[{"data":1,"prerenderedAt":581},["ShallowReactive",2],{"uc-policy-drafting-and-gap-analysis":3,"uc-regulations":377},{"useCase":4,"evidence":207,"blitsAiDeployments":280,"benchmarks":281,"indicative":282,"related":285,"indexability":375,"includeUnpublished":213},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":16,"functions":22,"patterns":26,"channels":31,"audience":33,"autonomy":34,"adoptionStage":35,"segment":36,"problem":37,"problemStats":38,"howItWorks":39,"valueDrivers":40,"kpis":45,"indicativeValue":50,"macroEstimates":85,"feasibility":91,"implementation":104,"risk":147,"blitsAi":183,"faq":185,"related":195,"datePublished":201,"dateModified":201,"lastVerified":202,"changelog":203,"slug":206},"AI for policy drafting and policy gap analysis","Policy drafting and gaps","AI for policy drafting and gap analysis","AI finds the policies a new rule touches, flags gaps and drafts redlines for owner approval. See how HHS ACF flags documents for review, and what it is worth.","published","An assistant that takes a new or changed obligation, finds every internal policy, standard and procedure it touches, flags clauses that now conflict or are silent, and drafts the updated wording in house style as a redline for the policy owner to approve.",[12,13,14,15],"AI policy writing assistant","policy gap analysis AI","regulatory change policy update","policy redlining assistant",[17,18,19,20,21],"cross-industry","banking","insurance","capital-markets","government",[23,24,25],"regulatory-compliance","legal","knowledge-management",[27,28,29,30],"rag-knowledge-assistant","content-generation","document-processing","summarization",[32],"internal-tools","employee-facing","copilot","emerging","second-line","A bank's policy estate is large and layered: group policies, standards, procedures and desk\ninstructions, written by different teams over many years. When a rule changes, someone has to\nfind every document it touches, work out which clauses now conflict or say nothing, and rewrite\nthem consistently. That work is mostly reading and cross referencing, done under deadline by\nspecialists whose time is better spent on judgement.\n\nThe result is predictable: documents that contradict each other, procedures that lag the policy\nthey implement, and wording that differs from team to team. When a supervisor asks how a policy\nimplements a rule, the trail from obligation to clause is often reconstructed after the fact.",[],"1. **Take the obligation.** Start from an obligation already mapped by horizon scanning or legal:\n   the new rule text, its effective date and the business it applies to.\n2. **Find what it touches.** Retrieval over the policy estate returns every policy, standard and\n   procedure that covers the topic, with the relevant clauses.\n3. **Flag gaps and conflicts.** The assistant compares each clause with the obligation and marks\n   it as compliant, conflicting, silent or unclear, quoting both texts.\n4. **Draft the change.** For each gap it drafts replacement or new wording using the approved\n   template and style guide, as a redline, never inventing requirements beyond the source.\n5. **Owner review.** The policy owner edits and approves; legal or compliance signs off where\n   required.\n6. **Keep the trail.** The link from obligation to clause, the drafts and the approvals are\n   stored with the version history.",[41,42,43,44],"compliance","employee-productivity","speed","risk-reduction",[46,47,48,49],"processing-time-reduction","time-saved-per-task","productivity-gain","accuracy",{"referenceOrg":51,"inputs":52,"formula":80,"currency":81,"period":82,"resultLabel":83,"caveat":84},"A bank that updates 300 policy and procedure documents a year after regulatory change",[53,59,66,73],{"key":54,"label":55,"low":56,"high":56,"unit":57,"note":58},"documents","Policy and procedure documents updated per year",300,"documents per year","The reference bank. Replace with your own volume.",{"key":60,"label":61,"low":62,"high":63,"unit":64,"note":65},"hoursPerDocument","Specialist hours per document update (analysis and drafting)",8,16,"hours per document","Editorial assumption, replace with your own time records.",{"key":67,"label":68,"low":69,"high":70,"unit":71,"note":72},"timeSaved","Share of analysis and drafting time saved",0.2,0.4,"fraction of time","Editorial assumption. No public measured benchmark for policy drafting was found; keep this conservative.",{"key":74,"label":75,"low":76,"high":77,"unit":78,"note":79},"hourlyCost","Fully loaded cost of a policy or compliance specialist",80,150,"USD per hour","Editorial assumption, replace with your own.","documents * hoursPerDocument * timeSaved * hourlyCost","USD","per year","Specialist time released from policy updates","Time only. It leaves out the value of fewer inconsistencies and findings, faster implementation of new rules, and the cost of building and maintaining the policy knowledge base.",[86],{"statement":87,"sourceTitle":88,"sourceUrl":89,"year":90},"In the Bank of England and FCA 2024 survey of UK financial firms, an additional 32% of respondents expected to use AI for regulatory compliance and reporting over the next three years.","Artificial intelligence in UK financial services 2024","https://www.bankofengland.co.uk/report/2024/artificial-intelligence-in-uk-financial-services-2024",2024,{"complexity":92,"complexityNote":93,"dataPrerequisites":94,"integrations":99},"medium","Retrieval and drafting are mature. The effort is in a clean, versioned policy estate with owners, a mapped obligation library and a template the drafts must follow.",[95,96,97,98],"A current, versioned policy and procedure library with owners","An obligation library or the new rule texts with effective dates","Approved templates and a style guide","Past redlines and approvals to test the assistant against",[100,101,102,103],"Policy management or document management system","Regulatory change or obligation management tool","Workflow for review and approval","Collaboration tools where owners edit drafts",{"steps":105,"guardrails":121,"humanInTheLoop":127,"kpisToInstrument":128,"failureModes":134},[106,109,112,115,118],{"title":107,"detail":108},"Clean the estate","Retire duplicates, assign an owner and review date to every document and fix the version history. Retrieval over a messy estate finds the wrong clause confidently.",{"title":110,"detail":111},"Start with gap analysis, then drafting","First use the assistant to find affected clauses and classify gaps, and measure how many it misses against expert review. Only then let it draft wording.",{"title":113,"detail":114},"Constrain the drafting","Give the model the template, the style guide and the obligation text, and require every drafted sentence to cite the obligation it implements. Anything without a source is removed.",{"title":116,"detail":117},"Test on past changes","Replay previous regulatory changes where the final policy text is known and compare the assistant's gaps and drafts with what the experts did.",{"title":119,"detail":120},"Embed in the approval workflow","Deliver drafts as redlines into the existing review tool, record who approved what, and keep the obligation to clause link after publication.",[122,123,124,125,126],"Every drafted clause cites the obligation or source text it implements","Drafts follow the approved template; the assistant cannot publish or approve","The policy owner approves every change; legal or compliance signs off where required","Retrieval is limited to current, approved versions of documents","Version history and approval trail retained for supervisors and audit","The policy owner reviews and approves every change and owns the interpretation of the rule. Compliance or legal signs off material changes. The assistant drafts and flags; it never decides that a policy is compliant.",[129,130,131,132,133],"Time from a rule's publication to approved policy updates","Recall of affected clauses against expert review on sampled changes","Share of drafted text accepted without material edits","Inconsistencies found between policy and procedure in periodic reviews","Audit and supervisory findings on policy coverage",[135,138,141,144],{"title":136,"detail":137},"Invented obligations","The model adds requirements that are not in the rule. Require a citation per sentence and strip anything unsupported.",{"title":139,"detail":140},"Missed documents","A procedure outside the indexed estate never shows up, so the gap persists. Measure recall and keep the estate complete.",{"title":142,"detail":143},"Style over substance","Polished drafts get approved without checking the interpretation. Owners must confirm the interpretation separately from the wording.",{"title":145,"detail":146},"Stale sources","Retrieval returns a superseded version. Index only current approved versions and show the version in every citation.",{"euAiAct":148,"regulations":151,"guidance":157,"controls":176,"incidents":182},{"tier":149,"basis":150},"minimal","Drafting internal policy text for human approval is not an Annex III use and has no direct effect on individuals. The Article 4 AI literacy measures still apply to the staff who use it.",[152,153,154,155,156],"eu-ai-act","gdpr","iso-42001","nist-ai-rmf","mas-ai-risk-management",[158,164,170],{"title":159,"issuer":160,"region":161,"url":162,"note":163},"Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)","NIST","north-america","https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence","A 2024 companion to the AI RMF that lists risks of generative AI, including confabulation, with suggested actions that apply directly to drafting assistants.",{"title":165,"issuer":166,"region":167,"url":168,"note":169},"Article 4, AI literacy","European Union","europe","https://artificialintelligenceact.eu/article/4/","Providers and deployers must take measures to support the AI literacy of their staff and others who operate and use AI systems on their behalf.",{"title":171,"issuer":172,"region":173,"url":174,"note":175},"Artificial Intelligence (AI) Model Risk Management","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/publications/monographs-or-information-paper/2024/artificial-intelligence-model-risk-management","Good practices for AI and generative AI model risk management observed in a 2024 thematic review of banks, covering governance, oversight, development and deployment.",[177,178,179,180,181],"Inventory entry for the assistant with an owner, scope and approved sources","Citation requirement and automated check for unsupported text","Approval workflow with recorded sign off per change","Periodic recall testing against expert gap analysis","Retention of the obligation to clause trail and version history",[],{"howToBuild":184},"On Blits.ai this is an **AI agent** over a **knowledge base** that holds the policy estate and\nthe obligation texts, with document version control and hybrid retrieval (vector and BM25) so\nexact clause wording is found as well as related concepts. **Prompt versioning** holds the house\ntemplate and style rules, and **structured output** returns each affected clause with its gap\nclassification, the cited obligation and a drafted redline.\n\nFor larger changes an **agentic workflow** walks the whole estate for one obligation, and **human\nin the loop confirmation** holds each drafted change for approval or rejection. Output\n**guardrails** check drafts against an admin authored policy, such as rejecting text without a\ncited source, **test suites** replay past regulatory changes against expert outcomes before a\nprompt or model change goes live, and the workflow run history and audit trail keep the trail\nfrom obligation to draft. The platform is model agnostic,\nwith EU and UAE data residency.",[186,189,192],{"question":187,"answer":188},"Can AI write our policies?","It can find what a new rule touches and draft consistent wording quickly, but the policy owner must approve every change and own the interpretation. The safe design constrains drafting to approved templates and requires a citation for every clause.",{"question":190,"answer":191},"Where do public deployments stand?","Mostly early. The Administration for Children and Families, part of the US Department of Health and Human Services, reported using AI since March 2025 to flag grants and position descriptions that may need revision under new directives, with staff making the final assessments. Policy drafting assistants reported by HRSA (initiated in 2024) and the FDIC (retired by 2025) never reported reaching production.",{"question":193,"answer":194},"How is this different from regulatory horizon scanning?","Horizon scanning finds new rules and maps them to obligations. Policy drafting and gap analysis starts from a mapped obligation and changes the bank's own documents to implement it.",[196,197,198,199,200],"regulatory-horizon-scanning","continuous-controls-testing","supervisory-exam-response-assembly","hr-and-policy-assistant","internal-audit-copilot","2026-09-27","2026-09-26",[204],{"date":201,"note":205},"First published","policy-drafting-and-gap-analysis",[208,241,261],{"title":209,"useCases":210,"organization":211,"vendors":215,"summary":221,"stage":222,"year":223,"channels":224,"languages":225,"metrics":227,"outcomeDisclosed":213,"sources":228,"verification":236,"grade":238,"id":239,"organizationSlug":240},"HHS Administration for Children and Families: AI review of documents against new directives",[206,196],{"name":212,"anonymized":213,"country":214,"region":161,"industry":21},"Administration for Children and Families",false,"US",[216,219],{"name":217,"role":218},"Palantir","platform",{"name":220,"role":218},"Credal","In March 2025 the Administration for Children and Families, part of the US Department of Health and Human Services, deployed AI to review its existing grants, new grant applications and position descriptions for alignment with HHS Secretarial Directives related to recent executive orders. The AI produces an initial list of documents that may need revision (for grants, with an initial assessment and example passages); program office staff then review, justify and recommend. For position descriptions the agency states that AI was not used to make any final determinations. It is the gap detection half of policy change work: finding which existing documents a new requirement touches.","production",2025,[32],[226],"en",[],[229,233],{"url":230,"title":231,"publisher":232},"https://github.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory","2025 Federal Agency AI Use Case Inventory","Office of Management and Budget (GitHub)",{"url":234,"title":235,"publisher":232},"https://raw.githubusercontent.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory/main/Data/2025_individually_reported_AI_use_cases.csv","2025 individually reported AI use cases (HHS/ACF entries Document Review for Alignment with Executive Orders)",{"level":237,"checkedAt":202},"source-verified","B","hhs-acf-directive-alignment-document-review",null,{"title":242,"useCases":243,"organization":244,"vendors":246,"summary":247,"stage":248,"year":90,"channels":249,"languages":250,"metrics":251,"outcomeDisclosed":213,"sources":252,"verification":258,"grade":238,"id":259,"organizationSlug":260},"FDIC: plain language policy drafting assistant, initiated then retired",[206],{"name":245,"anonymized":213,"country":214,"region":161,"industry":21},"Federal Deposit Insurance Corporation",[],"The FDIC reported in its 2024 AI inventory a planned assistant for its policy writers: it would check a draft policy against the Plain Language Writing Act for clarity, active voice, concision, jargon and acronyms, and redraft selected sections in plain language. In the 2025 inventory the entry is listed as retired. It is a useful signal that style and consistency checking of internal policy is an early candidate, and that not every initiative reaches production.","paused",[32],[226],[],[253,256],{"url":254,"title":255,"publisher":232},"https://raw.githubusercontent.com/ombegov/2024-Federal-AI-Use-Case-Inventory/main/data/2024_consolidated_ai_inventory_raw_v2.csv","2024 consolidated AI inventory (FDIC entry Plain Language Policy Assistant)",{"url":234,"title":257,"publisher":232},"2025 individually reported AI use cases (FDIC entry 3, Plain Language Policy Assistant, retired)",{"level":237,"checkedAt":202},"fdic-plain-language-policy-assistant","federal-deposit-insurance-corporation",{"title":262,"useCases":263,"organization":264,"vendors":266,"summary":267,"stage":268,"year":90,"channels":269,"languages":270,"metrics":271,"outcomeDisclosed":213,"sources":272,"verification":278,"grade":238,"id":279,"organizationSlug":240},"HRSA: Policy Assistant for first drafts of policy documents (initiated)",[206],{"name":265,"anonymized":213,"country":214,"region":161,"industry":21},"Health Resources and Services Administration",[],"The Health Resources and Services Administration, part of the US Department of Health and Human Services, reported in 2024 a Policy Assistant that uses large language models to generate first drafts of key policy documents, funding notices and budget documents from example documents, style guides, key policy decisions and its internal knowledge base, plus an editing tool that checks drafts for inconsistencies and errors. The goal is less drafting time and better document quality. The entry was at the initiated stage and does not appear in the 2025 inventory; no results are published.","announced",[32],[226],[],[273,276],{"url":274,"title":275,"publisher":232},"https://github.com/ombegov/2024-Federal-AI-Use-Case-Inventory","2024 Federal Agency AI Use Case Inventory",{"url":254,"title":277,"publisher":232},"2024 consolidated AI inventory (HHS/HRSA entry Policy Assistant)",{"level":237,"checkedAt":202},"hrsa-policy-document-drafting-assistant",0,[],{"low":283,"high":284},38400,288000,[286,306,321,332,357],{"slug":196,"title":287,"shortTitle":288,"definition":289,"status":9,"industries":290,"functions":294,"patterns":296,"audience":33,"autonomy":299,"adoptionStage":300,"segment":41,"evidenceCount":301,"publicEvidenceCount":302,"organizations":303,"bestGrade":238,"headline":240,"lastVerified":201,"indexable":305},"AI regulatory horizon scanning and obligation mapping","Regulatory horizon scanning","An AI system that continuously reads publications from the regulators and standard setters an organization answers to, classifies each item by relevance and urgency, breaks new rules into individual obligations and maps them to the internal policies and controls that meet them, so compliance owners see what changed and where the gaps are.",[17,18,19,291,292,293,21],"payments","wealth-and-asset-management","pharma-and-life-sciences",[23,24,295],"risk-management",[297,29,27,30,298],"classification-and-routing","agentic-workflow","assist","early-adopters",4,2,[304,212],"Financial Conduct Authority",true,{"slug":197,"title":307,"shortTitle":308,"definition":309,"status":9,"industries":310,"functions":311,"patterns":313,"audience":315,"autonomy":316,"adoptionStage":35,"segment":36,"evidenceCount":317,"publicEvidenceCount":317,"organizations":318,"bestGrade":238,"headline":240,"lastVerified":201,"indexable":305},"AI for continuous controls testing and control self assessment","Continuous controls testing","AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.",[17,18,19,20,21],[295,23,312],"operations",[298,29,314,297],"anomaly-detection","back-office","supervised-agent",3,[245,319,320],"U.S. Department of the Interior","Pension Benefit Guaranty Corporation",{"slug":198,"title":322,"shortTitle":323,"definition":324,"status":9,"industries":325,"functions":326,"patterns":328,"audience":33,"autonomy":34,"adoptionStage":35,"segment":36,"evidenceCount":317,"publicEvidenceCount":317,"organizations":329,"bestGrade":238,"headline":240,"lastVerified":201,"indexable":305},"AI for supervisory exam and information request responses","Exam response assembly","An assistant for the bank's regulatory affairs team that reads a supervisory information request or exam question, retrieves the relevant evidence, policies and prior correspondence, drafts a response for legal and compliance to approve, and tracks every commitment and remediation action through to closure.",[18,19,20,291],[23,24,327],"case-management",[27,28,29,298],[330,331],"U.S. Department of Homeland Security","Federal Emergency Management Agency",{"slug":199,"title":333,"shortTitle":334,"definition":335,"status":9,"industries":336,"functions":339,"patterns":341,"audience":33,"autonomy":316,"adoptionStage":300,"evidenceCount":343,"publicEvidenceCount":301,"organizations":344,"bestGrade":238,"headline":349,"lastVerified":201,"indexable":305},"AI assistant for HR and policy questions","HR and policy assistant","An employee self service assistant that answers questions on leave, pay and tax forms, benefits, expenses, travel and conduct policies from the organization's own HR documents, personalized to the employee's country and role, and starts simple HR transactions such as leave requests or employment letters in the HR system.",[17,18,337,338],"technology","healthcare",[340,25],"human-resources",[27,342,298],"conversational-agent",5,[345,346,347,348],"Bank of America","IBM","Turing","Vituity",{"kpi":350,"label":351,"unit":352,"n":302,"nUpTo":280,"kind":353,"value":354,"qualifier":355,"claimant":356,"organization":346,"vendorReported":213},"employee-adoption","Employee adoption","percent","reported",99,"exact","organization",{"slug":200,"title":358,"shortTitle":359,"definition":360,"status":9,"industries":361,"functions":362,"patterns":364,"audience":33,"autonomy":34,"adoptionStage":300,"evidenceCount":317,"publicEvidenceCount":317,"organizations":365,"bestGrade":369,"headline":370,"lastVerified":201,"indexable":305},"Generative AI copilot for internal audit","Internal audit copilot","A copilot for internal auditors that drafts planning memos and document request lists from prior audits, summarises large evidence sets, builds risk and control matrices from policies and process documents, and drafts findings and reports, with every statement traceable to its evidence and a qualified auditor accountable for every conclusion.",[17,18,19,21,20,292],[295,23,363],"finance-and-accounting",[27,30,28,29,314],[366,367,368],"Banco Bradesco","British Columbia Investment Management Corporation","XP Inc.","C",{"kpi":371,"label":372,"unit":352,"n":302,"nUpTo":280,"kind":353,"value":373,"qualifier":355,"claimant":374,"organization":366,"vendorReported":305},"handling-time-reduction","Handling time reduction",55,"vendor",{"indexable":305,"reasons":376},[],[378,383,388,395,400,406,413,419,424,431,438,444,450,457,463,468,475,481,487,493,499,505,511,516,521,528,534,539,545,552,558,564,570,575],{"id":152,"label":379,"issuer":166,"region":167,"url":380,"description":381,"useCases":382,"indexable":305},"EU AI Act","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":153,"label":384,"issuer":166,"region":167,"url":385,"description":386,"useCases":387,"indexable":305},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":154,"label":389,"issuer":390,"region":391,"url":392,"description":393,"useCases":394,"indexable":305},"ISO/IEC 42001","ISO and IEC","global","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":155,"label":396,"issuer":160,"region":161,"url":397,"description":398,"useCases":399,"indexable":305},"NIST AI Risk Management Framework","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":401,"label":402,"issuer":166,"region":167,"url":403,"description":404,"useCases":405,"indexable":305},"dora","DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":407,"label":408,"issuer":409,"region":167,"url":410,"description":411,"useCases":412,"indexable":305},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":414,"label":415,"issuer":304,"region":167,"url":416,"description":417,"useCases":418,"indexable":305},"uk-consumer-duty","FCA Consumer Duty","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":156,"label":420,"issuer":172,"region":173,"url":421,"description":422,"useCases":423,"indexable":305},"MAS AI risk management guidelines","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":425,"label":426,"issuer":427,"region":173,"url":428,"description":429,"useCases":430,"indexable":305},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":432,"label":433,"issuer":434,"region":391,"url":435,"description":436,"useCases":437,"indexable":305},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",20,{"id":439,"label":440,"issuer":441,"region":161,"url":442,"description":443,"useCases":437,"indexable":305},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":445,"label":446,"issuer":447,"region":167,"url":448,"description":449,"useCases":63,"indexable":305},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",{"id":451,"label":452,"issuer":453,"region":391,"url":454,"description":455,"useCases":456,"indexable":305},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":458,"label":459,"issuer":166,"region":167,"url":460,"description":461,"useCases":462,"indexable":305},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":464,"label":465,"issuer":166,"region":167,"url":466,"description":467,"useCases":462,"indexable":305},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":469,"label":470,"issuer":471,"region":161,"url":472,"description":473,"useCases":474,"indexable":305},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":476,"label":477,"issuer":166,"region":167,"url":478,"description":479,"useCases":480,"indexable":305},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":482,"label":483,"issuer":484,"region":161,"url":485,"description":486,"useCases":480,"indexable":305},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":488,"label":489,"issuer":490,"region":391,"url":491,"description":492,"useCases":480,"indexable":305},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":494,"label":495,"issuer":166,"region":167,"url":496,"description":497,"useCases":498,"indexable":305},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":500,"label":501,"issuer":502,"region":161,"url":503,"description":504,"useCases":498,"indexable":305},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":506,"label":507,"issuer":172,"region":173,"url":508,"description":509,"useCases":510,"indexable":305},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",10,{"id":512,"label":513,"issuer":166,"region":167,"url":514,"description":515,"useCases":510,"indexable":305},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":517,"label":518,"issuer":166,"region":167,"url":519,"description":520,"useCases":510,"indexable":305},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":522,"label":523,"issuer":524,"region":167,"url":525,"description":526,"useCases":527,"indexable":305},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":529,"label":530,"issuer":531,"region":161,"url":532,"description":533,"useCases":62,"indexable":305},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",{"id":535,"label":536,"issuer":166,"region":167,"url":537,"description":538,"useCases":62,"indexable":305},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":540,"label":541,"issuer":166,"region":167,"url":542,"description":543,"useCases":544,"indexable":305},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",6,{"id":546,"label":547,"issuer":548,"region":549,"url":550,"description":551,"useCases":343,"indexable":305},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":553,"label":554,"issuer":555,"region":167,"url":556,"description":557,"useCases":301,"indexable":305},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":559,"label":560,"issuer":561,"region":167,"url":562,"description":563,"useCases":301,"indexable":305},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":565,"label":566,"issuer":567,"region":173,"url":568,"description":569,"useCases":317,"indexable":305},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":571,"label":572,"issuer":166,"region":167,"url":573,"description":574,"useCases":317,"indexable":305},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":576,"label":577,"issuer":578,"region":161,"url":579,"description":580,"useCases":317,"indexable":305},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598301045]