MiCA

#### MiCA — Markets in Crypto-Assets Regulation

Regulation (EU) 2023/1114 · European Union

EU regulation for crypto-asset issuance and crypto-asset service providers (CASPs): custody, conduct, conflicts, complaints, and the Travel Rule overlay. Titles III–IV from Jun 2024; Title V from Dec 2024.

### 3

Enforced

### 1

Designed

### 1

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Custody & administration of crypto-assets (Art. 70, 75, 76) | Enforced | L3 Enforceable | Art. 75 | MiCA custody rule packEvidence Pack™ signingAuthority Gate |
| CASP conduct & conflict-of-interest screening (Art. 66, 72) | Enforced | L3 Enforceable | Art. 66, Art. 72 | Purpose Permission™Decision replay |
| Complaints handling (Art. 71)Evidenced complaint-handling response is design-locked; a CASP complaint-intake-and-tracking runtime path is not yet wired. | Designed | L2 Designed | Art. 71 | Comms Rail (evidenced response) |
| Travel Rule + AML overlay for crypto-asset transfers | Enforced | L3 Enforceable | Reg (EU) 2023/1113 | Travel-Rule rule packAML financial-crimes rule pack |
| Token white paper, authorisation & reserve of assetsReserve of assets, prudential own-funds, white-paper notification and issuer/CASP authorisation are prudential/licensing obligations of the regulated entity and its competent authority, outside KYE™'s lane. | Out of scope | L1 Mapped | Art. 16, Art. 36, Art. 54 | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

GENIUS Act

#### GENIUS Act — US payment stablecoin law

GENIUS Act (Pub. L. 119-27, 2025) · United States

First US federal law governing payment stablecoins: 1:1 reserve backing, redemption at par, monthly reserve disclosure, BSA/AML obligations, lawful-order (freeze/seize/burn) capability, and marketing restrictions. Prudential rulemaking deadline July 2026.

### 2

Enforced

### 1

Designed

### 2

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Redemption at par on demand | Enforced | L3 Enforceable | §4 | Purpose Permission™Authority Gate |
| Monthly reserve-composition disclosure (certified)KYE™ produces a tamper-evident, certify-able evidence pack for the disclosure; the reserve-composition data is the issuer's and the disclosure-assembly flow is design-locked, not yet wired. | Designed | L2 Designed | §4 | Evidence Pack™ signingWORM audit hash-chain |
| BSA / AML program + sanctions / lawful-order capability | Enforced | L3 Enforceable | §4 | AML financial-crimes rule packAuthority GateWORM audit hash-chain |
| 1:1 reserve backing & no-yield constraintHolding/investing the 1:1 reserve and the no-yield prohibition are balance-sheet/product obligations of the issuer, outside KYE™'s lane. | Out of scope | L1 Mapped | §4 | — |
| Issuer authorisation, charter & prudential supervisionFederal/state issuer authorisation, charter and prudential supervision are licensing/supervision obligations of the issuer and its regulator, outside KYE™'s lane. | Out of scope | L1 Mapped | §3, §5 | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Singapore PS Act

#### Singapore Payment Services Act 2019 (PS Act)

PS Act 2019 (No. 2 of 2019), as amended · Singapore

Singapore's licensing and conduct regime for payment service providers, administered by MAS: seven regulated activities (account issuance, domestic and cross-border money transfer, merchant acquisition, e-money issuance, digital payment token services, money-changing) across three licence classes, with AML/CFT, technology-risk and user-protection conditions. This framework is REGISTERED in the §70 Framework Mapping Rail following the statute-class precedent of the DORA and PSD2/PSD3 rows; deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.

### 0

Enforced

### 0

Designed

### 1

Out of scope

1 requirement group — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping\_state=registered): declared in framework-registry.json but no PS Act requirement is bound to a KYE Protocol™ artefact yet. The payment-authorization rail's authority controls are platform-level and cross-regime; PS-Act-specific deep mapping (licence-class conditions, DPT-service obligations) is scheduled through the §70 rail. Coverage is never inflated. | Out of scope | L1 Mapped | PS Act 2019 — licensing (Part 2), conduct of business (Part 3), and AML/CFT + technology-risk licence conditions; full text not yet decomposed into requirement-level mappings | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Singapore SFA

#### Singapore Securities and Futures Act 2001 (SFA)

SFA 2001 (2020 Revised Edition), as amended · Singapore

Singapore's capital-markets statute, administered by MAS: licensing of capital-markets services, regulation of organised markets and clearing facilities, offers of investments and prospectus requirements, market-conduct prohibitions (false trading, market rigging, insider trading), and derivatives-contract regulation. This framework is REGISTERED in the §70 Framework Mapping Rail following the statute-class precedent of the DORA and PSD2/PSD3 rows; deep per-requirement mapping has not yet been performed, so coverage is honestly reported as out of scope pending deep mapping.

### 0

Enforced

### 0

Designed

### 1

Out of scope

1 requirement group — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Registered in the §70 rail; deep per-requirement mapping not yet performedHonest registered state (§70 mapping\_state=registered): declared in framework-registry.json but no SFA requirement is bound to a KYE Protocol™ artefact yet. SFA-specific deep mapping (licensing, market-conduct, disclosure obligations) is scheduled through the §70 rail. Coverage is never inflated. | Out of scope | L1 Mapped | SFA 2001 — capital-markets services licensing, market conduct (Part 12), offers of investments (Part 13); full text not yet decomposed into requirement-level mappings | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

TARGET2

#### TARGET2 / T2 RTGS (ECB) — incl. Settlement Finality Directive 98/26/EC

ECB TARGET Guideline (EU) 2022/912 (ECB/2022/8) + Directive 98/26/EC Arts 3 & 5 · European Union

The Eurosystem's real-time gross settlement system settles payment orders in central bank money with finality conferred at the moment of entry under the Settlement Finality Directive — an entered order cannot be unwound. KYE Protocol™ governs the payment-authority dimension: every instruction (human- or AI-agent-originated) must resolve to a live, purpose-scoped mandate of an authorised user of an admitted participant, with the admissibility verdict, sealed decision context and hash-bound Evidence Pack™ complete BEFORE the finality moment, revocation biting on the very next action, and the message's authorisation lineage retained append-only over the record-keeping period. Settlement execution, legal conferral of finality and intraday liquidity/credit stay the Eurosystem's and the participant treasury's own (honest scope, §0). Per-requirement bijection at /compliance/target2-rtgs.html.

### 4

Enforced

### 1

Designed

### 2

Out of scope

7 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Participation, access criteria & authorised-user binding | Enforced | L3 Enforceable | target2-rtgs.participation-access-authority | Purpose Permission™Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Settlement finality & the pre-entry authority checkpoint (SFD 98/26/EC) | Enforced | L3 Enforceable | target2-rtgs.pre-settlement-authority-checkpoint | Authority GateContext sealEvidence Pack™Replay-Proof™ |
| Suspension, termination & revocation propagation | Enforced | L3 Enforceable | target2-rtgs.revocation-suspension-propagation | Authority GateAuthority-drift monitoringKill-switch semantics |
| ISO 20022 messaging integrity & record retention | Enforced | L3 Enforceable | target2-rtgs.message-integrity-records | Evidence Pack™WORM audit hash-chainRetention policy |
| Operational resilience, self-certification & incident notificationKYE™ supplies the machine-generated attestation cadence and sealed incident evidence the self-certification and notification duties run on; the participant's BCM programme, endpoint security and the submissions themselves are participant-owned and not claimed as enforced. | Designed | L2 Designed | target2-rtgs.operational-resilience-incident | ≤90-day attestationEvidence Pack™ |
| Settlement execution & legal conferral of finalitySettlement in central bank money and the SFD's legal conferral of finality/irrevocability are performed and owned by the Eurosystem as system operator — KYE™ is an AI-authority and evidence layer, not a settlement engine or designated system. | Out of scope | L1 Mapped | target2-rtgs.settlement-finality-execution | — |
| Liquidity provision & intraday creditFunding MCAs/DCAs, collateralised intraday credit and liquidity reservations are treasury and central-bank functions — KYE™ is not a liquidity-management or collateral engine. | Out of scope | L1 Mapped | target2-rtgs.liquidity-intraday-credit | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

CIPS

#### CIPS — Cross-Border Interbank Payment System (RMB)

CIPS participant and business rules — direct/indirect participation, ISO 20022 messaging, RTGS + hybrid netting · China

CIPS clears and settles cross-border RMB payments for direct participants (settling on CIPS accounts) and indirect participants routed through sponsoring direct participants, over ISO 20022-based messaging with RTGS and hybrid-netting settlement. KYE Protocol™ governs the payment-authority dimension only: participant mandate binding at the moment of action, the pre-settlement authority checkpoint (verdict + sealed evidence before the instruction is released), message-authorisation lineage retained append-only, and the authority + evidence layer of the participant's OWN financial-crime screening decision under the laws applicable to that participant — KYE™ takes no position on any jurisdiction's sanctions regime and provides nothing that weakens or routes around a screening obligation. Settlement execution, netting sessions and liquidity funding stay the operator's and participants' own (honest scope, §0). Per-requirement bijection at /compliance/cips-cross-border.html.

### 3

Enforced

### 2

Designed

### 1

Out of scope

6 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Participation & authorised-user binding | Enforced | L3 Enforceable | cips-cross-border.participant-authority | Purpose Permission™Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Pre-settlement authority checkpoint & irrevocability | Enforced | L3 Enforceable | cips-cross-border.pre-settlement-authority-checkpoint | Authority GateContext sealEvidence Pack™Replay-Proof™ |
| ISO 20022 messaging integrity & record retention | Enforced | L3 Enforceable | cips-cross-border.message-integrity-records | Evidence Pack™WORM audit hash-chainRetention policy |
| Financial-crime screening authority & evidenceScope-guarded: KYE™ governs the authority and evidence layer of the participant's own screening decision under the AML/CTF and sanctions laws applicable to that participant. Screening adjudication itself — list management, matching, disposition — is the participant's / their vendor's own and is not claimed. | Designed | L2 Designed | cips-cross-border.financial-crime-screening-authority | Named-authority bindingScreening tool-call evidenceDecision replay |
| Operational resilience & incident reportingKYE™ supplies sealed incident evidence and the attestation cadence; availability engineering, contingency arrangements and the incident report to the operator are participant-owned and not claimed as enforced. | Designed | L2 Designed | cips-cross-border.operational-resilience-incident | ≤90-day attestationEvidence Pack™ |
| Settlement execution & liquidity provisionClearing and settling RMB payments across CIPS accounts, netting sessions and liquidity funding are owned by the system operator and participant treasuries — KYE™ is an AI-authority and evidence layer, not a clearing, settlement or liquidity engine. | Out of scope | L1 Mapped | cips-cross-border.settlement-execution-liquidity | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

UK Faster Payments

#### UK Faster Payments (FPS)

UK Faster Payment System rules (Pay.UK) + PSR mandatory APP-scam reimbursement for Faster Payments (October 2024) · United Kingdom

Faster Payments processes UK retail payments in near real time — an accepted payment is irrevocable, so there is no recall window to correct an unauthorised agent action. KYE Protocol™ governs the payment-authority dimension: participant and sponsor/aggregator mandate binding at the moment of action, the pre-submission authority checkpoint (verdict + sealed evidence before release), message-authorisation lineage retained append-only over the record-keeping period, and the replay-verifiable authorisation evidence trail an APP-scam reimbursement investigation turns on (who or what authorised, under which mandate, with which fraud-assessment tool-calls). Scheme processing, settlement at the Bank of England, prefunding/net-sender-cap management and the reimbursement adjudication itself stay the scheme's, the Bank's and the PSPs' own (honest scope, §0). Per-requirement bijection at /compliance/uk-fps.html.

### 3

Enforced

### 2

Designed

### 2

Out of scope

7 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Participation, access criteria & authorised-user binding | Enforced | L3 Enforceable | uk-fps.participant-access-authority | Purpose Permission™Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Irrevocability & the pre-submission authority checkpoint | Enforced | L3 Enforceable | uk-fps.pre-submission-authority-checkpoint | Authority GateContext sealEvidence Pack™Replay-Proof™ |
| Messaging integrity & record retention | Enforced | L3 Enforceable | uk-fps.message-integrity-records | Evidence Pack™WORM audit hash-chainRetention policy |
| APP-fraud reimbursement & authorisation evidenceKYE™ supplies the replay-verifiable record of the authorising principal, mandate, purpose scope and fraud-assessment tool-calls a claim investigation needs; the reimbursement adjudication (gross-negligence assessment, 50:50 split, claim payment) is owned by the PSPs, Pay.UK and the PSR and is not claimed as enforced. | Designed | L2 Designed | uk-fps.app-fraud-reimbursement-evidence | Decision replayEvidence Pack™WORM audit hash-chain |
| Operational resilience & incident reportingKYE™ supplies sealed incident evidence and the attestation cadence; availability engineering, contingency arrangements and the notifications themselves are participant-owned and not claimed as enforced. | Designed | L2 Designed | uk-fps.operational-resilience-incident | ≤90-day attestationEvidence Pack™ |
| Scheme processing & settlement executionCentral-infrastructure processing, deferred multilateral net settlement at the Bank of England, and the conferral of irrevocability on accepted payments are owned by Pay.UK, the infrastructure provider and the Bank — KYE™ is an AI-authority and evidence layer, not a payment processor. | Out of scope | L1 Mapped | uk-fps.scheme-processing-settlement | — |
| Liquidity provision & net sender capsPrefunding the settlement account, sizing/managing the net sender cap and intraday liquidity monitoring are participant treasury functions — KYE™ is not a liquidity-management engine. | Out of scope | L1 Mapped | uk-fps.liquidity-net-sender-caps | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

SAFR

#### SAFR — Safeguards for Agentic Finance at Runtime

SAFR v1.0 (July 2026) · Global (industry reference; MAS Project MindForge lineage)

SAFR is an industry reference framework (BuildFin.AI) for a runtime governance layer over agentic AI in financial services: four components (Agent Identity, Controls Repository, Disposition Engine, Audit Log) exchanging a Governance Envelope, sitting after model guardrails and before execution. KYE Protocol™ maps to SAFR component-for-component at the moment-of-action admissibility check and adds Authority Finality™ — a Replay-Proof™ record verifiable from public keys alone. KYE™ governs whether the agentic financial action was allowed to become final; the rails execute if and only if approved.

### 6

Enforced

### 2

Designed

### 0

Out of scope

8 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Runtime governance at the point of action (pre-execution + per-step) | Enforced | L3 Enforceable | safr.pre-execution-governance, safr.per-step-independent-authority | Purpose Permission™Decision Engineper-action admissibility |
| Agent Identity — verified registered principal (SAFR component 1) | Designed | L3 Enforceable | safr.agent-identity-verification, safr.authoritative-registry-resolution | §0.30 agent-as-principal§52 authority bindingentity hierarchy |
| Controls Repository & capability-based mandate (SAFR component 2) | Enforced | L3 Enforceable | safr.controls-repository, safr.mandate-capability-authority | Rules Gateway™§52 authority claimDecision Map™ |
| Deterministic disposition — four outcomes, risk-calibrated (SAFR component 3) | Designed | L3 Enforceable | safr.deterministic-disposition, safr.four-outcome-disposition, safr.risk-calibrated-outcome | Decision EngineDecision Map™risk signals |
| Governance Envelope authenticated to origin | Enforced | L3 Enforceable | safr.governance-envelope-authenticated | Evidence Pack™tool-call pincontext seal |
| Immutable, tamper-evident audit log (SAFR component 4) | Enforced | L3 Enforceable | safr.immutable-audit-log | §30 WORMReplay-Proof™Authority Finality™ |
| Substantive human escalation (bounded, timeout, real authority) | Enforced | L3 Enforceable | safr.substantive-human-escalation | GovernedUI™ approval modestimeout→block/senior§9 no self-grant |
| Native + gateway integration and decision-not-settlement boundary | Enforced | L3 Enforceable | safr.native-and-gateway-integration, safr.decision-not-settlement-boundary | PEP (native + gateway)§0.33 Authority Finality™ category |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

AAOIFI SS

#### AAOIFI Shariah Standards

AAOIFI Shariah Standards (as at 2023 compilation) · International

AAOIFI's suite of Shariah Standards on Islamic-finance contracts and instruments — the substantive fiqh rulings adopted by many regulators and institutions.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Shariah Standards (substantive contract rulings) | Designed | L2 Designed | AAOIFI SS | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | AAOIFI SS | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/aaoifi-shariah-standards/)

AAOIFI GSIFI

#### AAOIFI Governance Standards (GSIFI)

AAOIFI Governance Standards for Islamic Financial Institutions (GSIFI) · International

AAOIFI's governance standards defining the Shariah supervisory board, review, audit, and governance-committee arrangements for Islamic financial institutions.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Governance Standards (GSIFI) | Designed | L2 Designed | AAOIFI GSIFI | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | AAOIFI GSIFI | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/aaoifi-governance-standards/)

AAOIFI FAS

#### AAOIFI Financial Accounting Standards (FAS)

AAOIFI Financial Accounting Standards (FAS) · International

AAOIFI's accounting standards for the recognition, measurement and disclosure of Islamic-finance contracts.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Financial Accounting Standards (FAS) | Designed | L2 Designed | AAOIFI FAS | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | AAOIFI FAS | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/aaoifi-accounting-standards/)

AAOIFI ASIFI

#### AAOIFI Auditing Standards (ASIFI)

AAOIFI Auditing Standards for Islamic Financial Institutions (ASIFI) · International

AAOIFI's auditing standards for external and Shariah-compliance audit of Islamic financial institutions.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Auditing Standards (ASIFI) | Designed | L2 Designed | AAOIFI ASIFI | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | AAOIFI ASIFI | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/aaoifi-auditing-standards/)

IFSB-10

#### IFSB-10 — Guiding Principles on Shari'ah Governance Systems

IFSB-10 (2009) · International

IFSB-10 sets guiding principles for the Shariah governance system: competence, independence, confidentiality and consistency of the Shariah board, plus review and audit functions.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Shariah Governance System (IFSB-10 guiding principles) | Designed | L2 Designed | IFSB-10 | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | IFSB-10 | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/ifsb-shariah-governance/)

IFSB

#### IFSB Prudential Standards (suite)

IFSB prudential standards suite · International

The IFSB's prudential and disclosure standards for institutions offering Islamic financial services, including corporate governance, core principles, and market-discipline disclosures.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Prudential & governance standards (IFSB suite) | Designed | L2 Designed | IFSB | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | IFSB | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/ifsb-prudential-standards/)

IIFM

#### IIFM Documentation Standards

IIFM documentation standards · International

IIFM's standardised master agreements and documentation for Islamic hedging, treasury, interbank and sukuk transactions.

### 1

Enforced

### 0

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Documentation & contract standards (IIFM) | Enforced | L3 Enforceable | IIFM | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | IIFM | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/iifm-documentation-standards/)

BNM SGF 2019

#### Bank Negara Malaysia — Shariah Governance Policy Document 2019

BNM/RH/PD 028-100 (2019) · Malaysia

BNM's Shariah Governance Policy Document (2019) sets board oversight, Shariah committee, and Shariah risk/review/audit/research control functions, operating under the binding rulings of BNM's Shariah Advisory Council (SAC).

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Shariah Governance (BNM SGF 2019 + SAC/IFSA 2013) | Designed | L2 Designed | BNM SGF 2019 | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | BNM SGF 2019 | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/bnm-shariah-governance/)

CBUAE HSA

#### CBUAE — Higher Shariah Authority and Shariah Governance Standard

CBUAE Shariah Governance Standard (2020) · United Arab Emirates

The CBUAE requires each Islamic financial institution to maintain an Internal Shariah Supervision Committee and Shariah control functions, operating under the binding resolutions of the CBUAE Higher Shariah Authority (HSA).

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Shariah Governance (CBUAE HSA Standard) | Designed | L2 Designed | CBUAE HSA | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | CBUAE HSA | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/cbuae-hsa-shariah-governance/)

CBB SG Module

#### Central Bank of Bahrain — Shariah Governance Module

CBB Rulebook — Shariah Governance Module · Bahrain

The CBB Shariah Governance Module mandates AAOIFI standards, an independent Shariah supervisory board, internal Shariah audit and review, and (from 2020) a centralised Shariah board.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Shariah Governance (CBB Module) | Designed | L2 Designed | CBB SG Module | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | CBB SG Module | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/cbb-shariah-governance/)

SAMA SGF

#### Saudi Central Bank — Shariah Governance Framework

SAMA Shariah Governance Framework (2020) · Saudi Arabia

SAMA's Shariah Governance Framework requires local banks to establish an independent Shariah committee, a Shariah division, and Shariah review and audit functions.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Shariah Governance (SAMA Framework) | Designed | L2 Designed | SAMA SGF | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | SAMA SGF | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/sama-shariah-governance/)

OJK / DSN-MUI

#### OJK / DSN-MUI — Indonesian Shariah Governance

OJK Shariah governance regulations + DSN-MUI fatawa · Indonesia

Indonesia operates a two-tier model: DSN-MUI issues national fatawa binding on Islamic financial institutions, while OJK regulates the institution-level Dewan Pengawas Syariah (Shariah Supervisory Board) and compliance functions.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Shariah Governance (OJK + DSN-MUI) | Designed | L2 Designed | OJK / DSN-MUI | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | OJK / DSN-MUI | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/ojk-shariah-governance/)

SBP SGF

#### State Bank of Pakistan — Shariah Governance Framework

SBP Shariah Governance Framework (2018) · Pakistan

SBP's Shariah Governance Framework mandates a board Shariah committee, a resident Shariah board member, a Shariah compliance department, and internal and external Shariah audit, under the SBP Shariah Advisory Committee's rulings.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Shariah Governance (SBP Framework) | Designed | L2 Designed | SBP SGF | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | SBP SGF | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/sbp-shariah-governance/)

QCB

#### Qatar Central Bank — Shariah Supervision and Governance

QCB Islamic banking instructions · Qatar

QCB and the QFCRA require Islamic financial institutions to maintain a Shariah supervisory board and Shariah review/audit functions, with broad reference to AAOIFI standards.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Shariah Governance (QCB / QFCRA) | Designed | L2 Designed | QCB | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | QCB | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/qcb-shariah-governance/)

CBK

#### Central Bank of Kuwait — Shariah Supervisory Governance

CBK Shariah supervisory governance instructions · Kuwait

The CBK requires Islamic banks to maintain an independent Shariah supervisory board and Shariah audit, coordinated with a higher committee for Shariah supervision at the CBK.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Shariah Governance (CBK) | Designed | L2 Designed | CBK | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | CBK | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/cbk-shariah-supervisory/)

CBO IBRF

#### Central Bank of Oman — Islamic Banking Regulatory Framework (IBRF)

CBO Islamic Banking Regulatory Framework (2012) · Oman

Oman's IBRF mandates a Shariah Supervisory Board, an internal Shariah reviewer, and Shariah audit for Islamic banks and windows, referencing AAOIFI standards.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Shariah Governance (CBO IBRF) | Designed | L2 Designed | CBO IBRF | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | CBO IBRF | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/cbo-ibrf-shariah/)

TKBB

#### TKBB — Participation Banking Standards (Türkiye)

TKBB participation-banking standards + BDDK regulation · Türkiye

In Türkiye, participation (Islamic) banks are supervised by BDDK; the TKBB Central Advisory Board issues participation-banking standards, and each bank maintains an advisory committee.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Participation Banking Governance (TKBB) | Designed | L2 Designed | TKBB | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | TKBB | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/tkbb-participation-banking/)

CBN NIFI

#### Central Bank of Nigeria — Non-Interest (Islamic) Financial Institutions

CBN guidelines for non-interest financial institutions · Nigeria

The CBN regulates Non-Interest (Islamic) Financial Institutions; a central Financial Regulation Advisory Council of Experts (FRACE) advises the CBN, and each institution maintains an Advisory Committee of Experts (ACE).

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Shariah Governance (CBN NIFI + FRACE) | Designed | L2 Designed | CBN NIFI | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | CBN NIFI | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/cbn-shariah-governance/)

FCA SSB model

#### UK FCA — Firm-Level Shariah Supervisory Board Model

FCA/PRA firm-level governance (no separate Shariah regime) · uk

The UK has no separate statutory Shariah regime; Islamic financial institutions operate under the standard FCA/PRA perimeter and appoint their own firm-level Shariah supervisory boards, typically applying AAOIFI standards.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Firm-Level Shariah Governance (UK FCA model) | Designed | L2 Designed | FCA SSB model | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | FCA SSB model | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/fca-ssb-firm-model/)

Brunei SFSB

#### Brunei — Syariah Financial Supervisory Board and BDCB

Syariah Financial Supervisory Board Order + BDCB regulation · Brunei Darussalam

Brunei's Syariah Financial Supervisory Board (SFSB) is the highest authority on Islamic finance matters; BDCB regulates institution-level Syariah advisory bodies.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Shariah Governance (Brunei SFSB) | Designed | L2 Designed | Brunei SFSB | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | Brunei SFSB | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/brunei-shariah-governance/)

CBJ Islamic

#### Central Bank of Jordan — Islamic Banking Shariah Governance

CBJ Islamic banking instructions · Jordan

The CBJ regulates Islamic banks under the Banking Law and dedicated instructions requiring a Shariah supervisory board and Shariah audit.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Shariah Governance (CBJ) | Designed | L2 Designed | CBJ Islamic | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | CBJ Islamic | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/jordan-islamic-banking/)

Egypt FRA

#### Egypt FRA — Islamic Finance Shariah Supervision

FRA Islamic finance regulations (sukuk, takaful) · Egypt

Egypt's FRA regulates non-banking Islamic finance (sukuk, takaful) with a central Shariah supervisory committee; the CBE oversees Islamic banking.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Shariah Governance (Egypt FRA) | Designed | L2 Designed | Egypt FRA | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | Egypt FRA | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/egypt-fra-shariah/)

Sudan HSSB

#### Central Bank of Sudan — High Shariah Supervisory Board

CBOS High Shariah Supervisory Board framework · Sudan

Sudan operates a fully Islamic banking system; the High Shariah Supervisory Board (HSSB) at the CBOS issues binding rulings, and each bank maintains a Shariah supervisory body.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Shariah Governance (Sudan HSSB) | Designed | L2 Designed | Sudan HSSB | Purpose Permission™Authority bindingWORM evidence chain |
| Substantive Shariah determination (halal/haram)The permissibility ruling is the exclusive authority of the Shariah board; KYE™ proves WHO ruled and that they were authorised, never the ruling itself (§70 §4). | Out of scope | L1 Mapped | Sudan HSSB | — |

[KYE™ framework reference](https://kyeprotocol.com/compliance/sudan-shariah-governance/)

RBI IT Governance MD

#### RBI IT Governance Master Direction

Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices · India

KYE™ governs the AUTHORITY + EVIDENCE layer where AI agents take consequential action inside a regulated entity's operations. KYE™ is OUT-OF-SCOPE for board-level IT governance structures, the entity's information-security programme, business-continuity capability and internal-audit function — those are the regulated entity's own, and RBI supervises them directly (§70 §4). Deep per-requirement mapping: 6 requirements, 2 enforced by KYE™ runtime, 4 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.

### 1

Enforced

### 0

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Authority + evidence at the action boundary — enforced by KYE™ runtime and verified by CI | Enforced | L3 Enforceable | rbi-master-direction-it.AGENT-ACTION-AUTHORITY — Consequential actions by automated systems resolve to a live delegated authority, rbi-master-direction-it.AUDIT-TRAIL — Tamper-evident audit trail over privileged and consequential operations | kye.compliance.attestation.v1kye.evidence.decision\_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context\_seal.v1internal |
| Obligations owed directly by the regulated entity — NOT discharged by KYE™KYE™ governs the AUTHORITY + EVIDENCE layer where AI agents take consequential action inside a regulated entity's operations. KYE™ is OUT-OF-SCOPE for board-level IT governance structures, the entity's information-security programme, business-continuity capability and internal-audit function — those are the regulated entity's own, and RBI supervises them directly (§70 §4). | Out of scope | L1 Mapped | rbi-master-direction-it.IT-GOVERNANCE-STRUCTURE — Board-level IT strategy committee and defined governance structure, rbi-master-direction-it.INFOSEC-PROGRAMME — Information-security policy, controls and periodic assessment, rbi-master-direction-it.BUSINESS-CONTINUITY — Business continuity and disaster-recovery capability with periodic testing, rbi-master-direction-it.IT-ASSURANCE — Independent assurance and internal audit over IT controls | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

### Healthcare AI — UK regulatory + clinical research

Frameworks specifically governing AI agents in clinical environments and UK medical-device regulation. Per-requirement bijection maps available at /compliance/<framework>.html.

PMDA SaMD

#### PMDA Software-as-a-Medical-Device (SaMD) Pathway

PMD Act SaMD pathway + PMDA review framework · Japan

The Pharmaceuticals and Medical Devices Agency's Software-as-a-Medical-Device review pathway under the PMD Act, including the SaMD two-step (DASH) approval scheme and AI/ML change-control expectations. KYE Protocol™ evidences the QMS, clinical-evaluation provenance, change-control, post-market surveillance and human-oversight obligations that bind an AI-supported clinical action; device classification and marketing approval remain the manufacturer's submission. Per-requirement bijection at /compliance/pmda-samd.html.

### 2

Enforced

### 1

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| QMS evidence & clinical-evaluation provenance | Enforced | L3 Enforceable | PMDA SaMD QMS evidence, PMDA SaMD clinical evaluation | WORM audit hash-chainEvidence Pack™Data Classification Engine |
| Change control, versioning & human oversight of clinical decisions | Enforced | L3 Enforceable | PMDA SaMD change control, PMDA SaMD human oversight | Conformance RunnerDrift DetectorGovernedUI™Authority Resolution™ |
| Post-market surveillance & incident reporting to the PMDAKYE™ assembles the PMDA adverse-event notification package; the regulator-side delivery channel to the PMDA is designed pending the per-jurisdiction reporting connector. | Designed | L1 Mapped | PMDA SaMD post-market surveillance | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

CLIA

#### CLIA — Clinical Laboratory Improvement Amendments (42 CFR Part 493)

42 CFR 493 · US

The Clinical Laboratory Improvement Amendments (42 CFR Part 493) set US federal quality standards for testing on human specimens. KYE Protocol™ enforces the test-report integrity and electronic-record audit-trail slices, and governs the authority of AI-supported result generation — testing, proficiency testing and competency stay the laboratory's quality system. Per-requirement bijection at /compliance/clia.html.

### 3

Enforced

### 1

Designed

### 1

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Test records & result-report integrity (Subpart J, 493.1291) | Enforced | L3 Enforceable | clia.493.1291-report-integrity | Decision replayEvidence Pack™ |
| Audit trail for electronic test records | Enforced | L3 Enforceable | clia.audit-trail | WORM audit hash-chain |
| Test-record retention (493.1105) | Designed | L2 Designed | clia.493.1105-record-retention | WORM audit hash-chain |
| Authority & oversight of AI-supported result generation (Subpart M) | Enforced | L3 Enforceable | clia.493.1445-ai-oversight | Purpose Permission™Authority Gate |
| Analytic-system QC, validation, proficiency testing & competency (Subparts K, H, M)Analytic-system quality control, method validation, proficiency testing and personnel competency are the laboratory's own quality and HR functions — out of scope for an AI-authority-governance protocol. | Out of scope | L1 Mapped | clia.493-subpart-k-analytic-systems, clia.493-pt-competency | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

HAARF v1.0

#### HAARF — Healthcare AI Agents Regulatory Framework

v1.0 (2026) · Global

Comprehensive security and governance standard for autonomous AI agents in clinical environments — 279 requirements across 8 categories.

### 1

Enforced

### 0

Designed

### 0

Out of scope

1 requirement group — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| 279 requirements across 8 categories — risk lifecycle, model passport, cybersecurity, human oversight, agent registration, autonomy governance, bias/equity, tool integration | Enforced | L3 Enforceable | HAARF C1–C8 | Decision EngineEvidence EngineGovernedUI approvalEdge Governance modesShadow ModeAgent Tool Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/compliance/haarf/)

ISO 15189

#### ISO 15189:2022 — Medical laboratories: quality and competence

2022 · International

ISO 15189:2022 sets quality and competence requirements for medical laboratories, including patient-safety risk management. KYE Protocol™ enforces the §7.4-7.6 report-integrity, §7.6/§8.4 data-integrity and audit-trail slices where a medical laboratory uses AI-supported decisioning — examination procedures and competence stay the laboratory's quality system. Per-requirement bijection at /compliance/iso-15189.html.

### 5

Enforced

### 0

Designed

### 1

Out of scope

6 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Reporting of results & integrity of the report (7.4-7.6) | Enforced | L3 Enforceable | iso-15189.7.4-report-integrity | Decision replayEvidence Pack™ |
| Control of records & audit trail (8.4) | Enforced | L3 Enforceable | iso-15189.8.4-record-control | WORM audit hash-chain |
| Information management & data integrity (7.6, 8.4) | Enforced | L3 Enforceable | iso-15189.7.6-data-integrity | Decision replayEvidence Pack™ |
| Impartiality & authorised decision-making (5.1, 6.2) | Enforced | L3 Enforceable | iso-15189.5.1-impartiality-authority | Purpose Permission™Authority Gate |
| Risk management & patient-safety evidence (8.5) | Enforced | L3 Enforceable | iso-15189.8.5-risk-patient-safety | Resilience Loop™ |
| Examination processes & technical competence (6, 7.3)Validation of examination procedures, reference intervals, equipment/reagents and technical competence are the medical laboratory's own quality system — out of scope for an AI-authority-governance protocol. | Out of scope | L1 Mapped | iso-15189.6-examination-competence | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

MHRA MDR 2002

#### UK Medical Devices Regulations 2002

2002 as amended through 2024 · United Kingdom

UK Statutory Instrument 2002/618 — risk classes, conformity assessment, essential requirements (Annex I regs 7-12), Annex IX classification rules, and post-market vigilance (regs 44-47). 53 requirements.

### 1

Enforced

### 0

Designed

### 0

Out of scope

1 requirement group — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| 53 requirements across risk classes + conformity assessment + essential requirements + classification rules + post-market vigilance | Enforced | L3 Enforceable | SI 2002/618 | Profile classificationSector packSigned evidence packTrust-domain UDI |

[KYE™ framework reference](https://kyeprotocol.com/compliance/mhra-mdr-2002/)

MHRA PMS 2025

#### MHRA Post-Market Surveillance Regulations 2025

SI 2024/1368 (effective June 2025) · United Kingdom

Explicit post-market surveillance obligations: PMS plan (Reg 7), post-market clinical follow-up (Reg 8), incident reporting timelines (2/10/15-day), Periodic Safety Update Reports (PSURs), trend reporting. 36 requirements.

### 1

Enforced

### 0

Designed

### 0

Out of scope

1 requirement group — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| 36 requirements across PMS plan, PMCF, incident timelines, PSURs, and trend reporting | Enforced | L3 Enforceable | SI 2024/1368 | Resilience-loop registryComms-rail templatesAnalytics-plane eventsGovernedUI two-person sign-off |

[KYE™ framework reference](https://kyeprotocol.com/compliance/mhra-pms-2025/)

MHRA SaMD & AI

#### MHRA Software and AI as a Medical Device Change Program

2023 Change Program · United Kingdom

41 requirements: 15 original work-packages + 7 PCCP (Predetermined Change Control Plan) obligations + 9 change-class triggers (capability / model\_params / training-data / bias drift) + 6 transparency obligations + 4 oversight/bias-mitigation controls.

### 1

Enforced

### 0

Designed

### 0

Out of scope

1 requirement group — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| 41 requirements across SaMD lifecycle, PCCP, change-class triggers, transparency, and oversight | Enforced | L3 Enforceable | MHRA SaMD Program 2023 | Canonical change-controlReplay-Proof™ envelopeDecision Map™Evidence Pack™Shadow ModeEdge Governance bundle versioning |

[KYE™ framework reference](https://kyeprotocol.com/compliance/mhra-samd-change-programme/)

PHIPA Ontario

#### PHIPA (Ontario) — Personal Health Information Protection Act, 2004

S.O. 2004, c. 3, Sched. A · Canada

Ontario's health-privacy statute (PHIPA, 2004): consent + lawful purpose, circle-of-care implied consent, data minimisation, the electronic audit-log duty, access/correction, and IPC breach notification for personal health information. Per-requirement bijection at /compliance/phipa-ontario.html.

### 4

Enforced

### 1

Designed

### 0

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Consent + lawful purpose (ss.29-30, 36-38) | Enforced | L3 Enforceable | s29, s38 | Authority GateDecision Map™Purpose Permission™ |
| Data minimisation (s.30(2)) | Enforced | L3 Enforceable | s30-2 | Purpose Permission™ |
| Electronic audit log + access control (s.10.1, s.12, O.Reg.329/04 s.6.3) | Enforced | L3 Enforceable | s10.1 | WORM audit hash-chain |
| Access + correction (ss.52-55) | Enforced | L3 Enforceable | s52 | Reporting EngineWORM audit hash-chain |
| Breach + IPC notification (s.12(2)-(3)) | Designed | L2 Designed | s12-2 | Incident DetectorReporting Engine |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

CDSCO MDR 2017

#### CDSCO Medical Devices Rules 2017

Medical Devices Rules, 2017, as amended · India

Where AI software qualifies as a medical device, KYE™ governs the AUTHORITY + EVIDENCE layer of clinical actions the software takes or recommends. KYE™ is OUT-OF-SCOPE for device classification, licensing, manufacturing quality systems and the clinical determination itself — those belong to the manufacturer and CDSCO (§70 §4). Deep per-requirement mapping: 5 requirements, 2 enforced by KYE™ runtime, 3 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.

### 1

Enforced

### 0

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Authority + evidence at the action boundary — enforced by KYE™ runtime and verified by CI | Enforced | L3 Enforceable | cdsco-medical-devices.CLINICAL-ACTION-AUTHORITY — Clinical actions by software resolve to a live authority and are evidenced, cdsco-medical-devices.POST-MARKET-EVIDENCE — Records supporting post-market surveillance and adverse-event review | kye.compliance.attestation.v1kye.evidence.decision\_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context\_seal.v1internal |
| Obligations owed directly by the regulated entity — NOT discharged by KYE™Where AI software qualifies as a medical device, KYE™ governs the AUTHORITY + EVIDENCE layer of clinical actions the software takes or recommends. KYE™ is OUT-OF-SCOPE for device classification, licensing, manufacturing quality systems and the clinical determination itself — those belong to the manufacturer and CDSCO (§70 §4). | Out of scope | L1 Mapped | cdsco-medical-devices.DEVICE-CLASSIFICATION — Risk-based classification of the device, cdsco-medical-devices.LICENSING — Manufacturing or import licence obtained and maintained, cdsco-medical-devices.QMS — Quality management system for design and manufacture | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

### Sectoral frameworks

Domain-specific AI accountability frameworks scoped to a single regulated sector.

API 580/581

#### API 580 / API 581 — Risk-Based Inspection for fixed equipment

2016 · Global

API RP 580 (RBI methodology) + API 581 (RBI quantitative technology) for fixed-equipment inspection planning. KYE Protocol™ governs the authority and evidence of an AI-recommended inspect/repair/replace action and records the inspection-interval + failure-mode reference vocabulary; KYE Protocol™ does not compute RBI risk. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 2

Designed

### 0

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| RBI decision documentation + review (contestable) | Designed | L2 Designed | api-580.10.0 | Evidence Pack™Authority Gate |
| High-consequence action named-engineer sign-off | Designed | L2 Designed | api-581.5.0 | Authority GateDecision Map™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Australia Group

#### Australia Group — Biological & Chemical Dual-Use Export Controls

2023 · Global

Australia Group dual-use export-control regime — harmonised control lists for dual-use biological agents, toxins, equipment, and chemical-weapon precursors. KYE Protocol™ governs whether an AI-generated design mapping to a controlled item may proceed to a consequential action — the KYE™ AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Dual-use biological control list | Designed | L2 Designed | australia-group.bio-agents, australia-group.bio-equipment | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Dual-use chemical precursor list | Designed | L2 Designed | australia-group.chem-precursors | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Controlled-item action gating | Designed | L2 Designed | australia-group.controlled-item-gate | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

BCBS 239

#### BCBS 239 — Risk Data Aggregation & Risk Reporting Principles

BCBS 239 (Principles for effective risk data aggregation and risk reporting, January 2013) · International

BCBS 239 sets the Basel Committee's 14 principles for effective risk data aggregation and risk reporting. KYE Protocol™ governs whether a model-driven output or risk report under it may proceed to a consequential action — only a currently-validated model used within its approved scope, model changes as named-authority decisions with evidence, every consequential decision pinned to model\_id + version + validation reference, and every risk report bound to its data-lineage evidence chain, sealed into a signed replay-provable Evidence Pack™. The quantitative model build / validation mathematics / capital computation / portfolio composition stays the bank's own work (honest scope, §0 — not investment advice). All 14 principles are mapped one row each (honest tri-state). Per-requirement bijection at /compliance/bcbs-239.html.

### 3

Enforced

### 0

Designed

### 3

Out of scope

6 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Risk-data governance & named authority on the report (P1) | Enforced | L3 Enforceable | bcbs-239.principle1-governance | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Risk-data aggregation lineage, completeness & adaptability (P3 / P4 / P6) | Enforced | L3 Enforceable | bcbs-239.principle3-accuracy-integrity-lineage, bcbs-239.principle4-completeness, bcbs-239.principle6-adaptability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Risk-report traceability, cadence & distribution evidence (P7 / P10 / P11) | Enforced | L3 Enforceable | bcbs-239.principle7-reporting-accuracy, bcbs-239.principle10-frequency, bcbs-239.principle11-distribution | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Bank data architecture & crisis-timeliness capability (P2 / P5)The data architecture, IT infrastructure, and crisis-timeliness aggregation capability are the bank's own data and technology estate — KYE™ is an AI-authority and evidence layer, not a data platform. | Out of scope | L1 Mapped | bcbs-239.principle2-data-architecture, bcbs-239.principle5-timeliness | — |
| Report substance — comprehensiveness & clarity (P8 / P9)Judging material-risk coverage and the report's editorial quality is the bank's risk and reporting functions' own work — KYE™ proves what the report aggregated and how, not whether it covered everything that mattered. | Out of scope | L1 Mapped | bcbs-239.principle8-comprehensiveness, bcbs-239.principle9-clarity-usefulness | — |
| Supervisory review, remedial tools & home/host cooperation (P12–P14)Principles 12–14 are addressed to supervisors — conducting the review, applying supervisory measures, and home/host cooperation are regulator functions; KYE™'s sealed evidence chains support the bank's side of the review but the obligations sit outside an AI-authority-governance protocol. | Out of scope | L1 Mapped | bcbs-239.principle12-supervisory-review, bcbs-239.principle13-remedial-actions, bcbs-239.principle14-home-host-cooperation | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Colorado SB21-169

#### Colorado SB21-169 — Insurers' Use of External Consumer Data & AI

Colorado SB21-169 (Restrict Insurers' Use of External Consumer Data; C.R.S. §10-3-1104.9) + Division of Insurance regulations · United States

Colorado SB21-169 restricts insurers' use of external consumer data, algorithms, and predictive models to prevent unfair discrimination, and requires testing, documentation, and consumer adverse-action reasons. KYE Protocol™ governs whether an AI-assisted underwriting or claims decision relying on external data may proceed to a consequential adverse action — under a named authority, with a recorded adverse-action reason-code, with proxy-discrimination / fairness-evidence captured, a signed replay-provable Evidence Pack™ per decision, and an appeal / contestability record. The external-data selection / pricing / methodology design on the merits stays the insurer's own work (honest scope, §0). Per-requirement bijection at /compliance/colorado-sb21-169.html.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Adverse-action reason explainability to the consumer | Enforced | L3 Enforceable | colorado-sb21-169.adverse-action-explainability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| External-data proxy-discrimination evidence | Enforced | L3 Enforceable | colorado-sb21-169.external-data-discrimination-evidence | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Named-authority on the external-data-driven decision | Enforced | L3 Enforceable | colorado-sb21-169.external-data-decision-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| External data source selection & pricing on the meritsThe external-data selection / pricing / methodology design on the merits is the insurer's own work — KYE™ is an AI-authority and evidence layer, not a pricing or data-selection engine. | Out of scope | L1 Mapped | colorado-sb21-169.external-data-source-selection-pricing | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

COSHH

#### COSHH — Control of Substances Hazardous to Health Regulations 2002 (UK)

2002 · United Kingdom

UK COSHH 2002 (SI 2002/2677), HSE-enforced. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved COSHH assessments and control instructions — the KYE™ HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| COSHH assessment authored under safety floor | Designed | L2 Designed | coshh.reg-6 | Purpose Permission™Edge Governance Safety Floor |
| Exposure-control measure advisory pending sign-off | Designed | L2 Designed | coshh.reg-7 | Authority GateDecision Map™ |
| Control-measure instruction contestable + evidenced | Designed | L2 Designed | coshh.reg-8 | Evidence Pack™Authority Gate |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

CWC / BWC

#### CWC + BWC — Chemical & Biological Weapons Conventions

1997-2024 · Global

Chemical Weapons Convention (CWC, Schedules 1/2/3) + Biological Weapons Convention (BWC, prohibited bio/toxin agents). KYE Protocol™ governs whether an AI-generated molecule or agent mapping to a scheduled/prohibited item may proceed to a consequential action — a hard stop routed to oversight, the KYE™ AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| CWC scheduled chemicals (Schedule 1/2/3) | Designed | L2 Designed | cwc-bwc.cwc-schedule1, cwc-bwc.cwc-schedule2-3 | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| BWC prohibited biological / toxin agents | Designed | L2 Designed | cwc-bwc.bwc-prohibited-agents | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Prohibited-agent action stop | Designed | L2 Designed | cwc-bwc.prohibited-agent-stop | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

DoD 5015.2

#### DoD 5015.02-STD — Records Management Application Design Criteria (RMA spine)

2007 · United States

DoD 5015.02-STD records-management-application spine for the KYE™ Chain of Authority™ for Iron Mountain InSight DXP. KYE Protocol™ overlays the action-boundary access-control + named-authority + governance-decision audit (enforced); the RMA record-declaration / file-plan / disposition criteria are out-of-scope (owned by the records-manager). §0: KYE Protocol™ retains PROOF-OF-GOVERNANCE, not the customer's records.

### 2

Enforced

### 0

Designed

### 2

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Access-control decision at the action boundary (authority overlay) | Enforced | L3 Enforceable | dod-5015-2.access-control-action-decision, dod-5015-2.named-authority-binding | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Audit of the action decision (authority overlay) | Enforced | L3 Enforceable | dod-5015-2.action-decision-audit | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Record declaration & categorisation / file plan (RMA criteria) | Out of scope | L1 Mapped | dod-5015-2.record-declaration-file-plan | — |
| Disposition & transfer (RMA criteria) | Out of scope | L1 Mapped | dod-5015-2.disposition-transfer | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Dodd-Frank §922

#### Dodd-Frank §922 + SEC Rule 21F — Whistleblower Programme

Dodd-Frank Act §922 (15 U.S.C. §78u-6) + SEC Rules 21F (whistleblower programme) · United States

Dodd-Frank §922 + SEC Rule 21F — Whistleblower Programme is the US SEC whistleblower programme (confidentiality, anti-retaliation, the Rule 21F-17 anti-impediment prohibition). KYE Protocol™ governs whether an AI-assisted access to a whistleblower's identity or a consequential case action may proceed — on a recorded need-to-know authority, with confidentiality evidence captured, a signed Evidence Pack™, and a contestability record. Assessing the securities-law tip on its merits, awarding the bounty, and adjudicating the §922 / Rule 21F claim stay with the SEC and counsel (honest scope, §0). Per-requirement bijection at /compliance/dodd-frank-whistleblower.html.

### 2

Enforced

### 0

Designed

### 1

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Confidentiality & anti-impediment evidence for a whistleblower's identity | Enforced | L3 Enforceable | dodd-frank-whistleblower.confidentiality-evidence | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & reconstruction of the handling / retaliation determination | Enforced | L3 Enforceable | dodd-frank-whistleblower.handling-contestability-reconstruction | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Securities-law merits, bounty award & Rule 21F adjudicationAssessing the tip, awarding the bounty, and adjudicating the §922 / Rule 21F claim is the SEC's and counsel's determination — KYE™ is an AI-authority and evidence layer, not an enforcement engine. | Out of scope | L1 Mapped | dodd-frank-whistleblower.securities-merits-and-award | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

EU AI Act insurance

#### EU AI Act — Annex III High-Risk Insurance

Regulation (EU) 2024/1689 (EU AI Act) — Annex III high-risk insurance use-cases (life & health risk assessment / pricing) · European Union

The EU AI Act classifies AI used for risk assessment and pricing in life and health insurance as high-risk (Annex III), triggering human-oversight (Art. 14), record-keeping (Art. 12), and transparency obligations. KYE Protocol™ governs whether an AI-assisted insurance decision in scope may proceed to a consequential adverse action — under a named human-oversight authority, with a recorded adverse-action reason-code, fairness-evidence captured, a signed replay-provable Evidence Pack™ (the Art. 12 log) per decision, and an appeal / contestability record. The risk pricing / system build / conformity assessment on the merits stays the provider's own work (honest scope, §0). Per-requirement bijection at /compliance/eu-ai-act-insurance.html.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Human oversight authority over the high-risk decision (Art. 14) | Enforced | L3 Enforceable | eu-ai-act-insurance.annex3-human-oversight | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Record-keeping / logging of the AI decision (Art. 12) | Enforced | L3 Enforceable | eu-ai-act-insurance.annex3-record-keeping-logging | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Transparency & contestability of the decision | Enforced | L3 Enforceable | eu-ai-act-insurance.annex3-transparency-contestability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Risk pricing, system build & conformity assessment on the meritsThe risk pricing / high-risk system build / Art. 43 conformity assessment on the merits is the provider's own work — KYE™ is an AI-authority and evidence layer at the action boundary, not a system-build, pricing, or conformity-assessment engine. | Out of scope | L1 Mapped | eu-ai-act-insurance.risk-pricing-system-build-conformity | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

EU Evidence Reg

#### EU Evidence Regulation 2020/1783 + eIDAS — Evidence Authenticity & Transmission

Regulation (EU) 2020/1783 (taking of evidence in civil/commercial matters) + eIDAS Regulation (EU) 910/2014 (electronic evidence integrity) · European Union

EU Evidence Regulation 2020/1783 + eIDAS — Evidence Authenticity & Transmission is the EU cross-border evidence and electronic-integrity framework (Regulation 2020/1783 + eIDAS). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/eu-evidence-regulation.html.

### 2

Enforced

### 0

Designed

### 1

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Chain-of-custody & integrity for cross-border evidence transmission | Enforced | L3 Enforceable | eu-evidence-regulation.evidence-authenticity-transmission | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Integrity-bound, contestable Evidence Pack™ (eIDAS-aligned) | Enforced | L3 Enforceable | eu-evidence-regulation.eidas-integrity-evidence-pack | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Member-State admissibility & substantive evidential assessmentThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. | Out of scope | L1 Mapped | eu-evidence-regulation.member-state-admissibility | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

EU Whistleblower Dir.

#### EU Whistleblower Directive — Directive (EU) 2019/1937

Directive (EU) 2019/1937 (protection of persons who report breaches of Union law) · European Union

EU Whistleblower Directive — Directive (EU) 2019/1937 is the EU whistleblower-protection framework (confidentiality, acknowledgement / feedback clocks, prohibition of retaliation). KYE Protocol™ governs whether an AI-assisted intake-triage decision, an access to a reporter's identity / PII, a case disposition (close / escalate), or an adverse action on a reporter may proceed to a consequential action — under a named handler's authority, on a recorded need-to-know basis, with confidentiality and retaliation-risk evidence captured, a signed replay-provable Evidence Pack™ per consequential action, and a contestability record so any disposition can be reconstructed and challenged. The substantive investigation / allegation merits / remediation decision stays the organisation's own work (honest scope, §0). Per-requirement bijection at /compliance/eu-whistleblower-directive.html.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Confidentiality & need-to-know access to a reporter's identity | Enforced | L3 Enforceable | eu-whistleblower-directive.confidentiality-need-to-know-access | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Named-authority on the case disposition (acknowledgement / feedback clocks) | Enforced | L3 Enforceable | eu-whistleblower-directive.case-disposition-named-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & reconstruction of the handling | Enforced | L3 Enforceable | eu-whistleblower-directive.handling-contestability-reconstruction | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive investigation & whether the breach occurredInvestigating the report on its merits and deciding the remediation is the organisation's own ethics / legal work — KYE™ is an AI-authority and evidence layer, not an investigation or adjudication engine. | Out of scope | L1 Mapped | eu-whistleblower-directive.substantive-investigation | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Fed SR 11-7

#### Fed SR 11-7 — Supervisory Guidance on Model Risk Management

SR 11-7 / OCC 2011-12 (Supervisory Guidance on Model Risk Management, April 2011) · United States

Fed SR 11-7 / OCC 2011-12 is the US supervisory guidance on model risk management (development, validation, governance). KYE Protocol™ governs whether a model-driven output or risk report under it may proceed to a consequential action — only a currently-validated model used within its approved scope, model changes as named-authority decisions with evidence, every consequential decision pinned to model\_id + version + validation reference, and every risk report bound to its data-lineage evidence chain, sealed into a signed replay-provable Evidence Pack™. The quantitative model build / validation mathematics / capital computation / portfolio composition stays the bank's own work (honest scope, §0 — not investment advice). Per-requirement bijection at /compliance/fed-sr-11-7.html.

### 4

Enforced

### 0

Designed

### 1

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Validated-model use authority at the decision boundary | Enforced | L3 Enforceable | fed-sr-11-7.model-use-named-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Model change control as a named-authority decision | Enforced | L3 Enforceable | fed-sr-11-7.model-change-control | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Decision traceability to model version & validation reference | Enforced | L3 Enforceable | fed-sr-11-7.decision-provenance-traceability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Model inventory & policy controls on model use | Enforced | L3 Enforceable | fed-sr-11-7.inventory-policy-controls | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Quantitative model development, validation & capital mathematicsThe quantitative model build, validation mathematics, and capital & liquidity computation are the bank's own quantitative work — KYE™ is an AI-authority and evidence layer, not a model-validation or capital-calculation engine. | Out of scope | L1 Mapped | fed-sr-11-7.quantitative-development-validation | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

OCC AI Supervision

#### OCC AI Supervisory Expectations — Model Risk · Third-Party Risk · New-Activity / Filing Readiness

2024 · United States

The U.S. Office of the Comptroller of the Currency (OCC) supervises national banks and federal savings associations. Its supervisory expectations for a bank deploying consequential AI draw on OCC Bulletin 2011-12 (model risk management, joint with Fed SR 11-7), OCC Bulletin 2013-29 + the 2023 Interagency Third-Party Risk Management Guidance, OCC heightened standards for risk governance, and the OCC's new-activity / examiner-engagement expectations. KYE Protocol™ governs the action-boundary subset at runtime — only a consequential AI action under its approved use and recorded authority proceeds, out-of-scope actions escalate or are refused, and every action that proceeds is replay-provable to an OCC examiner from public keys alone. KYE™ operationalises the OCC's expectations — it does NOT replace them (§0.25 integrate-not-compete). Honest scope: KYE™ does NOT run the bank's MRM program, validate models, make the bank's regulatory filing, or judge whether the AI's output is correct; that work, and the OCC's own supervisory determinations, stay out of scope. Broader, separate spine from the fed-sr-11-7 MRM-only row (references SR 11-7 lineage, does not duplicate it). Per-requirement bijection at /compliance/occ-ai-supervision.html.

### 4

Enforced

### 0

Designed

### 1

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Model risk management (approved-use authority + model-change as a named-authority decision) | Enforced | L3 Enforceable | occ-ai-supervision.validated-use-authority-at-the-decision-boundary, occ-ai-supervision.model-change-as-named-authority-decision | Purpose Permission™Authority GatewayGovernedUI™ named-authority sign-offEvidence Pack™ |
| Third-party / vendor AI risk (external authority register + escalation before finality)KYE™ governs what external/vendor AI is authorised to DO inside the bank's action boundary; vendor due-diligence and contract review on the merits stay the bank's own (honest scope). | Enforced | L3 Enforceable | occ-ai-supervision.third-party-ai-authority-register, occ-ai-supervision.out-of-scope-escalation-before-finality | Authority RegisterAuthority Gateway (REQUIRE\_APPROVAL)Edge Governance Safety FloorGovernedUI™ escalation |
| New-activity / filing & examiner readiness (replay-provable Evidence Packs + action-authority inventory)KYE™ proves to an OCC examiner how each consequential AI action was governed; making the regulatory filing and the OCC's supervisory determinations stay out of scope (honest scope). | Enforced | L3 Enforceable | occ-ai-supervision.new-activity-examiner-replayable-evidence, occ-ai-supervision.action-authority-inventory | Evidence Pack™Replay-Proof™WORM audit hash-chainEntity & Principal Registry |
| Heightened-standards governance & accountability (named accountability at the action boundary)KYE™ binds and proves named accountability at the boundary; staffing and running the bank's three-lines-of-defence operating model stays the bank's own (honest scope). | Enforced | L3 Enforceable | occ-ai-supervision.heightened-standards-named-accountability | GovernedUI™ named-authority sign-offDelegated Auditability RailAuthority Finality™ |
| Model development, validation & supervisory determinationsDeveloping and validating the model, running the bank's MRM program, making the regulatory filing, and the OCC's own supervisory determinations / examination ratings are the bank's and the regulator's own work — KYE™ is an AI-authority and evidence layer, not a model-validation engine, a filing service, or a supervisor. | Out of scope | L1 Mapped | occ-ai-supervision.model-development-validation-supervisory-determinations | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

FRCP e-discovery

#### FRCP e-Discovery — Rules 26 / 34 / 37 + FRE 502 (privilege)

FRCP (2015 e-discovery amendments; Rules 26 / 34 / 37 + FRE 502) · United States

FRCP e-Discovery — Rules 26 / 34 / 37 + FRE 502 (privilege) is the US federal e-discovery and privilege framework (FRCP 26 / 34 / 37 + FRE 502). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/frcp-ediscovery.html.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Named-authority on the privilege / discovery determination | Enforced | L3 Enforceable | frcp-ediscovery.rule26g-discovery-certification | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Discovery chain-of-custody for produced / withheld ESI | Enforced | L3 Enforceable | frcp-ediscovery.rule34-esi-chain-of-custody | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & sanctions-reconstruction of the determination | Enforced | L3 Enforceable | frcp-ediscovery.rule37-sanctions-reconstruction | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive privilege judgment & attorney certification on the meritsThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. | Out of scope | L1 Mapped | frcp-ediscovery.substantive-privilege-judgment | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

FRE 901/902

#### FRE 901 / 902 — Authentication & Self-Authentication of Evidence

FRE 901 / 902 (Authentication & Self-Authentication; 2017 ESI amendments) · United States

FRE 901 / 902 — Authentication & Self-Authentication of Evidence is the US evidence-authentication framework (FRE 901 / 902). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/fre-authentication.html.

### 2

Enforced

### 0

Designed

### 1

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| No-hallucinated-citation provenance pin for AI assertions | Enforced | L3 Enforceable | fre-authentication.rule901-authentication-evidence | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Hash-bound self-authenticating Evidence Pack™ | Enforced | L3 Enforceable | fre-authentication.rule902-self-authenticating-record | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive admissibility, relevance & weight of the evidenceThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. | Out of scope | L1 Mapped | fre-authentication.substantive-admissibility | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ABA Model Rules

#### ABA Model Rules of Professional Conduct (AI-relevant duties)

Rules 1.1 / 1.4 / 1.5 / 1.6 / 5.1 / 5.3 + ABA Formal Opinion 512 (2023) · United States

The ABA Model Rules of Professional Conduct set the US legal profession's core duties — competence (Rule 1.1, incl. technological competence), communication (1.4), reasonable fees (1.5), confidentiality (1.6), and supervision of subordinate lawyers and non-lawyer assistance (5.1 & 5.3) — extended to generative AI by ABA Formal Opinion 512 (2023) and state-bar guidance (California 2023, NYSBA 2024). KYE Protocol™ governs whether an AI-assisted legal action supporting each duty may proceed to a consequential step — under a named lawyer's authority, with the verification, confidentiality-isolation, communication and supervisory-accountability record captured as a signed, replay-provable Evidence Pack™ that predates the incident. Each AI-relevant duty is mapped onto the existing KYE™ Legal Pack™ (kye:sector-pack:legal) workflows at the requirement level and marked designed (authority boundary bound, no runtime engine wired yet), except the reasonable-fees duty (Rule 1.5), which has no KYE™ artefact governing legal billing and is honestly out of scope. KYE™ governs the AUTHORITY BOUNDARY of the AI action — NOT wholesale compliance with a professional-conduct duty, and NOT the practice of law: it does not draft, advise, judge attorney conduct, or render the lawyer's professional judgment. Per-requirement bijection at /compliance/aba-model-rules.html.

### 0

Enforced

### 5

Designed

### 1

Out of scope

6 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Competence — verified AI work product authority (Rule 1.1) | Designed | L2 Designed | aba-model-rules.rule-1-1-competence | Purpose Permission™Authority GateEvidence Pack™ |
| Client communication release authority (Rule 1.4) | Designed | L2 Designed | aba-model-rules.rule-1-4-communication | Purpose Permission™Evidence Pack™ |
| Confidentiality & client-information isolation (Rule 1.6) | Designed | L2 Designed | aba-model-rules.rule-1-6-confidentiality | Authority GateZero Contamination |
| Supervisory responsibility & firm AI-governance record (Rules 5.1 & 5.3) | Designed | L2 Designed | aba-model-rules.rule-5-1-5-3-supervision | Delegated AuditabilityGovernedUI™Evidence Pack™ |
| Generative-AI use authority boundary (Formal Opinion 512) | Designed | L2 Designed | aba-model-rules.formal-opinion-512-genai | Purpose Permission™Evidence Pack™GovernedUI™ |
| Reasonable fees (Rule 1.5)No KYE™ artefact governs legal billing or fee reasonableness — the firm's own regulated determination. Honest out-of-scope (§0); coverage never inflated. | Out of scope | L1 Mapped | aba-model-rules.rule-1-5-fees | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

GDPR Whistleblowing

#### GDPR (Whistleblowing) — Special-Category & Data-Minimisation in Reports

Regulation (EU) 2016/679 (GDPR) — whistleblowing data-protection slice (Art. 5, 6, 9, 15, 21) · European Union

GDPR (Whistleblowing) — Special-Category & Data-Minimisation in Reports is the data-protection slice of whistleblowing (data minimisation, special-category restriction, need-to-know access, data-subject access / objection). KYE Protocol™ governs whether an AI-assisted access to the personal / special-category data in a report may proceed — on a recorded need-to-know authority, with data-minimisation evidence captured, a signed Evidence Pack™, and a contestability record so a data-subject access or objection can be reconstructed. The lawful-basis assessment of the underlying processing, the DPIA, and data-subject adjudication stay with the controller / DPO / supervisory authority (honest scope, §0). Per-requirement bijection at /compliance/gdpr-whistleblower.html.

### 2

Enforced

### 0

Designed

### 1

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Need-to-know access & data-minimisation evidence for special-category report data | Enforced | L3 Enforceable | gdpr-whistleblower.special-category-need-to-know-access | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Data-subject contestability (access / objection) reconstruction | Enforced | L3 Enforceable | gdpr-whistleblower.data-subject-contestability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Lawful-basis assessment, DPIA & data-subject adjudicationThe lawful-basis assessment, the DPIA, and data-subject adjudication is the controller's / DPO's / supervisory authority's determination — KYE™ is an AI-authority and evidence layer, not a data-protection-compliance engine. | Out of scope | L1 Mapped | gdpr-whistleblower.lawful-basis-and-dpia | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ICH Q1

#### ICH Q1 — Stability Testing

ICH Q1A(R2) (2003) · International

ICH Q1 — Stability Testing is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q1.html.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Authority over an AI stability summary at the action boundary | Designed | L2 Designed | ich-q1.named-authority | Purpose Permission™Authority Gate |
| Stability study science & shelf-life determinationThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. | Out of scope | L1 Mapped | ich-q1.science | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ICH Q10

#### ICH Q10 — Pharmaceutical Quality System

ICH Q10 (2008) · International

ICH Q10 — Pharmaceutical Quality System is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q10.html.

### 3

Enforced

### 1

Designed

### 1

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Management responsibility & named-authority | Enforced | L3 Enforceable | ich-q10.management-responsibility-authority | Authority GateDecision replayEvidence Pack™ |
| Change-management authority at the action boundary | Enforced | L3 Enforceable | ich-q10.change-management-authority | Authority GateDecision replayEvidence Pack™ |
| Management review control (sign-off gate) | Enforced | L3 Enforceable | ich-q10.management-review-control | Authority GateDecision replayEvidence Pack™ |
| Personnel competence recorded before the action | Designed | L2 Designed | ich-q10.personnel-competence | Purpose Permission™Authority Gate |
| Quality-system substance (CAPA / change science)The scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. | Out of scope | L1 Mapped | ich-q10.quality-system-substance | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ICH Q2

#### ICH Q2(R2) — Validation of Analytical Procedures

ICH Q2(R2) (2023) · International

ICH Q2(R2) — Validation of Analytical Procedures is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q2.html.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Validation-package authority at the action boundary | Enforced | L3 Enforceable | ich-q2.validation-package-authority | Authority GateDecision replayEvidence Pack™ |
| Validation-conclusion justification recorded before the action | Enforced | L3 Enforceable | ich-q2.validation-conclusion-justification | Authority GateDecision replayEvidence Pack™ |
| Replay-provable validation-package provenance | Enforced | L3 Enforceable | ich-q2.validation-package-provenance | Authority GateDecision replayEvidence Pack™ |
| Analytical-method science & validation statisticsThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. | Out of scope | L1 Mapped | ich-q2.analytical-method-science | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ICH Q3

#### ICH Q3 — Impurities

ICH Q3 family · International

ICH Q3 — Impurities is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q3.html.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Authority over an AI impurity-assessment summary at the action boundary | Designed | L2 Designed | ich-q3.named-authority | Purpose Permission™Authority Gate |
| Impurity science & threshold determinationThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. | Out of scope | L1 Mapped | ich-q3.science | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ICH Q5

#### ICH Q5 — Quality of Biotechnological Products

ICH Q5 family · International

ICH Q5 — Quality of Biotechnological Products is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q5.html.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Authority over an AI biotech-quality summary at the action boundary | Designed | L2 Designed | ich-q5.named-authority | Purpose Permission™Authority Gate |
| Biotech product science (viral safety / comparability / stability)The scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. | Out of scope | L1 Mapped | ich-q5.science | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ICH Q6

#### ICH Q6 — Specifications

ICH Q6 family · International

ICH Q6 — Specifications is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q6.html.

### 0

Enforced

### 1

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Authority over an AI specification-justification summary at the action boundary | Designed | L2 Designed | ich-q6.named-authority | Purpose Permission™Authority Gate |
| Specification science & acceptance-criteria settingThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. | Out of scope | L1 Mapped | ich-q6.science | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ICH Q7

#### ICH Q7 — GMP for Active Pharmaceutical Ingredients

ICH Q7 (2000) · International

ICH Q7 — GMP for Active Pharmaceutical Ingredients is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q7.html.

### 4

Enforced

### 0

Designed

### 1

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Quality-Unit release authority at the action boundary | Enforced | L3 Enforceable | ich-q7.quality-unit-batch-release | Authority GateDecision replayEvidence Pack™ |
| Records & data integrity (ALCOA+) screened before the action | Enforced | L3 Enforceable | ich-q7.data-integrity-alcoa | Authority GateDecision replayEvidence Pack™ |
| Replay-provable GMP-record provenance | Enforced | L3 Enforceable | ich-q7.gmp-record-provenance | Authority GateDecision replayEvidence Pack™ |
| Batch release sign-off gate (§36 two-person) | Enforced | L3 Enforceable | ich-q7.batch-release-signoff | Authority GateDecision replayEvidence Pack™ |
| Physical API manufacture & analytical testingThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. | Out of scope | L1 Mapped | ich-q7.physical-api-manufacture | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ICH Q8

#### ICH Q8(R2) — Pharmaceutical Development

ICH Q8(R2) (2009) · International

ICH Q8(R2) — Pharmaceutical Development is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q8.html.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Development-content authority at the action boundary | Enforced | L3 Enforceable | ich-q8.development-justification-provenance | Authority GateDecision replayEvidence Pack™ |
| Development justification recorded before the action | Enforced | L3 Enforceable | ich-q8.justification-recorded-before-action | Authority GateDecision replayEvidence Pack™ |
| Replay-provable development-content provenance | Enforced | L3 Enforceable | ich-q8.development-content-provenance | Authority GateDecision replayEvidence Pack™ |
| Development science (QbD / design space / control strategy)The scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. | Out of scope | L1 Mapped | ich-q8.development-science | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ICH Q9

#### ICH Q9(R1) — Quality Risk Management

ICH Q9(R1) (2023) · International

ICH Q9(R1) — Quality Risk Management is an ICH Q-series quality guideline. KYE Protocol™ governs whether an AI-generated submission-evidence artefact under it may proceed to a consequential action (Quality-Unit approval, reliance in a dossier, lot release, Health-Authority submission) — under a named authority, with due diligence recorded before the action and replay-provable provenance. The scientific / quality content stays the firm's own quality system (honest scope, §0). Per-requirement bijection at /compliance/ich-q9.html.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Risk-based decision authority at the action boundary | Enforced | L3 Enforceable | ich-q9.qrm-decision-authority | Authority GateDecision replayEvidence Pack™ |
| Risk-decision justification recorded before the action | Enforced | L3 Enforceable | ich-q9.risk-decision-justification | Authority GateDecision replayEvidence Pack™ |
| Replay-provable QRM provenance | Enforced | L3 Enforceable | ich-q9.qrm-provenance | Authority GateDecision replayEvidence Pack™ |
| Risk-assessment science & control-strategy selectionThe scientific / quality substance is the firm's own quality system — KYE™ is an AI-authority and evidence layer, not a science engine. | Out of scope | L1 Mapped | ich-q9.risk-assessment-science | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

IEC 61508

#### IEC 61508:2010 — Functional safety of E/E/PE safety-related systems

2010 · Global

The umbrella functional-safety standard defining Safety Integrity Levels (SIL 1-4) and the safety lifecycle. KYE Protocol™ governs the authority, evidence and finality of an AI-recommended physical-safety action against a SIL-validated model-authority claim; KYE Protocol™ does not perform the SIL determination. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| SIL-validated model authority + safety floor | Designed | L2 Designed | iec-61508.part-1.7.6 | Purpose Permission™Edge Governance Safety Floor |
| Functional-safety decision evidence + named accountability | Designed | L2 Designed | iec-61508.part-1.7.14 | Evidence Pack™Reporting Engine |
| Contestable verification outcomes | Designed | L2 Designed | iec-61508.part-3.7.9 | Evidence Pack™Authority Gate |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

IEC 61511

#### IEC 61511:2016 — Safety instrumented systems for the process industry

2016 · Global

The process-sector application of IEC 61508 defining safety instrumented systems (SIS). KYE Protocol™ governs the authority and finality of an AI-recommended physical-safety action (turbine trip, unit shutdown, derate) under the safety floor. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| SIS actuating decision under safety floor | Designed | L2 Designed | iec-61511.clause-11.3 | Purpose Permission™Edge Governance Safety Floor |
| Operation & maintenance named accountability | Designed | L2 Designed | iec-61511.clause-16.2 | Authority GateDecision Map™ |
| Contestable / reviewable SIS decisions | Designed | L2 Designed | iec-61511.clause-11.9 | Evidence Pack™Authority Gate |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ISO 21448

#### ISO 21448:2022 — Safety Of The Intended Functionality (SOTIF)

2022 · Global

The companion to ISO 26262 governing the residual risk of a fault-free intended function (e.g. an ADAS / autonomous perception or decision function) operating at the edge of, or outside, its specified operating envelope. KYE Protocol™ governs the authority, the operating-envelope (control / safety-floor) admissibility, the evidence and the finality of an AI-recommended action against a declared intended-functionality envelope, with Replay-Proof™ failure-path reconstruction; KYE Protocol™ does not perform the SOTIF hazard analysis, triggering-condition identification, or the model's internal failure-mechanism analysis. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Operating-envelope (control / safety-floor) action admissibility | Designed | L2 Designed | iso-21448.clause-6 | Purpose Permission™Edge Governance Safety Floor |
| Replay-derivable intended-functionality decision evidence | Designed | L2 Designed | iso-21448.clause-10 | Evidence Pack™Reporting Engine |
| Named accountability + contestable outcomes | Designed | L2 Designed | iso-21448.clause-11 | Authority GateEvidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Law Society Protocol

#### Law Society Conveyancing Protocol

Conveyancing Protocol · United Kingdom

The Law Society of England & Wales — Conveyancing Protocol. KYE Protocol™ governs the AUTHORITY of an AI agent to take or finalise a protocol step, the client-due-diligence / source-of-funds EVIDENCE boundary (binding the deep-mapped uk-mlr-2017 store, not re-mapping it), and the replay-derivable transaction file; KYE Protocol™ does not perform the searches, draft the enquiries, or determine the legal correctness of the conveyance. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Protocol-step authority / finality on AI-assisted steps | Designed | L2 Designed | law-society-conveyancing-protocol.step-authority | Purpose Permission™Authority Gate |
| Client due diligence + source-of-funds evidence | Designed | L2 Designed | law-society-conveyancing-protocol.cdd-source-of-funds | Evidence Pack™ |
| Replay-derivable transaction file | Designed | L2 Designed | law-society-conveyancing-protocol.replay-file | Evidence Pack™Replay-Proof™ |
| Legal correctness of searches / enquiries | Out of scope | L1 Mapped | law-society-conveyancing-protocol.searches-enquiries-correctness | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

CLC Code

#### CLC Code of Conduct — Council for Licensed Conveyancers

Code of Conduct · United Kingdom

Council for Licensed Conveyancers (CLC) — Code of Conduct. KYE Protocol™ governs the AUTHORITY of an AI agent to act in the client's interest, named-accountable conveyancer sign-off, the confidentiality / isolation boundary, and the EVIDENCE boundary around client-money handling; KYE Protocol™ does not reconcile the client account, hold money, or determine CLC compliance. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 4

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Act-in-client-best-interest authority | Designed | L2 Designed | clc-code-of-conduct.client-best-interest | Purpose Permission™Authority Gate |
| Named accountable conveyancer sign-off | Designed | L2 Designed | clc-code-of-conduct.named-conveyancer-signoff | Delegated Auditability |
| Confidentiality and isolation of client matters | Designed | L2 Designed | clc-code-of-conduct.confidentiality | Authority Gate |
| Client-money handling evidence boundary | Designed | L2 Designed | clc-code-of-conduct.client-money | Evidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

HM Land Registry

#### HM Land Registry — Registration & Digital Identity Standard (Safe Harbour)

Registration & Digital Identity Standard · United Kingdom

HM Land Registry — registration requirements and the Digital Identity Standard (Safe Harbour). KYE Protocol™ governs the AUTHORITY of an AI agent to take a digital-identity-verification or application-submission action and the Safe Harbour EVIDENCE / replay boundary; KYE Protocol™ does not perform the identity-check determination, run the verification technology, or determine HMLR registration correctness. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Digital-identity verification action admissibility (Safe Harbour) | Designed | L2 Designed | hm-land-registry.digital-identity-admissibility | Purpose Permission™Evidence Pack™ |
| Application-submission authority | Designed | L2 Designed | hm-land-registry.application-submission-authority | Authority Gate |
| Replay-derivable submission record | Designed | L2 Designed | hm-land-registry.replay-submission-record | Evidence Pack™Replay-Proof™ |
| The conveyancer's identity-check determination | Out of scope | L1 Mapped | hm-land-registry.identity-check-determination | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Homes England CFG

#### Homes England Capital Funding Guide — Shared Ownership (model lease)

Capital Funding Guide — Shared Ownership · United Kingdom

Homes England — Capital Funding Guide (Shared Ownership + model lease). KYE Protocol™ governs the AUTHORITY of an AI agent to take a shared-ownership eligibility-decision action, the affordability / sustainability EVIDENCE boundary, and named-accountable sign-off / contestability; KYE Protocol™ does not make the eligibility determination, run the affordability assessment, or judge model-lease compliance. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Shared-ownership eligibility-decision authority | Designed | L2 Designed | homes-england-cfg.eligibility-authority | Purpose Permission™Authority Gate |
| Affordability / sustainability evidence | Designed | L2 Designed | homes-england-cfg.affordability-sustainability-evidence | Evidence Pack™ |
| Named-accountable sign-off and contestability | Designed | L2 Designed | homes-england-cfg.named-signoff-contestable | Delegated Auditability |
| Model-lease compliance determination | Out of scope | L1 Mapped | homes-england-cfg.model-lease-compliance | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ISO 14001

#### ISO 14001 — Environmental Management Systems

2015 · Global

ISO 14001:2015 environmental management system. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved environmental HSE instructions that discharge an EMS control — the KYE™ HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Environmental operational control under safety floor | Designed | L2 Designed | iso-14001.8.1 | Purpose Permission™Edge Governance Safety Floor |
| Environmental emergency instruction scope-bound | Designed | L2 Designed | iso-14001.8.2 | Purpose Permission™Authority Gate |
| Compliance evaluation contestable + evidenced | Designed | L2 Designed | iso-14001.9.1.2 | Evidence Pack™Authority Gate |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ISO 15489

#### ISO 15489-1:2016 — Records Management (records-management spine)

2016 · Global

ISO 15489-1:2016 records-management spine for the KYE™ Chain of Authority™ for Iron Mountain InSight DXP. Iron Mountain governs INFORMATION (records, custody, retention, classification); KYE Protocol™ governs ACTION — who was authorised to act on a record at the moment it drives a consequential AI action, evidenced, final, revocable. The authentic/reliable-records-at-the-action-boundary requirements are KYE Protocol™'s job (enforced); records storage / capture / retention / disposition are records-management's job (out-of-scope, owned by the records-manager / information-custodian).

### 2

Enforced

### 0

Designed

### 3

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Records authenticity & reliability (authority overlay) | Enforced | L3 Enforceable | iso-15489.authenticity-authority-binding, iso-15489.reliability-evidence-pin | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Records access & permissions (authority overlay) | Enforced | L3 Enforceable | iso-15489.access-permission-overlay | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Records creation, capture & metadata (records-management) | Out of scope | L1 Mapped | iso-15489.records-capture-metadata | — |
| Retention schedule & disposition authority (records-management) | Out of scope | L1 Mapped | iso-15489.retention-disposition-authority | — |
| Records storage & preservation (records-management) | Out of scope | L1 Mapped | iso-15489.storage-preservation | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ISO 16175

#### ISO 16175-1:2020 — Software for Managing Records (digital records spine)

2020 · Global

ISO 16175-1:2020 digital-records-software spine for the KYE™ Chain of Authority™ for Iron Mountain InSight DXP. KYE Protocol™ overlays the action-boundary access-control decision + the governance-decision audit trail (enforced); the records-software capture / classification / retention functions are out-of-scope (owned by Iron Mountain InSight DXP). §0: Iron Mountain proves where information travelled; KYE Protocol™ proves who was authorised to act on it.

### 2

Enforced

### 0

Designed

### 2

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Action-decision audit trail (authority overlay) | Enforced | L3 Enforceable | iso-16175.action-audit-trail, iso-16175.replayable-decision-record | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Access-control decision at the action boundary (authority overlay) | Enforced | L3 Enforceable | iso-16175.access-control-decision | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Capture & classification functional requirements (records-software) | Out of scope | L1 Mapped | iso-16175.capture-classification-functional | — |
| Retention & disposition functional requirements (records-software) | Out of scope | L1 Mapped | iso-16175.retention-disposition-functional | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ISO 17025

#### ISO/IEC 17025:2017 — Competence of testing and calibration laboratories

2017 · International

ISO/IEC 17025:2017 sets the general requirements for the competence, impartiality and consistent operation of testing and calibration laboratories. KYE Protocol™ enforces the §7.11 data-management integrity, §7.5/§7.8 technical-record reproducibility and audit-trail slices where a laboratory uses AI-supported decisioning — metrology, equipment and competence stay the laboratory's technical system. Per-requirement bijection at /compliance/iso-17025.html.

### 3

Enforced

### 1

Designed

### 1

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Control of data & information management (7.11) | Enforced | L3 Enforceable | iso-17025.7.11-data-management | WORM audit hash-chain |
| Technical records & integrity of results (7.5, 7.8) | Enforced | L3 Enforceable | iso-17025.7.5-technical-records | Decision replayEvidence Pack™ |
| Control of management-system records & audit trail (8.4) | Designed | L2 Designed | iso-17025.8.4-management-records | WORM audit hash-chain |
| Impartiality & authority over automated decisions (4.1, 6.2) | Enforced | L3 Enforceable | iso-17025.4.1-impartiality-authority | Purpose Permission™Authority Gate |
| Metrological traceability, measurement uncertainty, equipment & competenceMetrological traceability, measurement uncertainty, equipment calibration and technical competence are the laboratory's own technical/metrology system — out of scope for an AI-authority-governance protocol. | Out of scope | L1 Mapped | iso-17025.6.5-traceability, iso-17025.6.3-equipment-competence | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ISO/IEC 27035

#### ISO/IEC 27035 — Incident Management

ISO/IEC 27035 — Information security incident management · International

ISO/IEC 27035 is the international standard for information-security incident management, including careful incident-evidence handling. KYE Protocol™ governs whether an AI-assisted incident decision under it may proceed to a consequential action — under a named accountable officer's authority, with incident-evidence chain-of-custody recorded, the assessment pinned to verifiable signal sources, a signed replay-provable Evidence Pack™ per decision, and a contestability record for the lessons-learned reconstruction. Detection / response tooling / forensic analysis stays the organisation's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/iso-27035.html.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Incident-evidence chain-of-custody (evidence handling) | Enforced | L3 Enforceable | iso-27035.evidence-chain-of-custody | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Named-authority on the assessment-and-decision response | Enforced | L3 Enforceable | iso-27035.assessment-decision-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & lessons-learned reconstruction | Enforced | L3 Enforceable | iso-27035.lessons-learned-reconstruction | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Detection, response tooling & forensic analysisThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. | Out of scope | L1 Mapped | iso-27035.detection-response-forensics | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ISO 45001

#### ISO 45001 — Occupational Health & Safety Management Systems

2018 · Global

ISO 45001:2018 occupational health & safety management system. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved safety-critical HSE documents (permits-to-work, risk assessments, method statements) that discharge an OH&S control — the KYE™ HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 4

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Operational planning & control under safety floor | Designed | L2 Designed | iso-45001.8.1 | Purpose Permission™Edge Governance Safety Floor |
| Hierarchy-of-controls selection advisory pending sign-off | Designed | L2 Designed | iso-45001.8.1.2 | Authority GateDecision Map™ |
| Emergency-preparedness instruction scope-bound | Designed | L2 Designed | iso-45001.8.2 | Purpose Permission™Authority Gate |
| Incident / corrective action contestable + evidenced | Designed | L2 Designed | iso-45001.10.2 | Evidence Pack™Authority Gate |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ISO 55000

#### ISO 55000 / ISO 55001:2014 — Asset management management systems

2014 · Global

ISO 55000/55001 asset-management system requirements. KYE Protocol™ governs the authority, evidence and finality of AI-recommended asset-management actions and the scope of the AI's authority over the asset portfolio. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Asset-management objectives + scoped decision authority | Designed | L2 Designed | iso-55001.6.2.1 | Authority GateDecision Map™ |
| Planned actions — finality + named accountability | Designed | L2 Designed | iso-55001.6.2.2 | Purpose Permission™Edge Governance Safety Floor |
| Contestable performance review | Designed | L2 Designed | iso-55001.9.1 | Evidence Pack™Authority Gate |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Mastercard Disputes

#### Mastercard Chargeback Standards — Dispute Resolution & Arbitration

Mastercard Chargeback Standards — Dispute Resolution & Arbitration (Chargeback Guide) · Global

The Mastercard Chargeback Standards govern the dispute lifecycle — first chargeback, second presentment with supporting documentation, pre-arbitration, and arbitration on the documented record. KYE Protocol™ governs whether the second presentment / case filing may proceed — under a named owner's recorded authority, with the supporting evidence captured as evidence events at transaction time, and the bundle sealed as a signed, hash-bound, WORM-retained, replay-verifiable Evidence Pack™ so the documented record survives arbitration scrutiny. Whether to fight, the narrative, and the outcome stay the merchant's / network's own (honest scope, §0). Per-requirement bijection at /compliance/mastercard-dispute-rules.html.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Second-presentment evidence captured at transaction time | Enforced | L3 Enforceable | mastercard-dispute-rules.second-presentment-evidence-capture | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Named-authority on the chargeback response | Enforced | L3 Enforceable | mastercard-dispute-rules.chargeback-response-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Arbitration-grade reconstruction of the dispute record | Enforced | L3 Enforceable | mastercard-dispute-rules.arbitration-reconstruction-record | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Dispute merits adjudication & strategyWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. | Out of scope | L1 Mapped | mastercard-dispute-rules.dispute-merits-adjudication | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

MoReq2010

#### MoReq2010 — Modular Requirements for Records Systems (records-system spine)

2011 · European Union

MoReq2010 records-system spine for the KYE™ Chain of Authority™ for Iron Mountain InSight DXP. KYE Protocol™ overlays the action-boundary access-control service + entity-event governance-decision audit + custody→authority binding (enforced); the records-system classification / search / retention / disposition core services are out-of-scope (owned by Iron Mountain InSight DXP).

### 2

Enforced

### 0

Designed

### 2

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Access-control service at the action boundary (authority overlay) | Enforced | L3 Enforceable | moreq-2010.access-control-service-overlay, moreq-2010.custody-to-authority-binding | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Entity-event audit of the action decision (authority overlay) | Enforced | L3 Enforceable | moreq-2010.entity-event-action-audit | Action Admissibility™ GateAuthority Finality™Evidence Pack™Replay-Proof™ |
| Classification & search core service (records-system) | Out of scope | L1 Mapped | moreq-2010.classification-search-service | — |
| Retention & disposition core service (records-system) | Out of scope | L1 Mapped | moreq-2010.retention-disposition-service | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

MSHA

#### MSHA — Mine Safety and Health Administration standards (30 CFR)

2024 · United States

US MSHA standards under 30 CFR governing surface and underground mine safety. KYE Protocol™ governs the authority, evidence and finality of AI-recommended physical-safety actions on mine equipment (e.g. mine-hoist stop). Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Mine-equipment actuation under safety floor | Designed | L2 Designed | msha.30-cfr-56.18002 | Purpose Permission™Edge Governance Safety Floor |
| Hoisting stop named accountability | Designed | L2 Designed | msha.30-cfr-57.19021 | Authority GateDecision Map™ |
| Contestable equipment-safety decisions | Designed | L2 Designed | msha.30-cfr-75.1725 | Evidence Pack™Authority Gate |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

NAIC AI Bulletin

#### NAIC Model Bulletin on the Use of AI by Insurers

NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (adopted December 2023) · United States

The NAIC Model Bulletin on the Use of AI by Insurers is the US insurer-AI governance expectation (written AIS Program, named accountability, documentation, unfair-discrimination testing). KYE Protocol™ governs whether an AI-assisted underwriting or claims decision under it may proceed to a consequential adverse action — under a named underwriter's / adjuster's authority, with a recorded adverse-action reason-code, with proxy-discrimination / fairness-evidence captured, a signed replay-provable Evidence Pack™ per decision, and an appeal / contestability record so any decision can be reconstructed and contested. The actuarial pricing / risk-appetite / model design on the merits stays the insurer's own work (honest scope, §0). Per-requirement bijection at /compliance/naic-model-bulletin-ai.html.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Named accountability & governance of the AI decision | Enforced | L3 Enforceable | naic-model-bulletin-ai.governance-named-accountability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Adverse-action explainability & documentation | Enforced | L3 Enforceable | naic-model-bulletin-ai.adverse-action-documentation | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Unfair-discrimination testing evidence | Enforced | L3 Enforceable | naic-model-bulletin-ai.unfair-discrimination-testing | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Actuarial pricing, risk appetite & model design on the meritsThe actuarial pricing / risk-appetite / model design on the merits is the insurer's own work — KYE™ is an AI-authority and evidence layer, not a pricing, actuarial, or risk-modelling engine. | Out of scope | L1 Mapped | naic-model-bulletin-ai.actuarial-pricing-model-design | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

NERC CIP

#### NERC CIP — Critical Infrastructure Protection (bulk electric system)

2024 · United States

NERC CIP reliability standards governing cyber security of the North American bulk electric system. KYE Protocol™ governs the authority, evidence and finality of an AI-recommended physical-safety action on grid assets and the scope boundary of the AI's authority. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Controlled actuation of BES assets under safety floor | Designed | L2 Designed | nerc-cip.cip-007-6.r1 | Purpose Permission™Edge Governance Safety Floor |
| Purpose-scoped authority for grid actions | Designed | L2 Designed | nerc-cip.cip-004-6.r4 | Authority GateDecision Map™ |
| Contestable + evidenced incident decisions | Designed | L2 Designed | nerc-cip.cip-008-6.r1 | Evidence Pack™Authority Gate |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

NIS2 Incident

#### NIS2 Incident Reporting — Article 23 (24h / 72h)

NIS2 — Directive (EU) 2022/2555, Article 23 · European Union

NIS2 Incident Reporting (Directive (EU) 2022/2555, Article 23) is the EU 24-hour / 72-hour staged-notification regime for significant incidents. KYE Protocol™ governs whether an AI-assisted disclosure-timing decision or containment action under it may proceed to a consequential incident action — under a named accountable officer's authority, with chain-of-custody recorded, and a contestability record so the timing decision can be reconstructed and challenged. Incident detection / impact analysis stays the entity's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/nis2-incident.html.

### 2

Enforced

### 0

Designed

### 1

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Disclosure-timing authority on the 24h / 72h notification clock | Enforced | L3 Enforceable | nis2-incident.notification-clock-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Incident-evidence chain-of-custody for the notification | Enforced | L3 Enforceable | nis2-incident.notification-evidence-custody | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Incident detection & impact analysisThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. | Out of scope | L1 Mapped | nis2-incident.detection-impact-analysis | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

NIST CSF 2.0 RS/RC

#### NIST CSF 2.0 — RESPOND & RECOVER

NIST Cybersecurity Framework 2.0 (2024) — RESPOND (RS) + RECOVER (RC) · United States

NIST CSF 2.0 RESPOND & RECOVER is the incident-management, analysis, and recovery half of the NIST Cybersecurity Framework 2.0. KYE Protocol™ governs whether an AI-assisted response / recovery action under it may proceed to a consequential incident action — under a named accountable officer's authority, with the incident analysis pinned to verifiable signal sources, chain-of-custody recorded, a signed replay-provable Evidence Pack™ per decision, and a contestability record. Threat detection (DETECT) / response tooling / recovery execution stays the organisation's own security operations (honest scope, §0/§70). Per-requirement bijection at /compliance/nist-csf-2-respond-recover.html.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Named-authority on the RESPOND/RECOVER action (RS.MA / RC.RP) | Enforced | L3 Enforceable | nist-csf-2-respond-recover.rs-action-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Incident-analysis source pin (RS.AN) | Enforced | L3 Enforceable | nist-csf-2-respond-recover.rs-incident-evidence | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & post-incident reconstruction (RS.MA / improvement) | Enforced | L3 Enforceable | nist-csf-2-respond-recover.rs-contestability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Threat detection (DETECT) & recovery execution toolingThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. | Out of scope | L1 Mapped | nist-csf-2-respond-recover.detection-recovery-tooling | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Synthesis Screening

#### Nucleic-Acid Synthesis Screening — IBBIS Common Mechanism + IGSC Harmonized Screening Protocol

2023 · Global

Nucleic-acid synthesis screening regime — the IBBIS Common Mechanism and IGSC Harmonized Screening Protocol screen synthesis orders for sequences of concern before synthesis. KYE Protocol™ governs whether an AI-generated nucleic-acid sequence may proceed to a synthesis order, binding the screening result — the KYE™ AI Bio-Chem Governance Pack™. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Sequence-of-concern screening | Designed | L2 Designed | nucleic-acid-synthesis-screening.soc-screen, nucleic-acid-synthesis-screening.flagged-hold | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Customer / legitimacy screening | Designed | L2 Designed | nucleic-acid-synthesis-screening.customer-screen | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |
| Screening provenance & record-keeping | Designed | L2 Designed | nucleic-acid-synthesis-screening.screening-provenance | Action Admissibility™ GateEdge Governance Safety FloorEvidence Pack™ |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

NYDFS AI Circular

#### NYDFS Insurance Circular Letter on AI

NYDFS Insurance Circular Letter No. 7 (2024) — Use of AI Systems and External Consumer Data in Underwriting and Pricing · United States

NYDFS Insurance Circular Letter No. 7 (2024) sets expectations for insurers using AI and external consumer data in underwriting and pricing — senior-management accountability, unfair-discrimination testing, consumer transparency, documentation. KYE Protocol™ governs whether an AI-assisted insurance decision in scope may proceed to a consequential adverse action — under a named accountable authority, with a recorded adverse-action reason-code, proxy-discrimination / fairness-evidence captured, a signed replay-provable Evidence Pack™ per decision, and a consumer appeal / contestability record. The ECDIS selection / pricing / methodology design on the merits stays the insurer's own work (honest scope, §0). Per-requirement bijection at /compliance/nydfs-insurance-circular-ai.html.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Senior-management accountability for the AI decision | Enforced | L3 Enforceable | nydfs-insurance-circular-ai.senior-management-accountability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Unfair-discrimination testing evidence | Enforced | L3 Enforceable | nydfs-insurance-circular-ai.unfair-discrimination-testing | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Consumer transparency & appeal record | Enforced | L3 Enforceable | nydfs-insurance-circular-ai.consumer-transparency-appeal | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| ECDIS selection, pricing & methodology design on the meritsThe ECDIS selection / pricing / testing-methodology design on the merits is the insurer's own work — KYE™ is an AI-authority and evidence layer, not a data-selection, pricing, or testing-methodology engine. | Out of scope | L1 Mapped | nydfs-insurance-circular-ai.ecdis-selection-pricing-methodology | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

OECD GLP

#### OECD Good Laboratory Practice (Principles) + FDA 21 CFR Part 58

1998 + 21 CFR 58 · International / US

OECD Principles of Good Laboratory Practice and FDA 21 CFR Part 58 govern the integrity, traceability, audit-trail and archiving of non-clinical safety-study data. KYE Protocol™ enforces the ALCOA+ data-integrity, audit-trail and replay slices where an AI/automated step captures or transforms study data — physical study conduct stays the laboratory's GLP system. Per-requirement bijection at /compliance/oecd-glp.html.

### 3

Enforced

### 1

Designed

### 1

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Study data integrity & raw-data traceability (ALCOA+) | Enforced | L3 Enforceable | oecd-glp.data-integrity, oecd-glp.raw-data-traceability | WORM audit hash-chainDecision replayEvidence Pack™ |
| Audit trail & change control for electronic records (Part 11 overlap) | Enforced | L3 Enforceable | oecd-glp.audit-trail | WORM audit hash-chain |
| Archive & retention of study records | Designed | L2 Designed | oecd-glp.archive-retention | WORM audit hash-chain |
| QA & study-director oversight of automated steps | Enforced | L3 Enforceable | oecd-glp.oversight-of-automated-steps | Purpose Permission™Authority Gate |
| Physical study conduct & facilitiesApparatus calibration, test/reference-item handling and physical SOP execution are the laboratory's own GLP quality system — KYE™ is an AI-authority and evidence layer, not a lab-operations system. | Out of scope | L1 Mapped | oecd-glp.physical-study-conduct | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

OSHA PSM

#### OSHA PSM — Process Safety Management (29 CFR 1910.119)

1992 · United States

US OSHA Process Safety Management standard for facilities handling highly hazardous chemicals. KYE Protocol™ governs the authority, evidence and finality of AI-recommended physical-safety actions in a PSM-covered process. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Mechanical-integrity actuation under safety floor | Designed | L2 Designed | osha-psm.1910.119.j | Purpose Permission™Edge Governance Safety Floor |
| Operating-procedure named accountability | Designed | L2 Designed | osha-psm.1910.119.f | Authority GateDecision Map™ |
| Management-of-change contestable + evidenced | Designed | L2 Designed | osha-psm.1910.119.l | Evidence Pack™Authority Gate |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Permit to Work

#### Permit-to-Work Systems (HSE HSG250 guidance)

HSG250 · United Kingdom

Permit-to-work systems per UK HSE HSG250. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved permits-to-work — the KYE™ HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Permit advisory pending competent-authoriser sign-off | Designed | L2 Designed | permit-to-work.authorisation | Authority GateDecision Map™ |
| Permit scope & isolation bounded to authorised work | Designed | L2 Designed | permit-to-work.scope-isolation | Purpose Permission™Authority Gate |
| Hand-back & audit contestable + evidenced | Designed | L2 Designed | permit-to-work.handback-audit | Evidence Pack™Authority Gate |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

PRA SS1/23

#### PRA SS1/23 — Model Risk Management Principles for Banks

PRA SS1/23 (Model risk management principles for banks, May 2023; effective May 2024) · United Kingdom

PRA SS1/23 sets the UK model risk management principles for banks (Principles 1–5, explicitly including AI/ML models). KYE Protocol™ governs whether a model-driven output or risk report under it may proceed to a consequential action — only a currently-validated model used within its approved scope, model changes as named-authority decisions with evidence, every consequential decision pinned to model\_id + version + validation reference, and every risk report bound to its data-lineage evidence chain, sealed into a signed replay-provable Evidence Pack™. The quantitative model build / validation mathematics / capital computation / portfolio composition stays the bank's own work (honest scope, §0 — not investment advice). Per-requirement bijection at /compliance/pra-ss1-23.html.

### 5

Enforced

### 0

Designed

### 1

Out of scope

6 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Model identification & inventory resolution (Principle 1) | Enforced | L3 Enforceable | pra-ss1-23.principle1-model-inventory-resolution | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Governance & named SMF accountability (Principle 2) | Enforced | L3 Enforceable | pra-ss1-23.principle2-governance-named-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Model development, implementation & use incl. AI/ML (Principle 3) | Enforced | L3 Enforceable | pra-ss1-23.principle3-development-implementation-use | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Validation-status binding at the moment of use (Principle 4) | Enforced | L3 Enforceable | pra-ss1-23.principle4-validation-status-binding | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Model risk mitigants & restrictions on use (Principle 5) | Enforced | L3 Enforceable | pra-ss1-23.principle5-mitigants-restrictions | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Independent validation judgment & quantitative work on the meritsThe quantitative model build, validation mathematics, and capital & liquidity computation are the bank's own quantitative work — KYE™ is an AI-authority and evidence layer, not a model-validation or capital-calculation engine. | Out of scope | L1 Mapped | pra-ss1-23.independent-validation-judgment | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

PSD2 SCA Disputes

#### PSD2 SCA & Unauthorised-Transaction Liability (Arts. 72-74, 97)

PSD2 — Directive (EU) 2015/2366, Arts. 72-74 + 97 (SCA & unauthorised-transaction liability) · European Union

PSD2 Arts. 72-74 + 97 govern SCA and unauthorised-transaction liability in the EU — the PSP carries the burden of proof that the transaction was authenticated and accurately recorded. KYE Protocol™ governs whether an unauthorised-transaction refund / liability allocation may proceed — under a named owner's recorded authority, with the SCA / authentication evidence captured as evidence events at transaction time, and the liability-allocation bundle sealed as a signed, hash-bound, replay-provable Evidence Pack™ that meets the Article 72 burden of proof. The substantive fraud / authorisation determination stays the PSP's / merchant's own (honest scope, §0). Per-requirement bijection at /compliance/psd2-sca-disputes.html.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| SCA / authentication evidence captured at transaction time | Enforced | L3 Enforceable | psd2-sca-disputes.sca-evidence-capture | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Named-authority on the unauthorised-transaction refund | Enforced | L3 Enforceable | psd2-sca-disputes.unauthorised-transaction-refund-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Burden-of-proof evidence integrity for liability allocation | Enforced | L3 Enforceable | psd2-sca-disputes.liability-allocation-evidence | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive fraud / authorisation determination on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. | Out of scope | L1 Mapped | psd2-sca-disputes.fraud-determination | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Reg E

#### Reg E — EFTA Error Resolution (12 CFR 1005.11)

EFTA / Regulation E — 12 CFR Part 1005 (error resolution, §1005.11) · United States

Reg E (12 CFR 1005.11) is the US error-resolution framework for electronic fund transfers. KYE Protocol™ governs whether a provisional credit, refund, or error determination in the dispute flow may proceed — under a named owner's recorded authority, with the transaction evidence captured as evidence events at transaction time, a signed replay-provable Evidence Pack™, and a recorded contestable determination. The substantive error adjudication stays the institution's / merchant's own (honest scope, §0). Per-requirement bijection at /compliance/reg-e.html.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Named-authority on the provisional credit / refund action | Enforced | L3 Enforceable | reg-e.provisional-credit-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Investigation evidence record captured at transaction time | Enforced | L3 Enforceable | reg-e.investigation-evidence-record | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & written-determination reconstruction | Enforced | L3 Enforceable | reg-e.error-determination-contestability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive error adjudication on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. | Out of scope | L1 Mapped | reg-e.substantive-error-adjudication | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Reg Z

#### Reg Z — TILA Billing-Error Resolution (12 CFR 1026.13)

TILA / Regulation Z — 12 CFR Part 1026 (billing-error resolution, §1026.13) · United States

Reg Z (12 CFR 1026.13) is the US billing-error-resolution framework for credit accounts. KYE Protocol™ governs whether an account correction, credit, or billing-error determination in the dispute flow may proceed — under a named owner's recorded authority, with the transaction evidence captured as evidence events at transaction time, a signed replay-provable Evidence Pack™, and a recorded contestable determination. The substantive billing-error adjudication stays the creditor's / merchant's own (honest scope, §0). Per-requirement bijection at /compliance/reg-z.html.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Named-authority on the account correction / credit action | Enforced | L3 Enforceable | reg-z.billing-error-resolution-record | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Billing-dispute evidence record captured at transaction time | Enforced | L3 Enforceable | reg-z.billing-dispute-evidence-record | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & written-explanation reconstruction | Enforced | L3 Enforceable | reg-z.billing-dispute-contestability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive billing-error adjudication on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. | Out of scope | L1 Mapped | reg-z.substantive-billing-error-adjudication | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

RIDDOR

#### RIDDOR — Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013 (UK)

2013 · United Kingdom

UK RIDDOR 2013 (SI 2013/1471), HSE-enforced. KYE Protocol™ governs the authority, evidence and finality of AI-authored or AI-approved RIDDOR-reportable incident reports — the KYE™ HSE Authority Pack™. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Incident report authored under safety floor | Designed | L2 Designed | riddor.reg-4-6 | Purpose Permission™Edge Governance Safety Floor |
| Reportability determination advisory pending sign-off | Designed | L2 Designed | riddor.reporting-decision | Authority GateDecision Map™ |
| Incident records contestable + evidenced | Designed | L2 Designed | riddor.reg-12 | Evidence Pack™Authority Gate |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

SEC Cyber Disclosure

#### SEC Cyber Disclosure — Item 1.05 (4 business days)

SEC Cybersecurity Disclosure Rules (2023) — Item 1.05 + Item 106 · United States

SEC Cyber Disclosure (Item 1.05) is the US four-business-day material-cybersecurity-incident disclosure regime on Form 8-K. KYE Protocol™ governs whether an AI-assisted disclosure-timing decision under it may proceed to a consequential disclosure action — under a named accountable officer's authority, with incident-evidence chain-of-custody recorded, and a contestability record so the timing decision can be reconstructed and challenged. The substantive materiality determination / 8-K drafting / legal judgment stays the registrant's own work (honest scope, §0/§70). Per-requirement bijection at /compliance/sec-cyber-disclosure.html.

### 2

Enforced

### 0

Designed

### 1

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Disclosure-timing authority on the four-business-day clock | Enforced | L3 Enforceable | sec-cyber-disclosure.item105-materiality-disclosure-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability of the timing decision in an SEC / shareholder review | Enforced | L3 Enforceable | sec-cyber-disclosure.item105-timing-contestability | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive materiality determination & 8-K draftingThreat detection / forensics / remediation engineering is the customer's own security stack — KYE™ is an AI-authority and evidence layer, not a detection, forensics, or remediation engine. | Out of scope | L1 Mapped | sec-cyber-disclosure.substantive-materiality-drafting | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Sedona Principles

#### The Sedona Principles — Best Practices for Electronic Document Production

The Sedona Principles, Third Edition (2018) · United States

The Sedona Principles — Best Practices for Electronic Document Production is the leading US e-discovery best-practice commentary (The Sedona Principles, Third Edition). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/sedona-principles.html.

### 2

Enforced

### 0

Designed

### 1

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Defensible, reconstructable AI-review process record | Enforced | L3 Enforceable | sedona-principles.principle6-defensible-process | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Replay-provable evidence of the process when challenged | Enforced | L3 Enforceable | sedona-principles.replay-provable-process-evidence | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Methodology selection & substantive production completenessThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. | Out of scope | L1 Mapped | sedona-principles.methodology-and-completeness | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

SOX §806

#### SOX §806 — Whistleblower Anti-Retaliation (18 U.S.C. §1514A)

Sarbanes-Oxley Act §806 (18 U.S.C. §1514A) — whistleblower anti-retaliation · United States

SOX §806 — Whistleblower Anti-Retaliation (18 U.S.C. §1514A) is the US public-company anti-retaliation statute (contributing-factor / clear-and-convincing burden). KYE Protocol™ governs whether an AI-assisted adverse HR action that touches a reporter may proceed — only with a recorded retaliation-risk assessment evidence — and binds a contestability record so the employer's burden-of-proof can be reconstructed if a §806 complaint is filed. Whether the action was in fact retaliatory and the §806 adjudication stay with counsel / OSHA / the courts (honest scope, §0). Per-requirement bijection at /compliance/sox-806.html.

### 2

Enforced

### 0

Designed

### 1

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Retaliation-risk assessment evidence before an adverse action | Enforced | L3 Enforceable | sox-806.anti-retaliation-risk-record | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & burden-of-proof reconstruction | Enforced | L3 Enforceable | sox-806.contestability-burden-reconstruction | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Whether the action was in fact retaliatory & §806 adjudicationDeciding whether an action was retaliatory and adjudicating the §806 complaint is a legal determination for counsel and the courts — KYE™ is an AI-authority and evidence layer, not an adjudication engine. | Out of scope | L1 Mapped | sox-806.substantive-retaliation-adjudication | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

CPR PD 57AD

#### UK CPR Part 31 + PD 57AD — Disclosure & the Disclosure Certificate

CPR Part 31 + Practice Direction 57AD (Disclosure in the Business and Property Courts, 2022) · United Kingdom

UK CPR Part 31 + PD 57AD — Disclosure & the Disclosure Certificate is the English civil disclosure framework (CPR Part 31 + Practice Direction 57AD). KYE Protocol™ governs whether an AI-assisted privilege determination, document-production decision, or legal-research assertion under it may proceed to a consequential litigation action — under a named attorney's authority, with chain-of-custody recorded, no AI-asserted fact relied on without a pinned source (no-hallucinated-citation), a signed replay-provable Evidence Pack™ per reviewed item, and a contestability record so any determination can be reconstructed and challenged. The substantive legal judgment / document substance / case strategy stays the firm's own legal work (honest scope, §0). Per-requirement bijection at /compliance/uk-cpr-pd57ad.html.

### 2

Enforced

### 0

Designed

### 1

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Named-authority on the disclosure determination & certificate | Enforced | L3 Enforceable | uk-cpr-pd57ad.disclosure-certificate | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & reconstruction of a disclosure challenge | Enforced | L3 Enforceable | uk-cpr-pd57ad.disclosure-challenge-reconstruction | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Substantive disclosure review & adequacy judgmentThe substantive legal judgment / document substance / case strategy is the firm's own legal work — KYE™ is an AI-authority and evidence layer, not a legal-research or legal-judgment engine. | Out of scope | L1 Mapped | uk-cpr-pd57ad.substantive-disclosure-review | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

UK PIDA

#### UK PIDA — Public Interest Disclosure Act 1998 (ERA 1996 Part IVA)

UK Public Interest Disclosure Act 1998 (Employment Rights Act 1996, Part IVA) · United Kingdom

UK PIDA — Public Interest Disclosure Act 1998 (ERA 1996 Part IVA) is the UK protected-disclosure framework (protection from detriment and automatic-unfair dismissal). KYE Protocol™ governs whether an AI-assisted handling of a protected disclosure, or an adverse action on a worker who made one, may proceed — under a named handler's authority, with a recorded detriment / retaliation-risk assessment before adverse action, and a contestability record so a detriment / dismissal claim can be reconstructed. Whether the disclosure qualifies, whether a detriment occurred, and the tribunal adjudication stay with counsel and the tribunal (honest scope, §0). Per-requirement bijection at /compliance/uk-pida.html.

### 2

Enforced

### 0

Designed

### 1

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Named-authority on the protected-disclosure handling & detriment-risk record | Enforced | L3 Enforceable | uk-pida.protected-disclosure-handling-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Contestability & reconstruction for a detriment / dismissal claim | Enforced | L3 Enforceable | uk-pida.detriment-claim-reconstruction | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Whether the disclosure qualifies & employment-tribunal adjudicationDeciding whether a disclosure qualifies and adjudicating the tribunal claim is a legal determination for counsel and the tribunal — KYE™ is an AI-authority and evidence layer, not an adjudication engine. | Out of scope | L1 Mapped | uk-pida.qualifying-disclosure-and-adjudication | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Visa CE 3.0

#### Visa Compelling Evidence 3.0 (CE3.0)

Visa Compelling Evidence 3.0 (CE3.0) — remedied-dispute evidence requirements (Visa Rules, fraud reason code 10.4) · Global

Visa Compelling Evidence 3.0 defines the qualifying evidence set that remedies a card-absent fraud dispute (prior undisputed transactions, matching device / IP / address / account identifiers, delivery evidence). KYE Protocol™ governs whether the representment may proceed — under a named owner's recorded authority, with the qualifying evidence captured as evidence events at transaction time, and the representment bundle sealed as a signed, hash-bound, WORM-retained, replay-verifiable Evidence Pack™ — exactly the provable evidence set CE3.0 representments turn on. Whether to fight, the narrative, and the outcome stay the merchant's / network's own (honest scope, §0). Per-requirement bijection at /compliance/visa-ce30.html.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Qualifying evidence set captured at transaction time | Enforced | L3 Enforceable | visa-ce30.evidence-set-capture | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Representment bundle integrity (signed · hash-bound · WORM) | Enforced | L3 Enforceable | visa-ce30.representment-bundle-integrity | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Named-authority on the representment decision | Enforced | L3 Enforceable | visa-ce30.representment-authority | Authority GateDecision replayEvidence Pack™Replay-Proof™ |
| Dispute outcome adjudication & narrative on the meritsWhether to fight a dispute, the dispute narrative, the fraud scoring, and the dispute outcome are the merchant's / network's own — KYE™ is an AI-authority and evidence layer, not a dispute-management or fraud-scoring engine. | Out of scope | L1 Mapped | visa-ce30.dispute-outcome-adjudication | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

2 CFR 200 (Uniform Guidance)

#### US 2 CFR 200 — Uniform Guidance

2 C.F.R. Part 200 (Uniform Guidance) · United States

US federal grants-administration regulation: uniform administrative requirements, cost principles, and audit requirements for federal awards. KYE™ governs WHETHER a grants-lifecycle action by an AI agent may proceed and proves the basis (via the KYE™ Governed Grants Agent™); it does not write applications, run a grants-management platform, or move money.

### 3

Enforced

### 1

Designed

### 1

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Cost principles & allowability of costs (§200.403) | Enforced | L3 Enforceable | 2 C.F.R. §200.403 | Governed Grants Agent™ admit→decidePurpose Permission™Evidence Pack™ |
| Internal controls over the federal award (§200.303) | Enforced | L3 Enforceable | 2 C.F.R. §200.303 | Replay-Proof™WORM audit hash-chainEvidence Pack™ |
| Pass-through entity / subrecipient monitoring (§200.332) | Enforced | L3 Enforceable | 2 C.F.R. §200.332 | Governed Grants Agent™ admit→decideDelegated Auditability |
| Prior written approval & record retention (§200.407, §200.334) | Designed | L2 Designed | 2 C.F.R. §200.407, 2 C.F.R. §200.334 | GovernedUI two-person sign-off (Phase-2)WORM retention policy (Phase-2) |
| Grantee financial-management system & Single Audit (§200.302, §200.501) | Out of scope | L1 Mapped | 2 C.F.R. §200.302, 2 C.F.R. §200.501 | — |

[KYE™ framework reference](https://kyeprotocol.com/governed-agents/)

IT Rules 2021

#### IT Rules 2021

Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as amended · India

KYE™ governs whether an AI agent's content-affecting ACTION (publish, remove, restrict, distribute) was authorised and is evidenced. KYE™ is OUT-OF-SCOPE for the substantive content determination — whether material is unlawful — and for operating grievance-redressal machinery. Those are the intermediary's own obligations (§70 §4). Deep per-requirement mapping: 4 requirements, 1 enforced by KYE™ runtime, 3 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.

### 1

Enforced

### 0

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Authority + evidence at the action boundary — enforced by KYE™ runtime and verified by CI | Enforced | L3 Enforceable | it-rules-2021.ACTION-AUTHORITY — Content-affecting actions taken under resolved authority and evidenced | kye.compliance.attestation.v1kye.evidence.decision\_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context\_seal.v1internal |
| Obligations owed directly by the regulated entity — NOT discharged by KYE™KYE™ governs whether an AI agent's content-affecting ACTION (publish, remove, restrict, distribute) was authorised and is evidenced. KYE™ is OUT-OF-SCOPE for the substantive content determination — whether material is unlawful — and for operating grievance-redressal machinery. Those are the intermediary's own obligations (§70 §4). | Out of scope | L1 Mapped | it-rules-2021.GRIEVANCE-REDRESSAL — Grievance officer appointed and complaints resolved within prescribed timelines, it-rules-2021.DUE-DILIGENCE — Intermediary due-diligence obligations including publication of rules and privacy policy, it-rules-2021.SYNTHETIC-LABELLING — Identification of artificially generated or modified information | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

### Security & cyber-resilience

Information-security and operational-resilience frameworks that govern how systems are protected, monitored, and recovered.

ASD Essential Eight

#### ASD Essential Eight + ASD AI guidance

Nov 2023 maturity model + 2024 AI guidance · Australia

ASD/ACSC Essential Eight mitigation strategies + ASD 'Engaging with Artificial Intelligence' guidance, scoped to the AI-agent action path. Per-requirement bijection at /compliance/asd-essential-eight.html.

### 2

Enforced

### 0

Designed

### 0

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Restrict administrative privileges + multi-factor authentication | Enforced | L3 Enforceable | E8 — Restrict admin privileges, E8 — MFA | Authority GateAuthority Revocation OrchestratorWebAuthn step-up |
| Tamper-evident monitoring + AI supply-chain governance | Enforced | L3 Enforceable | E8 — Monitoring, ASD AI guidance — supply chain | WORM audit hash-chainStreaming Logs Contract™Authority Register |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

CISA CDM

#### CISA CDM — Continuous Diagnostics and Mitigation (AI-agent asset accountability)

CDM Program — DEFEND capability areas A–D · United States

CISA's Continuous Diagnostics and Mitigation program, mapped to the agentic-AI asset surface: an AI agent that holds credentials, reaches data, and acts on systems is a reportable cyber asset. KYE™ answers 'what agents exist, who owns them, what do they touch, what can they do, and are they drifting?'

### 4

Enforced

### 0

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Asset Management — HWAM/SWAM/CSM/VUL (the AI-agent asset inventory + approved-design baseline + drift) | Enforced | L3 Enforceable | HWAM, SWAM, CSM, VUL | §14 Agent Registry (reportable assets)Operating Model™ baselineReality Coupling™ drift |
| Identity & Access Management — TRUST/CRED/PRIV/BEHAVE | Enforced | L3 Enforceable | TRUST, CRED, PRIV, BEHAVE | Know Your Entity™ resolutionAuthority tokens + revocationPurpose Permission™ least privilege |
| Network Security Management — BOUND/MNGEVT (tenant isolation + suspend/revoke response) | Enforced | L3 Enforceable | BOUND, MNGEVT | §0.11 tenant isolationSuspend/Revoke/Kill-switchWORM audit |
| Data Protection Management — DPM (tamper-evident, replayable evidence) | Enforced | L3 Enforceable | DPM | WORM audit hash-chainEvidence Pack™Replay Proof™ |

[KYE™ framework reference](https://kyeprotocol.com/compliance/cisa-cdm/)

FedRAMP

#### FedRAMP — Federal Risk and Authorization Management Program

Rev 5 · United States

US federal cloud authorisation program built on the NIST SP 800-53 control baseline.

### 4

Enforced

### 0

Designed

### 1

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Access Control (AC) family | Enforced | L3 Enforceable | AC | Authority GatePurpose Permission™WebAuthn step-up |
| Audit & Accountability (AU) family | Enforced | L3 Enforceable | AU | WORM audit hash-chainDecision replay |
| Identification & Authentication (IA) family | Enforced | L3 Enforceable | IA | WebAuthn step-upAuthority Gate |
| System & communications protection — cryptographyA FIPS-validated cryptographic adapter and automated key rotation are in build. | Enforced | L3 Enforceable | SC-12, SC-13 | FIPS-validated crypto moduleAutomated key rotationEvidence Pack™ signing (COSE-Sign1) |
| Physical (PE) & Personnel (PS) familiesPhysical and personnel controls are operated by the customer's authorised cloud environment. | Out of scope | L1 Mapped | PE, PS | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Google SRE Change Mgmt

#### Google SRE — Change Management (progressive rollout & rollback)

SRE Book · International

Google SRE — Change Management (progressive rollout & rollback). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE™ Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.

### 1

Enforced

### 0

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Progressive rollout authority & rollback readiness (action-boundary, enforced) | Enforced | L3 Enforceable | google-sre-change-management.progressive-rollout-authority | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Monitoring, canary analysis & rollout-automation tooling (out-of-scope — sre / platform) | Out of scope | L1 Mapped | google-sre-change-management.monitoring-rollout-tooling | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ISO 27001

#### ISO/IEC 27001 — Information Security Management

2022 · International

Information security management system requirements and the Annex A control set.

### 3

Enforced

### 1

Designed

### 1

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Organisational & people controls | Enforced | L3 Enforceable | A.5.x, A.6.x | Purpose Permission™Authority Gate |
| Identity & access management | Enforced | L3 Enforceable | A.5.15-A.5.18, A.8.2-A.8.5 | Authority GateWebAuthn step-upPurpose Permission™ |
| Logging, monitoring & event management | Enforced | L3 Enforceable | A.8.15, A.8.16 | WORM audit hash-chainDecision replay |
| Cryptographic controls & key managementEd25519 signing runs in-process today; the KMS/HSM-backed key-rotation and FIPS-validated adapter are in build. | Designed | L2 Designed | A.8.24 | Evidence Pack™ signing (COSE-Sign1)Automated key rotationFIPS-validated crypto module |
| Physical security & training deliveryKYE™ records that training was completed as a capability grant, but does not deliver content or operate physical and environmental controls. | Out of scope | L1 Mapped | A.7.x, A.6.3 | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ISO/IEC 20000-1

#### ISO/IEC 20000-1 — Service Management (change management §8.5.1)

2018 · International

ISO/IEC 20000-1 — Service Management (change management §8.5.1). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE™ Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.

### 1

Enforced

### 0

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Change management §8.5.1 — authorization & records (action-boundary, enforced) | Enforced | L3 Enforceable | iso-iec-20000-1.clause8-5-1-change-management | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Service-management system operation, SLAs & continual improvement (out-of-scope — service-management) | Out of scope | L1 Mapped | iso-iec-20000-1.smsystem-operation | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

ITIL 4 Change Enablement

#### ITIL 4 — Change Enablement (change authority & assessment)

4 · International

ITIL 4 — Change Enablement (change authority & assessment). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE™ Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.

### 1

Enforced

### 0

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Change authority & assessment (action-boundary, enforced) | Enforced | L3 Enforceable | itil-4-change-enablement.change-authority-assessment | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Technical change evaluation, scheduling & change-model authoring (out-of-scope — change-management) | Out of scope | L1 Mapped | itil-4-change-enablement.change-evaluation-technical | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

NIS2

#### NIS2 — Network and Information Security Directive

Directive (EU) 2022/2555 · European Union

EU cybersecurity directive setting risk-management and incident-reporting duties for essential and important entities.

### 2

Enforced

### 1

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Cybersecurity risk-management measures | Enforced | L3 Enforceable | Art. 21 | Purpose Permission™Authority GateWORM audit hash-chain |
| Incident handling & reporting evidence | Enforced | L3 Enforceable | Art. 23 | WORM audit hash-chainDecision replay |
| Supply-chain security evidenceSupply-chain federation runs through the Directory tenant proxy today; signed supply-chain evidence packs are in build. | Designed | L2 Designed | Art. 21(2)(d) | Evidence Pack™ signing (COSE-Sign1)Directory tenant proxy |
| Management-body governance designationDesignation of management-body responsibility for cybersecurity risk is an organisational matter. | Out of scope | L1 Mapped | Art. 20 | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

NIST 800-207

#### NIST SP 800-207 — Zero Trust Architecture

1.0 · United States

Reference architecture for zero-trust security: per-request authorisation and continuous evaluation.

### 3

Enforced

### 0

Designed

### 1

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Policy decision & enforcement point | Enforced | L3 Enforceable | §2, §3.1 | Authority GatePurpose Permission™ |
| Continuous evaluation & per-request authorisation | Enforced | L3 Enforceable | §3.2 | Purpose Permission™WebAuthn step-up |
| Audit, telemetry & diagnostics | Enforced | L3 Enforceable | §3.4 | WORM audit hash-chainDecision replay |
| Deployment-topology selectionKYE™ aligns with every zero-trust deployment variant but does not prescribe one; deployment topology is the customer's choice. | Out of scope | L1 Mapped | §3.3 | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

NIST 800-53 CM

#### NIST SP 800-53 Rev 5 — Configuration Management (CM) family

Rev 5 · United States

NIST SP 800-53 Rev 5 — Configuration Management (CM) family. KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE™ Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.

### 1

Enforced

### 0

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| CM-3 configuration change control — authority & impact analysis (action-boundary, enforced) | Enforced | L3 Enforceable | nist-800-53-cm.cm-3-configuration-change-control | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| CM-2 baseline configuration & CM-8 component inventory (out-of-scope — config-management) | Out of scope | L1 Mapped | nist-800-53-cm.cm-2-baseline-inventory | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

NIST CSF

#### NIST Cybersecurity Framework

2.0 · United States

Outcome-based cybersecurity framework organised around the Govern, Identify, Protect, Detect, Respond, and Recover functions.

### 3

Enforced

### 1

Designed

### 0

Out of scope

4 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Govern function | Enforced | L3 Enforceable | GV | Purpose Permission™Authority Gate |
| Identify & Protect functions | Enforced | L3 Enforceable | ID, PR | Authority GatePurpose Permission™WebAuthn step-up |
| Detect, Respond & Recover functions | Enforced | L3 Enforceable | DE, RS, RC | WORM audit hash-chainDecision replay |
| Tamper-evident control evidenceThe append-only audit chain protects evidence integrity today; detached signatures that prove integrity to an external party are in build. | Designed | L2 Designed | PR.DS | Evidence Pack™ signing (COSE-Sign1) |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

SOC 2

#### SOC 2 — Trust Services Criteria

TSC 2017 · Global

AICPA Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy.

### 4

Enforced

### 1

Designed

### 1

Out of scope

6 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Control environment, communication & risk assessment | Enforced | L3 Enforceable | CC1.x, CC2.x, CC3.x | Purpose Permission™Authority GateWORM audit hash-chain |
| Logical access controls | Enforced | L3 Enforceable | CC6.1-CC6.8 | Authority GatePurpose Permission™WebAuthn step-up |
| System operations, monitoring & change management | Enforced | L3 Enforceable | CC7.x, CC8.1 | WORM audit hash-chainDecision replay |
| Confidentiality, availability & recovery | Enforced | L3 Enforceable | C1.x, A1.2, P4.1 | Authority GateWORM audit hash-chain |
| Independently verifiable transparency receiptsTransparency receipts are emitted today; the detached cryptographic signatures that make them third-party-verifiable are in build. | Designed | L2 Designed | CC2.3 | Evidence Pack™ signing (COSE-Sign1)Decision Map™ signing (JWS-detached) |
| Board oversight & physical securityBoard composition and data-centre physical controls are organisational; KYE™ records the actions of board members but does not establish governance structure. | Out of scope | L1 Mapped | CC1.2 | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

SOC 2 CC8

#### Production Action Authority — SOC 2 CC8 Change Management

2017 TSC · United States

SOC 2 — CC8 Change Management (Common Criteria). KYE Protocol™ governs ONLY the runtime-authority-resolvable subset at the action boundary — the moment an AI-driven production action (a rollback / hotfix / infra-change) moves toward a consequential effect — the KYE™ Production Action Authority Pack™ (§70 honesty bar). Autoheal finds the fix; KYE Protocol™ proves the fix had authority. The detection / RCA / monitoring / change-tooling substance is honestly out of scope and ceded to the SRE / change-management function and to incident-intelligence tools. Coverage is never inflated to 100%. Per-requirement bijection at framework-coverage-bijection.

### 1

Enforced

### 0

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| CC8.1 change authorization & evidence (action-boundary, enforced) | Enforced | L3 Enforceable | soc2-cc8-change-management.cc8-1-change-authorization | Action Admissibility™ GateAuthority Finality™Evidence Pack™ |
| Change design, development & testing (out-of-scope — engineering / qa) | Out of scope | L1 Mapped | soc2-cc8-change-management.cc8-development-testing | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

OWASP Agentic Top 10

#### OWASP Top 10 for Agentic Applications (Agentic AI Threats and Mitigations)

2025 · International

OWASP's agentic-AI threat taxonomy (2025), crosswalked by AIUC-1. KYE Protocol™ is the runtime authority + evidence + finality substrate each threat class assumes — it gates the agent action, binds agent identity, and seals replay-provable evidence. KYE™ proves the control operated at the action boundary; it is not an agent scanner. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Tool misuse / privilege / intent — gated by purpose-scope | Designed | L2 Designed | owasp-agentic.t2-tool-misuse, owasp-agentic.t3-privilege-compromise, owasp-agentic.t6-intent-goal-manipulation | Purpose Permission™Decision Map™Authority Gate |
| Repudiation / spoofing / deception — identity + replay evidence | Designed | L2 Designed | owasp-agentic.t8-repudiation-untraceability, owasp-agentic.t9-identity-spoofing, owasp-agentic.t7-misaligned-deceptive | Evidence Pack™Replay Proof™Delegated Auditability |
| Memory poisoning / HITL overwhelm — memory authority + approval modes | Designed | L2 Designed | owasp-agentic.t1-memory-poisoning, owasp-agentic.t10-hitl-overwhelm | Memory AuthorityGovernedUI |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

SASH Cyber Agents

#### Singapore SASH — Detecting Offensive Cyber Agents

2026 · Singapore

Singapore SASH 'Detecting Offensive Cyber Agents' defence-in-depth (2026). KYE Protocol™ makes a defending org's own agents first-class identifiable principals with replay-provable actions + a continuous posture signal — complementing the identity, triage and exchange (ACE) layers. KYE™ is the authority + evidence substrate, not an IDS/honeypot. Per-requirement bijection at framework-coverage-bijection.

### 0

Enforced

### 3

Designed

### 0

Out of scope

3 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Agent identity — first-class bound principals | Designed | L2 Designed | sash.agent-identity | Delegated Agent BindingAgent Identity |
| Detection & triage — continuous posture signal | Designed | L2 Designed | sash.detection-triage | Posture SignalDelegated Agent Binding |
| ACE exchange + post-incident replay | Designed | L2 Designed | sash.ace-exchange, sash.evidence-replay | Evidence Pack™Replay Proof™Delegated Auditability |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

CRA

#### EU Cyber Resilience Act (CRA)

Regulation (EU) 2024/2847 · European Union

EU horizontal cybersecurity regulation for products with digital elements; mandatory SBOM, vulnerability handling, security-by-design, and Article 14 vulnerability/incident reporting (24h/72h/14-day). Fully applicable Dec 2027.

### 3

Enforced

### 1

Designed

### 1

Out of scope

5 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Security-by-design essential requirements (Annex I, Part I) | Enforced | L3 Enforceable | Annex I, Part I | Purpose Permission™WORM audit hash-chainSIEM streaming logs |
| Vulnerability handling + remediation (Annex I, Part II) | Enforced | L3 Enforceable | Annex I, Part II | Cyber-resilience incident rule packDecision replay |
| SBOM generation & machine-readable bill of materialsKYE™ does not generate the product SBOM (manufacturer obligation); a manufacturer-supplied SBOM can be cited and pinned as evidence to a governed vulnerability-handling decision. Runtime ingest is designed, not yet wired. | Designed | L2 Designed | Annex I, Part II (1) | Document Intelligence Rail (cite-and-pin) |
| Article 14 vulnerability & severe-incident reporting (24h/72h/14-day) | Enforced | L3 Enforceable | Art. 14 | Incident lifecycleEvidence Pack™ signing |
| Conformity assessment & CE markingConformity assessment, CE marking and placing-on-the-market are product-certification obligations of the manufacturer and notified body, outside KYE™'s lane. | Out of scope | L1 Mapped | Art. 32, Annex VIII | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

CERT-In Directions

#### CERT-In Cyber Security Directions

Directions dated 28 April 2022 under s.70B(6), Information Technology Act, 2000 · India

KYE™ governs the AUTHORITY + EVIDENCE layer of incident response: what was decided, under whose authority, and when — sealed so the sequence is replayable against a statutory clock. KYE™ is OUT-OF-SCOPE for detecting cyber incidents across the customer's estate, for operating their SOC, and for making the regulatory filing to CERT-In. The six-hour obligation is the customer's; KYE™ makes the timeline provable (§70 §4). Deep per-requirement mapping: 5 requirements, 2 enforced by KYE™ runtime, 3 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.

### 1

Enforced

### 0

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Authority + evidence at the action boundary — enforced by KYE™ runtime and verified by CI | Enforced | L3 Enforceable | cert-in-directions-2022.SIX-HOUR-CLOCK — Specified cyber incidents reported to CERT-In within six hours of noticing, cert-in-directions-2022.LOG-RETENTION — ICT system logs maintained securely for a rolling 180-day period within Indian jurisdiction | kye.compliance.attestation.v1kye.evidence.pack.v1kye.replay.context\_seal.v1kye.resilience.availability\_gap.v1 |
| Obligations owed directly by the regulated entity — NOT discharged by KYE™KYE™ governs the AUTHORITY + EVIDENCE layer of incident response: what was decided, under whose authority, and when — sealed so the sequence is replayable against a statutory clock. KYE™ is OUT-OF-SCOPE for detecting cyber incidents across the customer's estate, for operating their SOC, and for making the regulatory filing to CERT-In. The six-hour obligation is the customer's; KYE™ makes the timeline provable (§70 §4). | Out of scope | L1 Mapped | cert-in-directions-2022.TIME-SYNC — System clocks synchronised to NPL or NIC network time, cert-in-directions-2022.INCIDENT-DETECTION — Detection and triage of reportable cyber incidents across the estate, cert-in-directions-2022.REGULATORY-FILING — Submission of the incident report to CERT-In in the prescribed format | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

SEBI CSCRF

#### SEBI CSCRF

Cybersecurity and Cyber Resilience Framework (CSCRF) · India

KYE™ governs the AUTHORITY + EVIDENCE layer of consequential actions and of incident RESPONSE decisions. KYE™ is OUT-OF-SCOPE for the identify/protect/detect capabilities themselves — asset inventory, network protection, monitoring — which the regulated entity operates (§70 §4). Deep per-requirement mapping: 6 requirements, 2 enforced by KYE™ runtime, 4 honestly out of scope. Requirement decomposition is PUBLISHER-LEVEL, not pinned to a retrieved primary text: India's official sources (meity.

### 1

Enforced

### 0

Designed

### 1

Out of scope

2 requirement groups — view detail

| Requirement group | Status | Maturity | Framework refs | KYE™ controls |
| --- | --- | --- | --- | --- |
| Authority + evidence at the action boundary — enforced by KYE™ runtime and verified by CI | Enforced | L3 Enforceable | sebi-cyber-resilience.RESPOND-AUTHORITY — Incident-response actions taken under resolved authority and sealed, sebi-cyber-resilience.EVIDENCE-RETENTION — Retention of security event records supporting audit and forensic review | kye.compliance.attestation.v1kye.evidence.decision\_map.v1kye.evidence.pack.v1kye.purpose.admissibility.v1kye.replay.context\_seal.v1internal |
| Obligations owed directly by the regulated entity — NOT discharged by KYE™KYE™ governs the AUTHORITY + EVIDENCE layer of consequential actions and of incident RESPONSE decisions. KYE™ is OUT-OF-SCOPE for the identify/protect/detect capabilities themselves — asset inventory, network protection, monitoring — which the regulated entity operates (§70 §4). | Out of scope | L1 Mapped | sebi-cyber-resilience.IDENTIFY-PROTECT — Asset identification and protective controls across the estate, sebi-cyber-resilience.DETECT-MONITOR — Continuous monitoring and detection of cyber events, sebi-cyber-resilience.INCIDENT-REPORTING — Reporting of cyber incidents to SEBI within prescribed timelines, sebi-cyber-resilience.RECOVER — Recovery and restoration capability with defined objectives | — |

[KYE™ framework reference](https://kyeprotocol.com/frameworks/)

Methodology

## One registry. Zero hand-authored numbers.

This page is generated. The framework roster, every count, and every headline number above are projected from `internal` — a schema-backed canonical registry validated on every build. The page cannot drift from the registry: a CI gate regenerates it and fails the build on any mismatch.

For the full per-control register — every article and criterion bound to its KYE™ runtime control — see the [compliance frameworks reference](https://kyeprotocol.com/frameworks/) and the [compliance program](https://kyeprotocol.com/compliance/). KYE Protocol™ is an evidence layer: it is not a certification, and it does not replace the customer’s own controls or an accredited assessment.

## See your own coverage map.

Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.

[Apply for pilot →](https://kyeprotocol.com/pilot-apply/) [Browse frameworks →](https://kyeprotocol.com/frameworks/)

Canonical KYE™ surfaces referenced on this page: [Audit Pilot](https://kyeprotocol.com/auditors/) · [Cohesion Cascade](https://kyeprotocol.com/glossary/) · [Delegated Auditability](https://kyeprotocol.com/glossary/) · [Evidence Pack™](https://kyeprotocol.com/evidence-pack/) · [KYE™ Comms Engine](https://kyeprotocol.com/glossary/) · [KYE™ Production Action Authority™](https://kyeprotocol.com/governance-for-the-ai-web/) · [KYE Protocol™](https://kyeprotocol.com/) · [KYE™ Reconciliation Engine](https://kyeprotocol.com/glossary/) · [Purpose Permission](https://kyeprotocol.com/glossary/) · [Resilience Loop](https://kyeprotocol.com/glossary/) · [Self-Governance](https://kyeprotocol.com/self-governance/).
