ComplyCube
ComplyCube is a London identity verification, know your customer, know your business and anti money laundering platform led by chief executive Dr Tarek Nechma, with Harry Varatharasan as chief product officer. It sells identity assurance, screening and due diligence through one platform reaching more than 220 countries and territories, supporting over 10,000 document types, drawing on more than 3,000 data sources and processing a reported ten million transactions weekly.
The identity assurance side covers document authentication, biometric verification with liveness detection, facial age estimation, address verification, electronic identity verification and multi bureau checks against government and credit bureau records. The screening side covers sanctions and politically exposed person screening, adverse media, watchlist checks and continuous monitoring. Around them sit a workflow builder, case management, risk scoring, smart forms and a policy assurance module, delivered through a documented API, web and mobile software development kits, a hosted verification page and a no code portal.
Named industries include financial services, fintech, payments, crypto, telecoms, accounting and mobility. Its distinguishing feature is the depth of independent certification: ISO/IEC 27001:2022 for information security, ISO 9001:2015 for quality management, UK Cyber Essentials, certification as a UK Identity Service Provider under the government's Digital Identity and Attributes Trust Framework across all Levels of Confidence with 23 certified profiles covering statutory Right to Work, Right to Rent and Disclosure and Barring Service checks, ISO/IEC 30107-3 Presentation Attack Detection Level 2 testing of its face matching and liveness system, and Age Check Certification Scheme certifications to ACCS 4:2020 for age check systems and ACCS 2:2021 for data protection and privacy with zero non conformities, the latter scheme approved by the UK Information Commissioner's Office under the UK GDPR. It is also registered with the Financial Services Qualification System and runs a standing trust centre, a public status page and a self service free trial.
Capability Axes
Capability grades
15 of 15 axes rated · 11 graded A or B
The models carry the core proposition. Document authentication against more than 10,000 document types, face matching, passive liveness detection, presentation attack detection and facial age estimation are all model output, and none of them has a non model substitute at the speed and volume claimed.
Strip the models and what survives is the database side of the platform, sanctions and watchlist matching and multi bureau record lookups, which is a screening service rather than an identity assurance one, and it is the identity assurance that the certifications and the trust framework standing are built on. This sits with the rest of the document and biometric proofing tier in this index, where the verification decision is the model.
The architecture puts the customer in control of where automated decisions land, which is a real oversight property. Identity assurance is framed around selecting the appropriate Level of Confidence for a given use case, so the institution sets the threshold rather than inheriting the vendor's.
Around it sit a no code workflow builder, configurable risk scoring, a policy assurance module and case management, which together imply a human review stage in the path for anything that does not clear automatically. Held at B because none of it is described as a control: no statement says what the platform may decide alone, what escalates, what happens at low confidence, or whether a human must sign off before an applicant is refused. Configurability is not the same as a published enforcement mechanism.
Genuine independent testing of a named model, which is what separates this tier from the rest of the index. The face matching and liveness detection system was tested to ISO/IEC 30107-3 at Presentation Attack Detection Level 2, assessing its reliability in distinguishing spoofed from genuine presentations, and it met the threshold requirements.
The claim identifies the tested system rather than gesturing at a programme, which is the distinction that separated two vendors on this axis previously. Capped at B by the standing rule this index applies across the whole proofing tier: being tested by somebody else is not the same as helping the institution validate the model itself.
No accuracy figure, no false accept or false reject rate, no error taxonomy and no validation pack for a customer's own model risk function is published, and the PAD threshold result is a pass or fail rather than a measurement a buyer can reason with.
Five customers are named on the pricing page under a trusted by heading, and two of them are consequential for this index: Citi and AXA, alongside Al Baraka Banking Group, Accenture and Lycamobile. A global bank, a global insurer and a regional Islamic banking group are exactly the buyers this category claims and rarely evidences. Three aggregate figures accompany them: a 98 percent onboarding rate, a 6.2 times average return on investment, and 100 percent service uptime.
Held at B rather than A because the two halves are never joined. No case study, quotation, named executive or attributed result connects any figure to any of those institutions, so the return figure floats free of the logos above it, and the presentation is a logo wall rather than a reference.
This index has recorded elsewhere in the same pocket that a trusted by row can mix customers with suppliers and partners, and Accenture is as plausibly an implementation partner as a buyer, so what is counted here is what is asserted rather than what is demonstrated.
The safety half is genuinely evidenced and the stewardship half is absent. On safety, the biometric system has been independently tested for adversarial robustness under ISO/IEC 30107-3 at Presentation Attack Detection Level 2, which is a real external check on whether the model can be deceived, and it sits alongside an ICO approved data protection certification, employee vetting, security and privacy training from day one, encryption at rest and in transit, and least privilege access with periodic review.
On stewardship there is nothing: no statement of whether customer data, submitted identity documents, facial images or verification outcomes are retained beyond the check, reused, or used to train or improve the models. That question is sharper here than for most vendors in this index because the material in question is biometric data belonging to people who are not the customer and did not choose the vendor.
A rare A on an axis that is C across most of this index, and it rests on a certification rather than a policy. ComplyCube is independently audited and certified to ACCS 2:2021 Technical Requirements for Data Protection and Privacy, incorporating PAS 1296:2018, and that certification scheme is itself approved by the UK Information Commissioner's Office under Articles 57(1)(n) and 58(3)(f) pursuant to Article 42(5) of the UK GDPR.
A privacy certification approved by the data protection supervisory authority is a materially stronger artifact than a compliance assertion, and almost nothing in this index holds one. Around it: a named data protection officer, ICO registration, separately described UK GDPR and DPA 2018 and EU GDPR positions with annual internal and external evaluation, CCPA coverage, privacy by design stated as a development practice, and GDPR and CCPA training for all employees from their first day. Held short of perfection only in that no subprocessor list or retention schedule was located.
The most thoroughly enumerated security disclosure in this pocket. Certifications are named with versions and scope rather than shown as badges: ISO/IEC 27001:2022 for the information security management system, ISO 9001:2015 for quality management, and UK Cyber Essentials, the government backed scheme. A standing trust centre sits on its own subdomain alongside a public service status page.
Beneath the certificates the page describes the controls themselves in specific terms: AWS hosting across multiple availability zones with no data held on company premises, AES-256 encryption at rest and TLS in transit, daily encrypted redundant backups, single sign on, role based access on a least required access principle with periodic review, code repository access via an identity provider with key authentication, continuous integration testing on every commit, releases initiated only by senior staff with pre and post deployment checks and version rollback, and infrastructure built to NIST, CIS Benchmarks, DSOMM and OWASP guidance behind network and web application firewalls.
One credential test note recorded rather than deducted: the footer badge row mixes these audited certifications with GDPR and CCPA marks, which are regulations nobody certifies against, and an industry list placement.
Not a licence, but genuine standing inside a government operated framework rather than a private standards scheme, which is the distinction this index draws. ComplyCube is a certified Identity Service Provider under the United Kingdom's Digital Identity and Attributes Trust Framework, certified across all Levels of Confidence and supporting 23 certified profiles, which permits it to perform checks that discharge statutory duties including Right to Work, Right to Rent and Disclosure and Barring Service checks.
That is enrolment in a government scheme with legal effect, the same shape as the eCBSV precedent that earned a B elsewhere. It is also registered with the Financial Services Qualification System, the shared supplier qualification scheme used by UK financial institutions. Held below an A because no financial regulator supervises the AI product itself, and the eIDAS and NIST positions are alignment and mapping claims rather than certifications.
No fairness disclosure, no demographic performance data and no AI governance framework, which is the defining gap of this tier and it holds here despite the certification depth. The exposure is concrete and larger than for most vendors because of what is sold. Facial age estimation is a named product used to gate age restricted services, and age estimation error is well understood to vary by skin tone, age band and sex, so the people wrongly refused are not randomly distributed.
Face matching and liveness carry the same question. The ISO/IEC 30107-3 testing the company does hold measures resistance to spoofing, which is an adversarial property and not a fairness one, so it earns nothing here. No published false accept or false reject rate broken down by demographic group was located.
Nothing published states what happens to a person the system refuses. A wrongly rejected applicant, a face incorrectly unmatched, an age wrongly estimated or a name wrongly matched to a sanctions entry has no relationship with this vendor, no notice that an automated determination produced the outcome, and no described route to appeal or correct it.
The consequence can be exclusion from a bank account, a job through a Right to Work check, or a tenancy through a Right to Rent check, which makes the absence of a recourse route more serious here than for a purely commercial verification.
One methodological note recorded for honesty: a search snippet attributed to this vendor's compliance page carried an explicit statement that regulated clients remain directly accountable and that the provider does not assume their liability obligations, but that text was not present in the current version of the page when fetched, so it earns nothing.
No model provider, family or version is named. The company describes the technology as proprietary and its cloud host as AWS, which identifies where the platform runs and not where the inference comes from. This is the pattern this index has recorded repeatedly: vendors that license model capability tend to name suppliers, vendors that call the capability proprietary name nobody.
Nothing states whether document authentication, face matching, liveness or age estimation are built in house or licensed, and nothing addresses what training data underpins the biometric models, which is the supply chain question that matters most for a system making determinations about faces.
A strong and fully documented integration surface: a published API reference with versioning and a changelog, web and native mobile software development kits, a hosted verification page, a no code portal, single sign on support, an integration checklist and a public API status page. A buyer can assess and begin integrating without contacting sales, which is more than most of this pocket allows.
Held below an A because the depth is toward the buyer's front end rather than into their systems of record: no core banking, customer, case management or loan origination platform is named as a connection target, and while more than 3,000 data sources are claimed, none of the upstream providers is identified.
The infrastructure is described more openly than most, naming AWS as the cloud provider, stating deployment across multiple availability zones for redundancy and disaster recovery, and confirming that no data is held on company premises with no dependency on office networks.
What is missing is residency: no region is named, no jurisdictional hosting option is offered or described, and nothing states where the identity documents, facial images and verification records of people in more than 220 countries are stored or whether a customer can require them to remain in a particular jurisdiction. For a vendor whose privacy posture is otherwise its strongest asset, and whose product processes biometric data classified as special category under GDPR, the silence on residency is the notable gap.
The most complete commercial disclosure located anywhere in this index, and it resets the reference bar for the axis. Plan prices are published: Starter at 99 dollars a month, Core at 299, with Growth and Enterprise quoted. Beneath them roughly twenty individual services carry a stated unit price at each of two tiers, so a buyer can model a real bill rather than a headline: standard anti money laundering screening at 50 and 35 cents a check, extensive screening including adverse media at 1.05 and 85 cents, document verification at 1.05 and 75 cents, photo liveness and facial similarity at 35 and 20 cents, facial age estimation at 25 cents, proof of address at 65 cents, United States multi bureau at 85 cents against United Kingdom at 1.25, device, email and mobile fraud intelligence at 7 to 11 cents, ongoing monitoring at 3 cents a month, one time passcodes by email at 3 cents and by text on a five band scale from 8 to 41 cents, and additional portal seats at 30 dollars.
Commercial terms are stated rather than implied: the monthly fee converts to usage credits spendable on any check, overage bills at the plan rate, there are no setup fees, annual billing and committed volume both attract discounts, plans can be upgraded at any time, and eight settlement currencies are accepted. One term is unusually favourable and rare enough to name: the customer is charged only for verifications that complete successfully.
Genuinely broad on every dimension the axis measures. Geographic: more than 220 countries and territories, with the site itself published in seven languages. Technical: over 10,000 document types and more than 3,000 data sources. Volume: a reported ten million transactions weekly. Segment: seven named industries including financial services, fintech, payments, crypto, telecoms, accounting and mobility, addressed as separate propositions rather than listed.
And an unusual regulatory breadth on top, with 23 certified profiles under the UK trust framework covering statutory use cases such as Right to Work, Right to Rent and Disclosure and Barring Service checks, which are legally distinct products rather than variations of one check.
Compared With
Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Alternatives to ComplyCube
The closest documented capability profiles to ComplyCube in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
A lighter documented profile than ComplyCube
Documents Deployment Model and Data Residency where ComplyCube does not
Documents Deployment Model and Data Residency where ComplyCube does not
Stronger documented coverage on Operational and Outcome Evidence
Documents Deployment Model and Data Residency where ComplyCube does not
Stronger documented coverage on Autonomy and Oversight Model
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.