[{"data":1,"prerenderedAt":626},["ShallowReactive",2],{"uc-merchant-underwriting-and-risk-monitoring":3,"uc-regulations":420},{"useCase":4,"evidence":197,"blitsAiDeployments":312,"benchmarks":313,"indicative":333,"related":336,"indexability":418,"includeUnpublished":202},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":17,"functions":21,"patterns":25,"channels":31,"audience":34,"autonomy":35,"adoptionStage":36,"problem":37,"problemStats":38,"howItWorks":39,"valueDrivers":40,"kpis":46,"indicativeValue":53,"macroEstimates":88,"feasibility":89,"implementation":103,"risk":146,"blitsAi":176,"faq":178,"related":188,"datePublished":192,"dateModified":192,"lastVerified":192,"changelog":193,"slug":196},"AI for merchant underwriting and risk monitoring","Merchant underwriting and monitoring","AI merchant underwriting and risk monitoring","AI screens merchant websites and ranks risky merchants for review. Airwallex reports 50% fewer false positives; Coris reports about 89% fewer daily reviews at Weave.","published","AI that helps acquirers, payment facilitators and software platforms with embedded payments decide which merchants to accept and on what terms, by checking what a business really sells and how risky it is at onboarding, and then watches every active merchant for changes in behaviour, ranking the few that need an analyst so fraud, prohibited trade and credit losses are caught early.",[12,13,14,15,16],"merchant risk AI","merchant onboarding underwriting automation","merchant website screening","merchant portfolio monitoring","PayFac risk automation",[18,19,20],"payments","technology","banking",[22,23,24],"onboarding-and-kyc","fraud-prevention","risk-management",[26,27,28,29,30],"prediction-and-scoring","anomaly-detection","classification-and-routing","summarization","agentic-workflow",[32,33],"internal-tools","api","back-office","supervised-agent","early-adopters","Every merchant accepted for card payments brings risk with it. The merchant may sell something\nthe card schemes or the law prohibit, never ship the goods, launder transactions for another\nbusiness or go out of business with open refunds and chargebacks. Visa requires the acquirer,\nthe financial institution with the direct relationship with the merchant, to run compliance\nchecks before a merchant can accept Visa payments, and the acquirer removes merchants engaged in\nillegal commerce that cannot comply with Visa's rules and applicable law. Visa's Acquirer Monitoring\nProgram, effective April 2025, also consolidates earlier fraud and dispute programs and sets\nfraud thresholds and enumeration criteria for acquirers and their merchants.\n\nThe traditional answer is manual. At onboarding an analyst checks the business registration,\nreads the website, looks up reviews and decides; after onboarding a small team works through\nexports of balances, refunds and chargebacks in spreadsheets. It does not scale: platforms with\nembedded payments sign up thousands of small merchants, keyword screening of websites produces\nmany false alarms, and only a small sample of the portfolio is ever looked at. Coris reports that\nbefore automation only about 3% of Weave's merchants received any manual scrutiny. That leaves\nroom for what Visa describes as merchants who fraudulently conceal the true nature of their\nbusinesses to avoid its compliance requirements.",[],"1. **Collect the application and the footprint.** The system takes the application data and\n   enriches it with business registry records, the merchant's website, online reviews, adverse\n   media and, where relevant, credit data.\n2. **Understand what the merchant sells.** A language model reads the website and product\n   descriptions in context, distinguishes allowed goods from prohibited ones and checks that\n   the declared business and merchant category match what is actually offered.\n3. **Score and decide at onboarding.** A risk score combines identity, footprint and category\n   signals. Low risk merchants are approved automatically within policy; the rest go to an\n   analyst with a summary of the evidence and a proposed decision, such as approve, approve with\n   a reserve or payout delay, request documents, or decline.\n4. **Monitor every active merchant.** Models watch processing behaviour (volume spikes, refunds,\n   chargebacks, negative balances, concentration of card numbers, changes to the website) and\n   score each merchant daily, so analysts start with the riskiest accounts instead of a random\n   sample.\n5. **Act and record.** Analysts decide on payout holds, reserves, outreach or offboarding, with\n   the agent drafting the merchant message and the case note, and every decision is kept for the\n   acquirer, the sponsor bank and the card schemes.",[41,42,43,44,45],"risk-reduction","employee-productivity","speed","compliance","cost-to-serve",[47,48,49,50,51,52],"alert-volume-reduction","false-positive-reduction","detection-rate-improvement","handling-time-reduction","automation-rate","fraud-losses-prevented",{"referenceOrg":54,"inputs":55,"formula":83,"currency":84,"period":85,"resultLabel":86,"caveat":87},"A software platform with embedded payments onboarding 20,000 merchants a year",[56,62,69,76],{"key":57,"label":58,"low":59,"high":59,"unit":60,"note":61},"merchants","New merchant applications per year",20000,"applications per year","The reference platform. Replace with your own application volume.",{"key":63,"label":64,"low":65,"high":66,"unit":67,"note":68},"minutesPerReview","Analyst minutes per manual review today",20,30,"minutes per application","Editorial assumption for web searches, registry checks and a decision. Replace with your own time study.",{"key":70,"label":71,"low":72,"high":73,"unit":74,"note":75},"reviewReduction","Share of manual reviews the AI removes",0.4,0.5,"fraction of reviews","The high end matches Airwallex's early result of 50 percent fewer websites needing a manual check at onboarding. Coris reports 70% fewer manual reviews at Tekmetric and about 89% fewer daily reviews at Weave, but those vendor figures include ongoing monitoring, so they are not used as the ceiling.",{"key":77,"label":78,"low":79,"high":80,"unit":81,"note":82},"costPerHour","Fully loaded risk analyst cost per hour",40,70,"USD per hour","Editorial assumption, replace with your own.","merchants * minutesPerReview / 60 * reviewReduction * costPerHour","USD","per year","Onboarding review effort avoided","Onboarding labour only. It leaves out the fraud and credit losses prevented by catching bad merchants earlier, the effort saved in ongoing monitoring, faster activation of good merchants, fewer breaches of card scheme thresholds, and the cost of the data sources, the models and the integration.",[],{"complexity":90,"complexityNote":91,"dataPrerequisites":92,"integrations":97},"medium","Scoring and website review can start on application data and public sources with little integration. The harder part is ongoing monitoring, which needs processing data from every acquirer or processor the platform uses, and a clear risk policy that says which score leads to which action.",[93,94,95,96],"A written risk appetite with prohibited and restricted categories and the action per risk level","Historical merchant applications with outcomes (approved, declined, later terminated, losses)","Processing data per merchant (volumes, refunds, chargebacks, balances, payouts)","Access to business registry, credit and adverse media data sources",[98,99,100,101,102],"Onboarding or application system","Payment processor or acquirer APIs and dashboards (for example connected account data)","Payout and reserve controls","Case management or CRM for analyst reviews and merchant outreach","Messaging or ticketing tool for merchant communication",{"steps":104,"guardrails":120,"humanInTheLoop":126,"kpisToInstrument":127,"failureModes":133},[105,108,111,114,117],{"title":106,"detail":107},"Write the policy before the model","Agree the prohibited and restricted categories, the risk levels and the action for each (approve, reserve, delay payouts, request documents, decline) with the sponsor bank or acquirer. The AI applies the policy; it does not invent it.",{"title":109,"detail":110},"Start with website and category screening","Let the model read the merchant's website and product descriptions and compare them with the declared business. Keyword rules on websites produce many false alarms, and Airwallex reports that its generative AI website scanner halved them in early results.",{"title":112,"detail":113},"Run in parallel before you switch","Score new applications and the existing portfolio alongside the current manual process for a few weeks, compare decisions and losses, and tune thresholds before the AI queue becomes the primary one.",{"title":115,"detail":116},"Extend to the whole portfolio","Monitor every active merchant daily, not a sample, and rank the queue by risk so analysts start with the top decile. Add automated actions such as payout holds only for clear, high confidence signals, with an analyst review the same day.",{"title":118,"detail":119},"Feed outcomes back","Label every decision with its outcome (losses, chargebacks, terminations) and use the labels to retrain and to prune rules that only add noise.",[121,122,123,124,125],"Declines, terminations and reserves above a set level always need an analyst decision","Every score comes with the evidence behind it, so the analyst and the merchant can be told why","Website and document content is treated as data, never as instructions to the model","Sole traders' personal data is limited to what the risk policy needs, and masked in prompts and logs","Regular checks that approval and decline rates do not differ unfairly between comparable merchant groups","Analysts decide every decline, termination and material reserve or payout hold, and review a sample of automatic approvals each week. The risk policy owner approves every change to categories, thresholds or automated actions, and the sponsor bank or acquirer can audit the decisions.",[128,129,130,131,132],"Share of applications approved automatically and time from application to approval","Manual reviews per week and share of reviews that lead to an action","False positive rate of website and category screening","Losses from merchants terminated for fraud or credit, per 1,000 merchants onboarded","Chargeback and fraud ratios against the card scheme thresholds",[134,137,140,143],{"title":135,"detail":136},"Fraudsters who look good on paper","Generated websites, fake reviews and borrowed business identities pass a one time check. Keep monitoring after onboarding and watch for website and behaviour changes.",{"title":138,"detail":139},"Automatic declines of good small businesses","Thin footprints and unusual categories push legitimate merchants into declines. Route uncertain cases to an analyst and track appeals.",{"title":141,"detail":142},"Rules and models that fight each other","Rules added on top of the score without review double the alert volume. Review the combined queue and remove rules that do not change decisions.",{"title":144,"detail":145},"A queue that nobody trusts","Analysts ignore scores they cannot explain. Show the drivers and the evidence with every score.",{"euAiAct":147,"regulations":150,"guidance":158,"controls":169,"incidents":175},{"tier":148,"basis":149},"context-dependent","Assessing businesses and detecting fraud is not an Annex III use as such, and Annex III point 5(b) excludes systems used to detect financial fraud. If the system evaluates the creditworthiness of a natural person, for example a sole trader applying to accept payments, it can fall under Annex III point 5(b), which covers evaluating the creditworthiness of natural persons or establishing their credit score, and be high risk. Keep credit assessment of individuals separate or treat it as a high risk system.",[151,152,153,154,155,156,157],"eu-ai-act","gdpr","pci-dss","eu-amlr","fatf-recommendations","us-bsa","dora",[159,165],{"title":160,"issuer":161,"region":162,"url":163,"note":164},"Introducing the Visa Acquirer Monitoring Program","Visa","global","https://corporate.visa.com/en/sites/visa-perspectives/security-trust/introducing-visa-acquirer-monitoring-program.html","Visa's acquirer program, effective April 2025, consolidates earlier fraud and dispute programs and sets fraud thresholds and enumeration criteria for acquirers and their merchants.",{"title":166,"issuer":161,"region":162,"url":167,"note":168},"Visa Network Integrity","https://corporate.visa.com/en/about-visa/visa-network-integrity.html","Describes how Visa monitors acquirers in high risk categories and how acquirers must remove merchants engaged in illegal commerce.",[170,171,172,173,174],"Documented risk policy with prohibited categories, thresholds and approved automated actions","Model inventory entry, validation and drift monitoring for the scoring models","Audit trail of every score, the evidence shown and the decision taken, per merchant","Periodic fairness and outcome review of approvals, declines and terminations","Oversight by the sponsor bank or acquirer, including access to decisions and samples",[],{"howToBuild":177},"On Blits.ai the merchant review is an **agentic workflow** that the onboarding system starts\nthrough the API for each application, and that runs on a schedule for portfolio checks. The\nagent uses built in **web page browsing** and **web search** to read the merchant's website and\nfootprint, **custom functions** to call registry, processor and internal systems through REST\nor SQL, and a **knowledge base** with hybrid retrieval that holds the risk policy and the\nprohibited category list. It returns a decision proposal with the evidence as **structured\noutput**.\n\n**Human in the loop approval** holds declines, terminations and payout holds above a set level\nfor an analyst, and the **tool execution policy** limits which actions the agent may take on its\nown. **Guardrails** and **PII masking** protect sole traders' personal data, every run has a\n**full audit trail**, and **test suites** evaluate the workflow against labelled historical applications before any\nchange to the policy or the model goes live. The platform is model agnostic, so the risk team can\npick the model per agent.",[179,182,185],{"question":180,"answer":181},"What does generative AI add to merchant underwriting?","Reading websites and documents in context. Airwallex says its generative AI website scanner can better distinguish a retailer selling a military style jacket from a merchant selling prohibited military goods, and that early results from its own internal analysis show 50 percent fewer false positives on average than its earlier rules based model.",{"question":183,"answer":184},"Is monitoring after onboarding really needed?","Yes. A check at signup only sees what the merchant chooses to show, and Visa says some merchants conceal the true nature of their businesses to avoid compliance requirements. Coris reports that Weave went from manual scrutiny of about 3% of merchants to automated checks across nearly all merchants with meaningful volume, while cutting daily reviews by about 89%. Visa says that, using its AI tools and machine learning models, it saw a fivefold increase in acquirer remediation and terminations for merchant noncompliance between 2020 and 2024.",{"question":186,"answer":187},"Can the AI decline merchants on its own?","It should not decline or terminate on its own. Let it approve clear low risk cases within policy and send everything else, with the evidence, to an analyst. If the assessment covers the creditworthiness of a sole trader, check whether it is high risk under the EU AI Act.",[189,190,191],"business-onboarding-and-ubo-discovery","chargeback-and-representment","real-time-fraud-scoring","2026-09-27",[194],{"date":192,"note":195},"First published","merchant-underwriting-and-risk-monitoring",[198,230,257,287],{"title":199,"useCases":200,"organization":201,"vendors":204,"summary":207,"stage":208,"year":209,"channels":210,"languages":211,"metrics":213,"outcomeDisclosed":222,"sources":223,"verification":225,"grade":227,"id":228,"organizationSlug":229},"Visa: AI and machine learning to find merchants breaking network rules",[196],{"name":161,"anonymized":202,"country":203,"region":162,"industry":18},false,"US",[205],{"name":161,"role":206},"in-house","Visa monitors merchant activity across its network for illegal commerce and acts through the acquirer that holds the merchant relationship; acquirers must remove merchants that cannot comply with Visa's rules and applicable law. Visa says that, using its AI tools and machine learning models, it saw a fivefold increase in acquirer remediation and terminations for merchant noncompliance between 2020 and 2024. Visa also monitors acquirers that serve high risk categories to check that their controls work.","scaled",2024,[32],[212],"en",[214],{"kpi":49,"value":215,"unit":216,"qualifier":217,"period":218,"baseline":219,"claimant":220,"quote":221,"sourceUrl":167},5,"multiplier","exact","2020 to 2024; counts acquirer remediation and termination actions, a proxy for detection rather than a measured detection rate","acquirer remediation and terminations for merchant noncompliance in 2020","organization","Using our AI tools and machine learning models, we have seen a 5x increase in acquirer remediation and terminations for merchant noncompliance between 2020 and 2024.",true,[224],{"url":167,"title":166,"publisher":161},{"level":226,"checkedAt":192},"source-verified","B","visa-network-integrity-merchant-monitoring","visa",{"title":231,"useCases":232,"organization":233,"vendors":235,"summary":237,"stage":238,"year":239,"channels":240,"languages":241,"metrics":242,"outcomeDisclosed":222,"sources":250,"verification":254,"grade":227,"id":255,"organizationSlug":256},"Airwallex: generative AI website screening in business onboarding",[196],{"name":234,"anonymized":202,"region":162,"industry":18},"Airwallex",[236],{"name":234,"role":206},"Airwallex, a global payments and financial platform for businesses, announced in December 2023 early results from a generative AI tool it uses in its know your customer and onboarding process. The tool scans new customers' websites to check what they really sell and whether it fits Airwallex's acceptable use policies. Compared with its earlier rules based and NLP scanner, Airwallex says the model can better distinguish, for example, a retailer selling a military style jacket from a merchant selling prohibited military goods. Early results from Airwallex's internal analysis show 50 percent fewer false positives on average and 20 percent more customers passing through onboarding without human intervention.","production",2023,[32],[212],[243],{"kpi":48,"value":244,"unit":245,"qualifier":217,"period":246,"baseline":247,"claimant":220,"quote":248,"sourceUrl":249},50,"percent","early results, website screening in onboarding, against the earlier rules based scanner; Airwallex's footnote defines the reduction as fewer customers whose websites need a manual check for red flags","legacy rules based and NLP website scanner","The new tool reduces ‘false positives’ by 50 percent on average, while boosting the number of customers that pass through the onboarding process without human intervention by 20 percent [1].","https://www.airwallex.com/newsroom/airwallex-improves-customer-onboarding-with-generative-ai",[251],{"url":249,"title":252,"publisher":234,"date":253},"Airwallex improves customer onboarding with generative AI","2023-12-06",{"level":226,"checkedAt":192},"airwallex-generative-ai-website-screening",null,{"title":258,"useCases":259,"organization":260,"vendors":263,"summary":269,"stage":238,"year":270,"channels":271,"languages":273,"metrics":274,"outcomeDisclosed":222,"sources":280,"verification":284,"grade":285,"id":286,"organizationSlug":256},"Tekmetric: AI merchant underwriting and monitoring for Tekmetric Payments",[196],{"name":261,"anonymized":202,"country":203,"region":262,"industry":19},"Tekmetric","north-america",[264,267],{"name":265,"role":266},"Coris","platform",{"name":268,"role":266},"Stripe","Tekmetric, a cloud based auto repair shop management platform, offers Tekmetric Payments on Stripe Connect. It replaced underwriting and monitoring based on static credit reports, spreadsheets and manual emails with the Coris risk platform: every active merchant is scored daily, each alert gets an AI generated recommendation and summary, and onboarding approvals and dispute reminders are sent to merchants automatically. Coris reports 70% fewer manual reviews and faster onboarding.",2025,[32,272],"email",[212],[275],{"kpi":47,"value":80,"unit":245,"qualifier":217,"period":276,"claimant":277,"quote":278,"sourceUrl":279},"manual merchant risk reviews after go live","vendor","Discover how Tekmetric reduced manual risk reviews by 70% and accelerated onboarding with Coris’ AI-driven workflows and real-time monitoring.","https://www.coris.ai/customer/how-tekmetric-automated-merchant-risk-and-cut-manual-reviews-by-70",[281],{"url":279,"title":282,"publisher":265,"archivedUrl":283},"How Tekmetric Automated Merchant Risk and Cut Manual Reviews by 70%","https://web.archive.org/web/20251014133241/https://www.coris.ai/customer/how-tekmetric-automated-merchant-risk-and-cut-manual-reviews-by-70",{"level":226,"checkedAt":192},"C","tekmetric-coris-merchant-risk-automation",{"title":288,"useCases":289,"organization":290,"vendors":292,"summary":295,"stage":238,"year":270,"channels":296,"languages":297,"metrics":298,"outcomeDisclosed":222,"sources":306,"verification":310,"grade":285,"id":311,"organizationSlug":256},"Weave: AI merchant risk triage and monitoring for Weave Payments",[196],{"name":291,"anonymized":202,"country":203,"region":262,"industry":19},"Weave Communications",[293,294],{"name":265,"role":266},{"name":268,"role":266},"Weave, a customer experience and payments software company for dental, optometry, veterinary and other local healthcare practices, runs Weave Payments mainly on Stripe Connect. It replaced manual merchant reviews from spreadsheet exports with the Coris risk platform, which scores merchants and transactions, ranks an alert queue by risk and triggers workflows such as payout pauses and outreach. Coris reports that daily reviews fell from about 80 to 9 or 10 accounts, and that automated checks now cover nearly all merchants with meaningful volume, against about 3% of merchants reviewed manually before.",[32],[212],[299],{"kpi":47,"value":300,"unit":245,"qualifier":301,"period":302,"baseline":303,"claimant":277,"quote":304,"sourceUrl":305},89,"approximately","daily merchant reviews, within a week of switching primary triage to Coris","about 80 accounts reviewed per day before Coris","AI triage cut daily reviews by ~89% (from ~80/day to ~9–10/day), so analysts spend time where judgment matters most.","https://www.coris.ai/customer/how-weave-built-a-modern-ai-powered-risk-program-with-coris",[307],{"url":305,"title":308,"publisher":265,"archivedUrl":309},"How Weave Built a Modern, AI-Powered Risk Program with Coris","https://web.archive.org/web/20251014131437/https://www.coris.ai/customer/how-weave-built-a-modern-ai-powered-risk-program-with-coris",{"level":226,"checkedAt":192},"weave-coris-merchant-risk-monitoring",0,[314,322,328],{"kpi":47,"label":315,"unit":245,"aggregate":222,"higherIsBetter":222,"n":316,"nUpTo":312,"median":317,"min":80,"max":300,"byClaimant":318,"vendorOnly":222,"points":319},"Alert volume reduction",2,79.5,{"organization":312,"vendor":316,"regulator":312,"independent":312},[320,321],{"evidenceId":311,"organization":291,"value":300,"qualifier":301,"claimant":277,"grade":285,"pooled":222},{"evidenceId":286,"organization":261,"value":80,"qualifier":217,"claimant":277,"grade":285,"pooled":222},{"kpi":49,"label":323,"unit":216,"aggregate":222,"higherIsBetter":222,"n":324,"nUpTo":312,"median":215,"min":215,"max":215,"byClaimant":325,"vendorOnly":202,"points":326},"Detection improvement",1,{"organization":324,"vendor":312,"regulator":312,"independent":312},[327],{"evidenceId":228,"organization":161,"value":215,"qualifier":217,"claimant":220,"grade":227,"pooled":222},{"kpi":48,"label":329,"unit":245,"aggregate":222,"higherIsBetter":222,"n":324,"nUpTo":312,"median":244,"min":244,"max":244,"byClaimant":330,"vendorOnly":202,"points":331},"False positive reduction",{"organization":324,"vendor":312,"regulator":312,"independent":312},[332],{"evidenceId":255,"organization":234,"value":244,"qualifier":217,"claimant":220,"grade":227,"pooled":222},{"low":334,"high":335},106666.66666666669,350000,[337,358,371,393],{"slug":189,"title":338,"shortTitle":339,"definition":340,"status":9,"industries":341,"functions":343,"patterns":345,"audience":34,"autonomy":35,"adoptionStage":347,"segment":348,"evidenceCount":349,"publicEvidenceCount":349,"organizations":350,"bestGrade":285,"headline":354,"lastVerified":192,"indexable":222},"AI for business onboarding (KYB) and beneficial ownership discovery","Business onboarding and UBO","An AI agent that builds the know your business (KYB) due diligence file for a new or reviewed corporate client, before any account is opened: it collects registry, incorporation and ownership documents, resolves the entity across sources, maps the ownership chain through holding companies, nominees and trusts to the ultimate beneficial owners, screens the entity and its owners, and presents a risk scored case for a compliance analyst to decide.",[20,18,342],"capital-markets",[22,344],"financial-crime-compliance",[346,30,28,29],"document-processing","emerging","specialized-businesses",3,[351,352,353],"BNY","Incore Bank","M-DAQ Global",{"kpi":51,"label":355,"unit":245,"n":324,"nUpTo":312,"kind":356,"value":357,"qualifier":217,"claimant":220,"organization":351,"vendorReported":202},"Automation rate","reported",25,{"slug":190,"title":359,"shortTitle":360,"definition":361,"status":9,"industries":362,"functions":364,"patterns":367,"audience":34,"autonomy":35,"adoptionStage":36,"segment":34,"evidenceCount":349,"publicEvidenceCount":316,"organizations":369,"bestGrade":227,"headline":256,"lastVerified":192,"indexable":222},"AI for chargeback and representment operations","Chargeback and representment","AI that runs the dispute engine room for issuers, acquirers and merchants: it maps each dispute to the network reason code, gathers the matching evidence, assembles a network compliant chargeback or representment package, drafts the rebuttal, tracks every deadline and processes pre dispute alerts so a refund can be issued before a chargeback lands.",[18,20,363],"retail-and-ecommerce",[365,23,366],"operations","customer-service",[30,346,368,28],"content-generation",[370,161],"GitHub",{"slug":191,"title":372,"shortTitle":373,"definition":374,"status":9,"industries":375,"functions":376,"patterns":377,"audience":34,"autonomy":378,"adoptionStage":379,"segment":380,"evidenceCount":381,"publicEvidenceCount":381,"organizations":382,"bestGrade":227,"headline":389,"lastVerified":192,"indexable":222},"Real time fraud scoring for card and instant payments","Real time fraud scoring","Machine learning that decides in milliseconds, without any conversation, how likely each card authorization and account to account payment is to be fraudulent, combining behavioural, device and network signals, so the bank can approve, challenge or block a payment before the money leaves. Working the resulting alerts and talking to the customer about them are separate use cases.",[20,18],[23],[26,27],"autonomous","mainstream","middle-office",9,[383,384,385,386,387,388,268,161],"ANZ, Commonwealth Bank, NAB, Suncorp Bank and Westpac (BioCatch Trust Australia)","Commonwealth Bank of Australia","Mastercard","NatWest Group","Pay.UK","Revolut",{"kpi":390,"label":391,"unit":245,"n":349,"nUpTo":312,"kind":392,"value":66,"qualifier":217,"claimant":220,"organization":256,"vendorReported":202},"fraud-loss-reduction","Fraud loss reduction","median",{"slug":394,"title":395,"shortTitle":396,"definition":397,"status":9,"industries":398,"functions":401,"patterns":403,"audience":405,"autonomy":406,"adoptionStage":36,"evidenceCount":407,"publicEvidenceCount":215,"organizations":408,"bestGrade":227,"headline":414,"lastVerified":192,"indexable":222},"aiops-incident-triage","AI for IT incident triage and root cause analysis (AIOps)","AIOps incident triage","AI that turns a flood of monitoring alerts into one probable incident, routes it to the right team, proposes likely root causes and remediation from runbooks and past incidents, and drafts the stakeholder updates and the post incident review, while an engineer authorizes every change.",[399,20,19,400,18],"cross-industry","telecommunications",[402,365,24],"it-and-engineering",[27,28,29,404,30],"rag-knowledge-assistant","employee-facing","copilot",6,[409,410,411,412,413],"Google","Meta","Microsoft","Mizuho Financial Group","TD Bank",{"kpi":415,"label":416,"unit":245,"n":349,"nUpTo":312,"kind":392,"value":417,"qualifier":217,"claimant":256,"organization":256,"vendorReported":202},"accuracy","Accuracy",90,{"indexable":222,"reasons":419},[],[421,428,433,440,447,452,459,466,474,480,485,491,498,504,509,514,520,526,532,538,544,550,556,561,566,572,579,584,589,596,603,609,615,620],{"id":151,"label":422,"issuer":423,"region":424,"url":425,"description":426,"useCases":427,"indexable":222},"EU AI Act","European Union","europe","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":152,"label":429,"issuer":423,"region":424,"url":430,"description":431,"useCases":432,"indexable":222},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":434,"label":435,"issuer":436,"region":162,"url":437,"description":438,"useCases":439,"indexable":222},"iso-42001","ISO/IEC 42001","ISO and IEC","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":441,"label":442,"issuer":443,"region":262,"url":444,"description":445,"useCases":446,"indexable":222},"nist-ai-rmf","NIST AI Risk Management Framework","NIST","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":157,"label":448,"issuer":423,"region":424,"url":449,"description":450,"useCases":451,"indexable":222},"DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":453,"label":454,"issuer":455,"region":424,"url":456,"description":457,"useCases":458,"indexable":222},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":460,"label":461,"issuer":462,"region":424,"url":463,"description":464,"useCases":465,"indexable":222},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":467,"label":468,"issuer":469,"region":470,"url":471,"description":472,"useCases":473,"indexable":222},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":475,"label":476,"issuer":477,"region":470,"url":478,"description":479,"useCases":357,"indexable":222},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",{"id":153,"label":481,"issuer":482,"region":162,"url":483,"description":484,"useCases":65,"indexable":222},"PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",{"id":486,"label":487,"issuer":488,"region":262,"url":489,"description":490,"useCases":65,"indexable":222},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":492,"label":493,"issuer":494,"region":424,"url":495,"description":496,"useCases":497,"indexable":222},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":155,"label":499,"issuer":500,"region":162,"url":501,"description":502,"useCases":503,"indexable":222},"FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":154,"label":505,"issuer":423,"region":424,"url":506,"description":507,"useCases":508,"indexable":222},"EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":510,"label":511,"issuer":423,"region":424,"url":512,"description":513,"useCases":508,"indexable":222},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":156,"label":515,"issuer":516,"region":262,"url":517,"description":518,"useCases":519,"indexable":222},"Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":521,"label":522,"issuer":423,"region":424,"url":523,"description":524,"useCases":525,"indexable":222},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":527,"label":528,"issuer":529,"region":262,"url":530,"description":531,"useCases":525,"indexable":222},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":533,"label":534,"issuer":535,"region":162,"url":536,"description":537,"useCases":525,"indexable":222},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":539,"label":540,"issuer":423,"region":424,"url":541,"description":542,"useCases":543,"indexable":222},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":545,"label":546,"issuer":547,"region":262,"url":548,"description":549,"useCases":543,"indexable":222},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":551,"label":552,"issuer":469,"region":470,"url":553,"description":554,"useCases":555,"indexable":222},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",10,{"id":557,"label":558,"issuer":423,"region":424,"url":559,"description":560,"useCases":555,"indexable":222},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":562,"label":563,"issuer":423,"region":424,"url":564,"description":565,"useCases":555,"indexable":222},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":567,"label":568,"issuer":569,"region":424,"url":570,"description":571,"useCases":381,"indexable":222},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",{"id":573,"label":574,"issuer":575,"region":262,"url":576,"description":577,"useCases":578,"indexable":222},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",8,{"id":580,"label":581,"issuer":423,"region":424,"url":582,"description":583,"useCases":578,"indexable":222},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":585,"label":586,"issuer":423,"region":424,"url":587,"description":588,"useCases":407,"indexable":222},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",{"id":590,"label":591,"issuer":592,"region":593,"url":594,"description":595,"useCases":215,"indexable":222},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":597,"label":598,"issuer":599,"region":424,"url":600,"description":601,"useCases":602,"indexable":222},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",4,{"id":604,"label":605,"issuer":606,"region":424,"url":607,"description":608,"useCases":602,"indexable":222},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":610,"label":611,"issuer":612,"region":470,"url":613,"description":614,"useCases":349,"indexable":222},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":616,"label":617,"issuer":423,"region":424,"url":618,"description":619,"useCases":349,"indexable":222},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":621,"label":622,"issuer":623,"region":262,"url":624,"description":625,"useCases":349,"indexable":222},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598300523]