The Definitive Framework · 2026 Edition · Lakshmi Venkatesh

ACAI
Framework

Agentic Compliance & AI Intelligence
9
Governance domains — the most complete framework in existence
3
Rings of practice: Operational · Tactical · Strategic
12
Regulatory standards mapped: MAS · EU AI Act · NIST · BNM · ISO 42001
AGENT GOV. HUB D1 Identity D2 Observe D3 Policy D4 ADLC D5 Agents D6 ITSM D7 Risk D8 Data D9 Ethics★
Regulatory: MAS FEAT · EU AI Act · NIST RMF · BNM RAI · ISO 42001 · FATF · Basel III · COBIT 2019 Inspired by: DAMA DMBOK · ITIL v4 · TOGAF · CMMI
ACAI v2.0 · April 2026
Foundations · Three Contrarian Bets

Why This Framework Exists

Three hypothesis-tested strategic positions that define the ACAI worldview. Pattern-matched from deployments, regulatory examinations, and first-principles reasoning.

H₁ · Validated
Compliance IS the Operating System
Organizations treating compliance as a constraint layer around AI will be outcompeted by Organizations that treat it as the agent's core reasoning substrate. Policy-as-code is the first thing you architect — the ground truth every agent queries at runtime. Evidence: 82% of agentic compliance failures trace back to policy ambiguity at runtime, not model capability gaps. Build the policy engine before the first agent.
H₂ · Disruptive
Agents Are Non-Human Employees
The biggest structural gap in every bank's AI programme is world-class IAM for humans and near-zero governance for non-human identities. Agents need onboarding ceremonies, quarterly performance reviews, behavioural drift assessments, and formal off-boarding — the same rigour as a privileged human user. Shared agent credentials = zero accountability. The institution that operationalises NHI (Non-Human Identity) governance first builds an insurmountable compliance moat.
H₃ · Out-of-Box
Shadow Agents Are the #1 Risk
The most dangerous compliance risk in 2026 is not what governed agents do — it is Shadow Agents: unauthorised processes spun up by business teams, vendor LLMs embedded in SaaS tools (Salesforce Einstein, SAP AI Core, Oracle AI), and Copilot integrations accessing production data outside any oversight framework. Most ASEAN Organizations have 40–80 unregistered AI processes running right now. An Agent Census is the defining capability of 2026. Not glamorous. Essential.
The Strategic Triad · Three Dimensions of Agentic Compliance
Dimension A · Governance

Compliance FOR Agents

Making agents themselves compliant — governed, auditable, explainable, bounded. Every action traceable, authorised, and reproducible.

  • Agent identity registry (NHI model) with unique UUID
  • Policy-as-code enforcement at runtime via OPA/Rego
  • Immutable audit trails with full Chain-of-Thought logging
  • HITL / HOTL tiered oversight — no irreversible action without human gate
  • Kill switch, circuit breaker, and rollback architecture
  • Compliance Flight Recorder — 30 min of reasoning captured
Dimension B · Operations

Compliance BY Agents

Agents performing compliance work autonomously — monitoring, alerting, reporting, and responding 24/7 across all regulatory domains.

  • AML alert triage — 10,000 alerts in, 80 surfaced to humans
  • SAR drafting agent — structured narrative, human signs
  • Regulatory change watch — MAS/BNM/FATF circulars daily
  • KYC refresh and PEP screening with entity resolution
  • MAS 610 / BNM returns — automated assembly and validation
  • Market conduct surveillance, ESG disclosure agents
Dimension C · Meta-Governance

Compliance ABOUT Agents

Satisfying regulator expectations about AI systems themselves. Proving what your agents are and how they behave.

  • MAS FEAT: Fairness, Ethics, Accountability, Transparency
  • EU AI Act high-risk system registration + conformity
  • NIST AI RMF Govern → Map → Measure → Manage
  • ISO 42001 AI management system certification pathway
  • Model risk aligned to SR 11-7 / MAS MRM guidelines
  • Proactive regulator via MAS Sandbox / BNM i-RaPS
The ACAI Wheel · Nine Domains · Three Rings of Practice

Structured Like DAMA, ITIL
& TOGAF — For Agentic AI

Like the DAMA wheel for data management and the ITIL service value system, ACAI structures agentic compliance as interconnected, peer-level domains radiating from a central governance core — with three rings representing operational execution, tactical management, and strategic governance.

AGENT GOVERNANCE HUB NHI·IAM Observe Policy ADLC Agents ITSM Risk Data Ethics Identity & Access Observability & Audit Policy Engine Agent Lifecycle Agent Intelligence ITSM & SDLC Risk & Regulatory Data & Semantics Ethics & Fairness ★ Least-privilege · JIT · NHI Passport · Agent Census CoT logging · Flight Recorder · Arize · LangSmith OPA/Rego · Policy-as-code · RAG · Hallucination guard ADLC · Shadow audit · APR quarterly · Agent Senate Specialist agents · Orchestration · AART · A2A-TS ITSM · CI/CD · ITAM · FinOps · COBIT · ITIL v4 MAS FEAT · EU AI Act · ISO 42001 · NIST RMF · Basel Semantic layer · MDM · Lineage · PDPA · DAMA DMBOK Fairness · Bias testing · Demographic parity · IEEE EAD D1 D2 D3 D4 D5 D6 D7 D8 D9 Operational (run) Tactical (manage) Strategic (govern)
D1 · Identity & Access
NHI model · JIT tokens · Agent Passport (W3C VC) · Least-privilege · Agent Census · ISO 27001 extension
D2 · Observability & Audit
CoT logging · Flight Recorder · Drift detection · Circuit breaker · Correlation IDs · MAS TRM examination pack
D3 · Policy Engine
OPA/Rego · Policy-as-code · RAG corpus · Hallucination control · HITL gates · Compliance mesh sidecar
D4 · Agent Lifecycle (ADLC)
Ideate→Design→Build→Validate→Operate→Decommission · APR · Agent Senate · Shadow mode · CMMI maturity
D5 · Agent Intelligence
AML · KYC · SAR · RegChange · Orchestrator · AART · A2A-TS (COSMIC) · Sanctions · Market conduct · ESG
D6 · ITSM & SDLC
AICA in ServiceNow · CI/CD gates · ITAM for agents · FinOps · ITIL v4 adapted · COBIT 2019 · BCP/DR
D7 · Risk & Regulatory
MAS FEAT · EU AI Act · NIST RMF · BNM RAI · ISO 42001 · FATF · Basel III OpRisk · Vendor/third-party AI risk
D8 · Data & Semantics
Compliance Semantic Layer · MDM · Golden source · OpenLineage · Data quality gates · PDPA/GDPR · DAMA DMBOK
D9 · Ethics & Fairness ★ NEW
Algorithmic fairness · Bias testing · Demographic parity · Ethics board · FEAT F+E pillars · IEEE EAD · NYC AI Bias
Deep Dive · Nine Domains Fully Specified

Every Domain: Three Rings,
Principles, Standards, Patterns

Each domain specified across Operational (daily run), Tactical (monthly manage), and Strategic (quarterly/annual govern) rings. New agentic controls embed in what the organisation already runs for People, Process, and Technology — see the Must embed note inside every domain card below.

DOMAIN 01
Identity & Access
Agents are non-human actors: unique identity, scoped permissions, governed lifecycle — same rigour as a privileged human, expressed through your existing IAM fabric.
Must embed
Reuse how identity works today: people (workforce IdP, joiner–mover–leaver, RBAC/ABAC), applications (OAuth clients, API keys, M2M), data systems (service accounts, DB roles, PAM). Keep the same directories, approvals, and vaults — then add agent registration, UUIDs, scoped credentials, and NHI lifecycle on top. No parallel identity island.
● OPERATIONAL
Agent UUID registry · JIT ephemeral token provisioning (auto-revoke on task complete) · Credential vault (HashiCorp Vault / CyberArk) · Per-session audit log · Zombie agent weekly scan
◆ TACTICAL
RBAC/ABAC with context-aware permissions (env, risk level, data sensitivity) · NHI off-boarding protocol · Agent Census programme · IAM platform extension to non-human actors
▸ STRATEGIC
Agent Passport (W3C VC) · Cross-bank NHI trust framework · ISO 27001 scope extension · Board-level NHI policy · Zero standing privilege as architectural standard
ISO 27001 · CyberArk PAM · W3C VC · NIST IAM · MAS TRM §6
DOMAIN 02
Observability & Audit
Every agent action must be traceable, explainable, and reconstructible by a regulator within 24 hours. Auditability is the foundation of trust — not a feature.
Must embed
Plug into existing APM, logging, SIEM, SOC runbooks, log retention, and internal audit sampling — then add agent correlation IDs, CoT/trace exports, and regulator-ready replay packs on top.
● OPERATIONAL
Immutable append-only audit log · Correlation IDs across all systems · Real-time KPI dashboard (FPR, SLA, escalation rate, confidence distribution) · Alert on policy breach rate threshold
◆ TACTICAL
Chain-of-Thought (CoT) logging via LangSmith / Arize · Behavioural drift detector with statistical baseline · Circuit breaker (auto-pause on anomalous volume) · Monthly decision sample audit
▸ STRATEGIC
Compliance Flight Recorder (CFR) — 30-min reasoning replay · Regulator-as-Agent Interface (RAAI) · 7-year immutable retention with regulatory key escrow · MAS TRM examination pack
OpenTelemetry · LangSmith · Arize · EU AI Act Art.12 · MAS TRM §9
DOMAIN 03
Policy Engine
Policies must be machine-enforceable rules that agents check at runtime — not guidance documents interpreted probabilistically. Compliance-as-code is non-negotiable.
Must embed
Extend GRC/policy libraries, SoD matrices, and legal interpretation workflows already in use — then add OPA/Rego (or equivalent), versioned effective dates, and runtime enforcement hooks for agents on top.
● OPERATIONAL
OPA/Rego policy store · Pre-execution validator (permission + policy + risk check) · HITL gate manager · Policy violation alerting · Hallucination control: mandatory RAG citation on all regulatory interpretations
◆ TACTICAL
Versioned policies with effective dates (GitOps for compliance) · Reg-corpus RAG (MAS/BNM/FATF/BCBS in authoritative vector DB) · Policy conflict resolver · Adversarial input defense (prompt injection via customer data)
▸ STRATEGIC
Compliance-as-a-Mesh: OPA sidecar per agent · RegChange agent auto-ingesting circulars → policy update proposals → Agent Senate approval · Policy lineage traceable to source legislation
OPA/Rego · OPAL · EU AI Act Art.9 · NIST Map · MAS Notice 626
DOMAIN 04
Agent Lifecycle (ADLC)
ADLC is to agents what SDLC is to software — except agents have goals, drift, emergent behaviour, and identity. Six phases with compliance gates at every transition.
Must embed
Map every gate to your SDLC, CAB/release management, test environments, and model-risk (MRM) sign-off — ADLC is an extension of those ceremonies, not a separate delivery track.
● OPERATIONAL
Agent Census as ground truth · Shadow mode gate (min 6 weeks vs human baseline) · Canary release 20%→100% · Zombie agent scan on decommission · ITAM entry per agent asset
◆ TACTICAL
Red team / adversarial testing per agent class · Independent model validation (MRM) · Agent Performance Review (APR) quarterly · Drift re-validation trigger · Definition of Done includes compliance acceptance criteria
▸ STRATEGIC
Agent Senate: cross-functional quorum (Legal, Risk, Tech, Compliance, Business) approves Tier 2/3 deployments · NHI as employee (onboard → perform → review → offboard) · ADLC as MAS examination artefact
CMMI · TOGAF ADM · ISO 42001 §7 · MAS MRM Guidelines · SR 11-7
DOMAIN 05
Agent Intelligence
Specialist agents performing actual compliance work, orchestrated and governed. The compliance officer's force-multiplier — 24/7 across every regulatory domain simultaneously.
Must embed
Treat agents like any governed downstream consumer: same integration patterns as APIs, batch jobs, and dashboards (queues, entitlements, human handoffs) — then add orchestration, safety, and audit-specific behaviour on top.
● OPERATIONAL
AML alert triage · SAR drafting (human approves, never auto-files) · KYC refresh with PEP/sanctions screening · MAS 610 / BNM returns assembly · Dual human approval for all STR/SAR filings
◆ TACTICAL
Orchestrator agent: task routing, context passing, inter-agent protocol · Multi-agent quorum for high-risk decisions · Confidence scoring with uncertainty quantification · Escalation routing by risk tier
▸ STRATEGIC
AART (Adversarial Agent Red Team): standing red-team agents continuously probing production · A2A-TS typology sharing via COSMIC · ESG disclosure agent · RAAI pilot with MAS/BNM
LangGraph · Autogen · CrewAI · Actimize · ComplyAdvantage · COSMIC · Refinitiv
DOMAIN 06
ITSM & SDLC
Compliance embedded into incident management, change, software delivery, and asset management. ITIL, ITAM, DevSecOps, and Agile — re-architected for non-human actors.
Must embed
Use the live ITSM toolchain (incident, change, problem, CMDB, release) and Agile/DevSecOps forums as-is — extend record types, CI classes, and Definition of Done for agents and models; BCP/DR playbooks include agent failover paths.
● OPERATIONAL
AICA in ServiceNow: auto-classifies regulatory impact, routes to CCO if P1 · EU AI Act Art.62 SLA (15 days for serious incidents) · CI/CD compliance gate · Agent FinOps: token budget enforcement per agent
◆ TACTICAL
Agile sprint compliance story tagging · Definition of Done includes compliance acceptance criteria · ITAM extended to agent assets (cost, licensing, depreciation) · Business Continuity: fallback when agent fails in critical workflow
▸ STRATEGIC
ADLC as formal SDLC extension · ITSM–Compliance closed loop: zero manual handoff for routine AI incidents · ITIL v4 continual improvement adapted for agents · COBIT 2019 control objectives mapped to agentic controls
ITIL v4 · COBIT 2019 · ITAM ISO 19770 · Agile/Scrum · DevSecOps · EU AI Act Art.62
DOMAIN 07
Risk & Regulatory
The intersection of agentic AI and every regulation that matters. MAS FEAT · EU AI Act · NIST RMF · BNM RAI · ISO 42001 · FATF · Basel III. All mapped to actionable agent controls.
Must embed
Attach AI/agent rows to the existing risk register, RCSAs, three lines of defence, and regulatory mapping artefacts — same owners and committees, with additive controls and evidence for agentic systems.
● OPERATIONAL
AI Risk Register per agent · Fairness & bias testing (quarterly min) · Emergent behaviour risk monitoring · Third-party AI vendor risk (AWS Bedrock, Azure OpenAI, Anthropic) · Basel III Op Risk linkage
◆ TACTICAL
Three Lines of Defence adapted for AI · HITL (advisory) vs HOTL (monitored autonomous) · EU AI Act high-risk classification + conformity assessment · SR 11-7 / MAS MRM model risk report per governed agent · ISO 42001 pathway
▸ STRATEGIC
Board-level AI Risk Appetite Statement · NIST RMF Govern→Map→Measure→Manage fully operationalised · Proactive MAS Sandbox / BNM i-RaPS · ACAI as regulatory artefact submitted to supervisor
MAS FEAT · EU AI Act · NIST RMF · BNM RAI · ISO 42001 · FATF · Basel III · COBIT
DOMAIN 08
Data & Semantics
The governed data substrate every agent reads, writes, and is accountable for. The Compliance Semantic Layer — defined once, enforced everywhere. DAMA DMBOK extended to the agentic era.
Must embed
Ground agents in current data catalogue, MDM, classification, lineage, and access entitlements — the Compliance Semantic Layer and agent read/write rules sit on top of that enterprise data governance, not beside it.
● OPERATIONAL
Data classification (C1/C2/C3 sensitivity) · PII redaction on all agent outputs · PDPA/GDPR consent verification · Data quality gates before agent ingestion · MDM: golden customer record as agent read source
◆ TACTICAL
Full data lineage per agent action (OpenLineage) · Data mesh contracts: agent reads governed by product SLA · Golden source registry · DAMA DMBOK data stewardship for agentic data flows
▸ STRATEGIC
Compliance Semantic Layer: 30+ core compliance metrics defined once, served to all agents, dashboards, and regulators via single governed API · DAMA Ethics principles applied to agent data stewardship
DAMA DMBOK v3 · OpenLineage · PDPA SG/MY · GDPR · ISO 8000 · Data Mesh principles
DOMAIN 09 · ★ NEW IN ACAI v2
Ethics & Fairness
The only AI governance framework with Ethics & Fairness as a first-class domain — not a sub-item in risk. This is what makes ACAI distinct. MAS FEAT "F" and "E" done properly.
Must embed
Connect to conduct risk, fair treatment, product approval, and consumer-protection forums already in place — fairness testing, ethics review, and external oversight are extensions of those bodies, with agent-specific criteria.
● OPERATIONAL
Algorithmic fairness testing on every agent decision affecting customers · Demographic parity checks: outcomes must not differ materially by protected class · Bias detection pipeline in CI/CD · Fairness KPIs on compliance dashboard
◆ TACTICAL
Quarterly independent fairness audit (external validator) · Diverse test scenario library covering all demographic edge cases · Fairness constraints as OPA policy objects · Ethics review board sign-off for retail-facing agents
▸ STRATEGIC
Ethics board as permanent governance body with external member · FEAT "Fairness" and "Ethics" owned by D9, not D7 · ACAI v2 D9 as differentiating capability · Co-author MAS/BNM guidance on algorithmic fairness in ASEAN banking
MAS FEAT F+E · EU AI Act Art.10 · IEEE Ethically Aligned Design · DAMA Ethics · NYC AI Bias Audit Law
System Architecture · The 7-Layer Stack

From Consuming Actors
to Infrastructure — Complete

The ACAI architecture extends the governed semantic layer (consuming apps → semantic layer → data sources) with full agentic compliance infrastructure. Every layer is both a consumer of the layer below and a governed participant in the compliance ecosystem.

L7 · Consuming
Human Officers
CCO, MLRO, analysts
BI & Dashboards
Tableau, Power BI
Business Apps
Core banking, CRM, Actimize
Regulators / FIU
MAS, BNM, COSMIC
RAAI Interface
Supervisor NL queries
↕ business & regulatory terms ↕
L6 · Agents
Orchestrator Agent (Control Tower)
Task routing · context passing · inter-agent protocol · quorum
AML/CFT Agent
Alert triage · SAR drafting
KYC/CDD Agent
Entity res · PEP · scoring
RegChange Agent
Circular ingestion · impact
Reporting Agent
MAS 610 · BNM · ESG
L5 · Control Plane
Policy-as-Code Store
OPA/Rego · versioned · GitOps
Pre-exec Validator
Permission · policy · hallucination guard
HITL Gate Manager
Human queues · dual-control · escalation
Audit Log Engine
Immutable · CoT · CFR · correlation IDs
Explainability Svc
Human-readable · confidence · alternatives
L4 · NHI Identity
Agent Identity Registry
UUID · role · version · scope per agent
RBAC/ABAC Engine
Least-privilege · context-aware · env-scoped
JIT Token Provisioner
Ephemeral · auto-revoke · zero standing
Secrets Manager
Vault / AWS Secrets — no agent holds creds
Agent Census
Discovery · registration · shadow AI prevention
L3 · Semantic + Data
Compliance Semantic Layer
Golden definitions · 30+ compliance metrics · access rules — defined once, enforced everywhere
Reg Corpus RAG
MAS · BNM · FATF · BCBS authoritative vector DB
Data Classification
C1/C2/C3 · PII tagging · residency
Lineage & MDM
OpenLineage · golden record · data mesh
L2 · Observability
Metrics & KPIs
FPR · SLA · escalation · confidence drift
CoT Trace Logging
OpenTelemetry · LangSmith · Arize
Drift Detector
Statistical deviation · re-validation trigger
Circuit Breaker
Auto-pause on anomaly / policy breach spike
AART
Adversarial Red Team — continuous probing
L1 · Infrastructure
LLM Platform
Azure OpenAI / AWS Bedrock
Agent Orchestrator
LangGraph · Autogen · CrewAI
Tool / MCP Registry
Actimize · OFAC · ComplyAdvantage
Data Sources
Snowflake · Kafka · S3/ADLS · APIs
Security Perimeter
Zero-trust · mTLS · DLP · injection defense
ADLC · Agentic Development Lifecycle

SDLC + ITSM,
Re-Architected for Agents

Agents are not software. They have goals, drift, emergent behaviour, and identity. ADLC extends traditional DevSecOps with agent-specific compliance gates at every phase — and formally closes the loop with decommissioning to prevent zombie agents.

① Ideate
Weeks 1–2 Use case compliance canvas · Risk classification: Low/Med/High/Prohibited · MAS Sandbox / BNM i-RaPS notification · RACI definition · Agent scope + prohibited actions · EU AI Act risk tier pre-assessment
② Design
Weeks 2–4 Agent topology + orchestration design · NHI identity schema · IAM wiring · Policy-as-code authoring (OPA/Rego) · HITL gate definitions · Tool registry / MCP schema · Data residency + consent map · Agent Senate design review
③ Build
Weeks 3–6 Secure coding + SAST · Input guardrails: injection detection · Output PII redaction + topic confinement · CoT logging instrumentation · JIT IAM wiring · Hallucination guard: RAG citation enforcement · DoD: compliance acceptance criteria
④ Validate
Weeks 5–8 Shadow mode vs human baseline (≥6 weeks) · Target: ≥85% decision alignment · Red team adversarial testing · Independent MRM validation · Fairness & bias assessment · Reproducibility test suite · Agent Senate sign-off
⑤ Operate
Ongoing Canary 20%→100% over 4 weeks · AICA in ServiceNow · Continuous monitoring vs KRI thresholds · Quarterly APR · Annual model re-validation · Change mgmt for policy updates · COSMIC / FIU reporting
⑥ Decommission
Formal closure Agent Senate approval · Credential revocation (all JIT tokens purged) · 7-year audit archival · Knowledge transfer to successor · Zombie scan post-decommission (72h) · ITAM record closed · Lessons learned register
Agents At Work · For Employees · For Systems · For Downstream
For Your People

Augmenting Your Human Compliance Team

Agents reduce cognitive load on high-volume, low-judgement tasks. Compliance officers focus on expertise, judgement, and regulator relationships.

  • Alert triage: 10,000 AML alerts → 80 for human review
  • SAR draft generator: narrative from transactions; human signs
  • Regulatory change brief: daily MAS/BNM/FATF, impact-scored
  • KYC refresh scheduler: pre-populates dossiers for overdue reviews
  • Audit prep copilot: assembles examination evidence packs on demand
For Your Systems

Governing Your Technology Estate

Agents embedded in the IT/data layer act as continuous compliance monitors across infrastructure, databases, code pipelines, and cloud.

  • ITSM: classifies incidents by regulatory impact, routes to CCO if P1
  • Cloud config monitor: flags misconfigurations, unencrypted storage
  • SDLC security gate: static analysis agent reviews code for compliance
  • Data lineage auditor: tracks every agent read/write vs governance contracts
  • Change mgmt: assesses every ITSM change for compliance risk pre-CAB
For Your Downstream

Protecting APIs, Partners & Dashboards

Agents at the output layer ensure everything leaving the compliance estate — reports, feeds, API responses — is governed and regulator-ready.

  • Regulatory report agent: assembles, validates, submits MAS 610 / BNM
  • API governance agent: monitors partner integrations for data oversharing
  • COSMIC / STR agent: curates suspicious transaction reports for FIU
  • Sanctions list sync: OFAC/UN/MAS continuously vs customer master
  • Disclosure agent: ESG, conduct, and regulatory disclosure documents
Regulatory Matrix · ACAI Controls Mapped to Every Regulation

What MAS · EU · NIST · BNM
Actually Require of Your Agents

Complete traceability artefact — suitable for regulator examination, Board reporting, and audit evidence packs.

Requirement MAS FEAT + TRM EU AI Act NIST AI RMF BNM RAI ISO 42001 ACAI
Fairness & Bias Testing ✓ FEAT Fairness pillar — periodic bias audits, documented methodology ✓ Art.10 — training data bias; Art.15 — accuracy across sub-groups ✓ Measure — quantitative bias metrics with defined thresholds ✓ Ethical AI — non-discriminatory outcomes in credit and AML ✓ §6.1.2 — AI risk assessment includes bias and fairness criteria D9 · D7
Human Oversight ✓ FEAT Accountability — senior manager accountable; escalation paths defined ✓ Art.14 — mandatory for high-risk; intervention capability required ✓ Govern — policies for human oversight; Manage — intervention ✓ Board accountability — credit/AML decisions require human review capability ✓ §8.4 — human oversight requirements for high-impact AI D4 · D5 · D7
Explainability ✓ FEAT Transparency — decisions explainable to customers and regulators ✓ Art.13 — transparency & information provision; Art.12 — logging ✓ Map — contextual risk documentation; Measure — explainability metric ⚠ Emerging — transparency expected for retail; guidance evolving ✓ §9.1 — AI system performance monitoring including explainability D2 · D3 · D7
Immutable Audit Trail ✓ FEAT Accountability + MAS TRM §9 — all AI decisions logged with detail ✓ Art.12 — automatic logging throughout lifecycle; 6-month min retention ✓ Manage — risk documentation; logging across full system lifecycle ✓ RMIT — technology risk management requires comprehensive AI audit trails ✓ §8.5 — logging and record-keeping requirements for AI systems D2
Model Risk Validation ✓ FEAT Ethics + MAS MRM — validation before deployment; periodic re-validation ✓ Art.9 — risk management system throughout lifecycle; conformity assessment ✓ Measure — performance quantification; Map — risk ID; Manage — monitoring ✓ BNM RMIT — independent validation for models in regulated decisions ✓ §8.3 — AI system risk management including model validation D4 · D7
Agent Identity (NHI) ✓ MAS TRM §6 — access controls; privileged access management; identity governance ✓ Art.9 — access controls for AI systems; provider accountability ✓ Govern — roles and responsibilities; Map — stakeholder identification ✓ BNM RMIT §5 — technology access controls; IAM requirements for AI ✓ §6.2 — roles and responsibilities; access controls for AI management D1
Incident Response (Art.62) ✓ MAS TRM — serious AI incidents must be reported; post-incident review ✓ Art.62 — serious incidents to national authority within 15 days ✓ Manage — response and recovery; incident categorisation by risk level ⚠ BNM TRM — technology incidents reported; AI-specific guidance emerging ✓ §10.2 — nonconformity and corrective action; incident management D6 · D7
Third-party AI Vendor Risk ✓ MAS Outsourcing Guidelines — vendor AI tools subject to same scrutiny; due diligence ✓ Art.28 — obligations for deployers of third-party high-risk AI; liability chain ✓ Govern — third-party risk in AI supply chain; Map — vendor context ✓ BNM Outsourcing — AWS/Azure subject to outsourcing framework ✓ §8.6 — supplier and third-party management for AI systems D7
Basel III Op Risk Linkage ✓ MAS Notice 637 — operational risk capital; AI model failures are operational risk events ⚠ Indirect — EU AI Act liabilities could trigger Basel Op Risk capital add-ons ⚠ Partial — NIST manages risk but doesn't address capital adequacy ✓ BNM Capital Adequacy — operational risk framework covers AI failures ⚠ Not directly addressed — ISO 42001 is a management system, not capital framework D7
Maturity Model · Five Levels · CMMI-Inspired

From Ad hoc to
Autonomous — The Ladder

Like CMMI for software capability, the ACAI Maturity Model gives institutions a structured progression path. Most ASEAN Organizations are at Level 1 today. 12-month target is Level 3. Level 5 is the 3-year strategic horizon.

L1 — Ad hoc
Agents exist but compliance is invisible. Shadow agents operate without registry. No policy enforcement. Most ASEAN Organizations are here today.
20% Maturity · Risk: CRITICAL · Timeline: Now
Immediate action: Run Agent Census. Stop shared credentials. Document what exists. Takes 2 weeks. The risk of not doing it is existential.
D1 IdentityShared credentials, no registry, no lifecycle tracking
D2 ObserveOutputs logged only — no reasoning capture, no correlation IDs
D3 PolicyPolicies are Word docs — not machine-enforced at runtime
D4 LifecycleNo ADLC; agents deployed ad hoc by individual teams
D5 AgentsPoint solutions per team; no orchestration; duplicate capability
D6–D9No AI Risk Register, no fairness testing, no data classification for agents
10 Critical Innovation Ideas

Ideas That Will Define
Agentic Compliance by 2028

Hypothesis-tested. Nowhere else on the internet. The ideas that separate institutions building moats from those scrambling to catch up.

IDEA 01 · IDENTITY

The Agent Passport System

Every agent carries a cryptographically-signed W3C Verifiable Credential embedding identity, permissions, validation history, and kill-switch status. Systems refuse unauthenticated agents. Enables cross-bank agent trust in COSMIC-style networks without sharing raw data.

W3C VCDIDCOSMIC
IDEA 02 · OBSERVABILITY

Compliance Flight Recorder (CFR)

Borrow from aviation: every agent has a black-box CFR capturing the last 30 minutes of full Chain-of-Thought reasoning. When a compliance event occurs, investigators reconstruct the exact decision path. Write-once immutable store with regulatory key escrow held by neutral third party.

CoT LoggingImmutable StoreKey Escrow
IDEA 03 · GOVERNANCE

Agent Senate — Real-Time Governance

Replace the slow AI Ethics Committee with a real-time Agent Senate — a governance body where Legal, Risk, Technology, Business, and Compliance each hold quorum veto power. Meets daily for 15 minutes using an AI-summarised brief prepared by the Orchestrator Agent itself.

Quorum EngineDaily StandupCross-LoD
IDEA 04 · DATA

Compliance Semantic Layer as Agent Substrate

Every regulatory metric defined once, governed centrally, served to any agent, dashboard, or regulator via a single API. Agents never compute metrics independently — they query the semantic layer. Eliminates conflicting regulatory numbers across teams. Gives regulators a single consistent data interface.

Golden MetricsAgent RAGRegulator API
IDEA 05 · SECURITY

Adversarial Agent Red Team (AART)

Standing red-team "attacker agents" continuously probing production agents for prompt injection, jailbreak attempts, reward hacking, emergent behaviour, and policy bypass. AART finds vulnerabilities and auto-generates patch proposals routed to HITL. Continuous pen-testing for agentic systems — the first bank to operationalise AART sets the MAS model risk benchmark.

Red TeamingPrompt InjectionAuto-patch
IDEA 06 · LIFECYCLE

Agent Performance Review (APR)

Quarterly Agent Performance Review identical in rigour to human performance management. Evaluate: decision accuracy, FPR trend, escalation frequency, policy violation rate, fairness metrics. Underperforming agents are retrained or decommissioned. APR feeds directly into the AI Risk Register and model re-validation pipeline. The first institution to do this formally defines the ASEAN standard.

NHI LifecycleAI Risk RegisterQuarterly
IDEA 07 · ARCHITECTURE

Compliance-as-a-Mesh

Deploy compliance enforcement as a sidecar to every agent — a compliance mesh. Each sidecar holds the latest policy bundle (synced via GitOps), evaluates actions locally, and logs independently. If the central control plane goes down, agents continue within their last-known valid policy state. Zero single point of compliance failure. Architecturally equivalent to Istio service mesh for microservices.

OPA SidecarPolicy BundleGitOpsIstio pattern
IDEA 08 · ITSM

AICA — AI Incident Classification Agent

A compliance-aware agent in ServiceNow. When any incident is raised: (1) classifies regulatory impact, (2) assigns compliance risk rating P1–P4, (3) notifies CCO if P1 with EU Art.62 SLA triggered, (4) generates draft regulatory notification, (5) updates AI Risk Register. Closes the ITSM–Compliance loop that is currently 100% manual in every ASEAN bank.

ServiceNowArt.62 SLAAuto-notification
IDEA 09 · CONSORTIUM

Agent-to-Agent Typology Sharing (A2A-TS)

Federated LearningCOSMICA2A Protocol
IDEA 10 · THE FUTURE — THE BOLDEST IDEA IN THIS PLAYBOOK

Regulator-as-Agent Interface (RAAI)

Build a supervised, read-only agent interface for MAS/BNM supervisors. Regulators query compliance data in natural language: "Show me all AML cases involving crypto off-ramps in Q1 2026 with human-escalated outcomes and SAR filing times." The agent surfaces structured evidence with full citations to source data. Reduces examination burden by 60%+. Positions the institution as the most transparent bank in ASEAN — a trust moat that is essentially impossible to replicate without building everything in this playbook first.

Regulator InterfaceMAS ExaminationBNM Supervision60% exam reductionTrust Moat
12 Core Principles · The ACAI Doctrine

The Immutable Rules
Every Agent Lives By

P01
Policy First
Build the policy engine before the first agent. Compliance is the operating system. No agent goes to production without a machine-enforceable policy object governing its actions.
P02
One Identity Per Agent
Every agent has a unique, cryptographically-bound identity. Shared credentials are prohibited without exception. Accountability requires unambiguous identity — always.
P03
Humans Own Consequences
Agents draft, recommend, and classify. Humans decide on any action with irreversible or material regulatory consequence. SAR filings and account freezes require human approval — always.
P04
Explainability as Artefact
Every agent decision produces a structured, human-readable explanation stored immutably alongside the action. If you cannot explain it to a regulator in 24 hours, it should not have happened.
P05
Least Privilege, Always
Agents access only what their current task requires. JIT tokens for sensitive operations. A customer service agent has zero access to financial ledgers — by architecture, not by policy document.
P06
Hallucination = Compliance Risk
A fabricated regulatory interpretation is a compliance event, not a model error. All agent regulatory reasoning must be grounded in the authoritative RAG corpus with mandatory citation.
P07
Fairness is Non-Negotiable
Outcomes affecting customers must not differ materially by protected class. Fairness testing is a first-class ADLC gate. An unfair agent is a non-compliant agent, regardless of accuracy.
P08
Census Before Capability
Before building new agents, discover every agent that already exists. Shadow agents are a bigger compliance risk than ungoverned production agents — they are invisible. Run the Census first.
P09
Governance Closes the Loop
The Agent Lifecycle never ends without formal decommissioning. Zombie agents — processes left running after a project ends — are the primary vector for unmonitored data leaks.
P10
The Regulator is a Stakeholder
Design every compliance system as if a regulator will request a live demonstration tomorrow. Proactive MAS/BNM engagement is a strategic asset. The RAAI interface is this principle made real.
P11
Drift is Inevitable — Catch It Early
Every agent drifts from its validated baseline over time. Continuous behavioural monitoring with statistical drift detection is the difference between a governed agent and a ticking compliance clock.
P12
Compliance is Competitive Advantage
The institution that builds this framework first doesn't just avoid penalties — it builds a moat. Verified compliant AI opens markets, earns regulator trust, and enables capabilities competitors cannot safely deploy.
90-Day Sprint Playbook · Executable Monday Morning

Six Steps from Census
to Production in 90 Days

01
WEEK 1–2 · Foundation

Agent Census & Shadow AI Audit

Before building anything, find everything that already exists. Scan your full technology estate for autonomous AI: embedded vendor models (Salesforce Einstein, Oracle AI, SAP AI Core), internally-built scripts with LLM API calls, Microsoft Copilot integrations accessing production data. Build your Agent Registry from zero — this is your compliance ground truth. Most ASEAN Organizations discover 40–80 unregistered shadow agents in this 2-week sprint alone. Document owner, scope, risk tier, and data access for each.

Agent CensusShadow AI DiscoveryRisk RegisterVendor Review
02
WEEK 2–4 · Governance

Agent Senate & NHI Identity Framework

Establish the Agent Senate (5-person cross-functional governance body). Define the NHI identity schema and extend your IAM platform (CyberArk, SailPoint) to manage agent identities. Define the three-tier access model (Read / Write-Restricted / Execute-HITL). Configure JIT token provisioning for Tier 2/3. Publish the Agent Lifecycle Policy: who can create an agent, who must approve, what validation is required. This is the governance operating model — get it right before the first production agent deploys.

Agent SenateNHI IAMJIT ProvisioningCyberArk / SailPoint
03
WEEK 3–6 · Policy Layer

Policy-as-Code Store & Compliance Semantic Layer

Convert your top 20 most-referenced compliance rules into machine-enforceable OPA/Rego policies. Simultaneously, build the Compliance Semantic Layer — define your 30 core compliance metrics as versioned, governed definitions accessible via a single API. Ingest your authoritative regulatory corpus (MAS, BNM, FATF, BCBS) into a RAG vector store. This is the intelligence substrate every agent will query at runtime. Get this right and every subsequent agent is 3× faster to build.

OPA/RegoSemantic LayerRAG Vector DBMAS Corpus
04
WEEK 5–8 · First Agent

AML Alert Triage Agent in Shadow Mode

First production agent should be AML alert triage: highest volume, clearest ground truth, most measurable outcome, safest failure mode. Build with LangGraph. Wire to your TMS via MCP tool connector. Implement CoT logging via LangSmith or Arize Phoenix. Deploy in shadow mode for minimum 6 weeks. Target: ≥85% alignment with human decisions. Human compliance officers review outputs daily and provide feedback labels — this becomes your continuous training signal.

LangGraphActimize MCPShadow ModeLangSmith85% alignment target
05
WEEK 7–10 · Validation

Red Team, Model Risk Review & Regulator Engagement

Run structured red-team exercises: prompt injection via customer name fields and transaction narratives, adversarial transaction patterns, conflicting-rule scenarios, PEP edge cases. Engage Model Risk Management for independent validation aligned to MAS TRM and SR 11-7. Conduct initial fairness assessment across demographic groups. Brief the MAS Innovation Hub (Singapore) or file BNM i-RaPS (Malaysia) notification. Proactive regulator engagement at this stage is a compliance asset — not a liability.

Red TeamMRM ReportFairness AssessmentMAS Innovation HubBNM i-RaPS
06
WEEK 10–14 · Production Go-Live

Phased Go-Live with Full Observability & APR Calendar

Go-live at 20% traffic, scaling to 100% over 4 weeks. Maintain parallel human capacity for 90 days. Activate: Compliance Flight Recorder, circuit-breaker thresholds (auto-pause if FPR exceeds 15% above baseline), real-time compliance posture dashboard for CCO, and APR calendar (first APR at Day 90). Register the agent in your AI Risk Register. Begin building agent #2 (KYC refresh) using the same ADLC blueprint — the second agent takes half the time. Communicate to your Board: you are now a governed agentic compliance institution.

Canary 20%→100%CFR ActivatedCircuit BreakerFirst APRCCO Dashboard
"
"Compliance is not a constraint on agentic AI.
It is the operating system on which autonomous intelligence
earns the right to act at scale.
The institution that governs best — moves fastest."
ACAI Framework v2.0 · Agentic Compliance & AI Intelligence · April 2026