[{"data":1,"prerenderedAt":591},["ShallowReactive",2],{"uc-adverse-event-case-intake":3,"uc-regulations":380},{"useCase":4,"evidence":199,"blitsAiDeployments":284,"benchmarks":285,"indicative":286,"related":289,"indexability":378,"includeUnpublished":205},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":17,"functions":20,"patterns":24,"channels":28,"audience":33,"autonomy":34,"adoptionStage":35,"problem":36,"problemStats":37,"howItWorks":43,"valueDrivers":44,"kpis":50,"indicativeValue":56,"macroEstimates":90,"feasibility":91,"implementation":104,"risk":147,"blitsAi":180,"faq":182,"related":192,"datePublished":194,"dateModified":194,"lastVerified":194,"changelog":195,"slug":198},"AI for pharmacovigilance adverse event case intake","Adverse event case intake","AI for adverse event case intake in drug safety","AI reads adverse event reports, checks validity and seriousness and extracts case data for safety staff. Pfizer and the FDA have deployed it for case intake.","published","AI that takes in adverse event reports about medicines, vaccines and devices from calls, emails, forms, literature and partner files, decides whether each is a valid case, flags seriousness, extracts and codes the case data into the safety database format, and routes it to drug safety professionals, who review medical content and regulatory reporting.",[12,13,14,15,16],"pharmacovigilance automation","ICSR intake automation","AI case processing for drug safety","adverse event report extraction","adverse event reporting chatbot",[18,19],"pharma-and-life-sciences","government",[21,22,23],"regulatory-compliance","case-management","operations",[25,26,27],"document-processing","classification-and-routing","conversational-agent",[29,30,31,32],"internal-tools","email","web-chat","api","back-office","supervised-agent","early-adopters","Marketing authorisation holders must collect, assess and report adverse events, and the volumes\nkeep rising: reports arrive from patients, doctors, clinical trial sites, call centres, social media,\nliterature and business partners, in every format and language. Each report has to be checked for\nthe minimum criteria of a valid case, triaged for seriousness because serious cases have short legal\nreporting deadlines, entered into the safety database and coded before medical review.\n\nMost of that intake work is repetitive data entry done by trained staff, while the scarce skill in\npharmacovigilance is medical judgment: causality, signal detection and benefit risk. Regulators face\nthe same flood from the other side, receiving individual case safety reports and sponsor safety\nreports that must be extracted and loaded before anyone can analyse them.",[38],{"statement":39,"sourceTitle":40,"sourceUrl":41,"year":42},"Pfizer reports that its Worldwide Safety organization processed approximately 1.4 million adverse events globally in 2019.","AI in Drug Safety: Building the Elusive 'Loch Ness Monster' of Reporting Tools","https://www.pfizer.com/news/articles/ai-drug-safety-building-elusive-%E2%80%98loch-ness-monster%E2%80%99-reporting-tools",2020,"1. **Collect reports from every channel.** Emails, scanned forms, call centre notes, partner files,\n   literature hits and web form or chatbot submissions arrive in one intake queue.\n2. **Check validity and triage.** The AI checks the four minimum criteria (an identifiable patient\n   and reporter, a suspect product and an adverse event), detects duplicates and flags seriousness,\n   such as fatal or life threatening outcomes, so the reporting clock is visible from day zero.\n3. **Extract and code.** It extracts patient, product, event, dates and narrative into the safety\n   database structure (E2B), suggests MedDRA terms and product dictionary matches, and shows a\n   confidence level per field.\n4. **Route for review.** Safety professionals check the extraction, especially low confidence fields\n   and serious cases, and complete medical assessment, follow up and regulatory reporting.\n5. **Help reporters report.** On the public side, a conversational assistant can guide patients and\n   professionals to the right form, ask for missing information and submit the report.",[45,46,47,48,49],"compliance","speed","employee-productivity","cost-to-serve","risk-reduction",[51,52,53,54,55],"automation-rate","handling-time-reduction","processing-time-reduction","accuracy","interactions-handled",{"referenceOrg":57,"inputs":58,"formula":85,"currency":86,"period":87,"resultLabel":88,"caveat":89},"A drug company that takes in 100,000 adverse event reports a year",[59,65,72,79],{"key":60,"label":61,"low":62,"high":62,"unit":63,"note":64},"cases","Adverse event reports taken in per year",100000,"reports per year","The reference company.",{"key":66,"label":67,"low":68,"high":69,"unit":70,"note":71},"intakeMinutes","Intake minutes per report today (triage, data entry and coding)",20,40,"minutes per report","Editorial assumption. Replace with a time study of your own intake step.",{"key":73,"label":74,"low":75,"high":76,"unit":77,"note":78},"effortSaved","Share of intake effort the AI removes",0.2,0.5,"fraction of intake minutes","Editorial assumption; the evidence on this page publishes no measured intake savings. Validate in a pilot before relying on it.",{"key":80,"label":81,"low":69,"high":82,"unit":83,"note":84},"costPerHour","Fully loaded cost per case processing hour",80,"USD per hour","Editorial assumption covering internal staff and outsourced case processing. Replace with your own.","cases * intakeMinutes / 60 * effortSaved * costPerHour","USD","per year","Case intake effort released","Intake effort only. It leaves out medical review, follow up and submission work, the value of fewer late reports, validation and inspection readiness costs, and the platform cost. No organization on this page has published measured savings, so treat the range as a hypothesis.",[],{"complexity":92,"complexityNote":93,"dataPrerequisites":94,"integrations":99},"high","Extraction from mixed documents is proven, but pharmacovigilance is a regulated, inspected process with legal reporting deadlines. The system must be validated, integrated with the safety database, and designed so that no serious case is missed or delayed.",[95,96,97,98],"Historical cases with source documents and the final database entries for testing","MedDRA and product dictionaries under licence and version control","Written case processing conventions and validity rules","Intake channel inventory with volumes and formats",[100,101,102,103],"Safety database that accepts E2B formatted cases","Email, call centre, web form and partner exchange intake channels","Literature monitoring sources","Quality management system for deviations and corrective actions",{"steps":105,"guardrails":121,"humanInTheLoop":127,"kpisToInstrument":128,"failureModes":134},[106,109,112,115,118],{"title":107,"detail":108},"Map intake by channel and volume","List every source of reports, its format and volume, and start with high volume, well structured sources such as email forms and partner files.",{"title":110,"detail":111},"Automate validity and seriousness triage first","Deciding whether a report is a valid case and whether it is fatal or life threatening is the first phase of Pfizer's tool; it protects deadlines and gives reviewers a prioritised queue.",{"title":113,"detail":114},"Extract with confidence scores","Extract fields into the E2B structure with a confidence per field, and send low confidence fields and all serious cases to a person for verification.",{"title":116,"detail":117},"Validate as a computerized system","Define the intended use, test against historical cases, document performance per field and case type, and put models, prompts and dictionaries under change control.",{"title":119,"detail":120},"Monitor and extend","Track missed cases, extraction accuracy and timeliness weekly, and add channels and languages one at a time.",[122,123,124,125,126],"Every case the AI marks invalid or non serious is sampled by a person; no report is discarded unreviewed","Serious and fatal cases always routed to a safety professional with the reporting deadline shown","Medical assessment, causality and regulatory submission decisions stay with qualified staff","Personal and health data of patients and reporters masked in logs and prompts","Models, prompts and coding dictionaries under validation and change control","Drug safety professionals verify low confidence extractions and every serious case, perform medical review and causality assessment, and decide what is reported to regulators. The qualified person for pharmacovigilance owns the process, and quality staff sample cases the AI screened out.",[129,130,131,132,133],"Share of reports processed without manual data entry","Field level extraction accuracy on a weekly sample","Time from receipt to case creation, and share of expedited reports submitted on time","Missed or wrongly invalidated cases found in quality samples","Duplicate cases detected",[135,138,141,144],{"title":136,"detail":137},"A serious case screened out","The AI marks a valid serious case as invalid or non serious and the deadline is missed. Sample every negative decision and track misses as deviations.",{"title":139,"detail":140},"Silent extraction errors","A wrong dose, date or product enters the database and distorts signal detection. Show confidence per field and verify key fields on every case.",{"title":142,"detail":143},"Validation that ends at go live","Performance drifts as new products, languages and sources arrive. Monitor accuracy continuously and revalidate after changes.",{"title":145,"detail":146},"A chatbot that discourages reporting","A public reporting assistant that is hard to use lowers reporting. Keep a direct form and a human route and test with real reporters.",{"euAiAct":148,"regulations":151,"guidance":156,"controls":173,"incidents":179},{"tier":149,"basis":150},"context-dependent","Internal intake, extraction and coding for review by safety staff is not listed in Annex III and is usually minimal risk. A public facing reporting assistant must tell people they are talking to an AI under Article 50. The main obligations come from pharmacovigilance law and good pharmacovigilance practices, which require validated, inspectable processes, and from GDPR rules on health data.",[152,153,154,155],"eu-ai-act","gdpr","iso-42001","nist-ai-rmf",[157,163,167],{"title":158,"issuer":159,"region":160,"url":161,"note":162},"Reflection paper on the use of artificial intelligence (AI) in the medicinal product lifecycle","European Medicines Agency","europe","https://www.ema.europa.eu/en/documents/scientific-guideline/reflection-paper-use-artificial-intelligence-ai-medicinal-product-lifecycle_en.pdf","Covers AI in pharmacovigilance, including adverse event report management and signal detection, in line with good pharmacovigilance practices, and expects marketing authorisation holders to validate, monitor and document these tools.",{"title":164,"issuer":159,"region":160,"url":165,"note":166},"Good pharmacovigilance practices (GVP)","https://www.ema.europa.eu/en/human-regulatory-overview/post-authorisation/pharmacovigilance-post-authorisation/good-pharmacovigilance-practices-gvp","The EU rules for collecting, managing and submitting reports of suspected adverse reactions, which an automated intake process must still meet.",{"title":168,"issuer":169,"region":170,"url":171,"note":172},"Considerations for the Use of Artificial Intelligence To Support Regulatory Decision-Making for Drug and Biological Products (draft guidance)","US Food and Drug Administration","north-america","https://www.fda.gov/media/184830/download","Proposes a risk based credibility assessment for AI models that produce information or data used to support regulatory decisions about safety, effectiveness or quality.",[174,175,176,177,178],"Validation package with intended use, test results per case type and field, and acceptance criteria","Audit trail from source document to database entry, including AI suggestions and human changes","Deviation and corrective action process for missed or late cases","Periodic sampling of AI negative decisions (invalid, non serious, duplicate)","Data protection controls for patient and reporter data, including transfers to vendors",[],{"howToBuild":181},"On Blits.ai intake runs as an **agentic workflow** per report. Reports arrive through the **email\nchannel**, partner systems trigger the workflow via **API tokens**, and a **flow** with a **receive\nattachment** block collects files that reporters upload. An **AI agent** with **structured output**\nextracts the case fields from the report text, checks the validity criteria and flags seriousness. **Custom functions** look up products and write the case to the safety\ndatabase, and a **knowledge base** holds the case processing conventions the agent follows.\n\nFor reporters, a **web chat** or **WhatsApp** agent with **flows** asks for the minimum information,\nin several languages, and hands over to a person when needed. **Human in the loop approval** keeps\nserious cases and low confidence extractions with safety staff, **PII masking** protects patient\ndata, the **audit trail** records every run, and **test suites** grade extraction against\nhistorical cases before each change.",[183,186,189],{"question":184,"answer":185},"Which parts of pharmacovigilance can AI automate safely?","Intake steps with clear rules: checking whether a report is a valid case, flagging seriousness, detecting duplicates, extracting data and suggesting codes. Pfizer's first phase covers basic intake decisions such as validity and whether a case is fatal or life threatening. Medical assessment, causality and reporting decisions stay with qualified people.",{"question":187,"answer":188},"Do regulators use AI on adverse event reports too?","Yes. The US FDA lists a deployed tool that extracts data from sponsors' IND safety reports and loads it into its adverse event database, and a chatbot that helps people submit adverse event and product problem reports through its Safety Reporting Portal.",{"question":190,"answer":191},"Why are there so few published results?","Most deployments are described by companies and vendors without measured before and after data, and for older programmes, such as Bayer's 2018 agreement with Genpact, we found no published results. Validate on your own historical cases and publish internally what the system misses, not only what it saves.",[193],"clinical-and-regulatory-document-drafting","2026-09-27",[196],{"date":194,"note":197},"First published","adverse-event-case-intake",[200,228,245,261],{"title":201,"useCases":202,"organization":203,"vendors":207,"summary":211,"stage":212,"year":213,"channels":214,"languages":215,"metrics":217,"outcomeDisclosed":205,"sources":218,"verification":223,"grade":225,"id":226,"organizationSlug":227},"US Food and Drug Administration: AI extraction of data from IND safety reports into FAERS",[198],{"name":204,"anonymized":205,"country":206,"region":170,"industry":19},"U.S. Food and Drug Administration, Center for Drug Evaluation and Research",false,"US",[208],{"name":209,"role":210},"ThinkTrends","platform","FDA's Center for Drug Evaluation and Research reports in the 2025 federal AI use case inventory that it uses OCR and AI, through the commercial tool ThinkTrends, to extract data from the Investigational New Drug safety reports that sponsors send in. The extracted data is converted to the E2B(R2) format and ingested automatically into the FDA Adverse Event Reporting System. The inventory describes manual extraction of these reports as labor intensive and time consuming for regulatory staff, and states the aim as faster processing and regulatory action on adverse events reported in clinical trials. It lists the use as deployed since March 2025.","production",2025,[29],[216],"en",[],[219],{"url":220,"title":221,"publisher":222},"https://raw.githubusercontent.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory/main/Data/2025_individually_reported_AI_use_cases.csv","2025 federal agency AI use case inventory, individually reported use cases (raw data)","Office of Management and Budget (GitHub)",{"level":224,"checkedAt":194},"source-verified","B","fda-ind-safety-report-extraction",null,{"title":229,"useCases":230,"organization":231,"vendors":233,"summary":236,"stage":212,"year":237,"channels":238,"languages":239,"metrics":240,"outcomeDisclosed":205,"sources":241,"verification":243,"grade":225,"id":244,"organizationSlug":227},"US Food and Drug Administration: chatbot for adverse event and product problem reports on the Safety Reporting Portal",[198],{"name":232,"anonymized":205,"country":206,"region":170,"industry":19},"U.S. Food and Drug Administration",[234],{"name":235,"role":210},"Druid","FDA reports in the 2025 federal AI use case inventory that a conversational assistant built on the commercial platform Druid helps people who report an adverse event or product problem through the Safety Reporting Portal. It answers questions from a knowledge base, routes the reporter to the right form for the product type, helps complete it and submits the report to the portal through an API, with the stated aims of better data integrity and faster form completion. The inventory lists it as deployed since March 2024; no measured results are published.",2024,[31,32],[216],[],[242],{"url":220,"title":221,"publisher":222},{"level":224,"checkedAt":194},"fda-safety-reporting-portal-chatbot",{"title":246,"useCases":247,"organization":248,"vendors":250,"summary":251,"stage":212,"year":42,"channels":252,"languages":253,"metrics":254,"outcomeDisclosed":205,"sources":255,"verification":259,"grade":225,"id":260,"organizationSlug":227},"Pfizer: AI platform for adverse event case intake in drug safety",[198],{"name":249,"anonymized":205,"country":206,"region":170,"industry":18},"Pfizer",[],"Pfizer's Worldwide Safety organization, which processed about 1.4 million adverse events in 2019, worked with industry experts to build an AI platform for the repetitive intake steps of adverse event case processing. In its first phase the model makes basic intake decisions, such as whether a report is a valid case and whether it is fatal or life threatening. The Drug Safety Unit in Rome was the first location to use it in live operations, and Pfizer described the aim as freeing safety professionals for signal detection and investigation rather than replacing them. No outcome figures are published.",[29],[],[],[256],{"url":41,"title":40,"publisher":249,"date":257,"archivedUrl":258},"2020-04-20","https://web.archive.org/web/2026/https://www.pfizer.com/news/articles/ai-drug-safety-building-elusive-%E2%80%98loch-ness-monster%E2%80%99-reporting-tools",{"level":224,"checkedAt":194},"pfizer-adverse-event-case-intake",{"title":262,"useCases":263,"organization":264,"vendors":267,"summary":270,"stage":271,"year":272,"channels":273,"languages":274,"metrics":275,"outcomeDisclosed":205,"sources":276,"verification":281,"grade":282,"id":283,"organizationSlug":227},"Bayer: Genpact pharmacovigilance AI for adverse event case processing",[198],{"name":265,"anonymized":205,"country":266,"region":160,"industry":18},"Bayer","DE",[268],{"name":269,"role":210},"Genpact","In November 2018 Genpact announced a multi year agreement with Bayer under which its Pharmacovigilance Artificial Intelligence (PVAI) suite, which incorporates the Genpact Cora PharmacoVigilance software product, is applied to Bayer's existing pharmacovigilance database and IT systems. Bayer's head of pharmacovigilance said the partnership offered an opportunity to further increase the efficiency of its pharmacovigilance operating model and case processing, and Genpact said Bayer was among the first companies going live with the AI based Case Management module of the PVAI suite. Neither company has published outcome figures.","announced",2018,[29],[],[],[277],{"url":278,"title":279,"publisher":269,"date":280},"https://media.genpact.com/2018-11-01-Genpact-and-Bayer-to-Co-innovate-to-Leverage-Artificial-Intelligence-Capabilities-for-Patient-Safety","Genpact and Bayer to Co-innovate to Leverage Artificial Intelligence Capabilities for Patient Safety","2018-11-01",{"level":224,"checkedAt":194},"C","bayer-genpact-pharmacovigilance-ai",0,[],{"low":287,"high":288},266666.66666666674,2666666.666666667,[290,315,332,357],{"slug":193,"title":291,"shortTitle":292,"definition":293,"status":9,"industries":294,"functions":295,"patterns":296,"audience":299,"autonomy":300,"adoptionStage":35,"evidenceCount":301,"publicEvidenceCount":301,"organizations":302,"bestGrade":225,"headline":305,"lastVerified":194,"indexable":314},"AI drafting of clinical study reports and regulatory documents","Clinical and regulatory document drafting","Generative AI that drafts clinical study reports and other regulated documents, such as protocols, patient materials and submission modules, from the trial's statistical tables, listings and figures and from approved template text, for medical writers to verify, edit and approve before anything is submitted to a regulator.",[18],[21,23],[297,298,25],"content-generation","rag-knowledge-assistant","employee-facing","copilot",2,[303,304],"Merck & Co.","Novo Nordisk",{"kpi":306,"label":307,"unit":308,"n":309,"nUpTo":284,"kind":310,"value":311,"qualifier":312,"claimant":313,"organization":303,"vendorReported":205},"error-reduction","Error reduction","percent",1,"reported",50,"exact","organization",true,{"slug":316,"title":317,"shortTitle":318,"definition":319,"status":9,"industries":320,"functions":321,"patterns":323,"audience":325,"autonomy":300,"adoptionStage":35,"evidenceCount":326,"publicEvidenceCount":326,"organizations":327,"bestGrade":225,"headline":227,"lastVerified":194,"indexable":314},"immigration-and-visa-application-assistant","AI for immigration and visa applications, from applicant questions to case preparation","Immigration and visa application assistant","AI that helps applicants understand immigration and visa requirements and submit complete applications, and helps immigration staff prepare cases by extracting form data, classifying evidence, routing applications and supporting interviews, while every grant or refusal is decided by an officer against the immigration rules.",[19],[322,22,23],"citizen-services",[27,25,26,324],"translation","customer-facing",4,[328,329,330,331],"Home Office (Visa, Status and Information Services)","U.S. Department of State (Bureau of Consular Affairs)","U.S. Immigration and Customs Enforcement","U.S. Citizenship and Immigration Services",{"slug":333,"title":334,"shortTitle":335,"definition":336,"status":9,"industries":337,"functions":341,"patterns":343,"audience":33,"autonomy":34,"adoptionStage":345,"evidenceCount":346,"publicEvidenceCount":347,"organizations":348,"bestGrade":225,"headline":352,"lastVerified":194,"indexable":314},"intelligent-document-processing","AI document intelligence for unstructured forms and documents","Intelligent document processing","AI that takes documents in any format, such as scanned forms, PDFs, photos, emails and handwritten notes, splits and classifies them, extracts the required fields with a confidence score, validates them against business rules and source systems, and sends only the uncertain cases to a person before the data enters the downstream process.",[338,19,339,340],"cross-industry","automotive","manufacturing",[23,22,342],"finance-and-accounting",[25,344,26],"computer-vision","mainstream",7,5,[349,350,330,331,351],"Ancine","Pupuk Indonesia","Volvo Group",{"kpi":54,"label":353,"unit":308,"n":309,"nUpTo":284,"kind":310,"value":354,"qualifier":355,"claimant":356,"organization":349,"vendorReported":314},"Accuracy",90,"at-least","vendor",{"slug":358,"title":359,"shortTitle":360,"definition":361,"status":9,"industries":362,"functions":366,"patterns":368,"audience":33,"autonomy":34,"adoptionStage":371,"segment":372,"evidenceCount":373,"publicEvidenceCount":373,"organizations":374,"bestGrade":225,"headline":227,"lastVerified":194,"indexable":314},"continuous-controls-testing","AI for continuous controls testing and control self assessment","Continuous controls testing","AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.",[338,363,364,365,19],"banking","insurance","capital-markets",[367,21,23],"risk-management",[369,25,370,26],"agentic-workflow","anomaly-detection","emerging","second-line",3,[375,376,377],"Federal Deposit Insurance Corporation","U.S. Department of the Interior","Pension Benefit Guaranty Corporation",{"indexable":314,"reasons":379},[],[381,387,392,399,405,411,418,425,433,440,446,452,459,466,472,477,484,490,496,502,508,514,520,525,530,537,544,549,555,562,568,574,580,585],{"id":152,"label":382,"issuer":383,"region":160,"url":384,"description":385,"useCases":386,"indexable":314},"EU AI Act","European Union","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":153,"label":388,"issuer":383,"region":160,"url":389,"description":390,"useCases":391,"indexable":314},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":154,"label":393,"issuer":394,"region":395,"url":396,"description":397,"useCases":398,"indexable":314},"ISO/IEC 42001","ISO and IEC","global","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":155,"label":400,"issuer":401,"region":170,"url":402,"description":403,"useCases":404,"indexable":314},"NIST AI Risk Management Framework","NIST","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":406,"label":407,"issuer":383,"region":160,"url":408,"description":409,"useCases":410,"indexable":314},"dora","DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":412,"label":413,"issuer":414,"region":160,"url":415,"description":416,"useCases":417,"indexable":314},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":419,"label":420,"issuer":421,"region":160,"url":422,"description":423,"useCases":424,"indexable":314},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":426,"label":427,"issuer":428,"region":429,"url":430,"description":431,"useCases":432,"indexable":314},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":434,"label":435,"issuer":436,"region":429,"url":437,"description":438,"useCases":439,"indexable":314},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":441,"label":442,"issuer":443,"region":395,"url":444,"description":445,"useCases":68,"indexable":314},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",{"id":447,"label":448,"issuer":449,"region":170,"url":450,"description":451,"useCases":68,"indexable":314},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":453,"label":454,"issuer":455,"region":160,"url":456,"description":457,"useCases":458,"indexable":314},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":460,"label":461,"issuer":462,"region":395,"url":463,"description":464,"useCases":465,"indexable":314},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":467,"label":468,"issuer":383,"region":160,"url":469,"description":470,"useCases":471,"indexable":314},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":473,"label":474,"issuer":383,"region":160,"url":475,"description":476,"useCases":471,"indexable":314},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":478,"label":479,"issuer":480,"region":170,"url":481,"description":482,"useCases":483,"indexable":314},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":485,"label":486,"issuer":383,"region":160,"url":487,"description":488,"useCases":489,"indexable":314},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":491,"label":492,"issuer":493,"region":170,"url":494,"description":495,"useCases":489,"indexable":314},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":497,"label":498,"issuer":499,"region":395,"url":500,"description":501,"useCases":489,"indexable":314},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":503,"label":504,"issuer":383,"region":160,"url":505,"description":506,"useCases":507,"indexable":314},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":509,"label":510,"issuer":511,"region":170,"url":512,"description":513,"useCases":507,"indexable":314},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":515,"label":516,"issuer":428,"region":429,"url":517,"description":518,"useCases":519,"indexable":314},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",10,{"id":521,"label":522,"issuer":383,"region":160,"url":523,"description":524,"useCases":519,"indexable":314},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":526,"label":527,"issuer":383,"region":160,"url":528,"description":529,"useCases":519,"indexable":314},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":531,"label":532,"issuer":533,"region":160,"url":534,"description":535,"useCases":536,"indexable":314},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":538,"label":539,"issuer":540,"region":170,"url":541,"description":542,"useCases":543,"indexable":314},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",8,{"id":545,"label":546,"issuer":383,"region":160,"url":547,"description":548,"useCases":543,"indexable":314},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":550,"label":551,"issuer":383,"region":160,"url":552,"description":553,"useCases":554,"indexable":314},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",6,{"id":556,"label":557,"issuer":558,"region":559,"url":560,"description":561,"useCases":347,"indexable":314},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":563,"label":564,"issuer":565,"region":160,"url":566,"description":567,"useCases":326,"indexable":314},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":569,"label":570,"issuer":571,"region":160,"url":572,"description":573,"useCases":326,"indexable":314},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":575,"label":576,"issuer":577,"region":429,"url":578,"description":579,"useCases":373,"indexable":314},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":581,"label":582,"issuer":383,"region":160,"url":583,"description":584,"useCases":373,"indexable":314},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":586,"label":587,"issuer":588,"region":170,"url":589,"description":590,"useCases":373,"indexable":314},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598300971]