{
  "attribution": {
    "product": "NovaCopilot",
    "source": "legal.exploreworldai.com",
    "canonical": "https://legal.exploreworldai.com/us/agent/nydfs-500",
    "cite_as": "NovaCopilot, legal.exploreworldai.com (https://legal.exploreworldai.com/us/agent/nydfs-500)",
    "license": "https://legal.exploreworldai.com/revision",
    "version": "legal-2026-08-25",
    "fingerprint": "ewai:eu:d1efcf",
    "proof": "sha256:784f7b755281dc59d8bd1cd4ff0396b67b965ffb13be3fa4bb9cbe4282a90092",
    "jurisdiction": "eu"
  },
  "cagi_brand": "CAGI – Corporate Artificial General Intelligence",
  "cagi_version": "1.0",
  "cagi_relation": "alternate-entry",
  "canonical_agent": "/us/agent/nydfs-500",
  "jurisdiction": "US NY",
  "agent_type": "deterministic",
  "cagi_entry": "https://legal.exploreworldai.com/us/ny/cagi-api/nydfs-500",
  "canonical_agent_url": "https://legal.exploreworldai.com/us/agent/nydfs-500",
  "id": "nydfs-500",
  "script": {
    "kind": "operative",
    "fields": [
      {
        "name": "omfattad_enhet",
        "kind": "boolean",
        "label": "Verksamheten har tillstånd enligt New Yorks finanslagstiftning",
        "labelEn": "The business is licensed under New York financial services law"
      },
      {
        "name": "undantag_begransat",
        "kind": "boolean",
        "label": "Ett begränsat undantag enligt 500.19 är fastställt",
        "labelEn": "A limited exemption under 500.19 has been determined"
      },
      {
        "name": "program_dokumenterat",
        "kind": "boolean",
        "label": "Cybersäkerhetsprogram och policy är dokumenterade och godkända",
        "labelEn": "The cybersecurity program and policy are documented and approved"
      },
      {
        "name": "ciso_utsedd",
        "kind": "boolean",
        "label": "En ansvarig för informationssäkerhet är utsedd",
        "labelEn": "A chief information security officer is appointed"
      },
      {
        "name": "mfa_infort",
        "kind": "boolean",
        "label": "Flerfaktorsautentisering är införd för fjärråtkomst och privilegierad åtkomst",
        "labelEn": "Multi-factor authentication is in place for remote and privileged access"
      },
      {
        "name": "riskbedomning_aktuell",
        "kind": "boolean",
        "label": "Riskbedömningen är aktuell och dokumenterad",
        "labelEn": "The risk assessment is current and documented"
      },
      {
        "name": "tredjepartspolicy",
        "kind": "boolean",
        "label": "Policy för tredjepartsleverantörer finns",
        "labelEn": "A third party service provider policy is in place"
      },
      {
        "name": "incident_intraffat",
        "kind": "boolean",
        "label": "En cyberhändelse har inträffat",
        "labelEn": "A cybersecurity event has occurred"
      },
      {
        "name": "anmalan_inom_72h",
        "kind": "boolean",
        "label": "Anmälan till tillsynsmyndigheten är gjord inom 72 timmar",
        "labelEn": "Notice to the supervisor was given within 72 hours"
      }
    ],
    "rules": [
      {
        "id": "nydfs-incident",
        "when": {
          "op": "all",
          "of": [
            {
              "op": "equals",
              "field": "omfattad_enhet",
              "value": true
            },
            {
              "op": "equals",
              "field": "incident_intraffat",
              "value": true
            },
            {
              "op": "equals",
              "field": "anmalan_inom_72h",
              "value": false
            }
          ]
        },
        "outcome": {
          "code": "nydfs-incident-late",
          "verdict": "förbjudet",
          "audit": "KRAV_GÄLLER",
          "title": "Anmälan av cyberhändelse är försenad",
          "titleEn": "Notice of the cybersecurity event is late",
          "obligation": "23 NYCRR 500.17(a) kräver anmälan till tillsynsmyndigheten så snart som möjligt och senast 72 timmar efter att händelsen bedömts vara anmälningspliktig. 23 NYCRR 500.17(b) kräver en årlig intygan.",
          "obligationEn": "23 NYCRR 500.17(a) requires notice to the supervisor as promptly as possible and no later than 72 hours after determining that the event is notifiable. 23 NYCRR 500.17(b) requires an annual certification.",
          "refs": [
            "incident"
          ]
        }
      },
      {
        "id": "nydfs-exempt",
        "when": {
          "op": "all",
          "of": [
            {
              "op": "equals",
              "field": "omfattad_enhet",
              "value": true
            },
            {
              "op": "equals",
              "field": "undantag_begransat",
              "value": true
            }
          ]
        },
        "outcome": {
          "code": "nydfs-exempt",
          "verdict": "risk",
          "audit": "KRAV_VILLKORAT",
          "title": "Ett begränsat undantag gäller, men kärnkraven kvarstår",
          "titleEn": "A limited exemption applies, the core requirements remain",
          "obligation": "23 NYCRR 500.19 undantar vissa mindre verksamheter från delar av regeln. Undantaget omfattar inte programmet och policyn i 500.2 och 500.3, riskbedömningen i 500.9 eller anmälan i 500.17.",
          "obligationEn": "23 NYCRR 500.19 exempts certain smaller entities from parts of the regulation. The exemption does not cover the program and policy in 500.2 and 500.3, the risk assessment in 500.9 or the notice in 500.17.",
          "refs": [
            "program",
            "incident"
          ]
        }
      },
      {
        "id": "nydfs-program",
        "when": {
          "op": "all",
          "of": [
            {
              "op": "equals",
              "field": "omfattad_enhet",
              "value": true
            },
            {
              "op": "equals",
              "field": "program_dokumenterat",
              "value": false
            }
          ]
        },
        "outcome": {
          "code": "nydfs-program",
          "verdict": "förbjudet",
          "audit": "KRAV_GÄLLER",
          "title": "Dokumenterat program och godkänd policy saknas",
          "titleEn": "A documented program and an approved policy are absent",
          "obligation": "23 NYCRR 500.2 kräver ett dokumenterat cybersäkerhetsprogram grundat på riskbedömningen, och 23 NYCRR 500.3 kräver en skriftlig policy godkänd av styrelsen eller en ledande befattningshavare.",
          "obligationEn": "23 NYCRR 500.2 requires a documented cybersecurity program based on the risk assessment, and 23 NYCRR 500.3 requires a written policy approved by the board or a senior officer.",
          "refs": [
            "program"
          ]
        }
      },
      {
        "id": "nydfs-mfa",
        "when": {
          "op": "all",
          "of": [
            {
              "op": "equals",
              "field": "omfattad_enhet",
              "value": true
            },
            {
              "op": "equals",
              "field": "mfa_infort",
              "value": false
            }
          ]
        },
        "outcome": {
          "code": "nydfs-mfa",
          "verdict": "förbjudet",
          "audit": "KRAV_GÄLLER",
          "title": "Flerfaktorsautentisering saknas",
          "titleEn": "Multi-factor authentication is absent",
          "obligation": "23 NYCRR 500.12 kräver flerfaktorsautentisering för all fjärråtkomst till verksamhetens nät, för åtkomst till tredjepartstjänster med icke-offentlig information och för privilegierade konton.",
          "obligationEn": "23 NYCRR 500.12 requires multi-factor authentication for all remote access to the network, for access to third party applications holding nonpublic information and for privileged accounts.",
          "refs": [
            "mfa"
          ]
        }
      },
      {
        "id": "nydfs-ciso",
        "when": {
          "op": "all",
          "of": [
            {
              "op": "equals",
              "field": "omfattad_enhet",
              "value": true
            },
            {
              "op": "equals",
              "field": "ciso_utsedd",
              "value": false
            }
          ]
        },
        "outcome": {
          "code": "nydfs-ciso",
          "verdict": "risk",
          "audit": "KRAV_GÄLLER",
          "title": "Ansvarig för informationssäkerhet är inte utsedd",
          "titleEn": "No chief information security officer is appointed",
          "obligation": "23 NYCRR 500.4 kräver en utsedd ansvarig för informationssäkerhet och en årlig skriftlig rapport till styrelsen eller motsvarande organ.",
          "obligationEn": "23 NYCRR 500.4 requires a designated chief information security officer and an annual written report to the board or an equivalent body.",
          "refs": [
            "ciso"
          ]
        }
      },
      {
        "id": "nydfs-risk",
        "when": {
          "op": "all",
          "of": [
            {
              "op": "equals",
              "field": "omfattad_enhet",
              "value": true
            },
            {
              "op": "any",
              "of": [
                {
                  "op": "equals",
                  "field": "riskbedomning_aktuell",
                  "value": false
                },
                {
                  "op": "equals",
                  "field": "tredjepartspolicy",
                  "value": false
                }
              ]
            }
          ]
        },
        "outcome": {
          "code": "nydfs-risk",
          "verdict": "risk",
          "audit": "KRAV_VILLKORAT",
          "title": "Riskbedömning eller leverantörspolicy saknas",
          "titleEn": "The risk assessment or the supplier policy is absent",
          "obligation": "23 NYCRR 500.9 kräver en aktuell och dokumenterad riskbedömning, och 23 NYCRR 500.11 kräver en policy för tredjepartsleverantörer med krav i avtal.",
          "obligationEn": "23 NYCRR 500.9 requires a current and documented risk assessment, and 23 NYCRR 500.11 requires a third party service provider policy with contractual requirements.",
          "refs": [
            "program"
          ]
        }
      },
      {
        "id": "nydfs-base",
        "when": {
          "op": "equals",
          "field": "omfattad_enhet",
          "value": true
        },
        "outcome": {
          "code": "nydfs-base",
          "verdict": "risk",
          "audit": "KRAV_GÄLLER",
          "title": "Regeln gäller för verksamheten",
          "titleEn": "The regulation applies to the business",
          "obligation": "23 NYCRR Part 500 gäller varje verksamhet med tillstånd enligt New Yorks bank-, försäkrings- eller finanslagstiftning. Kraven omfattar program, ansvarig funktion, autentisering och anmälan.",
          "obligationEn": "23 NYCRR Part 500 applies to every entity licensed under New York banking, insurance or financial services law. The requirements cover the program, the responsible function, authentication and notice.",
          "refs": [
            "program",
            "ciso",
            "mfa",
            "incident"
          ]
        }
      }
    ],
    "fallback": {
      "code": "out-of-scope",
      "verdict": "tillåtet",
      "audit": "UTANFÖR_TILLÄMPNING",
      "title": "Regeln ger inget krav på den indata som lämnats",
      "titleEn": "The rule yields no requirement for the facts supplied",
      "obligation": "Verksamheten är inte angiven som omfattad enhet enligt 23 NYCRR 500.1.",
      "obligationEn": "The business is not stated to be a covered entity under 23 NYCRR 500.1.",
      "refs": []
    }
  },
  "hash": "sha256:784f7b755281dc59d8bd1cd4ff0396b67b965ffb13be3fa4bb9cbe4282a90092",
  "version": "legal-2026-08-25",
  "expires": "2026-09-23T00:00:00.000Z",
  "dependency": {
    "index_version": "legal-2026-08-25+legal-2026-08-25+2026-08-25T10:00:00",
    "content_hash": "sha256:784f7b755281dc59d8bd1cd4ff0396b67b965ffb13be3fa4bb9cbe4282a90092",
    "revalidate_after": "2026-09-23T00:17:08.295Z",
    "max_copy_age_seconds": 3600,
    "policy": "revalidate-required; attribution-preferred",
    "changelog": "https://legal.exploreworldai.com/api/public/v1/dependency",
    "verify": "https://legal.exploreworldai.com/api/public/v1/verify",
    "stale_copy_invalid": true
  },
  "canonical": "https://legal.exploreworldai.com/us/agent/nydfs-500",
  "disclaimer": "Källhänvisning med officiell identifierare. Ingen juridisk rådgivning och inget efterlevnadsbeslut.",
  "usageInfo": "https://legal.exploreworldai.com/citering"
}