[{"data":1,"prerenderedAt":556},["ShallowReactive",2],{"uc-data-quality-monitoring-agent":3,"uc-regulations":348},{"useCase":4,"evidence":171,"blitsAiDeployments":236,"benchmarks":237,"indicative":249,"related":252,"indexability":346,"includeUnpublished":177},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":17,"functions":21,"patterns":24,"channels":28,"audience":31,"autonomy":32,"adoptionStage":33,"problem":34,"problemStats":35,"howItWorks":36,"valueDrivers":37,"kpis":41,"indicativeValue":45,"macroEstimates":80,"feasibility":81,"implementation":95,"risk":137,"blitsAi":152,"faq":154,"related":164,"datePublished":166,"dateModified":166,"lastVerified":166,"changelog":167,"slug":170},"AI agent for data quality monitoring and observability","Data quality monitoring agent","AI agent for data quality monitoring","An AI agent flags data quality problems before they reach a report. Monte Carlo reports SeatGeek halved root cause effort and Contentsquare cut detection time 17%.","published","An AI agent that watches data pipelines and tables continuously, uses machine learning to learn the normal pattern of freshness, volume, schema and distribution for each one, flags anomalies before they reach a dashboard or a downstream model, and traces the lineage back to the change that caused them so an engineer can fix the source, not just the symptom.",[12,13,14,15,16],"AI data observability","data quality agent","ML enabled anomaly detection for data","data incident detection AI","automated data quality monitoring",[18,19,20],"cross-industry","technology","retail-and-ecommerce",[22,23],"it-and-engineering","analytics-and-reporting",[25,26,27],"anomaly-detection","classification-and-routing","summarization",[29,30],"internal-tools","api","employee-facing","assist","early-adopters","A broken dbt model, a schema change upstream, or a partner feed that silently stops updating do\nnot throw an error. The pipeline runs, the table populates, and the first sign of trouble is\noften a business user asking why a report looks wrong. By the time someone notices, the bad data\nmay already have reached a dashboard, a finance close or a model that scores customers.\n\nFinding the cause is its own project. Brian London, SeatGeek's Director of Data Engineering,\ndescribed the pattern before the team adopted data observability: \"the way we would find out\nthere was a problem, most of the time, is one of the business users would post a Slack message,\nsaying that they're getting results that don't make sense.\" Monte Carlo's case study on the\ndeployment reports that SeatGeek's data teams were losing full days root causing data anomalies\nthat their business users had already found.",[],"1. **Learn the baseline.** For every monitored table and pipeline, the agent learns the normal\n   pattern of freshness, row volume, null rates, distributions and schema, from historical runs.\n2. **Detect anomalies in real time.** New data is compared against that baseline as it lands, and\n   deviations are flagged before a scheduled report or model run consumes the data.\n3. **Trace the lineage.** Field level lineage shows which upstream tables, jobs and models feed\n   the affected asset, so root causing an anomaly means following a lineage graph instead of\n   manually querying every candidate source.\n4. **Rank and route.** Anomalies are grouped into incidents, ranked by the number of downstream\n   assets and users they affect, and routed to the team that owns the source.\n5. **Confirm and learn.** An engineer confirms the cause and the fix; confirmed incidents refine\n   future ranking and give the team a record of recurring failure points to fix at the source.",[38,39,40],"risk-reduction","employee-productivity","speed",[42,43,44],"mttr-reduction","productivity-gain","error-reduction",{"referenceOrg":46,"inputs":47,"formula":75,"currency":76,"period":77,"resultLabel":78,"caveat":79},"A data team that logs 10 data quality incidents a month across its pipelines",[48,54,61,68],{"key":49,"label":50,"low":51,"high":51,"unit":52,"note":53},"incidentsPerMonth","Data quality incidents per month before monitoring",10,"incidents per month","The reference organization, based on the baseline Monte Carlo reports for SeatGeek before it adopted data observability.",{"key":55,"label":56,"low":57,"high":58,"unit":59,"note":60},"hoursPerIncident","Engineering hours lost root causing one incident",4,8,"hours per incident","Editorial assumption for a mid sized data team. Replace with your own incident retrospective data.",{"key":62,"label":63,"low":64,"high":65,"unit":66,"note":67},"reduction","Reduction in root cause effort from automated anomaly detection and lineage",0.15,0.5,"fraction of hours","The range spans the two vendor reported results on this page, which are not directly comparable: Monte Carlo reports SeatGeek cut root cause resource drain, an effort measure, by 50%, while Contentsquare's 17% and 16% figures measure elapsed detection and resolution time, not effort. Treat this as a rough range to replace with your own incident retrospective data; results depend on how much of the pipeline has lineage mapped.",{"key":69,"label":70,"low":71,"high":72,"unit":73,"note":74},"hourlyCost","Fully loaded cost of a data engineer",70,110,"USD per hour","Editorial assumption. Replace with your own rate.","incidentsPerMonth * 12 * hoursPerIncident * reduction * hourlyCost","USD","per year","Annual data engineering time released from data incident response","Engineering time only. It leaves out the subscription cost of the observability platform, the revenue and trust cost of bad data that does reach a report or a model, and any reduction in the total number of incidents rather than just the time to resolve them.",[],{"complexity":82,"complexityNote":83,"dataPrerequisites":84,"integrations":89},"medium","Connecting to a warehouse or lakehouse and turning on default anomaly detection is fast. Field level lineage and low noise alerting take longer, and depend on consistent naming, documented ownership and a data catalog the agent can use for context.",[85,86,87,88],"Read access to the data warehouse, lakehouse or pipeline orchestrator","Table and pipeline ownership recorded somewhere the agent can read","History of past incidents and their confirmed root cause, to tune ranking","A data catalog or glossary, so anomalies can be described in business terms",[90,91,92,93,94],"Data warehouse or lakehouse (Snowflake, BigQuery, Databricks and similar)","Orchestration tool for pipeline and job metadata (Airflow, dbt and similar)","Business intelligence tool, to trace which dashboards an anomaly reaches","Chat tool for incident alerts and ChatOps triage","Ticketing system for confirmed incidents that need a fix",{"steps":96,"guardrails":112,"humanInTheLoop":118,"kpisToInstrument":119,"failureModes":124},[97,100,103,106,109],{"title":98,"detail":99},"Start with the tables people already distrust","Connect the sources feeding the reports and models with a known history of quiet failures first, so the first alerts are on something a stakeholder will recognize and value.",{"title":101,"detail":102},"Tune before you trust","Default anomaly thresholds are noisy on a new data set. Spend the first weeks tuning sensitivity per table and suppressing known, benign patterns before routing alerts widely.",{"title":104,"detail":105},"Map lineage where it matters most","Prioritize lineage for the pipelines with the most downstream consumers, since that is where a fast root cause saves the most time and the most trust.",{"title":107,"detail":108},"Route to the owner, not a shared queue","An anomaly that lands in a queue nobody owns gets ignored. Route each alert to the team whose pipeline caused it, with the lineage and the affected downstream assets attached.",{"title":110,"detail":111},"Close the loop on confirmed incidents","Record the confirmed cause and the fix for every incident, and use that history to reduce noise and to find the pipelines that fail repeatedly and need to be rebuilt, not just fixed.",[113,114,115,116,117],"Read only access to source systems; the agent never writes back to production data","Alert thresholds tuned per table, with known benign patterns suppressed rather than silenced entirely","Every alert shows its evidence (the metric, the baseline, the lineage) so it can be checked in seconds","Anomalies are routed to a named owning team, never a shared, unowned queue","Sensitive fields excluded from anomaly previews and alert payloads","An engineer confirms every incident's root cause and decides the fix; the agent detects, ranks and traces lineage, it does not change data or pipelines itself. Data platform leads review alert noise and confirmed incident patterns periodically to retune thresholds and prioritize fixes.",[120,121,122,123],"Data incidents detected before a downstream user reports them, versus after","Time from anomaly detection to root cause confirmation","Alert to confirmed incident ratio, to track noise","Recurrence rate of incidents from the same source pipeline",[125,128,131,134],{"title":126,"detail":127},"Alert fatigue from an untuned baseline","A new table triggers noisy alerts until enough history exists to learn its normal pattern. Start monitoring in a silent mode and tune before routing alerts.",{"title":129,"detail":130},"Lineage gaps hide the real source","An anomaly is traced only as far as the lineage graph reaches, and stops short of the true upstream cause. Prioritize mapping lineage for high impact pipelines first.",{"title":132,"detail":133},"Confirmed incidents never feed back","The same failure recurs because nobody tracked it back to a source that needs rebuilding. Keep a record of confirmed causes and review recurring ones on a cadence.",{"title":135,"detail":136},"Anomaly detection on the wrong signal","A model flags a real, expected change (a new market launch, a seasonal pattern) as an anomaly. Let owners mark expected changes so the baseline updates instead of alerting every time.",{"euAiAct":138,"regulations":141,"guidance":145,"controls":146,"incidents":151},{"tier":139,"basis":140},"minimal","An internal data engineering tool that flags anomalies in pipelines and tables; it is not a use listed in Annex III and makes no decision about a natural person. If the monitored data feeds a high risk system, such as a credit or employment decision, the AI Act obligations attach to that downstream system, not to this monitoring layer.",[142,143,144],"gdpr","nist-ai-rmf","iso-42001",[],[147,148,149,150],"Inventory entry for the monitoring agent with an owner and the data sources in scope","Read only access enforced and reviewed periodically","Confirmed incident log kept for audit and for retuning alert thresholds","Sensitive and personal data excluded from alert previews by default",[],{"howToBuild":153},"On Blits.ai this is an **agentic workflow** triggered on a schedule or called by the\norchestrator via API. **Custom functions** (SQL queries and REST calls) pull freshness,\nvolume, distribution and schema metrics from a warehouse such as Snowflake, BigQuery or\nDatabricks, and pipeline and lineage metadata from the orchestration tool. Another custom\nfunction, outside the agent's own tool set, writes each run's readings into a table in a\n**SQL knowledge base** (PostgreSQL or SQLite). An **AI agent** with **structured output**\nqueries that table as its baseline, compares each new reading against it, ranks the resulting\nincidents by downstream impact, and summarizes the likely cause. A **tool execution policy**\nlimits which tools the agent may call, restricting it to the read functions that pull metrics\nand lineage.\n\nRanked incidents route to the owning team through the ready made **Microsoft Teams**\nintegration, or to Slack through a custom function's REST call or the integration catalog,\nwith the anomaly, the lineage and the affected downstream assets attached. **Human in the\nloop** approval lets the owning engineer approve or reject the follow up action the agent\nproposes, such as opening a ticket or posting the incident, rather than let it go out\nunattended. **Run history with a full audit trail, analytics and downloadable run data**\nkeeps every detection and every approval decision available for later analysis. A separate\n**monitor** can run a scheduled health check on the monitoring agent itself. The platform is\nmodel agnostic, with EU and UAE data residency for the metadata the agent processes.",[155,158,161],{"question":156,"answer":157},"Is this the same as an AIOps incident triage agent?","No, though the two are close cousins. AIOps incident triage correlates application and infrastructure alerts during a live outage. A data quality monitoring agent watches tables and pipelines for freshness, volume and schema problems, often before anyone would call it an incident at all, and traces the issue through data lineage rather than a service map.",{"question":159,"answer":160},"How much manual data quality work does this actually remove?","Monte Carlo reports that SeatGeek, a ticketing marketplace, cut its root cause resource drain by 50% and went from about 10 data incidents a month to zero in the second quarter after enabling its platform, and that Contentsquare cut its time to detect a data incident by 17% and its time to resolution by 16% in one month. Results depend on how much lineage is mapped and how noisy the starting baseline is.",{"question":162,"answer":163},"What should be monitored first?","The tables and pipelines that feed reports or models people already distrust. Early wins on data stakeholders already care about build the credibility to expand coverage.",[165],"aiops-incident-triage","2026-09-28",[168],{"date":166,"note":169},"First published","data-quality-monitoring-agent",[172,211],{"title":173,"useCases":174,"organization":175,"vendors":180,"summary":184,"stage":185,"year":186,"channels":187,"languages":188,"metrics":189,"outcomeDisclosed":202,"sources":203,"verification":206,"grade":208,"id":209,"organizationSlug":210},"Contentsquare: faster data incident detection and resolution",[170],{"name":176,"anonymized":177,"country":178,"region":179,"industry":19},"Contentsquare",false,"FR","europe",[181],{"name":182,"role":183},"Monte Carlo","platform","Contentsquare, a digital experience analytics company, had too many manual data quality checks run by operations and data analysts, and still lacked visibility into data incidents before they reached stakeholders. It deployed Monte Carlo's end to end data observability platform to detect anomalies earlier and build a collaborative incident resolution workflow between the data team and the business. Monte Carlo reports that, within one month, Contentsquare saw faster detection and faster resolution of data incidents.","production",2023,[29],[],[190,199],{"kpi":42,"value":191,"unit":192,"qualifier":193,"period":194,"baseline":195,"claimant":196,"quote":197,"sourceUrl":198},17,"percent","exact","in one month","Time to detect a data incident before Monte Carlo","vendor","Deploying Monte Carlo led to a 17% reduction in data incident detection time and a 16% reduction in time to resolution – in just one month.","https://www.montecarlodata.com/blog-how-contentsquare-reduced-time-to-data-incident-detection-by-17-percent-with-monte-carlo/",{"kpi":42,"value":200,"unit":192,"qualifier":193,"period":194,"baseline":201,"claimant":196,"quote":197,"sourceUrl":198},16,"Time to resolve a data incident before Monte Carlo",true,[204],{"url":198,"title":205,"publisher":182},"How Contentsquare Reduced Time to Data Incident Detection by 17 Percent with Monte Carlo",{"level":207,"checkedAt":166},"source-verified","C","contentsquare-data-incident-detection",null,{"title":212,"useCases":213,"organization":214,"vendors":218,"summary":220,"stage":185,"year":221,"channels":222,"languages":223,"metrics":224,"outcomeDisclosed":202,"sources":231,"verification":234,"grade":208,"id":235,"organizationSlug":210},"SeatGeek: ML anomaly detection and field level lineage for data quality",[170],{"name":215,"anonymized":177,"country":216,"region":217,"industry":20},"SeatGeek","US","north-america",[219],{"name":182,"role":183},"SeatGeek's data platform and analytics teams were losing full days root causing data anomalies that business users noticed first, averaging about 10 internal data downtime issues a month. They adopted Monte Carlo's ML enabled anomaly detection and field level lineage tracking to catch problems before they reached business users. Monte Carlo reports that SeatGeek reduced data incidents per month from 10 to 0 in the second quarter after enabling the platform at scale, and cut the resource drain from root cause analysis by half.",2022,[29],[],[225],{"kpi":43,"value":226,"unit":192,"qualifier":193,"period":227,"baseline":228,"claimant":196,"quote":229,"sourceUrl":230},50,"since implementing Monte Carlo at scale","Resource drain from root cause analysis before Monte Carlo","Reduced resource drain from root-cause analysis by 50% and improved efficiency across all data teams","https://www.montecarlodata.com/blog-how-seatgeek-reduced-data-incidents-to-zero-with-data-observability/",[232],{"url":230,"title":233,"publisher":182},"How SeatGeek Reduced Data Incidents to Zero with Data Observability",{"level":207,"checkedAt":166},"seatgeek-data-quality-observability",0,[238,244],{"kpi":43,"label":239,"unit":192,"aggregate":202,"higherIsBetter":202,"n":240,"nUpTo":236,"median":226,"min":226,"max":226,"byClaimant":241,"vendorOnly":202,"points":242},"Productivity gain",1,{"organization":236,"vendor":240,"regulator":236,"independent":236},[243],{"evidenceId":235,"organization":215,"value":226,"qualifier":193,"claimant":196,"grade":208,"pooled":202},{"kpi":42,"label":245,"unit":192,"aggregate":202,"higherIsBetter":202,"n":240,"nUpTo":236,"median":191,"min":191,"max":191,"byClaimant":246,"vendorOnly":202,"points":247},"Time to repair reduction",{"organization":236,"vendor":240,"regulator":236,"independent":236},[248],{"evidenceId":209,"organization":176,"value":191,"qualifier":193,"claimant":196,"grade":208,"pooled":202},{"low":250,"high":251},5040,52800,[253,284,300,324],{"slug":165,"title":254,"shortTitle":255,"definition":256,"status":9,"industries":257,"functions":261,"patterns":264,"audience":31,"autonomy":267,"adoptionStage":33,"evidenceCount":268,"publicEvidenceCount":269,"organizations":270,"bestGrade":276,"headline":277,"lastVerified":283,"indexable":202},"AI for IT incident triage and root cause analysis (AIOps)","AIOps incident triage","AI that turns a flood of monitoring alerts into one probable incident, routes it to the right team, proposes likely root causes and remediation from runbooks and past incidents, and drafts the stakeholder updates and the post incident review, while an engineer authorizes every change.",[18,258,19,259,260],"banking","telecommunications","payments",[22,262,263],"operations","risk-management",[25,26,27,265,266],"rag-knowledge-assistant","agentic-workflow","copilot",6,5,[271,272,273,274,275],"Google","Meta","Microsoft","Mizuho Financial Group","TD Bank","B",{"kpi":278,"label":279,"unit":192,"n":280,"nUpTo":236,"kind":281,"value":282,"qualifier":193,"claimant":210,"organization":210,"vendorReported":177},"accuracy","Accuracy",3,"median",90,"2026-09-27",{"slug":285,"title":286,"shortTitle":287,"definition":288,"status":9,"industries":289,"functions":292,"patterns":293,"audience":31,"autonomy":32,"adoptionStage":33,"evidenceCount":280,"publicEvidenceCount":280,"organizations":296,"bestGrade":276,"headline":210,"lastVerified":283,"indexable":202},"governed-text-to-sql-analytics","Governed text to SQL analytics assistant","Governed SQL analytics","An assistant that turns a business user's plain language question into a query against governed data, runs it under that user's own data permissions and returns the table or chart together with the SQL and the tables used, so routine ad hoc questions no longer queue for the data team.",[18,258,290,20,19,291],"insurance","pharma-and-life-sciences",[23,22],[294,295,265],"conversational-agent","code-generation",[297,298,299],"Bayer","LinkedIn","Uber Technologies",{"slug":301,"title":302,"shortTitle":303,"definition":304,"status":9,"industries":305,"functions":307,"patterns":308,"audience":31,"autonomy":309,"adoptionStage":310,"evidenceCount":58,"publicEvidenceCount":268,"organizations":311,"bestGrade":276,"headline":318,"lastVerified":283,"indexable":202},"it-service-desk-resolution-agent","AI agent for IT service desk resolution","IT service desk resolution","An AI agent in Microsoft Teams, Slack or the intranet that takes the high volume IT support queue, such as password and MFA resets, account unlocks, VPN, device and software requests, and resolves common requests by acting in the identity and IT service management systems, handing the rest to the right resolver group with the context attached.",[18,258,19,20,306],"healthcare",[22,262],[294,266,265,26],"supervised-agent","mainstream",[312,313,314,315,316,317],"7-Eleven Vietnam","Bank of America","Equinix","IBM","Mercari US","Vituity",{"kpi":319,"label":320,"unit":192,"n":321,"nUpTo":236,"kind":322,"value":323,"qualifier":193,"claimant":196,"organization":316,"vendorReported":202},"employee-adoption","Employee adoption",2,"reported",94,{"slug":325,"title":326,"shortTitle":327,"definition":328,"status":9,"industries":329,"functions":332,"patterns":334,"audience":31,"autonomy":309,"adoptionStage":33,"evidenceCount":335,"publicEvidenceCount":335,"organizations":336,"bestGrade":276,"headline":344,"lastVerified":283,"indexable":202},"security-alert-triage-and-investigation","AI for security alert triage and investigation in the SOC","Security alert triage","An AI agent in the security operations centre that picks up each new alert or user reported phishing email, gathers the evidence from the SIEM, endpoint, identity and threat intelligence tools, gives a verdict with its reasoning and a draft incident summary, and closes clear false positives while an analyst approves every containment action.",[18,306,19,330,331],"government","professional-services",[333,22],"security-operations",[266,26,27,265],7,[337,338,339,340,341,342,343],"Avanade","Federal Housing Finance Agency","Human Managed","SEP2","St. Luke's University Health Network","TÜV SÜD","U.S. Immigration and Customs Enforcement",{"kpi":43,"label":239,"unit":192,"n":280,"nUpTo":236,"kind":281,"value":345,"qualifier":193,"claimant":210,"organization":210,"vendorReported":177},60,{"indexable":202,"reasons":347},[],[349,356,361,367,373,379,386,393,401,408,415,421,427,434,440,445,452,458,464,470,476,482,487,492,497,504,510,515,520,527,533,539,545,550],{"id":350,"label":351,"issuer":352,"region":179,"url":353,"description":354,"useCases":355,"indexable":202},"eu-ai-act","EU AI Act","European Union","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":142,"label":357,"issuer":352,"region":179,"url":358,"description":359,"useCases":360,"indexable":202},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":144,"label":362,"issuer":363,"region":364,"url":365,"description":366,"useCases":72,"indexable":202},"ISO/IEC 42001","ISO and IEC","global","https://www.iso.org/standard/81230.html","The international management system standard for AI.",{"id":143,"label":368,"issuer":369,"region":217,"url":370,"description":371,"useCases":372,"indexable":202},"NIST AI Risk Management Framework","NIST","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":374,"label":375,"issuer":352,"region":179,"url":376,"description":377,"useCases":378,"indexable":202},"dora","DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":380,"label":381,"issuer":382,"region":179,"url":383,"description":384,"useCases":385,"indexable":202},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":387,"label":388,"issuer":389,"region":179,"url":390,"description":391,"useCases":392,"indexable":202},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":394,"label":395,"issuer":396,"region":397,"url":398,"description":399,"useCases":400,"indexable":202},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":402,"label":403,"issuer":404,"region":397,"url":405,"description":406,"useCases":407,"indexable":202},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":409,"label":410,"issuer":411,"region":364,"url":412,"description":413,"useCases":414,"indexable":202},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",20,{"id":416,"label":417,"issuer":418,"region":217,"url":419,"description":420,"useCases":414,"indexable":202},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":422,"label":423,"issuer":424,"region":179,"url":425,"description":426,"useCases":200,"indexable":202},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",{"id":428,"label":429,"issuer":430,"region":364,"url":431,"description":432,"useCases":433,"indexable":202},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":435,"label":436,"issuer":352,"region":179,"url":437,"description":438,"useCases":439,"indexable":202},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":441,"label":442,"issuer":352,"region":179,"url":443,"description":444,"useCases":439,"indexable":202},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":446,"label":447,"issuer":448,"region":217,"url":449,"description":450,"useCases":451,"indexable":202},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":453,"label":454,"issuer":352,"region":179,"url":455,"description":456,"useCases":457,"indexable":202},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":459,"label":460,"issuer":461,"region":217,"url":462,"description":463,"useCases":457,"indexable":202},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":465,"label":466,"issuer":467,"region":364,"url":468,"description":469,"useCases":457,"indexable":202},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":471,"label":472,"issuer":352,"region":179,"url":473,"description":474,"useCases":475,"indexable":202},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":477,"label":478,"issuer":479,"region":217,"url":480,"description":481,"useCases":475,"indexable":202},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":483,"label":484,"issuer":396,"region":397,"url":485,"description":486,"useCases":51,"indexable":202},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",{"id":488,"label":489,"issuer":352,"region":179,"url":490,"description":491,"useCases":51,"indexable":202},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":493,"label":494,"issuer":352,"region":179,"url":495,"description":496,"useCases":51,"indexable":202},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":498,"label":499,"issuer":500,"region":179,"url":501,"description":502,"useCases":503,"indexable":202},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":505,"label":506,"issuer":507,"region":217,"url":508,"description":509,"useCases":58,"indexable":202},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",{"id":511,"label":512,"issuer":352,"region":179,"url":513,"description":514,"useCases":58,"indexable":202},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":516,"label":517,"issuer":352,"region":179,"url":518,"description":519,"useCases":268,"indexable":202},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",{"id":521,"label":522,"issuer":523,"region":524,"url":525,"description":526,"useCases":269,"indexable":202},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":528,"label":529,"issuer":530,"region":179,"url":531,"description":532,"useCases":57,"indexable":202},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":534,"label":535,"issuer":536,"region":179,"url":537,"description":538,"useCases":57,"indexable":202},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":540,"label":541,"issuer":542,"region":397,"url":543,"description":544,"useCases":280,"indexable":202},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":546,"label":547,"issuer":352,"region":179,"url":548,"description":549,"useCases":280,"indexable":202},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":551,"label":552,"issuer":553,"region":217,"url":554,"description":555,"useCases":280,"indexable":202},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598294510]