[{"data":1,"prerenderedAt":623},["ShallowReactive",2],{"uc-procurement-contract-review":3,"uc-regulations":419},{"useCase":4,"evidence":220,"blitsAiDeployments":333,"benchmarks":334,"indicative":335,"related":338,"indexability":417,"includeUnpublished":226},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":17,"functions":23,"patterns":27,"channels":32,"audience":36,"autonomy":37,"adoptionStage":38,"problem":39,"problemStats":40,"howItWorks":41,"valueDrivers":42,"kpis":48,"indicativeValue":54,"macroEstimates":103,"feasibility":104,"implementation":118,"risk":165,"blitsAi":195,"faq":197,"related":210,"datePublished":215,"dateModified":215,"lastVerified":215,"changelog":216,"slug":219},"AI assistant for procurement and supplier contract review","Procurement and contract review","AI for procurement and supplier contract review","AI extracts key terms from supplier contracts and flags deviations for a buyer or lawyer to approve. The IRS uses it to draft and check contract file documents.","published","An assistant for procurement and vendor management that reads supplier contracts and proposals, extracts the key terms, flags deviations from the organization's standard positions, drafts requests for proposal and evaluation matrices, and prepares negotiation positions, with a procurement or legal owner approving every conclusion.",[12,13,14,15,16],"contract review AI","supplier contract analysis","AI contract abstraction","procurement copilot","AI supplier negotiation",[18,19,20,21,22],"cross-industry","banking","government","retail-and-ecommerce","manufacturing",[24,25,26],"procurement","legal","finance-and-accounting",[28,29,30,31],"document-processing","rag-knowledge-assistant","content-generation","agentic-workflow",[33,34,35],"internal-tools","microsoft-teams","email","employee-facing","copilot","early-adopters","A large organization holds thousands of supplier contracts, each with its own prices, renewal\ndates, service levels, liability caps, audit rights, data clauses and exit terms. Buyers and\nlawyers read them one by one: to check a new contract against the playbook, to find every\ncontract affected by a new regulation, or to prepare a renewal. Review queues grow, auto renewals\nslip through, and the long tail of smaller suppliers is barely negotiated at all. An HBR article\nco written by Walmart International's sourcing leaders described this: around 20% of Walmart's\nsuppliers had signed agreements with standard terms that were often not negotiated.\n\nIn financial services the stakes are regulatory. Third party rules such as DORA in the EU and APRA\nCPS 230 in Australia require specific clauses in contracts with ICT and material service providers.\nUnder DORA every ICT services contract must cover a description of the services, data locations\nand termination rights, and contracts for services that support critical or important functions\nmust also include audit and access rights and exit strategies. Both rules also require a register\nof those arrangements: under DORA the supervisor can request it, and under CPS 230 it is submitted\nto APRA.",[],"1. **Ingest and classify.** Contracts, amendments and supplier proposals are loaded from the\n   contract repository or email, split into clauses and classified by clause type.\n2. **Extract key terms.** The AI extracts parties, prices, dates, renewal and notice periods,\n   service levels, liability, audit rights, data protection and exit terms into a structured\n   record, citing the clause for each value.\n3. **Compare with the playbook.** Each clause is compared with the organization's standard and\n   fallback positions and with regulatory must haves; deviations are flagged with a risk rating\n   and a suggested redline.\n4. **Draft sourcing documents.** From the requirement and past tenders the assistant drafts the\n   request for proposal, the evaluation criteria and a first comparison of supplier responses.\n5. **Prepare the negotiation.** It summarises the contract history, benchmarks and open\n   deviations into a negotiation brief; for low value tail spend, some organizations let a bot\n   negotiate within limits the buyer sets, as Walmart has done with tail end suppliers.\n6. **Hand to the owner.** A buyer or lawyer reviews the extraction and the flags, decides, and the\n   decision and evidence are stored with the contract record.",[43,44,45,46,47],"cost-to-serve","employee-productivity","compliance","risk-reduction","speed",[49,50,51,52,53],"processing-time-reduction","time-saved-per-task","cost-reduction","automation-rate","accuracy",{"referenceOrg":55,"inputs":56,"formula":98,"currency":99,"period":100,"resultLabel":101,"caveat":102},"A bank with 2,000 supplier contracts and 400 new contracts or renewals reviewed a year",[57,63,70,77,84,91],{"key":58,"label":59,"low":60,"high":60,"unit":61,"note":62},"reviews","Contract reviews per year (new contracts, renewals and amendments)",400,"reviews per year","The reference organization. Replace with your own volume.",{"key":64,"label":65,"low":66,"high":67,"unit":68,"note":69},"hoursPerReview","Procurement and legal hours per review today",4,10,"hours per review","Editorial assumption covering reading, playbook comparison and write up.",{"key":71,"label":72,"low":73,"high":74,"unit":75,"note":76},"timeSaved","Share of review time saved by AI extraction and deviation flags",0.2,0.4,"fraction of review time","Editorial assumption; reviewers still read flagged clauses and confirm extracted terms.",{"key":78,"label":79,"low":80,"high":81,"unit":82,"note":83},"hourlyCost","Blended procurement and legal hour",80,150,"USD per hour","Editorial assumption. Replace with your own rate.",{"key":85,"label":86,"low":87,"high":88,"unit":89,"note":90},"tailSpend","Annual tail spend with suppliers that are rarely negotiated",5000000,20000000,"USD per year","Editorial assumption for a mid sized bank.",{"key":92,"label":93,"low":94,"high":95,"unit":96,"note":97},"tailSaving","Saving on negotiated tail spend",0.01,0.02,"fraction of spend","Conservative against the evidence on this page (Pactum reports a 3% average gain across Walmart's negotiations), because not every supplier agrees.","reviews * hoursPerReview * timeSaved * hourlyCost + tailSpend * tailSaving","USD","per year","Review time released plus savings on tail spend","It leaves out the value of avoided auto renewals, fewer missing regulatory clauses in material outsourcing contracts and faster sourcing cycles, and it leaves out the cost of loading and clause tagging the existing contract estate.",[],{"complexity":105,"complexityNote":106,"dataPrerequisites":107,"integrations":112},"medium","Extraction from clean digital contracts works well; scanned legacy contracts, amendments that override earlier terms and a missing clause playbook are where projects stall. Autonomous negotiation is a separate step that needs clear commercial limits.",[108,109,110,111],"A contract repository with contracts, amendments and supplier metadata in one place","A clause playbook with standard, fallback and unacceptable positions","The list of regulatory must have clauses for outsourcing and material service providers","Past tenders, evaluation matrices and awarded contracts as examples",[113,114,115,116,117],"Contract lifecycle management or document management system","Procurement suite (sourcing, purchase to pay, supplier master)","Third party risk management register","Email and Microsoft Teams for buyer and legal workflows","Electronic signature platform",{"steps":119,"guardrails":138,"humanInTheLoop":145,"kpisToInstrument":146,"failureModes":152},[120,123,126,129,132,135],{"title":121,"detail":122},"Write the playbook before the prompts","Agree standard and fallback positions for the clauses that matter, and the regulatory must haves for outsourcing contracts. The AI can only flag deviations from a position someone has written down.",{"title":124,"detail":125},"Start with extraction on new contracts","Extract key terms from incoming contracts with a citation per value and have buyers confirm them. Measure field level accuracy on a sample before trusting it on the back book.",{"title":127,"detail":128},"Run a back book sweep","Use the extraction on the existing estate to find renewal dates, missing audit or exit clauses and data location terms, and route gaps to contract owners as tasks.",{"title":130,"detail":131},"Add deviation flags and redlines","Compare clauses with the playbook, rate the deviation and suggest a redline. Lawyers approve or change every redline before it goes to a supplier.",{"title":133,"detail":134},"Draft sourcing documents","Generate first drafts of requests for proposal and evaluation matrices from templates and past tenders, and a first comparison of responses for the buying team to score.",{"title":136,"detail":137},"Consider negotiation bots only for the tail","If you automate negotiation, restrict it to low value suppliers and terms such as payment days and discounts, with limits set by a buyer, as Walmart has done with its tail end suppliers.",[139,140,141,142,143,144],"Every extracted term and deviation flag cites the clause it came from","A named buyer or lawyer approves every conclusion, redline and award recommendation","The AI does not sign, accept terms or commit spend; automated negotiation stays within limits a buyer set in advance","Supplier documents are treated as untrusted input, so instructions hidden in a contract or proposal cannot change the assistant's behaviour","Supplier evaluation scores are decided by the evaluation panel, not by the AI","Contract data stays in region and is not used to train external models","Procurement owns commercial decisions, legal owns clause positions and redlines, and the third party risk owner signs off material outsourcing contracts. The AI prepares, extracts and flags; people decide and their decisions are recorded with the contract.",[147,148,149,150,151],"Review cycle time from receipt to decision, before and after","Field level extraction accuracy on a monthly sample","Deviations flagged per contract and share accepted by legal","Missing regulatory clauses found in the back book and time to remediate","Savings on renegotiated contracts, net of supplier attrition",[153,156,159,162],{"title":154,"detail":155},"Amendments ignored","The AI reads the master agreement and misses the amendment that changed the price or the term. Link amendments to their master and extract the effective terms.",{"title":157,"detail":158},"Confident extraction from bad scans","Poor OCR on old contracts yields wrong dates or amounts that look authoritative. Flag low confidence fields and route them to a person.",{"title":160,"detail":161},"Playbook drift","Positions change but the playbook does not, so the AI flags the wrong deviations. Give the playbook an owner and version it.",{"title":163,"detail":164},"Automated procurement decisions without accountability","Tools that score suppliers or proposals can quietly become the decision when evaluators copy their output instead of forming their own view. Keep scoring advisory and record the panel's own reasoning.",{"euAiAct":166,"regulations":169,"guidance":175,"controls":188,"incidents":194},{"tier":167,"basis":168},"context-dependent","Contract review and sourcing are not among the Annex III high risk uses, so an internal assistant that makes no decisions about natural persons is minimal risk (with the Article 4 AI literacy duty). If a negotiation bot chats directly with supplier staff, Article 50(1) applies and it must tell them they are dealing with an AI system, unless that is obvious from the context. Public authorities using AI in procurement should still check national public procurement rules on transparency and equal treatment of bidders.",[170,171,172,173,174],"dora","apra-cps-230","gdpr","eu-ai-act","iso-42001",[176,182],{"title":177,"issuer":178,"region":179,"url":180,"note":181},"Digital Operational Resilience Act (Regulation (EU) 2022/2554), Article 30","European Union","europe","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Sets the key contractual provisions for ICT third party services at financial entities, which a contract review assistant should check as must have clauses.",{"title":183,"issuer":184,"region":185,"url":186,"note":187},"Operational risk management (CPS 230)","Australian Prudential Regulation Authority","asia-pacific","https://www.apra.gov.au/operational-risk-management","Requires formal agreements with material service providers covering specified terms, and a register of those providers submitted to APRA. Amendments that commenced on 1 July 2026 exempt some categories of service provider from specific contractual requirements.",[189,190,191,192,193],"Clause playbook and regulatory clause list owned by legal, versioned and reviewed","Human approval recorded for every redline, deviation acceptance and award recommendation","Sampled accuracy checks on extracted terms, with results kept as evidence","Access control on contract data by business unit and sensitivity","Inventory entry for the assistant with an accountable owner",[],{"howToBuild":196},"On Blits.ai this is an **AI agent** with a **knowledge base** holding the clause playbook,\nregulatory clause lists, templates and past tenders, retrieved with **hybrid search**. Contracts\nand proposals arrive as uploads or through **incoming email as a knowledge source**, and document\ningestion reads PDF, DOCX, image and Outlook email files. An **agentic workflow** extracts the key terms with\n**structured output**, compares them with the playbook, and writes the record back to the contract\nsystem through **custom functions** (REST calls), connectors from the **integration catalog**\n(for example SAP, Oracle, NetSuite, DocuSign) or the ready made SharePoint tool.\n\nBuyers and lawyers work with the agent in **Microsoft Teams** or email, and write backs and\noutgoing redlines are set to require **human in the loop approval**. Input and output\n**guardrails** block prompt injection attempts, **PII masking** protects personal data in contracts, **run history with a\nfull audit trail** keeps each extraction and approval, and **test suites** check extraction\naccuracy on a reference set of contracts after every change. The platform is model agnostic and\noffers EU and UAE data residency.",[198,201,204,207],{"question":199,"answer":200},"Can AI review supplier contracts reliably?","It is reliable as a first pass that extracts terms and flags deviations with a citation to the clause, and unreliable as the final word. Measure field level accuracy on your own contracts, route low confidence fields to a person, and keep a lawyer's approval on every redline.",{"question":202,"answer":203},"Can AI negotiate with suppliers?","For simple terms with low value suppliers, yes. An HBR article co written by Walmart International's sourcing leaders reported in 2022 that its negotiation chatbot had so far closed agreements with 68% of suppliers approached, and the vendor, Pactum, reports a 3% average gain across Walmart's negotiations. Buyers set the limits and strategic suppliers stay with people.",{"question":205,"answer":206},"How does this help with third party risk rules for banks?","Rules such as DORA and APRA CPS 230 require specific contractual provisions with ICT and material service providers. A back book sweep finds contracts missing audit, data location or exit clauses so they can be remediated, and the evidence is kept with each contract.",{"question":208,"answer":209},"How do government buyers use AI in public procurement?","Mostly as a drafting and review aid inside the existing procedure. The US Administration for Children and Families uses it to find passages in proposals and draft technical evaluation language, the IRS to draft and check contract file documents, and GSA to screen solicitations for missing compliance language. In the ACF and IRS entries the AI drafts and flags while officials make the final determinations. GSA also retired CALI, a machine learning tool for checking proposal compliance that was still in training, in November 2024 without publishing a reason.",[211,212,213,214],"vendor-due-diligence","supplier-invoice-processing","policy-drafting-and-gap-analysis","internal-audit-copilot","2026-09-27",[217],{"date":215,"note":218},"First published","procurement-contract-review",[221,247,262,283,305],{"title":222,"useCases":223,"organization":224,"vendors":229,"summary":230,"stage":231,"year":232,"channels":233,"languages":234,"metrics":236,"outcomeDisclosed":226,"sources":237,"verification":242,"grade":244,"id":245,"organizationSlug":246},"US General Services Administration: Solicitation Review Tool that screens ICT solicitations for compliance language",[219],{"name":225,"anonymized":226,"country":227,"region":228,"industry":20},"General Services Administration",false,"US","north-america",[],"GSA's Solicitation Review Tool screens federal information and communications technology solicitations published on SAM.gov and flags those that may lack required compliance language, automating a first screening that would otherwise need extensive manual review by agencies. A related version that checks for Section 508 accessibility requirements was listed as pre deployment. The inventory lists the tool as deployed without further detail on benefits or outcomes.","production",2025,[33],[235],"en",[],[238],{"url":239,"title":240,"publisher":241},"https://raw.githubusercontent.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory/main/Data/2025_individually_reported_AI_use_cases.csv","2025 federal agency AI use case inventory, individually reported use cases (raw data)","Office of Management and Budget (GitHub)",{"level":243,"checkedAt":215},"source-verified","B","gsa-solicitation-review-tool",null,{"title":248,"useCases":249,"organization":250,"vendors":252,"summary":253,"stage":231,"year":232,"channels":254,"languages":255,"metrics":256,"outcomeDisclosed":226,"sources":257,"verification":259,"grade":244,"id":260,"organizationSlug":261},"Internal Revenue Service: AI Contract Document Toolbox for drafting and reviewing procurement documents",[219],{"name":251,"anonymized":226,"country":227,"region":228,"industry":20},"Internal Revenue Service",[],"IRS procurement staff must produce extensive documentation for every contract file, and drafting and quality review were largely manual and slow, with some errors missed. Since July 2025 the IRS AI Contract Document Toolbox gives them a generative AI chat that drafts first versions of procurement documents, summarises and rewrites documents and extracts data, and that can be instructed to apply lessons learned and new procurement policy goals and to detect common past errors. Staff refine the drafts and vet documents together with the AI; the inventory states that the tool offers recommendations but does not approve contracts, and that agency officials make the final decisions. It records the use case as presumed high impact but determined not high impact. No outcome figures are published.",[33],[235],[],[258],{"url":239,"title":240,"publisher":241},{"level":243,"checkedAt":215},"irs-ai-contract-document-toolbox","internal-revenue-service",{"title":263,"useCases":264,"organization":265,"vendors":267,"summary":275,"stage":231,"year":232,"channels":276,"languages":277,"metrics":278,"outcomeDisclosed":226,"sources":279,"verification":281,"grade":244,"id":282,"organizationSlug":246},"US Administration for Children and Families: AI support for reviewing proposals and drafting technical evaluations",[219],{"name":266,"anonymized":226,"country":227,"region":228,"industry":20},"U.S. Department of Health and Human Services, Administration for Children and Families",[268,271,273],{"name":269,"role":270},"Credal","platform",{"name":272,"role":270},"Ask Sage",{"name":274,"role":270},"Microsoft","When the Administration for Children and Families receives many vendor responses to requests for information and proposals, review teams must write summarised comments on each response against pre established evaluation criteria. Since July 2025 evaluators use generative AI to find relevant passages in the proposals and to draft language for technical evaluation documents, for example pulling and formatting examples with page citations to support the evaluator's own assessment. The inventory states that AI does not make final determinations and that evaluators review all drafted language, revise it as needed and verify any cited excerpts. The systems listed are ACF Credal, Microsoft Copilot Chat and Ask Sage, with Ask Sage marked as decommissioned. No outcome figures are published.",[33],[235],[],[280],{"url":239,"title":240,"publisher":241},{"level":243,"checkedAt":215},"hhs-acf-proposal-review-drafting",{"title":284,"useCases":285,"organization":286,"vendors":287,"summary":293,"stage":294,"year":295,"channels":296,"languages":297,"metrics":298,"outcomeDisclosed":226,"sources":299,"verification":303,"grade":244,"id":304,"organizationSlug":246},"US General Services Administration: CALI proposal compliance checking tool, retired while in training",[219],{"name":225,"anonymized":226,"country":227,"region":228,"industry":20},[288,291],{"name":289,"role":290},"Octo Consulting","integrator",{"name":292,"role":270},"Amazon Web Services","GSA's Contract Acquisition Lifecycle Intelligence (CALI) is a machine learning tool built to check vendor proposals for compliance in four areas (format, forms, representations and certifications, and requirements) to support source selection, with designated evaluation members reviewing the results. It was offered by Octo Consulting as a hosted service on AWS. The 2024 federal AI use case inventory describes it as still being trained on sample data, gives no implementation date, states that no testing in an operational environment had been done, and lists it as retired on 1 November 2024. No outcome and no reason for retirement are published, and nothing in the source shows it was used on live source selections; it is recorded here because stopped projects are part of the evidence.","paused",2024,[33],[235],[],[300],{"url":301,"title":302,"publisher":241},"https://raw.githubusercontent.com/ombegov/2024-Federal-AI-Use-Case-Inventory/main/data/2024_consolidated_ai_inventory_raw_v2.csv","2024 consolidated federal AI use case inventory (raw data)",{"level":243,"checkedAt":215},"gsa-cali-proposal-evaluation",{"title":306,"useCases":307,"organization":308,"vendors":311,"summary":314,"stage":231,"year":315,"channels":316,"languages":318,"metrics":319,"outcomeDisclosed":320,"sources":321,"verification":330,"grade":244,"id":331,"organizationSlug":332},"Walmart: autonomous negotiation of supplier terms with tail end suppliers",[219],{"name":309,"anonymized":226,"country":227,"region":310,"industry":21},"Walmart","global",[312],{"name":313,"role":270},"Pactum","Walmart uses a chatbot from Pactum to negotiate payment terms and price discounts with tail end suppliers, where buyers lack time to negotiate and around 20% of suppliers had signed standard terms that are often not negotiated. The HBR article describing it is co written by two sourcing leaders at Walmart International and two University of Arkansas professors. Walmart decides the acceptable negotiation trade offs and the bot negotiates and closes agreements within them; the article advises starting in indirect spend categories with pre approved suppliers and scaling by geography, category and use case. The authors report that, so far, the chatbot has closed agreements with 68% of suppliers approached. Pactum, the vendor, reports a 3% average gain across negotiations while extending payment terms by an average of 35 days. The first is a supplier agreement rate and the second a commercial gain on negotiated terms; neither measures how much of the process runs without human touch or what procurement costs to run.",2022,[317,33],"web-chat",[235],[],true,[322,327],{"url":323,"title":324,"publisher":325,"date":326},"https://hbr.org/2022/11/how-walmart-automated-supplier-negotiations","How Walmart Automated Supplier Negotiations","Harvard Business Review","2022-11-08",{"url":328,"title":329,"publisher":313},"https://pactum.com/clients","Clients",{"level":243,"checkedAt":215},"walmart-autonomous-supplier-negotiation","walmart",1,[],{"low":336,"high":337},75600,640000,[339,356,382,397],{"slug":211,"title":340,"shortTitle":341,"definition":342,"status":9,"industries":343,"functions":346,"patterns":349,"audience":36,"autonomy":37,"adoptionStage":38,"segment":351,"evidenceCount":66,"publicEvidenceCount":66,"organizations":352,"bestGrade":244,"headline":246,"lastVerified":215,"indexable":320},"AI for third party and vendor risk due diligence","Vendor due diligence","AI that reviews a vendor's security questionnaires, SOC and assurance reports, contracts and model documentation against the organization's control requirements, researches the vendor's ownership, sanctions, financial health and adverse media, drafts the risk assessment for a human to approve and keeps the register of material service providers current with ongoing monitoring.",[18,19,344,20,345],"insurance","payments",[24,347,348],"risk-management","regulatory-compliance",[28,29,31,350],"summarization","second-line",[353,251,354,355],"U.S. Department of Justice","U.S. Department of Agriculture","U.S. Trade and Development Agency",{"slug":212,"title":357,"shortTitle":358,"definition":359,"status":9,"industries":360,"functions":362,"patterns":363,"audience":366,"autonomy":367,"adoptionStage":368,"segment":366,"evidenceCount":369,"publicEvidenceCount":66,"organizations":370,"bestGrade":244,"headline":375,"lastVerified":215,"indexable":320},"AI for supplier invoice processing in accounts payable","Supplier invoice processing","AI that captures supplier invoices from any format, extracts header and line data, matches them to purchase orders and goods receipts, proposes tax and cost centre coding, flags duplicates and suspected fraud, and routes them for approval and posting, leaving only exceptions to accounts payable staff.",[18,19,20,21,361],"energy-and-utilities",[26,24],[28,31,364,365],"anomaly-detection","classification-and-routing","back-office","supervised-agent","mainstream",5,[371,372,373,374],"Federal Deposit Insurance Corporation","Kingfisher","U.S. Immigration and Customs Enforcement","Veolia",{"kpi":376,"label":377,"unit":378,"n":333,"nUpTo":333,"kind":379,"value":80,"qualifier":380,"claimant":381,"organization":372,"vendorReported":226},"productivity-gain","Productivity gain","percent","reported","exact","organization",{"slug":213,"title":383,"shortTitle":384,"definition":385,"status":9,"industries":386,"functions":388,"patterns":390,"audience":36,"autonomy":37,"adoptionStage":391,"segment":351,"evidenceCount":392,"publicEvidenceCount":392,"organizations":393,"bestGrade":244,"headline":246,"lastVerified":396,"indexable":320},"AI for policy drafting and policy gap analysis","Policy drafting and gaps","An assistant that takes a new or changed obligation, finds every internal policy, standard and procedure it touches, flags clauses that now conflict or are silent, and drafts the updated wording in house style as a redline for the policy owner to approve.",[18,19,344,387,20],"capital-markets",[348,25,389],"knowledge-management",[29,30,28,350],"emerging",3,[371,394,395],"Administration for Children and Families","Health Resources and Services Administration","2026-09-26",{"slug":214,"title":398,"shortTitle":399,"definition":400,"status":9,"industries":401,"functions":403,"patterns":404,"audience":36,"autonomy":37,"adoptionStage":38,"evidenceCount":392,"publicEvidenceCount":392,"organizations":405,"bestGrade":409,"headline":410,"lastVerified":215,"indexable":320},"Generative AI copilot for internal audit","Internal audit copilot","A copilot for internal auditors that drafts planning memos and document request lists from prior audits, summarises large evidence sets, builds risk and control matrices from policies and process documents, and drafts findings and reports, with every statement traceable to its evidence and a qualified auditor accountable for every conclusion.",[18,19,344,20,387,402],"wealth-and-asset-management",[347,348,26],[29,350,30,28,364],[406,407,408],"Banco Bradesco","British Columbia Investment Management Corporation","XP Inc.","C",{"kpi":411,"label":412,"unit":378,"n":413,"nUpTo":414,"kind":379,"value":415,"qualifier":380,"claimant":416,"organization":406,"vendorReported":320},"handling-time-reduction","Handling time reduction",2,0,55,"vendor",{"indexable":320,"reasons":418},[],[420,425,430,436,443,447,454,461,468,472,479,485,492,499,505,510,517,523,529,535,541,547,552,557,562,569,576,581,587,594,600,606,612,617],{"id":173,"label":421,"issuer":178,"region":179,"url":422,"description":423,"useCases":424,"indexable":320},"EU AI Act","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":172,"label":426,"issuer":178,"region":179,"url":427,"description":428,"useCases":429,"indexable":320},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":174,"label":431,"issuer":432,"region":310,"url":433,"description":434,"useCases":435,"indexable":320},"ISO/IEC 42001","ISO and IEC","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":437,"label":438,"issuer":439,"region":228,"url":440,"description":441,"useCases":442,"indexable":320},"nist-ai-rmf","NIST AI Risk Management Framework","NIST","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":170,"label":444,"issuer":178,"region":179,"url":180,"description":445,"useCases":446,"indexable":320},"DORA","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":448,"label":449,"issuer":450,"region":179,"url":451,"description":452,"useCases":453,"indexable":320},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":455,"label":456,"issuer":457,"region":179,"url":458,"description":459,"useCases":460,"indexable":320},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":462,"label":463,"issuer":464,"region":185,"url":465,"description":466,"useCases":467,"indexable":320},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":171,"label":469,"issuer":184,"region":185,"url":186,"description":470,"useCases":471,"indexable":320},"APRA CPS 230","Australian operational risk standard covering critical operations and material service providers.",25,{"id":473,"label":474,"issuer":475,"region":310,"url":476,"description":477,"useCases":478,"indexable":320},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",20,{"id":480,"label":481,"issuer":482,"region":228,"url":483,"description":484,"useCases":478,"indexable":320},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":486,"label":487,"issuer":488,"region":179,"url":489,"description":490,"useCases":491,"indexable":320},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":493,"label":494,"issuer":495,"region":310,"url":496,"description":497,"useCases":498,"indexable":320},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":500,"label":501,"issuer":178,"region":179,"url":502,"description":503,"useCases":504,"indexable":320},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":506,"label":507,"issuer":178,"region":179,"url":508,"description":509,"useCases":504,"indexable":320},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":511,"label":512,"issuer":513,"region":228,"url":514,"description":515,"useCases":516,"indexable":320},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":518,"label":519,"issuer":178,"region":179,"url":520,"description":521,"useCases":522,"indexable":320},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":524,"label":525,"issuer":526,"region":228,"url":527,"description":528,"useCases":522,"indexable":320},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":530,"label":531,"issuer":532,"region":310,"url":533,"description":534,"useCases":522,"indexable":320},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":536,"label":537,"issuer":178,"region":179,"url":538,"description":539,"useCases":540,"indexable":320},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":542,"label":543,"issuer":544,"region":228,"url":545,"description":546,"useCases":540,"indexable":320},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":548,"label":549,"issuer":464,"region":185,"url":550,"description":551,"useCases":67,"indexable":320},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",{"id":553,"label":554,"issuer":178,"region":179,"url":555,"description":556,"useCases":67,"indexable":320},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":558,"label":559,"issuer":178,"region":179,"url":560,"description":561,"useCases":67,"indexable":320},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":563,"label":564,"issuer":565,"region":179,"url":566,"description":567,"useCases":568,"indexable":320},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":570,"label":571,"issuer":572,"region":228,"url":573,"description":574,"useCases":575,"indexable":320},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",8,{"id":577,"label":578,"issuer":178,"region":179,"url":579,"description":580,"useCases":575,"indexable":320},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":582,"label":583,"issuer":178,"region":179,"url":584,"description":585,"useCases":586,"indexable":320},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",6,{"id":588,"label":589,"issuer":590,"region":591,"url":592,"description":593,"useCases":369,"indexable":320},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":595,"label":596,"issuer":597,"region":179,"url":598,"description":599,"useCases":66,"indexable":320},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":601,"label":602,"issuer":603,"region":179,"url":604,"description":605,"useCases":66,"indexable":320},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":607,"label":608,"issuer":609,"region":185,"url":610,"description":611,"useCases":392,"indexable":320},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":613,"label":614,"issuer":178,"region":179,"url":615,"description":616,"useCases":392,"indexable":320},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":618,"label":619,"issuer":620,"region":228,"url":621,"description":622,"useCases":392,"indexable":320},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598297074]