GBG vs Ondato (2026)
The decision is whether you are joining a network or running a console. GBG is the network: a listed identity group founded in 1989 whose consortium spans several hundred organisations across more than twenty sectors and eighty countries, returning an identity trust score in seconds, with bureau access, due diligence, transaction monitoring and application fraud on one platform, and the lane's most modern integration surface bolted to its oldest business, an agent portfolio that grounds every identity, compliance or fraud decision as a real platform journey with a retrievable run identifier, deterministic and resumable, rather than a model guess. Ondato is the console: an operating system for know your customer work, with verification, screening, monitoring, risk scoring and case management in one modular platform, priced on a public page, tested for presentation attack detection at both levels, and carrying a live video branch for the markets that require a supervised interview. The grid's finding is that both operate a shared fraud memory and disclose it at opposite depths. GBG names its consortium, quantifies it, and claims the score returns without protected data being divulged, an assertion no mechanism accompanies. Ondato matches biometrics against a database of individuals previously flagged for fraud across its customer base, a shared negative list described in a product sentence, with nothing on who contributes, what places a person there, how long an entry lasts or whether it can be challenged. The oversight postures then invert the generations: the incumbent holds a rare A on autonomy by removing the model from agent decisions architecturally, while the challenger's human channel is a separate product and its default path completes without manual intervention.
- Scale of signal decides it. A consortium of several hundred organisations across more than twenty sectors and eighty countries feeds the trust score, with bureau access, due diligence, screening, transaction monitoring and application fraud on one platform serving the full customer lifecycle.
- Agents are in your roadmap. Identity, compliance and fraud decisions execute as deterministic, grounded platform journeys with retrievable run identifiers rather than model guesses, reachable through a command line binary, a hosted protocol server and an agent skill, the most concrete agent surface in this lane.
- You want model performance quantified at all. Published deltas for fraud detected and false positives reduced exist where most of this category publishes adjectives, though every figure is an up to construction stating a ceiling rather than a typical result.
- You want a console you can price and run. Identity verification, business onboarding, screening, monitoring, risk scoring and case management ship as one modular platform with per verification rates on a public page, sized for the European mid tier.
- Some of your markets require a face. The live video branch product conducts supervised interviews with document checks and facial matching where regulation demands a face to face check, a separate high assurance channel most API only vendors cannot offer.
- External testing is your floor. Presentation attack detection at both levels against the international standard and European electronic identification conformity certificates sit well above the category norm for a vendor this size.
This comparison is published by AI FinTech Index, an independent research platform that publishes independent ratings of AI vendors for financial services. GBG and Ondato are each graded against the same capability taxonomy, from each vendor's own public materials and the regulatory record, under the AI FinTech Index verification standard. No vendor pays for placement, and no vendor has reviewed this page. How this evidence is graded
Plain facts
| GBG | Ondato | |
|---|---|---|
| Primary category | AML, KYC & Financial Crime | AML, KYC & Financial Crime |
| Founded | 1989 | 2016 |
| Headquarters | Chester, United Kingdom | London, United Kingdom |
| Website | www.gbg.com | ondato.com |
Side by Side
| Axis | G GBG |
O Ondato |
|---|---|---|
| AI Centrality | ||
| Autonomy and Oversight Model | ||
| Model Risk Management and Transparency | ||
| Operational and Outcome Evidence | ||
| AI Safety and Data Stewardship | ||
| GLBA and Data Privacy Posture | ||
| Security Certifications and Trust Center | ||
| Regulatory Status and Licensure | ||
| AI Governance and Bias Disclosure | ||
| AI Liability and Recourse | ||
| Model Supply Chain Disclosure | ||
| Core Systems and Integration Depth | ||
| Deployment Model and Data Residency | ||
| Commercial Transparency | ||
| Institution and Segment Coverage |
The short version of each
GBG
GBG, a listed identity group founded in 1989, runs a consortium spanning several hundred organisations across more than twenty sectors and eighty countries, returning an identity trust score in seconds, with bureau access, due diligence, transaction monitoring and application fraud on one platform, and an agent portfolio grounding every decision as a deterministic platform journey with a retrievable run identifier, which earns a rare A on autonomy in the AI FinTech Index. The index records that its consortium privacy claim, a score returned without protected data divulged, names no mechanism, that its numbered certification lacks edition, scope and audit period, that no demographic performance is published anywhere, and that a person carried in the consortium signal has no route to learn, contest or expire the entry.
Source: AI FinTech Index, 2026
Ondato
Ondato packages know your customer work as a modular operating system, verification, screening, monitoring, risk scoring and case management, priced on a public page, tested for presentation attack detection at both levels, with a live video branch for markets requiring supervised interviews. The AI FinTech Index records its shared negative list, biometric matching against individuals previously flagged for fraud across its customer base, as described in a single product sentence with nothing on contribution, cause, duration or challenge, and notes its 99.8 percent accuracy claim across 192 countries carries no methodology and no independent audit, its information security certificate cites a superseded edition, and third party sites credit it with certifications absent from its own material.
Source: AI FinTech Index, 2026
Common questions
Is GBG better than Ondato for identity and KYC?
One is a network, the other a console. GBG, listed and founded in 1989, runs a consortium of several hundred organisations across eighty countries returning an identity trust score in seconds, with bureau access, due diligence and transaction monitoring on one platform. Ondato packages verification, screening, monitoring, risk scoring and case management as a modular operating system for know your customer work, priced on a public page. An institution wanting shared fraud memory joins GBG; one wanting a self contained priced stack runs Ondato. Graded by AI FinTech Index against the same capability axes from each vendor's own published materials, verified August 23, 2026. No vendor pays for placement.
Do GBG and Ondato share fraud data across customers?
Both do, at opposite disclosure depths, and the AI FinTech Index records the asymmetry as the page's finding. GBG names its consortium, quantifies it, and claims the trust score returns without protected data being divulged, an assertion no mechanism accompanies. Ondato matches biometrics against a database of individuals previously flagged for fraud across its customer base, a shared negative list described in a single product sentence, with nothing on who contributes, what places a person there, how long an entry lasts or whether it can be challenged.
How do the oversight architectures compare?
The generations invert. The incumbent holds a rare A on autonomy by removing the model from agent decisions architecturally: every identity, compliance or fraud decision grounds as a real platform journey with a retrievable run identifier, deterministic and resumable, rather than a model guess. The challenger's human channel is a separate product, and its default path completes without manual intervention. Graded by AI FinTech Index against the same capability axes from each vendor's own published materials, verified August 23, 2026. No vendor pays for placement.
What certification hygiene issues exist?
Ask for the certificates themselves. Ondato cites its information security certification to the superseded 2013 edition, and third party sites credit it with certifications absent from its own material, one of which does not exist in the form claimed. GBG claims a numbered certification without edition, scope or audit period, and its consortium privacy assertion should be asked to show its mechanism. Graded by AI FinTech Index against the same capability axes from each vendor's own published materials, verified August 23, 2026. No vendor pays for placement.
Who has no route at either vendor?
The person inside the shared memory. Someone carried in GBG's consortium signal or matched against Ondato's flagged biometrics database can be refused across institutions without learning why, contesting the entry or having it expire on any published schedule. Neither publishes demographic performance either, GBG with no breakdown at all, Ondato claiming 99.8 percent across 192 countries with no methodology and no independent audit. Graded by AI FinTech Index against the same capability axes from each vendor's own published materials, verified August 23, 2026. No vendor pays for placement.
How does the AI FinTech Index grade GBG and Ondato?
Both are graded on the same fifteen capability axes from public sources, each grade traceable to its artifact. The AI FinTech Index records both as operating shared fraud memories disclosed at opposite depths, notes GBG's rare A on autonomy for its deterministic agent architecture, and flags the certification hygiene items on both sides for direct verification. The index publishes no composite score and declares no winner.
Related comparisons
Other published head to head assessments involving these vendors or their closest peers. The full set for this category is on the Fraud Detection & Transaction Risk page.
Both operate a shared fraud memory and neither gives the person inside it a route: someone carried in GBG's consortium signal or matched against Ondato's flagged biometrics database can be refused across institutions without learning why, contesting the entry or having it expire on any published schedule.
Neither publishes demographic performance, and each averages where the variation lives, GBG running document and biometric checks globally with no breakdown at all, Ondato claiming 99.8 percent across 192 countries with no methodology and a third party evaluator noting it is not independently audited.
Two hygiene items for diligence: Ondato cites its information security certification to the superseded 2013 edition and third party sites credit it with certifications absent from its own material, one of which does not exist in the form claimed, so ask for the certificates themselves; GBG's consortium privacy claim, a score returned without protected data divulged, names no mechanism and should be asked to show one.