FinregE
AI powered regulatory compliance platform for regulated institutions, positioned as a regulatory operating system rather than a point solution. Seven modules span FinregE Horizon for horizon scanning and regulatory change management, FinregE Library for machine readable rules and legislative text, FinregE Map for mapping rules to internal policies and controls, FinregE Workflows for impact assessments and approval chains, FinregE Governance for policy drafting and version control, FinregE Action for regulatory project and task management, and FinregE Assurance for risk assessment and control testing. The AI engine is AI RIG, which classifies, tags and prioritises regulatory changes, summarises them, extracts obligations, maps those obligations to existing internal controls and procedures while highlighting gaps, assists in policy drafting by suggesting language against regulatory requirements, and answers questions within controlled workflows. The vendor states that every AI output is source cited for audit defensibility, and that the platform preserves an immutable audit trail recording who assessed a change, what changed, when it changed, why it was actioned, the evidence supporting the decision and the workflow routing history. Mappings are dynamic: when a regulation changes the system flags the affected policies and controls for review. Coverage is stated as more than three million regulatory data points drawn from over 2,000 sources across more than 160 jurisdictions, spanning prudential regulation, conduct, AML, sanctions, data protection, operational resilience, consumer duty, tax, reporting and ESG. Named regulators and regimes include the PRA, ECB, EBA, Basel Committee, SEC, FCA and CFPB, and MiFID II, AIFMD, Solvency II, PSD2, MiCA, DORA and AMLD6. Founded 2018, based at Level 39, One Canada Square, Canary Wharf, London. Holds a strategic investment from Moody's Corporation, an Innovate UK AI grant, and a natural language processing research collaboration with Imperial College. Selected by the Financial Conduct Authority to redesign, host and manage the FCA Handbook website. Certified to ISO/IEC 27001:2022, holds Cyber Essentials Plus, is FSQS registered, and is hosted on Microsoft Azure with single sign on, role based access control and an API first architecture.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
AI RIG is named as a distinct engine and reaches across all seven modules rather than sitting in one: classification, tagging, prioritisation, summarisation, obligation extraction, obligation to control mapping, policy drafting assistance and question answering. The vendor states production AI since 2018 and holds an Innovate UK AI grant and an Imperial College NLP research collaboration, so the model work is evidenced rather than asserted. Held at B rather than A because the spine underneath is a regulatory registry and workflow system that would still function as a rules inventory, task tracker and control testing tool with the AI removed. The AI makes it fast; it is not the only thing being sold. Compare Reveal at A, where removing the models removes most of the product.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
The claim is squarely made and the documentation behind it is not published. The vendor states that every AI output is fully source cited for audit defensibility, and separately that governance documents remain traceable back to regulatory requirements. Source citation on generated output is the right architecture for this use case and is more than most of the category claims. What does not exist anywhere in public: any accuracy figure, any extraction precision or recall number for obligation extraction, any hallucination rate, any published evaluation or test set, any independent benchmark, and any statement of what the system does when it cannot answer. Searched the home page, the AI Regulatory Expert page, the horizon scanning page, the RIG MAPS page, the news and blog index and the Terms of Use on 29 Aug 2026. Obligation extraction against regulatory text is a measurable task and nothing measured is published.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
The oversight model is documented in product terms rather than asserted as a principle. Output is framed throughout as AI assisted and AI guided rather than autonomous: the AI proposes obligations, suggests policy language and recommends control alignments, and FinregE Workflows routes every regulatory assessment to named stakeholders through defined approval chains with assigned ownership. The audit trail records who assessed, what changed, when, why it was actioned, the supporting evidence and the routing history, so a human decision point is recorded rather than implied. Held at B because no autonomy threshold is published: nothing states where the system acts without review, and no confidence score or escalation rule is described. The oversight is structural, from workflow design, rather than a stated policy a buyer could test.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
The strongest evidence on this record and the most unusual on the index so far: the vendor was selected by the Financial Conduct Authority to redesign, host and manage the FCA Handbook website. A regulator adopting the product to publish its own rulebook is a materially different class of evidence from a customer logo, because the buyer is the body whose text the product structures. Also named: a strategic investment from Moody's Corporation, FSQS registration, and a published case study claiming a 60 percent reduction in cost and a 100 percent reduction in risk at a UK bank. Held at B on two gaps. The case study figures carry no methodology, no baseline and no measurement period, and a 100 percent risk reduction is the unfalsifiable absolute shape this index does not credit. Every customer testimonial is anonymised by tier and sector rather than named. Note for a later reader: the home page counters for jurisdictions covered, weekly change volume, uptime and user numbers render client side and returned zero when fetched on 29 Aug 2026, so those figures were not captured and are not relied on here.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Nothing published that a buyer could check. No confidentiality commitment, no statement on how customer content is handled, no data processing agreement and no privacy policy were located. The only legal document published on the site is a Terms of Use that governs the marketing website rather than the platform, disclaiming the accuracy of site content and excluding liability for reliance on it. A buyer who clicked Terms of Use expecting product terms would find a website disclaimer. Checked the site navigation, the full site footer, the company page, the contact page, the sitemap page and the Terms of Use on 29 Aug 2026. This is an absence of publication rather than a finding about the product, and the platform serves Tier 1 banks and a regulator, so contractual protections almost certainly exist in the paper a customer signs. They are not public, and this index grades what is public.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
Not addressed in any located material. The product outputs regulatory interpretations, obligation extractions and drafted policy language, and the vendor markets to Legal and General Counsel as one of six named stakeholder audiences, so the question of whether output constitutes advice is live. Nothing states that output is not legal advice, nothing addresses the role of the qualified professional reviewing it, and no professional responsibility positioning of any kind was located. Checked the home page, the company page, the AI Regulatory Expert page, the stakeholder sections addressed to Legal and General Counsel, and the Terms of Use on 29 Aug 2026. The workflow design does require human assessment and sign off, which is the substance of the protection, but the vendor never says so in these terms.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Nothing published about this vendor's own model governance. The gap is worth naming precisely because the vendor publishes extensively about AI governance as a customer problem: blog material on AI governance frameworks for banks, coverage of the EU AI Act and AI governance regimes as tracked subject matter, and a public sector offering that helps agencies ensure AI governance. None of that is disclosure about FinregE's own system. Located nothing on model evaluation, bias testing, human review of model behaviour, drift monitoring, an AI policy, or ISO 42001. Checked the home page, the AI Regulatory Expert page, the company page and the blog index on 29 Aug 2026. Research limitation recorded rather than assumed: the home page FAQ includes an entry asking whether the AI is suitable for regulated environments, and the answers render client side and did not load, so that answer is unread. If it contains governance disclosure this grade is a correction candidate.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
No stewardship position located for customer content passing through the AI. Nothing states whether customer documents, policies and control libraries uploaded to the platform are used to improve models, how long inputs and outputs persist, whether processing is segregated by tenant, or what happens to derived artifacts. Security controls exist and are graded separately under Security Certifications, and are not double counted here. Checked the home page, the horizon scanning page, the company page, the site footer and the Terms of Use on 29 Aug 2026 and located no privacy policy, no data processing agreement and no security page. For a platform ingesting a regulated institution's internal policies, procedures and control libraries, this is the disclosure a buyer most needs and it is entirely absent from public material.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
No product liability position published. The only published legal document is a website Terms of Use, which excludes liability to any user for loss arising out of the use of, or reliance on, content on the site, and excludes representations that content is complete, accurate or up to date. That is a marketing site disclaimer and it says nothing about the platform, its output, or recourse when an obligation extraction or a policy mapping is wrong. Nothing was located on indemnity, warranty, service levels, or a remedy where AI output is incorrect. Checked the site footer, the Terms of Use and the sitemap page on 29 Aug 2026. Recorded as an absence of published product terms rather than as a limitation the vendor has imposed, since the operative terms are in a signed contract this index cannot see.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
The claim is made at architecture level and no integration is documented. The vendor describes an API first architecture, states that infrastructure is only valuable if it connects, and positions the platform as the brains of the compliance function feeding intelligence into tools teams already use. A customer testimonial from a global legal professional services firm specifically credits access to the regulatory data feed through customised APIs with filtering. What does not exist in public: any named integration or connector, any GRC platform the product sits beside, any API documentation, any authentication or scope detail, and any statement of what moves in which direction. Checked the home page, the ecosystem integration section, the automated compliance solutions page and the platform footer links on 29 Aug 2026. Compare Regology at B, which names ServiceNow, Archer and Hyperproof and states that no rip and replace is required.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The hosting platform is named and nothing beyond it is. The vendor states hosting on Microsoft Azure, single sign on, role based access control and a four to twelve week implementation. No region or data residency commitment was located, which is a live question for a London vendor selling to Tier 1 banks, insurers and regulators subject to UK and EU data localisation expectations. No single tenant, private instance or in perimeter deployment option is described, and nothing states where regulatory data or customer policy libraries are physically processed. Checked the home page, the horizon scanning page, the automated compliance solutions page and the company page on 29 Aug 2026. Naming the cloud provider is a real disclosure and earns the C; residency is the artifact that would move it.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Three credentials are named and none is evidenced. Named: ISO/IEC 27001:2022 with the standard version stated and a dated announcement carrying a quote from the named COO, Cyber Essentials Plus, and FSQS registration. Naming the 2022 revision rather than the withdrawn 2013 one is a real signal and better than several records on this index. Held at C rather than B because nothing behind the claims is reachable: no auditor or certification body is named, no certificate number, scope statement or expiry date is published, no SOC 2 of any type is claimed, and there is no trust centre, security page or documentation request route of any kind. Under the three tier test the artifact is neither open nor self serve request; it is absent. The certifications appear on the home page as badge images rather than as text a reader can verify. Checked the home page badge row, the ISO certification announcement, the company page and the full site footer on 29 Aug 2026. Compare Regology at B in this same category, which names BARR Advisory as the auditing firm and states the examination scope; FinregE names neither, so B here would sit inconsistently against a record already on the roster.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Nothing located. No foundation model provider is named anywhere in public material, no statement distinguishes proprietary models from third party models, and no subprocessor list exists. The vendor describes machine learning and natural language processing built since 2018 and an Imperial College research collaboration, which implies meaningful in house model work, but implication is not disclosure and the platform's generative and question answering features are not attributed to any named model. Checked the home page, the AI Regulatory Expert page, the company page, the site footer and the Terms of Use on 29 Aug 2026. For a buyer in a regulated institution, the identity of the model provider is a subprocessor question their own regulator may ask, and it cannot be answered from public sources.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing at any level of abstraction. No price, no range, no tier structure, no unit of charge, and no statement of what drives cost, whether that is users, jurisdictions monitored, modules licensed or regulatory sources ingested. Every commercial route on the site is a demo request or a booking link to a calendar. The one adjacent figure published is a case study claiming a 60 percent cost reduction at a UK bank, which describes the customer's savings rather than the vendor's price and is not transparency about what the product costs. Checked the home page, the sign up page, the contact page and the company page on 29 Aug 2026. Common for enterprise RegTech and still an absence a buyer cannot work around.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is stated with unusual specificity for this category, at the level of named regulators and named regimes rather than a jurisdiction count alone. Regulators named include the PRA, ECB, EBA, Basel Committee, SEC, FCA and CFPB. Regimes named include MiFID II, AIFMD, Solvency II, PSD2, MiCA, DORA, AMLD6 and Consumer Duty. Regulatory themes are enumerated across prudential regulation and conduct, AML, sanctions, data protection and information security, operational resilience, consumer protection, competition, health and safety, tax and reporting, and ESG. Sector coverage is set out for banking, payments, insurance, asset and wealth management, fintech and digital assets, lending and credit, accounting and tax, healthcare and pharma, public sector and development finance, energy, aerospace and defence, and automotive and transport. Scale is stated in the ISO certification announcement as more than three million regulatory data points from over 2,000 sources across more than 160 jurisdictions. Held at B rather than A because the jurisdiction list itself is not published: a buyer can read that 160 plus jurisdictions are covered and cannot check whether their own is among them, and no update lag or refresh frequency is stated for any source.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No located term or policy addresses the question either way.
Terms are silent. No agreement addressing customer content was located, and the only published legal document is a website Terms of Use whose scope is the marketing site, as the quoted phrase shows. It says nothing about the platform, customer uploads, or model training. No privacy policy and no data processing agreement exist on the site. Checked the site navigation, the full footer, the company page, the contact page, the sitemap page and the Terms of Use on 29 Aug 2026. Recorded as silent rather than as a negative commitment: a vendor that does not say it trains on client data has not said it does not.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long prompts and outputs are retained.
Not addressed. No retention period is stated for AI prompts, generated summaries, extracted obligations or question answering exchanges, and nothing indicates whether a customer can configure or zero retention. The platform does publish that it retains a permanent audit trail of assessments and decisions, which is a deliberate retention commitment in the opposite direction and is a product feature rather than a privacy disclosure. What is missing is any statement about the AI interaction layer itself. Checked the home page, the horizon scanning page, the workflows page, the site footer and the Terms of Use on 29 Aug 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Segregation is asserted in public materials with no published detail on how it is enforced.
Claimed and not documented. The vendor names role based access control and single sign on as platform capabilities, and describes routing assessments to specific stakeholders with assigned ownership, so an access model exists and is asserted. Nothing documents how it works: no permission granularity, no statement of whether access is enforced at query time against the AI layer as well as the record layer, and no description of segregation between business units within a single institution. This product has no document management system to inherit permissions from, so the inherits value does not apply and a second model is the only available shape. Checked the home page, the horizon scanning page and the workflows page on 29 Aug 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
No located term or policy addresses third party requests for customer data.
Not addressed. No government or law enforcement request clause was located, no commitment to notify a customer before producing their data, and no transparency report. The website Terms of Use contains no such clause because it governs the site rather than the service. Checked the site footer, the Terms of Use, the company page and the sitemap page on 29 Aug 2026. Worth noting for a later reader that this vendor holds regulator relationships, including hosting the FCA Handbook website, which makes the question of what it does with a customer's compliance record when asked by an authority more pointed than usual rather than less.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Sources are identified without stating the licence or rights basis.
Sources are named at regulator and regime level with no licence basis stated. Named regulators include the PRA, ECB, EBA, Basel Committee, SEC, FCA and CFPB, and named regimes include MiFID II, AIFMD, Solvency II, PSD2, MiCA, DORA and AMLD6. Scale is stated as more than three million regulatory data points from over 2,000 sources across more than 160 jurisdictions. Most of this corpus is government published regulatory text, where a licence question is less loaded than for case law, but the vendor never says so: no licence, no public domain basis, no source list a buyer can open, and no update lag or refresh frequency for any source. The full jurisdiction list is not published, so a buyer cannot confirm their own is covered.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
The vendor computes and surfaces subsequent history itself, with the method described.
Own treatment signal, operating on regulatory text rather than case law. The vendor states that mappings are dynamic and that when a regulation changes the system automatically flags the affected policies and controls for review, and describes version history maintained against regulatory requirements so governance documents stay traceable as rules move. That is the regulatory equivalent of a currency check: it tells a user that the authority underneath their policy has moved. It is the vendor's own mechanism rather than a licensed commercial citator, and no accuracy or completeness measure is published for change detection.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Not addressed. Nothing describes what the system does when it cannot find support for an answer, and no explicit no answer path, abstention behaviour or confidence score is documented anywhere in public material. The vendor states that AI operates within controlled workflows and that output is source cited, which bounds the output without describing the uncertainty case. Checked the home page, the AI Regulatory Expert page, the horizon scanning page and the blog index on 29 Aug 2026. Research limitation recorded: the home page FAQ entry asking whether the AI is suitable for regulated environments renders client side and did not load, so its answer is unread and may bear on this signal.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
None located, and the instrument used is stated so the finding is worth what the search is worth. General web searches on the vendor name combined with court, opinion, sanction and enforcement terms returned nothing on 29 Aug 2026. No named docket database or court record tracker was searched for this record. This is a UK vendor selling compliance tooling to institutions rather than a litigation product filing into courts, so the exposure shape differs from a research or drafting tool. Recorded as a statement about what was found, not as a clearance, and a named tracker search would strengthen it.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
Not addressed. No named ethics opinion, no ABA Formal Opinion 512, no Solicitors Regulation Authority or Law Society guidance, and no bar guidance engagement of any kind was located. The vendor addresses Legal and General Counsel as a named stakeholder audience and produces drafted policy language and regulatory interpretations, so professional guidance is relevant to how that output is used. The vendor writes extensively about regulatory obligations owed by its customers and nothing about the professional duties of the lawyers using it. Checked the home page, the company page, the stakeholder sections, the blog index and the news index on 29 Aug 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Savings claims only. The published case study claims a 60 percent reduction in cost and a 100 percent reduction in risk at a UK bank, and the wider positioning is built on eliminating manual effort and duplicative work. Nothing appears on the client's side of the equation: no statement about billing for AI assisted time, no record a firm could disclose to its own client, and no fee posture of any kind. The 100 percent risk reduction figure is the unfalsifiable absolute shape this index does not credit as evidence, and it is recorded here as the claim it is.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
No located public material supports a client side disclosure obligation.
Not addressed. No subprocessor list, no model provider disclosure, no data processing agreement, no trust centre and no security documentation request route were located. A firm could not forward anything to its own client without opening a sales conversation. The vendor does publish ISO/IEC 27001:2022, Cyber Essentials Plus and FSQS registration, which is the raw material for such a pack, but names no auditor, scope or certificate and provides no route to the underlying documents. Checked the home page badge row, the ISO certification announcement, the company page, the full site footer and the Terms of Use on 29 Aug 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
Partial record, and strong for its actual forum, which is a regulatory examination or an internal audit rather than a court. The vendor states an immutable audit trail recording who assessed a change, what changed, when it changed, why it was actioned, the evidence supporting the decision and the workflow routing history, and states that this exists to demonstrate compliance to regulators, auditors and boards. Rule applied, path taken, human sign off and evidence are all recorded and exportable into board ready reports. Held at partial rather than exportable record because the model used for a given AI output is never named and no per document export of model, sources retrieved and human verification is described. Same shape as Regology, and the second record in this category to make defensibility of the trail its central claim.