[{"data":1,"prerenderedAt":549},["ShallowReactive",2],{"uc-regulatory-horizon-scanning":3,"uc-regulations":346},{"useCase":4,"evidence":188,"blitsAiDeployments":246,"benchmarks":247,"indicative":248,"related":251,"indexability":344,"includeUnpublished":194},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":16,"functions":24,"patterns":28,"channels":34,"audience":38,"autonomy":39,"adoptionStage":40,"segment":41,"problem":42,"problemStats":43,"howItWorks":44,"valueDrivers":45,"kpis":48,"indicativeValue":53,"macroEstimates":82,"feasibility":83,"implementation":96,"risk":135,"blitsAi":164,"faq":166,"related":176,"datePublished":183,"dateModified":183,"lastVerified":183,"changelog":184,"slug":187},"AI regulatory horizon scanning and obligation mapping","Regulatory horizon scanning","AI regulatory horizon scanning for compliance","AI reads regulator publications, flags relevant changes and maps new obligations to controls. Corlytics reports a 25% efficiency gain at a European tier 1 bank.","published","An AI system that continuously reads publications from the regulators and standard setters an organization answers to, classifies each item by relevance and urgency, breaks new rules into individual obligations and maps them to the internal policies and controls that meet them, so compliance owners see what changed and where the gaps are.",[12,13,14,15],"regulatory change management","regulatory intelligence","obligation mapping","regulatory monitoring",[17,18,19,20,21,22,23],"cross-industry","banking","insurance","payments","wealth-and-asset-management","pharma-and-life-sciences","government",[25,26,27],"regulatory-compliance","legal","risk-management",[29,30,31,32,33],"classification-and-routing","document-processing","rag-knowledge-assistant","summarization","agentic-workflow",[35,36,37],"internal-tools","email","microsoft-teams","employee-facing","assist","early-adopters","compliance","A bank operating in a few countries answers to many regulators and standard setters, each\npublishing consultations, rules, guidance, speeches and enforcement actions. Compliance\nteams read feeds and newsletters by hand, decide what is relevant, and then work out which internal\npolicies and controls a new rule touches. The work is repetitive, depends on who is reading, and\nleaves little audit trail of why an item was judged irrelevant.\n\nThe cost of missing something is high: a late implementation, a finding in an examination, or a\nboard that cannot show how it stays current on regulatory change. Answering an examiner or auditor who\nasks how a rule is met takes a traceable line from each obligation to the policy and control that\nmeets it, and that line is hard to keep up to date by hand.",[],"1. **Collect.** The system monitors regulator websites, official journals, standard setters and\n   enforcement publications for every jurisdiction in scope.\n2. **Classify.** Each item is tagged by jurisdiction, topic, document type, business line and\n   urgency, and irrelevant items are filtered with a recorded reason.\n3. **Summarise.** Relevant items get a short summary, key dates and what is new compared with the\n   previous version or consultation.\n4. **Extract obligations.** Final rules are broken into individual obligations in a consistent\n   structure (who must do what, by when).\n5. **Map to the library.** Each obligation is matched to existing policies and controls through\n   retrieval over the internal obligation and control library, and unmatched or partly matched\n   obligations are flagged as gaps.\n6. **Route and record.** Items go to the owner of the affected area, who confirms materiality and\n   accepts, changes or rejects each mapping; the decision and reasoning are kept.",[41,46,47],"employee-productivity","risk-reduction",[49,50,51,52],"productivity-gain","hours-saved","time-saved-per-task","interactions-handled",{"referenceOrg":54,"inputs":55,"formula":77,"currency":78,"period":79,"resultLabel":80,"caveat":81},"A bank monitoring regulatory change across 10 jurisdictions",[56,63,70],{"key":57,"label":58,"low":59,"high":60,"unit":61,"note":62},"monitoringFte","Full time staff spent on monitoring and first assessment of regulatory change",6,12,"full time equivalents","Editorial assumption. Replace with your own team size.",{"key":64,"label":65,"low":66,"high":67,"unit":68,"note":69},"efficiency","Share of that effort saved",0.15,0.2,"fraction of effort","The high end is derived from the only published efficiency figure on this page, a 25% efficiency gain reported by a vendor, in the benefits section of a case study, for the compliance monitoring and compliance risk insight teams of an anonymous European tier 1 bank. A 25% efficiency (output per unit of effort) increase corresponds to about 20% of effort released, so it does not match the source figure directly. Treat it as a ceiling, not a typical result. The low end is an editorial assumption for teams that keep more manual review.",{"key":71,"label":72,"low":73,"high":74,"unit":75,"note":76},"costPerFte","Fully loaded cost per compliance analyst",120000,180000,"USD per year","Editorial assumption.","monitoringFte * efficiency * costPerFte","USD","per year","Compliance monitoring effort released","Counts analyst effort only. It leaves out licence and content costs, the cost of building and maintaining the obligation library, and the harder to price value of fewer missed changes and a cleaner audit trail for supervisors.",[],{"complexity":84,"complexityNote":85,"dataPrerequisites":86,"integrations":91},"medium","Monitoring and classification are mature, and commercial regulatory content feeds exist. The hard part is a clean internal library of policies and controls to map against, and owners who review the mappings.",[87,88,89,90],"A list of regulators, jurisdictions and topics in scope","A policy and control library with owners, ideally already linked to obligations","A taxonomy of business lines, products and risk types","Historical regulatory change decisions to test classification against",[92,93,94,95],"Regulatory content feeds or website monitoring","Governance, risk and compliance (GRC) platform","Policy management system","Collaboration tools for routing and sign off",{"steps":97,"guardrails":113,"humanInTheLoop":118,"kpisToInstrument":119,"failureModes":125},[98,101,104,107,110],{"title":99,"detail":100},"Define scope and relevance","List jurisdictions, regulators and topics, and write down what makes an item relevant for each business line. That definition is what the classifier is tested against.",{"title":102,"detail":103},"Clean the obligation and control library","Mapping only works against a library that is current, owned and consistently written. Fix the library before automating the mapping.",{"title":105,"detail":106},"Run in parallel with the manual process","For a quarter, let the system classify and map alongside the team and compare: what it missed, what it flagged that people missed, and where mappings differ.",{"title":108,"detail":109},"Route to owners with the evidence","Send each relevant item to the accountable owner with the summary, the proposed mappings and the source, and require a recorded decision.",{"title":111,"detail":112},"Report to management and the board","Use the recorded decisions to show open changes, gaps and implementation status per regulator and business line.",[114,115,116,117],"A named owner confirms materiality and accepts or overrides every mapping","Every filtered out item keeps its reason, so exclusions can be audited","Summaries always link to the official source text","Obligations are extracted from final texts, not from secondary commentary","Compliance owners confirm relevance and materiality, approve obligation mappings and decide on gaps. Legal interprets ambiguous rules. The system proposes; people decide, and their reasoning is retained for supervisors.",[120,121,122,123,124],"Share of relevant items found within a set number of days of publication","Items missed by the system but found by people, and the reverse","Owner agreement rate with proposed mappings","Analyst hours per week on monitoring and first assessment","Open gaps and their age",[126,129,132],{"title":127,"detail":128},"Silent misses","A source changes its website or feed and nothing arrives. Monitor each source's volume and alert when it drops to zero.",{"title":130,"detail":131},"Confident but wrong mappings","The system maps an obligation to a control that sounds similar but does not meet it. Require owner sign off and sample accepted mappings.",{"title":133,"detail":134},"Summaries treated as the rule","Staff act on a summary that missed a qualification. Always link to and quote the source text.",{"euAiAct":136,"regulations":139,"guidance":145,"controls":158,"incidents":163},{"tier":137,"basis":138},"limited","An internal tool that monitors and classifies regulatory publications for staff makes no decisions about natural persons, so it is not listed in Annex III and is not a prohibited practice under Article 5. Staff know they are using an AI tool and its summaries are not published to the public, so the Article 50 duties to inform users and to disclose published generated text add little for the deploying organization. Article 50(2) still requires the provider of a system that generates text to mark its output, in a machine readable format, as AI generated: usually the vendor, but an organization that builds its own summariser can itself be that provider, which is what puts this use case at the limited tier rather than minimal. Beyond this and AI literacy (Article 4), no specific obligations apply. General model risk and third party rules still apply.",[140,141,142,143,144],"dora","iso-42001","nist-ai-rmf","mas-ai-risk-management","apra-cps-230",[146,152],{"title":147,"issuer":148,"region":149,"url":150,"note":151},"MAS Guidelines for Artificial Intelligence Risk Management","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Proposed in a consultation paper of 13 November 2025 that closed on 31 January 2026; no final Guidelines were listed on the consultation page when checked on 27 September 2026. The proposed Guidelines will apply to all financial institutions, cover different AI applications and technologies, including generative AI and AI agents, and expect controls proportionate to the assessed risk materiality of each AI use.",{"title":153,"issuer":154,"region":155,"url":156,"note":157},"AI Risk Management Framework","NIST","north-america","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary framework to govern, map, measure and manage the risks of AI systems, including generative AI.",[159,160,161,162],"Documented source list with monitoring of each source's availability","Decision log of relevance, materiality and mapping decisions with owners and dates","Periodic sample review of excluded items and accepted mappings","Inventory entry for the tool with its intended use and limitations",[],{"howToBuild":165},"On Blits.ai the scanning runs as scheduled **agentic workflows**. The **knowledge base** crawls and\nrecrawls regulator web pages, ingests PDFs and email alerts through the **incoming email** source,\nand holds the internal policy and control library for **hybrid retrieval**. An **agent** with\n**structured output** classifies each new item, summarises it, extracts obligations and proposes\nmappings to the library with citations to the source text. **Custom functions**, ready made\ntools such as SharePoint, or systems from the integration catalog such as ServiceNow write the\nresults to the GRC or policy system.\n\nOwners receive items by email or in **Microsoft Teams**. Set the **human in the loop** threshold\nof the workflow so that every mapping waits for an owner to approve or reject it before it is\nrecorded. The **run history and audit trail** keep every classification and\ndecision, **monitors** run scheduled checks on the agent and alert by email or webhook when it\nfails, and **test suites** with LLM based\ngrading check classification against past decisions. Compliance staff can ask questions about the\nlibrary through an **agent** that answers from the **knowledge base** with retrieval augmented\ngeneration. The platform is model agnostic and can run in the EU\nor UAE region.",[167,170,173],{"question":168,"answer":169},"Can AI replace a regulatory change team?","No. It removes the reading and first sorting, and proposes obligation mappings, but relevance, materiality and interpretation stay with compliance owners and legal. The value is coverage, speed and an audit trail.",{"question":171,"answer":172},"What results have organizations reported?","Published figures are scarce and come from vendors. Corlytics reports a 25% efficiency gain for the compliance monitoring and compliance risk insight teams of an anonymous European tier 1 bank, stated in the benefits section of its case study rather than as a measured outcome. Other deployments on this page, such as the UK FCA Intelligent Handbook, where a machine learning framework developed with Corlytics auto tags Handbook content with review and a full audit trail, and the US Administration for Children and Families review of documents against new directives, describe their benefits in words only.",{"question":174,"answer":175},"Is regulatory horizon scanning high risk under the EU AI Act?","No, it is not a high risk Annex III use. It is limited risk: an organization that builds its own summariser can be the provider of a text generating system under Article 50(2), which requires marking its output as AI generated. Treat it as a model with an owner, documented limits and human sign off on every mapping.",[177,178,179,180,181,182],"policy-drafting-and-gap-analysis","continuous-controls-testing","regulatory-report-assembly","supervisory-exam-response-assembly","marketing-content-compliance-copilot","ai-model-inventory","2026-09-27",[185],{"date":183,"note":186},"First published","regulatory-horizon-scanning",[189,223],{"title":190,"useCases":191,"organization":192,"vendors":196,"summary":202,"stage":203,"year":204,"channels":205,"languages":206,"metrics":208,"outcomeDisclosed":194,"sources":209,"verification":217,"grade":220,"id":221,"organizationSlug":222},"HHS Administration for Children and Families: AI review of documents against new directives",[177,187],{"name":193,"anonymized":194,"country":195,"region":155,"industry":23},"Administration for Children and Families",false,"US",[197,200],{"name":198,"role":199},"Palantir","platform",{"name":201,"role":199},"Credal","In March 2025 the Administration for Children and Families, part of the US Department of Health and Human Services, deployed AI to review its existing grants, new grant applications and position descriptions for alignment with HHS Secretarial Directives related to recent executive orders. The AI produces an initial list of documents that may need revision (for grants, with an initial assessment and example passages); program office staff then review, justify and recommend. For position descriptions the agency states that AI was not used to make any final determinations. It is the gap detection half of policy change work: finding which existing documents a new requirement touches.","production",2025,[35],[207],"en",[],[210,214],{"url":211,"title":212,"publisher":213},"https://github.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory","2025 Federal Agency AI Use Case Inventory","Office of Management and Budget (GitHub)",{"url":215,"title":216,"publisher":213},"https://raw.githubusercontent.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory/main/Data/2025_individually_reported_AI_use_cases.csv","2025 individually reported AI use cases (HHS/ACF entries Document Review for Alignment with Executive Orders)",{"level":218,"checkedAt":219},"source-verified","2026-09-26","B","hhs-acf-directive-alignment-document-review",null,{"title":224,"useCases":225,"organization":226,"vendors":230,"summary":233,"stage":203,"year":234,"channels":235,"languages":236,"metrics":237,"outcomeDisclosed":194,"sources":238,"verification":243,"grade":244,"id":245,"organizationSlug":222},"Financial Conduct Authority: machine readable Intelligent Handbook",[187],{"name":227,"anonymized":194,"country":228,"region":229,"industry":23},"Financial Conduct Authority","GB","europe",[231],{"name":232,"role":199},"Corlytics","The UK Financial Conduct Authority worked with Corlytics to turn its Handbook into a searchable, machine readable rulebook. A pilot that started in September 2016 added taxonomy tagging with a four eyes approval workflow. Corlytics then developed with the FCA a machine learning framework for auto tagging and classifying content, which the vendor describes as using a rules based approach, with users able to review, approve or reject tags under a full audit trail. After the pilot, Corlytics delivered taxonomy tagging for the remaining Handbook provisions; it describes the Handbook as over 18,000 provisions. The system went live on 10 May 2017, and according to the vendor it made regulatory obligations much easier to identify. It shows the regulator side of obligation mapping. No outcome figure was published.",2017,[35],[207],[],[239],{"url":240,"title":241,"publisher":232,"date":242},"https://www.corlytics.com/case_studies/how-can-we-ensure-that-our-handbook-is-digitised-machine-readable-searchable-for-our-users/","How can we ensure that our handbook is digitised, machine-readable & searchable for our users?","2024-09-06",{"level":218,"checkedAt":183},"C","financial-conduct-authority-intelligent-handbook",0,[],{"low":249,"high":250},107999.99999999999,432000.00000000006,[252,270,284,297,308,330],{"slug":177,"title":253,"shortTitle":254,"definition":255,"status":9,"industries":256,"functions":258,"patterns":260,"audience":38,"autonomy":262,"adoptionStage":263,"segment":264,"evidenceCount":265,"publicEvidenceCount":265,"organizations":266,"bestGrade":220,"headline":222,"lastVerified":219,"indexable":269},"AI for policy drafting and policy gap analysis","Policy drafting and gaps","An assistant that takes a new or changed obligation, finds every internal policy, standard and procedure it touches, flags clauses that now conflict or are silent, and drafts the updated wording in house style as a redline for the policy owner to approve.",[17,18,19,257,23],"capital-markets",[25,26,259],"knowledge-management",[31,261,30,32],"content-generation","copilot","emerging","second-line",3,[267,193,268],"Federal Deposit Insurance Corporation","Health Resources and Services Administration",true,{"slug":178,"title":271,"shortTitle":272,"definition":273,"status":9,"industries":274,"functions":275,"patterns":277,"audience":279,"autonomy":280,"adoptionStage":263,"segment":264,"evidenceCount":265,"publicEvidenceCount":265,"organizations":281,"bestGrade":220,"headline":222,"lastVerified":183,"indexable":269},"AI for continuous controls testing and control self assessment","Continuous controls testing","AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.",[17,18,19,257,23],[27,25,276],"operations",[33,30,278,29],"anomaly-detection","back-office","supervised-agent",[267,282,283],"U.S. Department of the Interior","Pension Benefit Guaranty Corporation",{"slug":179,"title":285,"shortTitle":286,"definition":287,"status":9,"industries":288,"functions":289,"patterns":292,"audience":38,"autonomy":262,"adoptionStage":263,"segment":279,"evidenceCount":293,"publicEvidenceCount":293,"organizations":294,"bestGrade":220,"headline":222,"lastVerified":183,"indexable":269},"AI for regulatory report assembly","Regulatory report assembly","AI that assembles periodic and data driven regulatory filings and returns, such as prudential and statistical returns, threshold and transaction reports and disclosure packs, by pulling data into the regulator's schema, validating it, reconciling figures to source, explaining movements against prior periods and drafting commentary, before a named officer reviews and submits. Narratives for individual suspicious activity cases are a separate use case.",[18,19,257,20],[25,290,291],"finance-and-accounting","financial-crime-compliance",[33,278,261,32],2,[295,296],"Board of Governors of the Federal Reserve System","National Credit Union Administration",{"slug":180,"title":298,"shortTitle":299,"definition":300,"status":9,"industries":301,"functions":302,"patterns":304,"audience":38,"autonomy":262,"adoptionStage":263,"segment":264,"evidenceCount":265,"publicEvidenceCount":265,"organizations":305,"bestGrade":220,"headline":222,"lastVerified":183,"indexable":269},"AI for supervisory exam and information request responses","Exam response assembly","An assistant for the bank's regulatory affairs team that reads a supervisory information request or exam question, retrieves the relevant evidence, policies and prior correspondence, drafts a response for legal and compliance to approve, and tracks every commitment and remediation action through to closure.",[18,19,257,20],[25,26,303],"case-management",[31,261,30,33],[306,307],"U.S. Department of Homeland Security","Federal Emergency Management Agency",{"slug":181,"title":309,"shortTitle":310,"definition":311,"status":9,"industries":312,"functions":313,"patterns":315,"audience":38,"autonomy":262,"adoptionStage":40,"evidenceCount":317,"publicEvidenceCount":265,"organizations":318,"bestGrade":220,"headline":322,"lastVerified":183,"indexable":269},"AI copilot for marketing content with compliance pre review","Marketing content and compliance","A copilot that drafts campaign copy, product explainers and social posts on brand and in the customer's language from approved product facts, then runs a first pass compliance check against advertising rules and required disclosures, flagging unsupported claims and missing warnings before a human in marketing compliance approves publication.",[17,18,19,20,21,22],[314,25,26],"marketing",[261,31,29,316],"translation",5,[319,320,321],"Ally Financial","JPMorgan Chase","Klarna",{"kpi":49,"label":323,"unit":324,"n":325,"nUpTo":246,"kind":326,"value":327,"qualifier":328,"claimant":329,"organization":319,"vendorReported":194},"Productivity gain","percent",1,"reported",34,"exact","organization",{"slug":182,"title":331,"shortTitle":332,"definition":333,"status":9,"industries":334,"functions":336,"patterns":338,"audience":38,"autonomy":262,"adoptionStage":40,"evidenceCount":339,"publicEvidenceCount":339,"organizations":340,"bestGrade":220,"headline":222,"lastVerified":183,"indexable":269},"AI system and model inventory with shadow AI discovery","AI model inventory","A governed register of every AI system and model an organization builds, buys or uses, with its owner, purpose, data, risk tier and approval status, kept current by AI that discovers unregistered use, reads the documentation and assembles the evidence a board, auditor or supervisor asks for.",[17,18,19,23,335],"manufacturing",[27,25,337],"it-and-engineering",[33,30,31,29],4,[295,341,342,343],"Office of Management and Budget","Unilever","U.S. Department of Justice",{"indexable":269,"reasons":345},[],[347,354,360,367,371,376,383,389,393,399,406,412,419,426,432,437,444,449,455,461,467,473,479,484,489,496,503,508,513,520,526,532,538,543],{"id":348,"label":349,"issuer":350,"region":229,"url":351,"description":352,"useCases":353,"indexable":269},"eu-ai-act","EU AI Act","European Union","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":355,"label":356,"issuer":350,"region":229,"url":357,"description":358,"useCases":359,"indexable":269},"gdpr","GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":141,"label":361,"issuer":362,"region":363,"url":364,"description":365,"useCases":366,"indexable":269},"ISO/IEC 42001","ISO and IEC","global","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":142,"label":368,"issuer":154,"region":155,"url":156,"description":369,"useCases":370,"indexable":269},"NIST AI Risk Management Framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":140,"label":372,"issuer":350,"region":229,"url":373,"description":374,"useCases":375,"indexable":269},"DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":377,"label":378,"issuer":379,"region":229,"url":380,"description":381,"useCases":382,"indexable":269},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":384,"label":385,"issuer":227,"region":229,"url":386,"description":387,"useCases":388,"indexable":269},"uk-consumer-duty","FCA Consumer Duty","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":143,"label":390,"issuer":148,"region":149,"url":150,"description":391,"useCases":392,"indexable":269},"MAS AI risk management guidelines","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":144,"label":394,"issuer":395,"region":149,"url":396,"description":397,"useCases":398,"indexable":269},"APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":400,"label":401,"issuer":402,"region":363,"url":403,"description":404,"useCases":405,"indexable":269},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",20,{"id":407,"label":408,"issuer":409,"region":155,"url":410,"description":411,"useCases":405,"indexable":269},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":413,"label":414,"issuer":415,"region":229,"url":416,"description":417,"useCases":418,"indexable":269},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":420,"label":421,"issuer":422,"region":363,"url":423,"description":424,"useCases":425,"indexable":269},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":427,"label":428,"issuer":350,"region":229,"url":429,"description":430,"useCases":431,"indexable":269},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":433,"label":434,"issuer":350,"region":229,"url":435,"description":436,"useCases":431,"indexable":269},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":438,"label":439,"issuer":440,"region":155,"url":441,"description":442,"useCases":443,"indexable":269},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":445,"label":446,"issuer":350,"region":229,"url":447,"description":448,"useCases":60,"indexable":269},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",{"id":450,"label":451,"issuer":452,"region":155,"url":453,"description":454,"useCases":60,"indexable":269},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":456,"label":457,"issuer":458,"region":363,"url":459,"description":460,"useCases":60,"indexable":269},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":462,"label":463,"issuer":350,"region":229,"url":464,"description":465,"useCases":466,"indexable":269},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":468,"label":469,"issuer":470,"region":155,"url":471,"description":472,"useCases":466,"indexable":269},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":474,"label":475,"issuer":148,"region":149,"url":476,"description":477,"useCases":478,"indexable":269},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",10,{"id":480,"label":481,"issuer":350,"region":229,"url":482,"description":483,"useCases":478,"indexable":269},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":485,"label":486,"issuer":350,"region":229,"url":487,"description":488,"useCases":478,"indexable":269},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":490,"label":491,"issuer":492,"region":229,"url":493,"description":494,"useCases":495,"indexable":269},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":497,"label":498,"issuer":499,"region":155,"url":500,"description":501,"useCases":502,"indexable":269},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",8,{"id":504,"label":505,"issuer":350,"region":229,"url":506,"description":507,"useCases":502,"indexable":269},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":509,"label":510,"issuer":350,"region":229,"url":511,"description":512,"useCases":59,"indexable":269},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",{"id":514,"label":515,"issuer":516,"region":517,"url":518,"description":519,"useCases":317,"indexable":269},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":521,"label":522,"issuer":523,"region":229,"url":524,"description":525,"useCases":339,"indexable":269},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":527,"label":528,"issuer":529,"region":229,"url":530,"description":531,"useCases":339,"indexable":269},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":533,"label":534,"issuer":535,"region":149,"url":536,"description":537,"useCases":265,"indexable":269},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":539,"label":540,"issuer":350,"region":229,"url":541,"description":542,"useCases":265,"indexable":269},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":544,"label":545,"issuer":546,"region":155,"url":547,"description":548,"useCases":265,"indexable":269},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598303568]