[{"data":1,"prerenderedAt":647},["ShallowReactive",2],{"uc-requirements-to-test-case-generation":3,"uc-regulations":442},{"useCase":4,"evidence":191,"blitsAiDeployments":335,"benchmarks":336,"indicative":349,"related":352,"indexability":440,"includeUnpublished":197},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":15,"functions":20,"patterns":22,"channels":25,"audience":27,"autonomy":28,"adoptionStage":29,"problem":30,"problemStats":31,"howItWorks":32,"valueDrivers":33,"kpis":37,"indicativeValue":42,"macroEstimates":76,"feasibility":77,"implementation":90,"risk":136,"blitsAi":165,"faq":167,"related":180,"datePublished":185,"dateModified":185,"lastVerified":186,"changelog":187,"slug":190},"AI that turns requirements into user stories, acceptance criteria and test cases","Requirements to test cases","AI test case generation from requirements","AI drafts user stories and test cases from requirements for QA review. In a Tricentis case study, LTIMindtree cut simple test case design from 30 to 10 minutes.","published","AI that reads product requirements, specifications or recorded sessions, checks them for gaps, ambiguity and contradictions, and drafts structured user stories, acceptance criteria and test cases (for example in Gherkin) that QA engineers review, with each item traced back to the requirement it covers.",[7,12,13,14],"requirements engineering assistant","Gherkin and BDD scenario generation","acceptance criteria generator",[16,17,18,19],"technology","government","banking","cross-industry",[21],"it-and-engineering",[23,24],"content-generation","document-processing",[26],"internal-tools","employee-facing","copilot","emerging","Before anyone writes code or a test, someone has to read the requirements. In banking, insurance,\nautomotive and government projects these arrive as long documents, regulatory change notices,\nspreadsheets or workshop recordings, often with hundreds or thousands of individual requirements.\nAnalysts break them into user stories, testers write test cases by hand, and the link between a\nrequirement and the tests that prove it lives in a spreadsheet that goes stale.\n\nThe cost shows up late. Ambiguous or contradictory requirements are found during testing or in\nproduction, coverage gaps are invisible until an audit asks which test proves a control, and\nskilled testers spend their time typing steps rather than thinking about risk. Generative AI is\ngood at reading and restructuring text, which makes this front end of the delivery cycle a natural\nplace to apply it, as long as people stay accountable for what is tested.",[],"1. **Ingest the source.** The assistant reads requirement documents, backlog items, change\n   requests, regulations or transcripts of recorded sessions and walkthroughs.\n2. **Check the requirements.** It flags ambiguity, missing acceptance conditions, duplicates and\n   contradictions, and classifies each requirement (functional or not, safety or security relevant,\n   in or out of scope) for an analyst to confirm.\n3. **Draft stories and criteria.** For accepted requirements it drafts user stories and acceptance\n   criteria in the team's template.\n4. **Draft test cases.** It proposes positive, negative and boundary test cases, in Gherkin or the\n   team's test format, each tagged with the requirement it covers.\n5. **Review and publish.** A QA engineer edits and approves the drafts, which are then pushed to the\n   backlog and test management tool, where a coverage view shows which requirements have no\n   approved test yet.",[34,35,36],"employee-productivity","speed","risk-reduction",[38,39,40,41],"processing-time-reduction","accuracy","productivity-gain","time-saved-per-task",{"referenceOrg":43,"inputs":44,"formula":71,"currency":72,"period":73,"resultLabel":74,"caveat":75},"A bank's delivery organization with 50 QA engineers and analysts",[45,50,57,64],{"key":46,"label":47,"low":48,"high":48,"unit":46,"note":49},"people","QA engineers and analysts",50,"The reference organization.",{"key":51,"label":52,"low":53,"high":54,"unit":55,"note":56},"designShare","Share of their time spent analysing requirements and writing test cases",0.2,0.35,"fraction of working time","Editorial assumption. Replace with your own time split.",{"key":58,"label":59,"low":60,"high":61,"unit":62,"note":63},"timeSaved","Share of that time saved after review",0.25,0.5,"fraction of design time","Conservative against the benchmarks on this page (a Tricentis case study reports 67% to 83% less time per test case in an LTIMindtree pilot of 10 to 12 test cases), because review and correction take time and not all work is test drafting.",{"key":65,"label":66,"low":67,"high":68,"unit":69,"note":70},"loadedCost","Fully loaded cost per person",70000,120000,"USD per person per year","Editorial assumption. Replace with your own blended cost, including contractors.","people * designShare * timeSaved * loadedCost","USD","per year","QA and analysis capacity released","Capacity released, not cash saved, unless headcount or contractor spend actually changes. It leaves out the cost of the tool, integration work, and the value of defects caught earlier.",[],{"complexity":78,"complexityNote":79,"dataPrerequisites":80,"integrations":85},"medium","Drafting a test case from one clear requirement is easy. The work is in messy source documents, domain terms the model does not know, a house style for stories and tests, and a reliable link into the backlog and test management tools so traceability survives change.",[81,82,83,84],"Requirement sources in machine readable form (documents, backlog items, transcripts)","Templates and examples of good user stories, acceptance criteria and test cases","A glossary of domain terms, systems and products","Existing test cases linked to requirements, as examples and to find gaps",[86,87,88,89],"Backlog and requirements tool","Test management tool","Document stores that hold specifications and change requests","Test automation framework, when drafts become automated scripts",{"steps":91,"guardrails":110,"humanInTheLoop":116,"kpisToInstrument":117,"failureModes":123},[92,95,98,101,104,107],{"title":93,"detail":94},"Pick a well documented product area","Start with a system whose requirements are written down and whose testers are willing to compare drafts with their own work, not with the messiest legacy area.",{"title":96,"detail":97},"Teach it your formats","Give the assistant your story and test templates, Gherkin conventions, glossary and a set of approved examples, and version the prompts like code.",{"title":99,"detail":100},"Validate requirements before generating tests","Run the ambiguity, duplicate and contradiction checks first and send findings back to the business analyst. Tests generated from a bad requirement only automate the misunderstanding.",{"title":102,"detail":103},"Make traceability part of the output","Require every story and test case to carry the id of its source requirement, and reject drafts that do not. Build the coverage view from those links.",{"title":105,"detail":106},"Measure against a baseline","Time test design with and without the assistant on comparable requirements, and track how much of each draft reviewers change, not just how fast drafts appear.",{"title":108,"detail":109},"Connect to the tools last","Push approved drafts into the backlog and test management tools only after the quality of drafts is stable, and keep a human approval step on every push.",[111,112,113,114,115],"No generated story or test case enters the backlog or test library without a named reviewer's approval","Every generated item carries the id of the requirement it covers","Confidential specifications stay within approved models and regions, with no training on the organization's data","Findings about requirement quality go back to the requirement owner rather than being silently fixed in the tests","Regulated controls keep tests designed by an accountable person, with AI drafts as input only","Business analysts own the requirements and decide on every flagged ambiguity or contradiction. QA engineers review, edit and approve every story and test case, decide what is in scope and add the risk based and exploratory tests the AI does not think of. A test lead signs off coverage for each release.",[118,119,120,121,122],"Time to design tests per requirement, before and after","Share of each draft changed by the reviewer","Requirements with at least one approved test (coverage)","Requirement defects found before development versus found in testing or production","Defects that escape to production in areas designed with the assistant",[124,127,130,133],{"title":125,"detail":126},"Plausible tests that test nothing","Drafts restate the requirement without meaningful checks or data. Review samples against a checklist and track reviewer edit rates.",{"title":128,"detail":129},"Coverage theatre","Many generated tests inflate coverage numbers while risky paths stay untested. Measure coverage by requirement and risk, not by test count.",{"title":131,"detail":132},"Invented requirements","The model fills gaps with assumptions that look like requirements. Flag assumptions separately and send them to the requirement owner.",{"title":134,"detail":135},"Traceability that breaks on change","Requirements change and generated tests are not updated. Regenerate or flag linked tests whenever a requirement changes.",{"euAiAct":137,"regulations":140,"guidance":145,"controls":158,"incidents":164},{"tier":138,"basis":139},"minimal","An internal assistant that drafts requirements artifacts and test cases for engineers is not listed in Annex III and does not interact with the public, so no specific obligations apply beyond AI literacy (Article 4). The system under test may itself fall under the Act.",[141,142,143,144],"eu-ai-act","dora","iso-42001","nist-ai-rmf",[146,152],{"title":147,"issuer":148,"region":149,"url":150,"note":151},"Article 4, AI literacy","European Union","europe","https://artificialintelligenceact.eu/article/4/","Providers and deployers must take measures on the AI literacy of staff who use AI systems (the amended wording shown on this page asks them to support it rather than ensure a sufficient level). Here that means training analysts and testers on the limits of generated drafts.",{"title":153,"issuer":154,"region":155,"url":156,"note":157},"SP 800-218A, Secure Software Development Practices for Generative AI and Dual-Use Foundation Models","NIST","north-america","https://csrc.nist.gov/pubs/sp/800/218/a/final","NIST's SSDF community profile (July 2024) that adds secure development practices for producers of AI models, producers of AI systems that use them, and acquirers of those systems. A reference for the controls around an AI tool that feeds the delivery pipeline.",[159,160,161,162,163],"Approved tool with contractual data terms and no training on the organization's specifications","Mandatory human approval recorded against each generated test case","Traceability matrix from requirement to approved test, kept current on change","Periodic sample review of generated tests by the test lead","Change control on prompts and templates",[],{"howToBuild":166},"On Blits.ai this is an **agentic workflow** built around an **AI agent** with **structured\noutput**: the workflow reads requirement documents from the **knowledge base** (PDF, Word,\nPowerPoint, spreadsheets and Markdown are ingested and retrieved with hybrid search), runs a\nvalidation step that lists ambiguities and contradictions, and then drafts user stories,\nacceptance criteria and Gherkin test cases as structured records that each carry the source\nrequirement id. **Human in the loop confirmation**, set so that every push needs approval, lets a\nQA engineer approve or reject each batch before **custom functions** or connected **MCP** tools\nwrite it to the backlog or test management system.\n\n**Prompt versioning** keeps the story and test templates under change control, **execution\ntracing** shows how each draft was produced, **PII masking** keeps personal data out of prompts,\nand **guardrails** check inputs and outputs. The platform is model agnostic, with EU and UAE data\nresidency. For teams that build conversational agents, generated test cases can be imported as JSON into Blits.ai\n**test suites**, which run them against agents with deterministic or LLM based grading.",[168,171,174,177],{"question":169,"answer":170},"How much time does AI save on writing test cases?","The published results come from small pilots. A Tricentis case study of an LTIMindtree pilot covering 10 to 12 test cases reports low complexity test cases falling from 30 minutes to 10 and high complexity ones from 2 hours to 20 to 30 minutes. Review time and edits by testers should be counted before scaling these numbers.",{"question":172,"answer":173},"Can it check the requirements themselves, not just write tests?","Yes, and that is often where the value starts. Continental Automotive built a proof of concept that uses generative AI to scan requirement documents of up to 30,000 requirements, categorize them and compare them with its feature catalogue, and NASA's verification and validation programme is building tools that assess requirement quality and traceability for analysts to review.",{"question":175,"answer":176},"How is this different from an AI coding assistant?","A coding assistant works on code in the developer's editor and drafts unit tests for that code. This use case works upstream on requirements and produces stories, acceptance criteria and functional test cases for QA, traced to the requirement, before or alongside development.",{"question":178,"answer":179},"Should generated test cases go straight into the test library?","No. Treat them as drafts: a named QA engineer reviews and approves each one, and every test keeps a link to its requirement so coverage and change impact stay visible.",[181,182,183,184],"developer-coding-assistant","legacy-code-modernization","synthetic-test-data-generation","continuous-controls-testing","2026-09-27","2026-09-26",[188],{"date":185,"note":189},"First published","requirements-to-test-case-generation",[192,220,240,283,313],{"title":193,"useCases":194,"organization":195,"vendors":199,"summary":200,"stage":201,"year":202,"channels":203,"languages":204,"metrics":206,"outcomeDisclosed":197,"sources":207,"verification":215,"grade":217,"id":218,"organizationSlug":219},"NASA IV&V: generative AI review of requirements quality, traceability and test artifacts (planned)",[190],{"name":196,"anonymized":197,"country":198,"region":155,"industry":17},"National Aeronautics and Space Administration",false,"US",[],"NASA's Independent Verification and Validation programme at Goddard reports two related pre deployment tools. One drafts analysis of software requirements (quality attributes, decomposition of functionality, upward and backward traceability) and the other assesses test cases, procedures and steps for completeness and consistency. Analysts filter the findings by severity, give feedback and turn accepted findings into draft issues. Development used synthetic or open data; the move to beta and production on premises with real mission data was planned from fiscal year 2026.","announced",2025,[26],[205],"en",[],[208,212],{"url":209,"title":210,"publisher":211},"https://github.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory","2025 Federal Agency AI Use Case Inventory","Office of Management and Budget (GitHub)",{"url":213,"title":214,"publisher":211},"https://raw.githubusercontent.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory/main/Data/2025_individually_reported_AI_use_cases.csv","2025 individually reported AI use cases (entries NASA-908, IV&V Requirements Quality & Traceability Analysis, and NASA-910, IV&V Test Analysis)",{"level":216,"checkedAt":186},"source-verified","B","nasa-ivv-requirements-and-test-analysis",null,{"title":221,"useCases":222,"organization":223,"vendors":225,"summary":229,"stage":201,"year":202,"channels":230,"languages":231,"metrics":232,"outcomeDisclosed":197,"sources":233,"verification":237,"grade":217,"id":238,"organizationSlug":239},"US Department of Veterans Affairs: test case generation for Salesforce CRM apps with VA GPT (planned)",[190],{"name":224,"anonymized":197,"country":198,"region":155,"industry":17},"US Department of Veterans Affairs, Office of Information and Technology",[226],{"name":227,"role":228},"Provar Manager","platform","The VA Office of Information and Technology reports a pre deployment generative AI use case that integrates Provar Manager with VA GPT to generate test cases automatically for the Salesforce CRM applications that support Department of Veterans Affairs services. The stated aim is less manual effort in writing tests and a closer match between requirements and deliverables. No outcome is published.",[26],[205],[],[234,235],{"url":209,"title":210,"publisher":211},{"url":213,"title":236,"publisher":211},"2025 individually reported AI use cases (entry VA-25-5958, Integration of Provar Manager with VA GPT)",{"level":216,"checkedAt":186},"va-provar-test-case-generation","u-s-department-of-veterans-affairs",{"title":241,"useCases":242,"organization":243,"vendors":247,"summary":250,"stage":251,"year":252,"channels":253,"languages":254,"metrics":255,"outcomeDisclosed":271,"sources":272,"verification":280,"grade":281,"id":282,"organizationSlug":219},"LTIMindtree: natural language test case creation pushed into test management",[190],{"name":244,"anonymized":197,"country":245,"region":246,"industry":16},"LTIMindtree","IN","asia-pacific",[248],{"name":249,"role":228},"Tricentis","LTIMindtree (LTM), a technology services company and Tricentis Tosca implementation partner, piloted Tricentis Agentic Test Creation, in which testers describe the test they need in plain English and the system drafts the test case and pushes it straight into the qTest test management tool, replacing manual spreadsheet uploads. The pilot ran in an SAP GUI staging environment; its first phase covered 10 to 12 test cases across three complexity tiers, with several testers running identical cases to check consistency. Separately, Google Cloud lists an LTM Video Intelligence Agent that converts recorded videos into BDD test cases, without published results.","pilot",2026,[26],[205],[256,265],{"kpi":38,"value":257,"unit":258,"qualifier":259,"period":260,"baseline":261,"claimant":262,"quote":263,"sourceUrl":264},67,"percent","exact","Pilot, time to create a low complexity test case","30 minutes per test case written manually","vendor","Low complexity test cases dropped from 30 minutes to 10 minutes—a 67% reduction","https://www.tricentis.com/case-studies/ltm-accelerates-testing-transformation-agentic-ai",{"kpi":38,"value":266,"unit":258,"qualifier":267,"period":268,"baseline":269,"claimant":262,"quote":270,"sourceUrl":264},83,"up-to","Pilot, time to create a high complexity test case","2 hours per test case written manually","High complexity test cases fell from 2 hours to 20-30 minutes—up to 83% time savings",true,[273,276],{"url":264,"title":274,"publisher":249,"date":275},"LTM accelerates testing transformation with Tricentis agentic AI","2026-05-20",{"url":277,"title":278,"publisher":279},"https://cloud.google.com/transform/101-real-world-generative-ai-use-cases-from-industry-leaders","Real-world gen AI use cases from the world's leading organizations","Google Cloud",{"level":216,"checkedAt":186},"C","ltimindtree-agentic-test-case-creation",{"title":284,"useCases":285,"organization":286,"vendors":288,"summary":292,"stage":293,"year":202,"channels":294,"languages":295,"metrics":296,"outcomeDisclosed":271,"sources":307,"verification":311,"grade":281,"id":312,"organizationSlug":219},"BrowserStack: test case generation from user context in its test platform",[190],{"name":287,"anonymized":197,"country":245,"region":246,"industry":16},"BrowserStack",[289],{"name":290,"role":291},"Microsoft","model-provider","BrowserStack, a cloud testing platform, added Azure OpenAI based features that recommend and generate test cases from context the user provides, convert them into automated scripts and repair tests when the user interface changes. The figures on the page are product claims for the platform's customers in general, not a measured result at one named customer, and no baseline is given.","production",[26],[205],[297,302],{"kpi":38,"value":298,"unit":258,"qualifier":267,"period":299,"claimant":262,"quote":300,"sourceUrl":301},70,"QA cycle time, product claim across customers","The platform intelligently creates and maintains test cases, converting them into automated scripts, reducing QA cycle time by up to 70%.","https://www.microsoft.com/en-in/aifirstmovers/browserstack",{"kpi":39,"value":303,"unit":258,"qualifier":304,"period":305,"claimant":262,"quote":306,"sourceUrl":301},90,"at-least","Coverage accuracy of recommended test cases, product claim","Leveraging Azure OpenAI, BrowserStack platform recommends test cases based on user-provided context, ensuring comprehensive coverage with 90%+ accuracy.",[308],{"url":301,"title":309,"publisher":310},"Browserstack: Enhance testing with AI-driven productivity","Microsoft India",{"level":216,"checkedAt":186},"browserstack-ai-test-case-generation",{"title":314,"useCases":315,"organization":316,"vendors":320,"summary":325,"stage":251,"year":202,"channels":326,"languages":327,"metrics":328,"outcomeDisclosed":197,"sources":329,"verification":333,"grade":281,"id":334,"organizationSlug":219},"Continental Automotive: AI based requirements engineering for customer requirement documents",[190],{"name":317,"anonymized":197,"country":318,"region":149,"industry":319},"Continental AG","DE","automotive",[321,322],{"name":290,"role":228},{"name":323,"role":324},"NTT DATA","integrator","Continental's Automotive division receives customer requirement documents that can run to hundreds of pages and up to 30,000 individual requirements, which engineers used to read, categorize as functional or non functional, check for safety and security relevance and check for contradictions and duplicates by hand. With Microsoft and NTT DATA it built a generative AI solution on Azure AI that scans the document, finds relevant sections and keywords, categorizes requirements and compares them with a catalogue of generic Continental features. The proof of concept was built in three months and the company plans to scale it; no measured saving is published.",[26],[205],[],[330],{"url":331,"title":332,"publisher":290},"https://www.microsoft.com/en/customers/story/22437-continental-ag-azure-ai-services","Continental relies on Microsoft Azure AI: A game changer in R&D requirements management",{"level":216,"checkedAt":186},"continental-ai-requirements-engineering",0,[337,344],{"kpi":38,"label":338,"unit":258,"aggregate":271,"higherIsBetter":271,"n":339,"nUpTo":339,"median":257,"min":257,"max":257,"byClaimant":340,"vendorOnly":271,"points":341},"Cycle time reduction",1,{"organization":335,"vendor":339,"regulator":335,"independent":335},[342,343],{"evidenceId":312,"organization":287,"value":298,"qualifier":267,"claimant":262,"grade":281,"pooled":197},{"evidenceId":282,"organization":244,"value":257,"qualifier":259,"claimant":262,"grade":281,"pooled":271},{"kpi":39,"label":345,"unit":258,"aggregate":271,"higherIsBetter":271,"n":339,"nUpTo":335,"median":303,"min":303,"max":303,"byClaimant":346,"vendorOnly":271,"points":347},"Accuracy",{"organization":335,"vendor":339,"regulator":335,"independent":335},[348],{"evidenceId":312,"organization":287,"value":303,"qualifier":304,"claimant":262,"grade":281,"pooled":271},{"low":350,"high":351},175000,1050000,[353,377,398,423],{"slug":181,"title":354,"shortTitle":355,"definition":356,"status":9,"industries":357,"functions":360,"patterns":361,"audience":27,"autonomy":28,"adoptionStage":363,"evidenceCount":364,"publicEvidenceCount":364,"organizations":365,"bestGrade":217,"headline":372,"lastVerified":185,"indexable":271},"AI coding assistant for software developers","Developer coding assistant","An AI assistant in the developer's IDE and code review flow that completes and generates code, explains unfamiliar modules, drafts unit tests and reviews pull requests for common defects, while generated code goes through the same review, testing and change controls as any other code.",[19,18,358,16,359],"capital-markets","professional-services",[21],[362],"code-generation","mainstream",6,[366,367,368,369,370,371],"Accenture","ANZ","Bank of America","Citi","CME Group","Meta",{"kpi":40,"label":373,"unit":258,"n":374,"nUpTo":335,"kind":375,"value":376,"qualifier":259,"claimant":219,"organization":219,"vendorReported":197},"Productivity gain",3,"median",20,{"slug":182,"title":378,"shortTitle":379,"definition":380,"status":9,"industries":381,"functions":382,"patterns":383,"audience":27,"autonomy":28,"adoptionStage":386,"evidenceCount":364,"publicEvidenceCount":387,"organizations":388,"bestGrade":217,"headline":394,"lastVerified":185,"indexable":271},"AI for legacy code modernization","Legacy code modernization","AI that reads legacy code such as COBOL, PL/I or old Java, explains what each program does, maps its data flows and dependencies, drafts the equivalent modern code or specification, and generates the regression tests needed to prove the new system behaves like the old one.",[19,18,358,319,16],[21],[362,384,385],"summarization","agentic-workflow","early-adopters",5,[389,390,391,392,393],"Airbnb","Amazon","Google","Morgan Stanley","Toyota Motor Europe",{"kpi":38,"label":338,"unit":258,"n":339,"nUpTo":335,"kind":395,"value":48,"qualifier":396,"claimant":397,"organization":391,"vendorReported":197},"reported","approximately","organization",{"slug":183,"title":399,"shortTitle":400,"definition":401,"status":9,"industries":402,"functions":405,"patterns":407,"audience":409,"autonomy":410,"adoptionStage":386,"evidenceCount":411,"publicEvidenceCount":412,"organizations":413,"bestGrade":217,"headline":421,"lastVerified":186,"indexable":271},"AI for synthetic test data generation","Synthetic test data generation","AI that generates realistic synthetic datasets, such as customers, transactions, documents and conversations, which keep the structure and statistical properties of production data without containing real personal data, so teams can test software, train and validate models and run demos safely.",[19,18,403,404],"healthcare","insurance",[21,406],"analytics-and-reporting",[408,23],"synthetic-data-generation","back-office","supervised-agent",8,7,[414,415,416,417,418,419,420],"Boomi","Financial Conduct Authority","Internal Revenue Service","JPMorgan Chase","Kin Insurance","Merkur Versicherung AG","Patterson Dental",{"kpi":38,"label":338,"unit":258,"n":339,"nUpTo":335,"kind":395,"value":422,"qualifier":259,"claimant":262,"organization":420,"vendorReported":271},75,{"slug":184,"title":424,"shortTitle":425,"definition":426,"status":9,"industries":427,"functions":428,"patterns":432,"audience":409,"autonomy":410,"adoptionStage":29,"segment":435,"evidenceCount":374,"publicEvidenceCount":374,"organizations":436,"bestGrade":217,"headline":219,"lastVerified":185,"indexable":271},"AI for continuous controls testing and control self assessment","Continuous controls testing","AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.",[19,18,404,358,17],[429,430,431],"risk-management","regulatory-compliance","operations",[385,24,433,434],"anomaly-detection","classification-and-routing","second-line",[437,438,439],"Federal Deposit Insurance Corporation","U.S. Department of the Interior","Pension Benefit Guaranty Corporation",{"indexable":271,"reasons":441},[],[443,448,454,461,465,470,477,483,490,497,503,509,516,523,529,534,541,547,553,559,565,571,577,582,587,594,600,605,610,617,624,630,636,641],{"id":141,"label":444,"issuer":148,"region":149,"url":445,"description":446,"useCases":447,"indexable":271},"EU AI Act","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":449,"label":450,"issuer":148,"region":149,"url":451,"description":452,"useCases":453,"indexable":271},"gdpr","GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":143,"label":455,"issuer":456,"region":457,"url":458,"description":459,"useCases":460,"indexable":271},"ISO/IEC 42001","ISO and IEC","global","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":144,"label":462,"issuer":154,"region":155,"url":463,"description":464,"useCases":266,"indexable":271},"NIST AI Risk Management Framework","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",{"id":142,"label":466,"issuer":148,"region":149,"url":467,"description":468,"useCases":469,"indexable":271},"DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":471,"label":472,"issuer":473,"region":149,"url":474,"description":475,"useCases":476,"indexable":271},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":478,"label":479,"issuer":415,"region":149,"url":480,"description":481,"useCases":482,"indexable":271},"uk-consumer-duty","FCA Consumer Duty","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":484,"label":485,"issuer":486,"region":246,"url":487,"description":488,"useCases":489,"indexable":271},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":491,"label":492,"issuer":493,"region":246,"url":494,"description":495,"useCases":496,"indexable":271},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":498,"label":499,"issuer":500,"region":457,"url":501,"description":502,"useCases":376,"indexable":271},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",{"id":504,"label":505,"issuer":506,"region":155,"url":507,"description":508,"useCases":376,"indexable":271},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":510,"label":511,"issuer":512,"region":149,"url":513,"description":514,"useCases":515,"indexable":271},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":517,"label":518,"issuer":519,"region":457,"url":520,"description":521,"useCases":522,"indexable":271},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":524,"label":525,"issuer":148,"region":149,"url":526,"description":527,"useCases":528,"indexable":271},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":530,"label":531,"issuer":148,"region":149,"url":532,"description":533,"useCases":528,"indexable":271},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":535,"label":536,"issuer":537,"region":155,"url":538,"description":539,"useCases":540,"indexable":271},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":542,"label":543,"issuer":148,"region":149,"url":544,"description":545,"useCases":546,"indexable":271},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":548,"label":549,"issuer":550,"region":155,"url":551,"description":552,"useCases":546,"indexable":271},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":554,"label":555,"issuer":556,"region":457,"url":557,"description":558,"useCases":546,"indexable":271},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":560,"label":561,"issuer":148,"region":149,"url":562,"description":563,"useCases":564,"indexable":271},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":566,"label":567,"issuer":568,"region":155,"url":569,"description":570,"useCases":564,"indexable":271},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":572,"label":573,"issuer":486,"region":246,"url":574,"description":575,"useCases":576,"indexable":271},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",10,{"id":578,"label":579,"issuer":148,"region":149,"url":580,"description":581,"useCases":576,"indexable":271},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":583,"label":584,"issuer":148,"region":149,"url":585,"description":586,"useCases":576,"indexable":271},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":588,"label":589,"issuer":590,"region":149,"url":591,"description":592,"useCases":593,"indexable":271},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":595,"label":596,"issuer":597,"region":155,"url":598,"description":599,"useCases":411,"indexable":271},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",{"id":601,"label":602,"issuer":148,"region":149,"url":603,"description":604,"useCases":411,"indexable":271},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":606,"label":607,"issuer":148,"region":149,"url":608,"description":609,"useCases":364,"indexable":271},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",{"id":611,"label":612,"issuer":613,"region":614,"url":615,"description":616,"useCases":387,"indexable":271},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":618,"label":619,"issuer":620,"region":149,"url":621,"description":622,"useCases":623,"indexable":271},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",4,{"id":625,"label":626,"issuer":627,"region":149,"url":628,"description":629,"useCases":623,"indexable":271},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":631,"label":632,"issuer":633,"region":246,"url":634,"description":635,"useCases":374,"indexable":271},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":637,"label":638,"issuer":148,"region":149,"url":639,"description":640,"useCases":374,"indexable":271},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":642,"label":643,"issuer":644,"region":155,"url":645,"description":646,"useCases":374,"indexable":271},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598306635]