Backbase
Backbase is an Amsterdam banking software company founded in 2003 by Jouk Pleiter, selling an engagement layer that sits above a bank's existing core, payments, cards, risk and customer relationship systems rather than replacing them. In April 2026 it launched what it calls an AI native Banking OS, built on four layers: Nexus, a semantic layer giving employees and software agents one shared record of every customer, account, product and case; an orchestration layer running customer journeys, case routing and agent workflows; Sentinel, an authority layer that checks every action by a customer, employee or agent against bank policy before it executes and records a decision token; and an intelligence layer that feeds resolved cases and human overrides back into the models.
The company acquired Kasisto in June 2026, bringing that firm's banking specific language models and agent platform into the operating system, having acquired the wealth technology firm Nucoro in 2023. Backbase reports revenue above 350 million dollars for 2025 and more than 120 financial institutions across 50 countries, including Navy Federal Credit Union, TD Bank, KeyBank, Standard Bank Group, Eurobank and Techcombank.
Capability Axes
Capability grades
15 of 15 axes rated · 5 graded A or B
A twenty two year old engagement banking platform that launched its model layer in April 2026. Strip the models and the platform remains: channels, journeys, onboarding, case routing and the integration layer above the core, which is what more than 120 institutions bought before any agent existed.
Graded on the Clearwater and MyComplianceOffice precedent and included for the same reason, because the models sit inside the regulated operation rather than around it, executing disputes, onboarding steps and servicing actions against bank policy. Worth recording that the vendor makes the argument that would earn a higher grade, stating that adding artificial intelligence to old banking software does not work and presenting the operating system as a rebuild rather than a layer. Nothing published substantiates a rebuild rather than a re architecture of the existing platform.
The strongest autonomy disclosure located in this index, and the discriminator is worth reusing: asserting that gates exist is a B, naming the enforcement mechanism and its position in the execution path is an A. Sentinel is described as an authority layer in which no customer, employee or software agent acts without a decision token, every action is checked against bank policy before it executes rather than after, every action is logged, and authority can be revoked at any time in any domain.
Escalation rules and audit trail generation are inherited by every agent rather than configured per deployment. What is still missing is recorded rather than ignored: no confidence threshold, no sampling audit of automated decisions, and no account of how the system behaves where policy is silent rather than explicitly permissive.
No accuracy, precision or recall figure, benchmark or validation method was located, and the decision token audit trail is per action traceability, which makes an individual result explicable and says nothing about correctness across a corpus. There is a sharper point here than anywhere else in this index.
The architecture captures the correctness signal by design, because every human override of an agent is recorded and fed back, which means the rate at which people reverse the models is measurable inside the system today. It is not published. This is the first vendor reviewed whose own design demonstrably produces the number the category declines to disclose.
Several named institutions at real scale, which clears the bar comfortably, alongside reported revenue above 350 million dollars for 2025. Off an A because no quantified outcome is attached to any named customer. The headline efficiency claims float free of the logos: 20 to 40 percent lower cost to serve is presented as an achievable range rather than a measured result at a named bank, and the estimate that roughly 80 percent of frontline banking work happens between systems is the company's own inference from its deployments. A named logo and a separate unattributed percentage are not the same thing as a measured outcome.
The learning loop is published as a headline feature and its boundary is not. The company states that every resolved case, every completed journey and every human override feeds back into the models. Across more than 120 institutions in 50 countries, whether that feedback stays inside one bank or improves a shared model is the question a buyer needs answered, and it is not addressed anywhere located.
This is the sharpest form of the stewardship gap in the lane precisely because the mechanism is advertised rather than incidental, and the vendor has an easy answer if the isolation is per institution.
No privacy programme, data protection statement or customer data handling description was located for the platform. The scope is unusually broad by design: a shared semantic record of every customer, account, product and case across an institution, plus conversational history through the acquired assistant technology, which concentrates identified customer financial behaviour in one layer. Nothing published describes retention, minimisation, or the position of the bank customers whose records populate that layer and who have no relationship with the vendor.
A named framework, a named report type and a named scope, which sits above the category floor: a SOC 2 Type 2 attestation of the managed hosting service against the trust services criteria for security and availability, performed by a large public accounting firm. Off an A on currency and scope rather than on the noun.
The attestation located dates from 2021 and covers the hosting of one delivery option, not the platform, the operating system or the model layer, and no trust centre, current report, penetration testing summary or certification under an information security management standard was located.
A software vendor holding no financial licence of its own, with no supervisory programme, sandbox admission or regulator run test of the model layer located. Its customers carry the authorisations. The authority layer is explicitly positioned as enterprise artificial intelligence that a regulator can trust, which is a marketing claim rather than a credential, and no regulator has said so on the record.
The strongest C on this axis in the lane, and the split is worth stating precisely. Authority governance is genuinely disclosed through the decision token architecture, and the company argues publicly that governance must be co designed with agents rather than appended afterwards. Fairness is absent entirely. No bias testing, no fairness evaluation, no model documentation and no independent assessment or certification of an artificial intelligence management system were located.
Agents acting on disputes, onboarding and servicing decisions affect individual customers differently, and controlling what an agent is permitted to do is not the same as testing whether what it decides is even handed. Corlytics set the A on this axis with an independently audited certification.
Nothing published describes liability, indemnity or recourse when a software agent takes an action against a customer account and the action is wrong. The architecture makes the question more pressing rather than less, because the platform is explicitly built for agents that complete work rather than answer questions, so the failure mode is an executed transaction or an incorrectly resolved dispute rather than an inaccurate sentence. The decision token gives the institution a record of what happened, and no published framework establishes who carries the loss or how an affected customer contests the outcome.
More is named than most of this category manages, and still not enough to trace. The acquired assistant technology brings a named banking specific language model into the operating system, and the intelligence layer is described as learning from resolved cases and overrides. No base model, provider, version or hosting arrangement is disclosed for any agent running in the operating system. An institution subject to third party and model risk oversight cannot identify what is reasoning over its customer records, who supplies it, or where it runs.
The integration layer is the product rather than an adjunct to it. The platform is designed to sit above existing core banking, payments, cards, risk and customer relationship systems without replacing them, coordinating work across those systems and presenting one shared record to every actor, and it has done so across more than 120 deployments in 50 countries.
The company's own framing of the problem is itself the integration claim: it estimates that roughly 80 percent of frontline banking work happens in the handoffs and exceptions between systems that no single application owns.
A managed hosting option exists and is named, which is more than much of this category offers, but no region choice, hosting location, tenancy model, residency commitment or subprocessor list was located. That gap is material for a vendor selling into 50 countries where several customers operate under data residency obligations, and it is more material still for a model layer whose processing location is nowhere stated.
Enterprise licensing with pricing on request. No rate, band, module price or minimum is published anywhere located. The platform is sold as a multi year architectural commitment in which the software licence is only one component of cost, alongside implementation and change, so nothing public allows a buyer to estimate total cost of ownership even approximately.
More than 120 financial institutions across 50 countries, with the roster named rather than implied: Navy Federal Credit Union, TD Bank, KeyBank, Standard Bank Group, Eurobank and Techcombank, spanning retail banking, commercial banking, credit unions, private banking and wealth. Teams operate across North America, Europe, the Middle East, Asia Pacific, Africa and Latin America, and the company publishes regional research including a survey of 277 bank executives across Africa. Breadth is anchored to counted deployments and named institutions, which is the split that separated PerformLine from Saifr.
Alternatives to Backbase
The closest documented capability profiles to Backbase in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
A lighter documented profile than Backbase
Documents AI Centrality where Backbase does not
Documents AI Safety and Data Stewardship and Model Risk Management and Transparency where Backbase does not
Documents AI Centrality where Backbase does not
Stronger documented coverage on Operational and Outcome Evidence
Documents AI Centrality and AI Liability and Recourse where Backbase does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.