SBS
SBS, formerly Sopra Banking Software, is a French banking and lending software group serving more than fifteen hundred financial institutions and large scale lenders across eighty countries with roughly two thousand eight hundred staff in fifty offices. It is part of 74Software alongside Axway and carries a banking heritage the company dates at more than fifty years.
The composable product estate spans core banking, digital engagement, payments, cards, deposits, open banking and regulatory reporting on the banking side, and core lending, asset finance, wholesale dealer floorplan financing, portfolio management, digital asset audit and asset finance pricing on the lending side, delivered as software as a service on Amazon Web Services in the European Union, through a managed service variant, or on premises under a maintenance contract.
Named institutions include Santander, Societe Generale, BNP Paribas, Groupe BPCE, Credit Agricole, La Banque Postale, HSBC, Attijariwafa Bank, Nationwide, KCB Bank, BGFI Bank Group, Kensington Mortgages, Bank11, NextGear Capital, Mercedes-Benz and Toyota Financial Services. The learned layer is presented as a shared data and artificial intelligence platform underneath every product rather than as a separate application.
Shipped capability includes machine learning financial crime management covering sanctions screening and anti money laundering checks, artificial intelligence supported risk assessment and scoring inside loan origination, and collection strategies with automated prioritisation inside the lending lifecycle. In July 2026 the company announced SBS AI Foundation, a generative layer built on its data platform delivering customer engagement intelligence for relationship managers and an assistant for service, compliance and operations staff, drawing on data held inside each institution's own environment; the company states availability is limited to selected clients with broader rollout planned for early 2027.
Analyst placements include a top eight global core banking technology provider ranking from Everest Group in 2026, strong performer in the Forrester Wave for digital banking engagement platforms in 2026, leader in the QKS SPARK Matrix for digital banking platforms, and leader positions with Omdia and in an Everest Group PEAK Matrix.
Capability Axes
Capability grades
15 of 15 axes rated · 5 graded A or B
The Clearwater precedent at the largest scale it has been applied on this roster, and the vendor's own launch language settles it in a single clause: artificial intelligence is being embedded directly into the core banking, lending and digital banking products its clients already run.
Strip every model and a fifty year old estate covering deposits, payments, cards, core banking, lending, asset finance, wholesale financing, open banking and regulatory reporting continues to operate fifteen hundred institutions, because it did exactly that for decades.
The learned line is nonetheless real and named rather than decorative, which is what separates a build from a rejection here: machine learning financial crime detection, artificial intelligence supported scoring and risk assessment inside origination, automated prioritisation in collections, and a generative layer announced in July 2026.
Outcome asserted, no control named, which is the floor position on this axis. The published claim is that institutions can act on generated insights with the confidence that regulators and auditors require, and that framing states a result rather than a mechanism.
The products themselves are advisory by design, giving relationship managers a view of what a customer is likely to need and giving staff answers from their own data, but design is not disclosure: nothing states a threshold, a confidence band, a review requirement, a default configuration, or what a person must approve before an action reaches a customer.
In lending the language is automated prioritisation in collections and automated data gathering, scoring and risk assessment in origination, with no screen out path or exception route described. Worth recording plainly because it cuts against expectations of scale: Pennant, roughly a fortieth of this company's size and on the same analyst roster, publishes configurable approval workflows and a record of who signs off, and takes B for it.
Nothing. No accuracy figure, no validation methodology, no backtesting, no drift or versioning disclosure, no external assessment of any model, and no statement of how a bank would validate what it is deploying. The one performance number published anywhere is a reduction of financial crime false positives by up to eighty five percent, and the standing rule from the Azentio build applies here at more than twice the magnitude: suppressing alerts is trivial, suppressing only the wrong ones is the problem, and a false positive reduction figure published with no recall or false negative figure beside it is the one number in anti money laundering that cannot be read alone. No baseline, no institution, no methodology, no period, and the words up to make it a ceiling rather than a result.
A very long list of named institutions and not one attributed result. The customer roster is published in the company's own boilerplate and includes several of the largest banks in Europe, and the analyst set is the densest on this roster: top eight global core banking technology provider from Everest Group in 2026, strong performer in the Forrester Wave for digital banking engagement platforms in 2026, leader in the QKS Group Spark Matrix for digital banking platforms, a top ten European fintech placement from IDC, and leader positions with Omdia and in an Everest Group Peak Matrix.
Individual customer announcements are named and dated, including an eight year partnership extension with a German auto finance bank and a digital banking programme with a central African banking group. Held at B on the line applied four times on this roster: named customers plus dense analyst recognition is B, and A requires a result attached to a name. The only quantified performance claim found anywhere is a reduction of financial crime false positives by up to eighty five percent, attached to no institution.
The nearest thing to an answer in the published material is that the data the generative layer draws on remains governed and secured within each institution's own environment. Graded C because that sentence is genuinely ambiguous between an access control statement and a training exclusion, and an ambiguous claim earns nothing, a rule this index has applied where it costs a vendor a grade rather than only where it saves one.
Nothing states whether customer data trains or tunes any model, whether anything is pooled across the fifteen hundred institutions on a platform the company itself describes as a shared data and artificial intelligence platform, or what is excluded from a training corpus. That shared framing makes the unanswered question sharper here than for most, because competing banks sit on the same substrate.
A personal data protection charter is published in the footer alongside a modern slavery statement, and the generative layer is described as operating on data that remains governed and secured inside the institution's environment. Neither is a product level data handling position: no retention schedule, no deletion terms, no subprocessor list, no statement of how customer records are separated between tenants on the shared data platform, and no privacy specific attestation.
The exposure is large in proportion to the estate, since the platform holds deposit, payment, card, loan and arrears records for institutions serving retail customers across eighty countries. Queued check, cheap: the personal data protection charter was not opened.
A genuinely uncommon artifact and a new shape for this index: not a badge row, but the contractual security annex itself, published openly. A documentation page carries three downloadable Security Management Plans, each scoped to a specific contract type, each version stamped and dated, most in both English and French, and none behind a gate or a form: one for software as a service on Amazon Web Services in the European Union built on the company's own security framework, one for managed service customers, and one covering maintenance and on premises deployment.
In most of this index that document is an annex a buyer receives only under a non disclosure agreement during procurement. Held at B and not A because no certification, attestation report, audit period or independent assessor is named on the page: against the reference bar set by ICE Mortgage Technology, with per product SOC 2 reports on a dated cadence and bridge letters covering the gaps between audit periods, there is no third party assurance identified here at all. Queued check, cheap and specific: the plans themselves were not opened and would be the natural place for the certification list.
A software vendor with no licence, registration or supervised standing of its own, inside a listed international software group. Every regulatory reference in the material is about the buyer's position rather than the firm's: helping institutions meet regulatory requirements, supporting open banking and payment services regulation compliance, and delivering regulatory reporting as a product. Analyst placements and a corporate parent do not read across as regulatory standing.
Nothing published, and this is the largest unaddressed exposure found on the roster. Artificial intelligence supported scoring and risk assessment runs inside loan origination for fifteen hundred institutions across eighty countries, a substantial number of them inside the European Union, where creditworthiness assessment of natural persons is expressly a high risk use under the European artificial intelligence regulation.
A French headquartered vendor selling credit scoring capability to French and other European banks publishes no fairness testing, no protected characteristic treatment, no disparate impact analysis, no governance framework, no named standard and no position on that regulation at all. The company does publish commentary about helping banks cut through hype with governance, which is category content about the buyer's problem rather than disclosure about its own systems.
No recourse position published. The division is the standard one and the scale makes it unusually consequential: the software supports credit scoring at origination, prioritisation in collections and alert generation in financial crime screening, while the institution is the party a customer complains to and the only party a supervisor can sanction.
Nothing states whether a declined applicant or a screened customer is told a model was involved, how a wrong score or a wrong alert is contested, or how responsibility divides between the vendor supplying the models and the bank operating them. A false positive in sanctions screening freezes a real customer's payment, and nothing addresses that person at all.
Not one model, provider, version or base model is named, on a company that announced a generative artificial intelligence layer across its entire product estate. The buying forces disclosure rule points hard the other way: a generative layer at this scale is licensed, and the company publishes a named cloud dependency for its software as a service platform while naming nothing at the model layer.
That is precisely the distinction recorded against Pega and Opensee on this roster and against Pennant in this session: naming the cloud is not naming the model. The shared data and artificial intelligence platform is described as the foundation for everything above it and its own composition is never disclosed.
Graded A on the strongest available basis, the same one that earned Azentio its A: the vendor supplies the core itself. The estate includes the system of record for deposits, payments, cards, lending and regulatory reporting, so lending, asset finance and compliance attach natively rather than through connectors, and the composable architecture is sold as a set of components against that shared spine.
The point is made sharpest by the artificial intelligence layer, which the company describes as directly connected to data from the products the bank already runs rather than bolted on from the outside, which is a claim only a core provider can make. Open banking and PSD3 support supplies the outward integration surface. Deployment spans software as a service, a managed service and on premises, all three confirmed as distinct contract shapes in the company's own security documentation.
Answered from the vendor's own contract documentation rather than from a review site, which matters because the review site version and the vendor version differed. Three deployment shapes exist as separately documented contract types: software as a service on Amazon Web Services scoped explicitly to the European Union, a managed service variant, and on premises under a maintenance contract.
That is a named cloud with a named jurisdiction, which is a real residency statement rather than an adjective. The generative layer is separately described as drawing on data that remains inside each institution's own environment.
Held at B and not A because the only jurisdiction named is the European Union while the customer base spans eighty countries, so nothing states where data sits for customers in Africa, the Middle East, Asia or the Americas, and no region list, replication policy or transfer mechanism is published. The sovereign framing used in the navigation is never defined anywhere.
No pricing of any kind published. Notable only because the same footer that hides every price publishes the security annex and links a contract documents library and a software as a service agreements page, so the reticence is specific to commercial terms rather than general.
Queued and cheap: the contract documents and SaaS agreement pages were not opened and are the one place a vendor of this type sometimes publishes commercial structure, service levels or credit regimes even when it publishes no rate.
The widest coverage on this roster and among the widest in the index. More than fifteen hundred financial institutions and large scale lenders across eighty countries, with named customers spanning several genuinely different buyer types: global systemically important banks (Santander, BNP Paribas, Societe Generale, Credit Agricole, Groupe BPCE, HSBC), a state owned postal bank, a British building society, African banking groups (KCB, Attijariwafa, BGFI), a specialist mortgage lender, and captive manufacturer finance arms in both automotive and equipment (Mercedes-Benz, Toyota Financial Services, NextGear Capital, Bank11).
Product coverage runs retail, corporate, asset finance and wholesale dealer floorplan financing. Coverage of this breadth across institution type, geography and lending product is what the A on this axis is reserved for.
Alternatives to SBS
The closest documented capability profiles to SBS in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Stronger documented coverage on Operational and Outcome Evidence
Documents Autonomy and Oversight Model where SBS does not
Documents Autonomy and Oversight Model where SBS does not
Documents Model Risk Management and Transparency where SBS does not
Documents Model Supply Chain Disclosure where SBS does not
Documents AI Governance and Bias Disclosure and Model Risk Management and Transparency where SBS does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.