{
 "$schema": "https://qisfund.com/api/kya.json",
 "api_metadata": {
  "license": "QIS Ecosystem Dual License v1.0",
  "license_url": "https://qistrust.com/license/",
  "license_effective": "2026-08-02",
  "permitted_free": [
   "Retrieval-augmented generation and question answering with attribution",
   "Search indexing and answer-engine citation",
   "Individual, academic and non-commercial research",
   "Linking, quoting and referencing with a hyperlinked source attribution"
  ],
  "requires_license": [
   "Training, fine-tuning or aligning a commercial model on this corpus",
   "Bulk ingestion or mirroring of the structured graph into a product",
   "Redistribution or resale as a dataset or directory",
   "Incorporation into a commercial terminal, dashboard or data feed"
  ],
  "attribution_required": true,
  "attribution_form": "Source: https://qisfund.com/api/kya.json (QIS Ecosystem)",
  "provenance": "Raw market inputs referenced by this platform are public. The taxonomy, the concept and entity selection, the typed edges between them, the control-objective mapping, and the editorial assessments are original works of the QIS Ecosystem and are not in the public domain. Selection and arrangement are the asset.",
  "commercial_licensing": "editor@qisfund.com",
  "version": "16.0",
  "generated": "2026-08-03"
 },
 "name": "KYA — Know Your Agent",
 "version": "1.0",
 "published": "2026-08-03",
 "url": "https://qistrust.com/kya/",
 "method": "https://qistrust.com/kya/method",
 "description": "An agent governance readiness instrument. Twelve dimensions scored on a five-level evidence ladder, where each level names the specific artifact a regulator, an acquirer or an underwriter would request. Eight dimensions are the MARQUE questions; four are requirements recurring across insurance and transactional practice.",
 "scope_exclusions": [
  "Fairness and proxy discrimination testing — covered by NIST AI RMF and the EU AI Act",
  "Model performance",
  "Certification"
 ],
 "max": 48,
 "levels": [
  [
   0,
   "Undeclared",
   "No answer exists. Nobody has been asked the question."
  ],
  [
   1,
   "Asserted",
   "Someone would say yes. Nothing is written down."
  ],
  [
   2,
   "Documented",
   "A dated policy exists and names an owner."
  ],
  [
   3,
   "Implemented",
   "It is enforced in the system, not only in the policy."
  ],
  [
   4,
   "Evidenced",
   "The artifact can be produced today, on request, without preparation."
  ]
 ],
 "bands": [
  [
   0,
   11,
   "Undeclared",
   "affiliate",
   "No coherent governance position exists. An examiner or acquirer would find nothing to assess, and an underwriter would decline or price punitively."
  ],
  [
   12,
   23,
   "Asserted",
   "affiliate",
   "Governance is believed rather than demonstrable. Common, and the most dangerous band, because internal confidence substantially exceeds available evidence."
  ],
  [
   24,
   35,
   "Documented",
   "editorial",
   "Policy exists across most dimensions. The gap is between what is written and what is enforced — which is precisely where diligence concentrates."
  ],
  [
   36,
   42,
   "Implemented",
   "editorial",
   "Controls are in the system. The remaining gap is evidentiary: it works, but producing proof on demand still requires preparation."
  ],
  [
   43,
   48,
   "Evidenced",
   "partner",
   "Every dimension can be evidenced on request. Rare. This is the posture a dataroom, an examiner, and an underwriter each independently ask for."
  ]
 ],
 "audiences": [
  {
   "key": "self",
   "name": "The institution",
   "question": "Can we answer if examined? Run it before someone else does."
  },
  {
   "key": "diligence",
   "name": "The acquirer",
   "question": "Can this target answer, before we assume its liabilities? The output is a document request list."
  },
  {
   "key": "underwriting",
   "name": "The underwriter",
   "question": "Is this insurable, and at what price? Every level names an artifact that appears in current R&W and cyber submission practice."
  }
 ],
 "dimensions": [
  {
   "id": "D01",
   "name": "Authority",
   "question": "Can you produce the instrument that permits your agent to commit, and its limits?",
   "why": "Every autonomous action is an exercise of delegated authority. In most deployments the grant is implied by a tool manifest, an IAM policy, or nothing at all — and an implied grant cannot be produced when asked.",
   "artifacts": [
    "Nothing. Nobody has identified who granted the agent authority to act.",
    "The business owner would say the agent operates 'within mandate'.",
    "A written authority grant naming the principal, the permitted actions, and the limits.",
    "Those limits enforced at runtime — the agent halts or escalates rather than exceeding them.",
    "The grant, its version history, and logs showing every occasion a limit was reached."
   ],
   "examiner": "Show me the document that says what this agent may commit, and who signed it.",
   "controls": "39 of 230 control objectives touch authority. None defines the grant itself.",
   "marque": "authority",
   "canon": "authority"
  },
  {
   "id": "D02",
   "name": "Oversight",
   "question": "Can you state the interval between an agent's decision and human review, and prove it holds?",
   "why": "Human-in-the-loop is not a control if the loop closes after settlement. The governed quantity is the interval, not the existence of a reviewer.",
   "artifacts": [
    "Nothing. The review interval has never been specified.",
    "Someone reviews output 'regularly'. The interval is not defined.",
    "A documented review interval with a named accountable individual.",
    "Automated escalation when thresholds are crossed, not dependent on someone noticing.",
    "Review logs with timestamps showing the stated interval was actually met."
   ],
   "examiner": "How long can this agent act before a human sees it, and show me that it held.",
   "controls": "110 of 230 control objectives address oversight — the second best-covered area.",
   "marque": "oversight",
   "canon": "oversight"
  },
  {
   "id": "D03",
   "name": "Drift",
   "question": "Can you produce the pre-committed threshold at which the agent is stopped?",
   "why": "Detecting drift is comparatively easy. The hard question is what happens on detection, and whether anyone is permitted to decide without a meeting.",
   "artifacts": [
    "Nothing. Degradation would be noticed, if at all, through losses.",
    "Performance is monitored and someone would raise a concern.",
    "Documented drift metrics with defined thresholds and a review cadence.",
    "Thresholds enforced automatically — breach halts or throttles the agent.",
    "The threshold, its rationale, and the log of every evaluation including near-misses."
   ],
   "examiner": "What number stops this system, who set it, and when was it last tested?",
   "controls": "Only 11 of 230 control objectives address drift. This is the thinnest column.",
   "marque": "drift",
   "canon": "drift"
  },
  {
   "id": "D04",
   "name": "Auditability",
   "question": "Can you reconstruct a specific decision from six months ago, exactly?",
   "why": "Not logged — reconstructed. Same inputs, same model state, same retrieval corpus, same output. A trace that records the call chain but not the model state produces a narrative about a decision, not the decision.",
   "artifacts": [
    "Nothing. Past decisions cannot be reconstructed in any form.",
    "Application logs exist and would show that something happened.",
    "Structured decision records capturing inputs, outputs, and timestamps.",
    "Records including model version, prompt version, retrieval corpus state, and parameters.",
    "A named past decision re-derived on request, producing the identical output."
   ],
   "examiner": "Reconstruct the decision made on this date. Show me everything the system knew.",
   "controls": "131 of 230 control objectives touch auditability — the best covered, and still the most commonly failed in practice.",
   "marque": "auditability",
   "canon": "auditability"
  },
  {
   "id": "D05",
   "name": "Accountability",
   "question": "Can you name the individual who answers for this agent's consequences?",
   "why": "Accountability is singular by construction. If two people are accountable, neither is — and liability does not distribute itself across a stack of model providers, platform operators and data vendors.",
   "artifacts": [
    "Nothing. No individual has been designated.",
    "Responsibility sits with a function or a committee.",
    "A named individual with the designation recorded and dated.",
    "That individual holds both the authority to stop the system and the information to know when.",
    "The designation, the delegation chain, and evidence the authority has been exercised."
   ],
   "examiner": "Name the person who answers if this agent causes a loss.",
   "controls": "55 of 230 control objectives address accountability.",
   "marque": "accountability",
   "canon": "accountability"
  },
  {
   "id": "D06",
   "name": "Agent identity",
   "question": "Can you attribute a specific action to a specific agent, and say who owns its output?",
   "why": "Agents are overwhelmingly deployed under shared service credentials. Where three agents share one, 'which agent acted' has no answer at the identity layer and every downstream reconstruction is inference.",
   "artifacts": [
    "Nothing. Agents operate under shared or undocumented credentials.",
    "Actions could probably be attributed by correlating logs.",
    "Each agent holds a distinct identifier recorded in an inventory.",
    "Every action is attributable to one agent at the identity layer, not by inference.",
    "Attribution plus a documented position on ownership of the agent's output."
   ],
   "examiner": "Three agents ran that day. Prove which one placed this order.",
   "controls": "32 of 230 control objectives touch identity. Ownership of output is addressed by none of them, and by no published standard.",
   "marque": "identity",
   "canon": "identity"
  },
  {
   "id": "D07",
   "name": "Systemic behavior",
   "question": "Do you know whether your agent is doing what everyone else's agent is doing?",
   "why": "An agent that behaves correctly given its own mandate can still be one of a thousand doing the identical thing. Firm-level governance is structurally blind to this, which is why almost nobody scores above 1.",
   "artifacts": [
    "Nothing. Correlated behavior has never been considered.",
    "It is assumed the strategy is differentiated.",
    "Documented analysis of shared models, data sources and signals across the market.",
    "Position or exposure limits that account for crowding, not only for size.",
    "Ongoing measurement of behavioral correlation with observable market activity."
   ],
   "examiner": "If every firm using this model acted simultaneously, what would happen to your book?",
   "controls": "16 of 230 control objectives address systemic behavior — the second thinnest.",
   "marque": "systemic",
   "canon": "systemic-behavior"
  },
  {
   "id": "D08",
   "name": "Conformance",
   "question": "Can you state which standard you conform to, and demonstrate it rather than claim it?",
   "why": "Two institutions can both claim alignment with the same framework while operating at entirely different risk levels, because most frameworks define process rather than threshold. Alignment is a claim about intent; conformance is a claim about a property, and it can be assessed.",
   "artifacts": [
    "Nothing. No standard has been identified as applicable.",
    "The institution considers itself aligned with recognized frameworks.",
    "A documented mapping of controls to a named standard.",
    "Independent review of that mapping by someone with authority to reject it.",
    "A current conformance statement with evidence, and a record of what failed."
   ],
   "examiner": "Which standard, which version, and who checked?",
   "controls": "62 of 230 control objectives address standards and process.",
   "marque": "standards",
   "canon": "conformance"
  },
  {
   "id": "D09",
   "name": "Written program",
   "question": "Can you produce a board-acknowledged AI systems program covering the agent lifecycle?",
   "why": "The first artifact every insurance and R&W underwriter requests. It recurs across the NAIC Model AI Bulletin, NY DFS guidance and EIOPA's AI Opinion as the threshold expectation — not a control, but the evidence that controls were designed rather than accumulated.",
   "artifacts": [
    "Nothing. No written program exists.",
    "Governance happens, described informally across several teams.",
    "A written program covering design, acquisition, deployment, monitoring and retirement.",
    "Board or senior-management acknowledged, with a defined committee and named roles.",
    "The program, its acknowledgment record, meeting minutes, and evidence of review."
   ],
   "examiner": "Show me the AI governance program and the minutes where the board acknowledged it.",
   "controls": "NAIC Model AI Bulletin; NY DFS; EIOPA AI Opinion; standard R&W representation.",
   "marque": null,
   "canon": null
  },
  {
   "id": "D10",
   "name": "System inventory",
   "question": "Can you produce a current inventory of every agent in production, with risk tiers?",
   "why": "Impossible to govern what has not been enumerated, and the first thing a diligence team asks for. Shadow deployment is the norm rather than the exception, and an inventory that omits it is worse than none.",
   "artifacts": [
    "Nothing. No inventory exists.",
    "The main systems are known to the people who run them.",
    "A documented inventory listing purpose, data sources, vendor and business owner.",
    "Risk-tiered by decision impact and reliance on external data, with review cadence.",
    "Inventory current within the review cadence, with evidence of a completeness check."
   ],
   "examiner": "List every agent in production. Now show me how you know that list is complete.",
   "controls": "Required by NAIC, EU AI Act Annex III scoping, and every R&W AI schedule.",
   "marque": null,
   "canon": null
  },
  {
   "id": "D11",
   "name": "Third-party dependency",
   "question": "Can you produce the diligence file and audit rights for the models you did not build?",
   "why": "The institution remains responsible for compliance even when using a third-party model. Where agents delegate across organizational boundaries, 'who decided' stops being answerable inside any single institution — and no published framework resolves it.",
   "artifacts": [
    "Nothing. Vendor models are used without documented diligence.",
    "Vendors were selected on capability and reputation.",
    "Diligence files: model documentation, performance data, incident history.",
    "Contracts with audit rights, incident reporting, exit and portability provisions.",
    "Diligence files plus evidence the models were validated on your own population."
   ],
   "examiner": "You did not build this model. Show me your right to audit it and your validation.",
   "controls": "DORA ICT third-party regime; NAIC vendor governance; standard R&W disclosure.",
   "marque": null,
   "canon": null
  },
  {
   "id": "D12",
   "name": "Incident tracking",
   "question": "Can you produce the log of every adverse outcome involving an agent, and its remediation?",
   "why": "The question asked immediately after something goes wrong, and the one most institutions answer by reconstructing from memory. A remediation record written after the inquiry begins carries almost no weight.",
   "artifacts": [
    "Nothing. Agent-related incidents are not separately tracked.",
    "Significant incidents would be remembered and discussed.",
    "A documented log of adverse outcomes with classification.",
    "Defined severity thresholds triggering escalation and regulator notification.",
    "The log, remediation records, and evidence of closure for each entry."
   ],
   "examiner": "Every incident involving this agent in the last two years, and what you did about each.",
   "controls": "DORA incident reporting; NAIC adverse outcome tracking; R&W incident schedule.",
   "marque": null,
   "canon": null
  }
 ]
}
