Open Standard · RAFCF 1.0 · Draft 0.2 · July 2026

The Reddix Agent Financial Controls Framework

A rail-neutral, vendor-neutral standard for recording, classifying, gating, and recovering the financial actions taken by AI agents. RAFCF governs any agent-initiated instruction that creates, alters, extinguishes, or transfers a financial obligation — defines the control objective at each reversibility tier, and gives finance, audit, risk and insurance functions a shared vocabulary to cite in their own templates.

Published under CC BY 4.0. Conformance may be claimed by any organization without permission or fee. Requirement levels use RFC 2119 keywords — MUST, SHOULD, MAY.

The reversibility tiers

Every agent financial action is assigned exactly one tier. Tiers are ordinal: a higher tier means less recoverability after commit, and therefore more prevention before it.

Tier 0

Freely reversible

Control posture: log, register the inverse, allow. Undo at no cost and without counterparty cooperation.

Processor-internal transfers, pre-capture card auths, internal ledger entries, draft or unissued documents.

Tier 1

Compensable

Control posture: arm compensation at classification; execute on trigger. Recoverable via a defined mechanism within a bounded window and reason list, or unilaterally rescindable before counterparty reliance.

Card refunds, ACH reversals within window, credit memos, cancellation of an unaccepted order.

Tier 2

Hold before commit

Control posture: manufacture a window — maker-checker approval above threshold before release. No reliable post-commit undo; recovery depends on a counterparty’s cooperation.

Instant rails, wires, accepted purchase orders, approved invoices, vendor bank-detail changes.

Tier 3

Irreversible

Control posture: prevention only — block, or require approval before signing. No recovery primitive exists at all. Never promise undo.

On-chain settlement, executed contracts with no unilateral exit.

Classification is conservative by default: where an action's tier is uncertain, it MUST be assigned the higher (less reversible) tier until positively resolved. Automated classification MAY flag an unknown action for review but MUST NOT auto-lower a tier.

§2.2 · New in Draft 0.2

Commitment actions and movement actions

One tier scale governs both. For a movement, the tier follows the rail's finality law. For a commitment, it follows whether the organization can still withdraw unilaterally.

Why the distinction matters
Commitment actions typically precede movement actions and are less well controlled. An approved invoice is an obligation; the payment that follows is often downstream automation with no independent judgement in it. Governing only the payment leaves the decision that actually created the loss ungoverned.
Purchase commitmentIssues or amends a purchase order; releases against a blanket order; accepts a quote.
Tier 1–2tier 1 before acceptance
Fixed byTier 2 once the counterparty has accepted or relied.
Payable recognitionApproves an invoice for payment; releases a three-way match exception; posts an accrual.
Tier 1–2ledger vs counterparty
Fixed byReversible in the ledger; not reversible as a counterparty expectation.
Contract & price termsAccepts contract terms; sets or changes a price, discount, or rebate; renews a subscription.
Tier 2–3exit rights
Fixed byDepends on unilateral exit rights in the instrument.
Credits & concessionsGrants a refund authority, credit memo, goodwill concession, or write-off.
Tier 1–2on communication
Fixed byTier 1 in-ledger; Tier 2 once communicated to the counterparty.
Payee & master dataTier 2 by defaultCreates or alters a payee record, remittance instruction, or bank account detail in a vendor master.
Tier 2no reversal of exposure
Fixed byThe highest-leverage single field in the obligation surface. Maker-checker required independent of any payment it later affects.
Recurring commitmentEstablishes a subscription, standing order, usage-based commitment, or spend limit change.
Tier 2assessed on the series
Fixed byOne instruction creates an indefinite series of obligations. Materiality is measured on the obligation, not the instalment.
§4 · The normative core

Four control objectives

Written as auditable control statements in the COSO idiom, so an organization can assert each and an auditor can test it. Conformance is defined against these.

CO-1 · Record

An append-only, tamper-evident log

  • 1.1 Every action, classification, gate decision and recovery outcome is captured, currency-denominated, with agent identity and authorization context.
  • 1.2 The record is complete regardless of recovery outcome. Completeness is not contingent on success.
  • 1.3 A control reference is assigned at classification and propagated into the executing instruction and the resulting accounting entry.
  • 1.4 Records are retained tamper-evident, and a defined handover procedure transfers the evidence chain between implementations.
CO-2 · Classify

Tier and materiality before release

  • 2.1 Every action is assigned a reversibility tier and a materiality before it is gated or released.
  • 2.2 The basis for each classification is itself recorded and versioned, so prior classifications remain reconstructable.
  • 2.3 Commitment actions are classified on the same scale as movements, and a movement arising from a prior commitment records its reference.
CO-3 · Gate

Maker-checker on the material surface

  • 3.1 Actions at or above the materiality threshold for their tier are held for approval by a party distinct from the initiator.
  • 3.2 Fail-open versus fail-closed behaviour is defined per tier in advance and agreed contractually.
  • 3.3 The hold is a durable state, not a blocked connection — and an expiry is never recorded as a human decision.
  • 3.4 A hold withholds release of the instruction; it does not require the control plane to take possession of the value.
CO-4 · Recover

The inverse, armed at classification

  • 4.1 Where a mechanism permits recovery, the inverse is registered at classification time and executed on trigger.
  • 4.2 Where none exists, the system degrades to prepare-and-instruct, then to documented claim — side effects flagged, never assumed reconciled.
§5 · The loss-event schema

A record that survives the loss.

Standardized, currency-denominated, and comparable across organizations — the underwriting-grade data insurers entering agentic risk do not yet hold.

event_id· control_ref· action_ref· action_class· agent_identity· surface· tier· materiality· gate_decision· recovery_attempted· recovery_outcome· net_loss· side_effects· root_cause
Data ownership · §5.1 · normative
Loss events belong to the organization whose actions produced them. Recording to this schema transfers no ownership and grants no licence. Conformance MUST NOT be conditioned on granting anyone rights to your loss data — an implementation that requires data sharing as a condition of conformance is not conformant. Onward use is explicit, revocable and purpose-specific. Portability is not conditional: export may not be withheld as commercial leverage.
§6.2 · The comparable measure

Governed volume

Postures cannot be compared without a denominator. An organization gating a hundred million dollars is not in the same position as one gating a hundred thousand, even at identical conformance levels.

Governed volume
denominator
Total currency-denominated value of agent financial actions under the framework's controls in a period, counted once per action at the amount instructed or committed.
Gated volume
the material surface
The subset held for maker-checker approval. Typically a small fraction of action count but a large fraction of value.
Observed volume
Level 1 scope
Recorded and classified but not gated — Level 1 scope, or below-threshold actions at higher levels.
Committed volume
reported separately
The subset arising from commitment actions, reported apart from movement volume so the two are never double-counted.
Recovered value
against net loss
Value returned through executed compensation, reported against net loss from the loss-event schema.

Count at instruction, not at settlement. Where a movement discharges a previously counted commitment, count the commitment and reference the movement — never both. Scope must accompany the number: a figure covering two rails is not comparable to one covering six. Organizations SHOULD report governed volume as a proportion of total agent-initiated financial action value — the honest measure of how much of the surface is actually under control.

§7.1 · §7.3 · Stewardship

Editorship is not ownership.

A standard edited indefinitely by a single commercial implementer will, correctly, be discounted by the parties whose reliance makes it worth having.

The editor's conflict, stated
Reddix maintains this framework and also builds an implementation of it. That dual role is disclosed rather than obscured. No product is required — every conformance level is achievable in-house, with any third-party product, or a combination. Level names are descriptive, not product tiers. No certification monopoly: neither the editor nor any implementer operates an exclusive certification, accreditation or registry function, and conformance may be claimed and assessed without permission from any party.
Publication of Draft 0.3
editorial board
CommitmentSeat five to seven members from deploying organizations, audit practice and underwriting, with no more than one seat held by the editor.
First third-party conformance claim
independent body
CommitmentAny accreditation or assessor-qualification programme is operated independently — never by the editor or an implementer.
A stated adoption threshold
neutral host
CommitmentTransfer the specification, its trademark and the comment-disposition process to a neutral standards host. The specification travels free.

What is deliberately not promised: the editor does not commit to donating the Finality Registry data feed or the reference implementation. Separating a free specification from a commercially maintained current dataset is a legitimate structure, and stating it plainly is better than implying a transfer that will not occur.

Conformance is demonstrated, not asserted

A conformant organization can produce, on demand, a posture attestation generated from the Record plane — never compiled by hand.

Level 1

Observe

Record and Classify met in shadow mode: every agent financial action is logged, tiered, and assigned a control reference. This produces the exposure report. No gating yet.

CO-1 · CO-2
Level 2

Gate

Adds enforced maker-checker on material actions for routed surfaces, with defined fail-open / fail-closed policy and durable holds.

+ CO-3
Level 3

Recover

Adds armed compensation and prepare-and-instruct recovery, with loss events captured to the schema of §5.

+ CO-4 · §5

Conformance is per-surface and per-integration — an organization is conformant at a level for the surfaces and integrations in scope, never blanket. "Automated recovery" is claimed per surface, per access path. The attestation states its own scope.

First-party

The organization itself

Asserted from its own records. Internal governance, board and audit-committee reporting, vendor questionnaires. The default and the floor.

Second-party

A counterparty or platform

Partner onboarding, platform admission, contractual assurance between two parties.

Third-party

An independent assessor

External audit reliance and insurance underwriting. Normative: the assessor MUST be independent of the organization and of any vendor in the assessed scope. A party that supplies the controls cannot furnish an independent assessment of them — attestations generated by an implementation are first-party evidence regardless of format.

Comment on the draft.

The first comment window closes 31 October 2026. Cite the clause number. Every substantive comment will be logged, dispositioned — accepted, accepted-with-modification, or declined, each with a reason — and published alongside Draft 0.3.

Comment on the draft · standards@reddix.ai