Features
Every vendor in the index is assessed against fifteen capability axes in four groups. Each axis carries a letter grade and a source basis, and each is gradeable from public artifacts: vendor documentation, trust centers, regulatory databases and filings, integration marketplace listings, and published research.
For how the nine regulatory and compliance axes map to SR 11-7, GLBA, NYDFS Part 500, fair lending and the EU AI Act, and what share of the indexed market documents each one, see the compliance evaluation framework.
How grades read
Grades are not aggregated into a composite score. A grade reflects the assessed strength of the vendor’s disclosure and evidence on that axis, not a comparison to other vendors. See the Methodology for verification standards.
AI Centrality
Whether artificial intelligence is the product itself, the engine of a core module, or a feature layer on a platform whose value stands without it. This axis is how a reader distinguishes an AI-native product from a platform with AI capabilities. The index includes companies across the full range.
Autonomy and Oversight Model
What the AI is permitted to do (draft, decide, or act) and how rigorously the vendor discloses its human oversight structure: escalation thresholds, supervision, override paths, and the boundary between what the system decides alone and what a human reviews. Grades disclosure rigor, not autonomy itself. High autonomy with a documented oversight model can grade well; any autonomy with no disclosed oversight grades poorly.
Model Risk Management and Transparency
Disclosure of what is under the hood and how it is validated: proprietary models versus fine-tuned foundation models, training data claims, model cards, versioning and update practices, and the documentation a buyer needs to satisfy its own model risk management obligations under SR 11-7 and equivalent supervisory guidance. A vendor selling into banks that cannot support the buyer’s model validation is transferring that work to the buyer.
Operational and Outcome Evidence
The strength of evidence behind performance and outcome claims, from independently validated results measured against a named baseline at the top of the scale down to percentages published with no methodology. Detection rates, false positive reductions, straight through rates, and loss figures are recorded with their measurement basis. Vendor-reported statistics are recorded as vendor-reported and never restated as independent results.
AI Safety and Data Stewardship
How the vendor handles customer financial data and personal information across the AI lifecycle, including use in model training, retention, cross-client separation, and de-identification, along with safety engineering disclosures such as guardrails, hallucination mitigation, and incident reporting.
GLBA and Data Privacy Posture
How the vendor supports the buyer’s obligations for nonpublic personal information: GLBA Safeguards alignment, contractual data protection commitments, subprocessor disclosure, and privacy regime coverage (state privacy laws, GDPR where relevant). Grades the posture and disclosure quality a counterparty can verify.
Security Certifications and Trust Center
SOC 2 Type II, ISO 27001, and PCI DSS status where card data is in scope, verified through public trust centers wherever possible, along with security incident disclosure practices.
Regulatory Status and Licensure
The regulatory posture of the product and the entity behind it: registrations, charters, and licenses where the vendor itself performs regulated activity (money transmission, lending, brokerage, insurance), and clarity about which regulator’s perimeter the product operates inside when sold to a regulated buyer, including EU AI Act high-risk classification where it applies. Grades clarity and appropriateness of regulatory positioning; products for which licensure is not applicable are not penalized.
AI Governance and Bias Disclosure
Substantive responsible AI commitments: published model cards, bias and fairness evaluations with stated methodology, fair lending and disparate impact testing for credit-adjacent models, adverse action explainability, and third-party AI audits.
AI Liability and Recourse
Model Supply Chain Disclosure
Core Systems and Integration Depth
Integration maturity with the systems financial institutions actually run: core banking platforms, card networks and processors, loan origination and servicing systems, market data and custodial platforms, and open banking APIs, verified against integration documentation and named marketplace listings where available. For segments where core integration is not the relevant surface, the axis is assessed against the relevant surface or marked not applicable.
Deployment Model and Data Residency
Documented deployment options (cloud, virtual private cloud, on-premises) along with data residency commitments and tenant isolation disclosures, assessed against the outsourcing and third-party risk expectations regulated institutions must apply to their vendors.
Commercial Transparency
Whether a buyer can learn what the product costs and how it is priced without a sales engagement: published tiers, published pricing basis, self-serve trial availability. Specific figures are recorded in the vendor pricing record, with estimates labeled as estimates. Vendors that publish no pricing are recorded as Contact the vendor and graded on what a prospective buyer can establish before making contact; a failing grade is reserved for published pricing claims contradicted by evidence.
Institution and Segment Coverage
Clarity about which institutions and segments the product is validated to serve (banks by asset tier, credit unions, fintechs, broker-dealers, asset managers, insurers, merchants) and which product lines within them. Narrow coverage clearly stated grades well; the measure is clarity and validation, not breadth.