MGLA produces nothing that is not bound to an artefact. Every finding, every action, every actor sits on a tamper-evident chain — hashed, time-stamped, versioned, and inspectable by counsel, regulator or board.
Every t0 is hashed and write-once. Subsequent states reference the parent; the lineage is reconstructible.
Action and event logs are hash-linked. A modified record breaks the chain on inspection.
Each artefact carries a verifiable timestamp. Optional anchoring to a public ledger is available for regulated regimes.
Every finding carries the rule(s) that produced it and the artefacts the rule(s) read. No black-box assertions.
A finding is bound to the rule version that produced it. Re-runs against older rules are reproducible.
Given a snapshot, a rule version, and the inputs, the framework produces the same finding deterministically.
When a supervisory authority asks how a conclusion was reached, MGLA returns the snapshot, the rule version, and the artefacts the rule read. The reasoning is reproducible from the same inputs.
Where the regime requires it, the chain anchors to a public ledger; where it does not, the chain remains private to the institution. The framework is agnostic to the assurance regime the institution sits under.
A live regulatory analysis framework, developed and maintained by IT Law 2035.