Fraud Detection & Transaction Risk
O

Oz Forensics

Oz Forensics builds facial biometric liveness detection and face matching software sold to banks, fintechs, identity verification vendors, telecommunications operators, gaming operators and government agencies across more than twenty countries. Headquartered in Dubai and founded in 2017 by chief executive Artem Gerasimov, it was acquired in September 2024 by Unico, a Brazilian digital identity company, and continues to ship under its own name with its own products.

The two core products are Oz Liveness, which establishes that a real living person is present and defends against presentation attacks, injection attacks, deepfakes and three dimensional masks, and Oz Biometry, which matches two faces to confirm they belong to the same person. An optical character recognition capability for identity documents sits alongside them. Liveness can run actively or passively, on the device or on a server, in two or three dimensions, and across a single frame or multiple frames of video.

The company sells both as a hosted service and as an on premises licence, so an institution can keep biometric processing entirely inside its own environment. External validation is unusually deep for the category, spanning presentation attack detection testing at levels one and two by one accredited laboratory, separate presentation and injection attack assessments by a second, a level three presentation attack evaluation, and benchmarking of the face matching model in the United States national face recognition evaluation programme.

In March 2026 the company launched a public trust centre carrying its certifications, security and privacy documentation, client information and a list of its subprocessors. Named deployments include Eurasian Bank, which reported onboarding one million clients using the biometrics, and Sberbank Kazakhstan.

Last VerifiedAugust 19, 2026
Compare Oz Forensics with other vendors
Founded
2017
Headquarters
Dubai, United Arab Emirates
Website
ozforensics.com
Categories
fraud-and-transaction-risk, aml-kyc-financial-crime, customer-banking-agents
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 11 graded A or B

AI Capability
AI Centrality
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.
Vendor Published

There is no product here other than the models. Liveness detection, face matching, deepfake resistance, injection attack detection and document character recognition are the entire offering, sold as software development kits and licences to organisations that embed them. The company does not sell a workflow, a case manager, a screening database or a compliance platform, so nothing survives the removal test. This is the purest form of the pattern in this lane, and it is why other identity verification vendors appear on the customer list rather than only banks.

Autonomy and Oversight Model
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism, or full automation is presented as the entire disclosure. Human in the loop appears as a phrase rather than a described control.
Vendor Published

Liveness detection produces a binary determination and nothing published describes what surrounds it. There is no documented confidence threshold an institution can set, no described escalation route when a check fails, no manual review or adjudication surface, and no guidance on how many attempts a person is permitted before a permanent decision attaches.

Configurability exists in the form of active or passive modes and single or multiple frame capture, but those are capture settings rather than oversight controls. The gap matters more for a component vendor than it might appear, because the institution consuming the signal inherits an outcome it did not produce and has no published basis for deciding when to override it.

Model Risk Management and Transparency
BB on Model Risk Management and TransparencyReal transparency mechanisms are published, such as per alert explainability, confidence scoring or split testing, without the validation package or supervisory mapping behind them.
Vendor Published

This is the strongest showing on the axis in the index and it is held at the middle grade deliberately, because the evidence for the deciding property is ambiguous rather than present. External measurement is emphatic: two accredited laboratories, presentation attack detection at levels one, two and three, separate injection attack assessment, and submission of the face matching model to a national evaluation programme, with figures published for each.

What would lift this to the top grade is a mechanism by which the institution conducts its own validation. The trust centre does offer controlled access to documentation on request, which is closer than any peer has come, but the material located describes that documentation as security, privacy and policy material rather than model documentation, and an ambiguous claim is not credited.

Nothing describes drift monitoring, a validation summary, or a stated position on supporting a customer's model risk review under supervisory guidance. The published accuracy figures are also headline single numbers rather than error rates presented in both directions across conditions.

Operational and Outcome Evidence
AA on Operational and Outcome EvidenceNamed customers with hard performance figures and enough method to test them.
Vendor Published

Both routes are satisfied. A named institution reports a quantified outcome at scale: Eurasian Bank onboarded one million clients using the biometrics. A second named bank deployment carries a quoted managing director for retail business development describing a procedure completed in under five seconds without requiring a mobile application install.

Independent parties with something at stake have assessed the technology repeatedly rather than once, across two accredited biometric testing laboratories and a national face recognition evaluation programme. The company also won a major interbank messaging network's innovation challenge in 2017. Deployment breadth is stated across more than twenty countries covering banks, fintechs, identity verification vendors, telecommunications and government bodies.

AI Safety and Data Stewardship
AA on AI Safety and Data StewardshipThe cross client data boundary is answered specifically and falsifiably: commitments like zero training on customer data or per customer model instances.
Vendor Published

Both halves are answered, which is rare on this axis. Safety validation is the deepest located anywhere in the index: presentation attack detection testing at levels one and two by one accredited laboratory, separate presentation and injection attack detection assessments by a second accredited laboratory, and a level three presentation attack evaluation, which is a tier beyond what any peer in this lane holds.

Injection attack detection matters specifically because it addresses the newer threat where a manipulated stream is fed directly into the pipeline rather than shown to a camera. On stewardship, the on premises licensing option is a structural answer rather than an assurance, because an institution can run liveness and matching entirely inside its own environment so that biometric data never reaches the vendor at all, and on device processing narrows the exposure further even in the hosted model. The subprocessor list covers the remainder. No pooled dataset, shared negative list or cross customer fraud consortium was located, which distinguishes this vendor from two others in the same tier.

Regulatory and Compliance
GLBA and Data Privacy Posture
BB on GLBA and Data Privacy PostureA substantive privacy document that reaches the product itself, short of the subprocessor list or the full data handling detail.
Vendor Published

Better evidenced than most of the lane and grounded in architecture rather than assertion. The trust centre sets out privacy and data protection practices and names subprocessors, data protection regulation compliance is stated, and the on premises option means an institution can process facial biometrics without transferring them to the vendor at all, which answers the central privacy question for this product category structurally.

Short of the top grade because no privacy management system certification is held, no retention or deletion terms are published for facial images, liveness video or biometric templates in the hosted path, nothing addresses United States state biometric privacy law where several states impose separate consent and destruction duties with a private right of action, and no service provider position under United States financial privacy law is stated.

Security Certifications and Trust Center
AA on Security Certifications and Trust CenterCertifications named with their type and presented as retrievable artefacts, usually through a trust portal a buyer can open without asking.
Vendor Published

The first genuine trust centre encountered in this lane, launched in March 2026, and it is what the axis was written to reward. It carries the certifications and standards evaluations, the security measures and policies, the privacy and data protection practices, client information, staff training detail, controlled access to further documentation on request, and, most notably, a list of the subprocessors the company works with.

A published subprocessor list is the single item recorded as missing against every other vendor assessed in this sweep, including much larger ones. Information security management certification is held to the current 2022 edition and was achieved in December, not to a superseded edition, and a service organisation control report and data protection compliance are also stated. The remaining gap is that certificate numbers and audit periods are not published in the material located, so verification still depends on requesting documents rather than reading them.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

Oz holds no financial licence and no financial regulator has assessed the product, which is unsurprising for a biometric component supplier. The credentials it does hold are technical conformity assessments against biometric testing standards rather than regulatory authorisations, and they should not be read across as regulatory standing.

Government bodies are claimed among the customer base across more than twenty countries, which would ordinarily imply passage through public procurement vetting, but no specific agency, authorisation or programme is named, so this rests on an unattributed claim rather than a citable admission. Product material is written against fraud and biometric attack rather than directly against customer identification or anti money laundering obligations, which sit with the platforms that embed it.

AI Governance and Bias Disclosure
BB on AI Governance and Bias DisclosureAn independent demographic evaluation the vendor has submitted to, such as the NIST face evaluation class, or a governance framework with named process behind it.
Vendor Published

Submission of the face matching model to the national face recognition evaluation programme is the most meaningful fairness related step available in this field, because that programme measures demographic differentials by design and publishes results the vendor does not control.

Unlike a competitor in this same tier whose claim about that programme is ambiguous as to whose algorithms were tested, this one is unambiguous and independently corroborated by trade press reporting that the company's own face biometrics were benchmarked there. That places Oz ahead of most of the index.

It stops short of the top grade for the same reason as Incode: the company surfaces a single headline accuracy figure rather than the demographic breakdown its own submission generates, publishes no bias testing methodology of its own, and offers no analysis of how performance varies across the emerging markets that form the core of its footprint, where capture devices and lighting conditions differ sharply from evaluation conditions.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

Nothing published reaches the person being checked, and the failure mode here is unusually invisible. A liveness rejection typically presents to the individual as a failed attempt with a prompt to try again rather than as a decision, so a person repeatedly refused by a model may never learn that a model was involved or that a determination was made about them.

The component position lengthens the chain further, because the signal passes from this vendor to an identity verification platform to the institution before it reaches the individual, and no allocation of responsibility across those parties is published. There is no accuracy guarantee, no remediation commitment, no appeal route and no stated right to have a failed capture reviewed by a person.

Integration and Deployment
Model Supply Chain Disclosure
AA on Model Supply Chain DisclosureEvery party between the customer’s data and the output is enumerated by name, canonically through a public subprocessor list naming the model providers.
Vendor Published

The strongest position on this axis found anywhere in the index, and it closes the exact gap recorded against the closest peer. Oz builds the models it sells rather than assembling components, which makes it the supplier rather than an intermediary and gives an institution a single accountable party.

That claim is independently corroborated because the models themselves have been submitted to three separate external evaluators, so the technology being tested is demonstrably the company's own. Critically, and uniquely in this sweep, the trust centre publishes the subprocessors the company is partnered with, which means a buyer can actually trace the chain beneath the vendor instead of being told it is short. What is still absent is a model or version identifier that an institution could record against an individual decision in order to reconstruct later which build produced it.

Core Systems and Integration Depth
BB on Core Systems and Integration DepthNamed systems or a documented public API, with the depth or the production evidence left open.
Vendor Published

Integration is the product's whole delivery mechanism and the options are broad: web and mobile software development kits with front end customisation, on device and server side execution modes, hosted service and on premises licence, and configurable liveness modes covering active or passive checks and single or multiple frame capture.

The clearest evidence of integration depth is commercial rather than documentary, in that other identity verification vendors embed this technology inside their own platforms, which is a harder integration test than a direct customer deployment. A European distribution partnership extends reach.

It falls short of the top grade because nothing published describes named integration into core banking, account opening or origination platforms, and no partner directory, public status page or changelog was located.

Deployment Model and Data Residency
BB on Deployment Model and Data ResidencyStated residency commitments or regional hosting options.
Vendor Published

The delivery choice is the widest in this lane and it is genuinely residency relevant rather than an assurance. The software is available as a hosted service or as an on premises licence, liveness can execute on the end user device or on a server, and the company states this flexibility exists specifically to meet differing regulatory requirements for personal data processing.

An on premises licence is the strongest possible residency answer because the biometric data need never leave the institution's own infrastructure. The trust centre's subprocessor list further tells a buyer who is involved in the hosted path.

It is held below the top grade because, for the hosted service, specific hosting regions and in country residency options are not enumerated in the material located, and no data transfer mechanism is described for customers outside the vendor's home jurisdiction.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No rates, tiers, volume bands, minimum commitments or trial terms were located. The company operates both a subscription model for its hosted service and a licensing model for on premises deployment, and while naming those two structures tells a buyer something about how a deal would be shaped, neither carries a published figure or unit. For a product normally priced per check or per licensed instance, neither the unit nor the band is disclosed, so a buyer cannot size a deployment without entering a sales process.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Reach is wide and deliberately weighted toward emerging markets, spanning more than twenty countries with deployments described across banks, fintechs, identity verification and know your customer vendors, telecommunications operators, gaming and government bodies, with stated depth across the Commonwealth of Independent States, Africa, Asia, Latin America and a launch in Indonesia. Named financial institutions are regional banks rather than global groups.

It sits below the top grade for a structural reason rather than a gap in effort: this is a component supplier whose route to many institutions runs through other identity verification vendors, so segment coverage is partly inherited from customers rather than held directly, and no deployment at a large multinational bank was located.

Head to Head

Compared With

Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.

Alternatives to Oz Forensics

The closest documented capability profiles to Oz Forensics in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Stronger documented coverage on Institution and Segment Coverage

Documents Autonomy and Oversight Model where Oz Forensics does not

Documents Autonomy and Oversight Model and Regulatory Status and Licensure where Oz Forensics does not

Documents Regulatory Status and Licensure where Oz Forensics does not

Stronger documented coverage on Model Risk Management and Transparency

Documents Autonomy and Oversight Model and AI Liability and Recourse where Oz Forensics does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746