Swissi Institute for AI

ForschungFachartikelAugust 2025

Tiered compliant AI system for regulated financial institutions

Multi agentic execution capable framework with built in DLT audit trails for financial operations in DACH

Walter Kurz, Reinhard Magg

Swissi Institute for AI

Zitieren als:
Kurz, W., & Magg, R. (2025). Tiered compliant AI system for regulated financial institutions: Multi agentic execution capable framework with built in DLT audit trails for financial operations in DACH. Swissi Institute for AI. https://swissi-ai.institute/de/research/fina-ai

Zusammenfassung

Regulation is treated as an orientation layer rather than a deterministic ruleset: a matrix of regulatory intent and exposure is compiled into concrete prohibitions, obligations and runtime budgets. Evidence, decisions and reason codes bind to a permissioned DAG, so a supervisor can replay how an outcome was reached and attribute failure.

Schlagwörter:
  • DACH finance
  • regulated financial institutions
  • multi agent expert system
  • policy compiled orchestration
  • objective under constraints
  • permissioned DLT
  • DAG timestamping
  • audit trails
  • EU AI Act
  • MiFID II
  • DORA
  • GDPR
  • human oversight
  • execution gating
  • ESG budgets
  • verification and assurance

Introduction

The financial industry combines data intensity, complex decision processes and strict regulatory oversight, making it a natural environment for the application of artificial intelligence. Yet the adoption of AI in this domain is constrained by the absence of architectures that meet supervisory expectations for accountability, resilience and auditability. Existing implementations often prioritise performance or innovation at the expense of compliance, leaving institutions without frameworks that can be both operationally effective and regulatorily sound. This study addresses that gap by proposing a reference architecture for compliant AI in finance, designed to integrate supervisory requirements into system design from the outset. The analysis focuses on financial institutions in the DACH region. Germany, Austria and Switzerland combine deep capital markets, dense supervisory practice and high cross-border integration (European Central Bank 2024; Bank for International Settlements 2025; Swiss State Secretariat for International Finance (SIF) 2025). Institutions operate under comparable prudential expectations and reporting cultures: Germany and Austria within the EU prudential framework, Switzerland through equivalence-based alignment in selected domains. This convergence provides a coherent testing ground, supporting methodological consistency while enabling meaningful comparison across jurisdictions (Regulation (EU) No 575/2013 on Prudential Requirements for Credit Institutions and Investment Firms (CRR) 2013; Directive 2013/36/EU on Access to the Activity of Credit Institutions and the Prudential Supervision of Credit Institutions (CRD) 2013; Commission Implementing Regulation (EU) 2021/451 Laying down ITS for Supervisory Reporting Under the CRR 2021; European Commission 2025; Swiss State Secretariat for International Finance (SIF) 2025). For the purposes of this study, financial institutions are defined as supervised entities that accept deposits or other repayable funds, extend credit or investment services, insure or reinsure risk, manage collective assets, operate payment or settlement systems, or run market infrastructure. (Regulation (EU) No 575/2013 on Prudential Requirements for Credit Institutions and Investment Firms (CRR) 2013; Directive 2014/65/EU on Markets in Financial Instruments (MiFID II) 2014; Directive 2009/138/EC on the Taking-up and Pursuit of the Business of Insurance and Reinsurance (Solvency II) 2009; Directive 2009/65/EC on Undertakings for Collective Investment in Transferable Securities (UCITS) 2009; Directive 2011/61/EU on Alternative Investment Fund Managers (AIFMD) 2011; Directive (EU) 2015/2366 on Payment Services in the Internal Market (PSD2) 2015; Regulation (EU) No 648/2012 on OTC Derivatives, Central Counterparties and Trade Repositories (EMIR) 2012; Regulation (EU) No 909/2014 on Improving Securities Settlement in the European Union and on Central Securities Depositories (CSDR) 2014; Regulation (EU) No 600/2014 on Markets in Financial Instruments (MiFIR) 2014). Within the prudential perimeter, the taxonomy distinguishes credit institutions and banks under CRR/CRD, investment firms under MiFID II, insurance and reinsurance under Solvency II, asset managers under UCITS and AIFMD, and market infrastructures such as trading venues, CCPs and CSDs under MiFIR, EMIR and CSDR. Payment and e-money institutions fall under PSD and EMD (Regulation (EU) No 575/2013 on Prudential Requirements for Credit Institutions and Investment Firms (CRR) 2013; Directive 2013/36/EU on Access to the Activity of Credit Institutions and the Prudential Supervision of Credit Institutions (CRD) 2013; Directive 2014/65/EU on Markets in Financial Instruments (MiFID II) 2014; Regulation (EU) No 600/2014 on Markets in Financial Instruments (MiFIR) 2014; Directive 2009/138/EC on the Taking-up and Pursuit of the Business of Insurance and Reinsurance (Solvency II) 2009; Regulation (EU) No 648/2012 on OTC Derivatives, Central Counterparties and Trade Repositories (EMIR) 2012; Regulation (EU) No 909/2014 on Improving Securities Settlement in the European Union and on Central Securities Depositories (CSDR) 2014; Directive (EU) 2015/2366 on Payment Services in the Internal Market (PSD2) 2015; Directive 2009/110/EC on the Taking up, Pursuit and Prudential Supervision of the Business of Electronic Money Institutions (EMD II) 2009; Directive 2009/65/EC on Undertakings for Collective Investment in Transferable Securities (UCITS) 2009; Directive 2011/61/EU on Alternative Investment Fund Managers (AIFMD) 2011). A functional taxonomy complements this perimeter by grouping front-office decisioning and advisory, treasury and risk, payments and settlement, compliance and reporting, and back-office operations. Outsourcing and critical ICT providers enter scope where the ICT risk framework applies (Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector (DORA) 2022). European financial services are governed by an extensive regulatory corpus. The EU acquis sets binding requirements on prudential soundness, market conduct and investor protection through CRR/CRD, MiFID II and MiFIR, Solvency II, EMIR and CSDR, PSD and EMD, AML directives, MiCA, DORA and GDPR (Regulation (EU) No 575/2013 on Prudential Requirements for Credit Institutions and Investment Firms (CRR) 2013; Directive 2013/36/EU on Access to the Activity of Credit Institutions and the Prudential Supervision of Credit Institutions (CRD) 2013; Directive 2014/65/EU on Markets in Financial Instruments (MiFID II) 2014; Regulation (EU) No 600/2014 on Markets in Financial Instruments (MiFIR) 2014; Directive 2009/138/EC on the Taking-up and Pursuit of the Business of Insurance and Reinsurance (Solvency II) 2009; Regulation (EU) No 648/2012 on OTC Derivatives, Central Counterparties and Trade Repositories (EMIR) 2012; Regulation (EU) No 909/2014 on Improving Securities Settlement in the European Union and on Central Securities Depositories (CSDR) 2014; Directive (EU) 2015/2366 on Payment Services in the Internal Market (PSD2) 2015; Directive 2009/110/EC on the Taking up, Pursuit and Prudential Supervision of the Business of Electronic Money Institutions (EMD II) 2009; Directive (EU) 2015/849 on the Prevention of the Use of the Financial System for the Purposes of Money Laundering or Terrorist Financing (4AMLD) 2015; Directive (EU) 2018/843 Amending Directive (EU) 2015/849 (5AMLD) 2018; Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA) 2023; Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector (DORA) 2022; Regulation (EU) 2016/679 on the Protection of Natural Persons with Regard to the Processing of Personal Data (GDPR) 2016). These instruments specify licensing, governance, outsourcing, logging, testing, resilience and data protection duties, and enable passporting across the single market (Directive 2013/36/EU on Access to the Activity of Credit Institutions and the Prudential Supervision of Credit Institutions (CRD) 2013; European Securities and Markets Authority 2023a, 2023b; Commission Delegated Regulation (EU) 2017/565 Supplementing Directive 2014/65/EU 2017; Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector (DORA) 2022; Regulation (EU) 2016/679 on the Protection of Natural Persons with Regard to the Processing of Personal Data (GDPR) 2016; European Banking Authority 2024a). Supervised firms must evidence compliance through internal control systems, audit trails and supervisory reporting (Directive 2009/138/EC on the Taking-up and Pursuit of the Business of Insurance and Reinsurance (Solvency II) 2009; European Securities and Markets Authority 2023a; Commission Delegated Regulation (EU) 2017/565 Supplementing Directive 2014/65/EU 2017; Commission Implementing Regulation (EU) 2021/451 Laying down ITS for Supervisory Reporting Under the CRR 2021). The DACH region presents a coherent yet diverse regulatory landscape. Germany applies EU law through national instruments such as the Kreditwesengesetz (KWG) and Wertpapierhandelsgesetz (WpHG) under BaFin supervision (Gesetz Über Das Kreditwesen (KWG) 2025; Wertpapierhandelsgesetz (WpHG) 2025; BaFin 2019). Austria implements EU law through the Bankwesengesetz (BWG) and Wertpapieraufsichtsgesetz 2018 (WAG 2018) under FMA supervision (Bankwesengesetz (BWG) 2025; Finanzmarktaufsicht (FMA) 2024, 2025). Switzerland enforces FinSA and FinIA with FINMA, framed by EU equivalence decisions and bilateral arrangements (Federal Act on Financial Services (FinSA) 2024; Federal Act on Financial Institutions (FinIA) 2024; FINMA 2025; European Commission 2025; Swiss State Secretariat for International Finance (SIF) 2025). The region’s institutional scale and diversity are material: universal banks, savings and cooperative networks, global insurers, specialised asset managers and market utilities operate under comparable supervisory expectations, while preserving sufficient heterogeneity to test generality (European Central Bank 2024; EFAMA 2025). Burden asymmetries persist: in Austria, smaller firms bear proportionally higher fixed compliance costs, with studies documenting that regulatory obligations weigh more heavily on them than on larger institutions (European Investment Bank 2025; Financial Stability Board 2019; Financial Stability Institute 2018; Kurz et al. 2025).

Contribution

Current compliance mechanisms in financial institutions remain predominantly ex-post: obligations are verified through periodic audits, reconciliations, and manual attestations, while system execution itself proceeds without embedded regulatory constraints. This approach creates structural gaps, since audit trails can be incomplete, supervisory checks are delayed, and interpretations of legal texts remain siloed across departments. Controls are reactive rather than preventative, and compliance risk accumulates in the time between transaction and inspection. Addressing these deficiencies requires a design in which regulatory duties are formalised as machine-checkable constraints and enforced as part of orchestration and execution rather than appended as a reporting layer. This research develops an enterprise reference architecture for a tiered, compliant AI system in finance, aligned with the regulatory taxonomy and supervisory context of the DACH region yet transferable across the EU. The architecture encodes regulatory duties as machine-checkable constraints and binds them to orchestration and execution. A policy store and rule engine compile EU and DACH requirements into checks enforced both before and during execution. Multi-agent coordination is role scoped across institutional and consumer tiers, with explicit permissions, explainability thresholds and segregation of duties. Gated execution ensures that sensitive actions, such as order placement, occur only under dual control, and every step produces audit-ready evidence. Verification is achieved through a permissioned distributed ledger that employs a directed acyclic graph (DAG) for deterministic timestamping and inclusion proofs. The ledger captures routing instructions, budget usage and control attestations without imposing settlement semantics on application workflows. Decisions are formulated as objectives under constraints, with runtime budgets for risk, latency and ESG, enabling transparent trade-offs at schedule time. The architecture remains technology-agnostic at model level and interoperable with existing systems via supervised queues and APIs. In this way, it provides a reference design that meets supervisory expectations in DACH while supporting broader applicability across EU jurisdictions.

System Architecture

The proposed system architecture embeds regulatory compliance as a first-class design primitive rather than an external audit layer added post hoc. Orchestration and execution are bounded by machine-enforceable constraints compiled directly from legal provisions, ensuring that system behaviour remains verifiable at run time. The architecture is tiered across institutional and consumer contexts, portable across jurisdictions, and agnostic to specific model technologies. Its emphasis lies on properties that supervisory authorities recognise as audit-ready: determinism of execution, separation of roles, and transparent evidence generation. A distinctive element of the design is the integration of a permissioned distributed ledger that employs a directed acyclic graph (DAG) structure to anchor audit trails. Each agent action, constraint evaluation, and gating decision is recorded as a tamper-evident event with deterministic timestamping and inclusion proofs. Unlike traditional logging, which remains vulnerable to post-processing or selective disclosure, the DAG ledger produces an immutable sequence of verifiable attestations that can be inspected by internal control functions and supervisory authorities. The ledger is deliberately lightweight: it does not impose settlement semantics on application workflows but serves solely as a compliance substrate, capturing routing instructions, evidence packs, and oversight signatures. This enables continuous assurance without altering financial transaction flows.

Agnostic Regulatory Intent and Exposure Matrix

European financial regulation is dense and layered across prudential, conduct, market integrity, data protection and ICT risk instruments. Designing an enterprise system by listing acts and articles provides little direct operational guidance. To address this, we introduce a regulation-agnostic taxonomy that functions as a design primitive. Its purpose is to translate legal text into machine-enforceable control functions that govern orchestration and execution while remaining portable across DACH and the wider EU. We adopt a functional reduction of legal provisions to their operational effect on system behaviour: either a rule forbids an outcome or it demands an outcome with evidence. Compliance therefore reduces to abstention from a prohibited act or to the performance of a positive act that leaves a verifiable trace. This yields a law- and regulation-agnostic orientation in which agents need only decide whether to avoid or to act with evidence, while the specific statutory text is compiled at a later stage into guard families and evidence templates, with exposure handled separately for internal versus external outputs. Practically, this agnostic treatment simplifies handling heterogeneous regulations because the agent can synthesise, per task and context, a checklist of prohibitions and obligations that orchestration executes and tracks, with each item either preventing externalisation or requiring a verifiable artefact with provenance, deterministic timestamping and DAG inclusion proof; alternatively a dedicated compliance agent can apply the same checklist as a pre-output gate, sign the evidence pack, and authorise or withhold release.1 The taxonomy is formalised as a two-dimensional schema, the Regulatory Intent and Exposure Matrix. Each legal provision receives two labels rule type, capturing intent as either Prohibition or Obligation, and exposure, capturing context as Internal or External.

v=(t,e),t{Prohibition,Obligation},e{Internal,External}\begin{equation} v = (t,e), \quad t \in \{\text{Prohibition}, \text{Obligation}\}, \; e \in \{\text{Internal}, \text{External}\} \label{eq:rim-label} \end{equation}
(1)
1The regulatory intent and exposure label
The matrix is an orientation device rather than an execution rule. The label v=(t,e)v=(t,e) expresses a stance that guides reasoning and proposes candidate guard families and evidence templates; the selection and activation of concrete gates is compiled later by the rule engine from the policy store and context features, and may be revised by human oversight. In short, vv narrows the search space; it does not by itself prescribe what the system must do. A compact label provides the canonical representation. This schema enables candidate guard families and evidence templates to be proposed without first naming a statute, ensuring portability across instruments and jurisdictions. Prohibitions mark contexts where the system should consider blocking externalisation; obligations mark contexts where the system should consider requiring a positive act and admissible evidence. Whether these candidates become active gates depends on compiled policy, context, and approvals, not on the matrix alone.

This binary mapping is used for orientation in reasoning and as a compact handle for later compilation, as shown in Figure 1.

Figure 1Taxonomy of regulatory intent. Each legal provision (regulation, law, directive, guidance) maps to Prohibition or Obligation, indicating the primary reasoning objective.

Figure 1 frames two reasoning stances rather than execution rules. A Prohibition prompts scrutiny of potentially disallowed behaviour and a hold on externalisation until resolved. An Obligation prompts identification of duties and anticipation of evidence likely required if the task proceeds. Clauses are stored as atomic statements with mapping and citation to ensure fast reading and consistent interpretation. Concrete gates and logging are derived later once reasoning has reached sufficient confidence.

The second axis classifies exposure. Internal exposure refers to outputs confined to the institution, while external exposure refers to outputs delivered to clients, counterparties, authorities or markets. The distinction is contextual and combines with intent in Figure 2.

Figure 2Taxonomy of exposure. Internal indicates outputs confined to the institution; external indicates outputs leaving the institutional boundary. Mixed workflows default to external.

This classification orients reasoning by establishing the destination of outputs. Once combined with intent, it guides which questions and candidate actions are relevant. Figure 3 presents the joint view.

Figure 3Regulatory intent and exposure matrix. Quadrants orient reasoning and suggest candidate guard families and evidence expectations. Mixed workflows default to external.

At run time an agent performs a lightweight context check against the proposed matrix. If no mapped provision appears to apply, the agent continues under general IT controls and ordinary policy. If the check suggests applicability, the agent classifies the context using the matrix labels and treats that label as an orientation handle for reasoning rather than as an enforcement command, subject to revision as scope and evidence evolve. The context check can be formalised as a binary predicate that determines whether a task falls under a mapped legal provision:

χ:𝒯{0,1},χ(τ)={1if the mapped provision applies to τ0otherwise\begin{equation} \chi:\mathcal{T}\to\{0,1\},\qquad \chi(\tau)= \begin{cases} 1 & \text{if the mapped provision applies to }\tau\\ 0 & \text{otherwise} \end{cases} \label{eq:context-check} \end{equation}
(2)
2Whether a task falls under a mapped provision
If χ(τ)=0\chi(\tau) = 0, the task proceeds under baseline IT controls and operational policy. If χ(τ)=1\chi(\tau) = 1, the task is assigned a regulatory label v=(t,e)v=(t,e) as defined above. This label serves as an orientation handle that anchors subsequent reasoning.

Once classified, the agent frames the task as a constrained optimisation problem of the form

maxπΠU(π,τ)s.t.C(π,τ,v)=true,\begin{equation} \begin{aligned} \max_{\pi \in \Pi} \quad & U(\pi,\tau) \\ \text{s.t.} \quad & C(\pi,\tau,v) = \text{true}, \end{aligned} \label{eq:optimisation} \end{equation}
(3)
3The task as constrained optimisation
where π\pi is a candidate policy, U(π,τ)U(\pi,\tau) denotes the utility of executing π\pi on task τ\tau, and C()C(\cdot) encodes the selected guard families and evidence checks compiled from vv and context; the matrix label vv orients this compilation but does not, by itself, determine execution. Prohibitions are represented as hard constraints considered for activation to prevent disallowed outcomes, while obligations are represented as candidate duties that, if selected by policy, require admissible evidence. If no provision applies (χ(τ)=0\chi(\tau)=0), the constraint set CC collapses to baseline IT controls and ordinary operational policy. This formulation connects the taxonomy to decision-making without collapsing orientation into determination.

Minting the classification, checklist and gating decisions to the DAG enables ex post assurance and explicit failure analysis: an auditor can reconstruct the task state ϕ(τ)\phi(\tau) (see Eq. 5), recompute χ(τ)\chi(\tau) (see Eq. 2) and the label v=(t,e)v=(t,e) (see Eq. 1) to test whether the agent misunderstood the context, verify that each selected guard C(π,τ,v)C(\pi,\tau,v) in the optimisation constraint (see Eq. 3) was satisfied at the moment of externalisation, and match every obligation item to a concrete artefact with provenance, deterministic timestamping and inclusion proof; this makes distinct failure modes observable, including (i) misclassification of intent or exposure, (ii) correct classification and checklist generation but incomplete execution, (iii) execution with insufficient evidence quality or missing signatures, and (iv) sequencing or gating errors that allowed externalisation without preconditions, as well as budget breaches for risk, latency or ESG. The proposal turns compliance from after-the-fact attestation into assurance-by-construction, where reasoning, decisions and evidence are bound cryptographically so reviewers can check not only outcomes but also whether the agent’s understanding and follow-through were correct.

We propose a short, curated aid for cases where the context check indicates applicability. A quick reference vector is a concise entry prepared by a qualified oversight committee; it orients reasoning without prescribing execution. Each entry names the action archetype, states the typical matrix label, notes salient triggers and the initial evidence posture, and gives an escalation contact. Entries are versioned and signed so that provenance remains clear; they can be revised as scope or information changes. When a task matches such an entry, the agent adopts the entry as orientation and continues analysing the task toward the decision objective; if no entry fits, the agent proceeds under baseline controls and may flag the gap for later inclusion. The intent is speed and consistency in judgement, not hard rules.

r=(a,v,κ,ϵ,ν,σ)\begin{align} \label{eq:qr-vector} r = (a, v, \kappa, \epsilon, \nu, \sigma) \end{align}
(4)
where aa is the action archetype, v=(t,e)v=(t,e) is the matrix label from Equation Eq. 1, κ\kappa captures salient triggers and context features, ϵ\epsilon records the initial evidence posture, ν\nu denotes version and effective interval, and σ\sigma is the oversight signature.
R(τ)={rQsim(κr,ϕ(τ))θ}\begin{align} \label{eq:qr-candidates} R(\tau) = \{\, r \in Q \mid \mathrm{sim}\big(\kappa_r,\;\phi(\tau)\big) \ge \theta \,\} \end{align}
(5)
where QQ is the approved set, ϕ(τ)\phi(\tau) is a compact feature map of the task, and θ\theta is a reviewable threshold. If R(τ)=R(\tau)=\varnothing, the task proceeds under baseline controls and the context check is recorded for later improvement. If R(τ)R(\tau)\neq\varnothing, the top-ranked entry r̂\hat r is adopted as orientation and the analysis continues toward the decision objective in Equation Eq. 3.

Prohibitions as feasibility and obligations as task extension

The matrix provides orientation only; concrete enforcement is selected later by policy compilation and may be revised by human oversight. Given the label v=(t,e)v=(t,e) from Eq. 1 and the context determined by the predicate χ(τ)\chi(\tau) in Eq. 2, the rule engine surfaces candidate prohibitions PP and obligations OO, then selects active subsets PPP^{\star}\subseteq P and OOO^{\star}\subseteq O together with a strict partial order \prec over POP^{\star}\cup O^{\star}. The order \prec permits short-circuit evaluation where appropriate and defines a narrow top tier PPP^{\perp}\subseteq P^{\star} of dominant disqualifiers. Obligations map to mandatory sub-actions and a verifiable evidence artefact; let E()E(\cdot) denote the admissibility predicate capturing provenance, signatures, deterministic timestamping and DAG inclusion proof. None of these selections is implied by the matrix itself; the matrix narrows the search space, the policy store determines activation.

Prohibitions are encoded as feasibility constraints that prevent disallowed outcomes, while obligations extend the task with preconditions that must hold before optimisation under Eq. 3 is meaningful. The feasible policy set for task τ\tau is

Πfeas(τ)={πΠ|pP¬p(π,τ)oOE(artefacto(τ))}.\begin{equation} \Pi_{\mathrm{feas}}(\tau)=\Bigl\{\pi\in\Pi \ \Big|\ \bigwedge_{p\in P^{\star}} \neg p(\pi,\tau)\ \wedge\ \bigwedge_{o\in O^{\star}} E\bigl(\mathrm{artefact}_o(\tau)\bigr)\Bigr\}. \label{eq:feasible} \end{equation}
(6)
6The feasible policy set for a task
Optimisation proceeds lexicographically to respect feasibility first and utility second,
πargmaxπΠfeas(τ)U(π,τ)\begin{equation} \pi^\star \in \arg\max_{\pi\in\Pi_{\mathrm{feas}}(\tau)} U(\pi,\tau) \label{eq:lexi} \end{equation}
(7)
7Lexicographic optimisation, feasibility first

with optional secondary terms in UU for obligation quality such as latency, cost or completeness. This construction preserves the law- and regulation-agnostic stance: prohibitions shape the admissible set, obligations extend the task graph and demand admissible artefacts, and any burden from satisfying obligations may then be traded within the objective once feasibility is secured.

Externalisation refers to any output that leaves the institutional boundary, including recommendations, orders, client-facing summaries, supervisory reports and API calls, whereas internal artefacts, logs and operator messages remain non-external unless later reused. The gate outcome formalises block versus release for a proposed output y(π,τ)y(\pi,\tau), $$\begin{equation} \mathrm{Externalise}(\pi,\tau)= \begin{cases} \textsc{deny}(c) & \text{if }\exists p\in P^{\star}\text{ with }p(\pi,\tau)=1\ \ \text{or}\ \ \exists o\in O^{\star}\text{ with }E(\mathrm{artefact}_o(\tau))=\text{false},\\[4pt] \textsc{allow}(y) & \text{otherwise,} \end{cases} \label{eq:externalise} \end{equation}$$ where cc is a machine- and human-readable reason code minted to the DAG with a hold or release attestation. Blocking does not suppress internal reasoning; the system returns an explicit explanation to operators and records the decision and grounds for audit.

Short-circuit evaluation reduces latency and user friction without sacrificing assurance. If there exists a dominant disqualifier pPp\in P^{\perp} with p(π,τ)=1p(\pi,\tau)=1, then $\mathrm{Externalise}(\pi,\tau)=\textsc{deny}(c)$ by Eq. 8 and the remaining lower-tier checks in POP^{\star}\cup O^{\star} are marked skipped by policy. The audit pack minted to the DAG includes the orientation set, the selected P,OP^{\star},O^{\star}, the order \prec, the firing guard in PP^{\perp}, the skipped set with its policy basis, all artefact hashes and admissibility outcomes E()E(\cdot), and the reason code cc. This enables an auditor to reconstruct the state ϕ(τ)\phi(\tau) used in the quick-reference matching Eq. 5, to verify that the selected guards C(π,τ,v)C(\pi,\tau,v) in the optimisation constraint Eq. 3 were satisfied at the moment of externalisation, and to distinguish failure modes such as misclassification, incomplete execution of obligations, insufficient evidence quality, or sequencing errors that allowed externalisation without preconditions.

A composite example illustrates the semantics. Consider a cross-border retail transaction where the amount exceeds the threshold for retail investors and the client is under age. Orientation via vv surfaces multiple candidates; policy selects PP^{\star} that includes an under-age prohibition and places it in PP^{\perp} under \prec. The under-age guard fires, so $\mathrm{Externalise}(\pi,\tau)=\textsc{deny}(c)$ by Eq. 8; cross-border and amount checks are skipped by policy with the dominance certificate recorded in the audit pack. If, in a different context, no dominant disqualifier fires, obligations such as identification and know-your-customer documentation become active preconditions, and externalisation is permitted only once admissibility E()E(\cdot) holds, after which utility is optimised over Πfeas(τ)\Pi_{\mathrm{feas}}(\tau) according to Eq. 7. In both cases the matrix remains an orientation device; selection and activation are determined by compiled policy and oversight, and the full reasoning trail is minted to the DAG for ex post assurance.

We assume only mild regularity, namely that dominant disqualifiers in PP^{\perp} remain policy invariant for a given task state, so that p(π,τ)=p(π,τ)p(\pi,\tau)=p(\pi',\tau) holds for all π,πΠ\pi,\pi'\in\Pi; in practice these include conditions such as age thresholds, sanctions hits, or bans tied to specific product tiers. The admissibility predicate E()E(\cdot) is used to capture evidence quality requirements, including provenance, signatures, deterministic timestamping, and DAG inclusion, and is evaluated directly on the artefacts compiled for τ\tau.

Under these assumptions the feasible set is monotone: if the selected sets expand such that P1P2P^{\star}_1\subseteq P^{\star}_2 and O1O2O^{\star}_1\subseteq O^{\star}_2, then it follows that Πfeas(2)(τ)Πfeas(1)(τ)\Pi_{\mathrm{feas}}^{(2)}(\tau)\subseteq \Pi_{\mathrm{feas}}^{(1)}(\tau), where Πfeas(k)\Pi_{\mathrm{feas}}^{(k)} is defined by Eq. 6 under the selection Pk,OkP^{\star}_k,O^{\star}_k. The result follows immediately from Eq. 6, since adding further prohibitions or obligations introduces additional conjuncts that can only reduce the satisfying set.

Short-circuit evaluation is sound whenever dominant checks are policy invariant: if a single pPp\in P^{\perp} evaluates to one for some π\pi, then it evaluates to one for all π\pi', which implies Πfeas(τ)=\Pi_{\mathrm{feas}}(\tau)=\varnothing by Eq. 6 and forces $\mathrm{Externalise}(\pi,\tau)=\textsc{deny}(c)$ by Eq. 8. Conversely, if no element of PP^{\perp} fires and all selected obligations satisfy admissibility so that E()=trueE(\cdot)=\text{true}, then Πfeas(τ)\Pi_{\mathrm{feas}}(\tau) remains nonempty and the optimisation problem in Eq. 7 is well defined. Evaluation both terminates and remains auditable. Since the sets POP^{\star}\cup O^{\star} are finite and \prec is a strict partial order, a topological evaluation sequence necessarily exists, with short-circuiting at PP^{\perp} further bounding runtime. The DAG record contains the orientation set, the selected P,OP^{\star},O^{\star}, the order \prec, any firing element of PP^{\perp}, the admissibility outcomes E()E(\cdot), and the resulting gate decision Eq. 8, which together enable replay and independent re-evaluation using Eq. 2, Eq. 1, Eq. 6 and Eq. 3.

If obligation quality is intended to influence the objective once feasibility has been established, the framework admits a straightforward refinement in which U(π,τ)=U0(π,τ)λq(τ)U(\pi,\tau)=U_0(\pi,\tau)-\lambda^\top q(\tau), with q(τ)q(\tau) aggregating latency, cost, and completeness across satisfied obligations and λ0\lambda\ge 0 denoting policy weights. The lexicographic regime in Eq. 7 guarantees that such trade-offs are only evaluated within the feasible set Πfeas(τ)\Pi_{\mathrm{feas}}(\tau).

Agent activation by intent and exposure

The orientation matrix provides the initial signal, but the selection and activation of executors is determined by compiled policy and remains subject to oversight revision. Institutions may maintain standing rosters of domain-specific agents and persistent committees for recurring functions, while reserving the possibility of ad hoc committees when context requires. In a banking environment, a payments roster typically spans functions such as wiring funds between accounts, executing foreign-exchange conversions, and arranging treasury transfers. For an investment firm under MiFID II, routine activities encompass the reception and transmission of client orders, order execution on behalf of clients, the provision of investment advice with suitability and appropriateness checks, portfolio management, and post-trade reporting. These rosters remain dormant until activated by the orientation label v=(t,e)v=(t,e) from Eq. 1 in combination with the context check χ(τ)\chi(\tau) defined in Eq. 2. Committee formation follows a policy-driven logic. Where χ(τ)=0\chi(\tau)=0 or the task is assessed as internal and low risk, such as drafting an internal email or scheduling a meeting, a single role-scoped agent executes under baseline IT controls. When χ(τ)=1\chi(\tau)=1, activation depends on the exposure level ee, the number and dominance of active checks, and the availability of runtime budgets. This is formalised as

Committee(τ)={S(τ,v,context)if χ(τ)=1C(τ),{primary agent}otherwise,\begin{equation} \mathrm{Committee}(\tau)= \begin{cases} S(\tau,v,\text{context}) & \text{if } \chi(\tau)=1 \land C(\tau),\\[4pt] \{\text{primary agent}\} & \text{otherwise,} \end{cases} \label{eq:committee} \end{equation}
(8)
8The externalisation gate: block or release
where
C(τ):=(e=External)(|P|+|O|k)(P)budget breach (risk, latency, or cost).\begin{equation} C(\tau):=\big(e=\text{External}\big)\ \lor\ \big(|P^{\star}|+|O^{\star}|\ge k\big)\ \lor\ \big(P^{\perp}\neq\varnothing\big)\ \lor\ \text{budget breach (risk, latency, or cost)}. \end{equation}
(9)
9When a committee is activated
Here S()S(\cdot) yields the minimal role set required for the task, P,OP^{\star},O^{\star} denote the selected checks defined in the previous subsection, PP^{\perp} designates the dominant disqualifiers, and kk is a policy-defined threshold. The rule ensures proportionality and avoids unnecessary coordination overhead.

Execution proceeds through a structured handshake. The orchestration agent forwards the task τ\tau together with the orientation vv to the designated agent set or committee, which undertakes its domain-specific responsibilities and returns artefacts, rationales, and provisional outcomes. A dedicated compliance agent then applies the pre-output gate defined in Eq. 8; if admissibility is confirmed for all selected obligations and no prohibition fires, the output is released, whereas any failure results in blocked externalisation accompanied by a reason code. Each stage mints a committee token to the DAG ledger, recording membership, role scopes, selected checks, reason codes, and inclusion proofs, which collectively support later reconstruction and independent re-evaluation under Eq. 3.

Examples illustrate proportionality and dominance. A domestic, low-value internal transfer with χ(τ)=0\chi(\tau)=0 is executed by a single payments agent without committee escalation, reflecting the proportionality condition that internal exposure with few selected checks below the policy threshold kk activates only the primary role. A cross-border retail securities order with χ(τ)=1\chi(\tau)=1 and e=Externale=\text{External} activates the standing “securities orders” set comprising client categorisation and suitability, order execution, best-execution monitoring, and transaction reporting; if a dominant disqualifier in PP^{\perp}, such as an under-age client, fires, the committee collapses to the compliance gate and the externalisation returns $\textsc{deny}(c)$ under Eq. 8, with all skipped checks logged as skipped by policy. Formally,

PpP:p(π,τ)=1Committee(τ)={compliance gate},\begin{equation} P^{\perp}\neq\varnothing \ \wedge\ \exists p\in P^{\perp}: p(\pi,\tau)=1 \ \Longrightarrow\ \mathrm{Committee}(\tau)=\{\text{compliance gate}\}, \label{eq:dominance} \end{equation}
(10)
which ensures that functional agents are excluded by policy while a reason-coded denial is minted under Eq. 8. In both directions, whether escalation occurs because exposure or policy thresholds demand it, or collapse follows from dominance being triggered, the orientation matrix identifies relevant agents while compiled policy and supervisory oversight determine actual activation.

Evidence admissibility model

Admissibility must be explicit to ensure that obligation checks in Eq. 6Eq. 7 are verifiable at run time and reproducible on audit. Each obligation oOo\in O^{\star} is modelled as producing an artefact bundle

artefacto(τ)=text,hash,sig,prov,time,dag,ret.\begin{align} \mathrm{artefact}_o(\tau) &= \langle \text{text}, \text{hash}, \text{sig}, \text{prov}, \text{time}, \text{dag}, \text{ret} \rangle . \end{align}
(11)
11Dominance among active checks

The admissibility predicate is defined as the conjunction of policy-specified quality dimensions,

E(artefacto(τ))QprovQsigQtimeQdagQretQaccess,\begin{equation} E\bigl(\mathrm{artefact}_o(\tau)\bigr)\ \Leftrightarrow\ Q_{\mathrm{prov}}\ \wedge\ Q_{\mathrm{sig}}\ \wedge\ Q_{\mathrm{time}}\ \wedge\ Q_{\mathrm{dag}}\ \wedge\ Q_{\mathrm{ret}}\ \wedge\ Q_{\mathrm{access}}, \label{eq:evidence} \end{equation}
(12)
where QprovQ_{\mathrm{prov}} establishes provenance and chain of custody, QsigQ_{\mathrm{sig}} validates authorised signatures and key material, QtimeQ_{\mathrm{time}} confirms trusted time binding, QdagQ_{\mathrm{dag}} attests DAG inclusion through Merkle proof and index, QretQ_{\mathrm{ret}} enforces retention horizon and lawful basis, and QaccessQ_{\mathrm{access}} guarantees role-scoped readability with appropriate redaction of personal data.

Let Hash()\mathrm{Hash}(\cdot) denote a collision-resistant digest and TS()\mathrm{TS}(\cdot) a trusted timestamp. A minimal admissible bundle must then satisfy

hash=Hash(text)sig=Signkoversight(hash)time=TS(hash)dag=Include(hash,time),\begin{equation} \text{hash}=\mathrm{Hash}(\text{text})\ \wedge\ \text{sig}=\mathrm{Sign}_{k_{\mathrm{oversight}}}(\text{hash})\ \wedge\ \text{time}=\mathrm{TS}(\text{hash})\ \wedge\ \text{dag}=\mathrm{Include}(\text{hash},\text{time}), \label{eq:min-bundle} \end{equation}
(13)
13Admissibility of an evidence artefact
with prov\text{prov} linking to registered source identifiers and ret\text{ret} demonstrating that the object is scheduled for retention in accordance with policy and applicable law. Privacy is preserved by anchoring digests and metadata on the DAG while raw artefacts remain in controlled storage, accessible only through capability- and role-scoped URIs. This definition operationalises the obligation term in the feasible set Eq. 6 and ensures that evidence produced by obligation checks is admissible by construction and audit-ready for supervisory verification.

Policy compilation and governance

The orientation matrix provides the initial signal, while policy compilation determines the active checks. Given the label v=(t,e)v=(t,e) from Eq. 1 and the task context χ(τ)\chi(\tau) from Eq. 2, a compiler maps orientation and context into selected guards and their evaluation order, subject to human oversight and revision. The policy store is a versioned, time-scoped rule base with effective intervals, reviewer sign-off, and rollback support.

Compilation is modelled as a deterministic function of the effective policy version ν\nu at decision time tt:

Compileν,t(v,context,τ)(P,O,,P,B),\begin{equation} \mathrm{Compile}_{\nu,t}\bigl(v,\text{context},\tau\bigr)\ \to\ \bigl(P^{\star},\,O^{\star},\,\prec,\,P^{\perp},\,B\bigr), \label{eq:compile} \end{equation}
(14)
14The minimal admissible evidence bundle
where PPP^{\star}\subseteq P and OOO^{\star}\subseteq O are the selected prohibitions and obligations, \prec is a strict partial order over POP^{\star}\cup O^{\star}, PPP^{\perp}\subseteq P^{\star} are dominant disqualifiers, and B=Brisk,Blat,BcostB=\langle B_{\mathrm{risk}},B_{\mathrm{lat}},B_{\mathrm{cost}}\rangle are the active runtime budgets. Selection is constrained by jurisdiction and effective dates from the legal index, by the exposure label ee, and by any institutional policies specific to product or client tier. The matrix narrows the candidate set but does not enforce activation.

Budgets operate both at compile time and at run time. A budget-breach predicate informs committee activation in Eq. 9 and the externalisation gate in Eq. 8:

Breach(τ):=(risk(τ)>Brisk)(latency(τ)>Blat)(cost(τ)>Bcost).\begin{equation} \mathrm{Breach}(\tau)\ :=\ \bigl(\mathrm{risk}(\tau) > B_{\mathrm{risk}}\bigr)\ \lor\ \bigl(\mathrm{latency}(\tau) > B_{\mathrm{lat}}\bigr)\ \lor\ \bigl(\mathrm{cost}(\tau) > B_{\mathrm{cost}}\bigr). \label{eq:breach} \end{equation}
(15)
15Policy compilation at a version and time
Here risk may be a calibrated model score, while latency and cost are measured against defined service tiers. If the predicate fires, the compiler may escalate to a committee under Eq. 9 or deny externalisation under Eq. 8.

Obligation templates are bound to admissibility during compilation. For each oOo\in O^{\star}, the compiler selects an evidence schema and admissibility test E()E(\cdot) from Eq. 13, producing a concrete template for artefacto(τ)\mathrm{artefact}_o(\tau) with required provenance, signatures, trusted time, and DAG inclusion. The feasible set Eq. 6 and optimisation Eq. 7 then operate over these compiled guards rather than the full candidate space.

Governance ensures reproducibility and institutional control. Each compilation yields a certificate

Certcomp=v,hash(context),P,O,,P,B,ν,σcompiler,σoversight,\begin{equation} \mathrm{Cert}_{\mathrm{comp}}=\bigl\langle v,\,\mathrm{hash}(\text{context}),\,P^{\star},\,O^{\star},\,\prec,\,P^{\perp},\,B,\,\nu,\,\sigma_{\mathrm{compiler}},\,\sigma_{\mathrm{oversight}}\bigr\rangle, \label{eq:cert} \end{equation}
(16)
16The breach predicate
which is signed both by the compiler and by an oversight key, and anchored on the DAG with a reference to the policy store version. Replays reconstruct Certcomp\mathrm{Cert}_{\mathrm{comp}} and verify that identical inputs under the same ν\nu yield identical selections and order.

Overrides are permitted under controlled conditions. An authorised reviewer may issue Override(Certcomp,Δ)\mathrm{Override}(\mathrm{Cert}_{\mathrm{comp}},\Delta) that modifies (P,O,)(P^{\star},O^{\star},\prec) with reason code and dual control. Safety monotonicity applies to dominant prohibitions: if pPp\in P^{\perp} and p(π,τ)=1p(\pi,\tau)=1, the override cannot deactivate pp when exposure is external (e=External)(e=\text{External}); any attempted weakening is logged and forces $\textsc{deny}(c)$ under Eq. 8. Strengthening is always admissible, while removal of non-dominant checks requires reviewer signatures and the issuance of a new certificate version ν\nu'.

Determinism and time anchoring close the loop. The compiler is deterministic given (v,context,ν,t)(v,\text{context},\nu,t), and any change in output is attributable to context updates, policy version changes, or time-scoped rule amendments. Trusted time binds both ν\nu and Certcomp\mathrm{Cert}_{\mathrm{comp}} to replayable evidence via Eq. 14. The result is a governance process that integrates admissibility, feasibility, committee formation, and externalisation, while keeping the orientation matrix as a guidance device rather than a source of hard-coded execution rules.

Stylised simulation pseudocode

The following pseudocode illustrates a pass through context detection, policy compilation, dominant disqualifier short-circuiting, admissibility checks, and the externalisation gate defined in Equation Eq. 8.

Input: task τ\tau, context, candidate policy set Π\Pi, policy version ν\nu, time tt v(None,Internal)v \gets (\text{None}, \text{Internal}) MINT_DAG(τ\tau, decision = “allow_internal”) allow_internal vORIENT(context)v \gets \text{ORIENT}(\text{context}) (P,O,,P,B)Compileν,t(v,context,τ)(P^\star, O^\star, \prec, P^\bot, B) \gets \text{Compile}_{\nu,t}(v, \text{context}, \tau) MINT_DAG(τ\tau, decision = “deny”, reason = “budget breach”) deny(reason = “budget breach”) MINT_DAG(τ\tau, decision = “deny”, reason = “dominant prohibition”) deny(reason = “dominant prohibition”) (continued on next page)

aEXECUTE(o,τ,context)a \gets \text{EXECUTE}(o, \tau, \text{context}) MINT_DAG(τ\tau, decision = “deny”, reason = “inadmissible obligation”, failed = oo) deny(reason = “inadmissible obligation”) Πfeas{πΠpP:p(π,τ)=0,oO:E(a)=true}\Pi_{\text{feas}} \gets \{\pi \in \Pi \mid \forall p \in P^\star: p(\pi, \tau) = 0,\ \forall o \in O^\star: E(a) = \text{true}\} MINT_DAG(τ\tau, decision = “deny”, reason = “no feasible policy”) deny(reason = “no feasible policy”) πargmaxπΠfeasU(π,τ)\pi^\star \gets \arg\max_{\pi \in \Pi_{\text{feas}}} U(\pi, \tau) MINT_DAG(τ\tau, decision = “allow”, output = π\pi^\star) allow(output from π\pi^\star)

This pseudocode shows how the system detects applicability, assigns the orientation label, compiles policy deterministically, short-circuits on dominant disqualifiers, evaluates admissibility for obligation artefacts, optimises over the feasible set defined by Eq. 6Eq. 7, executes the externalisation gate Eq. 8, and records every decision path by minting a replayable, time-bound audit pack.

Discussion

The architecture treats regulatory constraints as first-class objects while preserving the distinction between orientation and determination. The matrix provides a compact label v=(t,e)v=(t,e) for classification and routing, while policy compilation selects and orders prohibitions and obligations subject to possible revision through oversight. Compliance is operationalised through feasibility and admissibility as defined in Eq. 6, Eq. 7, and Eq. 8, with every obligation bound to trusted time and anchored on a permissioned DAG to ensure replayability, provenance validation, and clear attribution of failure. A central benefit arises from the separation of concerns. Orientation remains stable and portable across jurisdictions, whereas activation is institution specific through the policy store and its governance processes. Prohibitions do not trade against utility, and obligations extend the task with artefacts that must satisfy the admissibility predicate E()E(\cdot) defined in Eq. 13. Committee activation under Eq. 9 ensures proportionality, while short-circuiting of dominant checks formalised in Eq. 11 reduces latency without compromising the completeness of audit trails. There are trade-offs. Misclassification or an excessively broad dominance set may lead to false blocks, while incomplete policy stores can result in false releases. The legal index and the intent–exposure mapping m(l)m(l) therefore require continuous curation with versioning and reviewer sign-off. Privacy constraints further limit what can be anchored on the ledger; hashes and metadata are sufficient for attestation, but disciplined key management and controlled storage are required for raw artefacts. Determinism also relies on stable time sources and reproducible compilation given (v,context,ν,t)(v,\text{context},\nu,t). The scope of the design is clearly delimited. It does not replace legal interpretation or product governance but instead provides an executable substrate that is law- and regulation-agnostic at the orientation layer and institution specific at the activation layer. Portability across DACH and the wider EU follows directly from this separation, since only compilation rules and evidence templates vary with local implementation.

Conclusion

The paper advances a compliance-first architecture that positions regulation as an orientation layer rather than a deterministic ruleset. The Regulatory Intent and Exposure Matrix provides the compact handle v=(t,e)v=(t,e) for classification and routing, while execution is delegated to a governed policy compiler. Prohibitions constrain feasibility through the admissible set Πfeas(τ)\Pi_{\mathrm{feas}}(\tau) in Eq. 6 and block externalisation via Eq. 8. Obligations extend tasks with admissible artefacts that must satisfy the predicate E()E(\cdot) in Eq. 13. Optimisation then proceeds over Πfeas(τ)\Pi_{\mathrm{feas}}(\tau) under lexicographic semantics in Eq. 7. Proportionality follows from policy-driven committee activation in Eq. 9, while dominance rules in Eq. 11 enable early termination without compromising audit completeness. Evidence, decisions and reason codes are bound to a permissioned DAG with deterministic timestamping, ensuring replayability, provenance checks and precise failure attribution. Portability across DACH and the wider EU results from the separation between orientation and activation, a clause-level indexed legal corpus, and capability-based agent routing. The architecture transforms compliance from retrospective attestation into assurance by construction, offering a generalisable design pattern that remains law- and regulation-agnostic at the orientation layer while retaining institution-specific control at activation.

Limitations and Future Research

Several limitations remain. The design depends on curated mappings from legal text to orientation m(l)vm(l)\to v and on the integrity of policy compilation; drift or gaps can cause false blocks or unintended releases. Formal guarantees for compiler determinism and reproducibility under (v,context,ν,t)(v,\text{context},\nu,t) require explicit proof obligations and differential testing. The admissibility predicate E()E(\cdot) must be calibrated to institutional standards for provenance, signatures, trusted time and retention, and cryptographic choices and key management directly affect audit reliability. Ledger privacy remains constrained by linkage risks across hashes and metadata, and selective disclosure, salting and zero-knowledge proofs warrant further evaluation. Institutional dependencies also arise. Externalisation boundaries can shift when internal artefacts are reused in external contexts, which necessitates systematic exposure re-checks and reuse monitors. Committee thresholds kk and runtime budgets BB determine latency and cost, so empirical calibration, red-teaming and scenario replay are needed to quantify trade-offs and client impact. Retrieval robustness relies on similarity functions, feature maps and citation consistency, suggesting the need for adversarial tests and benchmarks specific to legal retrieval. Human and governance factors remain material. Curation of the legal index and the intent–exposure mapping requires ongoing reviewer effort with versioning and sign-off. Reviewer workload, override workflows and reason-code clarity all influence governance quality and practical adoption. Future research will extend evaluation on institution-specific scenarios in DACH, develop auditor-facing query suites tied to Eq. 2, Eq. 1, Eq. 6, Eq. 13 and Eq. 8, and investigate privacy-preserving ledger designs and time-binding mechanisms that improve verifiability without undermining data minimisation.

It should also be noted that empirical evaluation at meaningful scale would require full system deployment across institutional and regulatory contexts, which entails investments beyond the scope of academic research. Smaller prototypes would not capture the systemic properties of budget enforcement, admissibility, or externalisation, and could therefore provide misleading evidence. For this reason, the present contribution is deliberately theoretical and algorithmic: it establishes the formal and operational basis on which future large-scale empirical work can be responsibly pursued.


  1. A prohibition can be illustrated with a consumer-tier agent that is not permitted to instruct a client to purchase a particular security or to transmit an order on their behalf without their permission. In this case the guard blocks both recommendation and order externalisation, recording at most a hold or release attestation on the DAG ledger. An obligation is exemplified by onboarding procedures, which require identification and know-your-customer documentation. Here the workflow executes the prescribed checks and generates a signed artefact with provenance metadata, deterministic timestamping, and a DAG inclusion proof before any advisory or execution services can be activated.↩︎

Ali, A., M. Ahmed, and A. Khan. 2021. “Audit Logs Management and Security: A Survey.” Security and Privacy 4 (3): e155. https://doi.org/10.1002/spy2.155.
Arham, M. W. 2025. “Transforming Auditing Through AI and Blockchain.” American Journal of Industrial and Business Management 15 (2): 225–41. https://doi.org/10.4236/ajibm.2025.152011.
BaFin. 2019. Securities Trading Act (WpHG)—Overview. https://www.bafin.de/SharedDocs/Veroeffentlichungen/EN/Aufsichtsrecht/Gesetz/WpHG_en.html.
Bank for International Settlements. 2025. BIS International Banking Statistics and Global Liquidity Indicators at End-September 2024. Report. BIS. https://www.bis.org/statistics/rppb2501.pdf.
Bankwesengesetz (BWG). 2025. RIS Bundeskanzleramt. https://www.ris.bka.gv.at/GeltendeFassung.wxe?Abfrage=Bundesnormen&Gesetzesnummer=10004827.
Cheng, L. C. 2024. “Multi-Agent Based Deep Reinforcement Learning Framework for Trading Strategy and Portfolio Management.” Applied Artificial Intelligence in Finance.
Commission Delegated Regulation (EU) 2017/565 Supplementing Directive 2014/65/EU. 2017. Official Journal of the European Union. https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32017R0565.
Commission Implementing Regulation (EU) 2021/451 Laying down ITS for Supervisory Reporting Under the CRR. 2021. Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg_impl/2021/451/oj.
Directive 2009/110/EC on the Taking up, Pursuit and Prudential Supervision of the Business of Electronic Money Institutions (EMD II). 2009. Official Journal of the European Union. https://eur-lex.europa.eu/eli/dir/2009/110/oj.
Directive 2009/138/EC on the Taking-up and Pursuit of the Business of Insurance and Reinsurance (Solvency II). 2009. Official Journal of the European Union. https://eur-lex.europa.eu/eli/dir/2009/138/oj.
Directive 2009/65/EC on Undertakings for Collective Investment in Transferable Securities (UCITS). 2009. Official Journal of the European Union. https://eur-lex.europa.eu/eli/dir/2009/65/oj.
Directive 2011/61/EU on Alternative Investment Fund Managers (AIFMD). 2011. Official Journal of the European Union. https://eur-lex.europa.eu/eli/dir/2011/61/oj.
Directive 2013/36/EU on Access to the Activity of Credit Institutions and the Prudential Supervision of Credit Institutions (CRD). 2013. Official Journal of the European Union. https://eur-lex.europa.eu/eli/dir/2013/36/oj.
Directive 2014/65/EU on Markets in Financial Instruments (MiFID II). 2014. Official Journal of the European Union. https://eur-lex.europa.eu/eli/dir/2014/65/oj.
Directive (EU) 2015/2366 on Payment Services in the Internal Market (PSD2). 2015. Official Journal of the European Union. https://eur-lex.europa.eu/eli/dir/2015/2366/oj.
Directive (EU) 2015/849 on the Prevention of the Use of the Financial System for the Purposes of Money Laundering or Terrorist Financing (4AMLD). 2015. Official Journal of the European Union. https://eur-lex.europa.eu/eli/dir/2015/849/oj.
Directive (EU) 2018/843 Amending Directive (EU) 2015/849 (5AMLD). 2018. Official Journal of the European Union. https://eur-lex.europa.eu/eli/dir/2018/843/oj.
EFAMA. 2025. Trends in European Investment Funds: Fact Book 2025. Report. European Fund; Asset Management Association. https://www.efama.org/sites/default/files/fact-book-2025_lowres.pdf.
EIOPA. 2025. Digital Operational Resilience Act (DORA). Https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en.
European Banking Authority. 2024a. PSD2, Article 28: Application to Exercise the Right of Establishment and Freedom to Provide Services. https://www.eba.europa.eu/regulation-and-policy/single-rulebook/interactive-single-rulebook/16236.
European Banking Authority. 2024b. Regulatory Technical Standards on ICT Services Supporting Critical or Important Functions. Https://www.eba.europa.eu/activities/single-rulebook/regulatory-activities/operational-resilience/regulatory-technical-standards-policy-ict-services-supporting-critical-or-important-functions.
European Central Bank. 2024. Financial Integration and Structure in the Euro Area. Report. ECB. https://www.ecb.europa.eu/pub/pdf/fie/ecb.fie202406.en.pdf.
European Commission. 2025. Equivalence of Non-EU Financial Frameworks: Overview and List of Decisions. https://finance.ec.europa.eu/eu-and-world/equivalence-non-eu-financial-frameworks_en.
European Investment Bank. 2025. EIB Investment Survey 2024: Country Overview—Austria. Report. EIB. https://www.eib.org/files/documents/lucalli/20240238_econ_eibis_2024_austria_en.pdf.
European Securities and Markets Authority. 2023a. MiFID II, Article 16: Organisational Requirements (Interactive Single Rulebook). https://www.esma.europa.eu/publications-and-data/interactive-single-rulebook/mifid-ii/article-16-organisational-requirements.
European Securities and Markets Authority. 2023b. MiFID II, Article 34: Freedom to Provide Investment Services and Activities (Passporting). https://www.esma.europa.eu/publications-and-data/interactive-single-rulebook/mifid-ii/article-34-freedom-provide-investment.
Faccia, A. 2022. “Is Permissioned Blockchain the Key to Support the External Audit Process?” International Journal of Disclosure and Governance 19 (4): 354–64. https://doi.org/10.1057/s41310-022-00153-2.
Federal Act on Financial Institutions (FinIA). 2024. Fedlex. https://www.fedlex.admin.ch/eli/cc/2018/801/en.
Federal Act on Financial Services (FinSA). 2024. Fedlex. https://www.fedlex.admin.ch/eli/cc/2019/758/en.
Financial Stability Board. 2019. Evaluation of the Effects of Financial Regulatory Reforms on SME Financing. Report. FSB. https://www.fsb.org/wp-content/uploads/P291119-1.pdf.
Financial Stability Institute. 2018. Proportionality in Banking Regulation: A Cross-Country Comparison. Report. Bank for International Settlements. https://www.bis.org/fsi/publ/insights1.pdf.
Finanzmarktaufsicht (FMA). 2024. Securities Supervision Act 2018 (WAG 2018) [Convenience Translation]. https://www.fma.gv.at/wp-content/plugins/dw-fma/download.php?d=2085.
Finanzmarktaufsicht (FMA). 2025. Financial Market Supervision in Austria (Integrated Model). https://www.fma.gv.at/en/financial-market-supervision-in-austria/.
FINMA. 2025. FINMA’s Legal Basis (Financial Market Supervision Act and Sectoral Laws). https://www.finma.ch/en/documentation/finma-s-legal-basis/.
Gesetz Über Das Kreditwesen (KWG). 2025. Gesetze im Internet (BMJ/Bundesanzeiger Verlag). https://www.gesetze-im-internet.de/kredwg/.
Hambly, B., R. Xu, and H. Yang. 2021. “Recent Advances in Reinforcement Learning in Finance.” Mathematical Finance 31 (3): 782–813. https://doi.org/10.1111/mafi.12315.
Kurz, Walter, Reinhard Magg, and Konrad Stromeyer. 2025. “Financial and Operational Impacts of Regulatory Compliance on the Austrian Securities Industry.” Journal of Next-Generation Research 5.0 1 (4): 137. https://doi.org/10.70792/jngr5.0.v1i5.137.
Malibari, N., I. Katib, and R. Mehmood. 2023. “Systematic Review on Reinforcement Learning in the Field of FinTech.” Journal of Cloud Computing 12 (1): 1–34. https://doi.org/10.1186/s13677-023-00449-1.
Regulation (EU) 2016/679 on the Protection of Natural Persons with Regard to the Processing of Personal Data (GDPR). 2016. Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2016/679/oj.
Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector (DORA). 2022. Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2022/2554/oj.
Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA). 2023. Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2023/1114/oj.
Regulation (EU) No 575/2013 on Prudential Requirements for Credit Institutions and Investment Firms (CRR). 2013. Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2013/575/oj.
Regulation (EU) No 600/2014 on Markets in Financial Instruments (MiFIR). 2014. Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2014/600/oj.
Regulation (EU) No 648/2012 on OTC Derivatives, Central Counterparties and Trade Repositories (EMIR). 2012. Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2012/648/oj.
Regulation (EU) No 909/2014 on Improving Securities Settlement in the European Union and on Central Securities Depositories (CSDR). 2014. Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2014/909/oj.
Singh, P., and A. Kumar. 2025. “Ensuring Data Integrity and Auditability in BPM Systems: A Blockchain-Based Approach.” International Journal of Information Technology & Management Information Systems.
Skadden. 2024. The EU’s Digital Operational Resilience Act (DORA). Https://www.skadden.com/insights/publications/2024/07/the-eus-digital-operational-resilience-act.
Sun, R. 2025. “A Novel Multi-Agent Hierarchical Deep Reinforcement Learning Framework for Portfolio Optimization.” Journal of Finance and Computation.
Swiss State Secretariat for International Finance (SIF). 2025. European Union: Market Access and Equivalence. https://www.sif.admin.ch/en/european-union-eu.
Wertpapierhandelsgesetz (WpHG). 2025. Gesetze im Internet (BMJ/Bundesanzeiger Verlag). https://www.gesetze-im-internet.de/wphg/.