Elucidate
Elucidate sells a rating of a financial institution rather than a tool an institution uses on its customers, which makes it structurally different from most of this lane. Its core asset is the Elucidate FinCrime Index, a scoring engine that produces nine scores across financial crime risk themes from more than 1,200 data points and more than 17 external sources, covering money laundering, corruption, tax evasion, trafficking and terrorist financing. The buyer is typically a correspondent bank deciding whether to take on, keep or price a respondent relationship, and the scored party is another bank.
The distinguishing fact is regulatory. Elucidate GmbH is an authorised benchmark administrator under the European Union Benchmarks Regulation, on the register maintained by the European Securities and Markets Authority and supervised by the German Federal Financial Supervisory Authority. It publishes the statutory disclosures that status requires, including an Article 27 benchmark statement, an Article 26 compliance statement, a complaint handling procedure, input data protocols and a change or cessation procedure. That is a financial services authorisation with a named supervisor rather than a self asserted credential, and it covers the index specifically.
The company has since repositioned around agents. The current platform presents three products: a portfolio assessment tool applying the benchmark across a counterparty book, a risk module builder assembling composable modules into a bank's own risk engine, and Eli, described as an autonomous compliance agent that screens, investigates and decides across message formats and case management. Twelve underlying capabilities are published as callable tools, including entity extraction, sanctions screening across 38 lists, network analysis for nesting and layering, anomaly detection, and narrative generation that drafts suspicious activity reports and customer due diligence write ups.
Named customers include a large central European banking group, a savings bank group entity in Malta, two major African trade and commercial banks, and a United States global bank. The product was originally built alongside Standard Chartered, where the founder had run financial crime compliance for correspondent banking. The company is Elucidate GmbH of Berlin, founded 2018.
Capability Axes
Capability grades
15 of 15 axes rated · 8 graded A or B
Learned components carry real weight, and the company's defining asset pulls in the opposite direction for an instructive reason. On the model side, the vendor describes machine learning applied to a bank's own data to produce a numerical risk score, and the current platform publishes twelve learned capabilities including entity extraction, network analysis for nesting and layering, anomaly detection against learned norms, behavioural clustering, confidence scored fingerprint matching and narrative generation that drafts reports.
The agent layer added on top is language model work by construction. The counterweight is the benchmark itself. A regulated index under the Benchmarks Regulation must be reproducible, documented and constrained in its use of discretion, which pushes its methodology toward a specified and auditable calculation rather than an opaque learned function.
So the asset the company is regulated for, and which anchors its market position, is a methodology, while the models cluster around it in the scoring inputs and in the newer agentic tooling. Strip the models and a documented benchmark framework with a defined data intake would survive in reduced form, which is why this does not reach the top band.
The most autonomous position encountered in this competitor sweep, stated as the headline rather than buried in a feature list. The platform is presented under the line that compliance is autonomous by design, the agent is described as investigating, screening and deciding at the speed of payments, and the marketing frames the absence of a human as the benefit, saying compliance never sleeps.
Among the twelve published capabilities is narrative generation, which drafts suspicious activity reports and customer due diligence write ups. A suspicious activity report is the document a regulator and potentially a court reads, written about a party who will never see it and cannot contest it, and this index has already recorded a competitor's report drafting as an oversight concern in a case where the workflow at least stated explicitly that a human investigator judges whether to file.
No equivalent statement was located here. Across two passes nothing published describes what the agent may not decide, what a person must review or attest to before a generated narrative becomes a filing, what confidence threshold governs an autonomous disposition, or where accountability sits when it is wrong. The vendor does state that generated notes are auditable by design, which is a control on reconstructing a decision rather than on making it.
Two disclosure standards operating inside one company, and the gap between them is the finding. The benchmark is documented to a regulated standard: an Article 27 benchmark statement describing the methodology, an Article 26 compliance statement, published input data protocols defining what respondent institutions submit, a complaint handling procedure, and a change or cessation procedure telling a buyer what happens if the index is altered or withdrawn.
Continuity disclosure of that last kind is rare anywhere in this index. The stated scale of the model is specific, nine scores across risk themes built from more than 1,200 data points and more than 17 external sources, and the whole methodology sits under supervision. The agentic layer is documented to no standard at all.
Its performance appears only as figures in an animated homepage panel, 99.7 percent screening accuracy and a false positive rate under 0.1 percent, with no definition, sample, date or method, and presented as live operational readings rather than as measured results. Publishing a supervised methodology for the index and unsourced telemetry for the agent leaves a buyer unable to apply the same scrutiny to both.
Institutional references of a quality few vendors here reach, sitting beside performance figures that do not survive inspection. The references are the strong part and they are named on both sides. A member of the management board of a large central European banking group is quoted directly, as is the head of compliance and anti money laundering at a savings bank group entity in Malta.
Customer marks additionally show two major African trade and commercial banks and a United States global bank. The product was co developed with a British multinational bank whose then head of correspondent banking is quoted on the commercial rationale. An open database scoring more than 17,000 institutions was published, which is a checkable artefact rather than a claim. The reservation is specific and material.
The current homepage carries an animated panel styled as live telemetry, marked live and 24 by 7, asserting 99.7 percent screening accuracy, a false positive rate under 0.1 percent, 1.2 million transactions screened today and 4,291 alerts resolved this week. None carries a date, definition or method, and one figure in the same panel, 347 entities monitored in real time, is not reconcilable with the scale the rest of the page claims.
Real accountability machinery on the regulated side, an unevidenced claim on exactly the credential that would matter most, and unsupported numbers on the product side. The machinery is genuine: as an authorised benchmark administrator the vendor operates supervised conflict of interest and governance controls, publishes a complaint handling procedure through which a scored institution can formally challenge a result, and publishes a change or cessation procedure.
Those are accountability artefacts with a regulator behind them. Against that sit two things. The homepage asserts conformance to the international standard for artificial intelligence management systems as a badge, with no certificate, no accredited certification body, no scope statement and no announcement located across two passes, which is the one credential that would independently evidence the safety practices this axis asks about, and comparable vendors announcing the same standard name their certifier and the scope it covers.
And the same page presents accuracy and false positive figures as live operational telemetry without definition or method. No red team result, evaluation methodology, incident disclosure or acceptable use boundary was located for the agent.
A German company with the European frame properly built and the American one absent, plus a structural advantage worth naming. The advantage is that the scored subject is an institution rather than a person. The benchmark rates banks, so the compiled dossier problem that sits under most of this category, where a named individual is profiled without consent and cannot see the result, largely does not arise for the core product.
It does arise at the edges, since the agent performs customer due diligence write ups and adverse media triage on entities and the people behind them, and nothing published addresses that narrower case. On the European side the vendor publishes a privacy policy, an imprint, a modern slavery statement and, more substantively, input data protocols defining what respondent institutions submit and how it is handled, which is data governance published as a document rather than promised in prose.
Benchmark regulation additionally imposes governance and conflict of interest controls over that data under supervision. Across two passes the Gramm Leach Bliley Act appears nowhere, no United States privacy programme or safeguards position was located, and nothing states whether customer or respondent data trains the vendor's models.
Two certification marks on the homepage, one with dated evidence behind it and one with none, and no trust centre to resolve either. The information security certification is the better documented of the pair: an announcement records the award against the 2013 revision of the standard, describing the management system scope across systems, policies, processes, technology and people.
That evidence is now old enough to matter, because the 2013 revision was superseded by the 2022 revision and the transition window for existing certificates closed in October 2025, so a certificate issued against the 2013 text cannot still be current and the homepage mark names no revision, no certificate number, no certification body and no scope. Whether the vendor has recertified against the current revision is not answerable from the public record and is the first question to ask.
The artificial intelligence management standard is asserted as a mark with nothing behind it at all across two passes. No trust centre, downloadable certificate, service organisation control report, penetration test summary or subprocessor list was located. A public service status page is published.
An actual financial services authorisation with a named supervisor, published statutory disclosures and a defined scope, which is the strongest showing on this axis in this lane. Elucidate GmbH is an authorised benchmark administrator under the European Union Benchmarks Regulation, entered on the register maintained by the European Securities and Markets Authority and supervised by the German Federal Financial Supervisory Authority. This clears the credential test on every limb.
There is a verb, authorisation granted by a supervisor who can withdraw it. There is a scope boundary, the Elucidate FinCrime Index specifically. And there is evidence rather than assertion: the vendor publishes the disclosures the regulation obliges an administrator to make, including an Article 27 benchmark statement, an Article 26 compliance statement, a complaint handling procedure, input data protocols and a change or cessation procedure.
The boundary is the thing a buyer must not read past. The authorisation attaches to the index, not to the platform, the composable modules or the autonomous agent, so supervision of the benchmark should not be taken as supervision of the agent that now sits on top of it. One oddity for the record: the page carrying these disclosures is set to be excluded from search indexing.
Statutory governance over the scoring process that most voluntary disclosure does not match, set against an unexamined harm specific to what this product decides. The governance is substantive because of what benchmark regulation is for: it exists to reduce manipulation by addressing conflicts of interest, governance controls and the use of discretion in setting an index, which is algorithmic governance in all but name, applied under supervision to the exact process this vendor sells.
The published complaint handling procedure gives a scored institution a formal route to challenge its own score, which is a right of contest that almost nothing else in this index offers to the party being assessed. Published input data protocols make the intake inspectable. The unexamined part is de risking.
A low financial crime score contributes to a correspondent bank declining or withdrawing a relationship, and the documented consequence of correspondent withdrawal has fallen disproportionately on institutions in lower income and emerging markets. Across two passes nothing published addresses whether scores distribute differently by jurisdiction for reasons of data availability rather than conduct, which is the fairness question this specific product raises.
One genuine and unusual form of recourse, scoped to the wrong half of the estate. The genuine part: as an authorised benchmark administrator the vendor publishes a complaint handling procedure, which gives an institution that believes its score is wrong a documented route to challenge it, with a named supervisor standing behind the process and the power to act if it is not honoured.
Recourse for the assessed party, rather than only for the paying customer, is close to unique in this index, and the published change or cessation procedure adds a further protection by telling a customer what happens if the benchmark they depend on is altered or withdrawn. The scope problem is that both attach to the index.
Across two passes no terms of service, master agreement, warranty, indemnity, liability cap or service level with credits was located for the platform, the composable modules or the agent, and nothing addresses what is owed if the agent wrongly disposes of an alert or generates a defective report narrative that an institution files. The regulated half offers a right of complaint; the autonomous half offers nothing published at all.
The data supply chain is disclosed by count and by protocol, the model supply chain not at all. On the data side the vendor states more than 17 external sources feeding the index and 38 sanctions and watchlist sources in the screening tooling, and it publishes input data protocols governing what respondent institutions submit, so the intake is structurally described even where individual suppliers are not named.
Naming those suppliers would move this, because a buyer inheriting an index built on undisclosed data vendors carries a concentration risk it cannot see, and several of the likely suppliers are themselves indexed here. On the model side nothing is disclosed.
The platform is presented as agentic, one of its twelve capabilities drafts report narratives and due diligence write ups in natural language, and language model involvement is unavoidable in that, yet no provider, model family or version is named anywhere across two passes, and nothing states whether the models run inside the vendor's environment or whether respondent bank data or customer case material passes to a third party during generation.
Built around the message formats correspondent banking actually runs on, which is the right integration answer for this product. The vendor states native support for the international payment messaging standard and its structured successor, which matters because counterparty risk work depends on parsing the originator, beneficiary and intermediary fields those messages carry, and a product that reads them natively avoids a translation layer where detail is lost.
Around that: 38 sanctions and watchlist sources integrated, more than 12 market integrations claimed, an interface first architecture with the twelve underlying capabilities each exposed as a callable tool a customer's own systems can drive, stated integration with existing know your customer, fraud and transaction monitoring stacks, and a composable module builder the vendor puts at under four weeks to production.
Public technical documentation is maintained on its own subdomain and a live service status page is published, both reachable without contact. Holding it below the top band: the integrations are given as counts rather than named, so a buyer cannot check whether their own case management or core system is among them, and no connector catalogue or named partner list was located across two passes.
Silence on a question this buyer set does not treat as optional. Across two passes nothing published states the deployment model, the hosting provider, the available regions, the tenancy arrangement, or any data residency commitment.
The available signals are indirect and insufficient to grade on: the company is registered in Berlin with a published German address, the customer entry point is a hosted login on the vendor's own subdomain which indicates managed multi tenant software rather than a customer deployment, and a public service status page implies a single operated service. No self hosted, private cloud or on premises option is described anywhere.
The gap matters more than usual for two reasons specific to this vendor. Respondent institutions submit their own financial crime control data into the index, so the question of where a bank's internal control documentation comes to rest is a supervisory one for that bank rather than a preference. And the customer base spans five continents including jurisdictions with data localisation requirements, which a buyer cannot assess against an unstated hosting footprint.
Two passes across the vendor's own site, its product and solution pages, its press archive and the software aggregator listings produced no price, tier, unit of billing or contract term for any of the three products. The published entry route is a 30 minute demonstration, offered with no card and no commitment, at which the vendor will score a counterparty the buyer brings.
There is a structural reason a buyer might expect better here and it is worth stating without overreaching: the company's own commercial thesis is that financial crime risk should be priced explicitly and made visible to both parties in a transaction, and it built a product to do exactly that for its customers, while publishing nothing about how it prices itself.
That is an observation about disclosure rather than an accusation of inconsistency, since a regulated benchmark administrator has no obligation to publish subscription fees. What the vendor does publish, and what keeps this from sitting lower, is its change or cessation procedure, which tells a buyer what happens if the benchmark they have built a process around is altered or withdrawn. That is a continuity term most vendors never address at any price.
Narrow by product and unusually wide by geography, including in places this index rarely reaches. The product addresses one job, counterparty financial crime risk in correspondent and network banking, with separate published material for network banks and domestic banks and an extension into payment institutions.
Within that job the institutional spread is real and named: a large central European banking group, a savings bank group entity in Malta, two major African trade and commercial banks, and a United States global bank, with coverage claimed across five continents.
The African references matter more than their number suggests, because correspondent banking withdrawal has fallen hardest on exactly those markets, and a vendor whose scores bear on those decisions having those institutions as customers is a substantive coverage fact rather than a logo. The open database published scores for more than 17,000 institutions, which is coverage of the scored population rather than the buying one.
What holds this below the top band is the absence of everything adjacent: no insurance, no fintech or payment startup tier, no credit union or community bank material, and no published customer count for the paying side.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Protection Terms | Implementation | Source |
|---|---|---|---|---|
|
Not published. No price, tier, unit of billing or contract term appears on any vendor surface for the benchmark, the modules or the agent
|
Not published. Three products are sold, a portfolio assessment tool applying the benchmark across a counterparty book, a composable risk module builder, and an autonomous compliance agent, and the vendor states each can be adopted separately or together. No basis is given for any of them, so a buyer cannot tell whether charging follows scored counterparties, transaction or screening volume, modules licensed, seats, or a platform fee. The entry route published for all three is a demonstration. Separately, and not to be confused with the vendor's own pricing, one of the company's products is itself a risk pricing framework built with a British multinational bank, under which a bank's service fees to a counterparty vary with that counterparty's financial crime score, with the resulting price made visible to both parties in the transaction. | Not published at tier level. Data handling commitments sit in the regulated layer rather than the commercial one: published input data protocols define what respondent institutions submit into the index and how it is treated, and benchmark administration imposes supervised governance and conflict of interest controls over that data. A privacy policy and imprint are published. No data processing agreement, subprocessor list, retention schedule, hosting location or model training commitment was located without contact, and none of the regulated disclosures extend to the agentic platform. | No implementation, onboarding, integration or configuration fee is published for any of the three products. The vendor markets speed to production rather than pricing it, stating that a composed risk model can be configured and shipped in under four weeks and that the platform integrates with a customer's existing know your customer, fraud and transaction monitoring stack through a single interface. Public technical documentation is maintained on its own subdomain and reachable without registration, so a buying team can scope integration effort internally before entering a commercial conversation. Support arrangements, service levels and any professional services rates are undisclosed. For the index specifically there is an unpriced obligation on the customer side that a buyer should plan for: scoring depends on respondent institutions supplying data according to published input protocols, so the effort of collecting that intake across a counterparty book sits with the buyer and is not described as a vendor delivered service. | Vendor Published |
Two passes across the vendor's own site, its three product pages, its solutions pages, its press archive and the software aggregator listings produced no price, tier, unit or term for any product. The published entry route is a 30 minute demonstration stated as requiring no card and no commitment, at which the vendor offers to score a counterparty the buyer brings to the call, which is a live product trial inside a sales meeting rather than a trial period.
Worth recording without overstating it: the company's commercial argument to its customers is that financial crime risk should be priced explicitly and made visible to both parties in a transaction, and it publishes nothing about how it prices itself. A benchmark administrator carries no obligation to publish fees, so this is a disclosure observation rather than an inconsistency.
The offsetting disclosure is genuine and rare, and it is contractual rather than commercial: the published change or cessation procedure means a buyer can find out in advance what happens to them if the index they have built a process around is changed or discontinued.