AML, KYC & Financial Crime
L

Lucinity

Lucinity builds what it calls Human AI for financial crime prevention, pairing models with the investigators who use them rather than replacing them. Its assistant Luci, launched in 2023 as the first generative copilot for this function, summarises and analyses complex cases, runs adverse media checks, drafts suspicious activity reports and takes investigations from hours to minutes, working either inside the company's own case management and customer view modules or as a plugin into whatever transaction monitoring, fraud and know your customer systems an institution already runs.

The platform is deliberately system agnostic, built on a major cloud provider's enterprise AI service, and uses retrieval augmented generation with validation and detailed audit logging. A large enterprise software group secured rights to the investigation technology in 2026 and embedded it in its own financial crime platform.

Last VerifiedAugust 14, 2026
Compare Lucinity with other vendors
Founded
Headquarters
Reykjavík, Iceland
Website
lucinity.com
Categories
aml-kyc-financial-crime, compliance-and-surveillance, fraud-and-transaction-risk
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 10 graded A or B

AI Capability
AI Centrality
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.
Vendor Published

The removal test leaves a case management tool. The company is built around its generative assistant, launched in 2023 as the first copilot for financial crime prevention, which renders complex data into real time insights, analyses cases, runs adverse media checks and drafts regulatory reports, turning work measured in hours into work measured in minutes. The stated purpose of the whole platform is combining models with human expertise, and the newer positioning around agent led operations pushes further in the same direction rather than away from it.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

Human involvement is the company's entire identity, expressed in a Human AI positioning that combines models with human expertise, delivered as a copilot supporting investigators rather than a system deciding for them, and underpinned by detailed audit logging described as ensuring maximum auditability because the product was built inside the compliance sector. A published ethical artificial intelligence pledge sits alongside it.

One shift deserves noting and is not addressed anywhere: the same product described in 2024 as your artificial intelligence copilot is described in 2026 as your artificial intelligence agent, with the partner integration framed around agent driven investigation workflows, and no corresponding statement explains what changed in the oversight model when the language changed.

Model Risk Management and Transparency
BB on Model Risk Management and TransparencyReal transparency mechanisms are published, such as per alert explainability, confidence scoring or split testing, without the validation package or supervisory mapping behind them.
Vendor Published

The architecture is named rather than asserted, with the assistant described as combining retrieval augmented generation with rigorous validation to deliver safe and accurate output, and the company has published specifically on how that combination works. Retrieval grounding is the correct control for this use case because it ties statements to case documents rather than to model recall.

Detailed audit logging means any conclusion can be reconstructed afterwards, which matters where findings support regulatory filings and potentially legal proceedings. What is missing is measurement: no accuracy rate, false positive figure, summarisation fidelity result or validation output is published, so a model risk function has an architecture to assess and no numbers to assess it against.

Operational and Outcome Evidence
AA on Operational and Outcome EvidenceNamed customers with hard performance figures and enough method to test them.
Vendor Published

The strongest single fact is recent and structural: in April 2026 a major enterprise software group secured rights to this company's investigation and case management technology and embedded it into its own financial crime and compliance platform, making agent led investigation workflows available to financial institutions across that group's global customer base. That is a large incumbent choosing to distribute a startup's technology rather than build its own.

Named customers include a payments business owned by a global card network, whose money laundering reporting officer is quoted directly, and a national bank. Financial Times reporting recorded seven large global banks requesting trials of the standalone copilot, with the chief executive stating usage among those customers had grown exponentially. The company won partner of the year for its country at a major cloud provider's 2024 partner awards.

AI Safety and Data Stewardship
BB on AI Safety and Data StewardshipA categorical stewardship commitment is published without the retention schedule or the engineering detail behind it.
Vendor Published

Two architectural facts answer most of this axis. The assistant runs on an enterprise cloud AI service chosen explicitly for data protection rather than on a consumer grade interface, which is the arrangement under which customer prompts and documents are not used to improve the provider's models.

And retrieval augmented generation means the system retrieves from an institution's own case material at query time rather than absorbing it into weights, so what one bank's investigations contain does not become part of a model serving another. Held at B because the retention terms behind that arrangement are not stated in the way Marloo states its own, and nothing addresses whether anything is learned across the customer base.

Regulatory and Compliance
GLBA and Data Privacy Posture
BB on GLBA and Data Privacy PostureA substantive privacy document that reaches the product itself, short of the subprocessor list or the full data handling detail.
Vendor Published

The privacy position is tied to a specific infrastructure choice and stated as the reason for it: the assistant was developed on a major provider's enterprise AI service in order to guarantee security standards and offer what the company describes as top tier protection for clients' sensitive data while meeting regulatory and enterprise requirements.

That matters because the payload is customer transaction histories, investigation case files and the personal circumstances of people suspected of financial crime, which is among the most sensitive material a bank holds. Held at B because no retention schedule, subprocessor list or data processing terms were located.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

Security is asserted through the infrastructure choice, with the enterprise cloud AI service described as providing secure infrastructure and the highest standards, and no attestation, certification, trust centre or enumerated framework was located.

Trials at seven large global banks and an embedding arrangement with a major enterprise software group mean vendor security assessment has been passed at demanding standards repeatedly, and none of that assurance is published for a prospective buyer to read.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

No regulator, statute or instrument is named. The product is deeply regulatory in function, generating and submitting suspicious activity reports with stated consistency, completeness and quality, and its buyer is typically the money laundering reporting officer, so the regime is implicit throughout.

What is absent is any citation: no supervisory body, reporting rule or programme requirement appears, and for a platform whose output becomes a regulatory filing, naming the regime that governs those filings would be the obvious disclosure.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

A published ethical artificial intelligence pledge is more than most vendors offer and it is a commitment document rather than a mechanism. Three exposures sit beneath it. Adverse media checking carries the documented false positive problem on common names and non Western naming conventions. A suspicious activity report is an accusation that follows a person, and a system that drafts them faster produces more of them.

And the least examined risk is summarisation itself: the assistant condenses complex case material for the investigator who decides, so what the summary omits is what the decision omits, and an investigator working from a generated summary cannot know what was left out. No error analysis, population level testing or summarisation fidelity measure was located.

AI Liability and Recourse
BB on AI Liability and RecourseA published falsifiable commitment such as an accuracy figure with its method, or a real correction route for the affected person, such as step up verification instead of silent denial.
Vendor Published

No commercial guarantee or indemnity was located, and accountability is nonetheless reconstructable by design. Detailed audit logging captures what the assistant did within an investigation, which matters more here than in most applications because the output feeds regulatory filings that may later be examined by supervisors or tested in proceedings, so an institution can show how a conclusion was reached and where a model contributed.

What is missing is the subject side entirely: a person named in a report has no knowledge of it by law and therefore no route to challenge an automated contribution to it, which is inherent to the regime rather than a vendor failing, and the vendor offers nothing beyond it.

Integration and Deployment
Model Supply Chain Disclosure
BB on Model Supply Chain DisclosureSubstantial partial disclosure, or a chain that is structurally short: an explicit in house build, on premise deployment, per customer instances, or zero retention at the model layer.
Vendor Published

The model provider is named explicitly and repeatedly, with the enterprise cloud artificial intelligence service identified as the foundation of the assistant and the choice justified on security and responsible development grounds rather than mentioned in passing. That is more than most vendors in this index disclose, and it lets a buyer assess the fourth party exposure directly. Retrieval augmented generation is named as the technique.

What is not disclosed is the rest of the chain: no subprocessor list appears, no data source is identified for adverse media or sanctions content, and no hosting arrangement is described beyond the cloud platform itself.

Core Systems and Integration Depth
AA on Core Systems and Integration DepthNamed integrations with the systems of record, core banking, policy administration, custodial or contact center platforms, verifiable in marketplace listings or public API documentation.
Vendor Published

Integration is the strategy rather than a feature. The platform is explicitly system agnostic, stated to connect with any transaction monitoring, fraud or know your customer system an institution currently runs or wishes to add, and the assistant is additionally available as a plugin that works inside an existing enterprise ecosystem, described as transforming siloed systems in seconds and providing value without replacing anything.

Distribution extends further through embedding into a major enterprise financial crime platform and through availability on a leading cloud marketplace. That combination, plugin, platform embedding and marketplace, reaches institutions three separate ways.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

The underlying cloud platform is named explicitly and repeatedly, which is more disclosure than most vendors provide, and it stops short of a residency position. No region selection, data location commitment or private deployment option is published, which matters for a company with corporate entities in three jurisdictions serving banks across Europe and North America, each with its own expectations about where customer investigation data is processed.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No pricing, packaging or basis of charge was located. One procurement route is published and it is more useful than it first appears: presence on a major cloud marketplace means an institution can draw on existing cloud commitments to pay for the platform, which shortens the purchasing cycle inside large banks considerably. The company has also published on the build versus buy question its buyers face. Neither amounts to a rate, and nothing indicates whether charge falls per seat, per case, per institution or on usage.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Buyers span retail and wholesale banks, payment institutions and fintechs, with corporate entities established in Iceland, the United Kingdom and the United States and reach extending globally through the enterprise platform partnership.

Functional coverage is broad within financial crime, running from transaction monitoring investigation and case management through customer view, adverse media, fraud and know your customer work to regulatory report generation and submission, with configurable workflow automation on top. The limit is domain: this is financial crime operations specifically, and it addresses the investigation and reporting layer rather than detection itself.

Head to Head

Compared With

Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.

Alternatives to Lucinity

The closest documented capability profiles to Lucinity in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Documents Regulatory Status and Licensure where Lucinity does not

Stronger documented coverage on Autonomy and Oversight Model and Model Risk Management and Transparency

Documents Regulatory Status and Licensure where Lucinity does not

A lighter documented profile than Lucinity

Documents Regulatory Status and Licensure and Security Certifications and Trust Center where Lucinity does not

Documents Commercial Transparency and Regulatory Status and Licensure where Lucinity does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746