Policy-Governed RAG - Research Design Study
Jean-Marie Le Ray

TL;DR
This paper proposes a policy-governed RAG architecture designed for audit-ready, compliant generation in regulated industries, integrating cryptographic evidence and policy checks to ensure verifiability and auditability.
Contribution
It introduces a novel triptych architecture combining control, evidence, and verification modules for regulated, audit-ready AI outputs.
Findings
Cryptographically anchored source evidence ensures verifiable provenance.
Policy gates improve auditability and compliance in regulated workflows.
Design targets error reduction, latency, and cost metrics for practical deployment.
Abstract
A policy-governed RAG architecture is specified for audit-ready generation in regulated workflows, organized as a triptych: (I) Contracts/Control (SHRDLU-like), which governs output adherence to legal and internal policies; (II) Manifests/Trails (Memex-like), which cryptographically anchors all cited source evidence to ensure verifiable provenance; and (III) Receipts/Verification (Xanadu-like), which provides the final, portable proof of compliance for auditors (portable COSE/JOSE) (see Section 4 and Appendix A). Rather than explaining model internals, outputs are gated ex-ante and bound to cryptographically verifiable evidence for each material answer. Unvalidated targets are stated (>=20% relative reduction in confident errors; p95 latency <= 900 ms; <= 2.2x serve cost) together with a pre-registered (optional) pilot using NO-GO gates. The design complements existing RAG/guardrails by…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsScientific Computing and Data Management · Explainable Artificial Intelligence (XAI) · Blockchain Technology Applications and Security
