Skip to content
Sanctions ComplianceCompliance Guide Verified Research

Sanctions Screening Software Buyer's Guide: 12 Criteria That Actually Matter

Evaluating sanctions screening vendors? Twelve concrete criteria — list freshness, match evidence, ownership graphs, audit artifacts — plus the questions that expose weak products in a demo.

Sanctix Research Desk

Global Trade & Export Control Policy Division

Published September 19, 2026(Updated September 19, 2026) 10 min read
Peer Reviewed & VerifiedRef: OFAC, EU, UN, UK OFSI program scope (Sep 2026)
18px
Sanctions Screening Software Buyer's Guide: 12 Criteria That Actually Matter

Procurement decisions deserve the same rigor as the screening itself.

Procurement teams evaluate screening software the way they'd buy any SaaS — feature checklists, per-seat math, a polished demo. Sanctions tooling punishes that approach: the differentiators that matter in an enforcement action are invisible in a standard demo. These twelve criteria are ordered by regulatory consequence, not by demo appeal.

LEGAL & REGULATORY NOTICE This document reflects publicly available regulatory guidance as of September 2026. It is intended for educational and research purposes and does not constitute legal advice.


1. List Coverage and Freshness (with proof)

Which authorities are covered — OFAC SDN and non-SDN programs, EU consolidated, UN, UK OFSI, plus relevant export-control lists — and crucially, the measured lag between official publication and vendor availability. Ask for: per-authority update-lag figures, the process when a publisher changes format without notice, and what the product shows during a feed outage (stale data with a timestamp, or silent failure — one of these is disqualifying).

2. Match Quality Evidence

Fuzzy matching claims are cheap; evidence is not. Ask for benchmark methodology: test-set construction, false-positive rates at production thresholds, non-Latin script coverage, alias and transliteration handling. Then run your own seeded proof of concept — see the FAQ above. A vendor's reaction to adversarial test data is itself a signal.

3. Ownership and Control Analysis

Named-party matching catches the easy cases. The OFAC 50 Percent Rule and control-based designations require ownership-graph traversal. Determine whether the product does this natively, via an integration you must buy separately, or not at all — and price the gap accordingly.

4. Audit Artifacts and Verifiability

Every screening decision should produce a replayable record: what was checked, against which list versions, when, with what result — plus tamper evidence. The gold standard is artifacts a third party can verify without your involvement, such as publicly verifiable certificates a correspondent bank can check independently. Ask what survives contract termination: can you still prove last year's screenings?

5. Ongoing Monitoring Model

Onboarding screening is table stakes; designations happen to existing counterparties. Evaluate whether rescreening is triggered by list updates (correct) or only by calendar schedule (a detection lag by design), per our real-time vs batch analysis.

6. API Operability

Latency percentiles at your volumes (not averages), rate limits and overage behavior, idempotency keys, sandbox fidelity, webhook reliability for monitoring alerts, and status transparency (example). Run load tests against the sandbox before signing.

7. Alert Triage and Case Management

Analyst workload is the hidden cost center. Evaluate match-explanation quality (why did this flag?), disposition workflows, false-positive suppression with audit-safe reasoning, and escalation paths. A 1% false-positive rate at a million screens a month is ten thousand analyst reviews — the triage UX is a cost line.

8. Data Residency and Security Posture

Where screening data is processed and stored, encryption standards, tenant isolation, key management, sub-processors, and the vendor's own compliance roadmap. Review their security posture the way they will review yours — procurement is mutual.

9. Coverage of Your Corridors

Generic global coverage may under-serve your actual trade lanes. If you operate in transshipment-heavy regions, evaluate maritime and corridor-specific intelligence — see our circumvention corridors framework for what that analysis looks like.

10. Licensing Model vs Your Growth

Model onboarding plus rescreening volumes over the contract term. Scrutinize overage pricing, mid-incident limit behavior, and post-termination data access. Compare against the build-vs-buy framework so the decision is explicit, not accidental.

11. Regulatory Change Response

Sanctions regimes change by press release. Ask how the vendor ships logic updates for new programs, how customers are notified, and for a recent example with dates. The answer reveals whether regulatory tracking is a staffed function or a hope.

12. Exit and Evidence Portability

Contracts end; audit obligations don't. Confirm you can export your full screening history in a usable format, that exported evidence remains verifiable, and what access (if any) persists after termination. Negotiate this before signing, when you still have leverage.


Demo Questions That Expose Weak Products

Bring these to every vendor demo:

  • Show me a party added to a list yesterday. When did your system reflect it?
  • Screen this transliterated name with the vowels removed. Walk me through the match explanation.
  • Show me the audit record for a screening from a year ago, and prove it hasn't been altered.
  • What does your API return when I exceed my rate limit during an incident?
  • My contract ends in year three. How do I prove year-one screenings to my regulator?
Official Regulatory Citations & Legal Frameworks

OFAC Framework for OFAC Compliance Commitments

U.S. Department of the Treasury (OFAC) • September 2026

Official Record

EU Sanctions and Restrictive Measures

European Commission • September 2026

Official Record

Frequently asked questions

What is the single most important criterion when buying screening software?

List freshness with evidence: how quickly vendor data reflects official publications, and proof of it. A vendor that cannot show you measured update lag per authority is asking you to trust the most failure-prone layer of the system on faith. Everything else — matching, workflows, reporting — operates on data that is either current or it isn't.

Should we run a proof of concept with our own data?

Yes, and seed it with known outcomes: confirmed true matches (including transliteration variants and ownership-chain cases), confirmed clean parties that resemble sanctioned names, and your actual volume patterns. A vendor confident in match quality will welcome adversarial test data; one that insists on their own demo dataset is telling you something.

How do we compare per-screen pricing against flat licenses?

Model your real volumes including rescreening, not just onboarding checks — ongoing monitoring often exceeds initial screening within the first year. Then price the failure modes: overage behavior, what happens when you exceed limits mid-incident, and whether audit-trail access survives contract termination. The cheapest per-screen price with hostile overage terms is rarely the cheapest contract.

Sanctix Research Desk

Global Trade & Export Control Policy Division

In-depth intelligence briefings on global trade restrictions, dual-use technology controls, and maritime sanctions enforcement.

Credentials:Sanctix Research DeskExport Compliance Analysis

Related Compliance Intelligence

Deepen your analysis with peer-reviewed guidance in related categories.

Executive Intelligence Briefing

Sanctions & Export Control Intelligence Delivered Weekly

Join 15,000+ trade attorneys, chief compliance officers, and maritime intelligence leaders who receive our peer-reviewed regulatory analysis and SDN updates.

Zero marketing spam. Strict privacy policy. Unsubscribe anytime with one click.