Corlytics
Corlytics is an AI-powered regulatory risk intelligence platform from Dublin. It combines regulatory monitoring, a digitised regulation library, obligations, policy management, controls mapping and non-financial risk for banks, insurers, regulators and life sciences.
What is Corlytics?
Corlytics is an AI-powered regulatory risk intelligence platform published by Corlytics Limited, an Irish company based in Dublin. Its positioning line is Regulation Actioned, and the product is organised around a four-stage value chain: Find, Understand, Implement and Evidence.
Find covers horizon scanning across the volume of regulatory change, which the company puts at 30 million pages of text a year, gathered through direct connections to international regulators. Understand applies machine learning and data science to analyse large volumes of legal text in real time and in several languages; Corlytics describes its approach as picking the best tool for the job and validating results scientifically. Implement turns that analysis into work: regulatory change management, red and green lining, obligation extraction and policy management. Evidence closes the loop with proof of compliance, a full audit trail, dashboards and reporting tools.
The platform is modular. The named modules are Regulatory Monitoring, Regulation Library, Regulatory Risk Analytics, Policy Management (which came from the acquisition of Clausematch), Regulatory Obligations Management, Regulatory Change Management, Regulatory Compliance Monitoring, Regulatory Controls Mapping, Non-financial Risk Management and Taxonomy Manager, the last in separate editions for firms and for regulators. Thematic trackers cover financial crime, crypto, payments, digital assets and ESG horizon scanning.
The audience is explicitly institutional: global banks, private banks, hedge funds, asset and investment managers, insurers, payments and big tech, regulators, and health and life sciences. Corlytics states that it serves 40% of the 30 largest systemically important financial institutions and names ING, BNY Mellon, ScotiaBank and Swiss Re among its clients; it also cites work with regulators, including the FCA, on regulation and intelligent taxonomies. It claims to be the first dedicated RegTech certified to ISO 42001 for AI governance.
What Corlytics is not is just as clear from the site. There is no self-service sign-up and no published price: access runs through a sales conversation and a contract, then through the client application at app.corlytics.com. A first-party API answers at api.corlytics.com but carries no public documentation. This is enterprise software for regulated organisations, not a tool an individual can pick up.
What it does
- Track regulatory change across global regulators and filter out the noise
- Classify and summarise regulatory documents and assess their impact
- Extract obligations automatically from regulatory text
- Map obligations, policies and controls, and run a gap analysis
- Manage the policy lifecycle: collaborative drafting, templates, review, distribution and attestation
- Analyse enforcement actions taken by regulators worldwide
- Produce dashboards, customised reports and a complete audit trail
When to use Corlytics / When not to
A quick filter to help you decide if Corlytics is the right fit.
When to use Corlytics
- Compliance, risk, legal and audit teams inside regulated financial institutions
- Regulators and supervisory authorities, served by a dedicated Taxonomy Manager edition and by stated work with the FCA
- Large multi-jurisdiction groups facing a high volume of regulatory change
- Health and life sciences organisations, covered by a dedicated vertical
- Organisations that must evidence their compliance through a complete audit trail
When not to use Corlytics
- Individuals, micro-businesses and one-off users: this is enterprise software sold under contract
- Buyers who need a published price before speaking to a salesperson, as no rate is disclosed anywhere
- Teams expecting a free plan or a self-service trial, since neither is advertised
- Mobile-first users, as no iOS or Android application is published
- Anyone looking for a general-purpose office suite or writing assistant: the scope is strictly regulatory
How to use Corlytics
A typical end-to-end flow, from setup to results.
- Read the solutions pages to identify which modules match your regulatory scope
- Request a demonstration through the 'Arrange a demo' or 'Get in touch' form, as there is no self-service sign-up
- Discuss scope and cost with the sales team, since no rate is published
- Contract with Corlytics and have your account set up by the vendor
- Sign in to the client application at app.corlytics.com
- Configure your regulatory perimeter: jurisdictions, obligations, policies and controls
- Connect the platform to IBM OpenPages or ServiceNow so that Corlytics data feeds your existing controls and workflows
- Ask the vendor about the first-party API at api.corlytics.com for bespoke integration, as no public documentation exists
- Request customised reports, which the official FAQ confirms are available on demand
- Use your dedicated Corlytics team or support@corlytics.com for day-to-day support
Pros & Cons
Pros
- End-to-end functional coverage, from horizon scanning to attestation, presented by the vendor as unique on the market
- Three certifications attributed explicitly to Corlytics: ISO/IEC 27001, SOC 2 Type 1 audited by Thoropass, and ISO 42001 for AI governance
- Documented native integrations with two major GRC platforms, IBM OpenPages and ServiceNow
- Blue-chip client references and stated work with regulators, including the FCA
- A named and contactable Data Protection Officer, with a detailed privacy notice covering both the UK GDPR and the EU GDPR
- Solid financial backing since Verdane's majority investment of April 2024
- Group structure and legal entities published openly
Cons
- No price is published at all: /pricing/ returns a 404 and cost can only be established through a sales conversation
- Neither a free trial nor a free plan is announced
- A first-party API exists but has no public documentation whatsoever
- No data processing agreement is mentioned anywhere on the site
- No sub-processor list is published, and nothing is said about whether customer data trains AI models or whether an opt-out exists
- Hosting countries are not named: the site offers only the phrase 'Geo-specific hosting'
- No terms of service are published: the /legal/ page is a website legal notice on content, trademarks and links, not a service contract
Pricing & Plans
Corlytics publishes no pricing information of any kind. There is no pricing page (the /pricing/ URL returns a 404 and no such page appears in the sitemap), no rate card and no order of magnitude anywhere on the site. The pricing model is therefore recorded as Contact-sales, and the starting price, currency and billing unit fields are all left empty together, since no amount has ever been published. No free trial and no free plan are announced either: the site does not refuse them, it simply never mentions them. Commercial contact runs through the 'Arrange a demo' form, by telephone on +353 1 903 8761 in Dublin, or by email to info@corlytics.com.
- Corlytics presents its offer by functional module rather than by package
- Regulatory Monitoring
- Regulation Library
- Regulatory Risk Analytics
- Policy Management
- Regulatory Obligations Management
- Regulatory Change Management
- Regulatory Compliance Monitoring
- Regulatory Controls Mapping
- Financial Services
- and Health and Life Sciences
Data, GDPR & hosting
A consolidated view of how Corlytics handles your data.
GDPR overview
Corlytics publishes a detailed privacy notice, effective November 2025, covering both the UK GDPR and the EU GDPR. A Data Protection Officer is named, Luca Dalla Giacoma, contactable at dpo@corlytics.com and at Miesian Plaza, Dublin 2. The notice enumerates data subject rights: information, access, rectification, erasure, restriction, portability, objection and rights over automated decisions, with a one-month response target extendable by two months where a request is complex. Transfers outside the UK and EEA rely on adequacy decisions, the European Commission's standard contractual clauses or other recognised safeguards. Listed security measures include access control and authentication, policies and training, incident notification, IP anonymisation, network security, continuity and recovery, regular testing, contractual confidentiality and encryption, alongside breach notification without undue delay. A separate CCPA section addresses California. No Article 27 representative is designated, and none is needed: the publisher is established in Ireland.
Who owns the data?
Corlytics acts as a controller under its privacy notice, effective November 2025, which covers the individuals it interacts with other than its staff, its customers and the users of its application: software users, job applicants, office visitors, prospects, suppliers and website visitors. Personal data may be shared with its own staff, with contracted technical suppliers, with public authorities such as HM Revenue and Customs, with professional advisers and with any potential buyer of the business. The notice states plainly that personal data is not sold for marketing purposes. No published clause addresses ownership of the customer content loaded into the platform: that question belongs to the client contracts, which Corlytics does not publish.
Reuse rights
The privacy notice cites six possible lawful bases and relies mainly on performance of a contract, legal obligation, consent and legitimate interests. Software user data is processed on consent for account creation and on legitimate interests for account set-up; marketing and newsletter data rest on legitimate interests and consent; job applications, supplier personnel and office security rest on legitimate interests or contract. Corlytics states that it uses no automated decision-making and no profiling, and undertakes to update the notice should that change. Website analytics are self-hosted, cookie-free and IP-anonymised, while the HubSpot CRM sets opaque identifier cookies. Nothing anywhere on the site mentions customer data being used to train AI models, in either direction. And because Corlytics publishes no service terms at all, the site sets out no reuse rights over platform data or outputs for the end user: the /legal/ page is a website legal notice about content, trademarks and links, not a service contract.
Data retention & training
Hosting summary
Corlytics names no hosting country and no region. The only hosting statement on the site is the phrase 'Geo-specific hosting', listed as a guiding principle of its security programme on the security and resilience page, with no jurisdiction attached to it. Its ISO/IEC 27001 certification is described as covering all activities of Corlytics Limited in the delivery of data and software delivered from its cloud solutions, and a SOC 2 Type 1 report, issued by the independent CPA firm Thoropass, assesses the design of controls at a point in time across security, availability, processing integrity, confidentiality and privacy. The privacy notice frames transfers outside the UK and EEA through adequacy decisions, standard contractual clauses or other recognised safeguards, which is a transfer clause and not a hosting declaration. Technical suppliers are mentioned for the hosting of the website, but none is named. The hosting country and region fields are consequently left empty: nothing published supports naming a jurisdiction, and infrastructure signals observed from outside, such as a content delivery network serving the client application, describe delivery rather than data residence.
Where Corlytics works
Country-level availability.
Not available in
Things to keep in mind
Risks and trade-offs to weigh before adopting Corlytics.
- Two authentic but competing addresses. The registered office recorded at the Irish CRO, at GLEIF and in the privacy notice is Floor 3, Block 3, Miesian Plaza, Dublin 2, D02 Y754, while the footer and VAT address, confirmed independently by VIES, is Nexus Building, Belfield Office Park, Clonskeagh, Dublin D04 V2N9. Neither is out of date, but check which one your contract names.
- No terms of service are published. The /legal/ page is a website legal notice on content, trademarks and links, not a service contract, so commercial, liability and data-processing terms only become visible during contracting.
- Obligation extraction and document classification are AI-driven, and the site publishes no accuracy commitment or service terms to sit behind them: outputs still need qualified human review before they drive a compliance decision.
- The company name appears in three spellings: 'Corlytics Ltd' in the footer and at VIES, 'CORLYTICS Limited' on the legal page, and 'CORLYTICS LIMITED' at the CRO. Corlytics Limited is the form used here.
- Corlytics is a multi-entity group. Alongside Corlytics Limited (Ireland, 535110), the publisher named in the legal notices, it includes Corlytics Solutions Limited (UK 10733490), ClauseMatch Limited (UK 08175056), Corlytics UNIPESSOAL LDA (Portugal, NIF 517023440) and ClauseMatch Inc DBA Corlytics (Delaware 7945123). The parent is Green Horizon BidCo Limited (Ireland 760734, registered 27 March 2024), Verdane's acquisition vehicle; the ultimate beneficial owner cannot be identified publicly, the Irish beneficial ownership register being closed to the public.
- Office addresses differ between sources. Lisbon is given as Rua Mouzinho da Silveira 32 on the contact page but as Rua Francisco Tomas da Costa 10 in the privacy notice; New York is 401 Park Avenue South on the contact page but 43 West 23rd St in the privacy notice.
- Read the site's logos carefully. The partner marks (Enterprise Ireland, EPA, ICA, CeADAR, Chainalysis, Solidatus, Fimatix and others) are partnerships and memberships rather than product integrations, and the AIFintech100, RegTech100, ESGtech100, FinCrimeTech50 and Chartis badges are awards and rankings, not certifications. Note too that the ClauseMatch brand has been absorbed, clausematch.com now redirecting to corlytics.com, and that the /legal-2/ page is a byte-for-byte duplicate of /legal/.
Setup & Integrations
Technical difficulty
Setting up Corlytics is an enterprise project rather than an installation. There is no self-service sign-up: access begins with a sales conversation and a contract, after which the platform is delivered as cloud software through the web application at app.corlytics.com. The real effort is configuration, mapping obligations, policies and controls onto your own regulatory perimeter. Integrations with IBM OpenPages and ServiceNow are described as native to the host product. A first-party API exists but is undocumented publicly, so bespoke integration must go through the vendor, and the site offers no tutorial, getting-started guide or public technical documentation.
Deployment
Integrations
Behind Corlytics
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What is Corlytics?
What solutions does Corlytics provide?
Who benefits from Corlytics?
What is regulatory risk intelligence?
Can I obtain customised reports?
Does Corlytics help with enforcement actions?
How much does Corlytics cost?
Is there an API?
What certifications does Corlytics hold?
Who publishes the tool, and is there a mobile app?
Should you pick Corlytics?
Corlytics is a mature enterprise platform rather than a tool you try out. Backed by a majority investor since April 2024 and certified to ISO/IEC 27001, SOC 2 Type 1 and ISO 42001, it covers the regulatory risk value chain end to end: horizon scanning, a digitised regulation library, obligation extraction, policy management, controls mapping, non-financial risk and the reporting needed to evidence compliance. Native integrations with IBM OpenPages and ServiceNow let it sit inside an existing GRC estate rather than replace it, and the named clients and regulator work match that ambition.
The counterweight is documentary opacity. No price is published anywhere: no pricing page, no rate card, no free plan, no free trial, so evaluation starts with a sales conversation. Several things a compliance buyer would normally check are missing too: no data processing agreement is mentioned, no sub-processor list is published, no hosting country is named beyond the phrase 'Geo-specific hosting', and nothing is said about whether customer data trains models. There are no service terms either, the legal page being a website notice on content and trademarks rather than a contract.
None of that makes the platform weak; it makes due diligence a private exercise. For a regulated group with real volumes of regulatory change, several jurisdictions to reconcile and an audit trail to produce, Corlytics is squarely aimed at you, and its security and AI-governance certifications go further than most of this market publishes. If you are smaller, want to self-serve, or need contractual and hosting answers before the first meeting, the site will not give them to you.
- Choosing a selection results in a full page refresh.
- Opens in a new window.