[{"data":1,"prerenderedAt":610},["ShallowReactive",2],{"uc-vendor-due-diligence":3,"uc-regulations":410},{"useCase":4,"evidence":210,"blitsAiDeployments":303,"benchmarks":304,"indicative":305,"related":308,"indexability":408,"includeUnpublished":216},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":17,"functions":23,"patterns":27,"channels":32,"audience":34,"autonomy":35,"adoptionStage":36,"segment":37,"problem":38,"problemStats":39,"howItWorks":47,"valueDrivers":48,"kpis":53,"indicativeValue":58,"macroEstimates":93,"feasibility":94,"implementation":107,"risk":149,"blitsAi":187,"faq":189,"related":199,"datePublished":205,"dateModified":205,"lastVerified":205,"changelog":206,"slug":209},"AI for third party and vendor risk due diligence","Vendor due diligence","AI for vendor due diligence and third party risk","AI reads vendor assurance reports, researches ownership and sanctions and drafts risk assessments. The US DOJ and USDA use AI tools for supplier risk checks.","published","AI that reviews a vendor's security questionnaires, SOC and assurance reports, contracts and model documentation against the organization's control requirements, researches the vendor's ownership, sanctions, financial health and adverse media, drafts the risk assessment for a human to approve and keeps the register of material service providers current with ongoing monitoring.",[12,13,14,15,16],"third party risk management AI","vendor risk assessment AI","supplier due diligence AI","AI vendor assessment","TPRM automation",[18,19,20,21,22],"cross-industry","banking","insurance","government","payments",[24,25,26],"procurement","risk-management","regulatory-compliance",[28,29,30,31],"document-processing","rag-knowledge-assistant","agentic-workflow","summarization",[33],"internal-tools","employee-facing","copilot","early-adopters","second-line","Banks depend on many third parties, and every material one needs due diligence before onboarding\nand monitoring after: security questionnaires, SOC 2 or ISAE reports, business continuity plans,\nfinancial statements, contracts, sanctions and adverse media checks. Analysts read long assurance\nreports to find the handful of exceptions and carve outs that matter, then chase the vendor for\nanswers. Reviews are slow, and once done they go stale until the next periodic review.\n\nAI vendors add new questions: what data trains or reaches the model, how outputs are tested for\nbias and accuracy, who the model and cloud providers are, and whether the bank can audit any of\nit. At the same time, DORA in the EU, APRA CPS 230 in Australia and the US interagency guidance on\nthird party relationships hold the bank accountable for its providers. DORA requires a register of\ninformation on ICT third party arrangements and CPS 230 a register of material service providers\nthat is submitted to APRA. Outsourcing a service never outsources the responsibility.",[40,45],{"statement":41,"sourceTitle":42,"sourceUrl":43,"year":44},"In the Bank of England and FCA 2024 survey, a third of all AI use cases at UK financial firms were third party implementations, up from 17% in the 2022 survey.","Artificial intelligence in UK financial services 2024","https://www.bankofengland.co.uk/report/2024/artificial-intelligence-in-uk-financial-services-2024",2024,{"statement":46,"sourceTitle":42,"sourceUrl":43,"year":44},"The same survey found that 46% of firms using or planning to use AI have only a partial understanding of the AI technologies they use, largely because of third party models.","1. **Scope the review.** The request comes in with the service, data involved and criticality;\n   the assistant proposes the risk tier and the due diligence set required for it.\n2. **Read the documents.** It reads the questionnaire answers, SOC or ISAE reports, bridge\n   letters, policies, contract and, for AI vendors, model documentation, and maps each to the\n   bank's control requirements.\n3. **Flag the gaps.** It lists exceptions in assurance reports, carve outs, missing controls,\n   unanswered questions and contract clauses that fall short of required terms, with citations.\n4. **Research the vendor.** It gathers ownership, sanctions, litigation, financial health and\n   adverse media from approved data sources.\n5. **Draft the assessment.** It drafts the risk assessment and the follow up questions for the\n   vendor; a third party risk analyst reviews, challenges and decides.\n6. **Monitor and update the register.** Ongoing monitoring flags news, certificate expiries and\n   changes, and keeps the register of material or critical providers current.",[49,50,51,52],"risk-reduction","compliance","employee-productivity","speed",[54,55,56,57],"processing-time-reduction","time-saved-per-task","productivity-gain","hours-saved",{"referenceOrg":59,"inputs":60,"formula":88,"currency":89,"period":90,"resultLabel":91,"caveat":92},"A bank that runs 500 vendor due diligence reviews a year",[61,67,74,81],{"key":62,"label":63,"low":64,"high":64,"unit":65,"note":66},"reviews","Vendor due diligence reviews per year (new and periodic)",500,"reviews per year","The reference bank. Replace with your own third party inventory and review cycle.",{"key":68,"label":69,"low":70,"high":71,"unit":72,"note":73},"hoursPerReview","Analyst hours per review",8,20,"hours per review","Editorial assumption across document review, research and write up. Replace with your own records.",{"key":75,"label":76,"low":77,"high":78,"unit":79,"note":80},"timeSaved","Share of review time saved",0.2,0.4,"fraction of time","Editorial assumption. No public measured benchmark was found; keep this conservative.",{"key":82,"label":83,"low":84,"high":85,"unit":86,"note":87},"hourlyCost","Fully loaded cost of a third party risk analyst",60,110,"USD per hour","Editorial assumption, replace with your own.","reviews * hoursPerReview * timeSaved * hourlyCost","USD","per year","Analyst time released from vendor reviews","Time only. It leaves out faster vendor onboarding for the business, the value of continuous monitoring between reviews and the cost of data sources and integration.",[],{"complexity":95,"complexityNote":96,"dataPrerequisites":97,"integrations":102},"medium","Document review and research are well suited to AI. The work is in encoding the bank's control requirements, integrating with the third party risk platform and keeping judgement with analysts.",[98,99,100,101],"The bank's third party control requirements and risk tiering methodology","Vendor documents such as questionnaires, assurance reports, contracts and policies","Licensed data for ownership, sanctions, financial health and adverse media","Past assessments and findings to test the assistant against",[103,104,105,106],"Third party risk management or GRC platform and the vendor register","Procurement and contract management systems","Sanctions, company data and adverse media providers","Regulatory register submission templates, such as the APRA material service provider register",{"steps":108,"guardrails":124,"humanInTheLoop":130,"kpisToInstrument":131,"failureModes":136},[109,112,115,118,121],{"title":110,"detail":111},"Encode what good looks like","Turn the bank's control requirements into a checklist per risk tier, including an AI vendor section on data use, model testing, subprocessors and audit rights.",{"title":113,"detail":114},"Start with assurance report review","Have the assistant extract scope, exceptions, carve outs and complementary user entity controls from SOC reports, and compare with analyst reviews on past cases.",{"title":116,"detail":117},"Add research and monitoring","Connect approved data sources for ownership, sanctions and adverse media, and schedule monitoring for material vendors between reviews.",{"title":119,"detail":120},"Draft assessments and questions","Let the assistant draft the assessment and follow up questions, with every finding cited to a document, and have analysts approve before anything reaches the vendor.",{"title":122,"detail":123},"Keep the register evidenced","Link each register entry to its latest assessment, contract and monitoring alerts, so the register submitted to the regulator is backed by evidence.",[125,126,127,128,129],"A human analyst owns every risk rating and a named executive owns every risk acceptance","Every finding cites the document page or data source it comes from","Vendor documents are processed under confidentiality terms and never used to train models","Research uses approved, licensed data sources only","Monitoring alerts on material vendors are reviewed within a set time","Third party risk analysts review and decide every assessment, business owners and risk committees accept residual risk, and legal approves contract positions. The AI reads, researches, drafts and monitors.",[132,69,133,134,135],"Cycle time from review request to approved assessment, by risk tier","Findings per review and analyst agreement with AI flagged gaps","Share of material vendors with current assessments and active monitoring","Time from a monitoring alert to analyst review",[137,140,143,146],{"title":138,"detail":139},"Missing the exception in the report","The assistant summarises a SOC report as clean while an exception affects the bank's service. Test recall on past reports with known exceptions.",{"title":141,"detail":142},"Questionnaire answers taken at face value","The vendor's self reported answers are treated as evidence. Weight independent assurance over self attestation.",{"title":144,"detail":145},"Stale register","Monitoring runs but alerts are not reviewed, so the register looks current but is not. Track alert review times.",{"title":147,"detail":148},"AI vendors assessed like any other vendor","Model, data and subprocessor risks are not asked about. Keep a dedicated AI section in the checklist.",{"euAiAct":150,"regulations":153,"guidance":161,"controls":180,"incidents":186},{"tier":151,"basis":152},"minimal","Assessing organizations as vendors is not an Annex III use. If assessments score individual natural persons, such as sole traders, check the design against Annex III and data protection rules. The EU AI Act also shapes what to ask AI vendors, since providers of high risk systems carry specific obligations.",[154,155,156,157,158,159,160],"dora","apra-cps-230","eu-ai-act","gdpr","iso-42001","nist-ai-rmf","nis2",[162,168,174],{"title":163,"issuer":164,"region":165,"url":166,"note":167},"Guidelines on third party risk management","European Banking Authority","europe","https://www.eba.europa.eu/regulation-and-policy/internal-governance/guidelines-on-outsourcing-arrangements","The EBA's final guidelines on the sound management of third party risk for non ICT services focus on arrangements that support critical or important functions and, once applicable, repeal the 2019 guidelines on outsourcing arrangements. ICT providers, including most AI vendors, fall under DORA.",{"title":169,"issuer":170,"region":171,"url":172,"note":173},"SR 23-4: Interagency Guidance on Third-Party Relationships: Risk Management","Federal Reserve, FDIC and OCC","north-america","https://www.federalreserve.gov/supervisionreg/srletters/sr2304.htm","Joint US guidance on sound risk management for all stages in the life cycle of third party relationships, from planning and due diligence to ongoing monitoring and termination. It imposes no new requirements.",{"title":175,"issuer":176,"region":177,"url":178,"note":179},"Operational risk management (CPS 230)","Australian Prudential Regulation Authority","asia-pacific","https://www.apra.gov.au/operational-risk-management","Under paragraph 51 of CPS 230, APRA regulated entities must submit their register of material service providers to APRA; APRA's template is the preferred way to do so.",[181,182,183,184,185],"Risk tiering methodology with required due diligence per tier","Documented AI vendor question set covering data, models, testing and audit rights","Evidence link from every register entry to its assessment and contract","Review of AI generated findings and ratings by a named analyst","Periodic quality review of assessments against a sample of manual reviews",[],{"howToBuild":188},"On Blits.ai this is an **agentic workflow** started from the third party risk platform through\nthe API. The **knowledge base** ingests the vendor's documents (PDF, Word, Excel, email) and the\nbank's control requirements, retrieved with hybrid search, and **custom functions** call\napproved data providers for ownership, sanctions and adverse media. The agent returns\n**structured output** with findings, citations, a draft rating and follow up questions.\n\n**Agentic tasks** with scheduled rechecks keep material vendors under monitoring, **human in the\nloop approval** routes every draft rating to an analyst, and the **tool execution policy**\nlimits which systems the agent may use. Per run audit trails and **test suites** built on past\nassessments show how each conclusion was reached, and the platform is model agnostic with EU and\nUAE data residency.",[190,193,196],{"question":191,"answer":192},"Can AI decide whether a vendor is acceptable?","No. It can read the documents, research the vendor and draft the assessment, but a human analyst owns the rating and a named executive owns the risk acceptance. Regulators are clear that outsourcing does not move responsibility away from the bank.",{"question":194,"answer":195},"What should we ask AI vendors specifically?","What data they use and retain, whether customer data trains their models, which model and cloud providers they rely on, how they test outputs for accuracy and bias, how incidents are reported and what audit and access rights the bank gets.",{"question":197,"answer":198},"Who uses AI for due diligence today?","Government buyers publish the clearest examples in their AI inventories: the US Department of Justice has used Exiger's AI platform since 2023 to build vendor risk profiles that inform acquisition decisions, USDA uses an AI search tool for supplier responsibility checks and the IRS pilots machine learning to flag contractors at risk of poor performance.",[200,201,202,203,204],"procurement-contract-review","continuous-controls-testing","ai-model-inventory","pep-and-adverse-media-screening","business-onboarding-and-ubo-discovery","2026-09-27",[207],{"date":205,"note":208},"First published","vendor-due-diligence",[211,241,263,284],{"title":212,"useCases":213,"organization":214,"vendors":218,"summary":222,"stage":223,"year":44,"channels":224,"languages":225,"metrics":227,"outcomeDisclosed":216,"sources":228,"verification":236,"grade":238,"id":239,"organizationSlug":240},"USDA: ProcureSight for market research and supplier responsibility checks",[209],{"name":215,"anonymized":216,"country":217,"region":171,"industry":21},"U.S. Department of Agriculture",false,"US",[219],{"name":220,"role":221},"ProcureSight","platform","Since October 2024 USDA has used ProcureSight, a free AI search tool over public SAM.gov and USASpending data, to assist with market research and with responsibility determinations on prospective suppliers. The department expects higher procurement productivity from precise searches over public procurement data. No outcome figures are published.","production",[33],[226],"en",[],[229,233],{"url":230,"title":231,"publisher":232},"https://github.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory","2025 Federal Agency AI Use Case Inventory","Office of Management and Budget (GitHub)",{"url":234,"title":235,"publisher":232},"https://raw.githubusercontent.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory/main/Data/2025_individually_reported_AI_use_cases.csv","2025 individually reported AI use cases (entry USDA-097, ProcureSight)",{"level":237,"checkedAt":205},"source-verified","B","usda-procuresight-responsibility-determination","u-s-department-of-agriculture",{"title":242,"useCases":243,"organization":244,"vendors":246,"summary":249,"stage":223,"year":44,"channels":250,"languages":251,"metrics":252,"outcomeDisclosed":216,"sources":253,"verification":260,"grade":238,"id":261,"organizationSlug":262},"USTDA: AI assisted due diligence research on prospective partners",[209],{"name":245,"anonymized":216,"country":217,"region":171,"industry":21},"U.S. Trade and Development Agency",[247],{"name":248,"role":221},"Exiger","In its 2024 AI inventory the US Trade and Development Agency reports that, since May 2024, Exiger's analysts have used Exiger's DDIQ research software for due diligence on individuals and companies under consideration for partnership with the agency. The AI reviews and consolidates publicly available information such as news reports, and Exiger's due diligence and research professionals review, refine and analyse the result. It is a managed service model: the AI makes the research more efficient while analysts do the assessment. The entry does not appear in the 2025 inventory, and no outcome figures are published.",[33],[226],[],[254,257],{"url":255,"title":256,"publisher":232},"https://github.com/ombegov/2024-Federal-AI-Use-Case-Inventory","2024 Federal Agency AI Use Case Inventory",{"url":258,"title":259,"publisher":232},"https://raw.githubusercontent.com/ombegov/2024-Federal-AI-Use-Case-Inventory/main/data/2024_consolidated_ai_inventory_raw_v2.csv","2024 consolidated AI inventory (USTDA entry Exiger Due Diligence IQ Research Software)",{"level":237,"checkedAt":205},"ustda-exiger-partner-due-diligence",null,{"title":264,"useCases":265,"organization":266,"vendors":268,"summary":270,"stage":223,"year":271,"channels":272,"languages":273,"metrics":274,"outcomeDisclosed":216,"sources":275,"verification":281,"grade":238,"id":282,"organizationSlug":283},"US Department of Justice: AI vendor risk profiles for supply chain risk management",[209],{"name":267,"anonymized":216,"country":217,"region":171,"industry":21},"U.S. Department of Justice",[269],{"name":248,"role":221},"Since September 2023 the Justice Management Division has used Exiger's DDIQ platform to run supply chain risk management assessments. The AI continuously ingests sources such as news articles, legal filings and public records and returns vendor profiles (corporate records, beneficial owners, sanctions lists, adverse media, litigation history, financial stability and supply chain relationships), risk dashboards and risk scores for foreign ownership, control or influence, reputational, criminal and regulatory issues and financial health. The department uses the output to decide whether to move forward with the acquisition of goods or services. No outcome figures are published.",2023,[33],[226],[],[276,277,279],{"url":230,"title":231,"publisher":232},{"url":234,"title":278,"publisher":232},"2025 individually reported AI use cases (entries DOJ-0174 and DOJ-0175, Exiger Supply Chain Risk Management)",{"url":258,"title":280,"publisher":232},"2024 consolidated AI inventory (DOJ entries Exiger Supply Chain Risk Management)",{"level":237,"checkedAt":205},"doj-exiger-supply-chain-risk-management","u-s-department-of-justice",{"title":285,"useCases":286,"organization":287,"vendors":289,"summary":290,"stage":291,"year":292,"channels":293,"languages":294,"metrics":295,"outcomeDisclosed":216,"sources":296,"verification":300,"grade":238,"id":301,"organizationSlug":302},"IRS: machine learning to predict contractor performance risk (pilot)",[209],{"name":288,"anonymized":216,"country":217,"region":171,"industry":21},"Internal Revenue Service",[],"The IRS reports a pilot, with a 2019 operational date, that researches supervised learning methods to assess contractor responsibility and predict whether a prospective vendor would perform successfully, identifying vendors at heightened risk of poor performance or non compliance. The models are trained on contractor and contract data from SAM.gov and USASpending.gov, and the risk assessments are delivered as spreadsheets or dashboards. The AI only recommends: contracting decisions go through several layers of review by agency officials. The seminal research and model training were done by IRS and US Navy personnel. It remains a pilot and no outcome figures are published.","pilot",2019,[33],[226],[],[297,298],{"url":230,"title":231,"publisher":232},{"url":234,"title":299,"publisher":232},"2025 individually reported AI use cases (entry TREAS-IRS-9, Vendor Risk Analytics)",{"level":237,"checkedAt":205},"irs-vendor-risk-analytics","internal-revenue-service",0,[],{"low":306,"high":307},48000,440000,[309,328,347,360,389],{"slug":200,"title":310,"shortTitle":311,"definition":312,"status":9,"industries":313,"functions":316,"patterns":319,"audience":34,"autonomy":35,"adoptionStage":36,"evidenceCount":321,"publicEvidenceCount":322,"organizations":323,"bestGrade":238,"headline":262,"lastVerified":205,"indexable":327},"AI assistant for procurement and supplier contract review","Procurement and contract review","An assistant for procurement and vendor management that reads supplier contracts and proposals, extracts the key terms, flags deviations from the organization's standard positions, drafts requests for proposal and evaluation matrices, and prepares negotiation positions, with a procurement or legal owner approving every conclusion.",[18,19,21,314,315],"retail-and-ecommerce","manufacturing",[24,317,318],"legal","finance-and-accounting",[28,29,320,30],"content-generation",6,5,[324,325,288,326],"General Services Administration","Administration for Children and Families","Walmart",true,{"slug":201,"title":329,"shortTitle":330,"definition":331,"status":9,"industries":332,"functions":334,"patterns":336,"audience":339,"autonomy":340,"adoptionStage":341,"segment":37,"evidenceCount":342,"publicEvidenceCount":342,"organizations":343,"bestGrade":238,"headline":262,"lastVerified":205,"indexable":327},"AI for continuous controls testing and control self assessment","Continuous controls testing","AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.",[18,19,20,333,21],"capital-markets",[25,26,335],"operations",[30,28,337,338],"anomaly-detection","classification-and-routing","back-office","supervised-agent","emerging",3,[344,345,346],"Federal Deposit Insurance Corporation","U.S. Department of the Interior","Pension Benefit Guaranty Corporation",{"slug":202,"title":348,"shortTitle":349,"definition":350,"status":9,"industries":351,"functions":352,"patterns":354,"audience":34,"autonomy":35,"adoptionStage":36,"evidenceCount":355,"publicEvidenceCount":355,"organizations":356,"bestGrade":238,"headline":262,"lastVerified":205,"indexable":327},"AI system and model inventory with shadow AI discovery","AI model inventory","A governed register of every AI system and model an organization builds, buys or uses, with its owner, purpose, data, risk tier and approval status, kept current by AI that discovers unregistered use, reads the documentation and assembles the evidence a board, auditor or supervisor asks for.",[18,19,20,21,315],[25,26,353],"it-and-engineering",[30,28,29,338],4,[357,358,359,267],"Board of Governors of the Federal Reserve System","Office of Management and Budget","Unilever",{"slug":203,"title":361,"shortTitle":362,"definition":363,"status":9,"industries":364,"functions":366,"patterns":369,"audience":34,"autonomy":35,"adoptionStage":36,"segment":371,"evidenceCount":372,"publicEvidenceCount":372,"organizations":373,"bestGrade":238,"headline":381,"lastVerified":205,"indexable":327},"AI for PEP and adverse media screening","PEP and adverse media screening","AI that continuously scans news, court records, registries and other open sources in many languages for negative information and political exposure linked to customers, counterparties and beneficial owners, discards look alikes, and summarises credible risk for the analyst with the sources attached.",[19,22,365],"wealth-and-asset-management",[367,368],"financial-crime-compliance","onboarding-and-kyc",[29,31,338,370],"translation","middle-office",7,[374,375,376,377,378,379,380],"Deutsche Bank","HSBC","Mashreq","OCBC","Santander UK","Save the Children","Scotiabank",{"kpi":382,"label":383,"unit":384,"n":385,"nUpTo":385,"kind":386,"value":84,"qualifier":387,"claimant":388,"organization":379,"vendorReported":327},"handling-time-reduction","Handling time reduction","percent",1,"reported","at-least","vendor",{"slug":204,"title":390,"shortTitle":391,"definition":392,"status":9,"industries":393,"functions":394,"patterns":395,"audience":339,"autonomy":340,"adoptionStage":341,"segment":396,"evidenceCount":342,"publicEvidenceCount":342,"organizations":397,"bestGrade":401,"headline":402,"lastVerified":205,"indexable":327},"AI for business onboarding (KYB) and beneficial ownership discovery","Business onboarding and UBO","An AI agent that builds the know your business (KYB) due diligence file for a new or reviewed corporate client, before any account is opened: it collects registry, incorporation and ownership documents, resolves the entity across sources, maps the ownership chain through holding companies, nominees and trusts to the ultimate beneficial owners, screens the entity and its owners, and presents a risk scored case for a compliance analyst to decide.",[19,22,333],[368,367],[28,30,338,31],"specialized-businesses",[398,399,400],"BNY","Incore Bank","M-DAQ Global","C",{"kpi":403,"label":404,"unit":384,"n":385,"nUpTo":303,"kind":386,"value":405,"qualifier":406,"claimant":407,"organization":398,"vendorReported":216},"automation-rate","Automation rate",25,"exact","organization",{"indexable":327,"reasons":409},[],[411,417,422,428,434,439,446,453,460,463,469,475,482,489,495,499,506,512,518,524,530,536,542,547,552,558,564,569,574,581,587,593,599,604],{"id":156,"label":412,"issuer":413,"region":165,"url":414,"description":415,"useCases":416,"indexable":327},"EU AI Act","European Union","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":157,"label":418,"issuer":413,"region":165,"url":419,"description":420,"useCases":421,"indexable":327},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":158,"label":423,"issuer":424,"region":425,"url":426,"description":427,"useCases":85,"indexable":327},"ISO/IEC 42001","ISO and IEC","global","https://www.iso.org/standard/81230.html","The international management system standard for AI.",{"id":159,"label":429,"issuer":430,"region":171,"url":431,"description":432,"useCases":433,"indexable":327},"NIST AI Risk Management Framework","NIST","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":154,"label":435,"issuer":413,"region":165,"url":436,"description":437,"useCases":438,"indexable":327},"DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":440,"label":441,"issuer":442,"region":165,"url":443,"description":444,"useCases":445,"indexable":327},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":447,"label":448,"issuer":449,"region":165,"url":450,"description":451,"useCases":452,"indexable":327},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":454,"label":455,"issuer":456,"region":177,"url":457,"description":458,"useCases":459,"indexable":327},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":155,"label":461,"issuer":176,"region":177,"url":178,"description":462,"useCases":405,"indexable":327},"APRA CPS 230","Australian operational risk standard covering critical operations and material service providers.",{"id":464,"label":465,"issuer":466,"region":425,"url":467,"description":468,"useCases":71,"indexable":327},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",{"id":470,"label":471,"issuer":472,"region":171,"url":473,"description":474,"useCases":71,"indexable":327},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":476,"label":477,"issuer":478,"region":165,"url":479,"description":480,"useCases":481,"indexable":327},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":483,"label":484,"issuer":485,"region":425,"url":486,"description":487,"useCases":488,"indexable":327},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":490,"label":491,"issuer":413,"region":165,"url":492,"description":493,"useCases":494,"indexable":327},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":160,"label":496,"issuer":413,"region":165,"url":497,"description":498,"useCases":494,"indexable":327},"NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":500,"label":501,"issuer":502,"region":171,"url":503,"description":504,"useCases":505,"indexable":327},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":507,"label":508,"issuer":413,"region":165,"url":509,"description":510,"useCases":511,"indexable":327},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":513,"label":514,"issuer":515,"region":171,"url":516,"description":517,"useCases":511,"indexable":327},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":519,"label":520,"issuer":521,"region":425,"url":522,"description":523,"useCases":511,"indexable":327},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":525,"label":526,"issuer":413,"region":165,"url":527,"description":528,"useCases":529,"indexable":327},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":531,"label":532,"issuer":533,"region":171,"url":534,"description":535,"useCases":529,"indexable":327},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":537,"label":538,"issuer":456,"region":177,"url":539,"description":540,"useCases":541,"indexable":327},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",10,{"id":543,"label":544,"issuer":413,"region":165,"url":545,"description":546,"useCases":541,"indexable":327},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":548,"label":549,"issuer":413,"region":165,"url":550,"description":551,"useCases":541,"indexable":327},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":553,"label":554,"issuer":164,"region":165,"url":555,"description":556,"useCases":557,"indexable":327},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":559,"label":560,"issuer":561,"region":171,"url":562,"description":563,"useCases":70,"indexable":327},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",{"id":565,"label":566,"issuer":413,"region":165,"url":567,"description":568,"useCases":70,"indexable":327},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":570,"label":571,"issuer":413,"region":165,"url":572,"description":573,"useCases":321,"indexable":327},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",{"id":575,"label":576,"issuer":577,"region":578,"url":579,"description":580,"useCases":322,"indexable":327},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":582,"label":583,"issuer":584,"region":165,"url":585,"description":586,"useCases":355,"indexable":327},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":588,"label":589,"issuer":590,"region":165,"url":591,"description":592,"useCases":355,"indexable":327},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":594,"label":595,"issuer":596,"region":177,"url":597,"description":598,"useCases":342,"indexable":327},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":600,"label":601,"issuer":413,"region":165,"url":602,"description":603,"useCases":342,"indexable":327},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":605,"label":606,"issuer":607,"region":171,"url":608,"description":609,"useCases":342,"indexable":327},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598302137]