Lending & Banking Operations
S

SBS

SBS, formerly Sopra Banking Software, is a French banking and lending software group serving more than fifteen hundred financial institutions and large scale lenders across eighty countries with roughly two thousand eight hundred staff in fifty offices. It is part of 74Software alongside Axway and carries a banking heritage the company dates at more than fifty years.

The composable product estate spans core banking, digital engagement, payments, cards, deposits, open banking and regulatory reporting on the banking side, and core lending, asset finance, wholesale dealer floorplan financing, portfolio management, digital asset audit and asset finance pricing on the lending side, delivered as software as a service on Amazon Web Services in the European Union, through a managed service variant, or on premises under a maintenance contract.

Named institutions include Santander, Societe Generale, BNP Paribas, Groupe BPCE, Credit Agricole, La Banque Postale, HSBC, Attijariwafa Bank, Nationwide, KCB Bank, BGFI Bank Group, Kensington Mortgages, Bank11, NextGear Capital, Mercedes-Benz and Toyota Financial Services. The learned layer is presented as a shared data and artificial intelligence platform underneath every product rather than as a separate application.

Shipped capability includes machine learning financial crime management covering sanctions screening and anti money laundering checks, artificial intelligence supported risk assessment and scoring inside loan origination, and collection strategies with automated prioritisation inside the lending lifecycle. In July 2026 the company announced SBS AI Foundation, a generative layer built on its data platform delivering customer engagement intelligence for relationship managers and an assistant for service, compliance and operations staff, drawing on data held inside each institution's own environment; the company states availability is limited to selected clients with broader rollout planned for early 2027.

Analyst placements include a top eight global core banking technology provider ranking from Everest Group in 2026, strong performer in the Forrester Wave for digital banking engagement platforms in 2026, leader in the QKS SPARK Matrix for digital banking platforms, and leader positions with Omdia and in an Everest Group PEAK Matrix.

Last VerifiedAugust 20, 2026
Compare SBS with other vendors
Founded
Headquarters
Paris, France
Categories
lending-and-banking-operations, aml-kyc-financial-crime, customer-banking-agents
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 5 graded A or B

AI Capability
AI Centrality
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.
Vendor Published

The Clearwater precedent at the largest scale it has been applied on this roster, and the vendor's own launch language settles it in a single clause: artificial intelligence is being embedded directly into the core banking, lending and digital banking products its clients already run.

Strip every model and a fifty year old estate covering deposits, payments, cards, core banking, lending, asset finance, wholesale financing, open banking and regulatory reporting continues to operate fifteen hundred institutions, because it did exactly that for decades.

The learned line is nonetheless real and named rather than decorative, which is what separates a build from a rejection here: machine learning financial crime detection, artificial intelligence supported scoring and risk assessment inside origination, automated prioritisation in collections, and a generative layer announced in July 2026.

Autonomy and Oversight Model
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism, or full automation is presented as the entire disclosure. Human in the loop appears as a phrase rather than a described control.
Vendor Published

Outcome asserted, no control named, which is the floor position on this axis. The published claim is that institutions can act on generated insights with the confidence that regulators and auditors require, and that framing states a result rather than a mechanism.

The products themselves are advisory by design, giving relationship managers a view of what a customer is likely to need and giving staff answers from their own data, but design is not disclosure: nothing states a threshold, a confidence band, a review requirement, a default configuration, or what a person must approve before an action reaches a customer.

In lending the language is automated prioritisation in collections and automated data gathering, scoring and risk assessment in origination, with no screen out path or exception route described. Worth recording plainly because it cuts against expectations of scale: Pennant, roughly a fortieth of this company's size and on the same analyst roster, publishes configurable approval workflows and a record of who signs off, and takes B for it.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

Nothing. No accuracy figure, no validation methodology, no backtesting, no drift or versioning disclosure, no external assessment of any model, and no statement of how a bank would validate what it is deploying. The one performance number published anywhere is a reduction of financial crime false positives by up to eighty five percent, and the standing rule from the Azentio build applies here at more than twice the magnitude: suppressing alerts is trivial, suppressing only the wrong ones is the problem, and a false positive reduction figure published with no recall or false negative figure beside it is the one number in anti money laundering that cannot be read alone. No baseline, no institution, no methodology, no period, and the words up to make it a ceiling rather than a result.

Operational and Outcome Evidence
BB on Operational and Outcome EvidenceVendor aggregate claims with real figures, or audited scale disclosures from a publicly listed company.
Vendor Published

A very long list of named institutions and not one attributed result. The customer roster is published in the company's own boilerplate and includes several of the largest banks in Europe, and the analyst set is the densest on this roster: top eight global core banking technology provider from Everest Group in 2026, strong performer in the Forrester Wave for digital banking engagement platforms in 2026, leader in the QKS Group Spark Matrix for digital banking platforms, a top ten European fintech placement from IDC, and leader positions with Omdia and in an Everest Group Peak Matrix.

Individual customer announcements are named and dated, including an eight year partnership extension with a German auto finance bank and a digital banking programme with a central African banking group. Held at B on the line applied four times on this roster: named customers plus dense analyst recognition is B, and A requires a result attached to a name. The only quantified performance claim found anywhere is a reduction of financial crime false positives by up to eighty five percent, attached to no institution.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

The nearest thing to an answer in the published material is that the data the generative layer draws on remains governed and secured within each institution's own environment. Graded C because that sentence is genuinely ambiguous between an access control statement and a training exclusion, and an ambiguous claim earns nothing, a rule this index has applied where it costs a vendor a grade rather than only where it saves one.

Nothing states whether customer data trains or tunes any model, whether anything is pooled across the fifteen hundred institutions on a platform the company itself describes as a shared data and artificial intelligence platform, or what is excluded from a training corpus. That shared framing makes the unanswered question sharper here than for most, because competing banks sit on the same substrate.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

A personal data protection charter is published in the footer alongside a modern slavery statement, and the generative layer is described as operating on data that remains governed and secured inside the institution's environment. Neither is a product level data handling position: no retention schedule, no deletion terms, no subprocessor list, no statement of how customer records are separated between tenants on the shared data platform, and no privacy specific attestation.

The exposure is large in proportion to the estate, since the platform holds deposit, payment, card, loan and arrears records for institutions serving retail customers across eighty countries. Queued check, cheap: the personal data protection charter was not opened.

Security Certifications and Trust Center
BB on Security Certifications and Trust CenterA recognised certification named in the vendor’s own material without the artefact, or with a scope or renewal question the buyer has to raise.
Vendor Published

A genuinely uncommon artifact and a new shape for this index: not a badge row, but the contractual security annex itself, published openly. A documentation page carries three downloadable Security Management Plans, each scoped to a specific contract type, each version stamped and dated, most in both English and French, and none behind a gate or a form: one for software as a service on Amazon Web Services in the European Union built on the company's own security framework, one for managed service customers, and one covering maintenance and on premises deployment.

In most of this index that document is an annex a buyer receives only under a non disclosure agreement during procurement. Held at B and not A because no certification, attestation report, audit period or independent assessor is named on the page: against the reference bar set by ICE Mortgage Technology, with per product SOC 2 reports on a dated cadence and bridge letters covering the gaps between audit periods, there is no third party assurance identified here at all. Queued check, cheap and specific: the plans themselves were not opened and would be the natural place for the certification list.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

A software vendor with no licence, registration or supervised standing of its own, inside a listed international software group. Every regulatory reference in the material is about the buyer's position rather than the firm's: helping institutions meet regulatory requirements, supporting open banking and payment services regulation compliance, and delivering regulatory reporting as a product. Analyst placements and a corporate parent do not read across as regulatory standing.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

Nothing published, and this is the largest unaddressed exposure found on the roster. Artificial intelligence supported scoring and risk assessment runs inside loan origination for fifteen hundred institutions across eighty countries, a substantial number of them inside the European Union, where creditworthiness assessment of natural persons is expressly a high risk use under the European artificial intelligence regulation.

A French headquartered vendor selling credit scoring capability to French and other European banks publishes no fairness testing, no protected characteristic treatment, no disparate impact analysis, no governance framework, no named standard and no position on that regulation at all. The company does publish commentary about helping banks cut through hype with governance, which is category content about the buyer's problem rather than disclosure about its own systems.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

No recourse position published. The division is the standard one and the scale makes it unusually consequential: the software supports credit scoring at origination, prioritisation in collections and alert generation in financial crime screening, while the institution is the party a customer complains to and the only party a supervisor can sanction.

Nothing states whether a declined applicant or a screened customer is told a model was involved, how a wrong score or a wrong alert is contested, or how responsibility divides between the vendor supplying the models and the bank operating them. A false positive in sanctions screening freezes a real customer's payment, and nothing addresses that person at all.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

Not one model, provider, version or base model is named, on a company that announced a generative artificial intelligence layer across its entire product estate. The buying forces disclosure rule points hard the other way: a generative layer at this scale is licensed, and the company publishes a named cloud dependency for its software as a service platform while naming nothing at the model layer.

That is precisely the distinction recorded against Pega and Opensee on this roster and against Pennant in this session: naming the cloud is not naming the model. The shared data and artificial intelligence platform is described as the foundation for everything above it and its own composition is never disclosed.

Core Systems and Integration Depth
AA on Core Systems and Integration DepthNamed integrations with the systems of record, core banking, policy administration, custodial or contact center platforms, verifiable in marketplace listings or public API documentation.
Vendor Published

Graded A on the strongest available basis, the same one that earned Azentio its A: the vendor supplies the core itself. The estate includes the system of record for deposits, payments, cards, lending and regulatory reporting, so lending, asset finance and compliance attach natively rather than through connectors, and the composable architecture is sold as a set of components against that shared spine.

The point is made sharpest by the artificial intelligence layer, which the company describes as directly connected to data from the products the bank already runs rather than bolted on from the outside, which is a claim only a core provider can make. Open banking and PSD3 support supplies the outward integration surface. Deployment spans software as a service, a managed service and on premises, all three confirmed as distinct contract shapes in the company's own security documentation.

Deployment Model and Data Residency
BB on Deployment Model and Data ResidencyStated residency commitments or regional hosting options.
Vendor Published

Answered from the vendor's own contract documentation rather than from a review site, which matters because the review site version and the vendor version differed. Three deployment shapes exist as separately documented contract types: software as a service on Amazon Web Services scoped explicitly to the European Union, a managed service variant, and on premises under a maintenance contract.

That is a named cloud with a named jurisdiction, which is a real residency statement rather than an adjective. The generative layer is separately described as drawing on data that remains inside each institution's own environment.

Held at B and not A because the only jurisdiction named is the European Union while the customer base spans eighty countries, so nothing states where data sits for customers in Africa, the Middle East, Asia or the Americas, and no region list, replication policy or transfer mechanism is published. The sovereign framing used in the navigation is never defined anywhere.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No pricing of any kind published. Notable only because the same footer that hides every price publishes the security annex and links a contract documents library and a software as a service agreements page, so the reticence is specific to commercial terms rather than general.

Queued and cheap: the contract documents and SaaS agreement pages were not opened and are the one place a vendor of this type sometimes publishes commercial structure, service levels or credit regimes even when it publishes no rate.

Institution and Segment Coverage
AA on Institution and Segment CoverageThe financial segments served are named and each carries its own maintained material, whether the coverage is broad or deliberately narrow.
Vendor Published

The widest coverage on this roster and among the widest in the index. More than fifteen hundred financial institutions and large scale lenders across eighty countries, with named customers spanning several genuinely different buyer types: global systemically important banks (Santander, BNP Paribas, Societe Generale, Credit Agricole, Groupe BPCE, HSBC), a state owned postal bank, a British building society, African banking groups (KCB, Attijariwafa, BGFI), a specialist mortgage lender, and captive manufacturer finance arms in both automotive and equipment (Mercedes-Benz, Toyota Financial Services, NextGear Capital, Bank11).

Product coverage runs retail, corporate, asset finance and wholesale dealer floorplan financing. Coverage of this breadth across institution type, geography and lending product is what the A on this axis is reserved for.

Alternatives to SBS

The closest documented capability profiles to SBS in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Stronger documented coverage on Operational and Outcome Evidence

Documents Autonomy and Oversight Model where SBS does not

Documents Autonomy and Oversight Model where SBS does not

Documents Model Risk Management and Transparency where SBS does not

Documents Model Supply Chain Disclosure where SBS does not

Documents AI Governance and Bias Disclosure and Model Risk Management and Transparency where SBS does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746