VELARU GALACTIC EXHIBIT PACK — DORA / FINANCIAL OPERATIONAL RESILIENCE Jurisdiction: Global / Multi-jurisdiction (global) Modality: Text / Chat Program: Velaru Mandate Registry — DORA / Financial Operational Resilience (galactic_dora) Product ID: dora:global:bundle:text Vertical: dora Generated: 2026-08-11T00:22:59.228527Z Authority: Global External Validation — DORA Art 17/28 ICT Incident Pack Deadline: DORA in force — ICT risk management Velaru verify: https://velaru.onrender.com/verify EXHIBIT A — AI INVENTORY [] EXHIBIT B — GOVERNANCE FRAMEWORK { "framework": "Velaru Mandate Registry \u2014 DORA / Financial Operational Resilience", "exhibit_authority": "Global External Validation \u2014 DORA Art 17/28 ICT Incident Pack", "regulatory_frameworks": [ "DORA Article 17", "DORA Article 19", "DORA Article 28", "ISO 42001", "NIST AI RMF 1.0", "OECD AI Principles" ], "standards_alignment": [ "POSS-2", "DRP-1", "TCB", "FRE 707 pre-compliance", "ISO 42001" ], "human_oversight": "onboard ICT third-party AI", "third_party_verification": "https://velaru.onrender.com/verify (operator-independent)", "data_lineage": "Hash-chained Ed25519 receipts; optional RFC3161 + external anchor", "mirror_trap": "Bank uses cloud AI \u2014 bank owns DORA compliance, cloud vendor owns shared responsibility matrix gap. \u00b7 Multinationals built for one jurisdiction fail exams in another \u2014 one receipt architecture, many filing packs.", "chain_integrity": { "depth": 39, "invariant_holds": true } } EXHIBIT D — DATA INPUTS & VALIDATION { "data_validation_method": "Cryptographic receipt per AI decision; public verify without trusting deployer, vendor, or Velaru operator", "bias_testing_proxy": "Asymmetry score from live chain signals", "model_change_control": "Policy lock registry \u2014 criteria hash frozen pre-dispute", "logging_retention": "90-day pre-dispute window minimum; permanent verify permalinks", "external_validator": "Nisaba LLC / Velaru", "validator_independence": "Client-side Ed25519 verify; BYOK tri-receipt optional", "headline_stat": "ICT third-party AI provider = critical function \u2014 register + audit or supervisory fine", "global_leaders_addressed": [ "EBA", "Deutsche Bank", "BNP Paribas", "Critical ICT providers", "ISO", "NIST", "OECD", "UNESCO" ] } MIRROR TRAP (regulatory insight) Bank uses cloud AI — bank owns DORA compliance, cloud vendor owns shared responsibility matrix gap. · Multinationals built for one jurisdiction fail exams in another — one receipt architecture, many filing packs. NERVE CARDS — WHY GLOBAL LEADERS CARE [ { "title": "Art 28 register", "body": "Critical ICT providers must be registered \u2014 AI vendors increasingly on list.", "source": "vertical" }, { "title": "Incident reporting", "body": "4-hour initial notification \u2014 AI-caused incident needs decision receipt.", "source": "vertical" }, { "title": "TLPT", "body": "Threat-led penetration testing includes AI attack paths.", "source": "vertical" }, { "title": "[Global / Multi-jurisdiction] Jurisdiction shopping ends", "body": "Regulators share examination findings via IAIS, IOSCO, Basel \u2014 governance gap in one market triggers another.", "source": "jurisdiction" }, { "title": "[Global / Multi-jurisdiction] Vendor contract forum", "body": "AI vendor chooses Delaware law \u2014 deployer owns EU, UK, and US state fines simultaneously.", "source": "jurisdiction" }, { "title": "[Text / Chat] Modality hook", "body": "Baseline \u2014 all frameworks apply to text decisions.", "source": "modality" } ] BOOK SUMMARY: { "total_insureds": 0, "compliant": 0, "grace_period": 0, "non_compliant": 0, "expired": 0, "not_enrolled": 0, "compliant_pct": 0.0 } TAM / EXPOSURE: EU financial entities · DORA applies now INSURANCE LINES: Cyber, D&O, Professional indemnity DISCLAIMER: External validation evidence pack — not legal advice, not filed rate approval.