Retail & commercial banking
PSD3, FFIEC, RBI, MAS, CRR3 — agent and employee actions need a payment authority chain, not an OAuth token. CorePaymentsTreasuryFederationCapabilityRecovery SOC 2 · ISO 27001 · PCI DSS 4.0 · PSD2/3 · DORA · NIS2
By sector · 18 regulated sectors
Sector packs add specialisation on top of canonical profiles. Banking, health, public-sector, insurance, telco — pre-wired.
Plain take
Pre-wired packs. Five sectors. Drop in and ship.
Sectors
Pick the sector you operate in. The profiles you need are listed below it. Adopt only those; Core handles the rest.
PSD3, FFIEC, RBI, MAS, CRR3 — agent and employee actions need a payment authority chain, not an OAuth token. CorePaymentsTreasuryFederationCapabilityRecovery SOC 2 · ISO 27001 · PCI DSS 4.0 · PSD2/3 · DORA · NIS2
Per-currency, per-rail, per-amount sPDP gating; signed proof bundles per authorise; ISO 20022 alignment in the high-assurance overlay. CorePaymentsCredentialsSignalsTelemetry PCI DSS 4.0 · PSD2/3 · DORA
HIPAA wants the consent chain. The hospital wants the redaction trace. The patient wants their AI not to leak their record. CoreHealthcareCredentialsCapabilityTelemetry HIPAA · ISO 27001 · EU AI Act
An autonomous treasury bot rebalances. Auditors need authority + scope + attestation + decision — not “the bot did it.” CoreTreasuryCustodyAttestationTransparencyRecovery SOC 2 · ISO 27001 · DORA
Wallets, signers, signers’ signers. Without an authority chain, “who moved this” is forensics, not policy. CoreCustodyAttestationCredentialsRecoveryCapability SOC 2 · ISO 27001 · MiCA
Underwriting agents pull data and price risk. Regulators need the data-source authority and the consent the customer gave. CoreCredentialsFederationCapabilityTelemetry SOC 2 · ISO 27001 · GDPR · EU AI Act
Your agent does something destructive. The user asks you to prove it wasn’t supposed to. Now do that for every agent on every tenant. CoreCapabilityAttestationSignalsRecoveryTelemetry EU AI Act · SOC 2 · NIS2
Cross-domain trust, attested workloads, FOIA-grade transparency log — one chain across agencies and contractors. CoreFederationAttestationTransparencyRecovery NIST 800-207 · FedRAMP · NIS2
Sellers, agents acting for sellers, model-trained tools acting for both. Disputes need the chain, not chat logs. CoreFederationCapabilitySignalsTelemetry SOC 2 · ISO 27001 · GDPR
Mission authority, command-chain audit for autonomous and semi-autonomous systems — rules of engagement attached to every action. CoreDefenceFederationAttestationRecovery NIST 800-207 · FedRAMP · NIS2 · EU AI Act
Operator, vendor, maintenance and emergency authority on safety-critical AI/automation across grid, water, telecom, transport. CoreEnergyCritical-InfraCapabilityRecovery NIS2 · IEC 62443 · ISO 27001
Robot, cobot, MES, SCADA, supplier tooling — prove who/what may act on which production asset, under what state and approval. CoreManufacturingCapabilityAttestationTelemetry ISO 27001 · ISO 9001 · IEC 62443 · EU AI Act
Field-asset authority, contractor delegation, safety-critical actions, emergency overrides, environmental incident evidence. CoreOil-GasCapabilityRecoveryTelemetry IOGP · ISO 14001 · IEC 62443 · NIS2
Autonomous equipment authority, site access, operator delegation, safety exclusion zones, remote-control authority. CoreMiningCapabilityAttestationRecovery ISO 27001 · ISO 45001 · IEC 62443
Vehicle software authority, OTA updates, supplier components, fleet/driver/dealer delegation, model/tool version audit. CoreAutomotiveCapabilityAttestationRecovery UNECE R155/R156 · ISO 21434 · IATF 16949 · EU AI Act
Vessel, crew/officer, port agent, cargo, customs, autonomous-vessel and inspection authority — one chain across the route. CoreMaritimeFederationCapabilityRecovery IMO MSC.428 · ISPS · ISO 27001
Shipment authority, warehouse-robot delegation, courier auth, customs delegation, cold-chain authority, exception approvals. CoreLogisticsFederationCapabilityTelemetry ISO 27001 · GDPR · IATA
Air operations, ground services, autonomous aviation systems — authority and audit for crew, ground, ATC, MRO. CoreAviationFederationAttestationRecovery FAA · EASA · ICAO · ISO 27001
Each sector profile composes with the EU AI Act profile (kye-euaiact-1.0) when AI systems or AI agents are involved. KYE™ Compliance Mapping Rail™ binds the resulting evidence to framework controls.
Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.
Canonical KYE™ surfaces referenced on this page: Evidence Pack™ · KYE Protocol™.