# Treasury Payment Agent Release Checklist

Version: 1.0
Published: 2026-07-28
Owner:

Use this checklist to define one governed treasury payment-preparation and release action. Copy it
into the control repository, ticket system, or operating procedure and complete every field.

This is general implementation guidance. Confirm the legal, regulatory, contractual, payment-rail,
and internal-control requirements for every jurisdiction, legal entity, account, currency, and
payment route.

## 1. Define payment intake and source authenticity

- Process:
- Payment request ID:
- Request channel:
- Source system:
- Source-system identity:
- Requesting principal:
- Source signature, digest, or immutable reference:
- Source timestamp:
- Approved template or instruction format:
- Required source fields:
- Data-quality rule:
- Duplicate-detection key:
- Intake rejection rule:

## 2. Record the payment context

- Payer legal entity:
- Payer account:
- Payee:
- Beneficiary:
- Beneficiary account:
- Beneficiary bank:
- Intermediary bank:
- Payer jurisdiction:
- Payee jurisdiction:
- Beneficiary jurisdiction:
- Bank and payment-rail jurisdictions:
- Currency:
- Amount:
- Payment purpose:
- Invoice, contract, or obligation reference:
- Requested execution date:
- Cutoff:
- Payment rail:
- Data Boundary:

## 3. Define agent identity and authority

- Agent identity:
- Agent Release:
- Accountable owner:
- Delegated user:
- Service or workload identity:
- Identity provider:
- Delegation reference:
- Permitted purpose:
- Permitted payment classes:
- Permitted payer accounts:
- Permitted tools:
- Permitted destinations:
- Amount authority:
- Aggregate authority:
- Environment:
- Authority expiry:
- Credential lifetime:
- Data fields allowed:
- Data fields denied:

## 4. Configure sanctions and watchlist screening

- Applicable legal jurisdictions:
- Sanctions programs in scope:
- Authoritative list sources:
- List or vendor version:
- List retrieved at:
- List digest:
- Payer fields screened:
- Payee fields screened:
- Beneficiary fields screened:
- Banks and intermediaries screened:
- Countries and regions screened:
- Ownership or control information required:
- Match threshold:
- False-positive adjudication role:
- Potential-match action:
- Confirmed-prohibition action:
- Screening-service unavailable action:
- Rescreen trigger:

## 5. Configure payment-control checks

| Check | Inputs | `allow` | `warn` | `require_approval` | `block` |
| --- | --- | --- | --- | --- | --- |
| Duplicate | | | | | |
| Amount and aggregate exposure | | | | | |
| Counterparty and account | | | | | |
| Data completeness and authenticity | | | | | |
| Anomaly | | | | | |
| Velocity | | | | | |
| Cutoff and value date | | | | | |
| Currency and jurisdiction | | | | | |
| Payment rail | | | | | |

Decision precedence:

1. `block`
2. `require_approval`
3. `warn`
4. `allow`

## 6. Separate preparation, review, and release

### Payment preparer

- Eligible role:
- Maximum authority:
- Actions allowed:
- Actions prohibited:
- Evidence produced:

### Payment checker

- Eligible role:
- Minimum competence:
- Maximum authority:
- Conflict rule:
- Requester comparison:
- Evidence reviewed:
- Decision evidence:

### Payment releaser

- Eligible human or service:
- Release condition:
- Bound request and decision:
- One-use authority:
- Idempotency rule:
- Evidence produced:

### Independence test

- Can the preparer review the request? Yes / No
- Can the checker change payment fields? Yes / No
- Can the agent approve its own proposal? Yes / No
- Can the release credential execute a changed request? Yes / No
- Identity source checked at decision time:
- Role source checked at decision time:
- Action-binding method:

## 7. Define permitted and prohibited actions

| Action | Agent may prepare | Agent may execute | Required approval | Absolute prohibition |
| --- | --- | --- | --- | --- |
| Read approved payment request | | | | |
| Validate required fields | | | | |
| Screen parties and route | | | | |
| Propose payment instruction | | | | |
| Submit bound release call | | | | |
| Change beneficiary account | | | | |
| Change sanctions result | | | | |
| Add or alter reviewer authority | | | | |
| Reuse approval | | | | |
| Disable evidence collection | | | | |

## 8. Set maker-checker and multi-party approval rules

- Maker identity fields:
- First checker role:
- Second checker role:
- Multi-party trigger:
- Sequential or parallel decisions:
- Required decision order:
- Value or risk authority per checker:
- Conflict and related-party checks:
- Presented-evidence digest:
- Required reason codes:
- Approval capability binding:
- Single-use enforcement:

## 9. Set expiry, reassignment, and escalation

- Requested at:
- Response target:
- Escalate at:
- Expires at:
- Early-expiry triggers:
- Queue owner:
- Replacement role:
- Reassignment authority:
- Reassignment reason required:
- Original-assignee retention:
- Safe state at expiry:
- Screening refresh after expiry:
- Payment-context refresh after expiry:
- New Decision Request rule:

## 10. Record bank and payment-rail outcomes

- Gateway:
- Payment rail:
- Message type:
- Idempotency key:
- Submission time:
- Bank or rail reference:
- Accepted, rejected, pending, settled, or returned:
- Reason or status code:
- Settlement time:
- Reconciliation source:
- Before-state digest:
- After-state digest:
- Unresolved downstream state:

## 11. Define rejection, rollback, incident, and revocation

- Policy rejection behavior:
- Reviewer rejection behavior:
- Bank or rail rejection behavior:
- Cancellation window:
- Recall or return procedure:
- Compensation procedure:
- Incident trigger:
- Incident owner:
- Agent disablement:
- Credential revocation:
- Tool deny rule:
- Queue and retry cancellation:
- Downstream reconciliation:
- Safe state:
- Recovery test:
- Restart approver:

## 12. Retain and export evidence

Use the public KLA AI Agent Audit Log Schema:

- Reference page: https://kla.digital/resources/ai-agent-audit-log-schema
- JSON Schema: https://kla.digital/ai-agent-audit-event/v1/schema.json

Required record groups:

- [ ] Payment request and source-authenticity proof
- [ ] Payer, payee, beneficiary, account, jurisdiction, currency, amount, and purpose context
- [ ] Requester, agent, service identity, delegated user, accountable owner, and component versions
- [ ] Sanctions and watchlist source, version, digest, query inputs, result, and adjudication
- [ ] Duplicate, anomaly, velocity, cutoff, threshold, and data-quality results
- [ ] Policy ID, version, outcome, matched rules, reasons, input digest, and decision time
- [ ] Decision Request, expiry, required roles, reviewer identities, reasons, and evidence digest
- [ ] Tool receipt, idempotency key, result digest, and downstream effects
- [ ] Bank or rail status, business outcome, rollback, return, or incident reference
- [ ] Ordered lineage, artifact manifest, privacy treatment, retention, record hash, signature, and
      verification result

- Retention class:
- Retention period:
- Legal hold process:
- Access policy:
- Redaction method:
- Sealed Evidence Bundle destination:
- Export owner:
- Offline verifier:
- Completed verification result:

## 13. Sign-off

- Treasury control owner:
- Sanctions compliance owner:
- Financial crime owner:
- IAM owner:
- Payment operations owner:
- Technical owner:
- Risk owner:
- Internal audit or assurance reviewer:
- Approved policy version:
- Approved list sources:
- Effective date:
- Next review:
- Last negative test:
- Last recovery drill:
- Evidence location:
