← RegLegBrief Findings by regulator All AI Labs whitepapers Hallucination Register Methodology Right of reply
$ rlb-eval --regulation CPMI-IOSCO-CYBER-2016 --model claude-opus-4.7 --web-search enabled
AI Labs · White Paper · BIS-CPMI · INT · substrate v1

CPMI-IOSCO Cyber Resilience 2016
— Hallucination Findings

// The international cyber standard for financial market infrastructures. Evaluation of AI model responses against the CPMI-IOSCO Guidance on Cyber Resilience for FMIs (2016). Multiple failure modes documented across frontier configurations.

DATE: 2026-06-07 METHODOLOGY: v2.3 SUBSTRATE: CPMI-IOSCO-CYBER-2016
Read the public briefing for this regulation
The standard

CPMI-IOSCO 2016 — the FMI cyber baseline

The CPMI-IOSCO Guidance on Cyber Resilience for Financial Market Infrastructures (June 2016) is the global baseline for cyber resilience at systemically important payment systems, CCPs, and securities settlement systems. Central banks and market supervisors worldwide use it. It covers governance, identification, protection, detection, response and recovery, testing, and situational awareness. It is a principles-based framework, not a compliance checklist.

The Guidance supplements the PFMI by providing specific cyber resilience expectations for FMIs. It has been implemented by supervisors across over 30 jurisdictions and is the document that compliance teams, FMI boards, and financial cyber regulators treat as the authoritative international baseline.

rlb@eval:~$ cat CPMI-IOSCO-CYBER-2016/metadata.json
{"issuer":"CPMI-IOSCO","year":2016,"type":"Guidance","scope":"Financial Market Infrastructures",
"covers":["governance","identification","protection","detection","response_recovery","testing","situational_awareness"],
"supplements":"PFMI","jurisdictions_implemented":"30+","status":"International_baseline"}
rlb@eval:~$ run-eval --model claude-opus-4.7 --questions CYBER-Q-SET-1
FINDING: Multiple hallucinations detected across question set
FINDING: Attribution errors on component scope
FINDING: Recovery time objective specifications incorrect
Binding to authenticated primary substrate: CPMI-IOSCO-CYBER-2016
Failure patterns documented

What the models got wrong and how

The RLB Specialist Panel's evaluation of frontier AI models against the 2016 Guidance found failures concentrated in three areas: the scope of the guidance and which FMI types it covers, specific technical parameters within the guidance including recovery time objective specifications, and attribution errors where model outputs assigned guidance provisions to the wrong component of the framework.

The guidance is a 2016 document that has accumulated significant secondary commentary, supervisory implementation notes, and follow-on CPMI-IOSCO publications. Models with web search active appeared to blend content from these secondary sources with the primary guidance text, producing composite answers that partially reflect the original guidance and partially reflect later commentary or national implementation documents.

Scope attribution errors
Model outputs mis-scoped which FMI types the 2016 Guidance applies to, in some cases extending it to entity types outside the CPMI-IOSCO FMI definition and in others narrowing it incorrectly.
Actual scope (2016 Guidance)
The 2016 Guidance applies to FMIs as defined in the PFMI: systemically important payment systems, central counterparties (CCPs), central securities depositories (CSDs), and securities settlement systems (SSSs).
RTO specifications
Recovery time objective parameters in model outputs diverged from the specific expectations in the 2016 Guidance text, with models producing figures that appear to draw from later national implementation guidance rather than the 2016 CPMI-IOSCO document.
Correct source
RTO expectations in the context of this audit are bound to the CPMI-IOSCO 2016 Guidance text. Later national implementation notes that modify or elaborate those expectations are distinct documents and should not be blended into citations of the 2016 Guidance itself.
CYBER GUIDANCE SOURCE BLENDING — MODEL FAILURE MAP PRIMARY SOURCE CPMI-IOSCO 2016 Guidance on Cyber Resilience for FMIs SECONDARY National implementation notes + follow-on CPMI-IOSCO papers MODEL OUTPUT ✗ Blended composite Attributed to 2016 Guidance only ✗ Web search blended primary 2016 text with later commentary — both attributed to 2016 source
Models with web search blended the 2016 primary guidance with later national implementation notes and follow-on CPMI-IOSCO publications, attributing the composite to the 2016 Guidance alone.
Operational signal

What AI labs need to know

FMI compliance teams, central bank cyber supervisors, and regtech builders embedding CPMI-IOSCO 2016 Guidance requirements into compliance tooling should expect frontier models to blend primary guidance text with secondary implementation commentary when web search is active. The blend is attributed with equal confidence to the primary source. Source-verification against the 2016 Guidance document is required for any specific provision, RTO parameter, or scope statement that the model produces.

// Document reference
CPMI-IOSCO Guidance on Cyber Resilience for Financial Market Infrastructures (2016) — BIS Committee on Payments and Market Infrastructures / IOSCO. Full hub: CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016 →

Hallucination Register: reglegbrief.com/hallucination-register/ · Right of Reply: reglegbrief.com/right-of-reply/