Skip to main contentSkip to footer

    Top Rated & Verified

    Top Clutch App Development Company Black Owned United StatesTop Clutch Java Developers France 2026Top Clutch Service Line Blind Company Black Owned 2026Top Clutch App Development Company Minority Owned 2026Top Clutch Web Developers Black Owned 2026Top Clutch App Development Company Black Owned 2026Top Clutch Flutter Developers France 2026Top Clutch Health & Wellness App Developers France 2026Top Clutch Swift Company France 2026Top Clutch Machine Learning Company France 2026Top Clutch Chatbot Company France 2026Top Clutch Artificial Intelligence Company France 2026Top Clutch App Development Company Minority Owned Los Angeles
    Back to Blog
    AI Agent Rankings
    August 23, 2026
    32 min read

    Top 10 AI Agents forCredit Unions in 2026

    Every ranking in this category scores containment, deflection and approval lift. Every one of those numbers is published by a vendor about itself — and two federal agencies now repeat one of them as though it were measured. This ranking scores only what your board can check before it signs.

    AI agents for credit unions and community banks in 2026 — ranked on verifiable attestations, documented core integrations and pricing disclosure
    2017
    Year of the Juniper Research forecast that both the CFPB (2023) and GAO (2025) cite for chatbot cost savings — a forecast, stated as measurement
    CFPB, Chatbots in consumer finance, fn 14; GAO-25-107197, fn 22; Juniper Research press release, July 24, 2017
    70%
    Share of depository institutions served by the three largest core providers in 2022; the largest alone served 42%
    OCC, Request for Information, 90 FR 54882 (Nov 28, 2025), citing Federal Reserve Bank of Kansas City research
    0
    Occurrences of AI, artificial intelligence or machine learning in NCUA's 2026 Supervisory Priorities letter, across 2,373 words
    NCUA Letter to Credit Unions 26-CU-01, January 2026, word-boundary counted August 23, 2026
    1 of 12
    Vendors examined that publishes a price — Hapax. Every other pricing cell in this article reads not publicly disclosed
    Frenchy Digital vendor documentation review, checked August 23, 2026

    Key Takeaways

    • The CFPB's 2023 chatbot spotlight and GAO-25-107197 cite the same source for chatbot economics: a Juniper Research press release of 24 July 2017. It is a forecast, not a measurement, the underlying report is paywalled with no published methodology, and the widely quoted per-interaction figure does not appear in it at all.
    • GAO relays two vendor claims unchallenged — a 40 percent increase in credit approvals for women and people of color, and a time reduction of up to 67 percent — each attributed only to representatives of one AI provider. Neither is a GAO finding, and neither should be cited as one.
    • NCUA cannot examine your AI vendor. The Examination Parity Act authority expired on 31 December 2001 and has not been restored — yet 12 CFR 748.1(c) still requires you to report the vendor's breach to NCUA within 72 hours of being notified.
    • Regulation B no longer contains the disparate-impact effects test. The final rule at 91 FR 21620 took effect 21 July 2026. It is in force, challenged in NFHA v. CFPB, and not enjoined — the plaintiffs never sought an injunction. The adverse-action machinery at 12 CFR 1002.9(b)(2) was not touched.
    • The Upstart figures everyone cites as a CFPB finding were disclaimed by the CFPB in writing: the simulations and analyses were not separately replicated by the Bureau. Upstart's FY2025 10-K contains zero occurrences of the claim, and the No-Action Letter was terminated on 8 June 2022 at Upstart's own request.
    • One genuine independent evaluation exists in this vertical — the Relman Colfax fair-lending monitorship of Upstart, four reports from April 2021 to 27 March 2024. It found no proxying, but approval disparities for Black applicants and a likely viable less discriminatory alternative, and it ended at an impasse. No independent benchmark of any commercial AI agent product in banking exists.
    • Of twelve vendors examined, exactly one publishes a price: Hapax, at $2.50 per credit pay-as-you-go or $150 per month for Pro with 85 credits included. Every other pricing cell reads not publicly disclosed.
    • Zero of seven major AI vendors checked appear in the Fiserv DNA AppMarket, and Jack Henry states plainly that not every fintech integrates to all cores. Any Jack Henry credit union can settle an integration claim with one email to VendorQA@jackhenry.com.
    • Frenchy Digital cost bands: discovery and workflow audit $9k–$22k in 2–4 weeks; single-workflow agent $28k–$70k in 4–9 weeks; multi-workflow platform with system integration $70k–$180k in 9–16 weeks; enterprise, multi-site or regulated build $180k–$420k+ in 14–24 weeks.

    The Claim Under Test — Two Federal Agencies, One 2017 Vendor Forecast

    The CFPB's 2023 issue spotlight on chatbots in consumer finance and the Government Accountability Office's GAO-25-107197 cite the same source for the economics of conversational AI in banking: a Juniper Research press release dated 24 July 2017.

    It appears at footnote 14 in the CFPB spotlight and at footnote 22 in the GAO report. It is not a study. It is a forecast, and it says so in its own first line:

    Juniper forecasts that chatbots will be responsible for cost savings of over $8 billion per annum by 2022, up from $20 million this year.

    Juniper Research press release, 24 July 2017 — the Wayback capture GAO itself cites

    The underlying report is paywalled and no methodology is published anywhere. And the figure that travels furthest from it — roughly seventy cents saved per interaction — does not appear in the release text at all. Both agencies present the economics as settled. Neither measured anything.

    That is this article's thesis, proven at the highest level available: a vendor produces a number, a credible institution repeats it with the attribution intact, and every downstream writer drops the attribution. By the time it reaches a board packet it looks like a federal finding. The same pattern is the reason this ranking scores contract terms, attestations and documented integrations rather than performance — the approach we take across our whole AI agent ranking series, and one you can apply to any vendor pitch that lands on your desk this quarter.

    GAO relays two vendor claims unchallenged in the same report. Neither is a GAO finding.

    The first, verbatim: representatives of one AI provider told us that credit unions that implemented its AI model reported a 40 percent increase in credit approvals for women and people of color. The second, in the same register: one AI provider told GAO its model reduced the time required for a process by up to 67 percent. Both are attributed inside the sentence — GAO did its job. Do not cite either as a GAO finding. If you see one presented that way in a vendor deck, that deck has an attribution problem, and it is unlikely to be the only one.

    The CFPB's other headline figures are equally derivative, and worth knowing because they turn up constantly. The claim that over 98 million users, roughly 37 percent of the US population, engaged with a bank's chatbot in 2022 is itself sourced to Insider Intelligence, a paid research firm, writing about one bank's assistant — attribute it that way. The claim that 80 percent of consumers who interacted with a chatbot left feeling more frustrated traces to a Forbes contributor column reporting a survey by a contact-centre vendor, with no sample size published. What the CFPB document does verify in its own voice is narrower and more useful: each of the top 10 largest commercial banks has deployed chatbots.

    This is not a hypothetical failure mode. A US regulator has already found that exactly this kind of number was materially misleading. In the Matter of Presto Automation Inc., Securities Act Release No. 11352 and Exchange Act Release No. 102177, decided 14 January 2025, is believed to be the SEC's first AI-washing enforcement action against a public company. Presto told investors its drive-thru voice AI delivered over 94% accuracy even in noisy environments. The SEC found the product lacked the capability to take orders on their own and required substantial human involvement, with human order takers located abroad, primarily in the Philippines and India, who processed the vast majority of drive-thru orders.

    The framing matters and is routinely mangled. Presto consented without admitting or denying the findings. The remedy was a cease-and-desist order with no civil penalty — nobody was fined. The findings are against Presto only; the order's Supplier A is a separate company against which the SEC made no findings whatsoever. And Presto Automation Inc. is not Presto Phoenix Inc. Read narrowly, the order still says the thing that matters here: the one time a US regulator actually audited a vendor's published AI performance metrics, the metrics did not survive contact.

    So the ranking below scores nothing that a vendor published about its own performance. No containment rate, no deflection rate, no approval lift, no hours saved, no ROI. Those are the columns every competing listicle fills, and not one cell in any of them is checkable by you.

    How We Ranked, and What We Refused to Rank On

    Everything scored below is something you can re-check yourself in about thirty minutes, from public sources, without an NDA. Everything refused is something only the vendor can assert.

    Date checked: 23 August 2026. Vendor pages change without notice, and several in this set changed materially during 2026. Re-check before you sign, not before you shortlist.

    Scored attributeHow you re-check it
    Documented public integrationsThe core provider's own partner directory — not the AI vendor's logo wall
    Whether a DPA is publicly offeredThe vendor's legal or trust page
    SOC 2 Type II / ISO 27001 status, and whose certificate it isThe vendor's trust centre, reading the certificate's named legal entity
    Named auditor and audit periodThe attestation letter or trust portal — a Type II report covers a window
    Pricing transparencyThe vendor's pricing page. If it is gated, the cell reads not publicly disclosed
    Locked to a suite vs standaloneProduct documentation and the reseller relationship
    Ownership and funding from public recordSEC filings, press releases, the acquirer's newsroom
    Data residency, retention and subprocessorsThe DPA or the published subprocessor list
    Whether any independent evaluation existsUsually: none

    Never scored:accuracy, containment, deflection, resolution rate, approval lift, ROI, time saved, hours returned, CSAT lift. Every published figure in this market is vendor marketing about itself. Where a vendor number appears in this article it is labelled as the vendor's claim and used as evidence about the vendor, not about the product.

    The inherited-compliance trap — check whose certificate it actually is

    A vendor's hosting provider's certification is not the vendor's certification. In this roster, Glia's security posture cites ISO 27001 — and that certificate belongs to AWS, not to Glia. Glia's own SOC 2 Type 2, PCI DSS and HIPAA/HITECH Type 1 attestations are real and are its own; the ISO claim is not. Before you score any compliance cell, confirm the certificate names the vendor's legal entity. Where it names a cloud provider, the honest cell reads not publicly disclosed — the certification cited belongs to its hosting provider. That distinction takes thirty seconds to check and it is the single most common overstatement in vendor security pages.

    The integration test that costs you one email

    Jack Henry publishes a searchable directory of verified integrations — the Fintech Integration Network, formerly the Vendor Integration Program — with 244 verified members, filterable by core. It also publishes the most useful paragraph in this entire subject area, which we quote in full because it does the work of an entire methodology section.

    Please note that Jack Henry neither recommends, nor endorses, the products provided by our FIN members. We can only verify the technical soundness of the product integration. Not every fintech integrates to all cores. Please email VendorQA@jackhenry.com if you would like to confirm that a fintech has an integration with a particular Jack Henry core.

    Jack Henry, Fintech Integration Network page, retrieved 23 August 2026

    Three things happen at once there. The core provider confirms, in its own words, the distinction this article is built on — it verifies plumbing, not product. It flatly contradicts the industry's favourite marketing line, because not every fintech integrates to all cores. And it hands you a free verification step. Before you take a vendor's word for it, email VendorQA@jackhenry.com and ask about your core.

    For that reason the integration column below is headed documented integration programme, never certified or approved — Jack Henry expressly declines to endorse. A missing entry means not in that directory as of 23 August 2026; it does not mean the vendor works with no core at all. And we checked the core providers' own directories rather than the vendors'. That surfaced three findings worth the exercise on its own: zero of seven major AI lending and service vendors appear in the Fiserv DNA AppMarket, so a credit union on Fiserv DNA has no listed DNA integration from any of the best-known names; Corelation applies an explicit KeyBridge Certified badge that neither interface.ai nor Posh carries even though both are listed, so the core itself distinguishes listed from certified; and Q2 states that it performs code reviews, tests the app deployment and completes an integration review of every app, which is the most substantive published verification standard we located anywhere.

    One more scoring rule, and it is the one that decides most of the table: every row needs a citation or the literal words not publicly disclosed. We never estimate a price. If pricing is gated, the cell says so — and in this market that cell says so eleven times out of twelve.

    The Comparison Table

    Ten vendors, six columns, every cell either citable or marked not publicly disclosed. Checked 23 August 2026.

    Read the ownership column first. Four of the best-known names in this category changed hands or changed names during the last twelve months, and a five-year core-adjacent contract signed into an unresolved ownership question is a governance problem before it is a technology one.

    Vendor and ownership of recordWhat it actually isAttestation — and whose certificate it isPricingCore integration, checked against the core's own directoryIndependent evaluation
    1. interface.ai — San Jose, CA. Bootstrapped by Srinivas Njay and Bruce Kim; first external round $30M led by Avataar Venture Partners, 22 Oct 2024. No round sinceVoice, chat and employee assist shipping today. The two products that would constitute actual autonomy — Agentic Online Banking and the Personal Finance App — are both marked coming soon; Smart Collections is alpha or betaThe strongest posture examined. SOC 2 Type 2, ISO/IEC 27001:2022 with a Year-1 surveillance certificate posted 15 Jan 2026, CSA STAR Level 1 and 2, GDPR, GLBA, CCPA. Auditor named: Prescient Assurance. DPA and subprocessor list published at trust.interface.aiNot publicly disclosed. Does publish one real commercial commitment: all necessary integrations provided at no cost under Fully Managed ServiceIn the Jack Henry FIN since Jan 2021, 40+ implementations, Episys via SymXchange named. Listed on Corelation's partner page but without the KeyBridge Certified badge. Absent from Q2 Innovation Studio and the Fiserv DNA AppMarketNone. CB Insights Fintech 100 is a promising-company list, not a product evaluation
    2. Posh — Posh Technologies, Inc., Boston, MIT spinout. Round led by Curql with Canapi and TruStage Ventures; Curql and TruStage are credit-union-owned fundsRules-bounded conversational self-service. Its own architecture wording is that Operating Procedures combine the intelligence and flexibility of LLMs with the control and precision of code. Simulator and CoachQA are staff training and QA tooling, not agentsSOC 2 Type II, described on its own page as a second year of Type II; SOC 3; CSA STAR; CSA AI Trustworthy Pledge 2025; CAIQ and AI CAIQ; pen-test report, DPA and Responsible AI statement at security.posh.ai. No ISO 27001. Note that its marketing page says only bank-grade security — the evidence is one click deeperNot publicly disclosed. The one verifiable commercial term located anywhere: CCUA offers specially priced Posh solutions to credit unions under $300M in assets, with no figure publishedThe best-corroborated in the set. Jack Henry FIN since 30 Apr 2025, Symitar via SymXchange. Dedicated Corelation partnership announced 12 May 2025, listed but without the KeyBridge badge. The only vendor of seven listed by Q2 itself in Innovation Studio. Absent from Fiserv DNA AppMarketNone. Its Feb 2026 production data report across 125+ institutions is vendor-authored
    3. Unit21 — Unit21 Technologies, Inc., San Francisco. Independent; last raise Series C, June 2023. Current CEO could not be resolved: one source reports a change in April 2026 while the company newsroom still presents the founderA genuine agent that is explicitly human-gated — configurable approval gates and per-step work logs, marketed as AI does the work, humans make the call. Financial crimes and fraud risk, not member serviceSOC 2 Type I and Type II, attested by Armanino — named auditor. Penetration testing by Doyensec and Cobalt. Publishes the commitment that your data is never used to train our agentsNot publicly disclosedIn the Jack Henry FIN under Financial Crimes and Fraud Risk. Not listed on Corelation, Q2 Innovation Studio or the Fiserv DNA AppMarketNone
    4. Glia — Glia Technologies, Inc., formerly SaleMove. $152M raised at roughly $1B valuation, but the last disclosed round was $45M in March 2022Agentic virtual assistant plus a human copilot, with explicit human oversight; answers constrained to pre-approved Knowledge Bank content rather than open-ended generationSOC 2 Type 2, PCI DSS, HIPAA and HITECH Type 1, CCPA. No ISO 27001 of its own — the ISO certification cited belongs to AWS, its hosting provider. That is an inherited certificate and we score it as not publicly disclosed for Glia itselfNot publicly disclosed as a figure, but it publishes the model, which is more buyer-relevant than most figures: $0 per minute, $0 per seat, $0 per token, unlimited seats and usage. No per-token AI chargeIn the Jack Henry FIN. Names 17 platforms on its own site as logo tiles with no per-integration technical documentationNone. Its automation claim moved from up to 60% in 2024 to up to 80%+ in 2026 with no restated methodology
    5. Eltropy — Eltropy, Inc., Milpitas, CA. Last disclosed round $25M Series A, 17 June 2021, led by K1 Investment Management with Curql Fund and CMFG Ventures. No Series B. Three acquisitions since: POPi/o, Marsview.ai and Lexop (6 Jan 2025)A contact-centre platform with a retrieval chatbot, marketed as agentic. Its own CPO said on 1 March 2026 that its agents already authenticate members and provide account information, and that the company is rapidly expanding into payments, loan system updates and collections workflows — those are roadmap, stated by the vendorAnnual SOC 2 Type 2 audits claimed, with auditor AARC-360 named in one place, but no report date, scope or trust portal. No ISO 27001. No PCI DSS despite shipping payments through Nuvei. No published DPA — the MSA defers it to per-deal negotiation. Best-in-set subprocessor transparency, which is how we know VoiceFlow is the dialog engineNot publicly disclosed. Ignore the $100/month figure circulating on software-comparison sites; it is not a vendor figureIn the Jack Henry FIN; Symitar VIP since 12 Oct 2019, now seven years old. Every core integration detail page on its own site is password-protected. Absent from Corelation's partner page and the Fiserv DNA AppMarket. Q2 claimed but not corroborated on q2.comNone. Its Fintech Value Creator of the Year award is from Curql, an Eltropy investor
    6. Hapax — Austin, Texas. $2.6M seed from RHS Investments is the only disclosed round and is roughly 29 months old — a genuine going-concern question for a multi-year contractInternal staff knowledge and productivity agents, not member-facing. Useful for policy and procedure lookup, not for anything that touches a member decisionSOC 2 Type II stated on its own security page, trust centre at trust.askhapax.ai. No ISO 27001 claimedPUBLISHED, and unique in this market: pay-as-you-go at $2.50 per credit with no monthly fee; Pro at $150 per month including 85 credits with additional credits at $1.50; Enterprise customNone at all. Its integrations page lists Salesforce, HubSpot, Slack, Teams, Jira, Snowflake, Google Drive, QuickBooks and Zendesk — zero cores and zero digital banking platforms. Not in the Jack Henry FINNone. Its partner asset figure appears as both $90B and $70B+ in different releases
    7. Casap — Casap Technologies, Inc., San Francisco and New York. $25M Series A, 7 Aug 2025, led by Emergence Capital; $33.5M totalGenuinely autonomous inside a narrow domain: the full card-dispute lifecycle end to end. Also the agentic layer inside Alkami's platform, sold through Alkami's partner programmeThe weakest disclosure of any vendor we rank. No security or trust page exists — /security and /trust both return 404. PCI-DSS and AICPA badge images in the footer only. It never states SOC 2 Type II in writing anywhere publicNot publicly disclosedIn the Jack Henry FIN under Financial Crimes and Fraud RiskNone
    8. Cotribute — ownership could not be established. No funding round, investor or parent company located in public record, which is itself the findingNext-best-action and growth agents — onboarding, account opening and member growth workflows. Not member service and not decisioningSOC 2 Type 2 stated in its Jack Henry FIN directory entry. No vendor trust page located, so the claim is second-hand even though the directory is a credible place to make itNot publicly disclosedOne of only three vendors with dated, documented, programme-level integration work: Jack Henry FIN across Digital Banking, Lending and Deposits and Operations, plus a Corelation KeyStone API partnership announced 4 Nov 2025 and extended 12 May 2026None
    9. Constant AI (Nia) — ownership completely opaque. No parent, investor or funding disclosure locatedSelf-service and operations agents launched 24 March 2026. The best procurement fact in the set for a small credit union: reachable inside Eltropy with no separate contractNot publicly disclosed — /security returns 404Not publicly disclosedIn the Jack Henry FIN. Names Symitar, SilverLake, Fiserv DNA, Corelation KeyStone and CU*Answers iPower. MSUFCU, an $8B credit union, is named liveNone
    10. Bretton AI — renamed from Greenlite AI on 9 February 2026 alongside a $75M Series B led by Sapphire Ventures; $90M total. greenlite.ai now redirects to bretton.comFinancial-crime compliance agents built for large institutions. Ranked last here for one reason: it fails the community credit union test on every checkable axisIts only public SOC 2 artifact is a blog post dated 9 April 2024, from the Greenlite era, naming no auditor and stating no audit period. A Type II report covers a window; no window, no assuranceNot publicly disclosedNot in the Jack Henry FIN. Named integrations are Actimize, nCino, Oracle, ServiceNow, FICO and ICE — enterprise and large-bank systems. No Symitar, no Fiserv DNA, no Corelation KeyStone, no Q2, no Alkami. Not one credit union is named as a customerNone

    The pricing column is the fastest read in the table. Of twelve vendors examined, exactly one publishes a price. The only other verifiable commercial term located anywhere in the market is a co-operative purchasing arrangement — the Cooperative Credit Union Association offers specially priced Posh solutions to credit unions under $300 million in assets — and even that publishes no figure.

    The Ten, Entry by Entry — and Ten We Refused to Rank

    The ordering reflects one thing: how much of what matters to a $100 million to $5 billion credit union this vendor lets you verify before you sign. It is not a quality ranking, because nobody can produce one.

    1. interface.ai — the strongest attestations in the market, and a roadmap tell

    What it does. Voice, chat and employee-assist agents for credit unions, with real reads and writes against the core via SymXchange on Symitar. Platform brand is BankGPT. Forty-plus implementations under the Jack Henry programme since January 2021.

    What is verifiable. More than any other vendor here. Its SafeBase trust centre publishes SOC 2 Type 2, ISO/IEC 27001:2022 with a Year-1 surveillance certificate posted 15 January 2026, CSA STAR Level 1 and Level 2, GDPR, GLBA and CCPA, a DPA, a subprocessor list, a pen-test report and an updated certificate of insurance posted 8 April 2026. The auditor is named: Prescient Assurance. Naming the auditor and the period is the difference between an attestation and a badge.

    What is not disclosed, and the tell.Pricing. And read the product taxonomy carefully: the two products that would constitute genuine autonomy — Agentic Online Banking, described as truly autonomous, and the Personal Finance App, described as watching, planning and acting on the member's behalf — are both marked coming soon. Smart Collections is alpha or beta. What ships today is voice, chat and employee assist, which is a good product but a different product. Its integrations page names roughly 23 systems, but the asset timestamps date that page to March 2024, and it names no Alkami, no Q2 and no Finastra.

    Who it fits. A Symitar or SilverLake credit union that wants member-facing voice and chat and whose board will actually read the trust portal. Who it does not. Anyone buying the autonomy language on the website today. Ask what is in production, at a named institution, this quarter.

    2. Posh — the best-corroborated integrations and the only complete residency disclosure

    What it does. Conversational self-service for banks and credit unions, architected as what the company calls Operating Procedures, combining the intelligence and flexibility of LLMs with the control and precision of code. That is a rules-bounded workflow executor, not open-ended autonomy — and saying so is to its credit.

    What is verifiable. Its trust centre publishes SOC 2 Type II — its own page describes a second year of Type II compliance — plus SOC 3, CSA STAR, the CSA AI Trustworthy Pledge 2025, CAIQ and AI CAIQ, a pen-test report, a DPA, a Responsible AI statement and a third-party AI diligence document. Its subprocessor list is the only complete data-residency disclosure we found in this market: every processor named with a location, all United States, with a single exception the company flags itself as USA/Global. Flagging your own exception is a scoring signal.

    What is not disclosed. Pricing, and there is no ISO 27001. Note also that its public marketing page says only bank-grade security and names no attestation at all — the real evidence is one click deeper at its security subdomain. That is a useful worked example in reverse: here the marketing page is weaker than the truth. Client counts drift across its own materials, from 100-plus clients to 125-plus financial institutions to more than 50, depending on the page.

    Who it fits.A credit union under $300 million that can access the association pricing, or any institution that wants integration claims it can corroborate from the core's side. Who it does not. Anyone who needs an agent to move money or write to the loan system unattended.

    3. Unit21 — the only vendor that publishes its own human-gating as a feature

    What it does. Fraud and financial-crime agents with configurable approval gates and per-step work logs. Its own framing is that AI does the work and humans make the call — which happens to be the correct compliance posture for anything touching BSA and AML work under 12 CFR 748.2.

    What is verifiable. SOC 2 Type I and Type II, attested by Armanino — named. Penetration testing by Doyensec and Cobalt — named. And a published commitment that your data is never used to train our agents, which almost nobody else in this set states in writing.

    What is not disclosed.Pricing. And one governance item we could not resolve: one source reports a CEO change in April 2026 while the company's own newsroom still presents the founder in the role. We did not print a name. Verify it yourself before you cite one. Last disclosed raise is a Series C from June 2023.

    Who it fits. A credit union whose alert queue is drowning its BSA officer and whose examiner will ask how dispositions were reached. Who it does not. Anyone looking for member-facing service.

    4. Glia — publishes the pricing model, inherits the ISO certificate

    What it does. An agentic virtual assistant plus a human copilot, with answers constrained to pre-approved Knowledge Bank content. Constraining generation to approved content is a design choice that trades ceiling for defensibility, and for a regulated institution that is usually the right trade.

    What is verifiable. SOC 2 Type 2, PCI DSS, HIPAA and HITECH Type 1, and CCPA. And the most buyer-relevant commercial disclosure in this entire article that is not a number: Glia publishes its pricing model — zero per minute, zero per seat, zero per token, unlimited seats and usage. In a market where every competitor meters AI consumption invisibly, no per-token charge is a term you can actually plan a budget around.

    What is not disclosed, and the trap. No ISO 27001 of its own — the ISO certification cited belongs to AWS. That is the inherited-compliance trap in this roster, and it is checkable in thirty seconds. Also: $152 million raised at roughly a $1 billion valuation, but the last disclosed round was $45 million in March 2022, which is four and a half years of product spend with no publicly disclosed capital behind it. And its automation claim moved from up to 60 percent in 2024 to up to 80 percent-plus in 2026 with no restated methodology — a number that drifts is marketing, not measurement.

    5. Eltropy — the classification is the story

    What it does.A contact-centre platform with a retrieval chatbot layer, marketed as agentic. That is not a criticism of the platform, which is widely deployed and useful; it is a correction to the category label. The decisive evidence is from Eltropy's own chief product officer on 1 March 2026, who said the agents already authenticate members and provide account information and that the company is rapidly expanding into payments, loan system updates and collections workflows. Payments and loan writes are roadmap, stated by the vendor's own product chief. Its AI Voice marketing page claims automation of loan payments while its Payments product routes money movement through human agents.

    What is verifiable. The best subprocessor transparency in this market — which is the only reason anyone knows that the conversational layer is assembled on VoiceFlow plus OpenAI rather than proprietary models. That changes the data-flow diagram, the model-risk question and who you escalate to at two in the morning. Publishing it was the honest thing to do and most vendors do not.

    What is not disclosed. A great deal. Annual SOC 2 Type 2 audits are claimed with no report date, scope or trust portal. No ISO 27001. No PCI DSS despite shipping payments through a third-party processor. No published DPA — the master agreement defers it to per-deal negotiation. No residency or retention commitment. And every core-integration detail page on its own site is password-protected, so there is no public technical documentation for any core integration; the only certified one is Symitar VIP from 12 October 2019, now seven years old.

    6. Hapax — the only vendor in this market that publishes a price

    What it does. Internal staff knowledge and productivity agents — policy lookup, procedure retrieval, drafting support for employees. Not member-facing, and it does not pretend to be.

    What is verifiable, and why it ranks here at all. Pay-as-you-go at $2.50 per credit with no monthly fee; Pro at $150 per month with 85 credits included and additional credits at $1.50; Enterprise custom. It is the only vendor of twelve examined that lets you build a budget before an NDA, and that alone is worth a place in the table. SOC 2 Type II is stated on its own security page with a trust centre.

    What is not disclosed, and the going-concern question. A $2.6 million seed round is the only disclosed capital and it is roughly 29 months old. It is not in the Jack Henry FIN. And it has no core integrations at all — its integrations page lists Salesforce, HubSpot, Slack, Teams, Jira, Snowflake, Google Drive, QuickBooks and Zendesk. Zero cores, zero digital banking platforms. For a multi-year contract, price the viability risk honestly: NCUA cannot examine this vendor for you.

    7. Casap — genuinely autonomous in a narrow lane, with the weakest disclosure we rank

    What it does. The full card-dispute lifecycle, end to end. This is one of the few products in the set that is genuinely autonomous inside a bounded domain rather than a chatbot with an agentic label. Dispute handling is a good domain for that: the workflow is procedural, the regulation is specific, and the outcomes are auditable.

    What is not disclosed — and this is disqualifying for some boards. There is no security or trust page at all. The /security and /trust paths both return 404. The footer carries PCI-DSS and AICPA badge images, and the company never states SOC 2 Type II in writing anywhere public. A badge is not a report, and 12 CFR Part 748 Appendix A section III.D.3 tells you to review audits, summaries of test results or other equivalent evaluations of your service providers. You cannot review an image.

    Ownership.$25 million Series A on 7 August 2025 led by Emergence Capital, $33.5 million total. Worth knowing: Casap is also the agentic layer inside Alkami's platform, so an Alkami institution may already be paying a platform margin for a product it could contract for directly.

    8. Cotribute — real documented core work, unestablishable ownership

    What it does. Next-best-action and growth agents across onboarding, account opening and member growth. Not member service, not decisioning.

    What is verifiable. It is one of only three vendors in this entire market with dated, documented, programme-level integration work: Jack Henry FIN membership across Digital Banking, Lending and Deposits and Operations, plus a Corelation KeyStone API partnership announced 4 November 2025 and extended 12 May 2026. That is a real commitment with dates attached, not a logo tile.

    What is not disclosed.Ownership — and we mean entirely. No funding round, no investor, no parent company could be located in public record. The cluster's methodology requires ownership from public record; where it cannot be established, that absence is the finding and it belongs in your vendor file. Its SOC 2 Type 2 claim appears in its Jack Henry directory entry rather than on a vendor trust page, which is a credible place to make the claim but still second-hand.

    9. Constant AI (Nia) — the best procurement fact for a small credit union

    What it does. Self-service and operations agents, launched 24 March 2026. It names Symitar, SilverLake, Fiserv DNA, Corelation KeyStone and CU*Answers iPower, and MSUFCU, an $8 billion credit union, is named live. It is in the Jack Henry FIN.

    The procurement fact. It is reachable inside Eltropy with no separate contract. For a credit union with a small executive team and no dedicated vendor- management function, adding a capability without opening a new master agreement, a new diligence file and a new annual board-report line is a material saving in effort that nobody prices.

    What is not disclosed. Security — /security returns 404 — and ownership, which is completely opaque. It ranks ninth rather than higher for exactly that reason: the commercial packaging is excellent and the verifiable record is thin. If you pursue it, the diligence questions write themselves.

    10. Bretton AI — ranked last, and here is precisely why

    Start with the name. This company was Greenlite AI until 9 February 2026, when it rebranded to Bretton AI alongside a $75 million Series B led by Sapphire Ventures; greenlite.ai now redirects to bretton.com. Any 2026 ranking still listing Greenlite AI was not re-checked before publication, and that tells you how much of the rest of it to trust.

    What is verifiable. It trades, it is well funded at roughly $90 million total, and its financial-crime compliance agents are real products with real enterprise deployments.

    Why it is last. It fails the community credit union test on every checkable axis. It is not in the Jack Henry FIN. Its named integrations are Actimize, nCino, Oracle, ServiceNow, FICO and ICE — enterprise and large-bank systems. There is no Symitar, no Fiserv DNA, no Corelation KeyStone, no Q2 and no Alkami. Not one credit union is named as a customer. And its only public SOC 2 artifact is a blog post dated 9 April 2024, from the Greenlite era, naming no auditor and stating no audit period. It is in the table because it is a serious company you will encounter; it is tenth because for a $100 million to $5 billion institution, nothing about it has been demonstrated.

    Ten more names appear in competing 2026 rankings and should not. Six are dead names, acquisitions or roadmaps; four are excellent companies that are simply not AI agents.

    NameWhy it is not ranked hereStatus of record
    KasistoAcquired. The release describes the team and assets as now part of Backbase, and kasisto.com carries a site-wide banner linking to it. The buying decision is now a Backbase decisionBackbase acquisition announced 23 June 2026; terms not disclosed
    Greenlite AIDead name. Publishing it in a 2026 ranking is the single clearest signal that a roster was not re-checkedRebranded to Bretton AI, 9 February 2026
    VerintNo longer independent; merged with Calabrio under private ownershipThoma Bravo acquisition closed 26 November 2025
    MeridianLinkTaken private and delisted, and its Millie agents are roadmap — mortgage slated Q4 2026, consumer early 2027. Not buyable todayCenterbridge Partners, $2.0B, closed 24 October 2025
    Arya.aiMajority-owned by an India-listed parent, with no US credit union footprint located67% acquired by Aurionpro Solutions
    Lumin DigitalNot an agent in 2026. Solaire Assist is an assist layer, and Lumin's own release puts conversational and agentic capability in the future tense. Also suite-locked$115M raised July 2026 at roughly $1.6B valuation
    UpstartNot an agent, and it never claims to be one. Its lender AI pages contain zero instances of agent, agentic or autonomous; the 10-K's only agentic AI reference is internal loan servicing, and its 91% fully automated figure is defined in-filing as straight-through processingOCC conditional approval 23 July 2026 to establish Upstart Bank, N.A. — a competitor to its own customers
    Zest AINot an agent. Custom machine-learning underwriting models plus a GenAI insights copilot. Legal entity is ZestFinance Inc. d/b/a Zest AI, structured as a CUSO with 70-plus credit-union investorsNo trust or security page exists at all; its privacy policy contains zero occurrences of SOC 2, ISO 27001, model risk, retention, residency or subprocessor
    AlkamiSells no AI agent of its own. Code Studio is a beta developer tool and Engage is predictive ML; the agentic AI in the platform is Casap's, via its partner programmeUnder an activist campaign — JANA Partners filed a Schedule 13D on 29 June 2026 pushing exploration of a sale
    Scienaptic AIDecisioning, not agents — and the weakest verifiable posture of any vendor examined. No trust, security or compliance page exists; zero occurrences of SOC 2 or ISO 27001 anywhere on the siteIts own privacy policy states that personal information may be transferred across national boundaries and stored and processed in any country around the world, with disputes governed by the laws of India

    The Scienaptic residency language deserves a second read, because it is the finding on this list most likely to matter to your board. Your obligation under 12 CFR Part 748 Appendix A follows member information maintained by or on behalf of the credit union. Four words that put the vendor inside your obligation. A privacy policy that permits processing in any country around the world under the law of another jurisdiction, with no DPA, no subprocessor list and no retention period published, is not a policy you can reconcile with that scope in a board report. There is a caveat worth stating fairly: a website privacy policy may not govern the customer master agreement. But nothing customer-facing is public, and you cannot put an unread agreement in a vendor file.

    The competitor this article has to name: the cores themselves.

    Fiserv has agentOS. FIS has a Financial Crimes AI Agent built with Anthropic, with two named launch institutions and general availability signalled for the second half of 2026. Jack Henry is building with Google Cloud. For a community credit union the honest default alternative to buying any vendor in the table above is waiting for your core to ship its own — and the core already controls the integration you would otherwise be paying a third party to negotiate. That is the strategic frame no competing listicle contains, because no competing listicle is incentivised to tell you that doing nothing for four quarters is a real option.

    The Binding Constraint: Nobody Examines Your Vendor, and You Still Own the Breach

    NCUA is the only federal banking regulator that cannot examine the technology vendors its institutions depend on — and 12 CFR 748.1(c) still requires the credit union to report the vendor's breach within 72 hours of being told about it.

    The federal banking agencies can examine a bank's technology service providers directly under the Bank Service Company Act at 12 U.S.C. 1867(c). NCUA cannot. Its equivalent authority came from the Examination Parity and Year 2000 Readiness for Financial Institutions Act of March 1998, and NCUA's own March 2022 white paper puts the date on it flatly: this authority expired on December 31, 2001. As of 23 August 2026 no enacted statute restoring it was located, and legislative vehicles have repeatedly stalled — with credit-union trade groups themselves among the opponents. Do not write that Congress has never acted; write that as of the date you checked, no such authority had been enacted.

    The most revealing passage in that white paper is about what happened when NCUA asked nicely:

    Until 2013, the NCUA conducted third-party vendor reviews on a voluntary basis. Several vendors declined the NCUA's examination requests for voluntary examinations, and other vendors rejected the NCUA's recommendations to implement corrective actions to mitigate identified risks.

    NCUA, Third-Party Vendor Authority white paper, March 2022

    The same document records that in 2016 the federal banking agencies discontinued NCUA's participation in significant service provider examinations, because NCUA is not statutorily authorised to conduct them. So when a bank buys the product in the table above, its regulator can go and look at the vendor. When a credit union buys the same product, nobody can — except the credit union. One hundred percent of the diligence burden is yours.

    What does bind you — and why SOC 2 Type II is a scoring column, not a nicety

    12 CFR Part 748 Appendix A, the Guidelines for Safeguarding Member Information, applies by its own terms to member information maintained by or on behalf of federally insured credit unions. Section III.D requires the credit union to exercise appropriate due diligence in selecting service providers, to require them by contract to implement appropriate measures, and — where indicated by risk assessment — to monitor them. The operative sentence is III.D.3: as part of this monitoring, a credit union should review audits, summaries of test results, or other equivalent evaluations of its service providers. Section III.F then requires an annual board report addressing, among other things, service provider arrangements.

    That is why the attestation column exists. A vendor that will not produce an audit, a summary of test results or an equivalent evaluation is asking you to fail a documented expectation in writing, once a year, in front of your board.

    The 72-hour clock, and the contract term that protects it

    12 CFR 748.1(c) requires notification of a reportable cyber incident no later than 72 hours after the credit union reasonably believes it has experienced one — or, where the incident is reported under paragraph (c)(1)(i)(C), within 72 hours of being notified by a third party, whichever is sooner. Paragraph (c)(1)(i)(C) expressly covers a disruption of business operations or unauthorized access to sensitive data facilitated through, or caused by, a compromise of a credit union service organization, cloud service provider, or other third-party data hosting provider, or by a supply chain compromise.

    The obligation flows down to you. The supervision does not flow up to them. Which makes the vendor notification SLA a regulatory term, not a procurement term. A vendor promising notice within a reasonable period, or without undue delay, has already spent a clock that belongs to you. Ask for a defined number of hours, in the contract, with a named contact and an escalation path that works at 2am on a Saturday.

    Two documents that are frequently handed to credit unions and do not apply. The Interagency Guidance on Third-Party Relationships published at 88 FR 37920 on 9 June 2023 was issued by the Federal Reserve, the FDIC and the OCC. NCUA was not an issuing agency — and that omission is meaningful, because NCUA islisted as an issuing agency on other interagency documents when it participates. A federally insured credit union's obligations run through NCUA Letter to Credit Unions 07-CU-13 and 12 CFR Part 748 instead. The practical expectations overlap heavily, but citing the wrong document in your vendor file is exactly the sort of thing an examiner notices. A community bank reader supervised by the FDIC or OCC is covered by the 2023 guidance; say which applies to which.

    And the CFPB is probably not your examiner. Bureau supervisory authority over depositories starts above $10 billion in assets under 12 U.S.C. 5515(a); at $10 billion or less, 12 U.S.C. 5516 puts the examination with the prudential regulator, with the Bureau able to include examiners on a sampling basis. So for a credit union under $10 billion, the CFPB writes the rules and NCUA runs the exam. The rules bind you either way — Regulation B applies to a $300 million credit union exactly as it applies to a $300 billion bank; only the examiner changes. Any article framing CFPB retrenchment as the rules relaxing is wrong twice over.

    NCUA has published AI guidance. It says the opposite of what several vendor blogs claim.

    From NCUA's own AI regulatory-compliance page, last modified 28 April 2026, quotable verbatim: Does NCUA have AI specific regulations? No. NCUA has not issued AI specific rules or regulation. However, existing regulations are technology-neutral and apply to AI use. And: AI is not treated differently than any other innovative technology. Our supervisory focus is on risk management, not the tool itself. The only NCUA-authored documents that page cites are Letters 07-CU-13 and 01-CU-20 — third-party due-diligence letters from 2007 and 2001. No NCUA Letter to Credit Unions on AI exists.

    GAO's May 2025 report puts the supervisory gap in sharper terms than NCUA does. It found that NCUA's model-risk guidance addresses only interest rate risk modeling and was last updated in October 2016, and concluded that it could not compare that guidance against the NIST AI Risk Management Framework because the guidance's limited scope did not allow for a meaningful comparison. It also records that NCUA has issued one document of resolution related to AI use since fiscal year 2020, plus a regional director letter to a credit union for insufficient governance, reporting and risk mitigation for an AI-driven program that instantly approved loans without traditional underwriting steps such as income verification. That is the shape of the enforcement risk: not the AI, the governance.

    The commercial half of the constraint has a federal regulator behind it too. In a Request for Information published at 90 FR 54882 on 28 November 2025, the OCC wrote that consolidation in the core service provider market can result in reduced competitive pressure, reduced negotiating power for many community banks vis-a-vis their core service providers, resulting in potentially burdensome contractual provisions and bundled products that raise fees, and a sense that many community banks do not believe their core providers are partners committed to their long-term success. Citing Federal Reserve Bank of Kansas City research, it noted that the three largest core service providers served more than 70 percent of depository institutions in 2022, with the largest alone serving 42 percent. It also named the increasingly high capital costs associated with switching core service providers. Whether an AI agent can read and write to your core is therefore controlled by a third party with no contractual obligation to your project — the constraint we work through in detail in our guide to integrating agents with legacy core systems.

    One live dispute is worth a sentence, stated precisely. A coalition of credit unions is suing Fiserv over what the complaints describe as improper early-termination and deconversion fees, and the court denied Fiserv's motion to dismiss on 18 June 2026. Dollar amounts are not public. A denied motion to dismiss is not a finding of liability — it means the claims survive to be litigated. If the case proceeds, it may produce the first credible deconversion figures anyone has put on the record.

    What Changed on 21 July 2026 — and What Did Not

    Regulation B no longer contains the disparate-impact effects test. The final rule at 91 FR 21620, published 22 April 2026, took effect on 21 July 2026 — five weeks before this article. It is in force, it is being challenged, and it has not been enjoined.

    Quote the amendatory text, not a law-firm summary. 12 CFR 1002.6(a) now reads, in full as adopted: except as otherwise provided in the Act and this part, a creditor may consider any information obtained, so long as the information is not used to discriminate against an applicant on a prohibited basis. The Act does not provide that the effects test applies for determining whether there is discrimination in violation of the Act. That final sentence is the change. What it replaced was language pointing to ECOA's legislative history and the Supreme Court's employment-law effects-test cases. The same rule also narrowed the discouragement provision at 1002.4(b) and added conditions on special purpose credit programs at 1002.8.

    Status questionCorrect answer as of 23 August 2026
    In force?Yes — effective 21 July 2026
    Challenged?Yes — National Fair Housing Alliance and others v. CFPB, filed in federal district court in May 2026, with an amended complaint reported in August 2026
    Enjoined?No — the plaintiffs did not seek preliminary injunctive relief
    Stayed?No
    Vacated?No
    Resolved?No — summary-judgment briefing is reported to extend into 2027

    Three framings are all wrong and all circulating: enjoined, struck down, and citing the old effects test as current. The correct sentence shape is the boring one — in force, under challenge, not enjoined. Confirm the docket and posture yourself before printing a case caption; ours comes from legal press reporting rather than a docket pull.

    The exposure did not disappear, and the rule itself says so.

    From the preamble, describing comments the Bureau declined to act on: creditors will remain subject to other Federal and State laws imposing disparate-impact liability. And the Bureau's own response: it has primary authority for administering ECOA, but not other Federal or State laws that include a disparate-impact component, and thus has neither the authority nor expertise to instruct regulated entities on how to comply with those other laws. Fair Housing Act disparate impact on the mortgage side, state fair-lending statutes, state UDAP law and state attorneys general are untouched. A credit union in a state with its own fair-lending regime has had one federal avenue narrowed while the others stand. The Bureau also declined to give creditors comfort on proxy and demographic analysis, saying such guidance would likely be too nuanced and detailed to be appropriate for inclusion in a regulation. If you were running fair-lending testing, keep running it.

    What did not change is the part that governs an AI lending agent day to day. 12 CFR 1002.9(b)(2) was not amended by the 2026 rule. It says the statement of reasons for adverse action must be specific and indicate the principal reasons, and that statements that the action was based on the creditor's internal standards or policies, or that the applicant failed to achieve a qualifying score on the creditor's credit scoring system, are insufficient. Read that twice. A score-based denial with no specific reason is insufficient on the face of the regulation — no interpretive guidance required. The credit union is the creditor. The model is proprietary and the vendor will not tell us are not defences available under that text.

    Two housekeeping facts, because both are commonly got wrong. CFPB Circular 2022-03, on adverse action notification in connection with credit decisions based on complex algorithms, was withdrawn on 12 May 2025as item 14 in a batch of 67 guidance documents at 90 FR 20084; Circular 2023-03 was item 7 in the same notice. Withdrawn is not repealed, vacated or overruled — it removes the Bureau's interpretive gloss, not the statutory duty. Anyone writing that the CFPB dropped the AI adverse-action rule has inverted the law.

    And there is no CFPB Circular 2026-03. It is fabricated.

    At least one low-quality regulation-aggregation site publishes a confident, circumstantial description of a Circular 2026-03 supposedly issued 5 May 2026, advising that lenders using complex algorithms remain fully responsible under ECOA and Regulation B for specific adverse-action reasons. A Federal Register query for CFPB documents matching Consumer Financial Protection Circular published on or after 13 May 2025 returns a count of zero, and a full listing of every CFPB Federal Register document in 2026 contains no circular of any number. What makes this fabrication genuinely dangerous is that it says roughly the right thing about the law — so a reviewer nods along at the substance and never checks the source. Cite 12 CFR 1002.9(b)(2) instead. And treat a confident citation to Circular 2026-03 as evidence that whatever else that source told you is unreliable.

    There is a genuine irony here worth one sentence, and no competing listicle will have it. Vendor marketing in this category has leaned for years on disparate-impact-style fairness testing across protected classes. The federal regulatory theory that made that framing commercially compelling was narrowed on 21 July 2026 — while the adverse-action obligation that explainability actually serves was left completely intact. The compliance case for model explainability got stronger relative to the marketing case for fairness dashboards, not weaker.

    The One Independent Evaluation in This Vertical — and How It Ended

    An independent fair-lending monitorship of one AI lender exists, it was adversarial and methodologically explicit, and it ended without agreement. No independent benchmark of any commercial AI agent product in banking exists at all. Hold that distinction precisely — a blanket denial would be false.

    Start with the claim that made AI lending respectable in this industry. The figures — 27 percent more approvals and 16 percent lower average APRs — are cited across the trade press, in vendor decks and in board packets as a CFPB finding. The CFPB disclaimed them in writing, in the same blog post that published them. Its 6 August 2019 post states that the No-Action Letter recipient agreed to allow the Bureau to share key highlights from simulations and analyses that it conducted, and that the simulations and analyses were not separately replicated by the Bureau. The independent monitor confirmed the same point at footnote 83 of its Initial Report of 14 April 2021: the CFPB did not separately replicate these analyses.

    Then check the one document where a securities lawyer reviews every sentence. Upstart's FY2025 Form 10-K, filed 10 February 2026, contains zero occurrences of no-action letter, of 27 percent, of 16 percent lower, and of access to credit. The claim is absent precisely where liability attaches for saying it. That is the cleanest possible demonstration of the through-line in this article: a number that is fine for marketing and not fine for the SEC.

    The No-Action Letter is also dead, and it died at the recipient's request. The CFPB terminated it on 8 June 2022, at Upstart's own request, because Upstart wanted model changes that would not be possible if the Bureau conducted the appropriate level of monitoring and review. No replacement exists. And the Bureau's current No-Action Letter policy, applicable 10 January 2025, narrates the episode in its own words: outside observers appear to have interpreted the NAL as an endorsement that Upstart's model did not violate the ECOA. It records that the independent monitor ended the relationship after coming to an impasse with Upstart about how to assess compliance with ECOA, and that the monitor detected that the model caused statistically and practically significant adverse approval and denial disparities for Black applicants. The policy then draws the operational conclusion: the Conditions also prevent firms from advertising the receipt of a NAL, which can create the false appearance of endorsement or favored regulatory status. The regulator has now banned the marketing use of the thing your vendor may still be citing.

    The monitorship itself is the genuinely independent work, and it is unflattering in a way no vendor whitepaper ever is. Relman Colfax, with Sentrana Inc. and BLDS, LLC, conducted a fair-lending examination of Upstart's model under a December 2020 agreement among Upstart Network, the NAACP Legal Defense Fund and the Student Borrower Protection Center. Four public reports ran from April 2021 to a Final Report dated 27 March 2024. It found no evidence that variables acted as close proxies for race, national origin, sex or age. It also identified approval disparities for Black applicants and a likely viable less discriminatory alternative model, and raised concerns that educational criteria can lead to discriminatory lending outcomes, particularly for communities of color. And then it stopped:

    the Parties remain at an impasse over the appropriate and legally required methodology for assessing whether the performance of a potential less discriminatory alternative model would be comparable to the performance of an existing model.

    Relman Colfax, Upstart fair-lending monitorship, Final Report, 27 March 2024

    Quote it carefully. This is a monitorship report, not a regulator's finding and not an enforcement action. Upstart was never found to discriminate and was never fined. What it is, is the only time anyone independent has examined one of these models adversarially and published the result — and the result was an unresolved methodological dispute between serious people. That is what genuine scrutiny of these systems looks like, and it is the honest answer to any vendor that tells you fairness is a solved engineering problem.

    Two further notes on figures in this corner of the market. Zest AI's approval-lift claim has drifted while the phrasing stayed fixed: its 8 September 2021 press release said a 15 percent increase in approval rates with no added risk; its 2026 site says lift approval rates 25 percent without additional risk and lift approvals by 30 percent on average across protected classes. Same construction, 15 to 25 or 30 percent over five years, and the methodology was published at no point in between. And Upstart's current headline comparison is built on a baseline of its own construction — a small Cox model Upstart itself built, trained on Upstart's own loan book and run on Upstart's own applicant pool. It is not a comparison against any credit union's actual underwriting. We do not quote Upstart's 2026 marketing figures here because upstart.com returns HTTP 403 to every automated request and we could not verify the current page text; treat any figure you see attributed to it as a vendor claim until you have loaded the methodology page yourself.

    The last thing to say about Upstart is structural rather than statistical. On 23 July 2026 the OCC granted conditional approval for Upstart Bank, N.A., with FDIC and Federal Reserve applications pending. A company whose lending platform many credit unions rely on has taken the first regulatory step toward becoming a competing depository. That belongs in your concentration analysis, not just your vendor file — and it is a useful reminder that a five-year contract is a bet on a counterparty's strategy, not only on its software.

    A Worked Example, With Real Arithmetic

    Only one vendor in this market lets you do arithmetic before signing an NDA. So we do the arithmetic on that one, and label the rest as unknowable — which is itself the finding.

    The one calculation you can actually run. Hapax publishes pay-as-you-go at $2.50 per credit with no monthly fee, and Pro at $150 per user per month including 85 credits, with additional credits at $1.50. Take a credit union with 40 staff you would put on an internal knowledge agent. At Pro, that is 40 x $150 = $6,000 a month, or $72,000 a year, with 3,400 credits a month included. If half those users exceed their allowance by 20 credits a month, add 20 x 20 x $1.50 = $600 a month, or $7,200 a year — a total of roughly $79,200. You can build a board paper from that today, without a call. For every other vendor in the table, the same paragraph cannot be written at all, because the input does not exist in public. When you are comparing options, that asymmetry is real information: one vendor has decided you may plan, and eleven have decided you may not.

    The second calculation, and it is the one that actually protects you. Your 72-hour clock under 12 CFR 748.1(c) starts when the third party notifies you. If the vendor contract says notice within a reasonable period, assume five business days — and your filing window has closed before you knew anything. Negotiate a defined figure. A 24-hour vendor notification SLA leaves you 48 hours to triage, confirm scope and file. A 48-hour SLA leaves you 24. Anything vaguer than a number in hours is a term that transfers regulatory risk to you for free.

    What an explainable decision engine actually looks like when you build one

    Our ScoreBiz 360 fintech platform build is not a credit union and not an AI agent deployment, and we are not going to pretend otherwise. It is a merchant credit-scoring platform serving 5,000-plus small businesses, delivered in three months for under $30,000 on React and TypeScript. What makes it worth reading in this context is a single design decision. The scoring model publishes its factor weights — payment history 35 percent, credit utilisation 30 percent, length of credit history 15 percent, new credit inquiries 10 percent, business stability 10 percent — and returns specific, ranked improvement actions with each score rather than a bare number.

    That is the architecture 12 CFR 1002.9(b)(2) implicitly demands: principal reasons that fall out of how the decision was actually made, rather than a plausible sentence generated afterwards to fill a required field. The build also carried audit logging of every data access, AES-256 at rest, TLS 1.3 in transit and row-level security — the ordinary controls a Part 748 Appendix A review expects to find. If a vendor cannot show you where its reason codes come from, you are buying an explanation layer, not an explainable model. The same buy-versus-build question, and the same disclosure tests, run through our ranking for accounting firms, where the constraint is a criminal disclosure statute rather than a lending regulation.

    What Breaks First

    Not a loud outage. Silent, plausible wrongness under load — output that looks exactly like correct work, produced at a volume no one is sampling.

    Prompt injection is unsolved, and every agent here reads untrusted input. Member messages, uploaded pay stubs, emailed statements, dispute documentation, vendor remittance advices — any of those can carry instructions aimed at the model rather than at the reader. There is no reliable defence at the model layer, so treat this as blast-radius reduction rather than prevention: separate identities per agent instead of a shared service account, least-privilege scopes bound to the specific operations a workflow needs, no write credential live in a session that is reading untrusted content, reversible writes wherever the core allows them, per-action audit logging that names both the agent and the human it acted for, and a kill switch that revokes the credential rather than pausing the code. Be sceptical of any vendor advertising a detection rate for injection attempts.

    Four failure modes with a detection signal for each. Reason-code drift — adverse-action notices start converging on two or three generic reasons; detect by sampling denials monthly against the underlying decision data. Escalation collapse — the agent stops handing off, because handing off scores badly on containment; detect by tracking the escalation rate as a floor, not a ceiling, and alarm when it falls. Third-party model change — your vendor's underlying model provider ships an update and behaviour shifts overnight; detect by running a fixed regression set of real historical cases weekly, which is only possible if you built one on day one. Vendor incident — you learn from the vendor, on their timetable, and your 72-hour clock is already running.

    Rollback has to be a contract term, not a hope. Before go-live, confirm in writing: who can disable the agent, how fast, without the vendor's help; whether decisions made during the failure window can be identified and re-run; and what happens to your data and your logs on termination. A vendor that cannot answer the termination question in the contract is a vendor whose exit you have not priced.

    For calibration, the most useful non-vendor data point available: the Bank of England and FCA's November 2024 survey of 118 firms found 75 percent using AI — and only 2 percent running it fully autonomously. The gap between adoption and autonomy is where the whole market actually sits, whatever the product naming suggests.

    The Human-in-the-Loop Boundary

    An agent may prepare and queue a credit decision; a human must adjudicate it, and the adverse-action notice must state the actual principal reasons — a score alone is insufficient under 12 CFR 1002.9(b)(2).

    Every line below traces to a citation in this article rather than to an opinion. Put it in the vendor file and in the procedure document, and make the vendor initial it.

    WorkflowAn agent MAYA human MUSTAuthority
    Loan decisioningGather, verify, populate, flag and prepare a recommendationAdjudicate the application, and ensure the notice carries specific principal reasons12 CFR §1002.9(b)(2)
    Adverse action noticeDraft the notice and assemble reason codesConfirm the reasons are the actual principal reasons, not a post-hoc label generated to fill a field12 CFR §1002.9(b)(2) — internal-standards and score-only statements are insufficient
    BSA/AML alert handlingTriage, enrich, rank and draft narrativesDispose of alerts and sign the SAR; the disposition logic must survive independent testing12 CFR §748.2(c)(1)–(2)
    Member service and product adviceAnswer, route, retrieve and scheduleOwn any statement about suitability, price or terms — the institution said it, not the software12 U.S.C. §§5531, 5536 (UDAAP)
    Vendor security incidentDetect and alertFile with NCUA within 72 hours of third-party notification12 CFR §748.1(c) and (c)(1)(i)(C)
    Vendor selection and monitoringAssemble the diligence file and track attestation expiryBoard-level due diligence, plus the annual board report covering service-provider arrangements12 CFR Part 748 App. A, §§III.D and III.F

    Two of these are more commonly breached than the others. The BSA line matters because the independent-testing pillar at 12 CFR 748.2(c)(2) is where an alert-triage agent gets audited: if an agent suppresses, ranks or closes alerts, its behaviour is inside the tested program and you must be able to reconstruct why any given alert was dispositioned. Model opacity is a BSA problem, not only an ECOA problem. And the UDAAP line matters because there is no AI-specific safe harbour and no AI-specific guidance — the exposure under 12 U.S.C. 5531 and 5536 is ordinary UDAAP exposure applied to a new speaker. If the agent tells a member a product is suitable, the credit union said it.

    Cost and Timeline for a Custom Build

    If you build rather than buy, these are our bands. They are the same bands we publish everywhere, and we do not vary them by vertical.

    EngagementRangeTimeline
    Discovery + workflow audit$9k–$22k2–4 weeks
    Single-workflow agent$28k–$70k4–9 weeks
    Multi-workflow platform with system integration$70k–$180k9–16 weeks
    Enterprise / multi-site / regulated build$180k–$420k+14–24 weeks

    Senior-led delivery at $150–$225 per hour; retainers $2,500–$9,500 per month; a 30-day post-launch warranty; and a fixed-price phased proposal within 5 business days of the discovery call. Full source-code and IP ownership transfers to you — which for a regulated institution is not a nicety, because it is the difference between an exit you control and a deconversion you litigate. We are a senior-led Black-owned Los Angeles agency, and you can reach us on +1 (424) 272-5601 or book directly at calendly.com/frenchydigital/discovery-call.

    The honest comparison against buying is rarely price. It is whether the workflow you want automated is one of the four or five that vendors have productised — member service, dispute handling, alert triage, onboarding, internal knowledge — or something specific to how your institution actually runs. If it is the former, buy, and spend the saved effort on the diligence file. If it is the latter, nobody is going to build it for you, because the addressable market is one credit union.

    Red Flags When Evaluating a Vendor

    Every red flag below was observed during this research, in this market, on a named vendor's own public materials. None of it is generic advice.

    Red flagWhere it was actually observedWhy it matters
    Compliance badges with no attestation behind themOne vendor shows PCI-DSS and AICPA badge images in its footer, has no security or trust page at all, and never states SOC 2 Type II in writing anywhere publicPart 748 App. A III.D.3 tells you to review audits, summaries of test results or equivalent evaluations. A badge is not a report
    A SOC 2 claim with no auditor and no audit periodOne vendor's only public SOC 2 artifact is a blog post from April 2024, under its former name, naming no auditor and stating no periodA Type II report covers a window. No window, no assurance. Contrast the vendors that name Armanino, AARC-360 and Prescient Assurance
    SOC 2 without Type I or Type II specifiedOne security page cites SOC 2 Trust Services Criteria and never states which typeType I is design at a point in time; Type II is operating effectiveness over months. Do not write Type II unless the vendor did
    Attestations locked behind a gateOne vendor's SOC 2 and pen-test reports require account creation and roughly 24 hours of provisioning, and its public security pages are blocked to crawlersNot disqualifying, but publicly verifiable is then false for that row. Score what you can actually check
    A named integration list with no technical documentationOne vendor names 13 cores and another names 17 platforms, as logo tiles with no per-integration docs. One password-protects every core integration page on its own siteJack Henry's own words: not every fintech integrates to all cores. Settle it at VendorQA@jackhenry.com
    An agent that is a roadmapTwo products marked coming soon on the vendor that otherwise has the strongest posture here; a delisted vendor's agents slated for Q4 2026 and early 2027; a suite vendor's own release putting agentic AI in the future tenseYou are buying a roadmap at agent prices. Ask what is in production today, at a named institution
    An orchestrator reselling someone else's modelOne vendor's published subprocessor list names a third-party conversational platform as the dialog engineFine, but it changes the data-flow diagram, the model-risk question and who you escalate to at 2am. It was only findable because that vendor publishes subprocessors
    A vendor whose only agent is someone else'sOne digital banking platform's agentic AI is another roster vendor's product, rented through a partner programmeYou may be paying a platform margin for something you could contract for directly
    Funding staleness against product ambition$2.6M seed roughly 29 months old; $152M raised but last round March 2022; last confirmed round June 2021 despite three acquisitions sinceNCUA cannot examine any of them. Vendor viability is your diligence problem alone
    Ownership you cannot establish at allTwo vendors in the ranked table have no locatable funding round, investor or parentThe methodology requires ownership from public record. Where it cannot be established, print that
    An unresolved corporate-control questionOne public vendor is under an activist 13D filed 29 June 2026 pushing exploration of a saleA five-year contract into an unresolved ownership question
    A customer case study where the customer is quoted only on experienceOne vendor-published credit union case study sources every number to the vendor; the credit union executive is quoted only on how the process feltThe metrics and the party publishing them are the same party. That is the Presto pattern in miniature
    A performance claim that movesOne automation claim went from up to 60 percent in 2024 to up to 80 percent-plus in 2026; one partner asset figure appears as both $90B and $70B-plus; one vendor's boilerplate moved from 150-plus lenders to 160-plus and from $3.9 trillion to $4 trillion-plus in about twelve weeksA number that drifts without a restated methodology is marketing, not measurement
    A claim that abuses the word independentOne vendor badges an independent benchmark study showing its credit unions grew 9X versus an industry median, naming no publisher, no author and no methodology; its independent recognition section lists revenue-growth and promising-company awardsRevenue-growth rankings are not product evaluations. This is exactly why the term needs defining

    The Numbers We Refused to Print

    Each of these was chased to origin. Where the origin does not support the claim, we say so and print nothing — and your vendor should be held to the same standard.

    Branch versus digital cost-to-serve — refuse every variant

    The familiar ladder — roughly a dollar per teller transaction down to a penny per internet transaction — fails at four separate points. First, the attribution is a thirty-year-old error. The oldest datable instance is a US Senate Banking Committee hearing chart dated 29 July 1997, and it credits Gemini Consulting 1996, not Booz Allen; Booz Allen's own 1996 article on this exact topic contains no per-transaction ladder at all. Second, its scholarly entry point is already a blend. BIS Papers No 7 of November 2001, Table 2, indexes branch 100, phone 50, ATM 27, PC 8, internet 1 — footnoted as a simple average of three studies, cited second-hand, and expressly excluding customer support cost. Third, the one rigorous study is systematically miscited. The FMSI Teller Line Study, 1992 to 2015 across more than 17 million transactions, measured teller labour cost per transaction only — no occupancy, no technology, no overhead — running $0.48 in 1992 to $0.85 in 2007 to $1.08 in 2013, and it published no digital comparison whatsoever. Any citation of the form FMSI says branch X versus digital Y is fabricated at the point of comparison, and the peak figure is roughly a quarter of what is routinely attributed to it. Fourth, the laundering is visible in the open: a widely-read analyst wrote that a source article did not include call-centre estimates, so let us assume a figure — then tabled that assumption beside real citations, and downstream copies reproduce it as data.

    And the regulator evidence points the other way. OCC work by Furst, Lang and Nolle and Federal Reserve Bank of Kansas City work by Sullivan, both from 2000 and summarised in that same BIS paper, found internet-banking banks had similar or worse costs and profitability. BIS's own conclusion is quotable: while many individual banks claim to be making efficiency gains, there is little sign of it in aggregate banking statistics. No post-2020 primary measurement of branch-versus-digital cost-to-serve exists. Vendors still publish the figure sourceless — one digital banking vendor published $4 to $6 branch versus $0.08 to $0.15 digital in April 2026 with no citation at all.

    Core conversion cost and duration

    The $2 to $5 million range has no traceable origin: exact-phrase searches return zero results, and the nearest thing to a source is an AI-generated SEO guide by a loan-origination vendor attributing a range to Cornerstone Advisors with no link and no footnote. Cornerstone's survey work is real and substantial — 416 executives — but it publishes no such figure, and Cornerstone sells core conversion consulting, advertising more than 350 conversions, which makes it a market participant rather than a benchmark publisher. Print that disclosure wherever the firm is cited. The 12 to 18 months figure traces to a GonzoBanker piece of 3 January 2013 that was a planning recommendation for merger-and-acquisition systems integration — a different exercise entirely; the origin of 18 to 24 months could not be located. The per-member figures circulating are conflated with 2018 recurring contract costs where samples run as low as two institutions and one core's mean and median differ by more than twenty-fold. Nobody in the credit union trade infrastructure publishes a conversion-cost figure, and that absence is the story — credit unions do not file with the SEC, which is why the only genuinely primary numbers anywhere are bank earnings disclosures of per-quarter project expense.

    Deflection, containment and approval-lift rates — and one site to never cite

    There is no independent benchmark of chatbot deflection or containment for credit unions or retail banking. What circulates are vendor figures with no source, sample or denominator: can be over 80 percent — note can be, which is a best case, not a mean — 45 percent in the first month, over 70 percent, 50 to 70 percent, 88 percent-plus on 11.8 million questions carrying the vendor's own disclaimer that rates vary by configuration and use case, and a 95 percent containment rate. One vendor in the space concedes the point usefully: most AI chatbot vendors advertise deflection rates of 70, 80 or even 90 percent. And gitnux.org is a statistics-fabrication site — it publishes figures such as an 85 percent resolution rate and a share of US credit unions using AI behind a logo wall of trade and agency marks, with zero citations and no links. Never cite it, and expect a competing article to have.

    Two regulatory claims that are simply untrue

    NCUA's 2026 supervisory priorities do not mention AI. Letter 26-CU-01 was fetched and word-boundary counted across 2,373 words: AI zero, artificial intelligence zero, machine learning zero, model risk zero, fair lending zero, Regulation B zero, and the word model in any use, zero. The accompanying 19 February 2026 webinar deck, 1,059 words, also contains zero AI mentions. Two vendor blogs assert otherwise. One, published 23 July 2026, states that NCUA named AI oversight as an examiner focus area — and hyperlinks that phrase to NCUA's internal federal AI-use page, so its own citation refutes it. The other states that the priorities explicitly include AI and that NCUA hired three AI officers to support examination teams, with zero citations for either. The three-officers claim garbles NCUA's AI Compliance Plan of September 2025, which names four review roles, contains zero occurrences of examiner and zero of hire, and governs NCUA's own use of AI rather than its supervision of yours. Several other vendors named alongside these in circulation quote the letter correctly and make no such claim; do not repeat an accusation you have not checked. And CFPB Circular 2026-03 does not exist — Federal Register count zero, as set out above.

    Also refused, per this series' standing list: the MIT-attributed claim that 95 percent of GenAI pilots fail, which rests on 52 interviews and 153 conference surveys of custom tools; the claim that 85 percent of AI projects fail, which misquotes a 2018 prediction about output quality; the claim that 87 percent never reach production, which originates in a sponsored post's rhetorical question; and the Gartner figure that 40 percent of agentic projects will be cancelled by 2027, which measured investment posture rather than project outcomes. We also do not print credit-union-specific core market-share percentages, because none could be verified to a primary source — the 70 and 42 percent figures above describe depository institutions, which is what the OCC actually said.

    Limitations — What We Could Not Verify

    A ranking that refuses vendor claims and then hides its own uncertainty has learned nothing. Everything below is a gap in this article, stated plainly, checked on 23 August 2026.

    • There is no independent evaluation of any product ranked here. We scored disclosure quality, which is a proxy for institutional seriousness — not for whether the software will do your work well.
    • Whether Congress has enacted NCUA third-party vendor examination authority as of your reading date. Re-check congress.gov; this is the fact on this page most likely to move.
    • The CFPB's current institutional condition — funding-cap figures, staffing levels, reduction-in-force litigation and the current Director. Both gao.gov and consumerfinance.gov block automated fetching, so we built no argument on any of it. The load-bearing facts here are the $10 billion supervisory threshold and the Regulation B amendments, both of which are verified.
    • The FinCEN AML/CFT program rule's final status and compliance date, the Corporate Transparency Act beneficial-ownership regime in 2026, and any CDD rule revision. All unverified. NCUA's own letter says only that significant developments and changes in the regulatory system are expected in 2026, which is a safe way to describe the landscape without asserting a status.
    • The docket number and current posture of the Regulation B challenge come from legal-press reporting rather than a docket pull. Confirm on PACER or CourtListener before printing a case caption.
    • The Federal Reserve Bank of Kansas City core-concentration briefing was not read directly — the host blocks automated fetching — so the 70 and 42 percent figures are cited as quoted by the OCC in the Federal Register, which is itself a primary source.
    • Upstart's current 2026 marketing figures could not be verified; upstart.com returns HTTP 403 to automated requests and no 2026 archive capture was available. We describe the comparison structure and quote nothing.
    • Two findings from the Relman Colfax Final Report — the absence of close proxies and the approval disparities for Black applicants — come from the monitorship record rather than a direct read of the full PDF. The two passages we quote verbatim were verified at source.
    • Unit21's current chief executive. Two sources conflict and we printed no name.
    • Alkami's partner directory could not be checked at all; alkami.com/partners returns HTTP 403 to every method including a real browser. Those cells are unverifiable rather than absent, and we say so.
    • Credit-union-specific core market-share percentages. None verified to a primary source; we print the depository-institution figures the OCC actually published.
    • Adoption, customer-count and scale figures throughout this article are vendor-published without exception and are attributed in text wherever they appear.

    Two cross-ties belong here rather than in the vendor entries, because they are structural rather than damning. A former Acting Comptroller of the Currency sits on one vendor's board and advises another in this table. And a credit-union-owned venture fund has money in two of these vendors and gave one of them an award. Neither is a scandal — the CUSO structure exists precisely so credit unions can invest in their own infrastructure, and two of the decisioning vendors discussed here are CUSOs with credit-union investors. But it does mean several of the awards and strategic investments these companies cite are not arm's-length, and should not be read as third-party validation.

    The honest closing position. Most of the products above are eighteen months old or less, in a market that has watched one leader acquired in June, one rename itself in February, one delisted in October and one of its best-known lending platforms apply to become a bank in July. The constraints, by contrast, are between five and twenty-five years old and are not moving: NCUA cannot examine your vendor, you must still report its breach in 72 hours, your adverse-action notice must state real principal reasons, and your core provider controls whether any of this connects to anything. Buy against the constraints, not against the roadmaps — and treat every performance number in this category as marketing until somebody publishes a methodology, which in this vertical nobody yet has.

    Want a Vendor Diligence File That Survives an Exam?

    Book a free 60-minute discovery call with Frenchy Digital — a senior-led Black-owned Los Angeles agency. You leave with a workflow census across member service, lending and BSA, a vendor file mapped to 12 CFR Part 748 Appendix A III.D and III.F, the notification-SLA language that protects your 72-hour clock, and a fixed-price phased proposal within 5 business days. Call +1 (424) 272-5601.

    Want a Vendor Diligence File That Survives an Exam?

    Book a free 60-minute discovery call. You leave with a workflow census, a vendor file mapped to Part 748 Appendix A, and a fixed-price phased proposal within 5 business days.

    1517 S Bentley Ave Unit 204, Los Angeles CA 90025

    Frequently Asked Questions

    Sources & References

    1. 1Juniper Research press release, 24 July 2017 — the forecast both agencies cite (Wayback capture)
    2. 2CFPB, Chatbots in consumer finance — issue spotlight, 6 June 2023 (PDF)
    3. 3GAO-25-107197, Artificial Intelligence in financial services regulation, 19 May 2025 (PDF)
    4. 4CFPB blog, 6 August 2019 — the non-replication disclaimer on the Upstart figures
    5. 5CFPB order terminating Upstart's No-Action Letter, 8 June 2022
    6. 6CFPB, Policy Statement on No-Action Letters — applicable 10 January 2025
    7. 7Relman Colfax, Upstart fair-lending monitorship — Final Report, 27 March 2024 (PDF)
    8. 8Relman Colfax, Upstart fair-lending monitorship — Initial Report, 14 April 2021 (PDF)
    9. 9Upstart Holdings, Inc. — FY2025 Form 10-K, filed 10 February 2026 (SEC EDGAR)
    10. 10Upstart receives OCC conditional approval to establish Upstart Bank, N.A., 23 July 2026
    11. 11Equal Credit Opportunity Act (Regulation B) final rule — 91 FR 21620, effective 21 July 2026
    12. 1212 CFR §1002.9 — adverse action notification and specific reasons (eCFR)
    13. 13CFPB guidance withdrawal — 90 FR 20084, 12 May 2025 (Circular 2022-03 is item 14)
    14. 14NCUA, Third-Party Vendor Authority white paper, March 2022 (PDF)
    15. 15NCUA Letter to Credit Unions 26-CU-01, NCUA's 2026 Supervisory Priorities (January 2026)
    16. 16NCUA, Artificial Intelligence regulatory compliance resources — Does NCUA have AI specific regulations? No.
    17. 17NCUA, Artificial Intelligence Compliance Plan (September 2025) — four review roles, zero occurrences of examiner
    18. 1812 CFR Part 748 — security program, incident reporting and Appendix A member-information guidelines (eCFR)
    19. 19NCUA, Quarterly Credit Union Data Summary, 2026 Q1 (PDF)
    20. 20OCC, Request for Information on community banks' engagement with core service providers — 90 FR 54882, 28 November 2025
    21. 21Interagency Guidance on Third-Party Relationships: Risk Management — 88 FR 37920, 9 June 2023 (NCUA is not an issuing agency)
    22. 22Jack Henry Fintech Integration Network (formerly VIP) — 244 verified members and the endorsement disclaimer
    23. 23SEC, In the Matter of Presto Automation Inc. — Rel. 33-11352 / 34-102177, 14 January 2025 (PDF)
    24. 24BIS Papers No 7, Electronic finance: a new perspective and challenges (November 2001) — Table 2 (PDF)
    25. 25US Senate Banking Committee hearing chart, 29 July 1997 — credits Gemini Consulting 1996, not Booz Allen (Wayback capture)
    Chris Machetto - CEO & Founder of Frenchy Digital

    Chris Machetto

    CEO & Founder of Frenchy Digital. Building apps and digital products since 2019 for startups and enterprises across LA, San Francisco, Paris, Geneva, and more globally.