[{"data":1,"prerenderedAt":129},["ShallowReactive",2],{"uc-reg-pra-ss1-23":3},{"regulation":4,"includeUnpublished":11,"indexable":12,"useCases":13},{"id":5,"label":6,"issuer":7,"region":8,"url":9,"description":10},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","europe","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",false,true,[14,47,74,97],{"slug":15,"title":16,"shortTitle":17,"definition":18,"status":19,"industries":20,"functions":25,"patterns":28,"audience":33,"autonomy":34,"adoptionStage":35,"segment":36,"evidenceCount":37,"publicEvidenceCount":37,"organizations":38,"bestGrade":42,"headline":43,"lastVerified":44,"indexable":12,"euAiActTier":45,"euAiActBasis":46},"model-risk-validation-copilot","AI copilot for model risk validation and monitoring","Model risk validation","A copilot for independent model validation and review, whether run by a bank's validation function, an external tester or a supervisor, that checks model documentation against the model risk standard, generates and scores challenger tests (for generative AI, often with an LLM as a judge calibrated against human experts), watches production models for drift and drafts and consistency checks the validation report. An accountable validator owns every conclusion.","published",[21,22,23,24],"banking","insurance","capital-markets","wealth-and-asset-management",[26,27],"risk-management","regulatory-compliance",[29,30,31,32],"agentic-workflow","document-processing","content-generation","anomaly-detection","employee-facing","copilot","emerging","second-line",3,[39,40,41],"European Central Bank (ECB Banking Supervision)","Standard Chartered","United Overseas Bank (UOB)","B",null,"2026-09-28","minimal","A validation copilot supports internal governance and is not itself an Annex III use, and its drafts are internal, so Article 50 transparency duties do not normally apply. It often helps validate models that are high risk under Annex III (point 5(b), creditworthiness and credit scoring of natural persons; point 5(c), life and health insurance pricing), and the testing and documentation it supports feed the provider obligations of Articles 9, 11 and 15.",{"slug":48,"title":49,"shortTitle":50,"definition":51,"status":19,"industries":52,"functions":54,"patterns":57,"audience":60,"autonomy":61,"adoptionStage":62,"segment":63,"evidenceCount":64,"publicEvidenceCount":64,"organizations":65,"bestGrade":42,"headline":43,"lastVerified":71,"indexable":12,"euAiActTier":72,"euAiActBasis":73},"alternative-data-credit-scoring","AI credit scoring with alternative data for thin file applicants","Alternative data credit scoring","A machine learning credit model that adds consumer permissioned alternative data, such as bank account cash flow, rent, utility and telco payments or ecosystem data, to credit bureau data, so a lender can assess applicants with thin or no credit files and return a decision with specific reasons.",[21,53],"payments",[55,56,26],"lending-and-credit","underwriting",[58,30,59],"prediction-and-scoring","conversational-agent","back-office","supervised-agent","early-adopters","lending",5,[66,67,68,69,70],"Atlanticus","Golden 1 Credit Union","GXS Bank","Patelco Credit Union","Upstart Network","2026-09-26","high","Annex III point 5(b): AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score are high risk, except systems used to detect financial fraud. Providers need risk management, data governance, logging and human oversight. Deployers must carry out a fundamental rights impact assessment before use (Article 27), and affected persons have a right to an explanation of individual decisions from the deployer (Article 86).",{"slug":75,"title":76,"shortTitle":77,"definition":78,"status":19,"industries":79,"functions":83,"patterns":85,"audience":33,"autonomy":34,"adoptionStage":62,"evidenceCount":88,"publicEvidenceCount":88,"organizations":89,"bestGrade":42,"headline":43,"lastVerified":94,"indexable":12,"euAiActTier":95,"euAiActBasis":96},"ai-model-inventory","AI system and model inventory with shadow AI discovery","AI model inventory","A governed register of every AI system and model an organization builds, buys or uses, with its owner, purpose, data, risk tier and approval status, kept current by AI that discovers unregistered use, reads the documentation and assembles the evidence a board, auditor or supervisor asks for.",[80,21,22,81,82],"cross-industry","government","manufacturing",[26,27,84],"it-and-engineering",[29,30,86,87],"rag-knowledge-assistant","classification-and-routing",4,[90,91,92,93],"Board of Governors of the Federal Reserve System","Office of Management and Budget","Unilever","U.S. Department of Justice","2026-09-27","context-dependent","Minimal for a system level register of systems and owners with no monitoring of individual employees; it is not listed in Annex III and is the instrument deployers use to meet obligations such as the Article 26 duties for high risk systems and the Article 49 registration of Annex III systems in the EU database. Limited where the plain language assistant that staff and auditors query is not obviously an AI system to its users: under Article 50(1) its provider must then design it so people are told they are dealing with AI. Possibly high risk under Annex III point 4(b) on worker management if the discovery process monitors or evaluates the behavior of individual employees rather than staying at the level of systems and owners.",{"slug":98,"title":99,"shortTitle":100,"definition":101,"status":19,"industries":102,"functions":103,"patterns":105,"audience":60,"autonomy":106,"adoptionStage":107,"segment":108,"evidenceCount":109,"publicEvidenceCount":109,"organizations":110,"bestGrade":42,"headline":119,"lastVerified":94,"indexable":12,"euAiActTier":45,"euAiActBasis":128},"real-time-fraud-scoring","Real time fraud scoring for card and instant payments","Real time fraud scoring","Machine learning that decides in milliseconds, without any conversation, how likely each card authorization and account to account payment is to be fraudulent, combining behavioural, device and network signals, so the bank can approve, challenge or block a payment before the money leaves. Working the resulting alerts and talking to the customer about them are separate use cases.",[21,53],[104],"fraud-prevention",[58,32],"autonomous","mainstream","middle-office",9,[111,112,113,114,115,116,117,118],"ANZ, Commonwealth Bank, NAB, Suncorp Bank and Westpac (BioCatch Trust Australia)","Commonwealth Bank of Australia","Mastercard","NatWest Group","Pay.UK","Revolut","Stripe","Visa",{"kpi":120,"label":121,"unit":122,"n":37,"nUpTo":123,"kind":124,"value":125,"qualifier":126,"claimant":127,"organization":43,"vendorReported":11},"fraud-loss-reduction","Fraud loss reduction","percent",0,"median",30,"exact","organization","Annex III point 5(b) lists creditworthiness assessment and credit scoring of natural persons as high risk but explicitly excludes AI systems used for the purpose of detecting financial fraud, and payment fraud scoring is not otherwise listed in Annex III or prohibited by Article 5. Behavioural biometrics used only to confirm that customers are who they claim to be fall under the biometric verification exclusion in Annex III point 1(a). The model does not interact with people, so Article 50 does not apply. GDPR Article 22 can still apply to solely automated declines with significant effects on customers.",1790598320110]