[{"data":1,"prerenderedAt":662},["ShallowReactive",2],{"uc-market-abuse-surveillance-triage":3,"uc-regulations":460},{"useCase":4,"evidence":215,"blitsAiDeployments":353,"benchmarks":354,"indicative":360,"related":363,"indexability":458,"includeUnpublished":221},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":16,"functions":20,"patterns":23,"channels":28,"audience":30,"autonomy":31,"adoptionStage":32,"segment":33,"problem":34,"problemStats":35,"howItWorks":43,"valueDrivers":44,"kpis":49,"indicativeValue":54,"macroEstimates":89,"feasibility":90,"implementation":104,"risk":147,"blitsAi":188,"faq":190,"related":203,"datePublished":209,"dateModified":209,"lastVerified":210,"changelog":211,"slug":214},"AI for market abuse surveillance alert triage","Market abuse surveillance","AI trade surveillance for market abuse alerts","AI gathers the evidence behind each market abuse alert and explains its trigger. In a Nasdaq proof of concept, analysts estimated 33% less investigation time.","published","AI that helps surveillance analysts triage market abuse and conduct alerts, such as spoofing, layering, wash trades, ramping and insider dealing, by gathering the trade, order, news and communications context, explaining in plain language what triggered each alert and drafting the investigation narrative for the analyst to disposition.",[12,13,14,15],"trade surveillance AI","market abuse alert triage","communications surveillance triage","insider dealing detection",[17,18,19],"capital-markets","banking","wealth-and-asset-management",[21,22],"regulatory-compliance","financial-crime-compliance",[24,25,26,27],"anomaly-detection","agentic-workflow","summarization","classification-and-routing",[29],"internal-tools","employee-facing","copilot","early-adopters","second-line","Banks, brokers and trading venues must detect and report suspicious orders and transactions.\nMost surveillance still runs on rules: an order that exceeds a size, moves a price or matches a\npattern raises an alert, and an analyst has to reconstruct what happened before deciding whether\nit is worth a closer look. That reconstruction is the expensive part: pulling the order book,\nrelated trades, the issuer's filings, news around the event and, for conduct cases, the trader's\nemails and chats.\n\nRules produce large volumes of false positives, and subtle manipulation that spans venues,\ninstruments or time zones does not match a single rule. Supervisors also expect firms to prove\nthat their surveillance works: in Market Watch 79 the FCA described alert scenarios that failed\nunnoticed, in one case for over three years, because of faulty alert logic or data that was never\ningested. The result is a team that spends much of its time closing noise, with the hard cases\ngetting less attention than they deserve.",[36,41],{"statement":37,"sourceTitle":38,"sourceUrl":39,"year":40},"1LoD's 2026 Surveillance Benchmarking Survey found that 89% of banks want AI enhanced trade surveillance but only 11% have it, and that 78% want generative AI assistants for analysts while 7% have deployed one.","Banks want AI surveillance but lack the data to run it","https://fintech.global/2026/09/21/banks-want-ai-surveillance-but-lack-the-data-to-run-it/",2026,{"statement":42,"sourceTitle":38,"sourceUrl":39,"year":40},"The same 1LoD survey reports that 93% of banks rate false positives a meaningful drag on surveillance and 52% call them a high challenge, which the survey attributes to fragmented data capture and ageing platforms upstream of the alert stage.","1. **Alert in.** The existing surveillance system (rules or models) raises an alert on an order\n   pattern, a trade ahead of a price move or a flagged message.\n2. **Assemble the context.** An agent pulls the relevant orders and trades, the instrument's\n   price and volume around the event, the issuer's filings and news, the trader's history and\n   prior alerts, and for conduct cases the linked communications.\n3. **Explain the trigger.** The AI states in plain language which behaviour set off the alert\n   and which facts make it more or less suspicious, with a link to each underlying record.\n4. **Score and route.** Alerts are ranked by likely risk; clear false positives are proposed\n   for closure with a reason, and the rest go to an analyst queue.\n5. **Draft the case.** For alerts that go further, the AI drafts the investigation narrative\n   and, where needed, the first version of a suspicious transaction and order report.\n6. **Human disposition.** An analyst reviews, edits and decides every alert. Their decisions\n   and reasons are logged and feed back into tuning.",[45,46,47,48],"compliance","employee-productivity","risk-reduction","speed",[50,51,52,53],"handling-time-reduction","false-positive-reduction","detection-rate-improvement","productivity-gain",{"referenceOrg":55,"inputs":56,"formula":84,"currency":85,"period":86,"resultLabel":87,"caveat":88},"A bank with a markets business raising 40,000 surveillance alerts a year",[57,63,70,77],{"key":58,"label":59,"low":60,"high":60,"unit":61,"note":62},"alerts","Surveillance alerts reviewed per year",40000,"alerts per year","The reference bank. Replace with your own alert volume across trade and communications surveillance.",{"key":64,"label":65,"low":66,"high":67,"unit":68,"note":69},"hoursPerAlert","Analyst hours per alert at first review",0.5,1,"hours per alert","Editorial assumption for gathering evidence and writing the first assessment. Replace with your own time study.",{"key":71,"label":72,"low":73,"high":74,"unit":75,"note":76},"timeSaved","Share of review time saved",0.15,0.3,"fraction of review time","Conservative against the benchmark on this page (in Nasdaq's proof of concept testing, surveillance analysts estimated a 33% reduction in investigation time).",{"key":78,"label":79,"low":80,"high":81,"unit":82,"note":83},"hourlyCost","Fully loaded cost of a surveillance analyst",60,100,"USD per hour","Editorial assumption, replace with your own.","alerts * hoursPerAlert * timeSaved * hourlyCost","USD","per year","Analyst time released from first line alert review","Counts analyst time only. It leaves out the cost of the AI and data work, any change in the number of alerts, and the value of detecting abuse that rules miss, which is the larger prize but hard to price.",[],{"complexity":91,"complexityNote":92,"dataPrerequisites":93,"integrations":98},"high","The AI layer is the easier part. The hard work is complete, reconciled trade, order and communications data with a clear chain of custody, and model governance that a supervisor will accept for a system that clears alerts.",[94,95,96,97],"Complete order and trade records across venues and asset classes, reconciled to source","Communications records (email, chat, voice transcripts) held in original form and linked to traders","Reference data, issuer filings and a news feed with timestamps","A labelled history of past alert dispositions with reasons",[99,100,101,102,103],"Existing trade and communications surveillance platforms (alert source)","Order management and execution systems, market data","Communications archive and voice recording platform","Case management for investigations and suspicious transaction and order reports","Model inventory and model risk management tooling",{"steps":105,"guardrails":121,"humanInTheLoop":127,"kpisToInstrument":128,"failureModes":134},[106,109,112,115,118],{"title":107,"detail":108},"Start with explanation, not auto closure","First give analysts a plain language summary and an evidence pack for every alert. Measure review time and analyst agreement before letting the system propose closures.",{"title":110,"detail":111},"Fix the data before the model","Reconcile order and trade feeds to source and check that every business line and venue is actually monitored. An AI layer on incomplete data reprocesses the same gaps faster.",{"title":113,"detail":114},"Define the closure policy","Write down which alert types may be proposed for closure, the evidence required, the sampling rate for quality checks and who signs off the policy.",{"title":116,"detail":117},"Validate like any surveillance model","Put the triage model through model validation: back testing on past alerts including known true cases, stability over time and a documented explanation of its logic.",{"title":119,"detail":120},"Add communications and cross product views","Once trade triage is trusted, link trade alerts to communications and to related instruments, where rules alone miss the most.",[122,123,124,125,126],"A human analyst dispositions every alert; the AI proposes, it never closes on its own","Every explanation links to the underlying orders, trades and messages it relies on","Random quality sampling of alerts the AI proposed to close, with results reported to compliance","Access to communications data limited by role and logged, with personal data minimised in prompts","Change control and regression tests on known true positive cases for every model or prompt change","Surveillance analysts own every disposition and every escalation to a suspicious transaction and order report. Second line compliance approves the closure policy and reviews quality samples, and model validation signs off the triage model before it goes live and after changes.",[129,130,131,132,133],"Median review time per alert, by alert type","Share of alerts proposed for closure and the analyst agreement rate","True positives found per period, including cases the rules did not flag first","Quality sample findings on closed alerts","Share of alerts with a complete evidence pack",[135,138,141,144],{"title":136,"detail":137},"Confident explanations on missing data","The AI writes a fluent rationale while part of the order flow was never ingested. Check data completeness per venue and show gaps in the evidence pack.",{"title":139,"detail":140},"Automation bias","Analysts accept the suggested disposition without reading the evidence. Track agreement rates, rotate blind reviews and sample closures.",{"title":142,"detail":143},"Tuning away real abuse","Optimising for fewer alerts lowers detection. Always back test on known true cases and report detection alongside false positives.",{"title":145,"detail":146},"Unexplainable to the supervisor","A model that cannot show why it cleared an alert fails regulatory scrutiny. Keep the reasoning and evidence for every alert.",{"euAiAct":148,"regulations":151,"guidance":159,"controls":181,"incidents":187},{"tier":149,"basis":150},"context-dependent","Surveillance of orders and transactions as such is not listed in Annex III. Where the system monitors and evaluates the behaviour of the firm's own staff, in their communications or their trading, it can fall under Annex III point 4(b) (AI used to monitor and evaluate the performance and behaviour of persons in work relationships), so the tier depends on whether the system scores individual employees. Inferring employees' emotions from biometric data such as voice recordings is prohibited in the workplace under Article 5(1)(f).",[152,153,154,155,156,157,158],"eu-ai-act","gdpr","us-sr-11-7","mas-ai-risk-management","iso-42001","eu-mar","mifid-ii",[160,166,170,175],{"title":161,"issuer":162,"region":163,"url":164,"note":165},"Market Abuse Regulation (EU) No 596/2014","European Union","europe","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Article 16 requires firms that arrange or execute transactions to have effective arrangements, systems and procedures to detect and report suspicious orders and transactions.",{"title":167,"issuer":162,"region":163,"url":168,"note":169},"Commission Delegated Regulation (EU) 2016/957","https://eur-lex.europa.eu/eli/reg_del/2016/957/oj","Technical standards for detecting and reporting suspicious orders and transactions, including the duty to keep for five years the analysis of each examined order or transaction and the reasons for submitting or not submitting a STOR.",{"title":171,"issuer":172,"region":163,"url":173,"note":174},"Market Watch 79","Financial Conduct Authority","https://www.fca.org.uk/publications/newsletters/market-watch-79","FCA examples of surveillance failures caused by data ingestion and alert logic issues, and its 2023 peer review of how 9 investment banks test automated surveillance models under UK MAR.",{"title":176,"issuer":177,"region":178,"url":179,"note":180},"Artificial Intelligence (AI) Model Risk Management","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/publications/monographs-or-information-paper/2024/artificial-intelligence-model-risk-management","Good practices MAS observed in its 2024 thematic review of banks' AI and generative AI model risk management, covering governance, oversight, development and deployment; relevant when validating a triage model.",[182,183,184,185,186],"Surveillance model and triage AI registered in the model inventory with an owner and validation status","Documented closure policy approved by compliance, with sampling of AI assisted closures","Data completeness checks per venue, asset class and communications channel","Full audit trail of alert, evidence, AI output, analyst decision and reason","Periodic back testing against known true positive cases",[],{"howToBuild":189},"On Blits.ai this is an **agentic workflow** triggered for each alert from the surveillance\nplatform through the API. **Custom functions** call the order, trade and market data services,\na **SQL knowledge base** exposes the alert and disposition history, and a **knowledge base**\nwith hybrid retrieval holds the surveillance procedures and typologies the explanation must\nfollow. The agent returns **structured output** (trigger, evidence links, risk rank, draft\nnarrative) into the case management system.\n\n**Human in the loop approval** keeps every disposition with the analyst, the **tool execution\npolicy** limits what the agent may read or write, and **PII masking** keeps personal data out of\nprompts where it is not needed. **Test suites** replay past alerts, including known true cases,\non every prompt or model change, and the per run audit trail and execution tracing give model\nvalidation and supervisors the full record. The platform is model agnostic and can run in EU or\nUAE data residency regions.",[191,194,197,200],{"question":192,"answer":193},"Can AI close market abuse alerts on its own?","It should not. The defensible pattern is that the AI assembles evidence, explains the trigger and proposes a disposition, and a named analyst decides. In the EU, Commission Delegated Regulation 2016/957 requires firms to keep, for five years, the analysis of every examined order or transaction and the reasons for reporting it or not, so each closure needs a documented rationale.",{"question":195,"answer":196},"How much analyst time does AI triage save?","Public figures are still few and early. Nasdaq reported that surveillance analysts estimated a 33% reduction in investigation time during proof of concept testing of its generative AI feature. Treat that as an estimate from a pilot and measure your own review times per alert type.",{"question":198,"answer":199},"Is AI surveillance high risk under the EU AI Act?","Surveillance of client orders and transactions generally is not. Monitoring and evaluating the behaviour of the firm's own employees, in their communications or their trading, can fall under Annex III point 4(b), so a design that scores individual staff needs the high risk controls.",{"question":201,"answer":202},"What is the biggest obstacle?","Data. In 1LoD's 2026 Surveillance Benchmarking Survey, 71% of answers on what most hinders surveillance pointed to fragmented, non standardised or poor quality data, and the report says this leaves many AI projects stuck at proof of concept.",[204,205,206,207,208],"aml-alert-triage","call-quality-and-compliance-monitoring","suspicious-activity-report-drafting","model-risk-validation-copilot","continuous-controls-testing","2026-09-27","2026-09-26",[212],{"date":209,"note":213},"First published","market-abuse-surveillance-triage",[216,254,277,302,324],{"title":217,"useCases":218,"organization":219,"vendors":224,"summary":228,"stage":229,"year":230,"channels":231,"languages":232,"metrics":234,"outcomeDisclosed":243,"sources":244,"verification":249,"grade":251,"id":252,"organizationSlug":253},"Nasdaq: generative AI for market abuse alert triage in its surveillance platform",[214],{"name":220,"anonymized":221,"country":222,"region":223,"industry":17},"Nasdaq",false,"US","north-america",[225],{"name":226,"role":227},"Amazon Web Services","platform","Nasdaq added a generative AI feature, built on Amazon Bedrock, to the market surveillance technology it runs for regulators and marketplaces. When an alert fires, the feature gathers and condenses the evidence an analyst needs for the initial assessment, such as a table of the company's regulatory filings, news summaries and sentiment and other mitigating or aggravating factors. The reported gain comes from proof of concept testing, in which analysts estimated the investigation time saved; Nasdaq said it planned to use the feature for its own US equity market surveillance.","pilot",2024,[29],[233],"en",[235],{"kpi":50,"value":236,"unit":237,"qualifier":238,"period":239,"claimant":240,"quote":241,"sourceUrl":242},33,"percent","approximately","proof of concept testing, estimated by surveillance analysts","organization","During proof-of-concept testing, surveillance analysts estimated a 33% reduction in investigation time, with improved overall outcomes.","https://press.aboutamazon.com/aws/2024/5/nasdaq-to-enhance-global-market-surveillance-offering-with-generative-ai",true,[245],{"url":242,"title":246,"publisher":247,"date":248},"Nasdaq to Enhance Global Market Surveillance Offering with Generative AI","Nasdaq (published on the Amazon press center)","2024-05-15",{"level":250,"checkedAt":210},"source-verified","B","nasdaq-market-surveillance-generative-ai",null,{"title":255,"useCases":256,"organization":257,"vendors":260,"summary":261,"stage":262,"year":263,"channels":264,"languages":265,"metrics":266,"outcomeDisclosed":221,"sources":267,"verification":275,"grade":251,"id":276,"organizationSlug":253},"CFTC: machine learning spoofing detection pilot, retired",[214],{"name":258,"anonymized":221,"country":222,"region":223,"industry":259},"Commodity Futures Trading Commission","government",[],"The CFTC Division of Enforcement ran a pilot in 2023 that applied supervised and unsupervised machine learning to order message data to find spoofing patterns, trained with the division's existing expert based spoofing detection algorithms. The model gave a probability of spoofing behaviour for every trader in a given market on a given day. The 2024 federal AI inventory lists the project as retired in April 2024; no results were published.","paused",2023,[29],[233],[],[268,272],{"url":269,"title":270,"publisher":271},"https://github.com/ombegov/2024-Federal-AI-Use-Case-Inventory","2024 Federal Agency AI Use Case Inventory","Office of Management and Budget (GitHub)",{"url":273,"title":274,"publisher":271},"https://raw.githubusercontent.com/ombegov/2024-Federal-AI-Use-Case-Inventory/main/data/2024_consolidated_ai_inventory_raw_v2.csv","2024 consolidated AI inventory (entry Spoofing Detection AI/ML Project)",{"level":250,"checkedAt":210},"cftc-spoofing-detection-pilot",{"title":278,"useCases":279,"organization":280,"vendors":283,"summary":288,"stage":289,"year":290,"channels":291,"languages":292,"metrics":294,"outcomeDisclosed":221,"sources":295,"verification":300,"grade":251,"id":301,"organizationSlug":253},"Japan Exchange Group: AI in preliminary investigations of unfair trading",[214],{"name":281,"anonymized":221,"country":282,"region":178,"industry":17},"Japan Exchange Group","JP",[284,286],{"name":285,"role":227},"NEC Corporation",{"name":287,"role":227},"Hitachi","Japan Exchange Regulation and the Tokyo Stock Exchange put two machine learning systems from NEC and Hitachi into their market surveillance operations on 19 March 2018. The systems were supplied with the knowledge surveillance staff had used to evaluate irregular trading, and help staff finish the preliminary investigation of orders flagged by the criteria based surveillance systems faster, so they can focus on detailed investigations. The decision whether to investigate further stays with surveillance personnel. No outcome figures were published.","production",2018,[29],[293],"ja",[],[296],{"url":297,"title":298,"publisher":281,"date":299},"https://www.jpx.co.jp/english/corporate/news/news-releases/0060/20180319-01.html","Introduction of Artificial Intelligence to Market Surveillance Operations","2018-03-19",{"level":250,"checkedAt":210},"japan-exchange-group-ai-market-surveillance",{"title":303,"useCases":304,"organization":305,"vendors":307,"summary":311,"stage":289,"year":290,"channels":312,"languages":313,"metrics":314,"outcomeDisclosed":221,"sources":315,"verification":322,"grade":251,"id":323,"organizationSlug":253},"US SEC: AI that surfaces accounts trading ahead of material price moves",[214],{"name":306,"anonymized":221,"country":222,"region":223,"industry":259},"U.S. Securities and Exchange Commission",[308],{"name":309,"role":310},"Aretec","integrator","The SEC Division of Enforcement uses a classical machine learning tool, operational since April 2018, to identify accounts whose trading came in advance of material equity price moves and that warrant further investigation. The output is a list of leads for enforcement staff, who decide what to investigate. The entry appears in the 2025 US federal AI use case inventory; no outcome figures are published.",[29],[233],[],[316,319],{"url":317,"title":318,"publisher":271},"https://github.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory","2025 Federal Agency AI Use Case Inventory",{"url":320,"title":321,"publisher":271},"https://raw.githubusercontent.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory/main/Data/2025_individually_reported_AI_use_cases.csv","2025 individually reported AI use cases (entry SEC-34, Single Event Insider Trading Analysis)",{"level":250,"checkedAt":210},"sec-single-event-insider-trading-analysis",{"title":325,"useCases":326,"organization":327,"vendors":330,"summary":333,"stage":334,"year":40,"channels":335,"languages":336,"metrics":337,"outcomeDisclosed":221,"sources":338,"verification":349,"grade":350,"id":351,"organizationSlug":352},"Deutsche Bank: agentic AI for trade and communications surveillance with Google Cloud (reported)",[214],{"name":328,"anonymized":221,"country":329,"region":163,"industry":18},"Deutsche Bank","DE",[331],{"name":332,"role":227},"Google Cloud","According to Bloomberg reporting relayed by trade press in February 2026, Deutsche Bank is working with Google Cloud on AI agents that monitor trading, spot anomalies in orders, trades and market moves and flag them to a human compliance officer, and plans to use the same approach on the communications of client facing staff such as traders and salespeople. AI News adds that Goldman Sachs is exploring agentic surveillance too and that human compliance staff remain responsible for reviewing flagged cases. No bank statement or outcome figure was found.","announced",[29],[233],[],[339,344],{"url":340,"title":341,"publisher":342,"date":343},"https://www.pymnts.com/news/artificial-intelligence/2026/deutsche-bank-google-build-ai-agents-patrol-trading/","Deutsche Bank and Google Build AI Agents to Patrol Trading","PYMNTS","2026-02-25",{"url":345,"title":346,"publisher":347,"date":348},"https://www.artificialintelligence-news.com/news/goldman-sachs-and-deutsche-bank-test-agentic-ai-for-trade-surveillance/","Goldman Sachs and Deutsche Bank test agentic AI for trade surveillance","AI News","2026-02-27",{"level":250,"checkedAt":210},"C","deutsche-bank-agentic-trade-surveillance","deutsche-bank",0,[355],{"kpi":50,"label":356,"unit":237,"aggregate":243,"higherIsBetter":243,"n":67,"nUpTo":353,"median":236,"min":236,"max":236,"byClaimant":357,"vendorOnly":221,"points":358},"Handling time reduction",{"organization":67,"vendor":353,"regulator":353,"independent":353},[359],{"evidenceId":252,"organization":220,"value":236,"qualifier":238,"claimant":240,"grade":251,"pooled":243},{"low":361,"high":362},180000,1200000,[364,392,419,433,447],{"slug":204,"title":365,"shortTitle":366,"definition":367,"status":9,"industries":368,"functions":370,"patterns":371,"audience":30,"autonomy":373,"adoptionStage":32,"segment":374,"evidenceCount":375,"publicEvidenceCount":375,"organizations":376,"bestGrade":251,"headline":385,"lastVerified":209,"indexable":243},"AI for AML transaction monitoring alert triage","AML alert triage","Machine learning and AI agents that score anti money laundering alerts for genuine risk, close clear false positives with a written and stored rationale, and hand investigators the remaining alerts already enriched with the customer, counterparty and transaction context.",[18,369],"payments",[22],[372,24,25,26],"prediction-and-scoring","supervised-agent","middle-office",8,[377,378,379,380,381,382,383,384],"Australia Post","BMO and Amalgamated Bank","HSBC","Nexo","Ratepay","Shift4","United Overseas Bank (UOB)","Uphold",{"kpi":51,"label":386,"unit":237,"n":387,"nUpTo":353,"kind":388,"value":389,"qualifier":390,"claimant":391,"organization":382,"vendorReported":243},"False positive reduction",2,"reported",86,"exact","vendor",{"slug":205,"title":393,"shortTitle":394,"definition":395,"status":9,"industries":396,"functions":402,"patterns":405,"audience":407,"autonomy":373,"adoptionStage":32,"evidenceCount":408,"publicEvidenceCount":408,"organizations":409,"bestGrade":350,"headline":415,"lastVerified":209,"indexable":243},"AI quality and compliance monitoring of every customer interaction","Call quality and compliance","Automated quality assurance that transcribes and scores every customer interaction, voice and chat, against the organization's own rubric, checking required disclosures and script adherence, flagging conduct and mis selling risk, and surfacing coaching opportunities, instead of the small sample a human QA team can review.",[397,18,398,399,400,401],"cross-industry","insurance","energy-and-utilities","telecommunications","retail-and-ecommerce",[403,21,404],"customer-service","operations",[406,27,26],"speech-analytics","back-office",5,[410,411,412,413,414],"British Gas","Central Bank","DoorDash","Oportun","VitalityHealth",{"kpi":416,"label":417,"unit":237,"n":67,"nUpTo":353,"kind":388,"value":418,"qualifier":238,"claimant":391,"organization":410,"vendorReported":243},"quality-score-uplift","Quality score uplift",10,{"slug":206,"title":420,"shortTitle":421,"definition":422,"status":9,"industries":423,"functions":424,"patterns":426,"audience":30,"autonomy":31,"adoptionStage":429,"segment":374,"evidenceCount":430,"publicEvidenceCount":430,"organizations":431,"bestGrade":251,"headline":253,"lastVerified":210,"indexable":243},"AI copilot for SAR and STR narrative drafting","SAR and STR drafting","Generative AI that drafts the narrative of a single suspicious activity or suspicious transaction report from the investigation file (who, what, when, where, why and how), with every fact linked to its source record, so the investigator verifies, edits and files instead of starting from a blank page. It works case by case, unlike the periodic data returns of regulatory reporting.",[18,369],[22,425],"case-management",[427,26,428,25],"content-generation","rag-knowledge-assistant","emerging",4,[432,378,380,384],"Finshark",{"slug":207,"title":434,"shortTitle":435,"definition":436,"status":9,"industries":437,"functions":438,"patterns":440,"audience":30,"autonomy":31,"adoptionStage":429,"segment":33,"evidenceCount":442,"publicEvidenceCount":442,"organizations":443,"bestGrade":251,"headline":253,"lastVerified":446,"indexable":243},"AI copilot for model risk validation and monitoring","Model risk validation","A copilot for independent model validation and review, whether run by a bank's validation function, an external tester or a supervisor, that checks model documentation against the model risk standard, generates and scores challenger tests (for generative AI, often with an LLM as a judge calibrated against human experts), watches production models for drift and drafts and consistency checks the validation report. An accountable validator owns every conclusion.",[18,398,17,19],[439,21],"risk-management",[25,441,427,24],"document-processing",3,[444,445,383],"European Central Bank (ECB Banking Supervision)","Standard Chartered","2026-09-28",{"slug":208,"title":448,"shortTitle":449,"definition":450,"status":9,"industries":451,"functions":452,"patterns":453,"audience":407,"autonomy":373,"adoptionStage":429,"segment":33,"evidenceCount":442,"publicEvidenceCount":442,"organizations":454,"bestGrade":251,"headline":253,"lastVerified":209,"indexable":243},"AI for continuous controls testing and control self assessment","Continuous controls testing","AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.",[397,18,398,17,259],[439,21,404],[25,441,24,27],[455,456,457],"Federal Deposit Insurance Corporation","U.S. Department of the Interior","Pension Benefit Guaranty Corporation",{"indexable":243,"reasons":459},[],[461,466,471,478,485,491,498,504,509,516,523,528,535,542,548,553,560,566,572,578,584,590,595,599,604,611,617,622,628,635,641,647,653,656],{"id":152,"label":462,"issuer":162,"region":163,"url":463,"description":464,"useCases":465,"indexable":243},"EU AI Act","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":153,"label":467,"issuer":162,"region":163,"url":468,"description":469,"useCases":470,"indexable":243},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":156,"label":472,"issuer":473,"region":474,"url":475,"description":476,"useCases":477,"indexable":243},"ISO/IEC 42001","ISO and IEC","global","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":479,"label":480,"issuer":481,"region":223,"url":482,"description":483,"useCases":484,"indexable":243},"nist-ai-rmf","NIST AI Risk Management Framework","NIST","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":486,"label":487,"issuer":162,"region":163,"url":488,"description":489,"useCases":490,"indexable":243},"dora","DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":492,"label":493,"issuer":494,"region":163,"url":495,"description":496,"useCases":497,"indexable":243},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":499,"label":500,"issuer":172,"region":163,"url":501,"description":502,"useCases":503,"indexable":243},"uk-consumer-duty","FCA Consumer Duty","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":155,"label":505,"issuer":177,"region":178,"url":506,"description":507,"useCases":508,"indexable":243},"MAS AI risk management guidelines","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":510,"label":511,"issuer":512,"region":178,"url":513,"description":514,"useCases":515,"indexable":243},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":517,"label":518,"issuer":519,"region":474,"url":520,"description":521,"useCases":522,"indexable":243},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",20,{"id":154,"label":524,"issuer":525,"region":223,"url":526,"description":527,"useCases":522,"indexable":243},"SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":529,"label":530,"issuer":531,"region":163,"url":532,"description":533,"useCases":534,"indexable":243},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":536,"label":537,"issuer":538,"region":474,"url":539,"description":540,"useCases":541,"indexable":243},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":543,"label":544,"issuer":162,"region":163,"url":545,"description":546,"useCases":547,"indexable":243},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":549,"label":550,"issuer":162,"region":163,"url":551,"description":552,"useCases":547,"indexable":243},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":554,"label":555,"issuer":556,"region":223,"url":557,"description":558,"useCases":559,"indexable":243},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":561,"label":562,"issuer":162,"region":163,"url":563,"description":564,"useCases":565,"indexable":243},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":567,"label":568,"issuer":569,"region":223,"url":570,"description":571,"useCases":565,"indexable":243},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":573,"label":574,"issuer":575,"region":474,"url":576,"description":577,"useCases":565,"indexable":243},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":579,"label":580,"issuer":162,"region":163,"url":581,"description":582,"useCases":583,"indexable":243},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":585,"label":586,"issuer":587,"region":223,"url":588,"description":589,"useCases":583,"indexable":243},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":591,"label":592,"issuer":177,"region":178,"url":593,"description":594,"useCases":418,"indexable":243},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",{"id":158,"label":596,"issuer":162,"region":163,"url":597,"description":598,"useCases":418,"indexable":243},"MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":600,"label":601,"issuer":162,"region":163,"url":602,"description":603,"useCases":418,"indexable":243},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":605,"label":606,"issuer":607,"region":163,"url":608,"description":609,"useCases":610,"indexable":243},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":612,"label":613,"issuer":614,"region":223,"url":615,"description":616,"useCases":375,"indexable":243},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",{"id":618,"label":619,"issuer":162,"region":163,"url":620,"description":621,"useCases":375,"indexable":243},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":623,"label":624,"issuer":162,"region":163,"url":625,"description":626,"useCases":627,"indexable":243},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",6,{"id":629,"label":630,"issuer":631,"region":632,"url":633,"description":634,"useCases":408,"indexable":243},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":636,"label":637,"issuer":638,"region":163,"url":639,"description":640,"useCases":430,"indexable":243},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":642,"label":643,"issuer":644,"region":163,"url":645,"description":646,"useCases":430,"indexable":243},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":648,"label":649,"issuer":650,"region":178,"url":651,"description":652,"useCases":442,"indexable":243},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":157,"label":654,"issuer":162,"region":163,"url":164,"description":655,"useCases":442,"indexable":243},"EU Market Abuse Regulation","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":657,"label":658,"issuer":659,"region":223,"url":660,"description":661,"useCases":442,"indexable":243},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598300485]