[{"data":1,"prerenderedAt":554},["ShallowReactive",2],{"uc-customs-risk-targeting-and-container-selection":3,"uc-regulations":334},{"useCase":4,"evidence":190,"blitsAiDeployments":241,"benchmarks":242,"indicative":243,"related":246,"indexability":332,"includeUnpublished":196},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":16,"functions":19,"patterns":23,"channels":26,"audience":29,"autonomy":30,"adoptionStage":31,"problem":32,"problemStats":33,"howItWorks":34,"valueDrivers":35,"kpis":40,"indicativeValue":46,"macroEstimates":81,"feasibility":82,"implementation":96,"risk":142,"blitsAi":169,"faq":171,"related":181,"datePublished":184,"dateModified":184,"lastVerified":185,"changelog":186,"slug":189},"AI for customs risk targeting, container selection and valuation checks","Customs risk targeting and container selection","AI container risk targeting for customs","AI models score customs declarations and cargo shipments for contraband, misclassification and undervaluation risk, deployed by CBP and Indian Customs.","published","Machine learning models that score every import or export declaration for the risk that it carries contraband, is misclassified or is undervalued, so a customs administration sends physical inspection, scanning and detailed review to the small share of containers, vehicles and parcels that need it, while the rest clear without an officer touching them, and an officer reviews and acts on every high risk alert.",[12,13,14,15],"AI cargo risk targeting","customs container selection AI","AI trade fraud and undervaluation detection","customs risk management system",[17,18],"government","logistics-and-transportation",[20,21,22],"risk-management","fraud-prevention","case-management",[24,25],"prediction-and-scoring","anomaly-detection",[27,28],"internal-tools","api","back-office","supervised-agent","early-adopters","A customs administration sees a declaration for every container, truck and parcel that crosses its\nborder, but can physically inspect or scan only a small fraction of them without stopping trade. The\ntraditional answer is fixed rules: flag anything from a listed country, anything over a value\nthreshold, anything in a sensitive tariff line. Rules catch what they are written for and miss what\nthey are not, they age as smuggling and invoice fraud patterns shift, and every officer hour spent\nopening a container that turns out clean is an hour not spent on the one that is not.\n\nThe fraud is not only physical. A shipment can be declared at the right tariff line but the wrong\nvalue, so importers under pay duty, or the invoice can be split, mislabelled or routed through a\nchain of related suppliers to break the pattern a simple rule would catch. Indian Customs describes\nthe underlying data problem: overseas supplier details arrive in free text on the declaration, with\nthe same supplier recorded under different spellings and addresses, particularly when that supplier\nships to multiple importers across the country, so without cleaning and matching that data first, a\nrisk engine cannot see that one high risk supplier behind many importers, or that one importer's\ndeclared values are drifting away from what the same product from the same supplier has cost\neveryone else.",[],"1. **Clean and match the underlying data.** Supplier names and addresses and free text goods\n   descriptions arrive inconsistent across declarations. Natural language processing standardizes\n   them, then clustering and string similarity models group the variants that are really the same\n   supplier or the same product, so the same trader cannot look like many small ones.\n2. **Score every declaration.** Models trained on past seizures, audits and confirmed fraud rank\n   the risk that a shipment carries prohibited goods, is misclassified or is undervalued, alongside\n   rules and watchlists that still catch what regulation requires every time.\n3. **Check the value against history.** For declared value specifically, a model compares the\n   item level price on this declaration with historical prices for the same product from the same\n   supplier, and flags a shipment whose price has drifted from that pattern.\n4. **Map the network.** Supply chain network analytics link importers, suppliers, customs brokers\n   and ports of entry so an officer can see when a new importer sits behind an already high risk\n   supplier or broker, not only whether this one declaration looks unusual on its own.\n5. **Route the outcome.** Low risk declarations clear without an officer looking at them; flagged\n   ones generate an alert with the supporting evidence for a specific action: document review,\n   scanning or physical inspection.\n6. **Feed enforcement back in.** Confirmed seizures, misclassifications and undervaluations update\n   the risk profile of the entities involved, so the next declaration from the same network starts\n   from a higher risk score.",[36,37,38,39],"risk-reduction","compliance","cost-to-serve","speed",[41,42,43,44,45],"detection-rate-improvement","false-positive-reduction","revenue-recovered","processing-time-reduction","automation-rate",{"referenceOrg":47,"inputs":48,"formula":76,"currency":77,"period":78,"resultLabel":79,"caveat":80},"A national customs administration processing 5 million import declarations a year",[49,55,62,69],{"key":50,"label":51,"low":52,"high":52,"unit":53,"note":54},"declarations","Import declarations per year",5000000,"declarations per year","The reference administration.",{"key":56,"label":57,"low":58,"high":59,"unit":60,"note":61},"flaggedShare","Share of declarations flagged for physical inspection or detailed review today",0.02,0.05,"fraction of declarations","Editorial assumption for a rule based baseline. Replace with your own inspection rate.",{"key":63,"label":64,"low":65,"high":66,"unit":67,"note":68},"falsePositiveCut","Share of those flags avoided by better targeting, at the same or better detection",0.1,0.25,"fraction of flagged declarations","Editorial assumption, replace with your own pilot results. CBP's own federal AI use case inventory entries describe these models as evaluating and prioritizing shipments for review \"while maintaining efficient cargo processing operations\", and Indian Customs reports its risk models are evaluated on false positive rate, but neither discloses a percentage.",{"key":70,"label":71,"low":72,"high":73,"unit":74,"note":75},"costPerReview","Cost of a physical inspection or detailed document review",150,500,"USD per declaration reviewed","Editorial assumption covering officer time, scanning and, for a share of cases, demurrage while a container waits. Replace with your own cost.","declarations * flaggedShare * falsePositiveCut * costPerReview","USD","per year","Unnecessary inspection cost avoided","Counts only reviews avoided at an unchanged or better detection rate; it leaves out the value of the duty, tax and seizures a better targeted model finds that a rule based one would miss, the cost of building and validating the models, and any change in trade facilitation revenue from faster clearance.",[],{"complexity":83,"complexityNote":84,"dataPrerequisites":85,"integrations":90},"high","The data work is the hard part: entity and product matching across inconsistent, free text declaration data must be solid before any risk score is trustworthy, and the models sit inside a national customs single window that already carries legal weight for every clearance decision.",[86,87,88,89],"Years of past declarations with the outcome (cleared, inspected, seized, reassessed) recorded","Reference price and classification data to compare a declared value or tariff line against","A cleaned, matched register of suppliers, importers and customs brokers","Watchlists and rules the administration is legally required to apply regardless of the model",[91,92,93,94,95],"National customs declaration and single window system","Scanning and imaging equipment at ports and border crossings","External trade and reference price data","Case management for the officers who act on flagged declarations","International risk and enforcement information exchange (for example the WCO Customs Enforcement Network or the EU's Customs Risk Management System)",{"steps":97,"guardrails":116,"humanInTheLoop":122,"kpisToInstrument":123,"failureModes":129},[98,101,104,107,110,113],{"title":99,"detail":100},"Fix entity and product matching first","Before scoring risk, clean and cluster supplier names, addresses and item descriptions so the same trader and the same product are recognised across every declaration. Every later model depends on this.",{"title":102,"detail":103},"Keep the required rules and watchlists in place","Add scoring and anomaly detection alongside, not instead of, the checks the administration is legally required to run on every declaration.",{"title":105,"detail":106},"Start with the highest volume, best labelled risk","Undervaluation against a known product and supplier history is easier to validate than contraband detection. Launch there, build the evidence base, then extend.",{"title":108,"detail":109},"Validate against confirmed outcomes, not alerts","Train and test on declarations with a confirmed audit, seizure or reassessment outcome, not on which declarations were previously flagged, or the model relearns the old rules' blind spots.",{"title":111,"detail":112},"Give officers the evidence, not just a score","An alert should carry the historical prices, the network links and the specific reason it was raised, so the officer can act quickly and the decision is defensible on review.",{"title":114,"detail":115},"Run in parallel before any auto clearance changes","Score live declarations while the existing process still runs unchanged, compare outcomes for a full cycle, and only then let the model's low risk band clear without review.",[117,118,119,120,121],"No declaration on a required watchlist or sanctions list clears without the checks regulation demands","Every flag carries the evidence and reason an officer can review, not only a score","Independent sampling of declarations the model cleared without review, at a rate that can detect drift","Fairness testing against nationality, country of origin and importer size, given the risk that a risk model concentrates stops on a protected or politically sensitive group","Model inventory entry, validation and a documented parallel run before any auto clearance threshold changes","An officer reviews and decides every flagged declaration; the model routes and prioritises, it does not detain, seize or clear on its own. A senior officer or risk manager sets and owns the thresholds that decide what counts as low enough risk to clear without review, and reviews the sampling results.",[124,125,126,127,128],"Detection rate (confirmed contraband, misclassification or undervaluation found) before and after, on a held out period","False positive rate, meaning flagged declarations that clear on review, before and after","Revenue recovered from confirmed undervaluation or misclassification cases the model surfaced","Time from declaration to clearance for the unflagged majority","Error rate found by independent sampling of declarations cleared without review",[130,133,136,139],{"title":131,"detail":132},"Matching that merges the wrong entities","Overly aggressive supplier or product matching can merge two different traders into one risk profile, or split one trader into many. Validate matches against known groupings before trusting the risk scores built on them.",{"title":134,"detail":135},"Learning the old rules' blind spots","A model trained only on what was previously flagged repeats the patterns the old rules already caught and misses what they missed. Include confirmed outcomes found through audits, tip offs and other administrations' alerts, not only past flags.",{"title":137,"detail":138},"Risk scores that concentrate on a nationality or origin","A model can reproduce or amplify bias present in past enforcement data. Test the score's distribution across nationality, country of origin and importer size, and set a review trigger if it concentrates on one group beyond what the confirmed outcome rate justifies.",{"title":140,"detail":141},"Clearance thresholds set to a savings target","Widening the clear without review band to save inspection cost, rather than from validated detection performance, quietly raises the risk of missed contraband or fraud. Set thresholds from the parallel run's confirmed outcomes.",{"euAiAct":143,"regulations":146,"guidance":151,"controls":163,"incidents":168},{"tier":144,"basis":145},"context-dependent","Not listed by name in Annex III. Recital 59 says AI systems used by tax and customs authorities in administrative proceedings should not be classified as high risk law enforcement systems; this covers the revenue, misclassification and valuation side of the risk targeting on this page. Contraband and narcotics targeting that leads to seizures sits nearer criminal enforcement: Annex III point 6 (law enforcement) can apply where customs acts in criminal enforcement and the system profiles a natural person, for example building a case around a seizure such as the heroin and methamphetamine finds Indian Customs describes. Annex III point 7(b) covers risk assessment of natural persons entering the Union; it does not apply here, since this use case scores goods, consignments and trading entities, not natural persons. Where a natural person is profiled, GDPR's profiling rules apply; Article 22 covers a decision based solely on automated processing that produces a legal or similarly significant effect, which this use case's human in the loop design (an officer decides every flagged case) is intended to keep out of scope on its own, a separate GDPR question from AI Act classification. Criminal customs investigations fall under the Law Enforcement Directive (EU) 2016/680 instead of the GDPR.",[147,148,149,150],"eu-ai-act","gdpr","nist-ai-rmf","iso-42001",[152,158],{"title":153,"issuer":154,"region":155,"url":156,"note":157},"Regulation (EU) 2024/1689 (AI Act), Recital 59","European Union","europe","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Systems intended for administrative proceedings by tax and customs authorities should not be classified as high risk law enforcement systems.",{"title":159,"issuer":160,"region":155,"url":161,"note":162},"EU Customs Risk Management Framework (CRMF)","European Commission, Taxation and Customs Union","https://taxation-customs.ec.europa.eu/customs-4/customs-risk-management_en","Describes the EU's common risk criteria, which customs authorities use to target shipments for control, and the Customs Risk Management System (CRMS2), which helps customs authorities share that risk information and communicate on risk management and control issues; together the risk based approach this use case automates.",[164,165,166,167],"Model inventory entry with an accountable owner, separate from the rules and watchlists still applied to every declaration","Fairness monitoring of flag rates by nationality, country of origin and importer size","Independent sampling of declarations cleared without review, with a threshold that triggers a review of the model","Audit trail linking every flag to the evidence and the officer's decision",[],{"howToBuild":170},"On Blits.ai the officer facing side runs as an **agentic workflow** triggered through the API for\nevery declaration that a risk score or rule flags. The agent calls **custom functions** that pull\nthe declaration, the matched supplier and product history and any prior alerts, queries a **SQL\nknowledge base** of past outcomes for similar declarations, and follows the administration's own\ninspection and escalation procedures from a **knowledge base** with hybrid retrieval, then returns\n**structured output**: a plain language reason for the flag, the supporting evidence and a\nsuggested action for the officer.\n\n**Human in the loop approval** keeps every flagged declaration with an officer; the platform never\nclears or holds a shipment itself. **Guardrails** and **PII masking** limit what personal data\nabout importers, brokers or individuals reaches a model, **test suites** replay historical,\nconfirmed declarations on every change to the prompts or logic, and **monitors** run scheduled\nchecks against the agent. The underlying risk and matching models can stay in the administration's\nown analytics environment; Blits.ai's part is the agent that turns a score into an evidenced,\nreviewable case for an officer, model agnostic and deployable with EU or UAE data residency.",[172,175,178],{"question":173,"answer":174},"Does AI replace customs officers' decisions?","No, in the deployments on this page it routes and prioritises. CBP's own AI use case inventory describes models that score cargo shipments and send high risk results to the Automated Targeting System for review by operational personnel, and Indian Customs describes models that proactively flag high risk consignments and generate daily alerts and machine generated instructions for front line customs officers. For Indian Customs, an officer decides every flagged case; the model decides which consignments reach an officer at all. That is how this pattern generally works: the model routes and prioritises, an officer acts.",{"question":176,"answer":177},"What does AI add to a rule based customs risk system?","Two things a fixed rule set struggles with: matching the same supplier or product across inconsistent, free text declaration data, and comparing a declared value against the actual history of that product from that supplier rather than a flat threshold. Indian Customs built supplier and description codification first, then built its valuation model and other risk models on top of it. Rules and watchlists stay in place for what regulation requires every time.",{"question":179,"answer":180},"Is this an Annex III high risk system under the EU AI Act?","Not automatically. Recital 59 keeps risk targeting and valuation checks used in administrative customs proceedings out of Annex III's law enforcement category. It can become high risk under Annex III point 6 where customs acts in criminal enforcement and the system profiles a natural person, for example around a seizure case. Annex III point 7(b) covers risk assessment of natural persons entering a Member State; it does not apply to this use case, which scores goods, consignments and trading entities, not natural persons. Where a natural person is profiled, GDPR's profiling rules and Article 22 apply, separately from AI Act classification, and criminal investigations fall under the Law Enforcement Directive (EU) 2016/680 instead.",[182,183],"customs-classification-and-declaration","tax-compliance-risk-scoring","2026-09-30","2026-09-29",[187],{"date":184,"note":188},"First published","customs-risk-targeting-and-container-selection",[191,219],{"title":192,"useCases":193,"organization":194,"vendors":199,"summary":202,"stage":203,"year":204,"channels":205,"languages":206,"metrics":207,"outcomeDisclosed":196,"sources":208,"verification":214,"grade":216,"id":217,"organizationSlug":218},"Indian Customs: AI and machine learning risk targeting, entity codification and valuation model",[189],{"name":195,"anonymized":196,"country":197,"region":198,"industry":17},"Indian Customs (Central Board of Indirect Taxes and Customs)",false,"IN","asia-pacific",[200],{"name":195,"role":201},"in-house","Indian Customs built an integrated, AI and machine learning powered risk management system. It codifies overseas suppliers and item descriptions with unsupervised machine learning so the same supplier and product can be matched across declarations, then runs a suite of models on top, including a \"Machine Learning-based Valuation Model\" that compares a shipment's declared value with historical declarations for the same product from the same supplier in real time, a supply chain network analytics tool, and predictive targeting of high risk suppliers. The models generate daily alerts and decision support for front line officers and were credited with supporting seizures including roughly 294 kg of heroin at Nhava Sheva Port and about 883 kg of methamphetamine in a maritime import consignment.","production",2025,[27],[],[],[209],{"url":210,"title":211,"publisher":212,"date":213},"https://mag.wcoomd.org/magazine/wco-news-108-issue-3-2025/codification-of-entities-and-goods-descriptions-indian-customs/","Artificial intelligence and machine learning-driven codification of entities and goods descriptions: transforming risk management in Indian Customs","World Customs Organization (WCO News), written by Indian Customs officials","2025-10-28",{"level":215,"checkedAt":185},"source-verified","B","indian-customs-ai-risk-targeting-and-valuation",null,{"title":220,"useCases":221,"organization":222,"vendors":226,"summary":228,"stage":203,"year":229,"channels":230,"languages":231,"metrics":232,"outcomeDisclosed":196,"sources":233,"verification":238,"grade":216,"id":239,"organizationSlug":240},"U.S. Customs and Border Protection: cargo and trade entity risk models feeding the Automated Targeting System",[189],{"name":223,"anonymized":196,"country":224,"region":225,"industry":17},"U.S. Customs and Border Protection","US","north-america",[227],{"name":223,"role":201},"CBP's own entries in the U.S. government's federal AI use case inventory describe three machine learning models that score cargo shipments and the entities behind them. Illicit Trade, live since July 2023, scores inbound cargo shipments for the risk that they violate trade regulations and sends its results to the Automated Targeting System for review. Cargo Security Assessment Model, live since December 2011, returns high risk shipments for narcotics smuggling threats as a rule hit an officer reviews and can act on. Trade Entity Risk Model, live since July 2025, builds a risk profile for each importer, supplier and trading partner from historical transactions, relationships and compliance history and feeds that score into CBP's other threat models. All three draw on data from the Automated Commercial Environment, the system that carries import and export declarations.",2023,[27],[],[],[234],{"url":235,"title":236,"publisher":237},"https://raw.githubusercontent.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory/main/Data/2025_individually_reported_AI_use_cases.csv","2025 Federal Agency AI Use Case Inventory: individually reported AI use cases (CSV), Department of Homeland Security submission, entries DHS-2390, DHS-2391 and DHS-95","U.S. Office of Management and Budget, consolidating U.S. Customs and Border Protection's own submission",{"level":215,"checkedAt":185},"us-cbp-cargo-and-trade-entity-risk-models","u-s-customs-and-border-protection",0,[],{"low":244,"high":245},1500000,31250000,[247,277,293,313],{"slug":182,"title":248,"shortTitle":249,"definition":250,"status":9,"industries":251,"functions":254,"patterns":257,"audience":29,"autonomy":30,"adoptionStage":31,"evidenceCount":262,"publicEvidenceCount":262,"organizations":263,"bestGrade":216,"headline":267,"lastVerified":275,"indexable":276},"AI for customs classification and declaration preparation","Customs classification and declarations","AI that reads what is being shipped (the commercial invoice, the product data and sometimes a photo), proposes the tariff classification code with its reasoning and a confidence score, drafts the customs declaration with value, origin and parties, and sends only uncertain or high risk entries to a licensed customs specialist before filing.",[18,252,253],"retail-and-ecommerce","cross-industry",[255,256],"operations","regulatory-compliance",[258,259,260,261],"classification-and-routing","document-processing","agentic-workflow","computer-vision",3,[264,265,266],"DHL Express","United Parcel Service","ZLS Zoll und Logistikservice GmbH",{"kpi":45,"label":268,"unit":269,"n":270,"nUpTo":241,"kind":271,"value":272,"qualifier":273,"claimant":274,"organization":265,"vendorReported":196},"Automation rate","percent",1,"reported",90,"exact","organization","2026-09-27",true,{"slug":183,"title":278,"shortTitle":279,"definition":280,"status":9,"industries":281,"functions":282,"patterns":283,"audience":29,"autonomy":284,"adoptionStage":31,"evidenceCount":285,"publicEvidenceCount":285,"organizations":286,"bestGrade":216,"headline":218,"lastVerified":275,"indexable":276},"AI for tax compliance risk scoring and audit selection","Tax compliance risk scoring","Models that score tax returns, taxpayers and transactions for the risk of error, underreporting or fraud, so that a tax administration spends its audit and compliance capacity where the risk is highest, with an officer deciding every compliance action and the selection itself monitored for fairness.",[17],[20,22,21],[24,25],"assist",6,[287,288,289,290,291,292],"Belastingdienst","Central Board of Indirect Taxes and Customs","HM Revenue and Customs","Inland Revenue Authority of Singapore","Internal Revenue Service","South African Revenue Service",{"slug":294,"title":295,"shortTitle":296,"definition":297,"status":9,"industries":298,"functions":299,"patterns":301,"audience":29,"autonomy":284,"adoptionStage":31,"evidenceCount":302,"publicEvidenceCount":302,"organizations":303,"bestGrade":216,"headline":309,"lastVerified":275,"indexable":276},"benefit-fraud-and-error-detection","AI for benefit fraud and error detection in social security","Benefit fraud and error detection","Risk models that help a social security or benefits agency decide which claims, payments and recipients to check for fraud or error, so that caseworkers verify the riskiest cases first, while every decision on entitlement stays with a person and the model is tested for fairness before and during use.",[17],[21,300,22],"citizen-services",[24,25],5,[304,305,306,307,308],"Centers for Medicare and Medicaid Services","Department for Work and Pensions","Gemeente Rotterdam","U.S. Department of the Treasury, Bureau of the Fiscal Service","Uitvoeringsinstituut Werknemersverzekeringen (UWV)",{"kpi":41,"label":310,"unit":311,"n":270,"nUpTo":241,"kind":271,"value":312,"qualifier":273,"claimant":274,"organization":305,"vendorReported":196},"Detection improvement","multiplier",2.5,{"slug":314,"title":315,"shortTitle":316,"definition":317,"status":9,"industries":318,"functions":319,"patterns":320,"audience":321,"autonomy":284,"adoptionStage":31,"evidenceCount":322,"publicEvidenceCount":322,"organizations":323,"bestGrade":216,"headline":218,"lastVerified":275,"indexable":276},"inspection-prioritization","AI for risk based inspection prioritization in food safety, workplace and environmental regulation","Inspection prioritization","Models that predict which premises, operators or activities are most likely to be non compliant, so that inspectors in food safety, workplace safety, environmental and other regulation spend their visits where the risk is highest, ideally with inspectors choosing the visits and random inspections testing the model.",[17],[20,22,256],[24,25],"employee-facing",8,[324,325,326,327,328,329,330,331],"Care Quality Commission","Driver and Vehicle Standards Agency","U.S. Environmental Protection Agency, Office of Enforcement and Compliance Assurance","U.S. Food and Drug Administration, Office of Information Operations","Food Standards Agency","Nederlandse Arbeidsinspectie","Nederlandse Voedsel- en Warenautoriteit (NVWA)","United States Coast Guard",{"indexable":276,"reasons":333},[],[335,339,344,351,357,364,370,377,384,391,398,404,410,416,423,430,436,443,448,454,461,468,473,478,483,490,495,500,507,512,519,526,532,538,543,548],{"id":147,"label":336,"issuer":154,"region":155,"url":156,"description":337,"useCases":338,"indexable":276},"EU AI Act","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",250,{"id":148,"label":340,"issuer":154,"region":155,"url":341,"description":342,"useCases":343,"indexable":276},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",223,{"id":150,"label":345,"issuer":346,"region":347,"url":348,"description":349,"useCases":350,"indexable":276},"ISO/IEC 42001","ISO and IEC","global","https://www.iso.org/standard/81230.html","The international management system standard for AI.",127,{"id":149,"label":352,"issuer":353,"region":225,"url":354,"description":355,"useCases":356,"indexable":276},"NIST AI Risk Management Framework","NIST","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",95,{"id":358,"label":359,"issuer":360,"region":155,"url":361,"description":362,"useCases":363,"indexable":276},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",73,{"id":365,"label":366,"issuer":154,"region":155,"url":367,"description":368,"useCases":369,"indexable":276},"dora","DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",67,{"id":371,"label":372,"issuer":373,"region":155,"url":374,"description":375,"useCases":376,"indexable":276},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",50,{"id":378,"label":379,"issuer":380,"region":198,"url":381,"description":382,"useCases":383,"indexable":276},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",37,{"id":385,"label":386,"issuer":387,"region":198,"url":388,"description":389,"useCases":390,"indexable":276},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":392,"label":393,"issuer":394,"region":347,"url":395,"description":396,"useCases":397,"indexable":276},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",22,{"id":399,"label":400,"issuer":401,"region":225,"url":402,"description":403,"useCases":397,"indexable":276},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":405,"label":406,"issuer":154,"region":155,"url":407,"description":408,"useCases":409,"indexable":276},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",17,{"id":411,"label":412,"issuer":413,"region":155,"url":414,"description":415,"useCases":409,"indexable":276},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",{"id":417,"label":418,"issuer":419,"region":225,"url":420,"description":421,"useCases":422,"indexable":276},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",16,{"id":424,"label":425,"issuer":426,"region":347,"url":427,"description":428,"useCases":429,"indexable":276},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":431,"label":432,"issuer":154,"region":155,"url":433,"description":434,"useCases":435,"indexable":276},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":437,"label":438,"issuer":439,"region":225,"url":440,"description":441,"useCases":442,"indexable":276},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":444,"label":445,"issuer":154,"region":155,"url":446,"description":447,"useCases":442,"indexable":276},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",{"id":449,"label":450,"issuer":451,"region":225,"url":452,"description":453,"useCases":442,"indexable":276},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":455,"label":456,"issuer":457,"region":347,"url":458,"description":459,"useCases":460,"indexable":276},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",12,{"id":462,"label":463,"issuer":464,"region":225,"url":465,"description":466,"useCases":467,"indexable":276},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",11,{"id":469,"label":470,"issuer":154,"region":155,"url":471,"description":472,"useCases":467,"indexable":276},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",{"id":474,"label":475,"issuer":154,"region":155,"url":476,"description":477,"useCases":467,"indexable":276},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":479,"label":480,"issuer":154,"region":155,"url":481,"description":482,"useCases":467,"indexable":276},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":484,"label":485,"issuer":486,"region":155,"url":487,"description":488,"useCases":489,"indexable":276},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",10,{"id":491,"label":492,"issuer":380,"region":198,"url":493,"description":494,"useCases":489,"indexable":276},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",{"id":496,"label":497,"issuer":154,"region":155,"url":498,"description":499,"useCases":489,"indexable":276},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":501,"label":502,"issuer":503,"region":225,"url":504,"description":505,"useCases":506,"indexable":276},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",7,{"id":508,"label":509,"issuer":154,"region":155,"url":510,"description":511,"useCases":506,"indexable":276},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",{"id":513,"label":514,"issuer":515,"region":516,"url":517,"description":518,"useCases":302,"indexable":276},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":520,"label":521,"issuer":522,"region":155,"url":523,"description":524,"useCases":525,"indexable":276},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",4,{"id":527,"label":528,"issuer":529,"region":155,"url":530,"description":531,"useCases":525,"indexable":276},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":533,"label":534,"issuer":535,"region":198,"url":536,"description":537,"useCases":262,"indexable":276},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":539,"label":540,"issuer":154,"region":155,"url":541,"description":542,"useCases":262,"indexable":276},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":544,"label":545,"issuer":154,"region":155,"url":546,"description":547,"useCases":262,"indexable":276},"eu-mortgage-credit-directive","EU Mortgage Credit Directive","https://eur-lex.europa.eu/eli/dir/2014/17/oj","Directive 2014/17/EU: creditworthiness assessment, disclosure and advice rules for residential mortgage lending.",{"id":549,"label":550,"issuer":551,"region":225,"url":552,"description":553,"useCases":262,"indexable":276},"nyc-local-law-144","NYC Local Law 144","New York City","https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page","Bias audits and notices for automated employment decision tools used in hiring and promotion in New York City.",1790783078289]