AI use case

AI for regulatory report assembly

AI that assembles periodic and data driven regulatory filings and returns, such as prudential and statistical returns, threshold and transaction reports and disclosure packs, by pulling data into the regulator's schema, validating it, reconciling figures to source, explaining movements against prior periods and drafting commentary, before a named officer reviews and submits. Narratives for individual suspicious activity cases are a separate use case.

By Len Debets · Last verified 27 September 2026 · 2 public deployments

USD 230,400 to USD 1.4 million
Indicative value per year
A bank with a regulatory reporting team of 40 people. Worked example, see how it is calculated.

What problem does it solve?

Banks file a steady stream of regulatory reports: prudential returns on capital, liquidity and large exposures, statistical returns to the central bank, threshold and cross border transaction reports to the financial intelligence unit, and public disclosures. Much of the effort goes into gathering data from many systems, formatting it into the regulator's schema (the EBA data point model and XBRL taxonomies for EU prudential returns, the goAML reporting format where the financial intelligence unit runs UNODC's goAML system), reconciling it to the ledger and explaining why numbers moved, rather than into judgment.

Errors are costly, because a wrong or late filing has to be corrected and explained to the authority that received it. The Basel Committee's BCBS 239 principles ask banks to aggregate risk data on a largely automated basis, reconcile it with source and accounting data, and control and document any manual processes and spreadsheets they still rely on. Where those manual steps sit on top of the reporting platform, every period end becomes a scramble. The narrative of a suspicious activity report is a separate job with its own page; this page covers the assembly and quality of the filing itself.

How does it work?

  1. Collect the data. The agent pulls ledger, risk, customer and transaction data for the period from the reporting data warehouse and source systems.
  2. Map and validate. It fills the regulator's schema field by field and runs the official validation and business rules, explaining every failure in plain language.
  3. Reconcile. It reconciles totals to the general ledger and to related returns, and flags breaks with the likely cause.
  4. Explain movements. It compares every material line with prior periods and drafts the variance commentary from the underlying drivers, citing the data behind each statement.
  5. Review and submit. A named officer reviews the pack, resolves open points, signs and submits. The system records what was compiled, changed and approved.
Audience
Employee facing
Autonomy
Copilot
Adoption
Emerging
Channels
Internal tools

What is it worth?

Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.

No public deployment has disclosed a measurable outcome yet.

Value drivers: Compliance quality, Employee productivity, Speed and cycle time, Risk and loss reduction.

Indicative value

A bank with a regulatory reporting team of 40 people

USD 230,400 to USD 1.4 million

Reporting effort released per year

How this is calculated

Formula: fte * hoursPerFte * assemblyShare * effortReduction * costPerHour. The low scenario uses every low input, the high scenario every high input.

InputLowHighBasis
Regulatory reporting staff fte, full time employees4040The reference bank. Replace with your own team size.
Working hours per employee per year hoursPerFte, hours per year1,6001,700Editorial assumption.
Share of time spent gathering, formatting, reconciling and explaining assemblyShare, fraction of working time0.40.6Editorial assumption; replace with your own activity analysis.
Share of that work the AI removes effortReduction, fraction of assembly time0.150.35Editorial assumption, deliberately cautious because public evidence with measured results is thin.
Fully loaded cost per hour costPerHour, USD per hour60100Editorial assumption, replace with your own.

What it leaves out: Labour only. It leaves out fewer resubmissions and supervisory findings, and the cost of the platform, data lineage work and model validation, which are often larger than the model cost.

Who already uses it?

2 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.

Board of Governors of the Federal Reserve System

United States · Government and public sector · 2024

ProductionGrade B

The Federal Reserve Board's Division of Supervision and Regulation uses models developed in house to check the data that reporting firms submit. In its Regulatory Data Analysis use case, in operation since September 2024, analysts receive predicted values at several percentile levels for each reporter to compare with the values it actually reported. A related use case, Decision Tree for Deposits Data (still in implementation and assessment), calculates set variables and filters them to flag potential outliers in the current reporting period. These are supervisor side checks that mirror the validation a bank can run on its own returns before filing. No outcome figures are published.

No outcome disclosed.

National Credit Union Administration

United States · Government and public sector · 2023

ProductionGrade B

The NCUA, which supervises US federal credit unions, uses a machine learning model developed in house to improve the quality of the quarterly Call Report data that credit unions file. Its output is a list of potential data outliers for each credit union. It has been in operation since February 2023. It is the supervisor side of regulatory reporting, and shows the kind of outlier check a filer can run on its own data before it submits. No outcome figures are published.

No outcome disclosed.

How do you implement it?

A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.

Data you need

  • Data lineage from source systems to each reported field
  • The regulator's schema, taxonomy and validation rules for each report
  • Prior period filings, adjustments and review comments

Systems to integrate

  • Regulatory reporting platform or data warehouse
  • General ledger, risk engines and customer data
  • Transaction and payments data for transaction reports
  • The regulator's submission portal

Complexity: High

The formats are well defined, but the data sits in many systems of varying quality, every figure must be traceable, and the reporting officer stays accountable for every number and word.

  1. 1

    Choose one report family

    Start with a single return or a high volume transaction report with a stable schema, not the full reporting estate.

  2. 2

    Trace every field to source

    Document where each field comes from and how it is transformed. Gaps in lineage are the main blocker and are worth fixing regardless of AI.

  3. 3

    Automate validation and reconciliation first

    Plain language explanations of validation failures and reconciliation breaks save time with the least model risk, because the checks themselves stay deterministic.

  4. 4

    Add variance commentary with citations

    Draft commentary only from the data, each statement linked to the figures behind it, and measure how much reviewers change.

  5. 5

    Validate and monitor

    Put any drafting or anomaly model in the model inventory, test it on past periods and monitor edit rates and resubmissions after go live.

Guardrails

  • Nothing is filed without a named officer's review and submission
  • Every number comes from the source of record; the model never generates figures
  • Every file passes the regulator's schema and validation rules before review
  • Commentary cites the data behind each statement and is blocked if it cannot

KPIs to instrument

  • Days from period end to submission
  • Validation failures at first run and at submission
  • Share of commentary text changed by reviewers
  • Resubmissions and restatements
  • Manual adjustments outside the reporting platform

Human in the loop

The reporting officer reviews every return and report, decides on adjustments, and submits. Finance and risk owners confirm variance explanations for their lines, and a second line team samples filed reports each period.

Common failure modes

Commentary that asserts more than the data
The draft explains a movement with a plausible but wrong driver. Require citations and have line owners confirm.
Automation bias in review
Reviewers accept packs because they look complete. Track edit rates and seed known errors in quality checks.
Silent data drift
A source system change alters a field's meaning. Keep lineage and reconciliation checks in every run.

What are the risks and rules?

EU AI Act

Limited risk (transparency)

Not an Article 5 practice and not listed in Annex III: the system prepares filings for authorities and makes no decision on the credit, insurance, employment or access to services of a natural person. It is an internal tool whose users know they are working with AI, and drafted text that ends up in public disclosures passes human review under a named person's editorial responsibility, which takes it outside the Article 50(4) deployer disclosure duty. The system still drafts variance commentary and plain language explanations of validation failures from underlying data, rather than lightly editing existing text, so the assistive function for standard editing exception does not fit. The bank that builds or operates the system is then the provider and carries the Article 50(2) duty to mark that generated text in a machine readable way as artificially generated, which has applied since 2 August 2026. The AI literacy duty of Article 4 also applies.

Guidance

  • Principles for effective risk data aggregation and risk reporting (BCBS 239) (Basel Committee on Banking Supervision, Global). Written for group risk reporting, and the Committee notes banks may also apply it to supervisory reporting. Expects accurate, complete and timely risk data, aggregated on a largely automated basis and reconciled with source and accounting data.
  • Reporting frameworks (European Banking Authority, Europe). The EU supervisory reporting taxonomies and validation rules that returns must pass.
  • goAML (United Nations Office on Drugs and Crime, Global). UNODC software built for financial intelligence units to receive, process and analyse the reports financial institutions file. Where a unit runs goAML, its reporting format is the target for the transaction reports a bank assembles.

Controls to put in place

  • Named officer sign off recorded for every submission
  • Full record of the data compiled, the draft, the edits and the approval
  • Model inventory entry and validation for any drafting or anomaly model
  • Reconciliation of every return to the ledger kept as evidence

Frequently asked questions

Can AI file regulatory reports on its own?
No. A named officer reviews and submits every report. AI gathers and maps the data, explains validation failures and drafts variance commentary, but the numbers come from the systems of record and accountability stays with the reporting officer.
How is this different from drafting suspicious activity reports?
Suspicious activity report drafting is about writing the investigation narrative, which has its own page. This use case covers assembling, validating and explaining the filing and the prudential and statistical returns around it.
Who uses machine learning on regulatory report data today?
Supervisors do. The US National Credit Union Administration uses machine learning to list potential outliers in each credit union's Call Report data, and the Federal Reserve Board gives its analysts model predicted values to compare with what each firm reported. Banks can run the same kind of checks before they submit. Public, measured results from banks using AI for their own returns are still rare.

How to cite this page

Blits.ai AI Use Case Library, "AI for regulatory report assembly", last verified 27 September 2026, https://www.blits.ai/ai-use-cases/regulatory-report-assembly. Licensed under CC BY 4.0. Method: how we verify use cases.

Changelog
  • 27 September 2026: First published

Related use cases

BankingInsurance

AI for supervisory exam and information request responses

An assistant for the bank's regulatory affairs team that reads a supervisory information request or exam question, retrieves the relevant evidence, policies and prior correspondence, drafts a response for legal and compliance to approve, and tracks every commitment and remediation action through to closure.

Deployments
3 public, best grade B
Autonomy
Copilot
BankingPayments and cards

AI for ledger and payment reconciliation

AI that matches entries across nostro and vostro statements, card and scheme settlement files, the general ledger and suspense accounts, proposes matches and clearing journals, and routes only the genuine breaks to an operator with a plain language explanation.

Deployments
4 public, best grade B
Autonomy
Supervised agent
Cross industryBanking

Governed text to SQL analytics assistant

An assistant that turns a business user's plain language question into a query against governed data, runs it under that user's own data permissions and returns the table or chart together with the SQL and the tables used, so routine ad hoc questions no longer queue for the data team.

Deployments
3 public, best grade B
Autonomy
Assist
BankingPayments and cards

AI copilot for SAR and STR narrative drafting

Generative AI that drafts the narrative of a single suspicious activity or suspicious transaction report from the investigation file (who, what, when, where, why and how), with every fact linked to its source record, so the investigator verifies, edits and files instead of starting from a blank page. It works case by case, unlike the periodic data returns of regulatory reporting.

Deployments
4 public, best grade B
Autonomy
Copilot
Cross industryBanking

AI regulatory horizon scanning and obligation mapping

An AI system that continuously reads publications from the regulators and standard setters an organization answers to, classifies each item by relevance and urgency, breaks new rules into individual obligations and maps them to the internal policies and controls that meet them, so compliance owners see what changed and where the gaps are.

Deployments
2 public, best grade B
Autonomy
Assist