Retail & commercial banking
PSD3, FFIEC, RBI, MAS, CRR3 — agent and employee actions need a payment authority chain, not an OAuth token.
Each sector profile composes Core with the relevant overlays. Banking, healthcare, capital markets, custody, AI labs, public sector, defence, energy, manufacturing, automotive, maritime, logistics, aviation — adopt only what you need.
Each sector profile composes Core + the relevant overlays. Adopt only what you need; the core never shifts under you.
Pick the sector you operate in. The profiles you need are listed below it. Adopt only those; Core handles the rest.
PSD3, FFIEC, RBI, MAS, CRR3 — agent and employee actions need a payment authority chain, not an OAuth token.
Per-currency, per-rail, per-amount sPDP gating; signed proof bundles per authorise; ISO 20022 alignment in the high-assurance overlay.
HIPAA wants the consent chain. The hospital wants the redaction trace. The patient wants their AI not to leak their record.
An autonomous treasury bot rebalances. Auditors need authority + scope + attestation + decision — not “the bot did it.”
Wallets, signers, signers’ signers. Without an authority chain, “who moved this” is forensics, not policy.
Underwriting agents pull data and price risk. Regulators need the data-source authority and the consent the customer gave.
Your agent does something destructive. The user asks you to prove it wasn’t supposed to. Now do that for every agent on every tenant.
Cross-domain trust, attested workloads, FOIA-grade transparency log — one chain across agencies and contractors.
Sellers, agents acting for sellers, model-trained tools acting for both. Disputes need the chain, not chat logs.
Mission authority, command-chain audit for autonomous and semi-autonomous systems — rules of engagement attached to every action.
Operator, vendor, maintenance and emergency authority on safety-critical AI/automation across grid, water, telecom, transport.
Robot, cobot, MES, SCADA, supplier tooling — prove who/what may act on which production asset, under what state and approval.
Field-asset authority, contractor delegation, safety-critical actions, emergency overrides, environmental incident evidence.
Autonomous equipment authority, site access, operator delegation, safety exclusion zones, remote-control authority.
Vehicle software authority, OTA updates, supplier components, fleet/driver/dealer delegation, model/tool version audit.
Vessel, crew/officer, port agent, cargo, customs, autonomous-vessel and inspection authority — one chain across the route.
Shipment authority, warehouse-robot delegation, courier auth, customs delegation, cold-chain authority, exception approvals.
Air operations, ground services, autonomous aviation systems — authority and audit for crew, ground, ATC, MRO.
Each sector profile composes with the EU AI Act profile (kye-euaiact-1.0) when AI systems or AI agents are involved. KYE Compliance Mapping Rail™ binds the resulting evidence to framework controls.