The independent AI audit for FinTech and HealthTech under regulatory oversight.
Across eleven regulatory frameworks, accountability for AI governance now lands on a named individual — and the only record of how that AI is governed is the one the company wrote about itself. That record has never been checked by anyone outside the company.
11
regulatory frameworks name AI governance
5
regulators, AU and UK regimes
1
named individual accountable
Every exposure in your business has a record behind it — except one. Your revenue, your headcount, your risk position: each is something you could table in front of a board and stand behind. How AI is run across your business is the one exposure that sits in your own seat, and the one you hold no independent record for. Closing that gap means producing a record you didn't write yourself — and that is a specific kind of instrument, not a better internal document.
kn0w is the independent AI audit for companies whose AI is subject to regulatory oversight. The audit is issued as a signed Statement — the same class of instrument a credit rating agency issues, or a Big Four partner signs at the bottom of a financial audit, or a certification body confers — adapted for the AI governance question regulated companies now have to answer. One fixed-scope engagement, issued as a signed Statement the people you answer to can rely on, and reissued each year under the same methodology.
Reissued annually because the question it has to survive does not go away. A board, a regulator, or a diligence lead asks the same question each time: what evidence do you have that reasonable steps — the statutory test under APRA FAR and its UK equivalent — were taken? Most companies answer it with a slide deck, an internal policy memo, or a law firm write-up.
None of the three is issued by a party independent of the company. Each reads, correctly, as something the company produced about itself.
Eleven regulatory frameworks across five regulators now name AI governance as an accountability area, and across the AU and UK regimes that accountability lands on a named individual.
Eleven frameworks, each turning AI governance into a named individual's personal accountability — and no audit instrument built for the question.
kn0w is the instrument built for it. The Statement is benchmarked against a defined cohort of peers — FinTech or HealthTech, 50 to 200 staff, in Australia or the UK under APRA, ASIC, FCA, TGA, or MHRA oversight — with the peer pool anonymised at a k=5 floor from the first audit.
kn0w was founded in 2026. It is operated by two entities. KN0W PTE. LTD. (Singapore, UEN 202615303G) is the data controller, the sole contracting party on every engagement, and the issuer of every Statement. kn0w LLC (Wyoming, United States) is the technical sub-processor and authorised payment agent, operating the infrastructure under instruction from Singapore. Audit data is held in AWS regional boundaries — Sydney ap-southeast-2 for Australian members, London eu-west-2 for United Kingdom members — and does not cross those boundaries except through a single anonymisation pipeline that enforces a k=5 floor from the first audit.
Singapore signs. Wyoming operates. And kn0w earns from one thing only — issuing the Statement. There is nothing else to sell you.
The corporate group is designed for two purposes. Data residency under the Australian Privacy Principles and UK GDPR is handled at the regional instance level, not by contractual promise. The signing act is separated from the operational layer, so the entity that issues a Statement is not the entity that earns infrastructure revenue from operating it.
Every Statement and every Annual Statement is issued under the kn0w hallmark and stamped with a four-part identifier of the form kn0w / NNNNNN / YYYY-MM-DD / vX.Y — recording the issuer, the sequence number, the date of issue, and the methodology version. The hallmark is date-stamped, uniquely identified, and backed by a timestamped audit log: if anything in a Statement changes after issue, it can be proven. The identifier is the institutional signature. The sequence number is shared across a member’s institutional relationship and appears on the founding Statement and on every Annual Statement that supersedes it. The authorising principals are named at /methodology.
Governance & assurance
Certifications
SOC 2 Type II and ISO 27001 in progress with Vanta. Neither is yet certified.
Data residency
Held within the AWS regional boundary for each member's jurisdiction; leaves it only through the k=5 anonymisation pipeline.
Legal review
Governing terms reviewed by external commercial counsel.
kn0w / 000142 / 2026-05-23 / v1.2
Pattern and worked example · the institutional signature on every Statement and every Annual Statement
There is no engagement partner, no team of consultants, no statement of work to negotiate.
Members log into a portal to view their operative artefact, their peer placement, and the integrations feeding the benchmark — but the Audit is commissioned, delivered through voice sessions, reviewed under the kn0w hallmark, and issued under a unique identifier. No configuration produces a better Statement. No badge is awarded, no pass or fail is rendered.
No enforcement power is claimed, and no member is compelled to commission.
kn0w is the independent party that issues the Statement.
Everything above exists to answer one question: the exposure that sits in your seat, on a record you didn't write. Commissioning is a single intake. Fixed scope. Fixed price. Issued four weeks later, under the kn0w hallmark, on behalf of KN0W PTE. LTD.