VERIDOM · OPERATING MODEL PROTOCOL — OMP™

Prove every decision.

Evidence infrastructure for regulated industries. Every interaction resolves to one of three accountable outcomes — and the proof is sealed at the moment of decision, verifiable by any third party without access to your systems or ours.

12 INTERNET-DRAFTS AT THE IETF PERMANENT DOI · ZENODO (CERN) 4 REGULATED DOMAINS

THE PREMISE

Evidence generators record what happened. OMP™ makes certain things impossible without evidence.

01 — THE PROBLEM

Every regulated institution operates with a gap between what its systems do and what it can prove they did.

Layer 01

Policy → Practice

The institution has the right policies. Its agents and systems do not consistently follow them.

Layer 02

Practice → Evidence

The practice happens — but the evidence trail is incomplete, reconstructed, or missing entirely.

Layer 03

Evidence → Examination

The evidence exists, but cannot be produced in the form a regulator requires, when the regulator requires it.

The dominant market response is observational — monitoring, dashboards, retrospective reports. It addresses the third layer at best. OMP closes the gap architecturally, at the point of decision: the wrong outcome cannot be produced without a sealed, externally verifiable record of why it was produced and under whose authority.

02 — WHAT YOU GET

We don't sell dashboards. We sell the answer.

When the question comes — from a regulator, an auditor, a court — what you need is the record. Veridom installs the layer that produces it, and hands you the proof.

A

Evidence Gap Diagnostic

A structured assessment of where your institution's evidence gap is widest — decision by decision, system by system. You see exactly what you can and cannot prove today.

ENGAGEMENT · THE STARTING POINT
B

OMP™ Deployment

The protocol installed above your existing stack — any model, any vendor. Deterministic routing, named accountability, and sealed evidence on every AI-mediated decision.

INFRASTRUCTURE · YOURS, NOT RENTED
C

The Proof-Point Artifact

A sealed, regulator-ready evidence pack covering every AI-mediated interaction in the period — produced in under 30 seconds, verifiable by anyone.

DELIVERABLE · EXAMINER-READY
Start with a diagnostic

03 — THE PROTOCOL

Five stages. Invariant across every vertical, every deployment, every version.

The Decision Engine determines what the system does. The Evidence System proves what the system did.

S1DECISION ENGINE

Ingestion & Normalisation

The interaction enters the pipeline. Payload validated, canonicalised under RFC 8785, hashed under SHA-256, timestamped at ingestion.

interaction_hash = SHA-256(payload_canonical)
S2DECISION ENGINE

Intent Classification

Hash integrity re-verified — any mismatch escalates immediately. The interaction is classified to a registered Intent Class with its own routing threshold θ.

mismatch → ESCALATED · ESC-09
S3DECISION ENGINE

Watchtower Evaluation

Domain-specific enforcement rules evaluated in priority order. Every Watchtower's verdict is recorded — whether or not it fired.

severity ∈ { HARD_BLOCK, FORCE_ASSISTED }
S4DECISION + EVIDENCE

Routing & Authority Binding

The deterministic routing function assigns exactly one outcome state. For ASSISTED and ESCALATED, a named accountable human is bound to verifiable authority — or execution is refused.

R(C, W, θ, φ) → { AUTONOMOUS · ASSISTED · ESCALATED }
S5EVIDENCE SYSTEM

Trace Sealing

The complete Audit Trace is sealed: content hash, RFC 3161 trusted timestamp, institutional signature, Merkle chain entry. Appended to the append-only ledger.

H_content → TST → signature → H_c

04 — THREE STATES. NO FOURTH OPTION.

The routing decision is a deterministic function. Same inputs, same outcome, every time.

Adjust the inputs below. The outcome is computed, not judged — identical inputs always resolve to the identical state.

AUTONOMOUS
routing_stateAUTONOMOUS
reasonCONFIDENCE_GE_THRESHOLD
authority_bindingEXEMPT
execution_permissionPERMITTED

Confidence clears the threshold. The system dispatches without human review — and the full trace is still sealed.

AUTONOMOUS

Confidence clears θ. No Watchtower objection. Dispatched without review; trace sealed.

ASSISTED

A named accountable human must approve, edit, or reject before dispatch — under bound authority.

ESCALATED

Direct human handling under SLA. Hard blocks, policy violations, ambiguous intent, low confidence.

05 — THREE INVARIANTS

The technical basis of every claim Veridom makes.

I

Deterministic Routing

Given canonicalised inputs — payload, source-state hashes, pinned model configuration — the routing outcome is deterministic. Identical inputs produce identical outcomes.

WHY IT HOLDS UPThe decision is reproducible from the sealed trace. No one can argue the system "might have" decided differently on the same inputs.
II

Immutable Trail

Every decision is sealed at the moment of decision: SHA-256 over canonical JSON, RFC 3161 trusted timestamp, institutional signature, Merkle-chained ledger.

WHY IT HOLDS UPPost-decision modification is detectable by any third party — without access to the institution's or Veridom's infrastructure.
III

Verifiable Authority Binding

Every ASSISTED or ESCALATED decision binds a named accountable human to verifiable authority at the moment of decision — or execution is refused, and the absence itself is sealed.

WHY IT HOLDS UPNo one can claim authority was present but undisclosed. AUTHORITY_UNBOUND is positive evidence of absence, not a silent failure.

06 — VERIFIABLE WITHOUT TRUST

Don't trust the record. Verify it.

Below is a sealed Audit Trace. Verification recomputes the SHA-256 content hash live in your browser — the same check a regulator, court, or auditor runs. Then tamper with it, and watch the seal break.

DECISIONRouted & resolved
SHA-256
H_CONTENTContent hash
RFC 3161
TIMESTAMPAccredited TSA
SIGNS
INSTITUTIONSelf-held key
CHAINS
H_C LEDGERAppend-only
AUDIT TRACE SEALED
interaction_id9f2c41aa-7e1b-4c0d-a2c4-d4b1e8f30a17
routing_stateASSISTED
decisionCredit limit increase — £25,000
officerOFF-0042 · BOUND
delegation_idDI-FCA-SMF16-OFF0042-2026-04-01
resolutionRA-1 APPROVE · 2026-05-15T14:33:21.002Z
h_contentcomputing…
rfc3161_tstTSA-eIDAS-QT · serial 0x5A2F…9C41
signatureinstitution:ECDSA-P256 ✓ self-held key

Recompute H_content

SHA-256 over the canonical trace, recomputed from the record itself.

Validate RFC 3161 timestamp

TimeStampToken checked against the accredited TSA's public certificate.

Verify institutional signature

The institution signs with its own key. Verification is independent of any vendor.

Recompute Merkle chain link

Each trace incorporates the previous trace's hash. History cannot be rewritten quietly.

Run verification to check this record's integrity.

07 — FOUR REGULATED DOMAINS. ONE CONSTRAINT SET.

The same invariants held in every domain OMP has been instantiated in.

Vertical configurations change — Watchtowers, thresholds, authority anchors. The protocol does not.

/01UNITED KINGDOM

Digital Credit

Lending Decisions

Per-decision evidence for digital lenders under FCA supervision — affordability, creditworthiness, and limit decisions. Watchtowers tuned to lending failure modes; accountability anchored to SM&CR responsibilities.

FCA CONSUMER CREDIT (CONC) · SM&CR
/02UNITED KINGDOM

Consumer Duty

Retail Financial Services

Board-defensible outcome evidence for AI-mediated pricing, lending, and support decisions. Accountability anchored to SM&CR Statements of Responsibility.

FCA CONSUMER DUTY · SM&CR
/03UNITED KINGDOM

Agent Oversight

Payments — Agent Distribution

Eliminates principal-agent blindness across distribution networks. Fully automated Watchtowers; accountability anchored to the principal firm's delegation matrix.

FCA PAYMENTS · AGENT DISTRIBUTION
/04UNITED STATES

Legal AI Supervision

Citation Verification

Two-gate citation verification with a supervisory compliance manifest. Court-filing consequence demands θ ≥ 0.992. Accountability anchored to the supervising attorney.

ABA MODEL RULE 5.3 · CA SB 574 · CO SB 24-205

08 — BUILT FOR BOTH SIDES OF THE TABLE

Compliance asks if it will satisfy the examiner. Engineering asks if it will break the stack. Yes — and no.

FOR COMPLIANCE & RISK LEADERS

"Will this satisfy the regulator?"

  • Examiner-ready evidence on every AI-mediated decision — not quarterly reconstructions
  • Named, verified accountability on every human sign-off — or execution refuses
  • Board-defensible artifacts produced in seconds, not weeks
FOR ENGINEERING & AI LEADERS

"Will this work in our stack?"

  • Sits above the inference layer — any model, any vendor, one evidence schema
  • Deterministic and testable: same inputs, same outcome, reproducible from the trace
  • Open specification published at the IETF — no proprietary lock-in
0Outcome states.
No fourth option.
0Protocol invariants,
formally specified.
0Regulated domains
instantiated.
0Internet-Drafts
published to the IETF.
0sRegulator-ready
Proof-Point artifact.
v1.3Open specification,
permanent DOI.

09 — THE OPEN LAYER

Open by design. Verifiable by anyone.

The full OMP™ specification is published for anyone to read, implement, and test against — twelve Internet-Drafts at the IETF, covering the core protocol and vertical profiles from UK Consumer Duty to the EU AI Act.

That openness is the point. Your auditors, your regulators, and your counterparties can check OMP™ evidence without asking Veridom — or anyone else — for permission. No proprietary formats. No gatekeepers.

12INTERNET-DRAFTS
AT THE IETF
v1.3SPECIFICATION
PERMANENT DOI
WHO MAY READ,
IMPLEMENT, VERIFY

READ IT · IMPLEMENT IT · VERIFY AGAINST IT

Your AI operates.Can you prove it accountably?

Initial engagements are diagnostic — a structured assessment of where your institution's evidence gap is widest. Share the institution, context, and gap you need to resolve, and we will determine whether a Veridom diagnostic is the right next step.

LONDON · TORONTO
CONFIDENTIAL INTAKE

Request a diagnostic

For regulated institutions, industry bodies, and research partners. Initial review is selective and confidential.