Compliance that lives in a policy document is only as reliable as the person reading it. Compliance that lives in code is applied every time, the same way, and leaves a record. Treating rules as enforceable configuration — testable, versioned and attributable — is the practical difference between a control that exists and one that works.
Rules as configuration
The core idea is to express obligations as data the system applies, rather than text a human remembers. Limits, ceilings and thresholds become parameters attached to a unit. Jurisdiction rules become conditions checked against the operation's route and counterparties.
This is where SUPA's design places policy: limits, approved counterparties and approval thresholds are applied below the model, where an agent cannot argue with them. Encoding rules this way also means an over-limit operation becomes a human approval request rather than a rejection — a queue a person resolves, with the reason recorded.
Versioning and attribution
Encoded rules change. When they do, the record must show which version governed which operation. Every ledger entry is attributed to a principal, an agent and a policy version for exactly this reason: reconstruction depends on knowing the rules in force at the time, not the rules today.
Jurisdiction is not uniform
Cross-border rules differ, and reliance is not permitted everywhere. FATF Recommendation 17 allows a regulated institution to rely on due diligence performed by another, but reliance does not transfer legal responsibility, and local-law limits are checked per jurisdiction. Compliance-as-code makes those differences explicit conditions rather than assumptions.
A practical pattern:
- express each rule as testable configuration
- version it and attribute operations to the version in force
- make jurisdiction an explicit condition, not a default
- route over-limit operations to human approval with a recorded reason
In short
- Encode rules as configuration, not prose.
- Version rules and attribute every operation to the version applied.
- Treat jurisdiction as an explicit condition per operation.
- Turn ceilings into approval queues, not silent failures.
This is general information, not legal, tax or financial advice. See how legitimacy validation works: protocol.