[{"data":1,"prerenderedAt":609},["ShallowReactive",2],{"uc-governed-text-to-sql-analytics":3,"uc-regulations":400},{"useCase":4,"evidence":203,"blitsAiDeployments":282,"benchmarks":283,"indicative":290,"related":293,"indexability":398,"includeUnpublished":209},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":17,"functions":24,"patterns":27,"channels":31,"audience":34,"autonomy":35,"adoptionStage":36,"problem":37,"problemStats":38,"howItWorks":44,"valueDrivers":45,"kpis":49,"indicativeValue":55,"macroEstimates":91,"feasibility":92,"implementation":105,"risk":152,"blitsAi":180,"faq":182,"related":192,"datePublished":198,"dateModified":198,"lastVerified":198,"changelog":199,"slug":202},"Governed text to SQL analytics assistant","Governed SQL analytics","Text to SQL assistant for governed data analytics","Governed text to SQL lets staff query data in plain language under their own permissions. See how LinkedIn and Uber built it, with accuracy data and controls.","published","An assistant that turns a business user's plain language question into a query against governed data, runs it under that user's own data permissions and returns the table or chart together with the SQL and the tables used, so routine ad hoc questions no longer queue for the data team.",[12,13,14,15,16],"text to SQL","natural language to SQL","conversational BI","chat with your data","self service analytics copilot",[18,19,20,21,22,23],"cross-industry","banking","insurance","retail-and-ecommerce","technology","pharma-and-life-sciences",[25,26],"analytics-and-reporting","it-and-engineering",[28,29,30],"conversational-agent","code-generation","rag-knowledge-assistant",[32,33],"internal-tools","microsoft-teams","employee-facing","assist","early-adopters","Most data questions in a business are small and urgent: how many applications came in from this\nchannel last week, what is the arrears rate by region, which branches missed target. Dashboards\nanswer the questions someone anticipated; everything else becomes a ticket for an analyst who\nknows which of thousands of tables holds the answer and how to join them. The queue slows\ndecisions and consumes analysts on work that is repetitive rather than analytical.\n\nGeneric text to SQL is not the answer on its own. On a real warehouse it picks the wrong table,\nmisreads a column or applies the wrong business definition, and returns a confident, wrong number.\nIn a bank or insurer the second risk is access: a query tool must never let a user see rows or\ncolumns their role does not permit. The job is therefore governed text to SQL: a curated semantic\nlayer, the user's own permissions, and the SQL always visible.",[39],{"statement":40,"sourceTitle":41,"sourceUrl":42,"year":43},"Snowflake, citing a Forrester report, says anecdotal evidence shows a best case rate of 70% for generating accurate, executable code on simple single table queries and around 20% at worst for queries with multiple tables or complex joins.","Cortex Analyst: Paving the Way to Self-Service Analytics with AI","https://www.snowflake.com/en/blog/cortex-analyst-ai-self-service-analytics/",2024,"1. **Understand the question.** The assistant restates the question in business terms and asks\n   for what is missing (\"which period?\", \"gross or net?\") instead of guessing.\n2. **Find the right data.** It retrieves from a curated semantic layer: certified tables, metric\n   definitions, join paths and example queries for the business domain. Uber narrows the search\n   with domain \"workspaces\"; LinkedIn had domain experts certify and describe key tables, and\n   draws example queries from notebooks that users have certified.\n3. **Write the query.** A model generates SQL against those definitions only, and the query is\n   validated (syntax, allowed tables, row limits) before it runs.\n4. **Run it as the user.** The query executes with the user's own credentials, so row and column\n   level security in the data platform decides what comes back.\n5. **Show the work.** The answer comes with the SQL, the tables and the definitions used, plus a\n   short explanation, so the user or an analyst can check it.\n6. **Learn from corrections.** Queries that analysts correct or certify become new examples in\n   the semantic layer.",[46,47,48],"speed","employee-productivity","cost-to-serve",[50,51,52,53,54],"accuracy","users-served","time-saved-per-task","employee-adoption","productivity-gain",{"referenceOrg":56,"inputs":57,"formula":86,"currency":87,"period":88,"resultLabel":89,"caveat":90},"A bank with 1,500 regular data consumers and a central data and BI team",[58,65,72,79],{"key":59,"label":60,"low":61,"high":62,"unit":63,"note":64},"requests","Ad hoc data requests to the data team per year",6000,12000,"requests per year","Editorial assumption, about four to eight requests per data consumer per year. Replace with your own ticket volume.",{"key":66,"label":67,"low":68,"high":69,"unit":70,"note":71},"selfServeShare","Share of requests the assistant answers without an analyst",0.15,0.35,"fraction of requests","Editorial assumption, deliberately conservative because accuracy falls on complex multi table questions (see the Forrester figure cited on this page).",{"key":73,"label":74,"low":75,"high":76,"unit":77,"note":78},"analystHours","Analyst hours per ad hoc request",1.5,3,"hours per request","Editorial assumption including clarification, query writing and checking.",{"key":80,"label":81,"low":82,"high":83,"unit":84,"note":85},"hourlyCost","Fully loaded analyst hour",60,100,"USD per hour","Editorial assumption. Replace with your own rate.","requests * selfServeShare * analystHours * hourlyCost","USD","per year","Analyst time released from routine ad hoc requests","Analyst time only. It leaves out the value of faster decisions for the business users, the cost of building and maintaining the semantic layer, and the cost of any wrong answers that are not caught, which is why the self serve share is kept low.",[],{"complexity":93,"complexityNote":94,"dataPrerequisites":95,"integrations":100},"medium","The model is the easy part. The work is the semantic layer (certified tables, metric definitions and example queries), enforcing each user's data permissions, and an evaluation set of real questions with known answers.",[96,97,98,99],"A curated set of certified tables or a semantic model with business definitions","Row and column level security defined in the data platform per role","A library of example questions with correct, reviewed SQL","Data classification, so sensitive columns can be excluded or masked",[101,102,103,104],"Data warehouse or lakehouse (SQL endpoint)","Semantic layer or data catalog","Identity provider for passing the user's identity to the data platform","BI tool or chat front end such as Microsoft Teams",{"steps":106,"guardrails":125,"humanInTheLoop":132,"kpisToInstrument":133,"failureModes":139},[107,110,113,116,119,122],{"title":108,"detail":109},"Pick one domain with a clean model","Start where definitions are settled and tables are few, for example sales pipeline or contact centre volumes. Write down the metric definitions before any model sees a question.",{"title":111,"detail":112},"Build the evaluation set first","Collect 100 to 200 real questions from the request queue with correct SQL and results. Run every change of model, prompt or semantic layer against it and publish the pass rate.",{"title":114,"detail":115},"Enforce permissions in the data platform, not the prompt","Run each query with the user's own identity so row and column security applies. Never rely on instructions to the model to hide data.",{"title":117,"detail":118},"Always show the SQL and the definitions","Users and analysts must be able to see how a number was produced. Label answers built on uncertified tables clearly.",{"title":120,"detail":121},"Close the loop with analysts","Route questions the assistant cannot answer confidently to the data team, and turn their corrected queries into new certified examples.",{"title":123,"detail":124},"Widen by domain, not by table count","Add the next domain only when the first meets its accuracy target, and track accuracy per domain separately.",[126,127,128,129,130,131],"Queries run with the user's own credentials; row and column level security is enforced by the data platform","Read only access, an allow list of schemas and a row limit on every query","The generated SQL, tables and definitions are shown with every answer","The assistant asks for clarification or declines when confidence is low instead of guessing","Every question, query and result is logged for audit and evaluation","Sensitive columns (personal data, account numbers) excluded or masked unless the role needs them","Analysts own the semantic layer and certify example queries. Any number that goes into a board pack, regulatory report or customer communication is checked by an analyst, not taken straight from the assistant. Users can flag a wrong answer, which goes to the data team for review.",[134,135,136,137,138],"Execution accuracy on the evaluation set, per domain","Share of questions answered without analyst involvement, and share later flagged as wrong","Weekly active users and repeat usage","Time from question to answer compared with the request queue","Denied or blocked queries by reason (permission, schema, row limit)",[140,143,146,149],{"title":141,"detail":142},"Confident but wrong numbers","The query runs and returns a plausible figure from the wrong table or definition. Show the SQL, restrict to certified tables, and measure accuracy on real questions.",{"title":144,"detail":145},"Permission leaks through a service account","The assistant queries with a powerful technical account and bypasses row level security. Pass the user's identity to the data platform.",{"title":147,"detail":148},"Definitions drift","The business changes a metric definition but the semantic layer does not. Give each definition an owner and a review date.",{"title":150,"detail":151},"Adoption stalls on trust","One visible wrong answer and users return to the queue. Start with a narrow domain, label uncertainty and publish the accuracy number.",{"euAiAct":153,"regulations":156,"guidance":162,"controls":173,"incidents":179},{"tier":154,"basis":155},"limited","Article 50(1) requires providers to design AI systems that interact directly with people so that those people are informed they are dealing with AI, unless this is obvious from the context, as it usually is for an internal assistant. An analytics assistant that makes no decisions about people is not a prohibited practice under Article 5 and is not listed in Annex III. It would be high risk only if it were intended for an Annex III purpose, such as assessing the creditworthiness of natural persons (point 5(b)).",[157,158,159,160,161],"gdpr","eu-ai-act","dora","iso-42001","nist-ai-rmf",[163,169],{"title":164,"issuer":165,"region":166,"url":167,"note":168},"General Data Protection Regulation, Article 25 data protection by design and by default","European Union","europe","https://eur-lex.europa.eu/eli/reg/2016/679/oj","Access to personal data must be limited to what each purpose needs, which argues for running every generated query under the user's own permissions and masking personal data by default.",{"title":170,"issuer":165,"region":166,"url":171,"note":172},"Article 50, transparency obligations for providers and deployers of certain AI systems","https://artificialintelligenceact.eu/article/50/","Providers must design AI systems that interact directly with people so that those people are informed they are interacting with AI, unless this is obvious from the context. Applies from 2 August 2026.",[174,175,176,177,178],"Data access enforced by the data platform per user, with no shared privileged service account","Query and answer logs retained and reviewable by the data owner","Evaluation set pass rate recorded for every release of model, prompt or semantic layer","Owner and review date for every certified table and metric definition","Inventory entry for the assistant with an accountable owner",[],{"howToBuild":181},"On Blits.ai this is an **AI agent** connected to a **SQL knowledge base**: a curated reporting\ntable, loaded into the platform's own storage, that holds only data every user of that\nassistant may see. The agent queries it with structured filters, sorting, column selection and\na row limit, not raw SQL. A **knowledge base** holds the metric definitions, table descriptions\nand certified example queries, retrieved with **hybrid search** so the agent applies the\napproved filters and definitions to the right table. For questions that need joins or\naggregation across tables, a **custom function** calls a governed endpoint of the data\nplatform (for example a text to SQL or semantic layer API) with a scoped, read only credential;\nthe platform does not pass each user's own identity through, so that endpoint must also expose\nonly data every user of the assistant may see, and data that differs by role belongs in a\nseparate assistant per audience. **Structured output** returns the tables used and the result\ntogether, plus the generated SQL for questions answered through the custom function.\n\nBusiness users ask questions in **Microsoft Teams** or a web chat embedded in the intranet, and\n**role based access control** in the tenant console decides who may build, change and publish\nthe assistant. **Guardrails** decline out of\nscope requests, **PII masking** removes personal data that users type into their questions; the\nloaded table itself must exclude personal data columns, because query results are not masked.\n**Test suites** run the\nevaluation set of real questions on every change, and **analytics** with thumbs up and down\nfeedback show which answers users reject. The platform is model agnostic, so the data team can\npick the model that scores best on its own evaluation set.",[183,186,189],{"question":184,"answer":185},"How accurate is text to SQL on real company data?","It depends heavily on the question and the data model. Snowflake, citing anecdotal evidence in a Forrester report, gives a best case of 70% on simple single table queries and around 20% at worst on complex joins. LinkedIn reports that about 95% of surveyed users rated SQL Bot's query accuracy \"Passes\" or above, a user rating rather than a measured accuracy rate. A curated semantic layer and a narrow scope make the difference.",{"question":187,"answer":188},"How do you stop users seeing data they are not entitled to?","Run every query with the user's own identity so the data platform's row and column level security applies, give the assistant read only access to an allow list of schemas, and mask sensitive columns. Instructions in a prompt are not an access control.",{"question":190,"answer":191},"Does this replace the BI team?","No. It takes routine, repetitive questions off the queue. Analysts still own the definitions, certify example queries and handle complex or novel analysis, and anything that goes into a regulatory report or board pack is checked by an analyst.",[193,194,195,196,197],"enterprise-knowledge-search","customer-feedback-analysis","regulatory-report-assembly","internal-audit-copilot","treasury-cash-flow-forecasting","2026-09-27",[200],{"date":198,"note":201},"First published","governed-text-to-sql-analytics",[204,233,262],{"title":205,"useCases":206,"organization":207,"vendors":212,"summary":215,"stage":216,"year":43,"channels":217,"languages":218,"metrics":220,"outcomeDisclosed":221,"sources":222,"verification":228,"grade":230,"id":231,"organizationSlug":232},"LinkedIn: SQL Bot text to SQL assistant in the DARWIN data platform",[202],{"name":208,"anonymized":209,"country":210,"region":211,"industry":22},"LinkedIn",false,"US","global",[213],{"name":208,"role":214},"in-house","LinkedIn's SQL Bot, built into its DARWIN data science platform, finds the right tables, writes the query and fixes errors so employees can answer data questions themselves; datasets keep their own access control lists, and the bot only supplies group credentials the user is entitled to. Domain experts certified and described hundreds of key tables, which improved retrieval, and the example queries come from notebooks certified by users and those meeting recency and reliability heuristics. The interface shows the retrieved tables and the query, and hundreds of employees across business units use it. In a user survey about 95% rated its query accuracy \"Passes\" or above (about 40% \"Very Good\" or \"Excellent\"); LinkedIn publishes no measured accuracy rate.","production",[32],[219],"en",[],true,[223],{"url":224,"title":225,"publisher":226,"date":227},"https://www.linkedin.com/blog/engineering/ai/practical-text-to-sql-for-data-analytics","Practical Text-to-SQL for Data Analytics","LinkedIn Engineering","2024-12-09",{"level":229,"checkedAt":198},"source-verified","B","linkedin-sql-bot-text-to-sql",null,{"title":234,"useCases":235,"organization":236,"vendors":238,"summary":241,"stage":242,"year":43,"channels":243,"languages":244,"metrics":245,"outcomeDisclosed":221,"sources":254,"verification":259,"grade":230,"id":261,"organizationSlug":232},"Uber: QueryGPT natural language to SQL",[202],{"name":237,"anonymized":209,"country":210,"region":211,"industry":22},"Uber Technologies",[239],{"name":240,"role":214},"Uber","Uber's QueryGPT turns an English question into SQL against its data platform, which handles about 1.2 million interactive queries a month. It narrows the problem with curated \"workspaces\" of tables and sample queries per business domain (such as Mobility, Ads and Core Services), picks the relevant tables and columns with separate agents, and returns the generated SQL with an explanation so the user can check it. It was released to some Operations and Support teams first.","pilot",[32],[219],[246],{"kpi":51,"value":247,"unit":248,"qualifier":249,"period":250,"claimant":251,"quote":252,"sourceUrl":253},300,"count","approximately","daily active users during the limited release","organization","With our limited release to some teams in Operations and Support, we are averaging about 300 daily active users, with about 78% saying that the generated queries have reduced the amount of time they would’ve spent writing it from scratch.","https://www.uber.com/us/en/blog/query-gpt/",[255],{"url":253,"title":256,"publisher":257,"date":258},"QueryGPT, Natural Language to SQL Using Generative AI","Uber Engineering Blog","2024-09-19",{"level":229,"checkedAt":260},"2026-09-26","uber-querygpt-natural-language-to-sql",{"title":263,"useCases":264,"organization":265,"vendors":268,"summary":272,"stage":216,"year":43,"channels":273,"languages":274,"metrics":275,"outcomeDisclosed":209,"sources":276,"verification":279,"grade":280,"id":281,"organizationSlug":232},"Bayer: natural language self service analytics with Snowflake Cortex Analyst",[202],{"name":266,"anonymized":209,"country":267,"region":166,"industry":23},"Bayer","DE",[269],{"name":270,"role":271},"Snowflake","platform","Bayer uses Snowflake Cortex Analyst as the query generation service and a Streamlit chat interface to answer natural language questions over its enterprise data platform, alongside its existing dashboards. The first phase answered executive questions from sales vice presidents, such as the market share of a product last month, and it has since been extended to business unit analysts with row level data. No outcome figures are published.",[32],[219],[],[277],{"url":42,"title":41,"publisher":270,"date":278},"2024-08-15",{"level":229,"checkedAt":260},"C","bayer-cortex-analyst-self-service-analytics",0,[284],{"kpi":51,"label":285,"unit":248,"aggregate":209,"higherIsBetter":221,"n":286,"nUpTo":282,"median":247,"min":247,"max":247,"byClaimant":287,"vendorOnly":209,"points":288},"Users served",1,{"organization":286,"vendor":282,"regulator":282,"independent":282},[289],{"evidenceId":261,"organization":237,"value":247,"qualifier":249,"claimant":251,"grade":230,"pooled":221},{"low":291,"high":292},81000,1260000,[294,315,342,362,379],{"slug":193,"title":295,"shortTitle":296,"definition":297,"status":9,"industries":298,"functions":302,"patterns":306,"audience":34,"autonomy":35,"adoptionStage":308,"evidenceCount":309,"publicEvidenceCount":309,"organizations":310,"bestGrade":230,"headline":232,"lastVerified":198,"indexable":221},"AI enterprise knowledge search for employees","Enterprise knowledge search","An assistant that lets any employee ask a question in plain language and get a synthesized answer from the organization's own policies, procedures, product manuals and research, with citations to the source documents and only from documents the employee is allowed to see.",[18,19,299,20,300,301],"wealth-and-asset-management","government","professional-services",[303,304,305],"knowledge-management","operations","customer-service",[30,28,307],"summarization","mainstream",4,[311,312,313,314],"Bank of America","Morgan Stanley","SIGNAL IDUNA","Wells Fargo",{"slug":194,"title":316,"shortTitle":317,"definition":318,"status":9,"industries":319,"functions":321,"patterns":323,"audience":326,"autonomy":327,"adoptionStage":308,"evidenceCount":328,"publicEvidenceCount":328,"organizations":329,"bestGrade":230,"headline":335,"lastVerified":198,"indexable":221},"AI for voice of the customer and feedback analysis","Customer feedback analysis","AI that reads every piece of free text customer feedback, such as survey verbatims, NPS comments, reviews, social posts, chat and call transcripts, and turns it into themes, sentiment, drivers and suggested actions that a named owner can act on, so the organization hears all of its customers instead of a sample.",[18,21,300,320],"manufacturing",[305,322,25],"marketing",[324,307,325],"classification-and-routing","speech-analytics","back-office","copilot",5,[330,331,332,333,334],"U.S. Department of Housing and Urban Development","Majid Al Futtaim Retail","Mattel","SBF Group","U.S. Social Security Administration",{"kpi":50,"label":336,"unit":337,"n":286,"nUpTo":282,"kind":338,"value":339,"qualifier":340,"claimant":341,"organization":333,"vendorReported":221},"Accuracy","percent","reported",84,"exact","vendor",{"slug":195,"title":343,"shortTitle":344,"definition":345,"status":9,"industries":346,"functions":349,"patterns":353,"audience":34,"autonomy":327,"adoptionStage":357,"segment":326,"evidenceCount":358,"publicEvidenceCount":358,"organizations":359,"bestGrade":230,"headline":232,"lastVerified":198,"indexable":221},"AI for regulatory report assembly","Regulatory report assembly","AI that assembles periodic and data driven regulatory filings and returns, such as prudential and statistical returns, threshold and transaction reports and disclosure packs, by pulling data into the regulator's schema, validating it, reconciling figures to source, explaining movements against prior periods and drafting commentary, before a named officer reviews and submits. Narratives for individual suspicious activity cases are a separate use case.",[19,20,347,348],"capital-markets","payments",[350,351,352],"regulatory-compliance","finance-and-accounting","financial-crime-compliance",[354,355,356,307],"agentic-workflow","anomaly-detection","content-generation","emerging",2,[360,361],"Board of Governors of the Federal Reserve System","National Credit Union Administration",{"slug":196,"title":363,"shortTitle":364,"definition":365,"status":9,"industries":366,"functions":367,"patterns":369,"audience":34,"autonomy":327,"adoptionStage":36,"evidenceCount":76,"publicEvidenceCount":76,"organizations":371,"bestGrade":280,"headline":375,"lastVerified":198,"indexable":221},"Generative AI copilot for internal audit","Internal audit copilot","A copilot for internal auditors that drafts planning memos and document request lists from prior audits, summarises large evidence sets, builds risk and control matrices from policies and process documents, and drafts findings and reports, with every statement traceable to its evidence and a qualified auditor accountable for every conclusion.",[18,19,20,300,347,299],[368,350,351],"risk-management",[30,307,356,370,355],"document-processing",[372,373,374],"Banco Bradesco","British Columbia Investment Management Corporation","XP Inc.",{"kpi":376,"label":377,"unit":337,"n":358,"nUpTo":282,"kind":338,"value":378,"qualifier":340,"claimant":341,"organization":372,"vendorReported":221},"handling-time-reduction","Handling time reduction",55,{"slug":197,"title":380,"shortTitle":381,"definition":382,"status":9,"industries":383,"functions":385,"patterns":387,"audience":34,"autonomy":35,"adoptionStage":36,"segment":389,"evidenceCount":328,"publicEvidenceCount":328,"organizations":390,"bestGrade":230,"headline":395,"lastVerified":198,"indexable":221},"AI cash flow forecasting for corporate treasury","Treasury cash forecasting","Machine learning and conversational analytics, offered by some banks inside their cash management platforms, that categorise a company's cash flows, forecast positions across accounts and currencies, and answer treasurers' questions in plain language, so the treasury team decides on funding and idle balances with better information and less spreadsheet work.",[19,18,384,21,320],"logistics-and-transportation",[386,351,25],"treasury",[388,324,28,354],"prediction-and-scoring","specialized-businesses",[391,311,392,393,394],"Amtrak","Domino's Pizza","JPMorgan Chase","Prysmian",{"kpi":54,"label":396,"unit":337,"n":358,"nUpTo":286,"kind":338,"value":397,"qualifier":249,"claimant":251,"organization":393,"vendorReported":209},"Productivity gain",90,{"indexable":221,"reasons":399},[],[401,406,410,416,423,428,435,442,450,457,464,470,477,484,490,495,502,508,514,520,526,532,538,543,548,555,562,567,573,580,586,592,598,603],{"id":158,"label":402,"issuer":165,"region":166,"url":403,"description":404,"useCases":405,"indexable":221},"EU AI Act","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":157,"label":407,"issuer":165,"region":166,"url":167,"description":408,"useCases":409,"indexable":221},"GDPR","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":160,"label":411,"issuer":412,"region":211,"url":413,"description":414,"useCases":415,"indexable":221},"ISO/IEC 42001","ISO and IEC","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":161,"label":417,"issuer":418,"region":419,"url":420,"description":421,"useCases":422,"indexable":221},"NIST AI Risk Management Framework","NIST","north-america","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":159,"label":424,"issuer":165,"region":166,"url":425,"description":426,"useCases":427,"indexable":221},"DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":429,"label":430,"issuer":431,"region":166,"url":432,"description":433,"useCases":434,"indexable":221},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":436,"label":437,"issuer":438,"region":166,"url":439,"description":440,"useCases":441,"indexable":221},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":443,"label":444,"issuer":445,"region":446,"url":447,"description":448,"useCases":449,"indexable":221},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":451,"label":452,"issuer":453,"region":446,"url":454,"description":455,"useCases":456,"indexable":221},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":458,"label":459,"issuer":460,"region":211,"url":461,"description":462,"useCases":463,"indexable":221},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",20,{"id":465,"label":466,"issuer":467,"region":419,"url":468,"description":469,"useCases":463,"indexable":221},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":471,"label":472,"issuer":473,"region":166,"url":474,"description":475,"useCases":476,"indexable":221},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":478,"label":479,"issuer":480,"region":211,"url":481,"description":482,"useCases":483,"indexable":221},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":485,"label":486,"issuer":165,"region":166,"url":487,"description":488,"useCases":489,"indexable":221},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":491,"label":492,"issuer":165,"region":166,"url":493,"description":494,"useCases":489,"indexable":221},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":496,"label":497,"issuer":498,"region":419,"url":499,"description":500,"useCases":501,"indexable":221},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":503,"label":504,"issuer":165,"region":166,"url":505,"description":506,"useCases":507,"indexable":221},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":509,"label":510,"issuer":511,"region":419,"url":512,"description":513,"useCases":507,"indexable":221},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":515,"label":516,"issuer":517,"region":211,"url":518,"description":519,"useCases":507,"indexable":221},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":521,"label":522,"issuer":165,"region":166,"url":523,"description":524,"useCases":525,"indexable":221},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":527,"label":528,"issuer":529,"region":419,"url":530,"description":531,"useCases":525,"indexable":221},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":533,"label":534,"issuer":445,"region":446,"url":535,"description":536,"useCases":537,"indexable":221},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",10,{"id":539,"label":540,"issuer":165,"region":166,"url":541,"description":542,"useCases":537,"indexable":221},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":544,"label":545,"issuer":165,"region":166,"url":546,"description":547,"useCases":537,"indexable":221},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":549,"label":550,"issuer":551,"region":166,"url":552,"description":553,"useCases":554,"indexable":221},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":556,"label":557,"issuer":558,"region":419,"url":559,"description":560,"useCases":561,"indexable":221},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",8,{"id":563,"label":564,"issuer":165,"region":166,"url":565,"description":566,"useCases":561,"indexable":221},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":568,"label":569,"issuer":165,"region":166,"url":570,"description":571,"useCases":572,"indexable":221},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",6,{"id":574,"label":575,"issuer":576,"region":577,"url":578,"description":579,"useCases":328,"indexable":221},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":581,"label":582,"issuer":583,"region":166,"url":584,"description":585,"useCases":309,"indexable":221},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":587,"label":588,"issuer":589,"region":166,"url":590,"description":591,"useCases":309,"indexable":221},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":593,"label":594,"issuer":595,"region":446,"url":596,"description":597,"useCases":76,"indexable":221},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":599,"label":600,"issuer":165,"region":166,"url":601,"description":602,"useCases":76,"indexable":221},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":604,"label":605,"issuer":606,"region":419,"url":607,"description":608,"useCases":76,"indexable":221},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598307409]