Sanctions Screening Software: Custom Build vs Off the Shelf
Buy. For nearly every institution the filter is not the problem, and writing a name matching engine is the wrong place to spend money. LexisNexis Bridger Insight, Fircosoft or Napier will screen competently.
On this page
Buy. For nearly every institution the filter is not the problem, and writing a name matching engine is the wrong place to spend money. LexisNexis Bridger Insight, Fircosoft or Napier will screen competently. Fund a build only when your hit queue rather than your matcher is the bottleneck, and when you cannot evidence why a threshold sits exactly where it does.
What the off the shelf products actually do well
Start with the part that costs us work. If you screen a few hundred names a day in batch against the Office of Foreign Assets Control (OFAC) Specially Designated Nationals list, the European Union consolidated list and the United Kingdom Office of Financial Sanctions Implementation list, you should buy something and move on.
LexisNexis Bridger Insight will get a community bank or a mid sized payments firm compliant in weeks, with list refreshes handled, hit records retained and reporting an examiner recognises. Fircosoft is the incumbent inline filter in large payment shops for good reasons: it survives volume, it sits in the SWIFT message path without falling over, and the people who tune it have been doing it for two decades. Napier and ComplyAdvantage bring more configurable architecture and a far better analyst interface than the older products. LSEG World-Check and Dow Jones Risk and Compliance supply data rather than software, and both supply good data.
None of that is faint praise. Building a matching engine from scratch is a poor idea for almost everyone. Transliteration handling, tokenisation, phonetic and edit distance scoring, entity type disambiguation and vessel name matching are specialist disciplines the vendors have worked on for years. If your gap is that you have no filter, buy a filter.
Buy also if you cannot name the person who owns your tuning record. Software does not tune thresholds, a sanctions officer does. A custom platform with nobody accountable for the matching parameters becomes an expensive version of the console you already ignore.
Where they stop: the same forty names cleared again every week
The workflow generic products model badly is disposition, not detection. It is 15:20, Fedwire has a cutoff, and the wire room has forty three open hits. Most are the same handful of common surnames that fired yesterday and the day before. Two are genuinely ambiguous. The queue is sorted by arrival time, because it has no idea which payment is about to miss its window and no idea which hit has been cleared eleven times already.
A screening product records that a hit was closed. What it rarely does is key that decision to the specific triple of subject, list entry and reason, so a recurrence presents as a one tap confirmation with the previous rationale attached rather than as a fresh investigation. That single distinction removes most of the clock time from a wire room queue, and no vendor sells it because it depends on your customer base rather than theirs.
Two more gaps are specific to this work. Good guy lists, meaning the whitelist of subjects previously determined not to be matches, are the most dangerous artefact in most compliance departments, because a name placed on one stops generating hits and sanctions authorities amend entries with new aliases and identifiers constantly. A whitelist entry should be scoped to a named list entry, carry an owner and an expiry, and be re screened against every list delta. In most institutions it is a spreadsheet.
Then there is the OFAC 50 percent rule, under which an entity owned in aggregate by blocked persons is itself blocked even though its name appears on no list. No fuzzy matcher finds that, because the string is not there to match. It has to be computed from the ownership graph your onboarding team already collected, and a bolt on filter cannot see that data.
The arithmetic: analyst seats and screened records versus a build
Do this with your own renewal invoice rather than ours. Screening in this segment is normally priced on some mix of named analyst seats, screened records and list data subscriptions, and the three scale differently, which is why the quote you compare against a build is never the number on the first page.
Take an illustrative shape. Suppose your quote lands at $2,000 per analyst seat per month, plus a list data subscription, plus a small per record fee on screened names. At four analysts that is $96,000 a year before data, which no build will beat and you should not try. At twelve analysts it is $288,000 a year, and adding a few million screened records a year on top puts the annual run rate somewhere near $350,000.
Now put the build beside it over five years, not one. A full custom platform in this category at $240,000 to $550,000, plus year two support and enhancement at 15 to 20 percent annually, plus migration, lands in a range that meets the subscription line somewhere between eight and ten analyst seats, or roughly two million screened records a year, depending where your quote sits in that spread.
The crossover is not really about the licence, though. It is about the seats you are paying for because the queue is inefficient. If four of your twelve analysts exist to re investigate names that were cleared last week, the honest comparison is a build against the fully loaded cost of four salaries plus the licence, and that comparison moves years earlier than the software line alone suggests.
What a custom build actually costs
From Digital Heroes delivery experience, a first release covering list ingestion with versioning and delta computation, a configurable and inspectable matching pipeline, and an operations hit queue with structured dispositions and recurrence handling runs $80,000 to $190,000 and ships in 12 to 18 weeks. A full platform adding inline screening in the payment path, historical replay for threshold testing, governed good guy lists, ownership rule evaluation and blocked property record keeping runs $240,000 to $550,000 across 8 to 16 months.
Two lines nobody puts in the proposal. Data migration is 10 to 25 percent of the build, and in screening that is not file copying: it is loading historical hits and dispositions in a form you can replay, which is the whole point of having them. Year two runs 15 to 20 percent of build cost annually for support and enhancement, and in this category that money buys list format changes, new jurisdictions and threshold retuning rather than new features.
What pushes the number up here specifically: inline payment screening, because a filter in a payment path carries latency and availability requirements a batch job does not, and its failure behaviour must be designed rather than defaulted. The number of lists, including internal and correspondent supplied ones. Non Latin script handling, which is genuine specialist work. And trade finance screening of vessels, ports and dual use goods, which is a different matching problem wearing the same name.
The four situations where building wins
Regulatory fit. An examiner will ask which list version was loaded when a specific payment was released on a specific Tuesday, and what the matching parameters were at that moment. Immutable list versions stamped onto every screening event cost almost nothing to design in and are close to impossible to retrofit. If you cannot answer that question today, buying a bigger licence does not fix it.
Scale economics. Past roughly ten analyst seats, the marginal cost of a licence stops being the interesting number and the marginal cost of a head becomes it. A queue that recognises recurrence changes headcount, and headcount is the line your chief financial officer actually feels.
A workflow that is your advantage. If you run corridors into South Asia or a large Arabic speaking book, your matching behaviour is not the vendor's default population, and tuning to your population is a commercial capability rather than a compliance chore. Every hour a corporate client's payment sits blocked is an hour your treasury sales team spends apologising.
Integration sprawl. When the ownership graph lives in onboarding, the payments run through a core, the case history sits in the screening tool and the evidence pack is assembled in a fourth place, you have four systems and no join. The 50 percent rule cannot be evaluated across that gap, and neither can a decent audit trail.
How to decide in a week
Export one month of alert history from your filter. Group every hit by the triple of subject, list entry and match reason, then count how many groups contain more than one hit. That percentage is your answer. Below roughly 30 percent, your queue is doing real work and a better filter or better thresholds is the right spend. Above 60 percent, you are paying analysts to re read decisions your institution has already made, and no vendor threshold change will fix it because the defect is in the workflow rather than the score.
Run the same export twice more: count hits still open past your payment cutoff, and count whitelist entries with no owner. Three numbers, two days, and you can walk into a steering meeting with something better than a feeling.
Then take it to a paid discovery phase. Digital Heroes writes a signed product requirements document before any code exists, covering the data model, the disposition schema, integration points and acceptance criteria, and you keep that specification whether you build with us, build elsewhere or decide to renew. It is what keeps a fixed quote fixed. We are the wrong firm if you want a body shop billing a day rate against a shifting scope, or if you need someone on site in your operations centre daily. Digital Heroes runs as an India LLP, a US LLC and a UK LTD, so the intellectual property assigns under your own law, and you meet the named engineers before signing. Our record is checkable on Clutch, Trustpilot, Fiverr Vetted Pro and our D-U-N-S listing, across more than 2,000 projects and a team of over fifty specialists, alongside our own products ShopScore, HeroCheckout and Section Vault.
Book a 30-minute call with Digital Heroes and get a written plan and a fixed quote within 48 hours.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- Per the Standish Group CHAOS 2020 report (reviewed at this URL), across tens of thousands of software projects roughly 31% end successfully, about 50% are 'challenged', and roughly 19% fail outright; small projects succeed far more often than large ones, and Agile approaches succeed at markedly higher rates than Waterfall. Source: The Standish Group (2020) →
- The median annual wage for U.S. software developers was $133,080 in May 2024, and employment is projected to grow 15% from 2024 to 2034 - a core input to any in-house build-vs-buy TCO model. Source: U.S. Bureau of Labor Statistics (2024) →
- SaaS spend averaged $4,830 per employee (up 21.9% year over year), with large enterprises (10,000+ employees) spending roughly $284M annually and running about 660 apps, while organizations wasted an average of $21M annually on unused licenses. Source: Zylo (2025) →
- An analysis of enrollment and completion data for 221 MOOCs (Katy Jordan, published in the International Review of Research in Open and Distributed Learning, IRRODL, 16(3), 2015 - not the Journal of Distance Education) found completion rates ranging from 0.7% to 52.1%, with a median completion rate of 12.6%, and completion negatively correlated with course length (longer courses had lower completion rates) - underscoring how unsupported self-paced online courses struggle to finish learners. Source: Journal of Distance Education (via ERIC / Katharina Jordan) (2015) →
Frequently asked questions
How much does it cost to build custom sanctions screening software?
A first release covering list ingestion with versioning, an inspectable matching pipeline and a hit queue with structured dispositions runs $80,000 to $190,000 over 12 to 18 weeks in Digital Heroes delivery experience. A full platform with inline payment screening, historical replay, governed whitelists and ownership rule evaluation runs $240,000 to $550,000 across 8 to 16 months. Budget migration at 10 to 25 percent on top.
How long before analysts feel a difference?
Measurement arrives first. A metrics layer reading your existing alert history can publish recurrence rates, open hits past cutoff and clearance times within three or four weeks, before anything touches the filter. The queue changes at first release, typically 12 to 18 weeks in. Inline screening in the payment path is a later phase because it needs latency testing and a designed failure mode.
Who owns the tuning parameters if an agency builds our screening system?
You should, and it belongs in the contract before kickoff rather than at handover. Your threshold history, your disposition records and your whitelist governance are the evidence that defends the programme in an examination. At Digital Heroes the client owns the repository, the cloud accounts and every record from the first commit, and we would tell any bank to refuse an arrangement where that evidence sits somewhere it cannot be extracted from.
What is the difference between a screening tool and a data provider?
LSEG World-Check and Dow Jones Risk and Compliance sell curated list and enrichment data. LexisNexis Bridger Insight, Fircosoft and Napier sell the software that matches your names against that data and gives analysts somewhere to work. You normally need both, and confusing them is how firms end up paying twice for the same coverage or blaming the wrong supplier when false positives climb.
Can we keep our existing filter and build only the workflow around it?
Yes, and for most institutions that is the right shape. Keep the vendor filter producing hits, then build the disposition layer: recurrence keyed to subject and list entry, deadline aware queue ordering, governed whitelists with expiry, and an evidence pack. It is cheaper, less disruptive, and it leaves you free to change filter vendors later without rebuilding the part your analysts actually touch.
What happens if OFAC amends an entry we already cleared?
That is precisely the event your process must catch, and most miss it. The correct behaviour is to compute the delta on every list update, re screen your book against added and amended entries, and force review of any whitelist entry whose underlying list record changed. Authorities add aliases, passport numbers and dates of birth to existing entries regularly, and an amendment can turn a cleared name into a real match.
Should a small payments firm build its own name matching?
No. If you screen modest volumes in batch and your customer base does not stress transliteration, buy a screening tool and spend the difference on a competent sanctions officer. Matching engines are decades of specialist work and your risk is not sitting there. Revisit the question only when your queue, your evidence trail or your corridor mix starts driving the cost rather than the filter itself.
What is the OFAC 50 percent rule and why does software struggle with it?
It treats an entity owned in aggregate fifty percent or more by blocked persons as blocked itself, even though that entity appears on no list. Fuzzy matching cannot find it because there is no string to match against. Catching it requires joining screening to the ownership graph collected during onboarding and computing aggregate blocked ownership through the chain, which needs both datasets in one model.
Can screening run inside our payment flow without breaking cutoffs?
It can, but inline screening is an engineering commitment rather than a configuration choice. The filter now carries a latency budget, an availability target and a defined behaviour when it is unavailable, which is a policy decision about whether payments hold or pass. Design that before you build it. Batch screening with a fast queue is often the better answer for firms without a genuine intraday payment path.
What happens if we skip this and keep the spreadsheet whitelist?
Nothing, until a list amendment lands on a name someone whitelisted globally three years ago. That subject stops generating hits permanently, the reason sits in a leaver's memory, and the failure only surfaces during an examination or after a payment. The fix is cheap while it is still a spreadsheet: give every entry an owner, an expiry and a specific list entry it applies to.
What does a $50,000 custom software budget actually buy?
One core workflow done properly: 10 to 15 screens, two or three user roles, a couple of integrations, an admin panel, and automated tests, delivered in roughly 12 to 14 weeks. What it does not buy is that workflow plus a mobile app plus AI features plus five more integrations. The discipline of picking the one workflow that matters is what separates $50,000 projects that ship from $50,000 projects that stall at 70% complete.
Should I hire a freelancer or an agency for my software project?
A skilled freelancer is the right call for a single-discipline scope under roughly $15,000, like a website, a plugin, or one integration. Above that, projects need design, backend, testing, and project management at once, and a solo builder becomes the single point of failure: if they get sick or take a bigger client, your project simply stops. Agencies bill 20-40% more per hour but carry continuity, code review, and someone to escalate to, which is what you are actually buying.
Is a solo freelancer enough for my project, or do I really need an agency?
A solo freelancer is a fine choice for a well-defined build under roughly $15,000 to $20,000 with a limited lifespan: an internal calculator, a scripted integration, a prototype. Above $50,000, or for any system your business will depend on for years, you are buying continuity as much as code: enforced code review, cover when someone is ill, and support that outlasts one person's career plans. Price the risk of a single point of failure, not just the hourly rate.
What should I have ready before I contact a development agency?
Three things, none of them technical: a one-page description of the problem in your own words, a list of the tools and spreadsheets the new system must replace or connect to, and a must-have versus nice-to-have split of features. Add a budget range, even a wide one, because it changes the conversation from fantasy to engineering. You do not need a formal specification; producing that is what a discovery phase is for.
What happens if I stop paying for maintenance after launch?
Nothing breaks on day one, which is what makes it dangerous. Within 6 to 18 months, unpatched dependencies accumulate known vulnerabilities, an integrated API like Stripe ships a breaking change, and the first fix requires a developer to relearn a stale codebase at full price. Budget 15 to 20% of the build cost per year for upkeep; it is the difference between a $500 patch and a $15,000 emergency.
How do I work out whether custom software will pay for itself?
Do the arithmetic on hours before anything else: if the system saves three staff eight hours a week at a $35 loaded hourly cost, that is about $43,700 a year against, say, a $70,000 build plus 15 to 20% annual maintenance, a payback around two years. Add revenue effects only if you can name them specifically, like faster quotes or fewer abandoned orders, not as vague growth. In our delivery experience the businesses that see payback inside 24 months are the ones automating a process they already measure.
What are the biggest mistakes first-time software buyers make?
Choosing the lowest bid, paying more than 30-40% upfront instead of on milestones, skipping a written specification, and having no maintenance plan for after launch. The most expensive of the four in Digital Heroes rescue projects is the missing spec: without written acceptance criteria, done becomes an argument instead of a checklist, and every disagreement resolves in the vendor's favor. Fix those four and you have avoided most of the ways these projects fail.
How do I make sure custom software is secure and compliant with rules like HIPAA?
Start with the baseline every business system should have: encryption in transit and at rest, role-based access control, and audit logs. If HIPAA applies, the hosting provider must sign a Business Associate Agreement, which AWS, Azure, and Google Cloud all offer, and access controls have to be designed in from day one, not bolted on. SOC 2 certifies a company's operating practices, not a codebase, so ask vendors what they have shipped in your regulated domain rather than which logos are on their website.
Will custom software work with the tools we already use, like QuickBooks and Stripe?
Yes, and this is one of custom software's genuine advantages: QuickBooks, Stripe, Shopify, and most mainstream business tools publish documented APIs built for exactly this. Expect each standard integration to add one to two weeks of build time, and be suspicious of any quote that lists five integrations without asking what data flows in which direction. The hard cases are legacy systems with no API, which is a question to raise in discovery, not in week nine.
Who can build a custom software system?
Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other software companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.
Related guides
Published · Last updated .