Agentic Screening Market Map

Evaluating AI agent vendors across AML/KYC screening and alert adjudication workflows.

14

8

4

Criteria

Vendors

Quadrants

Introduction

Do You Need a Market Map?

The term “AI agent” is now widely used across the AML/KYC market, but it does not mean the same thing from one vendor to the next. Products sold under the label include general-purpose AI chatbots, case summarization features added to existing platforms and purpose-built agents designed for specific financial crime compliance workflows. The label alone does not tell a buyer what work the product can do.

To define the market, we reviewed over 70 vendors with input from our investors, who collectively represent over 100 financial institutions. For this market map, we looked at whether each company offers AI agents built specifically for AML/KYC screening alert review and adjudication workflows, and whether those agents were central to its offering. White-labeled products, generic LLM connections and AI tools that only summarize cases were excluded.

Fourteen vendors met the criteria for inclusion. The market map compares them on two axes evaluating eight criteria:

  • Agentic screening capabilities: Which risks and alert review workflows can the agent handle, from initial alert review through enhanced due diligence? Can it gather evidence and apply the institution’s procedures? What data infrastructure supports its decisions?

  • Governance and reliability: Can the institution test the agent’s performance, trace its decisions to supporting evidence and maintain the records required for ongoing oversight?

The map provides a consistent framework for understanding how these vendors differ.

Market Map

14 Vendors Evaluated across Screening and Adjudication

Agentic Screening: Mapping the AI Agent Market for AML/KYC

Agentic Screening: Mapping the AI Agent Market for AML/KYC

Y axis - Agentic screening capabilities: Vendor data and screening ownership, alert adjudication coverage and depth.

X axis - Governance and reliability: Independent validation and MRM, agent training on client SOPs and decision consistency.

Using the map: Select any company on the market map to view additional details.

Quadrant chart of 14 AI agent vendors in AML/KYC screening, plotting agentic screening capabilities against governance and reliability. Select a marker to view that company’s profile.

Accuracy, Consistency, Explainability are Critical for Agent Effectiveness

A faster review has little value if the agent misses relevant risk or an institution cannot defend the agent’s decision with enough evidence. Fewer alerts mean little if the same case produces a different decision on the next run. The eight criteria examine what it takes to make an agent accurate, consistent and fit for regulated work.

  • Accuracy depends on the risk specialization and how thoroughly the agent reviews each alert as well as on the quality and freshness of the risk data behind each agent.

  • Consistency depends on whether the agent follows the institution’s procedures and produces repeatable decisions.

  • Regulatory alignment requires a complete record of the evidence and reasoning behind each decision, and independent validation and model risk management support.

Evidence of live use shows whether capabilities are available today and if it can be trusted in live regulated environments. Compatibility is reported separately because it affects implementation, not the quality of the agent’s decisions.

Vendor Profiles

Top AI Agent Vendors for AML/KYC Screening and Adjudication

The vendors below met our inclusion criteria for purpose-built AI agents supporting screening and alert review. Each profile summarizes the capabilities, data dependencies, governance evidence and deployment model that informed its placement. Categories reflect performance against this specific use case, not the vendor’s broader AML/KYC offering.

Castellum.AI

Trusted

Castellum.AI owns the risk data and matching technology available to its Arbiter alert-resolution agents. Arbiter reviews alerts generated by an institution’s screening system, applies the institution’s written policies and procedures, and produces a documented disposition with supporting evidence and rationale. 

When an alert requires additional investigation, Arbiter can run supplementary searches against Castellum.AI’s sanctions, PEP, adverse media and watchlist data using its matching capabilities. This gives the agent native access to current risk data rather than limiting its review to the information contained in the original alert or relying on data licensed from third-party providers.

Castellum.AI’s placement reflects four core capabilities:

  • Owned and current risk data: Castellum.AI owns its sanctions, PEP, adverse media and watchlist data. Risk data is refreshed every five minutes, and adverse media coverage draws from more than 200,000 sources.

  • Native supplementary search: Arbiter agents can use Castellum.AI’s risk data and matching capabilities to gather additional evidence while investigating an alert.

  • Institution-specific adjudication: Arbiter applies each institution’s policies, thresholds and procedures when investigating and dispositioning alerts and can be updated as those requirements change.

  • Independent validation and ongoing testing: Castellum.AI provides third-party validation results and continuous testing documentation that institutions can incorporate into their own model risk management review.

Clients include a top four US bank, a top five global payments company, Lead Bank, Persona and other regulated institutions.

Bretton AI

Trusted

Bretton AI develops agents for KYC and KYB reviews, AML and sanctions investigations and ongoing transaction monitoring. It offers both software deployments and a managed-service model. Under the managed-service model, Bretton analysts review the agents’ output before the results are delivered to the institution. Bretton uses third-party providers for its underlying risk data and business verification, including LexisNexis Risk Solutions and Middesk.

Silent Eight

Trusted

Silent Eight’s Iris platform provides agentic AI-driven alert adjudication across sanctions, AML, fraud and due diligence workflows. Silent Eight develops its own matching and investigation technology but licenses the underlying watchlist data from external providers. Model validation is conducted internally by Silent Eight.

Sphinx

Trusted

Sphinx offers browser-native AI compliance agents that work through the browser interfaces of the systems an institution already uses. Its agents can log into existing systems, including through native connections to Verafin and Jack Henry, without requiring a separate integration. Sphinx also offers Frontline, a managed-service model that delivers completed outcomes, including cleared cases and filed suspicious activity reports (SARs).

WorkFusion

Innovators

WorkFusion offers pre-built AI Digital Workers for Level 1 and selected Level 2 compliance tasks. Its agents support sanctions, PEP and adverse media alert review, KYC processes and transaction monitoring. WorkFusion relies on integrations with external screening systems and data providers for the underlying alerts and risk information.

Published user reviews report that deployments can require substantial training and support from WorkFusion before go-live. Some reviewers also cite limited integrations and functionality compared with other products they evaluated.

Themis

Innovators

Themis provides AML and due-diligence software across more than 30 modules. Its proprietary sanctions, PEP and adverse media data is refreshed every six hours and draws from official sources, including regulatory bodies, law enforcement agencies and policy institutions. Data coverage includes detailed criminal-conviction records and received one of the highest domain-coverage scores in our evaluation.

The AI Investigator product uses this data to automate parts of the investigation process. Level 2 and Level 3 decisions are delivered by human reviewers rather than AI agents. We did not identify a named independent validator. Themis is designed to replace an existing compliance system. Themis primarily serves small businesses and corporations rather than regulated financial institutions.

Axle

Specialists

Axle offers named AI agents for screening and transaction monitoring alert review, customer onboarding, enhanced due diligence and SAR narrative drafting. Its agents connect to an institution’s existing alert sources and rely on the data supplied by those systems.

spektr

Specialists

spektr provides no-code compliance automation for KYB and KYC onboarding, ongoing risk monitoring and case management. Its modular AI agents review documents, identify business networks and conduct source-of-funds checks.

The agents access the information required for these tasks through integrations with third-party data providers rather than data owned by spektr.

Roe AI

Specialists

Roe AI provides a browser-based investigation agent that works inside an institution’s existing consoles and case management systems rather than replacing them. It compiles the investigation and supporting evidence into a case file, cites each piece of evidence to its source and produces an audit trail that can be exported to a governance, risk and compliance (GRC) system.

Roe focuses on investigation automation and evidence traceability. It depends on the institution’s existing systems for screening data, alert generation and ongoing monitoring.

Footprint

Specialists

Footprint’s Percy agentic system builds agents from an institution’s written procedures for watchlist alert review, adverse media investigations, enhanced due diligence and ongoing monitoring. Institutions can test the agents against previously resolved cases. During an investigation, Percy pulls information from connected sources, cross-references findings and records the steps and reasoning behind its conclusions.

Percy connects to external data providers including LexisNexis, Experian and ComplyAdvantage. Footprint’s Trust Fabric makes prior case decisions available across compliance workflows and lets teams inspect the policy and evidence behind each finding. No named third-party validator was found in public sources.

Diligent AI

Newcomers

Diligent AI develops agents that review KYC and AML screening alerts, investigate merchant risk and support customer onboarding workflows. Its agents integrate with an institution’s existing screening and case management systems rather than replacing them.

Arva AI

Newcomers

Arva AI provides agents for AML, KYB and screening alert review. The company has an independent validation partnership with FairPlay, an AI assurance firm, covering its AML and KYB use cases.

Variance

Newcomers

Variance provides investigative agents for fraud, KYC, KYB, AML and transaction monitoring. The agents use an institution’s internal policies and procedures to guide their work and connect to external data sources for the risk information used during an investigation.

Tangos AI

Newcomers

Founded in 2025, Tangos AI develops agents for financial crime investigations. Its agents begin working after an alert has been generated and escalated for review. They gather evidence and compile case files for investigators rather than performing the initial detection or alert generation.

Buyers Guide

How to Evaluate an AI Agent for AML/KYC Screening

Evaluate capability and governance as separate requirements. A product demonstration can show what an agent does. It cannot establish that the agent is accurate, consistent and controllable in a live operational environment. Use the questions below to see how those capabilities fit your institution’s workflow and oversight requirements.

Agentic Screening Capabilities

Which risk workflows does the agent support?

Sanctions, PEP, adverse media, onboarding, EDD and ongoing re-screening require different data and investigation methods. Evaluate coverage and agent effectiveness for each risk type during proof-of-concept testing. Broad claims about “screening” should not substitute for results by domain.

How does the vendor define agentic?
Does the vendor incorporate an agentic harness around an LLM, or is it a wrapper? How does the architecture ensure recall and repeatability of decisions? Having structured guardrails around an agent ensures decisions always follow your policies and procedures.

Which parts of alert review can the agent perform?

Determine whether the agent only summarizes information, gathers evidence, recommends a decision or independently dispositions alerts. Ask how it applies your policies and thresholds, what work still requires an analyst and when human approval is required.

What data does the agent use during an investigation?

Establish whether the agent relies only on the information contained in the original alert, searches data owned by the vendor, queries third-party providers or simply checks public web-based sources. Ask who maintains the data, how frequently it is updated and how the agent handles incomplete or conflicting information. A vendor should be able to trace every AI decision to its supporting sources.

Can it work with your existing systems?

Determine whether the agent can operate with your current screening and case management systems or requires you to replace them. Ask for an implementation timeline based on your specific environment and references from institutions with a comparable size and technology stack.

Governance and Reliability

Has the agent been independently validated by a third-party, or does the vendor self-attest?

Internal testing is not the same as independent validation. Ask who performed the validation, what use cases and risks were tested, when the work was completed and whether identified issues were remediated. Review whether the methodology aligns with the guidance and frameworks relevant to your institution, such as SR 11-7, the NIST AI Risk Management Framework or ISO/IEC 42001.

The institution remains responsible for model risk management. The vendor should provide testing results, methodology and supporting documentation that your teams can incorporate into their own review.

What does a decision journal actually look like?
A disposition code and timestamp alone are not a sufficient audit trail. Ask to see a complete decision record. It should identify the input data, sources consulted, policies and thresholds applied, actions taken, final disposition and a confidence score or supporting rationale.

How does the agent handle edge cases, or does it escalate everything?
Ask how the agent distinguishes an acceptable deviation from a real anomaly and how those thresholds are aligned with your policies. Test difficult edge cases during proof-of-concept testing, such as fuzzy name and attribute alerts, transliterated PEP aliases and renamed sanctioned entities.

How are prior decisions retained and reused over time?
If the same subject triggers another alert, determine whether the agent considers the previous investigation or starts from scratch. If prior decisions are reused, ask how the agent checks for changes in risk data, customer information and institutional policy before relying on them.

How is model drift monitored and controlled?

Ask how the vendor monitors performance drift as models, underlying data or your policies change. Review how analyst feedback (tags, overrides, corrections) is recorded, whether updates require testing and approval and whether every change is version-controlled and reversible. "The model keeps learning" is not a reliable assurance without formal change control and a documented rollback process.

Can the agent produce repeatable results?

Ask the vendor to run the same representative cases multiple times and report how often the agent reaches the same disposition using the same evidence. What deterministic controls are there to ensure consistency? Castellum.AI reports decision consistency across repeated runs in the FinCrime Agent Benchmark. For vendors without comparable published results, request their test results and documentation showing how those controls work. Do not rely on broad claims about “consistency” or “recall.”

For a more detailed agent evaluation framework, download our Guide to Agentic Alert Resolution.

Methodology

How the Map Is Built

Each vendor is scored from 0 to 100 across eight criteria. The results are combined into two axes: agentic screening capabilities, which measures the vendor’s support for the screening and alert review process, and governance and reliability, which measures whether the agent’s decisions can be validated, explained and governed.

The map covers sanctions, PEP, adverse media and other watchlist screening, alert investigation and adjudication, ongoing re-screening as well as the data and controls supporting those activities. Transaction monitoring, fraud detection, SAR and STR filing, standalone case management, credit, underwriting and disputes are outside its scope.

On the inputs. Scores are based on publicly available information, including vendor websites, product documentation, funding announcements, press coverage and independent analyst research. When a capability could not be verified through a public source, it is recorded as not confirmed in public sources, rather than described as absent.

Evaluation Criteria

  1. Risk data coverage and control: Whether the vendor owns or licenses its sanctions, PEP, adverse media and watchlist data; how frequently that data is updated; and whether it controls the technology used to identify potential matches.

  2. Screening domain coverage: Support for sanctions, PEP, adverse media, other watchlists and ongoing re-screening.

  3. Screening adjudication coverage: Support for Level 1, Level 2 and enhanced due diligence, weighted by whether each capability is available for use or still in development.

  4. Consistency and explainability: Evidence that the same inputs produce the same decision across repeated runs. Apart from Castellum.AI, we found no published consistency test results among the vendors reviewed, so this score is based on publicly documented architecture and governance controls.

  5. Validation and model risk management: Whether a named third party has validated the agent, whether testing aligns with relevant guidance or frameworks such as SR 11-7, the NIST AI Risk Management Framework or ISO/IEC 42001 and whether the vendor supplies evidence institutions can incorporate into their own review.

  6. Client-specific training and tuning: Whether the agent applies the institution’s written policies, procedures and thresholds, produces a case-specific rationale and retains the evidence chain supporting each decision.

  7. Integration with AML/KYC stack: Whether the agent can work with an institution’s current screening and case management systems without replacing them. This criterion is shown for each vendor but is not currently weighted in either axis.

  8. Regulated financial institution clients: Evidence of live use by named financial institutions, the types of institutions served and their regulatory tiers, how long the product has been in production and whether cited capabilities are available today or remain on the roadmap.

Axis Weighting

Agentic screening capabilities (vertical):

  • 40% risk data coverage and control

  • 30% use by regulated financial institution clients

  • 15% screening domain coverage

  • 15% screening adjudication coverage

This weighting favors data and screening control, evidence of live use and capabilities available today above broader roadmap claims.
Governance and reliability (horizontal):

  • 50% validation and model risk management

  • 30% client-specific training and tuning

  • 20% consistency and explainability

This weighting reflects the evidence an institution needs to validate the agent, understand its decisions and maintain oversight after deployment.

Quadrant boundaries are set at 60 on both axes.

Frequently Asked Questions

Common Questions

From market map to actual workflow

See how Castellum.AI agents handle alert review, investigation and adjudication in one workflow.

“Castellum.AI is one of the most nimble vendors I’ve ever worked with, and they care about your ideas. Unlike other providers where you submit a ticket and wait weeks for a response, the team is always readily available for assistance and technical support. They put out a great product that allows us to truly own the risk and the process.”
— Daniel Schneider, Director of Financial Crimes, BSA Officer, SVP, Lead Bank