// The international cyber standard for financial market infrastructures. Evaluation of AI model responses against the CPMI-IOSCO Guidance on Cyber Resilience for FMIs (2016). Multiple failure modes documented across frontier configurations.
The CPMI-IOSCO Guidance on Cyber Resilience for Financial Market Infrastructures (June 2016) is the global baseline for cyber resilience at systemically important payment systems, CCPs, and securities settlement systems. Central banks and market supervisors worldwide use it. It covers governance, identification, protection, detection, response and recovery, testing, and situational awareness. It is a principles-based framework, not a compliance checklist.
The Guidance supplements the PFMI by providing specific cyber resilience expectations for FMIs. It has been implemented by supervisors across over 30 jurisdictions and is the document that compliance teams, FMI boards, and financial cyber regulators treat as the authoritative international baseline.
FINDING: Multiple hallucinations detected across question set
FINDING: Attribution errors on component scope
FINDING: Recovery time objective specifications incorrect
Binding to authenticated primary substrate: CPMI-IOSCO-CYBER-2016
Failure patterns documented
What the models got wrong and how
The RLB Specialist Panel's evaluation of frontier AI models against the 2016 Guidance found failures concentrated in three areas: the scope of the guidance and which FMI types it covers, specific technical parameters within the guidance including recovery time objective specifications, and attribution errors where model outputs assigned guidance provisions to the wrong component of the framework.
The guidance is a 2016 document that has accumulated significant secondary commentary, supervisory implementation notes, and follow-on CPMI-IOSCO publications. Models with web search active appeared to blend content from these secondary sources with the primary guidance text, producing composite answers that partially reflect the original guidance and partially reflect later commentary or national implementation documents.
Scope attribution errors
Model outputs mis-scoped which FMI types the 2016 Guidance applies to, in some cases extending it to entity types outside the CPMI-IOSCO FMI definition and in others narrowing it incorrectly.
Actual scope (2016 Guidance)
The 2016 Guidance applies to FMIs as defined in the PFMI: systemically important payment systems, central counterparties (CCPs), central securities depositories (CSDs), and securities settlement systems (SSSs).
RTO specifications
Recovery time objective parameters in model outputs diverged from the specific expectations in the 2016 Guidance text, with models producing figures that appear to draw from later national implementation guidance rather than the 2016 CPMI-IOSCO document.
Correct source
RTO expectations in the context of this audit are bound to the CPMI-IOSCO 2016 Guidance text. Later national implementation notes that modify or elaborate those expectations are distinct documents and should not be blended into citations of the 2016 Guidance itself.
Models with web search blended the 2016 primary guidance with later national implementation notes and follow-on CPMI-IOSCO publications, attributing the composite to the 2016 Guidance alone.
Operational signal
What AI labs need to know
FMI compliance teams, central bank cyber supervisors, and regtech builders embedding CPMI-IOSCO 2016 Guidance requirements into compliance tooling should expect frontier models to blend primary guidance text with secondary implementation commentary when web search is active. The blend is attributed with equal confidence to the primary source. Source-verification against the 2016 Guidance document is required for any specific provision, RTO parameter, or scope statement that the model produces.
// Document reference
CPMI-IOSCO Guidance on Cyber Resilience for Financial Market Infrastructures (2016) — BIS Committee on Payments and Market Infrastructures / IOSCO. Full hub: CPMI-IOSCO-CYBER-RESILIENCE-FMI-2016 →