AML, KYC & Financial Crime
P

Pegasystems

Pegasystems is a Cambridge, Massachusetts headquartered enterprise software company founded in 1983 and listed in the United States, selling a low code platform built on unified rules, process and case management with decisioning and workflow automation. Financial services is addressed through separately named prebuilt applications rather than an industry page.

Pega Client Lifecycle Management and Pega Know Your Customer orchestrate sales, onboarding, due diligence, credit, fulfilment and servicing end to end, handling institutional, advisor, fund and correspondent bank onboarding, with rules driven processes applying know your customer requirements by country, booking entity and product, and periodic reviews triggered automatically when screened third party information changes. Identity verification integrates facial recognition, video identification and biometrics, and the applications are positioned against eIDAS, anti money laundering, FATF, FATCA, common reporting standard and GDPR obligations.

The client lifecycle product integrates Moody's entity data and entity verification capability. Artificial intelligence has been embedded in the compliance line since 2018, when the company introduced product recommendation during onboarding while explicitly framing the difficulty that powerful models can make decisions which are not always explainable to regulators, and positioning control and transparency as the answer.

A December 2025 release added agentic features across onboarding, document processing, screening and risk assessment in multiple jurisdictions, with agents described as predictable and reliable and scoped to giving analysts context aware regulatory guidance rather than acting alone. Pega GenAI Blueprint generates a build ready workflow from a stated vision. ING is a named client for a global know your customer deployment, and the company reports onboarding seventy percent faster at sixty percent lower cost.

Last VerifiedAugust 20, 2026
Compare Pegasystems with other vendors
Founded
1983
Headquarters
Cambridge, Massachusetts, United States
Website
www.pega.com
Categories
aml-kyc-financial-crime, compliance-and-surveillance, lending-and-banking-operations
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 4 graded A or B

AI Capability
AI Centrality
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.
Vendor Published

A forty year old rules, process and case management platform with models layered onto it, and the vendor's own product page settles the question without argument: rules driven processes drive know your customer and due diligence by country, booking entity and product.

Strip every model and the case engine, the rules engine, the orchestration across front and back office, the omnichannel interfaces and the robotic automation all continue, because that is what the company sold for decades before generative capability existed.

Independent technical description of the architecture puts the platform in the role of workflow controller and decisioning engine invoking decision rules for classification, risk scoring and routing, with models and bots as executors beneath it. The agentic capability added in 2025 is real and specific, which is why this is a build at C rather than a rejection, and it is the newest layer on a deterministic spine.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

The scoping is deliberate and well stated, and the enforcement mechanism is not described. Agents in the 2025 compliance release are positioned as giving analysts instant, context aware regulatory guidance to support confident decision making, which places the model in an advisory role with the analyst deciding, and the company describes those agents as predictable and reliable rather than autonomous.

Audit trails, case history and accountability for changes are consistent themes, and the platform's case structure means every step is recorded by construction. The company has also stated since 2018 that banks must have control and transparency when using models in onboarding or face regulatory risk.

Held at B rather than A because control and transparency are asserted as properties without the mechanism being named: nothing states what constrains an agent at runtime, what confidence threshold routes a case to a person, or what the default review band is, which is precisely what lifted Appian to an A on this roster.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

No validation methodology, accuracy figure, error rate, versioning policy or drift monitoring is published for any capability, including the generative document processing and the screening models. One thing deserves recording because it is unusually candid and still does not carry the axis: in launching its first embedded models the company stated plainly that powerful technologies like artificial intelligence can make decisions that are not always explainable to regulators, naming the weakness of its own technology class in a product announcement.

Identifying the problem is not the same as publishing evidence that this implementation solves it, and the claim of complete control and transparency that follows is an assertion rather than a measurement.

Operational and Outcome Evidence
BB on Operational and Outcome EvidenceVendor aggregate claims with real figures, or audited scale disclosures from a publicly listed company.
Vendor Published

A named global bank and a quantified product claim that are never joined. ING is named for achieving a global know your customer solution on the client lifecycle platform, presented at the company's own conference. Separately the company reports onboarding seventy percent faster and costs sixty percent lower, but those figures are stated as product outcomes rather than attributed to ING or any other institution. Two named executives speak on the record, both the company's own.

Independent recognition is present but thinner than several peers on this roster, resting on an industry award for client lifecycle management rather than analyst quadrant placements. Held at B on the bar applied consistently across this roster: a customer is named, and no figure is attached to that name.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

Nothing states whether customer data trains the vendor's models. The question has real force here because the compliance applications process onboarding files, beneficial ownership structures, screening hits and biometric verification across many competing global banks, and because periodic review is driven by continuously screened third party information, so the platform holds both the institution's data and external data about its clients.

No exclusion from any training corpus, no separation commitment between institutions and no statement of controls around the generative components are published. Against the reference set of Mortgage Capital Trading, Needl and AlphaSense the silence is a choice.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

No privacy posture of the vendor's own is published. GDPR appears only as one of several regimes the application is positioned to help a bank satisfy, alongside eIDAS, anti money laundering rules, FATF, FATCA and the common reporting standard, which is a product capability claim rather than a commitment about how the supplier handles data.

Nothing addresses retention of the identity documents, video identification recordings and biometric templates the verification capability necessarily creates, purge on termination, or the treatment of screening results about individuals who are not the customer.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

No security certification is enumerated in the material reviewed. No SOC report of either type, no ISO 27001, no penetration testing statement and no trust portal was located. Queued check where the expected answer is strongly at odds with the grade, exactly as recorded for Appian: this company sells to global banks and to government, and processes identity documents, biometric templates and screening results, so attestations and government authorisation programmes are very likely to exist. Nothing was seen, so nothing is asserted in either direction.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

A software supplier with no financial services licence, authorisation or supervisory relationship of its own. Being listed on a United States exchange is corporate and securities regulation rather than financial services standing and does not read across under the standing bar. All regulatory language in the product material describes obligations the application helps an institution meet, which is a product claim. No registration, enrolment or supervised programme participation was found.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

No fairness testing, protected characteristic handling, model inventory or named governance framework is published. One adjacent engagement is worth recording because it is nearly unique on this roster: the company frames its embedded recommendation capability against regulations designed to prevent predatory sales practices, which require banks to ensure every product offer is suitable for the customer receiving it.

Suitability is the closest thing to a fairness obligation that appears anywhere in this quadrant, and the company engages with it as a compliance constraint the software helps manage rather than as a position about how its own models distribute offers.

The unaddressed exposure is concrete: facial recognition and biometric verification are deployed for account opening with no demographic performance breakdown and no false reject rate by cohort, the same gap recorded across the identity proofing tier.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

No recourse position is published. Nothing states who carries the consequence when biometric verification wrongly rejects an applicant, when screening produces a false match, when generative document processing misreads an onboarding file, or when an agent gives an analyst wrong regulatory guidance that is then acted on.

The last of these is a distinctive exposure created by the advisory design itself: when a model advises and a person decides, responsibility for a bad outcome is divided between the supplier that produced the guidance and the analyst who followed it, and nothing addresses that division. The individual wrongly matched or rejected has no relationship with the vendor at all.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

No model, family, version or provider is named for any capability, including the generative document processing, the screening models, the workflow generation tool and the compliance agents. One third party dependency is named and it is instructive that it is the wrong kind: Moody's is identified as the source of entity data and entity verification, which is a data supply chain disclosure rather than a model one.

The distinction matters and parallels one recorded against Opensee, where the cloud provider was named repeatedly and the model never was. Naming the data source is not naming the model, and vendors should not receive credit on this axis for the former.

Core Systems and Integration Depth
AA on Core Systems and Integration DepthNamed integrations with the systems of record, core banking, policy administration, custodial or contact center platforms, verifiable in marketplace listings or public API documentation.
Vendor Published

Integration is named and architectural rather than asserted. The client lifecycle product integrates Moody's entity data and entity verification capability, a specific third party dependency identified by name. Identity verification incorporates facial recognition, video identification and biometrics.

The platform orchestrates end to end from front office through back office on unified rules, process and case management, and reaches legacy systems through robotic automation where application programming interfaces are unavailable, which is the integration problem most acute in older banks. Omnichannel reach is enumerated across mobile application, live chat, web self service, co-browsing, telephone and in person. Screening of third party information is continuous enough to trigger client reviews automatically when data changes, which requires live connections rather than periodic extracts.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

No deployment or residency position was found in the material reviewed. Nothing located states which delivery models are supported, which regions are available, or where client data is processed and stored. The omission carries weight for this product line specifically, because due diligence is applied by booking entity and jurisdiction, which means the software is explicitly handling the question of which national rules apply to a client relationship while saying nothing about which national rules apply to the data about it. Queued rather than treated as settled, since an enterprise vendor of this scale commonly documents deployment options outside the pages reviewed here.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No pricing information was located in the material reviewed. No licence basis, no per case or per user metering, no tier structure and no indicative implementation cost for the compliance applications. Queued check with a specific warning attached, learned from Appian on this same roster: aggregator sources for enterprise low code pricing proved wildly unreliable there, returning five different answers across five sites including one stating no pricing was published at all. Any check on this vendor must go to its own material or a marketplace listing, and nothing found so far qualifies.

Institution and Segment Coverage
AA on Institution and Segment CoverageThe financial segments served are named and each carries its own maintained material, whether the coverage is broad or deliberately narrow.
Vendor Published

Deep across institution type and geography. The client lifecycle applications explicitly handle institutional, advisor, fund and correspondent bank onboarding as distinct shapes, which is a harder coverage claim than serving one segment well, and due diligence is applied differentially by country, booking entity and product across global jurisdictions.

The company operates across North America, Europe, Latin America and Asia Pacific and counts global banks among its client base, with ING named for a global deployment. Independent recognition includes a best client lifecycle management solution award at an industry banking technology programme.

The compliance line is positioned at the largest institutions, where the company cites external research that banks devote up to fifteen percent of full time staff to know your customer and anti money laundering work.

Alternatives to Pegasystems

The closest documented capability profiles to Pegasystems in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Stronger documented coverage on Operational and Outcome Evidence

Documents Deployment Model and Data Residency where Pegasystems does not

Documents AI Centrality where Pegasystems does not

Documents AI Centrality where Pegasystems does not

Documents AI Centrality where Pegasystems does not

Documents AI Centrality and Deployment Model and Data Residency where Pegasystems does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746