[{"data":1,"prerenderedAt":577},["ShallowReactive",2],{"uc-travel-and-expense-audit-agent":3,"uc-regulations":367},{"useCase":4,"evidence":184,"blitsAiDeployments":256,"benchmarks":257,"indicative":279,"related":282,"indexability":365,"includeUnpublished":190},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":16,"functions":20,"patterns":22,"channels":27,"audience":30,"autonomy":31,"adoptionStage":32,"segment":30,"problem":33,"problemStats":34,"howItWorks":35,"valueDrivers":36,"kpis":41,"indicativeValue":46,"macroEstimates":81,"feasibility":82,"implementation":94,"risk":136,"blitsAi":159,"faq":161,"related":174,"datePublished":179,"dateModified":179,"lastVerified":179,"changelog":180,"slug":183},"AI agent for travel and expense report audit","Travel and expense audit","AI audit for travel and expense reports","AI reviews every expense line against policy, not a sample. AppZen reports Takeda saved 4,000 auditor hours a quarter; Databricks found $483K in wasted spend.","published","An AI agent that checks every travel and expense report line against policy, receipts and prior submissions instead of a small manual sample, flags duplicates, altered receipts and policy violations with the evidence attached, and auto approves the clean majority so auditors spend their time on the reports that are genuinely risky.",[12,13,14,15],"expense report auditing","T&E audit automation","AI spend audit","expense fraud detection",[17,18,19],"cross-industry","pharma-and-life-sciences","technology",[21],"finance-and-accounting",[23,24,25,26],"document-processing","anomaly-detection","classification-and-routing","agentic-workflow",[28,29],"internal-tools","api","back-office","supervised-agent","early-adopters","Travel and expense spend is high volume, low value per transaction, and hard to police at scale.\nTraditional audit teams cannot review every report line by line, so they sample: only expenses\nabove a value threshold, or a random percentage, get a real look. At Takeda,\nAppZen reports that at times 70 to 100% of expenses triggered audit rules, yet sampling and value\nthresholds still left spend uncovered and exposed to duplicate submissions and employee spend\nleakage that a person reviewing one report at a time cannot see across the whole population.\n\nMultinational organizations add language and currency variation across dozens of countries, each\nwith its own per diem and travel policy, on top of the volume problem. The result is a familiar\ntrade off: either spend more headcount on audit, which does not scale with travel volume, or\naccept that most spend goes unchecked and hope the exceptions surface some other way, for example\nwhen a manager happens to notice.",[],"1. **Capture every report.** Expense reports, receipts and the underlying corporate card\n   transactions feed into one pipeline from the T&E platform, so every line has a receipt image or\n   card record to check against, not just the ones a person opens.\n2. **Score every line against policy.** Each line is checked against the organization's written\n   policy by category, region and grade, rather than a single value threshold, and against the\n   employee's own submission history.\n3. **Cross check for duplicates and altered receipts.** The agent compares receipts across reports\n   and employees for duplicate submissions (including the same meal claimed by two attendees) and\n   checks receipt images for signs of alteration.\n4. **Auto approve the clean majority.** Lines that pass every check within policy limits approve\n   automatically; anything flagged goes to an auditor with the receipt, the rule it triggered and\n   similar past decisions shown together.\n5. **Learn from auditor decisions.** Confirmed and overturned flags feed back as candidate rule\n   adjustments, which a T&E or finance manager reviews and approves before they change what\n   auto approves.\n6. **Feed the policy owners.** Patterns by category, region or employee go to the corporate card\n   and travel policy teams, so recurring issues get fixed at the policy level, not flagged again\n   every month.",[37,38,39,40],"cost-to-serve","risk-reduction","compliance","employee-productivity",[42,43,44,45],"automation-rate","hours-saved","cost-savings","interactions-handled",{"referenceOrg":47,"inputs":48,"formula":76,"currency":77,"period":78,"resultLabel":79,"caveat":80},"A company with 7,000+ employees submitting about 130,000 expense reports a year",[49,56,63,69],{"key":50,"label":51,"low":52,"high":52,"unit":53,"note":54,"sourceUrl":55},"reportsPerYear","Expense reports submitted per year",130000,"reports per year","AppZen reports that before AppZen, Databricks' \"two auditors manually reviewed nearly 130K expense reports annually\" across \"7,000+ employees globally.\" Replace with your own report volume.","https://www.appzen.com/databricks-improved-travel-expense-management/",{"key":57,"label":58,"low":59,"high":60,"unit":61,"note":62,"sourceUrl":55},"autoApprovalShare","Share of reports the AI approves without a person",0.63,0.72,"fraction of reports","Range spans the auto approval rates AppZen reports for its two customers: 63% at [Takeda](https://www.appzen.com/resources/case-studies/how-takeda-is-transforming-global-expense-auditing-with-ai) across 63 countries, 72% at Databricks, where AppZen says the team kept adjusting its configuration month after month. Expect a lower rate before your own policy is tuned.",{"key":64,"label":65,"low":66,"high":66,"unit":67,"note":68,"sourceUrl":55},"minutesPerReport","Auditor minutes saved per auto approved report",1.9,"minutes per auto approved report","Derived from the hours AppZen reports Databricks saved, spread only across the reports that were auto approved: about 1.9 minutes per auto approved report (nearly 3,000 auditor hours saved a year across 130,000 reports at a 72% auto approval rate), which anchors this figure to the reference org above. This is time saved on the reports the AI clears, not a manual review time per report; no source gives that figure. AppZen also reports [Takeda](https://www.appzen.com/resources/case-studies/how-takeda-is-transforming-global-expense-auditing-with-ai) saving 4,000 auditor hours a quarter across \"400K expense audits annually\" at a 63% auto approval rate, but that figure is not used here: AppZen never states that an expense audit is the same unit as an expense report, so it cannot be safely converted into minutes per report and applied to the reference org's report count. Replace with your own time study.",{"key":70,"label":71,"low":72,"high":73,"unit":74,"note":75},"costPerHour","Fully loaded cost of a T&E auditor",25,45,"USD per hour","Editorial assumption for a blended onshore and offshore audit team.","reportsPerYear * autoApprovalShare * minutesPerReport / 60 * costPerHour","USD","per year","Manual expense audit effort avoided","Labour only. It leaves out the wasteful and non compliant spend actually caught (AppZen reports Databricks identified $483K in wasteful spend over twelve months), faster employee reimbursement, and the cost of the platform and policy configuration work.",[],{"complexity":83,"complexityNote":84,"dataPrerequisites":85,"integrations":89},"medium","Checking a receipt against a rule is straightforward; the work is encoding a policy that differs by category, region and grade into machine readable rules, and tuning thresholds so genuine risk is not buried under false positives on routine claims like meals and mileage.",[86,87,88],"Twelve months of history of audited expense reports with the outcome and reason","The written expense policy by category, region and grade, in a machine readable form","Card and travel booking feeds to cross check receipts against actual charges",[90,91,92,93],"T&E and expense platform (SAP Concur, Expensify, Emburse, Ramp)","Corporate card and travel booking feeds","HR system for employee grade, location and manager","ERP or payroll for reimbursement posting",{"steps":95,"guardrails":114,"humanInTheLoop":119,"kpisToInstrument":120,"failureModes":126},[96,99,102,105,108,111],{"title":97,"detail":98},"Baseline current coverage and findings","Record what share of reports get a real manual look today, what the sampling rule is, and what the audit team actually finds, so the AI is credited only for the increment.",{"title":100,"detail":101},"Encode the policy as machine readable rules","Turn the written expense policy into structured rules by category, region and grade; most early gaps come from policy that only exists as prose no one reads consistently.",{"title":103,"detail":104},"Start with the highest risk categories","Pick two or three categories with the most manual audit volume or the most prior findings, such as meals, mileage or entertainment, rather than trying to cover every category at once.",{"title":106,"detail":107},"Run in parallel with current sampling","Let the AI score every report next to the existing sample based process for a full close cycle, and compare what each approach would have flagged before changing anything live.",{"title":109,"detail":110},"Automate approval within limits","Auto approve only lines that pass every check within an agreed value limit; anything flagged, anything above the limit, and anything the model has not seen before goes to a person.",{"title":112,"detail":113},"Feed the policy and card teams","Route recurring flag patterns by category or employee to the people who own travel policy and the corporate card program, so the root cause gets fixed, not just the individual claim.",[115,116,117,118],"Every report checked against policy, not a value threshold sample; 100% coverage is the point","Only clean, policy compliant lines under an agreed value limit auto approve; anything flagged goes to a human auditor","Duplicate and altered receipt checks run on every submission before reimbursement","Any flag that could support disciplinary or employment action goes to a manager or HR review; the AI never decides or triggers that action itself","Auditors review every flagged line and decide whether to reject it, ask the employee for more information, or approve it. A T&E or finance manager approves changes to policy rules and thresholds, and reviews a sample of auto approved lines every month for drift.",[121,122,123,124,125],"Auto approval rate by category and region","Auditor hours per period","Wasteful or non compliant spend identified","Reimbursement cycle time","Repeat flag rate by employee and category",[127,130,133],{"title":128,"detail":129},"False positives bury real risk","Too many low value flags on routine claims train auditors to rubber stamp the queue. Tune thresholds by category and track the override rate, not only the flag count.",{"title":131,"detail":132},"New patterns the model has not seen","A scheme built around the model's blind spot, such as a generated receipt image, goes through. Sample auto approved lines and periodically red team the checks with new patterns.",{"title":134,"detail":135},"Flags treated as verdicts","A flag is acted on as if it were a finding rather than a lead, which is unfair to the employee if the flag is wrong. Require a human decision and a documented reason before any action follows from a flag.",{"euAiAct":137,"regulations":140,"guidance":143,"controls":153,"incidents":158},{"tier":138,"basis":139},"high","Annex III point 4(b) covers AI systems intended to monitor and evaluate the performance and behaviour of persons in a work related relationship. Scoring every line against the employee's own submission history, and instrumenting a repeat flag rate by employee, is that kind of behavioural evaluation, so this design falls under Annex III. The only carve out, Article 6(3), lets a narrow procedural or preparatory task escape high risk with a documented assessment, but the last subparagraph of Article 6(3) removes that carve out whenever the system performs profiling of natural persons. Scoring lines against an individual employee's history is profiling, so the carve out is not available here: keeping a human auditor as the actual decision maker on any personnel action is a required control, not an exit from Annex III.",[141,142],"eu-ai-act","gdpr",[144,150],{"title":145,"issuer":146,"region":147,"url":148,"note":149},"Annex III, point 4(b): employment, workers' management and access to self employment","European Union","europe","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Lists AI systems intended to make decisions affecting the terms of a work related relationship, its promotion or termination, to allocate tasks based on individual behaviour or personal traits, or to monitor and evaluate the performance and behaviour of persons in that relationship, as high risk.",{"title":151,"issuer":146,"region":147,"url":148,"note":152},"Article 6(3): the narrow task exception, and why it does not apply here","An Annex III system escapes high risk only if it performs a narrow procedural task, improves the result of a previously completed human activity, detects deviations from prior human decision making patterns without replacing or influencing the completed human assessment, or is preparatory. The last subparagraph closes this exception whenever the system profiles natural persons, which per employee, history based scoring does.",[154,155,156,157],"Every flag reviewed by a human auditor before it affects reimbursement or any personnel action","Documented, versioned policy rules with an owner and a review date","Consistency sampling across regions, expense categories and employee grades to catch uneven flagging","Full audit trail of every flag, the rule it triggered, and the human decision that followed",[],{"howToBuild":160},"On Blits.ai this is an **agentic workflow** that runs on a schedule, or that the T&E platform\ncalls through the workflow's API token when a new batch of reports is ready. A **custom\nfunction** fetches the new expense reports and the underlying card transactions over REST from\nthe T&E platform. An **AI agent** with **structured output** scores each line against the policy\nrules held in the **knowledge base**, organized into documents by category, region and grade and\nfound through **hybrid retrieval**, and further **custom functions** cross check the line\nagainst the corporate card feed and prior submissions in the ERP or expense platform (for\nexample through the SAP, Workday or Oracle connections in the integration catalog) for\nduplicates.\n\n**Human in the loop confirmation** holds any flagged or above threshold line for an auditor to\napprove or reject; their decision is logged for the next policy review. When an auditor needs\nmore information before deciding, that follow up with the employee happens outside the\nplatform. **PII masking** keeps employee personal data out of prompts sent to the model,\n**guardrails** run content checks on what the agent produces, **test suites** replay a labelled\nset of past reports before any policy change goes live, and **monitors** run scheduled checks\nagainst the agent. **Workflow run history with analytics and downloadable run data** shows auto\napproved versus held lines and the reasons behind each hold; feed in your own time tracking data\nto show auditor hours by period too. The platform is **model agnostic**, so the policy scoring\nmodel can be changed without rebuilding the workflow.",[162,165,168,171],{"question":163,"answer":164},"What share of expense reports can AI approve without a person?","AppZen reports a 63% auto approval rate across 63 countries at Takeda and a 72% auto approval rate at Databricks, where AppZen says the team kept adjusting its configuration month after month. Expect a lower rate at first, since the policy rules and thresholds need tuning against your own spend patterns before the model earns a wider auto approval limit.",{"question":166,"answer":167},"Does full coverage replace sampling?","It changes what sampling is for. Instead of choosing which reports get a real look, every report is checked against policy and prior patterns, and the sample becomes a quality check on the AI itself: auditors periodically review a slice of auto approved lines to catch drift, not a slice of all submissions to find the risky ones.",{"question":169,"answer":170},"Is expense audit AI high risk under the EU AI Act?","As designed here, yes. Annex III point 4(b) covers AI systems that monitor and evaluate employee behaviour, and scoring lines against an employee's own history is that kind of evaluation. The Article 6(3) narrow task exception cannot rescue it, because that exception never applies once a system profiles individual people, which per employee, history based scoring does. Keeping a human auditor as the actual decision maker on any personnel action is a required control under Annex III, not a way around it.",{"question":172,"answer":173},"What should stay with a person?","Any decision with disciplinary or termination consequences, ambiguous policy interpretation that a rule cannot capture, and cross border cases with tax or immigration implications.",[175,176,177,178],"supplier-invoice-processing","procurement-spend-classification","internal-audit-copilot","continuous-controls-testing","2026-09-28",[181],{"date":179,"note":182},"First published","travel-and-expense-audit-agent",[185,225],{"title":186,"useCases":187,"organization":188,"vendors":193,"summary":197,"stage":198,"year":199,"channels":200,"languages":201,"metrics":203,"outcomeDisclosed":215,"sources":216,"verification":220,"grade":222,"id":223,"organizationSlug":224},"Databricks: AI expense audit finds $483K in wasteful spend",[183],{"name":189,"anonymized":190,"country":191,"region":192,"industry":19},"Databricks",false,"US","north-america",[194],{"name":195,"role":196},"AppZen","platform","Before AppZen, Databricks' four person global audit team relied on manager approval, which gave \"no visibility, no forensics, and no data analysis on receipts,\" plus a four eyes check where two auditors manually reviewed nearly 130,000 expense reports a year across more than 7,000 employees. AppZen's Expense Audit, layered onto the existing Emburse Chrome River expense system, automated that review for duplicates and policy risk. Custom AppStore models such as Double-Dip Detection catch employees who submit a meal expense while also being listed as an attendee on someone else's expense, something the team could not catch before AppZen.","production",2025,[],[202],"en",[204,210],{"kpi":43,"value":205,"unit":206,"qualifier":207,"period":78,"claimant":208,"quote":209,"sourceUrl":55},3000,"hours","approximately","vendor","In one year, Databricks saved nearly 3,000 manual auditor work hours.",{"kpi":42,"value":211,"unit":212,"qualifier":213,"claimant":208,"quote":214,"sourceUrl":55},72,"percent","exact","Databricks identified $483K in wasteful spend and saved 3,000 auditor hours annually with AppZen, achieving 72% auto-approval for 9,000 employees.",true,[217],{"url":55,"title":218,"publisher":195,"archivedUrl":219},"Databricks: $483K Savings & 72% Auto-Approval","https://web.archive.org/web/20250118115135/https://www.appzen.com/databricks-improved-travel-expense-management/",{"level":221,"checkedAt":179},"source-verified","C","databricks-expense-audit-automation",null,{"title":226,"useCases":227,"organization":228,"vendors":232,"summary":234,"stage":235,"year":236,"channels":237,"languages":238,"metrics":239,"outcomeDisclosed":215,"sources":250,"verification":254,"grade":222,"id":255,"organizationSlug":224},"Takeda: AI expense audit across 63 countries",[183],{"name":229,"anonymized":190,"country":230,"region":231,"industry":18},"Takeda","JP","asia-pacific",[233],{"name":195,"role":196},"Takeda deployed AppZen's Expense Audit solution to review 100% of employee expense reports across its global operations, replacing a manual process that, at times, flagged as much as 70 to 100% of expenses for audit based on trigger rules yet still left the company vulnerable to duplicates and employee spend leakage. The AI models include translation capability to handle the language differences across Takeda's European and Asian operations, and auditors now focus their attention on high risk expenses.","scaled",2022,[],[],[240,244,247],{"kpi":42,"value":241,"unit":212,"qualifier":213,"claimant":208,"quote":242,"sourceUrl":243},63,"Takeda achieved 63% auto-approval across 63 countries, processing 400K expense audits annually while saving 4,000 auditor hours quarterly with AppZen.","https://www.appzen.com/resources/case-studies/how-takeda-is-transforming-global-expense-auditing-with-ai",{"kpi":45,"value":245,"unit":246,"qualifier":207,"period":78,"claimant":208,"quote":242,"sourceUrl":243},400000,"count",{"kpi":43,"value":248,"unit":206,"qualifier":207,"period":249,"claimant":208,"quote":242,"sourceUrl":243},4000,"per quarter",[251],{"url":243,"title":252,"publisher":195,"archivedUrl":253},"Takeda Saves 4,000 Auditor Hours Quarterly","https://web.archive.org/web/20220702200424/https://www.appzen.com/resources/case-studies/how-takeda-is-transforming-global-expense-auditing-with-ai?hsLang=en",{"level":221,"checkedAt":179},"takeda-expense-audit-automation",0,[258,266,273],{"kpi":42,"label":259,"unit":212,"aggregate":215,"higherIsBetter":215,"n":260,"nUpTo":256,"median":261,"min":241,"max":211,"byClaimant":262,"vendorOnly":215,"points":263},"Automation rate",2,67.5,{"organization":256,"vendor":260,"regulator":256,"independent":256},[264,265],{"evidenceId":223,"organization":189,"value":211,"qualifier":213,"claimant":208,"grade":222,"pooled":215},{"evidenceId":255,"organization":229,"value":241,"qualifier":213,"claimant":208,"grade":222,"pooled":215},{"kpi":43,"label":267,"unit":206,"aggregate":190,"higherIsBetter":215,"n":260,"nUpTo":256,"median":268,"min":205,"max":248,"byClaimant":269,"vendorOnly":215,"points":270},"Hours saved",3500,{"organization":256,"vendor":260,"regulator":256,"independent":256},[271,272],{"evidenceId":255,"organization":229,"value":248,"qualifier":207,"claimant":208,"grade":222,"pooled":215},{"evidenceId":223,"organization":189,"value":205,"qualifier":207,"claimant":208,"grade":222,"pooled":215},{"kpi":45,"label":274,"unit":246,"aggregate":190,"higherIsBetter":215,"n":275,"nUpTo":256,"median":245,"min":245,"max":245,"byClaimant":276,"vendorOnly":215,"points":277},"Interactions handled",1,{"organization":256,"vendor":275,"regulator":256,"independent":256},[278],{"evidenceId":255,"organization":229,"value":245,"qualifier":207,"claimant":208,"grade":222,"pooled":215},{"low":280,"high":281},64837.5,133380,[283,311,327,352],{"slug":175,"title":284,"shortTitle":285,"definition":286,"status":9,"industries":287,"functions":292,"patterns":294,"audience":30,"autonomy":31,"adoptionStage":295,"segment":30,"evidenceCount":296,"publicEvidenceCount":297,"organizations":298,"bestGrade":303,"headline":304,"lastVerified":310,"indexable":215},"AI for supplier invoice processing in accounts payable","Supplier invoice processing","AI that captures supplier invoices from any format, extracts header and line data, matches them to purchase orders and goods receipts, proposes tax and cost centre coding, flags duplicates and suspected fraud, and routes them for approval and posting, leaving only exceptions to accounts payable staff.",[17,288,289,290,291],"banking","government","retail-and-ecommerce","energy-and-utilities",[21,293],"procurement",[23,26,24,25],"mainstream",5,4,[299,300,301,302],"Federal Deposit Insurance Corporation","Kingfisher","U.S. Immigration and Customs Enforcement","Veolia","B",{"kpi":305,"label":306,"unit":212,"n":275,"nUpTo":275,"kind":307,"value":308,"qualifier":213,"claimant":309,"organization":300,"vendorReported":190},"productivity-gain","Productivity gain","reported",80,"organization","2026-09-27",{"slug":176,"title":312,"shortTitle":313,"definition":314,"status":9,"industries":315,"functions":318,"patterns":320,"audience":30,"autonomy":31,"adoptionStage":32,"evidenceCount":297,"publicEvidenceCount":297,"organizations":322,"bestGrade":303,"headline":224,"lastVerified":310,"indexable":215},"AI spend classification and spend analytics for procurement","Spend classification","AI that reads purchase orders, invoices, card transactions and contracts and assigns each line of spend to a category in the organization's taxonomy, and to the right supplier, so that procurement can see what is bought, from whom and where to consolidate or negotiate.",[17,289,316,317],"manufacturing","healthcare",[293,21,319],"analytics-and-reporting",[25,23,321],"summarization",[323,324,325,326],"U.S. General Services Administration","Internal Revenue Service","U.S. Department of Agriculture","Veterans Health Administration",{"slug":177,"title":328,"shortTitle":329,"definition":330,"status":9,"industries":331,"functions":335,"patterns":338,"audience":341,"autonomy":342,"adoptionStage":32,"evidenceCount":343,"publicEvidenceCount":343,"organizations":344,"bestGrade":222,"headline":348,"lastVerified":310,"indexable":215},"Generative AI copilot for internal audit","Internal audit copilot","A copilot for internal auditors that drafts planning memos and document request lists from prior audits, summarises large evidence sets, builds risk and control matrices from policies and process documents, and drafts findings and reports, with every statement traceable to its evidence and a qualified auditor accountable for every conclusion.",[17,288,332,289,333,334],"insurance","capital-markets","wealth-and-asset-management",[336,337,21],"risk-management","regulatory-compliance",[339,321,340,23,24],"rag-knowledge-assistant","content-generation","employee-facing","copilot",3,[345,346,347],"Banco Bradesco","British Columbia Investment Management Corporation","XP Inc.",{"kpi":349,"label":350,"unit":212,"n":260,"nUpTo":256,"kind":307,"value":351,"qualifier":213,"claimant":208,"organization":345,"vendorReported":215},"handling-time-reduction","Handling time reduction",55,{"slug":178,"title":353,"shortTitle":354,"definition":355,"status":9,"industries":356,"functions":357,"patterns":359,"audience":30,"autonomy":31,"adoptionStage":360,"segment":361,"evidenceCount":343,"publicEvidenceCount":343,"organizations":362,"bestGrade":303,"headline":224,"lastVerified":310,"indexable":215},"AI for continuous controls testing and control self assessment","Continuous controls testing","AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.",[17,288,332,333,289],[336,337,358],"operations",[26,23,24,25],"emerging","second-line",[299,363,364],"U.S. Department of the Interior","Pension Benefit Guaranty Corporation",{"indexable":215,"reasons":366},[],[368,372,377,385,392,398,405,412,419,425,432,438,445,452,458,463,470,476,482,488,494,500,506,511,516,523,530,535,541,548,554,560,566,571],{"id":141,"label":369,"issuer":146,"region":147,"url":148,"description":370,"useCases":371,"indexable":215},"EU AI Act","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":142,"label":373,"issuer":146,"region":147,"url":374,"description":375,"useCases":376,"indexable":215},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":378,"label":379,"issuer":380,"region":381,"url":382,"description":383,"useCases":384,"indexable":215},"iso-42001","ISO/IEC 42001","ISO and IEC","global","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":386,"label":387,"issuer":388,"region":192,"url":389,"description":390,"useCases":391,"indexable":215},"nist-ai-rmf","NIST AI Risk Management Framework","NIST","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":393,"label":394,"issuer":146,"region":147,"url":395,"description":396,"useCases":397,"indexable":215},"dora","DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":399,"label":400,"issuer":401,"region":147,"url":402,"description":403,"useCases":404,"indexable":215},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":406,"label":407,"issuer":408,"region":147,"url":409,"description":410,"useCases":411,"indexable":215},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":413,"label":414,"issuer":415,"region":231,"url":416,"description":417,"useCases":418,"indexable":215},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":420,"label":421,"issuer":422,"region":231,"url":423,"description":424,"useCases":72,"indexable":215},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",{"id":426,"label":427,"issuer":428,"region":381,"url":429,"description":430,"useCases":431,"indexable":215},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",20,{"id":433,"label":434,"issuer":435,"region":192,"url":436,"description":437,"useCases":431,"indexable":215},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":439,"label":440,"issuer":441,"region":147,"url":442,"description":443,"useCases":444,"indexable":215},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":446,"label":447,"issuer":448,"region":381,"url":449,"description":450,"useCases":451,"indexable":215},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":453,"label":454,"issuer":146,"region":147,"url":455,"description":456,"useCases":457,"indexable":215},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":459,"label":460,"issuer":146,"region":147,"url":461,"description":462,"useCases":457,"indexable":215},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":464,"label":465,"issuer":466,"region":192,"url":467,"description":468,"useCases":469,"indexable":215},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":471,"label":472,"issuer":146,"region":147,"url":473,"description":474,"useCases":475,"indexable":215},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":477,"label":478,"issuer":479,"region":192,"url":480,"description":481,"useCases":475,"indexable":215},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":483,"label":484,"issuer":485,"region":381,"url":486,"description":487,"useCases":475,"indexable":215},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":489,"label":490,"issuer":146,"region":147,"url":491,"description":492,"useCases":493,"indexable":215},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":495,"label":496,"issuer":497,"region":192,"url":498,"description":499,"useCases":493,"indexable":215},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":501,"label":502,"issuer":415,"region":231,"url":503,"description":504,"useCases":505,"indexable":215},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",10,{"id":507,"label":508,"issuer":146,"region":147,"url":509,"description":510,"useCases":505,"indexable":215},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":512,"label":513,"issuer":146,"region":147,"url":514,"description":515,"useCases":505,"indexable":215},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":517,"label":518,"issuer":519,"region":147,"url":520,"description":521,"useCases":522,"indexable":215},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":524,"label":525,"issuer":526,"region":192,"url":527,"description":528,"useCases":529,"indexable":215},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",8,{"id":531,"label":532,"issuer":146,"region":147,"url":533,"description":534,"useCases":529,"indexable":215},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":536,"label":537,"issuer":146,"region":147,"url":538,"description":539,"useCases":540,"indexable":215},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",6,{"id":542,"label":543,"issuer":544,"region":545,"url":546,"description":547,"useCases":296,"indexable":215},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":549,"label":550,"issuer":551,"region":147,"url":552,"description":553,"useCases":297,"indexable":215},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":555,"label":556,"issuer":557,"region":147,"url":558,"description":559,"useCases":297,"indexable":215},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":561,"label":562,"issuer":563,"region":231,"url":564,"description":565,"useCases":343,"indexable":215},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":567,"label":568,"issuer":146,"region":147,"url":569,"description":570,"useCases":343,"indexable":215},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":572,"label":573,"issuer":574,"region":192,"url":575,"description":576,"useCases":343,"indexable":215},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598296042]