Abrigo
Abrigo is a United States banking software and advisory firm serving more than two thousand four hundred community and regional banks and credit unions, formed from the combination of Banker's Toolbox, Sageworks and MST and headquartered in Austin, Texas. The portfolio spans three product lines and a consulting practice. Lending and credit risk covers commercial, consumer, small business, construction, community and equipment leasing origination alongside credit risk analysis.
Financial crime covers anti money laundering transaction monitoring, case management, regulatory reporting, sanctions, watchlist and politically exposed person screening, and check fraud detection using image analysis and consortium data. Portfolio risk covers allowance and current expected credit loss calculation, asset and liability management, income recognition, investment accounting, loan review and stress testing.
AI is layered across that estate rather than sitting underneath it, presented as a modular portfolio of agents, assistants and AI enabled features: an internal knowledge search agent, an agentic lending product, assistants for anti money laundering investigation triage, credit narrative generation and loan review, machine learning inside fraud detection and screening, and generated allowance narratives intended for examiner communication. Outputs are consistently editable and the institution retains approval of the final document.
The company also sells AI adoption and governance advisory to the same institutions, and maintains a public AI hub covering its product portfolio, its stated approach and a glossary for bankers. Reported outcomes include a pilot in which fraud detection identified ninety three percent of one bank's total fraudulent check value, roughly three hundred and thirty thousand dollars of avoided loss, alongside claimed reductions of up to eighty percent in investigation time, about thirty percent in loan review cycles and up to fifty percent in alert volume. Security is documented through service organisation control reports of both the first and the second type, each at type two, with a dedicated data platform security page.
Capability Axes
Capability grades
15 of 15 axes rated · 5 graded A or B
The Clearwater precedent applied to community banking software. This is a long established suite assembled from three predecessor companies, and the models sit on top of it rather than carry it. Strip every AI capability and a complete working product remains: loan origination, credit risk analysis, transaction monitoring, case management, regulatory reporting, allowance calculation, asset and liability management, investment accounting and loan review all continue to function, because they are deterministic software the institutions ran for years before the AI hub existed.
The AI portfolio is real and broad rather than decorative, spanning eleven named capabilities, but its role is described accurately by the vendor itself as reducing repetitive work and shortening cycle times. That is acceleration, not the product.
Human retention of the final decision is described consistently at product level rather than asserted once: credit narratives, allowance narratives and loan review outputs are all generated as editable drafts, the anti money laundering assistant prioritises and summarises alerts rather than disposing of them, the fraud engine is configurable by the institution, and the stated design intent is that staff are augmented rather than replaced.
Held at B because none of it is specified: no thresholds, no confidence bands, no description of what the agentic lending product is permitted to complete without review, and no statement of what happens when a generated narrative is approved unread. The pattern is the right shape without the enforcement detail an A requires.
The word explainable is used more often here than by almost any vendor in this index and is never once defined as a method. The vendor's own AI approach page states that explainability means outputs are intended to be understandable and defensible, which restates the goal rather than describing how it is achieved.
There is no model inventory, no validation or testing methodology, no performance metrics for any individual model, no versioning or change control disclosure, and no monitoring or drift statement. Most striking for a vendor whose buyers are examined against United States supervisory model risk management guidance, and which sells model risk relevant products such as allowance calculation and stress testing, no reference to that guidance or to any recognised AI risk framework appears anywhere in the material reviewed.
A named customer with an attributed, quantified outcome, found in a standing success stories library. First United Bank and Trust Company, a Kentucky community bank that grew from three branches to seven across four counties, implemented Abrigo Fraud Detection after establishing a dedicated fraud department in 2024.
Daily fraud review time fell from four hours to under one hour, and the bank detected approximately 130,000 dollars in counterfeit checks against a recently acquired customer account, recovering the software investment within two months. The bank's fraud lead is named and on the record.
The library carries further named institutions with named executives quoted, including Bank Independent (Asset Quality Officer in credit administration, live on the portfolio risk product two months after purchase despite a concurrent core conversion), Union Bank and Trust on the AML platform, and CommunityAmerica Credit Union on income recognition.
An earlier and weaker headline, 93 percent of an institution's total fraudulent check value and roughly 330,000 dollars avoided, is attributed only to a Southeastern U.S. bank and is no longer the strongest evidence on this record. Remaining unattributed figures include 80 percent investigation time, 30 percent faster loan review, and 50 percent lower alert volume.
The vendor raises the pooled data question itself and then leaves it open, which makes this a sharper C than simple silence. Its AI approach material describes the platform as powered by insight from thousands of institutions and tells the buyer they are therefore not relying on their own data alone, and its fraud product is explicitly built on consortium data. Both statements imply that information moves across the customer base.
Nothing then states whether client data trains shared models, whether any institution can opt out, how long data persists in a shared signal, or whether external model providers receive it. Encryption and access control are answers to a different question.
Assertions without mechanism. Encrypted data environments, robust access controls and role based permissions are stated, and the analytics product is described as carrying data permissions suited to regulated environments, but nothing specifies retention periods, subprocessors, deletion rights, or how the financial institution's customer data is segregated between the vendor's products.
No privacy specific attestation or third party verification is claimed, and the customer data protection obligations of a vendor holding transaction level data for two thousand four hundred institutions are never set out.
Precise where most of this index is vague. Two audited reports are named in the site footer of every page with their types stated explicitly, service organisation control reports of both the first and the second type, each at type two, linked to a dedicated data platform security documentation page.
The first type report is the notable one and is uncommon in this index: it covers controls relevant to financial reporting, which is the correct report for a vendor whose allowance and current expected credit loss calculations feed audited financial statements. Held at B because no examination periods, auditor names or report access process are published, there is no information security management certification, and no penetration testing or vulnerability disclosure is mentioned.
A software and advisory vendor with no licence, charter or registration of its own and no supervised standing. It is subject to examination indirectly through the third party risk management obligations of its bank and credit union customers, and it positions its products as examiner ready, but the regulated party is always the institution. No sandbox participation, supervisory programme or regulator assessment of the AI products is claimed.
A dedicated AI approach page that contains principles and no mechanisms, which is worth recording precisely because the vendor also sells AI adoption and governance advisory to the same institutions. The page offers three commitments, on data privacy, regulatory compliance and employee impact, each a paragraph of intent.
Absent from it: any fairness or disparate impact testing, any treatment of protected characteristics in lending decisions, any named governance framework, any oversight or escalation structure, any incident handling process and any statement of who inside the vendor is accountable.
For a portfolio that touches credit origination and small business lending decisions at two thousand four hundred United States institutions, fair lending exposure is the obvious governance question and it is not addressed.
No recourse position published. The exposure is concrete rather than theoretical on two fronts: a generated credit narrative or allowance narrative that an institution approves and files carries the institution's name and not the vendor's, and the fraud product runs on consortium data, so a customer wrongly carried in a shared signal can be affected at institutions that never assessed them and has no stated appeal route or signal expiry. Nothing allocates responsibility between vendor and institution when an AI generated output proves wrong, and the burden falls where it always does in this category, on the regulated buyer.
No model, provider, base model or version is named anywhere across a portfolio containing generative agents and assistants that plainly rest on large language models. The vendor's positioning turns on being safer than general purpose AI platforms because those tools cannot be approved for sensitive financial institution data, an argument that would be considerably strengthened by naming what sits underneath its own assistants and on what terms, and it declines to make it. Silence here is a choice with a visible cost to its own case.
Stronger than the usual application vendor because the products are themselves systems of record for the workflows they serve: the loan origination system, the allowance calculation and the anti money laundering case file live here rather than elsewhere.
Public developer documentation is published at a dedicated subdomain and a separate partner and integrations portal is maintained for connecting the platform into an institution's wider estate, with shared case management and data integration across the financial crime suite named as a design goal.
Held at B because no core banking, general ledger or item processing connectors are named publicly, which for a vendor serving community institutions running a small number of well known core platforms is a conspicuous omission.
Undocumented. Encrypted data environments are asserted in the AI approach material, but no deployment model is specified, no hosting arrangement or cloud provider is named, no residency position is stated and no on premises or private option is described. Given an entirely United States customer base the residency question is commercially less pressing than for a cross border vendor, which may explain the silence, but the axis measures what a buyer can learn and the answer is nothing.
Nothing published. No prices, tiers, bands, module rates or indicative ranges anywhere across a large multi product estate, and every route through the site ends at a demo request. For a vendor selling modular adoption, where the whole pitch is starting small and scaling over time, the absence of any published module level pricing is the one thing that would make that proposition concrete and it is missing.
More than two thousand four hundred regulated financial institutions, one of the largest installed bases in the index, spanning community and regional banks and credit unions across the United States. Functional coverage inside those institutions is unusually complete, reaching lending, credit risk, financial crime, allowance and current expected credit loss, asset and liability management, income recognition, investment accounting, loan review and stress testing, which means the vendor sits with several distinct buying centres at the same customer.
The limit worth recording is geographic and institutional rather than functional: this is a United States only footprint aimed squarely at community and regional institutions rather than global banks.
Alternatives to Abrigo
The closest documented capability profiles to Abrigo in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Stronger documented coverage on Security Certifications and Trust Center
A lighter documented profile than Abrigo
A lighter documented profile than Abrigo
Stronger documented coverage on Core Systems and Integration Depth
Stronger documented coverage on Core Systems and Integration Depth
Documents AI Centrality where Abrigo does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.