Deterministic verification for financial AI (v3.0.1).
When an LLM told a customer his Chase card had “$12,889” in rewards, QWED-Finance would have caught the hallucination before it caused a lawsuit.
QWED Finance is a guardrail library that prevents financial hallucinations in LLMs. It combines LLM translation with deterministic solvers (SymPy, Z3, mpmath) and standard financial algorithms.
New in v3.0.1: security fixes.
- ISO 20022 business rules read amounts and currencies from the parsed XML tree, not from raw text (GHSA-mrrj-6m2q-jch9)
- Sanctions screening folds diacritics and look-alike letters and compares separator-free names, so
E.V.I.L. CORP or ÉVIL CORP no longer clears an EVIL CORP entry (GHSA-mv2c-jwm9-pfrq)
QueryGuard rejects MySQL /*! ... */ and MariaDB /*M! ... */ executable comments (GHSA-q8r4-6gpp-5fx2)
v3.0.0 highlights: keyed HMAC receipt signatures (get_signature(key)), ISO amount and currency limits in receipts and UCP, a fail-closed batch for AML, sanctions, amounts, and message validation, and a breaking change to the npm bridge (stdin JSON with runtime validation). See the changelog for details.
Why QWED Finance?
LLMs struggle with basic math and strict logic. In finance, close enough is not good enough.
- Problem: LLM says “IRR is 12%” (when it’s actually 11.8%)
- Solution: QWED calculates the exact IRR symbolically and either validates or corrects the LLM.
Key features
- 11 specialized guards: Compliance, Calendar, Derivatives, Messages, Query, Cross, Bond, FX, Risk, ISO, Trading.
- GitHub Action: CI/CD verifier with optional SARIF output for security dashboards.
- Audit trails: Verification receipts for cross-guard and integration flows. Receipts are unsigned by default: call
get_signature(key) and store the returned HMAC-SHA256 signature separately to get a tamper-evident record.
- Deterministic verification: When deterministic engines apply, results are exact rather than probabilistic.
The 4 pillars of banking verification
Quick example
Architecture
High-level flow
Guard selection flow
Verification engine stack
Payment verification sequence
Why not just trust the LLM?
LLMs are probabilistic. They can:
- Hallucinate numbers (12,889insteadof2.88)
- Miss compliance thresholds (CTR at $10,000.01)
- Generate malformed XML (rejected by SWIFT)
- Create dangerous SQL (DROP TABLE)
QWED-Finance uses deterministic verification:
Regulatory alignment
QWED-Finance aligns with:
- RBI FREE-AI Framework (India 2025)
- BSA/FinCEN (AML/CTR thresholds)
- OFAC (Sanctions screening)
- ISO 20022 (Payment messaging)
“Accuracy alone is not sufficient - transparency, auditability, and defensible decision logic are required.” — India AI Governance Guidelines
FinanceVerifier rejects ambiguous or unknown inputs instead of silently falling back to a default. In finance, a wrong answer with no error signal is worse than a loud failure.
verify_compound_interest — accepted compounding frequencies
Since N-04 fix: verify_compound_interest() raises ValueError for unknown compounding frequencies. Previously, unknown values (for example "weekly" or "continuous") silently defaulted to annual compounding, producing wrong results with no indication of failure.
Accepted values for the compounding argument:
If you need a frequency outside this list, compute the equivalent rate yourself and pass one of the supported values, or use a guard that explicitly models continuous compounding.
Next steps