[{"data":1,"prerenderedAt":602},["ShallowReactive",2],{"uc-continuous-controls-testing":3,"uc-regulations":400},{"useCase":4,"evidence":215,"blitsAiDeployments":292,"benchmarks":293,"indicative":300,"related":303,"indexability":398,"includeUnpublished":221},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":16,"functions":22,"patterns":26,"channels":31,"audience":33,"autonomy":34,"adoptionStage":35,"segment":36,"problem":37,"problemStats":38,"howItWorks":44,"valueDrivers":45,"kpis":50,"indicativeValue":56,"macroEstimates":97,"feasibility":98,"implementation":111,"risk":154,"blitsAi":191,"faq":193,"related":203,"datePublished":210,"dateModified":210,"lastVerified":210,"changelog":211,"slug":214},"AI for continuous controls testing and control self assessment","Continuous controls testing","AI for continuous controls testing and RCSA","AI for continuous controls testing. The US Interior Department uses AI tools that produce audit ready records for over 29,000 financial assistance actions a year.","published","AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.",[12,13,14,15],"continuous controls monitoring","AI control testing","automated RCSA","full population control testing",[17,18,19,20,21],"cross-industry","banking","insurance","capital-markets","government",[23,24,25],"risk-management","regulatory-compliance","operations",[27,28,29,30],"agentic-workflow","document-processing","anomaly-detection","classification-and-routing",[32],"internal-tools","back-office","supervised-agent","emerging","second-line","Periodic control testing checks a sample of items at a point in time, with evidence gathered\nfrom control owners by email and screenshots. The first line collects the evidence, the second\nline reviews it, and the result describes the control as it was when the sample was drawn. A\ncontrol that fails soon after a test can go unnoticed until the next cycle, and is found only if\nthe failing items happen to be in the sample.\n\nRisk and control self assessments have the same weakness. Anaptyss, a services vendor, describes\nthem as heavily manual, with control narratives that differ across teams and business units. Rules\nraise the bar at the same time: APRA CPS 230 requires regulated entities to regularly monitor,\nreview and test controls for design and operating effectiveness and to report the results to\nsenior management.",[39],{"statement":40,"sourceTitle":41,"sourceUrl":42,"year":43},"Anaptyss, a services vendor, states that risk and control self assessments in banks often take three to six weeks to complete, with some complex assessments extending beyond eight weeks.","From 20 Days to 5: The Operational Economics of AI-Led RCSA Execution","https://www.anaptyss.com/blog/from-20-days-to-5-the-operational-economics-of-ai-led-rcsa-execution/",2026,"1. **Codify the control.** Each automatable control gets a testable rule (for example: every\n   payment above a threshold has a second approver who is not the initiator) and a list of the\n   evidence that proves it.\n2. **Collect evidence continuously.** Agents pull records, logs, approvals and documents from\n   source systems on a schedule, instead of asking control owners for screenshots.\n3. **Read the artefacts.** Document AI reads policies, sign off records, reconciliations and\n   reports and maps each artefact to the control and the period it covers.\n4. **Test the whole population.** Every item is tested against the rule; exceptions are grouped\n   and explained with the evidence attached.\n5. **Human judgement on exceptions.** A tester or control owner reviews each exception, decides\n   whether it is a control failure and records the reason.\n6. **Prepare the RCSA.** The AI drafts control narratives and proposed ratings from test\n   results, incidents and losses; the business reviews, challenges and owns the final assessment.",[46,47,48,49],"compliance","risk-reduction","employee-productivity","speed",[51,52,53,54,55],"automation-rate","processing-time-reduction","hours-saved","interactions-handled","error-reduction",{"referenceOrg":57,"inputs":58,"formula":92,"currency":93,"period":94,"resultLabel":95,"caveat":96},"A bank that tests 2,000 key controls a year",[59,65,72,79,85],{"key":60,"label":61,"low":62,"high":62,"unit":63,"note":64},"controls","Key controls tested per year",2000,"controls per year","The reference bank. Replace with your own control library.",{"key":66,"label":67,"low":68,"high":69,"unit":70,"note":71},"hoursPerTest","Hours per control test (evidence collection, testing, review)",10,20,"hours per control test","Editorial assumption across first and second line effort. Replace with your own time records.",{"key":73,"label":74,"low":75,"high":76,"unit":77,"note":78},"automatable","Share of controls suitable for automated testing",0.2,0.4,"fraction of controls","Editorial assumption; system based controls automate first, judgement based controls stay manual.",{"key":80,"label":81,"low":76,"high":82,"unit":83,"note":84},"effortSaved","Share of test effort saved on those controls",0.7,"fraction of test effort","Editorial assumption, replace with your own pilot results. No public bank benchmark was found.",{"key":86,"label":87,"low":88,"high":89,"unit":90,"note":91},"hourlyCost","Fully loaded cost of a control tester",60,100,"USD per hour","Editorial assumption, replace with your own.","controls * hoursPerTest * automatable * effortSaved * hourlyCost","USD","per year","Control testing effort released","Effort only. It leaves out the build and integration cost, the value of finding failures months earlier across the full population, and the saving in audit and regulatory findings.",[],{"complexity":99,"complexityNote":100,"dataPrerequisites":101,"integrations":106},"high","Testing logic is simple once a control is codified. The work is in rewriting controls so they are testable, reaching evidence in dozens of source systems and agreeing with audit and the regulator that automated tests are reliable.",[102,103,104,105],"A control library with owners, objectives and testable attributes","Access to transaction, approval, access and configuration data in source systems","Incident, loss and issue data linked to controls","Prior test results to compare automated and manual outcomes",[107,108,109,110],"Governance, risk and compliance (GRC) platform with the control library and issues","Core banking, payments, identity and access management and ticketing systems","Document stores for policies, sign offs and reconciliations","Incident and operational loss databases",{"steps":112,"guardrails":128,"humanInTheLoop":134,"kpisToInstrument":135,"failureModes":141},[113,116,119,122,125],{"title":114,"detail":115},"Pick controls that are data rich and rule based","Start with access, approval, reconciliation and segregation of duties controls whose evidence already sits in systems. Leave judgement heavy controls for later.",{"title":117,"detail":118},"Rewrite each control as a test","For every control in scope, write the rule, the population, the evidence and the exception definition, and have the control owner and second line sign it off.",{"title":120,"detail":121},"Run parallel with manual testing","For one or two cycles test both ways, compare results and explain every difference before retiring the manual test. Share the comparison with internal audit.",{"title":123,"detail":124},"Industrialise exception handling","Route exceptions to owners with evidence, reasons and due dates, and link confirmed failures to issues and the RCSA.",{"title":126,"detail":127},"Draft, never auto approve, the RCSA","Use AI to prepare narratives and proposed ratings from data, and require the business to review and change them, so the assessment stays theirs.",[129,130,131,132,133],"Every exception and every proposed rating is reviewed and decided by a human","Test rules are versioned and signed off by the control owner and second line","The agent reads source systems with read only access through an allow list","Every test run stores its population, evidence and result for audit","Automated tests are recalibrated when the underlying process or system changes","Control owners and testers adjudicate every exception, second line approves test designs, the business owns the self assessment ratings and internal audit reviews the reliability of the automated testing.",[136,137,138,139,140],"Share of key controls tested on the full population","Time from control failure to detection","Exceptions raised, confirmed as failures and closed on time","Hours of evidence collection and testing per control, before and after","Differences between automated and manual test outcomes during parallel runs",[142,145,148,151],{"title":143,"detail":144},"Testing the wrong population","The agent tests the data it can reach, not the full population the control covers. Reconcile populations to source totals every run.",{"title":146,"detail":147},"Rubber stamped RCSA","The business accepts AI drafted ratings without challenge and the self assessment loses its point. Require recorded review and track how often drafts change.",{"title":149,"detail":150},"Silent test decay","A system change breaks the extraction and the test passes on empty data. Alert on volume anomalies and zero populations.",{"title":152,"detail":153},"Exception floods","A poorly specified rule produces thousands of exceptions that nobody reviews. Tune on parallel runs and group exceptions by cause.",{"euAiAct":155,"regulations":158,"guidance":165,"controls":184,"incidents":190},{"tier":156,"basis":157},"context-dependent","Testing controls over transactions and systems is not an Annex III use. Controls that monitor and evaluate individual employees' behaviour, such as trading or access conduct, can fall under Annex III point 4(b), so the design decides the tier.",[159,160,161,162,163,164],"eu-ai-act","dora","apra-cps-230","gdpr","iso-42001","nist-ai-rmf",[166,172,178],{"title":167,"issuer":168,"region":169,"url":170,"note":171},"Revisions to the principles for the sound management of operational risk","Basel Committee on Banking Supervision","global","https://www.bis.org/bcbs/publ/d515.htm","The Basel Committee's principles for operational risk management and the control environment, revised in 2021 with updated guidance on change management and ICT.",{"title":173,"issuer":174,"region":175,"url":176,"note":177},"Operational risk management (CPS 230)","Australian Prudential Regulation Authority","asia-pacific","https://www.apra.gov.au/operational-risk-management","Australia's cross industry operational risk standard for APRA regulated entities, covering operational risk controls, critical operations and material service providers.",{"title":179,"issuer":180,"region":181,"url":182,"note":183},"Article 4, AI literacy","European Union","europe","https://artificialintelligenceact.eu/article/4/","Providers and deployers must take measures to support the AI literacy of staff who use and oversee AI systems (the amended wording asks them to support it rather than ensure a sufficient level). Here that means training testers on the limits of automated results.",[185,186,187,188,189],"Inventory entry for the testing AI with an owner, scope and validation status","Signed off test specifications per control, under change control","Population reconciliation and completeness checks on every run","Parallel run evidence retained before a manual test is retired","Internal audit review of the reliability of automated testing",[],{"howToBuild":192},"On Blits.ai this is an **agentic workflow** per control family, triggered on a schedule or\nthrough the API. **Custom functions** (REST calls and SQL queries) pull populations and evidence\nfrom source systems with read only access, a **SQL knowledge base** lets the agent query test\ndata directly, and the **knowledge base** ingests policies, sign offs and reports in PDF, Word,\nExcel and email formats so the agent can map artefacts to controls. Results come back as\n**structured output** that the GRC platform can store.\n\n**Agentic tasks** with scheduled rechecks keep testing continuous, the **tool execution policy**\nfixes which tools each agent may use, and **human in the loop confirmation** holds agentic\nactions above a configurable threshold for an approve or reject decision. Exceptions and\nproposed RCSA ratings go to testers and control owners as structured results, and people make\nthe decision. The per run audit trail and downloadable\nrun data give auditors the evidence, and **test suites** and **monitors** catch prompt or model\nchanges that would alter test outcomes. The platform is model agnostic with EU and UAE data\nresidency.",[194,197,200],{"question":195,"answer":196},"Does continuous controls testing replace control testers?","It changes their work. Evidence collection and routine testing move to automation, and testers spend their time on exceptions, control design and judgement based controls that cannot be codified.",{"question":198,"answer":199},"Which controls should be automated first?","Controls whose evidence already sits in systems and whose rule can be written precisely: access reviews, approvals and limits, reconciliations and segregation of duties. Judgement heavy controls stay manual or AI assisted rather than automated.",{"question":201,"answer":202},"Is there public evidence this works?","Public bank figures are scarce. The US Department of the Interior reports AI tools in production since 2024 that run internal controls testing and produce audit ready records for more than 29,000 financial assistance actions a year. The FDIC and the Pension Benefit Guaranty Corporation list similar tools as pre deployment in the 2025 federal AI inventory. Vendor claims about faster RCSA cycles exist but are not tied to named banks.",[204,205,206,207,208,209],"internal-audit-copilot","policy-drafting-and-gap-analysis","complaints-root-cause-analysis","vendor-due-diligence","ai-model-inventory","regulatory-horizon-scanning","2026-09-27",[212],{"date":210,"note":213},"First published","continuous-controls-testing",[216,246,263],{"title":217,"useCases":218,"organization":219,"vendors":224,"summary":225,"stage":226,"year":227,"channels":228,"languages":229,"metrics":231,"outcomeDisclosed":221,"sources":232,"verification":240,"grade":243,"id":244,"organizationSlug":245},"FDIC: AI monitoring of invoices and payments for abnormalities (planned)",[214],{"name":220,"anonymized":221,"country":222,"region":223,"industry":21},"Federal Deposit Insurance Corporation",false,"US","north-america",[],"The FDIC's Division of Finance reports a use case in pre deployment that uses classical machine learning to monitor financials and invoices for proper submittal, duplicate payments and other abnormalities, described as an automated assist for its auditing and monitoring work. For each gap it would show why it was flagged and possible causes, in visual tables with drill downs to contract numbers and agency sections. Not yet live; no results published.","announced",2025,[32],[230],"en",[],[233,237],{"url":234,"title":235,"publisher":236},"https://github.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory","2025 Federal Agency AI Use Case Inventory","Office of Management and Budget (GitHub)",{"url":238,"title":239,"publisher":236},"https://raw.githubusercontent.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory/main/Data/2025_individually_reported_AI_use_cases.csv","2025 individually reported AI use cases (entry FDIC 39, CFOO Transactional Data Analysis)",{"level":241,"checkedAt":242},"source-verified","2026-09-26","B","fdic-transactional-data-monitoring","federal-deposit-insurance-corporation",{"title":247,"useCases":248,"organization":249,"vendors":251,"summary":252,"stage":226,"year":227,"channels":253,"languages":254,"metrics":255,"outcomeDisclosed":221,"sources":256,"verification":260,"grade":243,"id":261,"organizationSlug":262},"PBGC: generative AI for IT security and privacy control assessment (planned)",[214],{"name":250,"anonymized":221,"country":222,"region":223,"industry":21},"Pension Benefit Guaranty Corporation",[],"The Pension Benefit Guaranty Corporation reports a use case in pre deployment that applies AI to IT security and privacy control assessments: evaluating controls against federal cybersecurity and privacy guidelines, working through the supporting evidence, generating findings and drafting control implementation statements. The stated aims are a higher volume of control assessments, less manual work and shorter control tailoring and implementation times. It is not yet live and no results are published.",[32],[230],[],[257,258],{"url":234,"title":235,"publisher":236},{"url":238,"title":259,"publisher":236},"2025 individually reported AI use cases (entry PBGC - 11, IT Security and Privacy Control Assessment)",{"level":241,"checkedAt":242},"pbgc-security-and-privacy-control-assessment",null,{"title":264,"useCases":265,"organization":266,"vendors":268,"summary":269,"stage":270,"year":271,"channels":272,"languages":273,"metrics":274,"outcomeDisclosed":282,"sources":283,"verification":290,"grade":243,"id":291,"organizationSlug":262},"US Department of the Interior: AI internal controls testing across grant awards",[214],{"name":267,"anonymized":221,"country":222,"region":223,"industry":21},"U.S. Department of the Interior",[],"The Interior Department's Office of Grants Management built an in house set of AI tools, operational since April 2024, for three reviews of financial assistance awards that had been manual, inconsistent across bureaus and labour intensive: project descriptions, pre award eligibility validations in SAM.gov and budget submissions. The department says it needed a way to conduct internal controls testing, eligibility checks and budget reviews at scale. The tools produce automated scoring, flags for risks or inconsistencies, cross walks between budget documents and audit ready records aligned with internal control requirements. The 2024 inventory files the project description and SAM.gov work under internal controls testing, including a large language model that scores SAM.gov documents against the award date and a planned Azure app, to be built with Microsoft, that would let bureau staff test project descriptions themselves.","production",2024,[32],[230],[275],{"kpi":54,"value":276,"unit":277,"qualifier":278,"period":279,"claimant":280,"quote":281,"sourceUrl":238},29000,"count","at-least","per year, financial assistance actions","organization","Together, these outputs streamline oversight, strengthen regulatory compliance, and create a consistent, defensible documentation trail for more than 29,000 annual financial assistance actions.",true,[284,285,287],{"url":234,"title":235,"publisher":236},{"url":238,"title":286,"publisher":236},"2025 individually reported AI use cases (entry DOI-0180, PGM Grants Utility Tool)",{"url":288,"title":289,"publisher":236},"https://raw.githubusercontent.com/ombegov/2024-Federal-AI-Use-Case-Inventory/main/data/2024_consolidated_ai_inventory_raw_v2.csv","2024 consolidated AI inventory (Interior entries on internal controls testing)",{"level":241,"checkedAt":210},"interior-department-grants-internal-controls-testing",0,[294],{"kpi":54,"label":295,"unit":277,"aggregate":221,"higherIsBetter":282,"n":296,"nUpTo":292,"median":276,"min":276,"max":276,"byClaimant":297,"vendorOnly":221,"points":298},"Interactions handled",1,{"organization":296,"vendor":292,"regulator":292,"independent":292},[299],{"evidenceId":291,"organization":267,"value":276,"qualifier":278,"claimant":280,"grade":243,"pooled":282},{"low":301,"high":302},96000,1120000,[304,334,346,361,375,387],{"slug":204,"title":305,"shortTitle":306,"definition":307,"status":9,"industries":308,"functions":310,"patterns":312,"audience":316,"autonomy":317,"adoptionStage":318,"evidenceCount":319,"publicEvidenceCount":319,"organizations":320,"bestGrade":324,"headline":325,"lastVerified":210,"indexable":282},"Generative AI copilot for internal audit","Internal audit copilot","A copilot for internal auditors that drafts planning memos and document request lists from prior audits, summarises large evidence sets, builds risk and control matrices from policies and process documents, and drafts findings and reports, with every statement traceable to its evidence and a qualified auditor accountable for every conclusion.",[17,18,19,21,20,309],"wealth-and-asset-management",[23,24,311],"finance-and-accounting",[313,314,315,28,29],"rag-knowledge-assistant","summarization","content-generation","employee-facing","copilot","early-adopters",3,[321,322,323],"Banco Bradesco","British Columbia Investment Management Corporation","XP Inc.","C",{"kpi":326,"label":327,"unit":328,"n":329,"nUpTo":292,"kind":330,"value":331,"qualifier":332,"claimant":333,"organization":321,"vendorReported":282},"handling-time-reduction","Handling time reduction","percent",2,"reported",55,"exact","vendor",{"slug":205,"title":335,"shortTitle":336,"definition":337,"status":9,"industries":338,"functions":339,"patterns":342,"audience":316,"autonomy":317,"adoptionStage":35,"segment":36,"evidenceCount":319,"publicEvidenceCount":319,"organizations":343,"bestGrade":243,"headline":262,"lastVerified":242,"indexable":282},"AI for policy drafting and policy gap analysis","Policy drafting and gaps","An assistant that takes a new or changed obligation, finds every internal policy, standard and procedure it touches, flags clauses that now conflict or are silent, and drafts the updated wording in house style as a redline for the policy owner to approve.",[17,18,19,20,21],[24,340,341],"legal","knowledge-management",[313,315,28,314],[220,344,345],"Administration for Children and Families","Health Resources and Services Administration",{"slug":206,"title":347,"shortTitle":348,"definition":349,"status":9,"industries":350,"functions":353,"patterns":356,"audience":33,"autonomy":317,"adoptionStage":35,"segment":36,"evidenceCount":319,"publicEvidenceCount":319,"organizations":357,"bestGrade":243,"headline":262,"lastVerified":210,"indexable":282},"AI for complaints root cause and systemic issue analysis","Complaints root cause analysis","AI that reads the free text of complaints across all channels, clusters them into themes, separates systemic causes from one off events, links each theme to the product, process or control behind it and routes the insight to the owner who can fix it, with a human validating every root cause and every remediation.",[17,18,19,351,352,21],"payments","telecommunications",[24,354,355],"customer-service","analytics-and-reporting",[30,314,27,313],[358,359,360],"Centers for Medicare and Medicaid Services","Board of Governors of the Federal Reserve System","Federal Trade Commission",{"slug":207,"title":362,"shortTitle":363,"definition":364,"status":9,"industries":365,"functions":366,"patterns":368,"audience":316,"autonomy":317,"adoptionStage":318,"segment":36,"evidenceCount":369,"publicEvidenceCount":369,"organizations":370,"bestGrade":243,"headline":262,"lastVerified":210,"indexable":282},"AI for third party and vendor risk due diligence","Vendor due diligence","AI that reviews a vendor's security questionnaires, SOC and assurance reports, contracts and model documentation against the organization's control requirements, researches the vendor's ownership, sanctions, financial health and adverse media, drafts the risk assessment for a human to approve and keeps the register of material service providers current with ongoing monitoring.",[17,18,19,21,351],[367,23,24],"procurement",[28,313,27,314],4,[371,372,373,374],"U.S. Department of Justice","Internal Revenue Service","U.S. Department of Agriculture","U.S. Trade and Development Agency",{"slug":208,"title":376,"shortTitle":377,"definition":378,"status":9,"industries":379,"functions":381,"patterns":383,"audience":316,"autonomy":317,"adoptionStage":318,"evidenceCount":369,"publicEvidenceCount":369,"organizations":384,"bestGrade":243,"headline":262,"lastVerified":210,"indexable":282},"AI system and model inventory with shadow AI discovery","AI model inventory","A governed register of every AI system and model an organization builds, buys or uses, with its owner, purpose, data, risk tier and approval status, kept current by AI that discovers unregistered use, reads the documentation and assembles the evidence a board, auditor or supervisor asks for.",[17,18,19,21,380],"manufacturing",[23,24,382],"it-and-engineering",[27,28,313,30],[359,385,386,371],"Office of Management and Budget","Unilever",{"slug":209,"title":388,"shortTitle":389,"definition":390,"status":9,"industries":391,"functions":393,"patterns":394,"audience":316,"autonomy":395,"adoptionStage":318,"segment":46,"evidenceCount":369,"publicEvidenceCount":329,"organizations":396,"bestGrade":243,"headline":262,"lastVerified":210,"indexable":282},"AI regulatory horizon scanning and obligation mapping","Regulatory horizon scanning","An AI system that continuously reads publications from the regulators and standard setters an organization answers to, classifies each item by relevance and urgency, breaks new rules into individual obligations and maps them to the internal policies and controls that meet them, so compliance owners see what changed and where the gaps are.",[17,18,19,351,309,392,21],"pharma-and-life-sciences",[24,340,23],[30,28,313,314,27],"assist",[397,344],"Financial Conduct Authority",{"indexable":282,"reasons":399},[],[401,406,411,417,423,428,435,441,448,452,458,464,471,478,484,489,496,502,508,514,520,526,531,536,541,548,555,560,566,574,580,586,592,597],{"id":159,"label":402,"issuer":180,"region":181,"url":403,"description":404,"useCases":405,"indexable":282},"EU AI Act","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":162,"label":407,"issuer":180,"region":181,"url":408,"description":409,"useCases":410,"indexable":282},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":163,"label":412,"issuer":413,"region":169,"url":414,"description":415,"useCases":416,"indexable":282},"ISO/IEC 42001","ISO and IEC","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":164,"label":418,"issuer":419,"region":223,"url":420,"description":421,"useCases":422,"indexable":282},"NIST AI Risk Management Framework","NIST","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":160,"label":424,"issuer":180,"region":181,"url":425,"description":426,"useCases":427,"indexable":282},"DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":429,"label":430,"issuer":431,"region":181,"url":432,"description":433,"useCases":434,"indexable":282},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":436,"label":437,"issuer":397,"region":181,"url":438,"description":439,"useCases":440,"indexable":282},"uk-consumer-duty","FCA Consumer Duty","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":442,"label":443,"issuer":444,"region":175,"url":445,"description":446,"useCases":447,"indexable":282},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":161,"label":449,"issuer":174,"region":175,"url":176,"description":450,"useCases":451,"indexable":282},"APRA CPS 230","Australian operational risk standard covering critical operations and material service providers.",25,{"id":453,"label":454,"issuer":455,"region":169,"url":456,"description":457,"useCases":69,"indexable":282},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",{"id":459,"label":460,"issuer":461,"region":223,"url":462,"description":463,"useCases":69,"indexable":282},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":465,"label":466,"issuer":467,"region":181,"url":468,"description":469,"useCases":470,"indexable":282},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":472,"label":473,"issuer":474,"region":169,"url":475,"description":476,"useCases":477,"indexable":282},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":479,"label":480,"issuer":180,"region":181,"url":481,"description":482,"useCases":483,"indexable":282},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":485,"label":486,"issuer":180,"region":181,"url":487,"description":488,"useCases":483,"indexable":282},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":490,"label":491,"issuer":492,"region":223,"url":493,"description":494,"useCases":495,"indexable":282},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":497,"label":498,"issuer":180,"region":181,"url":499,"description":500,"useCases":501,"indexable":282},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":503,"label":504,"issuer":505,"region":223,"url":506,"description":507,"useCases":501,"indexable":282},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":509,"label":510,"issuer":511,"region":169,"url":512,"description":513,"useCases":501,"indexable":282},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":515,"label":516,"issuer":180,"region":181,"url":517,"description":518,"useCases":519,"indexable":282},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":521,"label":522,"issuer":523,"region":223,"url":524,"description":525,"useCases":519,"indexable":282},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":527,"label":528,"issuer":444,"region":175,"url":529,"description":530,"useCases":68,"indexable":282},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",{"id":532,"label":533,"issuer":180,"region":181,"url":534,"description":535,"useCases":68,"indexable":282},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":537,"label":538,"issuer":180,"region":181,"url":539,"description":540,"useCases":68,"indexable":282},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":542,"label":543,"issuer":544,"region":181,"url":545,"description":546,"useCases":547,"indexable":282},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":549,"label":550,"issuer":551,"region":223,"url":552,"description":553,"useCases":554,"indexable":282},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",8,{"id":556,"label":557,"issuer":180,"region":181,"url":558,"description":559,"useCases":554,"indexable":282},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":561,"label":562,"issuer":180,"region":181,"url":563,"description":564,"useCases":565,"indexable":282},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",6,{"id":567,"label":568,"issuer":569,"region":570,"url":571,"description":572,"useCases":573,"indexable":282},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",5,{"id":575,"label":576,"issuer":577,"region":181,"url":578,"description":579,"useCases":369,"indexable":282},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":581,"label":582,"issuer":583,"region":181,"url":584,"description":585,"useCases":369,"indexable":282},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":587,"label":588,"issuer":589,"region":175,"url":590,"description":591,"useCases":319,"indexable":282},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":593,"label":594,"issuer":180,"region":181,"url":595,"description":596,"useCases":319,"indexable":282},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":598,"label":599,"issuer":360,"region":223,"url":600,"description":601,"useCases":319,"indexable":282},"us-fcra","Fair Credit Reporting Act","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598299605]