Documentation
Regurai Project Manual
Enterprise platform for Tier-1 financial institutions to govern, monitor, and audit AI systems across regulatory frameworks (DORA, ISO 27001, NIST AI RMF, GDPR).
Contents
Executive Summary
Business purpose, product vision, key objectives, and stakeholders.
phase-5-rollup
tech-debt-8-decision-brief
System Architecture
Layers, runtime topology, component map, and data-flow diagrams.
User Guide
End-user workflows, feature walkthroughs, and common tasks.
Administrator Guide
User management, role management, configuration, monitoring.
Authentication & Authorization
Sign-in, MFA, AAL2 gate, RBAC model, permission matrix, sessions.
Security & Compliance
Security architecture, encryption, audit, controls, regulatory mapping.
Database
Schema, ERD, table definitions, relationships, indexes, migrations.
API & Integrations
Server functions, edge functions, webhooks, third-party integrations.
Operations
Deployment, environments, backups, DR, incident response.
Testing & Quality Assurance
Testing strategy, coverage, validation, release checklist.
Change Management
Version history, release notes, ADRs, technical debt register.
Phase 2.1 — Multi-Tenant Isolation Remediation
Standalone audit-grade evidence record of the Phase 2.1 tenant-isolation remediation pass — Incidents #1–6 with severity, dates, affected tables, and remediation migrations.
Appendix
Glossary, acronyms, references, external dependencies.
NIST AI Risk Management Framework — Practical Guide for Financial Institutions
How banks operationalize the NIST AI RMF — Govern, Map, Measure, Manage — across FX settlement, AML, credit, and customer-facing AI, with side-by-side EU AI Act mapping.