Temenos
Temenos is a Swiss banking software company founded in 1993, headquartered in Grand Lancy near Geneva and listed on the SIX Swiss Exchange, whose core, digital, payments, wealth and financial crime products serve more than 950 banks across retail, corporate, commercial, wealth and Islamic banking. It reported annual recurring revenue of 881 million dollars in the second quarter of 2026 and 316 customer go lives in 2025, and has been ranked the leading core banking provider by IBS Intelligence for twenty one consecutive years.
Its model layer is embedded across existing products rather than sold separately: Temenos AI Agents, a family of Copilots beginning with Copilot for Core and extending to workbench, financial crime, payments and wealth, and Conversational Studio, a natural language environment for building digital banking journeys. The financial crime AI agent screens sanctions in real time and was extended to instant payments in 2026, and a corporate actions agent supports wealth operations through complex market events.
The underlying investments are a banking knowledge graph, conversational interfaces, an agentic framework and a model context protocol implementation, running on Microsoft Azure AI and NVIDIA microservices. Temenos completed its acquisition of additiv on 17 July 2026, adding orchestration and mass affluent wealth reach.
Capability Axes
Capability grades
15 of 15 axes rated · 8 graded A or B
A core banking company trading since 1993 whose model layer arrived in 2025 and 2026. Strip the models and everything remains: the core ledger, digital channels, payments, wealth and financial crime products that more than 950 banks already run.
The vendor states the position itself, which makes this the same easy call Red Oak was, arguing that banks do not need artificial intelligence added on top of critical systems but intelligence built into the products and workflows they already trust. Included on the Clearwater and MyComplianceOffice precedent because the models sit inside regulated operations rather than around them, screening sanctions cases and disposing of financial crime alerts.
Sequencing is stated clearly and repeatedly, in the company's own formulation that the agents do the work and humans handle the judgement, alongside a stated commitment that agents operate while maintaining auditability and human oversight and three named non negotiables, explainable, auditable and governed. Conversational Studio is described as a governed build environment.
This is assertion at a consistent and senior level rather than description, which is precisely the Ruleguard position: no gate, threshold, confidence measure, escalation path or sampling audit is described for any agent, and an agent disposing of more than twenty percent of sanctions alerts is operating a threshold whether or not one is published.
No accuracy, precision or recall figure, benchmark or validation method was located for any agent, and none of the four properties this index accepts as evidence of model risk discipline is present. The financial crime agent is said to significantly reduce false positives, which names one error direction without a number and says nothing about the other.
The sharpest version of the gap is in the company's own investor material, which tells the market that the cost of errors in this domain is existentially high and that deterministic decision making is a must. A vendor that can state the stakes that precisely, to investors, and publish no error rate for the agents disposing of sanctions alerts, has made a disclosure choice rather than met a measurement obstacle.
Named customers with quantified outcomes, plus audited public financial disclosure as a listed company, which is the independent party with money at stake the bar contemplates. VPBank in Vietnam, a client since 2006, completed one of that country's largest core migrations in 2025 covering more than 18 million customer accounts, and Copilot for Core was co developed with Banque Internationale a Luxembourg and a large United States regional bank.
One qualification belongs on the record and it is the interesting part: the platform evidence is A grade and the model layer evidence is not. The single quantified deployment figure for the agents, a tier one bank processing hundreds of thousands of sanctions cases with more than twenty percent of alerts automated, is attached to an unnamed institution, and an automation rate measures how much work the model took rather than how well it did it.
No statement was located on training data, retention, or whether models learn across the banks on the platform. The company operates a single code base accessible to all clients, which is an efficiency argument that raises rather than answers the isolation question for a model layer embedded in that code base.
Its own investor material states zero tolerance for hallucinations and existentially high cost of errors, so the seriousness of the problem is understood and published while the boundary that would address it is not.
The strongest privacy position in this pocket and it rests on an external credential rather than an assurance. The company holds ISO 27018 certification, which covers protection of personal information in public cloud services, and has made a declaration of adherence to the European Union cloud code of conduct implementing Article 28 of the General Data Protection Regulation, verified by an accredited monitoring body whose verification report is published.
A security schedule sets out processing obligations and points to location specific coverage. Off an A because none of it is specific to the model layer: nothing describes what customer data the agents process, what is retained from an agent interaction, or the position of the bank end customers whose records those agents read.
The most complete security disclosure located in this sweep, and every noun is the right one. Certification under ISO 27001, ISO 27017, ISO 27018 and ISO 22301, with an annual audit of all mandated requirements inside the three year certification cycle. Attestation reports under SOC 1, SOC 2 and SOC 3 are made available to existing and prospective customers.
Recognition as a trusted cloud provider by an independent cloud security body, and an externally verified declaration of adherence to the European cloud code of conduct with the monitoring body's verification report published. A security schedule and a set of information security requirements are published rather than described, clients are permitted to commission their own external security testing of the cloud services by agreement, and an internal audit function is named. Held short of nothing material: reports are released to customers rather than posted publicly, and no subprocessor list was located.
A software vendor holding no financial licence of its own, with no supervisory programme, sandbox admission or regulator run assessment of the model layer located. Its clients carry the authorisations. Being listed brings securities disclosure obligations, which are real but are not a financial services licence and say nothing about the products.
Explainable, auditable and governed are named as non negotiables and no framework, bias testing, fairness evaluation, model documentation or independent assessment of an artificial intelligence management system was located behind them. A specific trap is worth recording here because this vendor sets it well: it holds strong independent ratings for sustainability and corporate responsibility, and those are environmental and governance ratings of the company, not assessments of its models.
Crediting them on this axis would be a category error. Corlytics set the A with an independently audited certification of an artificial intelligence management system, and a company already certified under four information security standards plainly knows how that process works.
Nothing published describes liability, indemnity or recourse when an agent embedded in a core banking or financial crime workflow produces a wrong result. The exposure is concrete rather than theoretical: an agent automating disposal of sanctions alerts sits directly on a regulated obligation, and both failure directions land on identified people, either a customer wrongly restricted or a screening obligation quietly unmet. No contest route, appeal path or allocation of loss was located for either.
More disclosure than most of this category, at the infrastructure layer rather than the model layer. The agent stack is publicly described as integrating a named hyperscaler's artificial intelligence services and a named accelerator vendor's microservices, and the model context protocol implementation is named as the integration mechanism, so a buyer can see which suppliers sit under the platform.
Off an A because no base model, provider or version is named for any agent or copilot, and the banking knowledge graph and agentic framework carry no stated provenance, so an institution still cannot record which model version produced a given decision.
This is the core system other vendors integrate into, delivered from a single code base with an interface first architecture and 316 go lives in one year. Integration is being rebuilt around the model layer rather than bolted beside it: a banking knowledge graph provides shared context, and a model context protocol implementation is described as the connective tissue between every system, letting models discover capabilities instead of requiring bespoke integrations. Implementation capacity is evidenced too, with roughly 700 internal consultants and 7,000 certified consultants across partner organisations.
Deployment choice is stated plainly and is the widest in this category: the software can be hosted on premises, on any private or public cloud, or consumed as software as a service on the vendor's own banking cloud, with cloud to cloud configurations offered for resilience. Certification and attestation coverage is documented as location specific in an annex to the published security framework.
Off an A because no residency regions are named in the public material located, and nothing states where the model layer itself executes, which is the specific gap Ruleguard closed to earn the A on this axis.
No pricing, band or rate is published for the platform or the model layer. As a listed company it discloses far more about its own commercial shape than any private peer in this category, reporting annual recurring revenue, the split between subscription, software as a service, term licence and maintenance, and growth by line, which tells a buyer a great deal about vendor viability and revenue model. None of that is a price. Nothing public indicates whether the agents and copilots are bundled, licensed separately or charged by consumption.
More than 950 banks across retail, corporate, commercial, wealth and Islamic banking segments, with 316 customer go lives recorded in 2025 and ranked the leading core banking provider by an independent industry research house for twenty one consecutive years. Regional sales rankings place it first in Europe, Latin America, the Middle East and Africa and second in North America for 2026. Coverage is anchored to counted deliveries and independent league table position rather than asserted, and named clients span Vietnam and Luxembourg among others.
Alternatives to Temenos
The closest documented capability profiles to Temenos in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Stronger documented coverage on Autonomy and Oversight Model
A lighter documented profile than Temenos
Documents AI Centrality and AI Safety and Data Stewardship where Temenos does not
Documents AI Centrality where Temenos does not
Documents AI Centrality where Temenos does not
A lighter documented profile than Temenos
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.