QIS-KYA-001 QISTRUST.COM THE GOVERNANCE LAYER REV 2026-08-03 · BUILD 16.0
The Governance Layer · KYA methodology

Score the evidence, not the intention.

Ask an institution whether it has oversight of its autonomous systems and the answer is always yes, always sincere, and always uninformative. KYC's actual mechanic is not "are you who you say you are" — it is "produce the document." KYA works the same way, and that single reframe is what makes the result worth having.

KYA v1.0·Published 2026-08-03·Free to use and cite

The scale

Five levels, identical across every dimension.

Identical so scores are comparable, and calibrated so that most institutions score low. A scale everyone passes measures nothing — the discrimination is the product.

ScoreLevelMeaning
0UndeclaredNo answer exists. Nobody has been asked the question.
1AssertedSomeone would say yes. Nothing is written down.
2DocumentedA dated policy exists and names an owner.
3ImplementedIt is enforced in the system, not only in the policy.
4EvidencedThe artifact can be produced today, on request, without preparation.
The line that matters

The gap between 3 — Implemented and 4 — Evidenced is where most institutions actually sit and where nearly all diligence failures occur. A control that works but cannot be demonstrated on request is, to an examiner or an acquirer, indistinguishable from one that does not exist.

Interpretation

Bands.

ScoreBandWhat it means
0–11UndeclaredNo coherent governance position exists. An examiner or acquirer would find nothing to assess, and an underwriter would decline or price punitively.
12–23AssertedGovernance is believed rather than demonstrable. Common, and the most dangerous band, because internal confidence substantially exceeds available evidence.
24–35DocumentedPolicy exists across most dimensions. The gap is between what is written and what is enforced — which is precisely where diligence concentrates.
36–42ImplementedControls are in the system. The remaining gap is evidentiary: it works, but producing proof on demand still requires preparation.
43–48EvidencedEvery dimension can be evidenced on request. Rare. This is the posture a dataroom, an examiner, and an underwriter each independently ask for.

The Asserted band is the dangerous one. Internal confidence substantially exceeds available evidence, which is precisely the condition under which an institution discovers the gap during an examination rather than before one.

Composition

Why twelve and not eight.

MARQUE defines eight questions. KYA assesses twelve, and the difference is deliberate and disclosed rather than a silent expansion of a published framework.

The eight are MARQUE. The additional four — written program, system inventory, third-party dependency, incident tracking — are what the insurance and transactional markets demonstrably require, recurring across the NAIC Model AI Bulletin, NY DFS guidance, EIOPA's AI Opinion and current representation and warranty underwriting practice.

MARQUE governs an agent committing capital. KYA assesses whether an institution can evidence that governance to a third party. Those are different questions, and conflating them would weaken both.

IDDimensionSourceCoverage
D01AuthorityMARQUE39 of 230 control objectives touch authority. None defines the grant itself.
D02OversightMARQUE110 of 230 control objectives address oversight — the second best-covered area.
D03DriftMARQUEOnly 11 of 230 control objectives address drift. This is the thinnest column.
D04AuditabilityMARQUE131 of 230 control objectives touch auditability — the best covered, and still the most commonly failed in practice.
D05AccountabilityMARQUE55 of 230 control objectives address accountability.
D06Agent identityMARQUE32 of 230 control objectives touch identity. Ownership of output is addressed by none of them, and by no published standard.
D07Systemic behaviorMARQUE16 of 230 control objectives address systemic behavior — the second thinnest.
D08ConformanceMARQUE62 of 230 control objectives address standards and process.
D09Written programTransactionalNAIC Model AI Bulletin; NY DFS; EIOPA AI Opinion; standard R&W representation.
D10System inventoryTransactionalRequired by NAIC, EU AI Act Annex III scoping, and every R&W AI schedule.
D11Third-party dependencyTransactionalDORA ICT third-party regime; NAIC vendor governance; standard R&W disclosure.
D12Incident trackingTransactionalDORA incident reporting; NAIC adverse outcome tracking; R&W incident schedule.
Scope

What this deliberately does not assess.

Fairness and proxy discrimination testing. It is a genuine underwriting expectation and it is absent here on purpose. It is thoroughly covered by the NIST AI Risk Management Framework and the EU AI Act, and MARQUE exists to occupy a gap that nothing else fills. Entering a crowded field would dilute that claim. If you need that assessment, those two instruments are better than anything we would write.

Model performance. KYA does not ask whether your agent is any good. A well-governed system can be unprofitable and a profitable one can be ungoverned; this instrument measures only the second axis.

Certification. Nobody is accredited to assess KYA conformance, and any claim otherwise is unauthorized. This is a self-assessment producing an honest account of what you can evidence.

Limits

Where this instrument can be wrong.

It is a self-assessment, so it inherits the optimism of whoever completes it. The evidence framing is designed to resist that — asking for an artifact is harder to answer generously than asking about a capability — but it does not eliminate it. A profile completed by the person who built the system will read differently from one completed by the person who would have to defend it.

Twelve dimensions is a compression of a large problem. The scoring is ordinal rather than interval: the distance between 3 and 4 is not the same as between 1 and 2, and totals should be read as bands rather than as measurements.

If a dimension is wrong, or an artifact is misnamed relative to what your underwriter actually asks for, tell us. Corrections are published with attribution, and an instrument nobody corrects is an instrument nobody uses.