[{"data":1,"prerenderedAt":648},["ShallowReactive",2],{"uc-inspection-prioritization":3,"uc-regulations":438},{"useCase":4,"evidence":179,"blitsAiDeployments":324,"benchmarks":325,"indicative":337,"related":340,"indexability":436,"includeUnpublished":185},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":16,"functions":18,"patterns":22,"channels":25,"audience":27,"autonomy":28,"adoptionStage":29,"problem":30,"problemStats":31,"howItWorks":32,"valueDrivers":33,"kpis":37,"indicativeValue":42,"macroEstimates":71,"feasibility":72,"implementation":83,"risk":126,"blitsAi":156,"faq":158,"related":168,"datePublished":174,"dateModified":174,"lastVerified":174,"changelog":175,"slug":178},"AI for risk based inspection prioritization in food safety, workplace and environmental regulation","Inspection prioritization","AI risk scoring for inspection prioritization","Regulators such as DVSA, the Dutch NVWA and the Netherlands Labour Authority use risk models to pick which sites to inspect first; staff still choose the visits.","published","Models that predict which premises, operators or activities are most likely to be non compliant, so that inspectors in food safety, workplace safety, environmental and other regulation spend their visits where the risk is highest, ideally with inspectors choosing the visits and random inspections testing the model.",[12,13,14,15],"risk based inspection targeting","inspection targeting AI","predictive inspections","regulatory inspection risk scoring",[17],"government",[19,20,21],"risk-management","case-management","regulatory-compliance",[23,24],"prediction-and-scoring","anomaly-detection",[26],"internal-tools","employee-facing","assist","early-adopters","Regulators and local authorities oversee far more restaurants, farms, workplaces, garages, care\nhomes and industrial sites than their inspectors can visit. Visits are traditionally scheduled by\nfixed frequencies, time since the last visit, the type of premises and complaints received. That\nspends scarce inspector time on operators that are almost always compliant, lets backlogs build\nup when new businesses register faster than they can be visited, and finds problems late at\noperators whose risk has changed since their last rating.\n\nRegulators hold useful signals: past inspection results, notifications, complaints, whistleblowing,\nregistration data and, for some sectors, detailed transaction data such as MOT test records. Using\nthem to rank the next visits is the promise of predictive targeting. The risk is that a model\nlearns from past inspection choices, keeps sending inspectors to the same kind of operator and\nlabels businesses before anyone has looked.",[],"1. **Pick the decision.** The model supports one choice, such as which new food businesses to\n   inspect first or which notified asbestos removals to visit, within an existing inspection\n   programme.\n2. **Learn from outcomes.** A supervised model (such as gradient boosting or a random forest, or\n   the best of several techniques on a held out test set) is trained on past inspection results,\n   or an outlier model flags operators whose behaviour deviates from peers when labelled outcomes\n   are scarce. Some regulators add a rules layer, for example on the age of the last rating.\n3. **Score the population.** Every operator in scope gets a risk score or a red, amber or green\n   rating, refreshed monthly or when new data arrives, including operators never inspected before.\n4. **Inspectors decide.** Officers see the score alongside other information and local knowledge\n   and choose the visits; the score is never a finding and never replaces the inspection.\n5. **Keep a random sample and feed back.** A share of visits stays random or complaint driven, and\n   their results measure whether the model finds more non compliance than the old approach and\n   whether it keeps skipping certain operators.",[34,35,36],"risk-reduction","employee-productivity","compliance",[38,39,40,41],"detection-rate-improvement","users-served","interactions-handled","accuracy",{"referenceOrg":43,"inputs":44,"formula":66,"currency":67,"period":68,"resultLabel":69,"caveat":70},"A national or regional inspectorate that carries out 20,000 inspections a year",[45,52,59],{"key":46,"label":47,"low":48,"high":49,"unit":50,"note":51},"inspections","Inspections per year",15000,25000,"inspections per year","Editorial assumption. Replace with your own programme.",{"key":53,"label":54,"low":55,"high":56,"unit":57,"note":58},"redirectedShare","Share of visits moved from low risk to higher risk operators",0.05,0.15,"fraction of inspections","Editorial assumption. Most programmes keep fixed frequency, complaint and random visits, so only part of the programme can be redirected.",{"key":60,"label":61,"low":62,"high":63,"unit":64,"note":65},"costPerInspection","Fully loaded cost of one inspection",300,600,"EUR per inspection","Editorial assumption covering preparation, travel, visit and reporting time. Replace with your own cost.","inspections * redirectedShare * costPerInspection","EUR","per year","Inspection capacity redirected to higher risk operators","This values the inspection capacity that is redirected, not the public health, safety or environmental harm avoided, which is the real benefit but is rarely measured. It leaves out the cost of building, validating and monitoring the model.",[],{"complexity":73,"complexityNote":74,"dataPrerequisites":75,"integrations":79},"medium","Regulators usually hold the inspection history, so the data for a first model is often at hand. The effort goes into data quality across local authorities or regions, a random inspection programme to evaluate against, and guidance that stops the score from being treated as a verdict.",[76,77,78],"Inspection history with outcomes, including inspections that found no breach","A register of the operators in scope, including new registrations","Notifications, complaints and other signals with a documented legal basis",[80,81,82],"Inspection case management or regulatory platform","Operator register and notification systems","Dashboard, map or list for inspection planners",{"steps":84,"guardrails":100,"humanInTheLoop":106,"kpisToInstrument":107,"failureModes":113},[85,88,91,94,97],{"title":86,"detail":87},"Start with a backlog or a clearly bounded programme","The Food Standards Agency piloted its model on food businesses awaiting their first inspection (the transparency record is now marked retired); the Netherlands Labour Authority scores notified asbestos removals. A bounded population makes the benefit measurable.",{"title":89,"detail":90},"Keep random and complaint driven inspections","Reserve part of the programme for random visits. The NVWA uses random inspections to test whether the model finds more problems than it would otherwise, and the Netherlands Labour Authority uses the results of its random inspections to improve its model.",{"title":92,"detail":93},"Show the score next to other information","Present the rating in the tools inspectors already use, with the main drivers. DVSA shows its monthly red, amber and green ratings in a Power BI app next to other data on each site, and the Care Quality Commission shows its risk category and the main data drivers on its regulatory platform.",{"title":95,"detail":96},"Write usage guidance","State what the score may and may not be used for: prioritizing visits, not judging an operator or deciding enforcement.",{"title":98,"detail":99},"Monitor coverage and drift","Compare the operators the model selects with the whole population every cycle, and retrain when the sector or the data changes.",[101,102,103,104,105],"The score only prioritizes visits; findings and enforcement rest on evidence from the inspection","Inspectors can override the ranking with local knowledge, and overrides are recorded","A random inspection sample runs alongside model selection","Scores stay internal and are not published or shared with the operator, so a score is never read as a finding about that operator","Personal data, such as businesses run from home addresses, is minimised and protected","Inspection planners and inspectors decide which visits to make and carry out every inspection. Regulators review the model's selections against the population and the random sample each cycle and can pause it when it stops predicting or keeps selecting the same type of operator.",[108,109,110,111,112],"Non compliance rate found in model selected visits versus random visits","Share of the operator population never selected over a full cycle","Backlog of operators awaiting a first inspection","Share of scores overridden by inspectors, with reasons","Time spent on building visit lists",[114,117,120,123],{"title":115,"detail":116},"Self confirming targeting","The model learns from where inspectors went before and keeps sending them back. Random visits and a check of population coverage break the loop.",{"title":118,"detail":119},"Prejudging the operator","An inspector who sees a red rating may look harder or rate lower. Guidance and, where possible, keeping the score out of the inspection itself reduce this bias.",{"title":121,"detail":122},"Automation bias or distrust","Inspectors either follow the ranking blindly or ignore it. Training, visible drivers and feedback on outcomes keep use balanced.",{"title":124,"detail":125},"Stale data for new operators","New businesses have no history, so predictions lean on area or type data that can encode socioeconomic bias. Test performance for this group separately.",{"euAiAct":127,"regulations":130,"guidance":137,"controls":149,"incidents":155},{"tier":128,"basis":129},"context-dependent","Prioritizing inspections of businesses and premises is not a use listed in Annex III, so such a system is usually not high risk. The assessment changes when it scores natural persons, such as individual licensed professionals or sole traders, and the inspectorate acts as a law enforcement authority: assessing the risk that a person offends, or profiling persons in the detection or investigation of criminal offences, is high risk under Annex III point 6 (d) and (e), and predicting that a person will commit a criminal offence based solely on profiling is prohibited by Article 5(1)(d). GDPR applies wherever sole traders, home based businesses or named professionals are scored.",[131,132,133,134,135,136],"eu-ai-act","gdpr","nist-ai-rmf","iso-42001","uk-gdpr","uk-atrs",[138,144],{"title":139,"issuer":140,"region":141,"url":142,"note":143},"Algorithmic Transparency Recording Standard hub","UK government","europe","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","The Food Standards Agency, DVSA and the Care Quality Commission publish transparency records for their inspection prioritization tools.",{"title":145,"issuer":146,"region":141,"url":147,"note":148},"Algoritmeregister van de Nederlandse overheid","Government of the Netherlands","https://algoritmes.overheid.nl/nl","Dutch inspectorates, including the NVWA and the Netherlands Labour Authority, register their risk models with purpose, method and human oversight.",[150,151,152,153,154],"Transparency record per model, published before use","Written usage guidance for inspectors and planners","Random inspection sample and yearly effectiveness review","Fairness and coverage checks across operator types and areas","Change control and revalidation when the model is retrained",[],{"howToBuild":157},"The risk model itself usually lives in the regulator's analytics environment. Blits.ai adds the\ninspector facing layer: an **AI agent** in **Microsoft Teams** or an internal web chat that answers\n\"why is this site rated red?\" from the model drivers and the site's history through **custom\nfunctions** and a **SQL knowledge base**, and a **knowledge base** with hybrid retrieval over the\ninspection manual and guidance.\n\nAn **agentic workflow** can prepare a visit pack (history, open issues, recent notifications)\nfor each site on the list, with **human in the loop approval** before anything goes to the\noperator. **Monitors** check the agent's answers on a schedule, **PII masking** protects personal\ndata about sole traders, and EU and UAE data residency keeps regulatory data in region.",[159,162,165],{"question":160,"answer":161},"Which regulators use AI to choose inspections?","Models in production on this page include DVSA's outlier model for MOT testing stations, the Netherlands Labour Authority's random forest for asbestos removal jobs, the Dutch NVWA's supervised machine learning model for pig farm welfare and the US EPA's classical machine learning model for hazardous waste generators. The UK Food Standards Agency piloted a LightGBM model with local authorities for food hygiene inspections (the transparency record is now marked retired). The Care Quality Commission combines its sector risk model scores with rating rules in a rules based risk categorisation, and says its machine learning model to prioritize care home inspections is still in development.",{"question":163,"answer":164},"Does predictive targeting replace routine inspections?","Not in the UK and Dutch cases on this page: there the score only informs which visits or reviews come first, and Care Quality Commission teams review the category and may then make a site visit or another form of review. The Netherlands Labour Authority, for example, in principle still inspects every certified asbestos removal company at least once every three years, and also follows up reports and selects some jobs at random. The US EPA inventory entry says only that its scores support inspections, classifies the use as high impact and does not describe how staff use the scores.",{"question":166,"answer":167},"Is it high risk under the EU AI Act?","Usually not when it targets businesses and premises, because inspection targeting is not listed in Annex III. It needs a closer look when it scores individuals, such as sole traders or licensed professionals, for a regulator that also investigates criminal offences: that can fall under Annex III point 6, and prediction based solely on profiling is banned by Article 5.",[169,170,171,172,173],"tax-compliance-risk-scoring","benefit-fraud-and-error-detection","permit-and-licence-application-processing","continuous-controls-testing","governed-text-to-sql-analytics","2026-09-27",[176],{"date":174,"note":177},"First published","inspection-prioritization",[180,217,241,263,284,303],{"title":181,"useCases":182,"organization":183,"vendors":187,"summary":191,"stage":192,"year":193,"channels":194,"languages":195,"metrics":197,"outcomeDisclosed":206,"sources":207,"verification":212,"grade":214,"id":215,"organizationSlug":216},"Driver and Vehicle Standards Agency: MOT risk rating to prioritise visits to testing stations",[178],{"name":184,"anonymized":185,"country":186,"region":141,"industry":17},"Driver and Vehicle Standards Agency",false,"GB",[188],{"name":189,"role":190},"Kainos","integrator","DVSA approves MOT testers and testing stations (the record counts about 64,000 active testers and 23,000 active garages) and visits them to raise standards and detect deliberate or fraudulent testing. Its MOT risk rating, first built by Kainos and now run by DVSA, applies an outlier detection model (local outlier factor) to MOT test data and gives each tester and station a red, amber or green rating that is refreshed every month. Vehicle examiners see the rating in a Power BI app alongside other data and decide which sites to visit; the tool is not used for disciplinary decisions, which rest on evidence found during a visit. Previously visits were prioritised by time since the last visit.","production",2025,[26],[196],"en",[198],{"kpi":39,"value":199,"unit":200,"qualifier":201,"period":202,"claimant":203,"quote":204,"sourceUrl":205},150,"count","approximately","DVSA officers using it on a daily basis","organization","Used on a daily basis by approx. 150 DVSA officers who will supervise visit and assess.","https://www.gov.uk/algorithmic-transparency-records/dvsa-mot-risk-rating",true,[208],{"url":205,"title":209,"publisher":210,"date":211},"DVSA: MOT Risk Rating (algorithmic transparency record)","GOV.UK","2025-02-10",{"level":213,"checkedAt":174},"source-verified","B","dvsa-mot-garage-risk-rating",null,{"title":218,"useCases":219,"organization":220,"vendors":223,"summary":227,"stage":192,"year":228,"channels":229,"languages":230,"metrics":232,"outcomeDisclosed":185,"sources":233,"verification":238,"grade":214,"id":240,"organizationSlug":216},"Netherlands Labour Authority: random forest risk model to select asbestos removal jobs for inspection",[178],{"name":221,"anonymized":185,"country":222,"region":141,"industry":17},"Nederlandse Arbeidsinspectie","NL",[224],{"name":225,"role":226},"In house (Nederlandse Arbeidsinspectie)","in-house","Asbestos removal jobs must be notified in advance, and the Netherlands Labour Authority inspects a share of them to protect workers and the surroundings. Its IPA risk model, a supervised random forest classifier trained on past notifications and inspection findings together with Chamber of Commerce and pseudonymised employment data, gives every notified removal a score for the likelihood that it is done incorrectly, and inspectors combine the score with other information to choose which jobs to inspect. Model based inspections are only part of the programme: in principle every certified company is inspected at least once every three years, some inspections follow reports from citizens and other regulators, and some jobs are chosen at random, with their results used to improve the model's reliability. In use since September 2024.",2024,[26],[231],"nl",[],[234],{"url":235,"title":236,"publisher":145,"date":237},"https://algoritmes.overheid.nl/nl/algoritme/oorg12349/74441495/ipa-risicomodel","IPA risicomodel, Algoritmeregister","2024-12-10",{"level":213,"checkedAt":239},"2026-09-26","nederlandse-arbeidsinspectie-asbestos-removal-risk-model",{"title":242,"useCases":243,"organization":244,"vendors":246,"summary":247,"stage":192,"year":248,"channels":249,"languages":250,"metrics":251,"outcomeDisclosed":206,"sources":257,"verification":261,"grade":214,"id":262,"organizationSlug":216},"Care Quality Commission: risk categorisation to prioritise assessment of health and care services",[178],{"name":245,"anonymized":185,"country":186,"region":141,"industry":17},"Care Quality Commission",[],"The Care Quality Commission, the health and social care regulator for England, gives each assessment service group of a registered location or provider a monthly risk category (medium, high or very high) that inspectors use to prioritise assessment activity. The category combines outputs of four sector risk models (adult social care, general practice, independent healthcare, urgent and emergency care), built on data such as statutory notifications, whistleblowing, safeguarding concerns and public feedback, with rules based on the age and level of the current rating. Inspectors see the main data drivers, local insight can override the score, and the output is tested against inspection outcomes. The record adds that a machine learning model to prioritise care home inspections is in development but not yet in production.",2023,[26],[196],[252],{"kpi":40,"value":253,"unit":200,"qualifier":201,"period":254,"claimant":203,"quote":255,"sourceUrl":256},46000,"refreshed risk scores per month","We are currently producing approxiately 46000 refreshed scores each month.","https://www.gov.uk/algorithmic-transparency-records/care-quality-commission-risk-categorisation",[258],{"url":256,"title":259,"publisher":210,"date":260},"Care Quality Commission: Risk Categorisation (algorithmic transparency record)","2026-03-30",{"level":213,"checkedAt":174},"care-quality-commission-inspection-risk-categorisation",{"title":264,"useCases":265,"organization":266,"vendors":268,"summary":271,"stage":272,"year":273,"channels":274,"languages":275,"metrics":276,"outcomeDisclosed":185,"sources":277,"verification":282,"grade":214,"id":283,"organizationSlug":216},"Food Standards Agency: machine learning to help local authorities prioritise food hygiene inspections",[178],{"name":267,"anonymized":185,"country":186,"region":141,"industry":17},"Food Standards Agency",[269],{"name":270,"role":190},"Cognizant","After the pandemic, the number of food businesses awaiting their first hygiene inspection in England, Wales and Northern Ireland grew steadily. The Food Standards Agency built a LightGBM model, trained on its hygiene rating data, census data and open location data, that predicts whether a business awaiting inspection is likely to be compliant and what rating it would get, and offers the predictions to local authority officers as a table, a map and a download. Use is voluntary, the prediction must not replace or be used in isolation from the officer's judgment, and the agency applied fairness and explainability tooling during development. The transparency record describes an alpha pilot with local authorities from April 2022; no outcome figures are published. GOV.UK now lists the record's phase as Retired, and no pilot outcomes were ever published.","paused",2022,[26],[196],[],[278],{"url":279,"title":280,"publisher":210,"date":281},"https://www.gov.uk/algorithmic-transparency-records/food-standards-agency-food-hygiene-rating-scheme-ai","Food Standards Agency: Food Hygiene Rating Scheme – AI (algorithmic transparency record)","2024-02-29",{"level":213,"checkedAt":239},"food-standards-agency-food-hygiene-inspection-prioritisation",{"title":285,"useCases":286,"organization":287,"vendors":289,"summary":292,"stage":192,"year":273,"channels":293,"languages":294,"metrics":295,"outcomeDisclosed":185,"sources":296,"verification":301,"grade":214,"id":302,"organizationSlug":216},"Netherlands Food and Consumer Product Safety Authority: compliance model to select pig farms for welfare inspections",[178],{"name":288,"anonymized":185,"country":222,"region":141,"industry":17},"Nederlandse Voedsel- en Warenautoriteit (NVWA)",[290],{"name":291,"role":226},"In house (NVWA)","The NVWA, the Dutch authority that checks among other things whether pig farmers care for their animals properly, predicts for every pig farm the chance that it does not comply with animal welfare rules. So far the model has been rebuilt each time it is used, comparing several supervised machine learning techniques on past inspection results and registry data and choosing the best predictor on a held out test set. People set how many farms go on the inspection list and check the list by hand, and every farm on it gets a normal inspection. The authority keeps inspecting randomly selected farms to test whether the model finds more problems, compares the selected farms with the whole population to spot farm types that are always picked or always skipped, and makes sure inspectors never know for certain whether the model selected a farm. In use since March 2022; a similar model covers dairy cattle welfare.",[26],[231],[],[297],{"url":298,"title":299,"publisher":145,"date":300},"https://algoritmes.overheid.nl/nl/algoritme/oorg10102/49428458/nalevingsmodel-varkenswelzijn","Nalevingsmodel Varkenswelzijn, Algoritmeregister","2026-05-22",{"level":213,"checkedAt":239},"nvwa-pig-welfare-compliance-model",{"title":304,"useCases":305,"organization":306,"vendors":310,"summary":313,"stage":192,"year":273,"channels":314,"languages":315,"metrics":316,"outcomeDisclosed":185,"sources":317,"verification":322,"grade":214,"id":323,"organizationSlug":216},"US Environmental Protection Agency: risk scoring of large quantity hazardous waste generators for inspections",[178],{"name":307,"anonymized":185,"country":308,"region":309,"industry":17},"U.S. Environmental Protection Agency, Office of Enforcement and Compliance Assurance","US","north-america",[311],{"name":312,"role":190},"University of Chicago Energy and Environment Lab","EPA's enforcement office reports in the 2025 federal AI use case inventory that it scores Large Quantity Generators of hazardous waste on a scale of 0 to 4 to support inspections under the Resource Conservation and Recovery Act (RCRA). The stated aims are reducing staff time and better identification of potential violators. The entry describes a classical machine learning model trained on historical compliance data, built in house together with the University of Chicago Energy and Environment Lab, marks it as high impact and lists it as deployed since October 2022. No outcome figures are published.",[26],[196],[],[318],{"url":319,"title":320,"publisher":321},"https://raw.githubusercontent.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory/main/Data/2025_individually_reported_AI_use_cases.csv","2025 federal agency AI use case inventory, individually reported use cases (raw data)","Office of Management and Budget (GitHub)",{"level":213,"checkedAt":174},"epa-hazardous-waste-generator-inspection-risk-scoring",0,[326,332],{"kpi":40,"label":327,"unit":200,"aggregate":185,"higherIsBetter":206,"n":328,"nUpTo":324,"median":253,"min":253,"max":253,"byClaimant":329,"vendorOnly":185,"points":330},"Interactions handled",1,{"organization":328,"vendor":324,"regulator":324,"independent":324},[331],{"evidenceId":262,"organization":245,"value":253,"qualifier":201,"claimant":203,"grade":214,"pooled":206},{"kpi":39,"label":333,"unit":200,"aggregate":185,"higherIsBetter":206,"n":328,"nUpTo":324,"median":199,"min":199,"max":199,"byClaimant":334,"vendorOnly":185,"points":335},"Users served",{"organization":328,"vendor":324,"regulator":324,"independent":324},[336],{"evidenceId":215,"organization":184,"value":199,"qualifier":201,"claimant":203,"grade":214,"pooled":206},{"low":338,"high":339},225000,2250000,[341,355,376,400,419],{"slug":169,"title":342,"shortTitle":343,"definition":344,"status":9,"industries":345,"functions":346,"patterns":348,"audience":349,"autonomy":28,"adoptionStage":29,"evidenceCount":350,"publicEvidenceCount":350,"organizations":351,"bestGrade":214,"headline":216,"lastVerified":174,"indexable":206},"AI for tax compliance risk scoring and audit selection","Tax compliance risk scoring","Models that score tax returns, taxpayers and transactions for the risk of error, underreporting or fraud, so that a tax administration spends its audit and compliance capacity where the risk is highest, with an officer deciding every compliance action and the selection itself monitored for fairness.",[17],[19,20,347],"fraud-prevention",[23,24],"back-office",3,[352,353,354],"Belastingdienst","HM Revenue and Customs","Internal Revenue Service",{"slug":170,"title":356,"shortTitle":357,"definition":358,"status":9,"industries":359,"functions":360,"patterns":362,"audience":349,"autonomy":28,"adoptionStage":29,"evidenceCount":363,"publicEvidenceCount":363,"organizations":364,"bestGrade":214,"headline":370,"lastVerified":174,"indexable":206},"AI for benefit fraud and error detection in social security","Benefit fraud and error detection","Risk models that help a social security or benefits agency decide which claims, payments and recipients to check for fraud or error, so that caseworkers verify the riskiest cases first, while every decision on entitlement stays with a person and the model is tested for fairness before and during use.",[17],[347,361,20],"citizen-services",[23,24],5,[365,366,367,368,369],"Centers for Medicare and Medicaid Services","Department for Work and Pensions","Gemeente Rotterdam","U.S. Department of the Treasury, Bureau of the Fiscal Service","Uitvoeringsinstituut Werknemersverzekeringen (UWV)",{"kpi":38,"label":371,"unit":372,"n":328,"nUpTo":324,"kind":373,"value":374,"qualifier":375,"claimant":203,"organization":366,"vendorReported":185},"Detection improvement","multiplier","reported",2.5,"exact",{"slug":171,"title":377,"shortTitle":378,"definition":379,"status":9,"industries":380,"functions":381,"patterns":382,"audience":27,"autonomy":387,"adoptionStage":388,"evidenceCount":363,"publicEvidenceCount":363,"organizations":389,"bestGrade":214,"headline":395,"lastVerified":239,"indexable":206},"AI for permit and licence application processing","Permit and licence application processing","AI that helps applicants submit complete permit and licence applications and helps officers process them, by answering questions about requirements, checking applications for missing or inconsistent information, pulling the relevant policies, history and constraints, and drafting reports, while the grant or refusal stays with a named officer or a published rule.",[17],[361,20,21],[383,384,385,386],"document-processing","agentic-workflow","rag-knowledge-assistant","conversational-agent","copilot","emerging",[390,391,392,393,394],"Intellectual Property Office","Leeds City Council","U.S. Fish and Wildlife Service","U.S. Department of Agriculture","West Berkshire Council",{"kpi":41,"label":396,"unit":397,"n":328,"nUpTo":324,"kind":373,"value":398,"qualifier":399,"claimant":203,"organization":391,"vendorReported":185},"Accuracy","percent",85,"at-least",{"slug":172,"title":401,"shortTitle":402,"definition":403,"status":9,"industries":404,"functions":409,"patterns":411,"audience":349,"autonomy":413,"adoptionStage":388,"segment":414,"evidenceCount":350,"publicEvidenceCount":350,"organizations":415,"bestGrade":214,"headline":216,"lastVerified":174,"indexable":206},"AI for continuous controls testing and control self assessment","Continuous controls testing","AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.",[405,406,407,408,17],"cross-industry","banking","insurance","capital-markets",[19,21,410],"operations",[384,383,24,412],"classification-and-routing","supervised-agent","second-line",[416,417,418],"Federal Deposit Insurance Corporation","U.S. Department of the Interior","Pension Benefit Guaranty Corporation",{"slug":173,"title":420,"shortTitle":421,"definition":422,"status":9,"industries":423,"functions":427,"patterns":430,"audience":27,"autonomy":28,"adoptionStage":29,"evidenceCount":350,"publicEvidenceCount":350,"organizations":432,"bestGrade":214,"headline":216,"lastVerified":174,"indexable":206},"Governed text to SQL analytics assistant","Governed SQL analytics","An assistant that turns a business user's plain language question into a query against governed data, runs it under that user's own data permissions and returns the table or chart together with the SQL and the tables used, so routine ad hoc questions no longer queue for the data team.",[405,406,407,424,425,426],"retail-and-ecommerce","technology","pharma-and-life-sciences",[428,429],"analytics-and-reporting","it-and-engineering",[386,431,385],"code-generation",[433,434,435],"Bayer","LinkedIn","Uber Technologies",{"indexable":206,"reasons":437},[],[439,445,450,457,463,469,475,482,490,497,504,510,515,522,528,533,540,546,552,558,564,570,576,581,586,593,600,605,611,618,625,631,637,642],{"id":131,"label":440,"issuer":441,"region":141,"url":442,"description":443,"useCases":444,"indexable":206},"EU AI Act","European Union","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":132,"label":446,"issuer":441,"region":141,"url":447,"description":448,"useCases":449,"indexable":206},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":134,"label":451,"issuer":452,"region":453,"url":454,"description":455,"useCases":456,"indexable":206},"ISO/IEC 42001","ISO and IEC","global","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":133,"label":458,"issuer":459,"region":309,"url":460,"description":461,"useCases":462,"indexable":206},"NIST AI Risk Management Framework","NIST","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":464,"label":465,"issuer":441,"region":141,"url":466,"description":467,"useCases":468,"indexable":206},"dora","DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":135,"label":470,"issuer":471,"region":141,"url":472,"description":473,"useCases":474,"indexable":206},"UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":476,"label":477,"issuer":478,"region":141,"url":479,"description":480,"useCases":481,"indexable":206},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":483,"label":484,"issuer":485,"region":486,"url":487,"description":488,"useCases":489,"indexable":206},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":491,"label":492,"issuer":493,"region":486,"url":494,"description":495,"useCases":496,"indexable":206},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":498,"label":499,"issuer":500,"region":453,"url":501,"description":502,"useCases":503,"indexable":206},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",20,{"id":505,"label":506,"issuer":507,"region":309,"url":508,"description":509,"useCases":503,"indexable":206},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":136,"label":511,"issuer":512,"region":141,"url":142,"description":513,"useCases":514,"indexable":206},"UK Algorithmic Transparency Recording Standard","UK Government","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":516,"label":517,"issuer":518,"region":453,"url":519,"description":520,"useCases":521,"indexable":206},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":523,"label":524,"issuer":441,"region":141,"url":525,"description":526,"useCases":527,"indexable":206},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":529,"label":530,"issuer":441,"region":141,"url":531,"description":532,"useCases":527,"indexable":206},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":534,"label":535,"issuer":536,"region":309,"url":537,"description":538,"useCases":539,"indexable":206},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":541,"label":542,"issuer":441,"region":141,"url":543,"description":544,"useCases":545,"indexable":206},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":547,"label":548,"issuer":549,"region":309,"url":550,"description":551,"useCases":545,"indexable":206},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":553,"label":554,"issuer":555,"region":453,"url":556,"description":557,"useCases":545,"indexable":206},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":559,"label":560,"issuer":441,"region":141,"url":561,"description":562,"useCases":563,"indexable":206},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":565,"label":566,"issuer":567,"region":309,"url":568,"description":569,"useCases":563,"indexable":206},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":571,"label":572,"issuer":485,"region":486,"url":573,"description":574,"useCases":575,"indexable":206},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",10,{"id":577,"label":578,"issuer":441,"region":141,"url":579,"description":580,"useCases":575,"indexable":206},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":582,"label":583,"issuer":441,"region":141,"url":584,"description":585,"useCases":575,"indexable":206},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":587,"label":588,"issuer":589,"region":141,"url":590,"description":591,"useCases":592,"indexable":206},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":594,"label":595,"issuer":596,"region":309,"url":597,"description":598,"useCases":599,"indexable":206},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",8,{"id":601,"label":602,"issuer":441,"region":141,"url":603,"description":604,"useCases":599,"indexable":206},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":606,"label":607,"issuer":441,"region":141,"url":608,"description":609,"useCases":610,"indexable":206},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",6,{"id":612,"label":613,"issuer":614,"region":615,"url":616,"description":617,"useCases":363,"indexable":206},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":619,"label":620,"issuer":621,"region":141,"url":622,"description":623,"useCases":624,"indexable":206},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",4,{"id":626,"label":627,"issuer":628,"region":141,"url":629,"description":630,"useCases":624,"indexable":206},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":632,"label":633,"issuer":634,"region":486,"url":635,"description":636,"useCases":350,"indexable":206},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":638,"label":639,"issuer":441,"region":141,"url":640,"description":641,"useCases":350,"indexable":206},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":643,"label":644,"issuer":645,"region":309,"url":646,"description":647,"useCases":350,"indexable":206},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598301472]