Regulatory Evidence

The Examiner Is Asking. Do You Have the Evidence?

A compliance output that cannot be verified is not evidence. It is an assertion. Regulators do not accept assertions.

Verbatim
Source Text Preserved
Zero
Paraphrased Obligations
Always
Evidence Retrievable

Describes the ProfytAI evidence architecture for in-product obligations and workflows. Your institution remains responsible for legal interpretation, scope, and supervisory engagement.

The Real Question

Can a General-Purpose AI Tool Produce Regulatory Evidence?

Banks ask whether tools like Copilot, ChatGPT, Claude, or Gemini can replace a purpose-built compliance evidence system. This is not a question of capability. It is a question of architecture.

How it reads regulations

General-purpose AI

Searches your documents and finds fragments that seem related to your question.

ProfytAI Evidence System

Ingests the full regulatory document. Preserves every obligation word-for-word. Assigns a unique ID to each.

What it produces

General-purpose AI

Writes a new answer in its own words every time you ask. The answer is different each time.

ProfytAI Evidence System

Returns the exact regulatory text, the same way, every time. The output is a stored record, not generated text.

What happens after

General-purpose AI

The answer appears in a chat window. When the session ends, nothing is stored. No audit trail exists.

ProfytAI Evidence System

Every output is stored, versioned, and linked to its source. The bank maps controls and attaches evidence. Users are assigned tasks. Audit readiness is tracked.

Under examination

General-purpose AI

The examiner asks you to reproduce the output. You cannot. The examiner asks for the source text. It was paraphrased. The examiner asks for the audit record. It does not exist.

ProfytAI Evidence System

The examiner requests any obligation by ID. The system returns the verbatim text, the mapped controls, the attached evidence, and the complete version history.

These are not two versions of the same tool. General-Purpose AI is a search and summarisation assistant. ProfytAI is a compliance evidence system. They solve fundamentally different problems.

The Examination Test

Three Questions Every Regulator Asks. General AI Fails All Three.

Standard examination questions. Any compliance tool that cannot answer them is a liability, not an asset.

01

Show me the exact regulatory text your control satisfies.

Every examiner asks this first. The answer must be verbatim. Paraphrasing is not acceptable.

Cannot comply

Paraphrases source text. The regulator's exact words are not preserved.

Verbatim source text

Stored word-for-word at ingestion. Retrievable on demand.

02

Reproduce this compliance output exactly as it was generated.

Reproducibility is a core examination requirement. If the output changes on re-run,it is not evidence.

Cannot comply

Probabilistic by design. Every run produces a different output.

Deterministic output

Same obligation ID returns identical output every time. Guaranteed.

03

Provide the audit record and evidence chain for this finding.

Without a stored record, there is no audit trail. Without an audit trail, there is no compliance.

Cannot comply

Session-based. When the session ends, nothing is stored. No record exists.

Versioned artifact

Every output is stored, versioned, and retrievable. Always.

0/3General AI
3/3ProfytAI

General AI was designed to answer questions. ProfytAI was designed to produce evidence that withstands examination.These are not the same system.

The Architectural Gap

Two Pipelines. Only One Produces Evidence.

The same compliance question enters two different systems. The divergence begins at step one and is irreversible. Follow each pipeline to see where they end.

General-Purpose AI Pipeline

You ask a question

Natural language input

Partial context

Finds document pieces

Fragments that seem related

Non-deterministic

AI writes a new answer

Different every time

Paraphrased

Text appears in chat

In the AI's own words

No artifact

Session ends

Nothing stored or versioned

vs

ProfytAI Evidence System Pipeline

Regulation ingested

Full document, verbatim

Validated

Obligations extracted

By modality and each with a unique ID

Bank input

Controls mapped

Added by the bank's team

Assigned

Evidence attached

Tasks assigned to users

Audit-ready

Artifact stored

Versioned, reproducible record

General-Purpose AI

Session ends with generated text. Nothing is stored. The output cannot be reproduced, traced, or submitted as evidence.

ProfytAI Evidence System

Every run ends with a stored compliance artifact: verbatim source text, obligation ID, mapped controls, attached evidence, and a complete version history.

The divergence begins at step one. A language model ends with generated text.No schema, no citation enforcement, no stored record. ProfytAI ends with a persisted, verifiable artifact.

Why General AI Fails Under Examination

One Examination. Three Architectural Failures.

These are properties of how language models work. No model, no prompt, and no configuration removes them.

Failure 01

Non-Determinism

Same query. Different output. Every time.

Same Query

Run 1

Institutions are expected to maintain a classification framework.

Run 2

Institutions should implement a data categorization process.

Outputs Diverged: No Canonical Record

Under Examination

When the examiner asks you to reproduce your evidence, the output will differ. A record that cannot be reproduced on request is not a record.

Can this be fixed by configuring the AI differently?

No. Language models sample from probability distributions. Even at temperature zero, outputs vary across sessions and model versions. There is no mechanism that guarantees identical output.

Failure 02

Paraphrasing

The regulator's words, rephrased by a model.

MAS TRM § 7.7.4 · Verbatim Governing Text

“The FI should configure system events or alerts to provide an early indication of issues that may affect its IT systems’ performance and security.”

AI synthesis

AI Output

“Financial institutions are expected to configure appropriate monitoring mechanisms to ensure early detection of system issues.

Obligation Reworded: Legal Precision Lost

Under Examination

The examiner asks for the exact words of the obligation your control satisfies. The AI output does not contain them. A paraphrase of a statute is not that statute.

Can this be fixed by configuring the AI differently?

No. Language models generate text. Generation means producing new words. The original regulatory text is lost in the process, even with retrieval-augmented generation.

Failure 03

Inferred Citation

A reference with nowhere to go.

“Refer to MAS TRM, Part IV (data management section) for the applicable requirements.”

~

Citation

Extracted

Source Text

Retrieved

Verbatim

Confirmed

Record

Stored

Evidence Chain: Broken at Retrieval

Under Examination

You cite the obligation. The examiner asks for the source text your system retrieved. You cannot produce it. The citation was generated, not retrieved.

Can this be fixed by configuring the AI differently?

No. The AI infers what the citation should be based on patterns in its training data. It does not retrieve a verified source record. The reference is a prediction, not a retrieval.

Changing models does not resolve these failures. Every large language model is non-deterministic, produces paraphrase, and cannot retrieve a verified citation because these are properties of the architecture, not limitations of any specific model. No amount of prompting, fine-tuning, or configuration changes this. An evidence system requires a different architecture entirely.

The ProfytAI Standard

Examination-Grade Compliance. Built for Scrutiny.

Verbatim

Source text preserved

Every obligation stored exactly as written in the regulation. No paraphrasing. No summarization. The regulator's exact words, retrievable on demand.

Reproducible

Same output every time

Any compliance artifact can be reproduced identically at any point in time. The output is the same output that was produced at ingestion.

Traceable

Every citation verified

Every obligation links directly to its source clause. Every control maps to the obligation it satisfies. Every evidence item is attached and retrievable.

The Four Guarantees

Every obligation is traceable to its exact source clause

Every output is reproducible on demand

Every artifact is stored, versioned, and retrievable

Every citation is independently verifiable

These properties apply to content and workflows delivered through the ProfytAI platform for covered regulatory material. They do not replace your policies, sign-offs, or external legal advice.

“A language model produces answers. An evidence system produces proof. The difference is not quality. It is architecture.”

ProfytAI is not a compliance assistant. It is a compliance evidence system - the layer between your institution and your regulator that makes examination a process of retrieval, not reconstruction.

Request a Demonstration

See the Evidence for Yourself.

We will walk through a live compliance artifact: obligation ID, verbatim source text, evidence chain, and audit record.