Fraud Detection & Transaction Risk
O

OneSpan

OneSpan is a Chicago based, publicly listed security vendor built on the authentication business formerly known as Vasco, serving more than 10,000 customers including over half of the hundred largest global banks. The portfolio spans hardware and software authenticators, mobile application shielding, a mobile security developer toolkit, identity verification, electronic signature and digital agreement workflows. The inference layer is a named and separately purchasable product line.

Risk Analytics scores transactions in real time using machine learning and data modelling over device integrity, application signals, user behaviour, malware indicators, transaction detail, beneficiary payment history and server side analytics, then drives workflows that act immediately according to policies and rules the bank defines, with automated alerts routed into a single case management interface for analyst review.

Intelligent Adaptive Authentication couples that risk engine to multi factor authentication so that higher risk activity automatically triggers a stronger challenge rather than a uniform one, shipped with preconfigured rule sets and predictive models tuned separately for mobile, online and corporate banking. The company positions both against named regulatory regimes, including European strong customer authentication rules and a central bank mandate in the United Arab Emirates, and publishes a customer engagement modernising authentication for an Italian bank under the revised European payments directive.

Last VerifiedAugust 20, 2026
Compare OneSpan with other vendors
Founded
1991
Headquarters
Chicago, Illinois, United States
Website
www.onespan.com
Categories
fraud-and-transaction-risk, payments-intelligence
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 4 graded A or B

AI Capability
AI Centrality
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.
Vendor Published

The established platform shape, and one of the clearest examples of it in the index. This is a business founded in 1991 on hardware authentication tokens, and strip the models out today and the authenticators, the multi factor stack, the application shielding, the developer toolkit, the identity checks and the electronic signature product all remain intact and are most of what the company sells. The inference layer is genuine and separately purchasable rather than decorative, which is why this is a build rather than a reject, but it sits on top of a portfolio that predates it by decades.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

The mechanism is described in a shape this index credits: the model produces a score, rules the institution defines decide what happens, and the resulting action is proportionate rather than binary, since higher risk raises the authentication requirement instead of blocking outright. Alerts route to a fraud analyst through a single case management interface, so a person remains in the loop on the flagged population.

Held off A because no threshold, default policy or floor is published, the action space is described as customer defined with nothing stating what the vendor will not allow, and step up friction applied to a legitimate customer has no described appeal.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

Predictive models tuned per channel, with no documentation, no accuracy or detection figures, no validation approach and no drift policy, for models that decide in real time whether a payment proceeds. The claim to watch is the familiar one in this pocket, fewer false positives with no baseline and no rate, which invites the standing question this index applies to every fraud vendor: what happened to the true positives. A model tuned to reduce analyst workload and a model tuned to catch fraud are not the same model, and nothing published distinguishes them.

Operational and Outcome Evidence
BB on Operational and Outcome EvidenceVendor aggregate claims with real figures, or audited scale disclosures from a publicly listed company.
Vendor Published

A named customer engagement with a described scope, an Italian bank whose authentication was modernised for the revised European payments directive, plus a large and specific installed base claim from a listed company. Held at B because no outcome is attached to the named customer and the quantified claims about the inference product are directional, and worth recording as a source discipline point: the strongest quote in the launch material comes from an industry analyst rather than from a bank, and an analyst endorsing a category is not evidence about a product.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

Nothing published on whether signals collected from one institution's customers inform models serving another. The question has force because the value of behavioural and device risk modelling rises with cross institutional exposure, so the commercial incentive to pool is strong, and a vendor sitting inside the mobile applications of half the largest banks in the world is in an unusually powerful position to do it. Silence here is not neutral.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

No published posture located. The exposure is unusually personal for a fraud product: the risk engine consumes device integrity signals, behavioural biometrics and transaction and beneficiary history on identified banking customers, which is continuous behavioural profiling of individuals, and nothing states how long those signals are retained, who may access them or what constrains their reuse.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

Held at C because no certification or trust portal was located in this pass, and an unverified credential earns nothing. Recorded plainly: this is the highest probability research miss on the record rather than a likely genuine absence, since a listed security vendor selling authentication to half the largest banks in the world will hold attestations and very likely hardware and cryptographic certifications specific to authenticator devices. The banked check is a dedicated certifications or compliance page, and device level scheme certifications alongside the usual organisational ones.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

Unlicensed and unsupervised as a firm. The product is built against named regulatory requirements, including European strong customer authentication and a central bank mandate in the Gulf with a stated compliance deadline, and the company publishes regulatory commentary from a named executive. All of that is product positioning and subject matter expertise rather than standing, and the party answerable to the supervisor remains the bank.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

No fairness testing or governance disclosure. The exposure is real and under discussed for this product category: adaptive authentication decides who is asked for additional proof, so model output translates directly into unequal friction between customers, and behavioural biometrics profile how a specific person holds and uses a device. Systematically higher challenge rates for particular groups would be invisible to the customer and unmeasured in anything published.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

No recourse route and no allocation of responsibility. A customer wrongly scored as high risk experiences repeated challenges or a blocked payment with no explanation, no visibility of the score and no route to contest it, and the bank rather than the vendor carries the relationship and the regulatory exposure.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

Machine learning and data modelling described generically, with no model, provider, architecture or version named. Consistent with the pattern that vendors building their own detection models disclose least, since nothing external forces the disclosure that a licensing relationship would.

Core Systems and Integration Depth
BB on Core Systems and Integration DepthNamed systems or a documented public API, with the depth or the production evidence left open.
Vendor Published

Positioned as an open platform that works alongside a bank's existing controls rather than replacing them, with a mobile developer toolkit, application shielding embedded into the bank's own app, and the risk engine consuming signals from the online and mobile channels it protects. Held off A because no named core banking, payments or case management system is identified, so integration is described by the surfaces it touches rather than by named counterparties.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

The adaptive authentication product is described as a cloud service, and the wider portfolio has historically been available in both hosted and customer run forms, but nothing published in this pass states region, residency, tenancy or the choice between them. That is a live question for a vendor whose customers include banks in Europe and the Gulf operating under different data localisation expectations.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No price, tier or unit published for the risk or authentication products. Banked check that could partly move this: the electronic signature line has historically been sold with published subscription tiers, and if those remain public then at least one product in the portfolio is priced openly even though the inference products are not.

Institution and Segment Coverage
AA on Institution and Segment CoverageThe financial segments served are named and each carries its own maintained material, whether the coverage is broad or deliberately narrow.
Vendor Published

More than 10,000 customers with over half of the hundred largest global banks among them, spanning retail, mobile and corporate banking channels plus insurers and public sector buyers. Segment coverage runs from digital onboarding and identity checks through authentication and transaction fraud to electronic signature and agreement workflow. Geographic reach is genuinely global and is evidenced by product work against separate regulatory regimes in Europe and the Middle East rather than by a claim of worldwide presence.

Alternatives to OneSpan

The closest documented capability profiles to OneSpan in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Documents AI Centrality where OneSpan does not

Documents AI Centrality and Regulatory Status and Licensure where OneSpan does not

Documents GLBA and Data Privacy Posture and AI Safety and Data Stewardship, among others where OneSpan does not

Documents AI Centrality and Model Risk Management and Transparency where OneSpan does not

Documents AI Centrality and AI Governance and Bias Disclosure, among others where OneSpan does not

Documents AI Centrality and Regulatory Status and Licensure, among others where OneSpan does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746