#Regulation
Regulatory requirements shape the technical architecture of healthcare and financial systems. These posts cover the 21st Century Cures Act CDS carve-out, HIPAA technical safeguards, and the approach of encoding regulatory obligations directly as code-level constraints.
9 posts tagged with regulation. ← All posts
How an engineer should read AI regulation without a law degree — what the EU AI Act, ISO/IEC 42001, the NIST AI RMF, and sector rules actually ask for, and how each obligation maps to a control or artifact your pipeline can already produce.
Orient in AI regulation and translate it into controls (not legal advice): the EU AI Act's risk tiers and obligations, ISO/IEC 42001 as a certifiable AI management system, NIST AI RMF, and a crosswalk mapping each obligation to the artifact that satisfies it.
How the two Basel liquidity ratios are computed from raw positions, and why the hard part is a data pipeline, not a formula.
How the Liquidity Coverage Ratio and Net Stable Funding Ratio are computed: HQLA classification, outflow factors, and the reporting pipeline.
How a trade turns into a regulator-ready report — eligibility, enrichment, validation, submission, and the break management loop that keeps you compliant.
The trade/transaction reporting pipeline: eligibility, enrichment (LEI/UPI/UTI), validation, submission to the ARM/TR, and break management.
Deciding low-value, TRA, and trusted-beneficiary exemptions so low-risk payments stay frictionless while genuine risk gets challenged via 3DS.
Decide PSD2 SCA exemptions (low-value, TRA, allowlist) to keep low-risk payments frictionless around 3DS.
Turn ICT asset and third-party risk, incident classification, and reporting into a system you can actually run — with a resilience-testing loop that keeps it honest.
Engineer DORA operational resilience: ICT asset/third-party risk, incident classification, reporting, and resilience testing.
Classify account tax residency and generate withholding and FATCA/CRS reporting files.
Classify account tax residency and generate withholding and FATCA/CRS reporting files.
How to build PSD2-grade open-banking APIs — strong customer authentication and its exemptions, the consent grant and its revocation, and the hard boundary between account-information and payment-initiation scopes.
Teaches how to build open-banking APIs: strong customer authentication and exemptions, consent grant/lifecycle, account-information vs payment-initiation scopes, and TPP authorization with token/consent revocation.
How to turn a book of exposures into risk-weighted assets and a capital ratio with a deterministic, auditable pipeline
Teaches the engineering of a risk-weighted-asset calculator: exposure classification, risk-weight lookup (standardized approach), credit-conversion factors for off-balance items, and capital-ratio aggregation for regulatory reporting.
The 21st Century Cures Act §3060 CDS carve-out criterion 4 expressed as a code-level queue, lossless on reject, with audit-recorded reviewer rationale. Build it once, satisfy GDPR Article 22 for free.
All posts on this site are written by Pratik Dhanave, an Agentic AI Architect with 7+ years building production distributed systems, multi-agent AI platforms, and cloud-native infrastructure. About the author → Each article includes working code, architecture diagrams, and references to the specific frameworks and standards discussed. Browse all posts or explore related topics using the tag cloud above.