Compliance, Surveillance & RegTech
B

Block Convey

Block Convey builds two AI governance layers for banks, asset managers, insurers and fintechs. PRISM captures every language model call, tool invocation and reasoning step in production, scores quality, applies guardrails that strip regulated identifiers at ingestion, and exports regulator-facing evidence packs in under a minute from tamper-proof immutable traces, with compliance teams reviewing session-level transcripts rather than raw logs. PRISMX is a managed browser extension enforcing data loss prevention on consumer assistants, intercepting paste-and-prompt traffic at the endpoint so personal data, health data and source code never reach an external model.

Obligations are mapped individually across US banking model risk guidance, state cybersecurity rules, fair lending requirements, insurance model bulletins and European AI and operational resilience regimes. Supported models, cloud platforms and agent frameworks are named explicitly.

Last VerifiedAugust 16, 2026
Compare Block Convey with other vendors
Founded
2023
Headquarters
United States
Website
blockconvey.com
Categories
compliance-and-surveillance, capital-markets-ai, insurance-ai
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 10 graded A or B

AI Capability
AI Centrality
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.
Vendor Published

The product exists only because models are in production and it operates on them directly, capturing every language model call, tool invocation and reasoning step, scoring output quality, generating its own analysis of each trace with a risk level and recommendations, and running evaluations that become readiness reports.

Its own diagnosis frames the need precisely: agents in production make thousands of decisions daily, and without observability an institution has no visibility into what they are saying, whether they follow instructions, or whether they are exposing sensitive data.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

The product is oversight infrastructure and its workflow keeps people in the loop by design, moving from detection where alerts flag a quality drop, through investigation of specific traces to identify root cause, to a fix applied as a versioned prompt change, a new guardrail rule or a parameter adjustment, then verification. Guardrails act automatically at ingestion, which is appropriate for data protection. Held at B because no escalation path, severity threshold or human approval requirement is described for the automatic blocking decisions.

Model Risk Management and Transparency
AA on Model Risk Management and TransparencyExplainability and validation are built into the product and mapped to the supervisory instrument they serve: per alert attribution, backtesting or test before deploy, with a stated alignment to a framework like SR 11-7, OCC 2011-12 or NYDFS Part 504.
Vendor Published

The evidence chain is complete and each link is specified. Traces are tamper-proof and immutable from creation, which is what makes them admissible rather than merely informative; regulator-facing evidence packs export in under sixty seconds; agent trajectories and model audits reconstruct how a decision was reached; and prompts are versioned through a library, treating them as controlled model artefacts rather than editable configuration, which is a control most institutions have not yet implemented themselves. Compliance teams review session-level transcripts rather than raw interface logs, which is the difference between a record and an auditable one.

Operational and Outcome Evidence
CC on Operational and Outcome EvidenceUnnamed case studies, customer logos, or claims without numbers. Prestige is not measurement: the calibre of the client list describes the buyer rather than the product, and coverage statistics are not adoption statistics.
Vendor Published

No customer, institution or deployment is named, and no adoption count, trace volume or outcome figure is published. Verifiable presence amounts to a place in an industry sandbox programme and participation in conferences. For a governance product whose value proposition is surviving examination, the absence of a single institution willing to be named is the gap most worth closing.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

The boundary this product enforces runs outward, keeping customer data from reaching external models, and that is a real control the buyer acquires. What is missing is the same boundary drawn around the vendor itself: the platform captures every model call, tool invocation and reasoning step across its customers, which is an exceptionally rich corpus of how regulated institutions actually use AI, and nothing states whether that material informs its own models, is isolated per customer, or is retained after an engagement ends.

Regulatory and Compliance
GLBA and Data Privacy Posture
BB on GLBA and Data Privacy PostureA substantive privacy document that reaches the product itself, short of the subprocessor list or the full data handling detail.
Vendor Published

Privacy is engineered and described mechanically rather than asserted. Guardrails strip the eighteen safe harbour identifiers at ingestion, which is the recognised health de-identification standard named precisely, and social security numbers, card numbers, dates of birth and credentials are scrubbed before reaching storage rather than after. The endpoint layer prevents personal and health data leaving for an external model at all. Held at B because no data processing agreement, retention schedule or subprocessor register was located for the trace corpus that remains after scrubbing.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

No attestation, certification or trust centre was located, which is conspicuous for a company whose product is compliance evidence and which maps its releases against payment card and operational resilience standards on its customers' behalf. Technical controls are strong and described in detail, including scrubbing before storage and immutability from creation, and none of it is independently attested.

Regulatory Status and Licensure
AA on Regulatory Status and LicensureThe regulatory position is stated and a formal admission process stands behind it: a register entry, an eCBSV enrolment, a payment network partner admission, or presence inside SAR or CTR filing paths.
Vendor Published

This is the most complete regulatory mapping in the index, and unusually it is obligation-by-obligation rather than a list of logos. United States banking model risk guidance is treated correctly, with the revised interagency guidance superseding both the 2011 supervisory letter and the 2021 statement, the three-pillar discipline carried forward and scaled to each bank's model risk profile, and evidence produced at every tier.

State cybersecurity rules are mapped to AI use by covered entities. Fair lending is handled specifically, noting that the consumer regulator has confirmed equal credit opportunity requirements apply to AI-driven decisions and that adverse action notices need specific reasons, which agent trajectories and model audits generate.

Insurance model bulletins and state patchwork are covered, alongside European AI, operational resilience and data protection regimes, financial reporting controls, payment card standards, health privacy and the national AI risk framework.

AI Governance and Bias Disclosure
BB on AI Governance and Bias DisclosureAn independent demographic evaluation the vendor has submitted to, such as the NIST face evaluation class, or a governance framework with named process behind it.
Vendor Published

Fairness is a stated purpose of the product, which helps customers demonstrate their models are fair, compliant and examination-ready, and the fair lending mapping is substantive because producing specific adverse action reasons from recorded agent reasoning is the operational form that fairness obligation takes. Insurance model bulletin coverage carries related expectations. Held at B because no bias testing methodology, disparity metric or fairness evaluation approach of its own is described, so what the readiness report actually measures on fairness is unclear.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

No guarantee, indemnity or correction process was located. The product improves the position of the affected consumer indirectly and genuinely, since specific adverse action reasons generated from recorded reasoning are exactly what a declined applicant is owed, and nothing states what the vendor stands behind if an evidence pack proves incomplete under examination or a guardrail fails to catch regulated data before it reaches an external model.

Integration and Deployment
Model Supply Chain Disclosure
AA on Model Supply Chain DisclosureEvery party between the customer’s data and the output is enumerated by name, canonically through a public subprocessor list naming the model providers.
Vendor Published

This is the most complete supply chain disclosure in the index, naming twelve components across three layers. Five model families are identified with specific versions where relevant, alongside support for custom and fine-tuned models; four cloud AI platforms are named; and three agent frameworks are listed plus custom implementations.

Because the product's purpose is observing what those models do, naming them is not incidental but structural, and an institution can therefore see exactly which external dependencies sit inside the governance layer meant to document its other dependencies.

Core Systems and Integration Depth
BB on Core Systems and Integration DepthNamed systems or a documented public API, with the depth or the production evidence left open.
Vendor Published

Integration targets the AI stack rather than banking systems, and within that scope it is thorough, connecting to any system making model calls in any language or framework, with setup stated at under fifteen minutes. The endpoint product deploys through the three major enterprise device management platforms, which is the practical detail that determines whether a bank can actually roll it out. Held at B because no core banking, origination or case management system appears, so evidence produced here still has to reach the institution's own control environment by unstated means.

Deployment Model and Data Residency
BB on Deployment Model and Data ResidencyStated residency commitments or regional hosting options.
Vendor Published

Four cloud AI platforms are named as supported environments, so an institution already running models in its own cloud tenancy knows the tooling meets it there, and the endpoint layer operates on the device before data leaves. Held at B because the vendor's own hosting, region options and residency commitments are not stated, which matters for a platform that stores immutable traces of regulated decision-making.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No pricing, packaging or basis of charge was located for either product. Charging model matters unusually here because one product captures every model call and the other is deployed per endpoint, so cost could scale with either usage volume or headcount, and neither is indicated.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Coverage spans banks under model risk guidance, insurers under model bulletins and state rules, lenders under fair lending requirements, asset managers, and fintechs and insurtechs needing to demonstrate readiness to their own institutional buyers. The obligation mapping extends into health data and payment card handling, which broadens applicability beyond financial services. Held at B because breadth of addressable segment is not the same as presence in it, and no deployment in any segment is evidenced.

Head to Head

Compared With

Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.

Alternatives to Block Convey

The closest documented capability profiles to Block Convey in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Documents Security Certifications and Trust Center where Block Convey does not

A lighter documented profile than Block Convey

Stronger documented coverage on Core Systems and Integration Depth

A lighter documented profile than Block Convey

Documents AI Safety and Data Stewardship and Security Certifications and Trust Center where Block Convey does not

Documents Security Certifications and Trust Center where Block Convey does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746