Lending & Banking Operations
B

Bottomline

Bottomline is payments infrastructure with fraud analytics layered on top, and the proportions matter for how this record reads. The company moves more than 16 trillion dollars a year across four connected businesses: Paymode, a business payments network with more than a million businesses on it exchanging over 500 billion dollars annually, a commercial digital banking platform sold to banks, financial messaging where the company is a top three service provider on the interbank messaging network, and cash management for corporate treasury.

The artificial intelligence sits in two places. Payments Fraud Defense, released in January 2026, consolidates behavioural analytics, interdiction, analytics tuning and session replay into one platform that the vendor positions explicitly as complementing a bank's existing fraud systems rather than replacing them. Its detection draws on the company's own analytics plus insights from third party risk solutions and consortium data, and it is aligned to named rail level obligations including the 2026 automated clearing house fraud monitoring rules. A pilot Fraud Intelligence Exchange launched in June 2026 to move fraud intelligence sharing between banks off manual processes. Separately an embedded agent was added to treasury and cash management in late 2025.

The network and the fraud work reinforce each other in a way worth noting: a 2026 capability inside the digital banking product analyses a bank's own payment history to identify customers still paying heavily by cheque and routes them toward electronic rails, which the company frames as fraud reduction through channel migration rather than through detection.

Founded 1989 in Portsmouth, New Hampshire, Bottomline listed on Nasdaq in 1999 and traded publicly for 23 years before Thoma Bravo took it private in May 2022 for roughly 2.6 billion dollars. It divested its legal spend business in 2025 to concentrate on payments, and American Express connected its buyer initiated payments into Paymode in 2026. Chief executive Craig Saks previously ran parts of ACI Worldwide.

Last VerifiedAugust 25, 2026
Compare Bottomline with other vendors
Founded
1989
Headquarters
Portsmouth, New Hampshire, United States
Categories
lending-and-banking-operations, fraud-and-transaction-risk, payments-intelligence
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 4 graded A or B

AI Capability
AI Centrality
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.
Vendor Published

The removal test leaves almost the whole company standing, and the vendor's own positioning says so. Payments Fraud Defense is described as designed to complement existing fraud systems and to work alongside the wider portfolio without a rip and replace project, which is the language of an addition rather than a foundation.

Take the models out and what remains is a payments business moving more than 16 trillion dollars a year: a business payments network with a million businesses on it, a commercial digital banking platform banks license, a top three position on the interbank financial messaging network, and corporate cash management. None of that is learned.

The learned components are real and current rather than decorative, covering behavioural analytics and adaptive detection in the fraud platform and an embedded agent added to treasury and cash management, and one 2026 digital banking capability analyses payment history to identify cheque heavy customers, which is analysis rather than modelling. This is a payments utility that has built artificial intelligence products, not an artificial intelligence company that processes payments.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

The platform can stop money moving, and it is nonetheless built around a human investigator. Interdiction is named as a capability and the vendor speaks of spotting anomalies across payment rails sooner so that action is faster and more decisive, which means the system is capable of holding a payment in flight. That is autonomous action on money movement and should be recorded as such.

Everything around it, though, is constructed for a person: session replay and analytics tuning exist specifically to reduce alert fatigue and accelerate case resolution for fraud teams, the platform is positioned as complementing an institution's existing fraud systems rather than superseding their judgement, and the bank owns the risk policy the interdiction runs under. No automatic closure of alerts, no autonomous filing and no agent disposing of a case is described anywhere.

The embedded treasury agent is a separate product and is not adjudicative. What is missing is the boundary in writing: nothing states what will not be interdicted automatically, or what a business whose legitimate payment is held is told.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

Directional claims with no number attached to any of them. The fraud platform is described as continuously refining analytics for greater accuracy and fewer false positives, as detecting anomalies sooner, and as building models that learn from real world attack patterns and adapt to identify complex behaviours with greater precision. Every one of those is a comparative statement without a baseline, a figure or a measurement.

The statistics the vendor does publish are third party research about the threat environment rather than about the product, covering industry fraud incidence, growth in deepfake driven losses and reported account takeover losses, and while those are properly attributed they say nothing about how this system performs. Across two passes no accuracy, detection rate, false positive rate, validation methodology, sample, observation period, drift or retraining disclosure was located.

The absence carries weight because institutions deploying this to satisfy a mandated rail level fraud monitoring obligation owe their supervisors an account of how the model performs, and none of that account is public.

Operational and Outcome Evidence
BB on Operational and Outcome EvidenceVendor aggregate claims with real figures, or audited scale disclosures from a publicly listed company.
Vendor Published

Scale evidence of a kind almost nothing in this index can match, and no outcome evidence for the product being graded. The scale is stated precisely and much of it is externally checkable: more than 16 trillion dollars in payments moved annually, over a million businesses on the payments network exchanging more than 500 billion dollars a year, more than 800 financial institutions served, a top three position as a service provider on the interbank messaging network, and roughly 90 percent of the Fortune 100 touching the platform.

The company also carries 23 years of audited public company disclosure before its 2022 take private at approximately 2.6 billion dollars, which leaves a historical record no privately held competitor here offers. A 2026 integration bringing a major card network's buyer initiated payments into the network is a named, verifiable partnership, and an industry award recognised the digital banking product in 2026. The gap is specific. Those figures describe the payments business.

For the fraud platform this record grades, no named bank customer, no detection rate, no false positive figure and no loss avoided figure was located across two passes, and the intelligence sharing capability remains a pilot.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

One data flow is disclosed clearly enough to raise the right question, and then the question goes unanswered. The vendor states that its fraud detection strategies draw on insights from third party risk solutions and consortium data, and separately that it has launched a pilot exchange to move fraud intelligence sharing between banks off the manual processes banks use today.

Disclosing that models are fed from outside the company is more candid than most, and the observation motivating the exchange, that manual sharing is slow and limits visibility across institutions, is correct. What follows from it is not addressed.

Nothing published describes what crosses an institutional boundary in that exchange, whether it is aggregated or identifiable, what a participating bank's customers are told, or how a business wrongly implicated by another institution's intelligence is unwound. The same silence covers whether customer payment data trains models used for other customers. Across two passes no model card, evaluation methodology, red team result, incident disclosure or acceptable use boundary was located.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

A thin public surface under an unusually heavy data burden. What this company holds is not incidental: payment instructions, bank account and routing details, vendor master records, remittance data and commercial banking credentials for more than a million businesses, plus the message traffic it carries as a top three service provider on the interbank network.

Across two passes no privacy programme detail, data processing description, retention schedule or subprocessor disclosure was located on the public surface beyond ordinary website policies, and the Gramm Leach Bliley Act appears nowhere despite a United States base and a customer base of United States banks.

One architectural point is stated and does bear on this axis: the fraud platform runs on what the company describes as its own secure regulated proprietary cloud rather than on a third party hyperscaler, which reduces the number of parties touching the data, though the word regulated is not attached to any named regulator. A vendor operating in the United Kingdom and Europe also carries obligations that are not addressed publicly.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

A disclosure gap rather than a security one, and the gap is wide given what stands behind it. Two passes located no trust centre, no named certification or attestation, no report available under agreement, no penetration test summary and no subprocessor list on the public surface. The only security language located is the assertion that the fraud platform runs on secure regulated proprietary cloud infrastructure, which is an architecture statement rather than a credential.

The controls almost certainly exist and have been examined hard: a top three service provider on the interbank financial messaging network operates inside that network's mandatory customer security programme, more than 800 financial institutions have run third party risk assessments on this company, and it moved through 23 years as a public reporting company. None of that is discoverable from outside. The practical effect is that a smaller institution without the leverage to demand documents in procurement, and anyone assessing the vendor from the public record, cannot establish what it holds.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

An unregulated supplier with two forms of standing that are more concrete than the usual claims, and no licence. The first is rail level: the fraud platform is stated to comply with evolving requirements across major payment rails and names the 2026 automated clearing house fraud monitoring rules specifically, which is a dated, mandatory obligation with the product positioned against it rather than a general assertion of helping with compliance.

The second is conferred rather than self declared: top three service provider status on the interbank financial messaging network is a position granted by the network operator, which runs its own security programme that participants must satisfy, so it carries external assessment behind it. Neither is a financial services authorisation and the company claims none.

What is absent across two passes is any published position on the European operational resilience regime, despite the company being an information technology supplier inside European banking customers' regulatory perimeter, and any position on the European artificial intelligence regulation.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

The subject scored here is a business rather than a consumer, which changes the shape of the exposure without removing it. When interdiction holds a payment, the party harmed is a company that may be running payroll, paying a supplier under terms, or meeting a tax deadline, and the consequences of a wrongly held payment are contractual and immediate.

The governance question is sharpened by where the signal comes from: detection draws on third party risk solutions and consortium data, so a business's treatment can be shaped by information it never supplied, cannot see, and has no route to correct, and the planned intelligence exchange would extend that across institutions.

Nothing published addresses whether detection performs differently by business size, sector, geography or payment pattern, which matters because smaller and newer businesses with thinner payment histories are the ones an anomaly model has least basis to judge. Across two passes no bias testing, fairness statement, model card, governance page or artificial intelligence regulation position was located.

AI Liability and Recourse
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.
Vendor Published

No commercial instrument is published. Across two passes no terms of service, master agreement, warranty, indemnity, liability cap, service level or uptime commitment was located on any public surface, and nothing addresses what an institution or a business is owed when the platform is wrong. The uncovered exposure is more concrete here than at most vendors in this index because the failure mode is not a mis scored alert but a payment that does not arrive.

Interdiction holds money in flight, and a wrongly held payment can mean staff unpaid, a supplier contract breached, or a filing deadline missed, with consequences that are contractual and dated rather than reputational. The party bearing them is a business that is often not the vendor's customer, since the bank licenses the platform and the business experiences the hold. Nothing published describes what that business is told, how quickly a hold is reviewed, or where liability sits between the vendor and the institution when the model is wrong.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

The dependency is admitted, which is the harder half, and then nothing is named. The vendor states plainly that its detection strategies draw on insights from trusted third party risk solutions and from consortium data, creating models that learn from real world attack patterns. That is an unusually direct acknowledgement that the analytics are not built solely in house and that outside data shapes the output, and vendors more often present a blended pipeline as wholly proprietary.

Having admitted it, the company names nothing: no third party risk provider, no consortium, and no indication of how many suppliers sit beneath the platform or what happens to detection quality if one relationship ends. Several plausible suppliers are themselves indexed here, so a buyer could be paying twice for the same signal without being able to tell. On the generative side, an embedded agent now ships in treasury and cash management and no model provider, family or version is named for it anywhere across two passes.

Core Systems and Integration Depth
BB on Core Systems and Integration DepthNamed systems or a documented public API, with the depth or the production evidence left open.
Vendor Published

Integration into the systems money actually moves through, which is a deeper form of connection than a connector catalogue. The company is a top three service provider on the interbank financial messaging network, which is infrastructure level participation rather than an integration, and it operates across multiple rails including automated clearing house, a premium tier of it, wires and real time schemes.

The fraud platform is explicitly designed to sit alongside an institution's existing fraud tools rather than displace them, and to work with the company's own digital banking, messaging and payments network without a rip and replace project, which is a commitment to coexistence that many competitors will not make.

The clearest demonstration is the digital banking product embedding the payments network inside a bank's own commercial banking environment so corporate customers transact without leaving it, and a major card network's buyer initiated payments were wired into that network in 2026. Holding it below the top band: across two passes no public interface documentation, developer portal, sandbox or connector catalogue was located, so an engineering team cannot scope work independently.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

One real architectural disclosure and none of the detail that would let a buyer act on it. The vendor states that the fraud platform runs on its own secure regulated proprietary cloud infrastructure rather than on a third party hyperscaler, and describes that as delivering superior compliance and safety. Operating owned infrastructure is a genuine and increasingly uncommon choice, and it does reduce the number of parties in the data path, so it belongs on the record as a positive fact.

The word regulated is doing unexamined work, however: no regulator is named, and cloud infrastructure operated by a software company is not itself a regulated entity in the way a bank is, so a buyer should establish what the term refers to before repeating it internally. Beyond that the picture is blank.

Across two passes nothing published states which regions process or store data, whether residency can be pinned for United Kingdom, European or other customers, what the tenancy model is, or whether any customer hosted or on premises option exists across the four business lines.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No price, unit or tier is published, and two passes across the vendor's site, its product and newsroom pages and the software aggregator listings produced nothing on how any of the four businesses are charged. The published entry route is a contact form. Two disclosures give a buyer more than silence.

The first is a deployment cost claim rather than a price: the fraud platform is described as deploying rapidly and delivering measurable value within weeks, and as integrating alongside existing tools without a costly rip and replace, which speaks to implementation burden even though no figure supports it.

The second is unusual and runs in the customer's favour: the payments network publishes that eligible payers can earn rebates on payment spend, so part of the commercial model returns money to the customer and the company says so openly. What remains unknown is everything structural. Nothing indicates whether charging follows payment volume, transaction count, seats, institutions or modules, and with four distinct businesses under one brand a buyer cannot tell what is bundled.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Both sides of the payment served by the same company, which is genuinely unusual in this lane. On the institution side there is a commercial digital banking platform licensed by banks, financial messaging where the company holds a top three service provider position on the interbank network, and a fraud platform sold to bank fraud teams, with more than 800 financial institutions stated.

On the corporate side there is a business payments network with more than a million businesses on it, cash management and treasury tooling, and stated reach into roughly 90 percent of the Fortune 100. Because the company sits on both ends it can do things a single sided vendor cannot, such as embedding its payments network inside a bank's own digital banking environment so corporate customers never leave it.

Geographic reach spans the United States and United Kingdom with global operations. Holding it below the top band: no financial institution is named anywhere, no material addresses credit unions or community banks as a distinct segment, and insurance, wealth and capital markets are absent entirely.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis Data Protection Terms Implementation Source
Not published. No price, unit of billing, tier or contract term appears on any vendor surface across the four business lines
Not published on any vendor surface. Four distinct businesses are sold under one brand, covering a business payments network, a commercial digital banking platform, financial messaging and a fraud platform, and nothing published indicates whether they are licensed separately or as a portfolio, nor whether charging follows payment volume, transaction count, institutions, seats or modules. One commercial mechanic is disclosed and runs toward the customer rather than away: eligible payers on the payments network can earn rebates on payment spend, which the vendor publishes as a benefit of moving payments onto electronic rails. Scale context published by the vendor, offered here as background rather than as pricing, includes more than 16 trillion dollars in payments moved annually and more than 500 billion dollars exchanged across the payments network each year. No tiered data protection terms are published. Across two passes no data processing agreement, subprocessor list, retention schedule or hosting region disclosure was located on the public surface. The one architectural statement bearing on data handling is that the fraud platform runs on the company's own secure regulated proprietary cloud infrastructure rather than a third party hyperscaler, which reduces the number of parties in the data path, though no regulator is named against the word regulated. Nothing published addresses what customer payment data or fraud outcomes contribute to models used for other customers, which matters because detection is stated to draw on consortium data. No implementation, onboarding, integration or professional services fee is published for any product line. The vendor markets deployment speed rather than pricing it, stating that the fraud platform deploys rapidly and delivers measurable value within weeks, and that it integrates with existing fraud tools and the wider portfolio without a costly rip and replace project, which is a claim about avoided cost rather than a disclosure of charged cost. The work involved is not trivial and the material implies as much: the digital banking product embeds the payments network inside a bank's own commercial banking environment, and the financial messaging business operates at service provider level on the interbank network, both of which are substantial programmes inside a bank's own change cycle. Across two passes no public interface documentation, developer portal or sandbox was located, so a buying institution cannot scope integration effort independently before entering a commercial conversation. Vendor Published

Two passes across the vendor's site, its product and solution pages, its newsroom and the software aggregator listings produced no price, unit or tier for any of the four business lines. The published entry route is a contact form. Two disclosures are worth recording because they are more than most enterprise vendors here offer. The rebate mechanism on the payments network is a published commercial term running in the customer's favour, which is unusual to state openly.

And the deployment claims are specific enough to be tested in a proof of concept, namely value within weeks and no rip and replace, even though no figure supports them. What a buyer still cannot do is compare. With a payments network, a digital banking platform, financial messaging and a fraud platform sold under one brand, nothing published indicates which are licensed together, whether the fraud platform can be bought without the payments estate, or what basis applies to each, and those are the first three questions in any evaluation against a single line competitor.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746