A control-and-evidence mapping, not a certification. Apply each row only where the named control is configured and its evidence is present. Hardware co-signing, source integrations and witnessed records are separate deployment capabilities, not guarantees of the hosted invoice trial. Regulatory sufficiency is the firm's compliance and legal determination.
NIST SP 800-207 (Zero Trust)Per-action enforce-before-action decisions, a least-privilege signed agent manifest (fail-closed), and signed, freshness-stamped context state.
OWASP Agentic AI Top 10Bounded agency via the manifest and committed mandate; a restraint receipt on every block; hardware human co-sign; tamper-evident, offline-verifiable audit.
EU AI Act, Art 12-15Signed, tamper-evident logging and offline-verifiable records can support transparency and oversight. Human approval and failure behavior depend on the configured route; this page does not establish article-level compliance.
DORA, Art 9Enforce-before-action prevention, a degraded-mode kill switch, and a witnessed, timestamped append-only record.
SEC 17a-4(f) / 204-2Customer-owned WORM storage plus a separately pinned third-party timestamp can strengthen retention and timing evidence. Boundary: those controls do not prove route coverage or legal sufficiency; the firm still needs the required storage configuration and counsel, and most fund and adviser prospects are not broker-dealers.
MiFID II, RTS 6Pre-trade mandate limits enforced by the gate, with signed control records. Boundary: today ScopeBlind governs agent-proposed actions in the research and operations loop; the live FIX/OMS order-path integration is the next step.
Full mapping with per-control source references is maintained in docs/compliance-mapping.md.