[{"data":1,"prerenderedAt":585},["ShallowReactive",2],{"uc-supervisory-exam-response-assembly":3,"uc-regulations":378},{"useCase":4,"evidence":205,"blitsAiDeployments":279,"benchmarks":280,"indicative":281,"related":284,"indexability":376,"includeUnpublished":211},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":16,"functions":21,"patterns":25,"channels":30,"audience":33,"autonomy":34,"adoptionStage":35,"segment":36,"problem":37,"problemStats":38,"howItWorks":39,"valueDrivers":40,"kpis":45,"indicativeValue":50,"macroEstimates":85,"feasibility":86,"implementation":99,"risk":142,"blitsAi":181,"faq":183,"related":193,"datePublished":200,"dateModified":200,"lastVerified":200,"changelog":201,"slug":204},"AI for supervisory exam and information request responses","Exam response assembly","AI for regulatory exam and information requests","AI drafts cited answers to supervisory exam questions and tracks each commitment. The US DHS already uses generative AI to summarise incoming information requests.","published","An assistant for the bank's regulatory affairs team that reads a supervisory information request or exam question, retrieves the relevant evidence, policies and prior correspondence, drafts a response for legal and compliance to approve, and tracks every commitment and remediation action through to closure.",[12,13,14,15],"regulatory exam response assistant","supervisory request response AI","regulator information request management","regulatory commitment tracking",[17,18,19,20],"banking","insurance","capital-markets","payments",[22,23,24],"regulatory-compliance","legal","case-management",[26,27,28,29],"rag-knowledge-assistant","content-generation","document-processing","agentic-workflow",[31,32],"internal-tools","email","employee-facing","copilot","emerging","second-line","Supervisors send banks a steady flow of information requests, exam questions, thematic review\nquestionnaires and follow up letters, each with a deadline. Answering them means working out\nwhat is really being asked, finding the evidence across policies, board papers, test results and\nearlier correspondence, getting contributions from several teams and making sure the answer is\nconsistent with everything the bank has told the supervisor before.\n\nUnder time pressure, answers get assembled by email and spreadsheet, evidence is sent without a\nrecord of exactly which version went, and commitments made in a response (\"we will complete the\nreview by Q3\") are tracked by memory. Accuracy is an obligation in its own right: the FCA's SUP\n15.6, for example, requires information given to the regulator to be factually accurate or, for\nestimates and judgements, fairly and properly based after appropriate enquiries.",[],"1. **Log and interpret the request.** Each request is logged with its deadline; the assistant\n   splits it into individual questions and states what each one asks for.\n2. **Retrieve evidence.** Retrieval over policies, procedures, committee papers, test results and\n   prior regulatory correspondence returns candidate evidence and earlier answers on the topic.\n3. **Assign contributors.** Questions that need new input go to named owners with the deadline.\n4. **Draft the response.** The assistant drafts answers from the retrieved evidence, cites each\n   document and flags statements that differ from earlier submissions.\n5. **Review and sign.** Subject matter experts, then legal and compliance, edit and approve the\n   final response. Nothing leaves without sign off.\n6. **Track commitments.** Every commitment in the sent response becomes a tracked action with an\n   owner and date, and the full package (request, evidence, response) is archived.",[41,42,43,44],"compliance","speed","employee-productivity","risk-reduction",[46,47,48,49],"response-time-reduction","processing-time-reduction","time-saved-per-task","accuracy",{"referenceOrg":51,"inputs":52,"formula":80,"currency":81,"period":82,"resultLabel":83,"caveat":84},"A mid sized bank answering 400 supervisory questions a year",[53,59,66,73],{"key":54,"label":55,"low":56,"high":56,"unit":57,"note":58},"questions","Supervisory questions and information request items per year",400,"questions per year","Editorial assumption for the reference bank, not a sourced figure. Replace with your own request log.",{"key":60,"label":61,"low":62,"high":63,"unit":64,"note":65},"hoursPerQuestion","Staff hours per question (search, drafting, review)",6,12,"hours per question","Editorial assumption across all contributors. Replace with your own records.",{"key":67,"label":68,"low":69,"high":70,"unit":71,"note":72},"timeSaved","Share of search and drafting time saved",0.15,0.3,"fraction of time","Editorial assumption. No public measured benchmark was found; review and sign off time is not reduced.",{"key":74,"label":75,"low":76,"high":77,"unit":78,"note":79},"hourlyCost","Fully loaded cost of compliance and specialist staff",90,150,"USD per hour","Editorial assumption, replace with your own.","questions * hoursPerQuestion * timeSaved * hourlyCost","USD","per year","Staff time released from supervisory responses","Time only. It leaves out the value of consistent answers and fewer missed commitments, which this estimate does not price, and the cost of building the evidence repository.",[],{"complexity":87,"complexityNote":88,"dataPrerequisites":89,"integrations":94},"medium","The technology is standard retrieval and drafting. The difficulty is confidentiality: supervisory correspondence is often confidential supervisory information, so hosting, access control and model provider terms must be settled first.",[90,91,92,93],"A repository of prior regulatory correspondence and submissions, with versions","Current policies, procedures, committee papers and test results with owners","A request log with deadlines and owners","Rules on confidential supervisory information from the relevant supervisors",[95,96,97,98],"Document management and regulatory correspondence systems","Governance, risk and compliance platform for issues and actions","Email and secure regulator portals (intake only, sending stays manual)","Workflow and task tools for contributors and commitments",{"steps":100,"guardrails":116,"humanInTheLoop":122,"kpisToInstrument":123,"failureModes":129},[101,104,107,110,113],{"title":102,"detail":103},"Settle confidentiality first","Classify which correspondence is confidential supervisory information, check what the supervisor allows, and choose hosting and model providers accordingly before loading data.",{"title":105,"detail":106},"Build the correspondence memory","Index prior requests, responses and evidence with dates and versions, so the assistant can show what the bank has already said on a topic.",{"title":108,"detail":109},"Start with interpretation and retrieval","Use the assistant to split requests into questions and find evidence and prior answers. Measure how often experts accept its evidence before adding drafting.",{"title":111,"detail":112},"Draft with citations and consistency checks","Every drafted sentence cites a document; statements that differ from prior submissions are highlighted for the reviewer.",{"title":114,"detail":115},"Close the loop on commitments","Extract commitments from sent responses into the action tracker and report overdue items to senior management.",[117,118,119,120,121],"Legal and compliance sign every response; the assistant cannot send anything","Drafts cite the evidence they rely on; unsupported statements are flagged","Confidential supervisory information stays in approved hosting with strict access control","Full record of each request, evidence sent, response version and approver","Consistency check against earlier submissions before sign off","Subject matter experts own the content, legal and compliance approve every response, and the head of regulatory affairs owns the relationship and the commitment log. The assistant prepares, drafts and tracks.",[124,125,126,127,128],"Time from request receipt to approved response","Share of responses sent on or before the deadline","Reviewer edits per drafted answer and evidence acceptance rate","Commitments tracked, closed on time and overdue","Inconsistencies with prior submissions caught before sending",[130,133,136,139],{"title":131,"detail":132},"Confidential information in the wrong place","Supervisory material is sent to a model provider or tool that the supervisor has not accepted. Settle hosting and terms first and block uploads elsewhere.",{"title":134,"detail":135},"Confident answers from stale evidence","The assistant cites a superseded policy or old test result. Index versions and show dates in every citation.",{"title":137,"detail":138},"Commitments lost after sending","The response is filed and the promise is forgotten. Extract commitments automatically and review them in governance.",{"title":140,"detail":141},"Over polished responses","Fluent drafts hide that the bank does not actually know the answer. Reviewers must confirm facts, not just wording.",{"euAiAct":143,"regulations":146,"guidance":152,"controls":174,"incidents":180},{"tier":144,"basis":145},"minimal","Drafting regulatory correspondence for human approval is not an Annex III use. The main risks are confidentiality and accuracy, which are handled by supervisory information rules, data protection law and internal controls.",[147,148,149,150,151],"eu-ai-act","gdpr","dora","iso-42001","nist-ai-rmf",[153,159,165,169],{"title":154,"issuer":155,"region":156,"url":157,"note":158},"12 CFR Part 261, Rules Regarding Availability of Information","Board of Governors of the Federal Reserve System","north-america","https://www.ecfr.gov/current/title-12/chapter-II/subchapter-A/part-261","Example of rules that restrict disclosure of confidential supervisory information, which govern where exam material may be processed.",{"title":160,"issuer":161,"region":162,"url":163,"note":164},"PRIN 2.1, The Principles","Financial Conduct Authority","europe","https://www.handbook.fca.org.uk/handbook/PRIN/2/1.html","Principle 11 requires firms to deal with regulators in an open and cooperative way and to disclose anything the regulator would reasonably expect notice of.",{"title":166,"issuer":161,"region":162,"url":167,"note":168},"SUP 15.6, Inaccurate, false or misleading information","https://www.handbook.fca.org.uk/handbook/SUP/15/6.html","Information given to the FCA must be factually accurate or, for estimates and judgements, fairly and properly based after appropriate enquiries; a firm must notify the FCA if information it gave may have been false, misleading, incomplete or inaccurate.",{"title":170,"issuer":171,"region":156,"url":172,"note":173},"Artificial Intelligence Risk Management Framework, Generative Artificial Intelligence Profile","NIST","https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence","Guidance on confabulation and information security risks that apply to drafting assistants handling sensitive material.",[175,176,177,178,179],"Classification and access control for confidential supervisory information","Approved hosting and model provider terms documented for supervisory material","Sign off workflow with recorded approvers for every response","Commitment register reviewed by senior management","Archive of each request, evidence package and final response",[],{"howToBuild":182},"On Blits.ai this is an **AI agent** over a **knowledge base** of policies, committee papers,\ntest results and prior regulatory correspondence, with version control and hybrid retrieval so\nexact prior wording is found. Incoming requests can arrive through the **email channel** or be\nuploaded (PDF, Word, Excel or Outlook .msg), and the agent returns **structured output**: the\nquestions, the evidence found with citations and a draft answer.\n\nAn **agentic workflow** handles multi part requests and extracts commitments into the bank's\ntask system through **custom functions**, with **human in the loop approval** before any draft\nis released to reviewers. **Tenant isolation**, role based access, **PII masking** and EU or UAE\ndata residency keep confidential material in approved boundaries, and because the platform is\nmodel agnostic the bank can pick a model and hosting that its supervisors accept.",[184,187,190],{"question":185,"answer":186},"Can we put supervisory correspondence into a generative AI tool?","Only within the rules on confidential supervisory information that apply to you and with hosting, access control and model provider terms your supervisors would accept. Settle this before loading any correspondence.",{"question":188,"answer":189},"Who uses AI for this today?","We found no named bank deployment in public sources. The public examples on this page come from US government bodies: the Executive Secretariat of the Department of Homeland Security has used generative AI since December 2024 to summarise incoming correspondence and information requests in its tracking system, with drafting of responses named as a future capability, and two related DHS and FEMA tools are reported as pre deployment.",{"question":191,"answer":192},"What delivers the most value first?","In our view, retrieval of prior answers and evidence, and tracking of commitments. They target inconsistent answers and missed promises, the failure modes described above, while drafting speed matters mainly for tight deadlines. No public measured comparison exists yet.",[194,195,196,197,198,199],"regulatory-report-assembly","policy-drafting-and-gap-analysis","continuous-controls-testing","internal-audit-copilot","regulatory-horizon-scanning","complaints-root-cause-analysis","2026-09-27",[202],{"date":200,"note":203},"First published","supervisory-exam-response-assembly",[206,242,257],{"title":207,"useCases":208,"organization":209,"vendors":214,"summary":218,"stage":219,"year":220,"channels":221,"languages":222,"metrics":224,"outcomeDisclosed":211,"sources":225,"verification":237,"grade":239,"id":240,"organizationSlug":241},"FEMA: generative AI over spend plan data to answer data calls and information requests (planned)",[204],{"name":210,"anonymized":211,"country":212,"region":156,"industry":213},"Federal Emergency Management Agency",false,"US","government",[215],{"name":216,"role":217},"Microsoft","model-provider","FEMA reports a pre deployment tool that lets staff ask questions of spend plan and actual execution data in common language, using Azure OpenAI inside the agency's system boundary, so they can give rapid responses to data calls and requests for information and show leadership where budget was planned and spent. It illustrates the evidence retrieval step of answering an oversight request from governed internal data. Not yet live; no results published.","announced",2025,[31],[223],"en",[],[226,230,233],{"url":227,"title":228,"publisher":229},"https://github.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory","2025 Federal Agency AI Use Case Inventory","Office of Management and Budget (GitHub)",{"url":231,"title":232,"publisher":229},"https://raw.githubusercontent.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory/main/Data/2025_individually_reported_AI_use_cases.csv","2025 individually reported AI use cases (entry DHS-2709, Spend Plan Analysis GPT)",{"url":234,"title":235,"publisher":236},"https://www.dhs.gov/ai/use-case-inventory/fema","DHS AI Use Case Inventory, FEMA (entry DHS-2709, Spend Plan Analysis GPT)","U.S. Department of Homeland Security",{"level":238,"checkedAt":200},"source-verified","B","fema-spend-plan-data-call-assistant",null,{"title":243,"useCases":244,"organization":245,"vendors":246,"summary":247,"stage":219,"year":220,"channels":248,"languages":249,"metrics":250,"outcomeDisclosed":211,"sources":251,"verification":255,"grade":239,"id":256,"organizationSlug":241},"DHS: turning statements in Congressional reports into trackable tasks (planned)",[204],{"name":236,"anonymized":211,"country":212,"region":156,"industry":213},[],"The DHS management directorate reports a pre deployment use case that converts plain text statements in Congressional reports into machine readable tasks that can be managed in Outlook, Jira or other project tracking software, and turns scanned financial tables into structured data. It corresponds to the commitment tracking step of oversight work: statements an overseer writes down become tasks that can be managed in project tracking software. Not yet live; no results published.",[31],[223],[],[252,253],{"url":227,"title":228,"publisher":229},{"url":231,"title":254,"publisher":229},"2025 individually reported AI use cases (entry DHS-2342, JES and Appropriations Insight)",{"level":238,"checkedAt":200},"dhs-congressional-report-task-extraction",{"title":258,"useCases":259,"organization":260,"vendors":261,"summary":264,"stage":265,"year":266,"channels":267,"languages":268,"metrics":269,"outcomeDisclosed":211,"sources":270,"verification":277,"grade":239,"id":278,"organizationSlug":241},"DHS Executive Secretariat: generative AI summaries of incoming inquiries and information requests",[204],{"name":236,"anonymized":211,"country":212,"region":156,"industry":213},[262],{"name":216,"role":263},"platform","Since December 2024 the DHS Executive Secretariat has used generative AI to summarise incoming letters when a new work package is created in its correspondence tracking system, so analysts can act on and assign requests faster; the summaries flow into the system that tracks correspondence and information requests. The department states a future aim of drafting responses to those requests. It is the intake and tracking half of answering an external request, run by a government body rather than a bank.","production",2024,[31],[223],[],[271,272,274],{"url":227,"title":228,"publisher":229},{"url":231,"title":273,"publisher":229},"2025 individually reported AI use cases (entry DHS-2453, ESEC Inquiry (STORM) Summarization)",{"url":275,"title":276,"publisher":236},"https://www.dhs.gov/ai/use-case-inventory/mgmt","DHS AI Use Case Inventory, Management Directorate (entry DHS-2453, ESEC Inquiry (STORM) Summarization)",{"level":238,"checkedAt":200},"dhs-executive-secretariat-inquiry-summarization",0,[],{"low":282,"high":283},32400,216000,[285,301,316,330,352,363],{"slug":194,"title":286,"shortTitle":287,"definition":288,"status":9,"industries":289,"functions":290,"patterns":293,"audience":33,"autonomy":34,"adoptionStage":35,"segment":296,"evidenceCount":297,"publicEvidenceCount":297,"organizations":298,"bestGrade":239,"headline":241,"lastVerified":200,"indexable":300},"AI for regulatory report assembly","Regulatory report assembly","AI that assembles periodic and data driven regulatory filings and returns, such as prudential and statistical returns, threshold and transaction reports and disclosure packs, by pulling data into the regulator's schema, validating it, reconciling figures to source, explaining movements against prior periods and drafting commentary, before a named officer reviews and submits. Narratives for individual suspicious activity cases are a separate use case.",[17,18,19,20],[22,291,292],"finance-and-accounting","financial-crime-compliance",[29,294,27,295],"anomaly-detection","summarization","back-office",2,[155,299],"National Credit Union Administration",true,{"slug":195,"title":302,"shortTitle":303,"definition":304,"status":9,"industries":305,"functions":307,"patterns":309,"audience":33,"autonomy":34,"adoptionStage":35,"segment":36,"evidenceCount":310,"publicEvidenceCount":310,"organizations":311,"bestGrade":239,"headline":241,"lastVerified":315,"indexable":300},"AI for policy drafting and policy gap analysis","Policy drafting and gaps","An assistant that takes a new or changed obligation, finds every internal policy, standard and procedure it touches, flags clauses that now conflict or are silent, and drafts the updated wording in house style as a redline for the policy owner to approve.",[306,17,18,19,213],"cross-industry",[22,23,308],"knowledge-management",[26,27,28,295],3,[312,313,314],"Federal Deposit Insurance Corporation","Administration for Children and Families","Health Resources and Services Administration","2026-09-26",{"slug":196,"title":317,"shortTitle":318,"definition":319,"status":9,"industries":320,"functions":321,"patterns":324,"audience":296,"autonomy":326,"adoptionStage":35,"segment":36,"evidenceCount":310,"publicEvidenceCount":310,"organizations":327,"bestGrade":239,"headline":241,"lastVerified":200,"indexable":300},"AI for continuous controls testing and control self assessment","Continuous controls testing","AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.",[306,17,18,19,213],[322,22,323],"risk-management","operations",[29,28,294,325],"classification-and-routing","supervised-agent",[312,328,329],"U.S. Department of the Interior","Pension Benefit Guaranty Corporation",{"slug":197,"title":331,"shortTitle":332,"definition":333,"status":9,"industries":334,"functions":336,"patterns":337,"audience":33,"autonomy":34,"adoptionStage":338,"evidenceCount":310,"publicEvidenceCount":310,"organizations":339,"bestGrade":343,"headline":344,"lastVerified":200,"indexable":300},"Generative AI copilot for internal audit","Internal audit copilot","A copilot for internal auditors that drafts planning memos and document request lists from prior audits, summarises large evidence sets, builds risk and control matrices from policies and process documents, and drafts findings and reports, with every statement traceable to its evidence and a qualified auditor accountable for every conclusion.",[306,17,18,213,19,335],"wealth-and-asset-management",[322,22,291],[26,295,27,28,294],"early-adopters",[340,341,342],"Banco Bradesco","British Columbia Investment Management Corporation","XP Inc.","C",{"kpi":345,"label":346,"unit":347,"n":297,"nUpTo":279,"kind":348,"value":349,"qualifier":350,"claimant":351,"organization":340,"vendorReported":300},"handling-time-reduction","Handling time reduction","percent","reported",55,"exact","vendor",{"slug":198,"title":353,"shortTitle":354,"definition":355,"status":9,"industries":356,"functions":358,"patterns":359,"audience":33,"autonomy":360,"adoptionStage":338,"segment":41,"evidenceCount":361,"publicEvidenceCount":297,"organizations":362,"bestGrade":239,"headline":241,"lastVerified":200,"indexable":300},"AI regulatory horizon scanning and obligation mapping","Regulatory horizon scanning","An AI system that continuously reads publications from the regulators and standard setters an organization answers to, classifies each item by relevance and urgency, breaks new rules into individual obligations and maps them to the internal policies and controls that meet them, so compliance owners see what changed and where the gaps are.",[306,17,18,20,335,357,213],"pharma-and-life-sciences",[22,23,322],[325,28,26,295,29],"assist",4,[161,313],{"slug":199,"title":364,"shortTitle":365,"definition":366,"status":9,"industries":367,"functions":369,"patterns":372,"audience":296,"autonomy":34,"adoptionStage":35,"segment":36,"evidenceCount":310,"publicEvidenceCount":310,"organizations":373,"bestGrade":239,"headline":241,"lastVerified":200,"indexable":300},"AI for complaints root cause and systemic issue analysis","Complaints root cause analysis","AI that reads the free text of complaints across all channels, clusters them into themes, separates systemic causes from one off events, links each theme to the product, process or control behind it and routes the insight to the owner who can fix it, with a human validating every root cause and every remediation.",[306,17,18,20,368,213],"telecommunications",[22,370,371],"customer-service","analytics-and-reporting",[325,295,29,26],[374,155,375],"Centers for Medicare and Medicaid Services","Federal Trade Commission",{"indexable":300,"reasons":377},[],[379,385,390,397,402,407,414,420,428,435,442,448,455,462,468,473,480,485,491,497,503,509,515,520,525,532,539,544,549,557,563,569,575,580],{"id":147,"label":380,"issuer":381,"region":162,"url":382,"description":383,"useCases":384,"indexable":300},"EU AI Act","European Union","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":148,"label":386,"issuer":381,"region":162,"url":387,"description":388,"useCases":389,"indexable":300},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":150,"label":391,"issuer":392,"region":393,"url":394,"description":395,"useCases":396,"indexable":300},"ISO/IEC 42001","ISO and IEC","global","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":151,"label":398,"issuer":171,"region":156,"url":399,"description":400,"useCases":401,"indexable":300},"NIST AI Risk Management Framework","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":149,"label":403,"issuer":381,"region":162,"url":404,"description":405,"useCases":406,"indexable":300},"DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":408,"label":409,"issuer":410,"region":162,"url":411,"description":412,"useCases":413,"indexable":300},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":415,"label":416,"issuer":161,"region":162,"url":417,"description":418,"useCases":419,"indexable":300},"uk-consumer-duty","FCA Consumer Duty","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":421,"label":422,"issuer":423,"region":424,"url":425,"description":426,"useCases":427,"indexable":300},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":429,"label":430,"issuer":431,"region":424,"url":432,"description":433,"useCases":434,"indexable":300},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":436,"label":437,"issuer":438,"region":393,"url":439,"description":440,"useCases":441,"indexable":300},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",20,{"id":443,"label":444,"issuer":445,"region":156,"url":446,"description":447,"useCases":441,"indexable":300},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":449,"label":450,"issuer":451,"region":162,"url":452,"description":453,"useCases":454,"indexable":300},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":456,"label":457,"issuer":458,"region":393,"url":459,"description":460,"useCases":461,"indexable":300},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":463,"label":464,"issuer":381,"region":162,"url":465,"description":466,"useCases":467,"indexable":300},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":469,"label":470,"issuer":381,"region":162,"url":471,"description":472,"useCases":467,"indexable":300},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":474,"label":475,"issuer":476,"region":156,"url":477,"description":478,"useCases":479,"indexable":300},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":481,"label":482,"issuer":381,"region":162,"url":483,"description":484,"useCases":63,"indexable":300},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",{"id":486,"label":487,"issuer":488,"region":156,"url":489,"description":490,"useCases":63,"indexable":300},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":492,"label":493,"issuer":494,"region":393,"url":495,"description":496,"useCases":63,"indexable":300},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":498,"label":499,"issuer":381,"region":162,"url":500,"description":501,"useCases":502,"indexable":300},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":504,"label":505,"issuer":506,"region":156,"url":507,"description":508,"useCases":502,"indexable":300},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":510,"label":511,"issuer":423,"region":424,"url":512,"description":513,"useCases":514,"indexable":300},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",10,{"id":516,"label":517,"issuer":381,"region":162,"url":518,"description":519,"useCases":514,"indexable":300},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":521,"label":522,"issuer":381,"region":162,"url":523,"description":524,"useCases":514,"indexable":300},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":526,"label":527,"issuer":528,"region":162,"url":529,"description":530,"useCases":531,"indexable":300},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":533,"label":534,"issuer":535,"region":156,"url":536,"description":537,"useCases":538,"indexable":300},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",8,{"id":540,"label":541,"issuer":381,"region":162,"url":542,"description":543,"useCases":538,"indexable":300},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":545,"label":546,"issuer":381,"region":162,"url":547,"description":548,"useCases":62,"indexable":300},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",{"id":550,"label":551,"issuer":552,"region":553,"url":554,"description":555,"useCases":556,"indexable":300},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",5,{"id":558,"label":559,"issuer":560,"region":162,"url":561,"description":562,"useCases":361,"indexable":300},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":564,"label":565,"issuer":566,"region":162,"url":567,"description":568,"useCases":361,"indexable":300},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":570,"label":571,"issuer":572,"region":424,"url":573,"description":574,"useCases":310,"indexable":300},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":576,"label":577,"issuer":381,"region":162,"url":578,"description":579,"useCases":310,"indexable":300},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":581,"label":582,"issuer":375,"region":156,"url":583,"description":584,"useCases":310,"indexable":300},"us-fcra","Fair Credit Reporting Act","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598301796]