Fourthline
Fourthline handles customer due diligence and anti money laundering compliance for European banks, fintechs, insurers and brokers, combining proprietary models for document authenticity, biometrics and liveness with screening, ongoing monitoring and a human expert review layer. Its distinguishing strength is jurisdictional depth rather than breadth, building onboarding flows that satisfy each European market's local interpretation of the directives, including regulated video identification where a country requires it, and it also remediates a bank's existing customer records. A merger with a Spanish identity provider was announced in July 2026, subject to regulatory approval.
Capability Axes
Capability grades
15 of 15 axes rated · 10 graded A or B
Models do the verification work and the published figures reflect it, with identity authentication reported at 99.98 percent and automatic fraud detection at 98 percent across document authenticity analysis, biometrics and liveness.
The platform is broader than that layer, combining models with screening list matching, a human expert review step described as part of the product rather than an escalation, remediation workflows for existing records, and in some markets regulated video identification conducted by a live agent. Apply the removal test and a compliance orchestration business with expert review survives, which is what outsourced due diligence looked like before.
Human involvement is partly structural rather than optional. Expert review is described as a component of the platform alongside models and biometrics, and in markets such as Germany and Austria the company supports regulated video identification conducted through a live conversation with an agent, which is a legally mandated human step rather than a design choice. Remediation workflows put a compliance team in control of correcting historic records. What is not described is the threshold architecture: nothing states when a case escalates from automated to expert review, or how disagreements between the two are resolved.
Three signals give a validator material. Accuracy is published separately for two distinct functions rather than as one headline. An independent analyst conducted customer interviews and published quantified findings the vendor did not control. And most usefully, the company has explained in detail how its verification flow and screening work to a national supervisor and its central bank, which is model transparency demonstrated rather than promised. What remains absent is the documentation itself: no methodology behind the accuracy figures, no error analysis by document type or market, and no model documentation package.
The strongest evidence in this index's identity cluster. Named customers are substantial and specific, spanning leading European neobanks, a retail brokerage, a listed broker group and a banking infrastructure provider, with executives at two of them quoted on the record. Financial disclosure is unusual for a private vendor, with revenue reported around 56.7 million dollars and the business described as profitable and positive on operating earnings.
An independent analyst study based on customer interviews quantifies gains rather than asserting them, reporting 15 to 20 minutes saved per case, 90 percent of verifications completed in under five minutes and a 25 percent conversion improvement at one fintech bank.
Two things put this above the category norm. Accuracy is published as figures rather than adjectives, separately for identity authentication and for fraud detection, which invites the measurement most competitors avoid. And human expert review sits inside the flow as a designed backstop rather than as an exception path, so a model's judgement is not the last word on a rejection.
The gaps match the cluster: no independent presentation attack certification was located, no model providers are identified, and nothing states whether verification data from one institution informs models serving another.
Privacy is treated as a design constraint rather than a policy page, which is what operating primarily under the European regime forces. Compliance with that regime and with each market's local anti money laundering directives is stated as a product property, identity records are held in what the company describes as a centralised secure vault, and the customer lifecycle is built to satisfy data protection alongside due diligence rather than in tension with it. What is absent is the documentation a reviewer would want next: no published retention schedule, no subprocessor list and no statement on how long biometric templates persist after verification.
No trust centre, enumerated certification list, attestation scope or audit period was located in this pass. Compliance with the European data protection regime is stated repeatedly, but that is a legal framework rather than an audited information security standard, and customers including major neobanks and a listed broker group would have required independent reports before biometric and identity data moved. The grade records what an outside buyer can verify without entering procurement.
Fourthline supplies technology and holds no licence, and it has been through something stronger than most vendors here can claim. At the request of business partners under examination, it demonstrated its due diligence flow and screening solution directly to the German federal financial supervisory authority and the central bank, explaining in detail how the system works and receiving feedback from the supervisor.
That is a regulator examining the actual product rather than a vendor asserting compliance. It falls short of a formal admission programme with published criteria, which is what separates this from the top grade, and the pending merger itself requires regulatory approval.
The published accuracy figures frame the unanswered question in the same way Veriff's do: if identity authentication is 99.98 percent accurate and fraud detection 98 percent, the composition of the remainder is the fairness issue, and across more than 30 jurisdictions and hundreds of document formats it will not be evenly distributed.
The company demonstrably understands document level variation, citing the placement of security features on particular national identity cards, and publishes nothing on population level variation. No demographic pass rates, independent biometric evaluation or accessibility analysis were located.
The expert review layer is genuine practical recourse, since a case a model would reject can reach a trained human before the applicant is turned away, and remediation tooling lets an institution correct records it later finds wrong. Neither is a commitment by the vendor.
No accuracy guarantee accompanies the published figures, no remediation term exists where a wrongly rejected customer costs an institution a relationship, and no route is described by which an applicant learns why verification failed or asks for it to be reconsidered.
The analytical layer is described as proprietary and, in the merger material, as a sovereign technology stack, which is a stronger provenance claim than ownership alone because it asserts jurisdictional control over where the models come from and who governs them, a live concern for European institutions weighing dependence on foreign providers. The merger will combine two proprietary stacks under one architecture. What is not disclosed is the rest of the chain: no screening or watchlist data suppliers are named, no infrastructure providers are identified, and no subprocessor list is published.
The proposition is deliberately simple: one interface integration gives access to the full modular set, from standard through bank grade verification, locally compliant flows, screening and remediation, and a single onboarding process can be reused across European markets rather than rebuilt per country. That reuse is the real integration value in a fragmented regulatory geography. What was not located is the surrounding depth, with no named core banking or onboarding platform partners, no public developer documentation and no status page found in this pass.
Delivery is cloud hosted from a European base serving institutions across more than 30 jurisdictions, and the company describes its technology stack in sovereign terms, implying European control over the models and infrastructure, which would matter to buyers weighing dependence on non European providers. That phrase is asserted rather than specified.
No hosting regions, in country residency options, transfer mechanisms or subprocessor locations were located, and the pending merger with a business operating across the Americas will change the picture.
No rates, tiers, billing unit or minimum were located, which is the norm in this category. The company does disclose more about its own economics than most private vendors do, publishing revenue and profitability, and the analyst study frames value in cost per case terms. Neither tells a buyer what a verification costs, and the modular structure means scope is the first commercial question a prospect would ask.
Institution types are named and varied, covering banks, fintechs, insurers, online brokers and non financial businesses, and the customer list demonstrates each rather than implying it. Jurisdictional coverage runs to more than 30 markets with real depth in each, which is the harder achievement in Europe where a single directive is interpreted differently country by country.
The limit is geography: this is a European business concentrated in northern and central markets, with southern Europe, the United States and Latin America arriving through a merger rather than through existing operations.
Compared With
Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Alternatives to Fourthline
The closest documented capability profiles to Fourthline in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Stronger documented coverage on AI Centrality
Documents Security Certifications and Trust Center where Fourthline does not
Documents AI Liability and Recourse where Fourthline does not
Stronger documented coverage on AI Centrality and Institution and Segment Coverage
Stronger documented coverage on AI Centrality and Institution and Segment Coverage
Stronger documented coverage on GLBA and Data Privacy Posture and AI Safety and Data Stewardship
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.