[{"data":1,"prerenderedAt":306},["ShallowReactive",2],{"uc-reg-fatf-recommendations":3},{"regulation":4,"includeUnpublished":11,"indexable":12,"useCases":13},{"id":5,"label":6,"issuer":7,"region":8,"url":9,"description":10},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","global","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",false,true,[14,44,76,96,120,147,166,187,200,215,236,253,269,282,295],{"slug":15,"title":16,"shortTitle":17,"definition":18,"status":19,"industries":20,"functions":23,"patterns":26,"audience":31,"autonomy":32,"adoptionStage":33,"segment":34,"evidenceCount":35,"publicEvidenceCount":35,"organizations":36,"bestGrade":39,"headline":40,"lastVerified":41,"indexable":12,"euAiActTier":42,"euAiActBasis":43},"source-of-wealth-diligence","AI agent for source of wealth due diligence in private banking","Source of wealth diligence","An AI agent that reads a prospective private client's documents, extracts and corroborates how their wealth was built, checks plausibility against benchmarks and external sources, and drafts the source of wealth and enhanced due diligence narrative for the relationship manager and compliance analyst, who decide on the risk rating and the relationship.","published",[21,22],"wealth-and-asset-management","banking",[24,25],"onboarding-and-kyc","financial-crime-compliance",[27,28,29,30],"document-processing","agentic-workflow","content-generation","summarization","employee-facing","copilot","early-adopters","front-office",3,[37,38],"Bank of Singapore","Deutsche Bank","B",null,"2026-09-26","context-dependent","Anti money laundering due diligence is not listed in Annex III, so an assistant that drafts source of wealth reports for a human decision is not high risk by default. It becomes high risk if it adds remote biometric identification of the client (Annex III point 1(a); verification that only confirms a claimed identity is excluded) or feeds an assessment of a natural person's creditworthiness, for example for lending to the client (Annex III point 5(b)). GDPR Article 22 on solely automated decisions applies if it ever refused a client on its own.",{"slug":45,"title":46,"shortTitle":47,"definition":48,"status":19,"industries":49,"functions":51,"patterns":54,"audience":57,"autonomy":58,"adoptionStage":33,"segment":34,"evidenceCount":59,"publicEvidenceCount":35,"organizations":60,"bestGrade":63,"headline":64,"lastVerified":74,"indexable":12,"euAiActTier":42,"euAiActBasis":75},"digital-onboarding-assistant","AI assistant for digital account onboarding and KYC","Digital onboarding","A customer facing AI assistant that guides a new applicant, a person or a small merchant, through a digital account, card or relationship application: it collects and checks identity and supporting documents, orchestrates the know your customer and anti money laundering checks, prefills what it can and sends only the unclear cases to a human reviewer with a summary. The ownership research for complex corporate clients is a separate back office job.",[22,50,21],"payments",[24,52,53],"sales","customer-service",[55,27,56,28],"conversational-agent","computer-vision","customer-facing","supervised-agent",6,[61,38,62],"Albo","M-DAQ Global","C",{"kpi":65,"label":66,"unit":67,"n":68,"nUpTo":69,"kind":70,"value":71,"qualifier":72,"claimant":73,"organization":62,"vendorReported":12},"productivity-gain","Productivity gain","multiplier",1,0,"reported",30,"exact","vendor","2026-09-27","The conversational assistant falls under the Article 50 transparency duty. Biometric verification whose sole purpose is to confirm that a person is who they claim to be is excluded from the Annex III biometric category. The system becomes high risk when the same journey assesses creditworthiness or a credit score of a natural person, for example for a credit card or overdraft (Annex III point 5(b)).",{"slug":77,"title":78,"shortTitle":79,"definition":80,"status":19,"industries":81,"functions":82,"patterns":84,"audience":31,"autonomy":32,"adoptionStage":86,"segment":87,"evidenceCount":88,"publicEvidenceCount":88,"organizations":89,"bestGrade":39,"headline":40,"lastVerified":41,"indexable":12,"euAiActTier":94,"euAiActBasis":95},"suspicious-activity-report-drafting","AI copilot for SAR and STR narrative drafting","SAR and STR drafting","Generative AI that drafts the narrative of a single suspicious activity or suspicious transaction report from the investigation file (who, what, when, where, why and how), with every fact linked to its source record, so the investigator verifies, edits and files instead of starting from a blank page. It works case by case, unlike the periodic data returns of regulatory reporting.",[22,50],[25,83],"case-management",[29,30,85,28],"rag-knowledge-assistant","emerging","middle-office",4,[90,91,92,93],"Finshark","BMO and Amalgamated Bank","Nexo","Uphold","minimal","Drafting internal reports for a human investigator is not listed in Annex III (the law enforcement uses in point 6 cover systems used by or for law enforcement authorities, not a bank's own reporting), and the text is not published to inform the public, so the deployer disclosure duty for generated text in Article 50(4) does not apply. Confidentiality rules for suspicious activity reports and GDPR apply in full.",{"slug":97,"title":98,"shortTitle":99,"definition":100,"status":19,"industries":101,"functions":102,"patterns":103,"audience":31,"autonomy":58,"adoptionStage":33,"segment":87,"evidenceCount":106,"publicEvidenceCount":106,"organizations":107,"bestGrade":39,"headline":113,"lastVerified":74,"indexable":12,"euAiActTier":94,"euAiActBasis":119},"aml-alert-triage","AI for AML transaction monitoring alert triage","AML alert triage","Machine learning and AI agents that score anti money laundering alerts for genuine risk, close clear false positives with a written and stored rationale, and hand investigators the remaining alerts already enriched with the customer, counterparty and transaction context.",[22,50],[25],[104,105,28,30],"prediction-and-scoring","anomaly-detection",8,[108,91,109,92,110,111,112,93],"Australia Post","HSBC","Ratepay","Shift4","United Overseas Bank (UOB)",{"kpi":114,"label":115,"unit":116,"n":117,"nUpTo":69,"kind":70,"value":118,"qualifier":72,"claimant":73,"organization":111,"vendorReported":12},"false-positive-reduction","False positive reduction","percent",2,86,"AML transaction monitoring is not listed in Annex III; point 5(b) covers creditworthiness and credit scoring and excludes systems used to detect financial fraud. The Article 5(1)(d) ban on predicting criminal offences from profiling alone does not apply to systems that support a human assessment already based on objective and verifiable facts linked to criminal activity, which is how alert triage should be designed. A decision to restrict an account taken solely by automated means would fall under GDPR Article 22 and national AML law, so consequential decisions need human review.",{"slug":121,"title":122,"shortTitle":123,"definition":124,"status":19,"industries":125,"functions":129,"patterns":132,"audience":133,"autonomy":58,"adoptionStage":33,"segment":34,"evidenceCount":59,"publicEvidenceCount":59,"organizations":134,"bestGrade":39,"headline":141,"lastVerified":41,"indexable":12,"euAiActTier":42,"euAiActBasis":146},"application-and-identity-fraud-detection","AI for application and identity fraud detection","Application and identity fraud","AI that checks incoming account and loan applications for forged or AI generated documents, synthetic and stolen identities, and coordinated application rings, by analysing documents, device and application data across the whole queue and cross checking against bureau and official sources.",[22,50,126,127,128],"cross-industry","government","telecommunications",[130,24,131],"fraud-prevention","lending-and-credit",[27,105,56,104],"back-office",[135,136,137,138,139,140],"BCU","Close Brothers Motor Finance","CNG Holdings","Department for Work and Pensions","Payoneer","Telstra",{"kpi":142,"label":143,"unit":67,"n":68,"nUpTo":69,"kind":70,"value":144,"qualifier":72,"claimant":145,"organization":138,"vendorReported":11},"detection-rate-improvement","Detection improvement",2.5,"organization","Annex III point 5(b) excludes AI used to detect financial fraud from the high risk credit scoring category, but a system that in effect decides on creditworthiness is high risk, and remote biometric identification is high risk under point 1(a), which excludes one to one biometric verification. When a public authority uses the model on claims for public benefits, point 5(a) can apply, because it covers AI used to grant, reduce, revoke or reclaim benefits and has no fraud exception. Keep fraud detection separate from the credit or eligibility decision and use biometrics only for one to one verification.",{"slug":148,"title":149,"shortTitle":150,"definition":151,"status":19,"industries":152,"functions":154,"patterns":155,"audience":133,"autonomy":58,"adoptionStage":86,"segment":157,"evidenceCount":35,"publicEvidenceCount":35,"organizations":158,"bestGrade":63,"headline":161,"lastVerified":74,"indexable":12,"euAiActTier":42,"euAiActBasis":165},"business-onboarding-and-ubo-discovery","AI for business onboarding (KYB) and beneficial ownership discovery","Business onboarding and UBO","An AI agent that builds the know your business (KYB) due diligence file for a new or reviewed corporate client, before any account is opened: it collects registry, incorporation and ownership documents, resolves the entity across sources, maps the ownership chain through holding companies, nominees and trusts to the ultimate beneficial owners, screens the entity and its owners, and presents a risk scored case for a compliance analyst to decide.",[22,50,153],"capital-markets",[24,25],[27,28,156,30],"classification-and-routing","specialized-businesses",[159,160,62],"BNY","Incore Bank",{"kpi":162,"label":163,"unit":116,"n":68,"nUpTo":69,"kind":70,"value":164,"qualifier":72,"claimant":145,"organization":159,"vendorReported":11},"automation-rate","Automation rate",25,"Customer due diligence on legal entities is not listed in Annex III, and an internal analyst tool usually carries no Article 50 transparency duty, so the system is usually minimal risk. The design decides the rest: biometric verification that only confirms a director is who they claim to be is excluded from Annex III point 1(a), but remote biometric identification (one to many matching) is high risk, and so is any use of the output to assess the creditworthiness of the natural persons involved (point 5(b)). GDPR applies to the personal data of owners and directors throughout. Keep biometric and credit steps in separately assessed components.",{"slug":167,"title":168,"shortTitle":169,"definition":170,"status":19,"industries":171,"functions":173,"patterns":175,"audience":133,"autonomy":58,"adoptionStage":33,"evidenceCount":88,"publicEvidenceCount":88,"organizations":176,"bestGrade":39,"headline":181,"lastVerified":74,"indexable":12,"euAiActTier":42,"euAiActBasis":186},"merchant-underwriting-and-risk-monitoring","AI for merchant underwriting and risk monitoring","Merchant underwriting and monitoring","AI that helps acquirers, payment facilitators and software platforms with embedded payments decide which merchants to accept and on what terms, by checking what a business really sells and how risky it is at onboarding, and then watches every active merchant for changes in behaviour, ranking the few that need an analyst so fraud, prohibited trade and credit losses are caught early.",[50,172,22],"technology",[24,130,174],"risk-management",[104,105,156,30,28],[177,178,179,180],"Airwallex","Tekmetric","Visa","Weave Communications",{"kpi":182,"label":183,"unit":116,"n":117,"nUpTo":69,"kind":70,"value":184,"qualifier":185,"claimant":73,"organization":180,"vendorReported":12},"alert-volume-reduction","Alert volume reduction",89,"approximately","Assessing businesses and detecting fraud is not an Annex III use as such, and Annex III point 5(b) excludes systems used to detect financial fraud. If the system evaluates the creditworthiness of a natural person, for example a sole trader applying to accept payments, it can fall under Annex III point 5(b), which covers evaluating the creditworthiness of natural persons or establishing their credit score, and be high risk. Keep credit assessment of individuals separate or treat it as a high risk system.",{"slug":188,"title":189,"shortTitle":190,"definition":191,"status":19,"industries":192,"functions":193,"patterns":194,"audience":133,"autonomy":32,"adoptionStage":33,"segment":87,"evidenceCount":35,"publicEvidenceCount":35,"organizations":195,"bestGrade":39,"headline":40,"lastVerified":74,"indexable":12,"euAiActTier":94,"euAiActBasis":199},"mule-network-detection","AI for money mule account and network detection","Mule network detection","Graph and behavioural machine learning that finds money mule accounts and the networks around them, such as circular flows, layering chains and clusters of newly linked accounts, and supports investigators in tracing scam proceeds and restricting accounts before the money is gone.",[22,50],[130,25],[105,104,28,30],[196,197,198],"BigPay","ANZ, Commonwealth Bank, NAB, Suncorp Bank and Westpac (BioCatch Trust Australia)","Reserve Bank Innovation Hub (Reserve Bank of India)","Detecting mule accounts is fraud and AML detection by a private firm, which Annex III does not list; point 5(b) explicitly excludes systems used to detect financial fraud from the credit scoring category. Restricting an account based solely on an automated score can be a decision with similarly significant effects under GDPR Article 22, so keep a human decision and a route to challenge.",{"slug":201,"title":202,"shortTitle":203,"definition":204,"status":19,"industries":205,"functions":206,"patterns":208,"audience":133,"autonomy":58,"adoptionStage":86,"segment":133,"evidenceCount":117,"publicEvidenceCount":117,"organizations":209,"bestGrade":39,"headline":211,"lastVerified":74,"indexable":12,"euAiActTier":94,"euAiActBasis":214},"payment-investigations-and-exceptions","AI for payment investigations and exceptions","Payment investigations and exceptions","AI that works the payments that fall out of straight through processing: it reads the failure, repairs or enriches the message, drafts the ISO 20022 or SWIFT investigation, chases the counterparty bank and proposes a return, recall or correction, while an operator approves anything that moves money.",[22,50],[207,53],"operations",[28,27,156,29],[159,210],"JPMorgan Chase",{"kpi":162,"label":163,"unit":116,"n":68,"nUpTo":69,"kind":70,"value":212,"qualifier":213,"claimant":145,"organization":159,"vendorReported":11},10,"at-least","Handling payment exceptions is not a use listed in Annex III and is not a prohibited practice under Article 5. If the agent interacts directly with customers, for example in a chat about the case, Article 50(1) requires that they are told they are interacting with an AI system.",{"slug":216,"title":217,"shortTitle":218,"definition":219,"status":19,"industries":220,"functions":221,"patterns":222,"audience":31,"autonomy":32,"adoptionStage":33,"segment":87,"evidenceCount":224,"publicEvidenceCount":224,"organizations":225,"bestGrade":39,"headline":231,"lastVerified":74,"indexable":12,"euAiActTier":94,"euAiActBasis":235},"pep-and-adverse-media-screening","AI for PEP and adverse media screening","PEP and adverse media screening","AI that continuously scans news, court records, registries and other open sources in many languages for negative information and political exposure linked to customers, counterparties and beneficial owners, discards look alikes, and summarises credible risk for the analyst with the sources attached.",[22,50,21],[25,24],[85,30,156,223],"translation",7,[38,109,226,227,228,229,230],"Mashreq","OCBC","Santander UK","Save the Children","Scotiabank",{"kpi":232,"label":233,"unit":116,"n":68,"nUpTo":68,"kind":70,"value":234,"qualifier":213,"claimant":73,"organization":229,"vendorReported":12},"handling-time-reduction","Handling time reduction",60,"Adverse media and PEP screening for due diligence is not listed in Annex III. It processes personal data, including data about alleged offences, so GDPR Article 10 and national AML law govern what may be collected and how long it is kept.",{"slug":237,"title":238,"shortTitle":239,"definition":240,"status":19,"industries":241,"functions":242,"patterns":243,"audience":133,"autonomy":58,"adoptionStage":86,"segment":87,"evidenceCount":244,"publicEvidenceCount":244,"organizations":245,"bestGrade":39,"headline":248,"lastVerified":41,"indexable":12,"euAiActTier":42,"euAiActBasis":252},"perpetual-kyc","AI for perpetual KYC and event driven customer due diligence","Perpetual KYC","AI that keeps each customer's due diligence file current by replacing calendar driven KYC reviews with continuous, event driven refreshes: it watches for trigger events such as a change of ownership, address, behaviour or a new adverse finding, refreshes the file automatically where it can, and involves an analyst only when something material has changed. The risk rating itself and the first file for a new business client are separate use cases.",[22,50,21],[24,25],[28,27,85,30],5,[38,246,210,227,247],"First National Bank of Omaha (FNBO)","Origin Bank",{"kpi":249,"label":250,"unit":116,"n":68,"nUpTo":69,"kind":70,"value":251,"qualifier":72,"claimant":145,"organization":210,"vendorReported":11},"cost-reduction","Cost reduction",40,"Keeping customer due diligence files current is not listed in Annex III, so a back office system that assembles reviews for an analyst to decide is usually minimal risk. The design decides the rest: a conversational agent that asks customers for missing information must tell them they are interacting with an AI system (Article 50(1)); biometric verification that only confirms a person is who they claim to be is excluded from Annex III point 1(a), while remote biometric identification is high risk; and Article 5(1)(d) prohibits assessing the risk that a person will commit a criminal offence based solely on profiling, so behavioural triggers should open a review for a human rather than score the customer. GDPR applies to the collection and retention of KYC data, including Article 22 if an automated refresh leads to a decision with legal or similarly significant effect, such as closing an account.",{"slug":254,"title":255,"shortTitle":256,"definition":257,"status":19,"industries":258,"functions":260,"patterns":263,"audience":31,"autonomy":32,"adoptionStage":86,"segment":133,"evidenceCount":117,"publicEvidenceCount":117,"organizations":264,"bestGrade":39,"headline":40,"lastVerified":74,"indexable":12,"euAiActTier":267,"euAiActBasis":268},"regulatory-report-assembly","AI for regulatory report assembly","Regulatory report assembly","AI that assembles periodic and data driven regulatory filings and returns, such as prudential and statistical returns, threshold and transaction reports and disclosure packs, by pulling data into the regulator's schema, validating it, reconciling figures to source, explaining movements against prior periods and drafting commentary, before a named officer reviews and submits. Narratives for individual suspicious activity cases are a separate use case.",[22,259,153,50],"insurance",[261,262,25],"regulatory-compliance","finance-and-accounting",[28,105,29,30],[265,266],"Board of Governors of the Federal Reserve System","National Credit Union Administration","limited","Not an Article 5 practice and not listed in Annex III: the system prepares filings for authorities and makes no decision on the credit, insurance, employment or access to services of a natural person. It is an internal tool whose users know they are working with AI, and drafted text that ends up in public disclosures passes human review under a named person's editorial responsibility, which takes it outside the Article 50(4) deployer disclosure duty. The system still drafts variance commentary and plain language explanations of validation failures from underlying data, rather than lightly editing existing text, so the assistive function for standard editing exception does not fit. The bank that builds or operates the system is then the provider and carries the Article 50(2) duty to mark that generated text in a machine readable way as artificially generated, which has applied since 2 August 2026. The AI literacy duty of Article 4 also applies.",{"slug":270,"title":271,"shortTitle":272,"definition":273,"status":19,"industries":274,"functions":275,"patterns":276,"audience":133,"autonomy":58,"adoptionStage":33,"segment":87,"evidenceCount":224,"publicEvidenceCount":224,"organizations":277,"bestGrade":39,"headline":280,"lastVerified":41,"indexable":12,"euAiActTier":94,"euAiActBasis":281},"sanctions-screening-adjudication","AI for sanctions screening alert adjudication","Sanctions screening adjudication","AI that works the alerts raised when customer, counterparty or payment names match sanctions and watchlists: it resolves fuzzy matches across transliterations, aliases and naming conventions, clears clear non matches with a documented reason, and escalates true or uncertain hits with the evidence attached.",[22,50],[25],[156,104,28],[278,246,109,226,110,279,112],"AJ Bell","Standard Chartered",{"kpi":114,"label":115,"unit":116,"n":68,"nUpTo":69,"kind":70,"value":234,"qualifier":72,"claimant":145,"organization":112,"vendorReported":11},"Sanctions screening by banks and payment firms is not listed in Annex III: point 5 covers credit scoring and life and health insurance pricing, and point 6 covers AI used by or on behalf of law enforcement authorities. It is not a prohibited practice under Article 5, and as an internal tool it carries no Article 50 transparency duty. It still processes personal data at scale, so GDPR applies, and decisions that block a payment or freeze assets remain human decisions.",{"slug":283,"title":284,"shortTitle":285,"definition":286,"status":19,"industries":287,"functions":288,"patterns":289,"audience":133,"autonomy":58,"adoptionStage":86,"segment":157,"evidenceCount":35,"publicEvidenceCount":35,"organizations":290,"bestGrade":63,"headline":40,"lastVerified":74,"indexable":12,"euAiActTier":94,"euAiActBasis":294},"trade-finance-crime-screening","AI screening of trade finance transactions for trade based money laundering","Trade crime screening","AI that screens every trade finance transaction for financial crime risk: it checks parties, vessels and ports against sanctions and watchlists, tests goods descriptions against dual use and controlled goods lists, compares unit prices with benchmarks for over or under invoicing, and reads trade documents and messages for laundering red flags, then prepares a case narrative for a human investigator.",[22],[25,207],[27,105,156,30],[291,292,293],"ANZ, HSBC and Lloyds Banking Group","Stanbic Bank Uganda","United Bank Limited","Financial crime screening of trade transactions is not listed in Annex III. It still processes personal data of individual parties, so GDPR applies, and supervisors expect it to be governed like any financial crime model.",{"slug":296,"title":297,"shortTitle":298,"definition":299,"status":19,"industries":300,"functions":301,"patterns":302,"audience":133,"autonomy":58,"adoptionStage":33,"segment":87,"evidenceCount":68,"publicEvidenceCount":68,"organizations":303,"bestGrade":39,"headline":40,"lastVerified":74,"indexable":12,"euAiActTier":42,"euAiActBasis":305},"dynamic-customer-risk-rating","Dynamic AML customer risk rating with machine learning","Dynamic customer risk rating","Explainable machine learning that produces the money laundering risk rating itself: it computes and continuously updates each customer's rating from due diligence data, products, geography, behaviour and screening results, and shows which factors drive the rating and when enhanced due diligence is warranted.",[22,50,21],[25,174],[104,105],[304],"bunq","An AML customer risk rating is not listed in Annex III. Article 5(1)(d) prohibits AI risk assessments that predict whether a natural person will commit or will likely commit a criminal offence based solely on profiling of that person or on assessing their personality traits and characteristics; it exempts only AI that supports the human assessment of a person's involvement in a criminal activity, which is already based on objective and verifiable facts directly linked to a criminal activity. An AML customer risk rating built from due diligence attributes, transaction behaviour and screening results is itself an automated evaluation of a person's situation and behaviour, which is profiling under GDPR Article 4(4), and due diligence facts such as occupation, geography and products are not facts directly linked to a criminal activity, so the rating does not sit squarely inside the exemption. What keeps it a defensible AML due diligence tool rather than an offence prediction is that it does not itself accuse a person of an offence: it sets a level of scrutiny, a human analyst reviews material moves, and regulatory minimum rules sit above the model as hard constraints. A rating driven mainly by nationality or other personal attributes weakens that position further, which is why the proxy discrimination guardrail matters. If the same score is used to evaluate the creditworthiness of natural persons or to establish their credit score, that use falls under Annex III point 5(b) and is high risk, so keep the AML rating and credit decisions separate.",1790598319464]