Prism Layer
Prism Layer encodes an organisation's risk frameworks, regulatory context and institutional knowledge into what it calls a governed agentic execution layer, aimed at financial services, payments and fintech firms. Its distinguishing claim is that rather than storing risk records after decisions are made, it executes the structured reasoning behind risk analysis as those decisions happen, producing auditable and defensible output at business speed. Supported work covers risk assessments, key risk indicators, controls testing, risk and control self-assessments and product risk review.
The company emerged from stealth in April 2026 with a pre-seed round led by a venture firm focused on financial services and regulatory technology whose partners include former senior leaders of the US consumer financial regulator. Its three co-founders were all risk executives at the same payments company, with prior enterprise risk leadership across money transfer, brokerage, card network and consumer lending businesses, and direct experience with Irish, Australian and UK regulators.
Capability Axes
Capability grades
15 of 15 axes rated · 2 graded A or B
The company describes itself as AI native and the architecture claim is specific rather than decorative: a governed agentic execution layer that executes the structured reasoning behind risk analysis as decisions happen, rather than documenting risk after the fact. Risk frameworks, regulatory context and institutional knowledge are encoded into the system as the material the agents reason over. Remove the models and what remains is the register-and-spreadsheet approach the company exists to displace.
Governance is built into the description of the architecture rather than added alongside it, with the execution layer characterised as governed and the output as auditable and defensible, and the product supports the risk function's own work rather than replacing its judgement. Risk and control self-assessments, controls testing and product risk review are all activities that terminate in a human sign-off.
Held at B because no approval step, escalation path or review requirement is specified, and an agentic layer executing reasoning at business speed raises exactly the question of where the risk officer intervenes.
Auditability and defensibility are stated as design goals and no mechanism is described to deliver them. Nothing published covers logging, citation to source frameworks, versioning of encoded risk logic, validation of the reasoning the agents perform, or accuracy of the analysis produced. For a platform whose output is meant to survive examination, the absence of a described evidence trail is the substantive gap, and it is the one most worth closing next.
The company emerged from stealth in April 2026 and is onboarding its first enterprise customers, with one proof of concept slot remaining at announcement. No customer is named, no deployment exists publicly, and the pre-seed amount is undisclosed.
What is unusually strong is the team rather than the record: three co-founders who were risk executives at the same payments company, with fifteen years of enterprise risk programme building across money transfer, brokerage and remittance businesses, framework and technology work across four jurisdictions with three named regulators, and enterprise risk leadership at a card network and a consumer lender. Credentials are not evidence the product works, and this grade reflects the record rather than the team.
No boundary statement was located, and the exposure here is unusual in kind. What the platform encodes is precisely a firm's most proprietary internal material: its risk frameworks, its control environment, its institutional judgement about what matters and why. Across several customers that becomes a comparative view of how regulated firms actually manage risk, and nothing states whether that informs the product, is isolated per client, or is retained.
No data protection agreement, retention schedule or subprocessor list was located. The platform ingests an institution's risk frameworks and institutional knowledge rather than customer records, so direct personal data exposure is lower than most vendors here, and control testing and product risk review touch material about how the firm treats its customers.
No attestation, certification, trust centre or control documentation was located, which is expected at pre-seed stage and is nonetheless the practical barrier to the first regulated deployment, since a risk function is precisely the buyer that will run a full vendor assessment before granting access to its own control environment.
The regulatory depth sits in the people rather than the published product. Three supervisors are named through founder experience and the lead investor's partners include former senior leaders of the US consumer financial regulator, which is meaningful context, and no statute, rule or supervisory framework is mapped to a product capability. Encoding an organisation's regulatory context is claimed as a feature without naming which regimes are supported, and output is said to hold up under regulatory scrutiny without indicating whose.
No fairness testing, bias monitoring or governance disclosure was located. The platform assesses institutional risk rather than individuals, which narrows the exposure, and product risk review is the point where it touches consumer outcomes, since the judgement of whether a product creates harm is one where the framework encoded determines what gets flagged. Nothing addresses how those judgements are formed or reviewed.
No guarantee, indemnity or correction process was located. The exposure is institutional rather than individual: if agentic analysis misses a risk that later materialises, or produces an assessment that does not hold up in examination, nothing describes where responsibility sits between the vendor supplying the reasoning layer and the firm whose risk officers signed the output.
No base model, provider, hosting arrangement or subprocessor is identified for the agentic layer. A firm adopting this platform to strengthen its own risk oversight would be expected by supervisors to document the third-party model dependency it introduces in doing so, and that information is not available.
No integration, connector, interface or supported system is named. Risk assessment and controls testing draw on evidence held across an institution's control, incident, audit and business systems, so how the platform reaches that material determines whether it can execute reasoning at business speed as claimed, and none of it is described.
No hosting provider, region, residency commitment or private deployment option was located. Founder experience spans four jurisdictions with distinct data expectations, which makes residency a question the company will face early from any regulated buyer, and nothing is published.
No pricing, packaging or basis of charge was located, which is expected at this stage and remains a gap for a buyer. The funding amount is also undisclosed, so a risk function assessing vendor viability before entrusting its framework to an early company cannot judge runway.
The target market is stated as highly regulated industries including financial services, payments and fintech, which is coherent given the founders' backgrounds, and nothing beyond that statement evidences coverage. No institution type, size band, geography or segment is described as served, and with no live deployments there is no basis to assess where the platform actually fits.
Alternatives to Prism Layer
The closest documented capability profiles to Prism Layer in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents Regulatory Status and Licensure where Prism Layer does not
Documents Institution and Segment Coverage and Regulatory Status and Licensure where Prism Layer does not
Documents Regulatory Status and Licensure and Model Risk Management and Transparency where Prism Layer does not
Documents Operational and Outcome Evidence and Institution and Segment Coverage where Prism Layer does not
Documents Regulatory Status and Licensure and Core Systems and Integration Depth where Prism Layer does not
Documents Institution and Segment Coverage and Regulatory Status and Licensure, among others where Prism Layer does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.