AI Hallucination ResearchFindings by audienceSectorsInternational / MultilateralCorporate BankingCompliance › Promoting the Harmonisation of Application Programming Interfaces to Enhance Cross-Border Payments: Recommendations and Toolkit
Corporate Banking × Compliance — International / Multilateral · Last updated 11 Jun 2026 · methodology v2.3 · Hallucination Register
Share / Print X LinkedIn Email

AI Hallucination on Promoting the Harmonisation of Application Programming Interfaces to Enhance Cross-Border Payments: Recommendations and Toolkit for Compliance teams at Corporate Banking firms in international jurisdictions

Corporate Banking Compliance teams: documentation and reporting gaps possible from AI reading of CPMI Cross-Border API Harmonisation 2024

Compliance officers at corporate banks operating cross-border payments rails on the CPMI API harmonisation programme are increasingly relying on AI to update onboarding checklists for new correspondent counterparties, generate trade-monitoring rule bulletins on the SARB pre-validation workstream, update sanctions and AML programme appendices on the 10 CPMI recommendations, draft board-level horizon-scan papers, and verify ISO 20022 address-format commitments against regulator-issued source text. The RLB Specialist Panel tested how that AI usage performs against the regulator's own primary text on CPMI's October 2024 d224 report and the related CPMI Brief and speech series.

The audit surfaced four substantive failure modes that the AI subjects delivered with regulator-fluent confidence.

Confident Denial, Stakeholder Taxonomy Fabrication and Fabricated Date-and-Format Commitment on CPMI API Harmonisation for Cross-Border Payments. Two frontier AI models tested by the RLB Specialist Panel returned confident, citable answers across the panel's CPMI substrate-bound question set on the October 2024 d224 report and the related CPMI Brief and speech series. The panel binds each AI finding to verbatim regulator-issued source text held as primary substrate.

Across the 3 findings in this Compliance teams at Corporate Banking firms briefing, the AI subjects denied that any pilot partner has been named for the CPMI pre-validation API recommendation; built a recommendation-by-recommendation stakeholder breakdown from category names rather than the regulator's actual recommendation text; introduced a specific November 2026 cutover commitment for structured ISO 20022 addresses that does not appear in the regulator's text.

A regulatory horizon scan that records 'no jurisdictional partner identified' on the CPMI pre-validation workstream when SARB is in fact the named partner is now a verifiable factual error on a supervisory deliverable. A November 2026 structured-ISO-20022-address cutover commitment that appears in a board paper as a CPMI mandate is a fabricated mandate quoted as if regulator-issued. A correspondent-banking stakeholder taxonomy lifted from AI output and pasted into the firm's scoping document carries fabricated assignments forward.

The next FCA, OCC or MAS examiner spot-check on AI use in compliance reads the memo, runs the same query, and the factual gap becomes a documented control finding.

The findings are published with immutable RLB Citation IDs: RLB-H-INT-BIS-CPMI-API-HARMONISATION-CROSS-BORDER-2024-Q007-Sonnet46, RLB-H-INT-BIS-CPMI-API-HARMONISATION-CROSS-BORDER-2024-Q008-Opus47, RLB-H-INT-BIS-CPMI-API-HARMONISATION-CROSS-BORDER-2024-Q009-Sonnet46. The full audit is published at the CPMI API Harmonisation for Cross-Border Payments hub on RegLegBrief.com.

Sanctions and AML monitoring desks inside large corporate banks read CPMI's d224 API harmonisation framework not for its standards content but for what it changes about pre-validation, beneficiary-address quality and the small set of central banks running live cross-border pilots. Those three hooks drop straight into the periodic horizon scan, the correspondent-banking due diligence pack and the board-level technology-risk update.

Across the six AI-generated answers tested against d224 and its adjacent CPMI briefs, three were confidently wrong on exactly those hooks: the SARB pre-validation partnership was denied (CPMI Brief No. 9 names it), the per-recommendation stakeholder table was invented off category labels rather than the regulator text, and a November 2026 structured-address phase-out was manufactured against the February 2026 ISO 20022 update. Each of those failures lands inside a deliverable a compliance team is already expected to produce, with no surface signal to the reviewer that the underlying retrieval never happened.

The pattern matters more than any one error: every one was a confident answer on a regulatory-source detail the AI could not actually retrieve.

What the AI got wrong, and why it matters here

Across these three failures the same control gap repeats: the AI did not flag that the primary CPMI document was out of reach, and instead reconstructed an answer from category names, default standard-setter membership and industry chatter about CBPR+ timelines. A compliance review that does not have an independent verification step against the regulator text will not see the gap.

Finding 1: SARB pre-validation pilot denied

Sonnet 4.6 was asked which central bank is explicitly named as the CPMI collaborator on the payment pre-validation API recommendation. It denied that any pilot partner has been named. CPMI Brief No. 9 (November 2025) states plainly that CPMI, in collaboration with the South African Reserve Bank, has been advancing the pre-validation API recommendation by interviewing market stakeholders. A clean factual denial of a named regulator-bilateral workstream is a hard miss inside a horizon-scan deliverable that supervisors may later read alongside the brief itself.

Citation: RLB-H-INT-BIS-CPMI-API-HARMONISATION-CROSS-BORDER-2024-Q007-Sonnet46.

Finding 2: Invented stakeholder taxonomy for the 10 recommendations

Opus 4.7 was asked which of d224's 10 recommendations target commercial banks, which target payment-system operators, which target central banks and so on. It returned a clean taxonomy naming ISO, BIAN, SWIFT, payment-system operators and others against specific recommendation groupings. None of that assignment is from the d224 text; it is reconstructed from category labels and the AI's general prior on API standards work. A compliance applicability matrix built on that taxonomy will misroute internal scoping work and will not survive an external review against the primary recommendation text.

Citation: RLB-H-INT-BIS-CPMI-API-HARMONISATION-CROSS-BORDER-2024-Q008-Opus47.

Finding 3: Fabricated November 2026 structured-address mandate

Sonnet 4.6 was asked what changed in the February 2026 update to d230 (harmonised ISO 20022 data requirements). It committed to a specific cutover, from November 2026 only structured or hybrid addresses will be permitted in ISO 20022 cross-border payment messages, and framed the line as drawn from the updated CPMI document. The d230 document text describes only generalised standardisation and regulatory developments since 2023 and a separate technical annex; the November 2026 cutover does not appear in the regulator's text.

Quoted into a correspondent-bank readiness memo or a SWIFT/CBPR+ briefing, the line asserts a mandate that the regulator did not document.

Citation: RLB-H-INT-BIS-CPMI-API-HARMONISATION-CROSS-BORDER-2024-Q009-Sonnet46.

When this hits the compliance calendar

Three points in the standing compliance calendar pull from CPMI work directly: the quarterly cross-border-payments horizon scan, the correspondent-bank annual due diligence refresh, and the ad hoc questions that come up when transaction monitoring trips an ISO 20022 address-quality alert.

Standing item Where the AI risk surfaces Failure mode
Quarterly cross-border payments horizon scan Naming live regulator pilots, especially South Africa Finding 1: denied SARB partnership
Correspondent-bank annual due diligence refresh Per-recommendation stakeholder mapping Finding 2: fabricated taxonomy
ISO 20022 address-quality alert response Commitments on structured-address cutover dates Finding 3: invented November 2026 deadline

Aggregate impact on the team

Three findings, three different deliverables, one root cause: AI confidence on regulatory-source detail without underlying retrieval. For sanctions and AML monitoring in a corporate bank, the failure surface is the audit trail itself.

Risk ImpactCountAffected findings
0
0

What this team should do

Add a regulator-source verification step to every AI-drafted CPMI summary that names a central-bank pilot partner, a per-recommendation stakeholder assignment, or an ISO 20022 cutover date. Treat those three answer shapes as controlled outputs requiring a human spot-check against the primary CPMI text, not the AI's synthesised paragraph.

Detection patterns to add to AI-review

  • Any AI output naming a specific central bank as a CPMI pilot partner must be verified against the relevant CPMI Brief (numbered series).
  • Any AI output presenting a stakeholder-to-recommendation table for d224 must be cross-checked against the recommendation text itself, not the category headings.
  • Any AI output asserting a specific date for an ISO 20022 format change must be verified against the d230 source text, not a SWIFT or CBPR+ industry summary.

How RLB can help

RLB maintains the failure-pattern catalogue against d224, d230 and the CPMI brief/speech series, refreshed against the live AI subjects on rotation. Compliance teams operating cross-border payment lines can wire the catalogue into the standing AI-output review step, so the three failure shapes above are flagged before they enter a controlled deliverable.

Every finding on this page compares an AI subject's account of the rule against the regulator's verbatim text from the regulator's own portal. Both are linked. Each delta, its root causes, and impact analysis are documented and published with immutable Citation IDs.