StableX Know Your Agent (KYA) Framework
Launched April 2026
The first governance architecture for AI agents in regulated financial services, authored by MetaComp, a MAS-licensed Major Payment Institution, and developed drawing on IMDA’s Model AI Governance Framework for Agentic AI.
StableX KYA governs AI agents across their full operational lifecycle — identified before they act, bounded in what they may do, monitored against their mandate, and accountable for how they interact.
Introduced 21 April 2026 at Money20/20 Asia, Bangkok.
Read the launch announcement →
The Governance Gap
AI agents are already operating in financial services — initiating payments, making compliance decisions, managing portfolios. What does not yet exist is an agreed standard for who those agents are, what they are permitted to do, or who is accountable when they act outside their mandate.
Consider identity. When a person leaves an organisation, their access is revoked. When an AI agent completes a transaction, its identity and permissions do not automatically expire. An agent can persist in a system long after its mandate has lapsed, with no verified identity anchor, no accountability chain and no mechanism to intervene.
Fewer than one in three organisations have adequate governance and controls in place to oversee the agents they are already deploying.¹ In Singapore, businesses outperform the global average on AI adoption, yet only 47 per cent have a documented responsible AI framework, against 63 per cent among global AI leaders.²
¹ McKinsey, State of AI Trust 2026. ² PwC Global AI Performance Study 2026.
What StableX KYA governs
StableX KYA governs AI agents across their full operational lifecycle: who the agent is, what it is permitted to do, what it actually does, and how it interacts.
Governance principles
StableX KYA was developed drawing on the four dimensions set out in IMDA’s Model AI Governance Framework for Agentic AI, published January 2026.
Assess and Bound Risks
Determine suitable use cases for agent deployment. Bound risks through design by defining agent limits and permissions.
Human Accountability
Clear allocation of responsibilities within and outside the organisation. Design for meaningful human oversight.
Technical Controls
Use technical controls during design and development. Test agents before deployment. Continuously monitor and test agents in production.
End-User Responsibility
Recognise that different users have different needs. Support users interacting directly with agents, and users integrating agents into work processes.
Four pillars, one architecture
The pillars are interdependent by design. An identified agent with unbounded authority remains a risk; a permissioned agent nobody monitors is a risk deferred, not removed.
01 — Agent Identity and Registration
Who the agent is
02 — Authority and Permission Control
What it is permitted to do
03 — VisionX Behaviour Monitoring and Risk Intelligence
What it actually does.
04 — Ecosystem and Interaction Governance
How it interacts with other agents.
How the layers work together
Governance only holds if it runs through execution rather than sitting beside it. Three layers operate as one architecture.
StableX KYA
Establishes identity and authority — every agent registered, bound to an accountable owner, and constrained to an explicit mandate before it acts.
VisionX Engine
Monitors behaviour in real time, bridging traditional KYC, AML and transaction monitoring with on-chain KYT and Travel Rule screening in a single execution layer.
AgentX Platform
is where agents execute, deploying MetaComp's regulated financial capabilities as Skills that any compatible AI agent can call. Every agent reaching MetaComp's infrastructure through the AgentX Platform operates under StableX KYA, and is monitored by VisionX as it does so.
Aligned with IMDA’s Model AI Governance Framework for Agentic AI
In January 2026, Singapore’s Infocomm Media Development Authority published the Model AI Governance Framework for Agentic AI — the world’s first cross-sector governance framework for AI agents. MetaComp developed StableX KYA drawing on that framework, and returned to IMDA directly for feedback.
IMDA’s framework is cross-sector. StableX KYA applies its principles to the specific conditions of regulated payments, compliance and wealth workflows. Read IMDA’s Model AI Governance Framework for Agentic AI →
Why A Licensed Institution Wrote This
MetaComp is licensed by the Monetary Authority of Singapore as a Major Payment Institution, and delivers regulated financial services through its agentic financial solution, AgentX.
That is where the gap became visible. A framework written from outside regulated finance can describe what AI agents ought to do. Writing from inside it means confronting what agents actually do when they reach licensed payment rails, compliance decisions and client assets, and what is missing when they do.
"AI agents are already operating in financial services — initiating payments, making compliance decisions, managing portfolios. And yet there is no agreed standard for who those agents are, what they are permitted to do, or who is accountable when they act outside their mandate. StableX KYA is our active contribution to establish that standard for regulated financial services. It governs agents across their full lifecycle — identity, authorisation, behaviour monitoring, and how they interact with each other — within a single architecture."
— Tin Pei Ling, Co-President, MetaComp
Published Openly, For Adoption
StableX KYA is not a proprietary control. MetaComp publishes it for adoption by financial institutions, regulators and network partners
“We are not presenting this as a finished answer. We are publishing it openly, because this is not a problem any one institution can resolve on its own. We are asking financial institutions, regulators, and technology partners to adopt it, challenge it, and build on it with us.”
— Tin Pei Ling, Co-President, MetaComp
Frequently Asked Questions
StableX KYA is a governance framework for AI agents operating in regulated financial services. It establishes that an agent is identifiable, that its authority is bounded, that its behaviour is monitored, and that an accountable person or institution stands behind it. MetaComp launched it on 21 April 2026 at Money20/20 Asia.
Existing identity standards assume a person or a legal entity initiates a transaction. When an AI agent initiates it instead, there is no established way to verify what the agent is, what it is permitted to do, or who answers for it. Agent permissions also do not expire the way human access does when someone leaves an organisation.
KYC verifies a natural person. KYB verifies a legal entity. KYA verifies an autonomous agent and traces accountability back to a verified person or institution. It sits alongside the existing two rather than replacing either.
MetaComp, a MAS-licensed Major Payment Institution. It was launched on 21 April 2026 at Money20/20 Asia in Bangkok. To the best of MetaComp’s knowledge and based on publicly available information, no licensed financial institution had previously published a governance architecture addressing agent identity, authorisation, action scope, behavioural monitoring, risk scoring, audit trails and agent-to-agent governance in a single framework for regulated financial services.
StableX KYA, MetaComp’s governance framework for AI agents in regulated financial services, is organised across four pillars: Agent Identity and Registration; Authority and Permission Control; VisionX Behaviour Monitoring and Risk Intelligence; and Ecosystem and Interaction Governance. Together they establish who the agent is, what it may do, what it actually does, and how it interacts.
StableX KYA was developed drawing on IMDA’s framework, published January 2026, and MetaComp sought IMDA’s feedback directly. IMDA’s framework is cross-sector; StableX KYA applies its principles to the specific conditions of regulated payments, compliance and wealth¹ workflows.
Yes. It is published openly for adoption by financial institutions, regulators and network partners. It is not a proprietary control.
The FATF Travel Rule requires institutions to exchange verified identity and transaction information when value moves between them. Ecosystem and Interaction Governance extends that same requirement to agents: when an agent initiates a transaction, or transacts with another agent, the same verified information must travel with it.
No FAQs found matching your search.
