Compliance, Surveillance & RegTech
R

Ruleguard

Ruleguard is a governance, risk and compliance platform built only for regulated financial services, and it now presents itself as an agentic one. Intelligent agents, described as digital team members trained on regulatory knowledge and the firm's own policies, read documents, apply rules, check for gaps, flag risks and produce audit ready evidence continuously rather than at quarterly snapshots.

Roughly twenty modules sit on a shared evidence and task layer, spanning client asset compliance, compliance monitoring, audit management, incident and breach management, operational resilience, operational risk, policy and document management, regulatory change and service organisation assurance, alongside accountability regimes, conflicts of interest, employee attestations, gifts and hospitality and personal account dealing, and a conduct set covering appointed representatives, client file reviews, complaints, Consumer Duty, financial promotions, product governance and supplier oversight.

The company publishes four claims about how it governs its own artificial intelligence: ISO 27001 certification independently verified and ISO 42001 compliance audited by the British Standards Institution, permanent recording of every agent decision, data source and output, configurable oversight checkpoints where the customer sets the level of autonomy, and a choice between frontier cloud models and an on premises deployment. Data hosting is offered across the United States, United Kingdom, European Union and Asia Pacific.

Ruleguard was founded in 2013 in the United Kingdom by John O'Dwyer as a software development consultancy, built its first platform in 2015 for the incoming client assets rules, and raised 3.5 million pounds from Foresight Group in 2022. It states that its customers include tier one banks, global insurers and leading wealth managers.

Last VerifiedAugust 19, 2026
Compare Ruleguard with other vendors
Founded
2013
Headquarters
United Kingdom
Categories
compliance-and-surveillance, insurance-ai
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 10 graded A or B

AI Capability
AI Centrality
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a rules or workflow system.
Vendor Published

A working platform sits underneath and the agents are layered on top, which is the standard B shape rather than the agent native one. The company was founded in 2013, built its first product in 2015 for the incoming client assets rules, and spent a decade assembling roughly twenty compliance modules on a shared evidence layer before the agentic positioning arrived.

Strip the models and all of that remains: registers, attestations, breach management, monitoring plans, policy libraries and task lists. The vendor states the relationship plainly in its own words, arguing that regulators are not asking for artificial intelligence but for evidence, transparency and accountability, which frames the models as a means to an established end.

Held at B rather than C because the agentic layer is presented as the platform's current identity with its own product surface and does the reading and reasoning across every module, not as one feature in a corner.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

Among the better positions in this competitor set and held off an A on a specific distinction worth keeping. The vendor publishes that oversight checkpoints are configurable and that the customer sets the level of autonomy, and pairs it with permanent recording of every agent decision, its data source and its output, plus immutable audit trails and the stated principle that the compliance team stays in control.

Making autonomy an explicit customer set parameter rather than a vendor default is genuinely better than the category norm. What is missing is the substance behind the claim: no checkpoint is described, no threshold or confidence measure is published, and no sampling audit of automated decisions is mentioned. The reference grade on this axis names the modes, states what constrains each, and describes how automated decisions are sampled. Asserting that gates are configurable is not the same as describing the gates.

Model Risk Management and Transparency
BB on Model Risk Management and TransparencyReal transparency mechanisms are published, such as per alert explainability, confidence scoring or split testing, without the validation package or supervisory mapping behind them.
Vendor Published

No accuracy, precision or recall figure was located, which would normally settle this at C, and two disclosures lift it. Every agent decision is recorded permanently together with the data source it drew on and the output it produced, which makes any determination reconstructable after the fact rather than merely explicable at the time.

And an externally audited artificial intelligence management system is the mechanism through which model performance evaluation, risk assessment and lifecycle control are supposed to be documented, which is closer to what a supervisor examining model risk actually asks for than a headline accuracy percentage would be.

What remains missing is the number itself, and with it the failure mode that recurs across this whole category: the obligation an agent never flagged produces no decision record, because there is no decision.

Operational and Outcome Evidence
CC on Operational and Outcome EvidenceUnnamed case studies, customer logos, or claims without numbers. Prestige is not measurement: the calibre of the client list describes the buyer rather than the product, and coverage statistics are not adoption statistics.
Vendor Published

Thirteen years of operating history and institutional backing, and not one customer named anywhere. The claim is that tier one banks, global insurers and leading wealth managers use the platform, which if evidenced would be among the stronger positions in this competitor set, but no institution is identified, no customer count is given, no case study was located and no analyst evaluation was found.

A 3.5 million pound investment from a named growth investor in 2022 is a diligence signal about the company rather than a measurement of the product. No quantified outcome of any kind appears: no review time saved, no error reduction, no efficiency figure. This is the C bar met exactly, and it is the sharpest contrast in the vendor's profile, since it discloses more than any peer about how its technology is governed and less than most about whether it works.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

No boundary statement was located on whether one firm's policies, evidence or agent interactions inform models, retrieval or outputs serving another, and the agents are explicitly described as trained on the firm's own policies, which is exactly the material a competitor would not want shared. One genuine control is recorded rather than credited: an on premises deployment option exists, and a customer that takes it keeps the question from arising at all.

That is a real answer for the firms that choose it and silence for everyone on the cloud path, which will be most of them. The accompanying framing about the customer's data and the customer's rules is a slogan attached to a deployment choice rather than a stated position on tenant separation or model training.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

No privacy statement, lawful basis, retention rule or handling commitment was located, and an information security certification is not one, since it covers how data is protected rather than what may be collected, why, and for how long. The scope reaches personal data on two distinct populations. Employee modules hold attestations, personal account dealing records, gifts and hospitality declarations and conflicts disclosures on named staff, which is career relevant material.

Client file review and complaints modules hold records about the firm's own customers, including the substance of grievances. Multi region hosting is a positive fact recorded under deployment and is not a privacy position either.

Security Certifications and Trust Center
BB on Security Certifications and Trust CenterA recognised certification named in the vendor’s own material without the artefact, or with a scope or renewal question the buyer has to raise.
Vendor Published

A named, current and independently verified certification, ISO 27001, which is the enumeration that separates a real credential from the assertion of compliance without specifics recorded against several vendors in this index. It is supported by described infrastructure, with data centres named across four regions rather than a generic cloud claim.

Held at B rather than A because no trust centre serving live artefacts was located, no service organisation control report or equivalent second attestation was found, and no penetration testing cadence or audit period is stated, so a buyer can confirm that a certification exists without seeing its scope statement or its currency.

Regulatory Status and Licensure
BB on Regulatory Status and LicensureThe regulatory position is clearly stated and appropriate to the product, with part of the verification left to the buyer.
Vendor Published

Correct technology supplier posture with the most granular regime mapping in this competitor set, and an origin story that demonstrates it. The company built its first platform in 2015 specifically for incoming client asset rules, and the module list now enumerates named British obligations one by one, covering client assets, the senior managers and certification regime, Consumer Duty, appointed representative oversight, product governance and operational resilience.

That is a vendor organised around the rulebook rather than around a technology. Graded at B on the standing bar because no formal admission process, regulator run programme or supervised test of the product was located, and no supervisor has examined the agents themselves.

AI Governance and Bias Disclosure
BB on AI Governance and Bias DisclosureAn independent demographic evaluation the vendor has submitted to, such as the NIST face evaluation class, or a governance framework with named process behind it.
Vendor Published

The second strongest position on this axis in the index and the reasoning behind the grade should not be re litigated later. The vendor states that its ISO 42001 compliance is audited by the British Standards Institution, which is the artificial intelligence management system standard assessed by the body holding the first national accreditation to certify against it, and pairs that with permanent recording of every agent decision and data source.

That is a real external governance credential where peers have none. It is a B and not an A because the vendor's own wording draws the distinction: information security is described as certification, independently verified, while the artificial intelligence standard is described as compliance being audited, and no certification announcement was located. A firm holding certification says certification. The reference A on this axis was set on an independently audited certification. No fairness position or bias testing is published separately.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

No accuracy warranty, service commitment or remedy was located, and the consequence structure is unusually direct because of what the product output is for. The agents generate audit ready evidence that a firm presents to its supervisor, so an incomplete or incorrect evidence pack does not merely inconvenience the compliance team, it becomes the record on which an examination turns, and the finding lands on the regulated firm.

A second population sits inside the platform without a contract: employees whose attestations, personal trading and hospitality declarations are assessed, and customers whose complaints and file reviews are processed, neither of whom has a described route to contest a determination made about them.

Integration and Deployment
Model Supply Chain Disclosure
BB on Model Supply Chain DisclosureSubstantial partial disclosure, or a chain that is structurally short: an explicit in house build, on premise deployment, per customer instances, or zero retention at the model layer.
Vendor Published

The vendor discloses the class of model and the deployment choice around it, stating that the platform runs on frontier cloud models or on premises. That is materially more than the near universal silence in this category, because it tells a buyer that third party foundation models are in use rather than proprietary ones, and that an alternative exists for a firm whose risk appetite or jurisdiction rules that out.

Combined with an externally audited artificial intelligence management system, a procurement team has something to work with. Held off an A because no provider, base model or version is named, so a firm cannot document which specific model its compliance controls depend on, and a platform built on frontier models inherits whatever changes beneath it when a provider revises one.

Core Systems and Integration Depth
BB on Core Systems and Integration DepthNamed systems or a documented public API, with the depth or the production evidence left open.
Vendor Published

The distinguishing fact is architectural rather than a connector list: roughly twenty modules run on one shared evidence and task layer, so a breach recorded in one place, an attestation gathered in another and a monitoring finding in a third resolve against the same record, which is the integration most firms are trying to buy when they consolidate point solutions.

An on premises deployment path adds real estate depth, since running inside a bank's own environment is a harder engineering commitment than a hosted tenancy. Held at B because no named integration to a core banking platform, human resources system, customer relationship system or document repository was located, and no public application programming interface documentation or connector catalogue was found, which is the outward facing layer an A requires.

Deployment Model and Data Residency
AA on Deployment Model and Data ResidencyOn premise or hybrid deployment is offered and documented, alongside where data rests.
Vendor Published

The most complete answer to this axis found anywhere in this sweep, and it clears the specific deficiency recorded against peers graded B. Hosting is offered across four named regions covering the United States, United Kingdom, European Union and Asia Pacific, which is region choice rather than a single stated location. An on premises deployment path exists for firms that cannot accept a hosted model at all.

And the choice extends to where the intelligence runs, with the vendor offering either frontier cloud models or an on premises alternative, which is the layer most vendors leave entirely unaddressed. A buyer with a data localisation obligation can therefore determine from public material that a compliant configuration exists. The remaining gaps are real and worth noting: no tenancy model is described and no subprocessor list is published.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No rate card, tier ladder or billing basis was located, and the closest thing to a pricing signal is a promise of compliance without spiralling costs, which is a claim about the direction of a number rather than the number. The gap is more consequential for a modular platform than for a single product, because roughly twenty modules can be bought in many combinations and public material gives no indication whether pricing runs per module, per user, per entity or per regulated permission. A firm trying to compare this against a point solution for one obligation cannot construct the comparison from anything published.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Functional breadth is the strongest part of the claim and it is genuine: roughly twenty modules covering prudential, conduct, employee and third party obligations on one evidence layer, which is a wider surface than any pure point solution in this competitor set. Infrastructure breadth supports it, with hosting offered across four regions spanning the United States, United Kingdom, European Union and Asia Pacific, which implies customers in each. Held at B rather than A on two grounds.

The encoded regimes are overwhelmingly British, built around client assets rules, the senior managers regime, Consumer Duty and appointed representatives, so the depth is national even where the hosting is not. And the buyer claim, tier one banks and global insurers, is unanchored by a single named institution or a customer count, and unanchored breadth does not earn an A.

Head to Head

Compared With

Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.

Alternatives to Ruleguard

The closest documented capability profiles to Ruleguard in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Stronger documented coverage on AI Centrality and Autonomy and Oversight Model

Stronger documented coverage on AI Centrality and Regulatory Status and Licensure

Documents GLBA and Data Privacy Posture where Ruleguard does not

Documents Operational and Outcome Evidence where Ruleguard does not

Documents GLBA and Data Privacy Posture where Ruleguard does not

Documents Operational and Outcome Evidence where Ruleguard does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746