First AML
First AML is an Auckland customer due diligence platform founded in 2017, co founded by Bion Behdin who serves as chief revenue officer, and now operating across New Zealand, Australia, the United Kingdom and Europe with separate platform instances for the Australasian and UK and European regions. The company began as a compliance operator rather than a software vendor and states it processed more than two million anti money laundering cases itself before releasing the platform, which is the experience it markets the product on.
It sells an end to end customer due diligence workflow covering onboarding, individual and business verification, screening, enhanced and ongoing due diligence, risk assessment and regulatory reporting, aimed at organisations with complex or international entity structures. Four named AI features sit inside it. Entity Insights searches public records, registries and credit data to produce a structured open source report on an entity with follow up questions, aimed specifically at foreign entities and thin data jurisdictions.
An AI document reader parses trust deeds, constitutions and other complex documents in around sixty seconds, extracts beneficial owners and certification details and builds the ownership structure inside the case. AI supported individual verification captures live video alongside an identity document and matches faces biometrically. Advanced AI screening surfaces court proceedings, criminal filings and paywalled content, and a screening agent labels each result as a false positive, false match or true match for a human to accept or override.
The company frames the arrangement as the customer owning the compliance rules and review steps while the AI runs against them, clears routine work and escalates cases needing judgment. It serves four industries, accounting, law and conveyancing, real estate, and finance, and in February 2026 partnered with the legal software group Aderant to reach law firms internationally. It has raised roughly 26 million dollars, including a 21 million dollar Series B, from investors including Bedrock Capital and Icehouse Ventures, and runs a trust centre, a security page, a public status page and a published plans and pricing page.
Capability Axes
Capability grades
15 of 15 axes rated · 6 graded A or B
The company's own history supplies the removal test and settles this at B. It states plainly that it processed more than two million anti money laundering cases itself before building the platform, so the workflow, case management, screening and reporting product demonstrably existed and functioned as a business before any AI feature arrived. Strip the models today and that platform remains.
What the models add is nonetheless substantial and specific rather than decorative: a document reader that parses trust deeds and constitutions in around sixty seconds and builds an ownership structure from them, entity research across registries and credit data aimed at thin data jurisdictions, biometric identity matching, and a screening agent that triages results into false positive, false match and true match. Held above a C, which means genuinely peripheral, because those features now carry real analytical throughput.
The division of authority is stated clearly and one control is unusually concrete. The company frames the arrangement as the compliance rules and review steps belonging to the customer's team, with the AI running against those rules, clearing routine work and flagging cases that need human judgment with context attached.
On screening specifically, the agent labels every result as a false positive, false match or true match and the human accepts or overrides, which is a real per decision control rather than a general assurance. Held at B rather than A because the boundary is undefined: nothing states what qualifies as routine, what the agent may close without review, or what happens when confidence is low. Compare the vendor in this same pocket that publishes human sign off enforced at every point, which leaves no undefined middle.
Every published figure measures speed rather than correctness: a complex document read in around sixty seconds, routine cases cleared, hours of reading reduced to a minute of review. No accuracy rate for document extraction, no precision or recall for the screening agent's false positive and true match labelling, no benchmark, no evaluation methodology, no model documentation and no validation material for a customer's own model risk function.
The screening triage is the place this matters most, because a result labelled a false positive and accepted by a busy analyst is a match that disappears, and no figure is published for how often that label is wrong.
Six customers are named on the company's Australian pricing page, and their composition matters as much as their existence: Rampersand, Blackbird and Second Quarter are venture capital firms, Alceon is an investment manager, Oceana Funds is a fund manager, and Certane is a corporate trustee and fund services group.
Every one is a financial firm, which is direct evidence that the finance vertical is a real book of business rather than a fourth item on a menu, on a company whose other three verticals are professional services. Scale is stated as thousands of companies and millions of clients verified, alongside the more than two million cases the company processed itself before the platform existed.
Held below an A because no outcome is attached to any of those names: no time saving, cost reduction, throughput or compliance result is attributed to a named firm, so the scale figures and the customer list sit side by side without meeting. A quantified client quotation does exist in the company's own commentary, describing 50 to 80 percent less time spent on customer due diligence, but it is unattributed.
Nothing states whether customer data, uploaded documents, extracted ownership structures or analyst decisions are used to train or improve models served to other customers. The silence is conspicuous because the company has published speculation about exactly this: its own commentary describes reinforcement learning systems that continually optimise by ingesting case outcomes and findings to adjust risk scoring and due diligence triggers, and federated learning that pools anti money laundering knowledge across institutions, describing both as opportunities that excite it. Having raised the possibility of learning from pooled case data in public, the company publishes no position on whether it does so with its own customers' cases.
A legal section exists and nothing further was located: no subprocessor list, no retention schedule, no deletion commitment and no data processing agreement terms. The gap is material for this product because the platform collects and stores identity documents, trust deeds, constitutions and beneficial ownership details for individuals who are not its customers but the customers of its customers, and holds them as a case record over time for ongoing due diligence. What happens to that material, how long it persists and who else can reach it is unaddressed.
Three separate assurance artifacts exist and none of their contents were verified: a trust centre on its own subdomain, a dedicated security page, and a public platform status page. That is more infrastructure than most of this pocket maintains.
No certification or attestation was enumerated in the material read, so nothing is credited, on exactly the basis applied to the other vendor in this pocket with an unopened portal: a trust centre whose contents are unverified is a route to evidence rather than evidence itself. This grade is explicitly movable and opening that portal is the cheapest available check on this vendor.
A software supplier outside the regulatory perimeter. No licence, registration, supervised sandbox participation or regulator run scheme was located. Its customers are the reporting entities carrying the statutory obligations and facing the supervisor. The company's own regulatory expertise is evident and it publishes detailed commentary on New Zealand and Australian regulatory change, but subject matter knowledge is not supervisory standing and this index keeps the two separate.
No fairness disclosure, no evaluation across jurisdictions or entity types, no governance certification. There is a pointed contrast worth recording: the company publishes thoughtful commentary naming bias as a central risk of applying AI to this field, writing that models risk exacerbating biases in data and training methods with discriminatory outcomes and that detecting, monitoring and mitigating bias must be considered.
That is written about the category in the abstract, and nothing is published about its own models. The exposure is concrete: entity research is aimed explicitly at foreign entities and thin data jurisdictions, which is precisely where public record coverage is sparsest, so an open source report is likely to be least complete exactly where it is most relied upon.
Nothing states who bears the cost of an error or how one is contested. The sharpest exposure here is specific to the document reader: it extracts beneficial owners and certification details from trust deeds and constitutions and builds the ownership structure inside the case.
An extraction error mis states who owns or controls an entity, and the person wrongly recorded as a beneficial owner, or wrongly omitted from the structure, is not the customer, has no notice that an automated reading produced the record, and has no described route to correct it. The regulated firm relying on that structure carries the supervisory consequence.
No model provider, family or version is named for any of the four AI features, and no third party provider case study naming this vendor was located. The features described span document understanding, open source research, facial biometrics and screening adjudication, which almost certainly involve more than one supplier and possibly a mix of commissioned and licensed capability, and none of it is disclosed. Nothing states where inference runs or whether documents and identity data are routed to an external provider, which sits awkwardly beside the regional platform separation the company does maintain.
Integrations exist as a named platform feature, and one integration is named and strategically significant: a partnership with the legal practice management software group Aderant, announced February 2026, to embed the compliance workflow where law firms already run their business.
Integrating into the system of record of a primary vertical is real depth rather than an API claim, and it is the same distribution pattern seen elsewhere in this pocket where vendors reach institutions through a partner's platform. Held below an A because the integration catalogue itself was not enumerated in the material read, so a buyer learns that one significant practice management platform is covered and not what else connects.
A genuine regional data separation that is observable rather than asserted, which is unusual on an axis where most of this index says nothing. The platform runs as two distinct instances with separate customer entry points, one for the United Kingdom and Europe and one for Australia and New Zealand, so European and Australasian case data sit in different deployments rather than one global tenancy.
For a product holding identity documents and beneficial ownership records across jurisdictions, that is a substantive residency answer and a buyer can verify it exists. Held below an A because no cloud provider, region or availability zone is named, no single tenant or private option is described, and no formal residency commitment or data transfer position is published.
Checked directly, and the page is a study in the form without the substance: a plans and pricing page carrying three named tiers, Launch, Optimise and Transform, each with a description of the organisation it suits, a comparison grid, and in place of every price the letters POA. Three tiers, three prices on application, plus a note that prices vary by jurisdiction.
Two pieces of genuine commercial information survive that and are worth crediting in the note if not in the grade: the entry tier states a qualifying volume of at least 400 individuals or 100 complex entities a year, which usefully tells a smaller firm it is not the customer, and the tiers are differentiated by operating shape rather than by feature count.
But a buyer leaves knowing which tier they belong to and nothing about what it costs, and every route from the page is a sales conversation. Held at C because this axis measures what a buyer can learn about cost, and the answer here is nothing.
Four named industries and four localised regional operations, with genuinely international reach for a company of this size: New Zealand, Australia, the United Kingdom and Europe, each with its own site and, for the platform itself, separate Australasian and UK and European instances. More than two million cases processed and a stated base of thousands of compliance practitioners. The February 2026 partnership with a legal software group extends it to law firms internationally.
Held at B, and the reason is a genuine composition point rather than a scale one: finance is one of four verticals and is listed last, behind accounting, law and conveyancing, and real estate. The buyer base is weighted toward professional services firms performing anti money laundering obligations rather than toward financial institutions, and no institution count or named financial services customer was located.
Alternatives to First AML
The closest documented capability profiles to First AML in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
A lighter documented profile than First AML
A lighter documented profile than First AML
A lighter documented profile than First AML
Documents AI Safety and Data Stewardship where First AML does not
Stronger documented coverage on AI Centrality
Stronger documented coverage on Operational and Outcome Evidence and Institution and Segment Coverage
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.