Procurement teams evaluate screening software the way they'd buy any SaaS — feature checklists, per-seat math, a polished demo. Sanctions tooling punishes that approach: the differentiators that matter in an enforcement action are invisible in a standard demo. These twelve criteria are ordered by regulatory consequence, not by demo appeal.
LEGAL & REGULATORY NOTICE This document reflects publicly available regulatory guidance as of September 2026. It is intended for educational and research purposes and does not constitute legal advice.
1. List Coverage and Freshness (with proof)
Which authorities are covered — OFAC SDN and non-SDN programs, EU consolidated, UN, UK OFSI, plus relevant export-control lists — and crucially, the measured lag between official publication and vendor availability. Ask for: per-authority update-lag figures, the process when a publisher changes format without notice, and what the product shows during a feed outage (stale data with a timestamp, or silent failure — one of these is disqualifying).
2. Match Quality Evidence
Fuzzy matching claims are cheap; evidence is not. Ask for benchmark methodology: test-set construction, false-positive rates at production thresholds, non-Latin script coverage, alias and transliteration handling. Then run your own seeded proof of concept — see the FAQ above. A vendor's reaction to adversarial test data is itself a signal.
3. Ownership and Control Analysis
Named-party matching catches the easy cases. The OFAC 50 Percent Rule and control-based designations require ownership-graph traversal. Determine whether the product does this natively, via an integration you must buy separately, or not at all — and price the gap accordingly.
4. Audit Artifacts and Verifiability
Every screening decision should produce a replayable record: what was checked, against which list versions, when, with what result — plus tamper evidence. The gold standard is artifacts a third party can verify without your involvement, such as publicly verifiable certificates a correspondent bank can check independently. Ask what survives contract termination: can you still prove last year's screenings?
5. Ongoing Monitoring Model
Onboarding screening is table stakes; designations happen to existing counterparties. Evaluate whether rescreening is triggered by list updates (correct) or only by calendar schedule (a detection lag by design), per our real-time vs batch analysis.
6. API Operability
Latency percentiles at your volumes (not averages), rate limits and overage behavior, idempotency keys, sandbox fidelity, webhook reliability for monitoring alerts, and status transparency (example). Run load tests against the sandbox before signing.
7. Alert Triage and Case Management
Analyst workload is the hidden cost center. Evaluate match-explanation quality (why did this flag?), disposition workflows, false-positive suppression with audit-safe reasoning, and escalation paths. A 1% false-positive rate at a million screens a month is ten thousand analyst reviews — the triage UX is a cost line.
8. Data Residency and Security Posture
Where screening data is processed and stored, encryption standards, tenant isolation, key management, sub-processors, and the vendor's own compliance roadmap. Review their security posture the way they will review yours — procurement is mutual.
9. Coverage of Your Corridors
Generic global coverage may under-serve your actual trade lanes. If you operate in transshipment-heavy regions, evaluate maritime and corridor-specific intelligence — see our circumvention corridors framework for what that analysis looks like.
10. Licensing Model vs Your Growth
Model onboarding plus rescreening volumes over the contract term. Scrutinize overage pricing, mid-incident limit behavior, and post-termination data access. Compare against the build-vs-buy framework so the decision is explicit, not accidental.
11. Regulatory Change Response
Sanctions regimes change by press release. Ask how the vendor ships logic updates for new programs, how customers are notified, and for a recent example with dates. The answer reveals whether regulatory tracking is a staffed function or a hope.
12. Exit and Evidence Portability
Contracts end; audit obligations don't. Confirm you can export your full screening history in a usable format, that exported evidence remains verifiable, and what access (if any) persists after termination. Negotiate this before signing, when you still have leverage.
Demo Questions That Expose Weak Products
Bring these to every vendor demo:
- Show me a party added to a list yesterday. When did your system reflect it?
- Screen this transliterated name with the vowels removed. Walk me through the match explanation.
- Show me the audit record for a screening from a year ago, and prove it hasn't been altered.
- What does your API return when I exceed my rate limit during an incident?
- My contract ends in year three. How do I prove year-one screenings to my regulator?
OFAC Framework for OFAC Compliance Commitments
U.S. Department of the Treasury (OFAC) • September 2026
EU Sanctions and Restrictive Measures
European Commission • September 2026
Frequently asked questions
What is the single most important criterion when buying screening software?
List freshness with evidence: how quickly vendor data reflects official publications, and proof of it. A vendor that cannot show you measured update lag per authority is asking you to trust the most failure-prone layer of the system on faith. Everything else — matching, workflows, reporting — operates on data that is either current or it isn't.
Should we run a proof of concept with our own data?
Yes, and seed it with known outcomes: confirmed true matches (including transliteration variants and ownership-chain cases), confirmed clean parties that resemble sanctioned names, and your actual volume patterns. A vendor confident in match quality will welcome adversarial test data; one that insists on their own demo dataset is telling you something.
How do we compare per-screen pricing against flat licenses?
Model your real volumes including rescreening, not just onboarding checks — ongoing monitoring often exceeds initial screening within the first year. Then price the failure modes: overage behavior, what happens when you exceed limits mid-incident, and whether audit-trail access survives contract termination. The cheapest per-screen price with hostile overage terms is rarely the cheapest contract.
In-depth intelligence briefings on global trade restrictions, dual-use technology controls, and maritime sanctions enforcement.

