AI Hallucination ResearchAudiencesSectorsInternational / MultilateralCorporate BankingComplianceDetail › Finding
Corporate Banking × Compliance — International / Multilateral · published 2026-05-28 · methodology v2.1

Definitional consistency between the 2016 Cyber Guidance and the FSB Cyber Lexicon

RLB-F-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q020
What the RLB Specialist Panel found

1. Definitional consistency between the 2016 Cyber Guidance and the FSB Cyber Lexicon

  • Question (paraphrased to protect IP): How does the CPMI-IOSCO 2016 Cyber Guidance define 'cyber resilience', and is that definition consistent with the FSB Cyber Lexicon published in November 2018?
  • Source regulation: Guidance on Cyber Resilience for Financial Market Infrastructures (CPMI-IOSCO 2016) (Regulator portal: https://www.bis.org)
  • What AI assistants typically say: Multiple AI tools gave similar incorrect responses, asserting that the two definitions are "broadly consistent" or "aligned" — and in some instances claiming the FSB Cyber Lexicon explicitly drew on and refined the CPMI-IOSCO 2016 definition, presenting the relationship between the two documents as an established, harmonised derivation.
  • What the regulator actually says: The FSB Cyber Lexicon was published in November 2018 — two years after the 2016 Cyber Resilience Guidance. Its standardised definitions postdate the 2016 guidance and may not match how the 2016 guidance used those terms in 2016.
  • Why the AI went wrong: AI tools resolved an explicitly uncertain relationship into a confident assertion of consistency, dropping the qualifier that the two documents' definitions may not align. One AI tool went further and fabricated a specific derivation claim — that the FSB Lexicon drew on the CPMI-IOSCO definition — for which no authoritative basis exists.
  • Cited source(s):
Impact for this audience

A Corporate Banking Compliance team relying on AI tools' assertion of definitional consistency between the 2016 Cyber Guidance and the FSB Cyber Lexicon may build internal policy frameworks, third-party due-diligence assessments, or regulatory mapping documents that treat the two standards as harmonised when the authoritative position is that their relationship is uncertain. If a supervisor or external auditor applies the correct, unresolved reading and finds the firm's documentation assumes alignment it cannot substantiate, the firm faces remediation of affected policies, potential regulatory scrutiny of its cyber governance framework, and the reputational cost of having relied on an AI-generated account of a definitional relationship that was never confirmed.

References — raw findings (per AI model)
This finding also affects
Next finding → Finding 2. Currency of the CPMI-IOSCO 2016 Cyber Resilience Guidance
Cite this finding

Each finding has a stable Citation ID (RLB-F-… for aggregated case-study findings, RLB-H-… for raw per-model hallucinations) — like a DOI, the ID always resolves to the canonical finding even if URLs change.

Plain text
RegLeg Specialist Panel (2026). "Definitional consistency between the 2016 Cyber Guidance and the FSB Cyber Lexicon — Corporate Banking × Compliance — International / Multilateral." Citation ID: RLB-F-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q020. RegLegBrief AI Hallucination Research, published 2026-05-28. https://reglegbrief.com/audiences/sectors/int/corporate_banking/compliance/finding/INT-BIS-CPMI-INT-001-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-v1-020/
APA 7th edition
RegLeg Specialist Panel. (2026). Definitional consistency between the 2016 Cyber Guidance and the FSB Cyber Lexicon [Hallucination finding RLB-F-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q020]. RegLegBrief AI Hallucination Research. https://reglegbrief.com/audiences/sectors/int/corporate_banking/compliance/finding/INT-BIS-CPMI-INT-001-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-v1-020/
Bluebook / OSCOLA (US + UK legal)
RegLeg Specialist Panel, Definitional consistency between the 2016 Cyber Guidance and the FSB Cyber Lexicon [RLB-F-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q020], RegLegBrief AI Hallucination Research (May 28, 2026), https://reglegbrief.com/audiences/sectors/int/corporate_banking/compliance/finding/INT-BIS-CPMI-INT-001-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-v1-020/.
BibTeX
@misc{reglegbrief_RLB_F_INT_BIS_CPMI_IOSCO_CYBER_RESILIENCE_FMI_2016_Q020,
  author    = {RegLeg Specialist Panel},
  title     = {Definitional consistency between the 2016 Cyber Guidance and the FSB Cyber Lexicon},
  year      = {2026},
  publisher = {RegLegBrief AI Hallucination Research},
  note      = {Hallucination finding Citation ID: RLB-F-INT-BIS-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-Q020},
  url       = {https://reglegbrief.com/audiences/sectors/int/corporate_banking/compliance/finding/INT-BIS-CPMI-INT-001-CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016-v1-020/}
}
← Back to case study summary Case study detail →