{
  "tool_id": "art-466-dora-roi-builder",
  "kernel_id": "art-466-dora-roi-builder",
  "display_name": "DORA Register of Information (RoI) Builder & Cross-Validator",
  "tool_version": "1.0.0",
  "mandate_type": "compliance_mandate",
  "purpose": "Constructs and cross-validates the core Register of Information (RoI) template relationships required under DORA (EU 2022/2554) Art. 28/30: entity + ICT third-party providers + functions + contractual arrangements. Validates ISO 17442 LEI format + mod-97 check-digit on the entity and every provider, referential integrity (every function's provider_id, every contract's function_id and provider_id, and function-to-contract provider consistency), and mandatory-field completeness per record type, emitting a form-shaped JSON dataset plus a validation report with per-record findings and compliance_flags. Distinct from the RoI's official xBRL-CSV submission format, which this kernel does NOT emit (a later WU handles ESA-format conversion). Distinct from art-467-dora-incident-classifier (this validates the standing RoI dataset; that classifies a single ICT incident's reporting obligations). Criticality of functions/providers is a caller-declared flag, not judged here.",
  "control_description": "Constructs and cross-validates the core Register of Information (RoI) template relationships required under DORA (EU 2022/2554) Art. 28/30: entity + ICT third-party providers + functions + contractual arrangements. Validates ISO 17442 LEI format + mod-97 check-digit on the entity and every provider, referential integrity (every function's provider_id, every contract's function_id and provider_id, and function-to-contract provider consistency), and mandatory-field completeness per record type, emitting a form-shaped JSON dataset plus a validation report with per-record findings and compliance_flags. Distinct from the RoI's official xBRL-CSV submission format, which this kernel does NOT emit (a later WU handles ESA-format conversion). Distinct from art-467-dora-incident-classifier (this validates the standing RoI dataset; that classifies a single ICT incident's reporting obligations). Criticality of functions/providers is a caller-declared flag, not judged here.",
  "declared_inputs": [],
  "declared_outputs": [],
  "kernel_digest": "sha256:4f605ce91ebec16f4f7e409b383f1f5f273b5f3e0551894aed9765e2b7681d80",
  "trust_label": "independently verified -- zkVM execution proof (risc0/groth16-bn254)",
  "data_vintage": "2026-07-24",
  "last_validated": "2026-07-24",
  "conformance_fixtures_vendored": true,
  "compute_proof_ready": "ready",
  "wave": 74,
  "source_url": "https://ainumbers.co/chaingraph/art-466-dora-roi-builder.html",
  "generated_at": "2026-07-25T20:02:55.601Z"
}
