Reference

Standards register

We know ISO, IFRS and South African credit law. We do not know your local rules. That is what a partner brings.

Standard What it covers Status Where it lives Notes
ISO 4217 Currency codes, numeric codes, minor units Complies Currency reference data; see currency-iso-standards.md Alphabetic code is the canonical identifier; numeric code and minor unit carried for interop. ADR-322: the claimed minor units are pinned by StandardsRegisterPinTests
ISO 20022 — InterestComputationMethod (external code set) Interest accrual basis — the named day count conventions a tenant may price against Complies DayCountConventionSettings catalogue (per tenant, ADR-273): Actual360 = A004 (Act/360) · Actual365 = A005 (Act/365 Fixed) · ThirtyThreeSixty = A001 (30/360 Bond Basis — see deviation row) · ActualActual = A008 (Act/Act ISDA) · ThirtyE360 = A007 (30E/360 Eurobond) Codes verified against the published external code set (Bite 6, 2026-07-28). A tenant adds a convention as a settings row over the closed numerator × denominator axes — no code change. ADR-322: the mapped code set is pinned by StandardsRegisterPinTests
30/360 accrued-to-date (vs A001 Bond Basis) Intra-month accrual under 30/360: where February’s shortfall lands Deviates (with an ADR) ADR-210 skip/catch-up in AccountValuation — skip the 31st, catch up 2–3 days on Feb 28/29 Totals match A001 over any full month or year; accrued-to-date inside February differs from ISDA 30/360, reproducing the legacy engine. See ADR-210 and ADR-273 Decision 7. ThirtyE360 (A007) carries no deviation
Business day conventions Rolling due dates off weekends and holidays Partial Schedule settings — BusinessDayConvention (ADR-225); CreateAccountValidator’s calendar gate (ADR-405 Decision 6) Following / Modified Following / Preceding supported. A convention other than None now requires at least one calendar at account creation — an empty list yielded a Monday-to-Friday calendar with no holidays, which adjusted off weekends and landed on public holidays. Accrual and Maturity schedules stay unadjusted by design. Holiday calendar coverage per tenant is still not documented, and the shared schedule editor (standing orders, debit orders, recurring tasks) is not yet gated — see ADR-405’s Calendar.CreateComposite follow-up
IFRS 9 §5.4.4 — write-off (de-minimis derecognition) Derecognising a residual loan balance with no reasonable expectation of recovery, once an account has ended Partial SmallBalanceWriteOffSettings on AccountType; SmallBalanceWriteOffStep (day-end); write-off expense / income GL accounts via posting rules Covers the de-minimis case only — a configured tolerance and wait period sweep the rounding residue on a Closing account, closing it with ClosureReason.SmallBalanceWriteOff. Provisioned bad-debt write-off is a separate concept, covered by its own row below (ADR-282). See ADR-276
IFRS 9 §5.5 — impairment (ECL, simplified provision-matrix approach) Expected credit loss provisioning over an ageing matrix, three-stage classification, and interest treatment on credit-impaired assets Deviates (with an ADR) ProvisioningSettings (matrix rows: fromDaysPastDue, coveragePercent, stage, cureProbationDays; exposure expression) per tenant; provision position + day-end recompute on the account aggregate; impairment expense / provision contra-asset / interest-in-suspense GL accounts via posting rules; za-retail seed Matrix, staging and cure probation are configuration — a tenant onboards without code. Individually assessed provisions and qualitative stage pins override the collective bucket, both four-eyes gated. Deviation: Stage 3 interest is purely suspended — zero income while impaired, the full suspense balance released to income on cure — rather than IFRS 9 net-basis unwinding of the discount, and there is no cash-first suspense release on partial recovery. Understates Stage 3 income relative to strict IFRS 9; a reporting-side reconciliation is the intended remedy. The default exposure base nets interest in suspense off gross carrying amount (Balance + Accrued - InterestSuspense), so suspended interest does not charge impairment expense against income never recognised — see ADR-275 Decision 7’s 2026-08-03 amendment, which is not accountant-reviewed. See ADR-275 Decisions 6, 7 and 9. ADR-322: the seeded exposure base and staging are pinned by StandardsRegisterPinTests
National Credit Act 34 of 2005 (South Africa) §125 — early settlement The amount a consumer must be quoted to settle a credit agreement early, and the cap on any early termination charge Complies SettlementSettings on AccountType (settlementInterestDays, settlementChargeCap); za-retail PersonalLoan / VehicleFinance issue-settlement-quote operations The cap is a configured expression evaluated against the agreement, never hardcoded: small and intermediate agreements carry no early termination charge, large agreements (principal ≥ R250 000) are capped at three months’ interest. Non-ZA tenants leave settlementChargeCap unset and are uncapped. See ADR-274 Decision 7
ISO 20022 — Bank Transaction Codes (BTC) + camt.053 Transaction classification (Domain/Family/SubFamily) on account and transaction types; end-of-day account statement export; which projected cash flows count as externally classified payments Deviates (with an ADR) AccountType.BtcFamily / TransactionType.BtcCode (Accounts domain config); Camt053StatementBuilder, GET /api/accounts/{id}/statements/camt053; NextPaymentsBuilder and the btc:INTR sort/filter key on the accounts listing Code list: BTC_Codification_30October2023.xls (iso20022.org, 30 Oct 2023). Deviation: BTC has no demand/call-deposit family — CallDeposit maps to LDAS/NTDP (Notice Deposits); see ADR-266 Decision 10. ADR-341 Decision 2 makes the classification load-bearing beyond reporting: a projected flow earns a next-payment entry only when its type resolves to a non-proprietary sub-family, and tenant-agnostic UI addresses entries by that sub-family rather than by a product’s transaction-type name
ISO 20022 camt.053 / SWIFT MT940 — statement identification The bank’s own number for a statement it sends us, so an operator can name the file a line came from when they talk to the bank Complies Camt053Parser reads Stmt/Id, falling back to LglSeqNb then ElctrncSeqNb; Mt940Parser reads :28C:, falling back to :28:. Carried on StatementImported.StatementReference and shown on the external account’s statement listing One field, because MT940’s :28C: is a statement number and sequence number combined (123/1) and splitting it would invent a shape camt.053 does not share. Null in profile-driven CSV/PDF/Excel imports, whose mappings carry no statement header
National Credit Act 34 of 2005 (South Africa) §40 — credit provider registration A person who conducts business as a credit provider must be registered with the National Credit Regulator Partial Credit Provider Registration identification type (issuer the NCR, expiry required, annual renewal warning) held by the operating entity; requiresOperatingEntityRegistration on the za-retail PersonalLoan, MortgageBond, VehicleFinance and Microloan account types, conditioned on regulatoryRegime being NCA; the eligibility guard at account creation, pending-account edit and activation The platform records what the tenant declares and refuses new NCA lending in an entity holding no current registration on the trading date — it does not verify the registration with the NCR, and no NCR register lookup exists. The demand is conditional because §4 exempts agreements the Act does not reach, and regulatoryRegime is chosen per account: an unconditional demand would refuse a lawful exempt booking. Existing accounts keep servicing when a registration lapses — the Act’s remedy for lending while unregistered is not a servicing freeze, and freezing run-down would harm the consumer. A day-end task warns ahead of expiry and again on lapse. Not claimed: the R500 000 turnover threshold for who must register is the tenant’s determination, not the platform’s; and migration and file-import paths are exempt, so a historical account carries no eligibility decision. See ADR-420 Decisions 7 to 10
National Credit Act 34 of 2005 (South Africa) §4 — applicability Which credit agreements fall under the Act, and therefore which statutory obligations attach Partial regulatoryRegime Lookup property (NCA / Unregulated) on the za-retail PersonalLoan, MortgageBond, VehicleFinance and Microloan account types; pre-filled from the account owner’s counterparty type The platform holds neither juristic asset/turnover nor arm’s-length data, so §4 is not derived: the clerk classifies each agreement and the property is required. The juristic-person threshold (R1 000 000) and the large-agreement threshold (R250 000) are set by ministerial notice in the Government Gazette and carried in the property label as clerk guidance, not as code — the specific notice reference is not yet recorded here, which is why this row is Partial. See ADR-278 Decisions 1 and 3
National Credit Act 34 of 2005 (South Africa) Reg 35(f) / §103(5) — cost of credit The cost-of-credit buckets a statement must summarise, which are also the buckets the in duplum cap counts Partial TransactionType.CostOfCreditCategory (Principal · Interest · InitiationFee · ServiceFee · CreditInsurance · CollectionCost · DefaultAdmin · Legal), configured in tenant YAML; CostOfCreditValidator in AccountTypesSettingsValidator Every charge on an NCA account type must carry a category — an uncategorised fee would vanish from the Reg 35 summary and undercount the §103(5) cap, so the validator rejects it. Classification, statement disclosure and the §103(5) cap are in. A default episode opens on the day the walk sees the account cross the regime’s days-past-due threshold, capturing the outstanding balance as the ceiling; day-end accrual clamps to the remaining headroom and an operator charge over it is refused (DefaultEpisode, DefaultEpisodeStep, RegulatoryLimitsSettings PerDefaultEpisode row). Not enforced: retro-remediation — charges already booked above the ceiling are never clawed back; and the no-revival reading (payments during an episode do not re-open headroom) is the standard position but is ours, not settled by us, and is a legal-review item. See ADR-278 Decision 4 and ADR-299
National Credit Act 34 of 2005 (South Africa) §§108–110 / Reg 35 — statements of account What a periodic statement must show, and how often it must be delivered Partial AccountStatementLine.Category, StatementIssued (agreement block, statement date, payment details, per-category totals); NCA statement renderer; StatutoryStatementDueProvider + day-end sweep; statutoryStatementMaxInterval on AccountType Reg 35 content is rendered only for accounts whose regulatoryRegime is NCA; non-NCA statements are unchanged. The day-end sweep issues a statement once an NCA account passes its statutory interval, including while Suspended. Proof of despatch is held: StatementEmailed carries a DocumentDespatch (channel, address used, timestamp, optional tracking reference), the same record the §129 notice path emits (ADR-302 Decision 4). No registered-mail channel exists yet, so only the email case is proven. See ADR-279
IFRS 9 §5.4.4 — write-off (provisioned bad debt) and post-write-off recoveries Derecognising a credit-impaired loan against its provision, and the treatment of amounts recovered afterwards Complies WriteOffAccount command on the loan (Stage 3 gated, four-eyes eligible); suspense reversal → provision true-up to E − S → write-off transaction → closure with ClosureReason.BadDebtWriteOff; cascade opens a linked salvage account carrying the claim as a memo pair; recovery receipts post to bad-debt recoveries income Write-off is derecognition, not forgiveness: the legal claim survives on the salvage account as a memo balance that nets to zero, so the balance sheet is clean while the claim stays visible and collectable. Recoveries go to P&L as income when received rather than reversing the original write-off. Only the true-up moves impairment expense. See ADR-282 Decisions 2–5
National Credit Act 34 of 2005 (South Africa) §129(1) — notice of default When a credit provider may first put a defaulting consumer on notice, and what that notice must offer Partial DefaultProcessSettings regime rows (noticeAfterBusinessDays, CalendarId) per tenant; DefaultProcess aggregate in Collections with the day-end eligibility derivation; NoticeDocument slice (issue → render → despatch, four-eyes gated); Pre-legal pool routing The 20-business-day gate is counted from the oldest unpaid due entry on the tenant’s calendar, not off an ageing band — ageing is calendar days and 20 business days (~28 calendar) falls inside a typical 30-day band. Holidays shift the boundary as configuration. The notice template’s wording is not lawyer-reviewed — the mechanism ships, the drafting is an open legal check. See ADR-302 Decisions 2, 3 and 9
National Credit Act 34 of 2005 (South Africa) §130(1) — when enforcement may begin The further waiting period after the §129 notice is delivered, and the requirement that the default still subsist Partial enforceAfterBusinessDays on the DefaultProcessSettings regime row; EnforcementEligibilityReached derived from the despatch date; DocumentDespatch proof on EnforcementNoticeDocumentDespatched; full-cure lapse of an issued notice The ten business days run from despatch, not from issue — what a court asks for is proof of delivery. A full arrears cure cancels eligibility and lapses an issued notice, so a surviving notice can never bless an enforcement over a cured account; re-default needs a fresh notice. Partial: only the email channel is proven — no registered-mail channel exists yet, so the Sebola/Kubyana tracking-reference field is shaped but unused. See ADR-302 Decisions 4 and 5
National Credit Act 34 of 2005 (South Africa) §86 — debt review as a protected state What changes for a consumer who applies for debt review: collections activity, enforcement, and the restructured agreement Partial CounterpartyHoldPlaced / CounterpartyHoldLifted on Counterparty (four-eyes; hold status, reference, effective and recorded dates), with the NCA counsellor details on the companion DebtReviewHoldDetailsRecorded; the seeded debt-review hold applied to every one of the consumer’s cases; enforcement-notice issue and EnforcementEligible hard-refused; ADR-300 raise seam degrades with a held-consumer reason; restructure-under-review operation on the za-retail lending products The state is generic — a party-level hold configured per regime, of which NCA §86 is the seeded instance — and orthogonal to CounterpartyStatus. The audit claim is “no collector was dispensed this account after the effective date, and nothing was presented for collection”, not “no collector touched it”: recording an outcome on a held case stays allowed, because refusing it pushes the contact history onto a notepad. Default charges and fee accrual continue — the agreement runs until restructured. §86(10) termination is clerk-driven with the state recorded, not automated. The counsellor is not enforced: ADR-731 made it optional so a hold with no counsellor — a death, a court order — uses the same command, so a debt-review hold can be recorded with none and nothing refuses it. Enforcing it belongs to the hold status’s own rules. See ADR-302 Decisions 6, 7 and 8 and ADR-731 Decision 3
Prescription Act 68 of 1969 (South Africa) §§11, 14 / National Credit Act §126B — prescribed debt When a debt claim expires, what interrupts the clock, and what a credit provider may no longer do once it has prescribed Complies PrescriptionSettings on the salvage AccountType (years, position, abandonmentTransactionType); prescription baseline inherited from the loan’s last payment date; interruption on receipt or AcknowledgeDebt; day-end flip to Prescribed; AbandonClaim closing with ClaimAbandoned The three-year clock runs from the loan’s last payment, not the write-off date — dating it from write-off would overstate the remaining life and is exactly the s126B breach this guards against. Acknowledgement of debt and part-payment both restart it (Prescription Act §14). Once Prescribed, further fees and acknowledgement are hard-refused, not merely flagged; a voluntary payment on a prescribed claim is still accepted and still recovery income. Blocking collection workflow on prescribed claims is not yet in. See ADR-282 Decisions 6–8
ISO 3166-1 alpha-2 Country codes Complies IsoCountryReference — the full alpha-2 set shipped in code, exposed as GET /api/iso-countries and stored as an IsoCountryCode value type (ADR-386); Country.Code on the Countries registry (ADR-102); the tax-jurisdiction lookup type on the operating-entity type, per tenant (ADR-324) Alpha-2 is the canonical country identifier, and three lists answer three different questions. The countries a tenant transacts in are operational configuration and stay per tenant. The jurisdictions it owes tax in are an operating-entity choice. The countries a document may be issued in are unbounded and are not a tenant choice at all — they are the standard, so that list ships in code and covers the full set. IsoCountryCode validates two uppercase ASCII letters, so ZA , ZAF and South Africa are all rejected rather than stored as three countries. Alpha-3 and numeric codes are still not carried
ITU-T E.164 International telephone number format Complies PhoneNumber property kind (ADR-222); a beneficiary’s notification mobile (BeneficiaryNotificationContacts.MobileNumberPattern, entered through the same dialling-code field) Numbers canonicalise to E.164 (+27821234567) on entry, with mobile-validity checks. Local-format input is accepted and converted against the account’s country — E.164 alone is not enough to parse a locally entered number
SACRRA Data Transmission Hub South African credit bureau submission layout and cadence Planned ADR-301: SubmissionRun aggregate with the Produced → Submitted → Acknowledged lifecycle and per-record acknowledgement counts; the NCA reportable set keyed on regulatoryRegime; the nca-borrower role-conditional identity block and the one readiness rule the run and the ops list share; monthly full-position and daily incremental extracts as CSV; bureau status mapped from RegulatorySubmissionSettings, with an unmapped state failing the run; audited artifact download; one record per owning party on a jointly-owned account, each carrying its own identity block (ADR-330 Decision 2) The L700v2 layout is not built — it is licensed and we do not hold it, so the extract’s field list is our own (ADR-301 Decision 6) and no SACRRA conformance is claimed. Transport is manual: files are downloaded and uploaded to the hub by hand, and acknowledgement counts are typed in from its response. Rendering L700v2 and DTH connectivity are each a follow-up ADR. Joint accounts are covered: each owning party gets their own bureau record carrying the whole obligation, because joint and several liability makes each of them liable for all of it — so the extract’s record count no longer equals its account count, and the readiness list names each incomplete subject separately
OECD Model Tax Convention Article 11 — withholding on interest paid to a non-resident The statutory withholding rate a source state applies to interest paid abroad, and the reduced rate a bilateral treaty substitutes for it Partial ADR-325: WithholdingRegimeSettings rows keyed by payer jurisdiction × payee residency country × withholding class, each naming a date-effective rate series; treaty relief gated on declared evidence held on TaxResidency (ADR-304); subtractive split at the interest capitalisation; per-tax-type TaxAccount liability and a periodic return writer The Article 11 shape is the configuration surface: a source-state statutory rate with treaty rates substituted per residency country, relief conditional on the beneficial owner’s declaration, and no rate in code. za-retail seeds the South African instance — 15% statutory (ITA s50A–s50H) with GB at 10% and NL at 0% — and the WT002 return. Absent evidence the statutory rate applies; absent a row for the payee’s country the statutory rate applies too and a Task raises the configuration gap, so resolution never fails toward less withholding. Not claimed: the treaty rates seeded are demo values, not a maintained treaty table, and a stale rate under-withholds; the WT002 field list is ours, not a SARS e-filing format, and no revenue authority has accepted a file we produced; paying the accumulated liability over is out of scope. The s50D payer-exemption analysis is not asserted — whether a given entity sits in an exempt payer class is a tax opinion, and the platform carries only the seeded value (withholdingPayerClass, empty for both za-retail entities). Dividends and royalties use the same mechanism and are unseeded
SARS IT3(b) third-party reporting (BRS v4.0.0D-10) Bi-annual interest-income return on every account holder — residents and non-residents alike — and the holder’s own tax certificate Partial ADR-304: TaxResidency concept aggregate, required to grant the investor role; the IT3(b) writer as an ADR-301 submission-run artifact, reporting-entity scoped, with the BRS §6.1 layout transcribed as a declarative table and pinned by a golden file; TaxCertificate document off the same InterestPerHolderPeriod projection, despatch-proofed per ADR-302 Non-residents are in scope, which is the whole point of capturing residency as a set: a holder with no South African tax number is still reported, on a passport or foreign-TIN basis. A holder with no residency declared travels on the run as a warning that blocks MarkSubmitted — it never fails the file, because the first run would otherwise fail against the entire back book. The certificate is built as the sum of the tax year’s two bi-annual periods rather than re-derived, so it cannot disagree with the file. Partial: transport is manual (no eFiling connectivity); partnership holders are refused because the partner record is not written; and the D/T variant question is open — the golden file is built against v4.0.0D-10 and that has not been confirmed as the live-platform variant. The WTI record type is ADR-325’s
Segregation of duties (maker-checker) Separation between the people who initiate a change and the people who authorise it Complies ADR-332: ApprovalExclusion derives contributors ∪ submitter from the frozen AuthorisationRequested snapshot, consumed by the approve guard, QuorumFeasibility, the approver push and the queue’s “Mine to approve” filter; change-sets.open-/submit-/discard-change-set permission keys; seeded Makers / Supervisors / Approvers groups Established practice requires segregation between initiators and approvers, not a single initiator — so a change set has many contributors and no owner, and every contributor plus the submitter is barred from approving it. Exclusion reads the immutable event, never the mutable draft, and fails toward more exclusion: a staged entry with no recorded author blocks approval outright rather than silently excluding nobody. Zero configuration — there is no tenant opt-out, and submit refuses up front when the exclusion is what leaves the quorum unmeetable. Named gap: staff-as-customer conflict — a user approving work on their own account — is a separate control in established practice and is not implemented (ADR-332 §Out of Scope). In Development only, AllowSelfApproval bypasses the whole exclusion for the single-user dev loop; a Production host ignores the flag
PayShap (BankservAfrica RPP) South African rapid payment rail: proxy-addressed, real-time, irrevocable Partial SettlementRail ordered candidates with settlementSpeed, amountLimit, requiredAddressing and channel (RppPayShap); submit-on-approve and DirectCreditStatus.Settled on DirectCreditInstruction; IProxyResolver + name confirmation; za-retail PayShap-Out / PayShap-In rails Partial: the RPP wire adapter needs a sponsor-bank / BankservAfrica relationship and does not exist, so scheme responses are simulated (SimulatedProxyResolver, simulated settlement) — the rail, routing, addressing and lifecycle are real, the wire is not. PayShap is irrevocable, so the inbound rail seeds returnWindowDays: 0 and holdDays: 0. Fraud/velocity controls beyond the rail amount limit and proxy name confirmation are out of scope until pilot. See ADR-306, ADR-298 D1
ISO 20022 — ExternalProxyAccountType1Code (external code set) The kind of alternative address a bank account is reachable by, so a proxy is scheme-neutral rather than a local invention Complies ProxyKind (LedgerTM.Contracts) on BankAccountProxy and on ShapIdIdentifier, mapped by ProxyKinds.IsoCodeOf (LedgerTM.Payments, ExternalAccounts/Domain/ProxyKinds.cs): MobileNumber = MBNO · EmailAddress = EMAL · CustomerIdentifier = CUST Codes verified against the published external code set (2026-08-12). MBNO is defined as a number in the international public telecommunication numbering plan, so a mobile proxy normalises to E.164, reusing ADR-222’s phone kind. Using the ISO set is what makes a PIX email proxy and a UPI customer-id proxy read as the same concept as a PayShap ShapID. ADR-322: the mapped code set is pinned by StandardsRegisterPinTests. See ADR-306 Decision 5. ADR-412 Decision 1 puts the same code set on a beneficiary’s own identifier, so a proxy-addressed beneficiary is scheme-neutral too
ISO 20022 — ChargeBearerType1Code (external code set) Who bears a payment’s charges — the payer, the beneficiary, both, or whatever the service level dictates Complies ChargeBearer (LedgerTM.Contracts), mapped by ChargeBearers.IsoCode (LedgerTM.Accounts, Domain/ChargeBearers.cs), declared per rail on SettlementRail.ChargeBearer (ADR-416 Decision 7): Debtor = DEBT · Creditor = CRED · Shared = SHAR · ServiceLevel = SLEV The full code set, not a subset. An unset rail is DEBT, the only bearer under which a contractual payment discharges the obligation in full. The wire code has one mapping, in Accounts, so two adapters cannot map one bearer two ways. The mapping and the default are pinned by StandardsRegisterPinTests
PayInc universal branch codes South African per-bank universal branch code, valid for both EFT credits and debit orders Planned ADR-310 (Proposed) Not built. PayInc (formerly BankservAfrica) publishes codes to participants, not as an open dataset — the registry is operator-maintained tenant settings, not a synchronised feed. ADR-322: the six-digit code shape is pinned by StandardsRegisterPinTests
PASA / DebiCheck authenticated collections (South Africa) — mandate lifecycle The payer’s authority for a named creditor to collect one agreement’s instalments from a named bank account: registration, bank authentication, amendment re-authentication, cancellation, and the disputability of each collection stream Partial CollectionAuthority aggregate (LedgerTM.Payments); SettlementRail.RequiresAuthority + per-state stream routing + DefaultTrackingDays; ICollectionAuthorityReader gate on activation, on the day-walk raise and at submission; ReturnDirectDebitNotAuthorisedCommand; za-retail DebiCheck rail A mandate is keyed on the agreement it collects — account + rail standard — which is what the scheme registers against a contract reference; the paying bank account, the payer and the creditor are recorded attributes, so a third party can pay. One generic lifecycle covers both ZA streams on day one: Authenticated means the payer’s bank holds proof (DebiCheck), Registered means lodged but unconfirmed (the RM stream — collectable and fully disputable). A material amendment or a re-numbered payer account re-authenticates, with the proven terms staying collectable meanwhile. Partial: the Bankserv wire adapter (TT1/TT2 messaging) does not exist — every authentication outcome is an operator action, so the lifecycle is complete but unconnected. See ADR-300, ADR-320. ADR-322: the per-state stream routing is pinned by StandardsRegisterPinTests
WebAuthn (W3C Web Authentication Level 2) Public-key credential registration and assertion ceremonies — the phone passkey an approver enrols and signs with Complies ApproverCredential aggregate (LedgerTM.Authorisation); registration + signed-decision ceremonies via fido2-net-lib; SignedAssertion persisted on the approval/rejection event and independently re-verifiable from the event stream alone Desktop approve/reject is unaffected and stays unsigned — WebAuthn only applies to the phone (PWA) approval path. Attestation is not requested (AttestationConveyancePreference.None) — the platform trusts the relying-party ceremony and the enrolling user’s authentication, not the authenticator’s manufacturer chain. See ADR-316
RFC 8292 — Voluntary Application Server Identification (VAPID) for Web Push Authenticating the application server to a push service so it can deliver notifications to a subscribed browser Complies WebPushSender (LedgerTM.Authorisation) via the WebPush NuGet package; VAPID key pair configured per environment; FakeWebPushSender selected outside Staging/Production Push payloads carry only a count and a deep link requiring sign-in — never deal or approval detail — so a stale or intercepted subscription leaks nothing confidential. See ADR-316
IFRS 8 §§27–29 — segment reporting: reallocation and prior-period correction Which segment an account’s balance and its income belong to when the account moves between segments, and how a prior-period misclassification is put right Informed by SubLedger.MoveToCostCentre / PostReclassificationEntries (Books) — balance sheet rows move, income statement rows stay with the period that earned them, closed years restated per fiscal year in both currency halves, every leg dated the trading date An ordinary transfer moves the asset only: income already earned stays with the departing cost centre, so a centre’s income statement survives a transfer. A mis-booking is corrected by moving with the effective date set to the day the books opened — one verb, no correction flag. Informed by, not governed by: cost centres are management segments, so IFRS 8 applies by analogy — §27’s measurement basis is the tenant’s policy on docs/business/models/cost-centre-accounting.md, §28’s inter-segment reconciliation is a scenario (a move’s transfer legs net to zero), and §29’s restate-or-disclose is met by disclosure: an append-only ledger cannot restate a closed fiscal year, so the closed years’ share is posted between the two centres dated the trading date, one pair per closed year, each stamped with the year it was intended for; period close sweeps in the reporting currency only, so a closed year’s account-currency income is moved as an ordinary income leg alongside it, and the departing centre is left flat in both currencies; a reader reconstructs the comparative from the stamp rather than from a restated figure. Not claimed: cost centres are internal management segments — no reportable-segment disclosure is produced, and no segment note is rendered anywhere in the platform. See ADR-771 Decisions 1, 3 and 4
Scheme participant identity — BankservAfrica user code; ISO 20022 CdtrSchmeId / InitgPty; Bacs SUN; NACHA Company Identification The identity a clearing scheme issued the submitting party, which the outbound file header carries and the scheme’s return file is addressed to Partial ChannelParticipantSettings (per tenant, ADR-739 Decision 1): one row per (channel, owning operating entity, sponsoring bank), holding the code the scheme issued. ChannelParticipantResolver picks the row a submission goes out under; BankservAfricaSubmissionFileGenerator writes it into the 01 header’s user-code field ISO 20022 has no single term for this: in pain.008 the identity is the Creditor Scheme Identification (CdtrSchmeId, the SEPA Creditor Identifier) and in pain.001 the Initiating Party (InitgPty); Bacs calls it a Service User Number, NACHA a Company Identification, BankservAfrica a user code. The platform models the concept generically and every channel declares a slot, so onboarding a bank’s identity is configuration. Partial for two reasons. Only the BankservAfrica slot is exercised — no other channel has a generator or parser, so no other mapping is proven against a wire format. And the BankservAfrica layout is not a published specification: the header’s user-code position is asserted from the outbound mirror in BankservAfricaFileFormat, the same pinned reconstruction ADR-727 records for the unpaids layout. A six-digit check refuses a code the header would otherwise truncate. Not claimed: no sponsoring bank has accepted a file we produced
ISO 20022 — RemittanceInformation (RmtInf/Ustrd) The reference a payment carries to the beneficiary, so they can match the money to what it is for Planned ADR-413 Decision 7: TheirReferenceDefault on an external account and the per-payment override stamped into DirectCreditInstructionInitiated; an approved beneficiary may declare a BeneficiaryReferencePolicy (required, plus an anchored pattern) enforced at capture The model is named for the standard so the mapping is mechanical when the rail adapters land; no outbound message is built onto RmtInf/Ustrd yet, which is why this is Planned and not Complies. MyReferenceDefault is deliberately outside the standard’s scope — it never leaves this platform. Row goes to Complies when an adapter emits the field and a round-trip against a scheme’s published schema is asserted
ISO 20022 — ExternalServiceLevel1Code (external code set) What a payment needs of the clearing system — non-urgent, urgent, or same-day value — so a service level means the same thing here as on the wire Partial PaymentServiceLevel (LedgerTM.Contracts.Payments): NonUrgent = NURG · Urgent = URGP · SameDayValue = SDVA. Carried on DirectCreditInstructionInitiated; SettlementRail.ServiceLevels declares which levels a rail serves and IsEligible tests it The platform uses three of the code set’s members — the three a push rail ladder can act on. A rail naming no levels serves them all, so a tenant configured before ADR-414 routes exactly as it did. Partial because no outbound adapter writes SvcLvl onto a wire message yet (ADR-298 D1 — the scheme response stays simulated pending a sponsor bank); the codes are modelled and asserted, not transmitted. Row goes to Complies when an adapter emits the field. See ADR-414 Decision 2
BankservAfrica Real Time Clearing (RTC), South Africa Same-day interbank credit cleared against an account number rather than a proxy — the tier between an instant proxy payment and the next-day EFT batch Partial PaymentChannelType.RtcBankserv (LedgerTM.Payments.Submissions.Domain); za-retail seeds RTC-Out and RTC-In in SettlementRailSettings.yaml, both SettlementSpeed.Instant and neither requiring a collection authority. RTC-Out serves URGP and SDVA only, so a non-urgent payment still clears on EFT RTC clears a credit and only a credit: there is no real-time pull in this market, and a settled RTC payment is irrevocable. The rails are routable and a payment reaches submission on them, but Partial because the scheme response is simulated pending a sponsor bank (ADR-298 D1) — a demo settles, a production payment does not leave the building. Row goes to Complies when the RTC adapter emits and reads a real wire message. RTC’s opening time and per-transaction cap are not modelled; the tenant configures the cap as a rail row when it has one. See ADR-414 Decisions 1 and 8