What problem does it solve?
Banks file a steady stream of regulatory reports: prudential returns on capital, liquidity and large exposures, statistical returns to the central bank, threshold and cross border transaction reports to the financial intelligence unit, and public disclosures. Much of the effort goes into gathering data from many systems, formatting it into the regulator's schema (the EBA data point model and XBRL taxonomies for EU prudential returns, the goAML reporting format where the financial intelligence unit runs UNODC's goAML system), reconciling it to the ledger and explaining why numbers moved, rather than into judgment.
Errors are costly, because a wrong or late filing has to be corrected and explained to the authority that received it. The Basel Committee's BCBS 239 principles ask banks to aggregate risk data on a largely automated basis, reconcile it with source and accounting data, and control and document any manual processes and spreadsheets they still rely on. Where those manual steps sit on top of the reporting platform, every period end becomes a scramble. The narrative of a suspicious activity report is a separate job with its own page; this page covers the assembly and quality of the filing itself.
How does it work?
- Collect the data. The agent pulls ledger, risk, customer and transaction data for the period from the reporting data warehouse and source systems.
- Map and validate. It fills the regulator's schema field by field and runs the official validation and business rules, explaining every failure in plain language.
- Reconcile. It reconciles totals to the general ledger and to related returns, and flags breaks with the likely cause.
- Explain movements. It compares every material line with prior periods and drafts the variance commentary from the underlying drivers, citing the data behind each statement.
- Review and submit. A named officer reviews the pack, resolves open points, signs and submits. The system records what was compiled, changed and approved.
- Audience
- Employee facing
- Autonomy
- Copilot
- Adoption
- Emerging
- Channels
- Internal tools
What is it worth?
Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.
No public deployment has disclosed a measurable outcome yet.
Value drivers: Compliance quality, Employee productivity, Speed and cycle time, Risk and loss reduction.
Indicative value
A bank with a regulatory reporting team of 40 people
USD 230,400 to USD 1.4 million
Reporting effort released per year
How this is calculated
Formula: fte * hoursPerFte * assemblyShare * effortReduction * costPerHour. The low scenario uses every low input, the high scenario every high input.
| Input | Low | High | Basis |
|---|---|---|---|
| Regulatory reporting staff fte, full time employees | 40 | 40 | The reference bank. Replace with your own team size. |
| Working hours per employee per year hoursPerFte, hours per year | 1,600 | 1,700 | Editorial assumption. |
| Share of time spent gathering, formatting, reconciling and explaining assemblyShare, fraction of working time | 0.4 | 0.6 | Editorial assumption; replace with your own activity analysis. |
| Share of that work the AI removes effortReduction, fraction of assembly time | 0.15 | 0.35 | Editorial assumption, deliberately cautious because public evidence with measured results is thin. |
| Fully loaded cost per hour costPerHour, USD per hour | 60 | 100 | Editorial assumption, replace with your own. |
What it leaves out: Labour only. It leaves out fewer resubmissions and supervisory findings, and the cost of the platform, data lineage work and model validation, which are often larger than the model cost.
Who already uses it?
2 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.
Board of Governors of the Federal Reserve System
United States · Government and public sector · 2024
The Federal Reserve Board's Division of Supervision and Regulation uses models developed in house to check the data that reporting firms submit. In its Regulatory Data Analysis use case, in operation since September 2024, analysts receive predicted values at several percentile levels for each reporter to compare with the values it actually reported. A related use case, Decision Tree for Deposits Data (still in implementation and assessment), calculates set variables and filters them to flag potential outliers in the current reporting period. These are supervisor side checks that mirror the validation a bank can run on its own returns before filing. No outcome figures are published.
No outcome disclosed.
National Credit Union Administration
United States · Government and public sector · 2023
The NCUA, which supervises US federal credit unions, uses a machine learning model developed in house to improve the quality of the quarterly Call Report data that credit unions file. Its output is a list of potential data outliers for each credit union. It has been in operation since February 2023. It is the supervisor side of regulatory reporting, and shows the kind of outlier check a filer can run on its own data before it submits. No outcome figures are published.
No outcome disclosed.
How do you implement it?
A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.
Data you need
- Data lineage from source systems to each reported field
- The regulator's schema, taxonomy and validation rules for each report
- Prior period filings, adjustments and review comments
Systems to integrate
- Regulatory reporting platform or data warehouse
- General ledger, risk engines and customer data
- Transaction and payments data for transaction reports
- The regulator's submission portal
Complexity: High
The formats are well defined, but the data sits in many systems of varying quality, every figure must be traceable, and the reporting officer stays accountable for every number and word.
- 1
Choose one report family
Start with a single return or a high volume transaction report with a stable schema, not the full reporting estate.
- 2
Trace every field to source
Document where each field comes from and how it is transformed. Gaps in lineage are the main blocker and are worth fixing regardless of AI.
- 3
Automate validation and reconciliation first
Plain language explanations of validation failures and reconciliation breaks save time with the least model risk, because the checks themselves stay deterministic.
- 4
Add variance commentary with citations
Draft commentary only from the data, each statement linked to the figures behind it, and measure how much reviewers change.
- 5
Validate and monitor
Put any drafting or anomaly model in the model inventory, test it on past periods and monitor edit rates and resubmissions after go live.
Guardrails
- Nothing is filed without a named officer's review and submission
- Every number comes from the source of record; the model never generates figures
- Every file passes the regulator's schema and validation rules before review
- Commentary cites the data behind each statement and is blocked if it cannot
KPIs to instrument
- Days from period end to submission
- Validation failures at first run and at submission
- Share of commentary text changed by reviewers
- Resubmissions and restatements
- Manual adjustments outside the reporting platform
Human in the loop
The reporting officer reviews every return and report, decides on adjustments, and submits. Finance and risk owners confirm variance explanations for their lines, and a second line team samples filed reports each period.
Common failure modes
- Commentary that asserts more than the data
- The draft explains a movement with a plausible but wrong driver. Require citations and have line owners confirm.
- Automation bias in review
- Reviewers accept packs because they look complete. Track edit rates and seed known errors in quality checks.
- Silent data drift
- A source system change alters a field's meaning. Keep lineage and reconciliation checks in every run.
What are the risks and rules?
EU AI Act
Limited risk (transparency)
Not an Article 5 practice and not listed in Annex III: the system prepares filings for authorities and makes no decision on the credit, insurance, employment or access to services of a natural person. It is an internal tool whose users know they are working with AI, and drafted text that ends up in public disclosures passes human review under a named person's editorial responsibility, which takes it outside the Article 50(4) deployer disclosure duty. The system still drafts variance commentary and plain language explanations of validation failures from underlying data, rather than lightly editing existing text, so the assistive function for standard editing exception does not fit. The bank that builds or operates the system is then the provider and carries the Article 50(2) duty to mark that generated text in a machine readable way as artificially generated, which has applied since 2 August 2026. The AI literacy duty of Article 4 also applies.
Rules that apply
Guidance
- Principles for effective risk data aggregation and risk reporting (BCBS 239) (Basel Committee on Banking Supervision, Global). Written for group risk reporting, and the Committee notes banks may also apply it to supervisory reporting. Expects accurate, complete and timely risk data, aggregated on a largely automated basis and reconciled with source and accounting data.
- Reporting frameworks (European Banking Authority, Europe). The EU supervisory reporting taxonomies and validation rules that returns must pass.
- goAML (United Nations Office on Drugs and Crime, Global). UNODC software built for financial intelligence units to receive, process and analyse the reports financial institutions file. Where a unit runs goAML, its reporting format is the target for the transaction reports a bank assembles.
Controls to put in place
- Named officer sign off recorded for every submission
- Full record of the data compiled, the draft, the edits and the approval
- Model inventory entry and validation for any drafting or anomaly model
- Reconciliation of every return to the ledger kept as evidence
Frequently asked questions
- Can AI file regulatory reports on its own?
- No. A named officer reviews and submits every report. AI gathers and maps the data, explains validation failures and drafts variance commentary, but the numbers come from the systems of record and accountability stays with the reporting officer.
- How is this different from drafting suspicious activity reports?
- Suspicious activity report drafting is about writing the investigation narrative, which has its own page. This use case covers assembling, validating and explaining the filing and the prudential and statistical returns around it.
- Who uses machine learning on regulatory report data today?
- Supervisors do. The US National Credit Union Administration uses machine learning to list potential outliers in each credit union's Call Report data, and the Federal Reserve Board gives its analysts model predicted values to compare with what each firm reported. Banks can run the same kind of checks before they submit. Public, measured results from banks using AI for their own returns are still rare.
How to cite this page
Blits.ai AI Use Case Library, "AI for regulatory report assembly", last verified 27 September 2026, https://www.blits.ai/ai-use-cases/regulatory-report-assembly. Licensed under CC BY 4.0. Method: how we verify use cases.
Changelog
- 27 September 2026: First published