[{"data":1,"prerenderedAt":573},["ShallowReactive",2],{"uc-supply-chain-disruption-monitoring":3,"uc-regulations":356},{"useCase":4,"evidence":177,"blitsAiDeployments":242,"benchmarks":243,"indicative":255,"related":258,"indexability":354,"includeUnpublished":183},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":16,"functions":19,"patterns":23,"channels":27,"audience":30,"autonomy":31,"adoptionStage":32,"segment":33,"problem":34,"problemStats":35,"howItWorks":36,"valueDrivers":37,"kpis":41,"indicativeValue":46,"macroEstimates":76,"feasibility":77,"implementation":90,"risk":127,"blitsAi":155,"faq":157,"related":170,"datePublished":172,"dateModified":172,"lastVerified":172,"changelog":173,"slug":176},"AI supply chain risk and disruption monitoring","Supply chain risk monitoring","AI supply chain risk monitoring for factories","AI reads transport and supplier signals to flag disruptions early. Schaeffler flagged 700 potential events across its network since April 2024.","published","AI that watches transport lanes, weather, strikes, ports and the suppliers behind a manufacturer's own suppliers for signs of a coming disruption, turns scattered news and sensor signals into one validated alert per event, and gives planners enough lead time to reroute, expedite or substitute before the disruption reaches production or the customer.",[12,13,14,15],"supply chain risk monitoring","transport disruption alerts","supplier network mapping AI","supply chain control tower AI",[17,18],"automotive","manufacturing",[20,21,22],"procurement","operations","risk-management",[24,25,26],"anomaly-detection","prediction-and-scoring","summarization",[28,29],"internal-tools","api","employee-facing","assist","early-adopters","supply-chain-risk","A modern vehicle or industrial product depends on thousands of parts moving through several\ntiers of suppliers and a handful of ports, rail lines and highways that everyone else depends on\ntoo. A strike at one port, a drought that lowers a canal, a fire at a supplier two tiers back:\neach can stop a line thousands of miles away days before anyone in procurement hears about it\nthrough the usual channels.\n\nTeams that rely on generic news alerts and their direct suppliers' own reporting find out late,\nbecause the alert has no way to say whether it actually touches their shipments, and because\nvisibility usually stops at the first tier of suppliers. Schaeffler, a global precision systems\nleader with more than 250 locations in 55 countries, is a case in point: Everstream Analytics'\ncase study on Schaeffler describes exactly this pattern before it changed its approach: limited\nreal time visibility, disruptions such as the Panama Canal drought and regional strikes\nidentified too late through generic alerts and public news, and dispersed teams working from\ninconsistent information. The result is reactive decisions under pressure: expedited freight at\na premium, urgent inventory moves and, in the worst case, a stopped line.",[],"1. **Map the network.** The platform builds a digital twin of the shipping lanes, ports,\n   suppliers and, where data allows, the suppliers behind them, so an event can be matched to\n   the parts and orders it actually affects.\n2. **Watch continuously.** Models read weather, news, port and carrier data, and other public\n   signals day and night, and combine them with the organization's own shipment and purchase\n   order data.\n3. **Score and validate.** Each candidate event is scored for relevance and severity to the\n   organization's own network, and, on platforms that offer it, checked by a human analyst\n   before it becomes an alert, so planners are not left to judge raw news themselves.\n4. **Alert the right team with context.** The alert names the lane, the shipment or supplier,\n   the shipment value and a confidence level, and reaches the planner, buyer or logistics owner\n   who can act, not a shared inbox nobody owns.\n5. **Decide and act.** A human decides the mitigation: reroute the shipment, expedite it,\n   substitute a part or supplier, or accept the risk, and the decision and its outcome are\n   recorded.\n6. **Learn from outcomes.** Confirmed catches and missed events both feed back into the scoring,\n   and recurring risk patterns turn into standing playbooks for the next similar event.",[38,39,40],"risk-reduction","speed","cost-to-serve",[42,43,44,45],"detection-rate-improvement","productivity-gain","cost-savings","interactions-handled",{"referenceOrg":47,"inputs":48,"formula":71,"currency":72,"period":73,"resultLabel":74,"caveat":75},"An automotive tier one supplier shipping components from 40 plants worldwide",[49,57,64],{"key":50,"label":51,"low":52,"high":53,"unit":54,"note":55,"sourceUrl":56},"majorEventsPerYear","Major transport or supplier disruptions flagged on the network per year",40,120,"flagged events per year","Editorial assumption, conservative against Schaeffler's reported 700 potential disruptions identified across its network since April 2024, published October 2025 (Everstream Analytics); a single tier one supplier's network is smaller than Schaeffler's full global footprint.","https://www.everstream.ai/case-study/schaeffler/",{"key":58,"label":59,"low":60,"high":61,"unit":62,"note":63},"avgCostPerEvent","Average cost of one unmanaged disruption, in expedited freight, missed production and penalties",8000,60000,"USD per event","Editorial assumption, replace with your own expedited freight and downtime cost data.",{"key":65,"label":66,"low":67,"high":68,"unit":69,"note":70},"shareMitigated","Share of flagged events where the earlier warning changes the outcome",0.15,0.35,"fraction of flagged events","Editorial assumption. Neither evidence record on this page separates events where the warning changed the outcome from ones that would have been managed anyway, so this stays conservative.","majorEventsPerYear * avgCostPerEvent * shareMitigated","USD","per year","Disruption cost avoided per year","Counts avoided disruption cost only. It leaves out the platform's own subscription cost, the analyst time spent triaging alerts, and the harder to price value of protecting the customer delivery promise and brand.",[],{"complexity":78,"complexityNote":79,"dataPrerequisites":80,"integrations":85},"medium","The event models and news processing come from the platform. The organization's own work is connecting purchase order, shipment and supplier master data, mapping the tiers behind the direct suppliers where visibility is weakest, and building a routine that gets a validated alert to the person who can act on it within hours, not days.",[81,82,83,84],"Supplier and shipment master data with lanes, parts and volumes","A defined map of critical suppliers and, where possible, the suppliers behind them","A named owner and an escalation path per region or category who can decide on mitigation","A record of past disruption events and what happened, to check the model over time",[86,87,88,89],"Enterprise resource planning or supply chain planning system for purchase orders and shipments","Supplier master data and category management system","Logistics and freight visibility systems","Alerting into the email, messaging or dashboard tools the team already uses",{"steps":91,"guardrails":107,"humanInTheLoop":111,"kpisToInstrument":112,"failureModes":117},[92,95,98,101,104],{"title":93,"detail":94},"Map the network before turning on alerts","Start with the lanes, ports and suppliers that carry the most value or the least slack, and add the tier behind them for the categories that matter most, rather than trying to map everything at once.",{"title":96,"detail":97},"Set the escalation path first","For each severity level, write down who receives the alert, how fast they must respond, and what they are allowed to decide on their own versus escalate.",{"title":99,"detail":100},"Start with the highest value lanes and categories","Pick the shipping lanes or supplier categories with the highest value at risk or the fewest alternative sources, and prove the alert to action loop there before widening it.",{"title":102,"detail":103},"Wire alerts into the tools planners already use","Send alerts into the messaging, email or planning tool the team works in every day; a dashboard nobody opens is not a monitoring programme.",{"title":105,"detail":106},"Record every decision and outcome","Log what the team decided for each real alert and what happened, so recurring risks turn into written playbooks and the scoring model can be checked against reality.",[108,109,110],"Every alert names the shipment, part or supplier it affects and the confidence behind it, so a planner can check it before acting","A human decides the mitigation; the AI never reroutes a shipment, contacts a supplier or places an order on its own","Escalation thresholds and owners are written down and reviewed after every real disruption","Procurement and supply chain planners review every alert that crosses a written severity threshold, decide the mitigation, and record what happened. That record is also how the model and the thresholds improve over time.",[113,114,115,116],"Share of flagged events confirmed as real and material, not noise","Lead time between the first alert and the event affecting a shipment","Disruption cost avoided per confirmed catch, written up case by case","Coverage, the share of critical suppliers and lanes actually monitored",[118,121,124],{"title":119,"detail":120},"Alert fatigue","Too many low value alerts and planners stop reading them. Tune thresholds to the lanes and categories that matter most and report the confirmation rate.",{"title":122,"detail":123},"Blind spots beyond the first tier","Visible risk usually sits with direct suppliers, but a shortage often starts two or three tiers back. Invest in mapping beyond the first tier, even starting with a sample of critical categories.",{"title":125,"detail":126},"Warnings nobody owns","An alert with no named owner or deadline gets read too late to matter. Write down who decides and how fast, before turning alerts on for a new region or category.",{"euAiAct":128,"regulations":131,"guidance":136,"controls":149,"incidents":154},{"tier":129,"basis":130},"minimal","The system scores transport lanes, shipments and suppliers, not natural persons, so it does not fall under an Annex III high risk category. It does not interact with the public and does not publish AI generated content, so it does not trigger the Article 50 transparency duty either. It stays minimal risk as long as its output only informs a human procurement or logistics decision.",[132,133,134,135],"eu-ai-act","gdpr","iso-42001","nist-ai-rmf",[137,143],{"title":138,"issuer":139,"region":140,"url":141,"note":142},"AI Risk Management Framework","NIST","north-america","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary framework for mapping, measuring and managing the risks of an AI system, useful for documenting the model's limits and the monitoring around a system that advises rather than decides.",{"title":144,"issuer":145,"region":146,"url":147,"note":148},"ISO/IEC 42001","ISO and IEC","global","https://www.iso.org/standard/81230.html","International management system standard for AI, a fit for governing a monitoring system that several regions and functions rely on for the same alerts.",[150,151,152,153],"Inventory entry for the monitoring platform with an owner and the categories or lanes it covers","Written escalation path and service level for every alert severity","Regular sampling of alerts against what actually happened, to catch drift and blind spots","No automated supplier contact or ordering without a human decision",[],{"howToBuild":156},"On Blits.ai this sits behind the risk platform's own event feed rather than replacing it. A\nSQL knowledge base registers the organization's own database of purchase orders, shipments\nand supplier and lane master data, so an AI agent can query it directly and answer a planner's\nquestion about which orders sit on an affected lane and what they are worth, in plain\nlanguage. An agentic workflow watches the incoming event feed and, when an event crosses a\nwritten threshold for a lane or category, drafts a one page brief (what happened, which\norders and suppliers it touches, and the options) and routes it to the named owner for that\nregion through human in the loop approval before anything leaves the team.\n\nGuardrails keep the agent inside answering questions and drafting briefs; it never contacts a\nsupplier or places an order itself, and PII masking strips personal names from supplier\ncontact records before they reach a model. Planners reach the agent through internal tools or\na channel such as Microsoft Teams, test suites check that a sample of past events still\nproduce the right brief after every change, monitors run scheduled health checks on the agent\nso a stalled workflow is caught quickly, and workflow run history and the audit trail record\neach brief and the approval that followed it. The platform is model agnostic and can run with\nEU or UAE data residency for teams that need it.",[158,161,164,167],{"question":159,"answer":160},"What counts as a supply chain disruption worth monitoring?","Anything that can stop parts moving on a lane or from a supplier the organization depends on: strikes, weather, port congestion, factory fires, sanctions and a supplier's own financial distress. Everstream Analytics' case study on Schaeffler names the Panama Canal drought and regional strikes as examples that used to reach it too late through generic news alerts.",{"question":162,"answer":163},"How is this different from vendor risk due diligence?","Vendor risk due diligence reviews a supplier once, and periodically, on security, compliance and financial health before and during a relationship. Supply chain disruption monitoring watches continuously for events on the shipping lanes and at the suppliers already onboarded, so the two are complementary rather than the same job.",{"question":165,"answer":166},"Does the AI decide how to respond to a disruption?","No. It scores and explains the event and names the shipments or suppliers it affects; a procurement or logistics planner decides whether to reroute, expedite, substitute or accept the risk, and that decision is recorded.",{"question":168,"answer":169},"How many tiers of suppliers can it actually see?","It depends on the data the organization and the platform can gather beyond direct suppliers. Visibility is usually strongest at the first tier and weakens further back; mapping the tiers behind critical categories is a deliberate, ongoing investment, not a one time setup step.",[171],"vendor-due-diligence","2026-09-29",[174],{"date":172,"note":175},"First published","supply-chain-disruption-monitoring",[178,220],{"title":179,"useCases":180,"organization":181,"vendors":186,"summary":190,"stage":191,"year":192,"channels":193,"languages":194,"metrics":196,"outcomeDisclosed":210,"sources":211,"verification":215,"grade":217,"id":218,"organizationSlug":219},"Schaeffler: AI powered transport risk monitoring across the automotive supply chain",[176],{"name":182,"anonymized":183,"country":184,"region":185,"industry":17},"Schaeffler",false,"DE","europe",[187],{"name":188,"role":189},"Everstream Analytics","platform","Schaeffler, a global precision systems leader with more than 250 locations in 55 countries, integrated Everstream Analytics AI powered risk intelligence into its transport planning to replace generic news alerts with round the clock, validated warnings about strikes, weather and other events on its shipping lanes. Schaeffler combined the alerts with its own Power BI dashboards and a defined risk community so that planning, sourcing, manufacturing and delivery teams act on the same information.","scaled",2024,[28],[195],"en",[197,204],{"kpi":45,"value":198,"unit":199,"qualifier":200,"period":201,"claimant":202,"quote":203,"sourceUrl":56},700,"count","approximately","since April 2024, published October 2025","vendor","700 Potential transport disruptions identified across the Schaeffler network since April 2024 (publication date: Oct 2025)",{"kpi":43,"value":205,"unit":206,"qualifier":207,"period":208,"claimant":202,"quote":209,"sourceUrl":56},50,"percent","at-least","as of October 2025 publication","50%+ Less manual work combining risk intelligence with data-driven assessments of shipment disruption impacts",true,[212],{"url":56,"title":213,"publisher":188,"date":214},"Schaeffler: People, process, technology: the formula for a resilient transport supply chain","2025-10-01",{"level":216,"checkedAt":172},"source-verified","C","schaeffler-transport-risk-monitoring",null,{"title":221,"useCases":222,"organization":223,"vendors":226,"summary":228,"stage":229,"year":230,"channels":231,"languages":232,"metrics":233,"outcomeDisclosed":210,"sources":234,"verification":240,"grade":217,"id":241,"organizationSlug":219},"Schneider Electric: AI transport event alerts prevent logistics disruptions",[176],{"name":224,"anonymized":183,"country":225,"region":185,"industry":18},"Schneider Electric","FR",[227],{"name":188,"role":189},"Schneider Electric uses Everstream Analytics' platform to receive automatic, real time notifications of events that may affect global transport logistics. This gives Schneider Electric extra lead time to make critical mitigation decisions and reroute shipments as necessary. Everstream Analytics reports that Schneider Electric has noted this previously prevented over 100 major events from negatively affecting its logistics and improved its customer delivery predictability.","production",2023,[28],[195],[],[235],{"url":236,"title":237,"publisher":188,"date":238,"archivedUrl":239},"https://www.everstream.ai/articles/10-supply-chain-risk-management-examples/","10 Supply Chain Risk Management Examples","2023-05-30","https://web.archive.org/web/20230530105757/https://www.everstream.ai/articles/10-supply-chain-risk-management-examples/",{"level":216,"checkedAt":172},"schneider-electric-transport-event-monitoring",0,[244,250],{"kpi":45,"label":245,"unit":199,"aggregate":183,"higherIsBetter":210,"n":246,"nUpTo":242,"median":198,"min":198,"max":198,"byClaimant":247,"vendorOnly":210,"points":248},"Interactions handled",1,{"organization":242,"vendor":246,"regulator":242,"independent":242},[249],{"evidenceId":218,"organization":182,"value":198,"qualifier":200,"claimant":202,"grade":217,"pooled":210},{"kpi":43,"label":251,"unit":206,"aggregate":210,"higherIsBetter":210,"n":246,"nUpTo":242,"median":205,"min":205,"max":205,"byClaimant":252,"vendorOnly":210,"points":253},"Productivity gain",{"organization":242,"vendor":246,"regulator":242,"independent":242},[254],{"evidenceId":218,"organization":182,"value":205,"qualifier":207,"claimant":202,"grade":217,"pooled":210},{"low":256,"high":257},48000,2520000,[259,285,313,331],{"slug":171,"title":260,"shortTitle":261,"definition":262,"status":9,"industries":263,"functions":269,"patterns":271,"audience":30,"autonomy":275,"adoptionStage":32,"segment":276,"evidenceCount":277,"publicEvidenceCount":277,"organizations":278,"bestGrade":283,"headline":219,"lastVerified":284,"indexable":210},"AI for third party and vendor risk due diligence","Vendor due diligence","AI that reviews a vendor's security questionnaires, SOC and assurance reports, contracts and model documentation against the organization's control requirements, researches the vendor's ownership, sanctions, financial health and adverse media, drafts the risk assessment for a human to approve and keeps the register of material service providers current with ongoing monitoring.",[264,265,266,267,268],"cross-industry","banking","insurance","government","payments",[20,22,270],"regulatory-compliance",[272,273,274,26],"document-processing","rag-knowledge-assistant","agentic-workflow","copilot","second-line",4,[279,280,281,282],"U.S. Department of Justice","Internal Revenue Service","U.S. Department of Agriculture","U.S. Trade and Development Agency","B","2026-09-27",{"slug":286,"title":287,"shortTitle":288,"definition":289,"status":9,"industries":290,"functions":293,"patterns":295,"audience":30,"autonomy":275,"adoptionStage":32,"evidenceCount":297,"publicEvidenceCount":298,"organizations":299,"bestGrade":283,"headline":306,"lastVerified":284,"indexable":210},"aiops-incident-triage","AI for IT incident triage and root cause analysis (AIOps)","AIOps incident triage","AI that turns a flood of monitoring alerts into one probable incident, routes it to the right team, proposes likely root causes and remediation from runbooks and past incidents, and drafts the stakeholder updates and the post incident review, while an engineer authorizes every change.",[264,265,291,292,268],"technology","telecommunications",[294,21,22],"it-and-engineering",[24,296,26,273,274],"classification-and-routing",7,6,[300,301,302,303,304,305],"Coinbase","Google","Meta","Microsoft","Mizuho Financial Group","TD Bank",{"kpi":307,"label":308,"unit":206,"n":309,"nUpTo":242,"kind":310,"value":311,"qualifier":312,"claimant":219,"organization":219,"vendorReported":183},"accuracy","Accuracy",3,"median",90,"exact",{"slug":314,"title":315,"shortTitle":316,"definition":317,"status":9,"industries":318,"functions":320,"patterns":322,"audience":324,"autonomy":275,"adoptionStage":325,"segment":326,"evidenceCount":277,"publicEvidenceCount":309,"organizations":327,"bestGrade":283,"headline":219,"lastVerified":284,"indexable":210},"portfolio-drift-monitoring-and-rebalancing","AI portfolio drift monitoring and rebalancing proposals","Drift and rebalancing","Continuous monitoring of every client portfolio against its mandate or model, which detects drift beyond agreed bands and prepares a tax aware, low turnover rebalancing proposal with its rationale for an advisor or portfolio manager to approve before any trade is placed.",[319,265],"wealth-and-asset-management",[21,22,321],"analytics-and-reporting",[24,274,25,323],"content-generation","back-office","emerging","middle-office",[328,329,330],"Morgan Stanley","SimCorp","Vanguard",{"slug":332,"title":333,"shortTitle":334,"definition":335,"status":9,"industries":336,"functions":337,"patterns":339,"audience":30,"autonomy":31,"adoptionStage":32,"segment":229,"evidenceCount":277,"publicEvidenceCount":277,"organizations":342,"bestGrade":283,"headline":347,"lastVerified":284,"indexable":210},"plant-operator-and-maintenance-copilot","AI copilot for plant operators and maintenance technicians","Plant operator and maintenance copilot","A generative AI assistant for the people who run and repair machines in plants, workshops and service centres: it answers fault and procedure questions from equipment manuals, fault reports, shift logs and live machine data, in the technician's language, with links to the sources, so faults are diagnosed faster and expert knowledge is not lost when experienced staff retire.",[18,17],[21,338],"knowledge-management",[273,340,26,341],"conversational-agent","translation",[343,344,345,346],"BMW Group","Georgia-Pacific","Husqvarna","Textron Aviation",{"kpi":348,"label":349,"unit":350,"n":242,"nUpTo":246,"kind":351,"value":352,"qualifier":353,"claimant":202,"organization":346,"vendorReported":210},"time-saved-per-task","Time saved per task","minutes","reported",18,"up-to",{"indexable":210,"reasons":355},[],[357,363,368,371,375,382,388,394,402,409,416,423,429,435,442,449,455,462,468,474,480,487,492,499,504,509,514,520,526,531,539,545,551,557,562,567],{"id":132,"label":358,"issuer":359,"region":185,"url":360,"description":361,"useCases":362,"indexable":210},"EU AI Act","European Union","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",230,{"id":133,"label":364,"issuer":359,"region":185,"url":365,"description":366,"useCases":367,"indexable":210},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",207,{"id":134,"label":144,"issuer":145,"region":146,"url":147,"description":369,"useCases":370,"indexable":210},"The international management system standard for AI.",122,{"id":135,"label":372,"issuer":139,"region":140,"url":141,"description":373,"useCases":374,"indexable":210},"NIST AI Risk Management Framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",92,{"id":376,"label":377,"issuer":378,"region":185,"url":379,"description":380,"useCases":381,"indexable":210},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",71,{"id":383,"label":384,"issuer":359,"region":185,"url":385,"description":386,"useCases":387,"indexable":210},"dora","DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":389,"label":390,"issuer":391,"region":185,"url":392,"description":393,"useCases":205,"indexable":210},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",{"id":395,"label":396,"issuer":397,"region":398,"url":399,"description":400,"useCases":401,"indexable":210},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",37,{"id":403,"label":404,"issuer":405,"region":398,"url":406,"description":407,"useCases":408,"indexable":210},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":410,"label":411,"issuer":412,"region":140,"url":413,"description":414,"useCases":415,"indexable":210},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",22,{"id":417,"label":418,"issuer":419,"region":146,"url":420,"description":421,"useCases":422,"indexable":210},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",21,{"id":424,"label":425,"issuer":359,"region":185,"url":426,"description":427,"useCases":428,"indexable":210},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",17,{"id":430,"label":431,"issuer":432,"region":185,"url":433,"description":434,"useCases":428,"indexable":210},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",{"id":436,"label":437,"issuer":438,"region":140,"url":439,"description":440,"useCases":441,"indexable":210},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",16,{"id":443,"label":444,"issuer":445,"region":146,"url":446,"description":447,"useCases":448,"indexable":210},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":450,"label":451,"issuer":359,"region":185,"url":452,"description":453,"useCases":454,"indexable":210},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":456,"label":457,"issuer":458,"region":140,"url":459,"description":460,"useCases":461,"indexable":210},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":463,"label":464,"issuer":465,"region":140,"url":466,"description":467,"useCases":461,"indexable":210},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":469,"label":470,"issuer":359,"region":185,"url":471,"description":472,"useCases":473,"indexable":210},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":475,"label":476,"issuer":477,"region":146,"url":478,"description":479,"useCases":473,"indexable":210},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":481,"label":482,"issuer":483,"region":140,"url":484,"description":485,"useCases":486,"indexable":210},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",11,{"id":488,"label":489,"issuer":359,"region":185,"url":490,"description":491,"useCases":486,"indexable":210},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",{"id":493,"label":494,"issuer":495,"region":185,"url":496,"description":497,"useCases":498,"indexable":210},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",10,{"id":500,"label":501,"issuer":397,"region":398,"url":502,"description":503,"useCases":498,"indexable":210},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",{"id":505,"label":506,"issuer":359,"region":185,"url":507,"description":508,"useCases":498,"indexable":210},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":510,"label":511,"issuer":359,"region":185,"url":512,"description":513,"useCases":498,"indexable":210},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":515,"label":516,"issuer":359,"region":185,"url":517,"description":518,"useCases":519,"indexable":210},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",9,{"id":521,"label":522,"issuer":523,"region":140,"url":524,"description":525,"useCases":297,"indexable":210},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",{"id":527,"label":528,"issuer":359,"region":185,"url":529,"description":530,"useCases":298,"indexable":210},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",{"id":532,"label":533,"issuer":534,"region":535,"url":536,"description":537,"useCases":538,"indexable":210},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",5,{"id":540,"label":541,"issuer":542,"region":185,"url":543,"description":544,"useCases":277,"indexable":210},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":546,"label":547,"issuer":548,"region":185,"url":549,"description":550,"useCases":277,"indexable":210},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":552,"label":553,"issuer":554,"region":398,"url":555,"description":556,"useCases":309,"indexable":210},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":558,"label":559,"issuer":359,"region":185,"url":560,"description":561,"useCases":309,"indexable":210},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":563,"label":564,"issuer":359,"region":185,"url":565,"description":566,"useCases":309,"indexable":210},"eu-mortgage-credit-directive","EU Mortgage Credit Directive","https://eur-lex.europa.eu/eli/dir/2014/17/oj","Directive 2014/17/EU: creditworthiness assessment, disclosure and advice rules for residential mortgage lending.",{"id":568,"label":569,"issuer":570,"region":140,"url":571,"description":572,"useCases":309,"indexable":210},"nyc-local-law-144","NYC Local Law 144","New York City","https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page","Bias audits and notices for automated employment decision tools used in hiring and promotion in New York City.",1790683494246]