Introduction
Institutional fundraising creates an information-control problem before it creates a writing problem. A manager must answer recurring questions about the firm, strategy, team, track record, governance, valuation, operations, compliance, cybersecurity, responsible investment and fund terms. The same facts appear in due-diligence questionnaires, investor portals, data-room documents, consultant databases, follow-up emails and investment-committee materials. Each answer can change as the fund, team, policy or reporting period changes. A fluent draft has limited value when its source, effective date, approval and permitted use cannot be established.
This paper develops a controlled architecture for using Claude Projects or the Anthropic API with retrieval over a fund manager's approved documents. The primary audience is B2 private equity, venture capital, real-estate, private-credit and other alternative-investment fund managers. The secondary audience is A1 limited partners, family offices, institutions, consultants and gatekeepers evaluating those managers. The operating objective is a faster, more consistent readiness process with evidence-linked answers, human approval, permission-aware disclosure and a complete audit trail.
The central unit is an approved claim. Each claim records a question, an answer, supporting evidence, source location, effective date, owner, reviewer, permitted audience, confidentiality class and expiry or refresh trigger. Retrieval-augmented generation can find relevant evidence and propose a draft. It cannot determine that a representation is current, complete, legally sufficient or suitable for a particular investor. Those decisions remain with authorised people.
The ILPA Due Diligence Questionnaire 2.0 organises private-markets diligence across twenty topic areas and includes a requested-document appendix [1]. AIMA publishes modular due-diligence questionnaires for investment managers, service providers and strategies [3]. The PRI offers responsible-investment questionnaires that begin a structured dialogue and remain complementary to broader diligence [5]. These standards reduce unnecessary variation and supply useful taxonomies. They do not create one universal answer set. Investor mandates, jurisdictions, strategy, fund structure and operational history still determine the final scope.
Anthropic describes Projects as self-contained workspaces with their own chat history and knowledge base [7]. Project knowledge can be shared across chats, and retrieval-augmented generation is automatically used as knowledge approaches the context limit [8,9]. The Anthropic API supports citations tied to source documents, including page, character or content-block locations for supported document formats [10]. These product capabilities can support evidence-linked drafting. Production use still requires a controlled document population, metadata, permission enforcement, evaluation, approval and monitoring.
The tracker specifies a hands-on build around a 150-question DDQ and a readiness-time ambition from months to weeks. In this paper, 150 is an unverified illustrative catalogue size rather than an industry standard. The time outcome is an unverified hypothesis. The before-and-after model sets out how a manager could test elapsed time, paid effort, answer acceptance, citation support, reviewer burden and exception rates. Attributed Matchpoint or client revenue, cash cost reduction, loss reduction and alpha remain USD 0 until approved observed evidence exists.
| Research question | Operating answer developed in this paper |
|---|---|
| What should Claude retrieve? | Approved source documents and structured claims with explicit owner, version, audience and effective date. |
| How should a DDQ be automated? | Through intake, classification, retrieval, cited drafting, materiality checks, human review, release and feedback. |
| How should the data room be maintained? | Through a versioned index, document requirements, permission classes, freshness rules, redaction and disclosure logs. |
| What can remain in Claude Projects? | A bounded collaborative workspace for approved knowledge and human-led drafting where access and governance fit the use. |
| When is an API architecture preferable? | When the manager needs system integration, field-level controls, custom retrieval, evaluation, audit or workflow automation. |
| What proves value? | Observed readiness outcomes and approved economics under a defined baseline and counterfactual. |
The paper reviews thirty primary and authoritative sources available through 1 August 2026. It provides a diligence taxonomy, source-of-truth model, Claude and retrieval architecture, 150-question workflow, data-room operating model, prompt patterns, evaluation framework, security and regulatory controls, two unverified illustrative scenarios and a ninety-day implementation roadmap.
The B2 And A1 Decision Perimeter
B2 fund-manager objectives
A fund manager needs a repeatable diligence response process that preserves accuracy while the organisation changes. The firm may be fundraising, deploying capital, exiting investments and reporting to existing investors at the same time. Senior investment, operating, finance, legal, compliance and investor-relations staff can become serial reviewers of the same facts. Readiness work competes with investment work.
The manager's operating objectives are specific:
- create one governed population of reusable answers and evidence;
- reduce repeated search, rekeying and reconciliation;
- identify questions that require a new management decision;
- distinguish public, prospective-investor, NDA, advanced-diligence and restricted material;
- preserve source, reviewer and release evidence for every material representation;
- keep the data-room index aligned with the current DDQ and investor requests;
- measure cycle time, quality, exception burden and approved financial value.
The manager also needs a clear boundary. Performance, attribution, valuations, legal terms, regulatory status, conflicts, side-letter capacity, personal data and security representations carry material consequences. Claude may retrieve and draft within an approved workflow. Authorised owners approve the released answer and any supporting document.
A1 limited-partner objectives
An allocator needs information that is current, comparable and supported. A polished response can accelerate review, yet polish alone does not establish investment quality or operational resilience. The LP needs a clear view of strategy, team, decision-making, realised and unrealised performance, attribution, governance, risk, operations, service providers, compliance and reporting.
An evidence-linked response improves the inspection path. The reviewer can move from a sentence to the governing policy, audited record, fund document, committee minute or approved analysis. The system should preserve unanswered questions and conflicts. It should not create the appearance of certainty where the evidence is incomplete.
Decision rights
| Decision | Drafting support | Required human authority |
|---|---|---|
| classify a question | taxonomy and similarity match | DDQ coordinator confirms scope |
| retrieve evidence | permission-aware search | source owner confirms authoritative population |
| draft a response | cited synthesis from approved evidence | answer owner approves substance |
| state performance | extract from approved performance source | finance, compliance and authorised investment owner |
| state track-record attribution | assemble approved deal evidence | named deal professionals, finance, compliance and management |
| disclose terms or side-letter position | retrieve current legal source | legal or authorised counsel and management |
| disclose a security control | retrieve current policy and assurance evidence | security owner and compliance |
| release a document | prepare package and record metadata | data-room owner under disclosure policy |
| make an investment recommendation | no delegated authority in this design | allocator's authorised investment process |
The system register should identify each material field and its owner. A response can have several owners. Finance may own the number, compliance may own the permitted presentation, and investor relations may own the final release. The approval record should preserve those distinct roles.
Diligence Is A Controlled Information System
The standards create a stable core
ILPA DDQ 2.0 covers the firm, fund, succession and key persons, strategy, co-investments, GP-led secondaries, credit facilities, investment process, team, alignment, market, terms, governance, risk and compliance, track record, accounting and valuation, reporting, legal, data security and technology, responsible investment and diversity [1,2]. The requested-document appendix makes the questionnaire and data room interdependent.
AIMA's current DDQ library provides modular questionnaires for investment managers, funds, strategies, digital assets, private markets, private credit and service providers [3,4]. The modular design supports an intake router: common manager questions can be answered once, while strategy and structure modules can be added for the mandate.
The PRI venture-capital LP questionnaire covers responsible-investment governance, fundraising, pre-investment, post-investment and reporting [5]. The ILPA Diversity Metrics Template provides a structured monitoring mechanism for diversity information [6]. These resources illustrate an important design rule: a diligence answer bank should store reusable facts and evidence, while the released response remains tailored to the requested framework and audience.
A practical 150-question catalogue
The following distribution is an unverified illustrative management assumption. It creates a build and evaluation population; it is not an ILPA, AIMA or PRI prescribed count.
| Catalogue domain | Illustrative questions | Typical evidence owner |
|---|---|---|
| firm, ownership and history | 8 | management, legal |
| fund structure, terms and service providers | 12 | legal, finance |
| strategy, market and portfolio construction | 14 | investment committee |
| sourcing, underwriting and investment process | 12 | investment team |
| team, succession and key persons | 10 | management, human resources |
| track record, attribution and case studies | 18 | investment team, finance, compliance |
| valuation, accounting and audit | 10 | finance, valuation committee |
| governance, conflicts and compliance | 12 | compliance, legal |
| risk management and leverage | 8 | risk, finance |
| operations, business continuity and service providers | 10 | operations |
| cybersecurity, privacy and technology | 10 | security, data owner |
| responsible investment, climate and diversity | 10 | responsible-investment owner, management |
| reporting, transparency and LP communications | 8 | investor relations, finance |
| co-investment, continuation and liquidity processes | 8 | investment team, legal |
| Total | 150 | multiple accountable owners |
The catalogue should not become a fixed script imposed on every investor. Its purpose is coverage, reuse and evaluation. New questions enter the catalogue with an owner and taxonomy. Obsolete questions remain archived with their history.
Four classes of answer
| Answer class | Description | Release rule |
|---|---|---|
| controlled fact | stable fact drawn directly from an approved system or document | verify freshness and cite source |
| calculated answer | result produced from approved data and deterministic method | preserve inputs, method, reviewer and period |
| management judgement | explanation of strategy, governance or decision practice | named owner approves current wording |
| restricted response | legal, personal, security, side-letter or other sensitive material | explicit audience, approval and disclosure log |
The model can assist all four classes. The control intensity rises with consequence. A stable office address can be pre-populated. A performance claim needs a controlled calculation and review. A strategy explanation needs current management ownership. A restricted answer needs permission and release evidence.
Source Of Truth And Document Taxonomy
Separate documents, claims and releases
The source layer should distinguish three objects. A document is an approved file or system extract. A claim is a reusable statement linked to one or more evidence locations. A release is the exact answer and attachment package sent to a named recipient at a particular time.
| Object | Minimum metadata |
|---|---|
| document | ID, title, type, owner, version, effective date, status, confidentiality, jurisdiction, permissions, retention, checksum |
| claim | question domain, approved wording, evidence links, period, owner, reviewer, audience, expiry, conflict status |
| release | recipient, mandate, question, answer version, citations, attachments, approvals, date, channel, restrictions |
This separation solves a common maintenance problem. Updating a policy document can trigger review of every dependent claim. A new claim can be approved without rewriting the source document. An old release remains reproducible even after the claim changes.
Document classes
The fund-document corpus can be organised into the following controlled classes:
- organisation and ownership;
- private-placement memorandum, limited-partnership agreement and subscription materials;
- track-record workbook and approved performance exhibits;
- investment, valuation, conflicts, allocation and responsible-investment policies;
- compliance manuals, regulatory filings and registers;
- audited financial statements and administrator reports;
- investment-committee, valuation-committee and advisory-committee records;
- service-provider agreements, due diligence and assurance reports;
- cybersecurity, privacy, business-continuity and incident evidence;
- portfolio monitoring, ESG, diversity and impact reports;
- organisation charts, biographies, role descriptions and succession evidence;
- prior DDQs, consultant databases and approved investor communications.
Prior DDQs are useful precedents. They should not become the source of truth where the underlying fact has a better authority. The answer bank should link the precedent to the governing document or record.
Effective dates and conflicts
Every source needs an effective date and status. The retrieval layer should prefer current approved sources and identify superseded material. When two current documents conflict, the system should abstain, show both and route the issue to the owners. A model-generated reconciliation can support the discussion; authorised owners decide the correction.
The ingestion process should calculate a checksum for each file, preserve the original, extract text without altering it and record every derivative. Scanned documents need optical character recognition and a quality check. Anthropic's citations documentation notes that scanned PDFs without extractable text cannot support normal PDF citations [10]. That limitation should be detected during ingestion rather than during a live investor request.
Claude Projects Or An Api Architecture
Claude Projects as a controlled drafting workspace
Anthropic describes a Project as a self-contained workspace with its own chat history and knowledge base [7]. Project instructions can establish the role, permitted sources, citation requirement, answer format and escalation rules. Files added to project knowledge can be used across chats [8]. Retrieval is automatically applied as the knowledge base approaches the context window [9].
A Project can fit a bounded readiness sprint where a named team works from an approved document population and retains human control of every release. A practical pattern is one project per fund or strategy, with separate projects where permission boundaries require them. Project instructions should state that the assistant drafts from project knowledge, cites the evidence, flags conflicts and missing information, and abstains from unsupported claims.
The Project operating procedure should record:
- approved users and roles;
- document owner and ingestion approval;
- project instructions and change history;
- source refresh schedule;
- permitted confidentiality classes;
- question and answer export process;
- reviewer and approval workflow outside the chat where necessary;
- incident, access-removal and retirement procedures.
Projects can reduce setup effort. The manager should still test permission behaviour, retention, export, audit and integration requirements against the selected Anthropic plan and current contract. Anthropic's enterprise materials describe controls including single sign-on, role-based access, audit logs, identity provisioning and custom retention [11]. Availability and configuration should be verified for the actual account before reliance.
API architecture for system integration and field controls
An API architecture becomes relevant when the manager needs a structured answer bank, integration with a data-room index or CRM, field-level permissioning, custom retrieval, deterministic validation, batch processing, evaluation, workflow approvals or release logs. The API should be one component inside the system. It should not receive an unrestricted file share by default.
The reference architecture has eight layers:
| Layer | Function | Minimum control |
|---|---|---|
| source systems | approved documents, records and data extracts | owner, version, status and permissions |
| ingestion | parsing, OCR, checksum, classification and malware screening | immutable original and processing log |
| index | chunks, embeddings, metadata and access labels | tenant, fund, audience and field filters |
| retrieval | query expansion, hybrid search and reranking | permission before retrieval, freshness and conflict rules |
| generation | Claude request with question, evidence and output schema | bounded context, citations and configuration record |
| validation | citation, number, name, date and policy checks | deterministic rules and abstention |
| workflow | owner review, compliance approval and release | segregation, sign-off, rollback and audit |
| monitoring | quality, exceptions, access, cost, latency and incidents | thresholds, alerts and periodic review |
Anthropic's citations capability can attach supported citations to document content included in an API request [10]. The manager should verify citation coverage for the chosen formats. Citation presence does not prove that a claim is complete or appropriate. The evaluator should test whether each material statement is supported by the cited span.
Architecture decision record
| Criterion | Project-led pattern | API-led pattern |
|---|---|---|
| initial setup | lower | higher |
| workflow integration | manual or limited | custom and system-connected |
| structured answer bank | external register advisable | native data object possible |
| custom permission filters | plan and workspace dependent | explicit application enforcement |
| evaluation automation | sample-led | batch and release-gated |
| audit evidence | plan and operating process dependent | application and provider logs combined |
| best fit | bounded readiness sprint and expert drafting | repeatable institutional process at scale |
The selection should follow requirements, current product capability, contract, data classification and operating capacity. A hybrid design is possible: the API maintains the governed claims and evaluation workflow, while authorised staff use Projects for controlled narrative development.
Retrieval, Chunking And Citations
Retrieve by authority before similarity
Semantic similarity can find relevant text, but authority determines whether it may support an answer. Retrieval should filter by fund, entity, document status, confidentiality, audience, effective period and user permission before ranking content. A current signed fund document should outrank an old marketing presentation for a legal term. The approved track-record source should outrank a prior narrative.
The retrieval record should preserve the query, filters, returned chunks, ranks, source versions and time. That record allows reviewers to understand why the assistant saw particular evidence.
Chunk along the document's decision structure
Chunking should preserve headings, clauses, table rows, dates and page references. Fixed-length chunks can separate a qualification from the statement it controls. Fund terms, policies and performance tables benefit from structure-aware parsing.
| Source type | Recommended retrieval unit | Required metadata |
|---|---|---|
| policy | section or control statement | owner, version, effective date, policy status |
| fund agreement | clause and defined terms | fund, agreement version, clause, legal status |
| performance table | row, column headers and calculation note | fund, currency, period, gross/net basis, approval |
| biography | role and dated experience statement | person, role, as-of date, consent class |
| committee record | approved decision extract | committee, date, agenda, confidentiality |
| cybersecurity evidence | control statement or assurance finding | owner, scope, test date, disclosure class |
| prior DDQ | question-answer pair and release date | recipient class, answer owner, superseded status |
Tables need special handling. The chunk should retain column headers, units, footnotes and period. A number detached from its definition can produce a materially misleading answer.
Citation quality tests
A citation evaluator should ask four questions:
- does the citation exist and resolve to the exact source version;
- does the cited span entail the material statement;
- does the evidence cover every material number, date, name and control claim;
- is the cited source permitted for the intended recipient.
The assistant should use precise citations for material statements and can group several adjacent low-consequence facts where the source clearly supports them. Unsupported material claims should trigger abstention or a request for owner input. A citation to an irrelevant but authoritative document is a failure.
Retrieval failure classes
| Failure | Example | Response |
|---|---|---|
| no evidence | new investor question has no approved source | create evidence request; do not invent |
| stale evidence | biography predates team change | block release and refresh owner |
| conflict | policy and prior DDQ describe different process | surface both and route resolution |
| access mismatch | restricted cybersecurity report retrieved for broad response | remove context, record event and review control |
| weak entailment | citation mentions valuation but not stated frequency | reject answer and refine retrieval |
| table loss | performance number detached from period or basis | reparse structured table and validate |
The 150-Question Ddq Workflow
Intake and normalisation
The incoming DDQ should be stored in its original form. A parser extracts question ID, section, question text, subparts, requested format, character limit, attachments and deadline. The system assigns a stable internal question ID while preserving the investor's numbering.
Normalisation maps each question to the catalogue and identifies repeated or near-duplicate questions. The match produces a candidate; the coordinator confirms it. A single investor question may combine several catalogue claims and require several owners.
Retrieval and cited drafting
For each confirmed question, the system retrieves approved claims and source evidence under the recipient's permission class. The generation request contains the exact question, output constraint, current approved claims, evidence spans, prohibited statements and required citation format. The response schema should separate answer, citations, missing evidence, conflicts, assumptions and suggested attachments.
The model should state when the evidence does not answer the question. It should never turn a missing control into a positive representation. A proposed future action should be labelled as planned and approved before release.
Deterministic validation
Before human review, deterministic checks can identify:
- unsupported numbers, dates and percentages;
- names or roles inconsistent with the current organisation register;
- performance statements without approved basis and period;
- terms inconsistent with the current fund documents;
- missing citations or unresolved source IDs;
- restricted words, claims or attachments;
- expired evidence;
- broken cross-references and unanswered subparts;
- inconsistent currency, units or date format;
- answer length and requested-format failures.
These checks improve review efficiency. They do not replace substantive approval.
Human review and release
Questions route to owners according to domain and consequence. The reviewer sees the question, draft, citations, source spans, conflicts, prior approved answer and changes. The approval event records the reviewer, time, answer version and any edits. Compliance or legal review is added where the release policy requires it.
The final package is generated only from approved answer versions. The release record contains the recipient, fund, DDQ version, approved answers, attachments and disclosure classification. If the manager later corrects a material answer, the system can identify affected releases.
Feedback and maintenance
Reviewer edits should be classified. A factual correction triggers source and claim review. A style change can update the answer pattern. A permission correction tests the disclosure policy. A new management judgement becomes a proposed claim with an owner and expiry. Raw reviewer edits should not silently train or update the approved answer bank.
| Workflow stage | Primary measure | Release gate |
|---|---|---|
| intake | extraction completeness | all questions and subparts captured |
| catalogue match | confirmed match rate | coordinator confirmation |
| retrieval | relevant permitted evidence | source coverage and freshness |
| draft | supported answer completeness | citation and deterministic validation |
| review | first-pass acceptance and material edit rate | named owner approval |
| package | completeness and format | release checklist |
| feedback | classified correction rate | governed claim update |
Data-Room Operating Model
The index is the control plane
The data-room index should be a governed register rather than a manually maintained contents page. Each requirement links to the current approved document, owner, disclosure class, effective date, refresh trigger and status. The index can map ILPA, AIMA, PRI and investor-specific requirements to the same document.
| Index field | Purpose |
|---|---|
| requirement ID | stable cross-framework reference |
| topic | DDQ and diligence taxonomy |
| document ID and version | exact approved evidence |
| owner and approver | accountability |
| confidentiality class | disclosure perimeter |
| effective and review dates | freshness |
| permitted recipients | access rule |
| redaction state | full, redacted, extract or unavailable |
| release history | who received which version |
| dependent claims | impact of document change |
Disclosure tiers
A practical structure can use five tiers:
- public or introductory material;
- prospective-investor material after qualification;
- NDA diligence material;
- advanced-diligence material with named approval;
- restricted material available only through a controlled response or inspection.
The exact tiers are management and legal decisions. Personal data, portfolio-company confidential information, security detail, side-letter terms and privileged material need specific review. The retrieval system should enforce the same classification as the data room.
Redaction and document derivatives
Redaction should create a derivative linked to the original. The record includes the redaction reason, scope, reviewer, tool, date and checksum. Visual black boxes alone can leave hidden text or metadata. The release procedure should verify the produced file and remove inappropriate comments, tracked changes, hidden sheets, formulas, document properties and embedded objects.
Continuous readiness
Readiness should be event-driven. A team change triggers biographies, organisation charts, succession answers and key-person analysis. A quarter-end triggers performance, portfolio and exposure records. A new policy triggers dependent claims. An incident triggers controlled updates and disclosure review. A fund-document amendment triggers terms and legal answers.
The dashboard should show missing requirements, expiring evidence, unresolved conflicts, unapproved claims and investor requests. A complete-looking data room with stale documents should fail the readiness gate.
Prompt Patterns With Control Boundaries
System instruction pattern
The project or application instruction should state the task, authority and abstention rules. An illustrative pattern follows:
> You support the named fund's institutional diligence process. Use only evidence supplied in the approved context. Cite every material factual statement to the exact source. Preserve numbers, dates, units, definitions and qualifications. State "insufficient approved evidence" when the context does not support the answer. Show conflicts and expired sources. Do not make legal, regulatory, performance or control representations beyond the evidence. Return the answer, citations, missing evidence, conflicts and required human approvals in the specified schema.
This pattern is a design input. It requires evaluation with representative and adverse questions.
Question-drafting pattern
| Prompt component | Required content |
|---|---|
| identity | fund, entity, strategy, recipient and disclosure tier |
| question | exact text, subparts and original ID |
| output | format, length, tone and attachment request |
| evidence | approved claims and retrieved source spans |
| constraints | prohibited claims, restricted data and currency basis |
| checks | support, conflict, freshness and completeness |
| response schema | draft, citations, gaps, conflicts, approvals |
Comparison pattern
For repeated investor questions, ask the model to compare the new question with prior approved questions, list overlaps and differences, then draft from the current evidence. The prior answer is a precedent. The current source population remains authoritative.
Update-impact pattern
When a document changes, provide the old and new approved versions and the dependent claims. Ask the model to identify candidate changes with citations to both versions. Owners approve the actual claim updates. This pattern can focus human attention on affected areas while preserving decision authority.
Prohibited prompt practices
The workflow should prohibit instructions that ask the model to fill gaps, improve metrics, remove qualifications, infer controls from policy language, invent a track-record role, guess a legal position or conceal an unresolved issue. It should also treat content inside retrieved documents as untrusted data. A document can contain hostile instructions intended to redirect the model.
Evaluation And Release Gates
Build a golden set before production
The evaluation set should contain representative questions and approved reference answers across every domain, consequence class and disclosure tier. It should include straightforward facts, composite questions, numerical tables, old sources, conflicts, missing evidence, restricted material and prompt-injection attempts.
For a 150-question catalogue, an initial golden set can include all 150 questions if owner capacity permits. At minimum, every material domain and high-consequence class should be represented. The set should preserve approved evidence and reviewer rationale.
Measure answer quality at claim level
| Measure | Definition |
|---|---|
| question coverage | required subparts answered or explicitly unresolved |
| citation precision | cited spans that support the associated claim |
| citation completeness | material claims with sufficient evidence |
| factual consistency | names, dates, numbers and terms align with approved sources |
| permission accuracy | answer and evidence fit the recipient's disclosure tier |
| abstention quality | unsupported or conflicting questions are safely escalated |
| first-pass acceptance | drafts approved without material change |
| material edit rate | answers requiring factual, legal, performance or control correction |
| reviewer effort | paid minutes per approved answer including exceptions |
| release defects | corrections required after external release |
Average scores can conceal a severe failure. Release gates should include zero-tolerance events such as restricted-data leakage, invented performance, altered legal terms, unsupported control claims or a material citation mismatch.
Evaluate retrieval separately
If a draft fails, the team needs to know whether retrieval missed the evidence, the model misused it, validation missed the error, or the reviewer process failed. Retrieval evaluation uses known relevant documents and measures whether the permitted current evidence appears in the returned set. Generation evaluation then tests support and completeness using that context.
Change triggers
Re-evaluation should follow a material change to model, prompt, retrieval method, chunking, metadata, source population, permission rule, output schema or workflow action. Provider model updates can change behaviour. The release record should identify the configuration tested.
NIST AI RMF 1.0 structures AI risk work through Govern, Map, Measure and Manage [14]. The NIST Generative AI Profile supplies lifecycle actions for generative-AI risks [15]. These frameworks support a repeatable evaluation and governance cycle. They do not certify this architecture or a manager's compliance.
Security, Privacy And Supplier Controls
Data classification comes before ingestion
Fund documents can contain personal data, portfolio-company confidential information, investor identities, security controls, legal advice and commercially sensitive performance. Each source should be classified before upload or indexing. The purpose, user population, provider, processing location, retention and deletion route should be recorded.
Anthropic states that for commercial products the customer generally acts as controller and Anthropic as processor, and that commercial inputs and outputs are not used to train its generative models unless the customer opts into a relevant programme [12]. The actual contract, configuration and current policy should be reviewed for the selected service. Product statements do not determine the manager's lawful basis or disclosure obligations.
Access and identity
Access should use named identities, least privilege and prompt removal when a user changes role. Shared generic accounts undermine release evidence. Project, index, source and workflow permissions should align. High-consequence exports may require step-up approval.
The system should log source access, retrieval, generation, review, export and release. Audit logs need an owner, retention period and review process. Sensitive prompts and outputs should receive the same classification as their sources.
Prompt injection and tool risk
Retrieved documents are untrusted input. A malicious or accidental instruction inside a file can ask the model to ignore policies, reveal other documents or call a tool. The architecture should separate system instructions from document content, constrain available tools, filter retrieval by permission, validate outputs and require human approval for material actions.
The Model Context Protocol defines a standard way for applications to expose resources, prompts and tools [17]. Its security guidance addresses threats including confused-deputy behaviour, token handling, session security and tool safety [18]. A connector to a data room, CRM or document store should expose the smallest required action. Read and write authority should be separate.
Supplier and continuity diligence
The supplier record should cover service description, data use, security assurance, subprocessors, locations, availability, incident notification, retention, deletion, model change, audit evidence, portability and exit. A manual fallback should allow the manager to answer an urgent DDQ when the model or index is unavailable.
NIST Cybersecurity Framework 2.0 provides a risk-management structure across Govern, Identify, Protect, Detect, Respond and Recover [16]. The manager can map the diligence system to this structure and retain evidence of the selected controls.
Regulatory And Representation Boundaries
Marketing and performance representations
The United States SEC investment-adviser marketing rule restricts false or misleading advertisements and sets conditions for performance, testimonials, endorsements and related records [19,20]. Applicability depends on the adviser, communication and jurisdiction. A DDQ response, data-room document or follow-up answer should be reviewed within the manager's compliance framework.
The SEC's 2024 enforcement release concerning two investment advisers describes charges for false and misleading statements about purported AI use [21]. The operational implication extends beyond AI marketing: the manager should preserve a reasonable evidence basis for material representations and ensure the released description matches actual practice.
Claude should not improve a performance statement by removing the gross or net basis, period, currency, vintage, realisation status, benchmark or limitation. Deterministic checks should compare performance output with the approved source and presentation policy.
DIFC and ADGM data protection
DIFC Data Protection Regulation 10 addresses personal-data processing through autonomous and semi-autonomous systems [22,23]. ADGM's Office of Data Protection administers the ADGM data-protection framework [24]. ADGM guidance on automated individual decision-making states that human review should be meaningful, active and performed by a person competent to change the decision [25].
This paper's workflow uses Claude for retrieval and drafting, with authorised people retaining release authority. That design can support human control. It does not establish legal compliance. The relevant entity, data, processing purpose, location, recipient, automation and contractual arrangement need qualified analysis.
The UAE federal personal-data framework sets requirements for electronic processing of personal data [26]. Managers should determine whether the federal law, a financial-free-zone regime, another jurisdiction or several regimes apply.
UK financial-services context
The Bank of England and FCA 2024 survey reports on AI use in UK financial services and associated governance and risk practices [27]. It is a sector survey, not a rule for this system. A UK-regulated manager should assess current FCA rules, principles, outsourcing, operational-resilience, consumer, market and data requirements applicable to its use.
Books, records and reproducibility
A controlled release record supports internal oversight and regulatory recordkeeping. It should preserve the exact question, answer, source version, approval, attachment and recipient. Required retention depends on the entity and communication. Qualified compliance advice should define the authoritative retention schedule.
Before-And-After Measurement
Establish the baseline
The baseline should sample representative DDQs and investor requests from a defined period. It records elapsed days, paid hours by role, number of questions, source searches, review rounds, answer reuse, missing documents, post-release corrections and data-room updates. The team should also record the fund stage, question mix and recipient type.
Define the target state
The target workflow captures each question once, retrieves current permitted evidence, drafts with citations, runs deterministic checks, routes to the correct owner and generates the release from approved answers. Data-room requirements and dependent claims update from the same register.
Unverified illustrative benchmark
The values below are unverified illustrative management assumptions. They demonstrate measurement structure and are not observed Matchpoint or client results.
| Measure | Illustrative current state | Illustrative target gate | Evidence required |
|---|---|---|---|
| elapsed readiness cycle | 60 calendar days | 21 calendar days | workflow timestamps on comparable scope |
| paid preparation effort | 360 hours | 160 hours | time records by role and stage |
| first-pass accepted answers | 45% | at least 80% | owner review disposition |
| material claims with valid citations | unknown | 100% | claim-level citation audit |
| unanswered or unresolved questions at release | unknown | 0 material items | release checklist |
| post-release material corrections | unknown | 0 | investor communication and incident log |
| restricted-data disclosure events | unknown | 0 | access and release logs |
The illustrative move from sixty to twenty-one days represents the tracker's months-to-weeks ambition. The organisation should replace every value with an approved baseline and target before use. Faster elapsed time can reflect reduced queueing rather than lower paid effort. Both should be measured.
Financial attribution
Released capacity is calculated as approved baseline paid effort less observed target paid effort for comparable scope. It becomes cash cost reduction only when approved cash spend is avoided or removed. It becomes revenue only when the released capacity produces collected revenue under an approved causal bridge. Programme cost includes licences, model use, integration, data preparation, security, review, training, change and incident work.
Observed net contribution = approved incremental gross profit + approved avoided cash cost + approved avoided loss - implementation cost - run cost - review and exception cost - incident and remediation cost.
Attributed Matchpoint or client revenue, cash cost reduction, loss reduction and alpha remain USD 0 until approved observed evidence exists.
Two Unverified Illustrative Scenarios
Scenario A: emerging private-equity manager
[Unverified illustrative scenario] A first-time institutional fund has a 150-question catalogue, sixty approved source documents and a five-person answer-owner group. Prior DDQs exist but contain inconsistent team counts and obsolete policy descriptions. The manager creates a controlled fund corpus, identifies twelve conflicting claims and approves a structured answer bank before drafting a new investor DDQ.
The target workflow uses a Claude Project for a bounded readiness sprint. Project instructions require source-linked answers, conflict disclosure and abstention. A coordinator exports every draft into the approval register. Performance, terms, compliance, data security and key-person answers require specialist approval. The data-room index links each requested document to its approved version and disclosure tier.
The pilot measures citation completeness, first-pass acceptance, reviewer minutes, unresolved conflicts and elapsed days. Management does not claim a financial outcome. The scenario records attributed revenue, cash cost reduction, loss reduction and alpha at USD 0.
Scenario B: established multi-strategy manager
[Unverified illustrative scenario] A multi-strategy manager receives questionnaires from institutions, consultants and family offices across several jurisdictions. The firm needs field-level permissions, structured performance validation, CRM linkage and a recipient-specific release log. It selects an API-led design with an approved claim store, permission-aware hybrid retrieval, Claude generation with citations, deterministic validation and workflow approvals.
The manager separates common firm claims from fund and strategy claims. Each performance answer is generated from an approved structured source and locked basis. The system blocks expired cybersecurity evidence and routes it to the security owner. A material policy update identifies dependent claims and prior releases for review.
The evaluation set includes 150 catalogue questions, restricted-data traps, source conflicts and prompt-injection documents. Production release requires zero material permission failures and zero unsupported performance claims in the test set. The scenario records attributed revenue, cash cost reduction, loss reduction and alpha at USD 0.
Operating Roles And Governance
Named operating roles
| Role | Accountability |
|---|---|
| accountable executive | approves scope, risk tolerance and production release |
| DDQ coordinator | owns intake, taxonomy, routing, deadlines and package completeness |
| source owner | approves authoritative documents and refresh |
| claim owner | approves reusable factual or judgement statement |
| finance owner | approves performance, valuation and financial facts |
| compliance or legal reviewer | approves regulated, legal and disclosure-sensitive content |
| security and data owner | approves security, privacy, access and incident representations |
| technical owner | operates ingestion, retrieval, evaluation, logging and change control |
| release owner | authorises recipient-specific response and attachments |
A small manager can combine roles. The approval record should preserve necessary segregation and expertise.
System and claims registers
The system register records intended use, users, affected people, sources, provider, model, configuration, tools, permissions, evaluation, release, monitoring, incidents and retirement. The claims register records approved statements, evidence, owners, periods, audiences and dependencies.
| Control | Evidence |
|---|---|
| source inventory | owner, version, effective date, classification and checksum |
| answer catalogue | question, domain, owner, consequence and status |
| approved claims | wording, citations, period, audience and expiry |
| evaluation | golden set, results, failures, approval and configuration |
| release | recipient, exact answer package, attachments and sign-offs |
| access | identities, roles, reviews and removals |
| change | model, prompt, retrieval, source, rule and workflow version |
| incident | detection, containment, notification, correction and learning |
| supplier | contract, assurance, subprocessors, retention, continuity and exit |
| value | baseline, counterfactual, outcome, cost and finance approval |
Management information
The operating dashboard should report catalogue coverage, approved-claim coverage, source freshness, unresolved conflicts, permission exceptions, evaluation results, DDQs in progress, owner queues, review effort, post-release corrections and data-room gaps. Activity measures such as prompts or drafted answers should remain separate from approved readiness outcomes.
Ninety-Day Implementation Roadmap
Days 0-15: mandate and inventory
Name the fund, user population, owner and disclosure perimeter. Collect current DDQs, source documents and data-room indices. Classify documents and identify systems of record. Select a representative 150-question catalogue or approved alternative. Record the baseline and regulatory-review perimeter.
Days 16-30: claim model and knowledge base
Create document, claim and release schemas. Assign owners, effective dates, permissions and refresh triggers. Resolve material conflicts. Select the Project-led, API-led or hybrid architecture. Configure the bounded knowledge base and record product and contract assumptions.
Days 31-45: golden set and workflow
Create approved reference answers and evidence for the evaluation set. Build intake, retrieval, cited drafting, validation and review steps. Establish the data-room index and disclosure tiers. Test scanned documents, tables, conflicts, missing evidence and restricted material.
Days 46-60: shadow operation
Run a real or historical DDQ without external release from the new system. Compare with the approved response. Measure retrieval coverage, citation support, material edits, reviewer time, permission accuracy and unresolved questions. Correct sources and controls before expanding scope.
Days 61-75: bounded live pilot
Use the workflow for one qualified investor request under explicit review. Keep the prior process available. Monitor owner queues, model cost, latency, exceptions and release evidence. Record every correction and classify its cause.
Days 76-90: release decision
The accountable group reviews quality, security, compliance, service and value evidence. It can stop, continue shadow operation, extend the pilot, release a bounded population or scale. Expansion follows approved evidence and operating capacity. Refresh cycles and incident exercises become part of normal readiness.
Release Checklist, Claims Register And Limitations
Release checklist
- fund, entity, strategy and recipient are confirmed;
- original questions and subparts are complete;
- every answer has a named owner;
- material claims link to current approved evidence;
- performance basis, period, currency and status are verified;
- fund terms match the current legal documents;
- restricted data and documents match the disclosure tier;
- conflicts, gaps and expired evidence are resolved or explicitly withheld;
- citations resolve to the exact source version;
- deterministic validation passes;
- required finance, compliance, legal, security and management approvals exist;
- attachments are current, sanitised and correctly permissioned;
- the exact response package is recorded;
- correction and incident routes are ready;
- the data-room index and dependent claims are updated.
Claims register
| Claim | Status in this paper |
|---|---|
| ILPA DDQ 2.0 covers twenty diligence topics and requested documents | supported by ILPA sources [1,2] |
| AIMA and PRI provide additional structured diligence resources | supported by AIMA and PRI sources [3-5] |
| Claude Projects can use a project knowledge base and retrieval | supported within current Anthropic product documentation [7-9] |
| Anthropic API citations can refer to supported source locations | supported within current Anthropic documentation and format limits [10] |
| a specific manager can cut readiness from months to weeks | unverified hypothesis requiring comparable observed evidence |
| this architecture produces regulatory compliance | not established; qualified review is required |
| this architecture eliminates disclosure, model or cyber risk | not established; residual risk remains |
Empirical limitations
This paper is an operating framework rather than an empirical study of a Matchpoint or client deployment. The 150-question distribution, scenario inputs, baseline, targets and thresholds are unverified illustrative management assumptions. Product features, plans, terms and documentation can change. Current product and contractual capability should be verified before implementation.
Financial limitations
The paper does not establish incremental revenue, gross profit, cash cost reduction, avoided loss, valuation effect or alpha for any organisation. Released time is capacity. A faster response is an operational outcome. Financial attribution requires an approved causal bridge and observed source evidence. Attributed Matchpoint or client revenue, cash cost reduction, loss reduction and alpha remain USD 0 until approved observed evidence exists.
Legal and regulatory limitations
Investment, marketing, performance, records, privacy, cybersecurity, intellectual-property, employment, outsourcing and contractual requirements vary by entity, activity and jurisdiction. This paper is general research for professional audiences. It is not investment, legal, regulatory, accounting, audit, tax, employment, privacy, cybersecurity or technology advice.
Technical and operating limitations
Retrieval can miss evidence. Models can produce unsupported or incomplete answers. Citations can be present and still fail to support a claim. Source documents can be stale, conflicting, scanned incorrectly or permissioned wrongly. Reviewers can over-rely on fluent output. Provider, connector and index behaviour can change. Human authority, evaluation, monitoring, fallback and incident handling remain necessary.
Conclusion
Claude can support institutional diligence when the manager treats the task as a controlled information system. The foundation is a governed population of documents, structured claims and recipient-specific releases. Retrieval finds permitted current evidence. Generation produces a cited draft. Deterministic checks identify high-value inconsistencies. Named owners approve the representation and the disclosure.
For B2 managers, this operating model can reduce repeated search and reconciliation while strengthening readiness evidence. For A1 allocators, it can create a clearer path from an answer to the underlying source and responsible owner. The value depends on the corpus, metadata, permissions, evaluation and approval process.
The first production target should be bounded. A representative question catalogue, one fund, one disclosure policy and one accountable owner provide a workable starting point. The manager should measure elapsed time, paid effort, first-pass acceptance, citation support, material corrections and permission events. Financial value remains separate until finance approves observed evidence.
References
[1] Institutional Limited Partners Association. 2021. ILPA Due Diligence Questionnaire 2.0. https://ilpa.org/resources-tools/resource-library/due-diligence-questionnaire/
[2] Institutional Limited Partners Association. 2021. ILPA DDQ 2.0. https://ilpa.org/wp-content/uploads/2021/11/ILPA-DDQ-2.0.pdf
[3] Alternative Investment Management Association. Current. Due diligence questionnaires. https://www.aima.org/sound-practices/due-diligence-questionnaires.html
[4] Alternative Investment Management Association. 2025. Presenting the 2025 edition of the AIMA DDQ. https://www.aima.org/article/presenting-the-2025-edition.html
[5] Principles for Responsible Investment. Current. Responsible investment DDQ for venture capital limited partners. https://public.unpri.org/responsible-investment-ddq-for-venture-capital-limited-partners/10635.article
[6] Institutional Limited Partners Association. 2023. Diversity Metrics Template and Monitoring Questionnaire. https://ilpa.org/wp-content/uploads/2023/10/ILPA-DEI-Monitoring-Questionnaire.pdf
[7] Anthropic. Current. What are projects? https://support.anthropic.com/en/articles/9517075-what-are-projects
[8] Anthropic. Current. How can I create and manage projects? https://support.anthropic.com/en/articles/9519177-how-can-i-create-and-manage-projects
[9] Anthropic. Current. Retrieval Augmented Generation for projects. https://support.anthropic.com/en/articles/11473015-retrieval-augmented-generation-rag-for-projects
[10] Anthropic. Current. Citations. https://docs.anthropic.com/en/docs/build-with-claude/citations
[11] Anthropic. Current. What is the Claude Enterprise plan? https://support.anthropic.com/en/articles/9797531-what-is-the-claude-enterprise-plan
[12] Anthropic. Current. Does Anthropic act as a data processor or controller? https://support.anthropic.com/en/articles/9267385-does-anthropic-act-as-a-data-processor-or-controller
[13] Anthropic. Current. Pricing. https://docs.anthropic.com/en/docs/about-claude/pricing
[14] National Institute of Standards and Technology. 2023. Artificial Intelligence Risk Management Framework 1.0. https://doi.org/10.6028/NIST.AI.100-1
[15] National Institute of Standards and Technology. 2024. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile. https://doi.org/10.6028/NIST.AI.600-1
[16] National Institute of Standards and Technology. 2024. Cybersecurity Framework 2.0. https://www.nist.gov/cyberframework
[17] Model Context Protocol. 2025. Core architecture. https://modelcontextprotocol.io/specification/2025-06-18/basic/index
[18] Model Context Protocol. Current. Security best practices. https://modelcontextprotocol.io/docs/tutorials/security/security_best_practices
[19] United States Securities and Exchange Commission. Current. Investment adviser marketing. https://www.sec.gov/resources-small-businesses/small-business-compliance-guides/investment-adviser-marketing
[20] United States Securities and Exchange Commission. 2020. Investment Adviser Marketing; Final Rule. https://www.sec.gov/files/rules/final/2020/ia-5653.pdf
[21] United States Securities and Exchange Commission. 2024. SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence. https://www.sec.gov/newsroom/press-releases/2024-36
[22] Dubai International Financial Centre. 2023. DIFC enacts amended Data Protection Regulations. https://www.difc.com/whats-on/news/difc-enacts-amended-data-protection-regulations
[23] Dubai International Financial Centre. Current. Regulation 10. https://www.difc.com/business/registrars-and-commissioners/commissioner-of-data-protection/regulation-10
[24] Abu Dhabi Global Market. Current. Office of Data Protection. https://www.adgm.com/operating-in-adgm/office-of-data-protection
[25] Abu Dhabi Global Market. Current. Data subject rights: automated individual decision-making. https://www.adgm.com/documents/office-of-data-protection/resources/brochures-flyers/adgm-data-subject-rights-automated-individual-decision-making-brochure.pdf
[26] United Arab Emirates Government. Current. Data protection laws. https://u.ae/en/about-the-uae/digital-uae/data/data-protection-laws
[27] Financial Conduct Authority and Bank of England. 2024. AI in UK financial services. https://www.fca.org.uk/publications/research-notes/ai-uk-financial-services
[28] Organisation for Economic Co-operation and Development. Updated 2024. OECD AI Principles. https://oecd.ai/en/principles
[29] World Wide Web Consortium. 2013. PROV-DM: The PROV Data Model. https://www.w3.org/TR/prov-dm/
[30] Cybersecurity and Infrastructure Security Agency. 2023. Secure by Design. https://www.cisa.gov/securebydesign
Appendix A. Approved Claim Record
| Field | Required content |
|---|---|
| claim ID | stable identifier |
| question domains | catalogue and framework mappings |
| approved wording | exact reusable statement |
| evidence | document IDs, versions and source locations |
| factual period | date or reporting period covered |
| fund and entity | applicability boundary |
| owner and reviewers | accountable people and approvals |
| disclosure tier | permitted recipient class |
| restrictions | legal, performance, personal, security or other boundary |
| status | proposed, approved, expired, conflicted or superseded |
| refresh trigger | date or event |
| dependent releases | recipients that received the claim version |
Appendix B. Ddq Response Schema
- investor question ID and exact question;
- internal catalogue ID and domain;
- fund, entity, strategy and reporting period;
- recipient and disclosure tier;
- proposed answer;
- material claims and citations;
- source versions and effective dates;
- missing evidence and conflicts;
- requested attachments;
- answer owner and specialist reviewers;
- validation results;
- approval status and timestamps;
- released answer version;
- post-release correction state;
- linked data-room requirements.
Appendix C. Evaluation Record
| Measure | Required evidence |
|---|---|
| evaluation population | questions, domains, consequences and disclosure tiers |
| source population | exact approved versions and permission labels |
| tested configuration | model, prompt, retrieval, validation and workflow versions |
| retrieval coverage | relevant evidence returned under correct permissions |
| citation precision | claim-level reviewer judgement |
| citation completeness | material claims supported |
| factual consistency | names, numbers, dates, terms and qualifications |
| abstention | missing, conflicting and restricted cases handled |
| material failures | count, severity, cause and remediation |
| reviewer effort | paid minutes and exception burden |
| approval | accountable owner, date and permitted release scope |
Appendix D. Data-Room Release Record
- recipient legal name and authorised users;
- fund, strategy and mandate;
- NDA or other disclosure basis;
- disclosure tier;
- document IDs, versions and checksums;
- redaction derivatives and approvals;
- access start, expiry and revocation;
- download, view or inspection restrictions;
- release owner and specialist approvals;
- questions and follow-up requests;
- corrections or withdrawal;
- retention and deletion obligations.
Appendix E. Glossary
A1. Matchpoint ICP for limited partners, family offices, institutions, consultants and other capital allocators.
Approved claim. A reusable statement with current evidence, named ownership, audience boundary and approval.
B2. Matchpoint ICP for alternative-investment fund managers.
Citation completeness. The share of material claims supported by sufficient cited evidence.
Citation precision. The share of citations whose source span supports the associated claim.
Data-room index. The controlled register linking diligence requirements to current documents, owners, permissions and release history.
Disclosure tier. A management-approved recipient and confidentiality class controlling which claims and documents may be released.
Golden set. A versioned population of representative questions, approved evidence, expected answers and reviewer rationale used for evaluation.
Material claim. A statement capable of affecting an investment, legal, regulatory, financial, operational, security or reputation decision.
Permission-aware retrieval. Search that applies identity, fund, document, audience and field controls before returning evidence.
Project-led pattern. A controlled Claude Project used by authorised people for evidence-linked drafting from an approved knowledge base.
Release. The exact answer and attachment package approved for a named recipient at a stated time.
Retrieval-augmented generation. Generation supplied with selected source evidence retrieved for the current question.
Unverified illustrative management assumption. A worked input created to demonstrate logic; it is not observed Matchpoint or client evidence.
Source Register
The full paper records the scope, evidence setting and limitations applied to these sources.
- [1] Institutional Limited Partners Association. 2021. *ILPA Due Diligence Questionnaire 2.0*. Open source
- [2] Institutional Limited Partners Association. 2021. *ILPA DDQ 2.0*. Open source
- [3] Alternative Investment Management Association. Current. *Due diligence questionnaires*. Open source
- [4] Alternative Investment Management Association. 2025. *Presenting the 2025 edition of the AIMA DDQ*. Open source
- [5] Principles for Responsible Investment. Current. *Responsible investment DDQ for venture capital limited partners*. Open source
- [6] Institutional Limited Partners Association. 2023. *Diversity Metrics Template and Monitoring Questionnaire*. Open source
- [7] Anthropic. Current. *What are projects?* Open source
- [8] Anthropic. Current. *How can I create and manage projects?* Open source
- [9] Anthropic. Current. *Retrieval Augmented Generation for projects*. Open source
- [10] Anthropic. Current. *Citations*. Open source
- [11] Anthropic. Current. *What is the Claude Enterprise plan?* Open source
- [12] Anthropic. Current. *Does Anthropic act as a data processor or controller?* Open source
- [13] Anthropic. Current. *Pricing*. Open source
- [14] National Institute of Standards and Technology. 2023. *Artificial Intelligence Risk Management Framework 1.0*. Open source
- [15] National Institute of Standards and Technology. 2024. *Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile*. Open source
- [16] National Institute of Standards and Technology. 2024. *Cybersecurity Framework 2.0*. Open source
- [17] Model Context Protocol. 2025. *Core architecture*. Open source
- [18] Model Context Protocol. Current. *Security best practices*. Open source
- [19] United States Securities and Exchange Commission. Current. *Investment adviser marketing*. Open source
- [20] United States Securities and Exchange Commission. 2020. *Investment Adviser Marketing; Final Rule*. Open source
- [21] United States Securities and Exchange Commission. 2024. *SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence*. Open source
- [22] Dubai International Financial Centre. 2023. *DIFC enacts amended Data Protection Regulations*. Open source
- [23] Dubai International Financial Centre. Current. *Regulation 10*. Open source
- [24] Abu Dhabi Global Market. Current. *Office of Data Protection*. Open source
- [25] Abu Dhabi Global Market. Current. *Data subject rights: automated individual decision-making*. Open source
- [26] United Arab Emirates Government. Current. *Data protection laws*. Open source
- [27] Financial Conduct Authority and Bank of England. 2024. *AI in UK financial services*. Open source
- [28] Organisation for Economic Co-operation and Development. Updated 2024. *OECD AI Principles*. Open source
- [29] World Wide Web Consortium. 2013. *PROV-DM: The PROV Data Model*. Open source
- [30] Cybersecurity and Infrastructure Security Agency. 2023. *Secure by Design*. Open source
