[{"data":1,"prerenderedAt":608},["ShallowReactive",2],{"uc-internal-audit-copilot":3,"uc-regulations":396},{"useCase":4,"evidence":211,"blitsAiDeployments":295,"benchmarks":296,"indicative":312,"related":315,"indexability":394,"includeUnpublished":217},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":16,"functions":23,"patterns":27,"channels":33,"audience":36,"autonomy":37,"adoptionStage":38,"problem":39,"problemStats":40,"howItWorks":51,"valueDrivers":52,"kpis":57,"indicativeValue":63,"macroEstimates":103,"feasibility":104,"implementation":117,"risk":164,"blitsAi":188,"faq":190,"related":200,"datePublished":206,"dateModified":206,"lastVerified":206,"changelog":207,"slug":210},"Generative AI copilot for internal audit","Internal audit copilot","Generative AI copilot for internal audit teams","An internal audit copilot drafts plans, evidence summaries and findings. Microsoft cites 55% less reporting time at Bradesco and 30% less report writing at BCI.","published","A copilot for internal auditors that drafts planning memos and document request lists from prior audits, summarises large evidence sets, builds risk and control matrices from policies and process documents, and drafts findings and reports, with every statement traceable to its evidence and a qualified auditor accountable for every conclusion.",[12,13,14,15],"AI for internal audit","audit copilot","generative AI audit assistant","AI audit workpapers",[17,18,19,20,21,22],"cross-industry","banking","insurance","government","capital-markets","wealth-and-asset-management",[24,25,26],"risk-management","regulatory-compliance","finance-and-accounting",[28,29,30,31,32],"rag-knowledge-assistant","summarization","content-generation","document-processing","anomaly-detection",[34,35],"internal-tools","microsoft-teams","employee-facing","copilot","early-adopters","Internal audit functions are asked to cover a widening risk universe (cyber, third parties, AI,\nconduct, operational resilience), and every new area competes for the same auditor hours. A large share\nof each engagement is reading and writing: going through prior workpapers, policies and process\ndocuments to plan the scope, summarising hundreds of pages of evidence, documenting walkthroughs,\nand drafting findings and reports that go through several rounds of review.\n\nGenerative AI fits that reading and writing work, and audit leaders are adopting it quickly. The\nquestion for a third line function is how to use it without weakening what makes audit valuable:\nindependence, evidence that stands up to challenge and a qualified auditor who owns every\nconclusion. A fluent sentence in a workpaper that no evidence supports is worse than no sentence.",[41,46],{"statement":42,"sourceTitle":43,"sourceUrl":44,"year":45},"Gartner reported in March 2024 that 41% of chief audit executives were using or planning to use generative AI that year; in its survey of 112 chief audit executives in mid 2023, 12% were already using it.","Gartner Survey Shows 41% of Internal Audit Teams Use or Plan to Use Generative AI this Year","https://web.archive.org/web/20240523072602/https://www.gartner.com/en/newsroom/press-releases/2024-03-11-gartner-survey-shows-41-percent-of-internal-audit-teams-use-or-plan-to-use-generative-ai-this-year",2024,{"statement":47,"sourceTitle":48,"sourceUrl":49,"year":50},"Gartner reported in August 2026 that 93% of audit leaders report some level of AI use but only 38% have an AI strategy; in its webinar poll of 743 audit professionals, 60% used AI to draft audit issues, ratings or reports.","Gartner Survey Finds Audit Teams' AI Use is Common, But Most Teams are Lacking Strategic Adoption and Application","https://web.archive.org/web/20260820091915/https://www.gartner.com/en/newsroom/press-releases/2026-08-10-gartner-survey-finds-audit-teams-ai-use-is-common-but-most",2026,"1. **Plan from what is known.** The copilot retrieves prior workpapers, previous findings and their\n   status, the risk assessment and relevant policy changes, and drafts the planning memo, scope and\n   document request list for the audit lead to edit.\n2. **Build the control picture.** From policies, procedures and process documents it drafts a risk\n   and control matrix and walkthrough narratives, citing the document behind each control.\n3. **Digest the evidence.** It summarises evidence files, meeting notes and management responses,\n   and answers the auditor's questions about them with page level citations.\n4. **Point at anomalies.** Analytics on full populations (payments, access logs, journal entries)\n   surface outliers and exceptions for the auditor to test; the AI explains the pattern, it does\n   not conclude on it.\n5. **Draft findings and reports.** It drafts findings in the house structure (condition, criteria,\n   cause, effect, recommendation) from the auditor's notes and tested evidence, and checks draft\n   reports for consistency and tone.\n6. **Keep the trail.** Every AI draft, the prompt context and the auditor's edits are stored with\n   the workpaper, so reviewers can see what the AI wrote and what the auditor concluded.",[53,54,55,56],"employee-productivity","speed","compliance","risk-reduction",[58,59,60,61,62],"productivity-gain","processing-time-reduction","handling-time-reduction","hours-saved","time-saved-per-task",{"referenceOrg":64,"inputs":65,"formula":98,"currency":99,"period":100,"resultLabel":101,"caveat":102},"A bank internal audit function with 60 auditors",[66,71,78,85,91],{"key":67,"label":68,"low":69,"high":69,"unit":67,"note":70},"auditors","Auditors using the copilot",60,"The reference organization.",{"key":72,"label":73,"low":74,"high":75,"unit":76,"note":77},"hoursPerYear","Productive hours per auditor per year",1500,1600,"hours per auditor per year","Editorial assumption after leave, training and administration.",{"key":79,"label":80,"low":81,"high":82,"unit":83,"note":84},"draftingShare","Share of auditor time spent on planning documents, evidence summaries, workpaper write ups and reports",0.25,0.4,"fraction of time","Editorial assumption. Replace with your own time recording.",{"key":86,"label":87,"low":88,"high":89,"unit":83,"note":90},"timeSaved","Share of that drafting and summarising time saved",0.15,0.3,"Conservative against the evidence on this page (Microsoft reports 30% less time writing internal audit reports at BCI and 55% less time in reporting at Bradesco), because those are vendor reported best cases.",{"key":92,"label":93,"low":94,"high":95,"unit":96,"note":97},"hourlyCost","Fully loaded auditor hour",70,120,"USD per hour","Editorial assumption. Replace with your own rate.","auditors * hoursPerYear * draftingShare * timeSaved * hourlyCost","USD","per year","Auditor capacity released for testing and additional coverage","Capacity only, which most functions reinvest in coverage rather than headcount. It leaves out the value of broader risk coverage and full population testing, and the cost of reviewing AI drafts and maintaining the workpaper corpus.",[],{"complexity":105,"complexityNote":106,"dataPrerequisites":107,"integrations":112},"medium","Drafting and summarising on a secure platform is quick to start. The harder parts are giving the copilot permission aware access to workpapers and evidence without breaching confidentiality between engagements, and agreeing the methodology changes for documenting AI assistance.",[108,109,110,111],"Prior workpapers, findings and reports in the audit management system","The audit methodology, templates and finding structure","Policies, procedures and process documents for the audited areas","Population data (transactions, logs, journals) for analytics where testing needs it",[113,114,115,116],"Audit management system (workpapers, issues, action tracking)","Document management and policy repositories","Data platform for population analytics","Microsoft Teams or the audit team's collaboration tool",{"steps":118,"guardrails":137,"humanInTheLoop":144,"kpisToInstrument":145,"failureModes":151},[119,122,125,128,131,134],{"title":120,"detail":121},"Update the methodology first","Decide where AI may assist (planning, summarising, drafting) and where it may not (forming opinions, rating findings), and how AI assistance is recorded in workpapers. Brief the audit committee and the external auditor.",{"title":123,"detail":124},"Start with low risk drafting","Planning memos, document request lists and summaries of prior audits give quick wins with little risk, because the auditor edits every output before it is used.",{"title":126,"detail":127},"Ground everything in the audit corpus","Connect prior workpapers, the methodology and policies with retrieval and require a citation for every statement, so reviewers can check it quickly.",{"title":129,"detail":130},"Respect engagement boundaries","Apply the audit management system's permissions, so the copilot only retrieves from engagements the auditor may see, especially for investigations and sensitive reviews.",{"title":132,"detail":133},"Add analytics and findings drafting","Move to anomaly detection on full populations and drafting of findings once reviewers trust the citations, and measure review time and rework per report.",{"title":135,"detail":136},"Audit the copilot","Treat the copilot as an AI system in the inventory, with testing of its outputs on past audits and periodic review by someone independent of the team that built it.",[138,139,140,141,142,143],"A qualified auditor reviews, edits and signs every workpaper, finding and report; the AI never forms an audit opinion or rates a finding","Every AI generated statement cites the evidence document and page it relies on","Retrieval respects engagement and document permissions, including restrictions on investigations","AI assistance is recorded in the workpaper, with the draft and the auditor's changes retained","Anomalies surfaced by analytics are leads for testing, never conclusions","Audit data stays within the approved tenancy and region and is not used to train external models","Auditors own every conclusion and the chief audit executive owns the methodology. Reviewers check AI assisted workpapers with the same rigour as any other, using the citations, and the audit committee is informed how AI is used in the function.",[146,147,148,149,150],"Hours per engagement phase (planning, fieldwork documentation, reporting), before and after","Time from fieldwork end to final report","Share of AI drafted statements changed or removed by the auditor or reviewer","Review notes raised on AI assisted workpapers compared with others","Audit plan coverage (auditable entities covered per year)",[152,155,158,161],{"title":153,"detail":154},"Unsupported statements in workpapers","A fluent summary includes a claim that no evidence supports and survives review. Require citations and train reviewers to check them.",{"title":156,"detail":157},"Confidentiality leaks across engagements","The copilot retrieves material from an investigation or another engagement the auditor may not see. Enforce document level permissions in retrieval.",{"title":159,"detail":160},"Independence eroded by shared tooling","Audit relies on the same AI tools and prompts as the first line it audits. Keep audit's own configuration and test it independently.",{"title":162,"detail":163},"Anchoring on the AI draft","Auditors accept the drafted risk and control matrix rather than challenging it. Have auditors edit, not approve, and track the change rate.",{"euAiAct":165,"regulations":168,"guidance":174,"controls":181,"incidents":187},{"tier":166,"basis":167},"minimal","An internal drafting and analysis assistant for auditors that makes no decisions about natural persons. It would need reassessment if used to evaluate individual employees' behaviour or performance, which falls under Annex III point 4(b).",[169,170,171,172,173],"eu-ai-act","gdpr","iso-42001","nist-ai-rmf","dora",[175],{"title":176,"issuer":177,"region":178,"url":179,"note":180},"2024 Global Internal Audit Standards","The Institute of Internal Auditors","global","https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/","A mandatory component of the IPPF, and The IIA expects every internal audit function to conform. Its principles (among them objectivity, due professional care and confidentiality) and the Domain V requirements for planning engagements and developing findings apply to AI assisted work as to any other.",[182,183,184,185,186],"Methodology section on AI use approved by the chief audit executive and shared with the audit committee","Workpaper field recording AI assistance, with the draft retained","Periodic independent testing of the copilot's outputs on past engagements","Access control aligned with engagement permissions in the audit management system","Inventory entry for the copilot with an accountable owner",[],{"howToBuild":189},"On Blits.ai this is an **AI agent** with a **knowledge base** holding prior workpapers, the audit\nmethodology, templates and policies, retrieved with **hybrid search**. Evidence files in PDF, Word, Excel and Outlook email formats are ingested\nper engagement, and **SQL knowledge bases** let the agent query extracted population data for\nanomaly analysis. **Structured output** produces findings in the house\nformat (condition, criteria, cause, effect, recommendation).\n\nAuditors use the agent in **Microsoft Teams** or a web chat. Fine grained **role based access\ncontrol**, with custom roles per tenant and per bot roles, lets investigations and sensitive\nreviews run on their own bot, agent and knowledge base, and **tenant isolation** keeps audit data apart from other tenants. **PII masking** keeps personal\ndata out of prompts, **conversation logs** and **execution tracing** retain what the AI produced\nfor the workpaper, and **test suites** check the agent against past engagements before every\nchange. The platform is model agnostic, so the audit function can choose its own model\nindependently of the first line.",[191,194,197],{"question":192,"answer":193},"How much time can generative AI save in internal audit?","Reported figures are early and vendor published, without a stated method. Microsoft reports that BCI reduced time spent writing internal audit reports by 30%, that Bradesco achieved 55% less time in reporting with its AILA audit assistant, and that XP Inc. increased audit team efficiency by 30%. Measure hours per engagement phase on your own audits before and after.",{"question":195,"answer":196},"Does using AI compromise auditor independence?","Not if the auditor owns every conclusion, the AI's contribution is recorded in the workpaper, and audit's tooling is configured and tested independently of the first line it audits. The Global Internal Audit Standards, including objectivity and due professional care, apply to AI assisted work as to any other.",{"question":198,"answer":199},"What should the AI never do in an audit?","Form an audit opinion, rate a finding, or treat an anomaly as a conclusion. It drafts, summarises and points at exceptions; qualified auditors test, judge and sign.",[201,202,203,204,205],"continuous-controls-testing","ai-model-inventory","policy-drafting-and-gap-analysis","supervisory-exam-response-assembly","governed-text-to-sql-analytics","2026-09-27",[208],{"date":206,"note":209},"First published","internal-audit-copilot",[212,253,276],{"title":213,"useCases":214,"organization":215,"vendors":220,"summary":224,"stage":225,"year":226,"channels":227,"languages":228,"metrics":230,"outcomeDisclosed":242,"sources":243,"verification":248,"grade":250,"id":251,"organizationSlug":252},"Banco Bradesco: AILA generative AI assistant for the audit process",[210],{"name":216,"anonymized":217,"country":218,"region":219,"industry":18},"Banco Bradesco",false,"BR","latin-america",[221],{"name":222,"role":223},"Microsoft (Azure OpenAI)","platform","Bradesco built AILA, an assistant on Azure OpenAI that supports its audit process across planning, reporting, drafting and proofreading, and root cause analysis. Microsoft reports efficiency and time savings for each of those steps in a customer story round up, without stating the measurement method or period.","production",2025,[34],[229],"pt",[231,239],{"kpi":58,"value":232,"unit":233,"qualifier":234,"baseline":235,"claimant":236,"quote":237,"sourceUrl":238},65,"percent","exact","audit planning efficiency before AILA","vendor","With AILA, they achieved 65% more efficiency in audit planning, 55% less time in reporting, 50% less time writing/proofreading, and improved the identification of the root cause of problems by reducing the time required for this step by 20%.","https://www.microsoft.com/en-us/microsoft-cloud/blog/2025/07/24/ai-powered-success-with-1000-stories-of-customer-transformation-and-innovation/",{"kpi":60,"value":240,"unit":233,"qualifier":234,"baseline":241,"claimant":236,"quote":237,"sourceUrl":238},55,"time spent in the audit reporting phase before AILA",true,[244],{"url":238,"title":245,"publisher":246,"date":247},"AI-powered success, with more than 1,000 stories of customer transformation and innovation","Microsoft Cloud Blog","2025-07-24",{"level":249,"checkedAt":206},"source-verified","C","banco-bradesco-aila-audit-assistant",null,{"title":254,"useCases":255,"organization":256,"vendors":260,"summary":263,"stage":225,"year":226,"channels":264,"languages":265,"metrics":267,"outcomeDisclosed":242,"sources":272,"verification":274,"grade":250,"id":275,"organizationSlug":252},"British Columbia Investment Management Corporation: automation cuts internal audit report writing time",[210],{"name":257,"anonymized":217,"country":258,"region":259,"industry":22},"British Columbia Investment Management Corporation","CA","north-america",[261],{"name":262,"role":223},"Microsoft (Microsoft 365 Copilot and Azure)","BCI uses Microsoft 365 Copilot and the Azure ecosystem to automate manual tasks across its operations. Among the outcomes Microsoft reports is less time spent writing internal audit reports; the source does not say which tool produced that result. The organization wide productivity figures on the same page are not specific to audit and are not recorded here.",[34],[266],"en",[268],{"kpi":60,"value":269,"unit":233,"qualifier":234,"baseline":270,"claimant":236,"quote":271,"sourceUrl":238},30,"time spent writing internal audit reports before the automation","The organization saved more than 2,300 person-hours through automation, reduced the time spent on writing internal audit reports by 30%, and saved a month of processing time to analyze 8,000 survey comments.",[273],{"url":238,"title":245,"publisher":246,"date":247},{"level":249,"checkedAt":206},"bci-copilot-internal-audit-reports",{"title":277,"useCases":278,"organization":279,"vendors":281,"summary":284,"stage":225,"year":226,"channels":285,"languages":286,"metrics":287,"outcomeDisclosed":242,"sources":291,"verification":293,"grade":250,"id":294,"organizationSlug":252},"XP Inc.: Microsoft 365 Copilot for the audit team",[210],{"name":280,"anonymized":217,"country":218,"region":219,"industry":21},"XP Inc.",[282],{"name":283,"role":223},"Microsoft (Microsoft 365 Copilot)","XP Inc. uses Microsoft 365 Copilot to automate tasks across the company, and Microsoft reports a gain in audit team efficiency alongside total hours saved. The hours figure is company wide; how efficiency was measured is not published.",[34],[229],[288],{"kpi":58,"value":269,"unit":233,"qualifier":234,"baseline":289,"claimant":236,"quote":290,"sourceUrl":238},"audit team efficiency before Copilot","XP Inc. uses leverages Microsoft 365 Copilot to automate tasks, significantly boosting productivity by saving more than 9,000 hours and increasing audit team efficiency by 30%.",[292],{"url":238,"title":245,"publisher":246,"date":247},{"level":249,"checkedAt":206},"xp-inc-copilot-audit-team",0,[297,305],{"kpi":60,"label":298,"unit":233,"aggregate":242,"higherIsBetter":242,"n":299,"nUpTo":295,"median":300,"min":269,"max":240,"byClaimant":301,"vendorOnly":242,"points":302},"Handling time reduction",2,42.5,{"organization":295,"vendor":299,"regulator":295,"independent":295},[303,304],{"evidenceId":251,"organization":216,"value":240,"qualifier":234,"claimant":236,"grade":250,"pooled":242},{"evidenceId":275,"organization":257,"value":269,"qualifier":234,"claimant":236,"grade":250,"pooled":242},{"kpi":58,"label":306,"unit":233,"aggregate":242,"higherIsBetter":242,"n":299,"nUpTo":295,"median":307,"min":269,"max":232,"byClaimant":308,"vendorOnly":242,"points":309},"Productivity gain",47.5,{"organization":295,"vendor":299,"regulator":295,"independent":295},[310,311],{"evidenceId":251,"organization":216,"value":232,"qualifier":234,"claimant":236,"grade":250,"pooled":242},{"evidenceId":294,"organization":280,"value":269,"qualifier":234,"claimant":236,"grade":250,"pooled":242},{"low":313,"high":314},236250,1382400,[316,336,351,364,376],{"slug":201,"title":317,"shortTitle":318,"definition":319,"status":9,"industries":320,"functions":321,"patterns":323,"audience":326,"autonomy":327,"adoptionStage":328,"segment":329,"evidenceCount":330,"publicEvidenceCount":330,"organizations":331,"bestGrade":335,"headline":252,"lastVerified":206,"indexable":242},"AI for continuous controls testing and control self assessment","Continuous controls testing","AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.",[17,18,19,21,20],[24,25,322],"operations",[324,31,32,325],"agentic-workflow","classification-and-routing","back-office","supervised-agent","emerging","second-line",3,[332,333,334],"Federal Deposit Insurance Corporation","U.S. Department of the Interior","Pension Benefit Guaranty Corporation","B",{"slug":202,"title":337,"shortTitle":338,"definition":339,"status":9,"industries":340,"functions":342,"patterns":344,"audience":36,"autonomy":37,"adoptionStage":38,"evidenceCount":345,"publicEvidenceCount":345,"organizations":346,"bestGrade":335,"headline":252,"lastVerified":206,"indexable":242},"AI system and model inventory with shadow AI discovery","AI model inventory","A governed register of every AI system and model an organization builds, buys or uses, with its owner, purpose, data, risk tier and approval status, kept current by AI that discovers unregistered use, reads the documentation and assembles the evidence a board, auditor or supervisor asks for.",[17,18,19,20,341],"manufacturing",[24,25,343],"it-and-engineering",[324,31,28,325],4,[347,348,349,350],"Board of Governors of the Federal Reserve System","Office of Management and Budget","Unilever","U.S. Department of Justice",{"slug":203,"title":352,"shortTitle":353,"definition":354,"status":9,"industries":355,"functions":356,"patterns":359,"audience":36,"autonomy":37,"adoptionStage":328,"segment":329,"evidenceCount":330,"publicEvidenceCount":330,"organizations":360,"bestGrade":335,"headline":252,"lastVerified":363,"indexable":242},"AI for policy drafting and policy gap analysis","Policy drafting and gaps","An assistant that takes a new or changed obligation, finds every internal policy, standard and procedure it touches, flags clauses that now conflict or are silent, and drafts the updated wording in house style as a redline for the policy owner to approve.",[17,18,19,21,20],[25,357,358],"legal","knowledge-management",[28,30,31,29],[332,361,362],"Administration for Children and Families","Health Resources and Services Administration","2026-09-26",{"slug":204,"title":365,"shortTitle":366,"definition":367,"status":9,"industries":368,"functions":370,"patterns":372,"audience":36,"autonomy":37,"adoptionStage":328,"segment":329,"evidenceCount":330,"publicEvidenceCount":330,"organizations":373,"bestGrade":335,"headline":252,"lastVerified":206,"indexable":242},"AI for supervisory exam and information request responses","Exam response assembly","An assistant for the bank's regulatory affairs team that reads a supervisory information request or exam question, retrieves the relevant evidence, policies and prior correspondence, drafts a response for legal and compliance to approve, and tracks every commitment and remediation action through to closure.",[18,19,21,369],"payments",[25,357,371],"case-management",[28,30,31,324],[374,375],"U.S. Department of Homeland Security","Federal Emergency Management Agency",{"slug":205,"title":377,"shortTitle":378,"definition":379,"status":9,"industries":380,"functions":384,"patterns":386,"audience":36,"autonomy":389,"adoptionStage":38,"evidenceCount":330,"publicEvidenceCount":330,"organizations":390,"bestGrade":335,"headline":252,"lastVerified":206,"indexable":242},"Governed text to SQL analytics assistant","Governed SQL analytics","An assistant that turns a business user's plain language question into a query against governed data, runs it under that user's own data permissions and returns the table or chart together with the SQL and the tables used, so routine ad hoc questions no longer queue for the data team.",[17,18,19,381,382,383],"retail-and-ecommerce","technology","pharma-and-life-sciences",[385,343],"analytics-and-reporting",[387,388,28],"conversational-agent","code-generation","assist",[391,392,393],"Bayer","LinkedIn","Uber Technologies",{"indexable":242,"reasons":395},[],[397,404,409,415,421,426,433,440,448,455,462,468,475,482,488,493,500,506,512,518,524,530,536,541,546,553,560,565,571,579,585,591,597,602],{"id":169,"label":398,"issuer":399,"region":400,"url":401,"description":402,"useCases":403,"indexable":242},"EU AI Act","European Union","europe","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":170,"label":405,"issuer":399,"region":400,"url":406,"description":407,"useCases":408,"indexable":242},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":171,"label":410,"issuer":411,"region":178,"url":412,"description":413,"useCases":414,"indexable":242},"ISO/IEC 42001","ISO and IEC","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":172,"label":416,"issuer":417,"region":259,"url":418,"description":419,"useCases":420,"indexable":242},"NIST AI Risk Management Framework","NIST","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":173,"label":422,"issuer":399,"region":400,"url":423,"description":424,"useCases":425,"indexable":242},"DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":427,"label":428,"issuer":429,"region":400,"url":430,"description":431,"useCases":432,"indexable":242},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":434,"label":435,"issuer":436,"region":400,"url":437,"description":438,"useCases":439,"indexable":242},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":441,"label":442,"issuer":443,"region":444,"url":445,"description":446,"useCases":447,"indexable":242},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":449,"label":450,"issuer":451,"region":444,"url":452,"description":453,"useCases":454,"indexable":242},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":456,"label":457,"issuer":458,"region":178,"url":459,"description":460,"useCases":461,"indexable":242},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",20,{"id":463,"label":464,"issuer":465,"region":259,"url":466,"description":467,"useCases":461,"indexable":242},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":469,"label":470,"issuer":471,"region":400,"url":472,"description":473,"useCases":474,"indexable":242},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":476,"label":477,"issuer":478,"region":178,"url":479,"description":480,"useCases":481,"indexable":242},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":483,"label":484,"issuer":399,"region":400,"url":485,"description":486,"useCases":487,"indexable":242},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":489,"label":490,"issuer":399,"region":400,"url":491,"description":492,"useCases":487,"indexable":242},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":494,"label":495,"issuer":496,"region":259,"url":497,"description":498,"useCases":499,"indexable":242},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":501,"label":502,"issuer":399,"region":400,"url":503,"description":504,"useCases":505,"indexable":242},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":507,"label":508,"issuer":509,"region":259,"url":510,"description":511,"useCases":505,"indexable":242},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":513,"label":514,"issuer":515,"region":178,"url":516,"description":517,"useCases":505,"indexable":242},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":519,"label":520,"issuer":399,"region":400,"url":521,"description":522,"useCases":523,"indexable":242},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":525,"label":526,"issuer":527,"region":259,"url":528,"description":529,"useCases":523,"indexable":242},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":531,"label":532,"issuer":443,"region":444,"url":533,"description":534,"useCases":535,"indexable":242},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",10,{"id":537,"label":538,"issuer":399,"region":400,"url":539,"description":540,"useCases":535,"indexable":242},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":542,"label":543,"issuer":399,"region":400,"url":544,"description":545,"useCases":535,"indexable":242},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":547,"label":548,"issuer":549,"region":400,"url":550,"description":551,"useCases":552,"indexable":242},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":554,"label":555,"issuer":556,"region":259,"url":557,"description":558,"useCases":559,"indexable":242},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",8,{"id":561,"label":562,"issuer":399,"region":400,"url":563,"description":564,"useCases":559,"indexable":242},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":566,"label":567,"issuer":399,"region":400,"url":568,"description":569,"useCases":570,"indexable":242},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",6,{"id":572,"label":573,"issuer":574,"region":575,"url":576,"description":577,"useCases":578,"indexable":242},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",5,{"id":580,"label":581,"issuer":582,"region":400,"url":583,"description":584,"useCases":345,"indexable":242},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":586,"label":587,"issuer":588,"region":400,"url":589,"description":590,"useCases":345,"indexable":242},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":592,"label":593,"issuer":594,"region":444,"url":595,"description":596,"useCases":330,"indexable":242},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":598,"label":599,"issuer":399,"region":400,"url":600,"description":601,"useCases":330,"indexable":242},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":603,"label":604,"issuer":605,"region":259,"url":606,"description":607,"useCases":330,"indexable":242},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598307257]