[{"data":1,"prerenderedAt":623},["ShallowReactive",2],{"uc-model-risk-validation-copilot":3,"uc-regulations":418},{"useCase":4,"evidence":220,"blitsAiDeployments":308,"benchmarks":309,"indicative":310,"related":313,"indexability":416,"includeUnpublished":226},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":18,"functions":23,"patterns":26,"channels":31,"audience":33,"autonomy":34,"adoptionStage":35,"segment":36,"problem":37,"problemStats":38,"howItWorks":49,"valueDrivers":50,"kpis":55,"indicativeValue":60,"macroEstimates":95,"feasibility":96,"implementation":109,"risk":152,"blitsAi":194,"faq":196,"related":209,"datePublished":215,"dateModified":215,"lastVerified":215,"changelog":216,"slug":219},"AI copilot for model risk validation and monitoring","Model risk validation","AI for model risk validation and monitoring","AI checks model documentation, tests generative AI with an LLM judge and drafts reports. See what the ECB runs and what UOB and Standard Chartered piloted.","published","A copilot for independent model validation and review, whether run by a bank's validation function, an external tester or a supervisor, that checks model documentation against the model risk standard, generates and scores challenger tests (for generative AI, often with an LLM as a judge calibrated against human experts), watches production models for drift and drafts and consistency checks the validation report. An accountable validator owns every conclusion.",[12,13,14,15,16,17],"AI model validation assistant","model validation automation","model monitoring and drift detection","LLM evaluation for model risk","LLM as a judge for model validation","AI assisted model review",[19,20,21,22],"banking","insurance","capital-markets","wealth-and-asset-management",[24,25],"risk-management","regulatory-compliance",[27,28,29,30],"agentic-workflow","document-processing","content-generation","anomaly-detection",[32],"internal-tools","employee-facing","copilot","emerging","second-line","Model inventories keep growing: credit, fraud, pricing, stress testing, anti money laundering and\nnow generative AI applications, each needing independent validation before use and periodic\nrevalidation after. Canada's OSFI describes a rapid rise in model applications, amplified by AI\nand machine learning. When validation capacity does not keep pace, backlogs build up and lower\nrisk models wait, or get reviewed with the same depth as critical ones.\n\nMuch validation effort is mechanical: checking that documentation covers every required section,\nrerunning the developer's tests, writing standard sections of the report and chasing monitoring\nresults. Generative AI adds a harder problem: testing open ended outputs at scale for accuracy,\nbias, leakage and robustness. When the US banking agencies replaced SR 11-7 in April 2026, they\nleft generative and agentic AI models outside the scope of the revised guidance because these\nmodels are novel and rapidly evolving, so banks must set those validation standards themselves.",[39,44],{"statement":40,"sourceTitle":41,"sourceUrl":42,"year":43},"Risk.net's 2026 Model Risk Benchmarking study of 44 banks found that banks are automating the testing of generative AI, but scope varies widely: LLM as judge testing offers model testing at scale, but few lenders use it to allow autonomous sign off.","Model Risk Benchmarking 2026 (Risk.net topic page, archived; the article itself is paywalled)","https://web.archive.org/web/20260921001318/https://www.risk.net/topics/model-risk-benchmarking-2026",2026,{"statement":45,"sourceTitle":46,"sourceUrl":47,"year":48},"In the Bank of England and FCA 2024 survey, 46% of responding firms said they have only a partial understanding of the AI technologies they use, largely because of third party models.","Artificial intelligence in UK financial services 2024","https://www.bankofengland.co.uk/report/2024/artificial-intelligence-in-uk-financial-services-2024",2024,"1. **Intake.** The model owner submits the model, its documentation, data and code into the\n   validation workflow; the copilot records it against the inventory entry and risk tier.\n2. **Documentation check.** The copilot reads the documentation and checks it against every\n   requirement of the model risk standard, listing gaps with the missing section and the rule.\n3. **Challenger testing.** It generates test plans, edge cases and scenarios (for generative AI:\n   synthetic inputs, adversarial prompts, grounding and bias test sets) and runs them through\n   approved tooling. For generative AI outputs, an LLM as a judge scores each output against a\n   checklist derived from the requirements (hallucinations, contradictions, completeness, policy\n   compliance), and human experts score a sample on the same scale to calibrate the judge.\n4. **Ongoing monitoring.** For production models it tracks drift, stability and performance\n   against thresholds and flags models due for revalidation.\n5. **Draft the report.** It drafts the standard sections of the validation report with every\n   result linked to its evidence, and checks findings for consistency with earlier reports and\n   similar models.\n6. **Validator decides.** The validator reviews, challenges, adds findings and signs the\n   conclusion. The copilot never approves a model.",[51,52,53,54],"compliance","risk-reduction","employee-productivity","speed",[56,57,58,59],"processing-time-reduction","productivity-gain","time-saved-per-task","accuracy",{"referenceOrg":61,"inputs":62,"formula":90,"currency":91,"period":92,"resultLabel":93,"caveat":94},"A bank that completes 150 model validations and revalidations a year",[63,69,76,83],{"key":64,"label":65,"low":66,"high":66,"unit":67,"note":68},"validations","Validations and revalidations per year",150,"validations per year","The reference bank. Replace with your own validation plan.",{"key":70,"label":71,"low":72,"high":73,"unit":74,"note":75},"hoursPerValidation","Validator hours per validation",80,200,"hours per validation","Editorial assumption; depends heavily on model tier. Replace with your own records.",{"key":77,"label":78,"low":79,"high":80,"unit":81,"note":82},"timeSaved","Share of validator time saved on documentation checks, testing and drafting",0.1,0.25,"fraction of time","Editorial assumption. No public measured benchmark of AI assisted validation was found; keep this conservative.",{"key":84,"label":85,"low":86,"high":87,"unit":88,"note":89},"hourlyCost","Fully loaded cost of a model validator",90,160,"USD per hour","Editorial assumption, replace with your own.","validations * hoursPerValidation * timeSaved * hourlyCost","USD","per year","Validator capacity released","Capacity only. It leaves out the value of clearing the validation backlog sooner, catching drift earlier and the cost of validating the copilot itself, which is a model in the inventory.",[],{"complexity":97,"complexityNote":98,"dataPrerequisites":99,"integrations":104},"high","The copilot touches the core of model governance, must preserve validation independence and is itself subject to model risk management. Integration with model development platforms, data and monitoring is substantial.",[100,101,102,103],"A model inventory with risk tiers, owners and validation history","The model risk standard and documentation templates in machine readable form","Access to model artefacts, test data and production monitoring metrics","Past validation reports and findings to test the copilot against",[105,106,107,108],"Model inventory and model risk management platform","Model development and MLOps platforms (code, data, experiments)","Production monitoring and data quality tooling","Document management for validation reports and evidence",{"steps":110,"guardrails":126,"humanInTheLoop":132,"kpisToInstrument":133,"failureModes":139},[111,114,117,120,123],{"title":112,"detail":113},"Start with documentation completeness","The lowest risk, highest volume task: check documentation against the standard and list gaps. Validators can confirm results quickly, which builds trust.",{"title":115,"detail":116},"Add monitoring triage","Summarise monitoring results across the inventory and flag models breaching thresholds or due for revalidation, so validators spend time where risk moved.",{"title":118,"detail":119},"Generate tests, run them in approved tooling","Let the copilot propose test plans and generative AI test sets, but execute them in the bank's validated tooling and keep the test set under version control.",{"title":121,"detail":122},"Draft report sections last","Only once checks and tests are trusted, draft standard report sections with links to evidence; conclusions and findings stay with the validator.",{"title":124,"detail":125},"Validate the validator","Register the copilot in the model inventory, validate it with a team not using it, and monitor its accuracy against validator decisions.",[127,128,129,130,131],"The accountable validator signs every conclusion; the copilot cannot approve, reject or tier a model","Every statement in a draft links to the test, data or document it rests on","The copilot is an inventoried model with its own validation and monitoring","Model developers cannot configure or prompt the copilot used by the validation team","Test sets and prompts are version controlled and reviewed","Independent validators own every test choice, finding and conclusion, and model risk committees approve models for use. The copilot prepares evidence and drafts; its outputs are reviewed like work from a junior validator.",[134,135,136,137,138],"Validation cycle time by model tier","Validation backlog and overdue revalidations","Documentation gaps found per model, and validator agreement with the copilot's gap list","Time from a monitoring breach to validator review","Share of drafted report text kept after validator review",[140,143,146,149],{"title":141,"detail":142},"Loss of independence","The same AI setup helps build and validate a model, so its blind spots repeat. Separate configurations and owners for development and validation.",{"title":144,"detail":145},"False comfort from generated tests","Generated tests cover what is easy to test, not what matters. Validators must review coverage against the model's use and risks.",{"title":147,"detail":148},"Boilerplate reports","Drafted sections read well but miss model specific issues. Keep findings and conclusions validator written.",{"title":150,"detail":151},"Unvalidated copilot","The copilot is treated as a tool, not a model, and drifts unnoticed. Inventory, validate and monitor it.",{"euAiAct":153,"regulations":156,"guidance":163,"controls":187,"incidents":193},{"tier":154,"basis":155},"minimal","A validation copilot supports internal governance and is not itself an Annex III use, and its drafts are internal, so Article 50 transparency duties do not normally apply. It often helps validate models that are high risk under Annex III (point 5(b), creditworthiness and credit scoring of natural persons; point 5(c), life and health insurance pricing), and the testing and documentation it supports feed the provider obligations of Articles 9, 11 and 15.",[157,158,159,160,161,162],"eu-ai-act","mas-ai-risk-management","nist-ai-rmf","iso-42001","pra-ss1-23","solvency-ii",[164,170,176,181],{"title":165,"issuer":166,"region":167,"url":168,"note":169},"SR 26-2, Revised Guidance on Model Risk Management","Federal Reserve, OCC and FDIC","north-america","https://www.federalreserve.gov/supervisionreg/srletters/SR2602a1.pdf","Issued on 17 April 2026, it supersedes and replaces SR 11-7 and SR 21-8, with a risk based approach to model risk management tailored to each bank's model risk profile. Generative and agentic AI models are explicitly outside its scope; traditional and non generative AI models are covered.",{"title":171,"issuer":172,"region":173,"url":174,"note":175},"SS1/23, Model risk management principles for banks","Prudential Regulation Authority","europe","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","The PRA's expectations for model risk management as a risk discipline in its own right, for UK banks with internal model approval; the PRA has also held a roundtable on model risk management for AI and machine learning.",{"title":177,"issuer":178,"region":167,"url":179,"note":180},"Guideline E-23, Model Risk Management","Office of the Superintendent of Financial Institutions","https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/guideline-e-23-model-risk-management-2027","Canadian model risk management expectations for all federally regulated financial institutions, banks and insurers alike, explicitly covering AI and machine learning models. It takes effect on 1 May 2027.",{"title":182,"issuer":183,"region":184,"url":185,"note":186},"Artificial Intelligence Model Risk Management: observations from a thematic review","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/publications/monographs-or-information-paper/2024/artificial-intelligence-model-risk-management","Good practices observed in a mid 2024 thematic review of banks, including independent validation of higher risk AI before deployment, monitoring for data and model drift, and controls for generative AI.",[188,189,190,191,192],"Copilot registered in the model inventory with its own validation and monitoring","Segregation between development and validation configurations","Evidence links and reviewer sign off for every drafted report section","Periodic comparison of copilot outputs with validator decisions","Version control for test sets, prompts and model versions used",[],{"howToBuild":195},"On Blits.ai this is an **agentic workflow** started per validation, with **custom functions**\nthat read model artefacts, monitoring metrics and test results from the bank's model platforms\nand a **knowledge base** holding the model risk standard, templates and past reports. The agent\nreturns **structured output**: a documentation gap list, a proposed test plan and draft report\nsections with evidence links.\n\nFor generative AI assistants and agents that run on Blits.ai, including the copilot itself,\n**test suites** with deterministic and LLM based grading, multi turn conversation sets and\n**monitors** with scheduled checks can serve as part of the challenger testing and ongoing\nmonitoring. **Human in the loop approval**, **prompt versioning**\nand per run audit trails keep the validator in control and the record complete, and because the\nplatform is model agnostic the validation team can use a different model from the developers.",[197,200,203,206],{"question":198,"answer":199},"Does using AI in validation undermine independence?","It can if the same tools and configurations are used to build and to validate a model. Keep the validation copilot under the validation team's control, validate it like any other model and leave every conclusion with an accountable validator.",{"question":201,"answer":202},"Who uses AI in model validation today?","Adoption is early and partial. Risk.net's 2026 Model Risk Benchmarking study of 44 banks found banks automating the testing of generative AI with widely varying scope, and few lenders using LLM as judge testing to allow autonomous sign off. ECB Banking Supervision runs Medusa, which it describes as an AI application for consistency checks of internal model assessment reports. In Singapore's Global AI Assurance Pilot, PwC tested generative AI tools at Standard Chartered and UOB with an LLM as a judge; none of these published a measured result of the AI assisted checks themselves.",{"question":204,"answer":205},"Can an LLM as a judge replace human validators?","No. In the Standard Chartered pilot the LLM judge let the tester score many outputs against the requirements, but human subject matter experts scored a subset on the same framework to check its calibration, and turning the requirements into judge test prompts took substantial technical effort. In the UOB pilot the judge checked each clause of an answer against retrieved passages of the source document, and scoring rested on ground truths that PwC built and UOB reviewed. Treat the judge as a model in its own right: validate it, version its prompts and keep conclusions with an accountable validator.",{"question":207,"answer":208},"Where should a validation team start?","With documentation completeness checks and monitoring triage, which are high volume and easy to verify, before moving to generated tests and drafted report sections.",[210,211,212,213,214],"ai-model-inventory","alternative-data-credit-scoring","insurance-pricing-and-actuarial-copilot","continuous-controls-testing","market-abuse-surveillance-triage","2026-09-28",[217],{"date":215,"note":218},"First published","model-risk-validation-copilot",[221,255,287],{"title":222,"useCases":223,"organization":224,"vendors":228,"summary":229,"stage":230,"year":231,"channels":232,"languages":233,"metrics":235,"outcomeDisclosed":226,"sources":236,"verification":250,"grade":252,"id":253,"organizationSlug":254},"European Central Bank: Medusa for drafting and consistency checks of internal model assessment reports",[219],{"name":225,"anonymized":226,"region":173,"industry":227},"European Central Bank (ECB Banking Supervision)",false,"government",[],"ECB Banking Supervision built Medusa, a suptech tool it describes as an AI application for intelligent consistency checks of these internal model assessment reports; its June 2023 overview of suptech tools lists Medusa as live, supporting the drafting and consistency checks of those reports. By October 2025 the ECB presented Medusa among its AI tools as a one stop shop for supervisory findings and measures, with smart search, reporting, visualisations and statistical analyses. The supervisors keep the judgement: the ECB stresses that its tools support and do not replace them. It is the supervisor's side of model validation, not a bank's own validation function.","production",2023,[32],[234],"en",[],[237,242,246],{"url":238,"title":239,"publisher":240,"date":241},"https://www.bankingsupervision.europa.eu/press/speeches/date/2023/html/ssm.sp230629~1b6d3ba3d7.en.pdf","The SSM Digitalisation Blueprint","European Central Bank","2023-06-29",{"url":243,"title":244,"publisher":240,"date":245},"https://www.bankingsupervision.europa.eu/press/interviews/date/2024/html/ssm.in240226~c6f7fc9251.en.html","From data to decisions: AI and supervision","2024-02-26",{"url":247,"title":248,"publisher":240,"date":249},"https://www.bankingsupervision.europa.eu/press/speeches/date/2025/html/ssm.sp251014~5bc6e60334.en.html","Artificial intelligence and supervision: innovation with caution","2025-10-14",{"level":251,"checkedAt":215},"source-verified","B","european-central-bank-medusa-internal-model-reports",null,{"title":256,"useCases":257,"organization":258,"vendors":262,"summary":266,"stage":267,"year":268,"channels":269,"languages":270,"metrics":271,"outcomeDisclosed":226,"sources":272,"verification":283,"grade":284,"id":285,"organizationSlug":286},"Standard Chartered: LLM as a judge testing of a generative AI email drafting tool with PwC",[219],{"name":259,"anonymized":226,"country":260,"region":261,"industry":19},"Standard Chartered","GB","global",[263],{"name":264,"role":265},"PwC","integrator","In the AI Verify Foundation's Global AI Assurance Pilot (February to May 2025), PwC acted as independent tester of a generative AI tool Standard Chartered built to draft personalised client emails for wealth relationship managers, a tool that was itself still in an internal pilot. PwC turned the requirements in the tool's system prompts into a structured checklist and ran batch tests on synthetic client profiles and edge cases, using an LLM as a judge to find hallucinations and contradictions against the input data and to score completeness, coherence, engagement and internal compliance, alongside NLP similarity metrics for robustness. Human subject matter experts scored a subset of drafts on the same framework to check that the automated judge was calibrated. The published case study reports the method and the effort involved, not the test results, which it says are confidential.","pilot",2025,[32],[234],[],[273,277,280],{"url":274,"title":275,"publisher":276},"https://assurance.aiverifyfoundation.sg/report/pilot-participants-and-use-cases/","Pilot participants and use cases","AI Verify Foundation",{"url":278,"title":279,"publisher":276},"https://assurance.aiverifyfoundation.sg/wp-content/uploads/2025/05/StanChart-X-PwC-Solutions.pdf","Wealth Relationship Manager Client Engagement Mail: Standard Chartered Bank x PwC",{"url":281,"title":282,"publisher":276},"https://aiverifyfoundation.sg/ai-assurance-pilot/","Global AI Assurance Pilot",{"level":251,"checkedAt":215},"C","standard-chartered-pwc-llm-judge-genai-validation","standard-chartered",{"title":288,"useCases":289,"organization":290,"vendors":293,"summary":295,"stage":267,"year":268,"channels":296,"languages":297,"metrics":298,"outcomeDisclosed":226,"sources":299,"verification":305,"grade":284,"id":306,"organizationSlug":307},"UOB: LLM as a judge testing of an internal generative AI chatbot with PwC",[219],{"name":291,"anonymized":226,"country":292,"region":184,"industry":19},"United Overseas Bank (UOB)","SG",[294],{"name":264,"role":265},"In the AI Verify Foundation's Global AI Assurance Pilot (February to May 2025), PwC tested UOB's internal retrieval augmented generation chatbot, which runs in production for selected staff on Meta Llama 3.1 and answers operational and domain questions from public company documents. The risk assessment focused on model risks. PwC combined rule based scoring for binary and multiple choice questions, embedding similarity for consistency across repeated runs, and LLM based checks of reasoning answers: an LLM split each answer into clauses, an LLM as a judge compared each clause with retrieved passages of the source document to flag contradictions (a clause with no supporting passage counted as a hallucination), and a judge listed the parts of each question left unanswered. Because the production infrastructure was shared with other use cases, outputs were generated manually in a sandbox; because of confidentiality, PwC used its own prompts and ground truths for ten companies, which UOB reviewed. The case study therefore treats the results as a proxy for the production tool and publishes none of them.",[32],[234],[],[300,301,304],{"url":274,"title":275,"publisher":276},{"url":302,"title":303,"publisher":276},"https://assurance.aiverifyfoundation.sg/wp-content/uploads/2025/05/Internal-GenAI-chatbot.pdf","Internal GenAI Chatbot: UOB x PwC",{"url":281,"title":282,"publisher":276},{"level":251,"checkedAt":215},"uob-pwc-llm-judge-genai-chatbot-testing","united-overseas-bank-uob",0,[],{"low":311,"high":312},108000,1200000,[314,335,358,383,396],{"slug":210,"title":315,"shortTitle":316,"definition":317,"status":9,"industries":318,"functions":321,"patterns":323,"audience":33,"autonomy":34,"adoptionStage":326,"evidenceCount":327,"publicEvidenceCount":327,"organizations":328,"bestGrade":252,"headline":254,"lastVerified":333,"indexable":334},"AI system and model inventory with shadow AI discovery","AI model inventory","A governed register of every AI system and model an organization builds, buys or uses, with its owner, purpose, data, risk tier and approval status, kept current by AI that discovers unregistered use, reads the documentation and assembles the evidence a board, auditor or supervisor asks for.",[319,19,20,227,320],"cross-industry","manufacturing",[24,25,322],"it-and-engineering",[27,28,324,325],"rag-knowledge-assistant","classification-and-routing","early-adopters",4,[329,330,331,332],"Board of Governors of the Federal Reserve System","Office of Management and Budget","Unilever","U.S. Department of Justice","2026-09-27",true,{"slug":211,"title":336,"shortTitle":337,"definition":338,"status":9,"industries":339,"functions":341,"patterns":344,"audience":347,"autonomy":348,"adoptionStage":326,"segment":349,"evidenceCount":350,"publicEvidenceCount":350,"organizations":351,"bestGrade":252,"headline":254,"lastVerified":357,"indexable":334},"AI credit scoring with alternative data for thin file applicants","Alternative data credit scoring","A machine learning credit model that adds consumer permissioned alternative data, such as bank account cash flow, rent, utility and telco payments or ecosystem data, to credit bureau data, so a lender can assess applicants with thin or no credit files and return a decision with specific reasons.",[19,340],"payments",[342,343,24],"lending-and-credit","underwriting",[345,28,346],"prediction-and-scoring","conversational-agent","back-office","supervised-agent","lending",5,[352,353,354,355,356],"Atlanticus","Golden 1 Credit Union","GXS Bank","Patelco Credit Union","Upstart Network","2026-09-26",{"slug":212,"title":359,"shortTitle":360,"definition":361,"status":9,"industries":362,"functions":363,"patterns":366,"audience":33,"autonomy":34,"adoptionStage":326,"segment":369,"evidenceCount":350,"publicEvidenceCount":350,"organizations":370,"bestGrade":252,"headline":376,"lastVerified":357,"indexable":334},"AI copilot for insurance pricing and actuarial analysis","Pricing and actuarial copilot","AI that speeds up the work of pricing and actuarial teams, from automated, transparent risk and demand model building to natural language analysis of rate filings, experience data and reserving diagnostics, while actuaries select the models, sign off the rates and own the professional judgment.",[20],[364,24,365],"product-and-pricing","analytics-and-reporting",[345,367,27,368],"code-generation","summarization","pricing",[371,372,373,374,375],"Accelerant Holdings","Europ Assistance","Generali France","Kinsale Capital Group","MAIF",{"kpi":57,"label":377,"unit":378,"n":379,"nUpTo":308,"kind":380,"value":350,"qualifier":381,"claimant":382,"organization":373,"vendorReported":226},"Productivity gain","multiplier",1,"reported","exact","organization",{"slug":213,"title":384,"shortTitle":385,"definition":386,"status":9,"industries":387,"functions":388,"patterns":390,"audience":347,"autonomy":348,"adoptionStage":35,"segment":36,"evidenceCount":391,"publicEvidenceCount":391,"organizations":392,"bestGrade":252,"headline":254,"lastVerified":333,"indexable":334},"AI for continuous controls testing and control self assessment","Continuous controls testing","AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.",[319,19,20,21,227],[24,25,389],"operations",[27,28,30,325],3,[393,394,395],"Federal Deposit Insurance Corporation","U.S. Department of the Interior","Pension Benefit Guaranty Corporation",{"slug":214,"title":397,"shortTitle":398,"definition":399,"status":9,"industries":400,"functions":401,"patterns":403,"audience":33,"autonomy":34,"adoptionStage":326,"segment":36,"evidenceCount":350,"publicEvidenceCount":350,"organizations":404,"bestGrade":252,"headline":410,"lastVerified":357,"indexable":334},"AI for market abuse surveillance alert triage","Market abuse surveillance","AI that helps surveillance analysts triage market abuse and conduct alerts, such as spoofing, layering, wash trades, ramping and insider dealing, by gathering the trade, order, news and communications context, explaining in plain language what triggered each alert and drafting the investigation narrative for the analyst to disposition.",[21,19,22],[25,402],"financial-crime-compliance",[30,27,368,325],[405,406,407,408,409],"Commodity Futures Trading Commission","Deutsche Bank","Japan Exchange Group","Nasdaq","U.S. Securities and Exchange Commission",{"kpi":411,"label":412,"unit":413,"n":379,"nUpTo":308,"kind":380,"value":414,"qualifier":415,"claimant":382,"organization":408,"vendorReported":226},"handling-time-reduction","Handling time reduction","percent",33,"approximately",{"indexable":334,"reasons":417},[],[419,425,431,437,443,449,456,463,468,475,482,488,495,502,508,513,520,526,532,538,544,550,556,561,566,573,580,584,590,597,600,606,612,617],{"id":157,"label":420,"issuer":421,"region":173,"url":422,"description":423,"useCases":424,"indexable":334},"EU AI Act","European Union","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":426,"label":427,"issuer":421,"region":173,"url":428,"description":429,"useCases":430,"indexable":334},"gdpr","GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":160,"label":432,"issuer":433,"region":261,"url":434,"description":435,"useCases":436,"indexable":334},"ISO/IEC 42001","ISO and IEC","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":159,"label":438,"issuer":439,"region":167,"url":440,"description":441,"useCases":442,"indexable":334},"NIST AI Risk Management Framework","NIST","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":444,"label":445,"issuer":421,"region":173,"url":446,"description":447,"useCases":448,"indexable":334},"dora","DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":450,"label":451,"issuer":452,"region":173,"url":453,"description":454,"useCases":455,"indexable":334},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":457,"label":458,"issuer":459,"region":173,"url":460,"description":461,"useCases":462,"indexable":334},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":158,"label":464,"issuer":183,"region":184,"url":465,"description":466,"useCases":467,"indexable":334},"MAS AI risk management guidelines","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":469,"label":470,"issuer":471,"region":184,"url":472,"description":473,"useCases":474,"indexable":334},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":476,"label":477,"issuer":478,"region":261,"url":479,"description":480,"useCases":481,"indexable":334},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",20,{"id":483,"label":484,"issuer":485,"region":167,"url":486,"description":487,"useCases":481,"indexable":334},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":489,"label":490,"issuer":491,"region":173,"url":492,"description":493,"useCases":494,"indexable":334},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":496,"label":497,"issuer":498,"region":261,"url":499,"description":500,"useCases":501,"indexable":334},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":503,"label":504,"issuer":421,"region":173,"url":505,"description":506,"useCases":507,"indexable":334},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":509,"label":510,"issuer":421,"region":173,"url":511,"description":512,"useCases":507,"indexable":334},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":514,"label":515,"issuer":516,"region":167,"url":517,"description":518,"useCases":519,"indexable":334},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":521,"label":522,"issuer":421,"region":173,"url":523,"description":524,"useCases":525,"indexable":334},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":527,"label":528,"issuer":529,"region":167,"url":530,"description":531,"useCases":525,"indexable":334},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":533,"label":534,"issuer":535,"region":261,"url":536,"description":537,"useCases":525,"indexable":334},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":539,"label":540,"issuer":421,"region":173,"url":541,"description":542,"useCases":543,"indexable":334},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":545,"label":546,"issuer":547,"region":167,"url":548,"description":549,"useCases":543,"indexable":334},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":551,"label":552,"issuer":183,"region":184,"url":553,"description":554,"useCases":555,"indexable":334},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",10,{"id":557,"label":558,"issuer":421,"region":173,"url":559,"description":560,"useCases":555,"indexable":334},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":562,"label":563,"issuer":421,"region":173,"url":564,"description":565,"useCases":555,"indexable":334},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":567,"label":568,"issuer":569,"region":173,"url":570,"description":571,"useCases":572,"indexable":334},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":574,"label":575,"issuer":576,"region":167,"url":577,"description":578,"useCases":579,"indexable":334},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",8,{"id":162,"label":581,"issuer":421,"region":173,"url":582,"description":583,"useCases":579,"indexable":334},"Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":585,"label":586,"issuer":421,"region":173,"url":587,"description":588,"useCases":589,"indexable":334},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",6,{"id":591,"label":592,"issuer":593,"region":594,"url":595,"description":596,"useCases":350,"indexable":334},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":161,"label":598,"issuer":172,"region":173,"url":174,"description":599,"useCases":327,"indexable":334},"PRA SS1/23 model risk management","UK model risk management principles for banks, covering AI and machine learning models.",{"id":601,"label":602,"issuer":603,"region":173,"url":604,"description":605,"useCases":327,"indexable":334},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":607,"label":608,"issuer":609,"region":184,"url":610,"description":611,"useCases":391,"indexable":334},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":613,"label":614,"issuer":421,"region":173,"url":615,"description":616,"useCases":391,"indexable":334},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":618,"label":619,"issuer":620,"region":167,"url":621,"description":622,"useCases":391,"indexable":334},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598298182]