[{"data":1,"prerenderedAt":601},["ShallowReactive",2],{"uc-reg-mas-ai-risk-management":3},{"regulation":4,"includeUnpublished":11,"indexable":12,"useCases":13},{"id":5,"label":6,"issuer":7,"region":8,"url":9,"description":10},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",false,true,[14,44,78,93,107,135,154,169,185,201,217,229,244,257,276,295,312,330,344,363,379,393,405,416,429,445,459,469,480,493,511,522,538,553,564,580],{"slug":15,"title":16,"shortTitle":17,"definition":18,"status":19,"industries":20,"functions":23,"patterns":26,"audience":31,"autonomy":32,"adoptionStage":33,"segment":34,"evidenceCount":35,"publicEvidenceCount":35,"organizations":36,"bestGrade":39,"headline":40,"lastVerified":41,"indexable":12,"euAiActTier":42,"euAiActBasis":43},"source-of-wealth-diligence","AI agent for source of wealth due diligence in private banking","Source of wealth diligence","An AI agent that reads a prospective private client's documents, extracts and corroborates how their wealth was built, checks plausibility against benchmarks and external sources, and drafts the source of wealth and enhanced due diligence narrative for the relationship manager and compliance analyst, who decide on the risk rating and the relationship.","published",[21,22],"wealth-and-asset-management","banking",[24,25],"onboarding-and-kyc","financial-crime-compliance",[27,28,29,30],"document-processing","agentic-workflow","content-generation","summarization","employee-facing","copilot","early-adopters","front-office",3,[37,38],"Bank of Singapore","Deutsche Bank","B",null,"2026-09-26","context-dependent","Anti money laundering due diligence is not listed in Annex III, so an assistant that drafts source of wealth reports for a human decision is not high risk by default. It becomes high risk if it adds remote biometric identification of the client (Annex III point 1(a); verification that only confirms a claimed identity is excluded) or feeds an assessment of a natural person's creditworthiness, for example for lending to the client (Annex III point 5(b)). GDPR Article 22 on solely automated decisions applies if it ever refused a client on its own.",{"slug":45,"title":46,"shortTitle":47,"definition":48,"status":19,"industries":49,"functions":51,"patterns":54,"audience":57,"autonomy":58,"adoptionStage":33,"segment":59,"evidenceCount":60,"publicEvidenceCount":61,"organizations":62,"bestGrade":39,"headline":65,"lastVerified":75,"indexable":12,"euAiActTier":76,"euAiActBasis":77},"corporate-client-servicing-assistant","AI assistant for corporate and commercial client servicing","Corporate client servicing","A conversational assistant inside the corporate banking portal, app and messaging channels that answers finance and treasury teams' servicing questions, such as payment status, balances, cut off times, fees and how to submit an instruction, resolves routine requests end to end and hands the rest to a service specialist who has an AI copilot.",[22,50],"payments",[52,53],"customer-service","operations",[55,56,28,30],"conversational-agent","rag-knowledge-assistant","customer-facing","supervised-agent","specialized-businesses",5,2,[63,64],"Bank of America","DBS Bank",{"kpi":66,"label":67,"unit":68,"n":69,"nUpTo":70,"kind":71,"value":72,"qualifier":73,"claimant":74,"organization":63,"vendorReported":11},"contact-deflection","Contact deflection","percent",1,0,"reported",16,"exact","organization","2026-09-27","limited","A chatbot that interacts with people at client companies must disclose that it is AI (Article 50). It does not evaluate creditworthiness or decide on access to an essential service (Annex III point 5), so it is not high risk.",{"slug":79,"title":80,"shortTitle":81,"definition":82,"status":19,"industries":83,"functions":84,"patterns":87,"audience":31,"autonomy":32,"adoptionStage":88,"segment":34,"evidenceCount":61,"publicEvidenceCount":61,"organizations":89,"bestGrade":39,"headline":40,"lastVerified":75,"indexable":12,"euAiActTier":42,"euAiActBasis":92},"goal-based-financial-planning-assistant","AI assistant for goal based financial planning","Goal based planning","An AI assistant that turns a client's goals into projections and what if scenarios using a rules based planning engine, explains the trade offs in plain language and prepares the plan for an advisor to validate, with every assumption disclosed and reproducible.",[21,22],[85,52,86],"sales","product-and-pricing",[55,29,28],"emerging",[90,91],"CIMB Niaga","Vanguard","Planning support for advisors is not listed in Annex III. A client facing version must disclose that the client is talking to AI (Article 50). It becomes high risk if it is used to assess the creditworthiness of individuals (Annex III point 5(b)) or for risk assessment and pricing of life or health insurance for individuals (Annex III point 5(c)).",{"slug":94,"title":95,"shortTitle":96,"definition":97,"status":19,"industries":98,"functions":99,"patterns":102,"audience":31,"autonomy":32,"adoptionStage":88,"segment":34,"evidenceCount":61,"publicEvidenceCount":61,"organizations":104,"bestGrade":39,"headline":40,"lastVerified":41,"indexable":12,"euAiActTier":42,"euAiActBasis":106},"suitability-assessment-assistant","AI assistant for investment suitability assessment and reports","Suitability assessment","An AI assistant that checks whether a proposed product or portfolio fits a client's risk tolerance, objectives, knowledge, experience and financial situation against the firm's rules, flags mismatches, and drafts the suitability rationale and report for the advisor to confirm, while hard rule failures are decided by deterministic checks, not by the model.",[21,22],[100,85,101],"regulatory-compliance","risk-management",[28,29,103],"classification-and-routing",[105,91],"Morgan Stanley","Investment suitability assessment is not listed in Annex III, so the tier depends on design. It becomes high risk where the same system assesses creditworthiness, for example for lending against a portfolio (Annex III point 5(b)). MiFID II suitability duties apply regardless of the AI Act tier.",{"slug":108,"title":109,"shortTitle":110,"definition":111,"status":19,"industries":112,"functions":117,"patterns":121,"audience":31,"autonomy":123,"adoptionStage":33,"segment":59,"evidenceCount":60,"publicEvidenceCount":60,"organizations":124,"bestGrade":39,"headline":129,"lastVerified":75,"indexable":12,"euAiActTier":76,"euAiActBasis":134},"treasury-cash-flow-forecasting","AI cash flow forecasting for corporate treasury","Treasury cash forecasting","Machine learning and conversational analytics, offered by some banks inside their cash management platforms, that categorise a company's cash flows, forecast positions across accounts and currencies, and answer treasurers' questions in plain language, so the treasury team decides on funding and idle balances with better information and less spreadsheet work.",[22,113,114,115,116],"cross-industry","logistics-and-transportation","retail-and-ecommerce","manufacturing",[118,119,120],"treasury","finance-and-accounting","analytics-and-reporting",[122,103,55,28],"prediction-and-scoring","assist",[125,63,126,127,128],"Amtrak","Domino's Pizza","JPMorgan Chase","Prysmian",{"kpi":130,"label":131,"unit":68,"n":61,"nUpTo":69,"kind":71,"value":132,"qualifier":133,"claimant":74,"organization":127,"vendorReported":11},"productivity-gain","Productivity gain",90,"approximately","Forecasting a company's cash flows is not listed in Annex III and makes no decision about a natural person, so the forecasting model itself carries no obligations beyond AI literacy (Article 4). The conversational layer interacts directly with treasury staff, so under Article 50(1) they must be informed that they are dealing with an AI system unless that is obvious from the context. Without a conversational layer the use case is minimal risk.",{"slug":136,"title":137,"shortTitle":138,"definition":139,"status":19,"industries":140,"functions":141,"patterns":144,"audience":145,"autonomy":58,"adoptionStage":33,"segment":146,"evidenceCount":147,"publicEvidenceCount":147,"organizations":148,"bestGrade":39,"headline":40,"lastVerified":41,"indexable":12,"euAiActTier":42,"euAiActBasis":153},"sme-cash-flow-underwriting","AI cash flow underwriting for small business loans","SME cash flow underwriting","An underwriting engine that assesses a small business's repayment capacity from live bank transactions, point of sale and payment flows, receivables and accounting data instead of audited accounts, and returns a decision recommendation with the evidence and reasons behind it.",[22],[142,143,101],"lending-and-credit","underwriting",[122,27,28,55],"back-office","lending",4,[149,150,151,152],"MYbank","National Australia Bank","OakNorth Bank","Sumitomo Mitsui Banking Corporation","Annex III point 5(b) makes AI systems that evaluate the creditworthiness of natural persons or establish their credit score high risk. Scoring a company is outside that point, but a sole trader is a natural person, and a model that also assesses the personal credit of owners, partners or guarantors evaluates natural persons. The tier therefore depends on who the borrower is and whose creditworthiness the model assesses.",{"slug":155,"title":156,"shortTitle":157,"definition":158,"status":19,"industries":159,"functions":161,"patterns":163,"audience":31,"autonomy":32,"adoptionStage":33,"segment":59,"evidenceCount":35,"publicEvidenceCount":35,"organizations":164,"bestGrade":39,"headline":40,"lastVerified":75,"indexable":12,"euAiActTier":167,"euAiActBasis":168},"client-briefing-and-call-report-copilot","AI copilot for corporate client briefings and call reports","Client briefing and call reports","An AI copilot for relationship managers, mainly in corporate and commercial banking, whose main job is preparation: before a client meeting it assembles a briefing pack from filings, news, internal notes, product holdings and upcoming maturities, and afterwards it turns the banker's notes into a structured call report and CRM update. Unlike a meeting notetaker, which centres on capturing the conversation, it centres on the credit and cross sell context around the meeting; wealth advisor tools that also prepare meetings overlap with it. The banker reviews every output.",[22,21,160],"capital-markets",[85,162],"knowledge-management",[56,30,29,28],[63,165,166],"Scotiabank","Standard Chartered","minimal","Bankers interact with the copilot directly, but Article 50(1) does not bite here: it requires telling people they are dealing with an AI system unless that is obvious to a reasonably well informed person, and an internal tool that is openly presented and labelled as an AI assistant meets that bar by design. The copilot never interacts with the client. Article 50(2) marking of generated text falls on the provider of the system, including a bank that builds it in house, but the copilot turns a banker's own notes into a call report, an assistive function for standard editing of the banker's input that does not substantially alter it, so the Article 50(2) exception applies and no machine readable marking is required. It is not an Annex III use: credit context about corporate clients is not the creditworthiness assessment of natural persons in Annex III point 5(b), so it falls outside the high risk tier. If a deployment starts to score individuals for credit, the tier changes. AI literacy duties under Article 4 still apply. If meeting capture is used, recording and transcription rules under data protection law apply separately.",{"slug":170,"title":171,"shortTitle":172,"definition":173,"status":19,"industries":174,"functions":176,"patterns":177,"audience":31,"autonomy":32,"adoptionStage":88,"segment":179,"evidenceCount":35,"publicEvidenceCount":35,"organizations":180,"bestGrade":39,"headline":40,"lastVerified":183,"indexable":12,"euAiActTier":167,"euAiActBasis":184},"model-risk-validation-copilot","AI copilot for model risk validation and monitoring","Model risk validation","A copilot for independent model validation and review, whether run by a bank's validation function, an external tester or a supervisor, that checks model documentation against the model risk standard, generates and scores challenger tests (for generative AI, often with an LLM as a judge calibrated against human experts), watches production models for drift and drafts and consistency checks the validation report. An accountable validator owns every conclusion.",[22,175,160,21],"insurance",[101,100],[28,27,29,178],"anomaly-detection","second-line",[181,166,182],"European Central Bank (ECB Banking Supervision)","United Overseas Bank (UOB)","2026-09-28","A validation copilot supports internal governance and is not itself an Annex III use, and its drafts are internal, so Article 50 transparency duties do not normally apply. It often helps validate models that are high risk under Annex III (point 5(b), creditworthiness and credit scoring of natural persons; point 5(c), life and health insurance pricing), and the testing and documentation it supports feed the provider obligations of Articles 9, 11 and 15.",{"slug":186,"title":187,"shortTitle":188,"definition":189,"status":19,"industries":190,"functions":191,"patterns":193,"audience":31,"autonomy":32,"adoptionStage":88,"segment":194,"evidenceCount":147,"publicEvidenceCount":147,"organizations":195,"bestGrade":39,"headline":40,"lastVerified":41,"indexable":12,"euAiActTier":167,"euAiActBasis":200},"suspicious-activity-report-drafting","AI copilot for SAR and STR narrative drafting","SAR and STR drafting","Generative AI that drafts the narrative of a single suspicious activity or suspicious transaction report from the investigation file (who, what, when, where, why and how), with every fact linked to its source record, so the investigator verifies, edits and files instead of starting from a blank page. It works case by case, unlike the periodic data returns of regulatory reporting.",[22,50],[25,192],"case-management",[29,30,56,28],"middle-office",[196,197,198,199],"Finshark","BMO and Amalgamated Bank","Nexo","Uphold","Drafting internal reports for a human investigator is not listed in Annex III (the law enforcement uses in point 6 cover systems used by or for law enforcement authorities, not a bank's own reporting), and the text is not published to inform the public, so the deployer disclosure duty for generated text in Article 50(4) does not apply. Confidentiality rules for suspicious activity reports and GDPR apply in full.",{"slug":202,"title":203,"shortTitle":204,"definition":205,"status":19,"industries":206,"functions":207,"patterns":208,"audience":145,"autonomy":58,"adoptionStage":33,"segment":146,"evidenceCount":60,"publicEvidenceCount":60,"organizations":209,"bestGrade":39,"headline":40,"lastVerified":41,"indexable":12,"euAiActTier":215,"euAiActBasis":216},"alternative-data-credit-scoring","AI credit scoring with alternative data for thin file applicants","Alternative data credit scoring","A machine learning credit model that adds consumer permissioned alternative data, such as bank account cash flow, rent, utility and telco payments or ecosystem data, to credit bureau data, so a lender can assess applicants with thin or no credit files and return a decision with specific reasons.",[22,50],[142,143,101],[122,27,55],[210,211,212,213,214],"Atlanticus","Golden 1 Credit Union","GXS Bank","Patelco Credit Union","Upstart Network","high","Annex III point 5(b): AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score are high risk, except systems used to detect financial fraud. Providers need risk management, data governance, logging and human oversight. Deployers must carry out a fundamental rights impact assessment before use (Article 27), and affected persons have a right to an explanation of individual decisions from the deployer (Article 86).",{"slug":218,"title":219,"shortTitle":220,"definition":221,"status":19,"industries":222,"functions":223,"patterns":224,"audience":31,"autonomy":123,"adoptionStage":33,"segment":146,"evidenceCount":35,"publicEvidenceCount":35,"organizations":225,"bestGrade":227,"headline":40,"lastVerified":75,"indexable":12,"euAiActTier":42,"euAiActBasis":228},"credit-early-warning-monitoring","AI early warning and covenant monitoring for loan portfolios","Credit early warning and covenants","A monitoring system that tracks covenant tests and borrower reporting across a loan book, reads financials, filings and news, and combines them with payment and sector signals to flag borrowers whose credit is deteriorating, with the evidence and a suggested next step for the relationship manager.",[22],[101,142],[178,27,28,30],[151,226,152],"PNC Financial Services","C","Monitoring the credit of companies is not listed in Annex III. Where the same system evaluates the creditworthiness of natural persons, such as sole traders or personal guarantors, it falls under Annex III point 5(b) and is high risk; because that evaluation profiles natural persons, the Article 6(3) exemption does not apply.",{"slug":230,"title":231,"shortTitle":232,"definition":233,"status":19,"industries":234,"functions":237,"patterns":238,"audience":31,"autonomy":123,"adoptionStage":239,"evidenceCount":147,"publicEvidenceCount":147,"organizations":240,"bestGrade":39,"headline":40,"lastVerified":75,"indexable":12,"euAiActTier":76,"euAiActBasis":243},"enterprise-knowledge-search","AI enterprise knowledge search for employees","Enterprise knowledge search","An assistant that lets any employee ask a question in plain language and get a synthesized answer from the organization's own policies, procedures, product manuals and research, with citations to the source documents and only from documents the employee is allowed to see.",[113,22,21,175,235,236],"government","professional-services",[162,53,52],[56,55,30],"mainstream",[63,105,241,242],"SIGNAL IDUNA","Wells Fargo","Article 50(1) requires that people who interact directly with an AI system are informed of it, unless this is obvious from the context, as it usually is for an internal assistant. The system would be high risk only if it were intended for an Annex III purpose, such as assessing the creditworthiness of natural persons (point 5(b)) or making decisions on or evaluating workers (point 4(b)).",{"slug":245,"title":246,"shortTitle":247,"definition":248,"status":19,"industries":249,"functions":250,"patterns":251,"audience":145,"autonomy":58,"adoptionStage":33,"segment":59,"evidenceCount":35,"publicEvidenceCount":35,"organizations":252,"bestGrade":39,"headline":40,"lastVerified":75,"indexable":12,"euAiActTier":167,"euAiActBasis":256},"trade-document-examination","AI examination of trade documents under letters of credit and collections","Trade document examination","AI that reads the full document presentation under a letter of credit or collection (bill of lading, commercial invoice, packing list, certificates), extracts and cross checks the data, tests it against the instructions and the ICC rules (for letters of credit, the credit terms, UCP 600 and ISBP), and lists discrepancies by severity with the rule cited, so qualified examiners focus on the genuine exceptions.",[22],[53,100],[27,103,28,30],[253,254,255],"ANZ, HSBC and Lloyds Banking Group","Rand Merchant Bank","Stanbic Bank Uganda","Checking trade documents for compliance with credit terms is not listed in Annex III and does not decide about natural persons. AI literacy duties under Article 4 apply, and the process falls under the bank's operational resilience and model governance.",{"slug":258,"title":259,"shortTitle":260,"definition":261,"status":19,"industries":262,"functions":263,"patterns":265,"audience":57,"autonomy":58,"adoptionStage":33,"segment":34,"evidenceCount":267,"publicEvidenceCount":268,"organizations":269,"bestGrade":39,"headline":40,"lastVerified":75,"indexable":12,"euAiActTier":42,"euAiActBasis":275},"financial-wellbeing-coach","AI financial wellbeing coach in the banking app","Financial wellbeing coach","An in app AI assistant that the customer opens to understand their own money: it uses the customer's transaction data to explain their spending, forecast upcoming bills and cash flow, set and track savings goals and answer money questions in plain language, staying on the guidance side of the line between guidance and regulated financial advice.",[22],[52,264],"marketing",[55,266,122,28],"recommendation-and-personalization",8,6,[63,270,271,272,273,274],"Commonwealth Bank of Australia","Hyundai Card","Royal Bank of Canada","Starling Bank","Westpac","The conversational assistant carries the Article 50 transparency duty: customers must be told they are interacting with an AI system. The system becomes high risk if it is used to evaluate the creditworthiness of natural persons or establish their credit score (Annex III point 5(b)). Article 5(1)(b) prohibits AI that exploits vulnerabilities due to a person's specific social or economic situation to materially distort their behaviour in a way that causes, or is reasonably likely to cause, significant harm.",{"slug":277,"title":278,"shortTitle":279,"definition":280,"status":19,"industries":281,"functions":282,"patterns":283,"audience":31,"autonomy":58,"adoptionStage":33,"segment":194,"evidenceCount":267,"publicEvidenceCount":267,"organizations":284,"bestGrade":39,"headline":289,"lastVerified":75,"indexable":12,"euAiActTier":167,"euAiActBasis":294},"aml-alert-triage","AI for AML transaction monitoring alert triage","AML alert triage","Machine learning and AI agents that score anti money laundering alerts for genuine risk, close clear false positives with a written and stored rationale, and hand investigators the remaining alerts already enriched with the customer, counterparty and transaction context.",[22,50],[25],[122,178,28,30],[285,197,286,198,287,288,182,199],"Australia Post","HSBC","Ratepay","Shift4",{"kpi":290,"label":291,"unit":68,"n":61,"nUpTo":70,"kind":71,"value":292,"qualifier":73,"claimant":293,"organization":288,"vendorReported":12},"false-positive-reduction","False positive reduction",86,"vendor","AML transaction monitoring is not listed in Annex III; point 5(b) covers creditworthiness and credit scoring and excludes systems used to detect financial fraud. The Article 5(1)(d) ban on predicting criminal offences from profiling alone does not apply to systems that support a human assessment already based on objective and verifiable facts linked to criminal activity, which is how alert triage should be designed. A decision to restrict an account taken solely by automated means would fall under GDPR Article 22 and national AML law, so consequential decisions need human review.",{"slug":296,"title":297,"shortTitle":298,"definition":299,"status":19,"industries":300,"functions":301,"patterns":302,"audience":145,"autonomy":58,"adoptionStage":88,"segment":59,"evidenceCount":35,"publicEvidenceCount":35,"organizations":303,"bestGrade":227,"headline":307,"lastVerified":75,"indexable":12,"euAiActTier":42,"euAiActBasis":311},"business-onboarding-and-ubo-discovery","AI for business onboarding (KYB) and beneficial ownership discovery","Business onboarding and UBO","An AI agent that builds the know your business (KYB) due diligence file for a new or reviewed corporate client, before any account is opened: it collects registry, incorporation and ownership documents, resolves the entity across sources, maps the ownership chain through holding companies, nominees and trusts to the ultimate beneficial owners, screens the entity and its owners, and presents a risk scored case for a compliance analyst to decide.",[22,50,160],[24,25],[27,28,103,30],[304,305,306],"BNY","Incore Bank","M-DAQ Global",{"kpi":308,"label":309,"unit":68,"n":69,"nUpTo":70,"kind":71,"value":310,"qualifier":73,"claimant":74,"organization":304,"vendorReported":11},"automation-rate","Automation rate",25,"Customer due diligence on legal entities is not listed in Annex III, and an internal analyst tool usually carries no Article 50 transparency duty, so the system is usually minimal risk. The design decides the rest: biometric verification that only confirms a director is who they claim to be is excluded from Annex III point 1(a), but remote biometric identification (one to many matching) is high risk, and so is any use of the output to assess the creditworthiness of the natural persons involved (point 5(b)). GDPR applies to the personal data of owners and directors throughout. Keep biometric and credit steps in separately assessed components.",{"slug":313,"title":314,"shortTitle":315,"definition":316,"status":19,"industries":317,"functions":318,"patterns":319,"audience":31,"autonomy":32,"adoptionStage":33,"segment":179,"evidenceCount":60,"publicEvidenceCount":60,"organizations":320,"bestGrade":39,"headline":325,"lastVerified":41,"indexable":12,"euAiActTier":42,"euAiActBasis":329},"market-abuse-surveillance-triage","AI for market abuse surveillance alert triage","Market abuse surveillance","AI that helps surveillance analysts triage market abuse and conduct alerts, such as spoofing, layering, wash trades, ramping and insider dealing, by gathering the trade, order, news and communications context, explaining in plain language what triggered each alert and drafting the investigation narrative for the analyst to disposition.",[160,22,21],[100,25],[178,28,30,103],[321,38,322,323,324],"Commodity Futures Trading Commission","Japan Exchange Group","Nasdaq","U.S. Securities and Exchange Commission",{"kpi":326,"label":327,"unit":68,"n":69,"nUpTo":70,"kind":71,"value":328,"qualifier":133,"claimant":74,"organization":323,"vendorReported":11},"handling-time-reduction","Handling time reduction",33,"Surveillance of orders and transactions as such is not listed in Annex III. Where the system monitors and evaluates the behaviour of the firm's own staff, in their communications or their trading, it can fall under Annex III point 4(b) (AI used to monitor and evaluate the performance and behaviour of persons in work relationships), so the tier depends on whether the system scores individual employees. Inferring employees' emotions from biometric data such as voice recordings is prohibited in the workplace under Article 5(1)(f).",{"slug":331,"title":332,"shortTitle":333,"definition":334,"status":19,"industries":335,"functions":336,"patterns":338,"audience":145,"autonomy":32,"adoptionStage":33,"segment":194,"evidenceCount":35,"publicEvidenceCount":35,"organizations":339,"bestGrade":39,"headline":40,"lastVerified":75,"indexable":12,"euAiActTier":167,"euAiActBasis":343},"mule-network-detection","AI for money mule account and network detection","Mule network detection","Graph and behavioural machine learning that finds money mule accounts and the networks around them, such as circular flows, layering chains and clusters of newly linked accounts, and supports investigators in tracing scam proceeds and restricting accounts before the money is gone.",[22,50],[337,25],"fraud-prevention",[178,122,28,30],[340,341,342],"BigPay","ANZ, Commonwealth Bank, NAB, Suncorp Bank and Westpac (BioCatch Trust Australia)","Reserve Bank Innovation Hub (Reserve Bank of India)","Detecting mule accounts is fraud and AML detection by a private firm, which Annex III does not list; point 5(b) explicitly excludes systems used to detect financial fraud from the credit scoring category. Restricting an account based solely on an automated score can be a decision with similarly significant effects under GDPR Article 22, so keep a human decision and a route to challenge.",{"slug":345,"title":346,"shortTitle":347,"definition":348,"status":19,"industries":349,"functions":350,"patterns":351,"audience":31,"autonomy":32,"adoptionStage":33,"segment":194,"evidenceCount":353,"publicEvidenceCount":353,"organizations":354,"bestGrade":39,"headline":359,"lastVerified":75,"indexable":12,"euAiActTier":167,"euAiActBasis":362},"pep-and-adverse-media-screening","AI for PEP and adverse media screening","PEP and adverse media screening","AI that continuously scans news, court records, registries and other open sources in many languages for negative information and political exposure linked to customers, counterparties and beneficial owners, discards look alikes, and summarises credible risk for the analyst with the sources attached.",[22,50,21],[25,24],[56,30,103,352],"translation",7,[38,286,355,356,357,358,165],"Mashreq","OCBC","Santander UK","Save the Children",{"kpi":326,"label":327,"unit":68,"n":69,"nUpTo":69,"kind":71,"value":360,"qualifier":361,"claimant":293,"organization":358,"vendorReported":12},60,"at-least","Adverse media and PEP screening for due diligence is not listed in Annex III. It processes personal data, including data about alleged offences, so GDPR Article 10 and national AML law govern what may be collected and how long it is kept.",{"slug":364,"title":365,"shortTitle":366,"definition":367,"status":19,"industries":368,"functions":369,"patterns":370,"audience":145,"autonomy":58,"adoptionStage":88,"segment":194,"evidenceCount":60,"publicEvidenceCount":60,"organizations":371,"bestGrade":39,"headline":374,"lastVerified":41,"indexable":12,"euAiActTier":42,"euAiActBasis":378},"perpetual-kyc","AI for perpetual KYC and event driven customer due diligence","Perpetual KYC","AI that keeps each customer's due diligence file current by replacing calendar driven KYC reviews with continuous, event driven refreshes: it watches for trigger events such as a change of ownership, address, behaviour or a new adverse finding, refreshes the file automatically where it can, and involves an analyst only when something material has changed. The risk rating itself and the first file for a new business client are separate use cases.",[22,50,21],[24,25],[28,27,56,30],[38,372,127,356,373],"First National Bank of Omaha (FNBO)","Origin Bank",{"kpi":375,"label":376,"unit":68,"n":69,"nUpTo":70,"kind":71,"value":377,"qualifier":73,"claimant":74,"organization":127,"vendorReported":11},"cost-reduction","Cost reduction",40,"Keeping customer due diligence files current is not listed in Annex III, so a back office system that assembles reviews for an analyst to decide is usually minimal risk. The design decides the rest: a conversational agent that asks customers for missing information must tell them they are interacting with an AI system (Article 50(1)); biometric verification that only confirms a person is who they claim to be is excluded from Annex III point 1(a), while remote biometric identification is high risk; and Article 5(1)(d) prohibits assessing the risk that a person will commit a criminal offence based solely on profiling, so behavioural triggers should open a review for a human rather than score the customer. GDPR applies to the collection and retention of KYC data, including Article 22 if an automated refresh leads to a decision with legal or similarly significant effect, such as closing an account.",{"slug":380,"title":381,"shortTitle":382,"definition":383,"status":19,"industries":384,"functions":385,"patterns":387,"audience":31,"autonomy":32,"adoptionStage":88,"segment":179,"evidenceCount":35,"publicEvidenceCount":35,"organizations":388,"bestGrade":39,"headline":40,"lastVerified":41,"indexable":12,"euAiActTier":167,"euAiActBasis":392},"policy-drafting-and-gap-analysis","AI for policy drafting and policy gap analysis","Policy drafting and gaps","An assistant that takes a new or changed obligation, finds every internal policy, standard and procedure it touches, flags clauses that now conflict or are silent, and drafts the updated wording in house style as a redline for the policy owner to approve.",[113,22,175,160,235],[100,386,162],"legal",[56,29,27,30],[389,390,391],"Federal Deposit Insurance Corporation","Administration for Children and Families","Health Resources and Services Administration","Drafting internal policy text for human approval is not an Annex III use and has no direct effect on individuals. The Article 4 AI literacy measures still apply to the staff who use it.",{"slug":394,"title":395,"shortTitle":396,"definition":397,"status":19,"industries":398,"functions":399,"patterns":400,"audience":145,"autonomy":58,"adoptionStage":33,"segment":194,"evidenceCount":353,"publicEvidenceCount":353,"organizations":401,"bestGrade":39,"headline":403,"lastVerified":41,"indexable":12,"euAiActTier":167,"euAiActBasis":404},"sanctions-screening-adjudication","AI for sanctions screening alert adjudication","Sanctions screening adjudication","AI that works the alerts raised when customer, counterparty or payment names match sanctions and watchlists: it resolves fuzzy matches across transliterations, aliases and naming conventions, clears clear non matches with a documented reason, and escalates true or uncertain hits with the evidence attached.",[22,50],[25],[103,122,28],[402,372,286,355,287,166,182],"AJ Bell",{"kpi":290,"label":291,"unit":68,"n":69,"nUpTo":70,"kind":71,"value":360,"qualifier":73,"claimant":74,"organization":182,"vendorReported":11},"Sanctions screening by banks and payment firms is not listed in Annex III: point 5 covers credit scoring and life and health insurance pricing, and point 6 covers AI used by or on behalf of law enforcement authorities. It is not a prohibited practice under Article 5, and as an internal tool it carries no Article 50 transparency duty. It still processes personal data at scale, so GDPR applies, and decisions that block a payment or freeze assets remain human decisions.",{"slug":406,"title":407,"shortTitle":408,"definition":409,"status":19,"industries":410,"functions":411,"patterns":412,"audience":145,"autonomy":32,"adoptionStage":33,"segment":194,"evidenceCount":35,"publicEvidenceCount":61,"organizations":413,"bestGrade":227,"headline":40,"lastVerified":75,"indexable":12,"euAiActTier":42,"euAiActBasis":415},"portfolio-reporting-and-commentary","AI generated client portfolio reports and commentary","Portfolio commentary","AI that drafts each client's periodic portfolio commentary and report narrative (performance, attribution, what drove returns, positioning and outlook) in plain language and in the client's language, where every figure comes from the portfolio system of record and a reviewer approves the text before delivery.",[21,22],[120,52,53],[29,30,352],[105,414],"Quilter","Drafting client reports for human review is not listed in Annex III and is not a practice prohibited by Article 5, so the tier turns on the firm's role under Article 50. A firm that deploys a third party generator (for example a feature of its portfolio platform) for private client reports has no Article 50 duty: the Article 50(4) disclosure duty covers AI generated text published to inform the public on matters of public interest, which private client reports are not, and it lapses anyway after human review under editorial responsibility. For that firm the tier is minimal. A firm that builds the generating system or places it on the market under its own name is a provider under Article 50(2) and must mark the synthetic text in a machine readable format; drafting whole commentaries goes beyond the exemption for an assistive function for standard editing, so for that firm the tier is limited.",{"slug":417,"title":418,"shortTitle":419,"definition":420,"status":19,"industries":421,"functions":422,"patterns":423,"audience":31,"autonomy":123,"adoptionStage":239,"segment":34,"evidenceCount":268,"publicEvidenceCount":268,"organizations":424,"bestGrade":39,"headline":40,"lastVerified":41,"indexable":12,"euAiActTier":76,"euAiActBasis":428},"wealth-advisor-knowledge-assistant","AI knowledge assistant for wealth advisors and relationship managers","Advisor knowledge assistant","A conversational assistant that answers a wealth advisor's or relationship manager's questions in seconds from the firm's own research, house view, product documentation and policies, with every answer linked to the source document so the advisor can check it before using it with a client.",[21,22],[162,85,52],[56,55],[63,425,127,105,426,427],"Citi","UBS","Yes Bank","Article 50(1) requires that people who interact directly with an AI system are informed of it, unless this is obvious from the context, as it usually is for an internal assistant labelled as AI; Article 50(2) requires providers of systems that generate text to mark the output as AI generated in a machine readable way. Helping advisors find information is not an Annex III use and not a prohibited practice under Article 5. It would become high risk only if the system were used to evaluate the creditworthiness of clients (point 5(b)) or to evaluate or make decisions about advisors (point 4(b)). If the assistant were opened to clients, they would have to be told they are dealing with AI.",{"slug":430,"title":431,"shortTitle":432,"definition":433,"status":19,"industries":434,"functions":435,"patterns":436,"audience":31,"autonomy":32,"adoptionStage":239,"segment":34,"evidenceCount":268,"publicEvidenceCount":268,"organizations":438,"bestGrade":39,"headline":442,"lastVerified":75,"indexable":12,"euAiActTier":167,"euAiActBasis":444},"client-meeting-notes-and-crm-update","AI meeting notes and CRM update for wealth advisors","Advisor meeting notes","An AI notetaker for wealth advisors that turns a client advice meeting, recorded with the client's consent, into the file note, follow up message and CRM record the firm needs to evidence its advice; unlike a general meeting summarizer, its output becomes part of the regulated client record. It drafts a structured note with the client's goals, circumstances, decisions and action items, and writes it into the CRM once the advisor has approved it.",[21,22],[85,100,53],[30,437,28,29],"speech-analytics",[63,439,105,414,440,441],"Commerzbank","SEB","UniSuper",{"kpi":130,"label":131,"unit":68,"n":69,"nUpTo":70,"kind":71,"value":443,"qualifier":73,"claimant":293,"organization":440,"vendorReported":12},15,"Transcribing and summarizing meetings for an employee is not a use listed in Annex III, and the advisor reviews every note before it is filed or sent. The tier would change if the tool inferred emotions: emotion recognition is high risk under Annex III point 1(c), and inferring the emotions of employees at work is prohibited under Article 5(1)(f). Both stay out of scope.",{"slug":446,"title":447,"shortTitle":448,"definition":449,"status":19,"industries":450,"functions":451,"patterns":452,"audience":31,"autonomy":123,"adoptionStage":33,"segment":34,"evidenceCount":60,"publicEvidenceCount":60,"organizations":453,"bestGrade":39,"headline":454,"lastVerified":75,"indexable":12,"euAiActTier":42,"euAiActBasis":458},"next-best-action-for-advisors","AI next best action prompts for wealth advisors","Advisor next best action","An AI engine for wealth advisors, not customers, that scans an advisor's whole book and surfaces a short, ranked list of client specific prompts, such as idle cash, a maturing deposit, a concentration to review, a life event or an early sign of attrition, each with the reasoning and data behind it, for the advisor to act on or dismiss.",[21,22],[85,264,120],[266,122,29],[90,425,127,105,426],{"kpi":455,"label":456,"unit":68,"n":69,"nUpTo":70,"kind":71,"value":457,"qualifier":73,"claimant":74,"organization":426,"vendorReported":11},"employee-adoption","Employee adoption",80,"Ranking investment and service prompts for an advisor is not listed in Annex III. It becomes high risk if the system evaluates the creditworthiness of natural persons, for example to decide which clients are offered lending (Annex III point 5(b)), so keep credit decisions out of the prompt engine. It is also high risk if the system itself is used to monitor or evaluate advisors' performance and behaviour, for example by scoring or ranking advisors on how they act on prompts (Annex III point 4(b)), so keep adoption reporting separate from performance management.",{"slug":460,"title":461,"shortTitle":462,"definition":463,"status":19,"industries":464,"functions":465,"patterns":466,"audience":57,"autonomy":32,"adoptionStage":88,"segment":59,"evidenceCount":61,"publicEvidenceCount":61,"organizations":467,"bestGrade":39,"headline":40,"lastVerified":75,"indexable":12,"euAiActTier":76,"euAiActBasis":468},"corporate-account-onboarding-orchestration","AI orchestration of corporate account opening and channel setup","Corporate onboarding operations","An AI agent that runs the operational setup of a corporate client after the due diligence has been approved: it reads mandates, board resolutions and signatory documents, prepares accounts, users, roles and payment entitlements for approval, configures channel access, and chases outstanding items with the client, turning a manual setup that passes between several teams into a tracked, guided flow.",[22],[24,53],[28,27,55,29],[425,166],"Operational setup of accounts and entitlements for corporate clients is not listed in Annex III and makes no decision about a natural person's access to a service or creditworthiness. The agent chases documents directly with client staff, so Article 50(1) applies: the provider must design the system so that they are informed that they are interacting with an AI system, unless that is obvious from the context. A purely internal version without client contact would be minimal risk.",{"slug":470,"title":471,"shortTitle":472,"definition":473,"status":19,"industries":474,"functions":475,"patterns":476,"audience":145,"autonomy":32,"adoptionStage":88,"segment":194,"evidenceCount":147,"publicEvidenceCount":35,"organizations":477,"bestGrade":39,"headline":40,"lastVerified":75,"indexable":12,"euAiActTier":42,"euAiActBasis":479},"portfolio-drift-monitoring-and-rebalancing","AI portfolio drift monitoring and rebalancing proposals","Drift and rebalancing","Continuous monitoring of every client portfolio against its mandate or model, which detects drift beyond agreed bands and prepares a tax aware, low turnover rebalancing proposal with its rationale for an advisor or portfolio manager to approve before any trade is placed.",[21,22],[53,101,120],[178,28,122,29],[105,478,91],"SimCorp","Monitoring portfolios and proposing trades for human approval is not listed in Annex III and is not a prohibited practice under Article 5, so the tier turns on the firm's role under Article 50. A firm that builds or brands the rationale writer in house is a provider under Article 50(2) and must mark the generated text in a machine readable format: drafting a rationale for the drift and the proposed trades goes beyond the exemption for an assistive function for standard editing, so for that firm the tier is limited. Article 50(1) also applies once the rationale reaches the client, as this page's own implementation step allows. A firm that only deploys a third party feature for internal approver use has no Article 50 duty, and for that firm the tier is minimal. Investment conduct rules such as MiFID II suitability and best execution still apply to the resulting trades.",{"slug":481,"title":482,"shortTitle":483,"definition":484,"status":19,"industries":485,"functions":487,"patterns":488,"audience":31,"autonomy":123,"adoptionStage":33,"segment":489,"evidenceCount":147,"publicEvidenceCount":61,"organizations":490,"bestGrade":39,"headline":40,"lastVerified":75,"indexable":12,"euAiActTier":76,"euAiActBasis":492},"regulatory-horizon-scanning","AI regulatory horizon scanning and obligation mapping","Regulatory horizon scanning","An AI system that continuously reads publications from the regulators and standard setters an organization answers to, classifies each item by relevance and urgency, breaks new rules into individual obligations and maps them to the internal policies and controls that meet them, so compliance owners see what changed and where the gaps are.",[113,22,175,50,21,486,235],"pharma-and-life-sciences",[100,386,101],[103,27,56,30,28],"compliance",[491,390],"Financial Conduct Authority","An internal tool that monitors and classifies regulatory publications for staff makes no decisions about natural persons, so it is not listed in Annex III and is not a prohibited practice under Article 5. Staff know they are using an AI tool and its summaries are not published to the public, so the Article 50 duties to inform users and to disclose published generated text add little for the deploying organization. Article 50(2) still requires the provider of a system that generates text to mark its output, in a machine readable format, as AI generated: usually the vendor, but an organization that builds its own summariser can itself be that provider, which is what puts this use case at the limited tier rather than minimal. Beyond this and AI literacy (Article 4), no specific obligations apply. General model risk and third party rules still apply.",{"slug":494,"title":495,"shortTitle":496,"definition":497,"status":19,"industries":498,"functions":499,"patterns":500,"audience":57,"autonomy":58,"adoptionStage":33,"segment":34,"evidenceCount":268,"publicEvidenceCount":268,"organizations":502,"bestGrade":39,"headline":506,"lastVerified":41,"indexable":12,"euAiActTier":76,"euAiActBasis":510},"scam-payment-interception","AI scam intervention for instant payments","Scam payment interception","AI that talks to the customer when they are about to authorise an instant payment that looks like a scam: it combines the payee check and the risk score, asks targeted questions about the payment in plain language, explains the specific scam pattern, and holds, delays or escalates the payment to a human specialist when the risk stays high. Unlike fraud scoring, which stops payments the customer did not make, it protects customers from payments they are being manipulated into making.",[22,50],[337,52],[55,122,28,501],"voice-agent",[270,503,504,273,505,274],"Mastercard","Revolut","Vodafone",{"kpi":507,"label":508,"unit":68,"n":61,"nUpTo":70,"kind":71,"value":509,"qualifier":73,"claimant":293,"organization":273,"vendorReported":12},"detection-rate-improvement","Detection improvement",300,"Annex III point 5(b) expressly excludes AI systems used to detect financial fraud from the high risk creditworthiness category, so the scoring is not high risk. The conversational part must disclose that it is AI under Article 50(1). If a voice component infers the customer's emotions from their voice, it becomes an emotion recognition system under Annex III point 1(c), which is high risk and needs the Article 50(3) notice, so keep coaching detection to what is said rather than to biometric signals.",{"slug":512,"title":513,"shortTitle":514,"definition":515,"status":19,"industries":516,"functions":517,"patterns":518,"audience":145,"autonomy":58,"adoptionStage":88,"segment":59,"evidenceCount":35,"publicEvidenceCount":35,"organizations":519,"bestGrade":227,"headline":40,"lastVerified":75,"indexable":12,"euAiActTier":167,"euAiActBasis":521},"trade-finance-crime-screening","AI screening of trade finance transactions for trade based money laundering","Trade crime screening","AI that screens every trade finance transaction for financial crime risk: it checks parties, vessels and ports against sanctions and watchlists, tests goods descriptions against dual use and controlled goods lists, compares unit prices with benchmarks for over or under invoicing, and reads trade documents and messages for laundering red flags, then prepares a case narrative for a human investigator.",[22],[25,53],[27,178,103,30],[253,255,520],"United Bank Limited","Financial crime screening of trade transactions is not listed in Annex III. It still processes personal data of individual parties, so GDPR applies, and supervisors expect it to be governed like any financial crime model.",{"slug":523,"title":524,"shortTitle":525,"definition":526,"status":19,"industries":527,"functions":528,"patterns":529,"audience":31,"autonomy":32,"adoptionStage":33,"segment":34,"evidenceCount":147,"publicEvidenceCount":147,"organizations":530,"bestGrade":39,"headline":531,"lastVerified":75,"indexable":12,"euAiActTier":42,"euAiActBasis":537},"investment-research-summarization","AI summaries of investment research and the house view","Research summaries","An AI assistant that condenses long research reports, overnight market moves and the house view into short, sourced briefings for advisors and analysts, answers \"what is our view on X\" on demand, and adapts approved research for different client segments and languages, with every figure traced to the original research.",[21,160,22],[120,85,162],[30,56,29,352],[425,38,105,426],{"kpi":532,"label":533,"unit":534,"n":70,"nUpTo":69,"kind":71,"value":535,"qualifier":536,"claimant":74,"organization":38,"vendorReported":11},"time-saved-per-task","Time saved per task","minutes",120,"up-to","Summarizing research for staff is not an Annex III use and is not a practice prohibited by Article 5, so the tier turns on the firm's role under Article 50. It is minimal for a purchased internal tool with no client or public facing exposure. Article 50 transparency applies when the firm builds the generating system itself, which brings the Article 50(2) duty to mark synthetic text in a machine readable format; when the assistant is offered to clients as a chatbot, which brings the Article 50(1) duty to tell them they are interacting with AI; or when AI generated text is published to inform the public on matters of public interest, which brings the Article 50(4) disclosure duty unless the text has gone through human review or editorial control and a person holds editorial responsibility for it.",{"slug":539,"title":540,"shortTitle":541,"definition":542,"status":19,"industries":543,"functions":544,"patterns":546,"audience":31,"autonomy":32,"adoptionStage":33,"evidenceCount":147,"publicEvidenceCount":147,"organizations":547,"bestGrade":39,"headline":40,"lastVerified":75,"indexable":12,"euAiActTier":42,"euAiActBasis":552},"ai-model-inventory","AI system and model inventory with shadow AI discovery","AI model inventory","A governed register of every AI system and model an organization builds, buys or uses, with its owner, purpose, data, risk tier and approval status, kept current by AI that discovers unregistered use, reads the documentation and assembles the evidence a board, auditor or supervisor asks for.",[113,22,175,235,116],[101,100,545],"it-and-engineering",[28,27,56,103],[548,549,550,551],"Board of Governors of the Federal Reserve System","Office of Management and Budget","Unilever","U.S. Department of Justice","Minimal for a system level register of systems and owners with no monitoring of individual employees; it is not listed in Annex III and is the instrument deployers use to meet obligations such as the Article 26 duties for high risk systems and the Article 49 registration of Annex III systems in the EU database. Limited where the plain language assistant that staff and auditors query is not obviously an AI system to its users: under Article 50(1) its provider must then design it so people are told they are dealing with AI. Possibly high risk under Annex III point 4(b) on worker management if the discovery process monitors or evaluates the behavior of individual employees rather than staying at the level of systems and owners.",{"slug":554,"title":555,"shortTitle":556,"definition":557,"status":19,"industries":558,"functions":559,"patterns":560,"audience":145,"autonomy":58,"adoptionStage":33,"segment":194,"evidenceCount":69,"publicEvidenceCount":69,"organizations":561,"bestGrade":39,"headline":40,"lastVerified":75,"indexable":12,"euAiActTier":42,"euAiActBasis":563},"dynamic-customer-risk-rating","Dynamic AML customer risk rating with machine learning","Dynamic customer risk rating","Explainable machine learning that produces the money laundering risk rating itself: it computes and continuously updates each customer's rating from due diligence data, products, geography, behaviour and screening results, and shows which factors drive the rating and when enhanced due diligence is warranted.",[22,50,21],[25,101],[122,178],[562],"bunq","An AML customer risk rating is not listed in Annex III. Article 5(1)(d) prohibits AI risk assessments that predict whether a natural person will commit or will likely commit a criminal offence based solely on profiling of that person or on assessing their personality traits and characteristics; it exempts only AI that supports the human assessment of a person's involvement in a criminal activity, which is already based on objective and verifiable facts directly linked to a criminal activity. An AML customer risk rating built from due diligence attributes, transaction behaviour and screening results is itself an automated evaluation of a person's situation and behaviour, which is profiling under GDPR Article 4(4), and due diligence facts such as occupation, geography and products are not facts directly linked to a criminal activity, so the rating does not sit squarely inside the exemption. What keeps it a defensible AML due diligence tool rather than an offence prediction is that it does not itself accuse a person of an offence: it sets a level of scrutiny, a human analyst reviews material moves, and regulatory minimum rules sit above the model as hard constraints. A rating driven mainly by nationality or other personal attributes weakens that position further, which is why the proxy discrimination guardrail matters. If the same score is used to evaluate the creditworthiness of natural persons or to establish their credit score, that use falls under Annex III point 5(b) and is high risk, so keep the AML rating and credit decisions separate.",{"slug":565,"title":566,"shortTitle":567,"definition":568,"status":19,"industries":569,"functions":573,"patterns":574,"audience":31,"autonomy":123,"adoptionStage":239,"evidenceCount":353,"publicEvidenceCount":60,"organizations":575,"bestGrade":39,"headline":578,"lastVerified":75,"indexable":12,"euAiActTier":42,"euAiActBasis":579},"live-agent-assist","Real time AI assist for contact centre agents","Live agent assist","A real time copilot for human contact centre agents during a live call or chat: it transcribes the conversation as it happens, surfaces the relevant knowledge and next step, drafts responses, and writes the after call summary and CRM notes, while the agent stays in control of what is said and done.",[113,22,175,570,571,115,572],"telecommunications","healthcare","technology",[52,53],[437,56,30,29],[64,576,577,440,241],"Definity","Oportun",{"kpi":130,"label":131,"unit":68,"n":61,"nUpTo":70,"kind":71,"value":443,"qualifier":73,"claimant":293,"organization":576,"vendorReported":12},"As a pure assist tool for agents it is minimal risk; the customer does not interact with the AI. It becomes high risk under Annex III point 4(b) if its data is used to monitor and evaluate individual agents' performance, and inferring agents' emotions at work is prohibited under Article 5(1)(f).",{"slug":581,"title":582,"shortTitle":583,"definition":584,"status":19,"industries":585,"functions":586,"patterns":587,"audience":145,"autonomy":588,"adoptionStage":239,"segment":194,"evidenceCount":589,"publicEvidenceCount":589,"organizations":590,"bestGrade":39,"headline":595,"lastVerified":75,"indexable":12,"euAiActTier":167,"euAiActBasis":600},"real-time-fraud-scoring","Real time fraud scoring for card and instant payments","Real time fraud scoring","Machine learning that decides in milliseconds, without any conversation, how likely each card authorization and account to account payment is to be fraudulent, combining behavioural, device and network signals, so the bank can approve, challenge or block a payment before the money leaves. Working the resulting alerts and talking to the customer about them are separate use cases.",[22,50],[337],[122,178],"autonomous",9,[341,270,503,591,592,504,593,594],"NatWest Group","Pay.UK","Stripe","Visa",{"kpi":596,"label":597,"unit":68,"n":35,"nUpTo":70,"kind":598,"value":599,"qualifier":73,"claimant":74,"organization":40,"vendorReported":11},"fraud-loss-reduction","Fraud loss reduction","median",30,"Annex III point 5(b) lists creditworthiness assessment and credit scoring of natural persons as high risk but explicitly excludes AI systems used for the purpose of detecting financial fraud, and payment fraud scoring is not otherwise listed in Annex III or prohibited by Article 5. Behavioural biometrics used only to confirm that customers are who they claim to be fall under the biometric verification exclusion in Annex III point 1(a). The model does not interact with people, so Article 50 does not apply. GDPR Article 22 can still apply to solely automated declines with significant effects on customers.",1790598319298]