Smarbl
Smarbl sells regulatory reporting and regulatory intelligence platforms to banks and other financial institutions, and runs two named products that sit in different places on the automation spectrum. SmartReg, the flagship, is a regulatory reporting automation platform built on pre configured business rules, validations and workflows bundled with a regulatory data model.
It ships out of the box returns for selected regulators across financial, capital, liquidity, credit quality, large exposure, statistical and transactional reporting, ingests compliance, anti money laundering, financial crime and risk data, and carries submissions through to the regulator with data lineage, reconciliations, version control, approvals, oversight dashboards and last mile integration through application programming interfaces and the XBRL standard.
RegPRISM, launched in July 2025 and co developed with United Arab Bank, is the regulatory intelligence and compliance management platform: it tracks regulatory change and extracts, interprets and routes the resulting obligations. A modular cloud ready data platform sits underneath both. The company was founded in 2023 by Ritesh Bakliwal, Ajay Raju and Tanujit Ghosh, is registered in Abu Dhabi Global Market and runs product engineering from Pune and Bhubaneswar in India, with roughly 40 staff and no disclosed external funding.
Chartis named SmartReg a category leader in its regulatory reporting quadrant in both 2024 and 2025 and listed the firm in its RiskTech100 for 2026, citing adoption by banks across the Middle East and North Africa. SmartReg is offered on cloud, on premise and hybrid deployments.
Capability Axes
Capability grades
15 of 15 axes rated · 7 graded A or B
The removal test splits this vendor cleanly along its own product line, which is why the grade is easy to defend. Take the models out and SmartReg survives entire: pre configured business rules, validations, a regulatory data model, reconciliation, lineage, approvals and submission through the XBRL standard are all deterministic, and the company describes them that way.
RegPRISM does not survive, because extracting an obligation from regulatory text and interpreting what it requires is the model rather than a feature of one. Same structure as Alloy, CUBE and Corlytics: a working engine underneath, a model dependent product layered on top and sold under its own name.
One detail is worth carrying forward because it is unusual and it argues against an A. The flagship product and both years of analyst recognition attach to the non model half, so the firm's market position was earned by the deterministic product and the intelligence layer is the newer bet.
The reporting product publishes a real control chain rather than a claim about one: validations and reconciliations before a return is built, version control, an approval step, monitoring and oversight dashboards, and adjustments passed in a controlled manner with end to end lineage back to source. That is a named gate with a named adjudicator, which is what this axis asks for. What holds it at B is where the controls sit.
Every one of them governs SmartReg, the deterministic half, while nothing published describes a review gate, confidence threshold or reviewer step for RegPRISM, where a model extracts and interprets obligations. The oversight architecture is attached to the product that needs it least, and the firm plainly knows how to build one, which makes the silence on the other side more conspicuous rather than less.
No accuracy figure, benchmark, validation method or error rate was located for obligation extraction or interpretation, and the claim is a measurable one. An obligation is either captured from the source text or it is not, and that is directly testable, in the same way the conversion claim was testable for Aptus.AI. The sharper point is internal to this vendor and it is worth reusing wherever a firm runs a deterministic product alongside a model dependent one.
SmartReg advertises validation, reconciliation, lineage and controlled adjustment as headline features, so the company demonstrably understands what evidencing correctness looks like and how to sell it. None of that apparatus, and no equivalent of it, is published for the half where a model decides what a regulation requires.
Two independent signals, both real. Chartis named SmartReg a category leader in its regulatory reporting quadrant in two consecutive years, 2024 and 2025, with published analyst commentary on execution and regional depth, and the firm entered the RiskTech100 for 2026. On the customer side, United Arab Bank is named, its chief executive is quoted, and the bank co developed RegPRISM rather than merely buying it.
Held at B on the standard set for CUBE and applied to Aptus.AI earlier in this same competitor set: a bank announcing a partnership is not a customer reporting a measured result. Nothing quantified is published anywhere. The global bank reference case is anonymised, no customer count is stated, and the phrase about adoption by banks across the Middle East and North Africa comes from the analyst rather than from any named institution.
No boundary statement was located on whether one institution's regulatory data, report configurations or obligation mappings inform models or outputs served to another. The exposure has a specific shape here that is worth recording because it is new to this index.
The intelligence product was co developed with a named bank, so a competing institution buying RegPRISM is buying something shaped in part by a rival's compliance expertise, and nothing published describes what that bank contributed, whether it retains any interest in the product, or whether its obligation interpretations sit inside what other customers now receive. Co development with a customer is a credible way to build a regulated product and it creates a stewardship question that arms length development does not.
No privacy statement, retention rule or data handling commitment was located. The material in scope is unusually consequential even by the standards of this index: a bank's full supervisory data set, including exposures, liquidity positions, credit quality and large exposure detail, alongside anti money laundering and financial crime reporting data that identifies individuals under investigation.
One architectural fact works in the vendor's favour and is recorded rather than credited, because it is a deployment option and not a policy: an institution that selects the on premise model keeps that data inside its own estate, which removes the question rather than answering it. For every customer on the cloud or hybrid model the question stands unanswered.
No information security certification, audit report, penetration testing statement or trust centre was located in this pass. The platform is described as designed for performance, security and extensibility, which is an architectural adjective rather than an attestation, and the distinction matters because a buyer cannot verify an adjective.
Recorded as an absence found rather than a proven absence and worth rechecking, since the lesson from the 73 Strings correction is that product and use case pages sometimes carry compliance claims that no security page repeats. The commercial cost is concrete: this vendor sells to supervised banks whose third party risk assessments open with exactly this question, and it competes in the same analyst quadrant as several incumbents that publish full assurance packages.
The posture is the correct one for a technology supplier and it carries two checkable facts rather than a generic compliance claim. The company is registered in Abu Dhabi Global Market, a financial free zone with its own financial services regulator, which fixes its jurisdiction publicly.
More substantively, the product ships pre built returns for named regulators and submits into supervisory reporting channels through regulator accepted formats including the XBRL standard, which means the output has to satisfy a supervisor's own schema to be accepted at all. That is the same class of fact as presence inside statutory filing paths, which supported a B for Socure. Graded at B rather than A because no supervisor has examined the model dependent product itself, which is what an A on this axis requires.
No governance framework, fairness position, testing programme or independent assessment was located. The product specific exposure is coverage and interpretation rather than protected class discrimination, and it is the same one that applies to any regulatory retrieval product: what the system surfaces determines what a compliance team believes the law requires of it. That risk scales unevenly with the growth strategy.
Coverage will be deepest for Gulf regulators, where the firm was built and where its named customer sits, and thinnest at the edges of the global expansion it describes, which is exactly where a new customer is least equipped to notice an obligation that never appeared. Recorded against the ladder set by Corlytics in this same competitor set, where an independently audited artificial intelligence management system certification earns an A.
No accuracy warranty, service commitment or remedy was located, and the consequence structure is heavier than for most products in this index because the output is filed. A regulatory return goes to a central bank in the institution's name, not the vendor's, so an error in a pre built template, a validation rule or a mapping becomes a supervisory matter for the bank, which may face a resubmission, a finding or a penalty.
The intelligence side carries the mirror version: an obligation that the model never surfaced becomes a compliance breach the institution owns and cannot easily discover, since the failure leaves no trace in the system that should have raised it. Nothing published describes where responsibility sits in either case, and no service level or correction commitment was found.
No provider, base model, hosting arrangement or build against buy statement was located for the intelligence product. The omission collides with the vendor's own strongest disclosure elsewhere, and the contradiction is the finding worth carrying forward. On premise deployment is offered specifically for institutions with data residency obligations, so a bank chooses it in order to keep regulatory and financial crime data inside its jurisdiction.
If the obligation extraction and interpretation layer calls an external model endpoint, that data leaves the estate anyway and the reason for choosing on premise is undone. Nothing published resolves it either way. Any vendor pairing an on premise option with an unattributed model layer should be asked this directly.
Real depth on the axis this vendor has to be strong on. The platform ingests and transforms data from core banking, risk and financial crime systems into a regulatory data model that is deliberately designed to distance submissions from the source systems, then carries returns out through last mile integration with regulator channels using application programming interfaces and the XBRL standard.
Architecture is cloud native with microservices, and deployment spans cloud, on premise and hybrid, which is itself an integration commitment because it means the product runs inside a bank's own estate. Held at B because no named core banking, general ledger or risk platform integration was located, and no public connector catalogue or developer documentation was found, which is the layer an A requires.
Among the better disclosures on this axis in the index, and earned on published specifics rather than a generic cloud claim. The vendor states three deployment models, cloud, on premise and hybrid, says the platform is compatible with leading cloud providers, and addresses the residency question directly by naming on premise as the answer for jurisdictions with data residency concerns.
Most vendors here never engage with the question at all, which is why 271 of 308 sat at C when the distribution was last measured. Held at B because the disclosure stops short of the detail a procurement team needs: no hosting regions are listed, the cloud providers are described as leading rather than named, and no tenancy model or subprocessor list is published. This is the second B on this axis inside one competitor set, alongside a peer that names its hosting country.
No rate card, tier ladder or billing basis was located and the route to a number is a demo request. The marketing makes cost claims without prices, describing zero costs and reduced capital and operating expenditure through pre built reports, which tells a buyer the direction of the argument and none of its magnitude.
Consistent with every regulatory vendor screened in this sweep so far, which now spans a pre Series A Italian platform, a 1,500 client conduct compliance platform and this firm at roughly 40 staff, so the opacity is a category norm rather than a size effect. The one partial disclosure with commercial content is architectural rather than financial: offering an on premise model tells a buyer that the deployment choice exists, without saying what choosing it costs.
Reporting domain breadth is genuine and is the strongest part of the case: financial, capital, liquidity, credit quality, large exposure, statistical and transactional returns, with compliance, anti money laundering and financial crime reporting integrated into the same data model, which covers most of what a bank actually files. Buyer type is correspondingly clear, since this is sold to banks and financial institutions rather than across industries.
Held at B on geographic concentration, the same reasoning applied to Aptus.AI in this competitor set. Out of the box returns exist for selected regulators, the analyst citation describes adoption across the Middle East and North Africa, global expansion is stated as a strategy rather than a footprint, and the only named customer is in the United Arab Emirates. A deep regional position is a legitimate strategy and a real limit on the axis as written.
Alternatives to Smarbl
The closest documented capability profiles to Smarbl in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Stronger documented coverage on Operational and Outcome Evidence
Documents AI Safety and Data Stewardship and Model Risk Management and Transparency where Smarbl does not
Documents Security Certifications and Trust Center where Smarbl does not
Documents Model Risk Management and Transparency where Smarbl does not
Stronger documented coverage on Operational and Outcome Evidence and Institution and Segment Coverage
Stronger documented coverage on Institution and Segment Coverage
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.