[{"data":1,"prerenderedAt":559},["ShallowReactive",2],{"uc-dynamic-customer-risk-rating":3,"uc-regulations":358},{"useCase":4,"evidence":209,"blitsAiDeployments":247,"benchmarks":248,"indicative":249,"related":252,"indexability":356,"includeUnpublished":215},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":16,"functions":20,"patterns":23,"channels":26,"audience":29,"autonomy":30,"adoptionStage":31,"segment":32,"problem":33,"problemStats":34,"howItWorks":40,"valueDrivers":41,"kpis":45,"indicativeValue":49,"macroEstimates":83,"feasibility":84,"implementation":98,"risk":138,"blitsAi":183,"faq":185,"related":198,"datePublished":204,"dateModified":204,"lastVerified":204,"changelog":205,"slug":208},"Dynamic AML customer risk rating with machine learning","Dynamic customer risk rating","AML customer risk rating with machine learning","How banks use explainable machine learning to rate and update AML customer risk, with a playbook, a value model and EU AI Act status.","published","Explainable machine learning that produces the money laundering risk rating itself: it computes and continuously updates each customer's rating from due diligence data, products, geography, behaviour and screening results, and shows which factors drive the rating and when enhanced due diligence is warranted.",[12,13,14,15],"customer risk rating","AML customer risk scoring","dynamic risk assessment","behavioural customer risk rating",[17,18,19],"banking","payments","wealth-and-asset-management",[21,22],"financial-crime-compliance","risk-management",[24,25],"prediction-and-scoring","anomaly-detection",[27,28],"internal-tools","api","back-office","supervised-agent","early-adopters","middle-office","Every bank must rate the money laundering risk of each customer and apply more scrutiny to the\nhigher risk ones. In many banks the rating is a static scorecard filled in at onboarding and\nrefreshed at fixed intervals; Fenergo describes periodic KYC checks as typically carried out\nannually or every two years. Between reviews the customer's behaviour can change completely\nwithout the rating moving.\n\nStatic scorecards can also drift out of line with reality: customers can end up high risk\nbecause of a single attribute, which adds work for enhanced due diligence teams, while risky behaviour in\na low rated customer can go unnoticed until an alert or a law enforcement request. Supervisors\nexpect a documented, risk based approach, and industry principles such as the Wolfsberg Group's\nask that machine learning results can be explained from the data that went in.",[35],{"statement":36,"sourceTitle":37,"sourceUrl":38,"year":39},"A Fenergo study found that more than half of financial institutions spend between 61 and 150 days on client KYC reviews, at an average cost of $2,200 per review.","Ongoing Customer Due Diligence with Perpetual KYC","https://resources.fenergo.com/blogs/perpetual-kyc-pkyc",2026,"1. **Combine the data.** Due diligence attributes, products and channels, geographies, screening\n   results, transaction behaviour and alert history are brought together per customer.\n2. **Score with explanations.** An interpretable model, or a model with feature attribution,\n   produces a risk score and the factors that raise or lower it, alongside the bank's\n   regulatory minimum rules (for example PEPs are always high risk).\n3. **Update on events.** The score is recalculated when behaviour or data changes, not only on the\n   review date, and a material move creates a task.\n4. **Route the work.** Customers moving into higher risk bands are queued for enhanced due\n   diligence with the drivers listed; moves down are reviewed before they reduce scrutiny.\n5. **Govern the model.** Rating distribution, stability and outcomes (alerts, reports, exits per\n   band) are monitored, and the model is validated like any other risk model.",[42,43,44],"compliance","risk-reduction","employee-productivity",[46,47,48],"detection-rate-improvement","productivity-gain","processing-time-reduction",{"referenceOrg":50,"inputs":51,"formula":78,"currency":79,"period":80,"resultLabel":81,"caveat":82},"A bank with 500,000 customers and 15,000 enhanced due diligence reviews a year",[52,58,65,72],{"key":53,"label":54,"low":55,"high":55,"unit":56,"note":57},"eddReviews","Enhanced due diligence reviews per year",15000,"reviews per year","The reference bank.",{"key":59,"label":60,"low":61,"high":62,"unit":63,"note":64},"hoursPerReview","Hours per enhanced due diligence review",2,5,"hours per review","Editorial assumption. Replace with your own.",{"key":66,"label":67,"low":68,"high":69,"unit":70,"note":71},"misratedShare","Share of reviews avoided because customers were rated high only by static rules",0.1,0.25,"fraction of reviews","Editorial assumption. Replace with the results of your own rerating exercise.",{"key":73,"label":74,"low":75,"high":76,"unit":77,"note":64},"costPerHour","Fully loaded analyst cost per hour",40,70,"USD per hour","eddReviews * hoursPerReview * misratedShare * costPerHour","USD","per year","Enhanced due diligence effort redirected","Assumes the released effort is redirected to genuinely risky customers rather than cut. It leaves out the value of catching risk between reviews and the cost of model validation.",[],{"complexity":85,"complexityNote":86,"dataPrerequisites":87,"integrations":92},"high","The rating drives regulatory obligations for every customer, so it must be explainable, stable, validated and consistent with the bank's documented risk assessment. Data joining across KYC, transactions and screening is usually the biggest piece of work.",[88,89,90,91],"Customer due diligence attributes with data quality measures","Transaction behaviour aggregated per customer","Screening, alert and suspicious activity report history","The bank's enterprise wide money laundering risk assessment and rating methodology",[93,94,95,96,97],"KYC and customer lifecycle management system","Transaction monitoring and case management","Screening engines","Core banking and product systems","Periodic review and enhanced due diligence workflow",{"steps":99,"guardrails":115,"humanInTheLoop":121,"kpisToInstrument":122,"failureModes":128},[100,103,106,109,112],{"title":101,"detail":102},"Keep the regulatory floor explicit","Write down the ratings that rules dictate (for example PEPs and high risk jurisdictions) and keep them as hard constraints above the model.",{"title":104,"detail":105},"Choose explainability over marginal accuracy","Prefer a model whose drivers an analyst can read out to an examiner. A slightly better score that nobody can explain is not usable.",{"title":107,"detail":108},"Back test against outcomes","Check that higher bands contain more alerts, reports and exits than lower ones, on history, and compare with the current scorecard.",{"title":110,"detail":111},"Rerate in parallel","Rerate the whole book in parallel and review the largest moves with compliance before switching, including customers that would move down.",{"title":113,"detail":114},"Turn on event driven updates","Recalculate on material events and route moves into higher bands to enhanced due diligence with the drivers attached.",[116,117,118,119,120],"Regulatory minimum ratings enforced as hard rules above the model","Every rating shows its contributing factors in plain language","Moves to a lower band that reduce scrutiny are reviewed by a human","Bias testing so that nationality or other protected characteristics do not drive ratings beyond what the risk assessment justifies","Model inventory entry with validation and stability monitoring","The model rates and updates; analysts confirm moves into and out of high risk, and compliance owns the methodology, approves the model and reviews distribution and outcome reports. Decisions to restrict or exit a customer remain human decisions.",[123,124,125,126,127],"Distribution of customers across bands and month on month stability","Alerts, reports and exits per band (the rating should separate them)","Enhanced due diligence volume and time per review","Share of rating moves overturned by analysts","Time from a material event to the updated rating",[129,132,135],{"title":130,"detail":131},"The black box rating","A rating the bank cannot explain is hard to defend to a supervisor and gives analysts nothing to investigate, however accurate it is. Use interpretable models or reliable attribution.",{"title":133,"detail":134},"Rating churn","Customers flip between bands with every transaction, creating work without insight. Smooth scores and use materiality thresholds.",{"title":136,"detail":137},"Proxy discrimination","The model leans on nationality or postcode beyond what the risk assessment supports. Test and constrain features.",{"euAiAct":139,"regulations":142,"guidance":154,"controls":172,"incidents":178},{"tier":140,"basis":141},"context-dependent","An AML customer risk rating is not listed in Annex III. Article 5(1)(d) prohibits AI risk assessments that predict whether a natural person will commit or will likely commit a criminal offence based solely on profiling of that person or on assessing their personality traits and characteristics; it exempts only AI that supports the human assessment of a person's involvement in a criminal activity, which is already based on objective and verifiable facts directly linked to a criminal activity. An AML customer risk rating built from due diligence attributes, transaction behaviour and screening results is itself an automated evaluation of a person's situation and behaviour, which is profiling under GDPR Article 4(4), and due diligence facts such as occupation, geography and products are not facts directly linked to a criminal activity, so the rating does not sit squarely inside the exemption. What keeps it a defensible AML due diligence tool rather than an offence prediction is that it does not itself accuse a person of an offence: it sets a level of scrutiny, a human analyst reviews material moves, and regulatory minimum rules sit above the model as hard constraints. A rating driven mainly by nationality or other personal attributes weakens that position further, which is why the proxy discrimination guardrail matters. If the same score is used to evaluate the creditworthiness of natural persons or to establish their credit score, that use falls under Annex III point 5(b) and is high risk, so keep the AML rating and credit decisions separate.",[143,144,145,146,147,148,149,150,151,152,153],"eu-ai-act","gdpr","fatf-recommendations","us-sr-11-7","mas-ai-risk-management","cbuae-ai-guidance","nist-ai-rmf","iso-42001","eu-amlr","us-bsa","mas-notice-626",[155,161,167],{"title":156,"issuer":157,"region":158,"url":159,"note":160},"Supporting Artificial Intelligence Adoption in AML/CFT","Hong Kong Monetary Authority","asia-pacific","https://brdr.hkma.gov.hk/eng/doc-ldg/docId/getPdf/20251118-3-EN/20251118-3-EN.pdf","Describes banks moving from rules to holistic, data driven AML approaches and the supervisor's support programme.",{"title":162,"issuer":163,"region":164,"url":165,"note":166},"Principles for Using Artificial Intelligence and Machine Learning in Financial Crime Compliance","Wolfsberg Group","global","https://wolfsberg-group.org/resources/202/93","Industry principles on accountability, openness and transparency that apply directly to a risk rating model.",{"title":168,"issuer":169,"region":158,"url":170,"note":171},"Notice 626 Prevention of Money Laundering and Countering the Financing of Terrorism, Banks","Monetary Authority of Singapore","https://www.mas.gov.sg/regulation/notices/notice-626","Example of national rules on risk based customer due diligence and enhanced measures for higher risk customers.",[173,174,175,176,177],"Documented rating methodology linked to the enterprise wide risk assessment","Factor level explanation stored with every rating","Independent validation, stability monitoring and annual review of the model","Bias testing on protected characteristics","Human review of material moves in both directions",[179],{"title":180,"url":181,"note":182},"De Nederlandsche Bank fines bunq for insufficient customer due diligence","https://www.dnb.nl/en/general-news/enforcement-measures-2025/fine-for-bunq-b-v-for-insufficient-customer-due-diligence/","On 6 May 2025 the Dutch central bank fined bunq EUR 2.6 million because it did not sufficiently follow up signals and transaction monitoring alerts in four customer files it had itself identified as high risk (period January 2021 to May 2022); bunq has appealed. The notice does not blame bunq's data driven approach, but it shows that a rating is only as good as the human follow up it triggers.",{"howToBuild":184},"The rating model belongs in the bank's analytics platform. Blits.ai handles the work it\ntriggers: when a rating moves into a higher band, an **agentic workflow**, started through the\nAPI, collects the drivers and the customer file through **custom functions** and **SQL knowledge\nbases**, drafts the enhanced due diligence request and the questions to ask, and routes it to an\nanalyst through **human in the loop approval**.\n\nWhere the bank needs information from the customer, a **conversational agent** in the bank's\nown app through the **REST API channel**, by **email** or on **WhatsApp** can collect source of funds or updated details and documents, with\n**PII masking**, **guardrails** and a **human handover** for anything sensitive. Runs keep a\nfull audit trail, **test suites** cover the drafting, and the platform is model agnostic with EU\nand UAE data residency.",[186,189,192,195],{"question":187,"answer":188},"What is a dynamic customer risk rating?","A money laundering risk rating that updates when the customer's data or behaviour changes, instead of only at a scheduled review, and shows which factors drive it.",{"question":190,"answer":191},"Does a machine learning risk rating have to be explainable?","In practice yes. The Wolfsberg Group's principles for AI and machine learning in financial crime compliance ask that results \"can be adequately explained or proven given the data inputs\", and analysts need the drivers to run enhanced due diligence. Choose interpretable models or reliable attribution over a small gain in accuracy.",{"question":193,"answer":194},"Is the risk rating high risk under the EU AI Act?","Not as an AML tool: AML risk rating is not listed in Annex III. It becomes high risk if the same score is used to evaluate the creditworthiness of natural persons or to set their credit score (Annex III point 5(b)), so keep the uses separate and documented. Article 5(1)(d) bans predicting that a person will commit an offence from profiling or personality traits alone; it is designed as a due diligence tool, not an offence prediction, so do not let it drive a rating from nationality or other personal traits alone, keep the regulatory minimum rules and analyst review in place, and treat the rating itself as a level of scrutiny rather than an accusation.",{"question":196,"answer":197},"How is this different from a machine learning transaction monitoring score?","A monitoring score such as HSBC's Dynamic Risk Assessment, which Google Cloud describes as a customer risk score offered as an alternative to rules based transaction alerting, decides which customers investigators look at for suspicious activity (see AML alert triage). The rating on this page decides the level of due diligence each customer gets. The two share data and methods, so HSBC's deployment is related evidence here rather than a direct example.",[199,200,201,202,203],"perpetual-kyc","aml-alert-triage","pep-and-adverse-media-screening","business-onboarding-and-ubo-discovery","source-of-wealth-diligence","2026-09-27",[206],{"date":204,"note":207},"First published","dynamic-customer-risk-rating",[210],{"title":211,"useCases":212,"organization":213,"vendors":218,"summary":221,"stage":222,"year":223,"channels":224,"languages":225,"metrics":228,"outcomeDisclosed":215,"sources":229,"verification":242,"grade":244,"id":245,"organizationSlug":246},"bunq: data analysis and machine learning in place of customer self reporting in due diligence",[208],{"name":214,"anonymized":215,"country":216,"region":217,"industry":17},"bunq",false,"NL","europe",[219],{"name":214,"role":220},"in-house","As described in a 2022 ruling, Dutch neobank bunq assigned new private customers a \"regular user profile\" derived from data analysis of its customer base, instead of asking each customer about the purpose of the account, and then monitored transaction behaviour to adjust that profile and raise the customer's risk scores when needed. bunq says it favours technology such as machine learning; the ruling mentions a machine learning model in transaction monitoring but does not show that machine learning produces the rating itself. In October 2022 the Dutch Trade and Industry Appeals Tribunal (CBb) ruled largely in bunq's favour in its dispute with De Nederlandsche Bank over this approach. In May 2025 De Nederlandsche Bank fined bunq EUR 2.6 million because it had not sufficiently followed up signals in four customer files it had itself identified as high risk; bunq has appealed, and the notice does not attribute the shortcomings to the data driven approach.","production",2022,[27],[226,227],"en","nl",[],[230,234,238],{"url":231,"title":232,"publisher":214,"date":233},"https://press.bunq.com/219361-bunq-wins-appeal-against-dutch-central-bank-dnb/","bunq wins appeal against Dutch Central Bank (DNB)","2022-10-18",{"url":235,"title":236,"publisher":237,"date":233},"https://uitspraken.rechtspraak.nl/details?id=ECLI:NL:CBB:2022:707","ECLI:NL:CBB:2022:707, College van Beroep voor het bedrijfsleven, 18-10-2022, 21/323 en 21/1108","College van Beroep voor het bedrijfsleven",{"url":181,"title":239,"publisher":240,"date":241},"Fine for bunq B.V. for insufficient customer due diligence","De Nederlandsche Bank","2025-08-25",{"level":243,"checkedAt":204},"source-verified","B","bunq-machine-learning-customer-due-diligence",null,0,[],{"low":250,"high":251},120000,1312500,[253,282,305,326,345],{"slug":199,"title":254,"shortTitle":255,"definition":256,"status":9,"industries":257,"functions":258,"patterns":260,"audience":29,"autonomy":30,"adoptionStage":265,"segment":32,"evidenceCount":62,"publicEvidenceCount":62,"organizations":266,"bestGrade":244,"headline":272,"lastVerified":280,"indexable":281},"AI for perpetual KYC and event driven customer due diligence","Perpetual KYC","AI that keeps each customer's due diligence file current by replacing calendar driven KYC reviews with continuous, event driven refreshes: it watches for trigger events such as a change of ownership, address, behaviour or a new adverse finding, refreshes the file automatically where it can, and involves an analyst only when something material has changed. The risk rating itself and the first file for a new business client are separate use cases.",[17,18,19],[259,21],"onboarding-and-kyc",[261,262,263,264],"agentic-workflow","document-processing","rag-knowledge-assistant","summarization","emerging",[267,268,269,270,271],"Deutsche Bank","First National Bank of Omaha (FNBO)","JPMorgan Chase","OCBC","Origin Bank",{"kpi":273,"label":274,"unit":275,"n":276,"nUpTo":247,"kind":277,"value":75,"qualifier":278,"claimant":279,"organization":269,"vendorReported":215},"cost-reduction","Cost reduction","percent",1,"reported","exact","organization","2026-09-26",true,{"slug":200,"title":283,"shortTitle":284,"definition":285,"status":9,"industries":286,"functions":287,"patterns":288,"audience":289,"autonomy":30,"adoptionStage":31,"segment":32,"evidenceCount":290,"publicEvidenceCount":290,"organizations":291,"bestGrade":244,"headline":300,"lastVerified":204,"indexable":281},"AI for AML transaction monitoring alert triage","AML alert triage","Machine learning and AI agents that score anti money laundering alerts for genuine risk, close clear false positives with a written and stored rationale, and hand investigators the remaining alerts already enriched with the customer, counterparty and transaction context.",[17,18],[21],[24,25,261,264],"employee-facing",8,[292,293,294,295,296,297,298,299],"Australia Post","BMO and Amalgamated Bank","HSBC","Nexo","Ratepay","Shift4","United Overseas Bank (UOB)","Uphold",{"kpi":301,"label":302,"unit":275,"n":61,"nUpTo":247,"kind":277,"value":303,"qualifier":278,"claimant":304,"organization":297,"vendorReported":281},"false-positive-reduction","False positive reduction",86,"vendor",{"slug":201,"title":306,"shortTitle":307,"definition":308,"status":9,"industries":309,"functions":310,"patterns":311,"audience":289,"autonomy":314,"adoptionStage":31,"segment":32,"evidenceCount":315,"publicEvidenceCount":315,"organizations":316,"bestGrade":244,"headline":321,"lastVerified":204,"indexable":281},"AI for PEP and adverse media screening","PEP and adverse media screening","AI that continuously scans news, court records, registries and other open sources in many languages for negative information and political exposure linked to customers, counterparties and beneficial owners, discards look alikes, and summarises credible risk for the analyst with the sources attached.",[17,18,19],[21,259],[263,264,312,313],"classification-and-routing","translation","copilot",7,[267,294,317,270,318,319,320],"Mashreq","Santander UK","Save the Children","Scotiabank",{"kpi":322,"label":323,"unit":275,"n":276,"nUpTo":276,"kind":277,"value":324,"qualifier":325,"claimant":304,"organization":319,"vendorReported":281},"handling-time-reduction","Handling time reduction",60,"at-least",{"slug":202,"title":327,"shortTitle":328,"definition":329,"status":9,"industries":330,"functions":332,"patterns":333,"audience":29,"autonomy":30,"adoptionStage":265,"segment":334,"evidenceCount":335,"publicEvidenceCount":335,"organizations":336,"bestGrade":340,"headline":341,"lastVerified":204,"indexable":281},"AI for business onboarding (KYB) and beneficial ownership discovery","Business onboarding and UBO","An AI agent that builds the know your business (KYB) due diligence file for a new or reviewed corporate client, before any account is opened: it collects registry, incorporation and ownership documents, resolves the entity across sources, maps the ownership chain through holding companies, nominees and trusts to the ultimate beneficial owners, screens the entity and its owners, and presents a risk scored case for a compliance analyst to decide.",[17,18,331],"capital-markets",[259,21],[262,261,312,264],"specialized-businesses",3,[337,338,339],"BNY","Incore Bank","M-DAQ Global","C",{"kpi":342,"label":343,"unit":275,"n":276,"nUpTo":247,"kind":277,"value":344,"qualifier":278,"claimant":279,"organization":337,"vendorReported":215},"automation-rate","Automation rate",25,{"slug":203,"title":346,"shortTitle":347,"definition":348,"status":9,"industries":349,"functions":350,"patterns":351,"audience":289,"autonomy":314,"adoptionStage":31,"segment":353,"evidenceCount":335,"publicEvidenceCount":335,"organizations":354,"bestGrade":244,"headline":246,"lastVerified":280,"indexable":281},"AI agent for source of wealth due diligence in private banking","Source of wealth diligence","An AI agent that reads a prospective private client's documents, extracts and corroborates how their wealth was built, checks plausibility against benchmarks and external sources, and drafts the source of wealth and enhanced due diligence narrative for the relationship manager and compliance analyst, who decide on the risk rating and the relationship.",[19,17],[259,21],[262,261,352,264],"content-generation","front-office",[355,267],"Bank of Singapore",{"indexable":281,"reasons":357},[],[359,365,370,376,383,389,396,403,408,414,421,426,433,439,444,449,455,461,467,473,479,485,489,494,499,506,512,517,523,529,536,542,548,553],{"id":143,"label":360,"issuer":361,"region":217,"url":362,"description":363,"useCases":364,"indexable":281},"EU AI Act","European Union","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":144,"label":366,"issuer":361,"region":217,"url":367,"description":368,"useCases":369,"indexable":281},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":150,"label":371,"issuer":372,"region":164,"url":373,"description":374,"useCases":375,"indexable":281},"ISO/IEC 42001","ISO and IEC","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":149,"label":377,"issuer":378,"region":379,"url":380,"description":381,"useCases":382,"indexable":281},"NIST AI Risk Management Framework","NIST","north-america","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":384,"label":385,"issuer":361,"region":217,"url":386,"description":387,"useCases":388,"indexable":281},"dora","DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":390,"label":391,"issuer":392,"region":217,"url":393,"description":394,"useCases":395,"indexable":281},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":397,"label":398,"issuer":399,"region":217,"url":400,"description":401,"useCases":402,"indexable":281},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":147,"label":404,"issuer":169,"region":158,"url":405,"description":406,"useCases":407,"indexable":281},"MAS AI risk management guidelines","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":409,"label":410,"issuer":411,"region":158,"url":412,"description":413,"useCases":344,"indexable":281},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",{"id":415,"label":416,"issuer":417,"region":164,"url":418,"description":419,"useCases":420,"indexable":281},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",20,{"id":146,"label":422,"issuer":423,"region":379,"url":424,"description":425,"useCases":420,"indexable":281},"SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":427,"label":428,"issuer":429,"region":217,"url":430,"description":431,"useCases":432,"indexable":281},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":145,"label":434,"issuer":435,"region":164,"url":436,"description":437,"useCases":438,"indexable":281},"FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":151,"label":440,"issuer":361,"region":217,"url":441,"description":442,"useCases":443,"indexable":281},"EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":445,"label":446,"issuer":361,"region":217,"url":447,"description":448,"useCases":443,"indexable":281},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":152,"label":450,"issuer":451,"region":379,"url":452,"description":453,"useCases":454,"indexable":281},"Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":456,"label":457,"issuer":361,"region":217,"url":458,"description":459,"useCases":460,"indexable":281},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":462,"label":463,"issuer":464,"region":379,"url":465,"description":466,"useCases":460,"indexable":281},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":468,"label":469,"issuer":470,"region":164,"url":471,"description":472,"useCases":460,"indexable":281},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":474,"label":475,"issuer":361,"region":217,"url":476,"description":477,"useCases":478,"indexable":281},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":480,"label":481,"issuer":482,"region":379,"url":483,"description":484,"useCases":478,"indexable":281},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":153,"label":486,"issuer":169,"region":158,"url":170,"description":487,"useCases":488,"indexable":281},"MAS Notice 626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",10,{"id":490,"label":491,"issuer":361,"region":217,"url":492,"description":493,"useCases":488,"indexable":281},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":495,"label":496,"issuer":361,"region":217,"url":497,"description":498,"useCases":488,"indexable":281},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":500,"label":501,"issuer":502,"region":217,"url":503,"description":504,"useCases":505,"indexable":281},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":507,"label":508,"issuer":509,"region":379,"url":510,"description":511,"useCases":290,"indexable":281},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",{"id":513,"label":514,"issuer":361,"region":217,"url":515,"description":516,"useCases":290,"indexable":281},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":518,"label":519,"issuer":361,"region":217,"url":520,"description":521,"useCases":522,"indexable":281},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",6,{"id":148,"label":524,"issuer":525,"region":526,"url":527,"description":528,"useCases":62,"indexable":281},"CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":530,"label":531,"issuer":532,"region":217,"url":533,"description":534,"useCases":535,"indexable":281},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",4,{"id":537,"label":538,"issuer":539,"region":217,"url":540,"description":541,"useCases":535,"indexable":281},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":543,"label":544,"issuer":545,"region":158,"url":546,"description":547,"useCases":335,"indexable":281},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":549,"label":550,"issuer":361,"region":217,"url":551,"description":552,"useCases":335,"indexable":281},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":554,"label":555,"issuer":556,"region":379,"url":557,"description":558,"useCases":335,"indexable":281},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598307212]