Fraud Detection & Transaction Risk
B

BioCatch

BioCatch analyses how a person physically and cognitively interacts with online and mobile banking, covering typing cadence, navigation patterns, hesitation and signs of duress, and turns those signals into real time fraud risk for the bank. Its platform targets account opening fraud, account takeover, social engineering scams and money mule accounts, and it runs an inter bank intelligence sharing network in Australia that lets participating banks act on behavioural financial crime signals collectively.

Last VerifiedAugust 8, 2026
Compare BioCatch with other vendors
Founded
Headquarters
Categories
fraud-and-transaction-risk, aml-kyc-financial-crime
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 6 graded A or B

AI Capability
AI Centrality
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.
Vendor Published

There is no non model version of this product. The company reports analysing more than 16 billion user sessions and collecting more than 3,000 behavioural signals to protect over half a billion digital banking customers, and the differentiating capability is inferential rather than deterministic: detecting hesitation, confusion and external pressure to identify a customer acting under a criminal's direction. Behavioural sequencing and predictive intelligence are the named mechanisms. Strip out the models and there is no signal at all, only raw telemetry.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

The architecture keeps the bank in charge by design. BioCatch produces behavioural risk signals that flow into the institution's existing fraud workflow and, through digital banking platform integrations, surface inside the bank's own online and mobile channels, so the decision to hold a payment or close an account stays with the institution.

The stated intent is proportionate response, applying additional security only where behaviour indicates elevated risk rather than adding blanket friction. What is not described publicly is the analyst side: no case management surface, no documented review queue, and no stated route by which a customer wrongly flagged as a mule has that judgement revisited.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

Conceptual transparency is better than average. The company publishes substantial explanatory research, including a five persona taxonomy for mule accounts distinguishing willing participants from coerced victims, and the quarterly fact sheet imposes some discipline on the numbers it circulates.

The supervisory package is absent: no model documentation, no validation summary, no published false positive or detection rates outside individual customer anecdotes, no retraining or drift monitoring description, and no stated position on supporting a bank's own model validation.

Operational and Outcome Evidence
AA on Operational and Outcome EvidenceNamed customers with hard performance figures and enough method to test them.
Vendor Published

Case studies are quantified and varied across geography and institution type: a top five United Kingdom bank saving 500,000 pounds a month by catching voice scams in progress, a large Australian financial services organisation stopping more than 90 percent of fraudulent payments while disrupting mule operations, a United States credit union cutting residual peer to peer payment fraud losses 95 percent in two months, a Latin American bank reducing false positives 66 percent, and a top five card issuer reporting a 10 million dollar annual uplift from new account fraud detection.

Scale is stated at more than 350 retail banks. Two practices stand out: the company publishes a fact sheet refreshed every quarter, which is unusual metric discipline, and it runs original survey research across 800 fraud and financial crime leaders in 17 countries. Institutions are mostly identified by tier rather than by name, which is the one thing holding the evidence short of fully checkable.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

Two structures deserve scrutiny and only one is disclosed. The disclosed one is positive: BioCatch Trust Australia is described openly as the first inter bank behaviour based financial crime intelligence sharing network, meaning signals derived from one institution's customers inform decisions at another, though nothing public defines what crosses the boundary, how it is de identified or what consent underpins it. The second is the capability itself.

Inferring cognitive state, that a user is confused, hesitant or under coercion, is a materially more sensitive act than fingerprinting a device, and no public governance describes how those inferences are bounded, validated or prevented from being repurposed.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

The privacy structure here is distinctive and under documented. Behavioural telemetry is collected passively and continuously from more than half a billion banking customers who hold a relationship with their bank and none with BioCatch, so notice and consent rest entirely on the institution with no published guidance on how that should be handled.

There is also a legal gap worth naming: the strictest United States biometric privacy statutes enumerate retina, iris, fingerprint, voiceprint and hand or face geometry, and behavioural patterns arguably fall outside that list, meaning the most pervasive form of biometric collection in banking may sit outside the regime built for biometrics. No public privacy framework, retention schedule or service provider position was found.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

Searching the public site and surrounding sources in this pass surfaced no trust centre, certifications page, attestation list or scope statement. A vendor processing continuous behavioural telemetry for more than 350 banks almost certainly holds the standard attestations, and several of its banking customers would require them contractually, but this index grades what a buyer can verify rather than what is likely, so the grade reflects the absence of published evidence rather than a judgement that controls are weak. Worth revisiting if a trust surface is published or located.

Regulatory Status and Licensure
BB on Regulatory Status and LicensureThe regulatory position is clearly stated and appropriate to the product, with part of the verification left to the buyer.
Vendor Published

BioCatch supplies technology and holds no financial licence, the expected position. Its regulatory anchoring is clearer than most because the products map onto named obligations: strong customer authentication under the European payment services regime, and mule account identification and proactive closure which sit inside anti money laundering duties and suspicious activity reporting.

Standing up an inter bank intelligence sharing network in Australia required navigating a domestic supervisory and competition framework, which is a form of formal engagement even though no specific authorisation is published.

AI Governance and Bias Disclosure
DD on AI Governance and Bias DisclosureNothing published on a product where the bias risk is concrete, such as credit decisioning or underwriting with no fair lending, disparate impact or adverse action disclosure.
Vendor Published

This is the most serious governance gap encountered in the index so far, and it follows directly from how the technology works. Risk is inferred from typing rhythm, navigation fluency, hesitation and session length, and every one of those varies systematically with age, motor impairment, tremor, neurodivergence, screen reader and assistive technology use, digital literacy and whether the customer is operating in a second language.

A model that reads atypical interaction as suspicious will tend to flag elderly, disabled and less digitally fluent customers more often, and the consequence is a blocked payment, a step up challenge or an account closed as a suspected mule. Nothing public addresses accessibility, demographic error rates, assistive technology handling or independent fairness testing.

AI Liability and Recourse
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.
Vendor Published

This is the weakest recourse position in the index relative to the harm the product can cause. A behavioural risk score can see a payment blocked or an account closed as a suspected mule, and the affected customer is never told that their typing rhythm and hesitation patterns were scored, by whom, or on what basis. No accuracy guarantee, no published error rate, no correction route, and no described process for a customer wrongly identified as a mule to have that judgement revisited.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

Behavioural signals are collected first hand from sessions in the bank's own digital channels, so the primary data chain is short and owned rather than purchased, which is a genuine structural advantage over enrichment based competitors. Against that, the inter bank intelligence sharing network means signals derived at one institution reach another, a supply relationship between customers that is disclosed in outline but never specified. No model providers, external data suppliers or subprocessors are named.

Core Systems and Integration Depth
BB on Core Systems and Integration DepthNamed systems or a documented public API, with the depth or the production evidence left open.
Vendor Published

The integration pattern is embedded rather than orchestrated. BioCatch runs inside the institution's own digital banking experience through platform partnerships, with a documented integration into a major digital banking provider that places live session risk signals directly into online and mobile banking, so the bank gains signal without redirecting the customer anywhere. Coverage spans web and mobile across devices. Public developer documentation, a partner directory of the breadth seen elsewhere in this lane, a service status page and a changelog were not found in this pass.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

Delivery is cloud hosted and operates across multiple continents, with deployments published in the United Kingdom, Australia, Latin America, the United States and France. The Australian intelligence sharing network strongly implies in country infrastructure and a domestic data boundary, which would be a meaningful residency capability if it were described.

It is not: no public material enumerates hosting regions, residency options, cross border transfer mechanisms or subprocessors, which matters given that behavioural telemetry from European and Australian banking customers is involved.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

Pricing is absent from public materials at every level, with no rates, tiers, minimums or unit of charge disclosed, and enterprise banking sales run through contact and demo paths. Given that pricing in this category typically keys to session or user volume, a buyer cannot even determine the billing unit from the public site, let alone estimate cost.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Depth in banking is real, spanning retail, corporate and wealth management institutions plus credit unions and payments organisations, with published deployments across the United Kingdom, Australia, Latin America, the United States and France and survey reach into 17 countries on five continents. The limit is channel rather than geography.

The product observes digital sessions on web and mobile, so it does not extend to branch, call centre or in person origination the way the identity platforms in this lane do, and adjacent financial segments such as insurance and capital markets are not addressed.

Head to Head

Compared With

Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.

Alternatives to BioCatch

The closest documented capability profiles to BioCatch in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Stronger documented coverage on AI Governance and Bias Disclosure and AI Liability and Recourse

Documents Model Risk Management and Transparency and Model Supply Chain Disclosure where BioCatch does not

Stronger documented coverage on Institution and Segment Coverage and AI Governance and Bias Disclosure

Documents Security Certifications and Trust Center where BioCatch does not

Stronger documented coverage on AI Governance and Bias Disclosure and AI Liability and Recourse

Documents Model Risk Management and Transparency where BioCatch does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 549 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 21, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746