[{"data":1,"prerenderedAt":588},["ShallowReactive",2],{"uc-complaints-root-cause-analysis":3,"uc-regulations":380},{"useCase":4,"evidence":202,"blitsAiDeployments":274,"benchmarks":275,"indicative":276,"related":279,"indexability":378,"includeUnpublished":208},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":16,"functions":23,"patterns":27,"channels":32,"audience":34,"autonomy":35,"adoptionStage":36,"segment":37,"problem":38,"problemStats":39,"howItWorks":45,"valueDrivers":46,"kpis":51,"indicativeValue":56,"macroEstimates":90,"feasibility":91,"implementation":104,"risk":147,"blitsAi":179,"faq":181,"related":191,"datePublished":197,"dateModified":197,"lastVerified":197,"changelog":198,"slug":201},"AI for complaints root cause and systemic issue analysis","Complaints root cause analysis","AI for complaints root cause analysis","AI groups every complaint into themes and traces themes to likely causes for analysts to validate. The Federal Reserve Board clusters complaints; CMS pilots it.","published","AI that reads the free text of complaints across all channels, clusters them into themes, separates systemic causes from one off events, links each theme to the product, process or control behind it and routes the insight to the owner who can fix it, with a human validating every root cause and every remediation.",[12,13,14,15],"complaint theme analysis","systemic issue detection","complaints insight analytics","voice of the customer root cause",[17,18,19,20,21,22],"cross-industry","banking","insurance","payments","telecommunications","government",[24,25,26],"regulatory-compliance","customer-service","analytics-and-reporting",[28,29,30,31],"classification-and-routing","summarization","agentic-workflow","rag-knowledge-assistant",[33],"internal-tools","back-office","copilot","emerging","second-line","Every complaint is handled one by one, but the reason it happened is rarely unique. The same\nunclear letter, broken app journey or misapplied fee produces hundreds of complaints, spread\nacross phone notes, emails, chat logs and ombudsman referrals, each coded slightly differently\nby a different handler. Complaint categories are built for handling and reporting volumes, not\nfor finding causes, so management information shows how many complaints arrived, not why.\n\nRegulators expect more. UK rules require firms to identify and remedy recurring or systemic\nproblems, and the FCA's review of complaints and root cause analysis at 40 firms found that\nfirms did not always measure whether their fixes worked, and that some complaints reports appeared\nto be prepared for operational purposes such as resourcing without also looking at how to improve\ncustomer outcomes. Manual root cause work at this volume often relies on samples, and the theme that matters most\ncan be the one nobody sampled.",[40],{"statement":41,"sourceTitle":42,"sourceUrl":43,"year":44},"The FCA's thematic review of complaints and root cause analysis at 40 firms found that firms did not always measure the impact of the changes they made after finding a root cause.","Complaints and root cause analysis: good practice and areas for improvement","https://www.fca.org.uk/publications/good-and-poor-practice/complaints-and-root-cause-analysis-good-practice-and-areas-improvement",2024,"1. **Collect every complaint.** Complaint records, call and chat transcripts, emails and\n   ombudsman cases land in one store with product, channel, outcome and customer segment.\n2. **Normalise and deduplicate.** The AI summarises each complaint in a standard form, removes\n   duplicates about the same event and tags vulnerability signals.\n3. **Cluster into themes.** Complaints are grouped by what actually went wrong, not by the code\n   a handler picked, and each theme gets a plain language description with example cases.\n4. **Trace to a cause.** Retrieval over process maps, product terms, change logs and the control\n   library links each theme to the likely process, product change or control failure, and flags\n   themes that grow, spread across products or hit vulnerable customers.\n5. **Validate and assign.** A root cause analyst validates the theme and the cause on a sample,\n   then assigns an owner in the business, not the complaints team.\n6. **Track the fix.** Actions, owners and dates are tracked, and the AI measures whether the\n   theme shrinks after the fix, which is the evidence regulators ask for.",[47,48,49,50],"compliance","customer-experience","risk-reduction","cost-to-serve",[52,53,54,55],"processing-time-reduction","productivity-gain","accuracy","interactions-handled",{"referenceOrg":57,"inputs":58,"formula":85,"currency":86,"period":87,"resultLabel":88,"caveat":89},"A retail bank receiving 100,000 complaints a year",[59,65,72,78],{"key":60,"label":61,"low":62,"high":62,"unit":63,"note":64},"complaints","Complaints received per year",100000,"complaints per year","The reference bank. Replace with your own volume.",{"key":66,"label":67,"low":68,"high":69,"unit":70,"note":71},"systemicShare","Share of complaints linked to a fixable systemic cause",0.1,0.2,"fraction of complaints","Editorial assumption. Replace with the share your own root cause work attributes to recurring causes.",{"key":73,"label":74,"low":69,"high":75,"unit":76,"note":77},"avoided","Share of those complaints avoided after the cause is fixed",0.4,"fraction of systemic complaints","Editorial assumption, replace with your own. No public benchmark exists yet.",{"key":79,"label":80,"low":81,"high":82,"unit":83,"note":84},"costPerComplaint","Fully loaded cost of handling one complaint",150,300,"USD per complaint","Editorial assumption covering handling time and review, excluding redress. Replace with your own.","complaints * systemicShare * avoided * costPerComplaint","USD","per year","Complaint handling cost avoided by fixing systemic causes","Handling cost only. It leaves out redress and remediation programmes avoided, ombudsman fees, the customer and conduct benefit and the cost of the fixes themselves, and it assumes the business acts on the insight.",[],{"complexity":92,"complexityNote":93,"dataPrerequisites":94,"integrations":99},"medium","Clustering text is straightforward; linking themes to causes needs process, product and change data, and the value depends on a governance route that makes business owners act.",[95,96,97,98],"Complaint records with free text, product, channel, outcome and redress","Call and chat transcripts or notes linked to the complaint","Process maps, product terms, change and incident logs, and the control library","A small set of complaints with expert validated root causes for testing",[100,101,102,103],"Complaints and case management system","Contact centre transcripts and conversation analytics","Change management, incident and control library (GRC) systems","Business intelligence and conduct risk reporting",{"steps":105,"guardrails":121,"humanInTheLoop":127,"kpisToInstrument":128,"failureModes":134},[106,109,112,115,118],{"title":107,"detail":108},"Build the evidence base first","Bring complaint text, transcripts and outcomes together for at least twelve months, with vulnerability and redress fields, before any modelling. Themes need history to show trend.",{"title":110,"detail":111},"Let themes emerge, then fix the taxonomy","Run clustering on the full population, have root cause analysts name and merge themes, and publish a stable theme list. Keep complaint handling codes separate.",{"title":113,"detail":114},"Link themes to owners","Map each theme to a process, product and control owner using the control library and change log, so insight goes to the person who can fix it, not back to complaints.",{"title":116,"detail":117},"Validate on samples","For every theme, analysts review a sample of complaints against the AI description and record agreement. Themes below the agreement threshold are not reported.",{"title":119,"detail":120},"Close the loop","Track actions to closure and measure the theme's volume and severity after each fix, and report both to the conduct or risk committee.",[122,123,124,125,126],"A human root cause analyst validates every theme and cause before it is reported or actioned","Every theme links to example complaints so a reviewer can check it","Personal data masked in prompts; outputs report themes, not individual customers","Vulnerability and detriment themes always escalate, regardless of volume","Theme definitions and model changes are versioned so trends stay comparable","Root cause analysts validate themes and causes, business owners decide the remediation, and the conduct or risk committee reviews progress. The AI never decides redress or closes an individual complaint.",[129,130,131,132,133],"Share of complaints read by the analysis (target the full population, not a sample)","Analyst agreement rate with AI themes and causes on samples","Time from a theme emerging to an owner being assigned","Complaint volume per theme before and after remediation","Share of remediation actions with measured impact",[135,138,141,144],{"title":136,"detail":137},"Themes that mirror the handling codes","The model learns the existing categories and finds nothing new. Cluster on the free text and compare with codes, rather than training on codes.",{"title":139,"detail":140},"Insight with no owner","Reports go back to the complaints team and nothing changes. Route every validated theme to a named business owner with a date.",{"title":142,"detail":143},"Plausible but wrong causes","The AI attributes a theme to a recent change because it is in the retrieved context. Require evidence and analyst validation before a cause is reported.",{"title":145,"detail":146},"Volume blindness","Small but severe themes, such as harm to vulnerable customers, are ranked low. Weight by severity and vulnerability, not volume alone.",{"euAiAct":148,"regulations":151,"guidance":157,"controls":172,"incidents":178},{"tier":149,"basis":150},"minimal","Analysing complaints in aggregate to find causes is not listed in Annex III, is not a practice prohibited by Article 5 and does not decide on individuals. It does not interact with the public, so the disclosure duty in Article 50(1) does not apply; the machine readable marking of generated text in Article 50(2) is a duty of the provider of the generative model or system that writes the summaries. If the same system decided individual complaint outcomes or redress, or its themes were used to evaluate the performance of individual complaint handlers (Annex III point 4), that design would need its own assessment.",[152,153,154,155,156],"uk-consumer-duty","gdpr","uk-gdpr","eu-ai-act","iso-42001",[158,164,166],{"title":159,"issuer":160,"region":161,"url":162,"note":163},"DISP 1.3 Complaints handling rules","Financial Conduct Authority","europe","https://www.handbook.fca.org.uk/handbook/DISP/1/3.html","Firms must put management controls in place to identify and remedy any recurring or systemic problems found in complaints.",{"title":42,"issuer":160,"region":161,"url":43,"note":165},"Thematic review of 40 firms with examples of good practice, including involving the owner of the process in root cause work and measuring the impact of fixes.",{"title":167,"issuer":168,"region":169,"url":170,"note":171},"RG 271 Internal dispute resolution","Australian Securities and Investments Commission","asia-pacific","https://asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-271-internal-dispute-resolution/","ASIC's standards for internal dispute resolution by Australian financial firms. Enforceable paragraph RG 271.120 requires firms to regularly analyse complaint data sets to identify systemic issues and escalate them for investigation and action.",[173,174,175,176,177],"Documented method for theme detection and cause attribution, owned by the complaints or conduct function","Sample based validation with recorded agreement rates per theme","Action log from theme to owner to fix to measured impact","Regular reporting of themes and actions to senior management and the board","Data protection impact assessment for the use of complaint text and transcripts",[],{"howToBuild":180},"On Blits.ai this is an **agentic workflow** that runs on a schedule over new complaints. It reads\ncomplaint records and transcripts through **custom functions** and a **SQL knowledge base**,\nsummarises each case into **structured output**, and groups cases into themes. A **knowledge\nbase** with hybrid retrieval over process documents, product terms and the control library lets\nthe agent propose the likely cause from the retrieved documents.\n\n**Human in the loop approval** holds each proposed theme and cause until a root cause analyst\napproves it, and only approved themes are pushed to the owner's case system. Complaint extracts\nare masked or redacted before ingestion, as a design step in the customer's own pipeline, **test\nsuites** evaluate theme and cause quality against expert labelled samples, and per run audit trails show how\nevery reported theme was built. The platform is model agnostic and supports EU and UAE data\nresidency.",[182,185,188],{"question":183,"answer":184},"How is this different from AI complaint handling?","Complaint handling works one complaint at a time: recognise, investigate, respond. Root cause analysis works across all complaints to find the recurring causes behind them and get them fixed, which is what rules such as the FCA's DISP 1.3 require on top of good handling.",{"question":186,"answer":187},"Can AI find root causes on its own?","It can read every complaint rather than a sample, cluster themes and propose likely causes. A human analyst should validate each cause, because a plausible explanation from retrieved context is not proof, and a business owner has to decide the fix.",{"question":189,"answer":190},"Who already does this?","The public records on this page come from US agencies. The Federal Reserve Board has applied topic modelling to consumer complaint narratives from the CFPB database since 2019, and the Federal Trade Commission has classified the complaints it receives and grouped duplicates with machine learning since 2019. Of these, only the US Centers for Medicare and Medicaid Services goes as far as root causes, and it is still a pilot that finds root causes and trends in complaint cases for expert validation.",[192,193,194,195,196],"complaints-handling-agent","customer-feedback-analysis","call-quality-and-compliance-monitoring","continuous-controls-testing","supervisory-exam-response-assembly","2026-09-27",[199],{"date":197,"note":200},"First published","complaints-root-cause-analysis",[203,234,254],{"title":204,"useCases":205,"organization":206,"vendors":211,"summary":212,"stage":213,"year":44,"channels":214,"languages":215,"metrics":217,"outcomeDisclosed":208,"sources":218,"verification":229,"grade":231,"id":232,"organizationSlug":233},"CMS: AI complaint analysis to find root causes, validated by experts (pilot)",[201],{"name":207,"anonymized":208,"country":209,"region":210,"industry":22},"Centers for Medicare and Medicaid Services",false,"US","north-america",[],"A team at the US Centers for Medicare and Medicaid Services is piloting AI that analyses a high volume of complaint cases to identify root causes and trends, maps them to the applicable regulatory citations, draws a sample for subject matter experts to validate and recommends next steps. The stated aim is to reduce repeat issues that delay benefits or access to care and to improve health plan compliance. The 2024 inventory describes an earlier proof of concept that used a large language model on complaint data used by the same office (OPOLE). No results are published.","pilot",[33],[216],"en",[],[219,223,226],{"url":220,"title":221,"publisher":222},"https://github.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory","2025 Federal Agency AI Use Case Inventory","Office of Management and Budget (GitHub)",{"url":224,"title":225,"publisher":222},"https://raw.githubusercontent.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory/main/Data/2025_individually_reported_AI_use_cases.csv","2025 individually reported AI use cases (HHS/CMS/OPOLE entry Complaint Analysis)",{"url":227,"title":228,"publisher":222},"https://raw.githubusercontent.com/ombegov/2024-Federal-AI-Use-Case-Inventory/main/data/2024_consolidated_ai_inventory_raw_v2.csv","2024 consolidated AI inventory (HHS entry Complaint Analysis POC)",{"level":230,"checkedAt":197},"source-verified","B","cms-complaint-root-cause-analysis","centers-for-medicare-and-medicaid-services",{"title":235,"useCases":236,"organization":237,"vendors":239,"summary":240,"stage":241,"year":242,"channels":243,"languages":244,"metrics":245,"outcomeDisclosed":208,"sources":246,"verification":250,"grade":231,"id":252,"organizationSlug":253},"Federal Reserve Board: Consumer Complaints Explorer topic modelling",[201],{"name":238,"anonymized":208,"country":209,"region":210,"industry":22},"Board of Governors of the Federal Reserve System",[],"The Federal Reserve Board's Division of Consumer and Community Affairs has used an in house natural language processing tool since 2019 to sort large volumes of consumer complaint narratives into topics, so staff can analyse and respond to them. For each narrative it outputs a topic number, a fit score and the top five terms of that topic. The input is complaint data from the CFPB. It is a central bank analysing consumer complaints about financial companies from the CFPB database rather than a firm analysing its own complaints, but the method is the same clustering step a bank's root cause work starts from.","production",2019,[33],[216],[],[247],{"url":248,"title":249,"publisher":238},"https://www.federalreserve.gov/AI-use-case-inventory-2025.htm","AI Use Case Inventory 2025",{"level":230,"checkedAt":251},"2026-09-26","federal-reserve-board-consumer-complaints-explorer","board-of-governors-of-the-federal-reserve-system",{"title":255,"useCases":256,"organization":257,"vendors":259,"summary":263,"stage":241,"year":242,"channels":264,"languages":265,"metrics":266,"outcomeDisclosed":208,"sources":267,"verification":271,"grade":231,"id":272,"organizationSlug":273},"FTC: AI classification and duplicate grouping of consumer fraud complaints",[201],{"name":258,"anonymized":208,"country":209,"region":210,"industry":22},"Federal Trade Commission",[260],{"name":261,"role":262},"Leidos","integrator","Since 2019 the US Federal Trade Commission has used AI on the complaints it receives through ReportFraud and other channels: one model classifies uncategorised complaints by product and service code, another groups duplicate complaints about the same issue so investigators can see which entities attract multiple reports, alongside graph analytics that connect complaints about the same company when it uses different names, phone numbers or aliases. It shows the two steps that make complaint themes countable: consistent categorisation and deduplication. No outcome figures are published.",[33],[216],[],[268,269],{"url":220,"title":221,"publisher":222},{"url":224,"title":270,"publisher":222},"2025 individually reported AI use cases (entries FTC-0001, FTC-0002 and FTC-0005)",{"level":230,"checkedAt":197},"ftc-consumer-complaint-classification-and-grouping",null,0,[],{"low":277,"high":278},300000,2400000,[280,306,330,351,367],{"slug":192,"title":281,"shortTitle":282,"definition":283,"status":9,"industries":284,"functions":285,"patterns":287,"audience":289,"autonomy":35,"adoptionStage":290,"segment":291,"evidenceCount":292,"publicEvidenceCount":292,"organizations":293,"bestGrade":231,"headline":296,"lastVerified":197,"indexable":305},"AI agent for complaints recognition, investigation and response","Complaints handling","An AI agent that recognizes when a customer interaction is a complaint, logs it against the regulatory definition, classifies its root cause and severity, gathers the evidence, drafts the acknowledgement and the response for a human handler to approve, and tracks every statutory deadline until the case is closed.",[17,18,20,19,21],[286,25,24],"case-management",[28,29,288,30,31],"content-generation","employee-facing","early-adopters","middle-office",2,[294,295],"Lloyds Banking Group","NatWest Group",{"kpi":297,"label":298,"unit":299,"n":300,"nUpTo":274,"kind":301,"value":302,"qualifier":303,"claimant":304,"organization":294,"vendorReported":208},"time-saved-per-task","Time saved per task","minutes",1,"reported",5,"approximately","organization",true,{"slug":193,"title":307,"shortTitle":308,"definition":309,"status":9,"industries":310,"functions":313,"patterns":315,"audience":34,"autonomy":35,"adoptionStage":317,"evidenceCount":302,"publicEvidenceCount":302,"organizations":318,"bestGrade":231,"headline":324,"lastVerified":197,"indexable":305},"AI for voice of the customer and feedback analysis","Customer feedback analysis","AI that reads every piece of free text customer feedback, such as survey verbatims, NPS comments, reviews, social posts, chat and call transcripts, and turns it into themes, sentiment, drivers and suggested actions that a named owner can act on, so the organization hears all of its customers instead of a sample.",[17,311,22,312],"retail-and-ecommerce","manufacturing",[25,314,26],"marketing",[28,29,316],"speech-analytics","mainstream",[319,320,321,322,323],"U.S. Department of Housing and Urban Development","Majid Al Futtaim Retail","Mattel","SBF Group","U.S. Social Security Administration",{"kpi":54,"label":325,"unit":326,"n":300,"nUpTo":274,"kind":301,"value":327,"qualifier":328,"claimant":329,"organization":322,"vendorReported":305},"Accuracy","percent",84,"exact","vendor",{"slug":194,"title":331,"shortTitle":332,"definition":333,"status":9,"industries":334,"functions":336,"patterns":338,"audience":34,"autonomy":339,"adoptionStage":290,"evidenceCount":302,"publicEvidenceCount":302,"organizations":340,"bestGrade":346,"headline":347,"lastVerified":197,"indexable":305},"AI quality and compliance monitoring of every customer interaction","Call quality and compliance","Automated quality assurance that transcribes and scores every customer interaction, voice and chat, against the organization's own rubric, checking required disclosures and script adherence, flagging conduct and mis selling risk, and surfacing coaching opportunities, instead of the small sample a human QA team can review.",[17,18,19,335,21,311],"energy-and-utilities",[25,24,337],"operations",[316,28,29],"supervised-agent",[341,342,343,344,345],"British Gas","Central Bank","DoorDash","Oportun","VitalityHealth","C",{"kpi":348,"label":349,"unit":326,"n":300,"nUpTo":274,"kind":301,"value":350,"qualifier":303,"claimant":329,"organization":341,"vendorReported":305},"quality-score-uplift","Quality score uplift",10,{"slug":195,"title":352,"shortTitle":353,"definition":354,"status":9,"industries":355,"functions":357,"patterns":359,"audience":34,"autonomy":339,"adoptionStage":36,"segment":37,"evidenceCount":362,"publicEvidenceCount":362,"organizations":363,"bestGrade":231,"headline":273,"lastVerified":197,"indexable":305},"AI for continuous controls testing and control self assessment","Continuous controls testing","AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.",[17,18,19,356,22],"capital-markets",[358,24,337],"risk-management",[30,360,361,28],"document-processing","anomaly-detection",3,[364,365,366],"Federal Deposit Insurance Corporation","U.S. Department of the Interior","Pension Benefit Guaranty Corporation",{"slug":196,"title":368,"shortTitle":369,"definition":370,"status":9,"industries":371,"functions":372,"patterns":374,"audience":289,"autonomy":35,"adoptionStage":36,"segment":37,"evidenceCount":362,"publicEvidenceCount":362,"organizations":375,"bestGrade":231,"headline":273,"lastVerified":197,"indexable":305},"AI for supervisory exam and information request responses","Exam response assembly","An assistant for the bank's regulatory affairs team that reads a supervisory information request or exam question, retrieves the relevant evidence, policies and prior correspondence, drafts a response for legal and compliance to approve, and tracks every commitment and remediation action through to closure.",[18,19,356,20],[24,373,286],"legal",[31,288,360,30],[376,377],"U.S. Department of Homeland Security","Federal Emergency Management Agency",{"indexable":305,"reasons":379},[],[381,387,392,399,406,412,418,423,430,437,444,450,457,464,470,475,482,488,494,500,506,512,517,522,527,534,541,546,552,559,566,572,578,583],{"id":155,"label":382,"issuer":383,"region":161,"url":384,"description":385,"useCases":386,"indexable":305},"EU AI Act","European Union","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":153,"label":388,"issuer":383,"region":161,"url":389,"description":390,"useCases":391,"indexable":305},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":156,"label":393,"issuer":394,"region":395,"url":396,"description":397,"useCases":398,"indexable":305},"ISO/IEC 42001","ISO and IEC","global","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":400,"label":401,"issuer":402,"region":210,"url":403,"description":404,"useCases":405,"indexable":305},"nist-ai-rmf","NIST AI Risk Management Framework","NIST","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":407,"label":408,"issuer":383,"region":161,"url":409,"description":410,"useCases":411,"indexable":305},"dora","DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":154,"label":413,"issuer":414,"region":161,"url":415,"description":416,"useCases":417,"indexable":305},"UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":152,"label":419,"issuer":160,"region":161,"url":420,"description":421,"useCases":422,"indexable":305},"FCA Consumer Duty","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":424,"label":425,"issuer":426,"region":169,"url":427,"description":428,"useCases":429,"indexable":305},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":431,"label":432,"issuer":433,"region":169,"url":434,"description":435,"useCases":436,"indexable":305},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":438,"label":439,"issuer":440,"region":395,"url":441,"description":442,"useCases":443,"indexable":305},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",20,{"id":445,"label":446,"issuer":447,"region":210,"url":448,"description":449,"useCases":443,"indexable":305},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":451,"label":452,"issuer":453,"region":161,"url":454,"description":455,"useCases":456,"indexable":305},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":458,"label":459,"issuer":460,"region":395,"url":461,"description":462,"useCases":463,"indexable":305},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":465,"label":466,"issuer":383,"region":161,"url":467,"description":468,"useCases":469,"indexable":305},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":471,"label":472,"issuer":383,"region":161,"url":473,"description":474,"useCases":469,"indexable":305},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":476,"label":477,"issuer":478,"region":210,"url":479,"description":480,"useCases":481,"indexable":305},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":483,"label":484,"issuer":383,"region":161,"url":485,"description":486,"useCases":487,"indexable":305},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":489,"label":490,"issuer":491,"region":210,"url":492,"description":493,"useCases":487,"indexable":305},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":495,"label":496,"issuer":497,"region":395,"url":498,"description":499,"useCases":487,"indexable":305},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":501,"label":502,"issuer":383,"region":161,"url":503,"description":504,"useCases":505,"indexable":305},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":507,"label":508,"issuer":509,"region":210,"url":510,"description":511,"useCases":505,"indexable":305},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":513,"label":514,"issuer":426,"region":169,"url":515,"description":516,"useCases":350,"indexable":305},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",{"id":518,"label":519,"issuer":383,"region":161,"url":520,"description":521,"useCases":350,"indexable":305},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":523,"label":524,"issuer":383,"region":161,"url":525,"description":526,"useCases":350,"indexable":305},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":528,"label":529,"issuer":530,"region":161,"url":531,"description":532,"useCases":533,"indexable":305},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":535,"label":536,"issuer":537,"region":210,"url":538,"description":539,"useCases":540,"indexable":305},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",8,{"id":542,"label":543,"issuer":383,"region":161,"url":544,"description":545,"useCases":540,"indexable":305},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":547,"label":548,"issuer":383,"region":161,"url":549,"description":550,"useCases":551,"indexable":305},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",6,{"id":553,"label":554,"issuer":555,"region":556,"url":557,"description":558,"useCases":302,"indexable":305},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":560,"label":561,"issuer":562,"region":161,"url":563,"description":564,"useCases":565,"indexable":305},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",4,{"id":567,"label":568,"issuer":569,"region":161,"url":570,"description":571,"useCases":565,"indexable":305},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":573,"label":574,"issuer":575,"region":169,"url":576,"description":577,"useCases":362,"indexable":305},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":579,"label":580,"issuer":383,"region":161,"url":581,"description":582,"useCases":362,"indexable":305},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":584,"label":585,"issuer":258,"region":210,"url":586,"description":587,"useCases":362,"indexable":305},"us-fcra","Fair Credit Reporting Act","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598299577]