Compliance frameworks · per-framework reference

One runtime. Every framework.

289 control mappings across 13 horizontal frameworks, plus 5 sectoral frameworks — all bound to KYE Protocol™ runtime controls through the KYE Compliance Mapping Rail™. Pick a framework; read the bound KYE™ controls and the official source.

Horizontal frameworks

Cross-sector controls.

Every claim here is backed by the open KYE Protocol™ contracts and verifiable end-to-end from the publisher's JWKS — you check it yourself, you don't take our word for it.

SOC 2 Trust Services Criteria

AICPA's audit framework for service organisations: security, availability, confidentiality, processing integrity, privacy.

KYE™ bindings: access reviews → /v1/graph/authority-path; audit evidence → signed evidence packs; change management → KYE™ audit chain; incident evidence → KYE™ Self-Audit™ runs.

AICPA SOC 2 →

ISO 27001:2022 ISMS

Information Security Management System. Annex A controls cover access, asset/entity inventory, privileged access, logging, supplier and incident management.

KYE™ bindings: entity inventory → KYE™ entity registry; privileged access → capability + state model; logging → KYE™ audit chain; supplier management → KYE™ delegation chain across trust domains.

ISO 27001:2022 →

ISO 42001 AI Management System

First international standard for AI management: inventory, responsibility mapping, risk/impact, lifecycle controls, oversight logs.

KYE™ bindings: AI inventory → KYE™ entity (agent, model) registry; responsibility → delegation chain; oversight logs → KYE™ audit chain + Decision Map™.

ISO/IEC 42001 →

EU AI Act Regulation 2024/1689

EU regulation on AI systems & agents. Title III high-risk obligations: risk classification, data governance, technical documentation, human oversight, post-market monitoring.

KYE™ bindings (10 controls): kye-euaiact-1.0 profile binds entity accountability, AI system registry, capability + risk classification, human-oversight gates, runtime authority decision logs, technical-documentation evidence pack, corrective action trail, role mapping, high-risk workflow profile, post-market monitoring hooks.

EUR-Lex 2024/1689 →

NIST AI RMF 1.0

US framework: Govern / Map / Measure / Manage AI risk lifecycle.

KYE™ bindings: Govern → delegation chain + role mapping; Map → capability registry; Measure → signal bus + telemetry; Manage → cascade revocation + recovery profile.

NIST AI RMF →

PCI DSS 4.0 Payment-card data

Payment-card industry data security standard. Covers credential state, payment-capability gating, wallet authority, audit logs.

KYE™ bindings: credential state → KYE™ state model; payment-capability gating → pep; wallet authority → capability + delegation; audit → KYE™ audit chain + signed proof bundle.

PCI SSC →

PSD2 / PSD3 EU Payment Services Directive

Strong customer authentication, third-party access (TPP), open banking, agent-action liability under PSD3.

KYE™ bindings: SCA evidence → credential state; TPP delegation → KYE™ delegation chain (TPP → PSP → user); per-action authority → POST /v1/runtime/authorize; audit → signed proof bundle.

EC PSD →

DORA Digital Operational Resilience Act

EU regulation on ICT third-party authority, operational resilience, incident response, auditability for financial entities.

KYE™ bindings: third-party authority → KYE™ delegation chain + trust-domain federation; incident evidence → KYE™ audit chain + Blast Radius Map™; operational resilience → recovery + break-glass profiles.

EIOPA DORA →

NIS2 EU cybersecurity directive

EU directive: cybersecurity governance, incident traceability, supply-chain controls, access authority for essential and important entities.

KYE™ bindings: incident traceability → KYE™ audit chain; supply-chain → capability registry + attestation; access authority → KYE™ delegation + scope.

EC NIS2 →

GDPR / UK GDPR Data protection

Role mapping (controller / processor / sub-processor), lawful authority trail, data access, automated decision governance, audit.

KYE™ bindings: role mapping → entity types + delegation; lawful authority → consent credential + scope; right-to-erasure → lifecycle tombstoned + redaction obligations.

GDPR.eu →

NIST 800-207 Zero-Trust Architecture

US federal zero-trust reference: identity, device, network, application, data telemetry signals continuously inform every decision.

KYE™ bindings: continuous evaluation → KYE™ state model; per-request decision → embedded PDP; signal-driven invalidation → KYE™ signal bus + cascade.

NIST SP 800-207 →

NIST CSF Cybersecurity Framework 2.0

Govern / Identify / Protect / Detect / Respond / Recover. The headline US cybersecurity reference.

KYE™ bindings: Govern → trademark + governance docs; Identify → entity registry; Protect → KYE™ authorize + state; Detect → signal bus; Respond → cascade revocation; Recover → recovery + break-glass profiles.

NIST CSF →

FedRAMP US federal cloud authorisation

Standardised authorisation program for cloud services used by US federal agencies. Builds on NIST 800-53 + 800-207.

KYE™ bindings: Continuous monitoring → KYE™ Self-Audit™ Cloud; access boundary → trust-domain federation; evidence pack → KYE™ evidence-pack generator with public-key verification.

FedRAMP →

Sectoral frameworks

Industry-specific obligations.

Every claim here is backed by the open KYE Protocol™ contracts and verifiable end-to-end from the publisher's JWKS — you check it yourself, you don't take our word for it.

MiCA EU Crypto-Asset Markets

EU regulation on crypto-asset issuers, service providers, white papers, conduct, and operational resilience.

KYE™ bindings: custody chain → financial-services rule pack + signer-of-signers delegation; recovery → evidence-replay profile; audit → signed evidence pack.

EUR-Lex 2023/1114 →

FFIEC US bank exam guidance

Federal Financial Institutions Examination Council guidance on authentication, third-party risk, BCP, AML.

KYE™ bindings: authentication evidence → credential state; third-party risk → trust-domain federation; AML → capability scope + obligation.

FFIEC →

IEC 62443 Industrial cybersecurity

Standards series for industrial automation & control systems. Used in energy, water, manufacturing, transport.

KYE™ bindings: operator / vendor / maintenance authority → KYE™ delegation + scope; emergency authority → break-glass profile; safety-critical actions → kye-energy-1.0 / kye-critical-infra-1.0 overlays.

IEC 62443 →

HIPAA US health-data protection

Healthcare entity access, minimum-necessary principle, emergency / break-glass, audit trails for PHI. Bound through the v1.1 healthcare profile overlay.

KYE™ bindings: minimum-necessary → capability scope; consent → credential entity; break-glass → recovery profile + signed time-boxed flow; audit → KYE™ audit chain with PHI redaction obligation.

HHS HIPAA →

42 CFR Part 2 US substance-use confidentiality

Strict consent + redaction rules for substance-use treatment records. Healthcare overlay.

KYE™ bindings: consent credential + redaction obligation; the healthcare sector pack (clinical extensions; v1.1 target Q3 2026).

eCFR 42 CFR Part 2 →

HAARF v1.0 Healthcare AI Agents Regulatory Framework

Comprehensive security & governance standard for autonomous AI agents in clinical environments — 279 requirements across 8 categories (risk lifecycle, model passport, cybersecurity, human oversight, agent registration, autonomy governance, bias/equity, tool-integration security).

KYE™ bindings: 88% weighted coverage — risk lifecycle → decision/evidence engines; model passport → agent registry + provenance audit; human oversight → GovernedUI approval modules; autonomy → Edge Governance modes + Shadow Mode; tool integration → capability scope + KYE Agent Tool Pack™. Per-requirement map →

medRxiv 2026.04.09.26350519v1 →

MHRA MDR 2002 UK Medical Devices Regulations

UK Statutory Instrument 2002/618 as amended — risk classes (I / IIa / IIb / III + software class) and conformity assessment (declaration / Approved Body / registration). 23 requirements.

KYE™ bindings: 91% coverage — risk class → profile classification + sector pack; conformity assessment → signed evidence pack; UKCA / CE mark → attestation chain; UDI → trust-domain identifiers. Per-requirement map →

SI 2002/618 →

MHRA PMS 2025 UK Post-Market Surveillance

MHRA Post-Market Surveillance Regulations effective June 2025 — amends MDR 2002 with explicit post-market surveillance obligations: PMS plan, periodic safety update report, trend reporting, incident reporting, FSCA notification. 9 requirements.

KYE™ bindings: 83% coverage — PMS plan → resilience-loop registry; incident reporting → comms-rail templates + audit chain; trend reporting → analytics-plane events; FSCA → GovernedUI two-person sign-off. Per-requirement map →

SI 2024/1368 →

MHRA SaMD & AI Change Program Software and AI as a Medical Device

MHRA Software and AI as a Medical Device Change Program (2023) — 15 work-packages covering qualification, classification, PCCP, clinical evidence, post-market scrutiny, transparency, bias, cybersecurity, real-world performance, AI Airlock, adaptive control, failure-mode analysis.

KYE™ bindings: 93% coverage — PCCP → canonical change-control with replay-proof envelope; transparency → Decision Map™ + Evidence Pack™; bias → HAARF C7 controls; AI Airlock → Shadow Mode + sandbox profile; adaptive control → Edge Governance compiled-bundle versioning. Per-requirement map →

MHRA SaMD Program →

EC-Council ADG Adopt · Defend · Govern (2026)

EC-Council ADG (Adopt · Defend · Govern, 2026) — 35 requirements across three pillars, nine governance surfaces, twelve minimum controls (MC-1..MC-12), and three autonomy tiers (HITL / HOTL / HOOTL). ADG defines what controls organisations should operate; KYE Protocol™ proves the action met them at runtime.

KYE™ bindings: 89% coverage — MC-1..MC-3 → verified entity + Purpose Permission™ grant + federation chain; MC-5/6 → admissibility + Decision Map™; MC-7 → KYE Tool & MCP Authority Register™; MC-9/10/11 → Evidence Pack™ + Replay-Proof™ + Authority Finality™; MC-12 → GovernedUI™ critical-point review. Per-requirement map → · ADG ↔ KYE crosswalk →

EC-Council ADG →

NYC Local Law 144 Automated Employment Decision Tools

NYC Local Law 144 (in force) bars using an Automated Employment Decision Tool (AEDT) to screen a candidate unless it has passed a bias audit in the last twelve months, with candidate notice and published results. Bound through the KYE Hiring Governance Pack™.

KYE™ bindings: AEDT bias audit → signed Evidence Pack™; candidate notice → contestability route. Per-requirement map → · KYE Hiring Governance Pack™ →

UK Equality Act 2010 Indirect discrimination

The UK Equality Act 2010 makes an automated selection rule that disadvantages a protected group unlawful indirect discrimination (s.19) unless it is a proportionate means of a legitimate aim. Bound through the KYE Hiring Governance Pack™.

KYE™ bindings: s.19 indirect discrimination → four-fifths adverse-impact review + signed justification. KYE Hiring Governance Pack™ →

EEOC Uniform Guidelines Four-fifths adverse-impact rule

The EEOC Uniform Guidelines on Employee Selection Procedures treat a selection rate below four-fifths (80%) of the highest group's rate as evidence of adverse impact, requiring validated, job-related selection procedures. Bound through the KYE Hiring Governance Pack™.

KYE™ bindings: four-fifths rule → runtime selection-rate-ratio metric + adverse-impact review Evidence Pack™. KYE Hiring Governance Pack™ →

Regional & sector reference

Other frameworks KYE™ aligns with.

These are referenced on the relevant sector pages with their respective KYE™ profile bindings. The full per-control mapping register is published in the public conformance repo (KYE-Protocol/conformance); the source-of-truth normative spec ships under commercial licence (request the procurement pack).

RBI · MAS · CRR3 · FAA · EASA · ICAO · IATA · IMO · IFRS

Honest coverage mapregulatory-coverage.html · Per-sector framework mappingsectors.html · full normative specwhitepaper.html#compliance · certification programcompliance.html

Ready to see your AI agents flagged?

Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.