[{"data":1,"prerenderedAt":389},["ShallowReactive",2],{"uc-reg-us-sr-11-7":3},{"regulation":4,"includeUnpublished":11,"indexable":12,"useCases":13},{"id":5,"label":6,"issuer":7,"region":8,"url":9,"description":10},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","north-america","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",false,true,[14,45,68,104,124,140,152,179,205,219,240,253,266,283,296,315,327,340,354,365],{"slug":15,"title":16,"shortTitle":17,"definition":18,"status":19,"industries":20,"functions":23,"patterns":26,"audience":31,"autonomy":32,"adoptionStage":33,"segment":34,"evidenceCount":35,"publicEvidenceCount":36,"organizations":37,"bestGrade":40,"headline":41,"lastVerified":42,"indexable":12,"euAiActTier":43,"euAiActBasis":44},"fraud-alert-triage","AI agent for fraud alert triage","Fraud alert triage","An AI agent that works the fraud alert queue behind the scenes as the analyst's first pass, without contacting the customer: it enriches each alert with customer, device and payment context, closes clear false positives under documented rules, merges duplicates, and routes genuine risk to an analyst with a drafted rationale.","published",[21,22],"banking","payments",[24,25],"fraud-prevention","operations",[27,28,29,30],"agentic-workflow","classification-and-routing","summarization","prediction-and-scoring","employee-facing","supervised-agent","early-adopters","middle-office",3,2,[38,39],"Coast","SEB","C",null,"2026-09-27","minimal","Internal triage of fraud alerts is not listed in Annex III, and point 5(b) explicitly excludes fraud detection from the high risk creditworthiness category. Article 50(1) covers any system that interacts directly with people, analysts included, but it does not apply where the use of AI is obvious to a reasonably well informed user, as it is in an internal analyst tool; the marking duties for generated content in Article 50(2) sit with the provider. Reassess if its output feeds credit decisions. Decisions that affect customers remain subject to GDPR and consumer protection rules.",{"slug":46,"title":47,"shortTitle":48,"definition":49,"status":19,"industries":50,"functions":52,"patterns":56,"audience":31,"autonomy":58,"adoptionStage":59,"segment":60,"evidenceCount":36,"publicEvidenceCount":36,"organizations":61,"bestGrade":64,"headline":41,"lastVerified":65,"indexable":12,"euAiActTier":66,"euAiActBasis":67},"suitability-assessment-assistant","AI assistant for investment suitability assessment and reports","Suitability assessment","An AI assistant that checks whether a proposed product or portfolio fits a client's risk tolerance, objectives, knowledge, experience and financial situation against the firm's rules, flags mismatches, and drafts the suitability rationale and report for the advisor to confirm, while hard rule failures are decided by deterministic checks, not by the model.",[51,21],"wealth-and-asset-management",[53,54,55],"regulatory-compliance","sales","risk-management",[27,57,28],"content-generation","copilot","emerging","front-office",[62,63],"Morgan Stanley","Vanguard","B","2026-09-26","context-dependent","Investment suitability assessment is not listed in Annex III, so the tier depends on design. It becomes high risk where the same system assesses creditworthiness, for example for lending against a portfolio (Annex III point 5(b)). MiFID II suitability duties apply regardless of the AI Act tier.",{"slug":69,"title":70,"shortTitle":71,"definition":72,"status":19,"industries":73,"functions":78,"patterns":82,"audience":31,"autonomy":84,"adoptionStage":33,"segment":85,"evidenceCount":86,"publicEvidenceCount":86,"organizations":87,"bestGrade":64,"headline":93,"lastVerified":42,"indexable":12,"euAiActTier":102,"euAiActBasis":103},"treasury-cash-flow-forecasting","AI cash flow forecasting for corporate treasury","Treasury cash forecasting","Machine learning and conversational analytics, offered by some banks inside their cash management platforms, that categorise a company's cash flows, forecast positions across accounts and currencies, and answer treasurers' questions in plain language, so the treasury team decides on funding and idle balances with better information and less spreadsheet work.",[21,74,75,76,77],"cross-industry","logistics-and-transportation","retail-and-ecommerce","manufacturing",[79,80,81],"treasury","finance-and-accounting","analytics-and-reporting",[30,28,83,27],"conversational-agent","assist","specialized-businesses",5,[88,89,90,91,92],"Amtrak","Bank of America","Domino's Pizza","JPMorgan Chase","Prysmian",{"kpi":94,"label":95,"unit":96,"n":36,"nUpTo":97,"kind":98,"value":99,"qualifier":100,"claimant":101,"organization":91,"vendorReported":11},"productivity-gain","Productivity gain","percent",1,"reported",90,"approximately","organization","limited","Forecasting a company's cash flows is not listed in Annex III and makes no decision about a natural person, so the forecasting model itself carries no obligations beyond AI literacy (Article 4). The conversational layer interacts directly with treasury staff, so under Article 50(1) they must be informed that they are dealing with an AI system unless that is obvious from the context. Without a conversational layer the use case is minimal risk.",{"slug":105,"title":106,"shortTitle":107,"definition":108,"status":19,"industries":109,"functions":110,"patterns":113,"audience":115,"autonomy":32,"adoptionStage":33,"segment":116,"evidenceCount":117,"publicEvidenceCount":117,"organizations":118,"bestGrade":64,"headline":41,"lastVerified":65,"indexable":12,"euAiActTier":66,"euAiActBasis":123},"sme-cash-flow-underwriting","AI cash flow underwriting for small business loans","SME cash flow underwriting","An underwriting engine that assesses a small business's repayment capacity from live bank transactions, point of sale and payment flows, receivables and accounting data instead of audited accounts, and returns a decision recommendation with the evidence and reasons behind it.",[21],[111,112,55],"lending-and-credit","underwriting",[30,114,27,83],"document-processing","back-office","lending",4,[119,120,121,122],"MYbank","National Australia Bank","OakNorth Bank","Sumitomo Mitsui Banking Corporation","Annex III point 5(b) makes AI systems that evaluate the creditworthiness of natural persons or establish their credit score high risk. Scoring a company is outside that point, but a sole trader is a natural person, and a model that also assesses the personal credit of owners, partners or guarantors evaluates natural persons. The tier therefore depends on who the borrower is and whose creditworthiness the model assesses.",{"slug":125,"title":126,"shortTitle":127,"definition":128,"status":19,"industries":129,"functions":130,"patterns":131,"audience":115,"autonomy":32,"adoptionStage":33,"segment":116,"evidenceCount":86,"publicEvidenceCount":86,"organizations":132,"bestGrade":64,"headline":41,"lastVerified":65,"indexable":12,"euAiActTier":138,"euAiActBasis":139},"alternative-data-credit-scoring","AI credit scoring with alternative data for thin file applicants","Alternative data credit scoring","A machine learning credit model that adds consumer permissioned alternative data, such as bank account cash flow, rent, utility and telco payments or ecosystem data, to credit bureau data, so a lender can assess applicants with thin or no credit files and return a decision with specific reasons.",[21,22],[111,112,55],[30,114,83],[133,134,135,136,137],"Atlanticus","Golden 1 Credit Union","GXS Bank","Patelco Credit Union","Upstart Network","high","Annex III point 5(b): AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score are high risk, except systems used to detect financial fraud. Providers need risk management, data governance, logging and human oversight. Deployers must carry out a fundamental rights impact assessment before use (Article 27), and affected persons have a right to an explanation of individual decisions from the deployer (Article 86).",{"slug":141,"title":142,"shortTitle":143,"definition":144,"status":19,"industries":145,"functions":146,"patterns":147,"audience":31,"autonomy":84,"adoptionStage":33,"segment":116,"evidenceCount":35,"publicEvidenceCount":35,"organizations":149,"bestGrade":40,"headline":41,"lastVerified":42,"indexable":12,"euAiActTier":66,"euAiActBasis":151},"credit-early-warning-monitoring","AI early warning and covenant monitoring for loan portfolios","Credit early warning and covenants","A monitoring system that tracks covenant tests and borrower reporting across a loan book, reads financials, filings and news, and combines them with payment and sector signals to flag borrowers whose credit is deteriorating, with the evidence and a suggested next step for the relationship manager.",[21],[55,111],[148,114,27,29],"anomaly-detection",[121,150,122],"PNC Financial Services","Monitoring the credit of companies is not listed in Annex III. Where the same system evaluates the creditworthiness of natural persons, such as sole traders or personal guarantors, it falls under Annex III point 5(b) and is high risk; because that evaluation profiles natural persons, the Article 6(3) exemption does not apply.",{"slug":153,"title":154,"shortTitle":155,"definition":156,"status":19,"industries":157,"functions":158,"patterns":160,"audience":31,"autonomy":32,"adoptionStage":33,"segment":34,"evidenceCount":161,"publicEvidenceCount":161,"organizations":162,"bestGrade":64,"headline":171,"lastVerified":42,"indexable":12,"euAiActTier":43,"euAiActBasis":178},"aml-alert-triage","AI for AML transaction monitoring alert triage","AML alert triage","Machine learning and AI agents that score anti money laundering alerts for genuine risk, close clear false positives with a written and stored rationale, and hand investigators the remaining alerts already enriched with the customer, counterparty and transaction context.",[21,22],[159],"financial-crime-compliance",[30,148,27,29],8,[163,164,165,166,167,168,169,170],"Australia Post","BMO and Amalgamated Bank","HSBC","Nexo","Ratepay","Shift4","United Overseas Bank (UOB)","Uphold",{"kpi":172,"label":173,"unit":96,"n":36,"nUpTo":174,"kind":98,"value":175,"qualifier":176,"claimant":177,"organization":168,"vendorReported":12},"false-positive-reduction","False positive reduction",0,86,"exact","vendor","AML transaction monitoring is not listed in Annex III; point 5(b) covers creditworthiness and credit scoring and excludes systems used to detect financial fraud. The Article 5(1)(d) ban on predicting criminal offences from profiling alone does not apply to systems that support a human assessment already based on objective and verifiable facts linked to criminal activity, which is how alert triage should be designed. A decision to restrict an account taken solely by automated means would fall under GDPR Article 22 and national AML law, so consequential decisions need human review.",{"slug":180,"title":181,"shortTitle":182,"definition":183,"status":19,"industries":184,"functions":187,"patterns":189,"audience":115,"autonomy":32,"adoptionStage":33,"segment":60,"evidenceCount":191,"publicEvidenceCount":191,"organizations":192,"bestGrade":64,"headline":199,"lastVerified":65,"indexable":12,"euAiActTier":66,"euAiActBasis":204},"application-and-identity-fraud-detection","AI for application and identity fraud detection","Application and identity fraud","AI that checks incoming account and loan applications for forged or AI generated documents, synthetic and stolen identities, and coordinated application rings, by analysing documents, device and application data across the whole queue and cross checking against bureau and official sources.",[21,22,74,185,186],"government","telecommunications",[24,188,111],"onboarding-and-kyc",[114,148,190,30],"computer-vision",6,[193,194,195,196,197,198],"BCU","Close Brothers Motor Finance","CNG Holdings","Department for Work and Pensions","Payoneer","Telstra",{"kpi":200,"label":201,"unit":202,"n":97,"nUpTo":174,"kind":98,"value":203,"qualifier":176,"claimant":101,"organization":196,"vendorReported":11},"detection-rate-improvement","Detection improvement","multiplier",2.5,"Annex III point 5(b) excludes AI used to detect financial fraud from the high risk credit scoring category, but a system that in effect decides on creditworthiness is high risk, and remote biometric identification is high risk under point 1(a), which excludes one to one biometric verification. When a public authority uses the model on claims for public benefits, point 5(a) can apply, because it covers AI used to grant, reduce, revoke or reclaim benefits and has no fraud exception. Keep fraud detection separate from the credit or eligibility decision and use biometrics only for one to one verification.",{"slug":206,"title":207,"shortTitle":208,"definition":209,"status":19,"industries":210,"functions":211,"patterns":213,"audience":115,"autonomy":58,"adoptionStage":59,"segment":115,"evidenceCount":97,"publicEvidenceCount":97,"organizations":215,"bestGrade":64,"headline":41,"lastVerified":217,"indexable":12,"euAiActTier":43,"euAiActBasis":218},"fee-and-interest-leakage-detection","AI for fee and interest leakage detection","Fee and interest leakage","An independent verification layer that recomputes what each fee, FX margin, spread and interest charge should have been under the contract and pricing tables, compares it with what was actually billed, and surfaces overcharges and undercharges account by account for correction, customer remediation and revenue recovery.",[21,22,74],[80,212,53,25],"product-and-pricing",[148,27,214],"rag-knowledge-assistant",[216],"State Bank of India","2026-09-28","Verifying charges against contracts is not listed in Annex III and is not a practice prohibited by Article 5. The system is internal, so the Article 50(1) duty to tell people they are dealing with AI does not arise; the Article 50(2) duty to mark generated text, such as the discrepancy explanations, falls on the provider of the generative model or system. It supports, but does not take, decisions about individual customers; remediation decisions stay with people.",{"slug":220,"title":221,"shortTitle":222,"definition":223,"status":19,"industries":224,"functions":226,"patterns":227,"audience":31,"autonomy":58,"adoptionStage":33,"segment":228,"evidenceCount":86,"publicEvidenceCount":86,"organizations":229,"bestGrade":64,"headline":235,"lastVerified":65,"indexable":12,"euAiActTier":66,"euAiActBasis":239},"market-abuse-surveillance-triage","AI for market abuse surveillance alert triage","Market abuse surveillance","AI that helps surveillance analysts triage market abuse and conduct alerts, such as spoofing, layering, wash trades, ramping and insider dealing, by gathering the trade, order, news and communications context, explaining in plain language what triggered each alert and drafting the investigation narrative for the analyst to disposition.",[225,21,51],"capital-markets",[53,159],[148,27,29,28],"second-line",[230,231,232,233,234],"Commodity Futures Trading Commission","Deutsche Bank","Japan Exchange Group","Nasdaq","U.S. Securities and Exchange Commission",{"kpi":236,"label":237,"unit":96,"n":97,"nUpTo":174,"kind":98,"value":238,"qualifier":100,"claimant":101,"organization":233,"vendorReported":11},"handling-time-reduction","Handling time reduction",33,"Surveillance of orders and transactions as such is not listed in Annex III. Where the system monitors and evaluates the behaviour of the firm's own staff, in their communications or their trading, it can fall under Annex III point 4(b) (AI used to monitor and evaluate the performance and behaviour of persons in work relationships), so the tier depends on whether the system scores individual employees. Inferring employees' emotions from biometric data such as voice recordings is prohibited in the workplace under Article 5(1)(f).",{"slug":241,"title":242,"shortTitle":243,"definition":244,"status":19,"industries":245,"functions":246,"patterns":247,"audience":115,"autonomy":58,"adoptionStage":33,"segment":34,"evidenceCount":35,"publicEvidenceCount":35,"organizations":248,"bestGrade":64,"headline":41,"lastVerified":42,"indexable":12,"euAiActTier":43,"euAiActBasis":252},"mule-network-detection","AI for money mule account and network detection","Mule network detection","Graph and behavioural machine learning that finds money mule accounts and the networks around them, such as circular flows, layering chains and clusters of newly linked accounts, and supports investigators in tracing scam proceeds and restricting accounts before the money is gone.",[21,22],[24,159],[148,30,27,29],[249,250,251],"BigPay","ANZ, Commonwealth Bank, NAB, Suncorp Bank and Westpac (BioCatch Trust Australia)","Reserve Bank Innovation Hub (Reserve Bank of India)","Detecting mule accounts is fraud and AML detection by a private firm, which Annex III does not list; point 5(b) explicitly excludes systems used to detect financial fraud from the credit scoring category. Restricting an account based solely on an automated score can be a decision with similarly significant effects under GDPR Article 22, so keep a human decision and a route to challenge.",{"slug":254,"title":255,"shortTitle":256,"definition":257,"status":19,"industries":258,"functions":260,"patterns":261,"audience":31,"autonomy":58,"adoptionStage":59,"segment":115,"evidenceCount":36,"publicEvidenceCount":36,"organizations":262,"bestGrade":64,"headline":41,"lastVerified":42,"indexable":12,"euAiActTier":102,"euAiActBasis":265},"regulatory-report-assembly","AI for regulatory report assembly","Regulatory report assembly","AI that assembles periodic and data driven regulatory filings and returns, such as prudential and statistical returns, threshold and transaction reports and disclosure packs, by pulling data into the regulator's schema, validating it, reconciling figures to source, explaining movements against prior periods and drafting commentary, before a named officer reviews and submits. Narratives for individual suspicious activity cases are a separate use case.",[21,259,225,22],"insurance",[53,80,159],[27,148,57,29],[263,264],"Board of Governors of the Federal Reserve System","National Credit Union Administration","Not an Article 5 practice and not listed in Annex III: the system prepares filings for authorities and makes no decision on the credit, insurance, employment or access to services of a natural person. It is an internal tool whose users know they are working with AI, and drafted text that ends up in public disclosures passes human review under a named person's editorial responsibility, which takes it outside the Article 50(4) deployer disclosure duty. The system still drafts variance commentary and plain language explanations of validation failures from underlying data, rather than lightly editing existing text, so the assistive function for standard editing exception does not fit. The bank that builds or operates the system is then the provider and carries the Article 50(2) duty to mark that generated text in a machine readable way as artificially generated, which has applied since 2 August 2026. The AI literacy duty of Article 4 also applies.",{"slug":267,"title":268,"shortTitle":269,"definition":270,"status":19,"industries":271,"functions":272,"patterns":273,"audience":115,"autonomy":32,"adoptionStage":33,"segment":34,"evidenceCount":274,"publicEvidenceCount":274,"organizations":275,"bestGrade":64,"headline":280,"lastVerified":65,"indexable":12,"euAiActTier":43,"euAiActBasis":282},"sanctions-screening-adjudication","AI for sanctions screening alert adjudication","Sanctions screening adjudication","AI that works the alerts raised when customer, counterparty or payment names match sanctions and watchlists: it resolves fuzzy matches across transliterations, aliases and naming conventions, clears clear non matches with a documented reason, and escalates true or uncertain hits with the evidence attached.",[21,22],[159],[28,30,27],7,[276,277,165,278,167,279,169],"AJ Bell","First National Bank of Omaha (FNBO)","Mashreq","Standard Chartered",{"kpi":172,"label":173,"unit":96,"n":97,"nUpTo":174,"kind":98,"value":281,"qualifier":176,"claimant":101,"organization":169,"vendorReported":11},60,"Sanctions screening by banks and payment firms is not listed in Annex III: point 5 covers credit scoring and life and health insurance pricing, and point 6 covers AI used by or on behalf of law enforcement authorities. It is not a prohibited practice under Article 5, and as an internal tool it carries no Article 50 transparency duty. It still processes personal data at scale, so GDPR applies, and decisions that block a payment or freeze assets remain human decisions.",{"slug":284,"title":285,"shortTitle":286,"definition":287,"status":19,"industries":288,"functions":289,"patterns":290,"audience":115,"autonomy":58,"adoptionStage":33,"segment":115,"evidenceCount":117,"publicEvidenceCount":117,"organizations":291,"bestGrade":64,"headline":41,"lastVerified":42,"indexable":12,"euAiActTier":66,"euAiActBasis":295},"settlement-fail-prediction-and-exception-management","AI for settlement fail prediction and post trade exception management","Settlement fail prediction","AI that scores each pending securities settlement instruction for its likelihood of failing, names the probable cause (unmatched instruction, wrong settlement details, lack of securities or cash), and helps operations teams work the exceptions and counterparty queries before the intended settlement date, so fewer trades fail and fewer late settlement penalties are paid.",[225,21,51],[25,55],[30,28,27,57],[292,293,294],"BNY","Clearstream","Euroclear","Predicting settlement fails and handling post trade exceptions between professional market participants is not a use listed in Annex III and is not a prohibited practice under Article 5, so the tier depends on how the agent communicates. While an operator reviews and sends every message, the system is minimal risk: the messages are the firm's own correspondence and the firm as deployer owes AI literacy for staff (Article 4). Once the agent sends queries or chasers to counterparty or custodian staff itself, as the playbook recommends for routine information requests, it interacts directly with natural persons and Article 50(1) requires telling the recipients they are dealing with an AI system. In both designs the provider of the text generating system must mark its output as AI generated in a machine readable format under Article 50(2). Model risk and operational resilience controls apply on top.",{"slug":297,"title":298,"shortTitle":299,"definition":300,"status":19,"industries":301,"functions":302,"patterns":304,"audience":31,"autonomy":84,"adoptionStage":33,"segment":60,"evidenceCount":86,"publicEvidenceCount":86,"organizations":306,"bestGrade":64,"headline":310,"lastVerified":42,"indexable":12,"euAiActTier":66,"euAiActBasis":314},"next-best-action-for-advisors","AI next best action prompts for wealth advisors","Advisor next best action","An AI engine for wealth advisors, not customers, that scans an advisor's whole book and surfaces a short, ranked list of client specific prompts, such as idle cash, a maturing deposit, a concentration to review, a life event or an early sign of attrition, each with the reasoning and data behind it, for the advisor to act on or dismiss.",[51,21],[54,303,81],"marketing",[305,30,57],"recommendation-and-personalization",[307,308,91,62,309],"CIMB Niaga","Citi","UBS",{"kpi":311,"label":312,"unit":96,"n":97,"nUpTo":174,"kind":98,"value":313,"qualifier":176,"claimant":101,"organization":309,"vendorReported":11},"employee-adoption","Employee adoption",80,"Ranking investment and service prompts for an advisor is not listed in Annex III. It becomes high risk if the system evaluates the creditworthiness of natural persons, for example to decide which clients are offered lending (Annex III point 5(b)), so keep credit decisions out of the prompt engine. It is also high risk if the system itself is used to monitor or evaluate advisors' performance and behaviour, for example by scoring or ranking advisors on how they act on prompts (Annex III point 4(b)), so keep adoption reporting separate from performance management.",{"slug":316,"title":317,"shortTitle":318,"definition":319,"status":19,"industries":320,"functions":321,"patterns":323,"audience":31,"autonomy":58,"adoptionStage":59,"segment":116,"evidenceCount":36,"publicEvidenceCount":97,"organizations":324,"bestGrade":64,"headline":41,"lastVerified":42,"indexable":12,"euAiActTier":66,"euAiActBasis":326},"loan-restructuring-recommendations","AI recommendations for loan restructuring and hardship arrangements","Restructuring recommendations","An assistant that assembles a stressed borrower's position, tests restructuring options such as a term extension, rate relief, payment holiday or due date change against policy and affordability, and recommends the best fit with a written rationale for a person to approve.",[21],[322,111,55],"collections-and-recovery",[27,214,114,305],[325],"Commonwealth Bank of Australia","Recommending restructuring terms for individuals involves assessing their ability to pay, which can amount to evaluating the creditworthiness of natural persons under Annex III point 5(b). Human approval alone does not remove that: the Article 6(3) exception covers only systems that do not materially influence the decision, such as a narrow procedural or preparatory task, and never applies when the system profiles natural persons. A tool that only assembles the case file can fall under the exception; restructuring for companies is outside point 5(b).",{"slug":328,"title":329,"shortTitle":330,"definition":331,"status":19,"industries":332,"functions":333,"patterns":334,"audience":115,"autonomy":32,"adoptionStage":59,"segment":85,"evidenceCount":35,"publicEvidenceCount":35,"organizations":335,"bestGrade":40,"headline":41,"lastVerified":42,"indexable":12,"euAiActTier":43,"euAiActBasis":339},"trade-finance-crime-screening","AI screening of trade finance transactions for trade based money laundering","Trade crime screening","AI that screens every trade finance transaction for financial crime risk: it checks parties, vessels and ports against sanctions and watchlists, tests goods descriptions against dual use and controlled goods lists, compares unit prices with benchmarks for over or under invoicing, and reads trade documents and messages for laundering red flags, then prepares a case narrative for a human investigator.",[21],[159,25],[114,148,28,29],[336,337,338],"ANZ, HSBC and Lloyds Banking Group","Stanbic Bank Uganda","United Bank Limited","Financial crime screening of trade transactions is not listed in Annex III. It still processes personal data of individual parties, so GDPR applies, and supervisors expect it to be governed like any financial crime model.",{"slug":341,"title":342,"shortTitle":343,"definition":344,"status":19,"industries":345,"functions":346,"patterns":348,"audience":31,"autonomy":58,"adoptionStage":33,"evidenceCount":117,"publicEvidenceCount":117,"organizations":349,"bestGrade":64,"headline":41,"lastVerified":42,"indexable":12,"euAiActTier":66,"euAiActBasis":353},"ai-model-inventory","AI system and model inventory with shadow AI discovery","AI model inventory","A governed register of every AI system and model an organization builds, buys or uses, with its owner, purpose, data, risk tier and approval status, kept current by AI that discovers unregistered use, reads the documentation and assembles the evidence a board, auditor or supervisor asks for.",[74,21,259,185,77],[55,53,347],"it-and-engineering",[27,114,214,28],[263,350,351,352],"Office of Management and Budget","Unilever","U.S. Department of Justice","Minimal for a system level register of systems and owners with no monitoring of individual employees; it is not listed in Annex III and is the instrument deployers use to meet obligations such as the Article 26 duties for high risk systems and the Article 49 registration of Annex III systems in the EU database. Limited where the plain language assistant that staff and auditors query is not obviously an AI system to its users: under Article 50(1) its provider must then design it so people are told they are dealing with AI. Possibly high risk under Annex III point 4(b) on worker management if the discovery process monitors or evaluates the behavior of individual employees rather than staying at the level of systems and owners.",{"slug":355,"title":356,"shortTitle":357,"definition":358,"status":19,"industries":359,"functions":360,"patterns":361,"audience":115,"autonomy":32,"adoptionStage":33,"segment":34,"evidenceCount":97,"publicEvidenceCount":97,"organizations":362,"bestGrade":64,"headline":41,"lastVerified":42,"indexable":12,"euAiActTier":66,"euAiActBasis":364},"dynamic-customer-risk-rating","Dynamic AML customer risk rating with machine learning","Dynamic customer risk rating","Explainable machine learning that produces the money laundering risk rating itself: it computes and continuously updates each customer's rating from due diligence data, products, geography, behaviour and screening results, and shows which factors drive the rating and when enhanced due diligence is warranted.",[21,22,51],[159,55],[30,148],[363],"bunq","An AML customer risk rating is not listed in Annex III. Article 5(1)(d) prohibits AI risk assessments that predict whether a natural person will commit or will likely commit a criminal offence based solely on profiling of that person or on assessing their personality traits and characteristics; it exempts only AI that supports the human assessment of a person's involvement in a criminal activity, which is already based on objective and verifiable facts directly linked to a criminal activity. An AML customer risk rating built from due diligence attributes, transaction behaviour and screening results is itself an automated evaluation of a person's situation and behaviour, which is profiling under GDPR Article 4(4), and due diligence facts such as occupation, geography and products are not facts directly linked to a criminal activity, so the rating does not sit squarely inside the exemption. What keeps it a defensible AML due diligence tool rather than an offence prediction is that it does not itself accuse a person of an offence: it sets a level of scrutiny, a human analyst reviews material moves, and regulatory minimum rules sit above the model as hard constraints. A rating driven mainly by nationality or other personal attributes weakens that position further, which is why the proxy discrimination guardrail matters. If the same score is used to evaluate the creditworthiness of natural persons or to establish their credit score, that use falls under Annex III point 5(b) and is high risk, so keep the AML rating and credit decisions separate.",{"slug":366,"title":367,"shortTitle":368,"definition":369,"status":19,"industries":370,"functions":371,"patterns":372,"audience":115,"autonomy":373,"adoptionStage":374,"segment":34,"evidenceCount":375,"publicEvidenceCount":375,"organizations":376,"bestGrade":64,"headline":383,"lastVerified":42,"indexable":12,"euAiActTier":43,"euAiActBasis":388},"real-time-fraud-scoring","Real time fraud scoring for card and instant payments","Real time fraud scoring","Machine learning that decides in milliseconds, without any conversation, how likely each card authorization and account to account payment is to be fraudulent, combining behavioural, device and network signals, so the bank can approve, challenge or block a payment before the money leaves. Working the resulting alerts and talking to the customer about them are separate use cases.",[21,22],[24],[30,148],"autonomous","mainstream",9,[250,325,377,378,379,380,381,382],"Mastercard","NatWest Group","Pay.UK","Revolut","Stripe","Visa",{"kpi":384,"label":385,"unit":96,"n":35,"nUpTo":174,"kind":386,"value":387,"qualifier":176,"claimant":101,"organization":41,"vendorReported":11},"fraud-loss-reduction","Fraud loss reduction","median",30,"Annex III point 5(b) lists creditworthiness assessment and credit scoring of natural persons as high risk but explicitly excludes AI systems used for the purpose of detecting financial fraud, and payment fraud scoring is not otherwise listed in Annex III or prohibited by Article 5. Behavioural biometrics used only to confirm that customers are who they claim to be fall under the biometric verification exclusion in Annex III point 1(a). The model does not interact with people, so Article 50 does not apply. GDPR Article 22 can still apply to solely automated declines with significant effects on customers.",1790598319420]