Know Your Agent (KY-A)
Govern AI across its entire lifecycle. KY-A ensures every AI initiative is identified, assessed, approved and continuously monitored — long before it reaches production.
Every AI system creates organisational risk
AI does not arrive through one door. It enters through pilots, vendor features, embedded models and business-led experiments — and most organisations cannot produce a complete list of where it is already running.
KY-A provides the governance framework that makes that inventory real: every AI system registered, classified by risk, assigned an owner, put through approval, and monitored once live.
Governance begins when an idea is created — not after AI is deployed.
What KY-A gives you
Ten governance capabilities delivered as one connected control environment, not ten disconnected tools.
AI Inventory
A single register of every AI system, model and agent in the organisation, with owner, purpose, data used and current lifecycle stage.
Risk Classification
Each system scored against defined criteria so oversight is proportionate to impact, in line with EU AI Act risk tiering.
AI Committee
Structured committee workflow with agendas, decisions and minutes captured as governance evidence rather than email threads.
Sandbox
A controlled environment for testing AI initiatives before any exposure to production data or customers.
Approval Workflows
Defined gates from idea to production, with the right approvers, criteria and a complete audit trail at each stage.
Agent Passport
A portable record for each AI agent: purpose, permissions, data access, controls, approvals and change history in one place.
Runtime Telemetry
Continuous monitoring of AI systems in production, so drift, failure and unexpected behaviour surface early rather than at audit.
Evidence
Every decision, approval and control test stored as evidence, ready for internal audit, the board and supervisors.
Human Oversight
Defined accountability and intervention points, so a named person remains responsible for consequential outcomes.
Policy Compliance
Continuous testing of AI systems against your internal AI policy and the regulatory obligations that apply to them.
Govern AI from idea to runtime
Identify
Capture every AI initiative in a central inventory from the moment it is proposed.
Classify
Assess risk and determine the governance, policy and oversight requirements that apply.
Govern
Route AI through defined approval workflows, committee review and controlled sandbox testing.
Monitor
Maintain continuous oversight through runtime telemetry, evidence, human oversight and policy compliance.
Aligned to the frameworks your supervisors test against
Controls are mapped once and the evidence is reused, so a single control test can satisfy obligations across several frameworks.
- ISO/IEC 42001 — AI management systems
- NIST AI Risk Management Framework
- EU AI Act — risk classification and obligations
- POPIA
- GDPR
- Your organisation’s internal AI policies
Know what your AI is actually doing.
Start with an inventory of the AI already running in your business. We will show you what KY-A registers, classifies and evidences from day one.