The Key 4 AIDifferent regulators, one sentence
Banking, medicine, energy, road, air, insurance, and the horizontal laws above them all: every serious regulator is converging on the same demand. Prove what your model does. In their words:
- 2011Federal Reserve and OCCSR 11-7 / OCC 2011-12, model risk management guidance
"Also, organizations should maintain an inventory of models implemented for use, under development for implementation, or recently retired."
- 2021FDA, Health Canada, MHRAGood Machine Learning Practice, guiding principles (GMLP)
"Deployed models have the capability to be monitored in 'real world' use with a focus on maintained or improved safety and performance."
Guiding principle 10; IMDRF final version January 2025.
- 2022Central Bank of the UAEModel Management Standards, Notice 5052/2022
"Institutions must maintain a comprehensive inventory of all their models employed in production to support decision-making."
- 2023NISTAI Risk Management Framework 1.0
"Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities."
- 2023Bank of England, PRASS1/23, model risk management principles
"A comprehensive model inventory should be maintained to enable firms to: identify the sources of model risk; provide the management information needed for reporting model risk; and help to identify model inter-dependencies."
May 2023 text; amended April 2026.
- 2023NAICModel Bulletin, use of AI systems by insurers
"Regardless of the existence or scope of a written AIS Program, in the context of an investigation or market conduct action, an Insurer can expect to be asked about its development, deployment, and use of AI Systems."
Model bulletin, as adopted by state insurance departments.
- 2023ISO/IEC42001:2023, AI management systems
"ISO/IEC 42001 is an international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within organizations."
Publisher's abstract; standard text is paywalled.
- 2024European UnionRegulation (EU) 2024/1689, the AI Act
"High-risk AI systems shall be designed and developed in such a way as to ensure that their operation is sufficiently transparent to enable deployers to interpret a system's output and use it appropriately."
- 2024ISO/PAS8800:2024, AI safety in road vehicles
"This document describes safety-related properties of AI systems that can be used to construct a convincing safety assurance claim for the absence of unreasonable risk."
Publisher's abstract; standard text is paywalled.
- 2025Monetary Authority of SingaporeConsultation paper, AI risk management guidelines
"MAS proposes that FIs establish and maintain an accurate and up-to-date inventory of AI use cases, systems or models to support governance and oversight, as well as risk management throughout the AI lifecycle."
Consultation, closed January 2026.
- 2026Reserve Bank of IndiaDraft guidance, model risk management principles
"It should ensure that no model is used, relied upon, or deployed unless it is part of inventory."
Draft, comments closed July 2026.
- 2026EASAConcept paper, AI applications guidance
"Explainability is a key property that any safety-related AI-based system should possess."
Proposed Issue 03, under consultation.
- 2026Central Electricity AuthorityCyber Security in Power Sector Regulations, 2026
"maintain asset register- (a) for all cyber assets along with the requisite details including ownership, hardware, firmware, software, and patch as per the procedure defined in Cyber Security Policy".
Closest sentence; the regulations do not mention models.
Thirteen documents, five continents, one sentence. Sourced from the primary text; statuses stated as they are.
The Ledger
- HeldEvery regulator we quote is quoted from its primary text, with its status stated.
Thirteen entries; two are drafts, one a consultation, one a proposed issue, two publisher's abstracts.
One address