Exiger
Exiger assesses risk in the third parties, suppliers and customers an organisation depends on, combining due diligence and screening engines long deployed in bank financial crime work with supplier network mapping, sanctions and denied party screening with ownership thresholds and alias resolution, and agentic automation that routes alerts to owners, launches remediation and records closure against an audit trail. Financial institutions use it for third party risk management, financial crime compliance and operational resilience obligations alongside corporate and government buyers.
Capability Axes
Capability grades
15 of 15 axes rated · 6 graded A or B
Models carry real weight here. Two named engines, one for due diligence and one for screening, are described as having been used by the largest banks for years in financial crime work, an agentic layer converts alerts into routed actions, and the company claims what it calls the most sophisticated global trade enforcement system built for identifying sanctions evasion and export control breaches.
Beneath that sits a substantial data and workflow estate: supplier network maps, ownership records, case files, attestation tracking. Apply the removal test and a risk data platform with workflow survives, diminished but functional, which places this with the platform vendors rather than the model native ones.
The agentic design is built for accountability rather than speed alone. Alerts are converted into actions with a named owner, remediation playbooks are launched, attestations requested and closures confirmed, all recorded against an audit trail, and enforcement oriented work carries shared case files with chain of custody so an investigative package holds together across teams. Chain of custody in particular is the right primitive when output supports a designation or a seizure.
What is not described is the gate: nothing states which actions an agent may take unilaterally, what threshold forces human sign off, or how a routed remediation is reviewed before it reaches a supplier.
The published seven dimension framework tells a reviewer how risk is structured, and an attributed customer quote credits a significant reduction in false positives, which is the familiar one sided metric across this category: the error that burdens the analyst is measured while the error that matters to the regulator, the risk the system did not surface, is not.
No accuracy or recall figures, model documentation, evaluation methodology or stated support for a customer's own validation were located, which is a notable gap for a vendor whose material foregrounds its artificial intelligence awards.
The validation surface is among the deepest in this index. Deployment is stated at 550 customers including 150 of the Fortune 500 and more than 50 government agencies, with an enterprise wide contract making the platform a government standard for supply chain and third party risk.
Third party assessment is extensive rather than self declared, including highest functional scores in an analyst evaluation covering both supply chain and third party risk management, recognition as a value leader in procurement technology, an industry association innovation award and more than forty awards across artificial intelligence and regulatory technology. Named case studies and attributed practitioner quotes exist, though outcome figures specific to a financial institution are not published.
A published seven dimension risk model gives buyers a stated framework for how risk is decomposed, covering foreign ownership and control, operational resilience, cybersecurity, reputational, criminal and regulatory exposure, which is more structure than most competitors disclose. The stewardship layer beneath it is not described.
No model documentation, no provenance for the underlying datasets including the forced labour corpus the company describes as the industry's largest, no statement on whether one customer's diligence work informs another's results, and no account of how the agentic layer is evaluated before it acts.
The platform assembles corporate ownership records, adverse media, trade and shipment data, sanctions listings and supplier relationships into profiles of companies and the individuals behind them, including beneficial owners who have no relationship with the customer running the search. Financial institution deployments extend that to customer risk. No published privacy framework, retention schedule, subprocessor list or statement on how individual data inside corporate records is handled was located.
No trust centre, enumerated certification list, attestation scope or audit period was located in this pass. Selection as a government wide platform handling supply chain risk for federal agencies would have required substantial security assessment, and older material references a service organisation controls accreditation, so the actual control environment is certainly stronger than the published record. The grade reflects what a buyer can verify from outside without entering procurement.
Exiger supplies technology and holds no financial licence, the expected posture, and its regulatory grounding spans an unusually wide set of named regimes: sanctions and denied party obligations, export control and trade enforcement, forced labour import prohibitions, foreign ownership control and influence rules, financial crime compliance, and the European operational resilience regulation with its third party provider requirements and turnover based penalties. Selection as a government wide platform implies passage through federal procurement and security review, though no specific authorisation is published.
The subjects here are companies and their owners rather than consumers, so the exposure is commercial rather than personal, and it is real. Sanctions and denied party screening with alias identification and ownership threshold analysis carries the same structural asymmetry seen elsewhere in this index: matching accuracy varies by naming convention, transliteration and script, and adverse media coverage is dominated by English language sources, so a supplier with non Western ownership draws a different risk picture as a property of the method. A wrongly flagged company can lose a banking relationship or a government contract. No error rates or correction process were located.
No accuracy guarantee, remediation commitment or published error rate was located, and no correction route exists for the party most exposed. A company screened by this platform and flagged for ownership, sanctions or adverse media risk may lose a banking relationship, a supplier contract or eligibility for government work, and it is not the customer, has no visibility into the assessment, and has no described mechanism to see or contest it. The audit trail serves the buyer's defensibility, not the assessed party's recourse.
Data categories are described clearly, spanning corporate registry records, trade and shipment data, sanctions and denied party lists, adverse media and a forced labour dataset, so a buyer understands what kinds of source feed a judgement. Who supplies them is not disclosed.
No individual data providers are named, no model providers are identified for the due diligence, screening or agentic layers, and no subprocessor list is published, which leaves the fourth party question unanswered for a platform whose entire output depends on external data.
The consolidation itself is the integration story: previously separate due diligence, screening and supply chain products now run under a single interface, which removes the reconciliation burden a buyer would otherwise carry across three tools. Recognition as a value leader in procurement technology implies working alongside procurement systems where supplier onboarding actually happens. What was not located is the outward detail the strongest integrators publish, with no named connector directory, no public developer documentation, no status page and no marketplace presence.
Delivery is cloud hosted software as a service with a customer base spanning commercial, financial and government users across multiple jurisdictions, and the government deployment almost certainly runs in a separated environment with its own controls. None of that is described publicly: no hosting regions, no residency options, no tenancy separation between commercial and public sector work, no transfer mechanisms and no subprocessor chain were located.
No rates, tiers, billing unit or minimum were located. The platform spans several previously separate products now consolidated under one interface, which makes the scope of any given engagement the first commercial question a buyer has, and nothing public indicates whether modules are licensed separately, how the tech enabled services component is charged, or what a financial institution deployment includes.
Banks are named consistently as a core buyer alongside corporations and government agencies, with a dedicated financial institutions practice, screening and due diligence engines built for bank financial crime, and material addressing the European operational resilience regulation and its third party provider requirements directly.
What is absent is differentiation inside financial services: no separate treatment of credit unions, insurers, asset managers or capital markets, and no institution type specific workflows. Financial services is one industry among several rather than the design centre, which is the honest cap on this grade.
Alternatives to Exiger
The closest documented capability profiles to Exiger in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Stronger documented coverage on Institution and Segment Coverage and AI Liability and Recourse
Documents Deployment Model and Data Residency where Exiger does not
Documents Model Risk Management and Transparency where Exiger does not
Documents Security Certifications and Trust Center where Exiger does not
Documents AI Safety and Data Stewardship where Exiger does not
Documents Security Certifications and Trust Center where Exiger does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.