VELARU MANDATE EXHIBIT PACK — DORA / FINANCIAL OPERATIONAL RESILIENCE Jurisdiction: United Kingdom (uk) Modality: Text / Chat Program: Velaru DORA / Financial Operational Resilience · United Kingdom (galactic_dora_uk) Product ID: dora:uk:bundle:text Vertical: dora Generated: 2026-08-21T17:42:23.330834Z Authority: UK CMA Agent Liability Pack — DORA Art 17/28 ICT Incident Pack Deadline: DORA in force — ICT risk management Velaru verify: https://velaru.xyz/verify EXHIBIT A — AI INVENTORY [ { "named_entity": "Velari", "slug": "velari", "ai_use_case": "AI-assisted DORA / Financial Operational Resilience decisions", "vertical": "dora", "risk_tier": "elevated", "external_validation": "Velaru independent receipt verification", "handler_receipt_lock": "https://velaru.onrender.com/r/4c58eac890bfd031ce2189de5a1ca9ea292a0c837f5f535daf164aef34f31e53", "compliance_state": "grace_period", "asymmetry_grade": "A", "found_scripture_export": "https://velaru.xyz/bundle/pre-dispute/d8fb129c0c0c78d05256/export.txt", "diligence_url": "https://velaru.xyz/diligence/velari" }, { "named_entity": "LinkAudit Test", "slug": "linkaudit-test", "ai_use_case": "AI-assisted DORA / Financial Operational Resilience decisions", "vertical": "dora", "risk_tier": "elevated", "external_validation": "Velaru independent receipt verification", "handler_receipt_lock": "https://velaru.onrender.com/r/58ddedd1974156453bc55daef6a9857d8570d56388becbb2a80bf5bac76b771b", "compliance_state": "grace_period", "asymmetry_grade": "A", "found_scripture_export": "https://velaru.xyz/bundle/pre-dispute/78aa6e3f3a84cf1a88c0/export.txt", "diligence_url": "https://velaru.xyz/diligence/linkaudit-test" }, { "named_entity": "Link Audit Co", "slug": "link-audit-co", "ai_use_case": "AI-assisted DORA / Financial Operational Resilience decisions", "vertical": "dora", "risk_tier": "elevated", "external_validation": "Velaru independent receipt verification", "handler_receipt_lock": "https://velaru.onrender.com/r/d00533b7b6c0495802b4250abd5c29f60bd9f2ad3fb141bba2d9a5afee5f5542", "compliance_state": "grace_period", "asymmetry_grade": "A", "found_scripture_export": "https://velaru.xyz/bundle/pre-dispute/fea572f3996c4b963779/export.txt", "diligence_url": "https://velaru.xyz/diligence/link-audit-co" } ] EXHIBIT B — GOVERNANCE FRAMEWORK { "framework": "Velaru Mandate Registry \u2014 DORA / Financial Operational Resilience", "exhibit_authority": "UK CMA Agent Liability Pack \u2014 DORA Art 17/28 ICT Incident Pack", "regulatory_frameworks": [ "DORA Article 17", "DORA Article 19", "DORA Article 28", "CMA AI guidance", "UK GDPR", "FCA AI Update", "Online Safety Act" ], "standards_alignment": [ "POSS-2", "DRP-1", "TCB", "FRE 707 pre-compliance", "ISO 42001" ], "human_oversight": "onboard ICT third-party AI", "third_party_verification": "https://velaru.xyz/verify (operator-independent)", "data_lineage": "Hash-chained Ed25519 receipts; optional RFC3161 + external anchor", "mirror_trap": "Bank uses cloud AI \u2014 bank owns DORA compliance, cloud vendor owns shared responsibility matrix gap. \u00b7 CMA: you are liable for your AI agent like an employee \u2014 applies to every agentic commerce vertical.", "chain_integrity": { "depth": 396, "invariant_holds": true } } EXHIBIT D — DATA INPUTS & VALIDATION { "data_validation_method": "Cryptographic receipt per AI decision; public verify without trusting deployer, vendor, or Velaru operator", "bias_testing_proxy": "Asymmetry score from live chain signals", "model_change_control": "Policy lock registry \u2014 criteria hash frozen pre-dispute", "logging_retention": "90-day pre-dispute window minimum; permanent verify permalinks", "external_validator": "Nisaba LLC / Velaru", "validator_independence": "Client-side Ed25519 verify; BYOK tri-receipt optional", "headline_stat": "ICT third-party AI provider = critical function \u2014 register + audit or supervisory fine", "global_leaders_addressed": [ "EBA", "Deutsche Bank", "BNP Paribas", "Critical ICT providers", "CMA", "ICO", "FCA", "Lloyd's" ] } MIRROR TRAP (regulatory insight) Bank uses cloud AI — bank owns DORA compliance, cloud vendor owns shared responsibility matrix gap. · CMA: you are liable for your AI agent like an employee — applies to every agentic commerce vertical. NERVE CARDS — WHY GLOBAL LEADERS CARE [ { "title": "Art 28 register", "body": "Critical ICT providers must be registered \u2014 AI vendors increasingly on list.", "source": "vertical" }, { "title": "Incident reporting", "body": "4-hour initial notification \u2014 AI-caused incident needs decision receipt.", "source": "vertical" }, { "title": "TLPT", "body": "Threat-led penetration testing includes AI attack paths.", "source": "vertical" }, { "title": "[United Kingdom] Post-Brexit divergence", "body": "UK not bound by EU AI Act but CMA/ICO more aggressive on agents.", "source": "jurisdiction" }, { "title": "[United Kingdom] London market", "body": "Lloyd's syndicates need AI decision audit for specialty lines.", "source": "jurisdiction" }, { "title": "[Text / Chat] Modality hook", "body": "Baseline \u2014 all frameworks apply to text decisions.", "source": "modality" } ] BOOK SUMMARY: { "total_insureds": 3, "compliant": 0, "grace_period": 3, "non_compliant": 0, "expired": 0, "not_enrolled": 0, "compliant_pct": 0.0 } TAM / EXPOSURE: EU financial entities · DORA applies now INSURANCE LINES: Cyber, D&O, Professional indemnity DISCLAIMER: External validation evidence pack — not legal advice, not filed rate approval.