Attestly.

Compare AI tools before your compliance team has to explain them

A working directory of AI tools used by advisers, banks and insurers — filtered by what actually matters to a regulated firm: data handling, training policy, and audit trail, not just features.

Read this first. Attestly summarizes public vendor documentation to help you narrow a search. It is not legal or compliance advice, and it doesn't replace your own due diligence or your compliance officer's sign-off. Some listings link to vendors through referral partnerships — see "How ratings work" below.
Category Must have

Listings

8 tools

No tools match those filters yet. Try clearing one.

How ratings work

Content last fact-checked: 22 September 2026

Each badge reflects what a vendor states in its own security documentation, trust center, or public policies — not an independent audit performed by Attestly. We link to primary sources where we can and flag anything we can't confirm as "unverified" rather than guessing.

Vendor participation is free. Where a vendor offers a referral or affiliate program, we may earn a commission if you sign up through a link on this site. That never changes which tools are listed or how they're rated — commission status is not a filter you can search by, and it isn't shown as a badge.

Before you sign a contract

  1. Confirm the vendor's current SOC 2 report and training policy directly — this page is a starting point, not a substitute for their latest documentation.
  2. Work out where the tool sits under the EU AI Act's risk tiers. The Digital Omnibus package pushed the Annex III high-risk deadline from August 2026 to 2 December 2027, so there's runway — but systems that determine creditworthiness or credit scoring, price or assess risk for life and health insurance, or drive fraud-detection decisions affecting someone's access to financial services are still named high-risk and will carry heavy documentation, oversight and conformity-assessment duties once that date arrives. Note that transparency obligations (disclosing AI interactions) were not delayed and already apply. Meeting-notes and general research tools are typically "limited risk" — but check before assuming, especially if a tool's output ever feeds a credit, pricing or eligibility decision.
  3. Check the tool against your firm's written supervisory procedures and your data protection obligations — UK/EU GDPR, FCA guidance, or Regulation S-P, depending on where you're regulated.
  4. Document the review. An undocumented "we checked" doesn't hold up in an exam.