QIS-KYA-000 QISTRUST.COM THE GOVERNANCE LAYER REV 2026-08-03 · BUILD 16.0
The Governance Layer · KYA v1.0

Know Your Agent.

Every governance self-assessment asks whether you have controls, and everyone answers yes. This one asks whether you can produce the evidence — today, on request, without preparation. That is the question a regulator, an acquirer, and an underwriter each ask, and it is the only one that discriminates.

The institutionCan we answer if examined? Run it before someone else does.
The acquirerCan this target answer, before we assume its liabilities? The output is a document request list.
The underwriterIs this insurable, and at what price? Every level names an artifact that appears in current R&W and cyber submission practice.

12 dimensions·~5 minutes·Nothing transmitted·No sign-up

Before you start

Answer for one agent, not for the institution.

Pick a single autonomous system that takes a consequential action — places orders, moves funds, approves something, or commits the firm in any way. Assess that one. Averaging across a portfolio produces a number that describes nothing.

Answer as if someone were standing in front of you asking for the artifact. If producing it would require a week of preparation, it does not count as evidenced. That is the entire calibration, and it is deliberately unforgiving: most institutions score between 12 and 23, and recognizing that is the useful part.

Your answers stay in your browser. Nothing is transmitted, no account is created, and the result is not gated. After you see it you may optionally contribute an anonymous profile to the benchmark — it is a button, never a default.

The instrument

Twelve dimensions.

Eight are the MARQUE questions. Four are what the insurance and transactional markets require in addition — written program, inventory, third-party dependency, incident tracking.

0 of 12

Can you produce the instrument that permits your agent to commit, and its limits?

Every autonomous action is an exercise of delegated authority. In most deployments the grant is implied by a tool manifest, an IAM policy, or nothing at all — and an implied grant cannot be produced when asked.

What you will be asked: “Show me the document that says what this agent may commit, and who signed it.”

Can you state the interval between an agent's decision and human review, and prove it holds?

Human-in-the-loop is not a control if the loop closes after settlement. The governed quantity is the interval, not the existence of a reviewer.

What you will be asked: “How long can this agent act before a human sees it, and show me that it held.”

Can you produce the pre-committed threshold at which the agent is stopped?

Detecting drift is comparatively easy. The hard question is what happens on detection, and whether anyone is permitted to decide without a meeting.

What you will be asked: “What number stops this system, who set it, and when was it last tested?”

Can you reconstruct a specific decision from six months ago, exactly?

Not logged — reconstructed. Same inputs, same model state, same retrieval corpus, same output. A trace that records the call chain but not the model state produces a narrative about a decision, not the decision.

What you will be asked: “Reconstruct the decision made on this date. Show me everything the system knew.”

Can you name the individual who answers for this agent's consequences?

Accountability is singular by construction. If two people are accountable, neither is — and liability does not distribute itself across a stack of model providers, platform operators and data vendors.

What you will be asked: “Name the person who answers if this agent causes a loss.”

Can you attribute a specific action to a specific agent, and say who owns its output?

Agents are overwhelmingly deployed under shared service credentials. Where three agents share one, 'which agent acted' has no answer at the identity layer and every downstream reconstruction is inference.

What you will be asked: “Three agents ran that day. Prove which one placed this order.”

Do you know whether your agent is doing what everyone else's agent is doing?

An agent that behaves correctly given its own mandate can still be one of a thousand doing the identical thing. Firm-level governance is structurally blind to this, which is why almost nobody scores above 1.

What you will be asked: “If every firm using this model acted simultaneously, what would happen to your book?”

Can you state which standard you conform to, and demonstrate it rather than claim it?

Two institutions can both claim alignment with the same framework while operating at entirely different risk levels, because most frameworks define process rather than threshold. Alignment is a claim about intent; conformance is a claim about a property, and it can be assessed.

What you will be asked: “Which standard, which version, and who checked?”

09Transactional requirement

Can you produce a board-acknowledged AI systems program covering the agent lifecycle?

The first artifact every insurance and R&W underwriter requests. It recurs across the NAIC Model AI Bulletin, NY DFS guidance and EIOPA's AI Opinion as the threshold expectation — not a control, but the evidence that controls were designed rather than accumulated.

What you will be asked: “Show me the AI governance program and the minutes where the board acknowledged it.”

10Transactional requirement

Can you produce a current inventory of every agent in production, with risk tiers?

Impossible to govern what has not been enumerated, and the first thing a diligence team asks for. Shadow deployment is the norm rather than the exception, and an inventory that omits it is worse than none.

What you will be asked: “List every agent in production. Now show me how you know that list is complete.”

11Transactional requirement

Can you produce the diligence file and audit rights for the models you did not build?

The institution remains responsible for compliance even when using a third-party model. Where agents delegate across organizational boundaries, 'who decided' stops being answerable inside any single institution — and no published framework resolves it.

What you will be asked: “You did not build this model. Show me your right to audit it and your validation.”

12Transactional requirement

Can you produce the log of every adverse outcome involving an agent, and its remediation?

The question asked immediately after something goes wrong, and the one most institutions answer by reconstructing from memory. A remediation record written after the inquiry begins carries almost no weight.

What you will be asked: “Every incident involving this agent in the last two years, and what you did about each.”

What to do with it

A score is a marketing artifact. A named gap is a work order.

  • If you scored under 24 — the fastest movement is dimensions 09 and 10. A written program and a complete inventory are the two artifacts every other request depends on, and neither requires engineering.
  • If you scored 24 to 35 — the gap is between policy and enforcement. Take the three lowest dimensions and ask, for each, what would have to be true in the system rather than in the document.
  • If you are running diligence — the artifact list is your document request. Ask for the items rated below 4 and treat any that cannot be produced within a week as unevidenced, whatever the target says.
  • If you are underwriting — dimensions 09, 11 and 12 map most directly to current R&W and cyber submission practice. A submission that cannot evidence those three is asking you to price an unmeasured exposure.

KYA is an editorial instrument published by the QIS Ecosystem. It is not legal advice, not a compliance determination, not a certification, and not a substitute for regulatory or professional judgment. It produces one thing: an honest account of what you can currently evidence.