Kiya.ai
Kiya.ai, which trades as KiyaAI and whose legal entity remains Infrasoft Technologies, is a Mumbai based banking software and services group serving more than four hundred and fifty clients across fifty countries from twelve offices, selling to banks, cooperative and rural banks, microfinance institutions, Islamic banks, neobanks, fintechs and governments. The estate is organised in five lines. Digital core banking covers a cloud native core, a hosted core, digital lending management, microfinance and Islamic banking.
Universal RegTech covers anti money laundering and anti fraud surveillance, governance risk and compliance, environmental and social reporting, data protection and operational resilience tooling, and a deep regulatory reporting bench spanning alternative investment fund reporting, tax information exchange, central credit register submissions, Spanish market regulator filings, country by country reporting, cross border arrangement reporting and structured business reporting.
The channel line covers internet, mobile, tablet, wallet and kiosk banking, an instant payments switch for India's unified payments interface, customer onboarding, contact management, a conversational interface and Kiyaverse, a banking metaverse used by Punjab National Bank for a virtual branch. Open finance is delivered through an application programming interface developer gateway with published support for the authorisation protocols and for onboarding and managing account information providers, payment initiation providers and other third parties.
Digital engineering services cover robotic process automation, cognitive analytics, big data, immersive interfaces, testing and application modernisation, and a separate artificial intelligence based analytics line sits alongside them. Named engagements include Jordan Ahli Bank, Punjab National Bank, Bank of Maharashtra, Kerala State Cooperative Bank, Agribusiness Rural Bank, Philtrust Bank in the Philippines and Merchant Finance in Fiji.
The company holds ISO 9001:2015 and ISO 27001:2022 and is appraised at CMMI Level 5, took nine placements in the 2026 IBSi Sales League Table including first in India for compliance, digital banking and payments, and won a best in class regulatory technology award in 2026.
Capability Axes
Capability grades
15 of 15 axes rated · 4 graded A or B
The Clearwater precedent, and the most instructive application of it on this roster because the vendor's own brand asserts the opposite. The company rebranded from an established Indian banking software house to a name ending in the artificial intelligence domain suffix, and its own copyright line still carries the original corporate name.
Strip every model and what remains is a complete working business: a cloud native and hosted core banking platform, lending and microfinance and Islamic banking modules, internet, mobile, tablet, wallet and kiosk channels, an instant payments switch, an open banking gateway, and a large regulatory reporting bench covering fund reporting, tax information exchange, credit register submissions and structured business reporting, none of which involve inference at all.
The learned line is real but narrow and mostly unspecified: an analytics offering, cognitive analytics, a conversational interface, machine learning inside anti money laundering and anti fraud surveillance, and tooling described as automating credit scoring, risk assessment and fraud detection inside loan origination.
Automation asserted, no control named, which is the floor. The published framing is that smart solutions automate processes and deliver cost efficiency, and that the lending origination tooling automates the entire origination process from campaign management and data capture through credit scoring, risk assessment and fraud detection.
The word entire is doing a great deal of work and nothing qualifies it: no approval step, no threshold, no confidence band, no review requirement, no exception route and no statement of what a person must sign off. Robotic process automation and bots are sold as separate lines beside it.
For a product set that reaches consumers directly through chat, kiosk and mobile channels and screens them for money laundering and fraud, the absence of any published oversight position is a material gap rather than a neutral one.
Nothing whatever. No accuracy figure, no error rate, no validation methodology, no backtesting, no drift monitoring, no versioning, no external assessment, and no description of how any model reaches a decision, across anti money laundering surveillance, fraud detection, credit scoring support and a conversational interface.
The contrast that makes this worth writing up sits on the same roster: Loxon never markets on artificial intelligence at all and publishes backtesting, signal significance testing, reject inference, plausibility checking and rating migration matrices, taking B on this axis. This vendor put the technology in its own brand name and publishes no model documentation of any kind.
The bar for this axis is a named customer with a quantified outcome and it is met twice, with the same institution, in the vendor's own client stories library. Jordan Ahli Bank is named against a sixty percent reduction in process turnaround time on the digital lending solution, and separately against a thirty percent rise in lead conversion on the customer relationship product.
Around them sit further named engagements with results described but not numbered: Punjab National Bank running its first virtual branch on the metaverse platform, Bank of Maharashtra on digital onboarding, Kerala State Cooperative Bank on digital channels, Agribusiness Rural Bank on anti money laundering, and dated 2026 announcements with Philtrust Bank and Merchant Finance in Fiji.
Independent measure exists as well in the form of nine placements in an industry sales league table with first position in India across three categories. Caveat recorded rather than deducted: both quantified outcomes are workflow results attached to the platform rather than to any model, so this is strong evidence that the software works and not evidence that the models do.
Silent. Nothing states whether customer data trains or tunes any model, whether anything is pooled across the four hundred and fifty institutions on the platform, what the conversational interface retains from a banking conversation, or how long anything persists.
The question is live rather than academic for this product set, because the same vendor operates hosted core banking, anti money laundering surveillance and a customer facing chat channel for the same institutions, which is an unusually complete view of a bank's customers, and no boundary between those surfaces is described anywhere.
A general website privacy statement and a modern slavery policy, and nothing at product level. No retention schedule, no deletion terms, no subprocessor disclosure, no tenant separation statement for a hosted multi customer core banking platform, and no privacy specific attestation.
The sharp point here is a commercial one rather than a technical one: the company sells a data protection compliance product and a governance risk and compliance product to the same institutions whose deposit, loan, transaction and onboarding records it holds, and publishes no data handling position of its own.
Two real certifications and one process appraisal, all correctly named, and the presentation is more precise than most of this roster: ISO 27001:2022 and ISO 9001:2015 are both given with the edition stated, and the maturity appraisal carries its version. Stating editions is the strong shape this index has recorded once before, and it lets a buyer see the credential is current rather than legacy.
Held at B and not A because only one of the three concerns security at all, and because everything a buyer would need next is absent: no certificate number, no certification body, no accreditation chain, no scope statement, no penetration testing disclosure, no SOC report of any type, and no trust portal.
One presentation observation recorded rather than deducted: the only page on the entire site naming a security credential is titled Quality Certifications and sits under the About Us menu beside a project management methodology dating from 1999, so a buyer looking for a security page would not find it. A minor inconsistency also stands, with the maturity appraisal version given differently on the company's own page and in its press boilerplate.
A software and services vendor with no licence, registration or supervised standing of its own. It is unusually close to regulatory machinery, since a large part of the estate exists to file regulatory returns and its open finance platform manages the onboarding of licensed third party providers, but every one of those is a customer obligation the software discharges rather than a position the firm holds. Industry awards and a sales league table placement are commercial recognition and carry no supervisory weight.
Nothing at product level. No fairness testing, no treatment of protected characteristics, no disparate impact analysis, no governance framework, no named standard and no position on any artificial intelligence regulation. The exposure is concrete and unusual in its shape: this vendor's buyers include rural banks, cooperative banks and microfinance institutions, which serve exactly the borrowers most exposed to proxy discrimination in automated credit scoring and least able to contest it, and the origination tooling is sold as automating credit scoring and risk assessment for those institutions. A vendor that sells governance, risk and compliance software and environmental and social reporting to the same customers publishes no governance position on its own models.
No recourse position published. The division is the standard one and it is compounded here by channel reach: automated screening can freeze a payment or block an onboarding, automated scoring can decline a loan, and the customer meets the outcome through a mobile app, a chat interface or a village kiosk rather than a person.
Nothing states whether a customer is told a model was involved, how a wrong outcome is challenged, what remedy exists, or how responsibility divides between the vendor supplying the models and the institution operating them. The institution is the regulated party and carries all of it.
Not one model, provider, version or base model is named anywhere, across a conversational interface, cognitive analytics, an analytics line and machine learning inside surveillance products. The buying forces disclosure rule points hard the other way: conversational and generative capability at this company's scale is licensed rather than built, and the vendor names nothing.
The only technology dependencies named anywhere are the developer environments its own gateway supports and the authorisation protocols it implements, which are integration surfaces rather than model components, the same distinction recorded against Pega, Opensee, Pennant and SBS.
Graded A on the basis that carried Azentio and SBS: the vendor supplies the core itself, in both cloud native and hosted forms, so lending, microfinance, Islamic banking, channels and regulatory reporting attach to its own system of record rather than through connectors. Two further pieces of real specificity sit on top and lift this above the roster norm.
It ships a switch for India's unified payments interface, which is integration with a named national real time payment scheme rather than a generic payments claim. And its open finance platform is described at protocol and role level rather than at category level: an application programming interface developer gateway with lifecycle governance from development through runtime to retirement, named authorisation and identity protocols, and onboarding, verification, offboarding and management of account information service providers, payment initiation service providers and other third party providers. That is the level of detail Pennant was held at B for lacking.
Deployment choice is answered at product level and residency is untouched. Cloud based core banking and hosted core banking are sold as separate named offerings rather than as one product with options, and cloud native architecture is claimed as a headline attribute. Nothing states which cloud, which regions, where data is held, how it is kept inside a jurisdiction, or what happens for the many customers in markets with data localisation rules.
That gap is wider here than for most vendors on this roster because the customer base spans India, the Gulf, southeast Asia, Africa, Europe and North America simultaneously, and because the company separately sells a data protection compliance product to the same buyers.
No pricing published in any form across five product lines sold in cloud, hosted and on premises shapes to buyers ranging from rural cooperative banks to national institutions and governments. No tiers, no bands, no module structure, no licensing model. Every route through the site ends at a demo request.
An investor relations page exists and was not opened, which for a company of this vintage is the one place a revenue or contract disclosure might surface, though it would be corporate reporting rather than product pricing.
More than four hundred and fifty clients across fifty countries from twelve offices, with a partner network spanning southeast Asia, Africa, the Middle East, Europe and North America. The buyer range is genuinely wide and includes several types this index sees rarely: alongside commercial banks it names cooperative banks, rural banks, microfinance institutions, Islamic banks and governments, and the named engagements bear that out across India, Jordan, the Philippines and Fiji.
Held at B on the same line applied to Loxon and Pennant: no tier one global institution appears among the named customers, the client count is self reported and differs between the company's own pages and its press boilerplate, and for a firm with a large services business a client is not necessarily a platform customer.
Alternatives to Kiya.ai
The closest documented capability profiles to Kiya.ai in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents Autonomy and Oversight Model where Kiya.ai does not
Documents Deployment Model and Data Residency where Kiya.ai does not
Documents Autonomy and Oversight Model where Kiya.ai does not
Documents Autonomy and Oversight Model where Kiya.ai does not
Documents Autonomy and Oversight Model where Kiya.ai does not
Documents Autonomy and Oversight Model where Kiya.ai does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.