QIS-S-100 QISTRUST.COM THE GOVERNANCE LAYER REV 2026-08-28 · BUILD 44
The Governance Layer · Standards

The standards register.

19 published standards that autonomous finance will be built on or measured against, each mapped to the MARQUE questions it serves — and to the ones it leaves open. The gaps are the point. No standard on this list was designed for an agent acting with capital, and reading them as though they were is the most likely governance error of the next few years.

QIS-S-100·19 standards·Mapped to MARQUE v1.0

Coverage against the eight questions.

Read the right-hand column first. Where it reads low, the standards community has not arrived yet — and that is where the writing is worth doing.

MARQUE question → standards that address it
QuestionAddressed byCount
AuthorityModel Context Protocol, IMDA Model AI Governance Framework for Agentic AI, FDX, W3C Decentralized Identifiers4
OversightOpenTelemetry, NIST AI Risk Management Framework, ISO/IEC 42001, SR 26-2, IMDA Model AI Governance Framework for Agentic AI, IOSCO Supervisory Toolkit for AI Use in Capital Markets, Financial Services AI Risk Management Framework, DORA, NIST Cybersecurity Framework 2.09
DriftOpenTelemetry, NIST AI Risk Management Framework2
AuditabilityOpenTelemetry, FIX Protocol, XBRL, SR 26-2, Financial Services AI Risk Management Framework, DORA, ISO 200227
AccountabilityNIST AI Risk Management Framework, ISO/IEC 42001, FIX Protocol, SR 26-2, IMDA Model AI Governance Framework for Agentic AI, IOSCO Supervisory Toolkit for AI Use in Capital Markets, Financial Services AI Risk Management Framework, DORA, NIST Cybersecurity Framework 2.09
IdentityModel Context Protocol, Agent-to-Agent, FDC3, IMDA Model AI Governance Framework for Agentic AI, AIEOG Shared AI Lexicon, FDX, W3C Decentralized Identifiers7
Systemic behaviorAgent-to-Agent, IOSCO Supervisory Toolkit for AI Use in Capital Markets, DORA3
Standards & interoperabilityModel Context Protocol, Agent-to-Agent, ISO/IEC 42001, FDC3, FIX Protocol, XBRL, IOSCO Supervisory Toolkit for AI Use in Capital Markets, Financial Services AI Risk Management Framework, AIEOG Shared AI Lexicon, ISO 20022, FDX, NIST Cybersecurity Framework 2.0, ACP13

The register.

Anthropic; open specification

An open protocol for connecting AI systems to external data sources and tools through a client–server interface. A host application runs clients; each client connects to a server that exposes a declared set of resources, tools and prompts.

3 of 8
Originated at Google; contributed to the Linux Foundation

A protocol for interoperability between autonomous agents built by different vendors on different frameworks — capability discovery, task delegation, and structured message exchange across organizational boundaries.

3 of 8
Cloud Native Computing Foundation

A vendor-neutral standard for traces, metrics and logs, with a common data model and wire format. The dominant instrumentation standard in distributed systems.

3 of 8
US National Institute of Standards and Technology

A voluntary framework organized around four functions — Govern, Map, Measure, Manage — for identifying and managing risk across an AI system's lifecycle. Published January 2023, with a generative AI profile added subsequently.

3 of 8
ISO / IEC

A management-system standard for artificial intelligence, structured like ISO 27001 — policy, roles, risk assessment, controls, internal audit, continual improvement. Certifiable by accredited third parties.

3 of 8
FINOS (Fintech Open Source Foundation, Linux Foundation)

An open standard for interoperability between financial desktop applications — shared context objects, intents, an app directory, and a channel model, so that selecting an instrument in one application propagates to others.

2 of 8
FIX Trading Community

The messaging standard for electronic trade communication — orders, executions, allocations and post-trade — in continuous use since the early 1990s and underpinning most institutional order flow.

3 of 8
XBRL International

An open standard for tagging business and financial reporting data against defined taxonomies, mandated for filings by numerous regulators including the SEC.

2 of 8
Federal Reserve · OCC · FDIC

Revised interagency guidance on model risk management, issued 17 April 2026, superseding SR 11-7 (2011) and SR 21-8 (2021). Most relevant to banking organizations with over $30 billion in total assets. Replaces fixed-cycle validation with materiality-based scaling, narrows the definition of 'model' to complex quantitative methods, and judges validation independence by the rigor of review rather than by organizational structure.

3 of 8
Infocomm Media Development Authority, Singapore

Launched 22 January 2026 at the World Economic Forum and updated to version 1.5 on 20 May 2026 after feedback from more than sixty organizations. The first governance framework built specifically for AI agents capable of autonomous planning, reasoning and action. Voluntary, and structured around four dimensions: assess and bound the risks upfront, make humans meaningfully accountable, implement technical controls and processes, and enable end-user responsibility.

4 of 8
International Organization of Securities Commissions

Final report FR/02/2026, published 25 May 2026 by IOSCO's Fintech Task Force after two years of work. Provides supervisors with practical, non-binding, non-prescriptive tools applicable across regulatory models, covering the full lifecycle of an AI system and all system types — from traditional machine learning through generative AI to emerging agentic techniques. A standalone extract of the toolkit is published separately as OR/07/2026 for use during inspections.

4 of 8
Cyber Risk Institute · FSSCC · US Treasury (AIEOG)

An operationalization of the NIST AI Risk Management Framework tailored to financial services, version 1.0, released 12 February 2026. Comprises an AI Adoption Stage Questionnaire, a Risk and Control Matrix, a User Guidebook and a Control Objective Reference Guide. The matrix contains 230 control objectives across four functions — Govern (81), Map (47), Measure (59) and Manage (43) — each paired with a named risk statement and mapped to maturity stages from Initial to Embedded.

4 of 8
US Treasury · FBIIC · FSSCC

A shared vocabulary for AI in financial services, published February 2026 by the AI Executive Oversight Group — a public-private partnership formed by the US Treasury with FBIIC and FSSCC. Defines roughly seventy terms drawn from standards, academic publications and government sources, including Agentic AI, AI Agent, AI drift, guardrails, human-in-the-loop, model risk, and third-party AI risk.

2 of 8
European Union — Regulation (EU) 2022/2554

Binding EU regulation on digital operational resilience for financial entities, in full application since 17 January 2025. Covers ICT risk management, incident reporting, resilience testing, and — most consequentially here — a dedicated regime for ICT third-party service providers, including an oversight framework for those designated critical. Financial entities completed their first mandatory Register of Information submissions to national competent authorities in Q1 2026, consolidating to the European Supervisory Authorities by 31 March 2026. Threat-led penetration testing cycles run to a January 2028 milestone for designated entities.

4 of 8
ISO — maintained by the Registration Management Group

The international standard for financial messaging, providing a common data model and structured message definitions across payments, cash management, securities, trade services and cards. Its defining property is richer, more structured data than the legacy formats it replaces.

2 of 8
Financial Data Exchange — industry standards body

The dominant open banking API standard in North America, currently at version 6.5. Standardizes how consumer and business financial data is shared between institutions and third parties, with a consent model specifying scope, duration and revocation, and alignment with US financial data rights rules. In April 2026 FDX launched a dedicated initiative to establish safety and data-sharing guidelines for AI agents transmitting consumer banking data.

3 of 8
World Wide Web Consortium — W3C Recommendation

A W3C Recommendation defining a URI scheme for identifiers that resolve to a DID document containing public keys, authentication methods and service endpoints. Identifiers are controlled by their subject rather than issued by a central registry, and are designed to be verifiable and persistent.

2 of 8
US National Institute of Standards and Technology

A voluntary framework organized around six functions — Govern, Identify, Protect, Detect, Respond, Recover — published in February 2024. Version 2.0 added the Govern function and broadened scope beyond critical infrastructure to organizations of all sizes and sectors.

3 of 8
IBM Research → Linux Foundation; merged into A2A

A REST-based agent messaging protocol launched by IBM Research in March 2025 to power the BeeAI platform, donated to the Linux Foundation, and merged into A2A in 2025. The ACP team wound down active development and contributed its technology directly into A2A; BeeAI, the platform ACP was built for, now runs on A2A. It is no longer a standalone specification.

1 of 8

How these were selected.

Three tests. The standard must be published and stable — no drafts, no vendor specifications with a single implementer. It must be plausibly load-bearing for an autonomous financial system, whether or not it was designed for one. And its limits must be statable: if we cannot say precisely what it does not cover, we do not understand it well enough to publish about it.

Every entry carries a caveat, and the caveat is the part you cannot get from the standards body.