Pre-submission reporting assurance · MiFIR & SFTR

Catch the rejection
before the regulator does.

Bring your MiFIR/SFTR reports. A deterministic engine of real ESMA validation rules checks every field against the authoritative sources — GLEIF, FIRDS, ISO — as of the trade date, catches the valid-but-wrong errors a format checker can't see, traces where each field broke, and seals audit-ready evidence. It runs in your own Azure tenant; your data never leaves.

▶ Validate your reportsLaunch the live demoread-only · runs in your tenant · nothing leaves
41
MiFIR / SFTR rules
the primary regime · add one = config
42/65
RTS 22 fields (MiFIR)
coverage computed, not claimed
100%
defect catch-rate · MiFIR
vs 36% for a format-only checker
9 rules
EMIR REFIT — foundation + IRS
9 supported fields · incl. interest-rate-swap rules, grounded to ESMA74-362-2683
figures from the current engine · MiFIR/SFTR is the primary regime; EMIR REFIT foundation — rules grounded to ESMA74-362-2683 · LEIs checked against GLEIF, instruments against FIRDS, as-of the trade date
The problem

Every reporting break asks the same ten questions

Today they're answered with custom Java harnesses, Kafka scripts, SQL, spreadsheets, Jira tickets and SME investigation — slowly, inconsistently, and with weak evidence when the regulator asks. And the downside is not small: transaction-reporting failures have drawn some of the largest regulatory fines — tens of millions — for firms whose controls missed the breaks.

Was the trade reportable?
Was the right report generated?
Was it on time?
Was it ACKed or NACKed?
Why was it rejected?
Is the issue isolated or systemic?
Which source system caused it?
Which trades are affected?
Is back-reporting needed?
What evidence do we keep for audit?
How it works

One evidence spine, five jobs

Taxonomy-driven and deterministic at the core; AI only where it's checked. The same run works on a laptop in simulator mode or against a bank's real SIT/UAT pipeline — no re-architecture.

01

Generate

Synthetic trades and lifecycle events across MiFIR & SFTR — checksum-valid identifiers, real venues, RTS 22 field-consistent, every reporting edge case.

02

Simulate

Push them through a reporting pipeline — Kafka, data lake, enrichment, reporting engine, ARM/TR — real or mocked.

03

Validate

Every field against real ESMA validation rules and the authoritative reference data (GLEIF, FIRDS, ISO) — format errors, cross-field & CFI-conditional breaks, and the valid-but-wrong ones, plus T+1/T+10 deadlines.

04

Trace

Field-level lineage: for each break, where the value came from, what it was checked against (as-of the trade date), and where in the chain it broke — cited to the exact RTS 22 / ESMA rule.

05

Seal

Human-approved, hash-chained evidence packs, stamped with the exact ruleset version that produced the verdicts. Audit-ready PDF and JSON, immutable once sealed.

Why it's defensible

The asymmetry principle

Agents that attack and test the deterministic core can only produce false alarms. Agents that act in the pipeline could produce false reports. So RegLab is maximally agentic on the attack side — and keeps zero agent authority on the act side.

Every AI explanation cites the exact evidence it used, or abstains. When many trades break at once, a systemic investigation clusters them, hypothesises one root cause, and an independent judge panel verifies it before a human ever sees it. Nothing is decided by AI — it's proven, checked, and human-approved.

Attack
Test generation, fuzzing, break investigation. Generate freely — the deterministic engine verifies every output. A wrong guess costs triage time, never report integrity.
Explain
Grounded, cited, judged. Draft explanations with mandatory citations; abstain over guess; independent judge panel confirms. Human approves before anything is final.
Act
Zero autonomy. No agent submits reports, activates knowledge, or notifies regulators. Ever.
What you get

Validate your reports

Paste a CSV of your own MiFIR/SFTR reports. The deterministic engine says exactly which would be rejected and why — cited to the real ESMA rule — and flags T+1 breaches. A free, read-only sweep of your reporting quality.

🔎

Systemic investigation

When a bad release breaks 97 trades, RegLab reports one root cause — not 97 defects — verified across completeness, parsimony and grounding by an independent judge panel.

📖

A real ESMA rule engine

Dozens of validation rules across nine predicate kinds — format, cross-field, CFI-conditional (Set 8), date-consistency — mapped to the real ESMA CON codes, over a computed slice of the 65-field RTS 22 report. Adding a rule is config, not code.

🌐

Checked against the authorities

Every LEI against GLEIF, every instrument against FIRDS, every MIC and currency against the ISO lists — as of the trade date, not a checksum proxy. The reference-data breaks a real ARM would raise.

🎛️

The valid-but-wrong class

Self-dealing, an option type that contradicts its instrument, a DEAL that isn't on own account, a maturity before the trade — schema-valid reports that are factually wrong. A format checker passes them; the engine doesn't.

🔒

Sealed evidence

Every finding becomes a human-approved, SHA-256 hash-chained evidence pack with separation of duties. Recompute the hash any time; the chain verifies or it doesn't.

🗺️

Coverage, computed

Breadth is measured against a canonical trade taxonomy, never asserted. Adding a trade type is configuration, not code. See exactly what's covered and what isn't.

Runs anywhere

Simulator mode needs zero infrastructure. Non-prod injection tests a real SIT/UAT Kafka pipeline. Production shadow observes read-only. Same engine throughout.

🛡️

AI in your tenant

Explanations draft on your own Azure OpenAI deployment — the model never leaves your boundary. Rule-based fallback means the lab never blocks on a model.

🎯

The unoccupied wedge

Nobody combines synthetic trade generation, pipeline testing, break intelligence and sealed evidence for MiFIR/SFTR. We test controls — we never replace your reporting engine.

See which of your reports would be rejected.

Paste your reports, get cited findings and a sealed evidence pack in minutes — or run a 100-scenario pack and watch the whole pipeline tested live. Read-only, in your own tenant.

▶ Validate your reportsTalk to usLaunch the live demo

This live demo runs open on synthetic data. Production is authenticated (Clerk), tenant-isolated (Postgres row-level security), and deployable in your own Azure tenant — the AI runs in-tenant; your data never leaves.