QIS-T-800 QISTRUST.COM THE GOVERNANCE LAYER REV 2026-08-28 · BUILD 44
The Governance Layer · Editorial infrastructure

The verification register.

Every dated assertion on this platform — regulatory citations, market figures, vendor names — is recorded here with its primary source and the date it was last checked against that source. The build fails if any entry passes its review date. A claim cannot go stale quietly here, because staleness breaks the deployment.

QIS-T-800·22 tracked claims·Enforced at build time

Why a citable platform needs this.

Link checking is a solved problem and every static site does it. Claim checking is not, and for a platform whose value is being cited, it is the one that matters. A working link to a superseded regulation is worse than a broken one — it looks maintained.

Review intervals are set by how fast the underlying thing moves: 90 days for active regulatory instruments and anything under consultation, 180 days for settled regulation and market figures with a published vintage, 365 days for historical facts that cannot change.

Shipping a claim past its review date requires re-reading the primary source and either confirming or correcting the assertion. There is no option to simply extend the date, which is the entire point of putting it in the build gate rather than in a calendar reminder.

The register.

acp-superseded
Verified 2026-08-02 · 180-day review

ACP (Agent Communication Protocol), launched by IBM Research in March 2025, merged into A2A under the Linux Foundation in 2025. The ACP team wound down active development and contributed its technology into A2A. ACP is no longer a standalone specification.
Primary source ↗

ai-txt-standard
Verified 2026-08-02 · 90-day review

No single ratified ai.txt specification exists as of this date. Competing proposals include Spawning's 2023 format, an IETF draft registering /.well-known/ai.txt, and the IETF AIPREF working group vocabulary. Our ai.txt claims conformance to none of them and says so.
Primary source ↗

aieog-lexicon
Verified 2026-08-02 · 180-day review

The AIEOG Shared AI Lexicon (February 2026) was produced by the AI Executive Oversight Group, a public-private partnership formed by the US Treasury with FBIIC and FSSCC. Expressly optional and not intended for legal interpretation.
Primary source ↗

dora
Verified 2026-08-02 · 90-day review

DORA (Regulation (EU) 2022/2554) has been in full application since 17 January 2025. Financial entities completed first mandatory Register of Information submissions to national competent authorities in Q1 2026, consolidating to the ESAs by 31 March 2026. Threat-led penetration testing runs to a January 2028 milestone for designated entities.
Primary source ↗

dual-license
Verified 2026-08-02 · 180-day review

The QIS Ecosystem Dual License v1.0, effective 2 August 2026, permits retrieval, citation, indexing and non-commercial research free and perpetually with attribution, and requires a license for commercial model training, bulk redistribution and enterprise ingestion.
Primary source ↗

eu-ai-act
Verified 2026-08-02 · 180-day review

Regulation (EU) 2024/1689 (the EU AI Act) entered into force in August 2024 with obligations phasing in through 2026-27.
Primary source ↗

fdx-version
Verified 2026-08-02 · 90-day review

FDX API v6.5 is the current stable version of the North American open banking standard. In April 2026 FDX launched an initiative to establish safety and data-sharing guidelines for AI agents transmitting consumer banking data. The initiative is not a published standard.
Primary source ↗

fs-ai-rmf
Verified 2026-08-02 · 180-day review

The CRI Financial Services AI Risk Management Framework Risk and Control Matrix v1.0 contains 230 control objectives across four functions: Govern (81), Map (47), Measure (59), Manage (43). Counted directly from the published matrix.
Primary source ↗

fs-ai-rmf-release
Verified 2026-08-26 · 180-day review

The CRI Financial Services AI Risk Management Framework was released on 12 February 2026. The US Treasury announced it separately on 19 February 2026, as part of a coordinated set of AIEOG deliverables.
Primary source ↗

imda-mgf
Verified 2026-08-02 · 90-day review

IMDA launched the Model AI Governance Framework for Agentic AI on 22 January 2026 at the World Economic Forum; version 1.5 published 20 May 2026 after feedback from more than sixty organizations. Voluntary. Four dimensions.
Primary source ↗

iosco-toolkit
Verified 2026-08-02 · 90-day review

IOSCO published FR/02/2026, Supervisory Toolkit for AI Use in Capital Markets, on 25 May 2026. Non-binding and non-prescriptive; covers the full AI system lifecycle and all system types including emerging agentic techniques. A standalone toolkit is published as OR/07/2026.
Primary source ↗

iso-42001
Verified 2026-08-02 · 180-day review

ISO/IEC 42001 is a certifiable management-system standard for artificial intelligence, structured comparably to ISO 27001.
Primary source ↗

jpm-notionals
Verified 2026-08-02 · 180-day review

JPMorgan reported crossing $100B in QIS notionals on its Strategic Indices platform in 2025 (Risk.net).
Risk.net (August 2025)

massive-rebrand
Verified 2026-08-02 · 180-day review

Massive rebranded as Massive effective 30 October 2025. Existing API keys and endpoints continue to work; massive.com redirects to massive.com.
Primary source ↗

nist-ai-rmf
Verified 2026-08-02 · 180-day review

The NIST AI Risk Management Framework (AI RMF 1.0) was published in January 2023 and is organized around four functions: Govern, Map, Measure, Manage. America's AI Action Plan (July 2025) directs NIST to revise it.
Primary source ↗

nist-csf-2
Verified 2026-08-02 · 180-day review

NIST Cybersecurity Framework 2.0 was published in February 2024, adding the Govern function and broadening scope beyond critical infrastructure.
Primary source ↗

qis-exposures
Verified 2026-08-02 · 180-day review

Bank QIS-linked exposures are projected to pass $1 trillion by 2028 (BCG Expand). A projection, and labeled as one wherever it appears.
BCG Expand (2025)

qis-revenue
Verified 2026-08-02 · 180-day review

Banks generated an estimated $8.5B of QIS revenue in 2025 per BCG Expand (reported by IFR), up from roughly $4B in 2019. Attributed estimate, not a measured figure.
BCG Expand, reported by IFR (December 2025)

sr-11-7-superseded
Verified 2026-08-02 · 365-day review

SR 11-7 (4 April 2011) governed model risk management at US banking organizations until superseded on 17 April 2026. All references on this platform are historical and say so.
Primary source ↗

sr-26-2
Verified 2026-08-02 · 90-day review

SR 26-2, issued 17 April 2026 by the Federal Reserve, OCC and FDIC, supersedes SR 11-7 (2011) and SR 21-8 (2021). Most relevant to banking organizations over $30 billion in total assets. Footnote 3 places generative and agentic AI outside the scope of the guidance.
Primary source ↗

ssrn-working-paper
Verified 2026-08-17 · 180-day review

The MARQUE working paper, 'Governing Delegated Authority in Autonomous Finance', is published on SSRN under abstract_id 7285180. That identifier resolves to the paper's public listing and is the citation landing this platform points third parties at.
Primary source ↗

w3c-did
Verified 2026-08-02 · 180-day review

Decentralized Identifiers (DID Core) is a W3C Recommendation defining a URI scheme for identifiers controlled by their subject rather than issued by a central registry.
Primary source ↗

Found something here that is out of date or wrong? editor@qisfund.com. Corrections are published, and we would rather be corrected than cited incorrectly.