Unit21
Unit21 consolidates fraud prevention and anti money laundering into one platform covering real time transaction monitoring, entity and network analysis, customer risk rating, case management and regulatory filing. Risk teams author detection logic through a no code interface without engineering support, machine learning scores expose which variables drove each alert, and configurable agents carry investigations from signal through evidence collection and narrative drafting to a regulator ready filing with a full audit trail.
Capability Axes
Capability grades
15 of 15 axes rated · 8 graded A or B
Machine learning does substantial work here, scoring risk with variable level attribution and driving agents that execute investigations end to end, and the company frames its current architecture as AI at every stage of the risk lifecycle rather than a bolt on. The substrate underneath is a no code rules engine, a connected entity data model and case management, which is what the product was before the agents arrived and what a customer still operates day to day when tuning thresholds. Apply the removal test and a working detection and investigation platform remains, which places this with the orchestration and rules vendors rather than the model native ones.
This is among the most automated products in the index and it carries the oversight architecture to match, which is why the grade holds. Agents are configurable rather than fixed, investigations are described explicitly as executed by AI with a human in the loop, every decision is mapped to the institution's own policies and traceable by an investigator, auditor or regulator back to the logic that produced it, and controls are tested before they go live rather than after.
Buyers should still probe one thing hardest: agents draft the narrative of a suspicious activity report, and a filing is a legal attestation by the institution, so the sign off step between machine drafted reasoning and submission is the control that matters most and is the least described.
The alert level disclosure is the strongest in the index on this axis. Customers are given visibility into how a machine learning score was generated including which variables contributed, models are described as fully explainable and auditable, decisions are mapped to documented policy, and controls are tested before deployment rather than validated retrospectively. A validator can therefore interrogate both the logic and an individual output without vendor assistance.
What remains absent is the package itself: no model documentation, no validation summary, no published accuracy, recall or false negative figures, and no stated position on supporting a customer's own validation under supervisory model risk guidance.
The customer roster is strong and named, spanning a large consumer neobank, a tax software company, a student lending institution, a prepaid and banking platform and major crypto exchanges, with deployment stated at more than 200 institutions and a traceable growth path from roughly 150 platforms several years earlier. Performance claims are specific, citing false positive reduction of up to 93 percent and handle times cut by 80 percent, with decisioning under 250 milliseconds.
The gap that keeps this off the top grade is attribution: those figures appear as vendor aggregates rather than as a named institution's measured result, so no reader can trace a number to a deployment. The company does publish original industry survey research.
Transparency is treated as a product requirement rather than a promise. The company states that its models are fully transparent and audit ready, that every alert is traceable with no black box risk, and that each AI decision is mapped to the customer's own policies and backed by documented risk reasoning and evidence. For a system whose outputs support account restrictions and regulatory filings, committing to reconstructable reasoning is the right stewardship posture.
What is not addressed is the data boundary: nothing states whether detection learning derived from one institution informs models serving another, whether the data agnostic architecture implies per tenant isolation, or which model providers sit behind the agents.
The platform ingests first and third party data across transactions, devices, entities and customer records for more than 200 institutions, and its data agnostic architecture is designed to absorb whatever a customer already holds, which by construction widens rather than narrows the data footprint. Sponsor bank deployments add a further dimension, since one platform tenant holds data spanning many fintech partner programmes. No published privacy framework, retention schedule, subprocessor disclosure or service provider position was located in this pass.
This pass located no trust centre, enumerated certification list, attestation scope or audit period on the public site. The platform holds transaction, device and customer data for more than 200 institutions including regulated banks and sponsor banks whose vendor risk programmes would require attestations before onboarding, so the published record almost certainly understates the control environment. The grade reflects what a buyer can verify without entering a sales process and should be revisited if a trust surface is published or located.
Unit21 supplies software and holds no licence, the expected posture, and its regulatory grounding is unusually precise. The product generates suspicious activity and currency transaction reports, handles information sharing requests under the specific statutory provision that lets the financial intelligence unit query institutions directly, runs sanctions list screening, and addresses clearing house rules for payments customers.
Naming that information sharing provision rather than gesturing at anti money laundering generally is a marker of real domain depth. The filing obligation remains the institution's, which the material states correctly.
Explainability here is better than most, since a reviewer can see which variables contributed to a given alert rather than receiving a bare score, and that genuinely helps contest an individual decision. The unexamined risk sits in a marketed feature.
The platform lets customers create tailored risk scores for different customer segments, such as small businesses, low touch users or groups designated high risk, which is operationally sensible and is also precisely where uneven treatment enters a system without anyone testing for it. Nothing public offers false positive rates by segment, demographic analysis, or guidance on validating that segmentation does not encode proxies.
Traceability is genuinely strong: every decision is mapped to the institution's own policies and can be reconstructed by an investigator, auditor or regulator, which means a wrong outcome can be identified and unwound internally. The vendor stands behind none of it.
No accuracy guarantee, no remediation term, and no correction route for a customer restricted or reported on the strength of an agent assembled investigation, which matters more where agents draft the narrative of a legal filing.
The data agnostic architecture is explicitly designed to consume whatever first and third party sources an institution already holds, which means the customer largely owns and knows its own chain rather than inheriting a bundled one, and a named banking core partnership shows one route in. What is not published is the vendor side of it: no model providers named for the agents, no subprocessor list, and no statement on where investigation content is processed.
The data agnostic architecture is the integration strategy: rather than requiring a canonical format, the platform ingests what an institution already has and transforms raw records into a connected entity model enriched with behavioural and device signals.
Connections run to core banking systems and payment channels with rapid deployment claimed, and a named partnership with a cloud native banking core serves banking as a service and embedded finance programmes, letting sponsor banks and their fintechs feed first and third party data into one place. Public developer documentation, a status page, a changelog and a named partner directory were not located in this pass.
Delivery is cloud hosted software as a service serving institutions globally, and payments customers are explicitly told the platform lets them operate globally while complying locally, which is a residency and jurisdiction claim in substance. It is not supported by any published detail: no hosting regions, no in country residency options, no transfer mechanisms, no tenancy separation description and no subprocessor list were located in this pass.
No rates, tiers, billing unit or minimum are published and every path leads to a demo request. The omission is worth noting against the product's own argument, which is that it replaces several fragmented tools with one system and removes engineering dependency, both of which are cost claims a buyer cannot evaluate without a number to set against the licences and headcount being displaced.
Six buyer types are addressed with genuinely different material rather than a shared page: banks, credit unions, sponsor banks, neobanks, payments fintechs and crypto businesses, each framed around the obligations that actually bind them, from clearing house rules and cross border complexity for payments firms to wallet takeover and sanctions evasion for crypto.
The sponsor bank capability stands out, letting an institution customise rules per fintech partner and maintain oversight across a portfolio from one platform, which addresses the supervisory pressure on bank and fintech partnerships more directly than anything else in this index.
What Changed
Material product, regulatory, evidence and commercial changes at Unit21, each verified against a live source and tagged to the capability axis it bears on. Funding rounds and awards are not product changes and are not logged.
Unit21's August product update, published 8 September, puts a remote MCP server live so that Claude, ChatGPT, Cursor or any other MCP client can connect directly to a customer's Unit21 environment. Webhook payloads are no longer fixed to a set list of fields and can be customised, goAML filing expands to Malta and the Netherlands, and the post closes two long standing gaps in CTR filing.
Unit21 introduced AI-powered SAR Agents that draft FinCEN-ready narratives directly into a SAR filing by synthesizing case data, alerts, and notes. The release also expanded real-time Payments Screening to cover PEP and adverse media watchlists, aligned goAML filing workflows with the SAR form generator, and introduced updated routing for alert auto-assignment.
Compared With
Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Alternatives to Unit21
The closest documented capability profiles to Unit21 in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Stronger documented coverage on Operational and Outcome Evidence
Stronger documented coverage on AI Centrality and Operational and Outcome Evidence
Documents Commercial Transparency and Security Certifications and Trust Center where Unit21 does not
Documents AI Governance and Bias Disclosure where Unit21 does not
Documents GLBA and Data Privacy Posture and Security Certifications and Trust Center where Unit21 does not
Stronger documented coverage on Operational and Outcome Evidence and Core Systems and Integration Depth
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.