Compliance that lives in a policy document is only as reliable as the person reading it. Compliance that lives in code is applied every time, the same way, and leaves a record. Treating rules as enforceable configuration — testable, versioned and attributable — is the practical difference between a control that exists and one that works.

Rules as configuration

The core idea is to express obligations as data the system applies, rather than text a human remembers. Limits, ceilings and thresholds become parameters attached to a unit. Jurisdiction rules become conditions checked against the operation's route and counterparties.

This is where SUPA's design places policy: limits, approved counterparties and approval thresholds are applied below the model, where an agent cannot argue with them. Encoding rules this way also means an over-limit operation becomes a human approval request rather than a rejection — a queue a person resolves, with the reason recorded.

Versioning and attribution

Encoded rules change. When they do, the record must show which version governed which operation. Every ledger entry is attributed to a principal, an agent and a policy version for exactly this reason: reconstruction depends on knowing the rules in force at the time, not the rules today.

Jurisdiction is not uniform

Cross-border rules differ, and reliance is not permitted everywhere. FATF Recommendation 17 allows a regulated institution to rely on due diligence performed by another, but reliance does not transfer legal responsibility, and local-law limits are checked per jurisdiction. Compliance-as-code makes those differences explicit conditions rather than assumptions.

A practical pattern:

  • express each rule as testable configuration
  • version it and attribute operations to the version in force
  • make jurisdiction an explicit condition, not a default
  • route over-limit operations to human approval with a recorded reason

In short

  • Encode rules as configuration, not prose.
  • Version rules and attribute every operation to the version applied.
  • Treat jurisdiction as an explicit condition per operation.
  • Turn ceilings into approval queues, not silent failures.

This is general information, not legal, tax or financial advice. See how legitimacy validation works: protocol.