OneSpan
OneSpan is a Chicago based, publicly listed security vendor built on the authentication business formerly known as Vasco, serving more than 10,000 customers including over half of the hundred largest global banks. The portfolio spans hardware and software authenticators, mobile application shielding, a mobile security developer toolkit, identity verification, electronic signature and digital agreement workflows. The inference layer is a named and separately purchasable product line.
Risk Analytics scores transactions in real time using machine learning and data modelling over device integrity, application signals, user behaviour, malware indicators, transaction detail, beneficiary payment history and server side analytics, then drives workflows that act immediately according to policies and rules the bank defines, with automated alerts routed into a single case management interface for analyst review.
Intelligent Adaptive Authentication couples that risk engine to multi factor authentication so that higher risk activity automatically triggers a stronger challenge rather than a uniform one, shipped with preconfigured rule sets and predictive models tuned separately for mobile, online and corporate banking. The company positions both against named regulatory regimes, including European strong customer authentication rules and a central bank mandate in the United Arab Emirates, and publishes a customer engagement modernising authentication for an Italian bank under the revised European payments directive.
Capability Axes
Capability grades
15 of 15 axes rated · 4 graded A or B
The established platform shape, and one of the clearest examples of it in the index. This is a business founded in 1991 on hardware authentication tokens, and strip the models out today and the authenticators, the multi factor stack, the application shielding, the developer toolkit, the identity checks and the electronic signature product all remain intact and are most of what the company sells. The inference layer is genuine and separately purchasable rather than decorative, which is why this is a build rather than a reject, but it sits on top of a portfolio that predates it by decades.
The mechanism is described in a shape this index credits: the model produces a score, rules the institution defines decide what happens, and the resulting action is proportionate rather than binary, since higher risk raises the authentication requirement instead of blocking outright. Alerts route to a fraud analyst through a single case management interface, so a person remains in the loop on the flagged population.
Held off A because no threshold, default policy or floor is published, the action space is described as customer defined with nothing stating what the vendor will not allow, and step up friction applied to a legitimate customer has no described appeal.
Predictive models tuned per channel, with no documentation, no accuracy or detection figures, no validation approach and no drift policy, for models that decide in real time whether a payment proceeds. The claim to watch is the familiar one in this pocket, fewer false positives with no baseline and no rate, which invites the standing question this index applies to every fraud vendor: what happened to the true positives. A model tuned to reduce analyst workload and a model tuned to catch fraud are not the same model, and nothing published distinguishes them.
A named customer engagement with a described scope, an Italian bank whose authentication was modernised for the revised European payments directive, plus a large and specific installed base claim from a listed company. Held at B because no outcome is attached to the named customer and the quantified claims about the inference product are directional, and worth recording as a source discipline point: the strongest quote in the launch material comes from an industry analyst rather than from a bank, and an analyst endorsing a category is not evidence about a product.
Nothing published on whether signals collected from one institution's customers inform models serving another. The question has force because the value of behavioural and device risk modelling rises with cross institutional exposure, so the commercial incentive to pool is strong, and a vendor sitting inside the mobile applications of half the largest banks in the world is in an unusually powerful position to do it. Silence here is not neutral.
No published posture located. The exposure is unusually personal for a fraud product: the risk engine consumes device integrity signals, behavioural biometrics and transaction and beneficiary history on identified banking customers, which is continuous behavioural profiling of individuals, and nothing states how long those signals are retained, who may access them or what constrains their reuse.
Held at C because no certification or trust portal was located in this pass, and an unverified credential earns nothing. Recorded plainly: this is the highest probability research miss on the record rather than a likely genuine absence, since a listed security vendor selling authentication to half the largest banks in the world will hold attestations and very likely hardware and cryptographic certifications specific to authenticator devices. The banked check is a dedicated certifications or compliance page, and device level scheme certifications alongside the usual organisational ones.
Unlicensed and unsupervised as a firm. The product is built against named regulatory requirements, including European strong customer authentication and a central bank mandate in the Gulf with a stated compliance deadline, and the company publishes regulatory commentary from a named executive. All of that is product positioning and subject matter expertise rather than standing, and the party answerable to the supervisor remains the bank.
No fairness testing or governance disclosure. The exposure is real and under discussed for this product category: adaptive authentication decides who is asked for additional proof, so model output translates directly into unequal friction between customers, and behavioural biometrics profile how a specific person holds and uses a device. Systematically higher challenge rates for particular groups would be invisible to the customer and unmeasured in anything published.
No recourse route and no allocation of responsibility. A customer wrongly scored as high risk experiences repeated challenges or a blocked payment with no explanation, no visibility of the score and no route to contest it, and the bank rather than the vendor carries the relationship and the regulatory exposure.
Machine learning and data modelling described generically, with no model, provider, architecture or version named. Consistent with the pattern that vendors building their own detection models disclose least, since nothing external forces the disclosure that a licensing relationship would.
Positioned as an open platform that works alongside a bank's existing controls rather than replacing them, with a mobile developer toolkit, application shielding embedded into the bank's own app, and the risk engine consuming signals from the online and mobile channels it protects. Held off A because no named core banking, payments or case management system is identified, so integration is described by the surfaces it touches rather than by named counterparties.
The adaptive authentication product is described as a cloud service, and the wider portfolio has historically been available in both hosted and customer run forms, but nothing published in this pass states region, residency, tenancy or the choice between them. That is a live question for a vendor whose customers include banks in Europe and the Gulf operating under different data localisation expectations.
No price, tier or unit published for the risk or authentication products. Banked check that could partly move this: the electronic signature line has historically been sold with published subscription tiers, and if those remain public then at least one product in the portfolio is priced openly even though the inference products are not.
More than 10,000 customers with over half of the hundred largest global banks among them, spanning retail, mobile and corporate banking channels plus insurers and public sector buyers. Segment coverage runs from digital onboarding and identity checks through authentication and transaction fraud to electronic signature and agreement workflow. Geographic reach is genuinely global and is evidenced by product work against separate regulatory regimes in Europe and the Middle East rather than by a claim of worldwide presence.
Alternatives to OneSpan
The closest documented capability profiles to OneSpan in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents AI Centrality where OneSpan does not
Documents AI Centrality and Regulatory Status and Licensure where OneSpan does not
Documents GLBA and Data Privacy Posture and AI Safety and Data Stewardship, among others where OneSpan does not
Documents AI Centrality and Model Risk Management and Transparency where OneSpan does not
Documents AI Centrality and AI Governance and Bias Disclosure, among others where OneSpan does not
Documents AI Centrality and Regulatory Status and Licensure, among others where OneSpan does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.