How to Hire a Sanctions Screening Software Development Company
Judge every firm on one thing: whether they will expose the matching pipeline stage by stage so your sanctions officer can explain why a name scored 87.
On this page
Judge every firm on one thing: whether they will expose the matching pipeline stage by stage so your sanctions officer can explain why a name scored 87. Expect $80,000 to $190,000 for a first release covering list ingestion, a configurable matcher and a disposition queue, and $240,000 to $550,000 for a full platform. Screening a few hundred names a day in batch? Buy a tool.
Every vendor in this category will show you a clean hit queue. None will show you the eleven hundred alerts that were suppressed to make it look that way, or who decided the threshold that suppressed them, or when.
That is the difficulty. Screening is an operations problem with a legal edge, and both failure modes are expensive in opposite directions. Let a real match through and liability can attach regardless of intent, with correspondent banking consequences behind it. Over block and legitimate commercial payments miss their cutoff, your corporate clients notice, and treasury sales spends the week apologising. Tuning is choosing where to sit between those. The examiner does not expect perfection. The examiner expects you to explain the choice, and most institutions cannot, because the threshold is a number in a vendor console and the evidence it works is the absence of a problem so far.
What a sanctions screening software company actually does
The screen your analysts see is a small fraction. The work sits under it.
List ingestion first, and treated as events rather than a refresh job. When OFAC amends the SDN list or the EU consolidated list changes, the correct behaviour is to compute the delta, re screen the existing book against added and amended entries, and hold every list version immutably so any screening event can be stamped with the version and parameter set that produced it. That last point is what an examination tests, and it is close to impossible to retrofit.
Then the matcher, exposed as separate inspectable stages: normalisation, transliteration handling, tokenisation, scoring, threshold. Match quality depends on your population, not a generic one. A book with a large Arabic speaking customer base faces transliteration variance an Anglophone book never sees. A payments corridor into South Asia brings patronymic patterns and name ordering that break default assumptions. Trade finance screens vessel names, ports and goods descriptions, which behave nothing like personal names.
Then the operational layer: a queue ordered by time remaining against the cutoff and by novelty rather than by arrival, so a hit identical to one you cleared last week on the same customer against the same list entry presents as a one click confirmation with its prior rationale attached. Structured dispositions that name the identifier which differentiated your customer from the listed party. Whitelists governed as objects with an owner, an expiry, supporting evidence and a specific list entry, never a global name.
What a 2026 build costs
| Scope | Cost | Timeline |
|---|---|---|
| First release: list ingestion with versioning and delta computation, configurable and inspectable matching pipeline, operations hit queue with structured dispositions | $80,000 to $190,000 | 12 to 18 weeks |
| Full platform: inline payment screening, historical replay for threshold testing, whitelist governance, ownership graph evaluation, blocked property reporting | $240,000 to $550,000 | 8 to 16 months |
| List data subscriptions, tuning support and independent testing | 15 to 20 percent of build per year, plus data licences | Ongoing |
Two costs are routinely absent from proposals.
The first is retuning for structured payment data. With Fedwire on ISO 20022 and the SWIFT MT coexistence window closed, name and address information now arrives in structured fields rather than free text lines. Match rates move. Thresholds evidenced against MT era traffic do not transfer, and the tuning work and the above the line and below the line testing that documents it is a separate exercise from building the filter. Budget it explicitly.
The second is the ownership rule. Sanctions exposure extends past the names on a list, and an entity owned in aggregate at or above fifty percent by blocked persons is itself blocked even where it appears nowhere. No fuzzy matcher finds that, because the name is not there to match. Joining screening to the ownership graph you already collect at onboarding is real engineering, and it is the clearest argument for a build over a bolt on tool.
Signals worth trusting
- They ask about your customer population before your volumes. Corridors, name conventions and script variance determine the matcher, not throughput.
- They separate data providers from matching engines. World-Check and Dow Jones supply lists and enrichment. They are not your workflow and a partner who conflates them is guessing.
- They want historical traffic for replay. Threshold changes have to be testable against real past hits before they go live.
- They key dispositions to a triple. Subject, list entry and reason, so recurrence is recognisable and the queue stops re investigating the same surname weekly.
- They treat whitelists as the most dangerous artefact in the department. Owner, expiry, evidence, scoped to one list entry, re screened on every list update.
- They stamp every screening event with the list version and parameters. Unprompted. This is the tell.
- They will not promise a false positive reduction number. Anyone quoting a percentage before seeing your data is selling.
Red flags in a screening pitch
- A closed box score. If nobody can explain why a name scored what it scored, you cannot evidence tuning and you have bought the problem you already had.
- Queue sorted by arrival time. Payment screening races a cutoff and onboarding races an SLA. A queue that knows neither will lose one.
- Whitelisting by name. Global name suppression means a new list entry with a similar name never fires. That is a control failure waiting for an examiner.
- List updates handled as a nightly file load. Without deltas and immutable versions you cannot show what was in force when a payment was released.
- No mention of independent testing. Tuning without documented testing is an opinion, and an opinion is not evidence.
What to ask on the first call
- Our sanctions officer asks why a name scored 87 against an SDN entry. Who answers, and with what detail from which pipeline stage?
- How do you handle transliteration variance for our largest customer corridors, and how would you test it before go live?
- How do we replay a proposed threshold change against last year's real hits before we apply it?
- How is a whitelist entry scoped, who owns it, when does it expire, and what happens when the underlying list entry is amended?
- Show me how a payment released on a given Tuesday can be proven against the list version and parameter set in force at that moment.
- How does the queue know which payment is closest to its cutoff?
- How do you evaluate aggregate blocked ownership through a corporate ownership chain, using onboarding data?
- What changes in your matching design now that name and address arrive as structured ISO 20022 fields rather than free text?
- Who owns the tuning parameters and the disposition history if we end the engagement?
How to decide, cleanly
Buy a paid discovery phase before you buy a build. Three to five weeks, priced separately, with your sanctions officer and your independent testing function involved, ending with a written specification you own: the matching pipeline stages and parameters, the list ingestion and versioning model, the queue prioritisation logic, the disposition taxonomy, the whitelist governance rules and a tuning evidence approach your examiner would accept. Then take it to Napier, to Fircosoft, to LexisNexis and to two agencies. If a configurable product meets it, buy the product. Discovering that for the cost of a few weeks is money well spent.
Digital Heroes works PRD first for that reason, and contracts through a UK LTD, US LLC or India LLP so intellectual property and the tuning parameters assign under your own law. Fiverr Vetted Pro, 2,000 plus projects, verifiable through D-U-N-S, Clutch and Trustpilot. We are the wrong choice for a small institution screening a few hundred names a day in batch. Building your own name matching is not where your risk sits, and a packaged tool with a competent analyst will serve you better.
Book a 30-minute call with Digital Heroes and get a written plan and a fixed quote within 48 hours.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- Median SaaS spend reached $9,455 per employee, and organizations leave an average of 36% of their SaaS licenses unused. Source: Zylo (2026) →
- McKinsey found that tech debt can amount to 20-40% of the value of a company's entire technology estate before depreciation, and CIOs report that 10-20% of the budget for new products is diverted to resolving tech-debt issues. Source: McKinsey & Company (2020) →
- 88% of customers say good customer service makes them more likely to purchase from a brand again in the future, quantifying the direct revenue link between support quality and retention. Source: HubSpot (2024) →
- Salesforce's field-service research (State of Service / field service trends, survey of 5,500+ service professionals) found that 74% of mobile workers report increasing workloads and 47% say appointments don't go as planned due to customer miscommunication, unaccounted-for parts, or insufficient appointment lengths and travel times. (The separate claim that admin tasks consume ~30% of a technician's hours is NOT supported by the report - the seventh-edition data instead states technicians spend about 18% of working hours, ~7 hours/week, on admin, and only ~32% of time interacting with customers.). Source: Salesforce (2024) →
Frequently asked questions
How much does custom sanctions screening software cost?
A first release covering list ingestion with versioning and delta computation, a configurable and inspectable matching pipeline and an operations hit queue with structured dispositions runs $80,000 to $190,000 across 12 to 18 weeks. A full platform adding inline payment screening, historical replay, whitelist governance and blocked property reporting runs $240,000 to $550,000 over eight to sixteen months, plus list data licences.
Should we buy a screening tool or build our own?
Buy if you screen modest volumes in batch and your customer base is linguistically uniform. Build when your hits are clearing late enough to threaten payment cutoffs, when your population brings transliteration or name ordering patterns that default algorithms mishandle, or when you cannot evidence why your thresholds sit where they do. The build worth funding is usually the tuning and disposition layer rather than a replacement filter.
How do we reduce false positives without missing a real match?
Attack the queue before the threshold. Most clock time goes on hits identical to ones already cleared, so key each decision to the subject, the list entry and the reason, then present recurrence as a one click confirmation with its prior rationale. Order the queue by time remaining against the cutoff and by novelty. Only then tune thresholds, and only with replay against real historical hits and documented testing.
What does the ISO 20022 migration mean for our screening?
Name and address data now arrives in structured fields rather than free text lines, which changes what the matcher sees and moves match rates. Thresholds evidenced against MT era traffic do not carry over, so retuning and fresh above the line and below the line testing are a separate workstream from building or configuring the filter. Very few proposals include that effort, so ask for it as a named line item.
Who owns the tuning parameters if an agency builds our screening system?
You must. Tuning parameters, the disposition history and the list version stamps are your evidence at examination, so require source code assignment on payment, your own repository from the first commit, and full export of parameters, decisions and screening events in a documented format. A vendor holding the reason your thresholds sit where they do is a supervisory problem, not a commercial one.
How long does it take from first call to software my team can actually use?
Plan for four to six months: two to three weeks of discovery, two to four weeks of design, then a 10 to 16 week build with testing. In Digital Heroes delivery experience the schedule killer is not engineering speed but decision lag; a client who takes two weeks to approve wireframes adds two weeks to launch. Book a weekly 30-minute decision slot before kickoff and most of that risk disappears.
Should I ask for a fixed price or pay the agency hourly?
Fixed price for the first version, hourly or retainer for what comes after launch. A fixed-scope, fixed-price V1 puts the estimation risk on the agency, which is exactly where you want it while trust is unproven; hourly billing on an unscoped greenfield build is a blank check. After launch, flip it, because maintenance and small features arrive unpredictably and fixed-pricing every ticket wastes everyone's time.
What are the biggest mistakes first-time software buyers make?
Choosing the lowest bid, paying more than 30-40% upfront instead of on milestones, skipping a written specification, and having no maintenance plan for after launch. The most expensive of the four in Digital Heroes rescue projects is the missing spec: without written acceptance criteria, done becomes an argument instead of a checklist, and every disagreement resolves in the vendor's favor. Fix those four and you have avoided most of the ways these projects fail.
Is it cheaper to customize Salesforce than to build a custom CRM from scratch?
If you use less than a third of what Salesforce does, a custom CRM is often cheaper by year three. Salesforce Enterprise lists at $165 per user per month, so 25 seats cost about $49,500 a year before admin and consultant fees, while a focused custom CRM runs $60,000 to $100,000 once plus 15 to 20% a year in maintenance. If you genuinely need Salesforce's ecosystem, reporting, and app marketplace, customizing it beats rebuilding it; the mistake is paying enterprise prices to use it as a glorified contact list.
Is a solo freelancer enough for my project, or do I really need an agency?
A solo freelancer is a fine choice for a well-defined build under roughly $15,000 to $20,000 with a limited lifespan: an internal calculator, a scripted integration, a prototype. Above $50,000, or for any system your business will depend on for years, you are buying continuity as much as code: enforced code review, cover when someone is ill, and support that outlasts one person's career plans. Price the risk of a single point of failure, not just the hourly rate.
Is custom software more secure than off-the-shelf SaaS?
Neither is secure by default; security tracks the practices of whoever builds and operates the system, not the model. SaaS gives you the vendor's certifications and patching but puts your data in a shared multi-tenant platform on their terms, while custom gives you full control over data residency, access rules, and compliance requirements like HIPAA, with the responsibility sitting with you and your agency. Before hiring anyone for a system holding sensitive data, ask for their security checklist: encryption at rest and in transit, an OWASP Top 10 review, role-based access, and a penetration test before launch.
How many SaaS seats do we need before building custom becomes cheaper?
The crossover usually shows up between 20 and 50 seats on premium tiers. Salesforce Enterprise lists at $165 per user per month, so 40 users cost about $79,000 a year in subscriptions, which is real money against a custom system you would own outright. Run the comparison over three years: if subscription spend beats the build cost plus 15-20% annual maintenance, custom wins on price before you even count workflow fit.
Can I build my product on a no-code tool like Bubble instead of hiring developers?
For testing whether anyone wants the product, yes, and Bubble's paid plans start at $29 a month, which is the cheapest validation you will ever buy. The ceiling arrives with complex data relationships, heavy integrations, performance at a few thousand users, and the fact that you cannot export a Bubble app to servers you control. A path many Digital Heroes clients take: prove demand on no-code, then rebuild custom once revenue justifies it, treating the no-code version as a paid prototype rather than a foundation.
What is a discovery phase, and is it worth paying for separately?
Pay for it, and treat the output as yours. A discovery phase runs two to three weeks, typically 5 to 10% of the eventual build budget, and produces a written scope, wireframes, and a fixed quote you can take to any vendor, including a competitor of the agency that wrote it. Skipping it is how projects end up quoted from a two-paragraph email and delivered at twice the price.
How long does it take to build a custom web or mobile app from scratch?
Plan on 8 to 16 weeks for a focused first version and 4 to 9 months for a larger platform, which is the typical spread across Digital Heroes builds. The first 2 to 3 weeks go to discovery and design before any production code ships. The two things that stretch timelines most are integrations with legacy systems and slow feedback from your side, not developer speed.
Does the tech stack matter, and which one should I ask for?
It matters less than agencies imply, provided it is boring. A mainstream stack, something like React or Next.js on the front end, Node.js or Python behind it, and PostgreSQL for data, means thousands of developers can maintain your system if you ever change vendors. Apply one test: ask how hard it would be to hire a replacement developer for the proposed stack, and walk away from anything built on an agency's in-house framework.
How do I vet a software development agency before signing a contract?
Ask to speak with two past clients whose projects resemble yours in size and industry, and ask exactly who will write your code, since some agencies sell senior faces and deliver junior or subcontracted hands. Demand a written specification with acceptance criteria before any fixed price, and check that their portfolio links to products that are actually live. An instant quote given without questions about your workflows is the clearest warning sign there is.
What happens if I stop paying for maintenance after launch?
Nothing breaks on day one, which is what makes it dangerous. Within 6 to 18 months, unpatched dependencies accumulate known vulnerabilities, an integrated API like Stripe ships a breaking change, and the first fix requires a developer to relearn a stale codebase at full price. Budget 15 to 20% of the build cost per year for upkeep; it is the difference between a $500 patch and a $15,000 emergency.
Who can build a custom software system?
Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other software companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.
Related guides
Published · Last updated .