Regulatory compliance is becoming harder to manage. Not simply because there are more regulations, but because regulatory requirements are becoming increasingly complex and time-consuming to interpret.
According to PwC's 2025 Global Compliance Survey, 85% of the 1,802 executives surveyed said their compliance requirements had become more complex over the previous three years. Among financial services organizations, that figure rose to 90%.
For compliance teams, the challenge becomes especially visible when managing regulatory obligations.
Traditionally, obligation management starts with a document.
An analyst reads the regulation, identifies the individual obligations buried within it, interprets what each requirement means for the organization, and then determines which policies, risks, and controls may be affected.
For a short document, that process may be manageable. For a large regulation containing hundreds of requirements, definitions, exceptions, cross-references, and supporting provisions, it quickly becomes a significant manual effort.
It also introduces another challenge: consistency. Different reviewers may interpret the same regulatory language differently, particularly when the work is distributed across regions, business units, or lines of defense.
With the latest release, MetricStream brings AI-Powered Regulatory Obligation Extraction and Content Mapping to the MetricStream Platform as part of its agentic AI capabilities.
The capability reads an uploaded regulatory document, identifies the obligations within it, and proposes mappings to relevant policies, risks, and controls already present in the MetricStream environment.
Instead of starting with a document and building the analysis from scratch, compliance teams start with a structured, traceable first draft, which is ready for human review, validation, and refinement.
And importantly, the AI doesn't just make recommendations. It explains why.
For every suggestion or recommendation, including proposed risk and control mappings, the AI provides a rationale that helps reviewers understand why a particular record was identified as relevant to an obligation.
A regulatory obligation is a specific requirement that an organization is expected to comply with. Obligations can originate from external sources such as laws, regulations, regulatory guidance, standards, and contracts. They can also come from internal sources, including corporate policies and standards.
The challenge is that obligations rarely appear neatly packaged for a compliance analyst.
A single regulatory document can contain hundreds of requirements mixed with definitions, exceptions, conditions, explanatory material, and cross-references. Identifying the actual obligations and separating them from the surrounding content requires careful analysis.
This is where AI can change the starting point.
1. Upload and Extract
The process starts with the regulatory document.
Once uploaded, MetricStream identifies key information such as the regulator, jurisdiction, and effective date, and suggests a task name. These fields remain editable, allowing the compliance team to correct or refine the information before proceeding.
The extraction process then runs asynchronously.
There is no need to keep the application open while the analysis is running. Users can leave the screen and return later. When extraction and mapping are complete, MetricStream provides notifications both in the application and by email, so users can continue with other work without having to monitor the process.
The result is not simply a collection of generated text. Each extracted obligation is connected back to the source document, providing the context needed for review.
2. Review What AI Found
Once processing is complete, results are available through two complementary views.
The Impact Visualization provides a paginated mind-map view connecting the regulatory document, extracted obligations, and mapped records. The page size can be configured based on the volume of information being reviewed.
The List View provides a more detailed, obligation-by-obligation experience. For each obligation, reviewers can see:
The rationale is an important part of the experience. Rather than presenting a reviewer with a recommendation and asking them to trust it, MetricStream provides context on why the AI considers a particular risk or control relevant to an obligation.
For example, when a control is recommended for an obligation, the rationale helps explain the relationship between the regulatory requirement and the control. The same principle applies to recommended risk mappings.
This gives reviewers an additional layer of context when deciding whether to accept, modify, or reject a recommendation.
3. Human Review Remains at the Center
AI provides the starting point. The reviewer makes the final decision.
AI-generated obligation content can be edited directly. Reviewers can accept or reject recommended mappings, and they can also add additional risk, control, or policy mappings that the AI did not recommend.
This is important because an organization's compliance context may include relationships that cannot always be inferred from the regulatory text or the available data.
The human reviewer therefore has two levels of control:
Reviewers can complete the task within MetricStream or export the results to an Excel template for additional review by legal, compliance, or the second line. Once the review is complete, the updated results can be uploaded back into the application.
AI accelerates the analysis. Human judgment remains part of the decision-making process.
Identifying an obligation is only part of the challenge. Understanding what that obligation affects within the organization's existing GRC environment is equally important.
Traditional keyword matching can struggle here.
Consider a regulatory requirement related to record retention. The language used in the regulation may be very different from the terminology used in an organization's control library. A relevant control may also be indirectly connected through a policy or risk rather than sharing obvious keywords with the regulatory text.
MetricStream addresses this through its Context Engine, which combines semantic similarity with the relationships already established within the MetricStream environment.
In other words, the system considers both:
The AI then provides recommended mappings together with a rationale explaining why each relationship was suggested.
The result is a set of contextual recommendations that reviewers can understand, validate, refine, or supplement with additional mappings.
This moves mapping from a purely text-matching exercise toward a more contextual and explainable approach.
When extraction and first-pass mapping happen before the analyst begins the detailed review, the nature of the work changes.
Here are six ways this can benefit compliance teams.
1. Faster Review Cycles
Instead of spending the initial review cycle reading the document and manually identifying every potential obligation, analysts begin with an AI-generated first pass.
The analyst's time can shift toward validation, interpretation, and decision-making.
2. Explainable Recommendations
Every AI recommendation is accompanied by a rationale.
Reviewers can understand why an obligation was identified and why a particular risk, control, or policy was recommended as a potential mapping.
This gives compliance teams more context when validating AI-generated results.
3. End-to-End Traceability
Each extracted obligation remains connected to its original verbatim source citation and its proposed mappings.
This creates a traceable path from:
Regulatory text → Obligation → Risk / Policy / Control
Combined with the AI rationale, reviewers have both the source evidence and the reasoning behind the recommendation.
4. More Consistent Analysis
A structured AI-generated first pass provides a common starting point for regulatory analysis.
For organizations operating across multiple geographies or lines of business, this can help teams apply a more consistent approach to identifying and classifying obligations—while still allowing local reviewers to apply their expertise and judgment.
5. Higher Throughput
The volume of regulatory content a compliance program can process manually is constrained by the amount of time analysts have available for reading, interpretation, and initial mapping.
Automating the first pass allows teams to process larger volumes of regulatory content without simply scaling the number of people performing the same manual task.
6. Human Review Workflows Stay Intact
AI adoption does not have to mean replacing established review and approval processes.
Reviewers can validate or reject AI recommendations, edit extracted obligation content, and add additional mappings when they identify relevant risks, controls, or policies that AI did not recommend.
Results can also be exported to an Excel template for offline legal or second-line review and uploaded back into MetricStream once that review is complete.
The technology accelerates the work while keeping expert judgment and established review processes in the loop.
Obligation extraction is more than an exercise in saving reading time. It changes the starting point of regulatory analysis. Instead of asking an analyst to begin with a lengthy document and determine what matters, AI can identify the potential obligations, propose relevant mappings, and explain the rationale behind those recommendations. The analyst can then focus on the questions that require human judgment:
That shift, from manually discovering the starting point to reviewing an intelligent, explainable first pass, is where agentic AI can begin to reshape regulatory compliance workflows.
And obligation extraction is only the beginning.
The same approach can extend into regulatory change management, where the challenge moves from understanding what a regulatory document says to understanding what has changed, which obligations are affected, and what those changes mean for the organization's policies, risks, and controls.
As regulatory volume continues to grow, the advantage may not come simply from being able to read more documents.
It may come from being able to move from regulatory text to actionable understanding faster, while keeping people
firmly in the loop.
See AI-Powered Regulatory Obligation Extraction in Action
Ready to see how MetricStream can transform the starting point of regulatory review?
AI-Powered Regulatory Obligation Extraction and Content Mapping is an agentic capability in the MetricStream Platform that analyzes an uploaded regulatory document, identifies the obligations it contains, and proposes mappings to existing risks, controls, and policies.
Each extracted obligation retains its original verbatim source citation. Recommended mappings include a confidence code and a rationale explaining why the AI considers the mapped record relevant.
A regulatory obligation is a specific requirement that an organization is expected to comply with.
Obligations can originate from external sources such as laws, regulations, standards, and contracts, as well as internal sources such as corporate policies and standards.
The MetricStream Context Engine combines semantic similarity with the relationships already established within the MetricStream environment.
It considers both the meaning of the regulatory text and how risks, controls, and policies are connected within the existing GRC environment.
For each recommended mapping, the AI provides a rationale explaining why the relationship was suggested.
The resulting mappings are recommendations for human review and validation; they are not automatically applied.
Yes. Users can edit AI-generated obligation content directly in the List View while retaining the original source citation for comparison.
Yes. Human reviewers can add additional mappings to relevant risks, controls, or policies that were not identified by AI.
This allows reviewers to incorporate their knowledge of the organization's business context and ensure the final mapping reflects the complete compliance landscape.
Yes. AI-generated recommendations are presented for human validation. Reviewers can evaluate the recommendation and its rationale and decide whether to accept, modify, or reject it.
Extraction runs asynchronously, so users do not need to remain on the screen while processing takes place.
Users receive notifications in the application and by email when extraction and mapping are complete.
Processing time depends on the size and complexity of the regulatory document.
Subscribe for Latest Updates
Subscribe Now