The Council for Education · Methodology publication
Banking Algorithm on Human Capital (BAoHC)
Financial control failures are recorded as transactions. They are produced by people — by who decides, who approves, who reconciles, and who was in a position to know.
BAoHC scores the human decision chain inside a financial institution and produces indicators for review. It is applied under engagement, by an institution that retains the Council. It reaches no institution that has not.
- Definition
-
Banking Algorithm on Human Capital (BAoHC)
n. — a proposed audit methodologyA method for scoring the human decision chain within a financial institution. BAoHC measures the structure of decision authority across a defined review period — who initiates, who approves, who reconciles, and who was positioned to know — and returns graded indicators together with the evidence each relied on. It is applied under engagement by an institution that has retained the Council. It returns no finding about any individual.
Mission
This methodology is published by The Council for Education — a nonprofit public benefit corporation and an IRC § 501(c)(3) public charity — which conducts independent third-party reviews at the intersection of cross-border banking and education finance. The Council’s organizational record, rulemaking participation, and intended proposals are documented on the Council’s own site; this page concerns the methodology.
CBMAS™ and the BAoHC methodology are before the Federal Reserve Board as intended proposals: submissions offered for consideration through public comment, proposing to replace the U.S. Department of Education’s eZ-Audit electronic submission system with more frequent, real-time data collection and AI-based analysis. They remain proposed methodologies — not adopted rules, and not validated deployments.
The two domains are one problem. The measurement gaps this model addresses in cross-border banking are the counterparts of the reporting gaps the Council has documented in education finance. In both cases the regulator’s own data system failed to capture the dominant flow channel, while the underlying activity continued at scale. A gap in measurement is not an absence of activity — it is an absence of visibility, and it is the condition this work exists to correct.
What the model scores
Four components, scored independently. Each returns a graded indicator and the evidence it relied on; none returns a finding. Where a component is structurally incapable of supporting a conclusion, that limit is stated with the component rather than in a footnote.
-
C-1
Insider relationship graph→ density · concentration
Maps decision-makers to counterparties and to one another across the review period, then scores the density of the resulting graph and the concentration of decision paths through any single node. A dense graph is a structural observation. It is not evidence of collusion.
-
C-2
Segregation-of-duties collapse→ role-conflict count
Identifies positions where initiation, approval, and reconciliation authority have collapsed into a single role, whether by design, by vacancy, or by delegation during absence. Scored by count and by the exposure sitting behind each conflict.
-
C-3
Key-person concentration→ dependency index
Measures the institution’s dependency on individuals whose discretion, absence, or departure would materially change an outcome. High concentration is a resilience finding first and a control finding second; the model reports both readings.
-
C-4
Knowledge-chain assembler→ assembled record · unscored
Assembles what was documented, when, and who received it, organised against the knowledge standards at 31 U.S.C. § 3729(b) — actual knowledge, deliberate ignorance, reckless disregard. The assembler orders the record for a human reviewer. It returns no score and makes no finding of scienter; that determination is reserved to counsel and the trier of fact.
Subject and stack
Three things are named here and they are not the same kind of thing. One is the conduct the model looks for. One is the model. One is the software that runs it. Collapsing them is the most common way this work is misread.
-
CBMAS™The subject — conduct under examination
Cross Border Monetary Arbitrage Scheme: the class of conduct the methodology is designed to detect. CBMAS is what is examined, not what is used. Detection is referenced to FATCA, the Common Reporting Standard, the Bank Secrecy Act (31 U.S.C. § 5311 et seq.), the Basel counterparty-credit-risk guidelines, and GAAP cross-border treatment.
-
BAoHCThe model — this document
Scores the human decision chain across the four components in §2. BAoHC is itself a model, and is therefore subject to the same validation expectations it is used to test — Federal Reserve SR 11-7 and OCC Bulletin 2011-12.
-
BAoHCThe runtime — deployment vehicle
Runs the model across five cooperating agents, each holding bounded authority and writing to a logged decision surface persisted in a hash-chained ledger. Authority grants are set out in §6.
How the model is engaged
BAoHC is applied under engagement. An institution retains the Council; the Council does not review institutions that have not retained it. Each route below has an existing regulatory basis under which independent third-party work is already contemplated.
-
Independent model validationValidation performed independently of the parties who developed and who use a model. Where an institution's own models touch cross-border activity, BAoHC scores the human decision chain around them.
SR 11-7
OCC Bulletin 2011-12 - Independent BSA/AML testingThe required independent test of an anti-money-laundering compliance program, which may be performed by an outside party rather than by the institution itself. 31 CFR 1020.210
-
Internal audit co-sourcingSpecialist capability supplied alongside an institution's internal audit function, under its audit committee's direction and its third-party risk program.
Interagency internal audit
and third-party guidance -
Agreed-upon proceduresA defined set of procedures over specific controls, agreed in advance, reported without an opinion. The narrowest and usually the fastest route to a first engagement.
Engagement letter
Scope fixed in S.T.E.E.R. stage one
The terms this creates. Authority here comes from the engagement, not from status. That has consequences, and they are stated rather than discovered:
- The institution engages the Council and may terminate the engagement. There is no standing relationship absent one.
- Findings are reported to the institution’s board and audit committee. They are not the Council’s to publish.
- The Council is a vendor, subject to the institution’s third-party risk management program, and expects to be diligenced as one.
- The Council has no reach over any institution that has not engaged it, and asserts none.
- Where a prospective engagement touches a subject of the Council’s public-interest work, the engagement is declined. A reviewer cannot be independent of a party it is litigating against, and independence is the only thing this methodology sells.
Governance: the S.T.E.E.R. sequence
A model that scores people needs its authority fixed before it runs, not adjudicated afterward. S.T.E.E.R. is the five-stage sequence governing every engagement. The order carries meaning: a model equipped before it is tasked has tools without a mandate, and one evaluated by its own operator has not been evaluated.
Fix the objective, the review subject, the scope boundary, and the success criteria — in the engagement letter, before any agent is instantiated.
Issue explicit instructions and an explicit authority grant. Anything not granted is withheld by default.
Supply only the context, data, and tools the granted authority requires. Access is scoped to the task, not to the agent.
Review reasoning, actions, and outputs against the stage-one criteria, by a reviewer with no write path to the system under review.
Tighten instructions and controls. Loosenings require recorded approval from outside the operating role; tightenings do not.
The sequence is part of a registered text. S.T.E.E.R., with the rest of the source methodology this page derives from, is the subject of a U.S. Copyright Office registration, documented in the public record on the Council’s site; the registered work itself remains unpublished.
Authority ledger
Each agent’s grant is enumerated and so is what it is refused. An authority that is not written down is not held.
| Agent | Granted | Withheld | Artifact written |
|---|---|---|---|
| A-1Ingestion | Read from sources named in the engagement manifest; hash and timestamp on receipt. | No transformation. No inference. No source not named in the manifest. | receipt_log.jsonl |
| A-2Pattern recognition | Score the four components in §2; attach a test identifier to every indicator returned. | No causal claim. No named individual in the scored output. No unflagged test. | indicator_register.jsonl |
| A-3Causality interpretation | Propose explanations for indicators, each with stated confidence and the evidence relied on. | No finding of intent. No release without corroboration from an independent source. | hypothesis_set.jsonl |
| A-4Investigation | Request further evidence through the engagement contact; assemble the record; mark gaps as gaps. | No direct contact with any scored individual. No outreach outside the engagement channel. | evidence_package/ |
| A-5Reporting | Draft the report and route it to the engagement partner for delivery to the audit committee. | No transmission. No delivery to any regulator. Every report leaves the system as a draft under a named person’s signature. | draft_report/ |
Evidentiary controls
Runtime evidence is the most fragile artifact the system produces: generated under degraded conditions, on infrastructure that may itself be failing. These controls assume that rather than the happy path.
- Local-first, fsync-backed writes. Evidence is durable on local disk before any network call. A record that exists only in flight does not exist.
- Hash-chained ledger. Each entry carries the digest of its predecessor. Append-only; entries are never edited or removed after write.
- Reconstructability as a hard gate. An indicator may be released only when it is both adjudicated and reconstructable. The conjunction is strict — there is no dual-approval path around a reconstruction failure.
- Corroboration before confidence. A confidence figure is computed only after the supporting sources are traced and shown to be genuinely independent of one another.
- Visible failure over silent recovery. On degraded evidence the system halts and says so. It does not retry its way to a clean-looking result.
- Separated observer. The assurance layer runs under its own credentials with no write path to execution state, and enforces findings through the standing of the record rather than by intervening at runtime.
Standing and limitations
Stated at the same weight as everything above, because a model that scores human conduct and hides its limits has already failed its first test.
What this is not
- The Council holds no examination authority over any financial institution. Bank examination authority is statutory and rests with the OCC, the Federal Reserve, the FDIC, and the state banking regulators. It is not delegable by private agreement, and the Council does not claim it.
- All work is performed under engagement. The Council reviews only institutions that have retained it, on the scope those institutions have agreed.
- CBMAS™ and BAoHC are proposed methodologies. They have not been validated, and they are not audits conducted in accordance with generally accepted government auditing standards.
- BAoHC returns indicators, not findings. No output constitutes a determination that any individual acted wrongfully, knowingly, or unlawfully. Adverse conclusions about a person are reserved to counsel, to the institution, and to the trier of fact.
Subscribe
Subscribe to the New Bank Committee’s newsletter.
We use your address only to send this newsletter. See the Privacy Policy. Protected by reCAPTCHA; Google’s Privacy Policy and Terms apply.
CBMAS™ is a trademark of The Council for Education, subject to a pending application before the United States Patent and Trademark Office. Proposed architecture, not a validated deployment. This page is a methodology publication and does not constitute legal, accounting, or audit advice.