Score the evidence, not the intention.
Ask an institution whether it has oversight of its autonomous systems and the answer is always yes, always sincere, and always uninformative. KYC's actual mechanic is not "are you who you say you are" — it is "produce the document." KYA works the same way, and that single reframe is what makes the result worth having.
Five levels, identical across every dimension.
Identical so scores are comparable, and calibrated so that most institutions score low. A scale everyone passes measures nothing — the discrimination is the product.
| Score | Level | Meaning |
|---|---|---|
| 0 | Undeclared | No answer exists. Nobody has been asked the question. |
| 1 | Asserted | Someone would say yes. Nothing is written down. |
| 2 | Documented | A dated policy exists and names an owner. |
| 3 | Implemented | It is enforced in the system, not only in the policy. |
| 4 | Evidenced | The artifact can be produced today, on request, without preparation. |
The gap between 3 — Implemented and 4 — Evidenced is where most institutions actually sit and where nearly all diligence failures occur. A control that works but cannot be demonstrated on request is, to an examiner or an acquirer, indistinguishable from one that does not exist.
Bands.
| Score | Band | What it means |
|---|---|---|
| 0–11 | Undeclared | No coherent governance position exists. An examiner or acquirer would find nothing to assess, and an underwriter would decline or price punitively. |
| 12–23 | Asserted | Governance is believed rather than demonstrable. Common, and the most dangerous band, because internal confidence substantially exceeds available evidence. |
| 24–35 | Documented | Policy exists across most dimensions. The gap is between what is written and what is enforced — which is precisely where diligence concentrates. |
| 36–42 | Implemented | Controls are in the system. The remaining gap is evidentiary: it works, but producing proof on demand still requires preparation. |
| 43–48 | Evidenced | Every dimension can be evidenced on request. Rare. This is the posture a dataroom, an examiner, and an underwriter each independently ask for. |
The Asserted band is the dangerous one. Internal confidence substantially exceeds available evidence, which is precisely the condition under which an institution discovers the gap during an examination rather than before one.
Why twelve and not eight.
MARQUE defines eight questions. KYA assesses twelve, and the difference is deliberate and disclosed rather than a silent expansion of a published framework.
The eight are MARQUE. The additional four — written program, system inventory, third-party dependency, incident tracking — are what the insurance and transactional markets demonstrably require, recurring across the NAIC Model AI Bulletin, NY DFS guidance, EIOPA's AI Opinion and current representation and warranty underwriting practice.
MARQUE governs an agent committing capital. KYA assesses whether an institution can evidence that governance to a third party. Those are different questions, and conflating them would weaken both.
| ID | Dimension | Source | Coverage |
|---|---|---|---|
| D01 | Authority | MARQUE | 39 of 230 control objectives touch authority. None defines the grant itself. |
| D02 | Oversight | MARQUE | 110 of 230 control objectives address oversight — the second best-covered area. |
| D03 | Drift | MARQUE | Only 11 of 230 control objectives address drift. This is the thinnest column. |
| D04 | Auditability | MARQUE | 131 of 230 control objectives touch auditability — the best covered, and still the most commonly failed in practice. |
| D05 | Accountability | MARQUE | 55 of 230 control objectives address accountability. |
| D06 | Agent identity | MARQUE | 32 of 230 control objectives touch identity. Ownership of output is addressed by none of them, and by no published standard. |
| D07 | Systemic behavior | MARQUE | 16 of 230 control objectives address systemic behavior — the second thinnest. |
| D08 | Conformance | MARQUE | 62 of 230 control objectives address standards and process. |
| D09 | Written program | Transactional | NAIC Model AI Bulletin; NY DFS; EIOPA AI Opinion; standard R&W representation. |
| D10 | System inventory | Transactional | Required by NAIC, EU AI Act Annex III scoping, and every R&W AI schedule. |
| D11 | Third-party dependency | Transactional | DORA ICT third-party regime; NAIC vendor governance; standard R&W disclosure. |
| D12 | Incident tracking | Transactional | DORA incident reporting; NAIC adverse outcome tracking; R&W incident schedule. |
What this deliberately does not assess.
Fairness and proxy discrimination testing. It is a genuine underwriting expectation and it is absent here on purpose. It is thoroughly covered by the NIST AI Risk Management Framework and the EU AI Act, and MARQUE exists to occupy a gap that nothing else fills. Entering a crowded field would dilute that claim. If you need that assessment, those two instruments are better than anything we would write.
Model performance. KYA does not ask whether your agent is any good. A well-governed system can be unprofitable and a profitable one can be ungoverned; this instrument measures only the second axis.
Certification. Nobody is accredited to assess KYA conformance, and any claim otherwise is unauthorized. This is a self-assessment producing an honest account of what you can evidence.
Where this instrument can be wrong.
It is a self-assessment, so it inherits the optimism of whoever completes it. The evidence framing is designed to resist that — asking for an artifact is harder to answer generously than asking about a capability — but it does not eliminate it. A profile completed by the person who built the system will read differently from one completed by the person who would have to defend it.
Twelve dimensions is a compression of a large problem. The scoring is ordinal rather than interval: the distance between 3 and 4 is not the same as between 1 and 2, and totals should be read as bands rather than as measurements.
If a dimension is wrong, or an artifact is misnamed relative to what your underwriter actually asks for, tell us. Corrections are published with attribution, and an instrument nobody corrects is an instrument nobody uses.