KYP
KYP, for Know Your Partner, monitors the businesses an institution depends on rather than the customers it onboards, replacing point in time due diligence with continuous surveillance. It aggregates more than 2,000 global data points covering credit scores, sanctions and politically exposed person lists, adverse media, insolvency filings, cyber risk assessments and dark web activity, then applies its own models to connect those signals into a single risk picture and raise alerts as it changes.
Named uses in financial services include merchant portfolio monitoring for acquirers and risk scoring of third party providers each time they access an account servicing institution under open banking, alongside supply chain due diligence and invoice risk scoring. Distribution runs largely through payments and embedded finance infrastructure partners.
Capability Axes
Capability grades
15 of 15 axes rated · 3 graded A or B
Models do the connecting work, with proprietary machine learning and regression models described as intelligently linking signals from more than 2,000 sources into a holistic view of a counterparty rather than presenting them as separate feeds, which is the difference between a data subscription and a risk picture.
Against that, the underlying asset is aggregation: assembling credit, sanctions, adverse media, insolvency, cyber and dark web data at that breadth is substantial work in its own right, and a customer receiving those signals with simple threshold alerts would still have something useful. Models sharpen the output rather than constituting it.
The product is positioned to inform rather than to conclude, generating actionable risk alerts and presenting connected signals through visualisation described as simplifying investigations, which places a human analyst at the point of judgement and is the right division for third party risk. That framing is implicit in the design rather than stated as a boundary.
Nothing published describes a confidence indication on a risk score, a threshold at which an alert escalates, or what an institution is expected to do when a monitored counterparty's score deteriorates, which for merchant monitoring is the moment that matters.
No accuracy, precision or false positive rate was located for the scoring or the matching, and intelligent connection of data points is asserted rather than measured. For a continuous monitoring product the operative figures are how often an alert reflects a real change in counterparty risk and how often a genuine deterioration is missed, and neither is published.
The visualisation layer means a user can inspect which signals drove a score, which is a genuine transparency mechanism, but inspecting an explanation is not the same as knowing how often the conclusion is right.
Evidence is partnership shaped rather than customer shaped. Four commercial relationships are named, including a cybersecurity ratings business owned by a major card network, a financial infrastructure provider whose chief executive is quoted describing the addition of continuous monitoring to its existing onboarding, screening and transaction monitoring, an embedded finance platform, and an open banking account provider.
Selection into a major consultancy's London financial technology innovation lab and a finalist place in a payments industry pitch competition judged by investors and bank representatives add independent recognition. Against all that, no customer is named, no monitored volume or portfolio figure is published, and funding is reported at only a few hundred thousand dollars for a company founded in 2021.
No data boundary statement was located. The platform's value rises with the breadth of counterparties it has already assessed, and distribution through infrastructure partners means many institutions query overlapping populations of merchants, suppliers and providers, so risk profiles built for one customer are the natural asset to serve the next.
Nothing states whether assessments are shared, whether a customer's own monitoring activity contributes to the wider picture, or how the fact that a particular institution is investigating a particular counterparty is protected.
No data protection agreement, retention schedule or subprocessor list was located. The subjects are mostly businesses rather than individuals, which shortens the personal data chain, but two of the enumerated sources cut across that: politically exposed person and adverse media data concerns named individuals and their associates, and dark web monitoring by definition processes material originating in breaches of other people's personal information. Nothing published describes how those categories are handled, how long an adverse finding persists, or what happens to a profile assembled on a business that never becomes a customer.
No attestation, certification, trust centre or enumerated framework was located. That is a particular gap for a vendor whose own proposition includes alerting institutions to damaging data breaches at their third parties, since a platform selling third party risk assurance is itself a third party in every customer's supply chain, and the assessment it invites others to perform is one it does not publish for itself.
Regulated roles are named where competitors would use generic language, with third party providers and account servicing payment service providers identified by their formal designations under open banking rules, which shows the product was built around a specific regulatory relationship rather than adapted to it. Anti money laundering and counter terrorist financing pressures are cited as the market driver.
What is missing is the instrument itself, with no regulator, statute or supervisory expectation named, and no statement of which obligation an acquirer discharges by monitoring its merchant portfolio through this platform.
The subjects are businesses, which removes the protected characteristic exposure that drives this axis in consumer lending, and replaces it with an accuracy problem that carries comparable consequence. A poor score can cause a merchant to be offboarded by its acquirer, a supplier to be dropped or a provider to be refused access, and two of the underlying source types are known to misfire: adverse media matching generates false positives on common names and on non Western naming conventions, and politically exposed person screening is notoriously imprecise about associates.
Combining more than 2,000 signals raises rather than lowers the chance that one bad match colours the whole picture. Nothing published describes match confidence, dispute handling or how a wrongly scored business learns it has been assessed at all.
No guarantee, indemnity or falsifiable accuracy commitment was located. The institution is served by visualisation that lets an analyst trace which signals produced a score before acting on it, which supports a defensible decision.
The monitored business has nothing: it is assessed without its knowledge, from sources including adverse media and dark web material it cannot see, and no correction, notification or dispute route is described, which matters most in the merchant monitoring case where the consequence is losing the ability to accept payments.
The data chain is enumerated by category with unusual specificity for a company this size, naming credit scores, dark web activity, politically exposed person and sanctions lists, adverse media, cyber risk assessments and insolvency checks across more than 2,000 global data points, so a buyer can see what kinds of signal underpin a score.
One supplier is named directly, the cybersecurity ratings business providing the cyber dimension, which is the component a buyer would most want attributed. What remains undisclosed is every other individual provider behind those categories, along with any model provider, subprocessor list or hosting arrangement.
The distribution model is the integration story and it is sensible for a company of this size: rather than selling directly to institutions, the platform is embedded into infrastructure that institutions already use, with a financial infrastructure provider adding it alongside its existing onboarding, screening and transaction monitoring, an embedded finance platform incorporating it into client onboarding, and an open banking account provider applying it to the providers reaching into its accounts.
A cybersecurity ratings business owned by a major card network supplies the cyber dimension. Interface based data connection is described. What is absent is any named institutional system on the other side.
No hosting provider, region selection, residency commitment or private deployment option was located. The company is United Kingdom based and its partners operate across Europe, so processing location is a question a regulated buyer would raise, and the aggregated data includes material about named individuals in the politically exposed person and adverse media categories where handling location carries its own requirements.
No pricing, packaging or basis of charge was located. The unit question matters for a continuous monitoring product, since cost could plausibly scale with the number of counterparties watched, the frequency of assessment or the volume of alerts, and an acquirer monitoring a large merchant portfolio faces very different economics from a business watching a handful of suppliers. Nothing indicates which applies.
Two use cases are specific to financial institutions and they are the ones that make this a member of this index rather than a corporate supply chain tool: merchant portfolio monitoring for acquirers, which is a supervised obligation for the institution carrying that portfolio, and risk scoring of third party providers each time they reach into an account servicing institution under open banking rules.
Alongside them sit general supply chain due diligence and invoice risk scoring, which serve corporate buyers. Neither the institutional footprint nor the geographic reach is evidenced, and no bank, acquirer or payment institution is named as a user, so coverage here is a described capability rather than a demonstrated one.
Alternatives to KYP
The closest documented capability profiles to KYP in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents Institution and Segment Coverage and Autonomy and Oversight Model where KYP does not
Documents Institution and Segment Coverage where KYP does not
Documents Operational and Outcome Evidence and Institution and Segment Coverage where KYP does not
Documents Operational and Outcome Evidence and Institution and Segment Coverage, among others where KYP does not
Documents Institution and Segment Coverage where KYP does not
Documents Institution and Segment Coverage and Regulatory Status and Licensure where KYP does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.