Coris
Coris supplies merchant risk infrastructure to the parties that underwrite merchants rather than to merchants themselves, covering software platforms with embedded payments, independent sales organisations, payment facilitators, acquiring and sponsor banks, marketplaces and lenders. It aggregates intelligence on around 330 million small and medium businesses across more than 50 countries, applies proprietary models to automate onboarding and underwriting, monitors card and ACH payments in real time using merchant and transaction signals rather than payer data alone, and issues early warning before a merchant fails.
Agents run risk playbooks by adjudicating alerts, pausing payouts and closing routine cases with full audit trails, while edge cases escalate to analysts. It integrates natively with a major payments platform's marketplace product.
Capability Axes
Capability grades
15 of 15 axes rated · 5 graded A or B
The removal test leaves a merchant database with manual review queues, which is exactly the operation being replaced. Proprietary risk models score merchants, a dedicated fraud model targets business impersonation and third party fraud, entity matching pre fills applications, agents adjudicate alerts and resolve routine cases, and assistants research merchants and summarise investigations so analysts decide in minutes rather than hours. Assessing 330 million businesses from alternative data has no rules based equivalent.
The scoping is stated plainly: agents with a human in the loop automate routine risk decisions while keeping escalation paths for edge cases, and agent activity carries full audit trails. That is the right division, since the routine cases are where volume sits and the edge cases are where judgement matters.
The qualification is what agents may do inside the routine band, because pausing a payout is a consequential act that stops money reaching a business, and nothing defines what separates a routine case from an edge case, what confidence threshold triggers escalation, or how quickly a paused merchant reaches a person.
Full audit trails on agent actions mean an automated decision can be reconstructed, which is a genuine control where an agent has paused a payout. Beyond that the published figures measure throughput rather than correctness: a 75 to 80 percent reduction in manual review time says how much work was removed, not how many of the removed reviews would have changed an outcome, and reducing false positives is claimed without a rate. No accuracy, precision or missed fraud figure is published, and for a platform that both approves merchants and stops their money the error rate in each direction is the number a buyer needs.
One customer is named with a quote about growing together, and two more are quoted anonymously, one describing obtaining structure, coverage and speed without building tools or hiring a risk team. The data asset is quantified at roughly 330 million small and medium merchants across more than 50 countries. A native integration with a major payments platform's marketplace product supplies distribution to a large installed base.
The founding credential is directly on point, with co founders having built risk and payment operations infrastructure at a payments company, a global payments network, a large technology company and a marketplace. Outcomes are stated at manual review time down 75 to 80 percent. Against that, funding stands at four million dollars from a single round and the company was founded in 2022.
No data boundary statement was located and the question here has real consequences. A merchant intelligence layer spanning 330 million businesses serves many platforms simultaneously, and merchants frequently hold accounts with several of them, so whether a risk signal generated at one payment facilitator travels with that merchant to the next is the material issue.
If it does, a business declined once may arrive pre tainted at every subsequent platform without notice or explanation; if it does not, each customer underwrites blind to what others have seen. Nothing states which applies, what is contributed to the shared layer, or whether a platform can withhold its own outcomes.
No data protection agreement, retention schedule, subprocessor list or deletion commitment was located. The subject is a business rather than a consumer, which lowers exposure, and small business underwriting necessarily reaches the individuals behind those businesses through ownership verification and impersonation checks.
A profile store covering around 330 million merchants across more than 50 countries, assembled from alternative sources, is a substantial holding and nothing published describes what is retained, for how long, or what happens to the record of a merchant that was declined.
No attestation, certification, trust centre or enumerated framework was located. Sponsor banks and payment facilitators are named buyers and both operate vendor assessment programmes under supervisory expectation, so a published control set is the artifact that unlocks that segment, and for a company holding risk profiles on hundreds of millions of businesses its absence is the most visible gap in an otherwise well specified product.
No supervisor, statute or instrument is named, and transaction monitoring is described as detecting compliance violations without identifying which. The gap matters because sponsor banks are a named buyer type and they carry specific supervisory obligations for oversight of the payment facilitators and platforms operating under their sponsorship, which is precisely the risk this product manages. Naming that framework would connect the product to the obligation it discharges.
The subject is a small business and the consequences are immediate, since a declined or paused merchant is often a firm whose cash flow stops that day, which is the severity point recorded at Porters transposed to commerce. Two exposures follow from the method.
Assessment rests on alternative data, so merchants with thin digital footprints, newly formed, informally operated, offline heavy or outside major markets generate weaker profiles and worse outcomes, in a data set spanning more than 50 countries where coverage cannot be uniform. And business impersonation detection carries the naming convention and common name false positive problem documented elsewhere in this index. No error analysis by merchant type, size or geography was located.
No guarantee, indemnity or falsifiable commitment was located. The platform customer is reasonably served, since full audit trails let it reconstruct why an agent declined a merchant or paused a payout and defend that to its own sponsor bank.
The merchant has nothing: a small business whose payouts are paused by an automated decision is not told what triggered it, cannot see the alternative data or signals that produced the assessment, and has no described route to contest it before the money stops.
Sources are described only by category, as alternative data about merchants drawn from multiple sources and combined with external signals and the customer's own data, and the models are stated to be proprietary. For a platform whose assessments rest entirely on what those external sources contain, the absence of any named provider leaves a buyer unable to judge coverage, freshness or licensing across the more than 50 countries claimed. No model provider is named for the agents or assistants, and no subprocessor list or hosting arrangement was located.
A native integration with a major payments platform's marketplace product is named and is the most consequential connection available in this market, since it reaches the software platforms that route merchant payments through that infrastructure. Delivery spans a developer interface with published documentation for screening, onboarding and monitoring, and a no code portal for reviewing profiles, alerts and cases, so both engineering and risk teams have a route in. The company also states it handles integration and setup itself with launch in weeks. No other named platform integration appears.
No hosting provider, region selection, residency commitment or private deployment option was located. Merchant data spans more than 50 countries and buyers include sponsor banks whose regulators expect documented oversight of where third party processing occurs, so a stated position would be expected as the customer base moves upmarket.
No pricing is published, with the model described as customised to business needs and scale and a demonstration required to obtain terms. Two adoption signals are given: the company handles integration and setup with launch stated in weeks rather than months, and its own risk specialists configure rules and workflows for each customer. Both address effort rather than cost, and nothing indicates whether charge falls per merchant screened, per transaction monitored or as a platform fee.
Eight buyer types are named explicitly, spanning software platforms with embedded payments, independent sales organisations, payment facilitators, acquiring and sponsor banks, marketplaces, buy now pay later and point of sale financing providers, business to business payments companies and lenders, and the company states its users are those who own merchant risk directly rather than consumer facing businesses or individual merchants. Merchant data coverage spans more than 50 countries.
Functional coverage runs the full lifecycle from onboarding and underwriting through transaction monitoring to disputes. The limit is that all of it serves one function, merchant risk, however many buyer types consume it.
Alternatives to Coris
The closest documented capability profiles to Coris in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents Model Risk Management and Transparency where Coris does not
Documents AI Safety and Data Stewardship and Model Risk Management and Transparency where Coris does not
Stronger documented coverage on Institution and Segment Coverage
Documents Regulatory Status and Licensure where Coris does not
Documents Regulatory Status and Licensure where Coris does not
Documents GLBA and Data Privacy Posture and Model Risk Management and Transparency where Coris does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.