Specimen — fictitious illustration · no standing conferred kn0w / 000142 / 2026-05-23 / v2.1
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
kn0w
AI Accountability Audit
Statement
Issued toNorthbeam Pay Holdings Pty Ltd
ACN 636 274 014
Sydney, Australia
Addressed toThe Board of Directors
Northbeam Pay Holdings Pty Ltd
Alex Marlowe, Chief Executive Officer
Accountable Person under APRA FAR
Engagement windowAudit conducted 9 March 2026 to 15 April 2026
Issued 23 May 2026
Issued byKN0W PTE. LTD.
Singapore · UEN 202615303G

This document is a published specimen of the kn0w Statement format. The subject company, accountable person, evidence references, dimensional readings, peer cohort composition, and findings are fictional. No real entity is described. No standing is conferred by this document.

Issued, not advised.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
Board Summary

Northbeam deploys AI like the top of its cohort — and governs it like the bottom.

For the Board of Northbeam Pay Holdings Pty Ltd, and for Alex Marlowe, Chief Executive and Accountable Person under APRA FAR. This one-page summary carries the findings a board needs; the full Statement follows and governs.

Composite reading51Systematic · 47th percentile
Governance · D43418th percentile · weakest
CEO Visibility Gap−18governance over-read
Recoverable p.a.A$747Kfloor · as the gap closes

The reading (Systematic · 51) places the company on the 0–100 scale; the percentile (47th) places it against its peers — the two are independent measures, not one number read twice.

The finding to act on

The company's documented governance posture is over-read by 18 points — the largest visibility gap on this Audit — concentrated on the two AI deployments that operate without formal governance: the merchant onboarding KYC automation and the internal product-analytics LLM. The fraud detection regime is governed, and is the exception. Bringing the other two into governance is the Accountable Person's clearest reasonable-steps action under APRA FAR; this Statement and its evidence ledger stand as the contemporaneous record that the gap was identified and the cure commissioned.

What must happen · 90 days

1 · Day 30Establish a documented governance posture on the merchant onboarding KYC deployment. CPS 230 ¶46–61
2 · Day 60Establish a documented governance posture on the internal product-analytics LLM. CPS 230 ¶23–32
3 · Day 90Close the AI-literacy gap in Compliance & Risk and Finance. s912A

Each obligation stamps Red today, carries a defined cure path in the full Statement, and is re-read at the next Quarterly Review — the Annual Statement records what closed. The next issuance is a fresh immutable record of whether the work was done.

Issued, not advised. kn0w sells no advisory, implementation, or remediation — the finding carries no interest in selling the fix. This Statement may be relied upon, on a non-transferable basis, by the Board, by APRA, by lead institutional investors in the next equity round, and by the company's D&O and cyber insurers. It is immutable, versioned, and open to challenge under the Contested Findings Protocol — not invoked on this issuance.
The readThe Statement, the Reading Summary, the CEO Visibility Gap, the Dollarised Exposure, and the Required Actions — pages 2, 3, 5, 16, 17. The evidenceThe six dimensions, the peer dataset and benchmark, the regulatory mapping, the evidence ledger, the methodology, and the conditions of reliance — pages 4, 6–15, 18–21. A relier need take nothing on trust: every finding traces to the evidence here. Your reliersAPRA reads the regulatory mapping and evidence ledger (14, 15); your D&O and cyber insurers read the required actions and the contested-findings record (17, 20); a lead investor reads this summary and the exposure (16).
Board Summary · precedes Page 2KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
The Statement

KN0W PTE. LTD. has conducted the kn0w Audit of Northbeam Pay Holdings Pty Ltd and issues the following Statement on the evidence collected across seven structured voice sessions during the engagement window of 9 March 2026 to 15 April 2026.

The Issuer finds that Northbeam Pay Holdings reads at 51 on a composite basis across six dimensions of AI accountability, classifying the company in the Systematic band (51–75) of the kn0w dimensional scale.

The reading is bifurcated. Three dimensional readings sit in the Systematic band — AI tool deployment (71), outcome tracking (63), and workflow automation rate (58) — anchored by a real-time fraud detection regime that has operated under documented governance since 2023: model cards, monthly performance review, an incident log, and a decision-rights matrix between the model and human reviewers. The reading reflects artefacts presented within the engagement window; it does not attest continuous operating effectiveness since 2023. Three readings sit in the Early-stage band — AI literacy (38), governance and oversight (34), and AI investment spend (42). The governance reading is the largest finding on this Audit.

Two further production deployments do not share the fraud detection regime's posture. A vendor-supplied merchant onboarding KYC automation operates on a vendor model card alone, with limited training-data visibility and no contractual right to audit. An internal product-analytics LLM, placed into production in Q3 2025 by the Growth & Revenue function, was deployed without formal governance review and is treated as a productivity utility rather than a regulated system.

On the KYC and internal product-analytics LLM deployments, the documented control evidence diverges from peer cohort posture on the obligation themes APRA addresses in CPS 230 paragraphs 23–32 (operational risk management) and 46–61 (service provider management) — a reading against publicly stated supervisory expectations, not a legal compliance determination. The company's obligations under FAR s21(1)(c) and s21(1)(d), CPS 230, s912A, and APP 1.2 are mapped and stamped at page 14. The fraud detection deployment is the exception: it exhibits the documented controls absent from the remaining two deployments.

The Chief Executive over-reads the company's documented governance posture by 18 points — the largest visibility gap on this Audit — and over-reads leadership AI capability by 14, with both gaps concentrating in the functions where the ungoverned deployments operate.

The company carries an estimated A$747,000 in dollarised annual exposure on the governance conditions identified — a structural estimate of the annual productivity recoverable across the ungoverned functions were the governance gap closed, calculated against the kn0w productivity reference and the kn0w productivity-loss calibration. It is treated in full at page 16.

Against the kn0w peer cohort of 23 AU FinTech companies of 50–200 staff, the company places at the 47th percentile on a composite basis as of 15 April 2026 — below the cohort median. Its composite reading of 51 sits in the Systematic band (51–75) of the dimensional scale; the two measures are independent and are treated separately at pages 3 and 12.


This Statement is issued on a fixed-scope basis under the kn0w methodology. It is issued, not advised. It is not an endorsement, an accreditation, or a regulatory approval, and kn0w is not endorsed, accredited or approved by any regulator. Conditions of reliance are stated under Scope & Reliance.

Page 2 of 21KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
Reading Summary
Dimension score · six readings, 0–100, weighted to one composite
51

Composite reading.

Systematic · 51–75 · 47th cohort percentile
0255075100

The composite is the weighted sum of the six dimensional readings, produced deterministically — the same inputs always produce the same output. Deterministic production covers reading calculation, banding, percentile assignment, and template selection from fixed rules; it is applied to evidence collected across seven structured voice sessions during the engagement window. Each dimensional reading is the company's reading against a fixed dimension construct on a 0–100 scale. The dimensions are weighted differently under a distribution that is fixed and calibrated across all Audits; the exact weights are held as methodology and are not disclosed.

CodeDimensionReadingBand
D1Workflow automation rate58Systematic
D2AI tool deployment71Systematic
D3AI literacy level38Early-stage
D4Governance and oversight34Early-stage
D5AI investment spend42Early-stage
D6Outcome tracking63Systematic
Composite51Systematic

The composite of 51 is bifurcated: three dimensional readings sit in the Systematic band and carry the composite upward; three sit in the Early-stage band and pull it downward. The bifurcation is concentrated by deployment — the fraud detection regime carries the strong readings; the merchant onboarding KYC and internal product-analytics LLM deployments carry the weak readings.

Classification bands

BandCompositeInterpretation
Embedded76–100Embedded AI practice; measurable outcomes; top of the peer benchmark.
Systematic51–75Systematic adoption underway; multiple dimensions active and expanding. this Statement
Early-stage26–50Early-stage adoption; isolated initiatives, no systematic programme.
Minimal0–25Minimal AI adoption; significant gap to peer median across most dimensions.

The four bands classify the composite reading on the 0–100 scale and are fixed across all Audits. Band placement (the reading against the scale) is distinct from the cohort percentile at page 12 (the reading against peers). Embedded is the strongest; Minimal is the weakest.

Page 3 of 21KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
Dimension Constructs

What each dimension reads.

Each of the six dimensions reads against a fixed construct. The construct defines what the dimension measures and at what unit of analysis. Constructs are fixed across all Audits and are not revised mid-issuance.

D1
Workflow automation rate. The proportion of a function's core workflows that run with an AI or automation component rather than manual execution. Measured at the function level and aggregated to the company level.
D2
AI tool deployment. The breadth, category, and deliberateness of AI tooling running in production across each function. Distinguishes tools embedded in workflow from tools adopted without formal evaluation.
D3
AI literacy level. The capability of each function to evaluate AI tools critically, identify failure modes, and make informed decisions about AI adoption.
D4
Governance and oversight. The documented policies, accountability ownership, testing regime, and incident response governing AI use across the organisation. D4 is the dimension most directly mapped to regulatory obligation.
D5
AI investment spend. The company's annual AI investment, normalised per function headcount and banded before storage. Reads what the company actually commits to AI — not what leadership believes it commits.
D6
Outcome tracking. The systematic measurement of AI outputs, errors, cost, and business impact. Captures whether the company measures what AI deployments do in production, not whether the company believes they perform.
Page 4 of 21KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
CEO Visibility Gap

The signed delta between perception and evidence.

Signed delta per dimension · headcount-weighted function evidence minus Session 0 perception

The CEO Visibility Gap reads as the signed delta between the Chief Executive's perception captured in Session 0 and the headcount-weighted function-head reading captured in Sessions 1 through 6, calculated per dimension: Gap(D) = Σ( function(D, f) × headcount(f) ⁄ total headcount ) − perception(D). Worked on D4: headcount-weighted function evidence 34; Session 0 perception 52; gap −18. Session 0 evidence is isolated from Sessions 1–6 evidence per the kn0w methodology. A negative delta reads that the Chief Executive over-estimates the company's reading on that dimension — the blind spot; a positive delta reads under-estimation. The Gap is an evidence-led instrument, not a scored dimension.

CodeDimensionWhere the gap concentrates
D1Workflow automation rateOperations and Customer Success
D2AI tool deploymentAligned across all functions
D3AI literacy levelCompliance & Risk; Finance
D4Governance and oversightAcross all regulated deployments
D5AI investment spendUncategorised function-budget spend
D6Outcome trackingOutside fraud detection regime

The pattern reads consistently: the Chief Executive's perception is calibrated to the fraud detection regime — where the documented posture is in place — and is extrapolated outward to deployments where the equivalent posture is not in place. The Chief Executive sees adoption clearly (D2 aligned at zero), over-reads control, and under-reads activity and spend. Named on the evidence, the gap is not an indictment but the starting point of the Accountable Person's reasonable-steps record: it identifies precisely where control was believed to exist and does not, and the Required Actions at page 17 convert that into the dated cure the record requires.

Page 5 of 21KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
Dimensional Reading
58

D1 · Workflow Automation Rate

Systematic · 51–75 · CEO gap +6

What moves it. Raised by core workflows running with AI or automation components; depressed by manual execution of core workflows, regardless of governance posture.

The reading. Northbeam reads at 58, seven points above the lower band boundary, consistent across function-head evidence in Operations, Customer Success, Compliance & Risk, and Finance.

The finding. Operations and Customer Success carry the strongest contribution — AI-assisted workflows across merchant onboarding queue triage, dispute intake routing, and internal ticket categorisation. The fraud detection regime contributes a structural automation layer across payments operations, with documented decision rights between automated output and human reviewer on the AUSTRAC reporting workflow. Finance reads moderate automation on month-end reconciliation and invoice processing; Growth & Revenue reads automation on lead-scoring and the internal product-analytics LLM addressed at D4.

The reading does not, on its own, describe the governance posture of the workflows it counts. Two of the three production AI deployments named in this Audit contribute to the D1 reading without contributing to the D4 governance reading. Automation breadth does not, in this Audit, sustain governance breadth.

Peer standing · 23 AU FinTech · 50–200 staff 64thpercentile
← Behind peersPeer medianAhead of peers →
Reads 58 — ahead of the cohort median. Better than 64% of the 23 AU FinTech peers at 50–200 staff.
Page 6 of 21KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
Dimensional Reading
71

D2 · AI Tool Deployment

Systematic · 51–75 · CEO gap 0

What moves it. Raised by breadth, category diversity, and deliberate evaluated adoption; depressed by tools adopted without formal evaluation.

The reading. The strongest dimensional reading on this Audit, four points below the upper band boundary.

The finding. Three production deployments anchor the reading. A real-time fraud detection ensemble model — in-house, in continuous operation since 2023, integrated into the merchant authorisation pipeline. A merchant onboarding KYC automation — vendor-supplied, deployed in the onboarding workflow. An internal product-analytics LLM — placed into production in Q3 2025 by Growth & Revenue against company product telemetry and merchant transaction patterns. The category mix spans in-house, vendor-supplied, and general-purpose LLM deployments across three functional perimeters.

The D2 reading does not read on governance posture. Each of the three deployments operates under a different posture, addressed at D4. The breadth captured here is a structural condition of the company's AI exposure, not yet of its AI accountability.

Peer standing · 23 AU FinTech · 50–200 staff 78thpercentile
← Behind peersPeer medianAhead of peers →
Reads 71 — well ahead of the cohort median. Better than 78% of the 23 AU FinTech peers, the strongest peer standing on this Audit.
Page 7 of 21KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
Dimensional Reading
38

D3 · AI Literacy Level

Early-stage · 26–50 · CEO gap −14

What moves it. Raised by demonstrated capability to evaluate models, identify failure modes, and decide independently of vendor representations; depressed by operational use without evaluative capability.

The reading. In the Early-stage band (26–50), thirteen points below the Systematic boundary, and weak across the Audit.

The finding. Literacy concentrates in the Technology function, which owns and operates the in-house fraud detection model. Outside Technology, capability density reads at less than half. Compliance & Risk evidences limited capability to evaluate the KYC vendor's model against independent benchmarks, to identify failure modes in the vendor's training data, or to make adoption-stage decisions without reliance on vendor representations. Finance reads the same limitation on the internal product-analytics LLM — the function uses outputs operationally without independent capability to evaluate failure modes or bound the model's operating envelope.

The Visibility Gap on D3 reads −14, the second-largest on this Audit, concentrating in the same functions where vendor and general-purpose LLM deployments operate without independent critical evaluation. The literacy concentration in Technology sustains the fraud detection regime's posture; the literacy gap in regulated functions does not sustain the equivalent posture elsewhere.

Peer standing · 23 AU FinTech · 50–200 staff 24thpercentile
← Behind peersPeer medianAhead of peers →
Reads 38 — below the cohort median. Ahead of only 24% of the 23 AU FinTech peers at 50–200 staff.
Page 8 of 21KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
Dimensional Reading
34

D4 · Governance and Oversight

Early-stage · 26–50 · CEO gap −18 — largest

What moves it. Raised by documented policies, designated ownership, testing regimes, and incident response in operation; depressed by defaulted ownership and undocumented controls.

The reading. Seventeen points below the Systematic boundary. The largest finding on this Audit. The reading is structurally bifurcated by deployment.

Fraud detection. A documented governance posture in continuous operation since 2023. Five governance artefacts are operative: model card; monthly performance review with documented attendance from Technology, data science, and Compliance & Risk; incident log maintained since 2023; decision-rights matrix between model output and human reviewer; named accountability ownership reporting to the Head of Risk. Taken in isolation, this deployment would read at the upper end of the dimensional scale.

Merchant onboarding KYC. A vendor-supplied model card is the sole governance artefact. Training-data visibility reads from vendor representations only. No contractual right to audit the vendor's model is documented. No internal testing regime operates on the vendor's outputs. No deployment-specific incident log is maintained.

Internal product-analytics LLM. No documented governance review at deployment. No model card. No testing regime. No incident log. Accountability reads informally to the Growth & Revenue function head. The deployment is treated as a productivity utility rather than a regulated system, on the function head's own framing.

On the evidence collected, the reading diverges from peer cohort posture on elements APRA addresses in CPS 230 paragraphs 23–32 and 46–61 on the KYC and internal LLM deployments. The fraud detection regime is the exception: it exhibits the documented controls absent from the remaining two deployments. The Visibility Gap on D4 reads −18, treated in full at page 5.

Peer standing · 23 AU FinTech · 50–200 staff 18thpercentile
← Behind peersPeer medianAhead of peers →
Reads 34 — well below the cohort median. Ahead of only 18% of the 23 AU FinTech peers, the weakest peer standing on this Audit.
Page 9 of 21KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
Dimensional Reading
42

D5 · AI Investment Spend

Early-stage · 26–50 · CEO gap +4

What moves it. Raised by committed, categorised annual AI investment per head; depressed by spend that is uncategorised, inertial, or invisible to leadership.

The reading. Upper end of the Early-stage band, nine points below the Systematic boundary. Annual AI investment is normalised per function headcount and banded before storage; the banded reading, not a raw figure, is the scored object.

The finding. Investment concentrates on the fraud detection regime — the monthly performance review, incident-log review, and decision-rights calibration absorb the majority of committed spend and attention from the Head of Risk and the Technology function head. Investment on the merchant onboarding KYC deployment reads at a quarterly cadence, and reads as primarily commercial — a vendor performance review, not a governance review. Investment on the internal product-analytics LLM reads as minimal.

The Visibility Gap on D5 reads +4: the Chief Executive under-estimates the company's AI investment, with the under-read concentrating in spend that sits inside function budgets uncategorised — expenditure that never presented itself as an AI decision. The reading is moderate in magnitude but structurally asymmetric across the three deployments, and the asymmetry tracks the governance bifurcation at D4.

Peer standing · 23 AU FinTech · 50–200 staff 38thpercentile
← Behind peersPeer medianAhead of peers →
Reads 42 — below the cohort median. Ahead of 38% of the 23 AU FinTech peers at 50–200 staff.
Page 10 of 21KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
Dimensional Reading
63

D6 · Outcome Tracking

Systematic · 51–75 · CEO gap −9

What moves it. Raised by systematic measurement of outputs, errors, cost, and business impact; depressed by measurement that is ad hoc, vendor-supplied and unverified, or absent.

The reading. Twelve points above the band boundary; the second-strongest dimensional reading on this Audit.

The finding. The reading is carried by the fraud detection regime: monthly performance metrics (false positive rate, false negative rate, model drift indicators), an incident log maintained since 2023, dollarised exposure tracking on authorised-and-confirmed-fraudulent transaction volume, and documented business-impact attribution against payments operations cost.

Outside the fraud detection regime, the measurement infrastructure reads materially thinner. The KYC deployment reads vendor-supplied performance metrics with no internal verification; no error categorisation is maintained on KYC adverse decisions. The internal product-analytics LLM reads no measurement infrastructure at all — output quality, error rate, and business impact are not tracked. The Visibility Gap on D6 reads −9: within fraud detection, Session 0 evidence aligns with function-head reading; outside it, the Chief Executive reads systematic measurement that the evidence does not sustain.

Peer standing · 23 AU FinTech · 50–200 staff 68thpercentile
← Behind peersPeer medianAhead of peers →
Reads 63 — ahead of the cohort median. Better than 68% of the 23 AU FinTech peers at 50–200 staff.
Page 11 of 21KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
Peer Dataset Placement

23 AU FinTech companies.

SectorFinTech
GeographyAustralia
Staff band50–200
Cohort sizen = 23; cohort membership counted at the 15 April 2026 audit date, observations frozen 31 March 2026
VintageObservations collected on a rolling 18-month window ending 31 March 2026; observations older than 24 months are retired. Next scheduled cohort refresh: Q3 2026.

The cohort is defined on three axes — sector, jurisdiction, staff band. The peer dataset is composed of audited companies that have executed a kn0w Data Contribution Agreement. Cohort statistics are derived from k-anonymised contributions of contributing members only, under the kn0w anonymisation pipeline with a k-anonymity floor of k≥5 from the first Audit. The floor is structural, not phased. Placements are reported only where the qualifying cohort meets k≥5; cohorts below the floor render as a fallback notice in place of a placement.

Composite placement · cohort percentile47th percentile
n = 23
below cohort median
025median75100

Sub-cohort fallback

A more proximate sub-cohort was tested at the request of the Audit scope: AU FinTech, payments vertical specifically. The sub-cohort returned n = 4 matching companies as of 15 April 2026 — below the k-anonymity floor.

Sub-cohort placement: insufficient peer data in your cohort.

Sub-cohort placement is reportable only at k≥5. Where the floor is reached at the next scheduled issuance event, sub-cohort placement renders in the next issued artefact. The Issuer is not under obligation to update this Statement in response to events occurring after issuance.

The cohort percentile is independent of the kn0w dimensional scale. The dimensional scale reads the company against the dimension construct on a 0–100 basis; the cohort percentile reads the company against its peer distribution. A 47th-percentile placement reads that eleven of the twenty-three cohort companies hold a lower composite reading than the company and the remaining twelve hold a higher one. It does not read on absolute adequacy: a company can lead its cohort and still carry material governance divergence.

Page 12 of 21KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
Benchmark Table

Where the company places against its peers.

One row per dimension, read against 23 AU FinTech companies at 50–200 staff. The centre line is the peer median: a green bar to the right places the company ahead of its peers, a rust bar to the left places it behind. The bar reaches the company's percentile; the faint ticks mark the cohort's 25th and 75th percentiles.

Dimension
Reading
%ile
← Behind peersPeer medianAhead of peers →
D1Workflow automation rate
58
64th
D2AI tool deployment
71
78th
D3AI literacy level
38
24th
D4Governance and oversight
34
18th
D5AI investment spend
42
38th
D6Outcome tracking
63
68th

Northbeam places above the cohort 75th percentile on D2 and above the cohort median on D1, D6, and on a composite basis. Northbeam places below the cohort 25th percentile on D3 and D4. The widest divergences from the cohort sit on the dimensions where the company's bifurcated posture reads most pronounced: the company deploys like the top of its cohort and governs like the bottom of it.

At n = 23, percentiles are comparative positions within a small cohort and read directionally, not as precise statistical estimates.

Page 13 of 21KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
Regulatory Mapping
Exceptions · divergence is stamped in plain view, not buried

Obligations, stamped.

The company's readings are routed to the regulatory instruments its footprint answers to. Eleven AU and UK frameworks sit in primary methodology scope; the four applicable to an APRA-regulated AU FinTech are treated below. CPS 230 (as in force 1 July 2026) ¶23–32 and ¶46–61 are read cohort-relatively against documented control evidence. FAR s21(1)(c)–(d), s912A and APP 1.2 are mapped to the evidence ledger and stamped. None of these stamps is a legal compliance determination.

Stamp legend. Evidenced — documented control evidence materially present and operating. Amber — evidence partial, non-systematic, or undocumented as a control. Red — evidence absent or materially insufficient for the deployment or obligation area. Statuses read on the evidence at page 15, per deployment where the posture diverges.

Obligation areaInstrumentStatusEvidence position
Accountable-person accountability and reasonable steps for AI-affected operations FAR s21(1)(c), s21(1)(d) Amber Accountable Person named (addressee). Reasonable-steps evidence exists and operates on the fraud detection deployment; it is absent on the KYC and internal LLM deployments. This Statement and its evidence ledger may be relied upon by the Accountable Person as evidence of steps taken; whether they satisfy the reasonable-steps obligation is a determination for the entity's counsel, APRA, or a court.
Operational risk management — in-house AI systems CPS 230 ¶23–32 Evidenced / Red Fraud detection: five operative governance artefacts, documented and operating since 2023. Internal product-analytics LLM: no governance review, no model card, no testing regime, no incident log.
Service provider management — vendor AI systems CPS 230 ¶46–61 Red KYC vendor: no contractual right to audit, no internal testing of vendor outputs, no deployment-specific incident log. Vendor model card is the sole artefact.
Efficient, honest and fair provision of financial services where AI supports decisions Corporations Act s912A · ASIC REP 798 Amber AI-supported adverse onboarding decisions operate without documented governance review or internal error categorisation; the general obligation is engaged where automated decisions affect consumers.
Privacy governance of AI inputs Privacy Act 1988 (Cth), APP 1.2 Amber Merchant and consumer data flows through vendor and general-purpose AI tools without AI-specific data-governance coverage in the operative privacy programme.
AI incident response and monitoring CPS 230 ¶31–32 Amber Incident log operative on the fraud detection deployment only; no AI-specific incident process or near-miss tracking on the remaining two deployments.

Statuses are the Issuer's reading of the documented posture against publicly stated obligations and supervisory expectations; they are not legal compliance determinations. Each Red and Amber stamp maps to a Required Action at page 17. Stamp status is re-read at each Quarterly Review and re-issued at the Annual Statement: the cure path is part of the record. Instrument references are verified per the verification status at page 18.

Page 14 of 21KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
Deployment Evidence Ledger

Three deployments. What was evidenced. What was absent.

Each production AI deployment identified in this Audit, its ownership, its decision impact, the governance artefacts evidenced in sessions, and the artefacts absent. Entries are session-verified; the underlying evidence ledger records each reference, its session of collection, and the chain of custody from collection through scoring through issuance.

DeploymentOwnerDecision impactEvidence seenEvidence absentRegulatory relevance
Real-time fraud detection
In-house · since 2023 · merchant authorisation pipeline
Head of Risk — named ownership Automated screening with human review per decision-rights matrix Model card (last approved Feb 2026); monthly performance review records (through Mar 2026); incident log (2023–, current); decision-rights matrix (last approved Nov 2025); AUSTRAC reporting workflow documentation (current) — none material CPS 230 ¶23–32
Merchant onboarding KYC automation
Vendor-supplied · onboarding workflow
Head of Operations — by default, not designation Adverse onboarding decisions Vendor model card (vendor-dated 2024); vendor agreement (executed Jul 2024); quarterly vendor review records through Q1 2026 (commercial in character) Contractual right to audit; internal testing records; deployment-specific incident log; independent benchmark evaluation — [cure: Action 1] CPS 230 ¶46–61
Internal product-analytics LLM
General-purpose · Q3 2025 · product telemetry and merchant transaction patterns
Growth & Revenue function head — informal Feeds commercial decisions; no documented decision boundary Session evidence only Governance review record; model card; testing regime; incident log; documented accountability ownership — [cure: Action 2] CPS 230 ¶23–32

The evidence-absent column is the working surface of the Required Actions at page 17: each absent artefact carries its cure routing. Artefact dates are as evidenced in sessions and recorded in the evidence ledger. Permitted reliers may request access to the underlying evidence ledger on the conditions stated under Scope & Reliance.

Page 15 of 21KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
Dollarised Exposure

What the governance gap costs — and what closing it recovers.

One dollarised figure attaches to this Audit. It is the annual productivity the company recovers by closing the governance and oversight gaps identified — equivalently, the productivity it carries as exposure for every year the gaps stay open. It is a structural estimate, not a forecast of realised loss and not a measure of historical loss, calculated deterministically from the company's function headcounts, the kn0w productivity reference for its sector and jurisdiction, and the kn0w productivity-loss calibration, with the coefficient locked at the lower bound of the defensible range. The figure is therefore a conservative floor.

Recoverable annual productivity
A$747,000
Conservative floor · structural estimate · lower-bound calibration · carried every year the gap stays open
FunctionHeadcountExposure scope
Technology30Out of scope — governed (fraud detection regime above the governance threshold)
Operations26In scope — merchant onboarding KYC ungoverned
Growth & Revenue24In scope — internal product-analytics LLM ungoverned
Customer Success23In scope
Finance9In scope
Compliance & Risk8In scope

Where the A$747,000 concentrates

ConcentrationAnnual exposureClosed by
Merchant onboarding KYC · Operations~A$188,000Required Action 1
Internal product-analytics LLM · Growth & Revenue~A$309,000Required Action 2
Compliance & Risk and Finance~A$118,000Required Action 3
Customer Success — balance to the total~A$132,000General governance programme
Total recoverableA$747,000

Exposure is driven by each function's governance-band coefficient, not by headcount alone — an ungoverned deployment in a smaller function can carry more than a better-governed one in a larger function; here the internal LLM in Growth & Revenue exceeds the KYC deployment in the larger Operations function. Concentrations tie to the Required Actions at page 17 and are stated to the nearest thousand; the Customer Success line is the residual to the total, closed by the general governance programme rather than a single action.

The figure concentrates where governance is absent. The fraud detection regime is out of scope — its function-level governance reading sits above the threshold — and contributes nothing. The merchant onboarding KYC and internal product-analytics LLM deployments carry the substantial majority; page 17 routes the recoverable figure to the action that closes each. At full target posture — every in-scope function lifted above the governance threshold, which takes the three Required Actions together with the general governance uplift in the remaining functions — the modelled figure approaches zero. The figure is not a target; it is carried in full every year the gap stays open and re-read at each Quarterly Review.

Exposure basis

Annual exposure is calculated per in-scope function as headcount × loaded hourly labour cost × productive hours per annum (1,650) × a productivity-loss coefficient set by the function's governance band. Functions whose governance reading sits above the threshold are out of scope and contribute zero, which excludes the fraud detection regime. Loaded labour cost is drawn per function from the kn0w productivity reference for the company's sector and jurisdiction. The productivity-loss coefficient is anchored against published evidence on AI value capture (OECD; Stanford HAI; Brynjolfsson et al.; Federal Reserve Bank of St. Louis) and locked at the lower bound of the defensible range. The per-function inputs, the coefficient set, and the calibration trace are held in the evidence ledger and are accessible to permitted reliers under Scope & Reliance. Calibration is subject to refresh at twelve months post-issuance.

Specimen figure — illustrative. Computed against the kn0w productivity-loss calibration for the specimen's stated function headcounts and governance readings; confidence rises at future issuance where operational records are connected and reconciled.

Page 16 of 21KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
Required Actions · 90 Days

Three required actions.

1
Head of Operations · reporting to Head of Risk and the Accountable Person under APRA FAR · Day 30

Establish a documented governance posture on the merchant onboarding KYC deployment equivalent to the fraud detection regime.

Model card (vendor-supplied or internally authored against vendor disclosures), monthly performance review, incident log, decision-rights matrix between vendor output and accountable human reviewer, and a contractual right-to-audit clause negotiated into the vendor agreement at the next renewal cycle. [Resolves: CPS 230 ¶46–61 Red; AI incident response Amber, KYC pathway; s912A Amber in part]

Recoverable ~A$188,000 p.a. — the recoverable productivity attributable to the KYC deployment in Operations (page 16).
Verified complete when the KYC deployment carries the five governance artefacts operative on the fraud detection regime — model card, monthly performance review, incident log, decision-rights matrix, and named accountability ownership — plus the contractual right-to-audit clause, and each has operated for one review cycle. CPS 230 ¶46–61 then re-stamps from Red at the next Quarterly Review.
2
Head of Risk · Accountable Person accountable for commissioning the review · Day 60

Establish a documented governance posture on the internal product-analytics LLM.

Formal governance review; accountability ownership transfer from Growth & Revenue to the Head of Risk; model card; testing regime; incident log. [Resolves: CPS 230 ¶23–32 Red, LLM; APP 1.2 Amber in part; AI incident response Amber, LLM pathway]

Recoverable ~A$309,000 p.a. — the recoverable productivity attributable to the internal LLM in Growth & Revenue (page 16); the largest single share.
Verified complete when the internal product-analytics LLM carries the same five governance artefacts under named ownership reporting to the Head of Risk, and each has operated for one review cycle. CPS 230 ¶23–32 then re-stamps from Red at the next Quarterly Review.
3
Head of Risk · Chief Executive accountable for programme commissioning · Day 90

Close the AI literacy gap in Compliance & Risk and Finance.

A structured capability programme covering vendor model evaluation, failure-mode identification, and adoption-stage decision-making independent of vendor representations. Actions 1 and 2 depend on this capability in operation. [Resolves: s912A Amber in part; sustains the FAR s21 reasonable-steps posture with Actions 1 and 2]

Recoverable ~A$118,000 p.a. — the recoverable productivity across Compliance & Risk and Finance (page 16).
Verified complete when Compliance & Risk and Finance demonstrate, on evidence, the capability to evaluate a vendor or general-purpose model against independent benchmarks, identify its failure modes, and reach an adoption decision without reliance on vendor representations. The D3 literacy reading re-reads against that demonstrated capability at the next issuance.

Together the three actions are attributed ~A$615,000 of the recoverable A$747,000; the balance (~A$132,000, Customer Success) is in scope on its own governance reading but is closed by no single action — it lifts with the general governance programme. Each closure is recorded in the evidence ledger and forms part of the Accountable Person's reasonable-steps record under FAR. Three obligations stamp Red at this issuance; each carries the defined cure path above and is re-read at the next Quarterly Review, and the Annual Statement records what closed — the next issuance is a fresh immutable record of whether the work was done, not a repeated opinion.

Exactly three required actions issue with every Statement. These are required actions, not recommendations. If any action is incomplete at its deadline, the Accountable Person notifies the Board at its next scheduled meeting, the delay is recorded in the evidence ledger, and the relevant obligation is re-stamped as unresolved at the next Quarterly Review. Function ownership is named; individual ownership is the company's to assign under its accountability framework. The CEO Visibility Gap at page 5 is addressed through the reporting line attached to each action: function-head evidence on governance posture and outcome tracking reaches the Chief Executive monthly and the Board quarterly, closing the −18 and −9 gaps by structure rather than by resolution.

Page 17 of 21KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
Methodology

How this Statement was produced.

This Statement is issued under the kn0w methodology on a fixed-scope basis. Evidence was collected across seven structured voice sessions during the engagement window of 9 March 2026 to 15 April 2026: one Session 0 with the Chief Executive (the structured perception session) and Sessions 1 through 6 with the heads of the canonical functions — Technology, Compliance & Risk, Operations, Finance, Growth & Revenue, and Customer Success. Each session combines structured written intake and a recorded conversational session. Perception questions are constructed so that no question implies a correct answer.

Session evidence was processed through a deterministic scoring process — the same inputs always produce the same output — to produce dimensional readings on a 0–100 scale per fixed dimension construct. The composite reading is the weighted sum of the six dimensional readings under a fixed, calibrated weight distribution; the dimensions are weighted differently, and the exact weights are held as methodology and are not disclosed. Cohort placements are computed against the kn0w peer dataset under the anonymisation pipeline with a k-anonymity floor of k≥5 from the first Audit. Methodology and architecture versions are recorded in the issuance binding on the signatory page.

Evidence ledger

The evidence ledger underlying this Statement is held in the kn0w issuance system. The ledger records each evidence reference cited in the dimensional readings, the session in which the evidence was collected, and the chain of custody from collection through scoring through issuance. Permitted reliers may request access to the evidence ledger on the conditions stated under Scope & Reliance.

Verification status

Every regulatory claim in this Statement is traced to a primary source, corroborated by secondary sources where the primary was inaccessible, or flagged as interpretation where the primary source is silent.

ClaimTraceSource
CPS 230 paragraph references (¶23–32, ¶46–61, ¶31–32)PrimaryAPRA Prudential Standard CPS 230 (as in force 1 July 2026)
FAR s21(1)(c), s21(1)(d) reasonable-steps obligationsPrimaryFinancial Accountability Regime Act 2023 (Cth)
s912A general obligations; REP 798 framingPrimaryCorporations Act 2001 (Cth); ASIC Report 798
APP 1.2 privacy governance obligationPrimaryPrivacy Act 1988 (Cth)
Peer cohort statistics and percentilesPrimarykn0w benchmark dataset, contributing members, k≥5
Deployment status, governance artefacts, ownership, and incident recordsPrimarySession evidence from the accountable function heads, indexed in the evidence ledger
Productivity coefficients (exposure basis, p.16)SecondaryCorroborated against published AI value-capture research — OECD, Stanford HAI, Brynjolfsson et al., Federal Reserve Bank of St. Louis; calibration trace in the evidence ledger
KYC vendor training-data characteristicsInterpretationStated on vendor representations; not independently verified — flagged at pages 9 and 15. This interpretation is load-bearing for the CPS 230 ¶46–61 Red stamp; if vendor representations are subsequently verified, the stamp is eligible for Amber reclassification at the next Quarterly Review.

Findings basis

Session evidence includes the artefact categories evidenced by respondents — model cards, incident logs, decision-rights documentation, vendor agreements, and review records — recorded per deployment in the Deployment Evidence Ledger at page 15. Session coverage: Session 0, the Chief Executive (Accountable Person); Sessions 1–6, the heads of Technology, Compliance & Risk, Operations, Finance, Growth & Revenue, and Customer Success — the owners of every deployment and control named in this Statement. No session was delegated below function-head level.

Findings are session-verified, not operationally verified: they reflect what the Chief Executive and function heads evidenced in structured engagement, not direct instrumentation of company systems. Readings are a view at the date of issuance and decay with organisational change.

Page 18 of 21KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
Scope, Independence, Reliance & Conditions
Scope · what this Statement does, and does not, cover

Scope

The scope of this Audit is the AI accountability posture of Northbeam Pay Holdings Pty Ltd as evidenced through seven structured voice sessions during the engagement window. The scope does not extend to financial audit, operational audit, security audit, or any audit conducted under any other framework or methodology. The Issuer confirms that the evidence collected is sufficient and appropriate to provide a basis for the readings, findings, and Statement issued in this document. The Issuer's security and certification posture is published and maintained at kn0w.co/security.

Independence

KN0W PTE. LTD. confirms that, during the engagement window and at issuance, the Issuer holds no commercial relationship with Northbeam Pay Holdings Pty Ltd beyond the Audit engagement that produced this Statement — no equity, no debt, no sub-contracted work, and no operating relationship with the addressee or any of its officers, directors, or material shareholders. The Issuer's fee is fixed at the price stated in the engagement letter and does not vary with the readings, findings, or Statement issued. The Issuer sells no advisory, no implementation, and no remediation services — to this addressee or to any member, before or after issuance. The bar is structural and permanent: acceptance of any such engagement is incompatible with the Issuer's model and would require withdrawal of this Statement.

Permitted reliers

Reliance on this Statement is permitted, on a non-transferable basis, by: (1) the addressee; (2) the Board of Directors of Northbeam Pay Holdings Pty Ltd; (3) the Australian Prudential Regulation Authority, where this Statement is submitted under the relevant prudential regime; (4) lead institutional investors committing A$5 million or more in the immediately subsequent priced equity round of the addressee, identified in writing by the addressee; (5) the addressee's directors' and officers' and cyber insurers, for the purpose of underwriting assessment at placement or renewal. Reliance by any other party is not permitted without the Issuer's written consent.

Limitations

  1. The Statement is issued on the evidence collected during the engagement window. Conditions outside the window are not within scope.
  2. Dimensional readings are produced deterministically on session evidence. They are not audited estimates of operational performance.
  3. The CEO Visibility Gap is an evidence-led instrument, not a scored dimension.
  4. Cohort placements are reported only where the qualifying cohort meets the k-anonymity floor of k≥5. The floor is structural, not phased.
  5. The dollarised figures at page 16 are structural estimates calibrated against the peer cohort productivity reference — not forecasts of realised gain or loss.
  6. Regulatory references identify standards in scope of the company's regulatory footprint. This Statement is not legal opinion on regulatory compliance and is not a substitute for legal counsel.
  7. This Statement is valid until the next scheduled issuance event or until material change in the company's AI accountability posture, whichever first occurs. The Issuer is not under obligation to update this Statement in response to events occurring after issuance.
  8. Findings may be contested only under the Contested Findings Protocol at page 20; the complete exchange appends to this Statement as a disclosed exhibit.

Validity

This Statement is valid as of 23 May 2026. Validity ceases earlier upon a material AI deployment change, a material control failure, or a new AI deployment entering a regulated decision path — each a defined re-Audit trigger under the kn0w methodology. Otherwise the next issuance event is the Annual Statement, scheduled at twelve months from issuance, on 23 May 2027. Three Quarterly Reviews track adherence to the required actions stated at page 17 in the interim; they do not amend this Statement.

Page 19 of 21KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
Contested Findings Protocol

Findings can be contested. On the record.

The addressee may contest any finding in this Statement in writing within ten business days of issuance, stating the finding contested and the evidence relied on. The Issuer responds with a reasoned written determination within ten business days of receipt. A finding changes only where the evidence warrants it; where a finding stands, it stands having survived the challenge. The complete exchange — contest, determination, and outcome — appends to this Statement as a disclosed exhibit available to every permitted relier. Findings are never adjusted by negotiation, and no exchange under this protocol is confidential from a permitted relier.

The protocol exists so that a relier need not take on trust that the stamps at page 14 were not softened before issuance: any challenge, and its result, is part of the record.

Protocol status for this issuance: NOT INVOKED — no finding was contested within the contest window.

Page 20 of 21KN0W PTE. LTD.
Issuerkn0wStatement000142Issued2026-05-23Versionv2.1
Issuance Binding
Issuer signature · an institutional act — no natural person signs
Issuerkn0w
Statement000142
Issued2026-05-23
Versionv2.1

This Statement was issued on the twenty-third day of May, two thousand and twenty-six, as an institutional act under the Statement Issuance Protocol.

KN0W PTE. LTD.
Issued 2026-05-23Singapore · UEN 202615303G

No natural person signs. Authentication is the kn0w hallmark, the issuance timestamp, and the four-part identifier. This document at this version is immutable. Corrections carry a taxonomy: clerical corrections issue as a minor version under the same sequence number; evidentiary or interpretive corrections issue as a major version, superseding the prior version on the record. No correction is silent.


Addressed toThe Board of Directors
Northbeam Pay Holdings Pty Ltd
Alex Marlowe, Chief Executive Officer · Accountable Person under APRA FAR
Conditions of relianceReliance permitted to the addressee, the Board, APRA where submitted under the relevant prudential regime, lead investors in the next equity round, and the addressee's D&O and cyber insurers for underwriting assessment, on a non-transferable basis. Conditions stated in full under Scope & Reliance.
Specimen — no standing conferred
Issued, not advised.Page 21 of 21 · © KN0W PTE. LTD. 2026