LexisNexis Risk Solutions
LexisNexis Risk Solutions is a data and analytics business founded in 1997, headquartered in Alpharetta, Georgia and owned by RELX. It sells across insurance, healthcare, government and law enforcement as well as financial services, and this record covers only its financial crime, fraud and identity lines. Those run deep. ThreatMetrix supplies digital identity and device intelligence drawn from the Digital Identity Network, a contributory pool the company describes as holding insight into more than 3.3 billion anonymised user identities and intelligence behind over 109 billion annual transactions.
LexID Digital provides a dynamically matched tokenised customer identifier, and Behavioral Biometrics layers interaction analysis over both. The Dynamic Decision Platform delivers orchestration, forensic investigation, case management and reporting, while RiskNarrative offers end to end financial crime lifecycle management through a single application programming interface, letting compliance teams change risk models directly and integrate within days.
Financial Crime Digital Intelligence combines ThreatMetrix, the Dynamic Decision Platform and the company's own WorldCompliance sanctions and politically exposed person data to assess sanctions exposure in digital channels, including a Sanctions Location Risk capability that pierces proxies and triangulates up to ten location signals. Underneath sits patented LexID Linking Technology and the HPCC Systems data platform. The company reports performing more than 100 million identity verification checks and over 100 billion screening requests annually and working with 93 percent of the Fortune 100.
Two legal entities matter to buyers: LexisNexis Risk Solutions Inc. is a consumer reporting agency under the Fair Credit Reporting Act, while LexisNexis Risk Solutions FL Inc., which provides identity verification and fraud prevention, is not.
Capability Axes
Capability grades
15 of 15 axes rated · 9 graded A or B
This is a data business with models layered over it rather than a modelling business, and the removal test makes that plain. Strip out the machine learning and what remains is enormous and still saleable: more than 3.3 billion anonymised identities in the Digital Identity Network, the company's own WorldCompliance sanctions and politically exposed person dataset, aggregated public records, and knowledge based authentication products such as InstantID Q and A which run interactive questioning against more than 300 data points without needing a model at all.
The company's own framing supports the reading, describing itself as using big data, proprietary linking and targeted solutions, and positioning LexID Linking Technology, a patented entity resolution method, as the machine behind many of its products. Real modelling sits on top and is not trivial: patented algorithms, predictive modelling, behavioural biometrics and two decades of stated AI work in fraud and identity. But the asset that competitors cannot replicate here is the data estate, not the models.
The orchestration layer is built around keeping the institution in control and the company says so directly, positioning RiskNarrative as putting financial crime experts in control of multiple information sources to make strategic changes to risk models in minutes. That is customer authored model change with a stated turnaround, not a support ticket.
Around it, the Dynamic Decision Platform supplies forensic investigation, case management, reporting and workflow orchestration, so alerts land in an analyst environment rather than triggering automatic action, and it allows additional intelligence sources to be layered in instantly. Financial Crime Digital Intelligence is described as operating through custom designed policies and automated workflows matched to the institution's own risk appetite, with configurable user roles.
What is not published is any specification of what the models do underneath: no default thresholds, no statement of how a customer is notified when scoring behaviour changes, and no description of what an analyst sees by way of explanation behind a given alert.
Architecture is described and performance is not. The company identifies patented LexID Linking Technology as the entity resolution method behind many of its products, names HPCC Systems as the underlying data platform, which is publicly documented in its own right, and states it applies data science, patented algorithms, predictive modelling, machine learning and artificial intelligence, with two decades of stated work in fraud and identity.
A reviewer can therefore understand the shape of the system. None of that is measurement. No accuracy figure, precision or recall measure, false positive rate, validation report, model documentation or monitoring statement was located for any product in scope.
The published data error disclaimer establishes that inputs may be wrong without quantifying how often or with what effect, and the company separately disclaims that its own documentation is complete or error free, which leaves a model risk function with no vendor supplied basis for validation at all.
The largest operating scale disclosed by any vendor in this index, stated in specific and independently checkable form. The company reports performing more than 100 million identity verification checks and over 100 billion customer and transaction screening requests annually, holding insight into more than 3.3 billion anonymised user identities, drawing intelligence from over 109 billion annual transactions, and working with 93 percent of the Fortune 100.
Ownership by RELX means the business sits inside a listed group with audited reporting. Named customer evidence exists, with Novuna reported reducing fraud, improving compliance and increasing efficiency using RiskNarrative, alongside described but unnamed deployments at a leading United Kingdom consumer lender and a large commercial bank. External recognition includes a Risk.net cyber risk solution of the year award.
The company also publishes recurring primary research including the Global State of Fraud and Identity, the Cybercrime Report drawn from its own network, and the True Cost of Financial Crime Compliance study, which are checkable artifacts rather than claims.
Better than the lane norm on framing and structure, still short on terms. Three things lift it. The Digital Identity Network is described as holding anonymised identities rather than identified ones, which is a stated processing constraint on the shared pool. The corporate structure separates the consumer reporting agency entity from the entity providing fraud and identity services, which is a governance control on how regulated consumer data and commercial risk data may mix.
And the company treats network participation as a buyer decision rather than an assumption, publishing research on consortium data models and asking prospects directly whether they are part of the right network, which is unusually honest framing for a vendor whose network is its advantage.
Against that, no contribution terms, opt out mechanism, segregation statement or retention schedule was located for the network itself, and the underlying business aggregates public records and third party data about individuals who have no relationship with the company and did not choose to be in it.
The strongest privacy position in this index, and it rests on structure and statute rather than on policy language. The company publishes which of its legal entities holds which regulated status: LexisNexis Risk Solutions Inc. is a consumer reporting agency as defined under the Fair Credit Reporting Act, while LexisNexis Risk Solutions FL Inc., which provides identity verification, fraud prevention and risk management, is not.
Publishing that split lets a buyer or an individual determine precisely which statutory regime governs a given product, which no other vendor here does. A consumer facing disclosure portal is operated where an individual may request a copy of the information maintained about them, which is a live access mechanism rather than a stated right.
A published Commitment to Data Responsibility sets out the governance position, the company states a comprehensive risk management programme with privacy and security policies designed to prevent impermissible access or use, and it acknowledges openly that it uses proprietary data alongside third party sources. What is absent is the processor detail a business buyer needs: no processing addendum, subprocessor list or retention schedule was located.
Two dedicated passes located extensive assertion and no credential. The company states that it is one of the largest protectors of private and confidential data in the world, that it has an entire organisation exclusively devoted to information security, that it operates a comprehensive risk management programme with strict privacy and security policies designed to ensure data is not accessed or used impermissibly, and that it is rigorous in its compliance with legal and regulatory guidelines, alongside a published Commitment to Data Responsibility.
None of that names a standard, an assessor, a scope or a date. No service organisation control report, ISO certificate, payment card attestation, penetration test summary or trust centre was located. That is a striking gap for an organisation of this size holding regulated consumer data, and the assessments will certainly exist inside enterprise procurement. Pre emptive negative finding: further statements about commitment and devotion to security will not move this grade. A named certification with its scope and assessor is what would.
This vendor holds an actual regulated status rather than selling compliance to those who do. LexisNexis Risk Solutions Inc. is a consumer reporting agency as defined under the Fair Credit Reporting Act, which carries statutory obligations on accuracy, permissible purpose, consumer access and dispute handling, and exposes the entity to federal supervision and enforcement. That is a supervisory relationship of a kind almost nothing else in this index has.
Products are built to named statutory instruments rather than to general compliance themes, including a red flags rule report for Fair and Accurate Credit Transactions Act compliance, sanctions, anti bribery and corruption and counter terrorist financing screening, and international enhanced due diligence. The corporate structure is disclosed with the regulatory consequence attached, telling a buyer which entity and therefore which regime governs a given product. The company additionally states it is rigorous in compliance with legal and regulatory guidelines, which on its own would be assertion, but here sits on top of a documented status.
One candid admission and no measurement behind it. The company publishes, on its product pages rather than buried in terms, that because of the nature and origin of public record information the public records and commercially available data sources used in its reports may contain errors. Very few data vendors state that plainly and it is directly relevant here, since those records feed identity, fraud and screening decisions. It is an acknowledgement rather than a control.
No error rate, false positive rate, accuracy measure, calibration statement or confidence metric is published for any model or dataset. No fairness testing or disparate impact analysis exists, and the exposure is substantial: public record and commercial data coverage is systematically thinner and less accurate for younger consumers, recent arrivals and people with limited credit and address histories, and thin coverage in an identity verification product produces a failure to verify rather than a neutral result. Nothing describes model change control or how a customer learns that scoring behaviour has shifted.
The only vendor in this index operating a live consumer access route, and it publishes the limit of that route itself. An individual may request a copy of the information maintained about them through a dedicated consumer disclosure service, and because LexisNexis Risk Solutions Inc. is a consumer reporting agency under the Fair Credit Reporting Act, statutory rights of access, dispute and correction attach to data held by that entity.
Nothing else graded here gives an affected person a mechanism at all. The limit is disclosed rather than hidden, and a buyer should read it carefully: LexisNexis Risk Solutions FL Inc., the entity stated to provide identity verification, fraud prevention and risk management, is explicitly not a consumer reporting agency, so the products this record covers sit outside the entity to which those statutory rights attach. For the institution there is no guarantee, indemnity or accuracy service level, and the company disclaims that its documentation guarantees any product functionality.
Internal components are named thoroughly and external suppliers are not named at all. On the internal side the disclosure is genuinely detailed: WorldCompliance is identified as the company's own sanctions and politically exposed person dataset, ThreatMetrix and the Digital Identity Network as the digital identity layer, LexID Linking Technology as the patented entity resolution method, and HPCC Systems as the data platform, so a buyer can trace which company owned asset produces which part of a decision.
The company also states openly that it uses proprietary data together with information from third party data sources, and that public records are an input which may contain errors. What it never does is say whose. No third party data supplier, credit bureau, telecommunications, device or email intelligence provider is named anywhere, no subprocessor list exists, no cloud infrastructure provider is identified, and no model or foundation model provider is named.
The integration story is consolidation rather than breadth of connectors, and it is credibly specified. RiskNarrative is described as needing only one integration to reach multiple services, delivered through a restful application programming interface, with availability stated within days rather than months, and it unifies onboarding, compliance and risk based workflows that would otherwise be separate integrations.
The Dynamic Decision Platform is the delivery vehicle for ThreatMetrix and is built so further intelligence and risk assessment solutions can be layered in instantly, which means adding a capability does not mean adding an integration. That architecture matters for a vendor selling eight or more products into the same institution.
What is absent is any enumerated connector catalogue: no named core banking, payment processing, customer relationship or case management integrations were located, and no public developer documentation was found for the products in scope.
Nothing was located on either half of this axis. No deployment model is stated for the products in scope, so it is not established whether they are available only as hosted services or whether private or on premises options exist, and no cloud provider, region, data centre or country of processing is named. No transfer mechanism, residency commitment or region selection appears.
The company operates globally with named United Kingdom customers alongside a United States base and a European parent, so cross border processing plainly occurs and none of it is described. HPCC Systems is identified as a cloud native platform underpinning the data estate, which establishes that the infrastructure exists without establishing where it runs. For a vendor holding regulated consumer data under a federal statute and selling into multiple jurisdictions, the absence of any published residency position is a real gap.
No rate, tier, band, entry point, free tier or trial was located across two dedicated passes, and no pricing page exists for any product in scope. No metering unit is disclosed either, so a buyer cannot tell whether the fraud and financial crime products are priced per verification check, per screening request, per monitored customer, per module or by enterprise subscription, which matters because the company sells at least eight distinct products into the same buyer.
The only commercial artifact published is a sales telephone number for the risk management suite. The company does publish a disclaimer stating that its own product documentation is for informational purposes only, does not guarantee functionality or features, and is not represented as complete or error free, which is candid about the status of the material a buyer would otherwise rely on and simultaneously removes it as a basis for commercial expectation.
Within financial services alone the coverage spans buyer types, workflow stages and geographies more completely than any competitor graded here. Buyers include banks, consumer lenders, payments businesses and online gaming operators, with named or described deployments at a United Kingdom consumer lender, a large commercial bank and Novuna.
Workflow coverage runs the full financial crime lifecycle: onboarding and identity verification, know your customer, enhanced due diligence, sanctions and politically exposed person screening, transaction screening, ongoing fraud detection, behavioural biometrics and case investigation, with RiskNarrative explicitly sold as end to end lifecycle management rather than a point solution.
Products exist for named statutory obligations including the Fair and Accurate Credit Transactions Act red flags rule. Reach beyond financial services into insurance, healthcare, government and law enforcement is outside this record's scope but demonstrates the underlying data estate's breadth. Working with 93 percent of the Fortune 100 evidences penetration rather than merely claiming it.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Protection Terms | Implementation | Source |
|---|---|---|---|---|
|
Not published. No rate, tier, metering unit, free tier or trial was located for any financial crime, fraud or identity product in scope.
|
Undisclosed. Neither a rate nor a metering unit is published for any product in scope. The scale figures the company does publish hint at the likely shape without confirming it, since it reports performing more than 100 million identity verification checks and over 100 billion customer and transaction screening requests annually, both of which are countable events of the kind data businesses conventionally meter. The product structure points to modular licensing, with device intelligence, tokenised identity, behavioural biometrics, sanctions and politically exposed person data, enhanced due diligence, orchestration and case management all sold as separate named offerings that a customer can take individually or combine, and with Financial Crime Digital Intelligence explicitly described as a package combining three of them. Nothing indicates whether contributory network participation affects price, which would be a material question for a buyer weighing whether to contribute data. | No processing addendum or subprocessor list was located, but the regulatory position is published more clearly than anywhere else in this index. The company states which of its entities holds which status: LexisNexis Risk Solutions Inc. is a consumer reporting agency under the Fair Credit Reporting Act, carrying statutory obligations on accuracy, permissible purpose and consumer dispute handling, while LexisNexis Risk Solutions FL Inc., which provides identity verification, fraud prevention and risk management, is not. A consumer disclosure service operates where an individual may request a copy of the information held about them. A Commitment to Data Responsibility is published. On assurance, two dedicated passes found extensive assertion about information security and no named certification, assessor, scope or date. | Not published and not disclaimed. The company's own integration claims suggest low implementation effort for the orchestration layer specifically: RiskNarrative is described as needing only one integration to reach multiple services through a restful application programming interface, with availability stated within days, and the Dynamic Decision Platform is built so additional intelligence sources can be layered in without further integration work. That architecture is designed to reduce exactly the cost this field asks about. Against it, the product set in scope spans at least eight distinct offerings covering identity verification, device intelligence, behavioural biometrics, sanctions screening, enhanced due diligence, case management and lifecycle orchestration, and no statement addresses configuration, policy design or data onboarding effort for any of them, nor whether professional services are chargeable. | Vendor Published |
Two dedicated passes returned no figure of any kind. No pricing page exists for any product in scope, no tier structure is published, and no metering unit is disclosed, so a buyer cannot tell whether these products are charged per identity verification check, per screening request, per monitored customer, per module or as an enterprise agreement. The only commercial artifact located is a sales telephone number attached to the risk management suite. Two pre emptive negative findings.
First, the company publishes a disclaimer that its own product documentation is for informational purposes only, does not guarantee functionality or features, and is not represented as complete or error free, so material a buyer might rely on during evaluation is expressly disclaimed as a basis for expectation.
Second, this is a very large multi industry data business selling the same underlying estate into insurance, healthcare and government as well as financial services, so any rate that surfaces for one product in one sector should not be treated as indicative for another.