A conventional due-diligence programme reviews on a calendar. An agent reviews on every list update — and emits a signed record each time. Detection latency falls from months to hours, and the cadence is proved on an evidence chain rather than asserted in a policy document.
ACAS-1 is the open standard for continuous, portable, provable customer due diligence in agent-to-agent commerce. One unit — the Compliance Step — four carriage classes describing how each result can and cannot travel, and a hard line between machine detection and human determination.
Diligence that cannot travel. Work performed by one institution stays inside it. There is no portable, verifiable form in which completed due diligence can be carried and independently checked, so every counterparty either repeats it or takes it on trust. The FATF Recommendations do contemplate third-party reliance — but reliance is negotiated and papered between named institutions, and does not scale to an open network of agents meeting for the first time.
Review at a volume no human can read. Agent-to-agent commerce will generate relationships and transactions faster than any review function can meaningfully consider them. The risk is not that a human is removed from the loop; it is that the human remains formally responsible for a queue they cannot read. Review that degrades into rubber-stamping is a control failure that presents as a control.
And an opportunity. An agent has no review cycle. It screens on every list publication and emits a signed record each time. That is not a workaround for the first two problems — it is a materially better control than the one it replaces.
A person is added to a designated list on a Tuesday. Under an annual refresh cycle, the institution holding them as a customer may not identify the exposure until the following review. That interval — between a fact becoming true in the world and the obliged entity acting on it — is real, material, and almost never measured.
ACAS-1 names it detection latency and makes it the assurance metric. It is measurable in hours rather than expressible as a maturity rating; it means the same thing across institutions, sectors and jurisdictions; and it is the number that actually determines outcomes, since the harm from an exposure is a function of how long it persisted undetected.
Calendar-driven refresh. Cadence stated in a policy and tested by sample. The interval is invisible because nobody reports it.
Execution on every list publication, each emitting a signed, timestamped, hash-chained record. The interval is a published, verifiable number.
An institution can evidence its own cadence — scheduler logs, batch records and internal audit testing are real evidence. The limitation is that the evidence is not portable: it sits inside the perimeter, it is interpretable only with context, and it is produced by the party whose programme is in question. Conventional assurance produces evidence for itself. These records produce evidence for anyone.
This also resolves what would otherwise be the hardest carriage problem in the standard. Cadence, list coverage, matching methodology and measured latency are properties of the programme, not of any person — so a monitoring commitment travels in full, verifiably, containing no personal data at all.
// carried on an ongoing_monitoring Step — no name, no subject data "programme": { "cadence": "on_list_update", "maxLatency": "PT4H", "listSetRefs": ["https://compliance.example.com/lists/un-ofac-eu-hmt"], "matching": { "method": "fuzzy", "threshold": 0.85, "providerRef": "did:ais1:..." }, "disposition": "human_required_on_hit" }, "performance": { "window": "P90D", "executions": 847, "expectedExecutions": 841, "maxObservedLatency": "PT3H12M", "missedWindows": 0, "evidenceChainRef": "aas1:chain/01K1ACAS..." }
Detection is automated. Determination is not. The standard automates the finding of facts and never the making of decisions reserved to a responsible person. Screening is cheap; dispositioning what screening surfaces is the expensive part, and it is the part the rules reserve. A programme declaring auto-clear where a profile reserves that determination is non-conformant, and the schema does not permit the value. What the model delivers is not fewer determinations — it is the same determination, reached hours rather than months after the fact arose, on evidence already assembled.
Three limits, stated plainly: no supervisory framework presently gives credit for a four-hour latency over a ninety-day one, so the immediate value is commercial and evidentiary rather than regulatory; continuous screening of a natural person is continuous processing and needs a lawful basis; and latency is the missing metric, not the only one — frequency without match quality is theatre, which is why the matching object is required.
A flat catalogue that treats every due-diligence result alike overstates the weak cases and undersells the strong ones. A verified identity is genuinely worth carrying. A sanctions screen is not — the recipient will re-run it in seconds, and should. A source-of-funds enquiry cannot travel in its substance at all, because what makes it meaningful is exactly what confidentiality and data-protection law require be withheld. And monitoring is not a result: a past search says nothing about a live relationship.
Costly work, durable result, independently verifiable. The recipient takes it into its own assessment on its own policy.
Scope, outcome and an integrity hash. A recipient with authorisation requests the material and verifies the hash matches.
The recipient re-performs the act. What travels is the existence, scope and recency of the subject's own programme.
Nothing useful travels as a past result. A live commitment does: declared programme, proved cadence, change notification.
Carriage is declared on every Step rather than inferred from its type. A profile may require a stricter class than the default; none may relax one. A fifth class, proved, is reserved for zero-knowledge predicates and is unspecified in v0.1.
The catalogue is anchored to the FATF Recommendations as given effect in national law. Recommendation 10 supplies four of the seven types; the remainder come from distinct obligations that customer due diligence sits alongside rather than within — worth stating, because sanctions screening in particular is routinely and incorrectly described as a CDD obligation.
| Step type | Anchor | Carriage | What actually travels |
|---|---|---|---|
| identity_verification | R.10(a) | portable | The verification result and its assurance level — identity drawn from AIS-1 |
| beneficial_ownership | R.10(b) · R.24/25 | portable + referenced | The determination travels; the sponsor entity's ownership data is referenced and requestable |
| purpose_and_nature | R.10(c) | portable | Stated purpose and any risk classification — low sensitivity |
| ongoing_monitoring | R.10(d) | subscription | Declared programme, evidenced performance, change-notification endpoint |
| sanctions_screening | R.6 / R.7 | freshness_signal | List set, matching, last execution, latency — the recipient re-screens |
| pep_screening | R.12 | freshness_signal | Source, methodology, last execution — the recipient re-screens |
| source_of_funds | R.10 (enhanced) · R.12 | referenced | Scope, date, outcome and a hash of the material examined |
Recommendations 20 and 21 are deliberately out of scope. Nothing in ACAS-1 may carry or permit inference that a suspicious transaction report has been made or contemplated — a schema constraint and a conformance requirement, not a stylistic preference.
Every Step records a determination level. These are not a ladder of decreasing human involvement, and should not be read as one. They record where the judgment sits and what it covered, which is what a recipient needs in order to apply its own policy.
An agent performed the act and its result stands on the evidence carried, where no person's determination is reserved. The result is a fact, not a judgment.
The act is performed and the package assembled; the reserved determination has not yet been made. The responsible person is named on the Step.
A responsible person has considered the evidence and concluded. The prepared Step is retained: the pair records what was put before them and what they decided.
An independent third party with its own regulatory standing has determined the result, which may allow a recipient's policy to require less of its own function.
The conformance test for a prepared package is strict: if the responsible person must go and perform an act the agent could have performed, the package was not conformant. Their attention is for the determination, not the assembly. None of these levels transfers the recipient's obligation.
A Compliance Record is held, not broadcast. What a counterparty receives is a Presentation: a signed subset constructed for that counterparty, for a stated purpose, valid for a stated window, containing only what their profile requires. It is issued under a scoped, revocable disclosure mandate, and every Presentation emits an evidentiary record — so the subject sees exactly what was disclosed, to whom, and when.
A standing mandate is an unlock, and the controls are structural rather than a consent prompt nobody reads. Five properties are required of any disclosure mandate, whatever object expresses it: the scope is enumerated with no wildcards; the grantor and grantee are named identities; the purpose is stated; there is an expiry; and revocation status is independently resolvable without the grantee's cooperation. The standard constrains the properties, not the format — an existing capability, authorisation or credential scheme may supply the mandate where those five hold.
// Agent A assesses Agent B before transacting assert(presentation.audienceRef === myDid); // audience-bound assert(now() < presentation.expiresAt); // time-bound assert(!(await mandate.isRevoked(presentation.mandateRef))); // act on carriage class — the substantive step switch (step.carriage) { case 'portable': accept(step.result); break; case 'referenced': m = await acas1.request(step.disclosure); assert(sha256(m) === step.disclosure.materialHash); break; case 'freshness_signal': riskSignal(step.inputs); await self.screen(subject, policy.listSets); break; case 'subscription': assert(await aas1.verifyChain(step.performance)); assert(step.performance.missedWindows === 0); await acas1.subscribe(step.result.endpoint); break; } // clear, or place a complete package before the responsible person return meetsPolicy ? clear(subject) : routeToOfficer(buildPackage(presentation));
Note the subscription branch: the verifier recomputes the evidence chain rather than trusting the summary. Until the chain is verified, the performance figures are assertions like any others.
The specification defines the artefacts. The manuals cover the practice — one for each side of a Presentation, because the party emitting one and the party relying on it have almost nothing in common operationally.
For the party relying on a Presentation. What travels and what does not, reading a Presentation, a transaction from your side, what you still have to do, setting your own policy, handling a hit, and the questions a supervisor will ask — with the honest answers.
For the party emitting a Presentation. The four capabilities, the order to build them in, declaring a programme you can hold, making cadence provable, mandate management, what you must never emit, cost, a pre-publication checklist, and a transaction worked end to end.
The Compliance Step primitive, the four carriage classes, the step-type catalogue and its FATF anchor, continuous assurance and detection latency, the determination model, the Record and Presentation split with the disclosure mandate. Step, Presentation and mandate schemas; both manuals.
Normative per-type constraints. FATF baseline and Bermuda DABA profiles. Prepared-package conformance criteria. Latency measurement methodology, including computation where a list publisher does not timestamp additions.
PayAgent operates a declared monitoring programme over 90 days and publishes the verified performance record; a counterparty agent clears against it.
The independently-determined level operationalised with a reference verifier programme. MiCA CASP and US BSA profiles.
Predicate catalogue, proving-system profile, and the supervisory viewing-key requirement for zero-knowledge disclosure.
Test vectors, conformance harness and reference verifier. Composition with ARS-1 for agent-to-agent payment.
Submission to FATF private-sector consultation and ISO TC 68. Stable schemas. Convening with supervisory authorities on latency as a reportable metric.
The full technical working paper. Continuous assurance and detection latency, the Compliance Step primitive, the four carriage classes, the step-type catalogue and its FATF anchor, the determination model, disclosure and consent, and the regulatory substrate.
For the party relying on a Presentation. What travels and what does not, reading a Presentation, a transaction from your side, what you still have to do, setting your own policy, handling a hit, and the questions a supervisor will ask.
For the party emitting a Presentation. The four capabilities, the order to build them in, declaring a programme you can hold, making cadence provable, mandates, what you must never emit, cost, a pre-publication checklist, and a worked transaction from onboarding to a status change on day 31.
The canonical ACAS-1 repository. Specification, both manuals, schemas, worked examples, changelog and the contributing guide.
JSON Schema 2020-12 for the Compliance Step, with conditional requirements driven by carriage class, plus the Presentation and disclosure-mandate schemas. The mandate schema rejects wildcard scope by construction.
A freshness-signal screening Step, a subscription Step carrying a proved 90-day monitoring programme, a referenced source-of-funds Step with its prepared determination, a full Presentation, and the disclosure mandate behind it.
The identity layer ACAS-1 binds to. Every subject, performer and determiner is an AIS-1 identity, and an identity Step draws its data from AIS-1 rather than restating it.
The evidence layer. A Compliance Step is a specialised AAS-1 record — and it is AAS-1's hash chaining that makes provable cadence possible at all.
Feedback is invited from compliance officers and MLROs, AML/CFT supervisors, FATF and FIUs, VASPs, EMIs, banks and digital-asset businesses running agent-mediated payments, screening and monitoring providers, data-protection practitioners, AI agent developers, and standards organisations including ISO TC 68 and the BIS Innovation Hub. The comment period closes 31 October 2026. A revised draft will be published as v0.2.
Whether detection latency is the right assurance metric, and how it should be measured and reported · whether the four carriage classes correctly describe how due-diligence results can and cannot travel · whether the detection / determination line is drawn in the right place, and whether the disposition conformance rule is strict enough · whether the tipping-off inference channels are completely enumerated · the lawful-basis analysis for an assessing party screening a counterparty's beneficial owners · real-world agent-to-agent deployments to pilot the standard.