Zusammenfassung
Regulation is treated as an orientation layer rather than a deterministic ruleset: a matrix of regulatory intent and exposure is compiled into concrete prohibitions, obligations and runtime budgets. Evidence, decisions and reason codes bind to a permissioned DAG, so a supervisor can replay how an outcome was reached and attribute failure.
Introduction
The financial industry combines data intensity, complex decision processes and strict regulatory oversight, making it a natural environment for the application of artificial intelligence. Yet the adoption of AI in this domain is constrained by the absence of architectures that meet supervisory expectations for accountability, resilience and auditability. Existing implementations often prioritise performance or innovation at the expense of compliance, leaving institutions without frameworks that can be both operationally effective and regulatorily sound. This study addresses that gap by proposing a reference architecture for compliant AI in finance, designed to integrate supervisory requirements into system design from the outset. The analysis focuses on financial institutions in the DACH region. Germany, Austria and Switzerland combine deep capital markets, dense supervisory practice and high cross-border integration (European Central Bank 2024; Bank for International Settlements 2025; Swiss State Secretariat for International Finance (SIF) 2025). Institutions operate under comparable prudential expectations and reporting cultures: Germany and Austria within the EU prudential framework, Switzerland through equivalence-based alignment in selected domains. This convergence provides a coherent testing ground, supporting methodological consistency while enabling meaningful comparison across jurisdictions (Regulation (EU) No 575/2013 on Prudential Requirements for Credit Institutions and Investment Firms (CRR) 2013; Directive 2013/36/EU on Access to the Activity of Credit Institutions and the Prudential Supervision of Credit Institutions (CRD) 2013; Commission Implementing Regulation (EU) 2021/451 Laying down ITS for Supervisory Reporting Under the CRR 2021; European Commission 2025; Swiss State Secretariat for International Finance (SIF) 2025). For the purposes of this study, financial institutions are defined as supervised entities that accept deposits or other repayable funds, extend credit or investment services, insure or reinsure risk, manage collective assets, operate payment or settlement systems, or run market infrastructure. (Regulation (EU) No 575/2013 on Prudential Requirements for Credit Institutions and Investment Firms (CRR) 2013; Directive 2014/65/EU on Markets in Financial Instruments (MiFID II) 2014; Directive 2009/138/EC on the Taking-up and Pursuit of the Business of Insurance and Reinsurance (Solvency II) 2009; Directive 2009/65/EC on Undertakings for Collective Investment in Transferable Securities (UCITS) 2009; Directive 2011/61/EU on Alternative Investment Fund Managers (AIFMD) 2011; Directive (EU) 2015/2366 on Payment Services in the Internal Market (PSD2) 2015; Regulation (EU) No 648/2012 on OTC Derivatives, Central Counterparties and Trade Repositories (EMIR) 2012; Regulation (EU) No 909/2014 on Improving Securities Settlement in the European Union and on Central Securities Depositories (CSDR) 2014; Regulation (EU) No 600/2014 on Markets in Financial Instruments (MiFIR) 2014). Within the prudential perimeter, the taxonomy distinguishes credit institutions and banks under CRR/CRD, investment firms under MiFID II, insurance and reinsurance under Solvency II, asset managers under UCITS and AIFMD, and market infrastructures such as trading venues, CCPs and CSDs under MiFIR, EMIR and CSDR. Payment and e-money institutions fall under PSD and EMD (Regulation (EU) No 575/2013 on Prudential Requirements for Credit Institutions and Investment Firms (CRR) 2013; Directive 2013/36/EU on Access to the Activity of Credit Institutions and the Prudential Supervision of Credit Institutions (CRD) 2013; Directive 2014/65/EU on Markets in Financial Instruments (MiFID II) 2014; Regulation (EU) No 600/2014 on Markets in Financial Instruments (MiFIR) 2014; Directive 2009/138/EC on the Taking-up and Pursuit of the Business of Insurance and Reinsurance (Solvency II) 2009; Regulation (EU) No 648/2012 on OTC Derivatives, Central Counterparties and Trade Repositories (EMIR) 2012; Regulation (EU) No 909/2014 on Improving Securities Settlement in the European Union and on Central Securities Depositories (CSDR) 2014; Directive (EU) 2015/2366 on Payment Services in the Internal Market (PSD2) 2015; Directive 2009/110/EC on the Taking up, Pursuit and Prudential Supervision of the Business of Electronic Money Institutions (EMD II) 2009; Directive 2009/65/EC on Undertakings for Collective Investment in Transferable Securities (UCITS) 2009; Directive 2011/61/EU on Alternative Investment Fund Managers (AIFMD) 2011). A functional taxonomy complements this perimeter by grouping front-office decisioning and advisory, treasury and risk, payments and settlement, compliance and reporting, and back-office operations. Outsourcing and critical ICT providers enter scope where the ICT risk framework applies (Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector (DORA) 2022). European financial services are governed by an extensive regulatory corpus. The EU acquis sets binding requirements on prudential soundness, market conduct and investor protection through CRR/CRD, MiFID II and MiFIR, Solvency II, EMIR and CSDR, PSD and EMD, AML directives, MiCA, DORA and GDPR (Regulation (EU) No 575/2013 on Prudential Requirements for Credit Institutions and Investment Firms (CRR) 2013; Directive 2013/36/EU on Access to the Activity of Credit Institutions and the Prudential Supervision of Credit Institutions (CRD) 2013; Directive 2014/65/EU on Markets in Financial Instruments (MiFID II) 2014; Regulation (EU) No 600/2014 on Markets in Financial Instruments (MiFIR) 2014; Directive 2009/138/EC on the Taking-up and Pursuit of the Business of Insurance and Reinsurance (Solvency II) 2009; Regulation (EU) No 648/2012 on OTC Derivatives, Central Counterparties and Trade Repositories (EMIR) 2012; Regulation (EU) No 909/2014 on Improving Securities Settlement in the European Union and on Central Securities Depositories (CSDR) 2014; Directive (EU) 2015/2366 on Payment Services in the Internal Market (PSD2) 2015; Directive 2009/110/EC on the Taking up, Pursuit and Prudential Supervision of the Business of Electronic Money Institutions (EMD II) 2009; Directive (EU) 2015/849 on the Prevention of the Use of the Financial System for the Purposes of Money Laundering or Terrorist Financing (4AMLD) 2015; Directive (EU) 2018/843 Amending Directive (EU) 2015/849 (5AMLD) 2018; Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA) 2023; Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector (DORA) 2022; Regulation (EU) 2016/679 on the Protection of Natural Persons with Regard to the Processing of Personal Data (GDPR) 2016). These instruments specify licensing, governance, outsourcing, logging, testing, resilience and data protection duties, and enable passporting across the single market (Directive 2013/36/EU on Access to the Activity of Credit Institutions and the Prudential Supervision of Credit Institutions (CRD) 2013; European Securities and Markets Authority 2023a, 2023b; Commission Delegated Regulation (EU) 2017/565 Supplementing Directive 2014/65/EU 2017; Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector (DORA) 2022; Regulation (EU) 2016/679 on the Protection of Natural Persons with Regard to the Processing of Personal Data (GDPR) 2016; European Banking Authority 2024a). Supervised firms must evidence compliance through internal control systems, audit trails and supervisory reporting (Directive 2009/138/EC on the Taking-up and Pursuit of the Business of Insurance and Reinsurance (Solvency II) 2009; European Securities and Markets Authority 2023a; Commission Delegated Regulation (EU) 2017/565 Supplementing Directive 2014/65/EU 2017; Commission Implementing Regulation (EU) 2021/451 Laying down ITS for Supervisory Reporting Under the CRR 2021). The DACH region presents a coherent yet diverse regulatory landscape. Germany applies EU law through national instruments such as the Kreditwesengesetz (KWG) and Wertpapierhandelsgesetz (WpHG) under BaFin supervision (Gesetz Über Das Kreditwesen (KWG) 2025; Wertpapierhandelsgesetz (WpHG) 2025; BaFin 2019). Austria implements EU law through the Bankwesengesetz (BWG) and Wertpapieraufsichtsgesetz 2018 (WAG 2018) under FMA supervision (Bankwesengesetz (BWG) 2025; Finanzmarktaufsicht (FMA) 2024, 2025). Switzerland enforces FinSA and FinIA with FINMA, framed by EU equivalence decisions and bilateral arrangements (Federal Act on Financial Services (FinSA) 2024; Federal Act on Financial Institutions (FinIA) 2024; FINMA 2025; European Commission 2025; Swiss State Secretariat for International Finance (SIF) 2025). The region’s institutional scale and diversity are material: universal banks, savings and cooperative networks, global insurers, specialised asset managers and market utilities operate under comparable supervisory expectations, while preserving sufficient heterogeneity to test generality (European Central Bank 2024; EFAMA 2025). Burden asymmetries persist: in Austria, smaller firms bear proportionally higher fixed compliance costs, with studies documenting that regulatory obligations weigh more heavily on them than on larger institutions (European Investment Bank 2025; Financial Stability Board 2019; Financial Stability Institute 2018; Kurz et al. 2025).
Contribution
Current compliance mechanisms in financial institutions remain predominantly ex-post: obligations are verified through periodic audits, reconciliations, and manual attestations, while system execution itself proceeds without embedded regulatory constraints. This approach creates structural gaps, since audit trails can be incomplete, supervisory checks are delayed, and interpretations of legal texts remain siloed across departments. Controls are reactive rather than preventative, and compliance risk accumulates in the time between transaction and inspection. Addressing these deficiencies requires a design in which regulatory duties are formalised as machine-checkable constraints and enforced as part of orchestration and execution rather than appended as a reporting layer. This research develops an enterprise reference architecture for a tiered, compliant AI system in finance, aligned with the regulatory taxonomy and supervisory context of the DACH region yet transferable across the EU. The architecture encodes regulatory duties as machine-checkable constraints and binds them to orchestration and execution. A policy store and rule engine compile EU and DACH requirements into checks enforced both before and during execution. Multi-agent coordination is role scoped across institutional and consumer tiers, with explicit permissions, explainability thresholds and segregation of duties. Gated execution ensures that sensitive actions, such as order placement, occur only under dual control, and every step produces audit-ready evidence. Verification is achieved through a permissioned distributed ledger that employs a directed acyclic graph (DAG) for deterministic timestamping and inclusion proofs. The ledger captures routing instructions, budget usage and control attestations without imposing settlement semantics on application workflows. Decisions are formulated as objectives under constraints, with runtime budgets for risk, latency and ESG, enabling transparent trade-offs at schedule time. The architecture remains technology-agnostic at model level and interoperable with existing systems via supervised queues and APIs. In this way, it provides a reference design that meets supervisory expectations in DACH while supporting broader applicability across EU jurisdictions.
System Architecture
The proposed system architecture embeds regulatory compliance as a first-class design primitive rather than an external audit layer added post hoc. Orchestration and execution are bounded by machine-enforceable constraints compiled directly from legal provisions, ensuring that system behaviour remains verifiable at run time. The architecture is tiered across institutional and consumer contexts, portable across jurisdictions, and agnostic to specific model technologies. Its emphasis lies on properties that supervisory authorities recognise as audit-ready: determinism of execution, separation of roles, and transparent evidence generation. A distinctive element of the design is the integration of a permissioned distributed ledger that employs a directed acyclic graph (DAG) structure to anchor audit trails. Each agent action, constraint evaluation, and gating decision is recorded as a tamper-evident event with deterministic timestamping and inclusion proofs. Unlike traditional logging, which remains vulnerable to post-processing or selective disclosure, the DAG ledger produces an immutable sequence of verifiable attestations that can be inspected by internal control functions and supervisory authorities. The ledger is deliberately lightweight: it does not impose settlement semantics on application workflows but serves solely as a compliance substrate, capturing routing instructions, evidence packs, and oversight signatures. This enables continuous assurance without altering financial transaction flows.
Agnostic Regulatory Intent and Exposure Matrix
European financial regulation is dense and layered across prudential, conduct, market integrity, data protection and ICT risk instruments. Designing an enterprise system by listing acts and articles provides little direct operational guidance. To address this, we introduce a regulation-agnostic taxonomy that functions as a design primitive. Its purpose is to translate legal text into machine-enforceable control functions that govern orchestration and execution while remaining portable across DACH and the wider EU. We adopt a functional reduction of legal provisions to their operational effect on system behaviour: either a rule forbids an outcome or it demands an outcome with evidence. Compliance therefore reduces to abstention from a prohibited act or to the performance of a positive act that leaves a verifiable trace. This yields a law- and regulation-agnostic orientation in which agents need only decide whether to avoid or to act with evidence, while the specific statutory text is compiled at a later stage into guard families and evidence templates, with exposure handled separately for internal versus external outputs. Practically, this agnostic treatment simplifies handling heterogeneous regulations because the agent can synthesise, per task and context, a checklist of prohibitions and obligations that orchestration executes and tracks, with each item either preventing externalisation or requiring a verifiable artefact with provenance, deterministic timestamping and DAG inclusion proof; alternatively a dedicated compliance agent can apply the same checklist as a pre-output gate, sign the evidence pack, and authorise or withhold release.1 The taxonomy is formalised as a two-dimensional schema, the Regulatory Intent and Exposure Matrix. Each legal provision receives two labels rule type, capturing intent as either Prohibition or Obligation, and exposure, capturing context as Internal or External.
This binary mapping is used for orientation in reasoning and as a compact handle for later compilation, as shown in Figure 1.
Figure 1 frames two reasoning stances rather than execution rules. A Prohibition prompts scrutiny of potentially disallowed behaviour and a hold on externalisation until resolved. An Obligation prompts identification of duties and anticipation of evidence likely required if the task proceeds. Clauses are stored as atomic statements with mapping and citation to ensure fast reading and consistent interpretation. Concrete gates and logging are derived later once reasoning has reached sufficient confidence.
The second axis classifies exposure. Internal exposure refers to outputs confined to the institution, while external exposure refers to outputs delivered to clients, counterparties, authorities or markets. The distinction is contextual and combines with intent in Figure 2.
This classification orients reasoning by establishing the destination of outputs. Once combined with intent, it guides which questions and candidate actions are relevant. Figure 3 presents the joint view.
At run time an agent performs a lightweight context check against the proposed matrix. If no mapped provision appears to apply, the agent continues under general IT controls and ordinary policy. If the check suggests applicability, the agent classifies the context using the matrix labels and treats that label as an orientation handle for reasoning rather than as an enforcement command, subject to revision as scope and evidence evolve. The context check can be formalised as a binary predicate that determines whether a task falls under a mapped legal provision:
Once classified, the agent frames the task as a constrained optimisation problem of the form
Minting the classification, checklist and gating decisions to the DAG enables ex post assurance and explicit failure analysis: an auditor can reconstruct the task state (see Eq. 5), recompute (see Eq. 2) and the label (see Eq. 1) to test whether the agent misunderstood the context, verify that each selected guard in the optimisation constraint (see Eq. 3) was satisfied at the moment of externalisation, and match every obligation item to a concrete artefact with provenance, deterministic timestamping and inclusion proof; this makes distinct failure modes observable, including (i) misclassification of intent or exposure, (ii) correct classification and checklist generation but incomplete execution, (iii) execution with insufficient evidence quality or missing signatures, and (iv) sequencing or gating errors that allowed externalisation without preconditions, as well as budget breaches for risk, latency or ESG. The proposal turns compliance from after-the-fact attestation into assurance-by-construction, where reasoning, decisions and evidence are bound cryptographically so reviewers can check not only outcomes but also whether the agent’s understanding and follow-through were correct.
We propose a short, curated aid for cases where the context check indicates applicability. A quick reference vector is a concise entry prepared by a qualified oversight committee; it orients reasoning without prescribing execution. Each entry names the action archetype, states the typical matrix label, notes salient triggers and the initial evidence posture, and gives an escalation contact. Entries are versioned and signed so that provenance remains clear; they can be revised as scope or information changes. When a task matches such an entry, the agent adopts the entry as orientation and continues analysing the task toward the decision objective; if no entry fits, the agent proceeds under baseline controls and may flag the gap for later inclusion. The intent is speed and consistency in judgement, not hard rules.
Prohibitions as feasibility and obligations as task extension
The matrix provides orientation only; concrete enforcement is selected later by policy compilation and may be revised by human oversight. Given the label from Eq. 1 and the context determined by the predicate in Eq. 2, the rule engine surfaces candidate prohibitions and obligations , then selects active subsets and together with a strict partial order over . The order permits short-circuit evaluation where appropriate and defines a narrow top tier of dominant disqualifiers. Obligations map to mandatory sub-actions and a verifiable evidence artefact; let denote the admissibility predicate capturing provenance, signatures, deterministic timestamping and DAG inclusion proof. None of these selections is implied by the matrix itself; the matrix narrows the search space, the policy store determines activation.
Prohibitions are encoded as feasibility constraints that prevent disallowed outcomes, while obligations extend the task with preconditions that must hold before optimisation under Eq. 3 is meaningful. The feasible policy set for task is
with optional secondary terms in for obligation quality such as latency, cost or completeness. This construction preserves the law- and regulation-agnostic stance: prohibitions shape the admissible set, obligations extend the task graph and demand admissible artefacts, and any burden from satisfying obligations may then be traded within the objective once feasibility is secured.
Externalisation refers to any output that leaves the institutional boundary, including recommendations, orders, client-facing summaries, supervisory reports and API calls, whereas internal artefacts, logs and operator messages remain non-external unless later reused. The gate outcome formalises block versus release for a proposed output , $$\begin{equation} \mathrm{Externalise}(\pi,\tau)= \begin{cases} \textsc{deny}(c) & \text{if }\exists p\in P^{\star}\text{ with }p(\pi,\tau)=1\ \ \text{or}\ \ \exists o\in O^{\star}\text{ with }E(\mathrm{artefact}_o(\tau))=\text{false},\\[4pt] \textsc{allow}(y) & \text{otherwise,} \end{cases} \label{eq:externalise} \end{equation}$$ where is a machine- and human-readable reason code minted to the DAG with a hold or release attestation. Blocking does not suppress internal reasoning; the system returns an explicit explanation to operators and records the decision and grounds for audit.
Short-circuit evaluation reduces latency and user friction without sacrificing assurance. If there exists a dominant disqualifier with , then $\mathrm{Externalise}(\pi,\tau)=\textsc{deny}(c)$ by Eq. 8 and the remaining lower-tier checks in are marked skipped by policy. The audit pack minted to the DAG includes the orientation set, the selected , the order , the firing guard in , the skipped set with its policy basis, all artefact hashes and admissibility outcomes , and the reason code . This enables an auditor to reconstruct the state used in the quick-reference matching Eq. 5, to verify that the selected guards in the optimisation constraint Eq. 3 were satisfied at the moment of externalisation, and to distinguish failure modes such as misclassification, incomplete execution of obligations, insufficient evidence quality, or sequencing errors that allowed externalisation without preconditions.
A composite example illustrates the semantics. Consider a cross-border retail transaction where the amount exceeds the threshold for retail investors and the client is under age. Orientation via surfaces multiple candidates; policy selects that includes an under-age prohibition and places it in under . The under-age guard fires, so $\mathrm{Externalise}(\pi,\tau)=\textsc{deny}(c)$ by Eq. 8; cross-border and amount checks are skipped by policy with the dominance certificate recorded in the audit pack. If, in a different context, no dominant disqualifier fires, obligations such as identification and know-your-customer documentation become active preconditions, and externalisation is permitted only once admissibility holds, after which utility is optimised over according to Eq. 7. In both cases the matrix remains an orientation device; selection and activation are determined by compiled policy and oversight, and the full reasoning trail is minted to the DAG for ex post assurance.
We assume only mild regularity, namely that dominant disqualifiers in remain policy invariant for a given task state, so that holds for all ; in practice these include conditions such as age thresholds, sanctions hits, or bans tied to specific product tiers. The admissibility predicate is used to capture evidence quality requirements, including provenance, signatures, deterministic timestamping, and DAG inclusion, and is evaluated directly on the artefacts compiled for .
Under these assumptions the feasible set is monotone: if the selected sets expand such that and , then it follows that , where is defined by Eq. 6 under the selection . The result follows immediately from Eq. 6, since adding further prohibitions or obligations introduces additional conjuncts that can only reduce the satisfying set.
Short-circuit evaluation is sound whenever dominant checks are policy invariant: if a single evaluates to one for some , then it evaluates to one for all , which implies by Eq. 6 and forces $\mathrm{Externalise}(\pi,\tau)=\textsc{deny}(c)$ by Eq. 8. Conversely, if no element of fires and all selected obligations satisfy admissibility so that , then remains nonempty and the optimisation problem in Eq. 7 is well defined. Evaluation both terminates and remains auditable. Since the sets are finite and is a strict partial order, a topological evaluation sequence necessarily exists, with short-circuiting at further bounding runtime. The DAG record contains the orientation set, the selected , the order , any firing element of , the admissibility outcomes , and the resulting gate decision Eq. 8, which together enable replay and independent re-evaluation using Eq. 2, Eq. 1, Eq. 6 and Eq. 3.
If obligation quality is intended to influence the objective once feasibility has been established, the framework admits a straightforward refinement in which , with aggregating latency, cost, and completeness across satisfied obligations and denoting policy weights. The lexicographic regime in Eq. 7 guarantees that such trade-offs are only evaluated within the feasible set .
Agent activation by intent and exposure
The orientation matrix provides the initial signal, but the selection and activation of executors is determined by compiled policy and remains subject to oversight revision. Institutions may maintain standing rosters of domain-specific agents and persistent committees for recurring functions, while reserving the possibility of ad hoc committees when context requires. In a banking environment, a payments roster typically spans functions such as wiring funds between accounts, executing foreign-exchange conversions, and arranging treasury transfers. For an investment firm under MiFID II, routine activities encompass the reception and transmission of client orders, order execution on behalf of clients, the provision of investment advice with suitability and appropriateness checks, portfolio management, and post-trade reporting. These rosters remain dormant until activated by the orientation label from Eq. 1 in combination with the context check defined in Eq. 2. Committee formation follows a policy-driven logic. Where or the task is assessed as internal and low risk, such as drafting an internal email or scheduling a meeting, a single role-scoped agent executes under baseline IT controls. When , activation depends on the exposure level , the number and dominance of active checks, and the availability of runtime budgets. This is formalised as
Execution proceeds through a structured handshake. The orchestration agent forwards the task together with the orientation to the designated agent set or committee, which undertakes its domain-specific responsibilities and returns artefacts, rationales, and provisional outcomes. A dedicated compliance agent then applies the pre-output gate defined in Eq. 8; if admissibility is confirmed for all selected obligations and no prohibition fires, the output is released, whereas any failure results in blocked externalisation accompanied by a reason code. Each stage mints a committee token to the DAG ledger, recording membership, role scopes, selected checks, reason codes, and inclusion proofs, which collectively support later reconstruction and independent re-evaluation under Eq. 3.
Examples illustrate proportionality and dominance. A domestic, low-value internal transfer with is executed by a single payments agent without committee escalation, reflecting the proportionality condition that internal exposure with few selected checks below the policy threshold activates only the primary role. A cross-border retail securities order with and activates the standing “securities orders” set comprising client categorisation and suitability, order execution, best-execution monitoring, and transaction reporting; if a dominant disqualifier in , such as an under-age client, fires, the committee collapses to the compliance gate and the externalisation returns $\textsc{deny}(c)$ under Eq. 8, with all skipped checks logged as skipped by policy. Formally,
Legal corpus indexing and agent routing
The legal corpus is treated as a structured, versioned asset rather than a flat vector space. Each instrument is normalised, segmented, and cited at clause level, with every chunk carrying canonical metadata , where encodes version and effective interval, supplemented by tags for instrument class (prudential, conduct, data protection, ICT), intent and exposure labels, and explicit cross-references. Ingestion preserves both the original language and a controlled translation, while recording equivalence mappings between recitals, articles, RTS/ITS, and supervisory Q&A, so that downstream retrieval can resolve different references to a single, time-scoped citation.
Indexing is hybrid in order to preserve meaning as well as citations. Three coordinated views are maintained for the same chunks: a dense semantic index for embeddings , a sparse citation and keyword index for exact retrieval, and a citation graph linking instruments through “refers to,” “implements,” and “interprets” edges. Queries are constructed from task features , the orientation from Eq. 1, triggers from the quick-reference vector Eq. 4, and the exposure . Retrieval proceeds in two stages: a semantic pre-filter selects top- candidates by similarity under jurisdiction and effective-date filters, and a reranker then fuses sparse scores with graph proximity to produce the final set . Every returned item includes together with its text span, ensuring human-readable grounding.
Clustering is dual to reflect legal reading practice. We compute instrument-anchored clusters for each statute or linked set of acts, and aspect clusters derived from the citation graph and tag distributions, covering recurring themes such as suitability, client categorisation, personal recommendations, onboarding, and record-keeping. Chunks may appear in both views. Aspect clusters allow rapid coverage across instruments, while instrument clusters ensure that the exact article and paragraph remain available for citation and audit. The design avoids reliance on a single global cluster.
Routing is performed by capability rather than by statute. Institutions register domain agents with declared capabilities and evidence schemas, covering for example payments, FX, treasury, onboarding, suitability and appropriateness, personal recommendations, order execution, reporting, data protection, and ICT controls. Orientation , exposure , and the retrieved set jointly determine which capability bundles are relevant. The router applies the same selection logic as Eq. 9 to activate either a single role or a minimal committee. A dedicated citation clerk agent attaches and extracts the governing spans, while a compliance agent executes the pre-output gate Eq. 8. This design keeps knowledge current and avoids brittle “one agent per law” silos.
Correlation between chunks and their governing law is guaranteed through metadata rather than embeddings. Each chunk carries its canonical citation, effective dates, and instrument identifiers (e.g. CELEX for EU acts, BaFin circular IDs, FINMA RS numbers). When retrieval proposes candidates, a citation-consistency check eliminates items whose lies outside the jurisdiction or effective interval of the task, and a majority-vote over top- candidates stabilises the legal basis. The resulting citation pack is signed by the citation clerk and minted to the DAG.
Mapping legal text to matrix intent and exposure constitutes orientation rather than determination. A curator-assisted classifier proposes for each chunk, with all proposals reviewed and versioned. At run time the router applies together with context to select and the order (cf. Eq. 6, Eq. 7), while concrete guard templates and artefact schemas are compiled from the policy store. The complete retrieval and routing trace is minted to the DAG alongside the gate result, enabling replay and auditor verification.
This design addresses practical concerns. Legal aspects are not collapsed into a single global cluster but organised into multiple coordinated views. Agents are not tied one-to-one with statutes but are registered by capability and routed according to orientation and retrieved evidence. Correlation between chunks and laws is secured by canonical citations and effective dates rather than embedding heuristics. The outcome is portable across jurisdictions, resilient to textual drift, and ready for supervisory scrutiny.
Evidence admissibility model
Admissibility must be explicit to ensure that obligation checks in Eq. 6–Eq. 7 are verifiable at run time and reproducible on audit. Each obligation is modelled as producing an artefact bundle
The admissibility predicate is defined as the conjunction of policy-specified quality dimensions,
Let denote a collision-resistant digest and a trusted timestamp. A minimal admissible bundle must then satisfy
Policy compilation and governance
The orientation matrix provides the initial signal, while policy compilation determines the active checks. Given the label from Eq. 1 and the task context from Eq. 2, a compiler maps orientation and context into selected guards and their evaluation order, subject to human oversight and revision. The policy store is a versioned, time-scoped rule base with effective intervals, reviewer sign-off, and rollback support.
Compilation is modelled as a deterministic function of the effective policy version at decision time :
Budgets operate both at compile time and at run time. A budget-breach predicate informs committee activation in Eq. 9 and the externalisation gate in Eq. 8:
Obligation templates are bound to admissibility during compilation. For each , the compiler selects an evidence schema and admissibility test from Eq. 13, producing a concrete template for with required provenance, signatures, trusted time, and DAG inclusion. The feasible set Eq. 6 and optimisation Eq. 7 then operate over these compiled guards rather than the full candidate space.
Governance ensures reproducibility and institutional control. Each compilation yields a certificate
Overrides are permitted under controlled conditions. An authorised reviewer may issue that modifies with reason code and dual control. Safety monotonicity applies to dominant prohibitions: if and , the override cannot deactivate when exposure is external ; any attempted weakening is logged and forces $\textsc{deny}(c)$ under Eq. 8. Strengthening is always admissible, while removal of non-dominant checks requires reviewer signatures and the issuance of a new certificate version .
Determinism and time anchoring close the loop. The compiler is deterministic given , and any change in output is attributable to context updates, policy version changes, or time-scoped rule amendments. Trusted time binds both and to replayable evidence via Eq. 14. The result is a governance process that integrates admissibility, feasibility, committee formation, and externalisation, while keeping the orientation matrix as a guidance device rather than a source of hard-coded execution rules.
Stylised simulation pseudocode
The following pseudocode illustrates a pass through context detection, policy compilation, dominant disqualifier short-circuiting, admissibility checks, and the externalisation gate defined in Equation Eq. 8.
Input: task , context, candidate policy set , policy version , time MINT_DAG(, decision = “allow_internal”) allow_internal MINT_DAG(, decision = “deny”, reason = “budget breach”) deny(reason = “budget breach”) MINT_DAG(, decision = “deny”, reason = “dominant prohibition”) deny(reason = “dominant prohibition”) (continued on next page)
MINT_DAG(, decision = “deny”, reason = “inadmissible obligation”, failed = ) deny(reason = “inadmissible obligation”) MINT_DAG(, decision = “deny”, reason = “no feasible policy”) deny(reason = “no feasible policy”) MINT_DAG(, decision = “allow”, output = ) allow(output from )
This pseudocode shows how the system detects applicability, assigns the orientation label, compiles policy deterministically, short-circuits on dominant disqualifiers, evaluates admissibility for obligation artefacts, optimises over the feasible set defined by Eq. 6–Eq. 7, executes the externalisation gate Eq. 8, and records every decision path by minting a replayable, time-bound audit pack.
Discussion
The architecture treats regulatory constraints as first-class objects while preserving the distinction between orientation and determination. The matrix provides a compact label for classification and routing, while policy compilation selects and orders prohibitions and obligations subject to possible revision through oversight. Compliance is operationalised through feasibility and admissibility as defined in Eq. 6, Eq. 7, and Eq. 8, with every obligation bound to trusted time and anchored on a permissioned DAG to ensure replayability, provenance validation, and clear attribution of failure. A central benefit arises from the separation of concerns. Orientation remains stable and portable across jurisdictions, whereas activation is institution specific through the policy store and its governance processes. Prohibitions do not trade against utility, and obligations extend the task with artefacts that must satisfy the admissibility predicate defined in Eq. 13. Committee activation under Eq. 9 ensures proportionality, while short-circuiting of dominant checks formalised in Eq. 11 reduces latency without compromising the completeness of audit trails. There are trade-offs. Misclassification or an excessively broad dominance set may lead to false blocks, while incomplete policy stores can result in false releases. The legal index and the intent–exposure mapping therefore require continuous curation with versioning and reviewer sign-off. Privacy constraints further limit what can be anchored on the ledger; hashes and metadata are sufficient for attestation, but disciplined key management and controlled storage are required for raw artefacts. Determinism also relies on stable time sources and reproducible compilation given . The scope of the design is clearly delimited. It does not replace legal interpretation or product governance but instead provides an executable substrate that is law- and regulation-agnostic at the orientation layer and institution specific at the activation layer. Portability across DACH and the wider EU follows directly from this separation, since only compilation rules and evidence templates vary with local implementation.
Conclusion
The paper advances a compliance-first architecture that positions regulation as an orientation layer rather than a deterministic ruleset. The Regulatory Intent and Exposure Matrix provides the compact handle for classification and routing, while execution is delegated to a governed policy compiler. Prohibitions constrain feasibility through the admissible set in Eq. 6 and block externalisation via Eq. 8. Obligations extend tasks with admissible artefacts that must satisfy the predicate in Eq. 13. Optimisation then proceeds over under lexicographic semantics in Eq. 7. Proportionality follows from policy-driven committee activation in Eq. 9, while dominance rules in Eq. 11 enable early termination without compromising audit completeness. Evidence, decisions and reason codes are bound to a permissioned DAG with deterministic timestamping, ensuring replayability, provenance checks and precise failure attribution. Portability across DACH and the wider EU results from the separation between orientation and activation, a clause-level indexed legal corpus, and capability-based agent routing. The architecture transforms compliance from retrospective attestation into assurance by construction, offering a generalisable design pattern that remains law- and regulation-agnostic at the orientation layer while retaining institution-specific control at activation.
Limitations and Future Research
Several limitations remain. The design depends on curated mappings from legal text to orientation and on the integrity of policy compilation; drift or gaps can cause false blocks or unintended releases. Formal guarantees for compiler determinism and reproducibility under require explicit proof obligations and differential testing. The admissibility predicate must be calibrated to institutional standards for provenance, signatures, trusted time and retention, and cryptographic choices and key management directly affect audit reliability. Ledger privacy remains constrained by linkage risks across hashes and metadata, and selective disclosure, salting and zero-knowledge proofs warrant further evaluation. Institutional dependencies also arise. Externalisation boundaries can shift when internal artefacts are reused in external contexts, which necessitates systematic exposure re-checks and reuse monitors. Committee thresholds and runtime budgets determine latency and cost, so empirical calibration, red-teaming and scenario replay are needed to quantify trade-offs and client impact. Retrieval robustness relies on similarity functions, feature maps and citation consistency, suggesting the need for adversarial tests and benchmarks specific to legal retrieval. Human and governance factors remain material. Curation of the legal index and the intent–exposure mapping requires ongoing reviewer effort with versioning and sign-off. Reviewer workload, override workflows and reason-code clarity all influence governance quality and practical adoption. Future research will extend evaluation on institution-specific scenarios in DACH, develop auditor-facing query suites tied to Eq. 2, Eq. 1, Eq. 6, Eq. 13 and Eq. 8, and investigate privacy-preserving ledger designs and time-binding mechanisms that improve verifiability without undermining data minimisation.
It should also be noted that empirical evaluation at meaningful scale would require full system deployment across institutional and regulatory contexts, which entails investments beyond the scope of academic research. Smaller prototypes would not capture the systemic properties of budget enforcement, admissibility, or externalisation, and could therefore provide misleading evidence. For this reason, the present contribution is deliberately theoretical and algorithmic: it establishes the formal and operational basis on which future large-scale empirical work can be responsibly pursued.
A prohibition can be illustrated with a consumer-tier agent that is not permitted to instruct a client to purchase a particular security or to transmit an order on their behalf without their permission. In this case the guard blocks both recommendation and order externalisation, recording at most a hold or release attestation on the DAG ledger. An obligation is exemplified by onboarding procedures, which require identification and know-your-customer documentation. Here the workflow executes the prescribed checks and generates a signed artefact with provenance metadata, deterministic timestamping, and a DAG inclusion proof before any advisory or execution services can be activated.↩︎