AML, KYC & Financial Crime
E

Entrust

Entrust sells identity verification to banks, payment companies and other regulated institutions through a named product line built on the Onfido technology it acquired in 2024. Document verification and facial biometrics run under Atlas AI for fully automated end to end checks, with a drag and drop orchestration layer letting an institution combine document checks, biometrics, trusted data sources and passive fraud signals into journeys tuned to its own risk, friction and regulatory requirements.

The position is distinctive because the parent also manufactures the card issuance infrastructure banks use, so verifying a customer and issuing them a physical debit card can happen in one continuous flow.

Last VerifiedAugust 12, 2026
Compare Entrust with other vendors
Founded
Headquarters
Minneapolis, Minnesota, United States
Categories
aml-kyc-financial-crime, fraud-and-transaction-risk, customer-banking-agents
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 6 graded A or B

AI Capability
AI Centrality
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a rules or workflow system.
Vendor Published

Models carry the verification itself. Atlas AI is stated to power fully automated end to end identity verification, with document intelligence and facial biometrics doing the judging and passive fraud signals running alongside, and the company describes the artificial intelligence as developed in house.

Against that, the platform is explicitly a combination of models and non model components, mixing document and biometric checks with trusted data sources under a no code orchestration layer that lets an institution assemble a journey. Strip the models and that orchestration layer plus the data source connections would remain and would still be useful, which is the Alloy and Signzy position rather than the pure computer vision position HyperVerge occupies.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

The architectural framing is better than most in this lane and it is published as a design principle rather than a feature. Identity verification is positioned explicitly as step up authentication for high risk or high value transactions, so the intended pattern is that friction is applied selectively where risk warrants it rather than uniformly to everyone, and the orchestration layer lets an institution tailor verification methods to individual user and market needs to meet its own risk, friction and regulatory thresholds.

That is real configurable control. What holds it below the top grade is direction. Persona earns an A because a failing applicant is routed into an additional evidence path, whereas step up here escalates into verification on risk signals rather than offering a recovery route out of a failed check, and the underlying engine is described as fully automated end to end with no manual adjudication surface named.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

No accuracy figure, false match or false rejection rate, validation evidence, error analysis or model documentation was located. Award winning artificial intelligence and catching the fraud others miss are competitive claims rather than measurements, and no accredited presentation attack detection result or independent benchmark appears.

For a product whose entire function is a binary judgement about whether a person is who they claim to be, the absence of any published error rate in either direction is the central gap, and it is more conspicuous here than for a smaller vendor given the scale of the installed base.

Operational and Outcome Evidence
AA on Operational and Outcome EvidenceNamed customers with hard performance figures and enough method to test them.
Vendor Published

The evidence surface is large and multiply sourced. The identity verification product is stated to serve more than 950 global businesses, and at acquisition the underlying business carried more than 1,200 customers and published annual recurring revenue above 130 million dollars, which is a figure almost nobody in this index discloses. A strategic acquirer paid a reported 650 million dollars for it after diligence, which is scrutiny of a different kind.

Prior named bank deployments are reported in trade coverage, and the banking page carries customer testimony from digital first institutions describing onboarding and sign up work, though those references are anonymised. The parent brings its own scale, with more than 2,500 staff across 150 countries, more than 30 billion payment and identity cards issued and over 100 million identities protected.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

No data boundary statement was located. The company states its artificial intelligence is developed in house and that automated security defences take a layered approach to fraud detection, which describes where the models come from without describing what they learn from.

Nothing addresses whether verification attempts submitted by one institution's applicants improve models serving another, which is the standing question in this lane and one that carries weight at a footprint of 950 plus businesses, nor whether biometric captures form part of any training corpus.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

No data protection agreement, retention schedule, subprocessor list or deletion commitment specific to the verification product was located. The payload is document images and facial biometrics, which is the category of personal data that cannot be reissued once exposed, and the parent states it protects more than 100 million identities without describing the terms on which any of them are held.

One indirect signal exists, since the acquired technology is described by the acquirer as having proven itself in Europe's high compliance environment, which implies practice shaped by a strict regime, but an implication drawn from an acquisition statement is not a published privacy position.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

No attestation, certification, trust centre or enumerated framework specific to the identity verification product was located, and no accredited presentation attack detection certification appears, which is the assurance a buyer compares directly in this lane and which two peers publish.

The situation is unusual because the parent is itself a trust infrastructure company whose certificate business operates under formal external audit and root programme requirements, so the organisational capability plainly exists, and none of it is presented as covering this product. Assurance that exists elsewhere in a group is not assurance a buyer of this line can rely on.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

Compliance is asserted repeatedly and no instrument is named. The material refers to complying with global regulations, meeting international regulations and standards, and to the technology having proven itself in a high compliance European environment, none of which identifies a supervisor, statute or admission process for the verification product.

The gap is notable because the parent's certificate business operates under formal external audit regimes and root programme requirements that are genuine passed processes, and none of that assurance transfers to this line or is claimed to. Naming compliance without naming the rule is describing the market.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

The company makes an explicit fairness claim and does not evidence it. Document verification is described as powered by award winning artificial intelligence and as fair, accurate and fast globally, and fairness is exactly the property that biometric and document verification cannot be assumed to have, since demographic error differentials in face matching are the best documented in applied machine learning and document recognition degrades on identity formats from less represented jurisdictions.

No demographic performance data, per market accuracy or independent evaluation result was located. The contrast within this lane is direct: Incode and HyperVerge both hold the higher grade specifically because they submitted their face models to government evaluations that measure those differentials by design, and asserting fairness without that submission is a weaker position than saying nothing.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

No guarantee, indemnity or falsifiable accuracy commitment was located. The institution holds genuine control through the orchestration layer, since it sets which checks apply to which users and can widen or narrow its own thresholds, which is challenge capability for the buyer. The party with no route is the applicant.

A person whose document is rejected or whose face fails to match is not told which system reached that conclusion, cannot see the result or the signals behind it, and no alternative evidence path or human review is described for them. Step up authentication escalates on risk rather than offering a way back from a failed check, so it does not fill that gap.

Integration and Deployment
Model Supply Chain Disclosure
BB on Model Supply Chain DisclosureSubstantial partial disclosure, or a chain that is structurally short: an explicit in house build, on premise deployment, per customer instances, or zero retention at the model layer.
Vendor Published

The model layer is stated to be built in house, with automated defences described as using artificial intelligence developed internally rather than licensed, which shortens the chain at the point that matters most and is the same disclosure that earns Incode its position on this axis. The commercial chain is also partly visible, with both major card networks and two major enterprise software providers named in the partner network.

What remains undisclosed is the data half: the platform explicitly draws on trusted data sources as one of its verification inputs and not one of those sources is identified, so an institution cannot establish which registries, bureaus or watchlists sit behind a decision. No subprocessor list or hosting arrangement was located.

Core Systems and Integration Depth
AA on Core Systems and Integration DepthNamed integrations with the systems of record, core banking, policy administration, custodial or contact center platforms, verifiable in marketplace listings or public API documentation.
Vendor Published

No other identity vendor in this index occupies this position. Verification connects forward into physical card issuance, so an institution can onboard a customer, authenticate them and issue a debit card within minutes in one continuous flow, and the parent has issued more than 30 billion payment and identity cards and supplies the issuance infrastructure banks run in branches.

Beyond that the verification layer extends across the parent's identity and access management, digital signing and authentication portfolio, so the same verified identity supports account recovery, high risk transaction protection and workforce verification rather than sitting isolated at onboarding. A drag and drop orchestration studio handles the configuration, and the partner network includes both major card networks and major enterprise platforms.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

No hosting provider, region selection, residency commitment or private deployment option was located for the verification product. The question is material given a footprint across more than 150 countries and a payload of biometric captures and identity documents, where transfer and localisation rules differ sharply by market, and the European heritage of the acquired technology raises rather than settles the question of where processing now occurs following integration into a United States parent.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No pricing, packaging or basis of charge is published for the identity verification line and every route in is a contact request. The question has real shape here because the product can be bought standalone or as part of a broader identity and access strategy spanning onboarding, account recovery, transaction protection, biometric authentication and digital signing, and nothing indicates how those are priced separately or together, or whether verification is charged per check or per protected customer.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Financial services is a named and separately maintained segment with its own banking page, its own customer references and a stated use case sequence specific to the industry, covering onboarding, authentication and card issuance. Coverage within it spans retail banks, digital first challengers and payments companies.

The limit is that this sits alongside government, travel, gaming, retail, healthcare and enterprise workforce verification as one vertical among several, so the product is a general identity platform with a substantial and deliberately maintained financial services practice rather than a purpose built financial institution product, which is the Persona position.

Alternatives to Entrust

The closest documented capability profiles to Entrust in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Documents Regulatory Status and Licensure where Entrust does not

A lighter documented profile than Entrust

A lighter documented profile than Entrust

Documents Regulatory Status and Licensure where Entrust does not

Stronger documented coverage on Institution and Segment Coverage

Documents AI Safety and Data Stewardship and AI Governance and Bias Disclosure where Entrust does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746