{
  "tool_id": "art-537-qfc-recordkeeping-file-validator",
  "kernel_id": "art-537-qfc-recordkeeping-file-validator",
  "display_name": "QFC Part 371 Recordkeeping File Validator",
  "tool_version": "1.0.0",
  "mandate_type": "compliance_control",
  "purpose": "Validates the shape of the institution's own 12 CFR part 371 qualified-financial-contract recordkeeping file -- the position, counterparty, and collateral record set the appendix to part 371 requires -- against its published record layout, and ties the file's declared totals to a supplied control-total summary. A file-shape defect and a totals mismatch are two separate, never-merged findings: a shape problem is checked first and routes to review_required regardless of how the totals compare, and only a clean-shaped file with a totals disagreement routes to escalate. Position identifier and counterparty identifier are enumerable low-entropy identifiers salted before this node ever sees them; QFC type and currency code stay opaque strings, with no table of contract-type or currency codes held here. Without a supplied control-total summary there is nothing to reconcile against, so the node reports did_not_run naming that precondition rather than assuming a tie-out. Emits a section 27.4 gate-policy value plus a sibling execution_state at a predictable output_payload pointer. Not a filing and not recordkeeping-adequacy advice.",
  "control_description": "Validates the shape of the institution's own 12 CFR part 371 qualified-financial-contract recordkeeping file -- the position, counterparty, and collateral record set the appendix to part 371 requires -- against its published record layout, and ties the file's declared totals to a supplied control-total summary. A file-shape defect and a totals mismatch are two separate, never-merged findings: a shape problem is checked first and routes to review_required regardless of how the totals compare, and only a clean-shaped file with a totals disagreement routes to escalate. Position identifier and counterparty identifier are enumerable low-entropy identifiers salted before this node ever sees them; QFC type and currency code stay opaque strings, with no table of contract-type or currency codes held here. Without a supplied control-total summary there is nothing to reconcile against, so the node reports did_not_run naming that precondition rather than assuming a tie-out. Emits a section 27.4 gate-policy value plus a sibling execution_state at a predictable output_payload pointer. Not a filing and not recordkeeping-adequacy advice.",
  "declared_inputs": [],
  "declared_outputs": [],
  "kernel_digest": "sha256:c7d0608caf559ede9bf75c63cee44bcc4cda97cc043ea6c689707e0e956709b9",
  "trust_label": "independently verified: zkVM execution proof (risc0/groth16-bn254)",
  "data_vintage": "2026-08-04",
  "last_validated": "2026-08-04",
  "conformance_fixtures_vendored": true,
  "compute_proof_ready": "ready",
  "wave": 84,
  "source_url": "https://ainumbers.co/chaingraph/art-537-qfc-recordkeeping-file-validator.html",
  "generated_at": "2026-08-15T11:12:17.704Z"
}
