QIS-S-100 QISTRUST.COM THE GOVERNANCE LAYER REV 2026-07-31 · BUILD 11.0
The Governance Layer · Standards

The standards register.

Eight published standards that autonomous finance will be built on or measured against, each mapped to the MARQUE questions it serves — and to the ones it leaves open. The gaps are the point. No standard on this list was designed for an agent acting with capital, and reading them as though they were is the most likely governance error of the next few years.

QIS-S-100·8 standards·Mapped to MARQUE v1.0

Coverage against the eight questions.

Read the right-hand column first. Where it reads low, the standards community has not arrived yet — and that is where the writing is worth doing.

MARQUE question → standards that address it
QuestionAddressed byCount
AuthorityModel Context Protocol1
OversightOpenTelemetry, NIST AI Risk Management Framework, ISO/IEC 420013
DriftOpenTelemetry, NIST AI Risk Management Framework2
AuditabilityOpenTelemetry, FIX Protocol, XBRL3
AccountabilityNIST AI Risk Management Framework, ISO/IEC 42001, FIX Protocol3
IdentityModel Context Protocol, Agent-to-Agent, FDC33
Systemic behaviourAgent-to-Agent1
Standards & interoperabilityModel Context Protocol, Agent-to-Agent, ISO/IEC 42001, FDC3, FIX Protocol, XBRL6

The register.

Anthropic; open specification

An open protocol for connecting AI systems to external data sources and tools through a client–server interface. A host application runs clients; each client connects to a server that exposes a declared set of resources, tools and prompts.

3 of 8
Originated at Google; contributed to the Linux Foundation

A protocol for interoperability between autonomous agents built by different vendors on different frameworks — capability discovery, task delegation, and structured message exchange across organisational boundaries.

3 of 8
Cloud Native Computing Foundation

A vendor-neutral standard for traces, metrics and logs, with a common data model and wire format. The dominant instrumentation standard in distributed systems.

3 of 8
US National Institute of Standards and Technology

A voluntary framework organised around four functions — Govern, Map, Measure, Manage — for identifying and managing risk across an AI system's lifecycle. Published January 2023, with a generative AI profile added subsequently.

3 of 8
ISO / IEC

A management-system standard for artificial intelligence, structured like ISO 27001 — policy, roles, risk assessment, controls, internal audit, continual improvement. Certifiable by accredited third parties.

3 of 8
FINOS (Fintech Open Source Foundation, Linux Foundation)

An open standard for interoperability between financial desktop applications — shared context objects, intents, an app directory, and a channel model, so that selecting an instrument in one application propagates to others.

2 of 8
FIX Trading Community

The messaging standard for electronic trade communication — orders, executions, allocations and post-trade — in continuous use since the early 1990s and underpinning most institutional order flow.

3 of 8
XBRL International

An open standard for tagging business and financial reporting data against defined taxonomies, mandated for filings by numerous regulators including the SEC.

2 of 8

How these were selected.

Three tests. The standard must be published and stable — no drafts, no vendor specifications with a single implementer. It must be plausibly load-bearing for an autonomous financial system, whether or not it was designed for one. And its limits must be statable: if we cannot say precisely what it does not cover, we do not understand it well enough to publish about it.

Every entry carries a caveat, and the caveat is the part you cannot get from the standards body.