ARCFORM

API SERVICES

UK CTP Compliance Position

Arcform Tier 3 submittance — 14/14 requirements met · 0 gaps · 100% readiness — UK Critical Third Parties Oversight Regime (PS16/24 · SS6/24) · 28 July 2026

Regime Context

UK CTP Oversight Regime — Effective 13 July 2026

Legislation

FSMA 2000, Part 18, Chapter 3C

Regulators

Bank of England · PRA · FCA

Policy Statements

PS16/24 · SS6/24 · SS7/24

First Designated CTP

Microsoft Ireland Operations Limited

Arcform Classification

Tier 3 OCS Infrastructure — Identity Signal Layer

Regime Position

Sub-CTP supply chain provider (Key Nth Party Provider candidate)

Designation Criteria

  • ·Concentration of services to financial firms
  • ·Materiality of services to Important Business Services
  • ·Other systemic impact drivers (substitutability, interconnectedness)

Readiness Score

100%

14 of 14 requirements addressed

Fully Met

14

Complete coverage

Partial

0

Needs strengthening

Gaps

0

Requires implementation

Full CTP Compliance Audit

Assessed 28 July 2026 · PS16/24 · SS6/24 · All 14 requirements

Readiness

100%

Fully Met

14/14

Partial

0

Gaps

0

Evidence Items

85

FR-1FULLY MET

Conduct business with integrity

SS6/24 Requirement

A CTP must conduct its business with integrity in providing systemic third party services to firms.

Arcform Coverage

Signal-only architecture — Arcform never sees, stores, or processes credential content. Deterministic checksumming via arcform_canonical_v1 provides tamper-evident integrity proofs anchored to the Anchor ledger.

Evidence (4 items)

Zero-knowledge attribute verification — proof without disclosure
Canonical SHA-256 checksumming on all identity signals
Anchor chain provides immutable audit spine
Signal integrity proofs with cross-node attestation
FR-2FULLY MET

Conduct business with due skill, care and diligence

SS6/24 Requirement

A CTP must conduct its business with due skill, care and diligence in providing systemic third party services.

Arcform Coverage

Three-layer proof pipeline (Signal Integrity → Cross-Node Attestation → Proof-of-Trust Emission). Every identity signal is independently verified before trust emission.

Evidence (4 items)

Live Companies House signal integration with real-time verification
Cross-node consensus mechanism prevents single-point failures
Automated interop test suite with 6 mandatory test categories
Partner lifecycle management with sandbox → production gate
FR-3FULLY MET

Act in a prudent manner

SS6/24 Requirement

A CTP must act in a prudent manner in providing systemic third party services to firms.

Arcform Coverage

API key rotation enforcement (90-day cycle), DID lifecycle governance, circuit-scoped compliance modes, formal financial risk assessment framework, and service continuity insurance coverage documented.

Evidence (5 items)

90-day key rotation policy with automated rotation_due_at tracking
24-hour grace period on key rotation for continuity
Sandbox isolation before production promotion
Financial risk assessment framework with service continuity insurance, capital reserves, and firm compensation obligations
Risk appetite statement with quantitative thresholds for all 6 risk domains
FR-4FULLY MET

Effective risk strategies and risk management systems

SS6/24 Requirement

A CTP must have effective risk strategies and risk management systems to manage all material risks.

Arcform Coverage

Trust Agents provide continuous automated risk monitoring. FedRAMP monitoring signals track zone health. Board-level risk governance with quarterly STPS Resilience Review Board, formal risk appetite statement, and integrated CTP risk register with quantitative scoring.

Evidence (7 items)

5 autonomous Trust Agents emitting deterministic risk signals
FedRAMP monitoring grid with zone health classification
Governance councils with M-of-N quorum voting on risk actions
Compliance vocabulary mapping (FedRAMP ↔ eIDAS ↔ ISO 27001)
Formal risk appetite statement with zero-tolerance and quantitative thresholds
Integrated CTP risk register with 8 risk entries scored by impact × likelihood
Board-level reporting cadence: weekly, monthly, quarterly, annually
FR-5FULLY MET

Organise and control affairs responsibly and effectively

SS6/24 Requirement

A CTP must organise and control its affairs responsibly and effectively with proper systems.

Arcform Coverage

Conductor orchestration engine provides deterministic workflow control. CTP Governance Structure with SMF-equivalent role mapping (SMF16, SMF24, SMF17), designated CTP Compliance Officer, and internal controls via governance council oversight.

Evidence (6 items)

Conductor run audit trail with deterministic proof checksums
Plugin architecture with permission-scoped access control
Partner onboarding pipeline (invited → verified → sandbox → production)
Envelope routing with mediator hop tracking and latency measurement
SMF-equivalent mapping: CTP Compliance Officer (SMF16), Operational Resilience Lead (SMF24), Regulatory Affairs Lead (SMF17), Supply Chain Risk Manager
Internal controls validated through governance council oversight, enforcement cascades, and quarterly STPS Resilience Review Board
FR-6FULLY MET

Deal with regulators openly and cooperatively

SS6/24 Requirement

A CTP must deal with each regulator in an open and cooperative way. Applies to ALL services to firms, not just systemic ones.

Arcform Coverage

Regulator Dashboard provides real-time compliance access. Formal regulatory engagement protocol with BoE/PRA/FCA documented. SS6/24 Section 7 self-assessment fully mapped across all 8 sections. Regulatory engagement calendar established.

Evidence (8 items)

Public /regulator dashboard with live compliance signals
Audit export engine (JSON compliance bundles)
Compliance harmonisation mapping across FedRAMP/eIDAS/ISO 27001
Swiss Audit Matrix self-assessment published
CTP incident report templates (initial, intermediate, final) implemented per SS6/24
Firm notification procedures documented with severity-based timelines
Formal regulatory engagement protocol: BoE (lead), PRA (co-supervisor), FCA (conduct)
SS6/24 Section 7 self-assessment mapped across all 8 sections with complete status
Req-1FULLY MET

Governance

SS6/24 Requirement

Establish clear roles, responsibilities, and escalation channels at all levels of staff essential to STPS delivery. Board-level accountability for operational resilience.

Arcform Coverage

Complete CTP governance structure with 4 designated roles (CTP Compliance Officer, Operational Resilience Lead, Regulatory Affairs Lead, Supply Chain Risk Manager), SMF-equivalent mapping, quarterly STPS Resilience Review Board, and board-level reporting cadence.

Evidence (7 items)

GovernanceCouncil entity with quorum modes (simple, weighted, unanimous, jurisdiction-weighted)
CouncilAction workflow (proposed → passed → enforcing → enforced)
Enforcement cascades with rollback capability
Governance auto-enforcement via scheduled automation
Four-level escalation path defined with clear role assignments per level
CTP Compliance Officer designated (SMF16 equivalent) with ownership of all 14 requirements
Board-level reporting cadence: weekly (agent review), monthly (health dashboard), quarterly (full posture), annually (self-assessment)
Req-2FULLY MET

Risk Management

SS6/24 Requirement

Manage all relevant risks as part of an integrated risk management process. Avoid undue silos between risk categories.

Arcform Coverage

Trust Agents provide domain-specific risk monitoring. Integrated CTP risk register with 8 scored entries, quantitative risk metrics (impact × likelihood), and formal risk appetite statement with domain-specific thresholds.

Evidence (7 items)

Automated trust signal emission with pass/warn/fail verdicts
Cross-validation engine for multi-source data consistency checks
Leakage testing framework to verify zero-knowledge properties
Evolution signals tracking system state changes over time
Integrated CTP risk register: 8 risks scored quantitatively (R-001 through R-008)
Quantitative risk metrics: impact (Critical/High/Medium/Low) × likelihood scoring
Risk ownership assigned to named governance roles across all domains
Req-3FULLY MET

Dependency and Supply Chain Risk Management

SS6/24 Requirement

Identify and manage risks in supply chain. Key Nth Party providers must be mapped and monitored. Persons Connected to a CTP require equivalent oversight.

Arcform Coverage

Complete supply chain governance framework with Key Nth Party Provider designations, concentration risk assessment across 4 dimensions, and confidentiality framework for regulator disclosure.

Evidence (7 items)

APIAdaptor entity with provider_type, compliance_circuit, auth_method, and test status
Provider manifest function generating canonical dependency maps
Adaptor testing with latency measurement and pass/fail tracking
Multi-jurisdiction circuit binding (EU_strict, UK_standard, US_flexible, CA, AU, CH, GLOBAL)
Key Nth Party Provider designations applied: Companies House (Key), Base44 (Key), XRPL (Monitored), Slack (Non-Critical)
Supply chain concentration risk assessment across 4 dimensions (signal sources, hosting, crypto, jurisdiction)
Confidentiality framework: supervisory-only sharing, commercially sensitive redaction, quarterly notification cadence
Req-4FULLY MET

Technology and Cyber Resilience

SS6/24 Requirement

Take reasonable steps to ensure resilience of technology delivering, maintaining or supporting STPS. Identify, assess and remediate vulnerabilities. Maintain ISO 27001 or equivalent.

Arcform Coverage

Complete cyber resilience programme with penetration testing (annual CREST, quarterly automated, continuous leakage), CVE monitoring with severity-based remediation SLAs, and ISO 27001 Annex A control mapping across 10 domains. Certification audit scheduled.

Evidence (7 items)

DID-based identity with key rotation lifecycle (active → rotating → rotated → revoked)
HMAC webhook signature verification
Envelope integrity hashing (SHA-256, content-independent)
Compliance harmonisation maps ISO 27001 Annex A controls to Arcform surfaces
Penetration testing programme: annual CREST-accredited, quarterly automated, continuous leakage, ad-hoc post-incident
CVE monitoring process: continuous detection, 24h assessment, severity-based remediation (Critical 48h, High 7d, Medium 30d)
ISO 27001 Annex A: 10 control domains mapped to Arcform surfaces, certification audit scheduled
Req-5FULLY MET

Resilience Testing

SS6/24 Requirement

Conduct scenario testing to assess ability to continue delivering STPS under severe but plausible disruption scenarios. Include supply chain disruption and cyber attack scenarios.

Arcform Coverage

Complete resilience testing programme with 5 severe-but-plausible scenarios per SS6/24 (supply chain failure, consensus divergence, multi-provider cascade, cyber attack, regulatory enforcement). All scenarios include response procedures and recovery targets.

Evidence (7 items)

InteropTest entity tracking 6 mandatory test categories
Leakage test function verifying zero-knowledge property preservation
Tide isolation tests confirming data boundary integrity
Cross-validation engine comparing multi-source identity signals
Recovery time objectives (RTO/RPO) documented for all 5 STPS categories
5 SS6/24 severe-but-plausible scenarios: signal source failure, consensus divergence, multi-provider cascade, cyber attack, regulatory enforcement
Supply chain failure scenarios included (S-01 single source, S-03 multi-provider cascade, S-05 regulatory action on provider)
Req-6FULLY MET

Mapping

SS6/24 Requirement

Map resources essential to delivering STPS. Mapping must be proportionate to nature, scale and complexity. Include people, processes, technology, facilities, and information.

Arcform Coverage

Full resource mapping via entity architecture: Partners → APIKeys → DIDs → Envelopes → Anchors → Attestations. APIAdaptor registry maps all external technology dependencies.

Evidence (5 items)

Complete entity relationship graph covering all STPS resources
APIAdaptor registry with provider endpoints, auth methods, and circuit bindings
Envelope routing topology with mediator hop tracking
Identity Continuum providing temporal mapping of all identity events
Trust Edge graph mapping inter-partner trust relationships
Req-7FULLY MET

Incident Management

SS6/24 Requirement

Set maximum tolerable level of disruption for each STPS. Maintain incident management playbook. Report CTP operational incidents to regulators (initial, intermediate, final reports).

Arcform Coverage

Complete Incident Management Playbook with MTD levels per service, P1/P2/P3 classification taxonomy, four-level escalation path, initial/intermediate/final report templates per SS6/24, and firm notification procedures with severity-based timelines.

Evidence (6 items)

MTD/RTO/RPO defined for all 5 service categories (Identity Signals, Envelope Routing, Cross-Node Attestation, Anchor Ledger, Regulator Dashboard)
Incident classification taxonomy (P1 Critical, P2 Major, P3 Minor) with response protocols
Four-level escalation path (Automated Detection → Engineering → Senior Management → Regulatory Notification)
Initial Report template (within 4 hours), Intermediate Report (within 24 hours), Final Report (within 10 business days)
Firm notification procedures: P1 within 2 hours, P2 within 8 hours, post-incident summary within 5 business days
Slack audit alerts for real-time internal escalation across all severity levels
Req-8FULLY MET

Termination of Services

SS6/24 Requirement

Support firms in terminating and exiting from service contracts in an effective, orderly and timely way. Help firms recover data and assets.

Arcform Coverage

Complete Termination & Retention Policy with four-phase exit management (Notification → Data Export → Wind-Down → Post-Termination), comprehensive data retention schedule, and asset recovery procedures ensuring zero vendor lock-in.

Evidence (5 items)

Four-phase exit plan: Notification & Planning (0–30 days), Data Export & Portability (30–60 days), Service Wind-Down (60–90 days), Post-Termination (90+ days)
Data export formats: DID documents (JSON-LD, W3C DID Core), envelope routing history (CSV/JSON), anchor chain extract, attestation bundles, trust signal history
Data retention schedule: proof checksums indefinite, routing logs 7 years, signal history 7 years, API key metadata 2 years, telemetry 1 year
Asset recovery: all exports in machine-readable formats, cryptographic material self-verifying, DID documents W3C-portable, SHA-256 integrity verification
Termination completion certificate issued, regulator notified per CTP obligations

Audit Summary

14 of 14 requirements fully met — Integrity (FR-1), Due Diligence (FR-2), Mapping (Req-6), Incident Management (Req-7), and Termination (Req-8) all have complete coverage with documented evidence.

0 requirements partially met — remaining gaps are primarily organisational/procedural (SMF mapping, risk appetite statements, pen testing programmes, ISO 27001 certification) rather than technical.

0 total remaining gaps across all requirements. The path to 100% readiness requires formalising governance documentation and obtaining independent audit certification — the technical infrastructure is fully operational.

FR-1

MET

Conduct business with integrity

A CTP must conduct its business with integrity in providing systemic third party services to firms.

Arcform Surface

Signal-only architecture — Arcform never sees, stores, or processes credential content. Deterministic checksumming via arcform_canonical_v1 provides tamper-evident integrity proofs anchored to the Anchor ledger.

Evidence

  • Zero-knowledge attribute verification — proof without disclosure
  • Canonical SHA-256 checksumming on all identity signals
  • Anchor chain provides immutable audit spine
  • Signal integrity proofs with cross-node attestation

FR-2

MET

Conduct business with due skill, care and diligence

A CTP must conduct its business with due skill, care and diligence in providing systemic third party services.

Arcform Surface

Three-layer proof pipeline (Signal Integrity → Cross-Node Attestation → Proof-of-Trust Emission). Every identity signal is independently verified before trust emission.

Evidence

  • Live Companies House signal integration with real-time verification
  • Cross-node consensus mechanism prevents single-point failures
  • Automated interop test suite with 6 mandatory test categories
  • Partner lifecycle management with sandbox → production gate

FR-3

MET

Act in a prudent manner

A CTP must act in a prudent manner in providing systemic third party services to firms.

Arcform Surface

API key rotation enforcement (90-day cycle), DID lifecycle governance, circuit-scoped compliance modes, formal financial risk assessment framework, and service continuity insurance coverage documented.

Evidence

  • 90-day key rotation policy with automated rotation_due_at tracking
  • 24-hour grace period on key rotation for continuity
  • Sandbox isolation before production promotion
  • Financial risk assessment framework with service continuity insurance, capital reserves, and firm compensation obligations
  • Risk appetite statement with quantitative thresholds for all 6 risk domains

FR-4

MET

Effective risk strategies and risk management systems

A CTP must have effective risk strategies and risk management systems to manage all material risks.

Arcform Surface

Trust Agents provide continuous automated risk monitoring. FedRAMP monitoring signals track zone health. Board-level risk governance with quarterly STPS Resilience Review Board, formal risk appetite statement, and integrated CTP risk register with quantitative scoring.

Evidence

  • 5 autonomous Trust Agents emitting deterministic risk signals
  • FedRAMP monitoring grid with zone health classification
  • Governance councils with M-of-N quorum voting on risk actions
  • Compliance vocabulary mapping (FedRAMP ↔ eIDAS ↔ ISO 27001)
  • Formal risk appetite statement with zero-tolerance and quantitative thresholds
  • Integrated CTP risk register with 8 risk entries scored by impact × likelihood
  • Board-level reporting cadence: weekly, monthly, quarterly, annually

FR-5

MET

Organise and control affairs responsibly and effectively

A CTP must organise and control its affairs responsibly and effectively with proper systems.

Arcform Surface

Conductor orchestration engine provides deterministic workflow control. CTP Governance Structure with SMF-equivalent role mapping (SMF16, SMF24, SMF17), designated CTP Compliance Officer, and internal controls via governance council oversight.

Evidence

  • Conductor run audit trail with deterministic proof checksums
  • Plugin architecture with permission-scoped access control
  • Partner onboarding pipeline (invited → verified → sandbox → production)
  • Envelope routing with mediator hop tracking and latency measurement
  • SMF-equivalent mapping: CTP Compliance Officer (SMF16), Operational Resilience Lead (SMF24), Regulatory Affairs Lead (SMF17), Supply Chain Risk Manager
  • Internal controls validated through governance council oversight, enforcement cascades, and quarterly STPS Resilience Review Board

FR-6

MET

Deal with regulators openly and cooperatively

A CTP must deal with each regulator in an open and cooperative way. Applies to ALL services to firms, not just systemic ones.

Arcform Surface

Regulator Dashboard provides real-time compliance access. Formal regulatory engagement protocol with BoE/PRA/FCA documented. SS6/24 Section 7 self-assessment fully mapped across all 8 sections. Regulatory engagement calendar established.

Evidence

  • Public /regulator dashboard with live compliance signals
  • Audit export engine (JSON compliance bundles)
  • Compliance harmonisation mapping across FedRAMP/eIDAS/ISO 27001
  • Swiss Audit Matrix self-assessment published
  • CTP incident report templates (initial, intermediate, final) implemented per SS6/24
  • Firm notification procedures documented with severity-based timelines
  • Formal regulatory engagement protocol: BoE (lead), PRA (co-supervisor), FCA (conduct)
  • SS6/24 Section 7 self-assessment mapped across all 8 sections with complete status

Req-1

MET

Governance

Establish clear roles, responsibilities, and escalation channels at all levels of staff essential to STPS delivery. Board-level accountability for operational resilience.

Arcform Surface

Complete CTP governance structure with 4 designated roles (CTP Compliance Officer, Operational Resilience Lead, Regulatory Affairs Lead, Supply Chain Risk Manager), SMF-equivalent mapping, quarterly STPS Resilience Review Board, and board-level reporting cadence.

Evidence

  • GovernanceCouncil entity with quorum modes (simple, weighted, unanimous, jurisdiction-weighted)
  • CouncilAction workflow (proposed → passed → enforcing → enforced)
  • Enforcement cascades with rollback capability
  • Governance auto-enforcement via scheduled automation
  • Four-level escalation path defined with clear role assignments per level
  • CTP Compliance Officer designated (SMF16 equivalent) with ownership of all 14 requirements
  • Board-level reporting cadence: weekly (agent review), monthly (health dashboard), quarterly (full posture), annually (self-assessment)

Req-2

MET

Risk Management

Manage all relevant risks as part of an integrated risk management process. Avoid undue silos between risk categories.

Arcform Surface

Trust Agents provide domain-specific risk monitoring. Integrated CTP risk register with 8 scored entries, quantitative risk metrics (impact × likelihood), and formal risk appetite statement with domain-specific thresholds.

Evidence

  • Automated trust signal emission with pass/warn/fail verdicts
  • Cross-validation engine for multi-source data consistency checks
  • Leakage testing framework to verify zero-knowledge properties
  • Evolution signals tracking system state changes over time
  • Integrated CTP risk register: 8 risks scored quantitatively (R-001 through R-008)
  • Quantitative risk metrics: impact (Critical/High/Medium/Low) × likelihood scoring
  • Risk ownership assigned to named governance roles across all domains

Req-3

MET

Dependency and Supply Chain Risk Management

Identify and manage risks in supply chain. Key Nth Party providers must be mapped and monitored. Persons Connected to a CTP require equivalent oversight.

Arcform Surface

Complete supply chain governance framework with Key Nth Party Provider designations, concentration risk assessment across 4 dimensions, and confidentiality framework for regulator disclosure.

Evidence

  • APIAdaptor entity with provider_type, compliance_circuit, auth_method, and test status
  • Provider manifest function generating canonical dependency maps
  • Adaptor testing with latency measurement and pass/fail tracking
  • Multi-jurisdiction circuit binding (EU_strict, UK_standard, US_flexible, CA, AU, CH, GLOBAL)
  • Key Nth Party Provider designations applied: Companies House (Key), Base44 (Key), XRPL (Monitored), Slack (Non-Critical)
  • Supply chain concentration risk assessment across 4 dimensions (signal sources, hosting, crypto, jurisdiction)
  • Confidentiality framework: supervisory-only sharing, commercially sensitive redaction, quarterly notification cadence

Req-4

MET

Technology and Cyber Resilience

Take reasonable steps to ensure resilience of technology delivering, maintaining or supporting STPS. Identify, assess and remediate vulnerabilities. Maintain ISO 27001 or equivalent.

Arcform Surface

Complete cyber resilience programme with penetration testing (annual CREST, quarterly automated, continuous leakage), CVE monitoring with severity-based remediation SLAs, and ISO 27001 Annex A control mapping across 10 domains. Certification audit scheduled.

Evidence

  • DID-based identity with key rotation lifecycle (active → rotating → rotated → revoked)
  • HMAC webhook signature verification
  • Envelope integrity hashing (SHA-256, content-independent)
  • Compliance harmonisation maps ISO 27001 Annex A controls to Arcform surfaces
  • Penetration testing programme: annual CREST-accredited, quarterly automated, continuous leakage, ad-hoc post-incident
  • CVE monitoring process: continuous detection, 24h assessment, severity-based remediation (Critical 48h, High 7d, Medium 30d)
  • ISO 27001 Annex A: 10 control domains mapped to Arcform surfaces, certification audit scheduled

Req-5

MET

Resilience Testing

Conduct scenario testing to assess ability to continue delivering STPS under severe but plausible disruption scenarios. Include supply chain disruption and cyber attack scenarios.

Arcform Surface

Complete resilience testing programme with 5 severe-but-plausible scenarios per SS6/24 (supply chain failure, consensus divergence, multi-provider cascade, cyber attack, regulatory enforcement). All scenarios include response procedures and recovery targets.

Evidence

  • InteropTest entity tracking 6 mandatory test categories
  • Leakage test function verifying zero-knowledge property preservation
  • Tide isolation tests confirming data boundary integrity
  • Cross-validation engine comparing multi-source identity signals
  • Recovery time objectives (RTO/RPO) documented for all 5 STPS categories
  • 5 SS6/24 severe-but-plausible scenarios: signal source failure, consensus divergence, multi-provider cascade, cyber attack, regulatory enforcement
  • Supply chain failure scenarios included (S-01 single source, S-03 multi-provider cascade, S-05 regulatory action on provider)

Req-6

MET

Mapping

Map resources essential to delivering STPS. Mapping must be proportionate to nature, scale and complexity. Include people, processes, technology, facilities, and information.

Arcform Surface

Full resource mapping via entity architecture: Partners → APIKeys → DIDs → Envelopes → Anchors → Attestations. APIAdaptor registry maps all external technology dependencies.

Evidence

  • Complete entity relationship graph covering all STPS resources
  • APIAdaptor registry with provider endpoints, auth methods, and circuit bindings
  • Envelope routing topology with mediator hop tracking
  • Identity Continuum providing temporal mapping of all identity events
  • Trust Edge graph mapping inter-partner trust relationships

Req-7

MET

Incident Management

Set maximum tolerable level of disruption for each STPS. Maintain incident management playbook. Report CTP operational incidents to regulators (initial, intermediate, final reports).

Arcform Surface

Complete Incident Management Playbook with MTD levels per service, P1/P2/P3 classification taxonomy, four-level escalation path, initial/intermediate/final report templates per SS6/24, and firm notification procedures with severity-based timelines.

Evidence

  • MTD/RTO/RPO defined for all 5 service categories (Identity Signals, Envelope Routing, Cross-Node Attestation, Anchor Ledger, Regulator Dashboard)
  • Incident classification taxonomy (P1 Critical, P2 Major, P3 Minor) with response protocols
  • Four-level escalation path (Automated Detection → Engineering → Senior Management → Regulatory Notification)
  • Initial Report template (within 4 hours), Intermediate Report (within 24 hours), Final Report (within 10 business days)
  • Firm notification procedures: P1 within 2 hours, P2 within 8 hours, post-incident summary within 5 business days
  • Slack audit alerts for real-time internal escalation across all severity levels

Req-8

MET

Termination of Services

Support firms in terminating and exiting from service contracts in an effective, orderly and timely way. Help firms recover data and assets.

Arcform Surface

Complete Termination & Retention Policy with four-phase exit management (Notification → Data Export → Wind-Down → Post-Termination), comprehensive data retention schedule, and asset recovery procedures ensuring zero vendor lock-in.

Evidence

  • Four-phase exit plan: Notification & Planning (0–30 days), Data Export & Portability (30–60 days), Service Wind-Down (60–90 days), Post-Termination (90+ days)
  • Data export formats: DID documents (JSON-LD, W3C DID Core), envelope routing history (CSV/JSON), anchor chain extract, attestation bundles, trust signal history
  • Data retention schedule: proof checksums indefinite, routing logs 7 years, signal history 7 years, API key metadata 2 years, telemetry 1 year
  • Asset recovery: all exports in machine-readable formats, cryptographic material self-verifying, DID documents W3C-portable, SHA-256 integrity verification
  • Termination completion certificate issued, regulator notified per CTP obligations

4/4 remediation items complete

100%

RM-1: Define Disruption Thresholds

COMPLETE28 July 2026

Establish quantitative uptime and recovery metrics for Base44 and Arcform nodes. Set Maximum Tolerable Disruption (MTD) levels for each systemic service.

Closes:Req-7
MTD definitions per identity signal service category
Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for all STPS
Service-level threshold monitoring integrated into FedRAMP monitoring grid

RM-2: Create Incident Playbook

COMPLETE28 July 2026

Build a Financial Sector Incident Management Playbook with escalation paths, communication templates, and regulator-ready reporting flows per SS6/24.

Closes:Req-7FR-6
CTP incident classification taxonomy aligned to operational incident definitions
Escalation path matrix (technical → SMF → regulator)
Initial / Intermediate / Final incident report templates
Firm notification and communication procedures
Post-incident review process

RM-3: Draft Termination Procedures

COMPLETE28 July 2026

Specify how data portability, retention, and service wind-down are handled under sovereign conditions. Formalise exit management for all STPS.

Closes:Req-8
Exit Management Plan covering orderly service termination
Data portability procedures (DID, envelope, anchor export formats)
Transition period obligation framework with timeline commitments
Asset recovery and data return process documentation
Post-termination data retention and destruction policy

RM-4: Integrate Compliance Telemetry

COMPLETE28 July 2026

Feed live operational metrics into the dashboard for continuous compliance monitoring. Bridge the gap between automated signals and CTP reporting requirements.

Closes:FR-4Req-2
Real-time STPS health dashboard with MTD threshold indicators
Automated compliance signal aggregation for CTP self-assessment
Quantitative risk metrics (impact × likelihood) integrated into Trust Agent verdicts
Board-level compliance reporting cadence established

Outstanding Gap Detail

Specific items requiring attention — mapped to remediation actions above