Fraud Detection & Transaction Risk
B

BioCatch

BioCatch analyses how a person physically and cognitively interacts with online and mobile banking, covering typing cadence, navigation patterns, hesitation and signs of duress, and turns those signals into real time fraud risk for the bank. Its platform targets account opening fraud, account takeover, social engineering scams and money mule accounts, and it runs an inter bank intelligence sharing network in Australia that lets participating banks act on behavioural financial crime signals collectively.

Last VerifiedAugust 8, 2026
Compare BioCatch with other vendors
Founded
Headquarters
Categories
fraud-and-transaction-risk, aml-kyc-financial-crime
Assessment

Capability Axes

AI Capability
AI Centrality
A
Vendor Published

There is no non model version of this product. The company reports analysing more than 16 billion user sessions and collecting more than 3,000 behavioural signals to protect over half a billion digital banking customers, and the differentiating capability is inferential rather than deterministic: detecting hesitation, confusion and external pressure to identify a customer acting under a criminal's direction. Behavioural sequencing and predictive intelligence are the named mechanisms. Strip out the models and there is no signal at all, only raw telemetry.

Autonomy and Oversight Model
B
Vendor Published

The architecture keeps the bank in charge by design. BioCatch produces behavioural risk signals that flow into the institution's existing fraud workflow and, through digital banking platform integrations, surface inside the bank's own online and mobile channels, so the decision to hold a payment or close an account stays with the institution.

The stated intent is proportionate response, applying additional security only where behaviour indicates elevated risk rather than adding blanket friction. What is not described publicly is the analyst side: no case management surface, no documented review queue, and no stated route by which a customer wrongly flagged as a mule has that judgement revisited.

Model Risk Management and Transparency
C
Vendor Published

Conceptual transparency is better than average. The company publishes substantial explanatory research, including a five persona taxonomy for mule accounts distinguishing willing participants from coerced victims, and the quarterly fact sheet imposes some discipline on the numbers it circulates.

The supervisory package is absent: no model documentation, no validation summary, no published false positive or detection rates outside individual customer anecdotes, no retraining or drift monitoring description, and no stated position on supporting a bank's own model validation.

Operational and Outcome Evidence
A
Vendor Published

Case studies are quantified and varied across geography and institution type: a top five United Kingdom bank saving 500,000 pounds a month by catching voice scams in progress, a large Australian financial services organisation stopping more than 90 percent of fraudulent payments while disrupting mule operations, a United States credit union cutting residual peer to peer payment fraud losses 95 percent in two months, a Latin American bank reducing false positives 66 percent, and a top five card issuer reporting a 10 million dollar annual uplift from new account fraud detection.

Scale is stated at more than 350 retail banks. Two practices stand out: the company publishes a fact sheet refreshed every quarter, which is unusual metric discipline, and it runs original survey research across 800 fraud and financial crime leaders in 17 countries. Institutions are mostly identified by tier rather than by name, which is the one thing holding the evidence short of fully checkable.

AI Safety and Data Stewardship
C
Vendor Published

Two structures deserve scrutiny and only one is disclosed. The disclosed one is positive: BioCatch Trust Australia is described openly as the first inter bank behaviour based financial crime intelligence sharing network, meaning signals derived from one institution's customers inform decisions at another, though nothing public defines what crosses the boundary, how it is de identified or what consent underpins it. The second is the capability itself.

Inferring cognitive state, that a user is confused, hesitant or under coercion, is a materially more sensitive act than fingerprinting a device, and no public governance describes how those inferences are bounded, validated or prevented from being repurposed.

Regulatory and Compliance
GLBA and Data Privacy Posture
C
Vendor Published

The privacy structure here is distinctive and under documented. Behavioural telemetry is collected passively and continuously from more than half a billion banking customers who hold a relationship with their bank and none with BioCatch, so notice and consent rest entirely on the institution with no published guidance on how that should be handled.

There is also a legal gap worth naming: the strictest United States biometric privacy statutes enumerate retina, iris, fingerprint, voiceprint and hand or face geometry, and behavioural patterns arguably fall outside that list, meaning the most pervasive form of biometric collection in banking may sit outside the regime built for biometrics. No public privacy framework, retention schedule or service provider position was found.

Security Certifications and Trust Center
C
Vendor Published

Searching the public site and surrounding sources in this pass surfaced no trust centre, certifications page, attestation list or scope statement. A vendor processing continuous behavioural telemetry for more than 350 banks almost certainly holds the standard attestations, and several of its banking customers would require them contractually, but this index grades what a buyer can verify rather than what is likely, so the grade reflects the absence of published evidence rather than a judgement that controls are weak. Worth revisiting if a trust surface is published or located.

Regulatory Status and Licensure
B
Vendor Published

BioCatch supplies technology and holds no financial licence, the expected position. Its regulatory anchoring is clearer than most because the products map onto named obligations: strong customer authentication under the European payment services regime, and mule account identification and proactive closure which sit inside anti money laundering duties and suspicious activity reporting.

Standing up an inter bank intelligence sharing network in Australia required navigating a domestic supervisory and competition framework, which is a form of formal engagement even though no specific authorisation is published.

AI Governance and Bias Disclosure
D
Vendor Published

This is the most serious governance gap encountered in the index so far, and it follows directly from how the technology works. Risk is inferred from typing rhythm, navigation fluency, hesitation and session length, and every one of those varies systematically with age, motor impairment, tremor, neurodivergence, screen reader and assistive technology use, digital literacy and whether the customer is operating in a second language.

A model that reads atypical interaction as suspicious will tend to flag elderly, disabled and less digitally fluent customers more often, and the consequence is a blocked payment, a step up challenge or an account closed as a suspected mule. Nothing public addresses accessibility, demographic error rates, assistive technology handling or independent fairness testing.

Integration and Deployment
Core Systems and Integration Depth
B
Vendor Published

The integration pattern is embedded rather than orchestrated. BioCatch runs inside the institution's own digital banking experience through platform partnerships, with a documented integration into a major digital banking provider that places live session risk signals directly into online and mobile banking, so the bank gains signal without redirecting the customer anywhere. Coverage spans web and mobile across devices. Public developer documentation, a partner directory of the breadth seen elsewhere in this lane, a service status page and a changelog were not found in this pass.

Deployment Model and Data Residency
C
Vendor Published

Delivery is cloud hosted and operates across multiple continents, with deployments published in the United Kingdom, Australia, Latin America, the United States and France. The Australian intelligence sharing network strongly implies in country infrastructure and a domestic data boundary, which would be a meaningful residency capability if it were described.

It is not: no public material enumerates hosting regions, residency options, cross border transfer mechanisms or subprocessors, which matters given that behavioural telemetry from European and Australian banking customers is involved.

Commercial
Commercial Transparency
C
Vendor Published

Pricing is absent from public materials at every level, with no rates, tiers, minimums or unit of charge disclosed, and enterprise banking sales run through contact and demo paths. Given that pricing in this category typically keys to session or user volume, a buyer cannot even determine the billing unit from the public site, let alone estimate cost.

Institution and Segment Coverage
B
Vendor Published

Depth in banking is real, spanning retail, corporate and wealth management institutions plus credit unions and payments organisations, with published deployments across the United Kingdom, Australia, Latin America, the United States and France and survey reach into 17 countries on five continents. The limit is channel rather than geography.

The product observes digital sessions on web and mobile, so it does not extend to branch, call centre or in person origination the way the identity platforms in this lane do, and adjacent financial segments such as insurance and capital markets are not addressed.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

AI FinTech Index

An independent reference for evaluating AI vendors in financial services. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
August 8, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746