A building block

A little help. A clear record.

dyna.ai - Compliance and Legal guide

Build a bot. Agree its boundaries. Follow the evidence.

Your organisation. Your operating rules. Build lending and servicing workflows with reviewed policies, controlled access and a record of the decisions behind the work.

Compliance and Legal guide

From source to enforced policy

Open Regulations & policies. Retain the official source snapshot, provision, enterprise interpretation and control mapping together. Record the jurisdiction, effective dates and scope. Review changes before adopting them into an active policy.

The Cedar editor holds executable source, schema and evaluation cases. Include both allowed and denied cases. Test missing evidence, conflicting locations, withdrawn permission, stale policy versions and changed identity. A passing test evaluates the supplied facts. It does not establish that every production fact is complete or correct.

An author submits the draft. A separate reviewer approves it. An authorised publisher activates the reviewed version. Campaigns retain the versions they use and check current restrictions before dispatch. Restore an earlier policy through a new reviewed draft so the history remains intact.

Share a regulation for review

Open Regulations & policies, select a policy and choose Share PDF. The download brings the retained source, interpretation, policy status and available Cedar code into one brief for colleagues. Review its contents before forwarding it to counsel, compliance or leadership.

The brief reflects the selected version at export time. Check its source dates, review status and any missing executable mapping. If the records do not separately identify a legal baseline and an enterprise restriction, the brief states that limitation. Sharing does not approve or activate a policy.

Links back to the workspace require the recipient's own account and permission. The downloaded file can be forwarded outside the workspace, so use your organisation's approved sharing channel. Customer records, call transcripts and credentials are excluded from the regulatory brief.

Communication and disclosure

Call admission and disclosure are separate decisions. Permission to place a call does not prove who answered or authorise disclosure of protected details. A model's classification, caller ID or possession of a phone is not verified customer identity.

For debt collection, the federal communication rule defines permitted recipients, restrictions and exceptions. An enterprise interpretation must account for the applicable definition of consumer and the relevant jurisdiction. Do not reduce the rule to one guessed recipient type. See 12 CFR 1006.6.

Use current-call, subject-bound verification from an approved source before protected retrieval or disclosure. If identity is unavailable or changes, stop protected discussion and use the approved neutral response or handoff. Save the decision and supporting evidence. Do not disclose the debt while explaining the identity failure.

For insurance workflows, distinguish intake, a request for assistance, qualification, underwriting and a coverage decision. A saved intake record does not establish coverage, bind a policy or confirm a claim outcome. Reserve those outcomes for the authorised business system and licensed process where required.

Review a call

Use Results & audit → Call recordings. Listen to the recording and follow the transcript. Generated alignment timestamps are approximate. Compare policy decisions, recorded facts, tool receipts and source outcomes before deciding whether the agent followed the approved process.

Separate a suspected issue from a confirmed finding. Record which evidence supports the finding and which evidence is missing. A completed carrier call or a model-generated summary does not prove compliance or successful business completion.

Evidence and coverage

Download the complete mission or workflow evidence envelope. Verify the digest over its exact canonical payload. Retain omission markers and unresolved states. Internal chain verification detects inconsistencies within the retained package. It is not independent external timestamping.

Read jurisdiction coverage as a statement about the specific sources, interpretations, controls and tests shown. A state with reviewed controls is not a certification that every activity in that state complies with every law.

Read the conversation policy ontology for the exact entities, actions, trusted facts and disclosure gates.