# ANNEX J - KYC / IDENTITY ASSURANCE CONTROL MATRIX

> Balanced Exchange Framework (BEF) - Framework Version 1.0, 2026-08-22.
> Source of record: https://balancedexchangeframe.work/doc/annex-j

Annex J translates P21 into the implementation profile for the current Being KYC upgrade. Technical values are implementation defaults and may be replaced by a regulator-approved or independently validated equivalent without changing the P21 control objective.

| Control | Implementation profile v1 | Public / private | Regulatory gate |
| --- | --- | --- | --- |
| Session binding | Fresh signed challenge/NIP-98; nonce/TTL/anti-replay; one active process; rate limits. | Private metadata | Mandatory before capture. |
| Document capture | Direct raw upload; high-resolution MRZ/VIZ; no public media URL; TD1/TD3 v1. | Strictly private | Accepted document list + fallback required. |
| MRZ/VIZ | Deterministic OCR/extraction + ICAO check digits + VIZ cross-check; LLM advisory only. | Private | Checksums are integrity, not authenticity. |
| Document authenticity | Risk signals + certified/eID/vendor seam. | Private | Independent validation before CASP production. |
| Face match | Local 1:1 embeddings; calibrated thresholds; grey zone retry/review. | Biometric private | DPIA + performance/bias testing. |
| Liveness/PAD | Random challenge + server timing + optional low-risk illumination nonce; multi-signal PAD. | Biometric private | Do not claim replay-proof; test/deploy vendor seam. |
| Screening | Sanctions + PEP local dataset; multilingual fuzzy/identifier matching; human candidate review. | Private | Commercial data licence + PEP/EDD workflow. |
| Decision | Automatic IDENTITY-VERIFIED allowed; separate CDD-PENDING -> human safeguarded decision where required. | Private decision | AMLR Article 76(5) readiness / GDPR Article 22. |
| Storage | Encrypted fields + sealed archive; no PII in logs; controlled break-glass retrieval. | Private | Article 77/current-law retention and retrievability. |
| Document fingerprint | HMAC of normalized issuer/country/type/number; raw number encrypted. | Private | Duplicate detection without public/plain hash. |
| Public attestation | 37105: person, verified/revoked, method, version, times, authority; no document/biometric/screening data. | Public minimal | Trusted authority signature + expiry/revocation. |
| Public photo | Separate user-selected profile photo, not KYC selfie; separate consent. | Optional public | Not a condition of regulatory KYC. |
| Ongoing KYC | Daily/event-driven screening update; expiry/review reminders; transaction-monitoring handoff. | Private | KYC is ongoing, not perpetual badge. |
| Travel Rule | 37105 identity evidence + separate wallet ownership/control proof when TFR requires. | Mixed/minimal | P17/TFR implementation remains separate. |
| KYB | Separate corporate/UBO/representative flow. | Private | HOLD for legal-person clients until implemented. |
| UK deployment legal basis | Reuse technical identity pipeline only with UK-specific CDD decisioning and privacy mapping. | Private; public 37105 remains minimal | UK MLR/FCA + UK GDPR/DPA 2018 + DPIA + biometric Article 9 condition; CP-38 |
| **U.S. deployment identity/biometric** | **Reuse P21 pipeline only after state privacy/biometric + OFAC/tax/obliged-entity mapping; KYB for B2B.** | **Private; public attestation minimal** | **CP-48/49; state-specific consent/retention/human-review** |
