MyComplianceOffice
MyComplianceOffice, which trades as MCO, sells compliance management software to regulated financial services firms. Thirty or more products run on a single platform and a single data set, organised into four suites. Know Your Employee covers personal trading and crypto trading compliance, gifts, entertainment and hospitality, political contributions, outside business activities, connected persons and relationships, licensing and registrations, attestations, and communications archive and review. Know Your Transactions covers trade surveillance, deal review and the management of insider and material non public information.
Know Your Third Party covers vendor lifecycle management, screening and risk assessment. Know Your Obligations covers regulatory change, policy governance, compliance risk and compliance assurance. The company dates to 2005, began as a technology development division inside Fidelity Investments and became a standalone business in 2008 under founder and chief executive Brian Fahey. It acquired Schwab Compliance Technologies from Charles Schwab in 2022, roughly doubling its client base, and reports more than 1,500 client companies across 125 or more countries with over one million users, served from offices in North America, Europe, Asia Pacific and the Gulf.
Models sit inside two workflows rather than underneath the platform: noise detection that prioritises which employee communications reach a supervisor, and summarisation of executed trade alerts to shorten investigation. Both shipped as enhancements to a rules driven engine of configurable lexicons, syntax and preclearance thresholds. Chartis named the company a category leader in its communications monitoring quadrant.
Capability Axes
Capability grades
15 of 15 axes rated · 6 graded A or B
The removal test settles this cleanly and it places the vendor with Clearwater Analytics, Dynamo Software and LeapXpert rather than with the agent native compliance vendors. Take the models out and thirty products remain fully working: trade surveillance running on configurable rules for preclearance, hold periods, excessive trading, large trades, spoofing and layering; communications review running on configurable syntax and lexicons; personal trading registers, gifts and hospitality logs, attestation workflows, third party screening and an obligations library.
That platform sold for roughly eighteen years before either model feature shipped, which is the plainest possible demonstration that nothing sellable depends on them. Built rather than rejected on the established line for legacy platforms: the model line is genuine and it sits inside a regulated operation rather than around it, since noise detection determines which employee communications a supervisor ever sees. Distinguish from the vendor rejected on this floor for putting models around a deterministic ledger, where no model ever touches the regulated transaction.
Autonomy is low by construction and the oversight model is published, which is more than most vendors offer. Review by exception is named as an operating model, communications are evaluated and prioritised for supervisory review with escalation and recorded evidence of disposition, preclearance sits in front of employee trades, and both model features are scoped to prioritisation and summarisation with the human decision preserved.
What holds it off an A is the direction the automation runs. Noise detection removes items from a supervisor's queue, so the machine decides what a human never sees, and no threshold, sampling audit, recall figure or override path is published for that suppression. The reference point for an A on this axis publishes what is automated, what constrains it and a random audit of the automated decisions. Suppression without a sampling control is the weaker half of that pattern.
No accuracy figure, recall rate, false negative rate, validation method or model documentation was located for either model feature. The Hadrius standard applies with more force here than it did there, because noise detection is not a tuning improvement but an explicit suppression mechanism, and the regulatory failure mode in supervision is the message that was never reviewed rather than the alert that wasted an hour.
A vendor that advertises less noise is advertising a threshold move, and a threshold move trades against detection. A second and separate point worth reusing for any summarisation feature in a supervised workflow: the generated summary of a trade alert becomes the artefact the reviewer acts on and may become part of the record an examiner later reads, so a summarisation error is not a convenience defect but a compliance record defect, and nothing published describes how the summary is validated against the underlying alert.
The strongest evidence surface seen in this competitor set. More than 1,500 client companies across 125 or more countries and over one million users, built over twenty years, with a stated 95 percent client retention rate. Chartis named the company a category leader in its communications monitoring quadrant, with a research principal quoted by name on the specific capability that earned it, which is an independent product evaluation rather than a scale claim.
The heaviest single signal is structural: Charles Schwab sold its compliance technology subsidiary and roughly 700 corporate clients into this platform in 2022, which is a party with money and reputation at stake choosing where its own clients would land. A published customer story library carries quantified outcomes, including a legacy communications system replaced in three weeks at an asset management holding company.
What keeps this honest rather than perfect is that the customer stories describe firms by type and geography rather than by name, so the quantified outcomes and the named logos sit in different documents.
The product page for communications review offers firms the ability to benchmark their own surveillance against other firms, which is an explicit cross client comparison feature and therefore an explicit statement that data crosses the tenant boundary in some aggregated form.
Nothing published describes what is pooled, at what level of aggregation, whether participation is optional, or whether lexicon and noise detection models improve from one client's reviewed outcomes and then serve a competitor. The exposure is concrete because 1,500 firms on one platform include asset managers, broker dealers and proprietary trading firms that compete directly, and the material in scope is their employees' communications and personal trading.
Same shape as the pooling questions left open by Feathery and Clearwater Analytics, with the aggravating detail that here the pooling is advertised as a feature rather than merely implied by the architecture.
Two problems, and the second is the one to carry forward. First, no lawful basis statement, employee notice framework or retention schedule was located for what is among the most sensitive employee data sets in finance: personal brokerage account holdings and transactions, personal messaging captured on personal devices across services such as WhatsApp and text, gifts and hospitality, political contributions, outside business activities, and connected persons and relationships.
That last category is data about the employee's family and associates, who have no relationship with the employer or with the vendor and cannot decline, which is the same consent structure problem recorded against behavioural biometrics elsewhere in this index.
Second, the published privacy credential cites participation in the European Union to United States Privacy Shield framework, which the Court of Justice of the European Union invalidated in 2020 and which was superseded in 2023, so a buyer reading the current material is reading a lapsed reference. Held at C rather than D because the employer is the controller with its own notice duties and the vendor does publish a security and privacy posture.
Certifications are named rather than asserted, which is the distinction that separates this from vendors claiming compliance without enumerating anything: a service organisation control type two report and ISO 27001, with encryption of data in transit and at rest, and a published page covering implementation, security and procurement written for buyer diligence.
That is above the category norm, where most vendors in this index sit at C. Held at B rather than A because no trust centre serving live artefacts was located, no penetration testing cadence or audit period is stated, and the adjacent privacy credential in the same published material points at a framework that lapsed in 2020, which raises a maintenance question about the certification set as a whole rather than about any single item in it.
The posture is the correct one for a technology supplier and it is stated with unusual specificity. Published material maps modules to named obligations rather than to generic compliance: the broker dealer rule on employee accounts held away, the investment adviser code of ethics rule, the adviser marketing rule, the European market abuse regulation and the second markets in financial instruments directive, and the Markets in Crypto Assets Regulation for digital asset firms.
Examination readiness is addressed directly through point in time reporting and evidence packages built for United States, United Kingdom and European supervisors. Graded at B rather than A on the standing bar, because no formal admission process, regulator run innovation programme or supervised live test of the model features was located. An A on this axis requires a supervisor to have examined the product itself, not the regimes it maps to.
No governance framework, fairness position, testing programme or independent assessment was located. Graded against product scope using the adaptation set for employee surveillance rather than the consumer lending frame: the subjects are employees, so the exposure is that lexicon classifiers and noise detection flag informal writers, second language speakers and people who use idiom or humour, and a flag lands in a supervisory record that can affect employment and registration status.
The multilingual dimension is sharper here than for any peer. The platform operates across 125 or more countries where most monitored communication is not in English, the company shipped configurable language settings for notifications in 2026, and no per language detection accuracy is published anywhere. Recorded against the ladder set by Corlytics in this same competitor set, where an independently audited artificial intelligence management system certification earns an A.
No accuracy warranty, service commitment or remedy was located. The consequence structure has an unusual feature worth recording, because the person who bears the risk of a model error is not the customer. If noise detection suppresses a message that should have been reviewed, the supervisory failure lands on the regulated firm and never on the vendor.
If a classifier flags an employee wrongly, the entry sits in that employee's supervisory record and can follow them through registration and employment, and no correction, appeal or notification path is published for the subject of the flag, who is not a party to the contract and generally does not know the threshold that caught them. A third group sits further out still: the connected persons whose relationships are recorded because an employee disclosed them, who have no relationship with either party.
No provider, base model, hosting arrangement or build against buy statement was located for either the noise detection or the trade alert summarisation. For this vendor the omission is a data flow question and not only a provenance one, because the material passing through a summarisation step is employee communications and trading activity captured from personal devices, and a buyer cannot tell from public material whether that content reaches a third party model endpoint, under what terms, or in which jurisdiction.
Contrast the peer in this same competitor set held at B, where granted patents in three jurisdictions publish a specification of the core method even though its generative layer is equally unattributed. Here neither layer is described.
Genuine depth on the capture side. Communications monitoring spans email, collaboration platforms such as Slack and Teams, consumer messaging including WhatsApp and text, voice and proprietary channels, including personal devices, supported by a named partnership for retaining Apple iMessage traffic.
Trade surveillance validates against external market data rather than firm records alone, and employee account monitoring rests on brokerage data feeds, a capability materially strengthened by absorbing Charles Schwab's compliance technology business. The single data set across thirty products is the real architectural claim: an alert can surface next to the same employee's personal trading, gifts, outside business activities and connected persons records in one investigation workspace.
Held at B because no connector catalogue or public application programming interface documentation was located this pass, and no named integration to an order or execution management system or a core banking platform was found, which is the layer an A on this axis requires.
Delivered as cloud software with follow the sun support from offices in North America, Europe, Asia Pacific and the Gulf, and with delegated administration allowing regional configuration of a global standard. None of that is a residency disclosure. Offices are where staff sit, and delegated administration is an access control, not a statement about where data is processed or stored. No hosting jurisdiction, region choice, tenancy model or subprocessor list was located.
The gap is most consequential exactly where this vendor is strongest, since serving 125 or more countries means European institutions under data protection and operational resilience obligations and Gulf institutions under data localisation rules are buying without a published answer. Compare the Italian peer in this same competitor set, which earned a B for the single act of naming Ireland as its hosting location.
No rate card, tier ladder or billing basis was located and the route to a number is a demo request. The company describes its software as affordable in its own positioning, which is a claim about price without a price. Worth recording as a category observation rather than a criticism of this vendor: every regulatory and conduct compliance vendor screened in this sweep sits at C here, from a pre Series A Italian platform to this one at 1,500 clients, so opacity in this category is not a function of size or maturity.
A modular platform of thirty products makes the gap more consequential than usual, because a buyer cannot tell from public material whether the price scales by module, by employee, by monitored channel or by transaction volume, and those four bases produce very different totals for the same firm.
Both dimensions the axis asks about are met without strain. Buyer breadth spans asset and investment managers, broker dealers, investment banks, capital markets and proprietary trading firms, banks, insurance and bancassurance groups, private equity, regulated crypto and digital asset firms, and the law firms and consulting firms that advise them, each addressed through separately maintained segment material.
Geographic breadth is 125 or more countries with delivery from offices in North America, Europe, Asia Pacific and the Gulf, and regulatory mapping covers United States, United Kingdom and European Union regimes alongside Asia Pacific jurisdictions. Delegated administration lets a global firm hold one standard while configuring regionally, which is the operational form breadth has to take to be real. Compare the Italian peer in this same competitor set held at B for a deep single country position.
Alternatives to MyComplianceOffice
The closest documented capability profiles to MyComplianceOffice in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents AI Centrality where MyComplianceOffice does not
A lighter documented profile than MyComplianceOffice
Stronger documented coverage on Core Systems and Integration Depth
Documents AI Centrality where MyComplianceOffice does not
Documents AI Centrality where MyComplianceOffice does not
Documents AI Centrality and Deployment Model and Data Residency where MyComplianceOffice does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.