Fraud Detection & Transaction Risk
F

Featurespace

Featurespace sells the ARIC Risk Hub to banks, acquirers and payment processors, a real time machine learning platform that builds an individual behavioural profile for every customer and scores each payment against it rather than against fixed fraud rules. Its Adaptive Behavioral Analytics and Automated Deep Behavioral Networks profile normal activity, peer group behaviour and scam patterns, and adapt continuously as behaviour and attack methods change. ARIC Scam Detect extends the same approach to authorised push payment scams. The company was founded out of Cambridge University engineering research and was acquired by Visa in December 2024, and the platform is now also distributed as a Visa solution.

Last VerifiedAugust 12, 2026
Compare Featurespace with other vendors
Founded
2008
Headquarters
Cambridge, United Kingdom
Categories
fraud-and-transaction-risk, aml-kyc-financial-crime
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 8 graded A or B

AI Capability
AI Centrality
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.
Vendor Published

The removal test leaves nothing at all. The company began as machine learning research in a university engineering department and the product is the model: Adaptive Behavioral Analytics builds a behavioural profile for each individual customer, Automated Deep Behavioral Networks extend it across peer groups and scam patterns, and the system is described as adapting by itself to changing behaviour and new attack types.

There is no rules engine, case management system or data platform underneath that would survive the models being taken out. The design premise is itself model dependent, since profiling what normal looks like for a specific person and detecting deviation from it cannot be expressed as static rules.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

The boundary is described concretely in a deployment rather than asserted in policy. Every payment is evaluated in real time, and where a payment is judged suspicious the system tells the bank to stop it and flags it as suspicious so it can be investigated further, which places the machine on the recommendation side and an identifiable institution on the decision side, with a named investigation step after the flag.

That is a clear division for a product operating at full transaction volume. What is missing is the specificity Federato publishes: no threshold at which a payment is held automatically rather than flagged, no sampling or audit of decisions the model made without escalation, and no statement of how a stopped payment is released once investigated.

Model Risk Management and Transparency
BB on Model Risk Management and TransparencyReal transparency mechanisms are published, such as per alert explainability, confidence scoring or split testing, without the validation package or supervisory mapping behind them.
Vendor Published

This vendor publishes numbers in both error directions, which almost nothing else in this index does. On the detection side a named institution reports a 90 percent reduction in phishing losses year on year. On the false positive side the company has published that false declines of genuine customers reduce by up to 70 percent, which is the cost most fraud vendors leave entirely unmeasured, and it matters because the two objectives trade against each other.

The mechanism is also described in enough detail to be interrogable, with profiling of past, current and projected customer actions and peer group comparison named as distinct components. What is absent is the formal package: no validation documentation, no model risk artifacts for an institution's own validators, and no statement of how a self adapting model is revalidated as it changes.

Operational and Outcome Evidence
AA on Operational and Outcome EvidenceNamed customers with hard performance figures and enough method to test them.
Vendor Published

Named institutions with quantified per customer outcomes, which is the standard this axis sets and few reach. Eika Gruppen, an alliance of 46 Norwegian banks, deployed ARIC across every payment initiated through online and mobile banking and recorded a 90 percent reduction in phishing losses in 2024 against 2023, with its chief architect quoted on the record. NatWest implemented the platform for enterprise wide transaction monitoring and payments fraud detection in 2020.

Other named deployments include a major card processor and a payments scheme. The platform is stated to be deployed to organisations operating in more than 180 countries, and a historic published figure claims false declines of genuine customers reduced by up to 70 percent. Fifteen years of operation and acquisition by a global payments network are corroboration of a different kind: a strategic buyer with the expertise to test the technology examined it first.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

The models are described as self learning and adapting by themselves, and no boundary statement was located. The pre acquisition question was already open, since a platform learning fraud patterns across banks in 180 countries plainly benefits from breadth, and nothing states whether one institution's fraud experience informs models serving another. The acquisition sharpens it considerably.

Published material describes integrating the platform's approach with the acquirer's global network intelligence into a single unified framework, which is an explicit statement that data from outside the customer relationship enters the model, and no account is given of what flows in which direction, what an institution's own data contributes to the shared layer, or whether participation is optional.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

No data protection agreement, retention schedule, subprocessor list or deletion commitment was located, and the payload is among the most intrusive in this index by design. The platform builds a persistent behavioural profile of each individual customer covering how they spend, where they log in from and when they typically transact, and scores every payment against it.

The acquisition adds a second layer, since the stated direction is integrating behavioural data with the acquiring network's global network intelligence, which means profiles built for one institution's customers sit alongside network level transaction data about the same people. Nothing published describes what is combined, what is retained or what the customer is told.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

No attestation, certification, trust centre or enumerated framework was located in vendor material. As with Zeta, the certifications almost certainly exist, because a platform scoring card transactions inline for acquirers and processors could not operate without payment card industry attestation and its parent operates under that regime globally, but nothing is published where a prospective buyer can read it. The grade reflects disclosure rather than a judgement that controls are absent.

Regulatory Status and Licensure
BB on Regulatory Status and LicensureThe regulatory position is clearly stated and appropriate to the product, with part of the verification left to the buyer.
Vendor Published

One regime is named and addressed as a dedicated product rather than a talking point. ARIC Scam Detect exists specifically for authorised push payment scams, identified as the fastest growing fraud type globally, which is the reimbursement liability shift that reallocated scam losses onto payment firms and created this market segment.

The platform also operates inside enterprise transaction monitoring at a systemically significant bank, which sits in the anti money laundering supervisory path. Against that, no supervisor, statute or guidance instrument is named anywhere, and the payment card industry obligations that necessarily apply to a processor scoring card transactions are not addressed in located material.

AI Governance and Bias Disclosure
DD on AI Governance and Bias DisclosureNothing published on a product where the bias risk is concrete, such as credit decisioning or underwriting with no fair lending, disparate impact or adverse action disclosure.
Vendor Published

The accessibility finding recorded for BioCatch applies here in its strongest form, because the mechanism is the same and the scale is larger. A system that flags deviation from an individual's established behavioural baseline will flag most often the people whose behaviour legitimately changes: the elderly, those experiencing cognitive change or illness, those recently bereaved or relocated, those travelling, and anyone whose circumstances shift.

The Norwegian deployment makes the tension explicit, noting that phishing attacks primarily target elderly customers, so the population the product protects is also the population most likely to trigger it wrongly, and a blocked payment for that customer can mean an unpaid bill or an inability to move their own money. Nothing published addresses demographic error rates, accessibility, or how a customer repeatedly flagged for legitimate behaviour is handled. Third instance of this finding after BioCatch and Reality Defender.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

No guarantee, indemnity or falsifiable commitment binds the vendor to its output. What sits above the floor is a described human path that reaches the affected customer indirectly: a suspicious payment is flagged for investigation rather than silently cancelled, so a wrongly stopped payment has a route back through a person at the institution.

The limits are that the route is the bank's rather than the vendor's, nothing describes how long an investigation takes or how a customer learns why their payment stopped, and no mechanism exists for a customer repeatedly flagged by their own behavioural profile to have that profile corrected. The person scored has no relationship with Featurespace and no way to see or contest the profile held about them.

Integration and Deployment
Model Supply Chain Disclosure
BB on Model Supply Chain DisclosureSubstantial partial disclosure, or a chain that is structurally short: an explicit in house build, on premise deployment, per customer instances, or zero retention at the model layer.
Vendor Published

The core is unusually short and clearly stated: the analytics are proprietary and were developed from the company's own university research, with Adaptive Behavioral Analytics and Automated Deep Behavioral Networks named as its own techniques rather than assembled from third parties, which forecloses the foundation model question that dominates this axis elsewhere.

The acquisition adds a named external input rather than obscuring one, since published material states the direction is combining the platform with the acquiring network's global network intelligence, so the most significant third party data source in the chain is identified. What is not disclosed is the mechanics: no subprocessor list, no hosting arrangement, and no statement of what network data enters a given institution's model or on what basis.

Core Systems and Integration Depth
BB on Core Systems and Integration DepthNamed systems or a documented public API, with the depth or the production evidence left open.
Vendor Published

The integration position is deep at the point that matters, since the platform sits inline on payment initiation and scores every transaction submitted through online and mobile banking in real time, which requires connection to the institution's payment path rather than to a reporting layer. Deployment across an alliance of 46 banks and inside a systemically significant institution demonstrates it works against very different technology estates.

What is not published is any named integration: no core banking platform, payment hub, case management or fraud operations system appears anywhere, and no developer documentation or interface reference was located, so a prospective buyer cannot establish what connecting it involves.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

No hosting model, cloud provider, region selection, residency commitment or on premise option was located. That gap is material at this footprint: a platform deployed to organisations operating in more than 180 countries and holding individual behavioural profiles for retail bank customers crosses many data localisation regimes, and the European deployments in particular sit under transfer rules the published material never mentions. Acquisition by a network with its own global processing infrastructure raises the question again rather than settling it.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No pricing, packaging or basis of charge is published, and the acquisition has made the question harder rather than easier. The platform is now offered inside a payment network's value added services portfolio, where pricing is typically negotiated as part of a broader commercial relationship, so an institution cannot establish what the fraud capability costs on its own terms or whether adopting it is bundled with other network services. Nothing addresses whether charging is per transaction scored, per protected account or as a platform fee.

Institution and Segment Coverage
AA on Institution and Segment CoverageThe financial segments served are named and each carries its own maintained material, whether the coverage is broad or deliberately narrow.
Vendor Published

The buyer set spans banks, acquirers, payment processors and financial institutions generally, and the deployment footprint reaches organisations operating in more than 180 countries. Coverage is deep as well as wide: the platform scores card fraud, payment fraud, account takeover and authorised push payment scams, and the Norwegian deployment demonstrates it operating across every payment initiated through online and mobile banking rather than on card rails alone.

It reaches both very large single institutions and alliances of small community banks buying collectively, which are different procurement shapes. Distribution through a global payments network now extends the addressable base further.

Head to Head

Compared With

Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.

Alternatives to Featurespace

The closest documented capability profiles to Featurespace in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Stronger documented coverage on Autonomy and Oversight Model and AI Governance and Bias Disclosure

A lighter documented profile than Featurespace

Documents AI Safety and Data Stewardship where Featurespace does not

Documents AI Safety and Data Stewardship where Featurespace does not

Documents AI Safety and Data Stewardship and AI Governance and Bias Disclosure where Featurespace does not

Documents AI Safety and Data Stewardship where Featurespace does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746