Customer & Banking Agents
B

Backbase

Backbase is an Amsterdam banking software company founded in 2003 by Jouk Pleiter, selling an engagement layer that sits above a bank's existing core, payments, cards, risk and customer relationship systems rather than replacing them. In April 2026 it launched what it calls an AI native Banking OS, built on four layers: Nexus, a semantic layer giving employees and software agents one shared record of every customer, account, product and case; an orchestration layer running customer journeys, case routing and agent workflows; Sentinel, an authority layer that checks every action by a customer, employee or agent against bank policy before it executes and records a decision token; and an intelligence layer that feeds resolved cases and human overrides back into the models.

The company acquired Kasisto in June 2026, bringing that firm's banking specific language models and agent platform into the operating system, having acquired the wealth technology firm Nucoro in 2023. Backbase reports revenue above 350 million dollars for 2025 and more than 120 financial institutions across 50 countries, including Navy Federal Credit Union, TD Bank, KeyBank, Standard Bank Group, Eurobank and Techcombank.

Last VerifiedAugust 19, 2026
Compare Backbase with other vendors
Founded
2003
Headquarters
Amsterdam, Netherlands
Categories
customer-banking-agents, wealth-and-advisory, compliance-and-surveillance
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 5 graded A or B

AI Capability
AI Centrality
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.
Vendor Published

A twenty two year old engagement banking platform that launched its model layer in April 2026. Strip the models and the platform remains: channels, journeys, onboarding, case routing and the integration layer above the core, which is what more than 120 institutions bought before any agent existed.

Graded on the Clearwater and MyComplianceOffice precedent and included for the same reason, because the models sit inside the regulated operation rather than around it, executing disputes, onboarding steps and servicing actions against bank policy. Worth recording that the vendor makes the argument that would earn a higher grade, stating that adding artificial intelligence to old banking software does not work and presenting the operating system as a rebuild rather than a layer. Nothing published substantiates a rebuild rather than a re architecture of the existing platform.

Autonomy and Oversight Model
AA on Autonomy and Oversight ModelWhat the system runs alone, what constrains it, and how a person checks it are all published: modes, thresholds, sampling or audit controls, and the route a case takes to human review.
Vendor Published

The strongest autonomy disclosure located in this index, and the discriminator is worth reusing: asserting that gates exist is a B, naming the enforcement mechanism and its position in the execution path is an A. Sentinel is described as an authority layer in which no customer, employee or software agent acts without a decision token, every action is checked against bank policy before it executes rather than after, every action is logged, and authority can be revoked at any time in any domain.

Escalation rules and audit trail generation are inherited by every agent rather than configured per deployment. What is still missing is recorded rather than ignored: no confidence threshold, no sampling audit of automated decisions, and no account of how the system behaves where policy is silent rather than explicitly permissive.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

No accuracy, precision or recall figure, benchmark or validation method was located, and the decision token audit trail is per action traceability, which makes an individual result explicable and says nothing about correctness across a corpus. There is a sharper point here than anywhere else in this index.

The architecture captures the correctness signal by design, because every human override of an agent is recorded and fed back, which means the rate at which people reverse the models is measurable inside the system today. It is not published. This is the first vendor reviewed whose own design demonstrably produces the number the category declines to disclose.

Operational and Outcome Evidence
BB on Operational and Outcome EvidenceVendor aggregate claims with real figures, or audited scale disclosures from a publicly listed company.
Vendor Published

Several named institutions at real scale, which clears the bar comfortably, alongside reported revenue above 350 million dollars for 2025. Off an A because no quantified outcome is attached to any named customer. The headline efficiency claims float free of the logos: 20 to 40 percent lower cost to serve is presented as an achievable range rather than a measured result at a named bank, and the estimate that roughly 80 percent of frontline banking work happens between systems is the company's own inference from its deployments. A named logo and a separate unattributed percentage are not the same thing as a measured outcome.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

The learning loop is published as a headline feature and its boundary is not. The company states that every resolved case, every completed journey and every human override feeds back into the models. Across more than 120 institutions in 50 countries, whether that feedback stays inside one bank or improves a shared model is the question a buyer needs answered, and it is not addressed anywhere located.

This is the sharpest form of the stewardship gap in the lane precisely because the mechanism is advertised rather than incidental, and the vendor has an easy answer if the isolation is per institution.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

No privacy programme, data protection statement or customer data handling description was located for the platform. The scope is unusually broad by design: a shared semantic record of every customer, account, product and case across an institution, plus conversational history through the acquired assistant technology, which concentrates identified customer financial behaviour in one layer. Nothing published describes retention, minimisation, or the position of the bank customers whose records populate that layer and who have no relationship with the vendor.

Security Certifications and Trust Center
BB on Security Certifications and Trust CenterA recognised certification named in the vendor’s own material without the artefact, or with a scope or renewal question the buyer has to raise.
Vendor Published

A named framework, a named report type and a named scope, which sits above the category floor: a SOC 2 Type 2 attestation of the managed hosting service against the trust services criteria for security and availability, performed by a large public accounting firm. Off an A on currency and scope rather than on the noun.

The attestation located dates from 2021 and covers the hosting of one delivery option, not the platform, the operating system or the model layer, and no trust centre, current report, penetration testing summary or certification under an information security management standard was located.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

A software vendor holding no financial licence of its own, with no supervisory programme, sandbox admission or regulator run test of the model layer located. Its customers carry the authorisations. The authority layer is explicitly positioned as enterprise artificial intelligence that a regulator can trust, which is a marketing claim rather than a credential, and no regulator has said so on the record.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

The strongest C on this axis in the lane, and the split is worth stating precisely. Authority governance is genuinely disclosed through the decision token architecture, and the company argues publicly that governance must be co designed with agents rather than appended afterwards. Fairness is absent entirely. No bias testing, no fairness evaluation, no model documentation and no independent assessment or certification of an artificial intelligence management system were located.

Agents acting on disputes, onboarding and servicing decisions affect individual customers differently, and controlling what an agent is permitted to do is not the same as testing whether what it decides is even handed. Corlytics set the A on this axis with an independently audited certification.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

Nothing published describes liability, indemnity or recourse when a software agent takes an action against a customer account and the action is wrong. The architecture makes the question more pressing rather than less, because the platform is explicitly built for agents that complete work rather than answer questions, so the failure mode is an executed transaction or an incorrectly resolved dispute rather than an inaccurate sentence. The decision token gives the institution a record of what happened, and no published framework establishes who carries the loss or how an affected customer contests the outcome.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

More is named than most of this category manages, and still not enough to trace. The acquired assistant technology brings a named banking specific language model into the operating system, and the intelligence layer is described as learning from resolved cases and overrides. No base model, provider, version or hosting arrangement is disclosed for any agent running in the operating system. An institution subject to third party and model risk oversight cannot identify what is reasoning over its customer records, who supplies it, or where it runs.

Core Systems and Integration Depth
AA on Core Systems and Integration DepthNamed integrations with the systems of record, core banking, policy administration, custodial or contact center platforms, verifiable in marketplace listings or public API documentation.
Vendor Published

The integration layer is the product rather than an adjunct to it. The platform is designed to sit above existing core banking, payments, cards, risk and customer relationship systems without replacing them, coordinating work across those systems and presenting one shared record to every actor, and it has done so across more than 120 deployments in 50 countries.

The company's own framing of the problem is itself the integration claim: it estimates that roughly 80 percent of frontline banking work happens in the handoffs and exceptions between systems that no single application owns.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

A managed hosting option exists and is named, which is more than much of this category offers, but no region choice, hosting location, tenancy model, residency commitment or subprocessor list was located. That gap is material for a vendor selling into 50 countries where several customers operate under data residency obligations, and it is more material still for a model layer whose processing location is nowhere stated.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

Enterprise licensing with pricing on request. No rate, band, module price or minimum is published anywhere located. The platform is sold as a multi year architectural commitment in which the software licence is only one component of cost, alongside implementation and change, so nothing public allows a buyer to estimate total cost of ownership even approximately.

Institution and Segment Coverage
AA on Institution and Segment CoverageThe financial segments served are named and each carries its own maintained material, whether the coverage is broad or deliberately narrow.
Vendor Published

More than 120 financial institutions across 50 countries, with the roster named rather than implied: Navy Federal Credit Union, TD Bank, KeyBank, Standard Bank Group, Eurobank and Techcombank, spanning retail banking, commercial banking, credit unions, private banking and wealth. Teams operate across North America, Europe, the Middle East, Asia Pacific, Africa and Latin America, and the company publishes regional research including a survey of 277 bank executives across Africa. Breadth is anchored to counted deployments and named institutions, which is the split that separated PerformLine from Saifr.

Alternatives to Backbase

The closest documented capability profiles to Backbase in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

A lighter documented profile than Backbase

Documents AI Centrality where Backbase does not

Documents AI Safety and Data Stewardship and Model Risk Management and Transparency where Backbase does not

Documents AI Centrality where Backbase does not

Stronger documented coverage on Operational and Outcome Evidence

Documents AI Centrality and AI Liability and Recourse where Backbase does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746