MiCA EU Crypto-Asset Markets
EU regulation on crypto-asset issuers, service providers, white papers, conduct, and operational resilience.
KYE™ bindings: custody chain → financial-services rule pack + signer-of-signers delegation; recovery → evidence-replay profile; audit → signed evidence pack.
EUR-Lex 2023/1114 →
FFIEC US bank exam guidance
Federal Financial Institutions Examination Council guidance on authentication, third-party risk, BCP, AML.
KYE™ bindings: authentication evidence → credential state; third-party risk → trust-domain federation; AML → capability scope + obligation.
FFIEC →
IEC 62443 Industrial cybersecurity
Standards series for industrial automation & control systems. Used in energy, water, manufacturing, transport.
KYE™ bindings: operator / vendor / maintenance authority → KYE™ delegation + scope; emergency authority → break-glass profile; safety-critical actions → kye-energy-1.0 / kye-critical-infra-1.0 overlays.
IEC 62443 →
HIPAA US health-data protection
Healthcare entity access, minimum-necessary principle, emergency / break-glass, audit trails for PHI. Bound through the v1.1 healthcare profile overlay.
KYE™ bindings: minimum-necessary → capability scope; consent → credential entity; break-glass → recovery profile + signed time-boxed flow; audit → KYE™ audit chain with PHI redaction obligation.
HHS HIPAA →
42 CFR Part 2 US substance-use confidentiality
Strict consent + redaction rules for substance-use treatment records. Healthcare overlay.
KYE™ bindings: consent credential + redaction obligation; the healthcare sector pack (clinical extensions; v1.1 target Q3 2026).
eCFR 42 CFR Part 2 →
HAARF v1.0 Healthcare AI Agents Regulatory Framework
Comprehensive security & governance standard for autonomous AI agents in clinical environments — 279 requirements across 8 categories (risk lifecycle, model passport, cybersecurity, human oversight, agent registration, autonomy governance, bias/equity, tool-integration security).
KYE™ bindings: 88% weighted coverage — risk lifecycle → decision/evidence engines; model passport → agent registry + provenance audit; human oversight → GovernedUI approval modules; autonomy → Edge Governance modes + Shadow Mode; tool integration → capability scope + KYE Agent Tool Pack™. Per-requirement map →
medRxiv 2026.04.09.26350519v1 →
MHRA MDR 2002 UK Medical Devices Regulations
UK Statutory Instrument 2002/618 as amended — risk classes (I / IIa / IIb / III + software class) and conformity assessment (declaration / Approved Body / registration). 23 requirements.
KYE™ bindings: 91% coverage — risk class → profile classification + sector pack; conformity assessment → signed evidence pack; UKCA / CE mark → attestation chain; UDI → trust-domain identifiers. Per-requirement map →
SI 2002/618 →
MHRA PMS 2025 UK Post-Market Surveillance
MHRA Post-Market Surveillance Regulations effective June 2025 — amends MDR 2002 with explicit post-market surveillance obligations: PMS plan, periodic safety update report, trend reporting, incident reporting, FSCA notification. 9 requirements.
KYE™ bindings: 83% coverage — PMS plan → resilience-loop registry; incident reporting → comms-rail templates + audit chain; trend reporting → analytics-plane events; FSCA → GovernedUI two-person sign-off. Per-requirement map →
SI 2024/1368 →
MHRA SaMD & AI Change Program Software and AI as a Medical Device
MHRA Software and AI as a Medical Device Change Program (2023) — 15 work-packages covering qualification, classification, PCCP, clinical evidence, post-market scrutiny, transparency, bias, cybersecurity, real-world performance, AI Airlock, adaptive control, failure-mode analysis.
KYE™ bindings: 93% coverage — PCCP → canonical change-control with replay-proof envelope; transparency → Decision Map™ + Evidence Pack™; bias → HAARF C7 controls; AI Airlock → Shadow Mode + sandbox profile; adaptive control → Edge Governance compiled-bundle versioning. Per-requirement map →
MHRA SaMD Program →
EC-Council ADG Adopt · Defend · Govern (2026)
EC-Council ADG (Adopt · Defend · Govern, 2026) — 35 requirements across three pillars, nine governance surfaces, twelve minimum controls (MC-1..MC-12), and three autonomy tiers (HITL / HOTL / HOOTL). ADG defines what controls organisations should operate; KYE Protocol™ proves the action met them at runtime.
KYE™ bindings: 89% coverage — MC-1..MC-3 → verified entity + Purpose Permission™ grant + federation chain; MC-5/6 → admissibility + Decision Map™; MC-7 → KYE Tool & MCP Authority Register™; MC-9/10/11 → Evidence Pack™ + Replay-Proof™ + Authority Finality™; MC-12 → GovernedUI™ critical-point review. Per-requirement map → · ADG ↔ KYE™ crosswalk →
EC-Council ADG →
NYC Local Law 144 Automated Employment Decision Tools
NYC Local Law 144 (in force) bars using an Automated Employment Decision Tool (AEDT) to screen a candidate unless it has passed a bias audit in the last twelve months, with candidate notice and published results. Bound through the KYE Hiring Governance Pack™.
KYE™ bindings: AEDT bias audit → signed Evidence Pack™; candidate notice → contestability route. Per-requirement map → · KYE Hiring Governance Pack™ →
UK Equality Act 2010 Indirect discrimination
The UK Equality Act 2010 makes an automated selection rule that disadvantages a protected group unlawful indirect discrimination (s.19) unless it is a proportionate means of a legitimate aim. Bound through the KYE Hiring Governance Pack™.
KYE™ bindings: s.19 indirect discrimination → four-fifths adverse-impact review + signed justification. KYE Hiring Governance Pack™ →
EEOC Uniform Guidelines Four-fifths adverse-impact rule
The EEOC Uniform Guidelines on Employee Selection Procedures treat a selection rate below four-fifths (80%) of the highest group's rate as evidence of adverse impact, requiring validated, job-related selection procedures. Bound through the KYE Hiring Governance Pack™.
KYE™ bindings: four-fifths rule → runtime selection-rate-ratio metric + adverse-impact review Evidence Pack™. KYE Hiring Governance Pack™ →