Two judgments.
One blind spot.
A payment agent and its checker trust the same incorrect record. Their agreement is dependent. An approved payment can still be wrong.
Separate roles do not make evidence independent.
SYSTEMIC AGENT RISK / FINANCIAL INSTITUTIONS
KYA = Know Your Agent. Knowing the individual agent is necessary. Understanding the system it enters is the next risk question.
We examine whether the combined system boundary actually holds.
Removing a human approval, expanding authority or connecting workflows? Yesterday’s approval may no longer describe the exposure.
SYSTEMIC EXPOSURE REVIEW
One consequential workflow.
One autonomy decision.
Know the agent. Question the system.
Examine the collective boundaryEach may release up to $10M. Two have released $8M each; a third proposes a separate batch of the same amount.
THE CONTROL QUESTION
Component-level control does not establish system-level control.
Systemic agent risk is the potential for financial or operational harm arising from how autonomous agents’ authority, dependencies and actions combine. The unit of review should match the exposure.
HYPOTHETICAL / THREE DISTINCT PAYMENT BATCHES
One institution. One release window. A $20M commitment cap. Each separate $8M batch passes a $10M local limit. Amounts represent release commitments—not losses.
LOCAL LIMITS: PASSSYSTEM BOUNDARY: EXCEEDED
All three batches commit. The $24M total exceeds the intended $20M boundary by $4M, although each local limit passes.
Nothing has to fail locally for exposure to exceed the intended system boundary.
The arithmetic is simple.
Establishing the right boundary is harder.
Which actions, authorities, dependencies and controls belong together? What stops a commitment before it exceeds the boundary? What changes when a shared assumption changes?
How AgentRisk examines itWHY NOW / YOUR NEXT AUTONOMY CHANGE
Removing approvals, expanding permissions or changing shared dependencies can change whether the existing boundary remains defensible.
Choose a situation you recognize. This reveals a control question—not a diagnosis.
What prevents an unacceptable commitment before a person can intervene?
Examine precommitment limits, interruption and the authority already delegated downstream.
Examine this changeWho owns the combined limit, and where is it enforced?
Examine overlapping permissions, concurrent actions and the scope of each limit.
Examine this changeCan one workflow change the state another relies upon?
Examine shared records, downstream commitments and sequential actions—even without direct agent-to-agent communication.
Examine this changeAre the executor and checker still independent if their shared model, source or service is wrong?
Examine correlated judgments, common controls and fallback behavior.
Examine this changeWho defines its scope, time window and accountable owner?
Start by defining what the institution intends to contain and which evidence would show that containment.
Define a review boundaryHOW AGENTRISK EXAMINES IT
We combine systemic-risk methodology, a working analytical engine and financial-institution risk experience to examine one consequential workflow. Client evidence and control tests determine what the analysis can establish.
ALONGSIDE YOUR RISK TEAM
Operational Risk, Model Risk, AI Governance, Cyber and Internal Audit retain their roles. AgentRisk adds a focused examination of relationships, collective boundaries and interaction-driven exposure across their review scopes.
The additional value: a research-derived method, engine-supported analysis where it fits, a credible comparator and targeted control tests—connected to one autonomy decision.
Name the decision and accountable owner. Map agents, humans, models, tools, data, permissions, dependencies and controls. Check methodological fit.
Client evidence + institutional context.Structure inputs for the engine where appropriate. Compare supported scenarios against a credible baseline. Challenge assumptions and trace plausible consequences.
Engine analysis + expert challenge.Examine whether relevant controls interrupt the path—and whether their evidence is independent. Agree access and test conditions; record what remains unknown.
Control response + evidence quality.Produce a Boundary Stress Profile and Autonomy Decision Record. Identify conditions, owners, escalation and changes that trigger reassessment.
Evidence for an institutional decision.RESEARCH → METHODOLOGY → WORKING ENGINE
Guy Burstein, an AgentRisk team member, developed systemic-risk methodology through his academic and PhD research and operationalized it in a working two-module analytical engine.
His role sits inside the methodology: how inputs are structured, interactions are examined and results are challenged. Financial-institution risk, controls and audit experience shapes how we apply that analysis.
ORGANIZATIONAL APPLICATION
The underlying methodology has been applied in organizational settings in Israel as part of Guy’s research. That experience informs the work; it does not establish validation for autonomous banking systems.
Engine existence and organizational application are team-confirmed. This page does not present an independently reproduced engine run or a documented client result.
RESEARCH PROVENANCE / EXACT EVIDENCE STATES
A Geometric Vector Framework for High-Dimensional Interaction Modeling Applications to Systemic Risk Using Dot and Cross Product InvariantsGuy Burstein · August 2026 · public preprint ↗Guy reports acceptance for forthcoming publication in Risks. The linked version is the public preprint reviewed for this site; formal publication has not been verified here.
EARLIER PEER-REVIEWED RESEARCH
Uncertainty Reduction in Operational Risk Management ProcessRisks · 2024 · co-authored by Guy Burstein and Inon Zuckerman ↗ Deconstructing Risk Factors for Predicting Risk Assessment in Supply Chains Using Machine LearningJournal of Risk and Financial Management · 2023 · both authors ↗Inon Zuckerman ↗ contributes AI and autonomous-agent research expertise. Academic collaboration informs dependence analysis, experimental design, uncertainty and quantitative challenge.
Affiliations and publications imply no institutional endorsement, predictive accuracy or validation of the commercial KYARisk offering.
WHAT THE ENGINE ADDS
Where its method fits, the engine supports analysis of interactions between structured risk factors. We examine what that analysis reveals or prioritizes beyond ordinary aggregation or a competent existing review.
A result is interpreted against its inputs and assumptions. It does not automatically establish a causal path, a financial loss or an effective control.
See how analysis becomes a decisionSYSTEMIC EXPOSURE REVIEW / DESIGN-PARTNER ENGAGEMENT
We examine what component-level reviews may leave between them: shared dependencies, combined authority, correlated actions and control gaps.
One bounded investigation combines the research-derived method, supported engine analysis, client evidence and controlled testing. The aim is evidence to approve, constrain, test further or defer the next autonomy decision.
Delivered by AgentRisk through KYARisk.
One autonomy decision, a defined boundary and an accountable institutional owner.
Workflow, authorities, limits, dependencies, control information and available logs. Agree access and testing separately.
A Boundary Stress Profile and Autonomy Decision Record, with conditions, ownership and reassessment triggers.
WORKS WITH YOUR EXISTING CONTROL STACK
Designed to work with evidence from existing GRC, SIEM, workflow and agent-orchestration environments. The review does not require replacing the institution’s current control stack.
Controls, ownership, approvals, logs, permissions, execution paths, transactions, limits and workflow state.
We structure the relevant system, apply the methodology and analytical engine where appropriate, and challenge whether controls interrupt the path.
The outputs return to the institution’s existing governance and approval process.
Start with a 20-minute scope-and-fit conversation. Assessment timing follows the evidence, access and testing required; no enterprise transformation program is needed to examine one workflow.
A useful diagnostic should do more than find issues. It should either change the autonomy decision—or establish why the existing exposure boundary remains defensible.
Why bring AgentRisk alongside your team? To apply a specialist systemic-risk method and analytical engine, challenge the result against a credible baseline, and connect control evidence to the specific decision your institution needs to make.
Discuss a Systemic Exposure ReviewWHAT THE INDIVIDUAL REVIEW MAY LEAVE UNSEEN
An agent’s permissions tell you what it can do. Its relationships help reveal what the system can cause.
The connection can carry the risk. A shared record aligns judgments. A release window combines authority. An approval service connects otherwise separate workflows.
One agent can change the state another consumes. Errors can reach payments or settlement without a direct agent-to-agent message.
An indirect path is still a path.
A payment agent and its checker trust the same incorrect record. Their agreement is dependent. An approved payment can still be wrong.
Separate roles do not make evidence independent.
Each release passes its $10M limit. Three $8M actions exceed an intended $20M total. No local malfunction is needed.
Who controls the combined authority?
One approval service protects three financial workflows. Its outage blocks unauthorized actions but can delay settlement. Risk is displaced, not simply removed.
Does the fallback preserve control and continuity?
Predefined conceptual examples, not simulations of your institution. Amounts are illustrative. Green marks represent selected component checks, not a declaration of safety.
TWO CONNECTED OUTPUTS
The Boundary Stress Profile is the analytical foundation. The Autonomy Decision Record states what management decides, why, under which conditions—and when that decision must be revisited.
The institution retains risk acceptance and approval. Control owners supply evidence; independent challenge remains distinct from operating the control.
01 / ANALYTICAL + EVIDENTIAL FOUNDATION
02 / EXECUTIVE + GOVERNANCE CONCLUSION
EVIDENCE DISCIPLINE
We distinguish established facts from inference, modeled outcomes and unknowns.
Confident about what can be examined. Explicit about what the evidence cannot establish.
A research direction, not a prediction engine. We do not certify regulatory compliance.
FOUR LEGITIMATE RESULTS
Evidence supports the tested boundary under stated conditions.
Proceed only with specified limits, checkpoints or other conditions.
The identified collective exposure is not adequately contained.
Further evidence or testing is needed for a defensible decision.
Research → Examine → Decide → Act → Reassess
What is happening, and what evidence supports it?
KYARISK.COM / YOU ARE HERESystemic exposure & decisionsWhat can this workflow collectively cause, and what would support greater autonomy?
AGENTRISK.IOEngagement, assurance & actionAct on findings, strengthen controls and revisit the decision as the workflow changes.
One provider: AgentRisk. KYARisk is the front door for systemic-agent-risk work.
AN AUTONOMY DECISION IN THE NEXT 90 DAYS?
Start with a 20-minute scope-and-fit conversation: the workflow, the autonomy change, the decision timeframe—and whether a Systemic Exposure Review is appropriate.
Start your enquiry Systemic Exposure Review — delivered by AgentRisk. Send your enquiry here on KYARisk.Bring the decision your institution needs to defend.
SYSTEMIC EXPOSURE REVIEW — DELIVERED BY AGENTRISK