[{"data":1,"prerenderedAt":537},["ShallowReactive",2],{"uc-exam-and-assessment-integrity":3,"uc-regulations":310},{"useCase":4,"evidence":178,"blitsAiDeployments":230,"benchmarks":231,"indicative":232,"related":235,"indexability":308,"includeUnpublished":184},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":17,"functions":19,"patterns":22,"channels":26,"audience":28,"autonomy":29,"adoptionStage":30,"problem":31,"problemStats":32,"howItWorks":33,"valueDrivers":34,"kpis":38,"indicativeValue":42,"macroEstimates":70,"feasibility":71,"implementation":84,"risk":125,"blitsAi":156,"faq":158,"related":171,"datePublished":173,"dateModified":173,"lastVerified":173,"changelog":174,"slug":177},"AI assisted proctoring and integrity monitoring for remote exams","Exam and assessment integrity","AI proctoring for remote exam integrity","Duolingo and ETS both pair AI behaviour analysis with human review for remote exams. See how AI proctoring works and why detectors alone are not trusted.","published","AI that supports the integrity of a remote, high stakes exam by verifying a test taker's identity, analysing behaviour such as typing patterns, facial matching and session activity for signs of impersonation or unauthorized help, and flagging sessions for a trained human reviewer to decide, rather than letting a model issue an automated finding of misconduct on its own.",[12,13,14,15,16],"AI exam proctoring","remote proctoring AI","automated cheating detection","AI test security","academic integrity monitoring",[18],"education",[20,21],"operations","security-operations",[23,24,25],"anomaly-detection","computer-vision","classification-and-routing",[27],"internal-tools","back-office","supervised-agent","mainstream","High stakes tests, from language proficiency exams to graduate admission tests and teacher\nlicensing exams, such as the GRE, TOEFL and Praxis, increasingly happen at home rather than in a\nsupervised test centre, a shift ETS says the Covid 19 pandemic forced within weeks. Remote testing\nremoves the travel and scheduling burden of a test centre, but it also removes the one thing a\nphysical test centre offered by default: a proctor who can see the whole room.\n\nA single human proctor watching a live video feed cannot reliably catch a hidden phone, a second\nscreen, a coached answer or a subtle handoff, and cannot review what happened after the fact\nunless the session was recorded. At the same time, evidence has piled up that automated cheating\ndetection is not reliable enough to stand alone: several institutions, including Yale, Vanderbilt\nand Johns Hopkins Universities, disabled Turnitin's AI writing detection feature, citing concerns\nabout false positives. The honest state of the art pairs AI generated signals with a trained human\ndecision, and treats an AI flag as a lead to investigate, not a verdict.",[],"1. **Verify identity before the exam starts.** Government ID checks, facial matching and, on some\n   exams, voice biometrics confirm the person taking the test is who they registered as, and\n   repeat through the session to catch a substitution.\n2. **Analyse behaviour throughout the session.** AI systems track keystroke and typing rhythm, keep\n   the same person confirmed in the seat and watch for a second person entering the room, and\n   monitor application or browser activity for patterns associated with outside help or content\n   that was memorized or copied rather than produced live.\n3. **Look across sessions, not just one.** Some systems, such as the Duolingo English Test, analyse\n   patterns across thousands of test sessions at once, for example near identical answers from test\n   takers in the same region, which a single proctor watching one session could never see.\n4. **Flag, do not decide.** The AI signals are handed to a trained human reviewer as a diagnosis to\n   investigate, with the full session recording available to pause, rewind and examine in context,\n   rather than triggering an automatic finding of misconduct.\n5. **Record for later review.** The full session is recorded, so a flagged case, a dispute or an\n   audit can be reviewed after the fact, which a live only human proctor in a test centre cannot\n   offer.",[35,36,37],"risk-reduction","compliance","inclusion-and-access",[39,40,41],"detection-rate-improvement","accuracy","users-served",{"referenceOrg":43,"inputs":44,"formula":65,"currency":66,"period":67,"resultLabel":68,"caveat":69},"A testing organization administering 500,000 remote exam sessions a year",[45,51,58],{"key":46,"label":47,"low":48,"high":48,"unit":49,"note":50},"sessions","Remote exam sessions per year",500000,"sessions per year","The reference organization.",{"key":52,"label":53,"low":54,"high":55,"unit":56,"note":57},"costPerHumanOnlyProctor","Cost of a fully live, one proctor per session model",8,20,"USD per session","Editorial assumption for a live, one to one remote human proctor; replace with your own proctoring contract rates.",{"key":59,"label":60,"low":61,"high":62,"unit":63,"note":64},"costReductionShare","Share of proctoring cost avoided by asynchronous, AI assisted review instead of live one to one proctoring",0.2,0.4,"fraction of cost","Editorial assumption. No source in this page's evidence discloses a cost figure; ETS and Duolingo describe the security approach, not its cost, so this range is a hypothesis to test against your own proctoring contract, not a benchmark.","sessions * costPerHumanOnlyProctor * costReductionShare","USD","per year","Proctoring cost avoided versus one to one live human proctoring","Entirely a modelled hypothesis with no disclosed cost benchmark behind it. It leaves out the cost of the AI systems themselves, the reviewer time still needed for every flagged session, and the cost of a false accusation or a missed cheating case, which for a high stakes exam can be far larger than the proctoring cost itself.",[],{"complexity":72,"complexityNote":73,"dataPrerequisites":74,"integrations":79},"high","Identity verification and basic recording are straightforward to buy from a proctoring vendor. The hard part is everything the flag touches afterward: a human review process trained and calibrated so it does not simply rubber stamp or blindly reject AI signals, a defensible appeals process, and a bias and accessibility review of biometric checks, since accuracy is not guaranteed to be even across skin tones or for test takers with some disabilities and should be tested on your own population rather than assumed.",[75,76,77,78],"A defined set of behaviours that count as a security signal, agreed with academic or legal stakeholders","Recorded video, audio and process data for every session, held under a clear retention policy","A calibration set of known good and known problematic sessions to test human reviewer judgment","Documented accommodations for test takers who cannot meet standard camera, room or biometric requirements",[80,81,82,83],"Identity verification and biometric matching provider","Secure testing application or lockdown browser","Session recording and case management for flagged reviews","Test delivery platform and score reporting system",{"steps":85,"guardrails":101,"humanInTheLoop":106,"kpisToInstrument":107,"failureModes":112},[86,89,92,95,98],{"title":87,"detail":88},"Decide what a flag means before you launch","Write down, before go live, exactly what a flagged session leads to: a human review, a request for clarification, a retest, or a finding, and who can override the AI's signal at each step.",{"title":90,"detail":91},"Calibrate human reviewers against automation bias","A reviewer can lean on an AI flag instead of independently checking the recording. Require guidance that asks for independent evidence in the recording, not the AI signal alone, and test reviewers against known false signals before launch and periodically after. Do not assume a human in the loop fixes accuracy on its own.",{"title":93,"detail":94},"Keep the full recording, not just the flag","A flag without the underlying video or process data cannot be investigated or defended in a dispute. Store the full session so a reviewer, and if needed an appeals panel, can see the context.",{"title":96,"detail":97},"Separate detection from adjudication","The team or system that raises a flag should not be the same one that issues a finding of misconduct against a student, mirroring how a fraud alert and a fraud decision are usually kept apart in other industries.",{"title":99,"detail":100},"Publish the appeal path and use it","Test takers need a real, timely way to contest a flag or a finding, with a person who was not involved in the original flag reviewing it.",[102,103,104,105],"No automated finding of misconduct without a trained human reviewer examining the recording","A documented, tested appeal path, reviewed by someone not involved in the original flag","Accommodations for test takers who cannot meet standard camera, room or biometric requirements","Retention and access limits on biometric data, video and process data of identifiable people","A trained human reviewer examines every flagged session before a finding of misconduct is recorded, and can pause, rewind and review the recording rather than relying on a real time glance alone. ETS describes a live proctor watching every session in real time, with the ability to cancel a session immediately if there is a clear attempt to cheat, pending review, while Duolingo describes a trained proctor reviewing every session's recording anonymously and asynchronously afterward. Both treat AI as an aid to that person's judgment, not a replacement for it.",[108,109,110,111],"False positive and false negative rate of the AI signal against reviewer decisions, on a calibration set","Reviewer agreement rate and how often reviewers accept an AI signal without independent evidence","Time from flag to human decision","Appeals received, upheld and their outcomes",[113,116,119,122],{"title":114,"detail":115},"Automation bias in the human reviewer","A reviewer trusts the AI's flag instead of independently checking the recording, accepting it more often than an accurate signal alone would justify. Test and monitor reviewer behaviour against known false signals, not only model accuracy.",{"title":117,"detail":118},"Detection tool disabled after real world false positives","Several universities, including Yale, Vanderbilt and Johns Hopkins, turned off Turnitin's AI writing detector after it produced false positives that undermined confidence in it; a tool that is not trusted stops being used. Validate detection accuracy on your own population before relying on it for a consequence.",{"title":120,"detail":121},"Biometric and behavioural checks that fail some test takers more than others","Facial matching and behavioural analysis are not guaranteed to perform evenly across skin tones, ages or for test takers with certain disabilities, which can produce more false flags for those groups if left untested. Test accuracy across demographic groups on your own population and provide a fallback for accommodations.",{"title":123,"detail":124},"A false accusation that is never corrected","An incorrect finding of misconduct can end a student's exam, admission or licensure prospects. A slow or absent appeal path turns a detection error into a life changing one. Time bound the appeal process and staff it independently of the original decision.",{"euAiAct":126,"regulations":128,"guidance":132,"controls":145,"incidents":151},{"tier":72,"basis":127},"Annex III point 3(d) lists AI systems intended to be used for monitoring and detecting prohibited behaviour of students during tests in the context of education and training institutions as high risk. One to one biometric identity verification, confirming a test taker is who they claim to be, falls outside the biometric identification use covered by Annex III point 1(a). The Article 5 restriction that does apply is different: Article 5(1)(f) prohibits AI systems that infer emotions in an education institution, so the behavioural analysis in this use case must stay limited to security signals such as identity and typing patterns, and must not be built or read as emotion inference.",[129,130,131],"eu-ai-act","gdpr","uk-gdpr",[133,139],{"title":134,"issuer":135,"region":136,"url":137,"note":138},"Annex III, high risk AI systems (point 3, education and vocational training)","European Union","europe","https://artificialintelligenceact.eu/annex/3/","Lists monitoring and detecting prohibited student behaviour during tests as a high risk education use.",{"title":140,"issuer":141,"region":142,"url":143,"note":144},"Protecting Student Privacy","US Department of Education, Student Privacy Policy Office","north-america","https://studentprivacy.ed.gov/","Guidance on FERPA, relevant to video, audio and biometric data collected during a proctored exam.",[146,147,148,149,150],"Human review of the full session recording before any finding of misconduct","A timed, independently staffed appeal process","Documented accommodations for camera, room and biometric requirements","Retention limits and access controls on video, audio and biometric data","Accuracy testing of identity and behaviour signals across demographic groups",[152],{"title":153,"url":154,"note":155},"Universities disable Turnitin's AI writing detector over false positives","https://web.archive.org/web/2026/https://www.chronicle.com/article/to-catch-ai-cheating-turnitin-wants-to-monitor-students-keystrokes","Several institutions, including Yale, Vanderbilt and Johns Hopkins Universities, have disabled Turnitin's AI detection feature, citing concerns about false positives, The Chronicle of Higher Education reported. The live article returns an HTTP 403 for automated access; this is the Wayback Machine copy, checked 2026-09-29.",{"howToBuild":157},"Blits.ai is not a proctoring vendor: it has no biometric identity verification, gaze tracking or\nkeystroke forensics of its own, and building this use case means treating those signals as an\nexternal system's output, never generating a finding of misconduct with a language model.\nWhat Blits.ai can build well is the case management and communication layer around a proctoring\nvendor's signals. A **custom function** receives a flagged session's summary and evidence links\nfrom the proctoring provider's API, and an **agentic workflow** opens a review case, assigns it\nto a trained reviewer queue and tracks its status end to end in the **run history**, with\n**human in the loop confirmation** required before any finding is recorded.\n\nA **RAG knowledge assistant**, grounded in the institution's own testing policy and\naccommodations rules, can answer test takers' questions before and after the exam about identity\nverification, room setup and the appeal process, on **web chat**, **email** or **WhatsApp**, and\n**human handover** routes an actual dispute to a person immediately. **Guardrails** keep the\nknowledge assistant from speculating about a specific flagged case, **PII masking** protects\nidentity documents and biometric references in logs, and a scheduled **monitor** runs recurring\nchecks that the knowledge assistant keeps answering test takers' questions correctly, alerting a\ncompliance owner by email or webhook if it starts failing.",[159,162,165,168],{"question":160,"answer":161},"Can AI alone determine that a student cheated?","In the systems in this page's evidence, no. Duolingo and ETS both describe a trained human proctor reviewing every session, with AI as an aid to detect signals a person watching in real time would miss, not as the decision maker. Duolingo says in a blog post that decisions \"aren't automated.\"",{"question":163,"answer":164},"Why are universities turning off AI cheating detectors?","Because the accuracy has not matched the stakes. Several institutions, including Yale, Vanderbilt and Johns Hopkins, disabled Turnitin's AI writing detection tool after it produced false positives. This is different from remote proctoring's identity and behaviour signals, which are reviewed by a human before a finding is recorded, but the lesson, validate before you rely on it, applies to both.",{"question":166,"answer":167},"How does remote AI proctoring compare with a human proctor in a test centre?","ETS says it built its first remote proctored option, with ProctorU, in six weeks in 2020, and has since run it for hundreds of thousands of test takers on the GRE, TOEFL iBT, HiSET and Praxis exams, layering identity checks, environmental scanning and process data analysis on top of live human proctoring. Duolingo argues this catches some cheating methods, such as collusion patterns across thousands of sessions, that a single test centre proctor never could.",{"question":169,"answer":170},"Is exam proctoring AI regulated?","Under the EU AI Act, Annex III point 3(d) lists AI used to monitor and detect prohibited student behaviour during tests as high risk, which brings obligations for risk management, human oversight, logging and conformity assessment. Facial recognition used for identity checks can raise separate biometric data questions under GDPR and similar laws.",[172],"automated-scoring-of-written-responses","2026-09-29",[175],{"date":173,"note":176},"First published","exam-and-assessment-integrity",[179,208],{"title":180,"useCases":181,"organization":182,"vendors":186,"summary":187,"stage":188,"year":189,"channels":190,"languages":191,"metrics":193,"outcomeDisclosed":194,"sources":195,"verification":203,"grade":205,"id":206,"organizationSlug":207},"Duolingo English Test: AI assisted proctoring and cheating detection",[177],{"name":183,"anonymized":184,"country":185,"region":142,"industry":18},"Duolingo",false,"US",[],"The Duolingo English Test, a remote, at home English proficiency test, secures every session with a proprietary lockdown testing application, layered identity verification (government ID, facial matching, device fingerprinting), and AI assisted behaviour analysis, including keystroke and typing rhythm monitoring and cross session pattern detection. Duolingo states that AI flags suspicious sessions for review but that \"decisions aren't automated\": a trained human proctor individually reviews every test session, with the ability to pause, speed up or slow down the recording, before any action follows.","production",2026,[27],[192],"en",[],true,[196,200],{"url":197,"title":198,"publisher":199},"https://blog.englishtest.duolingo.com/why-cant-test-centers-catch-cheating-effectively","Why can't test centers catch cheating effectively?","Duolingo English Test",{"url":201,"title":202,"publisher":199},"https://blog.englishtest.duolingo.com/remote-english-test-security-ai-fairness/","Remote English test security and AI fairness",{"level":204,"checkedAt":173},"source-verified","B","duolingo-english-test-ai-proctoring",null,{"title":209,"useCases":210,"organization":211,"vendors":213,"summary":217,"stage":188,"year":218,"channels":219,"languages":220,"metrics":221,"outcomeDisclosed":194,"sources":222,"verification":228,"grade":205,"id":229,"organizationSlug":207},"ETS: AI assisted remote proctoring for GRE, TOEFL, HiSET and Praxis",[177],{"name":212,"anonymized":184,"country":185,"region":142,"industry":18},"Educational Testing Service (ETS)",[214],{"name":215,"role":216},"ProctorU","platform","ETS built a remote proctored testing option for the GRE General Test and TOEFL iBT test in six weeks in 2020, in collaboration with ProctorU, later extending it to the HiSET exam and Praxis tests. The at home option layers identity verification (ID matching and, for TOEFL, voice biometrics), a live remote proctor who conducts a 360 degree room scan and monitors the session, and artificial intelligence that continuously scans for irregularities such as a second person entering the room, working alongside process data analysis by ETS's research and psychometrics team to detect suspicious patterns over time.",2020,[27],[192],[],[223],{"url":224,"title":225,"publisher":226,"date":227},"https://www.ets.org/news/stories/can-i-trust-an-at-home-test.html","Can I Trust an At-Home Test?","ETS","2020-08-24",{"level":204,"checkedAt":173},"ets-remote-exam-ai-security",0,[],{"low":233,"high":234},800000,4000000,[236,250,268,292],{"slug":172,"title":237,"shortTitle":238,"definition":239,"status":9,"industries":240,"functions":242,"patterns":243,"audience":28,"autonomy":29,"adoptionStage":30,"evidenceCount":245,"publicEvidenceCount":245,"organizations":246,"bestGrade":205,"headline":207,"lastVerified":249,"indexable":194},"AI scoring of essays and written answers in assessments","Essay and written answer scoring","AI that scores students' essays and short written answers against a rubric, trained on responses scored by human raters, with human raters rescoring a sample of responses and every response the engine is unsure about. In hybrid programmes such as Texas, a human score is the score of record whenever a human scores a response.",[18,241],"government",[20],[25,244],"prediction-and-scoring",3,[226,247,248],"Massachusetts Department of Elementary and Secondary Education","Texas Education Agency","2026-09-27",{"slug":251,"title":252,"shortTitle":253,"definition":254,"status":9,"industries":255,"functions":258,"patterns":259,"audience":260,"autonomy":261,"adoptionStage":262,"evidenceCount":245,"publicEvidenceCount":245,"organizations":263,"bestGrade":267,"headline":207,"lastVerified":173,"indexable":194},"physical-security-video-analytics","AI video analytics and screening for physical security","Physical security video analytics","AI that watches camera feeds or walk through sensors at a site, flags a likely weapon, intrusion or theft in real time or on search, and leaves the verification and every response action to a human guard or investigator, rather than acting on its own.",[256,18,257],"retail-and-ecommerce","cross-industry",[21],[24,23,25],"employee-facing","assist","early-adopters",[264,265,266],"Charlotte-Mecklenburg Schools","Harry Rosen","Utica City School District","C",{"slug":269,"title":270,"shortTitle":271,"definition":272,"status":9,"industries":273,"functions":275,"patterns":276,"audience":260,"autonomy":261,"adoptionStage":30,"segment":277,"evidenceCount":278,"publicEvidenceCount":278,"organizations":279,"bestGrade":205,"headline":282,"lastVerified":291,"indexable":194},"radiology-worklist-triage","AI prioritization of radiology and imaging worklists","Radiology worklist triage","An AI system that analyzes a medical image immediately after a scan, flags time sensitive findings such as a brain bleed, a stroke causing large vessel occlusion or a pulmonary embolism, and reorders the radiologist's worklist and notifies the care team so the most urgent cases are read and acted on first, while a radiologist confirms every finding before it changes a patient's treatment.",[274],"healthcare",[20],[24,25,23],"emergency and inpatient imaging",2,[280,281],"Adventist Health + Rideout","Sheba Medical Center",{"kpi":283,"label":284,"unit":285,"n":286,"nUpTo":230,"kind":287,"value":288,"qualifier":289,"claimant":290,"organization":280,"vendorReported":194},"processing-time-reduction","Cycle time reduction","percent",1,"reported",44,"approximately","vendor","2026-09-28",{"slug":293,"title":294,"shortTitle":295,"definition":296,"status":9,"industries":297,"functions":298,"patterns":300,"audience":303,"autonomy":29,"adoptionStage":262,"evidenceCount":245,"publicEvidenceCount":245,"organizations":304,"bestGrade":205,"headline":207,"lastVerified":249,"indexable":194},"student-enrollment-and-services-assistant","AI assistant for student enrollment and student services","Student enrollment assistant","An AI assistant that answers admitted and current students' questions about admissions, financial aid, registration, housing and deadlines by text message and web chat, sends timely reminders for the tasks each student still has to complete, and hands personal or complex cases to staff.",[18],[299,20],"customer-service",[301,302,25],"conversational-agent","rag-knowledge-assistant","customer-facing",[305,306,307],"Adelphi University","Austin Peay State University","Georgia State University",{"indexable":194,"reasons":309},[],[311,316,321,329,336,342,348,355,363,370,377,384,390,396,403,410,416,423,429,435,441,448,453,460,465,470,475,481,488,494,502,509,515,521,526,531],{"id":129,"label":312,"issuer":135,"region":136,"url":313,"description":314,"useCases":315,"indexable":194},"EU AI Act","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",230,{"id":130,"label":317,"issuer":135,"region":136,"url":318,"description":319,"useCases":320,"indexable":194},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",207,{"id":322,"label":323,"issuer":324,"region":325,"url":326,"description":327,"useCases":328,"indexable":194},"iso-42001","ISO/IEC 42001","ISO and IEC","global","https://www.iso.org/standard/81230.html","The international management system standard for AI.",122,{"id":330,"label":331,"issuer":332,"region":142,"url":333,"description":334,"useCases":335,"indexable":194},"nist-ai-rmf","NIST AI Risk Management Framework","NIST","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",92,{"id":131,"label":337,"issuer":338,"region":136,"url":339,"description":340,"useCases":341,"indexable":194},"UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",71,{"id":343,"label":344,"issuer":135,"region":136,"url":345,"description":346,"useCases":347,"indexable":194},"dora","DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":349,"label":350,"issuer":351,"region":136,"url":352,"description":353,"useCases":354,"indexable":194},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",50,{"id":356,"label":357,"issuer":358,"region":359,"url":360,"description":361,"useCases":362,"indexable":194},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",37,{"id":364,"label":365,"issuer":366,"region":359,"url":367,"description":368,"useCases":369,"indexable":194},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":371,"label":372,"issuer":373,"region":142,"url":374,"description":375,"useCases":376,"indexable":194},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",22,{"id":378,"label":379,"issuer":380,"region":325,"url":381,"description":382,"useCases":383,"indexable":194},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",21,{"id":385,"label":386,"issuer":135,"region":136,"url":387,"description":388,"useCases":389,"indexable":194},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",17,{"id":391,"label":392,"issuer":393,"region":136,"url":394,"description":395,"useCases":389,"indexable":194},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",{"id":397,"label":398,"issuer":399,"region":142,"url":400,"description":401,"useCases":402,"indexable":194},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",16,{"id":404,"label":405,"issuer":406,"region":325,"url":407,"description":408,"useCases":409,"indexable":194},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":411,"label":412,"issuer":135,"region":136,"url":413,"description":414,"useCases":415,"indexable":194},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":417,"label":418,"issuer":419,"region":142,"url":420,"description":421,"useCases":422,"indexable":194},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":424,"label":425,"issuer":426,"region":142,"url":427,"description":428,"useCases":422,"indexable":194},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":430,"label":431,"issuer":135,"region":136,"url":432,"description":433,"useCases":434,"indexable":194},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":436,"label":437,"issuer":438,"region":325,"url":439,"description":440,"useCases":434,"indexable":194},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":442,"label":443,"issuer":444,"region":142,"url":445,"description":446,"useCases":447,"indexable":194},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",11,{"id":449,"label":450,"issuer":135,"region":136,"url":451,"description":452,"useCases":447,"indexable":194},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",{"id":454,"label":455,"issuer":456,"region":136,"url":457,"description":458,"useCases":459,"indexable":194},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",10,{"id":461,"label":462,"issuer":358,"region":359,"url":463,"description":464,"useCases":459,"indexable":194},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",{"id":466,"label":467,"issuer":135,"region":136,"url":468,"description":469,"useCases":459,"indexable":194},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":471,"label":472,"issuer":135,"region":136,"url":473,"description":474,"useCases":459,"indexable":194},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":476,"label":477,"issuer":135,"region":136,"url":478,"description":479,"useCases":480,"indexable":194},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",9,{"id":482,"label":483,"issuer":484,"region":142,"url":485,"description":486,"useCases":487,"indexable":194},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",7,{"id":489,"label":490,"issuer":135,"region":136,"url":491,"description":492,"useCases":493,"indexable":194},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",6,{"id":495,"label":496,"issuer":497,"region":498,"url":499,"description":500,"useCases":501,"indexable":194},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",5,{"id":503,"label":504,"issuer":505,"region":136,"url":506,"description":507,"useCases":508,"indexable":194},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",4,{"id":510,"label":511,"issuer":512,"region":136,"url":513,"description":514,"useCases":508,"indexable":194},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":516,"label":517,"issuer":518,"region":359,"url":519,"description":520,"useCases":245,"indexable":194},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":522,"label":523,"issuer":135,"region":136,"url":524,"description":525,"useCases":245,"indexable":194},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":527,"label":528,"issuer":135,"region":136,"url":529,"description":530,"useCases":245,"indexable":194},"eu-mortgage-credit-directive","EU Mortgage Credit Directive","https://eur-lex.europa.eu/eli/dir/2014/17/oj","Directive 2014/17/EU: creditworthiness assessment, disclosure and advice rules for residential mortgage lending.",{"id":532,"label":533,"issuer":534,"region":142,"url":535,"description":536,"useCases":245,"indexable":194},"nyc-local-law-144","NYC Local Law 144","New York City","https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page","Bias audits and notices for automated employment decision tools used in hiring and promotion in New York City.",1790683489000]