[{"data":1,"prerenderedAt":653},["ShallowReactive",2],{"uc-ai-model-inventory":3,"uc-regulations":456},{"useCase":4,"evidence":255,"blitsAiDeployments":367,"benchmarks":368,"indicative":369,"related":372,"indexability":454,"includeUnpublished":261},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":17,"functions":23,"patterns":27,"channels":32,"audience":35,"autonomy":36,"adoptionStage":37,"problem":38,"problemStats":39,"howItWorks":45,"valueDrivers":46,"kpis":51,"indicativeValue":56,"macroEstimates":110,"feasibility":111,"implementation":127,"risk":173,"blitsAi":229,"faq":231,"related":244,"datePublished":250,"dateModified":250,"lastVerified":250,"changelog":251,"slug":254},"AI system and model inventory with shadow AI discovery","AI model inventory","AI model inventory and shadow AI discovery","An AI inventory records every AI system with its owner, risk tier and approval. See how the DOJ, the Federal Reserve and Unilever build and run theirs.","published","A governed register of every AI system and model an organization builds, buys or uses, with its owner, purpose, data, risk tier and approval status, kept current by AI that discovers unregistered use, reads the documentation and assembles the evidence a board, auditor or supervisor asks for.",[12,13,14,15,16],"AI inventory","AI register","AI use case inventory","model inventory","shadow AI discovery",[18,19,20,21,22],"cross-industry","banking","insurance","government","manufacturing",[24,25,26],"risk-management","regulatory-compliance","it-and-engineering",[28,29,30,31],"agentic-workflow","document-processing","rag-knowledge-assistant","classification-and-routing",[33,34],"internal-tools","microsoft-teams","employee-facing","copilot","early-adopters","AI governance frameworks start from the same question: which AI systems do you run? The NIST AI\nRisk Management Framework asks for mechanisms to inventory AI systems, the Monetary Authority of\nSingapore's proposed AI risk management guidelines expect financial institutions to keep accurate\nand up to date AI inventories, US federal agencies (with limited exceptions) must inventory their\nAI use cases every year,\nand the EU AI Act's deployer and registration duties presume an organization knows which high risk\nsystems it uses. Answering the question per system, with an owner, a purpose, a risk tier and\nevidence of approval, is harder than it looks.\n\nA register kept as a spreadsheet that project teams fill in once, at approval, misses the AI that\narrives inside software someone bought, the assistant a team switched on in a SaaS tool, and the\nprompts employees paste into public chatbots. Use also grows fast: the US Department of Justice\nreports that its 2025 inventory holds 315 entries, 30.7% more than the year before. Gaps\nhave consequences. In May 2026 CB Financial Services reported a material cybersecurity incident to\nthe SEC after non public customer information at its subsidiary Community Bank was handled with an\nunauthorized AI based application, the kind of unregistered use that discovery aims to surface early.",[40],{"statement":41,"sourceTitle":42,"sourceUrl":43,"year":44},"In its 2025 workshops with 13 banks, ECB Banking Supervision observed that all banks preparing for the AI Act had built up AI systems inventories and a set process to put AI models into production, while data governance adapted to AI was emerging only in a small number of cases.","AI workshops with banks 2025, annex","https://www.bankingsupervision.europa.eu/ecb/pub/pdf/annex/ssm.nl251120_1_annex.en.pdf",2025,"1. **Define the record.** One schema for every AI system: owner, business purpose, users,\n   vendor or in house, model and version, data categories (including personal data), autonomy\n   level, risk tier under internal policy and the EU AI Act, approval status, review date and\n   links to documentation.\n2. **Discover what is actually running.** An agent reconciles the register against evidence\n   sources: procurement and contract records, SaaS and API usage logs, cloud and model platform\n   accounts, code repositories and network egress to AI services. Anything that looks like AI and\n   has no entry becomes a candidate record for an owner to confirm or retire.\n3. **Draft the entry from the documents.** Document AI reads model cards, vendor documentation,\n   data protection impact assessments and approval minutes and pre fills the record, citing the\n   page each field came from. The owner confirms or corrects every field.\n4. **Classify and route.** The draft risk tier and the triggers for deeper review (personal data,\n   decisions about people, customer facing use, material service provider) are proposed by rules\n   plus a model, and a governance officer decides.\n5. **Keep it current.** Scheduled checks flag records past their review date, models whose\n   version changed, vendors whose terms changed and systems whose usage jumped.\n6. **Answer and assemble.** Staff and auditors ask questions in plain language (\"which customer\n   facing systems use personal data and a third party model?\") and get answers with links to the\n   records, and the agent assembles the evidence pack for a named system on request.",[47,48,49,50],"compliance","risk-reduction","employee-productivity","speed",[52,53,54,55],"hours-saved","time-saved-per-task","productivity-gain","accuracy",{"referenceOrg":57,"inputs":58,"formula":105,"currency":106,"period":107,"resultLabel":108,"caveat":109},"A bank or insurer with 150 AI systems and models in scope of its AI policy",[59,65,72,79,86,92,99],{"key":60,"label":61,"low":62,"high":63,"unit":60,"note":64},"systems","AI systems and models in the register",100,200,"Editorial assumption for a mid sized regulated firm, counting vendor AI and generative AI tools. Replace with your own count.",{"key":66,"label":67,"low":68,"high":69,"unit":70,"note":71},"hoursPerSystem","Manual effort per system per year to discover, document, attest and review",8,20,"hours per system per year","Editorial assumption covering the owner, the second line reviewer and the inventory administrator. Replace with your own time study.",{"key":73,"label":74,"low":75,"high":76,"unit":77,"note":78},"automationShare","Share of that effort the discovery and drafting removes",0.25,0.45,"fraction of effort","Editorial assumption; no public benchmark exists yet. Owners still confirm every field.",{"key":80,"label":81,"low":82,"high":83,"unit":84,"note":85},"requests","Evidence requests per year from supervisors, auditors and the board",6,15,"requests per year","Editorial assumption. Replace with your own count of inventory related requests.",{"key":87,"label":88,"low":69,"high":89,"unit":90,"note":91},"hoursPerRequest","Hours to assemble one evidence pack by hand",60,"hours per request","Editorial assumption.",{"key":93,"label":94,"low":95,"high":96,"unit":97,"note":98},"requestReduction","Share of evidence assembly time saved",0.3,0.5,"fraction of time","Editorial assumption; assembly still needs a human review before anything leaves the firm.",{"key":100,"label":101,"low":89,"high":102,"unit":103,"note":104},"hourlyCost","Fully loaded cost of a risk or technology specialist hour",110,"USD per hour","Editorial assumption. Replace with your own rate.","(systems * hoursPerSystem * automationShare + requests * hoursPerRequest * requestReduction) * hourlyCost","USD","per year","Specialist time released from inventory upkeep and evidence assembly","Time released only. It leaves out the value that matters most and is hardest to price: the incidents, fines and failed audits avoided because shadow AI is found early, and the faster approval of new AI use cases once the register is trusted. It also leaves out the cost of the discovery integrations.",[],{"complexity":112,"complexityNote":113,"dataPrerequisites":114,"integrations":120},"medium","Keeping a register is easy; keeping it true is the work. Discovery needs read access to procurement, SaaS, cloud and network data, which crosses several owners, and the risk classification needs a written policy before any AI can apply it.",[115,116,117,118,119],"A written AI policy with a definition of what counts as AI and a risk tiering method","The current register, however incomplete, and the list of approved AI tools and vendors","Procurement and contract records that show which suppliers provide AI features","Usage logs from SaaS administration, cloud accounts, API gateways and network egress","Model cards, vendor documentation, impact assessments and approval records",[121,122,123,124,125,126],"Governance, risk and compliance platform or the existing model inventory","Procurement and contract management system","SaaS management, identity provider and cloud accounts for usage signals","Code repositories and model registries","Document stores holding model documentation and approvals","Ticketing or workflow tool for owner attestations",{"steps":128,"guardrails":147,"humanInTheLoop":153,"kpisToInstrument":154,"failureModes":160},[129,132,135,138,141,144],{"title":130,"detail":131},"Write the definition and the schema first","Agree what counts as an AI system (include vendor features and general purpose assistants), the mandatory fields and the risk tiers. Map the tiers to the EU AI Act categories and to your sector rules so one record answers every framework.",{"title":133,"detail":134},"Seed from what you already know","Load the existing register, the model risk inventory, the approved tool list and the procurement records. Deduplicate before adding anything new, as the US Department of Justice did when it combined similar, widely adopted AI use cases into single department wide entries.",{"title":136,"detail":137},"Add discovery sources one at a time","Start with the highest yield signals (SaaS admin consoles, API keys to model providers, network egress to AI domains), and route each unregistered hit to a named owner as a candidate record, not as an accusation.",{"title":139,"detail":140},"Let AI draft, owners confirm","Pre fill records from documents with a citation per field, then ask the owner to confirm. Measure how often owners correct the draft and fix the extraction where corrections cluster.",{"title":142,"detail":143},"Put the register in the approval path","No production release, contract signature or tool enablement without a record. This is what keeps the register current after the first clean up.",{"title":145,"detail":146},"Rehearse the evidence request","Pick one high risk system and ask for the full evidence pack as a supervisor would, time it, and fix the gaps before the real request arrives.",[148,149,150,151,152],"The AI proposes records, tiers and links; a named human owner confirms every record and a governance officer approves every risk tier","Every field drafted from a document cites the source document and page","Discovery reads metadata and usage signals, not the content of employee prompts, unless policy and law allow it","The register itself is access controlled and logged, because it maps the organization's most sensitive systems","The inventory agent is itself an entry in the register, with its own owner and review date","Owners attest to their records, the second line approves risk tiers and exceptions, and the AI governance committee decides on retiring or blocking unregistered systems. The AI never changes an approval status or blocks a tool on its own.",[155,156,157,158,159],"Coverage, the share of discovered AI systems that have a confirmed record","Number of unregistered systems found per month and time from discovery to confirmed record or retirement","Share of records past their review date","Owner correction rate on AI drafted fields","Hours to assemble an evidence pack for one system",[161,164,167,170],{"title":162,"detail":163},"The register is complete on paper only","Teams fill it in once at approval and never again. Tie the record to release, contract renewal and tool enablement, and flag records whose model version or usage changed.",{"title":165,"detail":166},"Discovery as surveillance","Reading employee prompts to find shadow AI creates a privacy and trust problem. Use metadata and usage signals first, involve the works council or employee representatives where required, and offer an approved alternative for every tool you block.",{"title":168,"detail":169},"Confident but wrong classification","A model tier that looks authoritative gets copied into reports without review. Keep the tier as a proposal until a named person approves it and record who did.",{"title":171,"detail":172},"Definition too narrow","Only in house machine learning models get registered, while vendor features and generative AI assistants carry most of the new risk. Include anything that infers outputs from input, as the EU AI Act definition does.",{"euAiAct":174,"regulations":177,"guidance":187,"controls":218,"incidents":224},{"tier":175,"basis":176},"context-dependent","Minimal for a system level register of systems and owners with no monitoring of individual employees; it is not listed in Annex III and is the instrument deployers use to meet obligations such as the Article 26 duties for high risk systems and the Article 49 registration of Annex III systems in the EU database. Limited where the plain language assistant that staff and auditors query is not obviously an AI system to its users: under Article 50(1) its provider must then design it so people are told they are dealing with AI. Possibly high risk under Annex III point 4(b) on worker management if the discovery process monitors or evaluates the behavior of individual employees rather than staying at the level of systems and owners.",[178,179,180,181,182,183,184,185,186],"eu-ai-act","iso-42001","nist-ai-rmf","mas-ai-risk-management","dora","gdpr","apra-cps-230","us-sr-11-7","pra-ss1-23",[188,194,198,204,210,215],{"title":189,"issuer":190,"region":191,"url":192,"note":193},"Article 49: Registration","European Union","europe","https://artificialintelligenceact.eu/article/49/","Providers register high risk systems listed in Annex III in the EU database before placing them on the market or putting them into service (critical infrastructure systems under point 2 are registered nationally), and deployers that are public authorities register their use; an internal register is the practical source for that data.",{"title":195,"issuer":190,"region":191,"url":196,"note":197},"Article 26: Obligations of deployers of high risk AI systems","https://artificialintelligenceact.eu/article/26/","Deployers must monitor the operation of high risk systems, keep logs and assign human oversight, which presumes they know which systems they deploy.",{"title":199,"issuer":200,"region":201,"url":202,"note":203},"MAS Guidelines for Artificial Intelligence (AI) Risk Management, consultation paper","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Financial institutions are expected to identify AI usage across the firm, maintain accurate and up to date AI inventories and assess risk materiality.",{"title":205,"issuer":206,"region":207,"url":208,"note":209},"AI RMF Core, GOVERN 1.6","NIST","north-america","https://airc.nist.gov/airmf-resources/airmf/5-sec-core/","Mechanisms are in place to inventory AI systems, resourced according to organizational risk priorities.",{"title":211,"issuer":212,"region":207,"url":213,"note":214},"M-25-21: Accelerating Federal Use of AI through Innovation, Governance, and Public Trust","US Office of Management and Budget","https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-21-Accelerating-Federal-Use-of-AI-through-Innovation-Governance-and-Public-Trust.pdf","Federal agencies must inventory AI use cases at least annually, submit them to OMB and publish a public version; a useful template for the fields a register needs.",{"title":42,"issuer":216,"region":191,"url":43,"note":217},"ECB Banking Supervision","Supervisory observations from 13 bank workshops, including AI systems inventories, AI Act self assessments and, as an emerging practice, automated tools that monitor the inventory and workflow.",[219,220,221,222,223],"A single register with an accountable owner per record and a documented definition of AI","Record required before production release, contract signature or tool enablement","Periodic attestation by owners and validation of the register by the second line","Audit trail of every change to a record, tier or approval status","Approved alternatives for common generative AI tasks, so blocking shadow AI does not stop the work",[225],{"title":226,"url":227,"note":228},"CB Financial Services 8-K, Item 1.05: customer data handled in an unauthorized AI application","https://www.sec.gov/Archives/edgar/data/1605301/000160530126000021/cbfv-20260507.htm","CB Financial Services disclosed in May 2026 that its subsidiary Community Bank had found non public customer information, including names, social security numbers and dates of birth, handled with an unauthorized artificial intelligence based application, and judged the incident material.",{"howToBuild":230},"On Blits.ai the inventory assistant is an **AI agent** that answers questions over the register,\nwhich lives in a **SQL knowledge base** so every answer comes from the records themselves, and a\n**knowledge base** with **hybrid retrieval** over model cards, vendor documents and approvals. An\n**agentic workflow**, triggered **on a schedule**, calls **custom functions** (REST calls to the\nprocurement system, SaaS admin consoles and the governance platform) to compare usage signals\nwith the register and draft candidate records, with **human in the loop confirmation** before\nanything is written back. Connectors from the **integration catalog** (for example ServiceNow,\nSAP, Okta, Jira, SharePoint) and **MCP** servers extend the discovery sources.\n\nOwners receive attestation requests and answer in **Microsoft Teams** or email. **PII masking**\nkeeps personal data out of prompts, **run history with a full audit trail** records every draft\nand every approval, and **test suites** check the agent's answers against the register before\neach change. The platform is model agnostic, so the inventory agent itself can run on the model\nthe organization has approved, and **EU and UAE data residency** keeps the register in region.",[232,235,238,241],{"question":233,"answer":234},"What should an AI inventory record for each system?","At minimum the owner, purpose, users, vendor or in house status, model and version, data used (including personal data), risk tier, approval status and review date. The US federal inventory is a useful public template: the Federal Reserve Board records stage, purpose, vendor, data, personal data involvement and high impact designation for each use case.",{"question":236,"answer":237},"How do you find shadow AI without monitoring employees' prompts?","Start with metadata: SaaS administration consoles, API keys to model providers, procurement records and network egress to AI services. Route each hit to a named owner to confirm or retire, and offer an approved alternative, because blocking alone pushes use further out of sight.",{"question":239,"answer":240},"Is an AI inventory required by the EU AI Act?","The Act does not set a general inventory duty, but its obligations presume one: deployers of high risk systems must monitor them and assign human oversight, and providers (and deployers that are public authorities) must register Annex III high risk systems in the EU database. Sector supervisors go further: the Monetary Authority of Singapore's proposed guidelines expect financial institutions to maintain accurate, up to date AI inventories.",{"question":242,"answer":243},"Can AI maintain the inventory on its own?","No, and it should not. AI can discover candidates, pre fill records from documents and flag stale entries, but an accountable owner confirms each record and a governance officer approves the risk tier. The inventory agent is itself a system in the register.",[245,246,247,248,249],"model-risk-validation-copilot","internal-audit-copilot","continuous-controls-testing","vendor-due-diligence","regulatory-horizon-scanning","2026-09-27",[252],{"date":250,"note":253},"First published","ai-model-inventory",[256,283,317,338],{"title":257,"useCases":258,"organization":259,"vendors":263,"summary":264,"stage":265,"year":44,"channels":266,"languages":267,"metrics":269,"outcomeDisclosed":261,"sources":270,"verification":277,"grade":280,"id":281,"organizationSlug":282},"Federal Reserve Board: AI use case inventory and high impact review",[254],{"name":260,"anonymized":261,"country":262,"region":207,"industry":21},"Board of Governors of the Federal Reserve System",false,"US",[],"The Federal Reserve Board runs a central AI Program that collects every AI use case in Board work and in functions delegated to the Reserve Banks, checks each against the Board's AI policy, screens it for high impact characteristics and routes it to the matching governance path. Use cases sit in a common repository that supports reporting and ongoing tracking and is validated periodically. The 2025 public inventory records, per use case, the stage, purpose, vendor, data used, personal data involvement and high impact designation.","production",[33],[268],"en",[],[271,274],{"url":272,"title":273,"publisher":260},"https://www.federalreserve.gov/publications/files/compliance-plan-for-omb-memorandum-m-25-21-202509.pdf","Compliance Plan for OMB Memorandum M-25-21",{"url":275,"title":276,"publisher":260},"https://www.federalreserve.gov/AI-use-case-inventory-2025.htm","AI Use Case Inventory 2025",{"level":278,"checkedAt":279},"source-verified","2026-09-26","B","federal-reserve-board-ai-use-case-inventory","board-of-governors-of-the-federal-reserve-system",{"title":284,"useCases":285,"organization":286,"vendors":288,"summary":289,"stage":290,"year":44,"channels":291,"languages":292,"metrics":293,"outcomeDisclosed":303,"sources":304,"verification":314,"grade":280,"id":315,"organizationSlug":316},"US federal government: consolidated AI use case inventory",[254],{"name":287,"anonymized":261,"country":262,"region":207,"industry":21},"Office of Management and Budget",[],"US federal agencies must inventory their AI use cases every year, submit the inventory to the Office of Management and Budget and publish the releasable part as machine readable data. OMB consolidates the agency inventories in a public repository with a fixed schema (purpose, stage, vendor, data, risk designation). The 2025 consolidation, as of 13 April 2026, lists 3,611 individually reported AI use cases, 445 of them high impact, plus separately consolidated commercial off the shelf AI uses; the 2024 consolidation listed 2,133 use cases from 41 agency submissions.","scaled",[33],[268],[294],{"kpi":295,"value":296,"unit":297,"qualifier":298,"period":299,"claimant":300,"quote":301,"sourceUrl":302},"ai-systems-inventoried",3611,"count","exact","2025 consolidated federal inventory, individually reported use cases in all stages, as of 13 April 2026","organization","3,611 individually-reported AI use cases (all stages of development)","https://github.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory",true,[305,308,312],{"url":302,"title":306,"publisher":307},"2025 Federal Agency AI Use Case Inventory","Office of Management and Budget (GitHub)",{"url":309,"title":310,"publisher":307,"date":311},"https://github.com/ombegov/2024-Federal-AI-Use-Case-Inventory","2024 Federal Agency AI Use Case Inventory","2025-01-23",{"url":213,"title":211,"publisher":287,"date":313},"2025-04-03",{"level":278,"checkedAt":279},"omb-federal-ai-use-case-inventory",null,{"title":318,"useCases":319,"organization":320,"vendors":322,"summary":323,"stage":290,"year":44,"channels":324,"languages":325,"metrics":326,"outcomeDisclosed":303,"sources":332,"verification":335,"grade":280,"id":336,"organizationSlug":337},"US Department of Justice: consolidated 2025 AI use case inventory",[254],{"name":321,"anonymized":261,"country":262,"region":207,"industry":21},"U.S. Department of Justice",[],"The Department of Justice consolidates the AI use cases of all its components into one annual inventory, reviewed by component representatives on its Emerging Technology Board with the Chief AI Officer. The 2025 inventory covers use cases in every stage from pre deployment to retired, combines similar, widely adopted AI use cases into single department wide entries and removes duplicate or mislabeled entries. It holds 315 entries, 30.7% more than the 2024 inventory, which DOJ attributes to closer collaboration between components to accelerate AI adoption.",[33],[268],[327],{"kpi":295,"value":328,"unit":297,"qualifier":298,"period":329,"claimant":300,"quote":330,"sourceUrl":331},315,"2025 inventory","The 2025 AI Use Case Inventory includes 315 entries, a 30.7% increase from the 2024 inventory.","https://www.justice.gov/ai/ai-inventory",[333],{"url":331,"title":334,"publisher":321},"AI Inventory",{"level":278,"checkedAt":279},"us-department-of-justice-ai-use-case-inventory","u-s-department-of-justice",{"title":339,"useCases":340,"organization":341,"vendors":344,"summary":348,"stage":290,"year":349,"channels":350,"languages":351,"metrics":352,"outcomeDisclosed":261,"sources":353,"verification":364,"grade":365,"id":366,"organizationSlug":316},"Unilever: AI inventory and assurance process with Holistic AI",[254],{"name":342,"anonymized":261,"country":343,"region":191,"industry":22},"Unilever","GB",[345],{"name":346,"role":347},"Holistic AI","platform","Unilever built an AI assurance process in which every new AI application, broadly defined to include any prediction or automation, is registered, triaged and rated red, amber or green for effectiveness and ethical risk before it goes into production. Holistic AI co created the inventory and risk management platform that the data ethics team uses to track submissions, completeness and risk ratings across a decentralised global business, with a growing share of assessments mapped to the EU AI Act. No quantified outcome is published in a form that can be quoted as a sentence.",2023,[33],[268],[],[354,358,361],{"url":355,"title":356,"publisher":357},"https://sloanreview.mit.edu/article/ai-ethics-at-unilever-from-policy-to-process","AI Ethics at Unilever: From Policy to Process","MIT Sloan Management Review",{"url":359,"title":360,"publisher":346},"https://uploads-ssl.webflow.com/6305e5d52c28356b4fe71bac/63dce08cf171bb4803af691c_Holistic-AI-Case-Study-Unilever.pdf","Case Study: AI Inventory and Risk Management for Unilever",{"url":362,"title":363,"publisher":346},"https://www.holisticai.com/how-we-helped-unilever","How We Helped Unilever",{"level":278,"checkedAt":279},"C","unilever-ai-inventory-and-assurance",0,[],{"low":370,"high":371},14160,247500,[373,392,413,427,441],{"slug":245,"title":374,"shortTitle":375,"definition":376,"status":9,"industries":377,"functions":380,"patterns":381,"audience":35,"autonomy":36,"adoptionStage":384,"segment":385,"evidenceCount":386,"publicEvidenceCount":386,"organizations":387,"bestGrade":280,"headline":316,"lastVerified":391,"indexable":303},"AI copilot for model risk validation and monitoring","Model risk validation","A copilot for independent model validation and review, whether run by a bank's validation function, an external tester or a supervisor, that checks model documentation against the model risk standard, generates and scores challenger tests (for generative AI, often with an LLM as a judge calibrated against human experts), watches production models for drift and drafts and consistency checks the validation report. An accountable validator owns every conclusion.",[19,20,378,379],"capital-markets","wealth-and-asset-management",[24,25],[28,29,382,383],"content-generation","anomaly-detection","emerging","second-line",3,[388,389,390],"European Central Bank (ECB Banking Supervision)","Standard Chartered","United Overseas Bank (UOB)","2026-09-28",{"slug":246,"title":393,"shortTitle":394,"definition":395,"status":9,"industries":396,"functions":397,"patterns":399,"audience":35,"autonomy":36,"adoptionStage":37,"evidenceCount":386,"publicEvidenceCount":386,"organizations":401,"bestGrade":365,"headline":405,"lastVerified":250,"indexable":303},"Generative AI copilot for internal audit","Internal audit copilot","A copilot for internal auditors that drafts planning memos and document request lists from prior audits, summarises large evidence sets, builds risk and control matrices from policies and process documents, and drafts findings and reports, with every statement traceable to its evidence and a qualified auditor accountable for every conclusion.",[18,19,20,21,378,379],[24,25,398],"finance-and-accounting",[30,400,382,29,383],"summarization",[402,403,404],"Banco Bradesco","British Columbia Investment Management Corporation","XP Inc.",{"kpi":406,"label":407,"unit":408,"n":409,"nUpTo":367,"kind":410,"value":411,"qualifier":298,"claimant":412,"organization":402,"vendorReported":303},"handling-time-reduction","Handling time reduction","percent",2,"reported",55,"vendor",{"slug":247,"title":414,"shortTitle":415,"definition":416,"status":9,"industries":417,"functions":418,"patterns":420,"audience":421,"autonomy":422,"adoptionStage":384,"segment":385,"evidenceCount":386,"publicEvidenceCount":386,"organizations":423,"bestGrade":280,"headline":316,"lastVerified":250,"indexable":303},"AI for continuous controls testing and control self assessment","Continuous controls testing","AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.",[18,19,20,378,21],[24,25,419],"operations",[28,29,383,31],"back-office","supervised-agent",[424,425,426],"Federal Deposit Insurance Corporation","U.S. Department of the Interior","Pension Benefit Guaranty Corporation",{"slug":248,"title":428,"shortTitle":429,"definition":430,"status":9,"industries":431,"functions":433,"patterns":435,"audience":35,"autonomy":36,"adoptionStage":37,"segment":385,"evidenceCount":436,"publicEvidenceCount":436,"organizations":437,"bestGrade":280,"headline":316,"lastVerified":250,"indexable":303},"AI for third party and vendor risk due diligence","Vendor due diligence","AI that reviews a vendor's security questionnaires, SOC and assurance reports, contracts and model documentation against the organization's control requirements, researches the vendor's ownership, sanctions, financial health and adverse media, drafts the risk assessment for a human to approve and keeps the register of material service providers current with ongoing monitoring.",[18,19,20,21,432],"payments",[434,24,25],"procurement",[29,30,28,400],4,[321,438,439,440],"Internal Revenue Service","U.S. Department of Agriculture","U.S. Trade and Development Agency",{"slug":249,"title":442,"shortTitle":443,"definition":444,"status":9,"industries":445,"functions":447,"patterns":449,"audience":35,"autonomy":450,"adoptionStage":37,"segment":47,"evidenceCount":436,"publicEvidenceCount":409,"organizations":451,"bestGrade":280,"headline":316,"lastVerified":250,"indexable":303},"AI regulatory horizon scanning and obligation mapping","Regulatory horizon scanning","An AI system that continuously reads publications from the regulators and standard setters an organization answers to, classifies each item by relevance and urgency, breaks new rules into individual obligations and maps them to the internal policies and controls that meet them, so compliance owners see what changed and where the gaps are.",[18,19,20,432,379,446,21],"pharma-and-life-sciences",[25,448,24],"legal",[31,29,30,400,28],"assist",[452,453],"Financial Conduct Authority","Administration for Children and Families",{"indexable":303,"reasons":455},[],[457,462,467,473,478,483,490,496,500,506,512,517,524,530,536,541,548,554,560,566,572,578,584,589,594,601,607,612,617,625,630,636,642,647],{"id":178,"label":458,"issuer":190,"region":191,"url":459,"description":460,"useCases":461,"indexable":303},"EU AI Act","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":183,"label":463,"issuer":190,"region":191,"url":464,"description":465,"useCases":466,"indexable":303},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":179,"label":468,"issuer":469,"region":470,"url":471,"description":472,"useCases":102,"indexable":303},"ISO/IEC 42001","ISO and IEC","global","https://www.iso.org/standard/81230.html","The international management system standard for AI.",{"id":180,"label":474,"issuer":206,"region":207,"url":475,"description":476,"useCases":477,"indexable":303},"NIST AI Risk Management Framework","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":182,"label":479,"issuer":190,"region":191,"url":480,"description":481,"useCases":482,"indexable":303},"DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":484,"label":485,"issuer":486,"region":191,"url":487,"description":488,"useCases":489,"indexable":303},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":491,"label":492,"issuer":452,"region":191,"url":493,"description":494,"useCases":495,"indexable":303},"uk-consumer-duty","FCA Consumer Duty","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":181,"label":497,"issuer":200,"region":201,"url":202,"description":498,"useCases":499,"indexable":303},"MAS AI risk management guidelines","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":184,"label":501,"issuer":502,"region":201,"url":503,"description":504,"useCases":505,"indexable":303},"APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":507,"label":508,"issuer":509,"region":470,"url":510,"description":511,"useCases":69,"indexable":303},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",{"id":185,"label":513,"issuer":514,"region":207,"url":515,"description":516,"useCases":69,"indexable":303},"SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":518,"label":519,"issuer":520,"region":191,"url":521,"description":522,"useCases":523,"indexable":303},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":525,"label":526,"issuer":527,"region":470,"url":528,"description":529,"useCases":83,"indexable":303},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",{"id":531,"label":532,"issuer":190,"region":191,"url":533,"description":534,"useCases":535,"indexable":303},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":537,"label":538,"issuer":190,"region":191,"url":539,"description":540,"useCases":535,"indexable":303},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":542,"label":543,"issuer":544,"region":207,"url":545,"description":546,"useCases":547,"indexable":303},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":549,"label":550,"issuer":190,"region":191,"url":551,"description":552,"useCases":553,"indexable":303},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":555,"label":556,"issuer":557,"region":207,"url":558,"description":559,"useCases":553,"indexable":303},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":561,"label":562,"issuer":563,"region":470,"url":564,"description":565,"useCases":553,"indexable":303},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":567,"label":568,"issuer":190,"region":191,"url":569,"description":570,"useCases":571,"indexable":303},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":573,"label":574,"issuer":575,"region":207,"url":576,"description":577,"useCases":571,"indexable":303},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":579,"label":580,"issuer":200,"region":201,"url":581,"description":582,"useCases":583,"indexable":303},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",10,{"id":585,"label":586,"issuer":190,"region":191,"url":587,"description":588,"useCases":583,"indexable":303},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":590,"label":591,"issuer":190,"region":191,"url":592,"description":593,"useCases":583,"indexable":303},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":595,"label":596,"issuer":597,"region":191,"url":598,"description":599,"useCases":600,"indexable":303},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":602,"label":603,"issuer":604,"region":207,"url":605,"description":606,"useCases":68,"indexable":303},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",{"id":608,"label":609,"issuer":190,"region":191,"url":610,"description":611,"useCases":68,"indexable":303},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":613,"label":614,"issuer":190,"region":191,"url":615,"description":616,"useCases":82,"indexable":303},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",{"id":618,"label":619,"issuer":620,"region":621,"url":622,"description":623,"useCases":624,"indexable":303},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",5,{"id":186,"label":626,"issuer":627,"region":191,"url":628,"description":629,"useCases":436,"indexable":303},"PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":631,"label":632,"issuer":633,"region":191,"url":634,"description":635,"useCases":436,"indexable":303},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":637,"label":638,"issuer":639,"region":201,"url":640,"description":641,"useCases":386,"indexable":303},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":643,"label":644,"issuer":190,"region":191,"url":645,"description":646,"useCases":386,"indexable":303},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":648,"label":649,"issuer":650,"region":207,"url":651,"description":652,"useCases":386,"indexable":303},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598306607]