Lending & Banking Operations
J

Jack Henry

Jack Henry is the third of the three companies whose core systems run most United States banking, and it is the one aimed squarely at the small end of the market. Roughly 7,400 community banks and credit unions depend on it, and the company defines that segment with unusual precision in its annual report: its average core bank client holds 1.29 billion dollars in assets and its average core credit union client 1.20 billion. Symitar is the dominant credit union core and SilverLake serves a large share of community banks, with the Banno digital platform above them reaching more than 15.8 million registered users across over a thousand institutions.

The artificial intelligence line is broad rather than concentrated in one flagship. Management reported 22 artificial intelligence enabled products in market at the close of its 2026 financial year with more than 20 further capabilities identified for release within six months, stating on the record that strict risk management, compliance and governance frameworks would be maintained so that clients always remain in control.

The most developed product is Financial Crimes Defender, a cloud native real time fraud and Bank Secrecy Act compliance platform covering checks, deposits, transfers, automated clearing house and instant payments, able to stop a transaction before it leaves the institution. It screens against sanctions and watchlists, files the required regulatory reports, and has the Federal Reserve's fraud classification model built in natively. It reached 189 completed installations by 30 June 2026 with 57 more in progress, and now includes assisted drafting of suspicious activity report narratives, which the company puts at saving at least an hour per investigation. Notably, the platform is built through a named partnership with Feedzai rather than on a proprietary engine.

Separately, a collaboration with Google Cloud dating to 2022 was extended in June 2026 to build a proprietary artificial intelligence security platform using that provider's agentic defence products, alongside operational use cases on its enterprise agent platform. The company is listed on Nasdaq and headquartered in Monett, Missouri.

Last VerifiedAugust 25, 2026
Compare Jack Henry with other vendors
Founded
1976
Headquarters
Monett, Missouri, United States
Categories
lending-and-banking-operations, fraud-and-transaction-risk, customer-banking-agents
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 7 graded A or B

AI Capability
AI Centrality
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.
Vendor Published

A core processing company with a broad artificial intelligence programme layered across it. Management reported 22 artificial intelligence enabled products in market with more than 20 further capabilities identified for release within six months, which is a wider spread than most competitors here can claim, but the phrasing is the point: these are capabilities added to products rather than products that exist because of them.

Strip the models and the company remains substantially intact, since the credit union and community bank cores, the digital banking platform serving more than 15.8 million registered users, the payments modules and the treasury estate are all deterministic systems of record that predate the models by decades. The financial crimes platform is the most model dependent product, and even there the analytics engine is a partner's rather than the company's own.

The security work with a cloud provider applies agentic defence to protect the estate rather than to sell intelligence. The company's own framing in its annual report places artificial intelligence within a technology strategy that also covers cloud rollout, serving both internal ways of working and product offerings.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

Consistently assistive by design, stated as a commitment, with one item that needs the usual scrutiny. The pattern across the products is a person deciding: the digital banking assistant supplies suggested responses for staff and hands off between employee and automation rather than replacing the conversation, the fraud platform detects and alerts with investigators dispositioning, and management commits publicly that clients always remain in control.

Real time interdiction exists, since the platform can stop a transaction before it leaves the institution, but under rules the institution sets. The item to examine is assisted drafting of suspicious activity report narratives. That document is what a regulator and potentially a court reads, written about a person who will never see it and cannot contest it, and the framing here is better than at several competitors because the stated benefit is giving the investigator back an hour to investigate further rather than removing the investigator. Nothing published states what the investigator must review or attest before a drafted narrative becomes a filing, which is the question this capability always raises.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

The best outcome disclosure in this sweep on one side of the ledger, and silence on the side that would make it interpretable. The published figure is unusually well constructed: alert rates below one percent, representing roughly an 80 percent reduction in alerts reaching institutions, stated with the mechanism and the population rather than as a bare percentage, alongside at least an hour saved per investigation on narrative drafting. What is missing is the counterpart.

An 80 percent reduction in alerts carries no accompanying figure for how much genuine fraud detection was retained, and a reduction of that size is trivially achievable by detecting less, which is precisely the criticism this index has already recorded against another vendor in this lane. The reference to meaningful alerts gestures at retention without quantifying it.

Also absent across two passes: validation methodology, false negative rate, sample and observation period, drift or retraining disclosure, and any model documentation an institution could put in front of its own examiners, which is complicated further by the engine belonging to a partner.

Operational and Outcome Evidence
AA on Operational and Outcome EvidenceNamed customers with hard performance figures and enough method to test them.
Vendor Published

Evidence reported quarterly under securities law, which makes adoption claims auditable rather than assertable, and outcome figures that carry a mechanism. Adoption for the artificial intelligence products is stated with specificity and movement: 189 completed financial crimes platform installations as at 30 June 2026 with 57 more in progress, 183 new contracts across that platform and the faster payment modules over the year with 61 in the fourth quarter, 191 faster payment modules installed with 231 in progress, and digital platform signings of 219 for the year, up 24 percent, reaching more than 15.8 million registered users, up 11 percent.

Outcome evidence is quantified and explained rather than asserted: alert rates below one percent representing roughly an 80 percent reduction in alerts reaching institutions, and assisted drafting of regulatory report narratives saving at least an hour per investigation. Customers are named with named executives, including a federal savings bank and a community bank president. Independent recognition includes an analyst assessment naming the small business digital platform the leading one in its category and an industry award for the fraud platform.

AI Safety and Data Stewardship
BB on AI Safety and Data StewardshipA categorical stewardship commitment is published without the retention schedule or the engineering detail behind it.
Vendor Published

A governance commitment made where it carries consequences, and two design choices that support it. Management stated on the record in a quarterly earnings call that across all 22 artificial intelligence enabled products and the further capabilities in development, strict risk management, compliance and governance frameworks would be maintained so that clients always remain in control.

A statement to investors on a call carries securities exposure that a marketing page does not, which makes it the most accountable governance commitment located in this sweep. The design choices reinforce it. Adopting the Federal Reserve's published fraud classification model natively means classifications follow a public regulator authored taxonomy rather than a proprietary scheme, which makes outcomes comparable across institutions and harder to quietly redefine.

And the cloud collaboration applies agentic capability to defence, using artificial intelligence to protect the estate rather than only to expose new surface. Absent across two passes: model card, evaluation methodology, red team result, incident disclosure and any statement on what accountholder data trains or contextualises the models.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

Regulatory compliance is sold as a product and not much is published about the company's own posture. The financial crimes platform is built around obligations its customers carry, screening against sanctions and watchlists, filing suspicious activity and currency transaction reports and validating Bank Secrecy Act and anti money laundering compliance, so the company demonstrably understands the regime its clients operate under.

That is compliance delivered to customers rather than privacy practised by the vendor, and the two should not be read as the same thing. Across two passes no privacy programme description, data processing disclosure, retention schedule or subprocessor list was located, and the Gramm Leach Bliley Act appears nowhere on the surfaces examined despite the company processing deposit accounts for roughly 7,400 institutions governed by it.

The gap has an added dimension here because the fraud analytics run on a named third party engine and the security platform on a named cloud provider, so accountholder transaction data reaches parties beyond the vendor without any published description of what moves or under what terms.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

A disclosure gap made conspicuous by what the company sells. Across two passes no trust centre, named certification, attestation report, penetration test summary or subprocessor list was located on the public surface. The controls exist beyond reasonable doubt, since a processor running deposit systems for roughly 7,400 supervised institutions is examined continually by those institutions and their regulators, and the company is a listed registrant with internal control obligations.

What makes the silence stand out is the positioning: this company is currently building a proprietary artificial intelligence security platform to sell to its clients, explicitly designed around the strict compliance, regulatory and security requirements of community institutions, while publishing nothing verifiable about its own security credentials. A vendor asking institutions to trust it with their cyber defence has a stronger than usual reason to publish what it holds. The practical effect falls hardest on the smallest clients, who lack the procurement leverage to demand documents a larger bank would simply require.

Regulatory Status and Licensure
BB on Regulatory Status and LicensureThe regulatory position is clearly stated and appropriate to the product, with part of the verification left to the buyer.
Vendor Published

No licence of its own, and the most concrete regulatory engagement among the core providers in this index. The financial crimes platform is built directly to named United States obligations rather than described as helping with compliance generally, covering Bank Secrecy Act validation, suspicious activity and currency transaction report filing, and sanctions and watchlist screening.

More distinctive is the native adoption of the Federal Reserve's published fraud classification model, which means the vendor has taken a regulator authored taxonomy as its own classification scheme rather than inventing one, a choice that makes an institution's reporting legible to its examiners without translation.

The security platform is explicitly positioned against the compliance, regulatory and security requirements of community institutions, a segment supervised by multiple federal agencies. As a listed registrant the company carries quarterly and annual reporting obligations and makes governance commitments on the record. Absent: any published account of its own examinations as a bank service provider, and any position under the European artificial intelligence regulation, though its footprint is essentially domestic.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

The determinations here reach individuals and nothing published addresses whether they land evenly. The fraud platform monitors accountholder transactions, flags suspicious activity, screens against watchlists and now drafts the narrative that becomes a regulatory filing about a named person who is never told and cannot respond.

Financial crime alerting has well documented uneven effects across geography, name origin and transliteration, and the added exposure here is structural: the analytics engine belongs to a third party, so a community bank sits two removes from the model that judges its members and has correspondingly less ability to interrogate it.

Adoption of the regulator's published classification taxonomy is a genuine partial mitigation, because it standardises what a fraud type means across institutions and makes patterns comparable, but a shared vocabulary for classifying outcomes says nothing about whether the outcomes are distributed fairly. Across two passes no fairness testing, differential performance analysis, model card or bias statement was located for any of the 22 artificial intelligence enabled products.

AI Liability and Recourse
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.
Vendor Published

No commercial instrument is published. Across two passes no terms of service, master agreement, warranty, indemnity, liability cap or published service level was located, and nothing states what an institution is owed when an artificial intelligence product is wrong. Three exposures sit uncovered and they are not equivalent. The platform can stop a transaction before it leaves the institution, so a wrongly held payment is a direct customer harm.

Assisted drafting produces the narrative of a regulatory filing, so a defective draft that survives review becomes the institution's problem with its examiner rather than the vendor's. And because the analytics engine belongs to a named third party, an institution seeking recourse for a detection failure faces a chain rather than a counterparty, with nothing published describing how responsibility is divided between the platform and the engine behind it. Management's commitment that clients always remain in control is a governance posture, and it arguably places responsibility with the institution rather than allocating it contractually.

Integration and Deployment
Model Supply Chain Disclosure
AA on Model Supply Chain DisclosureEvery party between the customer’s data and the output is enumerated by name, canonically through a public subprocessor list naming the model providers.
Vendor Published

This vendor names the suppliers that actually matter, which is rare enough to be the strongest feature of the record. The financial crimes platform is stated to be built through a partnership with a named specialist fraud analytics company, with both parties publishing joint material about the collaboration and its results, so a buyer knows precisely whose models judge their accountholders.

The security platform is built on a named cloud provider's agentic defence products under a relationship dating to 2022, and operational capabilities run on that provider's enterprise agent platform. Naming both the analytics engine and the cloud artificial intelligence provider lets an institution assess those parties directly rather than inheriting undisclosed dependencies.

One consequence follows that a buyer should see and that only disclosure makes visible: the named analytics partner is itself an independent vendor in this market and appears elsewhere in this index, so an institution running both that vendor directly and this platform may be paying twice for one model estate and carrying more concentrated exposure to a single engine than it realises. No model family or version is named.

Core Systems and Integration Depth
AA on Core Systems and Integration DepthNamed integrations with the systems of record, core banking, policy administration, custodial or contact center platforms, verifiable in marketplace listings or public API documentation.
Vendor Published

This vendor is the core for roughly 7,400 institutions, and it has made a structural choice that works against its own gatekeeping position. The integration network launched in July 2025 gives third party applications direct access to technical resources and open interfaces, explicitly removing the financial institution from the middle of the integration process, which is the opposite of the usual incumbent behaviour of routing every connection through the core provider and charging for the privilege.

The digital toolkit provides a public interface surface for the banking platform, and the company reports an open ecosystem of more than a thousand third party providers. The financial crimes platform connects across the company's own digital and payments estate and outward to third party systems including a major person to person network and custom institution systems. Payments reach spans the instant schemes with adoption reported by scheme.

For a community institution with no engineering capacity, being able to reach a fintech without the core provider standing in the way is the single most consequential integration property available, and this company publishes it as policy.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

Cloud native and fully hosted, with the placement questions unaddressed. The financial crimes platform is described as fully hosted and built on public cloud, which the company presents as enabling real time data, more accurate reporting, open integrations and speed, and the wider technology strategy is stated to include a rollout of cloud solutions. A named cloud provider relationship dating to 2022 underpins the security platform and operational artificial intelligence work.

What is absent across two passes is anything a regulated buyer would need to close the question: no region list, no residency commitment, no tenancy description, and no statement of what remains on institution controlled infrastructure versus what moves to the vendor or onward to its partners. That last point carries weight for this particular buyer set.

Community banks and credit unions with average assets around 1.2 to 1.3 billion dollars have limited leverage in vendor negotiations and limited internal capacity to interrogate a hosting arrangement, so published clarity would matter more to them than to a large institution able to demand it.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No price, unit or tier is published for the core, the digital platform, the financial crimes product or any of the artificial intelligence capabilities, and two passes produced nothing across the company's site, its investor materials and the trade press. What the securities filings supply instead is a structural picture of the commercial model that a buyer can genuinely use.

Because the company reports contract signings and installations separately for the financial crimes platform and the faster payment modules, distinct from core client counts, it is evident that these are modular products contracted individually rather than bundled into a core agreement, which tells a prospective buyer that adopting one does not require adopting everything and that each carries its own commercial negotiation.

Segment revenue, client counts and growth rates are published quarterly with management commentary, so the size and health of the business unit selling to them is visible. None of that is a price, and nothing indicates whether the artificial intelligence capabilities carry incremental charges or arrive within existing licences.

Institution and Segment Coverage
AA on Institution and Segment CoverageThe financial segments served are named and each carries its own maintained material, whether the coverage is broad or deliberately narrow.
Vendor Published

The deepest coverage of the small institution tier in this index, and the only vendor here that defines that tier precisely rather than gesturing at it. Roughly 7,400 community banks and credit unions are served, and the annual report states the average core bank client at 1.29 billion dollars in assets and the average core credit union client at 1.20 billion, which tells a prospective buyer exactly which end of the market this company is built for.

Credit unions are a segment most vendors in this index do not address at all, and here the credit union core is the dominant platform in its category rather than a secondary line. Coverage runs across the estate those institutions actually need, spanning core processing, digital banking for retail and small business, payments including the instant schemes with adoption reported by scheme, lending, treasury management, financial crime and Bank Secrecy Act compliance. What is absent is scale in the other direction, since nothing here addresses large national or global institutions, and the geographic footprint is essentially domestic.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis Data Protection Terms Implementation Source
Not published. No price, unit of billing, tier or contract term appears on any vendor surface
Not published on any vendor surface. The estate spans core processing for banks and credit unions, digital banking for retail and small business, payments including the instant schemes, lending, treasury management, and financial crime and Bank Secrecy Act compliance, with no published indication of the commercial basis for any of them. Securities reporting does establish that the artificial intelligence bearing products are commercially modular rather than bundled into core agreements, since the financial crimes platform and the faster payment modules are reported with their own contract signings and installation counts separate from core client numbers. Segment revenue, client counts and growth are published quarterly with management commentary, giving scale without price. No tiered data protection terms are published. Compliance capability is sold as product function rather than described as vendor posture: the financial crimes platform screens against sanctions and watchlists, files suspicious activity and currency transaction reports and validates Bank Secrecy Act compliance for the institution. Across two passes no data processing agreement, subprocessor list, retention schedule or residency commitment for the vendor's own handling was located, which is a live question here because the fraud analytics run on a named third party engine and the security work on a named cloud provider, so accountholder data reaches parties beyond the vendor under terms that are not public. No implementation, conversion or professional services fee is published. Implementation volume is visible in a way it is not elsewhere, since the company reports installations completed and in progress each quarter, showing 189 financial crimes platform installations completed with 57 under way and 191 faster payment modules installed with 231 in progress as at 30 June 2026. Those figures indicate a substantial and continuous implementation practice without disclosing what it costs the client. The integration network launched in July 2025 is the material cost lever the company does describe, because giving third party providers direct access to open interfaces removes the institution from the middle of integration work it would otherwise pay someone to coordinate, and the open ecosystem is reported at more than a thousand providers. For a community bank or credit union with no engineering team, avoided integration cost is the relevant economics. Nothing published describes onboarding timelines, conversion effort or whether artificial intelligence capabilities require separate enablement work. Vendor Published

Two passes across the company's site, its investor materials, its product pages and the trade press produced no price, unit or tier for any product. Securities reporting supplies a partial substitute and an unusually useful one, because the company reports installations and contract signings by product line each quarter.

A buyer can therefore see that the financial crimes platform reached 189 completed installations with 57 in progress and that 183 contracts were signed across it and the faster payment modules in a year, which establishes both that these are separately contracted modules and roughly how fast the market is adopting them. That is competitive intelligence a private vendor would never publish.

One question the disclosure does not answer is the most important one for this buyer set: whether the 22 artificial intelligence enabled products carry incremental charges or arrive inside existing licences, which for an institution of around 1.2 billion dollars in assets is the difference between adopting them and not.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746