A rail-neutral, vendor-neutral standard for recording, classifying, gating, and recovering the financial actions taken by AI agents. RAFCF governs any agent-initiated instruction that creates, alters, extinguishes, or transfers a financial obligation — defines the control objective at each reversibility tier, and gives finance, audit, risk and insurance functions a shared vocabulary to cite in their own templates.
Published under CC BY 4.0. Conformance may be claimed by any organization without permission or fee. Requirement levels use RFC 2119 keywords — MUST, SHOULD, MAY.
Every agent financial action is assigned exactly one tier. Tiers are ordinal: a higher tier means less recoverability after commit, and therefore more prevention before it.
Control posture: log, register the inverse, allow. Undo at no cost and without counterparty cooperation.
Processor-internal transfers, pre-capture card auths, internal ledger entries, draft or unissued documents.
Control posture: arm compensation at classification; execute on trigger. Recoverable via a defined mechanism within a bounded window and reason list, or unilaterally rescindable before counterparty reliance.
Card refunds, ACH reversals within window, credit memos, cancellation of an unaccepted order.
Control posture: manufacture a window — maker-checker approval above threshold before release. No reliable post-commit undo; recovery depends on a counterparty’s cooperation.
Instant rails, wires, accepted purchase orders, approved invoices, vendor bank-detail changes.
Control posture: prevention only — block, or require approval before signing. No recovery primitive exists at all. Never promise undo.
On-chain settlement, executed contracts with no unilateral exit.
Classification is conservative by default: where an action's tier is uncertain, it MUST be assigned the higher (less reversible) tier until positively resolved. Automated classification MAY flag an unknown action for review but MUST NOT auto-lower a tier.
One tier scale governs both. For a movement, the tier follows the rail's finality law. For a commitment, it follows whether the organization can still withdraw unilaterally.
Written as auditable control statements in the COSO idiom, so an organization can assert each and an auditor can test it. Conformance is defined against these.
Standardized, currency-denominated, and comparable across organizations — the underwriting-grade data insurers entering agentic risk do not yet hold.
Postures cannot be compared without a denominator. An organization gating a hundred million dollars is not in the same position as one gating a hundred thousand, even at identical conformance levels.
Count at instruction, not at settlement. Where a movement discharges a previously counted commitment, count the commitment and reference the movement — never both. Scope must accompany the number: a figure covering two rails is not comparable to one covering six. Organizations SHOULD report governed volume as a proportion of total agent-initiated financial action value — the honest measure of how much of the surface is actually under control.
A standard edited indefinitely by a single commercial implementer will, correctly, be discounted by the parties whose reliance makes it worth having.
What is deliberately not promised: the editor does not commit to donating the Finality Registry data feed or the reference implementation. Separating a free specification from a commercially maintained current dataset is a legitimate structure, and stating it plainly is better than implying a transfer that will not occur.
A conformant organization can produce, on demand, a posture attestation generated from the Record plane — never compiled by hand.
Record and Classify met in shadow mode: every agent financial action is logged, tiered, and assigned a control reference. This produces the exposure report. No gating yet.
Adds enforced maker-checker on material actions for routed surfaces, with defined fail-open / fail-closed policy and durable holds.
Adds armed compensation and prepare-and-instruct recovery, with loss events captured to the schema of §5.
Conformance is per-surface and per-integration — an organization is conformant at a level for the surfaces and integrations in scope, never blanket. "Automated recovery" is claimed per surface, per access path. The attestation states its own scope.
Asserted from its own records. Internal governance, board and audit-committee reporting, vendor questionnaires. The default and the floor.
Partner onboarding, platform admission, contractual assurance between two parties.
External audit reliance and insurance underwriting. Normative: the assessor MUST be independent of the organization and of any vendor in the assessed scope. A party that supplies the controls cannot furnish an independent assessment of them — attestations generated by an implementation are first-party evidence regardless of format.
The first comment window closes 31 October 2026. Cite the clause number. Every substantive comment will be logged, dispositioned — accepted, accepted-with-modification, or declined, each with a reason — and published alongside Draft 0.3.