The verification register.
Every dated assertion on this platform — regulatory citations, market figures, vendor names — is recorded here with its primary source and the date it was last checked against that source. The build fails if any entry passes its review date. A claim cannot go stale quietly here, because staleness breaks the deployment.
Why a citable platform needs this.
Link checking is a solved problem and every static site does it. Claim checking is not, and for a platform whose value is being cited, it is the one that matters. A working link to a superseded regulation is worse than a broken one — it looks maintained.
Review intervals are set by how fast the underlying thing moves: 90 days for active regulatory instruments and anything under consultation, 180 days for settled regulation and market figures with a published vintage, 365 days for historical facts that cannot change.
Shipping a claim past its review date requires re-reading the primary source and either confirming or correcting the assertion. There is no option to simply extend the date, which is the entire point of putting it in the build gate rather than in a calendar reminder.
The register.
ACP (Agent Communication Protocol), launched by IBM Research in March 2025, merged into A2A under the Linux Foundation in 2025. The ACP team wound down active development and contributed its technology into A2A. ACP is no longer a standalone specification.
Primary source ↗
No single ratified ai.txt specification exists as of this date. Competing proposals include Spawning's 2023 format, an IETF draft registering /.well-known/ai.txt, and the IETF AIPREF working group vocabulary. Our ai.txt claims conformance to none of them and says so.
Primary source ↗
The AIEOG Shared AI Lexicon (February 2026) was produced by the AI Executive Oversight Group, a public-private partnership formed by the US Treasury with FBIIC and FSSCC. Expressly optional and not intended for legal interpretation.
Primary source ↗
DORA (Regulation (EU) 2022/2554) has been in full application since 17 January 2025. Financial entities completed first mandatory Register of Information submissions to national competent authorities in Q1 2026, consolidating to the ESAs by 31 March 2026. Threat-led penetration testing runs to a January 2028 milestone for designated entities.
Primary source ↗
The QIS Ecosystem Dual License v1.0, effective 2 August 2026, permits retrieval, citation, indexing and non-commercial research free and perpetually with attribution, and requires a license for commercial model training, bulk redistribution and enterprise ingestion.
Primary source ↗
Regulation (EU) 2024/1689 (the EU AI Act) entered into force in August 2024 with obligations phasing in through 2026-27.
Primary source ↗
FDX API v6.5 is the current stable version of the North American open banking standard. In April 2026 FDX launched an initiative to establish safety and data-sharing guidelines for AI agents transmitting consumer banking data. The initiative is not a published standard.
Primary source ↗
The CRI Financial Services AI Risk Management Framework Risk and Control Matrix v1.0 contains 230 control objectives across four functions: Govern (81), Map (47), Measure (59), Manage (43). Counted directly from the published matrix.
Primary source ↗
The CRI Financial Services AI Risk Management Framework was released on 12 February 2026. The US Treasury announced it separately on 19 February 2026, as part of a coordinated set of AIEOG deliverables.
Primary source ↗
IMDA launched the Model AI Governance Framework for Agentic AI on 22 January 2026 at the World Economic Forum; version 1.5 published 20 May 2026 after feedback from more than sixty organizations. Voluntary. Four dimensions.
Primary source ↗
IOSCO published FR/02/2026, Supervisory Toolkit for AI Use in Capital Markets, on 25 May 2026. Non-binding and non-prescriptive; covers the full AI system lifecycle and all system types including emerging agentic techniques. A standalone toolkit is published as OR/07/2026.
Primary source ↗
ISO/IEC 42001 is a certifiable management-system standard for artificial intelligence, structured comparably to ISO 27001.
Primary source ↗
JPMorgan reported crossing $100B in QIS notionals on its Strategic Indices platform in 2025 (Risk.net).
Risk.net (August 2025)
Massive rebranded as Massive effective 30 October 2025. Existing API keys and endpoints continue to work; massive.com redirects to massive.com.
Primary source ↗
The NIST AI Risk Management Framework (AI RMF 1.0) was published in January 2023 and is organized around four functions: Govern, Map, Measure, Manage. America's AI Action Plan (July 2025) directs NIST to revise it.
Primary source ↗
NIST Cybersecurity Framework 2.0 was published in February 2024, adding the Govern function and broadening scope beyond critical infrastructure.
Primary source ↗
Bank QIS-linked exposures are projected to pass $1 trillion by 2028 (BCG Expand). A projection, and labeled as one wherever it appears.
BCG Expand (2025)
Banks generated an estimated $8.5B of QIS revenue in 2025 per BCG Expand (reported by IFR), up from roughly $4B in 2019. Attributed estimate, not a measured figure.
BCG Expand, reported by IFR (December 2025)
SR 11-7 (4 April 2011) governed model risk management at US banking organizations until superseded on 17 April 2026. All references on this platform are historical and say so.
Primary source ↗
SR 26-2, issued 17 April 2026 by the Federal Reserve, OCC and FDIC, supersedes SR 11-7 (2011) and SR 21-8 (2021). Most relevant to banking organizations over $30 billion in total assets. Footnote 3 places generative and agentic AI outside the scope of the guidance.
Primary source ↗
The MARQUE working paper, 'Governing Delegated Authority in Autonomous Finance', is published on SSRN under abstract_id 7285180. That identifier resolves to the paper's public listing and is the citation landing this platform points third parties at.
Primary source ↗
Decentralized Identifiers (DID Core) is a W3C Recommendation defining a URI scheme for identifiers controlled by their subject rather than issued by a central registry.
Primary source ↗
Found something here that is out of date or wrong? editor@qisfund.com. Corrections are published, and we would rather be corrected than cited incorrectly.