The paperwork behind financial partnerships
Kobalt Labs sells AI-assisted risk and compliance software to financial institutions and fintech companies. Its central task is third-party risk management, or TPRM: reviewing the vendors and partners an institution relies on. The platform examines diligence materials against requirements, surfaces potential gaps and organizes the review. [1]
The underlying problem is practical. A prospective partner can submit policies, security assessments and contracts in different formats, with important information scattered across documents. Finding a clause is only the first step; deciding whether it satisfies the institution’s requirements involves context and judgment. Automation can change that division of labor without resolving every substantive question.
Founders and financing
Y Combinator lists Kobalt as founded in 2023 and a member of its Summer 2023 batch. Its founder profiles identify Kalyani Ramadurgam as chief executive and Ashi Agrawal as chief technology officer. Ramadurgam’s background includes financial-security products at Apple and AI study at Stanford; Agrawal’s includes engineering at Affirm, Nuna and Meta. [2]
A public financing announcement by Ramadurgam, reproduced in an investor’s LinkedIn post, states that Kobalt raised an $11 million Series A led by Ali Rowghani at First Harmonic, with Alloy Labs, Y Combinator and other participants. This establishes an announced financing, not revenue or valuation. The reviewed primary materials do not establish a complete funding history or audited operating financials. [3]
From documents to an accountable workflow
Kobalt describes three steps: ingesting materials, analyzing them against regulations and internal standards, and tracking the resulting risks. Its advertised functions include suggested wording, extracted data, risk reports, approvals and exceptions. The company also describes coverage of internal policies, marketing materials and security documentation. Those are product descriptions, not evidence that every relevant legal obligation is captured correctly. [1]
Analysis: the useful distinction is between a document repository and a review workflow. A repository preserves files; a workflow connects evidence, questions, decisions and ownership. A generated finding becomes operationally valuable when a reviewer can trace it to the underlying material, challenge its interpretation and record what happened next. A polished report alone cannot establish the quality of the conclusion.
A bank announcement and a later operating account
Core Bank independently announced its Kobalt partnership on January 6, 2026. The Omaha bank said it had compared the platform with competing third-party-management products and manual reviews as it developed sponsor and embedded-banking relationships. Its release described faster turnaround, but did not publish the test population, methodology or independent quality assessment. [4]
Kobalt’s July 16, 2026 case study subsequently described implemented controls-based reviews at Core, with evidence mapped to requirements and reports validated by reviewers. This is more specific evidence of operating use than the original partnership announcement, though the later account is published by the vendor. The distinction matters: an announced selection, a completed implementation and a measured production outcome are different milestones. [5]
Core Bank’s speed figures have boundaries
The Core case study compares 10–16 hours for high-risk-third-party document review before Kobalt with 1–3 hours afterward. Its footnotes specify that the earlier figure is reading time, while the later figure reflects the risk officer’s time; specialist escalation can require approximately three hours. The page also reports risk-assessment time falling from eight hours to two or three. These are workflow benchmarks, not an audited, like-for-like productivity experiment. [5]
The same account includes favorable examiner remarks and an anecdote about a partner reaching launch in five days. Neither is a published supervisory finding or regulatory endorsement of Kobalt. Favorable comments about one bank’s program cannot establish that a software product is universally compliant, and one rapid launch does not establish a typical onboarding duration. [5]
Meriwest illustrates the value of earlier questions
A Kobalt case study dated August 28, 2025 describes Meriwest Credit Union using document analysis to identify missing information before involving specialists. It reports initial vendor risk review declining from eight hours to under two. Its summary describes onboarding falling from more than six weeks to under three, while the body says three weeks; the consistent conclusion is an approximately halved reported process, rather than an exact verified endpoint. [6]
Analysis: elapsed onboarding time includes waiting as well as work. Identifying a missing document on the first day can shorten a process even if specialist review remains necessary. That mechanism is different from replacing a compliance professional. It also means that turnaround improvements depend partly on vendor responsiveness and internal coordination, not solely on AI processing speed.
Payscout offers a separate compliance example
Kobalt’s January 31, 2025 Payscout case study reports an 87% reduction in document-review time. It describes a two-month evaluation and three-day implementation, followed by screening of policies, merchant agreements and third-party materials. The account attributes fewer policy and procedural issues in subsequent document audits to feedback from Payscout’s banking partner. These are vendor-published customer claims; the underlying timing sample, error rates and audit records are not disclosed. [7]
Analysis: the example broadens the use case beyond a bank screening a fintech. A payments company can also use the software to prepare its own materials for a banking relationship. Faster preparation and fewer reported deficiencies are potentially complementary benefits, but the public case does not isolate the effects of software from process changes or increased attention to documentation.
Adoption is visible, but the denominator is incomplete
The American Bankers Association’s partner directory describes Kobalt as used by at least 50 community and regional banks and lists examples including Core Bank, Celtic Bank, Emprise Bank and Lincoln Savings Bank. The directory entry does not provide an independently validated customer census, contract status or deployment dates. Its breadth is therefore a reported adoption claim, distinct from the named operating examples above. [8]
Analysis: customer count can mean signed contracts, pilots, active users or fully deployed institutions. Those measures imply different levels of adoption. Public evidence supports a real institutional market for the product, while leaving unclear how deeply customers use it, how much business each generates and how many renew or expand.
The economics depend on usable capacity
No standard rate card, customer-level profitability analysis or audited Kobalt revenue figures were established in the reviewed sources. A claimed reduction in hours therefore cannot be translated directly into a verified return on investment. Subscription expense, implementation work, reviewer oversight and the cost of resolving incorrect findings all affect the net result.
Analysis: saved time can appear as additional review capacity, shorter queues or avoided hiring rather than an immediate payroll reduction. Revenue may arrive sooner when an otherwise-ready partnership clears review faster, but that requires demand and a viable partner. The public cases illustrate possible operating benefits without measuring the full incremental economics or proving a causal revenue increase.
Competition includes established workflows
Ncontracts provides a useful competitive reference point: its public platform spans vendor review, contract management, compliance, findings and audit, and it markets AI-assisted capabilities alongside specialist expertise. This is evidence of overlapping functionality, not a head-to-head performance ranking. [9]
Analysis: Kobalt competes with existing systems, manual professional review and the decision to extend an incumbent platform. Its opportunity lies in making document analysis materially more useful inside financial-institution workflows. An AI feature alone is unlikely to settle that competition; integration, evidence traceability, implementation effort and the treatment of difficult exceptions can matter as much as the first generated answer.
Security statements and contractual detail
Kobalt’s website advertises SOC 2 certification and says it does not train on company information. No underlying auditor report was available in the public materials reviewed, so the report’s period, scope, opinion and exceptions were not independently assessed. The marketing statement cannot substitute for those details. [1]
The privacy statement, updated January 28, 2026, names Render, Azure, OpenAI and Anthropic among subprocessors. It says the AI providers do not train on uploaded customer data and retain it only for analysis under retention and deletion arrangements. Separately, Kobalt says it retains service data during the customer relationship and for a period afterward. The notice describes U.S. processing of personal information. These are company disclosures, not a tested data-flow map or a complete account of each customer’s negotiated terms and technical configuration. [10]
Outsourcing oversight still leaves an accountable institution
The banking agencies’ 2023 third-party guidance explains that using a provider does not remove a bank’s responsibility for safe operations and legal compliance. Their 2024 community-bank guide makes the point particularly clearly for outsourcing third-party risk management itself. is not a new statute or a product-approval regime. [11][12]
On September 11, 2026, the Federal Reserve, FDIC, OCC and NCUA proposed a replacement framework emphasizing risk-proportionate oversight. The September 15 Federal Register notice says finalized guidance would replace the 2023 framework and supplemental resources. As of this October 4 research date, this is a proposal, not a completed replacement. It does not certify any vendor’s platform. [13][14]
The model-risk boundary changed in 2026
April 17, 2026 revised model-risk guidance, issued through SR 26-2, superseded SR 11-7 and SR 21-8. It expressly excludes generative and agentic AI from its scope because those technologies are evolving rapidly, while stating that institutions’ broader risk-management and governance practices should guide appropriate controls. The guidance is most relevant to banks above $30 billion in assets, with certain smaller-bank exceptions. It does not establish that every component of an AI-enabled platform falls outside model-risk guidance. [15]
Analysis: exclusion from that document is not an exemption from accountability. Incorrect citations, missed exceptions, inconsistent outputs and changes in underlying models can still affect decisions. Kobalt’s public record demonstrates implemented uses and customer-reported efficiency gains. The less visible question is sustained review quality across customers and difficult cases, alongside the economics and controls needed to make that efficiency durable.
Sources
- Kobalt Labs product and security statements; reviewed October 4, 2026SourceBack to text: ↑1↑2↑3
- Y Combinator: Kobalt Labs company and founder profiles; reviewed October 4, 2026SourceBack to text: ↑
- Kalyani Ramadurgam Series A announcement reproduced in Adam Hashchyshyn’s public post; reviewed October 4, 2026SourceBack to text: ↑
- Core Bank: partnership announcement; January 6, 2026Source · PDFBack to text: ↑
- Kobalt Labs: Core Bank customer case study and measurement footnotes; July 16, 2026SourceBack to text: ↑1↑2↑3
- Kobalt Labs: Meriwest customer case study; August 28, 2025SourceBack to text: ↑
- Kobalt Labs: Payscout customer case study; January 31, 2025SourceBack to text: ↑
- American Bankers Association partner directory: Kobalt Labs; reviewed October 4, 2026SourceBack to text: ↑
- Ncontracts product overview; reviewed October 4, 2026SourceBack to text: ↑
- Kobalt Labs Privacy Statement; updated January 28, 2026SourceBack to text: ↑
- Federal Reserve: interagency third-party guidance; June 6, 2023Official releaseBack to text: ↑
- Federal Reserve: Third-Party Risk Management, A Guide for Community Banks; May 2024Official sourceBack to text: ↑
- OCC: agencies propose revised third-party risk-management guidance; September 11, 2026Official releaseBack to text: ↑
- Federal Register: proposed third-party risk-management guidance; September 15, 2026Official sourceBack to text: ↑
- Federal Reserve: SR 26-2 revised model-risk guidance; April 17, 2026Official source · PDFBack to text: ↑