Unified document: deploy, runbooks, E2E tests, checklists, and evidence dossier.
- .NET SDK 9.0
- PostgreSQL (local Docker or remote)
- Optional: Docker Desktop (Postgres/E2E), OpenAI-compatible LLM host / ContextMemory
docker compose up -d # Optional local PostgreSQL
# or use remote DB in ConnectionStrings__CreditAiDatabaseMigrations applied automatically on API and Web startup.
dotnet run --project src/CreditAI.API
dotnet run --project src/CreditAI.Web| Verification | URL |
|---|---|
| Web | http://localhost:5188 |
| Health | GET /health |
| ReDoc | /redoc (Development) |
| Login | /Identity/Account/Login |
dotnet build CreditAI.slndotnet run --project tools/CreditAI.MrmGatedotnet test CreditAI.sln.\scripts\generate-homologation-evidence.ps1 -StartApp- Execute manual scenarios — E2E_HOMOLOGATION.md
- Fill HOMOLOGATION_CHECKLIST.md
- Pen test → SECURITY_PEN_TEST_CHECKLIST.md
| Document | File |
|---|---|
| Checklist | HOMOLOGATION_CHECKLIST.md |
| E2E scenarios | E2E_HOMOLOGATION.md |
| Technical runbook | HOMOLOGATION_RUNBOOK.md |
| Requirements matrix | INSTITUTIONAL_REQUIREMENTS_MATRIX.md |
| Pen test | SECURITY_PEN_TEST_CHECKLIST.md |
File: azure-pipelines.yml
Stages: Build + MRM gate → Unit + Architecture → Integration → Postgres (Testcontainers) → E2E Playwright.
Structure in dossier/README.md:
docs/dossier/
01-pipeline-core/ → F1, intake, human review, Art. 22
02-model-risk/ → MRM gate, model cards, drift
03-aml-solvency/ → AML, solvency, goAML
04-narrative-ai/ → grounding, OpenAI-compatible LLM
05-monitoring/ → EWI, watchlist
06-audit/ → audit export, immutability
07-regulatory-exports/ → supervisor, CIRBE, CRC
08-manual-data/ → manual entry contingency
09-e2e/ → .trx, health, OpenAPI, logs
10-security/ → pen test
Generate automatically:
.\scripts\generate-homologation-evidence.ps1
.\scripts\run-e2e-ui-homologation.ps1
.\scripts\run-homologation-full.ps1
cd scripts/generate-docx-docs && npm install && npm run generate| Integration | Institutional responsibility |
|---|---|
| BPnet CRC mTLS | Bank integration team |
| World-Check API | Compliance / IT |
| Yapily open banking | Digital banking |
| FIU goAML Portal | AML compliance |
| Iberian CIRBE | Credit risk |
| Internal LLM GPU (OpenAI-compatible) | AI infrastructure |
| Entra ID app registrations | IAM |
| Azure Key Vault | Cloud platform |
| Role | Responsible | Date |
|---|---|---|
| Compliance | ||
| Model validation | ||
| CISO / pen test | ||
| DPO (DPIA) |