Built to be submitted.

You've seen the exposure. This is the instrument that measures it — how it's built, why it holds, and what makes a kn0w Statement defensible on the record. Independent by construction, issued under the kn0w hallmark, benchmarked against your peer cohort under one published methodology.

01 — Built to be submitted

A measurement standard, not an opinion.

Australian Securities and Investments Commission REP 798 · Beware the gap: Governance arrangements in the face of AI innovation

"Governance arrangements were often lagging the adoption of the technology … a heavy reliance on existing governance frameworks that were not updated to address the new risks created by AI."

asic.gov.au · REP 798 · 29 October 2024

Every regulator in scope of this methodology has chosen the same posture: existing technology-neutral law applies to AI without modification. Accountability is named at senior individual level. Documentation is the evidentiary bar.

When an algorithm shapes a decision about a person, the question each regulator arrives at is the same: is the decision contestable, explicable, and non-discriminatory, and what evidence proves it?

Few companies can answer that on demand today — not because the work is undone, but because no one has measured where their own answer would hold and where it would not. kn0w is the measurement. Everything below is how it is constructed, so that what it issues stands up when someone asks.

02 — The CEO Visibility Gap

What you believe is happening, and what is, are not the same reading.

The evidence a regulator expects sits inside the functions, not in the boardroom. Where a CEO's account of the company's AI posture diverges from what each function actually runs, that distance is the company's real evidentiary position — and it is invisible from the top of the company precisely where it is being asked for.

kn0w names that distance the CEO Visibility Gap and reports it, per dimension, inside the issued Statement — where it is carried as a composite reading, benchmarked against the member’s peer cohort (the k=5 floor applies to that benchmark pool; the member’s own Statement is their own named data).

kn0w · Illustrative specimen · benchmark placement as issued
Issued
Composite reading
Systematic47th percentile of cohort
Cohort
FinTech · Australia · 50–200 staff
CEO Visibility Gap
Reported per dimension within the Statement
kn0w / 000142 / 2026-05-23 / v1.2Illustrative specimen · figures are not a benchmark
03 — Regulatory mapping

Eleven frameworks. Routed to dimensions through primary text.

The exposure is not abstract. The Audit produces readings that can be submitted as evidence against named regulatory frameworks — eleven in primary scope, each in force or dated to commence. Mapping is explicit, not interpretive: every framework routes to specific dimensions through specific instrument questions, anchored to primary regulatory text.

Members are routed by sector × jurisdiction at intake.

app.kn0w.co / methodology / mapping
Regulatory Mapping · Primary Scope
In scope
Routed by sector × jurisdiction
Frameworks anchored to primary regulatory text
Frameworks
11
FrameworkAnchorStatus
APRA FARs21(1)(c)/(d) reasonable-steps test, operationalised by APRA's 30 April 2026 Letter to Industry on AIIn force
APRA CPS 230Operational risk management, paragraph 51 MSP registerIn force since 1 July 2025
ASIC s912AEfficiently, honestly and fairly, anchored by REP 798 (29 October 2024)In force
FCA SM&CRSenior Managers reasonable-steps test, SoR-by-SoR allocationIn force
FCA Consumer DutyPrinciple 12 outcomes test, FCA April 2024 AI UpdateIn force
FCA SYSC 15AOperational resilience, written self-assessment, governing-body approvalIn force
TGA SaMDTherapeutic Goods Act 1989, AI-enabled software as a medical deviceIn force
MHRA SaMDMedical Devices Regulations 2002, AI Airlock regulatory sandboxIn force
Privacy Act 1988APP 1.7–1.9 ADM transparency (Privacy and Other Legislation Amendment Act 2024)Commences 10 December 2026
UK GDPR / DUAA Articles 22A–DSafeguards-operational test for solely-automated significant decisionsIn force from 5 February 2026
Equality Act 2010Section 19 indirect discrimination, provision, criterion or practiceIn force
kn0w · Regulatory mappingMapping is explicit, not interpretive

Most frameworks route primarily through governance and oversight — accountability is overwhelmingly named at senior individual level across the AU and UK regimes. The Equality Act 2010 and FCA Consumer Duty both route primarily through outcome tracking, because the section 19 indirect-discrimination test and the Consumer Duty good-outcomes test are fundamentally outcome tests on protected groups and retail customers respectively. The TGA framework routes through governance and AI tool deployment as co-primary, because the regulator’s evidentiary frame demands model-level disclosure of training data, statistical methodology, and demographic representation. The methodology routes each regulator’s question to the dimensions that match the regulator’s actual evidentiary demand, rather than forcing every framework to a single canonical routing.

Mapping distinguishes obligations that are in force, regulator commentary signalling intent (thematic reviews, sandbox findings, speeches), and consulted-but-not-yet-in-force proposals. Each obligation routed in a Statement is stamped with its status. The audit does not treat soft signal as hard rule.

Frameworks not currently in scope are tracked against documented promotion triggers — for example, a regulator publishing AI-specific guidance, or a public enforcement action turning materially on AI-driven evidence. Members operating into EU markets are subject to the EU AI Act in addition to the AU and UK frameworks; the Statement names which evidentiary basis each finding supports.

04 — The instrument

kn0w is structurally an institutional issuer — the same class of institution as a credit rating agency or a financial audit firm — adapted for the AI governance question regulated companies now have to answer.

Six dimensions. Two channels. Measured twice.

The kn0w Audit measures AI accountability posture across six dimensions, each through two channels. Measuring each dimension twice, from two perspectives, is a structural device this methodology calls dimensional parallelism. Session 0 captures the CEO's perception across all six dimensions at company-wide level; Sessions 1 through 6 capture function-head reporting of actual practice across the same six. Every Session 0 question has a corresponding Sessions 1–6 counterpart measuring the same construct, so the Gap reports real divergence rather than phrasing artefacts. Each dimension's gap is weighted by the headcount of the function reporting it.

Written intake carries the factual and quantitative half of the instrument; the CEO completes a two-stage company intake before the engagement begins, and each function head completes a structured pre-session questionnaire before their voice session. Voice carries the perception and judgement half — Session 0 with the CEO and Sessions 1 through 6 with the heads of Technology, Compliance & Risk, Operations, Finance, Growth & Revenue, and Customer Success. Sessions run within regional infrastructure, end-to-end.

D · 01
Workflow Automation Rate
The proportion of a function's core workflows that run with an AI or automation component rather than manual execution.
D · 02
AI Tool Deployment
The breadth, category, and deliberateness of AI tooling running in production across each function.
D · 03
AI Literacy Level
The capability of each function to evaluate AI tools critically, identify failure modes, and make informed decisions about AI adoption.
D · 04
Governance and Oversight
The documented policies, accountability ownership, testing regime, and incident response governing AI use across the organisation.
D · 05
AI Investment Spend
The annual AI investment in USD, normalised per function headcount — capturing AI tooling, platform and compute, allocated AI-headcount cost, and implementation.
D · 06
Outcome Tracking
The systematic measurement of AI outputs, errors, cost, and business impact.

Dimensions are ordered descending by scoring weight per Technical Architecture v4.5 §4, which carries the locked codebase contract. Dimension strings, ordering, and weights are governed by Tech Arch §4 as the senior source of truth.

The issued Statement carries a reading per dimension and a composite reading at the company level, reported as a band — Minimal, Early-stage, Systematic, or Embedded — alongside a cohort percentile, benchmarked against the peer cohort described in §5. Dimension weights are fixed across every issued artefact and are not published. Where the cohort meets the coefficient threshold, the operative artefact also carries a dollarised exposure figure — a structural estimate of recoverable annual productivity exposure attributable to the governance and oversight gaps identified.

05 — Peer dataset

A peer dataset no incumbent is built to hold.

The dataset is consented, de-identified, and derived from how each member actually operates — pooled under a single data-contribution agreement and held as one asset. Its exclusivity is structural, not competitive: a firm that also sells advisory work, remediation, or governance software cannot be the independent issuer of a finding against it, and a partner-signed audit cannot be the same instrument issued the same way every time. kn0w sells neither side of that conflict. The dataset compounds with every audit issued, on a contractual and anonymisation architecture built for contribution from the first engagement — which is why standing is the condition of being in it.

The dataset is held in regional AWS boundaries: Sydney for Australian engagements, London for UK engagements. Standing is required for the Statement to be benchmarked.

The dataset is structured along three cohort axes: sector (FinTech or HealthTech), jurisdiction (Australia or United Kingdom), and staff band (50–100, 101–150, 151–200 — the primary cohort, 50–200 staff; a secondary band at 201–500 is captured but resolves only when it independently reaches the k=5 floor).

The dataset operates at a k-anonymity floor of k=5 from the first audit. Every percentile query resolves against at least five peer companies in the matching cohort, or it does not resolve. In the early operating period — before every cohort reaches k=5 — some queries return insufficient peer data in your cohort rather than a percentile. The dataset refreshes quarterly.

k=5
Anonymity floor from the first audit; queries below this threshold do not resolve
2
Regional AWS boundaries — Sydney ap-southeast-2, London eu-west-2
2
Sectors in primary scope — FinTech and HealthTech
Quarterly
Dataset refresh cadence across every cohort axis
06 — Bias mitigation

Two bias risks. Three structural controls.

Every audit instrument is exposed to two bias risks: respondents anchoring their answers toward what a good organisation would report, and respondents drifting between cycles in ways that create artificial consistency. A fourth control — dimensional parallelism — is covered in §4 above.

Risk 01

Social desirability

Respondents anchor toward what a good organisation would report.

Risk 02

Longitudinal drift

Respondents drift between cycles in ways that create artificial consistency.

controlled by

01
The Elicitation Principle
Every perception question is tested against one rule before it enters the instrument: does the phrasing, scale, or framing signal what a good organisation would answer? If yes, the question is rewritten and re-tested.
02
Two-channel architecture
The split between written and voice is itself a bias control. Factual and quantitative questions are delivered in writing; perception and judgement questions are delivered in voice. A factual question delivered in voice invites estimation; a perception question delivered in writing invites the polished answer the rule is designed to defeat. The split is structural.
03
Six longitudinal controls
Applied to every Quarterly Review and every Annual Statement.
Temporal anchoring · Behavioural specificity · Randomised question order · Anchor question consistency · Social desirability framing · Longitudinal respondent consistency
07 — Discipline

What we verify. Where data lives. What this is not.

The boundary conditions of the instrument. Each Statement carries these sections verbatim near the end of the document; the marketing page describes them once.

Verification Status
Every regulatory claim is traced, corroborated, or flagged.

Every regulatory claim in the Statement is traced to a primary source, corroborated by secondary where the primary was inaccessible, or flagged as interpretation where the primary source is silent.

Internal integrity ledger · operational, not published
Data handling
Audit data is held in regional AWS boundaries.

Sydney (ap-southeast-2) for Australian engagements; London (eu-west-2) for UK engagements. Raw member-identifiable data does not leave its home region. Anonymisation runs through a dedicated pipeline — the single permitted crossing point — before any cohort query resolves. The Data Contribution Agreement names both parties and is signed once per engagement.

  • Controller · KN0W PTE. LTD. (Singapore · UEN 202615303G)
  • Sub-processor · kn0w LLC (Wyoming)
  • Retention · standing plus twelve months
  • Session audio · deleted within thirty days
SOC 2 Type II · ISO 27001 · in active implementation · neither yet certified
Limitations
Not a rating. A reading.

The Audit is a fixed-scope instrument. It measures what the six dimensions describe, against the peer cohort the member falls into.

  • Does not evaluate the technical performance of specific AI models.
  • Does not issue legal advice.
  • Does not certify individual AI systems or tools.
  • Does not produce a risk register, policy library, or implementation plan.
Issued, then reissued · never amended in place

Point-in-time issuance

Every artefact kn0w issues is issued at a point in time. Neither the founding Statement nor any Annual Statement is a continuous rating, and neither is amended to reflect the member’s subsequent state. The lifecycle admits three distinct version-bumping events: amendment (defect-driven only), supersession by Annual Statement (calendar-cadence at the institutional anniversary), and member-commissioned re-Audit (member-triggered, off-cycle, following a material change event). Issued, then reissued — amended only to correct defects, transparently versioned. This is the same discipline that governs ratings agencies, audit firms, and certification bodies: an issued Statement records the member’s posture as measured on the date stamped in its identifier, not a rolling guarantee that moves with them afterward.

08 — Engagement shape

One cycle. Identical for every member.

Standing follows a fixed annual cycle. The founding kn0w Audit combines written intake and seven voice sessions, and issues the founding Statement. Three Quarterly Reviews at months 3, 6, and 9 are written-intake only — no voice; they produce indicative dimension movement against the operative artefact baseline and never amend or supersede it. The Annual Statement at month 12 is a full re-engagement that issues under the same hallmark and supersedes the prior operative artefact. Across a standing year, the member encounters written intake at every issuance event and voice sessions at the founding Audit and the Annual Statement.

4wk
kn0w Audit — founding engagement, written intake plus seven voice sessions
3
Quarterly Reviews — months 3, 6, 9, written-intake only
1
Annual Statement — month 12, supersedes the prior operative artefact
7
Voice sessions per founding Audit and per Annual Statement
09 — Issuance

Every Statement is issued under the hallmark.

Every founding Statement and every Annual Statement is issued under the kn0w hallmark, stamped with the four-part identifier: kn0w / 000142 / 2026-05-23 / v1.2 — the issuing party, the sequence number, the date of issue, and the artefact version. The hallmark and the identifier together constitute the issuance mark — the institutional record of what was issued, by whom, and when. No natural person signs; issuance is by KN0W PTE. LTD. under the hallmark, against the published methodology under which each artefact issues.

The sequence number is shared across the member’s institutional relationship: the same number appears on the founding Statement, on every Annual Statement that supersedes it, and on every member-commissioned re-Audit.

Issued by KN0W PTE. LTD.
under the kn0w hallmark

Commission a Statement.

The gap between what you believe and what you could prove does not close on its own. kn0w issues the Statement that names it — the per-dimension reading of where you stand, on the record. Fixed scope. Fixed price. One engagement. Four weeks. Issued under the kn0w hallmark, stamped with a unique identifier.