SymphonyAI
SymphonyAI is a Palo Alto headquartered vertical AI company operating across several industries, and this record covers only its financial services division, built around NetReveal, the financial crime platform it acquired from BAE Systems in 2022, and its own Sensa artificial intelligence line. The combination is deliberate: NetReveal supplies established rules based transaction monitoring, customer due diligence, name and transaction screening, watchlist management, fraud management and regulatory reporting, and Sensa layers machine learning over it.
The distinctive product is SensaAI, an overlay that augments an institution's existing transaction monitoring system using supervised and unsupervised learning without requiring replacement, so a bank can add detection capability to infrastructure it already runs rather than migrating off it. Around that sit Sensa Investigation Hub for case management, Sensa Copilot, a generative assistant that lets investigators interrogate a case in natural language and produce investigation summaries from which they judge whether a suspicious activity report is warranted, and Sensa Agents, which conduct research and draft report narratives.
Sensa Risk Intelligence, launched in October 2025, packages large language models, analytics and agentic capability into an AI native compliance platform. The company publishes five principles of responsible AI and explains how each is met in the design of named products, ships explanations alongside predictions with a stated probability of match, and surfaces machine learning predictions inside the case management interface to support ongoing model validation. Published results include false positive reductions of up to 70 percent and a proof of concept reporting an 80 percent false positive reduction while retaining all true positives. Deployment runs on both Amazon Web Services and Microsoft Azure, with Sensa Copilot built on Azure OpenAI.
Capability Axes
Capability grades
15 of 15 axes rated · 10 graded A or B
The company sells its AI as additive and says so plainly, which settles this. NetReveal Transaction Monitoring is described as combining traditional rules based monitoring with predictive and generative capabilities, SensaAI is positioned explicitly as an overlay that augments existing transaction monitoring without requiring replacement, and the division's own managing director framed the proposition as giving institutions the right blend of rules based and AI insights.
Apply the removal test and a complete, mature product remains: the rules based detection, customer due diligence, name and transaction screening, watchlist management, case management and regulatory reporting that NetReveal carried under BAE Systems ownership before this company acquired it in 2022.
The modelling is real and substantial, spanning supervised and unsupervised learning, behavioural graph network analysis, generative investigation assistance and agentic research, and it is the reason to buy the current product rather than the previous one. It is still a layer over a working system rather than the system.
The oversight construction is strong through the investigation stage and thins out at the point of highest consequence. Through investigation it is well built: predictions arrive with a probability of match and a human readable explanation of why the model reached its conclusion, machine learning predictions are surfaced inside the case management interface so an analyst sees the model's reasoning in the same place they work, alert scoring is continuously surfaced for transparent assessment, and the workflow is explicit that an investigator interrogates the case through the assistant and then determines whether a suspicious activity report is necessary, so the regulatory judgement stays with the human.
The concern sits one step later. Sensa Agents are described as conducting research and producing consistent report narratives in seconds, and a suspicious activity report narrative is the document a regulator and potentially a court will read. Nothing published describes what an investigator must review, edit or attest to before an agent drafted narrative becomes a filing.
Model governance is built into the working interface rather than delivered as a document, which is the useful form. Machine learning predictions are viewed inside the NetReveal case management interface and the company describes this as providing transparent, ongoing model validation and assessment to support model governance, so a second line function can observe model behaviour in production through the same system investigators use.
Suggested alert scoring is surfaced automatically and continuously to allow detailed assessment of AI results. Each prediction carries a probability of match and a human readable explanation. The published proof of concept, an 80 percent false positive reduction retaining all true positives, gives a reviewer both error directions rather than one.
What is missing is the documentary layer: no production accuracy figure, precision or recall measure, validation report or monitoring statement was located, and none of the published percentages carries a population, period or methodology.
Tier one institutional users across three sectors, multiple published outcome figures, and independent corroboration. Recorded users include Wells Fargo and Absa Group in banking, AXA and Progressive in insurance, and the State of Massachusetts in government, though that customer list comes from a third party install base database rather than from the vendor and carries that provenance.
Quantified results are published across several products: false positive reduction up to 70 percent, investigation time reduced by 40 percent, risk detection accuracy improved by more than 70 percent, and investigator productivity up to 70 percent from the generative assistant.
Independent corroboration exists in a Microsoft published customer story reporting roughly 60 percent productivity improvement in a financial institution's compliance department during early testing, which is a lower and more credible figure than the marketing number and is attributed to a named partner rather than the vendor. Named analysts at Celent and Chartis Research commented on the platform launch. The underlying product carries a long institutional track record from its BAE Systems origins.
Two structural points lift this above the lane norm. First, there is no cross customer data consortium anywhere in this product line. SensaAI operates as an overlay on an institution's own existing monitoring system and its own data, deployments are provisioned per customer on either major cloud, and nothing describes pooling one institution's transactions or outcomes into models serving another, so the contribution, segregation and retention questions that cap most records here do not arise in the same form.
Second, the company publishes five principles of responsible AI and an account of how they are applied in the design and deployment of named products, with accountability defined concretely as identifying and holding responsible the individuals, teams and organisations behind design, implementation and oversight.
Against that, no retention or data handling terms were located, and the generative and agentic components introduce a third party model service into the path without any published statement about what data reaches it.
Nothing was located. No data processing addendum, subprocessor list, retention schedule, named supervisory authority, transfer mechanism or named privacy regime appears in retrievable material for the financial services division.
The gap is sharpened by the generative architecture: Sensa Copilot is built on Azure OpenAI, so investigation content concerning identified individuals under suspicion passes through a third party large language model service, and nothing published describes what is sent, what is retained, whether prompts or completions are used for any secondary purpose, or how that flow is governed.
A compliance function evaluating this platform would need that answered before deployment, and the company that names the underlying model service, which is itself unusual candour, does not go on to describe the data handling around it.
Two dedicated passes located no security certification, attestation, trust centre, penetration test summary or enumerated control framework held by this company and stated in its own voice. What exists is operational rather than assured: the managed cloud deployment carries service levels covering security patching, support responsiveness and system upgrades, which describes maintenance discipline rather than an audited control environment, and the company points to the availability, reliability and security of the underlying cloud platform, which is the provider's assurance and not the vendor's.
That gap is notable given the customer base, since systemically important banks and global insurers cannot contract without supplier assurance evidence, so the assessments will exist inside procurement. Pre emptive negative finding: an inherited cloud provider certification will not move this grade, because the platform is also delivered on a second cloud and the question is about this vendor's own controls over customer investigation data.
No licence, supervisory relationship, named regulator counterparty or regulatory approval was located. The products address named obligations, covering anti money laundering, customer due diligence, sanctions and watchlist screening and suspicious activity reporting, and the platform is described as maintaining full regulatory compliance and audit transparency while processing transactions in real time, which is a claim about the product's fitness rather than about the company's standing.
The NetReveal heritage under BAE Systems ownership brought long standing deployment inside heavily supervised institutions, and the recorded user base includes systemically important banks whose own supervisors will have examined this platform in situ, but that is supervision of the customers rather than of the vendor. Nothing here counts against a technology supplier not expected to hold a licence, and nothing lifts the record either.
The most developed governance disclosure located in this index, resting on four separate artifacts rather than a single claim. The company publishes five principles of responsible AI together with an article setting out how each is met in the design and deployment of specific named products, defining accountability concretely as identifying and holding responsible the individuals, teams and organisations behind design, implementation and oversight.
It states openly why the burden is higher here, that because the model is not a rules based system designed and understood by humans, the level of scrutiny and governance must be high, which is a vendor acknowledging the governance cost of its own architecture rather than minimising it. Explainability ships as product output, with every prediction returned alongside a probability of match and a human readable explanation of the reasoning.
And the published proof of concept result reports both sides of the trade off, an 80 percent reduction in false positives while retaining 100 percent of true positives, where nearly every competitor publishes only the false positive figure, which can be achieved simply by detecting less. What remains absent is fairness testing and any disparate impact analysis.
No guarantee, indemnity or accuracy service level attaching to detection quality was located. Service levels are published for the managed cloud deployment covering availability, security patching, support responsiveness, upgrades and maintenance, and those are operational commitments about the platform running rather than about the decisions it produces, which is a distinction a buyer should hold clearly.
For the individual the position is constrained by law rather than by vendor choice, since tipping off a subject of a suspicious activity report is prohibited in the jurisdictions this platform serves, and that is credited as context rather than criticised.
What the vendor could address and does not is the consequence of its newest capability: an agent drafted report narrative becomes part of a regulatory filing about a named person who will never see it, cannot contest it and has no route to correct it, and nothing published describes what review that narrative receives, how errors in it are detected, or what happens to the subject's record if a filing is later withdrawn.
The foundation model provider is named, which almost nothing else in this index does. Sensa Copilot is stated to be built on Azure OpenAI alongside Azure infrastructure, Azure Kubernetes Service and Azure AI services, so a buyer evaluating the generative layer knows whose model sits behind it and can assess that provider's own terms and certifications directly rather than accepting an undisclosed dependency.
Amazon Web Services is named as the infrastructure behind the compliance suite deployment. Provenance of the core platform is also disclosed, with NetReveal identified as acquired from BAE Systems in 2022, so its lineage is traceable rather than presented as native.
What is not disclosed is the data chain: no sanctions, politically exposed person or adverse media list provider is named anywhere despite watchlist management and name screening being sold products, and no subprocessor list exists.
This vendor's flagship AI product is designed to run on top of a competitor's installed system, which is a deeper integration commitment than anything else graded here. SensaAI is sold explicitly as an overlay that augments an institution's existing transaction monitoring using supervised and unsupervised learning without requiring replacement, so the integration surface is not a connector list but another vendor's platform.
Around that, the architecture is described as platform agnostic software as a service enabling rapid deployment without disrupting operational systems, with stated integration into existing legacy banking infrastructure, data warehouses and compliance systems, and standard regulatory compliance data interfaces designed for the customer's specific industry and territory, which is pre built rather than bespoke mapping.
Availability on both major cloud marketplaces gives enterprise buyers procurement paths against existing commitments, and a packaged bundle covering due diligence, anti money laundering and watchlist management is offered for out of the box deployment.
Both major cloud platforms are named specifically rather than left implicit, and the components are identified. The compliance suite is delivered on Amazon Web Services with the vendor providing provisioning, management and support of both the business solutions and the underlying infrastructure as a single point of contact, under service levels covering hardware and software availability, security patching, support responsiveness, upgrades and maintenance.
Sensa Copilot runs on Microsoft Azure infrastructure using Azure Kubernetes Service, Azure AI services and Azure OpenAI. Territorial configuration is acknowledged, with standard regulatory compliance data interfaces described as designed for the customer's industry and territory.
What is absent is the residency detail itself: no region list, customer region selection, data centre location, sovereignty commitment or transfer mechanism was located, and no private or on premises option is described despite the platform's heritage in institutions that historically required one.
No rate, tier, band, entry point, free tier or trial was located across two dedicated passes, and no metering unit is disclosed for any product. One commercial term is published and is worth recording because it addresses the barrier this market is known for: the cloud delivered version of the compliance suite is offered on a flexible commercial model with no upfront costs, which the company frames as minimising a customer's capital expenditure.
Service levels are also described in outline for that deployment, covering hardware and software availability, security patching, support responsiveness, system upgrades and maintenance. So a buyer learns that the engagement can be operating expenditure rather than capital, and that operational service commitments exist, without learning the price of either. Listings exist on two major cloud marketplaces, which is the channel that normally forces a published figure, and none was retrievable.
Coverage spans buyer types, institution sizes and geographies more completely than most of this lane. Recorded users run across retail and commercial banking, insurance and public sector, in the United States, France, South Africa and the United Kingdom, which is unusual reach for a financial crime platform and reflects that money laundering obligations bind insurers and government agencies as well as banks.
Product coverage is end to end within the compliance function, running from customer due diligence and onboarding through name and transaction screening, watchlist management, transaction monitoring and fraud detection to investigation, case management and automated regulatory reporting.
Two packaging choices extend reach downward: a bundled compliance offering delivered out of the box with due diligence, anti money laundering and watchlist management preconfigured, and the SensaAI overlay, which lets an institution adopt the AI capability without replacing its incumbent platform and therefore without an enterprise scale procurement.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Protection Terms | Implementation | Source |
|---|---|---|---|---|
|
Not published. A flexible commercial model with no upfront costs is stated for the cloud delivered compliance suite, with no rate, tier or metering unit attached.
|
Undisclosed beyond structure. No rate or metering unit is published, so it cannot be established whether these products are licensed per monitored customer, per transaction, per alert, per module, per seat or as an enterprise subscription. What is disclosed is that the cloud delivered suite is offered with no upfront cost on a flexible model, which points to subscription or consumption rather than perpetual licensing with capital outlay, and is consistent with the company's positioning against incumbent platforms that require large initial commitments. The product line is modular across transaction monitoring, customer due diligence, name and transaction screening, watchlist management, fraud management, investigation and case management, with a packaged bundle available covering three of those, so a customer's cost will depend heavily on scope adopted. The SensaAI overlay is sold as an addition to an existing third party system, which implies it can be priced independently of a full platform licence. | No data processing addendum, subprocessor list, retention schedule or named privacy regime was located for the financial services division. The generative architecture makes that gap sharper than usual: Sensa Copilot is built on Azure OpenAI, so investigation content about identified individuals under suspicion passes through a third party large language model service, and nothing published describes what is transmitted, what is retained, or whether prompts or outputs are used for any secondary purpose. On assurance, two dedicated passes found no certification, attestation or trust centre stated in the company's own voice, only operational service levels covering patching and availability on the managed cloud deployment and references to the underlying cloud provider's own security. | Not disclaimed, and the company describes an implementation model that is unusually explicit about who does the work. For the managed cloud deployment it provides advisory services alongside implementation, migration and management of the regulatory and compliance solutions, and takes responsibility for provisioning, management and support of both the business applications and the underlying infrastructure as a single point of contact. That is a professional services relationship rather than a self serve integration, and no rate, engagement minimum or inclusion boundary is stated for it. Two design choices cut the other way and reduce customer side cost: standard regulatory compliance data interfaces built for the customer's industry and territory reduce mapping effort, and the SensaAI overlay adds detection capability to an incumbent monitoring platform without requiring replacement, avoiding a migration entirely. | Vendor Published |
Two dedicated passes returned no figure. No pricing page, tier structure or metering unit was located for any product in the financial services line, and listings on two major cloud marketplaces, the channel that normally forces a published rate, yielded none.
One genuine commercial term is published for the cloud delivered compliance suite: a flexible commercial model with no upfront costs, framed by the company as minimising customer capital expenditure, alongside stated service levels covering hardware and software availability, security patching, support responsiveness, system upgrades and maintenance.
That tells a buyer the engagement can be structured as operating expenditure with operational commitments attached, without telling them the price of either. Pre emptive negative finding: this is a multi industry group selling vertical AI into retail, industrial and other markets alongside financial services, so any rate that surfaces under the parent brand should be checked against the financial crime products specifically before it is treated as relevant.