Napier AI
Napier AI is a London regulatory technology company founded in 2015 and led by chief executive Greg Watson, selling anti money laundering and financial crime compliance software to banks, payments firms, insurers and wealth and asset managers. Its platform, Napier AI Continuum, spans client screening, transaction screening, transaction monitoring across more than 100 money laundering typologies, client activity review, perpetual client risk assessment and regulatory reporting.
It is offered in three configurations: Continuum Pro for enterprise deployment, Continuum Live as a managed plug and play service, and Continuum Flow, which routes alerts from the screening and monitoring engines into an institution's own existing case management interface rather than replacing it. The company describes its approach as AI enhanced rather than AI native, arguing that the right method blends the transparency of traditional rules with the pattern detection of machine learning.
Four AI capabilities sit across the platform: Advisory AI recommending whether an alert should be reviewed or discounted, Explainable AI giving human readable justifications naming the features that drove a recommendation, Investigative AI supporting natural language querying of risk data, and Insights AI adding behavioural analytics to transaction monitoring. A sandbox, which the company says it pioneered in this market, lets non technical compliance staff test configurations against real data and measure impact before committing to production.
Chief Data Scientist Dr Janet Bastiman chairs the Royal Statistical Society's Data Science and AI Section and sits on the Financial Conduct Authority's Synthetic Data Expert Group. The company reports more than 150 financial institutions as customers, took a 45 million pound investment from Crestline Investors in 2024, and publishes the Napier AI / AML Index with GlobalData.
Capability Axes
Capability grades
15 of 15 axes rated · 10 graded A or B
The company's own framing settles this and it is unusually honest. Napier describes itself consistently as AI enhanced rather than AI native, and states directly that the right approach blends the transparency and familiarity of traditional rules with the adaptability and pattern detection of machine learning.
Apply the removal test to that and a complete previous generation product remains: fuzzy matching screening against sanctions, politically exposed person and adverse media lists, rules based transaction monitoring, a sandbox, case management and regulatory reporting.
The machine learning sits on top, and the company has published that its models detected laundering typologies more effectively than conventional rules while demanding less compute, which is a claim about improvement over a working baseline rather than about a baseline that does not exist without them.
Four AI capabilities are named and real, covering alert triage recommendation, feature level explanation, natural language investigation and behavioural analytics, and a data science team continuously tunes the models. This is a rules platform made materially better by models, not a modelling company.
The most complete oversight construction located anywhere in this index, and it is built into the product rather than asserted around it. Four elements combine. The AI recommends rather than decides: Advisory AI proposes whether an alert should be reviewed or discounted based on match quality and available attributes, leaving the disposition to the analyst.
Explanation is at feature level: Explainable AI gives human readable justifications setting out why an alert triggered and which features contributed, so a reviewer can interrogate the reasoning rather than accept a score. Change is testable before it is live: the sandbox, which the company says it pioneered in this market and built for non technical business users, lets staff define and iterate rules and screening configurations against actual data and measure the impact before committing to production.
And the company states its governance position publicly through its named Chief Data Scientist, that accountability for compliance decisions sits with humans regardless of AI involvement. The product framing follows the same line, describing the purpose as putting power into the hands of analysts to make human in the loop decisions. What is absent is a published specification of default thresholds before configuration.
The sandbox is the substantive artifact and it addresses the exact thing a model risk function needs. The company states that analysts can fine tune screening and monitoring configurations based on results from actual data before committing changes to the live environment, and measure the impact of each change as it is introduced, which is validation and change control handed to the customer rather than performed opaquely by the vendor.
Supporting it, the company has published a comparative finding that its tested models detected laundering typologies more effectively than conventional rules based systems while requiring considerably less compute, models are stated to be continuously tuned by a named data science team, and feature level explanation makes individual outputs inspectable. Synthetic typology datasets let an institution benchmark its own detection independently.
What is absent is the documentary half: no validation report, accuracy figure, precision or recall measure, false positive rate or monitoring statement was located, and the comparative claim against rules is asserted without published figures.
The named customer set is geographically broad and includes institutions whose procurement is a reference in itself: Australia Post, Banco do Brasil, Al Rajhi Capital, Brighter Super, Column Bank, Financial House, FundsDLT, and Satchel, which embedded the platform inside its white labelled banking as a service offering.
One deployment carries technical detail rather than only a logo, with Australia Post running Continuum in Microsoft Azure integrating transaction monitoring, client screening and behavioural analytics. A named executive reference exists in Wendy Langridge, Chief Regulatory Officer at BCS Global Markets.
Scale is stated at more than 150 financial institutions, and external recognition includes an Aite Novarica impact award for AML innovation in 2022 and inclusion in CNBC's World's Top Fintech Companies 2026 in the regtech category. A 45 million pound investment from Crestline Investors in February 2024 is externally attested.
What holds this below the top grade is the absence of any quantified customer outcome: no false positive reduction, alert volume change or investigation time saving is published against any named institution, and the customer count itself moves between 100, 150 and 200 across sources without reconciliation.
This vendor does not run the shared data network that caps almost every other record in this index, and that absence is the point rather than an omission. Each institution's deployment operates on its own data, models are tuned for that customer, and the deployment options extend to private cloud, on premise and air gapped configurations in which the vendor holds nothing at all.
There is no cross customer consortium, no pooled fraud database and therefore none of the contribution, segregation and retention questions that go unanswered elsewhere. Two further practices support the position. The sandbox lets analysts test configuration changes against real data in a non production environment before committing them, so experimentation does not run against live customers.
And the company works with synthetic datasets containing money laundering typologies, developed through regulatory collaboration and made available for institutions to test their own monitoring, which is detection development on manufactured rather than real customer data. What remains unstated is what the managed service configuration retains and for how long.
Nothing was located across repeated retrieval. No data processing addendum, subprocessor list, retention schedule, named supervisory authority, transfer mechanism or named privacy regime appears on the vendor's own surface. That is a thin published position for a platform processing customer identity, transaction and behavioural data on behalf of institutions in the United Kingdom, Brazil, Saudi Arabia and Australia, each with its own data protection regime.
The deployment architecture partly mitigates the risk in practice rather than on paper, since an institution choosing on premise, private cloud or air gapped deployment keeps the data inside its own boundary and the vendor never holds it, and that architecture is credited on the deployment axis. It is not a substitute for published processing terms for the managed service customers who do hand data over.
Two dedicated passes located no security certification, attestation, trust centre, penetration test summary or enumerated control framework published under this vendor's name. No ISO 27001 certificate, service organisation control report or equivalent was found.
That is a conspicuous absence for a supplier whose customers include Banco do Brasil, Al Rajhi Capital and Australia Post, all of which impose supplier assurance requirements as a condition of contracting, so the assessments almost certainly exist and are handled in procurement rather than published.
One caveat on confidence: the second pass returned heavily contaminated results dominated by generic compliance automation vendors rather than this company, so this is recorded as not located rather than as established absence. Pre emptive negative finding: an inherited cloud provider certification will not move this grade, since the platform is also sold on premise and air gapped where no such inheritance applies. A certificate naming this company with its scope is what would.
This vendor sits inside the supervisory apparatus rather than merely selling against it, which is what the top grade on this axis requires. The company states it partners closely with the Financial Conduct Authority to ensure its product aligns with regulatory guidance and meets policy goals on reducing economic crime, and that relationship is evidenced rather than claimed: its Chief Data Scientist, Dr Janet Bastiman, sits on the Financial Conduct Authority's Synthetic Data Expert Group, and the company's published work names collaboration with that regulator, The Alan Turing Institute and the consultancy Plenitude.
The synthetic dataset containing money laundering typologies was produced through that regulatory collaboration and made available to financial institutions to test and optimise their own monitoring, which is a vendor contributing infrastructure to the supervised community rather than consuming guidance from it. The Napier AI / AML Index, produced with GlobalData, ranks the impact of AI on anti money laundering by market alongside country level regulation. The company holds no licence itself, which is correct for a technology supplier and not a deduction.
Explainability here is a shipped product capability rather than a claim, which is what lifts this above the lane. Explainable AI is described as producing human readable justifications that set out why an alert was triggered and what features contributed to the decision, so an analyst receives attribution rather than a number, and that output is auditable for the regulatory record.
Governance is stated publicly by a named and externally credentialled individual: the Chief Data Scientist chairs the Royal Statistical Society's Data Science and AI Section, sits on a regulator's expert group, and publishes on explainability, governance and responsible AI adoption in this domain, including the position that accountability for decisions remains with humans. Published research through the AI / AML Index adds a further public artifact. What is missing is measurement.
No error rate, false positive rate, precision measure or calibration statement is published, and the claim that the tools dramatically reduce both false positives and false negatives carries no figure, baseline or population. No fairness testing or disparate impact analysis exists, which matters because money laundering typologies correlate with geography, remittance corridors and customer nationality.
No guarantee, indemnity, accuracy service level or falsifiable commitment was located, and structurally the vendor does not make the decision: Advisory AI recommends, the institution's analyst disposes, and the institution files the suspicious activity report in its own name and carries the regulatory consequence. The company states that position explicitly through its Chief Data Scientist, that accountability sits with humans, which is honest and is credited on the autonomy axis.
For the individual the position needs stating carefully rather than criticised by reflex. A person flagged in anti money laundering monitoring receives no notification, no evidence and no appeal, but that is a legal requirement rather than a vendor choice, since tipping off a subject is a criminal offence in most jurisdictions this platform operates in.
What the vendor could publish and does not is what happens to a subject cleared after investigation: whether the alert history persists, whether it influences future risk scoring, and how long a discounted alert continues to affect that customer's assessment.
Several third parties are named and the one that matters most is not. Microsoft Azure is identified as the managed deployment environment, GlobalData as the research partner behind the published AI / AML Index, and the Financial Conduct Authority, The Alan Turing Institute and Plenitude as collaborators on synthetic data and typology work. What is entirely absent is the watchlist chain.
This platform screens clients and transactions in real time and batch against sanctions regimes, politically exposed person registers and adverse media, and the quality of every screening decision depends on whose lists those are, how often they update and how they are curated, yet no data provider is named anywhere. The company states only that its platform is trusted by the world's leading data providers, which describes a relationship without identifying a single one.
For a screening product that is the material omission. No subprocessor list exists and no model or foundation model provider is named for the generative component behind natural language investigation.
The integration model is unusually thoughtful about not being the system of record. Continuum Flow exists specifically for institutions that have already built or bought their own case management interface, routing alerts from the screening and monitoring engines into that existing workflow so the customer keeps its front end and its analysts keep their tools, while gaining the detection layer underneath.
That is a vendor designing around the buyer's existing estate rather than requiring replacement, and it is a materially different posture from platforms that demand the whole workflow. Alongside it, Continuum Pro serves full enterprise deployment and Continuum Live a managed service, the architecture is described as cloud native and application programming interface first, and the platform has been embedded inside a third party banking as a service product at Satchel, which is integration as white label distribution.
What is absent is an enumerated connector catalogue: no named core banking, payment processing or customer relationship platform integrations were located, and no public developer documentation was found.
The strongest deployment position located anywhere in this index, and the company markets it as such, calling it a world first in deployment choice. The platform can be taken as fully managed standalone software as a service in any Microsoft Azure data centre, which gives the customer region selection rather than a fixed location, or in any public cloud, or in any private cloud, or in an air gapped configuration, or fully on premise.
That range matters more for this product than for most, because anti money laundering data is customer identity and transaction history at regulated institutions, and several of the markets this vendor sells into impose localisation requirements or supervisory expectations that the data not leave the jurisdiction or the institution. An air gapped or on premise deployment means the vendor never holds the data at all, which answers the residency question by removing it.
A named reference deployment exists, with Australia Post running the platform in Azure. What would move this no higher is that no specific region list, sovereignty commitment or transfer mechanism is published for the managed service.
No rate, tier, band, entry point, free tier or trial was located across two dedicated passes, and no pricing page exists on the vendor's own surface. What is published is packaging rather than price: three named configurations, Continuum Pro for enterprise deployment, Continuum Live as a managed plug and play service and Continuum Flow for application programming interface integration into an existing stack, plus six separately named solution modules covering screening, monitoring, client activity review, risk assessment and regulatory reporting.
A buyer can therefore work out what shape of engagement they would be buying and which modules they need, without learning what any of it costs or what the metering unit is. The company markets lower total cost of ownership as a benefit without publishing any figure that would let a buyer test the claim.
Four regulated segments are addressed with their own material: banking, payments, wealth and asset management, and insurance, with banking as a service providers reached through the Satchel embedding. Geographic evidence is genuinely spread rather than concentrated, with named customers in Brazil, Saudi Arabia, Australia, the United States and the United Kingdom, and the company reports more than 150 institutions worldwide.
Coverage within the compliance function is complete rather than partial, running from client screening and onboarding risk assessment through transaction screening and monitoring to client activity review and regulatory reporting, so an institution can buy the whole financial crime workflow or one module. The three deployment configurations extend reach down market, since Continuum Live gives a smaller firm a managed service where Continuum Pro serves a tier one enterprise.
What holds this below the top grade is that the buyer is always a regulated financial institution's compliance function, and no evidence of reach into merchants, marketplaces or non financial sectors was located.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Protection Terms | Implementation | Source |
|---|---|---|---|---|
|
Not published. No rate, tier, entry point, free tier or trial was located on the vendor's own surface or from any third party. Three named configurations and six named modules are published without prices.
|
Undisclosed. Neither a rate nor a metering unit is published, so it is not possible to tell whether the platform is licensed per module, per screened client, per monitored transaction, per seat or as an enterprise subscription. The packaging suggests a modular licence, since six solutions are sold separately and a customer can take one or all of them, layered over a configuration choice between enterprise deployment, managed service and application programming interface integration. Deployment choice will itself move the price materially, because a fully managed service in an Azure data centre and an air gapped on premise installation carry very different cost structures for the vendor. The company sells against incumbent enterprise platforms on total cost of ownership, which implies a commercial position below those competitors, but no figure is published by the vendor or available from any third party to test that. | No data processing addendum, subprocessor list, retention schedule or named privacy regime was located. The deployment architecture changes the shape of this question rather than answering it: an institution taking the platform on premise, in its own private cloud or air gapped holds all the data itself and the vendor is never a processor, so no addendum is needed. For managed service customers taking Continuum Live or software as a service in an Azure data centre, processing terms would be required and none is published. On assurance, two dedicated passes located no certification, attestation or trust centre under this vendor's name, though the second pass returned heavily contaminated results so this is recorded as not located rather than established absence. | Not published and not disclaimed. Implementation cost will vary more than for most vendors in this index because the three configurations differ fundamentally in effort: Continuum Live is presented as plug and play, Continuum Flow integrates the detection engines into a customer's existing case management interface, and Continuum Pro plus the on premise and air gapped options involve standing up the platform inside the institution's own infrastructure, which is a project rather than an integration. The company states it works closely with customers to deliver the right deployment outcome, which is professional services in substance, and no rate, engagement minimum or inclusion boundary is stated. Configuration is designed to be customer performed, with the sandbox built explicitly for non technical business users to define and test rules without vendor involvement. | Vendor Published |
Two dedicated passes returned no rate, tier, band, entry point, free tier or trial, and no pricing page exists on the vendor's own surface. What the company does publish is the shape of the engagement, which is more useful here than usual because the shape drives the cost: three configurations covering enterprise deployment, managed service and application programming interface integration, and six separately purchasable modules spanning client screening, transaction screening, transaction monitoring, client activity review, perpetual client risk assessment and regulatory reporting.
A buyer can therefore determine what they would be buying without learning what it costs. The company markets lower total cost of ownership as a benefit and publishes no figure against which that claim could be tested. Pre emptive negative finding: because the platform is sold on premise and air gapped as well as as a service, any single quoted figure would describe one deployment model only, and a rate surfacing from a directory should not be treated as comparable across the three configurations.