Avaloq
Avaloq is a Zurich core banking and wealth management platform founded in 1985 by Francisco Fernandez, and a subsidiary of NEC Corporation since 2020. It serves more than 170 financial institutions across over 35 countries, including private banks, wealth managers, investment managers, retail banks and neobanks, with more than four trillion Swiss francs of client assets on the platform and over 2,500 employees. The Avaloq Platform runs front to back in one architecture covering account management, payments, securities trading, portfolio management, client onboarding, digital channels and regulatory reporting.
It is delivered as cloud software as a service or on premises, and the company also operates clients' banking operations directly under a business process as a service model from hubs in Singapore and Manila. Avaloq describes a line of AI agents spanning client services, banking operations and front to back office work, and has built an artificial intelligence corporate actions processing solution with NEC that automates back office work traditionally done by hand while retaining human oversight. Named clients include RBC Wealth Management and BDO Unibank, and partner integrations include BlackRock Aladdin, Adviscent and Comyno. The company states that it reinvests around a quarter of software revenue in research and development.
Capability Axes
Capability grades
15 of 15 axes rated · 5 graded A or B
A core banking platform trading since 1985, where the models are the newest layer on a forty year old product. Strip them and everything remains: the ledger, payments, securities trading, portfolio management, onboarding, reporting and the operations business built on top.
Included on the Clearwater and MyComplianceOffice precedent because the models sit inside the regulated operation rather than around it, most concretely in corporate actions processing, which is a regulated back office obligation with real settlement consequences when it goes wrong.
This is the lowest centrality position the index builds at, and the note matters as much as the grade: the agent line is described only in outcome language, automation, insight and decision support without compromising accuracy, compliance or trust, with no named product, no scope and no launch date located.
The only oversight statement located is a single phrase, human in the loop, reported by a third party about one solution presented at a regional conference. The vendor's own published material describes the agent line by its intended outcome rather than its controls, asserting automation and decision support without compromising accuracy, compliance or trust.
That is an assertion of result, not a description of oversight, and it sits below even the configurable gates claim that held Ruleguard at a B. No gate, threshold, confidence measure, escalation path or sampling audit is described anywhere located.
No accuracy, precision or recall figure, benchmark or validation method was located for any agent or for the corporate actions solution. The failure mode in that specific application is unusually concrete and worth naming: a corporate action processed wrongly or missed produces incorrect entitlements, and the loss lands on identified account holders rather than on an abstract compliance posture. Neither an error rate nor an exception rate is published, and none of the four properties this index accepts as evidence of model risk discipline is present.
Named institutions publicly describing the platform, plus recognition as a leader in an independent analyst evaluation of worldwide wealth management technology services in 2025, which is analyst assessed rather than submitted. Industry awards were not credited, on the same basis as the submission based directories declined elsewhere in this index.
Off an A because no quantified outcome attaches to any named customer, and nothing published measures what the model layer specifically achieved: no processing volume, no straight through rate, no reduction figure for the corporate actions work the agents were built to automate.
No statement was located on training data, retention, or whether models learn across the institutions on the platform. The exposure is larger here than for a pure software vendor because of the operations business: under the business process model the company runs client banking operations directly from its own hubs, so its staff and systems handle client data as a matter of course, and an agent layer inside that operation acts on the records of institutions that compete with one another. Nothing published draws either boundary, between institutions or between the software business and the operations business.
No privacy programme, retention position, data processing terms or subject rights framework was located for the platform or the agent line. The information security certification covers confidentiality as a control objective, which is not the same as a published privacy posture.
Scope is unusually wide: a core banking platform holds the full transaction and holdings record of identified individuals, and the operations business means those records are handled by a third party the account holder has no relationship with and is unlikely to know exists.
The correct noun, used correctly: products, services and processes within the organisation hold ISO 27001 certification, and entries for group entities including the Singapore and Philippines operations are verifiable in a certification body register rather than only asserted on the vendor's own page.
Off an A because the published scope is loose, numerous products, services and processes, with no certificate scope statement, date or list of covered systems on the accreditations page itself, and no trust centre, attestation report, penetration testing summary or subprocessor disclosure was located.
A software and operations provider holding no financial licence of its own, with no supervisory programme, sandbox admission or regulator run assessment of the model layer located. Its clients carry the authorisations. The operations business does place the company inside the outsourcing arrangements that supervisors examine under operational resilience rules, which is a real regulatory relationship, but it is a client obligation rather than a credential held by the vendor.
No framework, bias testing, fairness evaluation, model documentation or independent assessment of an artificial intelligence management system was located. The parent group is named as a source of research capability in artificial intelligence, biometrics and cybersecurity, which speaks to where models come from rather than how they are governed. Corlytics set the A on this axis with an independently audited certification, and a company already holding certification under one international standard demonstrably knows how that process works.
Nothing published describes liability, indemnity or recourse when an agent acting inside core banking operations produces a wrong result. The operations business sharpens the question rather than softening it, because when the vendor runs the process as well as supplying the software, the line between a product defect and a service failure is exactly what a contract has to settle, and none of it is public. An account holder affected by a mishandled corporate action has no described route to a determination, and would in most cases not know a model was involved.
No base model, provider, version or hosting arrangement is named for any agent. The one provenance signal available is corporate: the parent group is described as the source of research capability in artificial intelligence and is a named collaborator on the corporate actions solution, which tells a buyer roughly where models originate without identifying any of them. For institutions applying third party and model risk oversight to a platform that holds their core ledger, that is not enough to trace what is running or where.
The platform is the core system rather than a layer above one, integrating core banking, portfolio management and digital channels in a single architecture and supporting multi entity, multi jurisdiction operation. Third party integration is a named part of the offering through a partner network, with a portfolio and risk analytics platform, an advisory content provider and a securities finance connectivity provider among those named. Depth is evidenced by the position rather than asserted: this is the system other wealth technology vendors in this index describe integrating into.
Deployment choice is real and stated plainly, which almost nothing else in this category offers: cloud software as a service or on premises, both developed and operated by the vendor itself, plus a fully outsourced operations option. That answers the question a bank under a data localisation obligation asks first, because on premises remains available.
Off an A because no data residency regions are named, no tenancy model is described, no subprocessor list was located, and nothing states where the models themselves run, which is the specific gap Ruleguard closed to earn the A on this axis.
No pricing, band or rate is published for the platform, the operations service or the agent line. Enterprise contracting by quote. The absence is more consequential than usual because three commercial models sit side by side, software as a service, on premises licensing and outsourced operations, and nothing public indicates how the model layer is charged across them, whether bundled, per seat or by consumption.
More than 170 financial institutions across over 35 countries with more than four trillion Swiss francs of client assets on the platform, spanning private banks, wealth managers, investment managers, retail banks and neobanks. Named clients include RBC Wealth Management and BDO Unibank. Delivery reaches Europe, Asia Pacific with hubs in Singapore and Manila, the Middle East, India and, through a 2026 group partnership, South Africa, Kenya, Mauritius and Nigeria. Multi entity and multi jurisdiction operation is an explicit design requirement rather than a claim, and the breadth is anchored to counted institutions and assets.
Alternatives to Avaloq
The closest documented capability profiles to Avaloq in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents Autonomy and Oversight Model where Avaloq does not
Documents AI Centrality where Avaloq does not
A lighter documented profile than Avaloq
Documents Regulatory Status and Licensure and Model Supply Chain Disclosure where Avaloq does not
Documents Autonomy and Oversight Model and Model Supply Chain Disclosure where Avaloq does not
Documents Autonomy and Oversight Model and Model Risk Management and Transparency where Avaloq does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.