These tools and metrics are designed to help AI actors develop and use trustworthy AI systems and applications that respect human rights and are fair, transparent, explainable, robust, secure and safe.
VeritasChain Protocol (VCP)
The VeritasChain Protocol (VCP) is an open, vendor-neutral specification for cryptographically verifiable audit trails in algorithmic and AI-driven trading systems. It is maintained by the VeritasChain Standards Organization. Trading decisions are increasingly made by algorithms and AI models, and regulators require firms to keep detailed records of these decisions. However, conventional logs must be taken on trust: auditors cannot easily confirm that records are complete, correctly ordered and unaltered. VCP addresses this by defining a common audit format that regulators, auditors and market participants can verify mathematically, rather than relying on the firm's word.
The specification covers the full trading process. It records the signals and decisions produced by algorithms, every stage of an order's lifecycle from submission to execution or cancellation, and risk controls with snapshots of their settings. It also records AI governance metadata, such as which model made a decision, the factors behind it and any approvals. Accurate timestamps and event ordering are required throughout.
VCP is organised into six modules. These cover event headers and security data, trading and execution, algorithm governance and AI transparency, risk parameters, privacy and recovery from disruptions. The privacy module supports pseudonymisation and crypto-shredding, which makes personal data unreadable by deleting its encryption key while keeping the audit trail intact. VCP is designed to support compliance with MiFID II, Article 12 of the EU AI Act on record-keeping, the GDPR and the US Consolidated Audit Trail. The current version is 1.2, and the specification is released under a CC BY 4.0 licence.
About the tool
You can click on the links to see the associated tools
Tool type(s):
Objective(s):
Target sector(s):
Country/Territory of origin:
Lifecycle stage(s):
Type of approach:
Usage rights:
Use Cases
Would you like to submit a use case for this tool?
If you have used this tool, we would love to know more about your experience.
Add use case




























