AML, KYC & Financial Crime
D

Duna

Duna is a business identity platform for regulated companies, automating know your business, know your customer, customer due diligence and anti money laundering checks during onboarding. The platform collects and structures company data, routes checks to third party data providers, applies real time risk scoring and runs automated audit trails. Its stated direction is a shareable digital passport for every business, evolving into a network where one verification is reused across institutions for one click onboarding. Buyers are banks, fintechs, payment infrastructure providers and regulated platforms, concentrated in Europe.

Last VerifiedAugust 12, 2026
Compare Duna with other vendors
Founded
2023
Headquarters
Amsterdam, Netherlands
Website
duna.com
Categories
aml-kyc-financial-crime, fraud-and-transaction-risk, compliance-and-surveillance
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 4 graded A or B

AI Capability
AI Centrality
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a rules or workflow system.
Vendor Published

The company describes itself as AI native throughout and the models do real work: extraction and structuring of company documents, real time risk scoring, smart routing that decides which third party data provider to query for a given jurisdiction and entity type, and automated audit generation. The removal test still returns a product.

Strip the models and what remains is an onboarding orchestration platform with a good applicant interface, configurable workflows and connections to registry and screening providers, which is a real and saleable thing. This is the Alloy shape, where models sit on top of a decision and routing engine rather than constituting it, and it earns the same grade for the same reason.

Autonomy and Oversight Model
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism, or full automation is presented as the entire disclosure. Human in the loop appears as a phrase rather than a described control.
Vendor Published

Automation is the pitch and the oversight model is undescribed. Real time risk scoring, smart routing and automated audits are named, and the outcome claims are all throughput and conversion, but no review queue, escalation path, approval threshold or analyst adjudication surface appears in public material.

The decision being automated gates a business's access to a bank account, a payment facility or a marketplace, and the founder's own framing acknowledges that legitimate customers are refused today. Nothing describes what happens to a business the system cannot verify, whether an alternative evidence route exists, or who reviews a refusal. Compare Persona, which earns an A on this axis specifically for step up verification that routes a failing applicant into an additional evidence path instead of rejecting them.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

No accuracy figure, validation evidence, false positive or false negative rate, or model documentation was located anywhere. The published numbers are throughput and conversion, which measure how fast and how many rather than how often the system was right, and the two can move together while correctness falls.

Automated audits are named as a feature, which is the platform auditing the onboarding process rather than anyone auditing the models that drive it, the same distinction recorded for Elysian's claim review product. For output that supports a regulated institution's customer due diligence file, no validation support or documentation package is offered.

Operational and Outcome Evidence
BB on Operational and Outcome EvidenceVendor aggregate claims with real figures, or audited scale disclosures from a publicly listed company.
Vendor Published

Strong for a company founded in 2023 with 21 to 50 staff. Named customers span the buyer set rather than clustering in one segment: SVEA Bank and Brand New Day Bank on the bank side, Plaid and CCV, a Fiserv subsidiary, in payments infrastructure, plus Moss, Sequra and Bol. Outcomes are quantified and unusually specific for an early company, with customers reported as achieving onboarding 10.6 times faster, 4.8 times productivity gains and up to 38 percent higher onboarding conversion.

More than 40 million euros raised across a seed led by Index Ventures and a 30 million euro Series A led by CapitalG, Alphabet's growth fund. What holds this at B is that the outcome figures are presented as aggregates of what customers report rather than attributed to a named institution with a quoted executive, and estimated annual revenue of roughly 2.5 million dollars puts the deployed footprint well behind the naming.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

The stated destination is explicitly a cross institution data architecture: a digital passport for every business, evolving into a network for shareable identity and one click onboarding. That is the most consequential stewardship question a vendor in this lane can raise and none of the governing terms are published.

No statement of who owns a passport, whether the verified business or the institution that paid for the verification, no consent or opt out mechanism, no account of what a receiving institution sees versus what the originating one holds, and no description of how a passport is corrected or revoked. Buyers are adopting ahead of terms that do not exist yet, which is the same shape recorded for Feathery's roadmap data network. The benchmark answers to compare against are DiligenceVault consent, Saphyre permissioning and DwellFi tenant containment.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

No data protection agreement, retention schedule, subprocessor list or deletion commitment was located, and a company based in the Netherlands and Germany sits inside the European data protection regime by default. The payload deserves an explicit account that does not exist.

Know your business work resolves beneficial ownership, which means collecting identity documents and personal details for directors and ultimate beneficial owners who are individuals with no relationship to Duna and often no knowledge that a verification is running.

The shareable passport direction sharpens this further, because reuse of a business passport across institutions carries the personal data of those individuals with it, and nothing published states whose consent governs that reuse or how it is withdrawn.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

No attestation, certification, trust centre or dedicated security page was located, and no service organisation control report or international information security standard certificate is announced or offered on request. That is a visible gap for a vendor holding identity documents and beneficial ownership records on behalf of licensed banks, and it is the first item a bank vendor risk review raises. Peers in this lane set a clear bar: Sumsub and Incode both hold and publish accredited presentation attack detection certification, and Rulebase names attestations alongside residency.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

The regulatory domain is named clearly and repeatedly, know your customer, know your business, customer due diligence and anti money laundering for regulated institutions, and the company states its intent to maintain the high regulatory standards banks require. What is absent is any named instrument, supervisor or admission process.

No reference to the European anti money laundering directives or the new anti money laundering regulation and authority, no national supervisor named, no registration or accreditation, and no mapping of which obligation each product step discharges. Naming the acronyms of a regime is describing the market, not stating a regulatory position. Duna holds no licence and needs none, which is the correct posture for a technology supplier under the index convention.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

One genuine credit, then the gap. The founder names refusals of legitimate customers as a real cost alongside fraud and fines, and the platform measures a 38 percent conversion improvement, which means wrongful exclusion is treated as a tracked business outcome rather than an externality. Most identity vendors market false positive reduction purely as analyst efficiency. The gap is that no analysis of which businesses are refused is published.

The AiPrise finding applies directly: registry completeness, name matching, transliteration and adverse media coverage all perform worst in exactly the jurisdictions and for exactly the business types that are already underserved, so error rates are not evenly distributed and a conversion average conceals that. No per market accuracy, no false positive rate by jurisdiction or entity type, and no statement on how thin digital or registry footprints are treated.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

No guarantee, indemnity or falsifiable accuracy commitment was located. Two things keep this off the floor. The affected party is a business rather than an individual, so it has more capacity to contest a refusal than a declined consumer, and the vendor's incentive is genuinely aligned because it sells conversion improvement, which means a wrongful refusal is a metric it is trying to reduce. Against that sits a risk specific to the roadmap and worth stating plainly.

Today a business refused by one institution can approach another, and that second independent assessment is the de facto appeal. A shared passport reused across the network removes it: an error, a stale registry record or an adverse media false match propagates to every participant at once, and the business's existing remedy, going somewhere else, is precisely what one click onboarding is designed to eliminate. Nothing published describes correction, revocation or challenge of a passport.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

The architecture is described, the parties are not. Smart routing to third party data providers is a core capability, which means registry, screening and adverse media sources sit in the decision path for every check, and not one of them is named anywhere. No model provider, hosting arrangement or subprocessor is disclosed either, and whether company documents and beneficial ownership records reach an external model provider during extraction is unstated.

This is the fourth party question a bank examiner asks directly, and the comparison in this lane is unflattering: Alloy names more than 270 data partners each with its own page and lets the customer choose its chain, while Sumsub names specific screening providers under bring your own key.

Core Systems and Integration Depth
BB on Core Systems and Integration DepthNamed systems or a documented public API, with the depth or the production evidence left open.
Vendor Published

Smart routing to third party data providers is the substantive integration story: registry, screening and enrichment sources are selected per jurisdiction and entity type rather than the customer wiring each one, which is the same architecture that earns Alloy its position and removes real integration work from the buyer. Dynamic applicant interfaces and configurable workflows sit on top.

What is not evidenced is the other direction: no named integration to a core banking platform, case management system or customer relationship system was located, so a bank cannot confirm how verification outcomes land in the systems its analysts and examiners actually work in. No individual data provider is named either, which is where Alloy earns its A on supply chain and Duna does not.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

No cloud provider, region selection, residency commitment or private deployment option was located. For a European vendor selling to European banks the default assumption is regional hosting, but assumption is not disclosure, and the shareable passport direction makes the question harder rather than easier because a network for reusable identity implies data held centrally and accessible across institutions and borders. Nothing published describes where a passport lives or which jurisdictions it crosses when reused.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No pricing, packaging, tiers or basis of charge is published and every route into the product is a contact or demo request. Nothing indicates whether charging is per verification, per seat, per platform or a hybrid, and in this category that matters because the underlying third party data provider calls carry their own per check cost that a buyer inherits.

That is the orchestration cost stack problem first recorded with Alloy, and it is a category wide transparency gap rather than a Duna specific failing. Sumsub remains the benchmark with published per verification rates.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

The stated buyer set is large banks, fintechs, platforms and financial institutions, and the named customers bear that out across five distinct shapes: licensed banks, payment infrastructure, a payment terminals and acquiring business owned by a major processor, spend management, buy now pay later and marketplace. Built under the Persona precedent, where financial services is a named and separately maintained segment even though platforms outside financial services are also served.

The limit is geographic rather than segmental: the footprint and the registry coverage that matters most are European, with the company based in the Netherlands and Germany, and no equivalent depth is evidenced in North America or Asia.

Alternatives to Duna

The closest documented capability profiles to Duna in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Documents Autonomy and Oversight Model where Duna does not

Documents Autonomy and Oversight Model where Duna does not

Stronger documented coverage on AI Centrality

Documents Autonomy and Oversight Model and Deployment Model and Data Residency where Duna does not

Documents AI Governance and Bias Disclosure and Security Certifications and Trust Center where Duna does not

A lighter documented profile than Duna

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746