Directory of AI model risk management and AI governance vendors

The AI FinTech Index holds 9 of them, each graded on the same 15 capability axes from public sources, with the artifact every grade was read from attached to the record.

No vendor pays for inclusion, placement or rating. Counts generated 2026-08-24 across 490 indexed vendors. What moved is in the change log.

The supervisory guidance this segment sold against was replaced on 17 April 2026, and the replacement excludes generative and agentic systems from its scope while disclaiming its own enforceability. Ask what a vendor is actually mapping to now.

What is in this directory. Screened to products that govern, validate or document models and AI systems. Products that are themselves the governed model sit elsewhere.

Part of the wider Compliance, Surveillance & RegTech category.

What the public record shows in this directory

The share of the 9 indexed vendors here whose public record answers each of the nine regulatory questions a financial institution diligence process works through, and where this directory ranks against the other 50 directories in the index on the same question, highest share first. A thin share means the public record is thin, not that a control is absent.

how the model works and how it is validated89%
8 of 9 vendors, 5 highest of 50 directories
regulatory status and licensure67%
6 of 9 vendors, 11 highest of 50 directories
data privacy posture under GLBA22%
2 of 9 vendors, 26 highest of 50 directories
security certification depth22%
2 of 9 vendors, 24 highest of 50 directories
AI governance and bias testing22%
2 of 9 vendors, 13 highest of 50 directories
how much the system decides on its own78%
7 of 9 vendors, 30 highest of 50 directories
liability and customer recourse0%
0 of 9 vendors, 40 highest of 50 directories
which models sit underneath33%
3 of 9 vendors, 27 highest of 50 directories
deployment model and data residency44%
4 of 9 vendors, 3 highest of 50 directories
The finding in this segment

This is the lane that sells accountability, and it is the lane that accepts none. Every one of the vendors here grades C on commercial transparency and C on AI liability and recourse, without exception: not one publishes a price, and not one states who carries the cost when the governance layer itself gets something wrong. The recursion is the point. A product whose entire proposition is that a buyer should be able to inspect, validate and assign responsibility for a model is a product that has published neither the terms of its own failure nor what it charges. What makes this a finding rather than an excuse is the third axis, where the pattern breaks: a minority of these vendors do publish operational and outcome evidence at A or B, which removes early stage or too small as the explanation for the other two silences. The capability to publish exists in this lane. It has not been directed at the vendor own accountability. Ask each one, in writing, what happens commercially when its validation misses something.

In summary

The AI FinTech Index lists 9 AI model risk management and AI governance vendors, graded on 15 capability axes from public sources with no paid placement and no aggregate score. Across this directory the best documented part of the public record is how the model works and how it is validated at 89 percent, and the thinnest is liability and customer recourse at 0 percent, which is 40 highest of 50 directories in the index on that question. Across the whole index of 490 vendors, none documents all nine regulatory axes in public and the average documents 2.94.

This is the lane that sells accountability, and it is the lane that accepts none. Every one of the vendors here grades C on commercial transparency and C on AI liability and recourse, without exception: not one publishes a price, and not one states who carries the cost when the governance layer itself gets something wrong. The recursion is the point. A product whose entire proposition is that a buyer should be able to inspect, validate and assign responsibility for a model is a product that has published neither the terms of its own failure nor what it charges. What makes this a finding rather than an excuse is the third axis, where the pattern breaks: a minority of these vendors do publish operational and outcome evidence at A or B, which removes early stage or too small as the explanation for the other two silences. The capability to publish exists in this lane. It has not been directed at the vendor own accountability. Ask each one, in writing, what happens commercially when its validation misses something.

Source: AI FinTech Index, August 2026

Vendors in this directory
9 indexed
Vendor Category AI Centrality Website
A
AlphaBitCore
AlphaBitCore builds what it calls an AI control plane for regulated enterprises, aimed at moving AI from pilot to production by solving the governance, auditability and approval problems that block deployment. It unifies models, agents, tools and workflows under a single governed runtime with policy enforcement, sealed execution records and verifiable replay, so compliance, risk and audit teams can verify exactly what an AI workflow did rather than only what it produced, with any governed execution deterministically replayable from its event stream. A virtualisation layer converts disconnected tools, local scripts and remote data into a single governed, sandboxed executable surface rather than exposing raw interfaces to agents. For financial services it ships a preconfigured investment and wealth workbench of 23 agents, 95 workflows, 78 skills, 12 models and more than ten protocol connectors covering research, portfolio, advisory and compliance work, aligned to emerging broker-dealer regulator expectations on agentic AI oversight. Founders come from a market data firm, a corporate research lab and two capital markets institutions.
Compliance, Surveillance & RegTech A alphabitcore.com
B
Block Convey
Block Convey builds two AI governance layers for banks, asset managers, insurers and fintechs. PRISM captures every language model call, tool invocation and reasoning step in production, scores quality, applies guardrails that strip regulated identifiers at ingestion, and exports regulator-facing evidence packs in under a minute from tamper-proof immutable traces, with compliance teams reviewing session-level transcripts rather than raw logs. PRISMX is a managed browser extension enforcing data loss prevention on consumer assistants, intercepting paste-and-prompt traffic at the endpoint so personal data, health data and source code never reach an external model. Obligations are mapped individually across US banking model risk guidance, state cybersecurity rules, fair lending requirements, insurance model bulletins and European AI and operational resilience regimes. Supported models, cloud platforms and agent frameworks are named explicitly.
Compliance, Surveillance & RegTech A blockconvey.com
E
Ethos
Ethos builds an end-to-end platform for model risk management at banks and fintechs, covering the full supervisory lifecycle from model development and documentation through validation, reporting and governance. It gives institutions real-time visibility and automation across their whole model inventory, and is designed to handle both conventional statistical models and newer machine learning and generative systems, which is the gap most existing frameworks have: institutions have deployed machine learning faster than their model risk functions could absorb it, and model governance is now a primary focus for United States banking examiners. The company positions itself against the decisions models actually drive at financial institutions, spanning lending, loss forecasting, fraud detection and anti money laundering. Founded in 2023 and backed by two financial services specialist funds alongside a major bank's venture arm.
Compliance, Surveillance & RegTech B ethos.ai
E
EVE AI Core
EVE AI Core is a deterministic control plane that intercepts every AI action before execution rather than reviewing it afterwards, returning an allow, block or modify verdict against versioned policy packs in under a millisecond, fail-closed and with no language model anywhere in the decision path. Its argument is that a safety layer built on a model can itself hallucinate, so a non-deterministic safety check is not a safety check. Every verdict emits a cryptographically signed certificate bound to the exact policy version in force, appended to hash-chained trails, replayable on demand and verifiable offline by a third party without the vendor in the loop. It governs agent actions rather than only prompts and responses, refusing unregistered tools, risk-scoring each step and requiring human approval for high-stakes actions. It positions itself as the runtime enforcement and evidence layer beneath an existing model risk programme, for lending, insurance and trading decisions.
Compliance, Surveillance & RegTech A eveaicore.com
F
Fiddler AI
Fiddler AI is a Palo Alto based AI observability and agent control plane vendor that sells a separately addressed financial services line rather than a financial services page, which is what brings it inside this index. The platform evaluates, monitors, enforces and governs predictive models, generative applications and first party, third party and coding agents through the gateway an enterprise already runs, capturing every prompt, tool call and outcome and producing unified audit trails and compliance reporting across the agent lifecycle. The financial services capability is specific rather than adapted: credit, lending and underwriting model monitoring with drift root cause analysis and a slice and explain function for segment level feature impact; automated lending decision explanation using Shapley values and a proprietary variant, at both local and global level, with what if analysis on prediction outcomes; fraud detection monitoring tuned for heavily imbalanced datasets with real time anomaly alerting; credit card and payment default risk with fairness metrics shipped out of the box, namely disparate impact, group benefit, equal opportunity and demographic parity; and robo advisory drift detection against market volatility and asset class performance. The agentic line covers multi agent lending systems that assess collateral and recommend terms, collections agents that negotiate payment plans, and financial crime investigation agents, with real time moderation that blocks agent conversations for policy breaches and detects personal data leakage before exposure, and enforced human approval on high value loans. Evaluation runs on the company own Trust and Centor model families, which execute inside the customer virtual private cloud so that governance of generative agents requires no data sharing and no external model interface calls. Published work includes a Fortune 100 financial services institution spanning wealth management, brokerage and asset management, and a named data science leader quoted on production monitoring.
Compliance, Surveillance & RegTech B fiddler.ai
I
ibl.ai
ibl.ai supplies a self-hosted, model-agnostic agent platform to banks, broker-dealers, asset managers and wealth firms, deployed inside the institution's own virtual private cloud, on-premise, or fully air-gapped with no route to the public internet. Its argument is that model risk guidance places validation, governance and monitoring on the bank rather than the vendor, so the bank must be able to inspect the whole stack: it runs several named model families including self-hosted open-weight options, lets the institution's model risk team pin specific versions and sign off validation packs, treats any model swap as a new validation event rather than a vendor surprise, ships platform code under an open licence with a perpetual platform licence so orchestration logic is inspectable and reproducible, and writes every call to the bank's own security monitoring system with model version, prompt template, input hash, output, decision flag and disposition. A knowledge graph unifies customer data fragmented across core banking, customer, risk and financial crime systems, connected over open protocol with row and field level security, and ownership is transferred to the institution's team.
Compliance, Surveillance & RegTech A ibl.ai
M
Monitaur
Monitaur is a Boston based AI governance software company selling to highly regulated enterprises, with its deepest expertise in insurance and a growing financial services segment. The platform is organised on a policy to proof roadmap running from policy definition and taxonomy through model inventory, stakeholder collaboration and lifecycle governance execution to continuous monitoring, validation and audit ready reporting, so that a governance framework becomes checkable evidence rather than a document. The distinguishing asset is a validated controls library that a carrier maps to the policies and frameworks it already operates against, shipped with alignment to named regulatory instruments rather than generic principles: the National Association of Insurance Commissioners model bulletin, the National Institute of Standards and Technology risk management framework, and the European Union artificial intelligence regulation, alongside model filings, market conduct examination, own risk and solvency assessment, actuarial standards of practice and the individual state insurance departments. Capabilities include model validation, continuous fairness and bias stress testing, performance and quality monitoring across multiple modelling paradigms, and governance of third party and vendor supplied models, the last of which an enterprise insurer customer cited as the differentiator because it integrated with existing third party risk management workflows. Named customer work includes the property analytics firm CAPE Analytics, whose general counsel is quoted on the selection, and case studies covering an enterprise insurer and a Fortune 200 financial services and insurance company. The advisory board includes a former director of the Arizona insurance regulatory agency who co chaired the innovation and technology committee at the national insurance commissioners body, and the company has an alliance with a large professional services firm in Germany covering European regulatory compliance.
Compliance, Surveillance & RegTech B monitaur.ai
P
Prism Layer
Prism Layer encodes an organisation's risk frameworks, regulatory context and institutional knowledge into what it calls a governed agentic execution layer, aimed at financial services, payments and fintech firms. Its distinguishing claim is that rather than storing risk records after decisions are made, it executes the structured reasoning behind risk analysis as those decisions happen, producing auditable and defensible output at business speed. Supported work covers risk assessments, key risk indicators, controls testing, risk and control self-assessments and product risk review. The company emerged from stealth in April 2026 with a pre-seed round led by a venture firm focused on financial services and regulatory technology whose partners include former senior leaders of the US consumer financial regulator. Its three co-founders were all risk executives at the same payments company, with prior enterprise risk leadership across money transfer, brokerage, card network and consumer lending businesses, and direct experience with Irish, Australian and UK regulators.
Compliance, Surveillance & RegTech A prismlayer.ai
V
ValidMind
ValidMind automates model documentation, testing and validation for bank model risk management teams, and is the only platform in independent comparisons built exclusively for financial institution use rather than adapted from enterprise AI governance. It maps directly to the supervisory regimes that govern this work across four jurisdictions, covering United States interagency guidance old and new, the United Kingdom prudential regulator's principles, the Canadian supervisor's model lifecycle requirements and European AI legislation, producing audit-ready evidence against each. Recent work extends the same framework to autonomous agents, recording who approved an agent, under what conditions and at what risk tier, with real-time policy enforcement rather than periodic review. A major credit bureau has embedded the platform inside its own analytics environment so banks can document credit and fraud models against several regimes at once.
Compliance, Surveillance & RegTech B validmind.com

Common questions

Is there a directory of AI model risk management and AI governance vendors?

Yes. The AI FinTech Index lists 9 AI model risk management and AI governance vendors, each graded on the same 15 capability axes from public sources, with the artifact every grade was read from attached to the record. No vendor pays for inclusion, placement or rating, no vendor is contacted before it is listed, and nothing sits behind a form. Counts generated 2026-08-24.

What counts as model risk and AI governance in this directory?

Screened to products that govern, validate or document models and AI systems. Products that are themselves the governed model sit elsewhere. The index holds 9 vendors meeting that screen, drawn from a wider Compliance, Surveillance & RegTech category and from adjacent categories where the vendor belongs on the same shortlist. A vendor filed under a different category can still appear here, because a buyer building this shortlist does not sort by our filing.

What should a buyer check before shortlisting model risk and AI governance vendors?

Start with what this segment does not publish. Across the 9 indexed vendors, the thinnest parts of the public record are liability and customer recourse at 0 percent, AI governance and bias testing at 22 percent, and security certification depth at 22 percent. A thin public record predicts the length of a diligence process rather than the absence of a control, so these are the questions to put in writing early. The supervisory guidance this segment sold against was replaced on 17 April 2026, and the replacement excludes generative and agentic systems from its scope while disclaiming its own enforceability. Ask what a vendor is actually mapping to now.

Head to Head

Comparisons inside this directory

6 published

Other directories in Compliance, Surveillance & RegTech

One category is several buying decisions sharing a label. Each of these narrows the same market to a different one.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746