In-house counsel in corporate banking touch CPMI's d224 framework at a small number of points: the change-of-law clause in correspondent-banking service agreements, the stakeholder-obligation mapping that drives vendor-impact memos, and the occasional board-level question on jurisdictional payments-rail risk. The CPMI text itself never reads as live obligation, but it routes into those deliverables through specific assertions: which central bank is a named pilot partner, and which stakeholder a given recommendation actually binds. The two AI failures that surfaced on this regulation land squarely on those two assertions.
Opus 4.7 denied the SARB pre-validation partnership that CPMI Brief No. 9 (November 2025) names, and Opus 4.7 returned a stakeholder taxonomy for d224's 10 recommendations built off category labels rather than the recommendation text. Both errors are the kind a legal reviewer would normally catch on a primary-source read, and both shipped clean past the AI's surface confidence.
What the AI got wrong, and why it matters here
Both failures share the same upstream gap: Opus 4.7 did not access the primary CPMI text in the path that produced the answer, and instead synthesised an answer that reads like a clean legal summary. The product of the failure is a sentence in a memo, not a transparently flagged retrieval gap.
Finding 1: SARB pre-validation partnership denied
Opus 4.7 was asked which central banks are actively involved in piloting or implementing specific API harmonisation recommendations, and whether any central bank is specifically partnered with CPMI on the pre-validation track. It answered that it is plausible SARB is engaged with the d224 implementation track but that there is no public CPMI statement naming SARB as the specific partner on the pre-validation API recommendation. CPMI Brief No. 9 (November 2025) names SARB outright as the partner on the pre-validation API recommendation.
Quoted into a change-of-law memo on a South-Africa-touching correspondent relationship, the answer creates an avoidable misalignment with what the regulator has actually said in print.
Citation: RLB-H-INT-BIS-CPMI-API-HARMONISATION-CROSS-BORDER-2024-Q007-Opus47.
Finding 2: Invented stakeholder taxonomy for the 10 recommendations
Opus 4.7 was asked which of d224's 10 recommendations specifically target commercial banks or correspondent banks, which target payment-system operators, and which target central banks. It returned a clean structured taxonomy. The taxonomy is reconstructed from category labels (facilitative / global harmonisation processes) and from the AI's general prior on who participates in API standards work; it is not extracted from the recommendation text. A vendor-impact assessment or affiliate-scoping memo that cites the taxonomy commits the bank to obligation routing that the d224 text itself does not establish.
Citation: RLB-H-INT-BIS-CPMI-API-HARMONISATION-CROSS-BORDER-2024-Q008-Opus47.
When this hits the legal calendar
Counsel touches CPMI material on three recurring legal-work items: change-of-law clause drafting in inter-bank service agreements, vendor-impact assessments that map who an obligation binds, and the board's occasional jurisdictional-risk question on cross-border payments innovation.
| Standing item | Where the AI risk surfaces | Failure mode |
|---|---|---|
| Change-of-law clause drafting for correspondent agreements | Naming central-bank pilot partners and live regulator workstreams | Finding 1: denied SARB partnership |
| Vendor-impact assessment on cross-border payments work | Mapping the 10 d224 recommendations to bound stakeholders | Finding 2: fabricated taxonomy |
| Board-level jurisdictional risk memo | Both | Both findings |
Aggregate impact on the team
The two errors do not stack to a worst-case for legal; they each independently corrupt a single legal deliverable. The audit-trail and disclosure consequences are larger than the operational impact.
| Risk Impact | Count | Affected findings |
|---|---|---|
| 0 | ||
| 0 |
What this team should do
Treat any AI output naming a CPMI pilot partner or producing a d224 stakeholder mapping as draft material requiring verification against the relevant primary CPMI text before it enters a contractual memo, vendor-impact assessment or board appendix.
Detection patterns to add to AI-review
- Pilot-partner naming must be verified against the CPMI Brief number cited, not against the AI's summary.
- Stakeholder-to-recommendation mappings on d224 must be verified against the recommendation text headings, not against category labels.
- Any AI assertion about a specific implementation track for a named jurisdiction should be cross-checked against the most recent CPMI Brief on cross-border payments.
How RLB can help
RLB tracks AI failure patterns across d224 and the CPMI brief series and refreshes the catalogue against the live AI subjects on rotation. In-house counsel can wire the catalogue into the standing AI-draft review step so these two failure shapes are caught at the draft stage, before the language ships into a contractual memo, vendor-impact assessment or board paper.
