Global Trade Compliance Software: Switch On SAP GTS, or Build the Control Layer?
Count the places a trade decision gets made, because that number decides this.
On this page
Count the places a trade decision gets made, because that number decides this. If your entire business runs on one enterprise resource planning (ERP) instance with one order channel and a manageable product range, buy: switch on SAP Global Trade Services or Oracle Global Trade Management and spend the difference on classification content and a compliance analyst. If you have an acquired division on a second system, a legacy regional order path and a direct channel that was never in scope, the vendor module reaches one of four decision points and the violation happens at the other three. Even then, buy the screening service and the content, and build only the enforcement layer.
When is off the shelf genuinely the right call here?
If your business runs on a single SAP instance with a straightforward product range, switch on SAP Global Trade Services. If you run Oracle, the equivalent statement holds for Oracle Global Trade Management. Both are deeply integrated inside their own estate, both reach every place a decision is made in that estate, and both are the correct answer there. Spend the difference on classification content and a compliance analyst, which will do more for your risk position than any custom code.
Buy the content whatever else you decide. Restricted party list curation, tariff schedules and export control classification content are commodities maintained daily against regulatory change by vendors whose entire business is that maintenance. Thomson Reuters ONESOURCE Global Trade is strong here if content is your gap. Descartes Visual Compliance is a capable screening service and plenty of companies use it well as exactly that. e2open is broad and network oriented, with the configuration effort that comes with breadth.
Nobody should be rebuilding list infrastructure. A developer who proposes it is quoting you hours you do not need to buy, and they are also proposing a permanent maintenance obligation with no compliance benefit.
The honest test is whether your control currently executes at the moment of the decision or afterwards. If screening runs synchronously at order entry inside the systems where people actually work, you have prevention and you should keep buying. If it runs as a weekly batch, you are producing evidence of violations rather than preventing them, and no renewal fixes that.
When does a custom build actually pay off?
The scene that funds these projects is always the same. An order goes to a distributor, ships on Thursday, and the following Tuesday's screening batch matches the ultimate consignee against a restricted party list. The goods are on a vessel. The conversation with the board is now about a control failure rather than a near miss.
The build case is not that the products are inadequate. It is that you have a mixed estate. An acquired division on a different enterprise resource planning system, a legacy regional order system nobody wants to touch, a direct to consumer channel that was never in scope, and one escalation workflow and one audit trail have to span all of them. Every vendor module is strongest at the compliance content and weakest at the last mile into your specific systems, and the last mile is where the violation happens.
The second trigger is classification. Vendors sell classification content, and content answers a general question while yours is specific: what is the status of this assembly, given the bill of materials, given that the controlled component sits three levels down, given that engineering approved a substitute part last quarter, and given that it ships with software carrying its own control status. Classification anchored to a flat part list decays quietly the moment a design changes, and nobody notices until an auditor asks why an item was treated as uncontrolled.
How do they compare on the things that matter in this industry?
- Reach across the estate. This is the whole argument. A vendor trade module enforces beautifully inside its own system and has nothing to say about the three order paths outside it. Each additional enforcement point is real integration work with its own latency budget and its own regression surface, and it is work no module removes.
- Latency at the decision point. A control that adds two minutes to order entry will be routed around within a month. Synchronous screening in seconds is an engineering requirement rather than a preference, and it is the requirement that decides whether the business works with the control or against it.
- Ownership analysis. An entity owned fifty percent or more in aggregate by blocked persons is itself blocked even when its own name appears on no list. Screening a name is therefore not sufficient, and handling that properly needs beneficial ownership data plus logic that most implementations skip.
- Classification propagation. Treating classification as a field on a part record is why these projects fail. Classifying at the level where the control attaches, propagating up the bill of materials with an explicit rule, and triggering review on engineering change is a product structure problem, not a content problem.
- Escalation design. A hit is not a violation and most hits are false positives on common names. Graded responses, meaning automatic clearance for previously reviewed matches, soft holds that allow order entry but block release, and hard blocks reserved for high confidence matches on the most serious lists, cost the same to build as blunt ones and determine everything about adoption.
What does total cost of ownership look like at your scale?
From Digital Heroes delivery experience, a first release covering classification anchored to your product structure, synchronous screening at order entry and shipment release with a graded escalation workflow, and a complete audit trail runs $130,000 to $280,000 and ships in four to seven months. A full platform adding licence and exception management with live balance tracking, preferential origin determination with supplier solicitation, denied party workflows at every entry point, duty and drawback support and multi entity reporting runs $400,000 to $1,100,000 phased over 12 to 24 months.
Enforcement point count is the dominant lever. A manufacturer with two enterprise resource planning systems after an acquisition, one legacy regional order system and one direct channel, with no defence articles and preferential origin deferred, comes in around $270,000 across roughly seven months. The same scope against a single system with one order channel lands near $150,000, because three of the four integrations and most of the regression surface disappear.
Annual running cost is 15 to 20 percent of build, so $40,000 to $54,000 against that $270,000 release, covering hosting, patching and small changes. On top sit the subscriptions the design assumes and should assume: the screening service, tariff and control classification content, and beneficial ownership data. Then integration repair, because every system upgrade is a regression test of every enforcement point and your vendors do not schedule releases around your compliance calendar. Then the analyst time to work the exception queue, which is a permanent operating cost you choose when you set escalation thresholds.
The comparison worth running is not licence against build. Add your trade module renewal, the content subscriptions, the implementation partner days you buy each year to change how the module behaves, and the loaded cost of manual review a graded escalation model would clear automatically. Then ask your general counsel what the last voluntary self disclosure cost including outside counsel and management attention. That is not an annual number, but it is the number the control exists to avoid.
What does the hybrid look like, and when is it the honest answer?
Here the hybrid is not one option among several, it is the recommended architecture and we would argue against anything else. Buy the screening service. Buy the tariff and control classification content. Build the enforcement points, the escalation workflow, the classification propagation through your bill of materials and the audit trail. Those four are specific to you and nobody sells them.
There is a second hybrid inside a mixed estate that is worth naming. Keep SAP Global Trade Services or Oracle Global Trade Management doing the work inside their own footprint, where they are genuinely strong, and build the control layer only for the systems outside it, with a shared escalation queue and a single audit trail spanning both. That is cheaper than replacing a working module and it fixes the actual gap, which is that three of your four decision points currently have no control at all.
Sequence enforcement points by transaction volume and risk rather than doing all of them at once. Order entry and shipment release in your highest volume system first, then the secondary paths. Enforcement points are additive rather than entangled, so this gets the control over most of your order flow at roughly the cost of one integration instead of four.
Leave preferential origin out of the first release. It is a supplier engagement programme with a software component: collecting declarations, chasing renewals, running regional value content calculations and holding evidence a customs authority will ask for. Start the supplier solicitation as a commercial workstream immediately and build the software around it later. Bundling it in is the most reliable way to miss a first release date, because the pace is set by how quickly suppliers reply rather than by anyone coding.
Which should you choose, by operator size and stage?
One enterprise resource planning instance, one order channel, straightforward product range: buy the vendor module and stop. Put the difference into classification content and an analyst. Nothing else here applies to you.
Content is your gap rather than enforcement: buy content. If your classifications are stale and your list coverage is thin but the control does execute at order entry, you have a subscription problem, not a software problem, and it is a much cheaper one.
Two or more systems where trade decisions are made: build the control layer for the systems your module does not reach, and keep the module where it works. Start with the highest volume path, run in parallel with the existing batch for four to six weeks, and retire the batch only when the synchronous control has been proven on live orders.
Manufacturers whose classification depends on engineering structure: build, and fix the product master mapping with your own engineering team before kickoff. That work needs no developer, it removes the most common cause of a stalled classification workstream, and it is your first project whether or not it appears in anyone's quote.
Exporters carrying licences with value or quantity ceilings: build licence balance tracking in phase two, and treat a licence as a live balance that shipments decrement, that refuses to be drawn on when expired or exhausted, and that warns at a threshold so renewal starts before goods reach the dock.
Anyone handling defence articles: budget the International Traffic in Arms Regulations work as separate scope rather than a variant of Export Administration Regulations workflow, and include deemed export exposure in the same line. Releasing controlled technology to a foreign national inside your own facility is a controlled event even though nothing crosses a border, and it is a common audit finding precisely because companies treat compliance as a shipping problem.
When the shortlist is down to two and you need a tiebreaker, Digital Heroes contracts through India LLP, US LLC and UK LTD entities, so the agreement and the intellectual property assignment sit under law your own advisers already read. You can take that specification to any other firm on your shortlist.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- Digital Champions expect to achieve about 16% in cost savings and around 15% in revenue gains from digital operations over five years; the study surveyed 1,155 manufacturing executives across 26 countries. Source: PwC / Strategy& (2018) →
- In a survey of 579 supply chain professionals (July 31 to October 1, 2024), only 29% had built at least three of the five capabilities Gartner identifies as needed for future competitiveness (agility, resilience, regionalization, integrated ecosystems, and enterprise-wide strategy). Source: Gartner (2025) →
- The average developer spends more than 17 hours a week dealing with maintenance issues such as debugging and refactoring, and about four of those hours on 'bad code' - waste that equates to nearly $85 billion annually worldwide in opportunity cost. Source: Stripe (2018) →
- The median annual wage for U.S. software developers was $133,080 in May 2024, and employment is projected to grow 15% from 2024 to 2034 - a core input to any in-house build-vs-buy TCO model. Source: U.S. Bureau of Labor Statistics (2024) →
Frequently asked questions
What does it cost to move off SAP GTS or Oracle GTM later?
Usually you do not move off it, and that is the point of the layered approach. The module keeps working inside its own footprint while the control layer covers everything outside, so a later decision to change modules affects one estate rather than your whole compliance posture.
If you did leave, the expensive part is classification decisions and their reasoning rather than the transactional records. Ask what a structured export of classifications with their supporting rationale looks like, because a code without the rule, the date and the decision maker is not much use to an auditor.
What happens if our screening or content vendor raises prices?
Model it against your projected transaction volume and party count, because those drive most screening pricing more than seat counts do. It is worth knowing which of your costs are content, which are screening calls and which are ownership data, since they reprice independently.
A control layer that calls a commercial service rather than embedding one keeps that swappable. Changing screening provider becomes an integration change measured in weeks rather than a compliance programme, which is worth more at renewal time than any negotiated discount.
How long does a trade compliance build take?
Four to seven months to a first release and 12 to 24 months for a full platform, with four to six weeks of discovery before either. Plan four to six weeks of parallel running against live orders before retiring your existing batch screening.
Two things slow projects down predictably. Product master data quality, because classification cannot be automated over part numbers nobody can map to an engineering structure. And preferential origin, where the pace is set by how quickly suppliers return declarations rather than by development effort.
Is SAP GTS enough on its own for a manufacturer after an acquisition?
Inside the SAP estate, yes, and we would keep it. It is deeply integrated where it lives and replacing it buys nothing.
Outside that estate it has nothing to say. An acquired division on a different system, a legacy regional order path and a direct channel each remain places where an order can be released without a control executing. That is the specific gap worth building for, and it is integration work rather than a licensing question, so no module upgrade closes it.
Should we build our own restricted party list infrastructure?
No, and a proposal to do so tells you more about the developer than about the scope. List curation is a maintained commodity that changes constantly, and rebuilding it creates a permanent obligation with no compliance benefit.
Call a commercial screening service and spend the budget on what is specific to you: where the control executes, how ownership analysis is handled, how a hit is escalated, and what evidence survives an examination. That split is also the cheapest version of the project.
How do we stop false positives from grinding order entry to a halt?
Design graded responses instead of treating every hit as a block. Previously reviewed matches clear automatically with the prior decision recorded, medium confidence matches become soft holds that let order entry continue while blocking release, and hard blocks are reserved for high confidence matches on the most serious lists.
Without this the business pressures compliance to loosen thresholds, which produces exactly the failure mode the control existed to prevent. The escalation model also sets your permanent analyst headcount, so it is a budget decision as much as a design one.
Can we roll this out one system at a time?
Yes, and you should. Enforcement points are additive rather than entangled, so sequencing by transaction volume and risk gets the control over most of your order flow at roughly the cost of one integration instead of four.
Get the classification and escalation model right at the start though. Retrofitting graded responses or bill of materials propagation once three integrations are already live means touching all of them, which is the one place where phasing costs you money rather than saving it.
Who owns the code and the compliance records if an agency builds this?
You should hold the repository, the infrastructure accounts, the data and the right to appoint another supplier, settled in writing before kickoff. At Digital Heroes the client owns the code from the first commit.
This matters more here than in most categories. Records must be retained for five years and produced under audit, and a system whose evidence lives in a supplier's cloud account is a system you cannot fully answer for when a regulator asks. Ownership of both code and data is the only defensible arrangement.
Will custom software scale as we add warehouses, SKUs, and order volume?
Yes, if multi-location support and your target volumes are stated requirements at design time, because a schema built for one warehouse is expensive to retrofit for ten. A well-built system on PostgreSQL comfortably handles millions of SKUs and tens of thousands of orders per day on modest cloud hardware, so scaling cost shows up in hosting bills rather than rewrites. Give your agency the 3-year growth picture upfront even if phase one covers a single site.
What tech stack is best for custom supply chain software?
Boring and mainstream wins: a typed backend such as Node with TypeScript, Python, or C#, PostgreSQL for transactional inventory data, a React web frontend, and hosting on AWS, Azure, or GCP. Real-time needs like scanner feeds or live shipment tracking add a message queue such as Redis or RabbitMQ. Be wary of any agency pitching an exotic stack; in Digital Heroes handover work, systems built on niche frameworks are consistently the hardest and most expensive for a new team to take over.
When is SAP actually a better choice than building custom supply chain software?
Choose SAP when you need a full ERP, operate in a heavily audited industry that expects standard systems, or run global operations where localization, tax, and compliance content matter more than workflow fit. SAP's strength is breadth: finance, manufacturing, and supply chain in one validated suite. Custom wins when your edge lives in a specific workflow, like how you allocate inventory or route orders, that SAP would force you to bend to its standard process. Many Digital Heroes clients keep SAP as the system of record and build custom operational tools around it.
What security and compliance requirements should supply chain software meet?
At minimum: role-based access control, encryption in transit and at rest, audit logs on inventory and order changes, and tested backups, because the system holds supplier pricing and customer purchase history your competitors would love to see. If enterprise customers connect to it, expect security questionnaires and possibly SOC 2 expectations; food, pharma, and aerospace add traceability rules like FDA lot tracking or ITAR data handling. Raise these in the first scoping call, since retrofitting audit trails onto a live system costs far more than designing them in.
How do I calculate whether custom software will pay for itself?
Divide the build cost by the monthly benefit, where benefit is hours saved times loaded hourly cost, plus subscription fees replaced, plus any revenue the software unlocks. Three staff saving 10 hours a week each at a $40 loaded rate is about $62,000 a year, which pays back a $60,000 build in roughly 12 months. Across Digital Heroes internal-tool projects, 12 to 24 months is the normal payback range, and anything projecting under 6 months usually means the spreadsheet is hiding costs.
What are the biggest mistakes first-time software buyers make?
Choosing the lowest bid, paying more than 30-40% upfront instead of on milestones, skipping a written specification, and having no maintenance plan for after launch. The most expensive of the four in Digital Heroes rescue projects is the missing spec: without written acceptance criteria, done becomes an argument instead of a checklist, and every disagreement resolves in the vendor's favor. Fix those four and you have avoided most of the ways these projects fail.
How long does it take to build custom supply chain software?
Plan on 10 to 14 weeks for a first production release covering one or two core workflows, and 6 to 9 months for a full platform spanning procurement, inventory, and fulfillment. Digital Heroes ships most supply chain MVPs in about 12 weeks with a 4 to 6 person team. Integrations are the schedule risk: each ERP, EDI, or carrier connection typically adds 2 to 4 weeks of build and testing.
How long does it take to build a custom web or mobile app from scratch?
Plan on 8 to 16 weeks for a focused first version and 4 to 9 months for a larger platform, which is the typical spread across Digital Heroes builds. The first 2 to 3 weeks go to discovery and design before any production code ships. The two things that stretch timelines most are integrations with legacy systems and slow feedback from your side, not developer speed.
Who can build a custom supply chain software system?
Digital Heroes builds custom supply chain software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other supply chain software companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.
Related guides
Published · Last updated .