[{"data":1,"prerenderedAt":580},["ShallowReactive",2],{"uc-healthcare-claims-fraud-waste-abuse-detection":3,"uc-regulations":356},{"useCase":4,"evidence":187,"blitsAiDeployments":251,"benchmarks":252,"indicative":259,"related":262,"indexability":354,"includeUnpublished":193},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":17,"functions":21,"patterns":24,"channels":29,"audience":32,"autonomy":33,"adoptionStage":34,"segment":35,"problem":36,"problemStats":37,"howItWorks":43,"valueDrivers":44,"kpis":48,"indicativeValue":53,"macroEstimates":89,"feasibility":90,"implementation":102,"risk":140,"blitsAi":163,"faq":165,"related":178,"datePublished":182,"dateModified":182,"lastVerified":182,"changelog":183,"slug":186},"AI for healthcare claims fraud, waste and abuse detection","Healthcare claims FWA detection","Health claims fraud, waste and abuse detection AI","AI flags suspect health claims before payment. CMS reports its rule based prepayment edits saved over 20.4 million dollars; Highmark also uses AI against fraud.","published","AI that reads healthcare claims and provider billing patterns to flag fraud, waste and abuse before or shortly after a claim is paid, sending every flag with its reasons to a payment integrity investigator, while a narrow set of clear rule violations can be denied automatically before payment.",[12,13,14,15,16],"healthcare fraud, waste and abuse detection","FWA detection","payment integrity AI","health claims fraud analytics","provider fraud detection",[18,19,20],"healthcare","insurance","government",[22,23],"claims","fraud-prevention",[25,26,27,28],"anomaly-detection","prediction-and-scoring","document-processing","classification-and-routing",[30,31],"api","internal-tools","back-office","assist","early-adopters","payer","Health insurers and public payers handle enormous claim volumes: the US Government Accountability\nOffice reported that in fiscal year 2016 alone, Medicare covered about 57 million elderly and\ndisabled beneficiaries at a cost of about 699 billion US dollars. A share of paid claims are not\nwhat they claim to be: services billed but never given, codes inflated to a more expensive\nprocedure, tests ordered mainly to generate a claim. The National Health Care Anti Fraud\nAssociation's conservative estimate is that losses to health care fraud alone run 3% of total US\nhealth care expenditure, with some government and law enforcement agencies placing the loss as\nhigh as 10%. Waste and abuse add further losses that this estimate does not size separately.\n\nTraditional controls catch some of this with static rules and after the fact audits, but rules do\nnot adapt as billing schemes change, and manual review cannot keep pace with claim volume. The\nresult is either large sums paid out that are never fully recovered, or slow, blunt reviews that\ndelay payment to honest providers along with the dishonest ones.\n\nThe work splits into two very different jobs: a small set of clear, documented rule violations that\ncan be denied automatically before a claim pays, and a much larger set of suspicious patterns that\nneed a trained investigator, clinical judgement and, eventually, a decision to suspend a provider\nor refer the case to law enforcement.",[38],{"statement":39,"sourceTitle":40,"sourceUrl":41,"year":42},"The National Health Care Anti Fraud Association estimates that financial losses to health care fraud run into the tens of billions of dollars a year; a conservative estimate is 3% of total health care expenditure, while some government and law enforcement agencies place the loss as high as 10%, which could mean more than 300 billion US dollars.","The Challenge of Health Care Fraud","https://www.nhcaa.org/tools-insights/about-health-care-fraud/the-challenge-of-health-care-fraud/",2019,"1. **Screen every claim before it pays, not just after.** A first layer of deterministic edits\n   checks each claim against documented billing and coverage rules and denies the ones that clearly\n   break them, the way CMS's Fraud Prevention System denies claims that misstate where a service\n   was provided.\n2. **Score the rest for suspicious patterns.** A predictive model looks at billing patterns across a\n   provider's claims over time, such as more services than could reasonably fit in a day, unusual\n   coding mixes, or billing that jumps after a policy change, and ranks providers and claims by how\n   much they resemble confirmed fraud, waste or abuse.\n3. **Build the case, not just the score.** Each flag comes with the specific pattern that triggered\n   it and the provider's recent billing history, so an investigator opens a case file rather than a\n   bare number.\n4. **Investigate and decide.** A special investigations unit or program integrity team reviews the\n   flagged claims and providers, requests medical records where needed, and decides whether to\n   recover money, suspend payments or refer the case to law enforcement.\n5. **Share signals across payers.** Organized schemes often bill several payers at once, so\n   participating in a cross payer data sharing effort, such as the Healthcare Fraud Prevention\n   Partnership that CMS helped establish, surfaces patterns no single payer's own data would show.",[45,46,47],"risk-reduction","cost-to-serve","compliance",[49,50,51,52],"fraud-losses-prevented","detection-rate-improvement","alert-volume-reduction","cost-savings",{"referenceOrg":54,"inputs":55,"formula":84,"currency":85,"period":86,"resultLabel":87,"caveat":88},"A health plan paying 10 million medical claims a year",[56,62,69,76],{"key":57,"label":58,"low":59,"high":59,"unit":60,"note":61},"claimsPerYear","Paid medical claims per year",10000000,"claims per year","The reference health plan.",{"key":63,"label":64,"low":65,"high":66,"unit":67,"note":68,"sourceUrl":41},"fraudShare","Share of paid claim value lost to health care fraud",0.03,0.1,"fraction of paid claim value","NHCAA's conservative estimate is that losses to health care fraud run 3% of total health care expenditure; some government and law enforcement agencies place the loss as high as 10%. This sizes fraud only; it does not include waste or abuse.",{"key":70,"label":71,"low":72,"high":73,"unit":74,"note":75},"avgClaimValue","Average paid amount per medical claim",400,1200,"USD per claim","Editorial assumption for a mixed medical claims book, replace with your own average paid amount per claim.",{"key":77,"label":78,"low":79,"high":80,"unit":81,"note":82,"sourceUrl":83},"preventionRate","Share of fraud value the model and investigations team stop before payment",0.05,0.15,"fraction of fraud value stopped before payment","Editorial assumption, replace with your own. For scale, CMS reported that its Fraud Prevention System's rule based prepayment edits, which do not score claims for risk, denied nearly 324,000 claims and saved more than 20.4 million US dollars in fiscal year 2016 alone, as reported by the Government Accountability Office; that figure is a small fraction of NHCAA's fraud estimate for the whole US health system, so this range is not benchmarked against it.","https://www.gao.gov/products/gao-17-710","claimsPerYear * fraudShare * avgClaimValue * preventionRate","USD","per year","Fraudulent payments avoided per year","Gross avoided payments only, and only for the fraud share NHCAA sizes; it leaves out waste and abuse, which are not sized separately here, the cost of running the model and the investigations team, false positives that delay legitimate provider payments, and fraud caught only after payment through postpay recovery.",[],{"complexity":91,"complexityNote":92,"dataPrerequisites":93,"integrations":97},"high","Detecting fraud, waste and abuse needs claims, provider, eligibility and often medical record data joined at the claim line level, current procedural and diagnosis coding knowledge, and a defensible audit trail, because every flag can end in a provider investigation, a payment suspension or a law enforcement referral.",[94,95,96],"Historical paid and denied claims labelled by a confirmed fraud, waste or abuse outcome","Provider enrollment, network and billing history data","Current procedural and diagnosis coding rules and the payer's own billing policies",[98,99,100,101],"Claims adjudication and payment system, for prepayment edits","Provider data management and network systems","Case management system for the special investigations unit","Legal and law enforcement referral workflow, for confirmed fraud cases",{"steps":103,"guardrails":119,"humanInTheLoop":124,"kpisToInstrument":125,"failureModes":130},[104,107,110,113,116],{"title":105,"detail":106},"Start with clear, defensible rules before the model","Encode known billing violations, such as a place of service mismatch, as deterministic prepayment edits, the way CMS's Fraud Prevention System does, before adding predictive scoring on top.",{"title":108,"detail":109},"Separate the prepay stop from the postpay lead","Decide which flags block payment automatically under strict, documented criteria, and which only generate a lead for a human investigator. Most flags should be the latter.",{"title":111,"detail":112},"Ground the model in confirmed outcomes","Train and validate on claims with a documented investigation outcome, not just claims that \"look unusual,\" and revalidate regularly as coding and billing patterns shift.",{"title":114,"detail":115},"Build the investigator workflow, not just the score","Give investigators the claim, the provider's billing history and the specific reason for the flag, so they are not starting from a blank claim.",{"title":117,"detail":118},"Coordinate with peers and law enforcement","Contribute to and use a cross payer data sharing programme; organized fraud usually spreads across payers, and no single payer's data shows the whole pattern.",[120,121,122,123],"No predictive fraud score ever triggers an automatic denial on its own; the system denies a claim automatically only through a deterministic rule edit, and every predictive score, however high, goes to a human investigator as a lead, not a denial","A provider is never suspended or reported to law enforcement without human sign off and a documented investigation","Regular review of false positive rates by specialty, to catch a model that disproportionately flags one type of provider or patient population","Legal review before any bulk payment suspension or law enforcement referral","Investigators, clinical reviewers and compliance staff make every provider suspension, recoupment and law enforcement referral decision. The model's job is to surface the claims and providers worth their time faster than manual sampling or a static rule set could.",[126,127,128,129],"Confirmed fraud, waste or abuse found per investigator hour, against the manual baseline","False positive rate on flagged claims, by specialty and payer","Value of prepayment edits and postpay recoveries, tracked separately","Time from claim submission to a confirmed investigation outcome",[131,134,137],{"title":132,"detail":133},"Automatic edits that block legitimate care","A prepayment edit written too broadly denies claims for care that was actually delivered and coded correctly, delaying provider payment. Test every edit thoroughly against real claims before it goes live; CMS has its Medicare Administrative Contractors help develop and test FPS edits before they go into the system, to make sure they work as intended.",{"title":135,"detail":136},"Model drift as billing patterns shift","Fraud schemes adapt once providers learn what gets flagged. Retrain on recent confirmed outcomes and watch for a falling hit rate, often the first sign a scheme has moved on.",{"title":138,"detail":139},"Savings claimed that the model did not cause","A payment integrity programme's total savings can get attributed to a new AI tool that only touched a fraction of it. Track the model's own attributable savings separately from the rest of the programme.",{"euAiAct":141,"regulations":144,"guidance":150,"controls":157,"incidents":162},{"tier":142,"basis":143},"context-dependent","Claims fraud, waste and abuse detection is not itself listed in Annex III. Annex III point 5(a) only covers AI used by or on behalf of public authorities to evaluate a natural person's eligibility for essential public assistance benefits and services, or to grant, reduce or revoke them, which can cover statutory health schemes run by or for public bodies such as Medicare; it does not cover a private health insurer denying a member's own claim. For a private insurer, only Annex III point 5(c), risk assessment and pricing in life and health insurance, can make a system high risk, and claims fraud, waste and abuse detection by itself is not covered by it. Provider level detection that never decides a patient's own entitlement to care stays outside Annex III either way.",[145,146,147,148,149],"eu-ai-act","gdpr","hipaa","nist-ai-rmf","iso-42001",[151],{"title":152,"issuer":153,"region":154,"url":155,"note":156},"Medicare Program Integrity Manual, Chapter 4: Program Integrity","Centers for Medicare and Medicaid Services","north-america","https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/pim83c04.pdf","Sets the process Medicare contractors must follow to identify, develop and refer suspected fraud, waste and abuse, including through automated edits and data analysis.",[158,159,160,161],"Documented investigation and sign off before any provider payment suspension or law enforcement referral","False positive and disparate impact monitoring by provider specialty and patient population","Independent validation of every automated prepayment edit before and after launch","Data sharing governance for any cross payer fraud data pooling",[],{"howToBuild":164},"On Blits.ai the investigation workflow runs as an **agentic workflow**, triggered when the\npayer's own fraud, waste and abuse model flags a claim or a provider. The agent calls **custom\nfunctions** that pull the claim, the provider's billing history and prior flags from **SQL\nknowledge bases**, and follows the payer's own investigation and referral procedures from a\n**knowledge base** with hybrid retrieval. It returns a structured case summary with the specific\nrule or pattern that triggered the flag and the evidence behind it, so an investigator opens a\ncase file directly instead of starting from a blank claim.\n\nEvery suspension, recoupment or law enforcement referral goes through **human in the loop\napproval**, with a full audit trail. **PII masking** limits the patient and provider data that\nreaches the model, **guardrails** keep the agent inside its documented scope, **test suites**\nreplay confirmed past cases before every change to the workflow, and **monitors** alert on\nfailures. The fraud, waste and abuse scoring model itself typically stays in the payer's own\nanalytics stack; the platform is model agnostic and supports EU and UAE data residency for the\nworkflow around it.",[166,169,172,175],{"question":167,"answer":168},"How is this different from general insurance claims fraud detection?","General insurance claims fraud detection looks for staged accidents, inflated losses and organized rings in property, casualty and life claims. Healthcare payer fraud, waste and abuse detection is built around medical coding and billing rules, such as upcoding, unbundling and services never rendered, checked against payment policy rather than a police report.",{"question":170,"answer":171},"What share of healthcare spending is lost to fraud, waste and abuse?","The National Health Care Anti Fraud Association's conservative estimate is that losses to health care fraud alone run 3% of total health care expenditure, with some government and law enforcement agencies placing the loss as high as 10%. That figure covers fraud specifically; NHCAA does not size waste and abuse separately, and neither figure is specific to any one payer's book, so use it only as an order of magnitude.",{"question":173,"answer":174},"Does the AI ever deny a claim on its own?","In CMS's Fraud Prevention System, automatic denials come only from deterministic prepayment edits that check a claim against a documented Medicare rule, such as an impossible place of service. The Government Accountability Office reports that, according to CMS officials, CMS \"does not have the authority to use FPS to automatically deny individual claims based on risk\" and that FPS edits \"do not analyze individual claims to automatically deny payments based on risk alone or the likelihood that they are fraudulent.\" A predictive fraud score only produces a lead for a human investigator; it never denies a claim on its own.",{"question":176,"answer":177},"Is this the same tool that reviews prior authorization requests?","No. Prior authorization and claims adjudication support checks a specific request or claim against clinical and policy criteria for a clinician or adjudicator to decide. Fraud, waste and abuse detection looks across claims and providers over time for patterns that indicate deliberate wrongdoing, not a single coverage decision.",[179,180,181],"claims-fraud-detection","health-prior-authorization-and-claims-adjudication","medical-coding-automation","2026-09-29",[184],{"date":182,"note":185},"First published","healthcare-claims-fraud-waste-abuse-detection",[188,221],{"title":189,"useCases":190,"organization":191,"vendors":195,"summary":199,"stage":200,"year":201,"channels":202,"languages":203,"metrics":205,"outcomeDisclosed":193,"sources":206,"verification":216,"grade":218,"id":219,"organizationSlug":220},"Highmark: AI to strengthen fraud, waste and abuse detection",[186],{"name":192,"anonymized":193,"country":194,"region":154,"industry":18},"Highmark Inc.",false,"US",[196],{"name":197,"role":198},"Codoxo","platform","Highmark Inc.'s Financial Investigations and Provider Review (FIPR) department announced in February 2020 that it had begun using artificial intelligence to identify potentially fraudulent activity earlier than its existing rules based tools, through a partnership with Codoxo's FraudScope platform that Codoxo's own press release says started in 2019. Highmark's Vice President of Financial Investigations and Provider Review, Kurt Spear, said Highmark's Payment Integrity program runs 28 initiatives to help ensure claims payment accuracy, 15 of them embedded within FIPR, and described AI as helping the team predict aberrancies earlier and adapt more quickly to changing provider behaviour than traditional tools. Highmark's own announcement reports FIPR's total financial impact for 2019, 260 million US dollars, without attributing any part of it to AI, since the tool had only \"just recently\" gone live; Codoxo's press release, unlike Highmark's, attributes the 2019 escalation in that total \"in part\" to the newly implemented AI, alongside the department's existing manual and rules based work, without isolating an AI specific savings figure.","production",2020,[],[204],"en",[],[207,212],{"url":208,"title":209,"publisher":192,"date":210,"archivedUrl":211},"https://www.highmark.com/newsroom/press-releases/02-03-2020-highmark-incs-anti-fraud-department-using-artificial-intelligence-to-reduce-fraud-waste-and-abuse-impact","Highmark Inc.'s Anti-Fraud Department using Artificial Intelligence to reduce fraud, waste and abuse impact","2020-02-03","https://web.archive.org/web/2026/https://www.highmark.com/newsroom/press-releases/02-03-2020-highmark-incs-anti-fraud-department-using-artificial-intelligence-to-reduce-fraud-waste-and-abuse-impact",{"url":213,"title":214,"publisher":197,"date":215},"https://www.codoxo.com/press-release/fraudscope-ai-platform-delivers-results-for-highmark-inc-financial-investigations-and-provider-review-department/","FraudScope AI Platform Delivers Results for Highmark Inc. Financial Investigations and Provider Review Department","2020-02-18",{"level":217,"checkedAt":182},"source-verified","B","highmark-ai-fraud-waste-abuse-detection",null,{"title":222,"useCases":223,"organization":224,"vendors":225,"summary":226,"stage":227,"year":228,"channels":229,"languages":230,"metrics":231,"outcomeDisclosed":243,"sources":244,"verification":248,"grade":218,"id":249,"organizationSlug":250},"CMS: Fraud Prevention System predictive analytics for Medicare",[186],{"name":153,"anonymized":193,"country":194,"region":154,"industry":20},[],"The Centers for Medicare and Medicaid Services (CMS) built the Fraud Prevention System (FPS), a data analytic system implemented in 2011 that develops leads for fraud investigations by CMS program integrity contractors and denies improper Medicare fee for service claims before payment through automated, rule based prepayment edits. The US Government Accountability Office (GAO) reviewed CMS's use of FPS and reported that, in fiscal year 2016, FPS backed about a fifth of Medicare fraud investigations, contributed to provider payment suspensions during ongoing investigations, and its prepayment edits denied claims that violate documented Medicare rules or policies. GAO states that these edits \"do not analyze individual claims to automatically deny them based on risk alone or the likelihood that they are fraudulent,\" and that CMS does not have the authority to use FPS to deny a claim automatically based on risk alone. CMS also helped establish the Healthcare Fraud Prevention Partnership, which pools claims data across public and private payers to spot billing patterns no single payer's data would show.","scaled",2011,[],[204],[232,239],{"kpi":52,"value":233,"unit":234,"currency":85,"qualifier":235,"period":236,"claimant":237,"quote":238,"sourceUrl":83},20400000,"currency","at-least","fiscal year 2016","organization","CMS reported that FPS edits denied nearly 324,000 claims and saved more than $20.4 million in fiscal year 2016.",{"kpi":52,"value":240,"unit":234,"currency":85,"qualifier":241,"period":236,"claimant":237,"quote":242,"sourceUrl":83},6700000,"approximately","In fiscal year 2016, CMS reported that 90 providers had their payments suspended because of investigations initiated or supported by FPS, which resulted in an estimated $6.7 million in savings.",true,[245],{"url":83,"title":246,"publisher":247},"Medicare: CMS Fraud Prevention System Uses Claims Analysis to Address Fraud","U.S. Government Accountability Office",{"level":217,"checkedAt":182},"cms-fraud-prevention-system","centers-for-medicare-and-medicaid-services",0,[253],{"kpi":52,"label":254,"unit":234,"currency":85,"aggregate":193,"higherIsBetter":243,"n":255,"nUpTo":251,"median":233,"min":233,"max":233,"byClaimant":256,"vendorOnly":193,"points":257},"Cost savings",1,{"organization":255,"vendor":251,"regulator":251,"independent":251},[258],{"evidenceId":249,"organization":153,"value":233,"qualifier":235,"claimant":237,"grade":218,"pooled":243},{"low":260,"high":261},6000000,180000000,[263,280,307,326],{"slug":179,"title":264,"shortTitle":265,"definition":266,"status":9,"industries":267,"functions":268,"patterns":269,"audience":32,"autonomy":33,"adoptionStage":271,"segment":22,"evidenceCount":272,"publicEvidenceCount":272,"organizations":273,"bestGrade":218,"headline":220,"lastVerified":279,"indexable":243},"AI for insurance claims fraud detection","Claims fraud detection","AI that scores every insurance claim for fraud from first notice of loss onwards, combining claim, policy, document, image and network data to find suspicious claims, organised rings and inflated losses, and sends each alert with its reasons to a claims handler or special investigations unit for review.",[19],[22,23],[25,26,27,270,28],"computer-vision","mainstream",5,[274,275,276,277,278],"Assurant","AXA Switzerland","General Insurance Association of Singapore","Lemonade","Tokio Marine & Nichido Fire Insurance","2026-09-27",{"slug":180,"title":281,"shortTitle":282,"definition":283,"status":9,"industries":284,"functions":285,"patterns":288,"audience":292,"autonomy":293,"adoptionStage":34,"segment":22,"evidenceCount":272,"publicEvidenceCount":272,"organizations":294,"bestGrade":218,"headline":299,"lastVerified":279,"indexable":243},"AI for health insurance prior authorization and claims adjudication support","Health prior authorization and adjudication","AI that reads prior authorization requests, medical claims and appeals with their clinical and billing documents, extracts diagnoses, treatments and costs, checks them against the policy and published clinical criteria, and prepares a summary and recommendation for a clinician or adjudicator, who makes every adverse decision.",[19,18],[22,286,287],"case-management","operations",[27,289,290,28,291],"summarization","rag-knowledge-assistant","content-generation","employee-facing","copilot",[295,296,153,297,298],"Acentra Health","AdvanceCare","ICICI Lombard","Manulife",{"kpi":300,"label":301,"unit":302,"n":303,"nUpTo":251,"kind":304,"value":305,"qualifier":241,"claimant":306,"organization":295,"vendorReported":243},"handling-time-reduction","Handling time reduction","percent",2,"reported",50,"vendor",{"slug":181,"title":308,"shortTitle":309,"definition":310,"status":9,"industries":311,"functions":312,"patterns":314,"audience":32,"autonomy":315,"adoptionStage":34,"evidenceCount":316,"publicEvidenceCount":316,"organizations":317,"bestGrade":218,"headline":321,"lastVerified":279,"indexable":243},"AI medical coding for clinical encounters","Medical coding automation","AI that reads the clinical documentation of an encounter and assigns the diagnosis and procedure codes (such as ICD-10, CPT and HCPCS) needed for billing and reporting, either as suggestions for a certified coder or autonomously for encounters it can code with high confidence, sending the rest to coders with the reasons.",[18],[313,287],"finance-and-accounting",[28,27],"supervised-agent",3,[318,319,320],"Mass General Brigham","US Department of Veterans Affairs, Veterans Health Administration","Your Health",{"kpi":322,"label":323,"unit":302,"n":255,"nUpTo":251,"kind":304,"value":324,"qualifier":325,"claimant":237,"organization":320,"vendorReported":193},"accuracy","Accuracy",98.3,"exact",{"slug":327,"title":328,"shortTitle":329,"definition":330,"status":9,"industries":331,"functions":336,"patterns":339,"audience":32,"autonomy":315,"adoptionStage":34,"segment":340,"evidenceCount":341,"publicEvidenceCount":341,"organizations":342,"bestGrade":218,"headline":349,"lastVerified":353,"indexable":243},"application-and-identity-fraud-detection","AI for application and identity fraud detection","Application and identity fraud","AI that checks incoming account and loan applications for forged or AI generated documents, synthetic and stolen identities, and coordinated application rings, by analysing documents, device and application data across the whole queue and cross checking against bureau and official sources.",[332,333,334,20,335],"banking","payments","cross-industry","telecommunications",[23,337,338],"onboarding-and-kyc","lending-and-credit",[27,25,270,26],"front-office",6,[343,344,345,346,347,348],"BCU","Close Brothers Motor Finance","CNG Holdings","Department for Work and Pensions","Payoneer","Telstra",{"kpi":50,"label":350,"unit":351,"n":255,"nUpTo":251,"kind":304,"value":352,"qualifier":325,"claimant":237,"organization":346,"vendorReported":193},"Detection improvement","multiplier",2.5,"2026-09-26",{"indexable":243,"reasons":355},[],[357,364,369,376,382,389,395,401,409,416,423,430,436,442,448,455,461,468,474,480,486,493,498,505,510,515,520,526,533,538,545,552,558,564,569,574],{"id":145,"label":358,"issuer":359,"region":360,"url":361,"description":362,"useCases":363,"indexable":243},"EU AI Act","European Union","europe","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",230,{"id":146,"label":365,"issuer":359,"region":360,"url":366,"description":367,"useCases":368,"indexable":243},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",207,{"id":149,"label":370,"issuer":371,"region":372,"url":373,"description":374,"useCases":375,"indexable":243},"ISO/IEC 42001","ISO and IEC","global","https://www.iso.org/standard/81230.html","The international management system standard for AI.",122,{"id":148,"label":377,"issuer":378,"region":154,"url":379,"description":380,"useCases":381,"indexable":243},"NIST AI Risk Management Framework","NIST","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",92,{"id":383,"label":384,"issuer":385,"region":360,"url":386,"description":387,"useCases":388,"indexable":243},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",71,{"id":390,"label":391,"issuer":359,"region":360,"url":392,"description":393,"useCases":394,"indexable":243},"dora","DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":396,"label":397,"issuer":398,"region":360,"url":399,"description":400,"useCases":305,"indexable":243},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",{"id":402,"label":403,"issuer":404,"region":405,"url":406,"description":407,"useCases":408,"indexable":243},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",37,{"id":410,"label":411,"issuer":412,"region":405,"url":413,"description":414,"useCases":415,"indexable":243},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":417,"label":418,"issuer":419,"region":154,"url":420,"description":421,"useCases":422,"indexable":243},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",22,{"id":424,"label":425,"issuer":426,"region":372,"url":427,"description":428,"useCases":429,"indexable":243},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",21,{"id":431,"label":432,"issuer":359,"region":360,"url":433,"description":434,"useCases":435,"indexable":243},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",17,{"id":437,"label":438,"issuer":439,"region":360,"url":440,"description":441,"useCases":435,"indexable":243},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",{"id":147,"label":443,"issuer":444,"region":154,"url":445,"description":446,"useCases":447,"indexable":243},"HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",16,{"id":449,"label":450,"issuer":451,"region":372,"url":452,"description":453,"useCases":454,"indexable":243},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":456,"label":457,"issuer":359,"region":360,"url":458,"description":459,"useCases":460,"indexable":243},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":462,"label":463,"issuer":464,"region":154,"url":465,"description":466,"useCases":467,"indexable":243},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":469,"label":470,"issuer":471,"region":154,"url":472,"description":473,"useCases":467,"indexable":243},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":475,"label":476,"issuer":359,"region":360,"url":477,"description":478,"useCases":479,"indexable":243},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":481,"label":482,"issuer":483,"region":372,"url":484,"description":485,"useCases":479,"indexable":243},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":487,"label":488,"issuer":489,"region":154,"url":490,"description":491,"useCases":492,"indexable":243},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",11,{"id":494,"label":495,"issuer":359,"region":360,"url":496,"description":497,"useCases":492,"indexable":243},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",{"id":499,"label":500,"issuer":501,"region":360,"url":502,"description":503,"useCases":504,"indexable":243},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",10,{"id":506,"label":507,"issuer":404,"region":405,"url":508,"description":509,"useCases":504,"indexable":243},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",{"id":511,"label":512,"issuer":359,"region":360,"url":513,"description":514,"useCases":504,"indexable":243},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":516,"label":517,"issuer":359,"region":360,"url":518,"description":519,"useCases":504,"indexable":243},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":521,"label":522,"issuer":359,"region":360,"url":523,"description":524,"useCases":525,"indexable":243},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",9,{"id":527,"label":528,"issuer":529,"region":154,"url":530,"description":531,"useCases":532,"indexable":243},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",7,{"id":534,"label":535,"issuer":359,"region":360,"url":536,"description":537,"useCases":341,"indexable":243},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",{"id":539,"label":540,"issuer":541,"region":542,"url":543,"description":544,"useCases":272,"indexable":243},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":546,"label":547,"issuer":548,"region":360,"url":549,"description":550,"useCases":551,"indexable":243},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",4,{"id":553,"label":554,"issuer":555,"region":360,"url":556,"description":557,"useCases":551,"indexable":243},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":559,"label":560,"issuer":561,"region":405,"url":562,"description":563,"useCases":316,"indexable":243},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":565,"label":566,"issuer":359,"region":360,"url":567,"description":568,"useCases":316,"indexable":243},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":570,"label":571,"issuer":359,"region":360,"url":572,"description":573,"useCases":316,"indexable":243},"eu-mortgage-credit-directive","EU Mortgage Credit Directive","https://eur-lex.europa.eu/eli/dir/2014/17/oj","Directive 2014/17/EU: creditworthiness assessment, disclosure and advice rules for residential mortgage lending.",{"id":575,"label":576,"issuer":577,"region":154,"url":578,"description":579,"useCases":316,"indexable":243},"nyc-local-law-144","NYC Local Law 144","New York City","https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page","Bias audits and notices for automated employment decision tools used in hiring and promotion in New York City.",1790683490599]