SEC Regulation Best Interest
source ↗eCFRBroker-dealers must act in the retail customer's best interest at the time a recommendation is made, with care, disclosure, conflict and compliance obligations. Automated recommendation engines inherit the full standard, including documented conflict mitigation.
16 components0 articles / obligations1 triggering use casesopen in graph AI Register & Model Registry / Factsheets
100% of use casesAI register & model registry: central inventory of every model, agent, RAG pipeline and embedded third-party SaaS AI across the estate, with factsheets per asset. v2.0 duty: every application — internal, open-source or procured — continuously publishes a machine-readable AI-BOM and Factsheet into the register; an asset without a current AI-BOM is an inventory gap, not a formality. Feeds Colorado AIA/ LL144 disclosure duties and the Art. 11 technical file; the enforcement backstop is Shadow-AI discovery on the risk register.
- practice-derived1 triggering use case require AI Register & Model Registry / Factsheets
Bias Testing & Data Quality Pipeline
100% of use casesRepresentativeness checks, bias metrics and mitigation per ISO/IEC 5259; versioned datasets with lineage.
- practice-derived1 triggering use case require Bias Testing & Data Quality Pipeline
BYOK via External HSM
100% of use casesCustomer-controlled key sovereignty; cascaded encryption independent of the cloud provider.
- practice-derived1 triggering use case require BYOK via External HSM
Confidence Scoring & Threshold Gate
100% of use casesComputes a probabilistic confidence score for every output and holds the transaction when the score falls below the workflow's regulatory threshold.
- practice-derived1 triggering use case require Confidence Scoring & Threshold Gate
Confidential Computing Enclaves
100% of use casesAMD SEV / Intel TDX: data protected from the cloud operator even in memory during inference.
- practice-derived1 triggering use case require Confidential Computing Enclaves
HITL Escalation Queue & Review UI
100% of use casesHITL escalation queue & review UI ('Human-as-a-Tool': the agent calls the human like any other tool via propose-action objects). Confidence- and risk-threshold routing, SLA timers, structured accept/modify/reject verdicts with digital reviewer signature at gate release — each verdict is itself Art. 14 evidence and feeds the active-learning loop.
- practice-derived1 triggering use case require HITL Escalation Queue & Review UI
Isolated Tenant Storage Enclave
100% of use casesPer-client storage boundary for raw payloads, intermediate artefacts and outputs, so no tenant data is co-mingled or reachable across engagements.
- practice-derived1 triggering use case require Isolated Tenant Storage Enclave
Kill Switch / Graceful Degradation
100% of use casesOperator stop controls and degraded-mode fallbacks; real-time override (veto) channels for HOTL operation.
- practice-derived1 triggering use case require Kill Switch / Graceful Degradation
Multi-Model Router & Fallback Abstraction
100% of use casesAbstraction layer decoupling application logic from model providers: dynamic routing on capability, cost, latency SLA and regulatory constraint (sensitive-data classes pinned to ZDR private/VPC endpoints or on-prem open-weight instances); real-time health monitoring with automatic fallback to secondary endpoints or local fine-tuned models on outage/latency spikes. Discharges resilience duties (DORA-class), prevents provider lock-in, and makes model deprecations a routing-table change instead of a re-architecture. Router decisions are logged into the decision trace — model version per event is an audit-packet field.
- practice-derived1 triggering use case require Multi-Model Router & Fallback Abstraction
Multi-Region Failover & Resilience Testing
100% of use casesDORA-grade continuity: regional redundancy, chaos testing, exit strategies for critical third parties.
- practice-derived1 triggering use case require Multi-Region Failover & Resilience Testing
OpenTelemetry / FCoT Tracing
100% of use casesHierarchical trace spans for every sub-task, prompt, retrieved document and API call — the reconstructible decision path for Art. 12/14 and PLD disclosure.
- practice-derived1 triggering use case require OpenTelemetry / FCoT Tracing
Sovereign Context Layer
100% of use casesGoverned runtime workspace operationalizing Art. 10: traceable lineage for every RAG chunk and training record at execution time, canonical version-controlled business glossary (documents Art. 10(2)(d) baseline assumptions), and continuous data-quality monitoring with threshold alerts and logged remediation for the Art. 10(3) 'error-free and complete' standard.
- practice-derived1 triggering use case require Sovereign Context Layer
Supervisor Attribution Chain
100% of use casesEvery model inference, data interaction and client-facing artefact is bound to an authorised supervising natural person — never to a shared service account. Required for SEC Rule 204-2 attribution, SOX segregation of duties and AI Act Art. 26 deployer oversight records.
- practice-derived1 triggering use case require Supervisor Attribution Chain
Vendor & Model Due-Diligence Kit
100% of use casesScoring model: jurisdiction (CLOUD Act exposure), zero-data-retention, BYOK support, audit evidence (C5/AIC4/ISO 42001/EN 18286:2026), tenant isolation.
- practice-derived1 triggering use case require Vendor & Model Due-Diligence Kit
WORM / Immutable Audit Vault
100% of use casesAppend-only, hash-chained audit vault (WORM object-lock storage, AES-256 at rest, TLS 1.3 in transit). Guarantees tamper-evidence within the organization's trust domain — which stops your own team, but not an admin who can rebuild the vault. Pair with an external trust anchor and key ceremonies outside the operating team for evidence that holds against the insider scenario.
- practice-derived1 triggering use case require WORM / Immutable Audit Vault
Zero-Trust Ingestion Gateway
100% of use casesAuthenticated, policy-checked entry point for client payloads; enforces tenant identity, schema validation and rate limits before any data reaches an inference path.
- practice-derived1 triggering use case require Zero-Trust Ingestion Gateway