MnemoPay for Compliance Teams — EU AI Act Article 12 audit bundles, ISO 42001, agent governance
EU AI Act · Article 12 · ISO 42001 · SOC 2

Tamper-evident records of every tool call, payment, memory write, and refusal. Merkle-rooted, signed, regulator-shaped. Exportable on demand.

01
Article 12
audit bundle export · shipped
02
Ed25519
signed every action
03
FiscalGate
budget enforcement
04
SOC 2 in progress
Type II observation Q3 2026
Where we are, plainly

“Honest about what’s shipped, what’s in flight, what isn’t.”

No vapor.
No surprises in procurement.

If we don’t have it yet, this page tells you that. SOC 2 Type II is in observation phase. ISO 42001 alignment is underway. The audit-bundle export and FiscalGate are live in v1.4.2. Dates are honest commitments — not pitch-deck dates.

Shipped · v1.4.2

Article 12 audit bundle export

Merkle-rooted SHA-256 chain over every tool call, payment, memory write, refusal. Signed receipts. Exportable as a single JSON+signatures bundle for deployer or regulator review.

Shipped

Ed25519 agent identity

Every action signed by the agent’s keypair. Every receipt verifiable independently. Canary honeypots flag impersonation. Cryptographic chain of custody for the audit trail.

Shipped

FiscalGate budget enforcement

Charters declare a max-USD budget. Every priced tool call routes through a hold/settle two-phase commit. Runaway agents hit the cap and abort. Auditable record of every approval and refusal.

Shipped

PII redaction on memory write

Email, phone, credit-card, SSN-shaped patterns redacted before persistence. Decay policies by domain. Right-to-erasure tooling for GDPR / CCPA subject requests.

In progress

SOC 2 Type II

Type I attestation in scoping. Type II observation period targeting Q3 2026. Auditor selection in flight. We’ll publish the report URL on this page when complete.

In progress

ISO 42001 alignment

Mapping each ISO 42001 control to a corresponding MnemoPay SDK primitive or operational policy. Targeting alignment doc by Q3 2026; certification targeting H1 2027.

In progress

AIGP-certified personnel

Founder enrolled in IAPP AIGP certification path. Adding a fractional GRC advisor (CIPP/E + AIGP) for enterprise pilot engagements.

Roadmap

DORA Article 17 mapping

For financial-services agents in EU. Mapping audit-bundle format to DORA ICT incident reporting expectations. Customer-driven; first design partner targeting Q4 2026.

Roadmap

Colorado AI Act + state-level US

Colorado AI Act (effective June 30, 2026) overlaps Article 12 obligations. State-by-state mapping doc planned. NIST AI RMF crosswalk first.

The bundle

What an
Article 12 bundle
actually looks like.

Every audit bundle is a single signed JSON file containing the agent’s identity and capability tokens; every tool call with arguments and return values (secrets redacted); every payment hold/settle/refund with rail and counterparty; every memory write with content hash; every refusal and approval with rationale; the Merkle root binding it together.

Typical size
~2–4 MB / day
at 1000 actions/day, ~600 KB compressed
Retention
6 months +
extensible to 7 years (DORA)
article12-bundle.json
"bundleVersion": "1.0.0",
"missionId": "ms_3a8...c91",
"agent": { "id": "checkout-bot", "publicKey": "ed25519:..." },
"generatedAt": "2026-05-06T19:47:02.144Z",
"retentionMonths": 6,
"events": [
  {
    "ts": "2026-05-06T19:32:11.020Z",
    "kind": "payment.hold",
    "rail": "stripe",
    "amountUsd": 24.99,
    "counterparty": "cus_***[redacted]",
    "fiscalGate": { "remainingUsd": 75.01, "status": "approved" },
    "sig": "ed25519:8xK..."
  },
  { "ts": "...", "kind": "memory.write", "contentHash": "sha256:9b2..." },
  { "ts": "...", "kind": "tool.refusal", "tool": "delete_user", "reason": "out_of_scope" }
],
"merkleRoot": "sha256:f1c4...8d3",
"signature": "ed25519:..."
JSON Schema published at github.com/mnemopay/mnemopay-sdk
Regulations · mapped

One bundle.
Multiple regimes.

Compliance officers don’t buy SDKs — they buy mappings. Here’s where MnemoPay’s audit bundle satisfies what.

EU AI Act · Article 12
Direct

Automatic recording of events for high-risk AI systems. 6-month minimum retention. Bundle export covers logging requirement directly. Article 26 (deployer obligations) inherits.

Enforcement Aug 2, 2026
ISO 42001
Alignment

AI management systems standard. Bundle satisfies controls A.6.2 (records), A.7 (lifecycle), A.8 (data & PII). Crosswalk doc in flight; full alignment Q3 2026.

Voluntary, but procurement-grade
NIST AI RMF
Crosswalk

US voluntary framework, de-facto standard. Bundle maps to Govern (GV), Manage (MG), Measure (MS) functions. Same evidence file works for Colorado AI Act safe harbour.

Foundation for state-level US compliance
DORA · Article 17
Roadmap

Financial sector ICT incident reporting. Bundle format being extended for 7-year retention + financial-supervisor format. Customer-driven; first design partner Q4 2026.

For EU financial-services agents
Pilots

Three to five
enterprise pilots.

A pilot is 90 days, fixed-fee, with a defined deliverable: a working agent with full audit-bundle export, mapped to your specific compliance regime — EU AI Act, NIST AI RMF, ISO 42001, NYC LL144, or sector-specific.

Mid-market
$25K–$60K

90-day pilot, fixed-fee. Single agent, single regime mapping. Includes audit-bundle integration, custom event taxonomy, regulator-shaped export, and a compliance summary report at end of period.

Enterprise
$100K+

Multi-agent fleet, multi-regime mapping, named CSM, sector-specific work (finance, health, public-sector). Includes co-development of evidence formats with your auditor of record.

Honest about the gap

SOC 2 Type II is in observation period, expected Q3 2026. We’ll be transparent about that during procurement — and we’ll work with your InfoSec team to bridge it (segmented data handling, contractual controls, attestation letter from our Type I auditor) until Type II lands.

Email pilot enquiry arrow_forward jeremiah@getbizsuite.com · response within 48 hours

No surprise sales cycle · yes / no / not-yet, plainly