How Much Does Sanctions Screening Software Cost to Build in 2026?
$80,000 to $550,000 is the band for building sanctions screening, and the one decision that decides where you land is whether the filter sits inline in a live payment path or runs as a batch.
On this page
$80,000 to $550,000 is the band for building sanctions screening, and the one decision that decides where you land is whether the filter sits inline in a live payment path or runs as a batch. Batch screening is an application: you can be wrong for ten minutes and recover, so a first release covering list ingestion with versioning, an inspectable matching pipeline and an operations hit queue with structured dispositions prices at $80,000 to $190,000 over 12 to 18 weeks in Digital Heroes delivery experience. Put that same filter in front of a wire and you have bought latency budgets, redundancy, defined failure behaviour and an on call rota, which is the single largest reason programmes reach the $240,000 to $550,000 band across 8 to 16 months.
The bands a screening build falls into
Three price points, and the middle one is where most institutions actually belong.
The first release is the tuning and disposition layer. List ingestion with immutable versions and computed deltas, a matching pipeline whose stages you can inspect and whose parameters you can version, an operations queue that recognises a repeat hit, structured dispositions that reference the identifier which differentiated your customer from the listed party, and a screening event store that records which list version and parameter set produced every decision. In our delivery experience that runs $80,000 to $190,000 over 12 to 18 weeks.
The full platform adds inline screening in the payment path, a historical replay harness so threshold changes can be proven before release, governed good guy lists, ownership rule evaluation and blocked property record keeping. That is $240,000 to $550,000 phased over 8 to 16 months.
The third price is zero. A smaller institution screening a few hundred names a day in batch, with a customer base that does not stress transliteration, should buy a screening tool. Building a name matcher is effort spent away from where your risk actually is.
What drives a screening build up
The estimate in this category is dominated by non functional requirements, which is unusual and catches finance teams out.
- Inline payment screening. A filter in a payment path has a latency budget, an availability target and a failure mode that must be a deliberate decision rather than a default. Both blocking every payment and releasing every payment during an outage are choices with consequences, and designing, testing and operating that behaviour is a substantial line rather than a feature.
- Number of lists. Not just the major public lists. Internal lists, correspondent supplied lists and lists that arrive as an emailed spreadsheet each have their own ingestion, versioning and change handling.
- Non Latin script handling. Transliteration is genuine specialist work and it is corridor specific. A bank with a large Arabic speaking book faces variance a mostly Anglophone book never encounters, and it does not come free with any library.
- Trade finance screening. Vessel names, ports, goods descriptions and dual use references behave nothing like personal names. It is a second matching problem in the same building, with its own reference data.
- Historical replay. Replaying two years of screening events through a candidate parameter set requires those events to have been stored in a queryable form from day one. Retrofitting it means you cannot prove a tuning change is safe until two years after you start storing.
What keeps the number down
The cheapest defensible screening programme we have delivered spent nothing on the filter and everything on the queue.
Start with recurrence. In most operations the majority of daily hits are the same handful of common surnames against the same list entries, cleared last week by the same analyst. Recognising that triple of subject, list entry and reason, and presenting the prior decision with its rationale for one click confirmation, removes most of the clock time without changing coverage by a single basis point. It is the cheapest thing in this article and the most valuable.
Keep your existing filter and build the layer around it. If Fircosoft or a comparable engine sits in your payment path today and works, wrapping it with a proper queue, versioned parameters and a replay harness is a fraction of replacing it, and it removes the argument about who is accountable for a missed name.
Never build list curation. LSEG World-Check and Dow Jones Risk and Compliance are data businesses with research teams, and their output is the input to your system, not a thing to reproduce.
Defer trade finance and non Latin script to a second phase unless they are your primary exposure. Both are real work and neither improves the payment queue that is currently your bottleneck.
A worked example that adds up
A mid sized bank with commercial payment volume, correspondent relationships, two corridors that generate transliteration variance and a hit queue that regularly runs to the Fedwire cutoff. Phase one, delivered in 16 weeks:
- List ingestion with immutable versioning and delta computation across four public lists plus two correspondent supplied lists: $28,000
- Inspectable matching pipeline with normalisation, tokenisation, scoring and thresholds held as versioned parameters: $52,000
- Operations hit queue with deadline ordering, recurrence keying and structured dispositions: $41,000
- Screening event store stamping every decision with list version and parameter set: $17,000
That totals $138,000, inside the first release band. Phase two, over the following eleven months:
- Inline screening service in the payment path with a latency budget, redundancy and defined failure behaviour: $86,000
- Historical replay harness for proving threshold changes before release: $39,000
- Governed good guy list with per entry scoping, owners, expiry and re screening on every list update: $31,000
- Ownership graph evaluation for aggregate blocked ownership: $44,000
- Transliteration and non Latin script handling for two corridors: $37,000
- Blocked property records and regulatory reporting: $26,000
Phase two is $263,000, putting the programme at $401,000 across roughly fifteen months. Notice that inline screening alone is $86,000, a third of the second phase, and it buys no new detection at all. It buys the ability to run the same detection against a payment cutoff.
How the spend phases
Screening projects front load differently from most compliance builds, because the first thing you have to agree is not a requirement, it is a position.
Discovery is three to four weeks and costs roughly $14,000 to $22,000 at this size. Most of it is documenting the tuning rationale you do not currently have written down: why the thresholds sit where they do, what your institution accepts as a differentiating identifier, and who is allowed to clear what. That document is worth having even if the build stops there, because it is the thing an examiner asks for and the thing nobody can produce.
The build runs the middle. Then plan a shadow period, four to eight weeks, where the new pipeline screens the same traffic as the incumbent and the hit sets are compared line by line. Budget it at ten to fifteen percent of the phase. Any difference is either an improvement you can evidence or a gap you have just avoided shipping.
Inline deployment belongs at the end of phase two and behind a switch, with the batch path retained as a fallback for the first quarter.
The ongoing costs nobody quotes
Screening carries the highest standing cost of any compliance system we build, and most of it is not software.
- List data subscriptions continue. Building the platform does not reduce your World-Check or Dow Jones spend, and that line is often larger than the annual software cost. Keep it in the model.
- Support and change: 15 to 20 percent of build cost annually. On a $401,000 programme, roughly $60,000 to $80,000. Lists change format, corridors change, new correspondent lists arrive.
- Availability engineering for the inline path. An on call rota, redundancy across zones, and regular failover testing. If nobody has ever tested what happens when the screening service is unavailable at 15:20, you have an assumption rather than a control.
- Periodic independent validation. Tuning parameters generally need review by someone who did not set them. Budget an annual engagement.
- Examination support. Producing screening evidence for a review consumes analyst and engineering time. It is far cheaper if the event store was designed for it, which is exactly why that $17,000 line exists in phase one.
Comparing a build against your current renewal
Institutions usually compare a licence fee to a build fee and conclude the vendor is cheaper. Then they leave out the three lines that matter.
First, price structure. Much of this category prices per screened name or per transaction, so your cost rises with your volume and with any decision to screen more thoroughly. Model three years at your intended volume, not last year's.
Second, tuning services. Changing matching behaviour in a mature filter is specialist work that iterates slowly, and each cycle is a professional services engagement with a calendar attached. Ask your incumbent what a threshold change costs and how long it takes end to end, including the evidence they will give you that it is safe. The answer to the second half is often the decisive fact.
Third, the queue. Count analyst hours spent clearing hits, then estimate what proportion are repeats of decisions already made. You do not need a study for this. Pull one week of dispositions and count. That figure, annualised at your loaded staff cost, is usually larger than the entire first release, which is why recurrence handling is the line we recommend building first.
When buying beats building
Buy if you are a smaller institution screening modest volumes in batch, with a customer base that does not stress transliteration and no inline payment cutoff pressure. LexisNexis Bridger Insight is a capable mid market screening tool that will get you compliant quickly and is proportionate to that risk profile. Building a matching engine at that scale is money spent where your exposure is not.
Buy the data whatever you decide. LSEG World-Check and Dow Jones Risk and Compliance supply lists and enrichment, and no build should attempt to replace research operations of that kind.
Consider a hybrid, which is what we recommend most often. Keep the incumbent filter, including Fircosoft in a large payment shop or Napier where more configurability is already available, and build the layer that owns your evidence: the queue, the recurrence model, the versioned parameters, the replay harness and the disposition history. That combination costs materially less than replacing the filter and it fixes the thing that is actually slow.
Build outright when two or more apply: screening sits inline against a cutoff and the queue is the bottleneck, your corridors create matching behaviour that default algorithms handle badly, you cannot evidence why your thresholds sit where they do, or your good guy list has grown past a few hundred entries with nobody governing it.
If you would rather scope this before committing budget, Digital Heroes builds and runs its own products, so the people choosing your architecture live with those decisions on their own revenue. You can take that specification to any other firm on your shortlist.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- A 100-millisecond delay in website load time can cut conversion rates by 7%; a two-second delay increases bounce rates by 103%; and 53% of mobile visitors leave a page that takes longer than three seconds to load. Source: Akamai Technologies (2017) →
- Only about 30% of digital transformations succeed at meeting their objectives, but getting six critical success factors in place (leadership commitment, talent, agile culture, progress monitoring, clear strategy, and a modernized platform) raises the odds of success from 30% to 80%. Source: Boston Consulting Group (BCG) (2020) →
- Workers can expect 39% of their existing skill sets to be transformed or become outdated over 2025-2030; 77% of employers plan to upskill their workforce, and 63% identify skill gaps as the biggest barrier to business transformation. Source: World Economic Forum (2025) →
- SaaS spend averaged $4,830 per employee (up 21.9% year over year), with large enterprises (10,000+ employees) spending roughly $284M annually and running about 660 apps, while organizations wasted an average of $21M annually on unused licenses. Source: Zylo (2025) →
Frequently asked questions
What is the total cost of building sanctions screening software?
A first release covering list ingestion with immutable versioning, an inspectable matching pipeline, an operations hit queue with recurrence handling and structured dispositions, and a screening event store runs $80,000 to $190,000 over 12 to 18 weeks in Digital Heroes delivery experience.
A full platform adding inline payment screening, a historical replay harness, governed good guy lists, ownership rule evaluation and blocked property reporting runs $240,000 to $550,000 across 8 to 16 months. A mid sized bank with correspondent relationships and two transliteration heavy corridors typically lands near $401,000 over about fifteen months.
What does a screening platform cost to run annually?
Budget 15 to 20 percent of build cost for support and change, so roughly $60,000 to $80,000 a year on a $401,000 programme. Then add the lines people forget: your list data subscription does not go away and is often larger than the software line, and an inline path needs an on call rota, redundancy and regular failover testing.
Plan an annual independent validation of your tuning parameters by someone who did not set them, and expect examination support to consume analyst and engineering time. The last of those is far cheaper if your event store was designed to answer it.
How long does it take to build and deploy screening?
Twelve to eighteen weeks for a first release. Discovery takes three to four weeks and is mostly spent writing down the tuning rationale your institution has never documented, which is worth having even if the build goes no further.
Then allow four to eight weeks of shadow running, where the new pipeline screens the same traffic as the incumbent and the two hit sets are compared line by line. Inline deployment belongs at the very end, behind a switch, with the batch path retained as a fallback for the first quarter of live operation.
How does building compare with licensing LexisNexis Bridger Insight?
Compare three year totals at your intended volume, since much of this category prices per screened name or per transaction and your cost therefore rises when you decide to screen more thoroughly. Then ask your incumbent two specific questions: what a threshold change costs, and what evidence they will give you that the change is safe.
Bridger Insight is a capable mid market tool and at modest batch volumes it is the right answer. The build case appears when you need to explain your own matching behaviour to an examiner and cannot see inside the scoring.
Why does inline payment screening cost so much more than batch?
Because you are buying availability rather than detection. A filter in a live payment path has a latency budget, a redundancy requirement and a failure mode that has to be designed: both blocking every payment and releasing every payment during an outage are decisions with consequences, and each needs testing and an operating procedure.
In the worked example inline screening is $86,000 of a $263,000 second phase, and it adds no new detection at all. It buys the ability to run the same detection against a wire cutoff without the queue becoming the constraint.
What is the cheapest change that reduces false positive workload?
Recurrence handling, and it is not close. Most daily hits are the same common surnames against the same list entries, cleared last week by the same analyst. Keying a decision to the triple of subject, list entry and reason, then presenting the prior decision for one click confirmation, removes most of the queue's clock time without changing coverage.
It is part of the $41,000 queue line in the worked example. Pull one week of your own dispositions and count how many are repeats. That number, annualised at loaded staff cost, usually exceeds the entire first release.
Do we still pay for World-Check or Dow Jones if we build?
Yes, and the subscription should stay in your model at full value. LSEG World-Check and Dow Jones Risk and Compliance are data businesses with research operations behind them, supplying lists and enrichment rather than matching engines or workflow.
Building your own list curation is one of the few genuinely bad ideas in this category. What a build owns is everything downstream of the data: how it is versioned, how it is matched against your population, how hits are worked, and what evidence survives the decision. The data itself you buy.
Can we keep our existing filter and build only part of this?
That is the arrangement we recommend most often. Keep the incumbent engine, whether that is Fircosoft in a large payment shop or Napier where you already have configurability, and build the layer that owns your evidence: the hit queue, recurrence handling, versioned parameters, the replay harness and the disposition history.
That scope typically prices at the lower end of the first release band, in the $80,000 to $130,000 range, because you are not rebuilding matching. It also removes the accountability argument, since the vendor still owns detection and you own how decisions are made and proven.
How do we prove a threshold change is safe before it goes live?
Replay. Take historical screening events, run them through the candidate parameter set, and compare the hits produced, paying particular attention to the ones that would no longer fire. Anything short of that is an opinion with a deployment date attached.
The catch is that replay requires screening events to have been stored in queryable form from the beginning, which is why the event store appears as a $17,000 line in phase one rather than an optimisation later. Retrofit it and you cannot prove a tuning change is safe until two years after you start collecting.
How many people should be working on my software project?
Three to five for a typical focused build: a project lead, one or two engineers, a designer, and part-time QA, which is the standard shape across 2,000+ Digital Heroes projects. Larger platforms justify 6 to 10, but a ten-person team on a small first version usually signals bill padding rather than horsepower. What predicts success is whether a senior engineer is writing your code daily, not the headcount on the proposal.
If we build for 20 users now, will the software cope with 500 later?
It should, without a rewrite, if it was built on a standard cloud stack; going from 20 to 500 users is mostly a hosting configuration change costing hundreds a month, not a second project. What actually breaks under growth is sloppier work: database queries never indexed for volume and features designed assuming one office's worth of data. Before signing, ask the vendor what happens to the system at ten times today's data, and listen for a specific answer.
We run everything on Airtable and spreadsheets. When is it time to go custom?
The switch usually makes sense when you hit one of two walls: Airtable's record caps (125,000 records per base on the Business plan) or logic the tool cannot express, like multi-step approvals with conditional pricing. There is also a simple cost signal: 25 people on Business at roughly $45 per seat per month is about $13,500 a year, forever, for a tool you are already fighting. Custom is worth it when the workflow is core to how you make money; for peripheral processes, staying on Airtable is the right call.
Couldn't I just build my app in Bubble or another no-code tool instead of hiring an agency?
For validating an idea with real users, yes, and we tell clients that honestly. The walls come later: Bubble apps cannot be exported as code to run anywhere else, performance drops on complex data operations, and usage-based pricing climbs as you grow. A meaningful share of Digital Heroes custom builds are rebuilds of no-code MVPs that proved the business worked, which is the system operating as intended: validate cheap, then build the version that scales.
Will custom software work with the tools we already use, like QuickBooks and Stripe?
Yes, and this is one of custom software's genuine advantages: QuickBooks, Stripe, Shopify, and most mainstream business tools publish documented APIs built for exactly this. Expect each standard integration to add one to two weeks of build time, and be suspicious of any quote that lists five integrations without asking what data flows in which direction. The hard cases are legacy systems with no API, which is a question to raise in discovery, not in week nine.
How do I calculate whether custom software will pay for itself?
Divide the build cost by the monthly benefit, where benefit is hours saved times loaded hourly cost, plus subscription fees replaced, plus any revenue the software unlocks. Three staff saving 10 hours a week each at a $40 loaded rate is about $62,000 a year, which pays back a $60,000 build in roughly 12 months. Across Digital Heroes internal-tool projects, 12 to 24 months is the normal payback range, and anything projecting under 6 months usually means the spreadsheet is hiding costs.
Can I build my product on a no-code tool like Bubble instead of hiring developers?
For testing whether anyone wants the product, yes, and Bubble's paid plans start at $29 a month, which is the cheapest validation you will ever buy. The ceiling arrives with complex data relationships, heavy integrations, performance at a few thousand users, and the fact that you cannot export a Bubble app to servers you control. A path many Digital Heroes clients take: prove demand on no-code, then rebuild custom once revenue justifies it, treating the no-code version as a paid prototype rather than a foundation.
How small can the first version of my software be and still be worth building?
One workflow, end to end, for one type of user: the single process that currently burns the most hours or loses the most money. In Digital Heroes delivery experience, first versions scoped to 6 to 10 weeks of build time ship, get used, and generate the feedback that makes version two obviously right, while 9-month first versions routinely launch with features nobody touches. Everything you cut from v1 gets cheaper to build later, because real usage reorders the roadmap for you.
Who can build a custom software system?
Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other software companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.
Related guides
Published · Last updated .