KYARiskBY AGENTRISK

SYSTEMIC AGENT RISK / FINANCIAL INSTITUTIONS

KYA = Know Your Agent. Knowing the individual agent is necessary. Understanding the system it enters is the next risk question.

Individually
permitted.
Collectively
exposed.

We examine whether the combined system boundary actually holds.

Removing a human approval, expanding authority or connecting workflows? Yesterday’s approval may no longer describe the exposure.

SYSTEMIC EXPOSURE REVIEW

One consequential workflow.
One autonomy decision.

Discuss a Systemic Exposure Review

Know the agent. Question the system.

Examine the collective boundary
THREE LOCAL REVIEWS. ONE SYSTEM.ILLUSTRATIVE · NOT LIVE DATA
Three permitted payments above one institutional exposure Hypothetical example: three agents may each release $8M within a $10M limit. Together their $24M release exceeds an intended $20M aggregate boundary by $4M. Agent A $8M PERMITTED Agent B $8M PERMITTED Agent C $8M PROPOSED WHAT DOES THE REVIEW LEAVE OUT? Shared transaction record TWO JUDGMENTS · ONE SOURCE Error reaches payment
Component checksShared dependency
01 / 03

Every agent has a limit.

Each may release up to $10M. Two have released $8M each; a third proposes a separate batch of the same amount.

THE CONTROL QUESTION

Which control keeps their combined actions inside the approved boundary?
What evidence shows that it works?

Component-level control does not establish system-level control.

Systemic agent risk is the potential for financial or operational harm arising from how autonomous agents’ authority, dependencies and actions combine. The unit of review should match the exposure.

HYPOTHETICAL / THREE DISTINCT PAYMENT BATCHES

Let the control prove its value.

One institution. One release window. A $20M commitment cap. Each separate $8M batch passes a $10M local limit. Amounts represent release commitments—not losses.

BATCH A / LOCAL PASS$8MCommitted
BATCH B / LOCAL PASS$8MCommitted
BATCH C / LOCAL PASS$8MCommitted
COMMITTED IN WINDOW$24M$20M cap · $4M over

LOCAL LIMITS: PASSSYSTEM BOUNDARY: EXCEEDED

All three batches commit. The $24M total exceeds the intended $20M boundary by $4M, although each local limit passes.

Nothing has to fail locally for exposure to exceed the intended system boundary.

The arithmetic is simple.
Establishing the right boundary is harder.

Which actions, authorities, dependencies and controls belong together? What stops a commitment before it exceeds the boundary? What changes when a shared assumption changes?

How AgentRisk examines it

WHY NOW / YOUR NEXT AUTONOMY CHANGE

Same permissions.
Different system.
Different exposure.

Removing approvals, expanding permissions or changing shared dependencies can change whether the existing boundary remains defensible.

Choose a situation you recognize. This reveals a control question—not a diagnosis.

We are removing human approval.

What prevents an unacceptable commitment before a person can intervene?

Examine precommitment limits, interruption and the authority already delegated downstream.

Examine this change
We are increasing delegated authority.

Who owns the combined limit, and where is it enforced?

Examine overlapping permissions, concurrent actions and the scope of each limit.

Examine this change
We are connecting another autonomous workflow.

Can one workflow change the state another relies upon?

Examine shared records, downstream commitments and sequential actions—even without direct agent-to-agent communication.

Examine this change
We are changing a shared dependency.

Are the executor and checker still independent if their shared model, source or service is wrong?

Examine correlated judgments, common controls and fallback behavior.

Examine this change
We are unsure where the collective boundary sits.

Who defines its scope, time window and accountable owner?

Start by defining what the institution intends to contain and which evidence would show that containment.

Define a review boundary

HOW AGENTRISK EXAMINES IT

Research-derived analysis.
A decision you can defend.

We combine systemic-risk methodology, a working analytical engine and financial-institution risk experience to examine one consequential workflow. Client evidence and control tests determine what the analysis can establish.

ALONGSIDE YOUR RISK TEAM

Operational Risk, Model Risk, AI Governance, Cyber and Internal Audit retain their roles. AgentRisk adds a focused examination of relationships, collective boundaries and interaction-driven exposure across their review scopes.

The additional value: a research-derived method, engine-supported analysis where it fits, a credible comparator and targeted control tests—connected to one autonomy decision.

  1. 01 / DEFINE + MAP

    Establish the boundary.

    Name the decision and accountable owner. Map agents, humans, models, tools, data, permissions, dependencies and controls. Check methodological fit.

    Client evidence + institutional context.
  2. 02 / ANALYZE + CHALLENGE

    Examine the interactions.

    Structure inputs for the engine where appropriate. Compare supported scenarios against a credible baseline. Challenge assumptions and trace plausible consequences.

    Engine analysis + expert challenge.
  3. 03 / TEST + TRACE

    Test what contains them.

    Examine whether relevant controls interrupt the path—and whether their evidence is independent. Agree access and test conditions; record what remains unknown.

    Control response + evidence quality.
  4. 04 / DECIDE + REVISIT

    Make the decision explicit.

    Produce a Boundary Stress Profile and Autonomy Decision Record. Identify conditions, owners, escalation and changes that trigger reassessment.

    Evidence for an institutional decision.

RESEARCH → METHODOLOGY → WORKING ENGINE

There is analytical work
behind the question.

Guy Burstein, an AgentRisk team member, developed systemic-risk methodology through his academic and PhD research and operationalized it in a working two-module analytical engine.

His role sits inside the methodology: how inputs are structured, interactions are examined and results are challenged. Financial-institution risk, controls and audit experience shapes how we apply that analysis.

ORGANIZATIONAL APPLICATION

The underlying methodology has been applied in organizational settings in Israel as part of Guy’s research. That experience informs the work; it does not establish validation for autonomous banking systems.

Engine existence and organizational application are team-confirmed. This page does not present an independently reproduced engine run or a documented client result.

RESEARCH PROVENANCE / EXACT EVIDENCE STATES

A Geometric Vector Framework for High-Dimensional Interaction Modeling Applications to Systemic Risk Using Dot and Cross Product InvariantsGuy Burstein · August 2026 · public preprint ↗

Guy reports acceptance for forthcoming publication in Risks. The linked version is the public preprint reviewed for this site; formal publication has not been verified here.

EARLIER PEER-REVIEWED RESEARCH

Uncertainty Reduction in Operational Risk Management ProcessRisks · 2024 · co-authored by Guy Burstein and Inon Zuckerman ↗ Deconstructing Risk Factors for Predicting Risk Assessment in Supply Chains Using Machine LearningJournal of Risk and Financial Management · 2023 · both authors ↗

Inon Zuckerman ↗ contributes AI and autonomous-agent research expertise. Academic collaboration informs dependence analysis, experimental design, uncertainty and quantitative challenge.

Affiliations and publications imply no institutional endorsement, predictive accuracy or validation of the commercial KYARisk offering.

WHAT THE ENGINE ADDS

Repeatable analysis.
Explicit assumptions.

Where its method fits, the engine supports analysis of interactions between structured risk factors. We examine what that analysis reveals or prioritizes beyond ordinary aggregation or a competent existing review.

A result is interpreted against its inputs and assumptions. It does not automatically establish a causal path, a financial loss or an effective control.

See how analysis becomes a decision

SYSTEMIC EXPOSURE REVIEW / DESIGN-PARTNER ENGAGEMENT

Bring a workflow.
Bring a decision.

We examine what component-level reviews may leave between them: shared dependencies, combined authority, correlated actions and control gaps.

One bounded investigation combines the research-derived method, supported engine analysis, client evidence and controlled testing. The aim is evidence to approve, constrain, test further or defer the next autonomy decision.

Delivered by AgentRisk through KYARisk.

THE SCOPEOne consequential workflow.

One autonomy decision, a defined boundary and an accountable institutional owner.

YOU PROVIDEEvidence of how it operates.

Workflow, authorities, limits, dependencies, control information and available logs. Agree access and testing separately.

YOU RECEIVEAnalysis connected to a decision.

A Boundary Stress Profile and Autonomy Decision Record, with conditions, ownership and reassessment triggers.

WORKS WITH YOUR EXISTING CONTROL STACK

Use the evidence
you already have.

Designed to work with evidence from existing GRC, SIEM, workflow and agent-orchestration environments. The review does not require replacing the institution’s current control stack.

  1. 01 / EXISTING ENTERPRISE SYSTEMSGRC · SIEM · Agent/AI orchestration · Workflow/transaction systems

    Controls, ownership, approvals, logs, permissions, execution paths, transactions, limits and workflow state.

  2. 02 / KYA RISK ANALYSISBoundary · Authority · Dependencies · Interactions · Control evidence

    We structure the relevant system, apply the methodology and analytical engine where appropriate, and challenge whether controls interrupt the path.

  3. 03 / DECISION EVIDENCEBoundary Stress Profile · Autonomy Decision Record

    The outputs return to the institution’s existing governance and approval process.

Start with a 20-minute scope-and-fit conversation. Assessment timing follows the evidence, access and testing required; no enterprise transformation program is needed to examine one workflow.

DECISION QUALITY IS THE STANDARD
A useful diagnostic should do more than find issues. It should either change the autonomy decision—or establish why the existing exposure boundary remains defensible.

Why bring AgentRisk alongside your team? To apply a specialist systemic-risk method and analytical engine, challenge the result against a credible baseline, and connect control evidence to the specific decision your institution needs to make.

Discuss a Systemic Exposure Review

WHAT THE INDIVIDUAL REVIEW MAY LEAVE UNSEEN

They don’t have to talk.
They just have to
share something.

An agent’s permissions tell you what it can do. Its relationships help reveal what the system can cause.

The connection can carry the risk. A shared record aligns judgments. A release window combines authority. An approval service connects otherwise separate workflows.

One agent can change the state another consumes. Errors can reach payments or settlement without a direct agent-to-agent message.

Agent Ashared stateAgent B

An indirect path is still a path.

A / SHARED CONTEXT

Two judgments.
One blind spot.

A payment agent and its checker trust the same incorrect record. Their agreement is dependent. An approved payment can still be wrong.

Separate roles do not make evidence independent.

B / ACCUMULATED AUTHORITY

Within every limit.
Beyond the total.

Each release passes its $10M limit. Three $8M actions exceed an intended $20M total. No local malfunction is needed.

Who controls the combined authority?

C / CONTROL CONCENTRATION

A stronger check.
A shared point of failure.

One approval service protects three financial workflows. Its outage blocks unauthorized actions but can delay settlement. Risk is displaced, not simply removed.

Does the fallback preserve control and continuity?

Predefined conceptual examples, not simulations of your institution. Amounts are illustrative. Green marks represent selected component checks, not a declaration of safety.

A RELATED CONTROL TEST / AUTHORITY AFTER STOP

The agent has stopped.
Has its authority?

A stop command may halt new instructions without cancelling accepted work, delegated permissions or downstream commitments.

Containment has to follow the authority, not just the agent.

HYPOTHETICAL PAYMENT QUEUE / NO SHARED CANCELLATION

ORIGINATING AGENTActiveCan issue new instructions
ALREADY ACCEPTED DOWNSTREAM
Instruction 01 $8MInstruction 02 $8M
These instructions have left the agent’s control.
Two accepted instructions remain in the queue.

In this example, stopping the agent does not cancel instructions already accepted by the payment service.

Test the stop: does it reach the queue, delegated access and downstream execution—or only the originating agent?

TWO CONNECTED OUTPUTS

The evidence underneath.
The decision it supports.

The Boundary Stress Profile is the analytical foundation. The Autonomy Decision Record states what management decides, why, under which conditions—and when that decision must be revisited.

ProceedProceed with conditionsTest furtherConstrainDeferReassess after material change

The institution retains risk acceptance and approval. Control owners supply evidence; independent challenge remains distinct from operating the control.

AGENTRISK / KYARISKILLUSTRATIVE FORMAT · NOT ENGINE OUTPUT

01 / ANALYTICAL + EVIDENTIAL FOUNDATION

Boundary Stress Profile

Boundary
$20M aggregate commitments in one release window; three distinct batches, $10M local limits.
Scenario
Three concurrent $8M requests. Compare absent shared enforcement with an effective reservation.
Analysis / comparator
MODELED $24M without the guard; $16M committed and $8M held with it. Ordinary arithmetic is sufficient for this illustration.
Engine contribution
No engine result is asserted here. In a fitted assessment, attach versioned inputs, supported outputs, assumptions and a credible comparison.
Control evidence
UNKNOWN Actual reservation, retry, duplicate and cancellation behavior. The illustration does not test an institution’s control.
Residual consequence
A held batch can affect settlement or service. Containing one boundary does not establish overall safety.
Version the scope, scenarios, sources, analysis and control evidence.
EVIDENCE INFORMS THE DECISION
AGENTRISK / KYARISKILLUSTRATIVE · NOT A CLIENT RESULT

02 / EXECUTIVE + GOVERNANCE CONCLUSION

Autonomy Decision Record

Decision proposed
Remove human approval for the three locally permitted batches.
Illustrative decision
Test further. Retain the existing checkpoint. Establish that shared reservation holds under concurrent releases, retries and cancellation before increasing autonomy.
Ownership / escalation
Name the business owner of the combined exposure, control operator and independent challenger. Record unresolved evidence and the escalation route.
Decision conditions
Reference the Boundary Stress Profile, agreed test criteria, action owners and remaining settlement implications.
Reassess when
Authority, agents, models, limits, release windows or shared dependencies materially change.
A decision record, not a risk score or certificate.

EVIDENCE DISCIPLINE

The map is incomplete.
That belongs in the analysis.

We distinguish established facts from inference, modeled outcomes and unknowns.

Confident about what can be examined. Explicit about what the evidence cannot establish.

A research direction, not a prediction engine. We do not certify regulatory compliance.

Known
Supported facts about the workflow, authority and controls, with their sources and scope.
Observed
Behavior seen in a trace or test, under stated conditions. Observation is not proof of every possible outcome.
Hypothesized
A plausible interaction path that still needs evidence or testing.
Modeled
A result conditional on explicit assumptions and a defined system boundary.
Unknown
What we cannot yet establish—including paths, dependencies or behavior outside the available evidence.

FOUR LEGITIMATE RESULTS

A useful review can conclude
that the control holds.

01

Control holds

Evidence supports the tested boundary under stated conditions.

02

Control needs constraint

Proceed only with specified limits, checkpoints or other conditions.

03

Control is insufficient

The identified collective exposure is not adequately contained.

04

Evidence is insufficient

Further evidence or testing is needed for a defensible decision.

One provider: AgentRisk. KYARisk is the front door for systemic-agent-risk work.

AN AUTONOMY DECISION IN THE NEXT 90 DAYS?

Before you give the system
more autonomy,
what would change
your decision?

Start with a 20-minute scope-and-fit conversation: the workflow, the autonomy change, the decision timeframe—and whether a Systemic Exposure Review is appropriate.

Start your enquiry Systemic Exposure Review — delivered by AgentRisk. Send your enquiry here on KYARisk.

Bring the decision your institution needs to defend.

Learn more about AgentRisk

Optional: prepare a private conversation brief

SYSTEMIC EXPOSURE REVIEW — DELIVERED BY AGENTRISK

Tell us what is changing.

AgentRisk uses these details to respond and scope your enquiry. Do not include confidential customer records, credentials or sensitive transaction data. Privacy.