Know Your Agent.
Every governance self-assessment asks whether you have controls, and everyone answers yes. This one asks whether you can produce the evidence — today, on request, without preparation. That is the question a regulator, an acquirer, and an underwriter each ask, and it is the only one that discriminates.
Answer for one agent, not for the institution.
Pick a single autonomous system that takes a consequential action — places orders, moves funds, approves something, or commits the firm in any way. Assess that one. Averaging across a portfolio produces a number that describes nothing.
Answer as if someone were standing in front of you asking for the artifact. If producing it would require a week of preparation, it does not count as evidenced. That is the entire calibration, and it is deliberately unforgiving: most institutions score between 12 and 23, and recognizing that is the useful part.
Your answers stay in your browser. Nothing is transmitted, no account is created, and the result is not gated. After you see it you may optionally contribute an anonymous profile to the benchmark — it is a button, never a default.
Twelve dimensions.
Eight are the MARQUE questions. Four are what the insurance and transactional markets require in addition — written program, inventory, third-party dependency, incident tracking.
—
Dimension profile
| Dimension | Level | Score | Standing |
|---|
Artifacts you cannot currently produce
This is the deliverable. Each line is a document a diligence team or an underwriter would request, and which you would not be able to hand over today.
What you would be asked first
Ordered by weakness. These are the questions an examiner, an acquirer's counsel, or an underwriter opens with — because they are the ones you are least able to answer.
Copy the schedule below into a diligence memo, a board pack, or an underwriting submission. It is formatted to be pasted, not screenshotted.
Twelve scores and, if you choose, a sector and size band. No identity, no institution name, no free text, no IP address. We publish aggregates only and never a figure derived from fewer than ten responses. Nothing links a contribution to your session or to any other data we hold.
The benchmark is the point: once enough profiles exist, you can see where you stand rather than only what you are missing. That is not available anywhere today.
A score is a marketing artifact. A named gap is a work order.
- If you scored under 24 — the fastest movement is dimensions 09 and 10. A written program and a complete inventory are the two artifacts every other request depends on, and neither requires engineering.
- If you scored 24 to 35 — the gap is between policy and enforcement. Take the three lowest dimensions and ask, for each, what would have to be true in the system rather than in the document.
- If you are running diligence — the artifact list is your document request. Ask for the items rated below 4 and treat any that cannot be produced within a week as unevidenced, whatever the target says.
- If you are underwriting — dimensions 09, 11 and 12 map most directly to current R&W and cyber submission practice. A submission that cannot evidence those three is asking you to price an unmeasured exposure.
KYA is an editorial instrument published by the QIS Ecosystem. It is not legal advice, not a compliance determination, not a certification, and not a substitute for regulatory or professional judgment. It produces one thing: an honest account of what you can currently evidence.