Jurisdictions · clause in, evidence out

The regulator does not ask you to assert compliance.
It asks when you last proved it.

Read any supervisory guideline closely and one shape recurs: a clock, a coverage window, an independence requirement, or a record that must survive years and an examiner. Each obligation below is set against what is produced to answer it. Every citation is to published text; sources are at the foot of the page.

§ 01

Central Bank of the UAE. Sovereignty is a location requirement.

The Master System of Record holding Confidential Data must be continuously maintained and stored within the UAE (Outsourcing Regulation, Art. 6.1). A foreign branch may hold a daily-refreshed copy with approval (6.2); providers must offer the same standard of safeguarding (6.4); the institution stays accountable for everything a provider does. Self-hosted inside the perimeter does not answer these requirements well — it removes the question. And the enabling-technologies guidelines have asked for five-year AI audit trails, version records and independent validation since November 2021.

CBUAE — the obligation
What is produced
Article 6.1 — a location requirement, not a preference
The Master System of Record stays inside the UAE perimeter
Five-year audit trail of decisions, versions and data — cl. 3.97
Every step witnessed, sealed and anchored at the time it ran; the record still means something in year five
Explainable, reconstructable model decisions — cl. 2.27, 3.98
A conclusion nobody can reconstruct is not evidence of a decision; replay to source, as of any date
Independent validation before and after deployment — cl. 3.102, 3.106
Evidence portable to a validator who has never touched the system
Robust versioning of data, code and expected outcomes — cl. 3.108
A version change is an input change, and is recorded as one
Institution remains accountable for providers — cl. 3.96
Nothing outsourced holds the record; audit rights exercised against a system inside your estate
Governing body · cl. 3.94, 3.95, 3.115
Accountable for AI outcomes under a framework it approved. Needs to know what was deployed, on whose approval, on what basis.
Model owner · cl. 3.99, 3.103, 3.108
Holds design documentation, data-quality position and the versioning record — produced as the work happens.
CISO · cloud owner · cl. 3.24, 3.31–3.34, 3.61
Materiality, data-centre due diligence, contracts with audit rights, annual security testing.
Internal audit · cl. 2.2, 2.3
Independent review at a frequency set by materiality; a record it can verify without relying on the function that produced it.
Schematic: the Master System of Record remains inside the UAE; crossing requires central bank approval, written customer consent and customer acknowledgement.
FIG. G — Deployed inside the bank, the dashed arrow is never drawn. There is no crossing to approve, consent to, or disclose.
§ 02

Bank of Mauritius. Show the work, not the conclusion.

The guidelines apply proportionately — what proportionality adjusts is the scale of the framework, not the requirement to evidence it. A D-SIB carries a two-year audit cycle and a distinct cyber sub-committee; a mid-tier bank the same forty-eight-month window with a dozen people; a branch may adopt its parent's framework provided it can be evidenced locally. A smaller framework is permitted. A smaller record is not.

Bank of Mauritius — the obligation
What is produced
Every obligation tested within a three-year cycle, never beyond 48 months — Compliance § 2.14
A last-proved date per obligation, aged against the window; who tested, on what evidence
Any new or amended law tested within one year of effect — § 2.17
Effective date carried as an input; the clock is the record's, not a calendar's
Quarterly board report on breaches, deficiencies and remediation — § 2.18
Closed means closed against verified evidence; a closure without it is reported as claimed, not complete
Compliance independent of business lines and reviewed by internal audit — § 2.1(b), § 3.1–3.3
Separation enforced by the system that records the work: the person who remediates cannot be the person who closes
Critical logs and digital evidence retained seven years — Cyber ¶ 58; audits ¶ 65, 67, 95
Sealed observations, replayable after the staff, the tooling and the vendor have all changed
Hosting outside Mauritius: host-country due diligence, foreign-authority access risk, audit rights, evidenced exit — Cyber ¶ 38(v), 43–46
Deployed inside the institution, most of that file does not arise; evidence never leaves the bank's own estate

Five people — Head of Compliance, CRO, CISO, Internal Audit, the examiner — and four of them required to be independent of each other. What serves all five is a record whose integrity an examiner checks on their own machine. Not "trust the platform." Not "trust the bank." An examiner who must trust the vendor to believe the evidence has not received evidence.

Each mark is one obligation, plotted by months since it was last tested, against the 48-month limit.
FIG. H — The obligation nobody is looking at is the one closest to the wall. Schematic — shape only, no data.
§ 03

EU AI Act. Annex IV is a state to remain in, not a date to survive.

Article 11 requires technical documentation for every high-risk system; Annex IV specifies its contents; the obligation runs for a decade. Below is what Annex IV asks for, and what is produced against it.

1 · System description
Intended purpose, deployment context, architecture, dependencies — emitted from the planning layer.
2 · Detailed design
Methodology, design choices, key parameters, training data and validation procedures — captured at blueprint generation.
3 · Monitoring & control
Human oversight measures, accuracy and robustness specifications — bound into the enforcement contract.
4 · Risk management
Identified risks, mitigations, residual risk — versioned alongside the blueprint and re-evaluated on change.
5 · Lifecycle changes
Change log, validation outcomes, version history — every change is a sealed event.
6 · Standards applied
Harmonised standards and technical specifications — declared and traceable to controls.
7 · Declaration of conformity
Issued against a specific blueprint version with a stable, citable reference.
8 · Post-market monitoring
Continuous observation against specification — produced live, not assembled retroactively.
9 · Performance metrics
Accuracy, robustness and cybersecurity metrics in the form expected by notified bodies.
A deadline is one tick on the axis; the documentation obligation runs ten years past it.
FIG. I — Not a date to survive. A state to remain in.
§ 04

US frameworks. Resolved once, not maintained nine times.

NIST AI RMF · NIST CSF 2.0
Governance, mapping, measurement and management functions expressed as executable controls rather than a maturity narrative.
SOX · ICFR
Control design and operating effectiveness for financial reporting, with change authority and segregation of duties evidenced at the moment of change.
SEC cybersecurity disclosure
Item 1.05 materiality determination and Item 106 governance disclosure, supported by a record of what was known, when, and on which system.
HIPAA · HITECH
Security Rule safeguards and breach-notification timelines, with administrative, physical and technical controls held as one sequence.
FedRAMP · NIST SP 800-53
Baseline control inheritance, continuous monitoring and POA&M evidence produced as system output rather than assembled for assessment.
PCI DSS 4.0 · NY DFS Part 500
Customised-approach documentation and annual certification obligations, held against the systems that actually implement them.
ISO/IEC 27001 · 42001 · SOC 2
Statement of applicability, AI management system requirements and Trust Services Criteria mapped once across overlapping scope.

Where two authorities conflict, the decision is recorded — not left to the reader. The overlap is resolved once into one control set, emitting one evidence record that answers every framework above.

§ 05

Where each claim stops.

The four boundaries on the home page apply here without amendment. Five more are specific to these jurisdictions.

Mapping is not approval
Obligations from published CBUAE and Bank of Mauritius text are represented as controls. Nothing here is endorsed, reviewed or approved by either regulator, and no representation is made that it has been.
Evidence is not compliance
This system produces records of what was examined and what was found. Whether an institution meets its obligations is a supervisory judgement, made by people, on the whole of its conduct.
What coverage means
It does not mean every control is automated. Some obligations are governance acts performed by named officers — a board approval, a semi-annual meeting, a notification. The system records them. It does not perform them.
Not model assurance
Deployment inside the institution answers a data-location requirement. It does not establish that a model is accurate, fair or fit for purpose — that rests on validation the institution performs.
Not advice
Nothing here substitutes for the institution's own reading of the text it is bound by. Clause references are to the text as published at the dates below; where our reading and yours differ, yours governs.

Sources — Central Bank of the UAE Rulebook: Outsourcing Regulation for Banks, Art. 6; Guidelines for Financial Institutions Adopting Enabling Technologies, 15 November 2021. Bank of Mauritius: Guideline on Compliance Risk Management and Governance Framework, 13 November 2024; Guideline on Cyber and Technology Risk Management, 29 May 2023; Guideline on Use of Cloud Services, 7 September 2022; Guidelines on Outsourcing by Financial Institutions, 6 January 2026. Regulation (EU) 2024/1689, Art. 11 and Annex IV.

Logic Axon Shield LLC§ 06 · Begin

Bring the guideline you are worried about.

A diligence call covers the mapping to the specific text that binds you, deployment inside your perimeter, what the evidence does and does not establish, and pilot scope. Thirty minutes. With the founder. No SDR layer, no qualification gauntlet.