GBG
GBG is a listed identity verification, location intelligence and fraud prevention group headquartered in Chester, founded in 1989, with revenue of roughly 283 million pounds and about 1,100 staff. Its platform, GBG Go, delivers identity and address verification, document and biometric checks, customer due diligence, business verification and risk analysis through a single interface, with access to multiple credit bureaux through one integration. The inference layer runs across several products.
Transaction monitoring applies machine learning to transaction events and behavioural patterns alongside expert fraud rules, with published performance of up to 34 percent more fraud detected and up to 51 percent fewer false positive alerts. Application fraud detection claims up to 30 percent more online fraud identified. The document product defends against synthetic media by analysing lip movement and mouth shapes in video for synchronisation discrepancies and failing the check when they appear.
Underneath sits a consortium identity network spanning several hundred organisations across more than twenty sectors and eighty countries, applying pattern matching, data mining and machine learning to return an identity trust score in seconds, which the company states it does without ever divulging protected data. A regional early warning product in Australia draws on forty million verifications a year from more than eight hundred businesses to detect identity theft and money muling.
A separate agent portfolio launched in 2026 exposes verification to autonomous software: one product is generally available through a command line binary, a hosted protocol server, an agent skill and a web interface, and a second, in beta, grounds agents so that every identity, compliance or fraud decision executes as a real platform journey with a retrievable run identifier rather than as a model guess.
Capability Axes
Capability grades
15 of 15 axes rated · 8 graded A or B
The established platform shape, and the fourth instance graded this way in a single session, which is itself a useful consistency check. This is a business founded in 1989 on identity data, address verification and bureau access, and those are deterministic matching operations that survive the removal of every model intact and account for much of the revenue.
The inference layer is genuine and material rather than decorative, covering transaction monitoring, application fraud, the consortium trust score and synthetic media detection, which is why this is a build. But the company sold identity verification for three decades before any of it existed.
The clearest published answer in this index to the question of what stops an autonomous agent inventing a compliance decision, and it earns the grade on architecture rather than on assurance. The agent product grounds every identity, compliance or fraud decision as a real platform journey rather than a model output, with four stated properties: deterministic, so the same input yields the same decision every time; grounded, described explicitly as a real journey and not a model guess; stateful and resumable, so a run holds open for missing evidence under the same identifier; and auditable, with a retrievable run identifier for every decision.
It also returns confidence scores an agent can threshold on rather than codes requiring interpretation, and strictness is policy driven by use case. That is an enforcement mechanism named and placed in the execution path, and it removes the model from the decision rather than supervising it there.
Two caveats recorded rather than deducted: the grounding product is in beta while the verification product is generally available, and the corporate claim to maintain human oversight of all deployed AI is an assertion with no mechanism attached, unlike the architecture above it.
Two real properties. First, quantified performance deltas are published for the detection models, which is rare enough in this index to count even in imperfect form. Second, and more useful, the agent product offers reproducibility as a stated design property: the same input yields the same decision every time, and every decision carries a retrievable run identifier with a full audit trail, so a buyer can re run a case and look up any past one.
Reproducibility and per decision traceability are genuine model risk controls. Held off A because the performance figures are ceilings with no baseline, no methodology and no distribution, there is no model documentation or validation approach, and the detection models are described as continuously learning and adapting to new fraud behaviours with no drift governance published beside that claim, which is precisely where drift governance belongs.
Quantified model performance is published, which most of this index will not do: more fraud detected and fewer false positive alerts on transaction monitoring, a separate figure for application fraud, and volume evidence of forty million verifications a year from more than eight hundred businesses in one region. Group revenue and headcount come from listed company reporting.
Held at B because not one of the performance figures is attached to a named institution, and because of how they are framed. Every one is an up to figure, which states a ceiling and reads as a typical result. That construction belongs beside the unit free percentage in the claim shapes catalogue: it is a bound presented as an outcome, and the distribution behind it is never shown.
The consortium is disclosed openly and quantified by participating organisations, sectors, countries and record counts, and it is presented as the source of the detection signal rather than buried. Beyond disclosure, the company makes a privacy claim about the pooling itself, that a score is returned without protected data being divulged, which is a step further than any other pooled corpus vendor in this index has gone.
Held off A because the claim is asserted rather than explained, and because the terms remain unpublished: nothing states whether contribution is a condition of consuming the network, whether a participant can opt out of contributing, what use limits apply, or what happens to contributed records on exit.
Privacy by design is stated alongside the security certification and a commitment to track regulatory developments across markets. The substantive claim is architectural and uncommon: the consortium returns an identity trust score in seconds while, in the company's words, never divulging protected data. If accurate that is a technical answer to the pooled data problem rather than a contractual one, and this index has not previously encountered a vendor claiming one. Held off A because the mechanism behind that claim is not described anywhere, and because no data processing agreement, subprocessor list, retention period or residency commitment accompanies it.
A numbered international information security certification is claimed in the company's own material, alongside a stated privacy by design approach. That is a real credential from the vendor rather than from a directory, which clears the source test.
Held off A on the familiar imprecision: no edition year, no scope statement, no certificate or register link, no audit period, no trust portal and no service organisation control reporting mentioned for a group processing identity data for regulated buyers across eighty countries.
A listed company rather than a licensed or supervised financial firm, and listing is a capital markets status that confers nothing on the product. Banked check worth running before this is treated as settled: identity and bureau data businesses fall inside specific regimes in several of the markets this group operates in, and if any national entity holds a registration attaching to the data products themselves rather than to an adjacent business, that would move this grade on the same reasoning applied elsewhere in this index.
A published governance statement exists, covering safe deployment, accountability and human oversight, but its content is values and process rather than fairness, and the parts that are substantive are credited on the autonomy and stewardship rows already. On fairness specifically there is nothing, and the gap is conspicuous for this vendor above almost any other in the index.
Document and biometric verification is the single best documented site of demographic performance disparity in identity technology, with error rates known to vary by document type, issuing country and skin tone, and this company runs those checks globally at scale while publishing no accuracy breakdown, no demographic testing and no independent evaluation of the underlying algorithms.
No recourse route and no allocation of responsibility. A person wrongly failed at onboarding is refused an account with no explanation, no sight of the trust score, no knowledge that a consortium contributed to it and no route to contest it.
The agent product sharpens the question rather than answering it: a retrievable run identifier means the decision can be reconstructed after the fact, which is auditability for the buyer and not recourse for the subject, and nothing states who answers when an autonomous agent acts on a confidence score and is wrong.
Machine learning, data mining and expert derived pattern matching described generically, with no model, provider, architecture or version named for any detection product. The agent portfolio does name the assistant ecosystem it plugs into, but that is a distribution channel rather than a supply chain disclosure: it tells a buyer where the product can be called from and nothing about what runs inside the trust score or the transaction models. Held at C on that distinction, which is the difference between this record and others in the session where the vendor also stated its posture toward the providers behind its own inference.
A single interface across the whole platform, multiple credit bureaux reachable through one integration, and straight through application processing wired into front and back office systems. The newer agent portfolio adds an unusually specific and modern integration surface, naming four distinct modalities including a command line binary, a hosted protocol server and an agent skill for a named assistant, which is more concrete than most vendors in this index manage. Held off A because no named core banking, origination or case management system appears, so the depth is in the modalities offered rather than in named counterparties.
Delivered as a service with distinct regional operations and separate national sites for the United Kingdom, the Americas and Asia Pacific, which implies regional infrastructure without stating it. Nothing published names a region, a residency commitment, a tenancy model or a hosting choice, and that gap is more consequential here than usual because the underlying consortium spans more than eighty countries and the data is identity records on named individuals.
No price, tier or unit located on the company's own pages, with everything routed through contact and demo requests. Banked check: third party software directories carry pricing entries for this vendor, and while a directory is never creditable as evidence under the source test, it is a signal that a published price may exist somewhere on the vendor's own regional sites, which run as separate domains.
Genuinely broad on every dimension the axis measures. The consortium network alone spans several hundred organisations across more than twenty sectors and eighty countries, with a regional footprint of over a thousand customers in Australia and New Zealand across dozens of industry segments.
Product coverage runs the full customer lifecycle: onboarding verification, document and biometric proofing, customer due diligence, business verification, politically exposed person and sanctions screening, transaction monitoring, application fraud and investigations. Banking and financial services is named as the core buyer while the platform also serves other regulated sectors.
Compared With
Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Alternatives to GBG
The closest documented capability profiles to GBG in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents AI Centrality and Regulatory Status and Licensure where GBG does not
Stronger documented coverage on Operational and Outcome Evidence
Documents AI Centrality and Commercial Transparency, among others where GBG does not
Stronger documented coverage on Core Systems and Integration Depth
Documents AI Centrality where GBG does not
Documents AI Centrality and Regulatory Status and Licensure where GBG does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.