AML, KYC & Financial Crime
M

Middesk

Middesk is a business identity platform that verifies companies rather than people, and takes that verification through to a decision. It pulls from primary government sources first, with direct connections to the Internal Revenue Service and all fifty Secretary of State offices, then layers alternative sources and network signals across a stated four hundred data providers, covering business name and address verification, taxpayer identification matching, beneficial ownership, sanctions screening, uniform commercial code filings and ongoing monitoring.

An orchestration layer routes each case through specialised agents that investigate discrepancies, pull additional sources and return a resolved outcome, while purpose built models detect shell companies, synthetic businesses and entity relationship patterns that indicate coordinated fraud. Institutions configure rules for straight through approval and send the remainder to human review, or run rules and agents in parallel. A separate registration product files with state and federal agencies on a client's behalf so businesses can be set up for payroll and tax.

The company states more than five hundred customers across financial technology, banking, lending, marketplaces, insurance and payroll, naming Plaid, Bluevine, Rippling, Novo and Fora Financial, with a published integration into a major engagement banking platform used by banks and credit unions. Coverage is United States only, with international verification stated as a future addition.

Last VerifiedAugust 17, 2026
Compare Middesk with other vendors
Founded
Headquarters
San Francisco, United States
Website
www.middesk.com
Categories
aml-kyc-financial-crime, credit-decisioning
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 7 graded A or B

AI Capability
AI Centrality
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a rules or workflow system.
Vendor Published

Remove the models and a substantial product survives, because direct connections to the tax authority and all fifty state registries are data engineering rather than model work, and a deterministic verification interface over those sources was the original business.

What the models add is the step the company now sells hardest, moving from data to a resolved decision: specialised agents that investigate discrepancies and pull further sources rather than returning an unresolved case, and purpose built detection of shell companies, synthetic businesses and relationship patterns that only surface through inference across a graph. That is the same pattern as the identity decisioning peers in this index, where a working orchestration product sits underneath and the models carry the judgement.

Autonomy and Oversight Model
AA on Autonomy and Oversight ModelWhat the system runs alone, what constrains it, and how a person checks it are all published: modes, thresholds, sampling or audit controls, and the route a case takes to human review.
Vendor Published

The autonomy model is published in the terms this axis exists to reward, naming what runs unattended, what constrains it and where a person enters. Institutions set their own rules for straight through approval, low risk applications are auto approved while complex ones route to human review with the assembled context attached, and agents handle edge cases.

The strongest element is the option to run rules and agents in parallel, which lets an institution compare an autonomous outcome against its existing policy before trusting it, a shadow mode control almost nobody in this index offers. Outputs carry timestamped decisions, source attribution and explainable results, stated as built for examiner review and credit committee defensibility.

Model Risk Management and Transparency
BB on Model Risk Management and TransparencyReal transparency mechanisms are published, such as per alert explainability, confidence scoring or split testing, without the validation package or supervisory mapping behind them.
Vendor Published

Traceability is designed in rather than promised. Every decision is described as carrying a timestamp, attribution to the source that supported it and an explainable result, framed explicitly for examiner review and credit committee defensibility, which means a reviewer can reconstruct why a business was approved or rejected and which record drove it. That is the evidence base supervisory guidance actually asks for and it is stronger than most in this index.

It stops short of an A because performance is never quantified: no accuracy figure, no false positive or false negative rate for shell and synthetic detection, no validation methodology and no drift monitoring cadence appears anywhere.

Operational and Outcome Evidence
AA on Operational and Outcome EvidenceNamed customers with hard performance figures and enough method to test them.
Vendor Published

A named customer appears with numbers attached to it. A small business lender is described as having deployed four billion dollars to more than fifty five thousand businesses while approving loans in under twenty four hours, with the specific contribution stated as automated industry classification and digital fraud signals that its previous providers did not surface.

Four further customers are named across payments infrastructure, digital lending, workforce software and digital banking, against a stated base of more than five hundred customers spanning financial technology, banking, lending, marketplaces, insurance and payroll. A published integration with an established engagement banking platform extends reach to banks and credit unions, and the company has placed on a national financial technology ranking.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

One published phrase raises the question and nothing answers it. Where primary sources are insufficient, the platform is described as layering in alternative sources and network signals automatically, and a network signal in this context means information derived from activity across the customer base. That is the same consortium shape several vendors in this index rely on, and it is genuinely useful for detecting coordinated fraud rings, which is exactly why the boundary matters. Nothing published states what a network signal is built from, whether contribution is a condition of use, or whether one institution's application flow informs decisions served to a competitor.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

The framing as business verification understates the personal data involved. Customer identification and due diligence work on a business requires identifying its beneficial owners, which means names, addresses and identifiers for private individuals, assembled alongside relationship graphs connecting people across entities.

Searched the platform, product and documentation material for a privacy statement covering that personal information, how long it is retained, what happens on termination and how an individual named in an ownership graph could learn of or correct it, and located none. Sole proprietors are explicitly in scope, and for a sole proprietor the business record and the person are the same record.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

Searched the company site, product pages, developer documentation and third party review material across two passes for an enumerated attestation, an information security standard, a penetration testing statement or a trust centre, and located none. An independent review of the platform published in 2026 discusses pricing opacity and international coverage as the principal constraints without citing a security credential either.

For a vendor holding beneficial ownership records and verification decisions on behalf of banks and credit unions, which are institutions contractually obliged to assess vendor security, the absence of any public position is the widest gap in this profile.

Regulatory Status and Licensure
BB on Regulatory Status and LicensureThe regulatory position is clearly stated and appropriate to the product, with part of the verification left to the buyer.
Vendor Published

No licence is required for the verification business and none is claimed, which is not penalised. What lifts this above the norm is that products are built against named regulatory programmes rather than compliance in the abstract, addressing customer identification, customer due diligence and enhanced due diligence as distinct workflows, screening against the federal sanctions list, matching taxpayer identifiers directly with the tax authority, and handling uniform commercial code filings.

The registration product goes further and performs actual filings with state and federal agencies on a client's behalf, which is a regulated activity conducted as agent rather than software sold to someone else to use.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

The fairness question for business verification is which businesses fail, and the company deserves credit for addressing part of it: it states that sole proprietors, new formations and businesses trading under assumed names are verified where legacy tools return nothing, and those are precisely the applicants most often rejected for absence of record rather than for risk. The unaddressed half is the detection side.

Shell company identification and relationship graphs that flag coordinated rings will also flag legitimate clusters, including family businesses at shared addresses, immigrant owned business networks and firms using shared registered agents. A false shell flag costs a real business a bank account or a loan, and no error rate by business type, size, geography or ownership is published.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

What this product decides is access. A business that fails verification does not open the account, does not receive the loan and frequently never learns which signal caused it, and the company markets autonomous resolution as the point of the platform. Nothing published states a service level, a warranty, a correction obligation or any allocation of responsibility between the vendor and the institution when a verification outcome is wrong. There is also no published route by which a wrongly flagged business reaches the vendor at all, since the commercial relationship runs to the institution and the affected party is its applicant.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

The architecture is described with more precision than most, naming an orchestration layer, specialised sub agents each trained for a particular task, and purpose built detection models, which tells a buyer how the system is arranged. It stops short of saying whose models perform the work.

No provider, model family or hosting arrangement is identified, nothing separates models developed in house from services called externally, and nothing states whether business records and ownership information leave the environment during agent investigation. Describing an agent architecture is not the same as disclosing what sits behind it.

Core Systems and Integration Depth
AA on Core Systems and Integration DepthNamed integrations with the systems of record, core banking, policy administration, custodial or contact center platforms, verifiable in marketplace listings or public API documentation.
Vendor Published

Depth runs in both directions and the specifics are published. Inbound, direct connections to the federal tax authority and all fifty state business registries sit alongside postal and sanctions sources and a stated four hundred data providers, which is primary source access rather than resold aggregation.

Outbound, the platform is interface first with documented integration paths, ships an integration with an established engagement banking platform serving banks and credit unions, and embeds business registration inside a client's own product rather than referring it elsewhere. The documentation surface is also unusually machine addressable, publishing an index for artificial intelligence agents and a markdown rendering of every page.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

Delivery is a cloud hosted interface with a web application alongside it, and the published material goes no further. Searched for hosting regions, a residency commitment, a single tenant option or any description of where verification records and ownership graphs are stored and processed, and located none.

Residency pressure is lower than for a global vendor since the data is United States sourced and the customer base is domestic, but the company states international coverage is coming, which will make the question live rather than academic.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No rates, tiers or unit of charge are published and every engagement begins with a sales conversation, a point third party reviewers make directly. The gap is compounded by a product surface that spans verification calls, ongoing monitoring, agent driven investigation and per filing registration services, four things that would naturally price on entirely different units. A buyer cannot tell whether cost scales with applications submitted, businesses monitored, agent investigations run or filings made, which are the four questions that decide the annual number.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Buyer breadth is real, running across financial technology firms, banks, credit unions, lenders, marketplaces, insurers and payroll providers at more than five hundred customers, and the banking platform integration reaches institutions of a size the company would not sell to directly. Geographic coverage is what holds this to a B rather than higher.

Verification is United States only, built on domestic registries and the federal tax authority, with international coverage described as forthcoming rather than available. An institution onboarding businesses outside the United States needs a second vendor today, and that is a structural limit rather than a gap in disclosure.

Alternatives to Middesk

The closest documented capability profiles to Middesk in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Stronger documented coverage on Institution and Segment Coverage

Documents Security Certifications and Trust Center where Middesk does not

Documents Model Supply Chain Disclosure where Middesk does not

Documents Model Supply Chain Disclosure where Middesk does not

Documents AI Safety and Data Stewardship where Middesk does not

Documents Deployment Model and Data Residency where Middesk does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746