Strise
Strise is an anti money laundering automation platform founded in Oslo in 2016 by Marit Rodevand, Patrick Skjennum and Sigve Sorasen, launched commercially in 2019 after three years of development, and now operating from Oslo and a London office. Its core proposition is data resolution rather than data aggregation: a continuously updated knowledge graph, marketed as SuperData, that links companies, directors, ownership structures, sanctions exposure and adverse media into one connected record instead of leaving them in separate databases, with natural language processing extracting information from documents and agentic components triaging and dispositioning screening alerts.
Nine named products sit on it, covering business onboarding, individual onboarding, ongoing due diligence, identity verification, beneficial ownership discovery, back book remediation, risk scoring, screening and alert triage, and document analysis. It states that roughly 70 percent of top tier Nordic banks use it, and names customers across banking, payments, insurance, pensions, wealth management, audit and law, including Nordea, Danske Bank, Handelsbanken, the SpareBank 1 alliance, Vipps MobilePay, Storebrand, Fremtind, KLP, Formue, BDO Norway, PwC Norway, EY UK and Orrick.
Its Storebrand deployment runs across a group managing 1,281 billion Norwegian kroner with more than 55,000 corporate and 2.2 million retail customers. Reported outcomes include a 90 percent reduction in due diligence time, roughly 30 percent cost savings, up to 85 percent lower remediation costs, and onboarding cut from about an hour to twelve minutes. It raised a Series A of about 10.8 million dollars led by Atomico with Curiosity, Maki.vc and Sondo, taking total funding to roughly 12 million pounds, and partners with Kyckr for registry data across more than 300 registries, Signicat for digital identity and Stacc and PSA Solutions for distribution. It publishes ISO/IEC 27001:2022 certification and a SOC 2 Type 2 attestation naming its auditor, and runs a standing security trust centre and a public platform status page.
Capability Axes
Capability grades
15 of 15 axes rated · 6 graded A or B
The removal test is clean and the company draws the line itself. Its stated differentiator against the rest of the market is resolution rather than aggregation: most platforms check records, this one maps relationships, holding entities, directors, ownership chains and sanctions exposure in one continuously updated graph rather than siloed databases.
Around that sit natural language processing extracting from documents, matching that suppresses false positives, and agentic components that dispose of screening alerts. Strip the models and what remains is registry data licensed from a partner, which is somebody else's product. Same position as arva-ai in this pocket, and it is the CleverChain side of the orchestration line rather than the Ondorse side: this reasons and concludes rather than routing and logging.
A clearly stated division of labour with an audit trail through the whole path, and a tension the company has not resolved. On one side, the positioning is explicit that the human keeps the decision: manual work ends, the audit trail is built throughout, and what is left is judgement work that stays with the customer's team.
Risk based prioritisation is a real mechanism sitting before the decision, routing low risk onboarding to instant approval and pushing complex cases to deeper human review, which is how the Vipps deployment is described. On the other side, screening dispositioning is marketed as agentic AI making autonomous decisions.
Both statements are published and nothing reconciles them: no threshold is given for which alerts the agent may close by itself, no abstention or escalation rule is described, and no failsafe is named. B rather than A, because the A bar requires the enforcement mechanism and its position in the execution path, and here the boundary of autonomous action is exactly what is missing.
Operational outcomes are published in quantity and model evidence is absent entirely. No precision or recall figure, no false positive or false negative rate, no benchmark, no evaluation methodology, no model documentation and no validation pack for the institution's own model risk function, which matters here because European banks are expected to be able to validate the financial crime models they rely on rather than accept a supplier's assurance.
Explainability is asserted rather than demonstrated, and an audit trail records what the system did, not whether it was right. The headline claim, fewer false positives than any other screening tool on the market, is the third instance in two days of the unverifiable comparative shape recorded on hudson-labs and needl: a comparison against every competitor with no benchmark, no score and no evaluator named.
The A bar is a named customer carrying a quantified outcome, and this vendor meets it repeatedly rather than once. Named institutions across four countries and six industries, several announced individually with the workflow they replaced, plus a named executive on the record at Storebrand.
The numbers attach to that base: a 90 percent reduction in due diligence time, roughly 30 percent cost savings, up to 85 percent lower remediation costs, onboarding cut from about an hour to twelve minutes, and a stated 70 percent share of top tier Nordic banks. The Storebrand engagement is quantified by scale rather than percentage, at more than 55,000 corporate and 2.2 million retail customers across a group managing 1,281 billion kroner. The figures are vendor reported rather than independently audited, which is normal at this bar, but they are anchored to institutions a buyer can call.
The pooled corpus question is sharper here than for almost any vendor in the index and it is not addressed at all. The product is a shared knowledge graph across customers, and customers actively contribute into it: the platform supports real time ownership editing, corrections to beneficial ownership maps, and comments on those edits. So competing banks, insurers and law firms are resolving overlapping corporate universes on one data layer while feeding their own analysis back into it.
Nothing states whether one institution's uploaded documents, ownership corrections, risk assessments or search patterns inform what another institution sees, whether that material trains shared models, or how a customer's contributions are treated when it leaves. Two vendors in other pockets have now answered this question plainly, so it is answerable, and silence on it is a choice.
A privacy policy, a cookie policy and a published GDPR commitment, with European entities and European cloud hosting, and nothing further located in the vendor's own material: no subprocessor list, no retention schedule, no deletion commitment and no data processing agreement terms.
Graded C deliberately and for consistency, on exactly the reasoning applied to needl in the same session: a policy plus a GDPR badge is the ordinary floor rather than a disclosure, and the existence of a trust centre is already credited on the security axis. GLBA itself is not the governing regime for a Norwegian vendor selling to European institutions, so the axis is read here as general data privacy posture.
The strongest security disclosure in this pocket and it passes every part of the credential test on the vendor's own material. ISO/IEC 27001:2022 with the correct current edition of the standard named, not an invented year. A SOC 2 Type 2 attestation that names the attesting firm, Prescient Assurance, which almost nothing in this index does and which is the single cheapest thing a vendor can do to make a claim checkable.
A standing security trust centre on its own subdomain rather than a badge row, and a separate public platform status page, so availability is observable rather than asserted. A third party review additionally describes penetration test reports and a bug bounty programme obtainable through that trust centre; that detail sits outside the vendor's own material so it is recorded here and not credited, on the same principle that kept an ISO claim off the ICE record.
A software supplier sitting outside the regulatory perimeter. No licence, no registration, no supervised sandbox participation and no enrolment in a regulator run data or access scheme was located in the vendor's own material. Its customers carry the anti money laundering obligations and the supervisory relationship; it carries neither.
Note that a trade article covering this pocket referred to an unnamed provider participating in the UK FCA sandbox, and that reference was not attributable to this vendor, so nothing has been credited from it.
No fairness disclosure, no ISO 42001, no evaluation published across name types or jurisdictions. The exposure in this pocket is specific and well understood in the field: politically exposed person and sanctions matching performs unevenly across scripts, transliterations and naming conventions, so people with non Latin script names, names with multiple accepted romanisations, or surnames common in a particular region are flagged more often for how they are named than for anything they have done.
The consequence lands on the person or business, who may be delayed or refused at onboarding. The company markets fewer false positives than any other screening tool and publishes no rate, no method and no breakdown by name origin, so the axis where its claim is strongest is also the one where it shows least.
The party most exposed to an error is not the customer. A business wrongly matched to a sanctions or adverse media record, or scored as high risk on a mistaken ownership resolution, may be delayed or declined by its bank without ever learning that a vendor's model produced the finding, and it has no relationship with the vendor, no notice that a flag exists and no route to contest it.
Nothing published states how a disputed match is corrected, whether a correction propagates to other institutions running the same graph, or who bears the cost of a wrongful decline or a missed match. The regulated institution absorbs the supervisory consequence for a model it did not build and cannot fully validate, which is the same allocation this index recorded across the collections software pocket.
No model provider, family or version is named anywhere located. The platform is described through its own components, a proprietary knowledge graph with natural language processing and agentic layers, which is the standard pattern this index has recorded: vendors that license capability name their suppliers, vendors that call the capability proprietary name nobody.
The supplier discloses the vendor check was applied and returned nothing, so no third party has published this vendor as a customer either. Nothing states where inference runs, whether any external provider receives customer documents or entity data, or what those providers may retain.
Integration is real and named, and unusually it runs through other vendors' rails rather than only an API. Kyckr supplies live company registry data across more than 300 registries, Signicat supplies digital identity in a joint no code offering, Stacc embeds the platform in Nordic banking software, and PSA Solutions carries it inside its Custodian product for law firms. Reaching institutions through three partners' platforms is genuine distribution depth.
Held below an A because no core banking, CRM or case management system of record is named, so a buyer learns which partners resell and supply, not what must be connected on their own estate for the platform to work.
A single tenant cloud application with a public status page and European corporate entities in Norway and the United Kingdom, and no published deployment or residency choices: no named regions, no cloud provider identified in the vendor's own material, no on premise or private deployment option, and no statement of where customer data physically rests or whether a customer can pin it to a jurisdiction.
A third party review describes hosting on major European cloud providers with defined recovery time and recovery point objectives, which would matter to a UK operational resilience assessment, but that is not the vendor's own material and is recorded rather than credited.
No pricing published. Enterprise licensing quoted per customer against portfolio size, user count, modules selected and integration complexity, with tiering described only in general terms by a third party review rather than by the vendor. For a platform whose core claim is cost reduction of a specific percentage, no cost figure of any kind is available for a buyer to test that claim against.
The broadest segment coverage in this pocket by a wide margin, and the only vendor in it earning an A. Seven regulated verticals with named customers in most: banking (Nordea, Danske Bank, Handelsbanken, SpareBank 1), payments (Vipps MobilePay), insurance and pensions (Fremtind, KLP), wealth and asset management (Storebrand, Formue), audit and advisory (BDO Norway, PwC Norway, EY UK), law (Orrick, PSA Solutions) and real estate.
The penetration claim is unusual in kind rather than degree: roughly 70 percent of top tier Nordic banks, which is a share of a national banking sector rather than a customer count. The Storebrand deployment alone spans insurance, pension, banking and asset management inside one group.
The offsetting limitation, recorded rather than penalised, is geographic: the base is overwhelmingly Nordic with the UK expansion recent, so this is depth across segments in one region rather than global reach.
Alternatives to Strise
The closest documented capability profiles to Strise in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
A lighter documented profile than Strise
A lighter documented profile than Strise
Documents Regulatory Status and Licensure where Strise does not
Documents AI Safety and Data Stewardship and Regulatory Status and Licensure, among others where Strise does not
Documents Regulatory Status and Licensure and Model Risk Management and Transparency where Strise does not
Documents AI Safety and Data Stewardship where Strise does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.