The structure behind the Statement.

The independent AI audit for FinTech and HealthTech under regulatory oversight.

Across eleven regulatory frameworks, accountability for AI governance now lands on a named individual — and the only record of how that AI is governed is the one the company wrote about itself. That record has never been checked by anyone outside the company.

11

regulatory frameworks name AI governance

5

regulators, AU and UK regimes

1

named individual accountable

01 — Why kn0w exists

Independent, not aligned.

Every exposure in your business has a record behind it — except one. Your revenue, your headcount, your risk position: each is something you could table in front of a board and stand behind. How AI is run across your business is the one exposure that sits in your own seat, and the one you hold no independent record for. Closing that gap means producing a record you didn't write yourself — and that is a specific kind of instrument, not a better internal document.

The instrument

kn0w is the independent AI audit for companies whose AI is subject to regulatory oversight. The audit is issued as a signed Statement — the same class of instrument a credit rating agency issues, or a Big Four partner signs at the bottom of a financial audit, or a certification body confers — adapted for the AI governance question regulated companies now have to answer. One fixed-scope engagement, issued as a signed Statement the people you answer to can rely on, and reissued each year under the same methodology.

The test

Reissued annually because the question it has to survive does not go away. A board, a regulator, or a diligence lead asks the same question each time: what evidence do you have that reasonable steps — the statutory test under APRA FAR and its UK equivalent — were taken? Most companies answer it with a slide deck, an internal policy memo, or a law firm write-up.

None of the three is issued by a party independent of the company. Each reads, correctly, as something the company produced about itself.

The named individual

Eleven regulatory frameworks across five regulators now name AI governance as an accountability area, and across the AU and UK regimes that accountability lands on a named individual.

APRA FAR
APRA FAR names individual executives accountable for how their company manages material risks, including AI.
FCA SM&CR
The FCA's Senior Managers and Certification Regime names individual Senior Managers accountable for AI governance failures.
TGA · MHRA
The TGA and the MHRA regulate AI-enabled software as a medical device.

Eleven frameworks, each turning AI governance into a named individual's personal accountability — and no audit instrument built for the question.

The cohort
FinTech · HealthTech
50–200 staff
AU · UK
k=5 floor

kn0w is the instrument built for it. The Statement is benchmarked against a defined cohort of peers — FinTech or HealthTech, 50 to 200 staff, in Australia or the UK under APRA, ASIC, FCA, TGA, or MHRA oversight — with the peer pool anonymised at a k=5 floor from the first audit.

It is evidence built to be submitted, not explained.
02 — How kn0w is structured

Independence is structural.

kn0w was founded in 2026. It is operated by two entities. KN0W PTE. LTD. (Singapore, UEN 202615303G) is the data controller, the sole contracting party on every engagement, and the issuer of every Statement. kn0w LLC (Wyoming, United States) is the technical sub-processor and authorised payment agent, operating the infrastructure under instruction from Singapore. Audit data is held in AWS regional boundaries — Sydney ap-southeast-2 for Australian members, London eu-west-2 for United Kingdom members — and does not cross those boundaries except through a single anonymisation pipeline that enforces a k=5 floor from the first audit.

Singapore signs. Wyoming operates. And kn0w earns from one thing only — issuing the Statement. There is nothing else to sell you.

The corporate group is designed for two purposes. Data residency under the Australian Privacy Principles and UK GDPR is handled at the regional instance level, not by contractual promise. The signing act is separated from the operational layer, so the entity that issues a Statement is not the entity that earns infrastructure revenue from operating it.

Every Statement and every Annual Statement is issued under the kn0w hallmark and stamped with a four-part identifier of the form kn0w / NNNNNN / YYYY-MM-DD / vX.Y — recording the issuer, the sequence number, the date of issue, and the methodology version. The hallmark is date-stamped, uniquely identified, and backed by a timestamped audit log: if anything in a Statement changes after issue, it can be proven. The identifier is the institutional signature. The sequence number is shared across a member’s institutional relationship and appears on the founding Statement and on every Annual Statement that supersedes it. The authorising principals are named at /methodology.

Governance & assurance

Certifications

SOC 2 Type II and ISO 27001 in progress with Vanta. Neither is yet certified.

Data residency

Held within the AWS regional boundary for each member's jurisdiction; leaves it only through the k=5 anonymisation pipeline.

Legal review

Governing terms reviewed by external commercial counsel.

The hallmark
Issuer
kn0w
Identifier
NNNNNN
Date issued
YYYY-MM-DD
Version
vX.Y

kn0w / 000142 / 2026-05-23 / v1.2

Pattern and worked example · the institutional signature on every Statement and every Annual Statement

Not a consultancy

kn0w is not a consultancy.

There is no engagement partner, no team of consultants, no statement of work to negotiate.

Commissioned · not retained
Not self-service software · not a certifier

kn0w is not a self-service compliance platform. kn0w is not a certification body.

Members log into a portal to view their operative artefact, their peer placement, and the integrations feeding the benchmark — but the Audit is commissioned, delivered through voice sessions, reviewed under the kn0w hallmark, and issued under a unique identifier. No configuration produces a better Statement. No badge is awarded, no pass or fail is rendered.

Issued · not configured · not badged
Not a regulator

kn0w is not a regulator.

No enforcement power is claimed, and no member is compelled to commission.

Independent · not an authority

kn0w is the independent party that issues the Statement.

The Statement is the product. This page describes how it is issued.

Everything above exists to answer one question: the exposure that sits in your seat, on a record you didn't write. Commissioning is a single intake. Fixed scope. Fixed price. Issued four weeks later, under the kn0w hallmark, on behalf of KN0W PTE. LTD.