[{"data":1,"prerenderedAt":544},["ShallowReactive",2],{"uc-regulatory-report-assembly":3,"uc-regulations":337},{"useCase":4,"evidence":203,"blitsAiDeployments":249,"benchmarks":250,"indicative":251,"related":254,"indexability":335,"includeUnpublished":209},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":16,"functions":21,"patterns":25,"channels":30,"audience":32,"autonomy":33,"adoptionStage":34,"segment":35,"problem":36,"problemStats":37,"howItWorks":38,"valueDrivers":39,"kpis":44,"indicativeValue":50,"macroEstimates":92,"feasibility":93,"implementation":105,"risk":144,"blitsAi":180,"faq":182,"related":192,"datePublished":198,"dateModified":198,"lastVerified":198,"changelog":199,"slug":202},"AI for regulatory report assembly","Regulatory report assembly","AI for regulatory report assembly and validation","AI assembles, validates and reconciles regulatory returns and drafts variance commentary for officer sign off. The Federal Reserve Board and NCUA run similar checks.","published","AI that assembles periodic and data driven regulatory filings and returns, such as prudential and statistical returns, threshold and transaction reports and disclosure packs, by pulling data into the regulator's schema, validating it, reconciling figures to source, explaining movements against prior periods and drafting commentary, before a named officer reviews and submits. Narratives for individual suspicious activity cases are a separate use case.",[12,13,14,15],"AI regulatory reporting","regulatory return preparation","XBRL return automation","goAML report assembly",[17,18,19,20],"banking","insurance","capital-markets","payments",[22,23,24],"regulatory-compliance","finance-and-accounting","financial-crime-compliance",[26,27,28,29],"agentic-workflow","anomaly-detection","content-generation","summarization",[31],"internal-tools","employee-facing","copilot","emerging","back-office","Banks file a steady stream of regulatory reports: prudential returns on capital, liquidity and\nlarge exposures, statistical returns to the central bank, threshold and cross border transaction\nreports to the financial intelligence unit, and public disclosures. Much of the effort goes into\ngathering data from many systems, formatting it into the regulator's schema (the EBA data point\nmodel and XBRL taxonomies for EU prudential returns, the goAML reporting format where the\nfinancial intelligence unit runs UNODC's goAML system), reconciling it to the ledger and\nexplaining why numbers moved, rather than into judgment.\n\nErrors are costly, because a wrong or late filing has to be corrected and explained to the\nauthority that received it. The Basel Committee's BCBS 239 principles ask banks to aggregate risk\ndata on a largely automated basis, reconcile it with source and accounting data, and control and\ndocument any manual processes and spreadsheets they still rely on. Where those manual steps sit\non top of the reporting platform, every period end becomes a scramble. The narrative of a\nsuspicious activity report is a separate job with its own page; this page covers the assembly\nand quality of the filing itself.",[],"1. **Collect the data.** The agent pulls ledger, risk, customer and transaction data for the\n   period from the reporting data warehouse and source systems.\n2. **Map and validate.** It fills the regulator's schema field by field and runs the official\n   validation and business rules, explaining every failure in plain language.\n3. **Reconcile.** It reconciles totals to the general ledger and to related returns, and flags\n   breaks with the likely cause.\n4. **Explain movements.** It compares every material line with prior periods and drafts the\n   variance commentary from the underlying drivers, citing the data behind each statement.\n5. **Review and submit.** A named officer reviews the pack, resolves open points, signs and\n   submits. The system records what was compiled, changed and approved.",[40,41,42,43],"compliance","employee-productivity","speed","risk-reduction",[45,46,47,48,49],"processing-time-reduction","productivity-gain","error-reduction","hours-saved","time-saved-per-task",{"referenceOrg":51,"inputs":52,"formula":87,"currency":88,"period":89,"resultLabel":90,"caveat":91},"A bank with a regulatory reporting team of 40 people",[53,59,66,73,80],{"key":54,"label":55,"low":56,"high":56,"unit":57,"note":58},"fte","Regulatory reporting staff",40,"full time employees","The reference bank. Replace with your own team size.",{"key":60,"label":61,"low":62,"high":63,"unit":64,"note":65},"hoursPerFte","Working hours per employee per year",1600,1700,"hours per year","Editorial assumption.",{"key":67,"label":68,"low":69,"high":70,"unit":71,"note":72},"assemblyShare","Share of time spent gathering, formatting, reconciling and explaining",0.4,0.6,"fraction of working time","Editorial assumption; replace with your own activity analysis.",{"key":74,"label":75,"low":76,"high":77,"unit":78,"note":79},"effortReduction","Share of that work the AI removes",0.15,0.35,"fraction of assembly time","Editorial assumption, deliberately cautious because public evidence with measured results is thin.",{"key":81,"label":82,"low":83,"high":84,"unit":85,"note":86},"costPerHour","Fully loaded cost per hour",60,100,"USD per hour","Editorial assumption, replace with your own.","fte * hoursPerFte * assemblyShare * effortReduction * costPerHour","USD","per year","Reporting effort released","Labour only. It leaves out fewer resubmissions and supervisory findings, and the cost of the platform, data lineage work and model validation, which are often larger than the model cost.",[],{"complexity":94,"complexityNote":95,"dataPrerequisites":96,"integrations":100},"high","The formats are well defined, but the data sits in many systems of varying quality, every figure must be traceable, and the reporting officer stays accountable for every number and word.",[97,98,99],"Data lineage from source systems to each reported field","The regulator's schema, taxonomy and validation rules for each report","Prior period filings, adjustments and review comments",[101,102,103,104],"Regulatory reporting platform or data warehouse","General ledger, risk engines and customer data","Transaction and payments data for transaction reports","The regulator's submission portal",{"steps":106,"guardrails":122,"humanInTheLoop":127,"kpisToInstrument":128,"failureModes":134},[107,110,113,116,119],{"title":108,"detail":109},"Choose one report family","Start with a single return or a high volume transaction report with a stable schema, not the full reporting estate.",{"title":111,"detail":112},"Trace every field to source","Document where each field comes from and how it is transformed. Gaps in lineage are the main blocker and are worth fixing regardless of AI.",{"title":114,"detail":115},"Automate validation and reconciliation first","Plain language explanations of validation failures and reconciliation breaks save time with the least model risk, because the checks themselves stay deterministic.",{"title":117,"detail":118},"Add variance commentary with citations","Draft commentary only from the data, each statement linked to the figures behind it, and measure how much reviewers change.",{"title":120,"detail":121},"Validate and monitor","Put any drafting or anomaly model in the model inventory, test it on past periods and monitor edit rates and resubmissions after go live.",[123,124,125,126],"Nothing is filed without a named officer's review and submission","Every number comes from the source of record; the model never generates figures","Every file passes the regulator's schema and validation rules before review","Commentary cites the data behind each statement and is blocked if it cannot","The reporting officer reviews every return and report, decides on adjustments, and submits. Finance and risk owners confirm variance explanations for their lines, and a second line team samples filed reports each period.",[129,130,131,132,133],"Days from period end to submission","Validation failures at first run and at submission","Share of commentary text changed by reviewers","Resubmissions and restatements","Manual adjustments outside the reporting platform",[135,138,141],{"title":136,"detail":137},"Commentary that asserts more than the data","The draft explains a movement with a plausible but wrong driver. Require citations and have line owners confirm.",{"title":139,"detail":140},"Automation bias in review","Reviewers accept packs because they look complete. Track edit rates and seed known errors in quality checks.",{"title":142,"detail":143},"Silent data drift","A source system change alters a field's meaning. Keep lineage and reconciliation checks in every run.",{"euAiAct":145,"regulations":148,"guidance":156,"controls":174,"incidents":179},{"tier":146,"basis":147},"limited","Not an Article 5 practice and not listed in Annex III: the system prepares filings for authorities and makes no decision on the credit, insurance, employment or access to services of a natural person. It is an internal tool whose users know they are working with AI, and drafted text that ends up in public disclosures passes human review under a named person's editorial responsibility, which takes it outside the Article 50(4) deployer disclosure duty. The system still drafts variance commentary and plain language explanations of validation failures from underlying data, rather than lightly editing existing text, so the assistive function for standard editing exception does not fit. The bank that builds or operates the system is then the provider and carries the Article 50(2) duty to mark that generated text in a machine readable way as artificially generated, which has applied since 2 August 2026. The AI literacy duty of Article 4 also applies.",[149,150,151,152,153,154,155],"eu-ai-act","dora","fatf-recommendations","us-sr-11-7","apra-cps-230","us-bsa","solvency-ii",[157,163,169],{"title":158,"issuer":159,"region":160,"url":161,"note":162},"Principles for effective risk data aggregation and risk reporting (BCBS 239)","Basel Committee on Banking Supervision","global","https://www.bis.org/publ/bcbs239.htm","Written for group risk reporting, and the Committee notes banks may also apply it to supervisory reporting. Expects accurate, complete and timely risk data, aggregated on a largely automated basis and reconciled with source and accounting data.",{"title":164,"issuer":165,"region":166,"url":167,"note":168},"Reporting frameworks","European Banking Authority","europe","https://www.eba.europa.eu/risk-and-data-analysis/reporting-frameworks","The EU supervisory reporting taxonomies and validation rules that returns must pass.",{"title":170,"issuer":171,"region":160,"url":172,"note":173},"goAML","United Nations Office on Drugs and Crime","https://www.unodc.org/unodc/en/global-it-products/goaml.html","UNODC software built for financial intelligence units to receive, process and analyse the reports financial institutions file. Where a unit runs goAML, its reporting format is the target for the transaction reports a bank assembles.",[175,176,177,178],"Named officer sign off recorded for every submission","Full record of the data compiled, the draft, the edits and the approval","Model inventory entry and validation for any drafting or anomaly model","Reconciliation of every return to the ledger kept as evidence",[],{"howToBuild":181},"On Blits.ai this is an **agentic workflow** that runs at period end or on a schedule. **Custom\nfunctions** and **SQL knowledge bases** pull the reporting data, deterministic checks run as\ncustom code, and an **AI agent** with **structured output** explains validation failures and\ndrafts variance commentary. Reporting instructions and prior review comments sit in the\n**knowledge base** with hybrid retrieval.\n\n**Human in the loop approval** holds the pack for the reporting officer; the platform does not\nsubmit on its own. Each run keeps a **full audit trail**, **prompt versioning** records how the\ndrafting instructions changed, and **test suites** grade commentary against past periods. The\nplatform is model agnostic and runs in EU or UAE regions where data must stay local.",[183,186,189],{"question":184,"answer":185},"Can AI file regulatory reports on its own?","No. A named officer reviews and submits every report. AI gathers and maps the data, explains validation failures and drafts variance commentary, but the numbers come from the systems of record and accountability stays with the reporting officer.",{"question":187,"answer":188},"How is this different from drafting suspicious activity reports?","Suspicious activity report drafting is about writing the investigation narrative, which has its own page. This use case covers assembling, validating and explaining the filing and the prudential and statistical returns around it.",{"question":190,"answer":191},"Who uses machine learning on regulatory report data today?","Supervisors do. The US National Credit Union Administration uses machine learning to list potential outliers in each credit union's Call Report data, and the Federal Reserve Board gives its analysts model predicted values to compare with what each firm reported. Banks can run the same kind of checks before they submit. Public, measured results from banks using AI for their own returns are still rare.",[193,194,195,196,197],"supervisory-exam-response-assembly","ledger-and-payment-reconciliation","governed-text-to-sql-analytics","suspicious-activity-report-drafting","regulatory-horizon-scanning","2026-09-27",[200],{"date":198,"note":201},"First published","regulatory-report-assembly",[204,233],{"title":205,"useCases":206,"organization":207,"vendors":213,"summary":214,"stage":215,"year":216,"channels":217,"languages":218,"metrics":220,"outcomeDisclosed":209,"sources":221,"verification":227,"grade":230,"id":231,"organizationSlug":232},"Federal Reserve Board: machine learning checks on regulatory report data",[202],{"name":208,"anonymized":209,"country":210,"region":211,"industry":212},"Board of Governors of the Federal Reserve System",false,"US","north-america","government",[],"The Federal Reserve Board's Division of Supervision and Regulation uses models developed in house to check the data that reporting firms submit. In its Regulatory Data Analysis use case, in operation since September 2024, analysts receive predicted values at several percentile levels for each reporter to compare with the values it actually reported. A related use case, Decision Tree for Deposits Data (still in implementation and assessment), calculates set variables and filters them to flag potential outliers in the current reporting period. These are supervisor side checks that mirror the validation a bank can run on its own returns before filing. No outcome figures are published.","production",2024,[31],[219],"en",[],[222],{"url":223,"title":224,"publisher":225,"date":226},"https://raw.githubusercontent.com/ombegov/2024-Federal-AI-Use-Case-Inventory/main/data/2024_consolidated_ai_inventory_raw_v2.csv","2024 consolidated AI use case inventory (raw data, version 2)","Office of Management and Budget (GitHub)","2025-01-23",{"level":228,"checkedAt":229},"source-verified","2026-09-26","B","federal-reserve-board-regulatory-data-analysis","board-of-governors-of-the-federal-reserve-system",{"title":234,"useCases":235,"organization":236,"vendors":238,"summary":239,"stage":215,"year":240,"channels":241,"languages":242,"metrics":243,"outcomeDisclosed":209,"sources":244,"verification":246,"grade":230,"id":247,"organizationSlug":248},"National Credit Union Administration: machine learning validation of Call Report data",[202],{"name":237,"anonymized":209,"country":210,"region":211,"industry":212},"National Credit Union Administration",[],"The NCUA, which supervises US federal credit unions, uses a machine learning model developed in house to improve the quality of the quarterly Call Report data that credit unions file. Its output is a list of potential data outliers for each credit union. It has been in operation since February 2023. It is the supervisor side of regulatory reporting, and shows the kind of outlier check a filer can run on its own data before it submits. No outcome figures are published.",2023,[31],[219],[],[245],{"url":223,"title":224,"publisher":225,"date":226},{"level":228,"checkedAt":229},"ncua-call-report-machine-learning-validation",null,0,[],{"low":252,"high":253},230400,1428000,[255,272,290,309,322],{"slug":193,"title":256,"shortTitle":257,"definition":258,"status":9,"industries":259,"functions":260,"patterns":263,"audience":32,"autonomy":33,"adoptionStage":34,"segment":266,"evidenceCount":267,"publicEvidenceCount":267,"organizations":268,"bestGrade":230,"headline":248,"lastVerified":198,"indexable":271},"AI for supervisory exam and information request responses","Exam response assembly","An assistant for the bank's regulatory affairs team that reads a supervisory information request or exam question, retrieves the relevant evidence, policies and prior correspondence, drafts a response for legal and compliance to approve, and tracks every commitment and remediation action through to closure.",[17,18,19,20],[22,261,262],"legal","case-management",[264,28,265,26],"rag-knowledge-assistant","document-processing","second-line",3,[269,270],"U.S. Department of Homeland Security","Federal Emergency Management Agency",true,{"slug":194,"title":273,"shortTitle":274,"definition":275,"status":9,"industries":276,"functions":279,"patterns":281,"audience":35,"autonomy":282,"adoptionStage":283,"segment":35,"evidenceCount":284,"publicEvidenceCount":284,"organizations":285,"bestGrade":230,"headline":248,"lastVerified":198,"indexable":271},"AI for ledger and payment reconciliation","Ledger and payment reconciliation","AI that matches entries across nostro and vostro statements, card and scheme settlement files, the general ledger and suspense accounts, proposes matches and clearing journals, and routes only the genuine breaks to an operator with a plain language explanation.",[17,20,19,277,278,212],"cross-industry","wealth-and-asset-management",[23,280],"operations",[26,27,265],"supervised-agent","early-adopters",4,[286,287,288,289],"Comrade Trustee Services","Ginnie Mae","National Bank of Greece (Cyprus)","World Food Programme",{"slug":195,"title":291,"shortTitle":292,"definition":293,"status":9,"industries":294,"functions":298,"patterns":301,"audience":32,"autonomy":304,"adoptionStage":283,"evidenceCount":267,"publicEvidenceCount":267,"organizations":305,"bestGrade":230,"headline":248,"lastVerified":198,"indexable":271},"Governed text to SQL analytics assistant","Governed SQL analytics","An assistant that turns a business user's plain language question into a query against governed data, runs it under that user's own data permissions and returns the table or chart together with the SQL and the tables used, so routine ad hoc questions no longer queue for the data team.",[277,17,18,295,296,297],"retail-and-ecommerce","technology","pharma-and-life-sciences",[299,300],"analytics-and-reporting","it-and-engineering",[302,303,264],"conversational-agent","code-generation","assist",[306,307,308],"Bayer","LinkedIn","Uber Technologies",{"slug":196,"title":310,"shortTitle":311,"definition":312,"status":9,"industries":313,"functions":314,"patterns":315,"audience":32,"autonomy":33,"adoptionStage":34,"segment":316,"evidenceCount":284,"publicEvidenceCount":284,"organizations":317,"bestGrade":230,"headline":248,"lastVerified":229,"indexable":271},"AI copilot for SAR and STR narrative drafting","SAR and STR drafting","Generative AI that drafts the narrative of a single suspicious activity or suspicious transaction report from the investigation file (who, what, when, where, why and how), with every fact linked to its source record, so the investigator verifies, edits and files instead of starting from a blank page. It works case by case, unlike the periodic data returns of regulatory reporting.",[17,20],[24,262],[28,29,264,26],"middle-office",[318,319,320,321],"Finshark","BMO and Amalgamated Bank","Nexo","Uphold",{"slug":197,"title":323,"shortTitle":324,"definition":325,"status":9,"industries":326,"functions":327,"patterns":329,"audience":32,"autonomy":304,"adoptionStage":283,"segment":40,"evidenceCount":284,"publicEvidenceCount":331,"organizations":332,"bestGrade":230,"headline":248,"lastVerified":198,"indexable":271},"AI regulatory horizon scanning and obligation mapping","Regulatory horizon scanning","An AI system that continuously reads publications from the regulators and standard setters an organization answers to, classifies each item by relevance and urgency, breaks new rules into individual obligations and maps them to the internal policies and controls that meet them, so compliance owners see what changed and where the gaps are.",[277,17,18,20,278,297,212],[22,261,328],"risk-management",[330,265,264,29,26],"classification-and-routing",2,[333,334],"Financial Conduct Authority","Administration for Children and Families",{"indexable":271,"reasons":336},[],[338,344,350,357,364,369,376,382,390,396,403,408,415,421,427,432,438,444,450,456,462,468,474,479,484,490,497,501,507,515,521,527,533,538],{"id":149,"label":339,"issuer":340,"region":166,"url":341,"description":342,"useCases":343,"indexable":271},"EU AI Act","European Union","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":345,"label":346,"issuer":340,"region":166,"url":347,"description":348,"useCases":349,"indexable":271},"gdpr","GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":351,"label":352,"issuer":353,"region":160,"url":354,"description":355,"useCases":356,"indexable":271},"iso-42001","ISO/IEC 42001","ISO and IEC","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":358,"label":359,"issuer":360,"region":211,"url":361,"description":362,"useCases":363,"indexable":271},"nist-ai-rmf","NIST AI Risk Management Framework","NIST","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":150,"label":365,"issuer":340,"region":166,"url":366,"description":367,"useCases":368,"indexable":271},"DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":370,"label":371,"issuer":372,"region":166,"url":373,"description":374,"useCases":375,"indexable":271},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":377,"label":378,"issuer":333,"region":166,"url":379,"description":380,"useCases":381,"indexable":271},"uk-consumer-duty","FCA Consumer Duty","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":383,"label":384,"issuer":385,"region":386,"url":387,"description":388,"useCases":389,"indexable":271},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":153,"label":391,"issuer":392,"region":386,"url":393,"description":394,"useCases":395,"indexable":271},"APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":397,"label":398,"issuer":399,"region":160,"url":400,"description":401,"useCases":402,"indexable":271},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",20,{"id":152,"label":404,"issuer":405,"region":211,"url":406,"description":407,"useCases":402,"indexable":271},"SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":409,"label":410,"issuer":411,"region":166,"url":412,"description":413,"useCases":414,"indexable":271},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":151,"label":416,"issuer":417,"region":160,"url":418,"description":419,"useCases":420,"indexable":271},"FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":422,"label":423,"issuer":340,"region":166,"url":424,"description":425,"useCases":426,"indexable":271},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":428,"label":429,"issuer":340,"region":166,"url":430,"description":431,"useCases":426,"indexable":271},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":154,"label":433,"issuer":434,"region":211,"url":435,"description":436,"useCases":437,"indexable":271},"Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":439,"label":440,"issuer":340,"region":166,"url":441,"description":442,"useCases":443,"indexable":271},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":445,"label":446,"issuer":447,"region":211,"url":448,"description":449,"useCases":443,"indexable":271},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":451,"label":452,"issuer":453,"region":160,"url":454,"description":455,"useCases":443,"indexable":271},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":457,"label":458,"issuer":340,"region":166,"url":459,"description":460,"useCases":461,"indexable":271},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":463,"label":464,"issuer":465,"region":211,"url":466,"description":467,"useCases":461,"indexable":271},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":469,"label":470,"issuer":385,"region":386,"url":471,"description":472,"useCases":473,"indexable":271},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",10,{"id":475,"label":476,"issuer":340,"region":166,"url":477,"description":478,"useCases":473,"indexable":271},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":480,"label":481,"issuer":340,"region":166,"url":482,"description":483,"useCases":473,"indexable":271},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":485,"label":486,"issuer":165,"region":166,"url":487,"description":488,"useCases":489,"indexable":271},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":491,"label":492,"issuer":493,"region":211,"url":494,"description":495,"useCases":496,"indexable":271},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",8,{"id":155,"label":498,"issuer":340,"region":166,"url":499,"description":500,"useCases":496,"indexable":271},"Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":502,"label":503,"issuer":340,"region":166,"url":504,"description":505,"useCases":506,"indexable":271},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",6,{"id":508,"label":509,"issuer":510,"region":511,"url":512,"description":513,"useCases":514,"indexable":271},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",5,{"id":516,"label":517,"issuer":518,"region":166,"url":519,"description":520,"useCases":284,"indexable":271},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":522,"label":523,"issuer":524,"region":166,"url":525,"description":526,"useCases":284,"indexable":271},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":528,"label":529,"issuer":530,"region":386,"url":531,"description":532,"useCases":267,"indexable":271},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":534,"label":535,"issuer":340,"region":166,"url":536,"description":537,"useCases":267,"indexable":271},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":539,"label":540,"issuer":541,"region":211,"url":542,"description":543,"useCases":267,"indexable":271},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598301321]