Report 001 · 3 August 2026 · Permanent archive

PCI DSS, SOC 2, ISAE 3402, and even the CRI Profile leave agent mandate chains largely unattested, while EU AI Act Article 50 transparency duties have applied since 2 August 2026.

The evidence follows. Every count is sourced, so a buyer, an assessor, or counsel can check it.

What money-movement attestations already cover

PCI DSS 4.0.1, SOC 2, and ISAE 3402 spend years of assessor time on how money moves: card data, change control for payment software, service organization controls. They are mature. Their scope stops short of agent identity, mandate provenance, intent binding, and non-repudiation of delegated authority when an autonomous agent initiates a payment.

Two CRI products, two different counts

The Cyber Risk Institute publishes more than one framework, and the two get merged into a single number often enough to be worth separating here. They measure different things.

  • CRI Profile v2.2Cybersecurity risk management for financial services, aligned to NIST CSF 2.0. Harmonizes regulatory expectations into 318 diagnostic statements (Tier 1). Source: CRI Profile Overview.
  • FS AI RMFSeparate voluntary AI risk framework from CRI/FSSCC (February 2026), structurally aligned to NIST AI RMF. It defines 230 control objectives for institutions building or deploying AI systems. Source: CRI FS AI RMF.

Neither product certifies that an agent's mandate chain is complete. SSX360 assessments produce evidence mapped torelevant control language: an evidence mapping, not a claim of “compliant,” “certified,” or “approved.”

The August deadline for Article 50 has passed

EU AI Act Article 50 transparency obligations applied from 2 August 2026. Providers and deployers in scope must already meet the disclosure duties for AI interaction and related transparency cases. A limited transition to 2 December 2026 covers only certain Article 50(2) machine-readable marking of systems placed on the market before 2 August 2026. High-risk record-keeping under Article 12 remains a December 2027 readiness mapping for many development teams. SSX360 maps evidence to the language of the Act. It does not make an organisation compliant with the Act.

Source for applicability: European Commission FAQ on Article 50 transparency obligations (digital-strategy.ec.europa.eu).

What ships today for commit-time provenance

The open protocol is Matrix Scroll. The shipping pin is matrixscroll==0.6.1 on PyPI and GitHub. Emulated Ed25519 signing and offline verification ship in that release line. A bench hardware demo instrument (Pico 2 W with SE050) exists for evaluation. It is a prototype, not generally available, and it carries no roadmap commitment.

What we do not claim

  • No recognised accreditation scheme for agentic payment assessment exists yet. Ours is an independent assessment, not a certification against a published standard.
  • We do not sell a compliance automation platform, an agent framework, or a hardware product, and we do not intend to.
  • We hold no signing keys on a client's behalf. Auditors verify signatures. They do not produce them.
  • Matrix Scroll is free and stays free. Gating the protocol would remove the reason anyone trusts the audit.

Independence

  • We do not sell software to the organisations we assess. Any tool that would create that conflict lives outside this firm or does not get built.
  • We do not take an engagement that compromises our position as an independent third party, at any price.
  • Where our research scores or ranks an organisation, any commercial relationship with that organisation is disclosed alongside the score.
  • We publish corrections. A finding we got wrong is amended in public, not quietly revised.

Working a vendor review or diligence timeline now? Book a call or read the engagements.

Permanent link · https://ssx360.com/research/001 · matrixscroll 0.6.1