Compliance, Surveillance & RegTech
A

ACA Group

ACA Group is a governance, risk and compliance provider to financial services firms, founded in 2002 by five former regulators and headquartered in New York. It pairs an advisory and managed services business of more than 1,400 professionals with ComplianceAlpha, its regulatory technology platform, which carries modules for marketing and financial promotions review, electronic communications surveillance and archiving, employee compliance and personal trading, market abuse surveillance, anti money laundering and customer identification checks, compliance management, and training. The firm reports more than 6,350 clients and more than 1,600 firms on the platform.

Encore AI, launched in September 2025, is the proprietary model layer running across those modules. Encore AI for Marketing Review, released in February 2026, scans documents to flag potentially non compliant language, missing disclosures and inconsistencies using machine learning tagging, and produces audit ready reports with traceable review history; the underlying module reports nearly 1,300 clients, over 143,000 submissions and roughly 8.9 million pages of content reviewed. A separate release brings model based extraction of employee brokerage statements into personal trading surveillance. The platform is sold on its own or alongside ACA managed services, and the group also operates a Financial Conduct Authority regulated hosting umbrella through ACA Mirabella.

Last VerifiedAugust 19, 2026
Compare ACA Group with other vendors
Founded
2002
Headquarters
New York, New York, United States
Categories
compliance-and-surveillance, aml-kyc-financial-crime
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 5 graded A or B

AI Capability
AI Centrality
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.
Vendor Published

Encore AI launched in September 2025 as a model layer across a platform that had been shipping for years, and the marketing review module reports roughly 8.9 million pages reviewed before that layer arrived. Strip the models and the entire product remains: a workflow, archive and case management platform plus an advisory business of more than 1,400 people. Graded on the same removal test as Clearwater, MyComplianceOffice and Red Oak, and included for the same reason those were.

The models sit inside the regulated operation rather than around it. Noise reduction in communications surveillance decides which employee messages a supervisor ever sees, and marketing flags decide what a reviewer looks at before a filing under the marketing rule of the United States Securities and Exchange Commission.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

Sequencing is clearly disclosed and consistently stated. The model flags potentially non compliant language, missing disclosures and inconsistencies, and a compliance reviewer retains the approving decision, with human validation named explicitly on the personal trading extraction. Off an A on two counts. No threshold, confidence measure or sampling audit is published for any module.

And enhanced noise reduction in communications surveillance automatically filters low value content out of the review queue, which is an autonomous suppression decision taken before any human sees the item, and it is described only by its benefit.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

No accuracy, precision or recall figure, benchmark or validation method was located. What is published is audit ready reporting with traceable review history, which makes any individual result explicable and says nothing about how often the system is right across a corpus. The failure that matters is a missing disclosure the model never flagged, which produces no record to trace and reaches investors inside approved material. Scale figures count pages processed rather than errors caught or missed, which is the volume for accuracy substitution recorded against this whole category.

Operational and Outcome Evidence
CC on Operational and Outcome EvidenceUnnamed case studies, customer logos, or claims without numbers. Prestige is not measurement: the calibre of the client list describes the buyer rather than the product, and coverage statistics are not adoption statistics.
Vendor Published

The scale figures are the most specific in this pocket and every one of them is firm reported: 8.9 million pages, 143,000 submissions, 6,350 clients. No customer is named anywhere located. Published case studies are anonymised by size rather than identified, one described only as a ten billion dollar investment adviser, and platform testimonials carry no attribution.

Directory and list recognitions were not credited, on the same basis as the submission based rankings declined elsewhere in this category. Worth recording that this is the pocket norm rather than a failing unique to this vendor: almost every financial promotions vendor reviewed names no customer at all, with Luthor the single exception.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

Nothing is published about whether the model layer learns from client content, and this platform holds the largest cross client corpus in the pocket by a wide margin: marketing material, archived employee communications, personal trading records and brokerage statements belonging to thousands of firms that compete with each other. A second boundary sits alongside the model one and is equally undescribed.

Managed services staff work inside client systems by design, so the question is not only what the models retain across clients but what people employed by the vendor can see. The firm has an easy answer to both if the isolation is per client, and has not given it.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

The General Data Protection Regulation is named alongside encryption in transit and at rest and role based access control, which is more than most of this pocket offers, but it appears as a single assurance line rather than a described privacy programme. The scope point matters more than the wording.

Employee compliance and personal trading modules hold brokerage statements, holdings and trade requests belonging to identified individuals, and communications surveillance holds their messages. These are people whose employer bought the system, and no notice, access or correction route for them was located.

Security Certifications and Trust Center
BB on Security Certifications and Trust CenterA recognised certification named in the vendor’s own material without the artefact, or with a scope or renewal question the buyer has to raise.
Vendor Published

Named controls and a named framework, which lifts it above the pocket floor: compliance with SOC 2 and the General Data Protection Regulation, encryption in transit and at rest, audit logging and role based access control. The group also runs its own cybersecurity practice performing risk assessments, vendor due diligence and penetration testing for clients. Off an A on the noun, applied here as it was to Ruleguard: complying with SOC 2 is not holding a report. No report type, scope, date, auditor or trust centre was located, and the assurance appears as one answer in a frequently asked questions block rather than as published evidence.

Regulatory Status and Licensure
BB on Regulatory Status and LicensureThe regulatory position is clearly stated and appropriate to the product, with part of the verification left to the buyer.
Vendor Published

The group holds real regulatory authorisation rather than a programme placement. ACA Mirabella operates a regulatory hosting umbrella in the United Kingdom and European Union, which requires an authorised principal firm, and the group performs verification against the Global Investment Performance Standards.

Products are built to named regimes including the marketing rule of the United States Securities and Exchange Commission and the advertising standards of the Financial Industry Regulatory Authority. Off an A because no financial regulator has supervised, tested or admitted the model layer itself, which is the bar CleverChain set.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

Governance is asserted for the model layer in the language of transparency, auditability and human control, with no framework named, no bias or fairness testing described, and no independent audit or certification of an artificial intelligence management system. The gap is sharper here than anywhere else in this category because the firm sells governance advice on this exact subject.

It publishes guidance for broker dealers on governing artificial intelligence use, analysis of regulators converging on governance expectations, and a survey reporting that most firms increased their own testing this year. A buyer following this vendor's published advice could not evaluate this vendor's own model layer using anything the vendor publishes.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

Nothing published describes liability, indemnity or recourse when a model assisted review misses a disclosure and the material reaches investors. The services hybrid raises the question in its sharper form, as it did for NuArca, Red Oak and Luthor. Reviews can be delivered by the vendor's own managed services team using the same model layer and backed by former regulators, so a determination looks materially like professional judgement, and who stands behind it is not addressed. The individuals subject to personal trading and communications surveillance have no described route to contest a determination made about them either.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

Encore AI is described as proprietary and purpose built for compliance, which is positioning rather than disclosure. No base model, provider, version or hosting arrangement is named for any module, and no statement was located about whether third party foundation models sit underneath. A customer subject to the third party and vendor oversight expectations this firm advises other companies on cannot identify the model supply chain of the system reviewing its regulated communications.

Core Systems and Integration Depth
AA on Core Systems and Integration DepthNamed integrations with the systems of record, core banking, policy administration, custodial or contact center platforms, verifiable in marketplace listings or public API documentation.
Vendor Published

Integration is counted rather than claimed. Communications capture runs through more than 85 connectors across enterprise platforms using native capabilities and proprietary partnerships, covering email, collaboration tools and mobile devices. The employee compliance module reaches feed level coverage of statements from any brokerage, which is the integration most personal trading systems lack.

Single sign on is supported, user management can be automated from connected workflow systems, and the modules read across one another so communications, employee conduct and market abuse data can be viewed together.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

Described only as a secure cloud platform. No region choice, no hosting location, no tenancy model, no on premises path and no subprocessor list were located, despite the firm operating across the United States, United Kingdom, European Union and Middle East and selling to firms carrying residency obligations in each. Ruleguard shows what a complete answer looks like in this same market at a fraction of the size.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No pricing is published. The stated answer is that pricing is customised by firm size, regulatory need and modules selected, with a quote on request. Module based packaging is at least disclosed in structure, so a buyer can see what the units of purchase are, but no rate, band or minimum is given for any of them. The pairing of platform and managed services makes it worse than a missing price list, because the total cost of a working deployment is not derivable from anything public.

Institution and Segment Coverage
AA on Institution and Segment CoverageThe financial segments served are named and each carries its own maintained material, whether the coverage is broad or deliberately narrow.
Vendor Published

Breadth is anchored to counted facts rather than asserted, which is the split that separated PerformLine from Saifr. The firm reports more than 6,350 clients and more than 1,600 firms on the platform, and the marketing module alone reports nearly 1,300 clients and over 143,000 submissions.

Segments named across the business include asset managers, investment advisers, private funds, hedge funds, broker dealers, wealth managers, investment companies, commodity trading advisors, banks and insurers. Regimes span the United States Securities and Exchange Commission, the Financial Industry Regulatory Authority, the Commodity Futures Trading Commission and National Futures Association, the Financial Conduct Authority, and the Dubai and Abu Dhabi financial services regulators.

Alternatives to ACA Group

The closest documented capability profiles to ACA Group in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Documents Operational and Outcome Evidence where ACA Group does not

Documents Operational and Outcome Evidence where ACA Group does not

Documents AI Centrality and Operational and Outcome Evidence where ACA Group does not

Documents AI Centrality and Operational and Outcome Evidence where ACA Group does not

Documents AI Centrality and Operational and Outcome Evidence, among others where ACA Group does not

Documents AI Centrality and Operational and Outcome Evidence, among others where ACA Group does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746