No padding for coverage.
If a deployment does not trigger an assessment in a jurisdiction, none is recommended for that jurisdiction. Silence is more honest than a fabricated obligation.
Claims on this site are architectural decisions you can inspect. This page documents how LegisGate produces regulatory findings, why no language model authors them, and where our role ends and your counsel's begins.
The Meridian is LegisGate's curated regulatory intelligence source — the reference each finding is verified against. It is built and maintained by human curation: statutes, regulations, and supervisory authority guidance are read, mapped into obligations, and validated with effective dates and citation records.
“Verified to the Meridian™” means each citation in a report is resolved against this curated source. It is a machine-enforced validation of sourcing and structure — not a substantive legal review, which remains counsel's role.
The Meridian is read-only from the assessment pipeline. No report run can write to it. Vendor-specific intelligence flows through a separate per-assessment path and is not written into the regulatory source — preventing one customer's assessment from contaminating the regulatory intelligence used by another.
Regulatory findings are assembled deterministically from Meridian-validated templates and rule evaluations. A language model does not author the statute identified, the citation, the obligation description, the severity, or the required actions.
Regulatory citation
12 CFR Part 748 Appendix A
Verified · LegisGate Meridian™
View in Intelligence LibraryPotential penalty exposure
No statutory maximum mapped for this finding in the report penalty model.
If a finding cannot be traced to a validated Meridian record or a deterministic rule, it does not ship.
Assembled findings are checked before a report is delivered. The gate applies quality checks across sequential batches so each report meets the verification bar before it ships.
| Check | What it tests |
|---|---|
| Deduplication | No finding appears twice under different framings |
| Citation accuracy | Each citation resolves to its Meridian record |
| Severity consistency | Ratings are consistent with the obligation's statutory basis |
| Completeness | Required fields are present for each finding |
| Jurisdiction validity | Each finding is valid for the jurisdictions in scope |
| Count reconciliation | Findings, obligations, and assessment determinations reconcile |
Quality metrics from the gate are logged for each report.
Mandatory assessments are determined by evaluating a deployment's facts against statutory threshold criteria for each jurisdiction in scope. A mandated assessment is identified when the statute's thresholds are met, with the statutory basis recorded in the determination.
If a deployment does not trigger an assessment in a jurisdiction, none is recommended for that jurisdiction. Silence is more honest than a fabricated obligation.
LegisGate prepares the regulatory substance of an assessment: which laws apply, which citations anchor each obligation, which risks the statute contemplates, and which thresholds triggered which mandated documents.
Your counsel supplies the organizational substance: measures implemented, data flows, internal controls, personnel and contracts — the facts only your organization knows, and the judgment only counsel can apply.
Sections requiring organizational input are explicitly identified in each prepared document. They are never pre-populated with generative content.
Counsel reviews, completes, and determines sufficiency. LegisGate prepares the file. We do not provide legal advice, certify compliance, or promise an enforcement outcome.
Each report carries a SHA-256 digest computed over its contents at generation. The digest appears on the report cover and allows counsel, auditors, or regulators to confirm the document matches the report as issued.
The Regulatory Review Initiation Record documents when an organization initiated its regulatory review of a deployment. It records the initiation of a review; it is not a certification of compliance or of the sufficiency of subsequent action.
Monitored vendor documents are baselined by cryptographic hash, and detected changes are evaluated against the assessments they affect.
We do not provide legal advice. Counsel determines the sufficiency of any review, assessment, or remediation.
We do not certify compliance, and no output promises an enforcement outcome.
Coverage is curated, not exhaustive. The Meridian is maintained on an ongoing basis; counsel supplements where their judgment requires.
We do not author regulatory findings with a language model, and we do not let assessment runs write to the regulatory source.
We do not contact regulators about any client, and we do not participate in a client's regulatory matter.
A methodology you can inspect is the only kind worth trusting.
See the methodology in the artifact it produces.
See a sample report →