Zenmem
Login
⚖️

SEBI suitability auditor

WealthSEBI compliancePython 3.14 · CLIzenmem-open/sebi-suitability-auditor

View source

About this agent

An automated SEBI compliance and suitability auditor for RIAs and MFDs, run as an invisible check before an advisor's recommendation goes to a client. Every proposed trade — a fresh purchase or a switch — is checked against the client's documented risk profile and IPS notes, the firm's own house rules (sector caps, an exit-load/rationale requirement, a cap on repeated switches within a rolling 90 days), and connected SEBI/AMC reference data such as Risk-o-meter ratings, all inside one zenmem session that also pulls the client's own prior audit history back in as context. The model returns a structured verdict — PASS, FAIL or NEEDS_REVIEW — together with a suitability statement and a Direct-vs-Regular fee/commission disclosure; if its output doesn't parse as valid JSON the auditor fails closed to NEEDS_REVIEW rather than silently passing. PASS and FAIL are the only verdicts ever written to the audit trail: they're committed atomically, alongside the suitability statement, the disclosure and a consent note, into a project-scoped ledger built for SEBI inspection. NEEDS_REVIEW is returned to the caller but never auto-committed — a compliance officer has to resolve it by hand before anything is recorded as final. Firm-wide guardrails live in company-scope memory, seeded once and read automatically into every audit afterwards, so a policy change doesn't require touching the audit code itself.

RUNTIMEPython 3.14 · CLI
MEMORY TYPESession + company + long-term
SDKzenmem 0.4.4
INTERFACECLI

What changed with Zenmem?

The same agent, built twice against the same contract — once on Zenmem, once on MongoDB + LangChain/LangGraph.

Before → after

Code for the audit trail−36%

Code for the suitability verdict−63%

New infrastructure to stand upnone

New dependencies to install0

Schema, collection and index worknone

House rules changed without a releasea seeded scope

Verdict and disclosure written togetherone transaction

Before With Zenmem

What the team gained

  • Firm house rules — sector caps, switch-frequency limits — are seeded into company scope and read into every audit, so a policy change never means a code change.
  • A PASS or FAIL verdict, its suitability statement and its fee disclosure are written atomically, because a regulator inspecting a half-written verdict is the failure that matters.
  • The audit trail is its own project scope, so the record a regulator reads is not mixed with the working state of a review.
  • A proposed-trade review closes as soon as the verdict is returned, leaving nothing live to reconcile.
  • A new house rule is a seeded document, not a schema change across the audit log.

How memory is scoped

Three scopes doing three different jobs. Company-scope memory holds the firm's house rules — sector caps, switch-frequency limits — seeded once and read into every audit automatically, so a policy change never means a code change. Session scope holds one proposed-trade review: the live audit call and any temporary rationale, closed as soon as the verdict is returned. Project scope, keyed to projectId="SEBI_AUDIT_LOGS", is the audit trail itself — the only place a PASS or FAIL verdict, its suitability statement and its fee/commission disclosure get written, atomically and together, because a regulator inspecting the log can never be shown a half-written record.

How it works

Audit, parse the verdict, commit only what's final.

Open a review session

One session per proposed recommendation, so the audit call and any temporary rationale don't leak into other clients' reviews.

Audit against risk profile and house rules

The client's risk profile, the firm's company-scope guardrails, and connected SEBI/AMC Risk-o-meter data all feed the same audit call.

Fail closed on a bad verdict

If the model's response doesn't parse as the expected structured JSON, the verdict defaults to NEEDS_REVIEW rather than a silent PASS.

Commit only PASS or FAIL

A final verdict is written atomically to the project-scoped audit ledger, together with its disclosure and consent note.

Route NEEDS_REVIEW to a human

Anything the auditor can't resolve on its own goes back to the caller for a compliance officer to close out — it is never auto-committed.

Commands

A CLI over the same review workflow available as a Python library.

Commands

  • audit-shield ping — checks connectivity to the configured zenmem deployment.
  • audit-shield seed-rules — seeds the firm's default house-rule guardrails into scope="company".
  • audit-shield audit --client ... --pan ... --risk-profile ... --scheme ... --scheme-category ... --amount ... [--switch] --rationale ... — runs a full suitability and disclosure audit on one proposed trade and prints the verdict.
  • AuditShieldAgent.review_recommendation() — the Python API equivalent: audits a trade and commits it if the verdict is final.
  • AuditShieldAgent.start_review_session() / end_review_session() — owns the session lifecycle around one audit.
  • AuditLedger.commit_if_final() — atomically writes PASS/FAIL verdicts to the project-scoped ledger; NEEDS_REVIEW is never committed.