VELARU MANDATE EXHIBIT PACK — BANK MODEL RISK MANAGEMENT (SR 11-7) Jurisdiction: European Union (eu) Modality: Text / Chat Program: Velaru Bank Model Risk Management (SR 11-7) · European Union (galactic_model_risk_eu) Product ID: model_risk:eu:bundle:text Vertical: model_risk Generated: 2026-08-23T05:59:22.688743Z Authority: EU AI Act Conformity Pack — SR 11-7 Model Validation Evidence Pack Deadline: Freddie Mac AI governance (SR 11-7 baseline) Velaru verify: https://velaru-erra.onrender.com/verify EXHIBIT A — AI INVENTORY [] EXHIBIT B — GOVERNANCE FRAMEWORK { "framework": "Velaru Mandate Registry \u2014 Bank Model Risk Management (SR 11-7)", "exhibit_authority": "EU AI Act Conformity Pack \u2014 SR 11-7 Model Validation Evidence Pack", "regulatory_frameworks": [ "Federal Reserve SR 11-7", "OCC 2011-12", "Basel III Pillar 2", "CECL model governance", "EU AI Act Annex III", "FINRA Rule 3110", "EU AI Act 2024/1689", "GDPR Art 22", "Product Liability Directive" ], "standards_alignment": [ "POSS-2", "DRP-1", "TCB", "FRE 707 pre-compliance", "ISO 42001" ], "human_oversight": "deploy model to production", "third_party_verification": "https://velaru-erra.onrender.com/verify (operator-independent)", "data_lineage": "Hash-chained Ed25519 receipts; optional RFC3161 + external anchor", "mirror_trap": "Banks validate models quarterly but cannot produce per-inference audit \u2014 examiners now ask both. \u00b7 Annex III high-risk list covers 8 domains \u2014 one vertical per domain minimum for compliance.", "chain_integrity": { "depth": 6, "invariant_holds": true } } EXHIBIT D — DATA INPUTS & VALIDATION { "data_validation_method": "Cryptographic receipt per AI decision; public verify without trusting deployer, vendor, or Velaru operator", "bias_testing_proxy": "Asymmetry score from live chain signals", "model_change_control": "Policy lock registry \u2014 criteria hash frozen pre-dispute", "logging_retention": "90-day pre-dispute window minimum; permanent verify permalinks", "external_validator": "Nisaba LLC / Velaru", "validator_independence": "Client-side Ed25519 verify; BYOK tri-receipt optional", "headline_stat": "CMRO must document human review before remediation \u2014 receipt or 483-equivalent", "global_leaders_addressed": [ "Federal Reserve", "OCC", "JPMorgan", "Goldman Sachs", "Moody's", "EU AI Office", "EDPB", "European Parliament" ] } MIRROR TRAP (regulatory insight) Banks validate models quarterly but cannot produce per-inference audit — examiners now ask both. · Annex III high-risk list covers 8 domains — one vertical per domain minimum for compliance. NERVE CARDS — WHY GLOBAL LEADERS CARE [ { "title": "Model drift", "body": "Performance degradation without documented override = consent order pattern.", "source": "vertical" }, { "title": "Vendor models", "body": "Third-party credit models \u2014 bank owns validation, vendor owns nothing.", "source": "vertical" }, { "title": "CECL correlation", "body": "AI loss forecasting for CECL requires auditable assumption chain.", "source": "vertical" }, { "title": "[European Union] FRIA requirement", "body": "Fundamental rights impact assessment for public/high-risk \u2014 exhibit pack maps to FRIA.", "source": "jurisdiction" }, { "title": "[European Union] PLD strict liability", "body": "Dec 2026 product liability directive \u2014 software and AI explicitly included.", "source": "jurisdiction" }, { "title": "[Text / Chat] Modality hook", "body": "Baseline \u2014 all frameworks apply to text decisions.", "source": "modality" } ] BOOK SUMMARY: { "total_insureds": 0, "compliant": 0, "grace_period": 0, "non_compliant": 0, "expired": 0, "not_enrolled": 0, "compliant_pct": 0.0 } TAM / EXPOSURE: Every OCC-supervised bank · SR 11-7 is law since 2011 INSURANCE LINES: Bank E&O, D&O, Crime DISCLAIMER: External validation evidence pack — not legal advice, not filed rate approval.