- Jurisdiction, institution, product, and policy time
- Bind every case to the regulated or policy owner, institution type, product, relationship, customer type, jurisdictions, effective laws and policy versions, risk appetite, required checks, decision authority, reporting and review cadence; stop when applicability is unresolved.
- Purpose, minimum data, accessibility, and consent
- Map each field and source to a lawful and stated purpose; collect the minimum; provide notices, language, accessible and human alternatives, assistance and redress; record consent where applicable; prevent secondary use; and apply explicit retention and deletion.
- Original evidence, identity steps, and provenance
- Retain original artifacts and responses with digests; separate resolution, validation and verification; record issuer, validity, source and method; protect biometrics and sensitive data; expose forged, expired, weak and conflicting evidence; and never generate missing facts.
- Entity, ownership, and authority graph
- Use stable entity and person identifiers; version registries and organizational documents; calculate ownership exactly; record control and representative roles with effective dates; preserve incomplete or circular chains; and require qualified conclusions for beneficial ownership and authority.
- List version, candidate explainability, and disposition
- Screen the right subjects against current approved datasets; retain publication time, query fields, normalization and scoring; show identifiers, programs, alternatives and counterevidence; treat results as candidates; prohibit protected-trait proxies and require authorized match and risk decisions.
- Permissions, security, lifecycle, and recovery
- Separate collect, validate, screen, review, approve, report, create, restrict, close and administer capabilities; isolate tenants, encrypt data, protect secrets, log access, test restore, retain original decisions, refresh by policy and events, support export, correction and deletion and retire providers safely.