Apply data minimisation + scope enforcement + localisation + cross-border transfers per applicable regulation. Data Minimisation and Scope Enforcement must (a) enforce OAuth scope checking at every API endpoint + (b) return only data within authorised scope + (c) prevent broad consent abuse + (d) align with applicable data minimisation principle (UK GDPR + EU GDPR + national equivalents + sector-specific). Data localisation and cross-border transfers must (a) honor data residency requirements per applicable regulation (Brazil LGPD + China PIPL + Russia + UAE + KSA + India + Vietnam + similar), (b) implement transfer safeguards per applicable mechanism (SCCs + BCRs + adequacy + consent + regulator approval), (c) maintain transfer impact assessment for sensitive transfers. Sanctions and AML integration must (a) integrate open banking transactions with sanctions screening + AML monitoring + suspicious activity reporting, (b) align with FATF Recommendations + national AML/CTF regimes + Office of Foreign Assets Control + UK OFSI + EU + UN sanctions + sectoral.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.