Skip to content
OfacScanner

Sanctions Screening Software Buyer Guide for Compliance Teams

October 7, 2026

Two compliance analysts reviewing a possible match together on dual monitors

Sanctions screening software checks your customers, counterparties and payments against government sanctions lists and tells you when a name needs a closer look. Most tools promise the same thing on their homepage. The differences show up later, in how fast lists update, how many false alerts your team clears each week, and whether you can prove what you checked when someone asks.

This guide walks through what to compare, the questions worth asking every vendor, and a checklist you can use in your own evaluation.

Start with your own screening needs

Before you look at any product, write down what you actually screen and how often. A small marketplace that onboards a few hundred sellers a month has different needs from a payments company that screens every transfer. Answer these first.

  • Who do you screen? Individuals, companies, owners and officers, vessels, payment parties.
  • When do you screen? At onboarding, before each payment, after every list update, or all three.
  • How do records reach the tool? Typed in by hand, uploaded as a file, or sent from your own systems through an API.
  • Which lists apply to you? OFAC lists for U.S. exposure, and possibly UN, EU, UK or other regimes depending on where you operate.
  • Who reviews alerts, and how many people share that work?

With those answers in hand, the comparison below becomes much easier, because you can ignore features that don't matter to you and focus on the ones that do.

What to compare in sanctions screening software

List coverage and update speed

Coverage is the first filter. For U.S. exposure you need the OFAC SDN list and the Consolidated (non SDN) lists at a minimum. Ask which other lists are available today and which are planned, and be wary of a single "global" figure with no breakdown.

Update speed matters as much as coverage. OFAC publishes changes without a fixed schedule, and a designation applies from the moment it is published. Ask how soon after a change the new list version is live in the tool, and whether you can see which version a given check used.

Fuzzy matching and transliteration

Exact matching misses too much. Names on sanctions lists come with aliases, alternate spellings and transliterations from Arabic, Cyrillic, Chinese and other scripts. Good matching handles reordered names, missing middle names, typos and spelling variants, and it searches aliases as well as primary names.

Ask whether you can tune the match threshold, and whether secondary data such as date of birth, nationality or country of address is used to rank results. Run your own test names, including deliberate misspellings of real list entries.

False positive handling

Every screening tool produces false positives. The question is how much effort each one costs. Look for a clear side by side view of your record and the list entry, the reason for the match, and the ability to mark a result as a false positive with a note. A cleared match should not come back as a fresh alert every time the same unchanged record is re-screened.

Batch screening

If you have an existing customer base, you need to screen it in one go. Check whether the tool accepts a CSV upload, how it maps your columns, and what the results file looks like. A good batch sanctions screening flow returns every row with a clear status, not only the matches.

API and webhooks

For screening at onboarding or before payments, the tool has to sit inside your own flow. Ask for public API documentation, response times, authentication methods and how errors are reported. Webhooks should be signed so your system can verify that an alert really came from the vendor. A dedicated sanctions screening API with clear examples saves weeks of integration work.

Ongoing monitoring

Screening once at onboarding is not enough. A customer who was clean last year can be designated tomorrow. Ongoing sanctions monitoring re-screens your saved records after every list update and raises an alert only when something new appears. Ask how monitored records are added and removed, and whether the plan limits how many you can keep.

Evidence record and audit trail

Under 31 CFR 501.601, records relating to OFAC regulated transactions have to be kept, and the retention period moved from five to ten years in 2025. Your screening tool should store, for each check, the input, the list version, the results, the reviewer and the decision. Ask whether you can export that record and whether changes to decisions are logged rather than overwritten.

Case management

Once more than one person handles alerts, you need cases with owners, statuses and notes, and a way to escalate. Check whether the tool supports roles, so that a reviewer can clear a match while only a senior officer can confirm a true match.

Pricing without overage fees

Pricing models vary widely. Some vendors charge per check with surprise overage bills, others require annual contracts sized by a sales call. Look for published prices, a clear monthly check allowance and no overage fees, so a busy month does not turn into an invoice you didn't plan for. Compare what each tier includes, especially monitoring and API access.

Comparison table

AreaWhat good looks likeRed flag
List coverageNamed lists with sources, versions visible per checkA vague "global coverage" claim
Update speedNew list versions live shortly after publicationNo answer, or weekly updates
MatchingAliases, transliteration, tunable thresholdExact or near exact matching only
False positivesSide by side review, notes, no repeat alertsCleared matches keep returning
BatchCSV upload with full results fileManual entry only
APIPublic docs, signed webhooksDocs only after signing a contract
MonitoringRe-screening after every list updateManual re-runs only
Audit trailExportable evidence per check, logged decisionsResults not stored
PricingPublished plans, no overage feesPrice only after a sales call

Questions to ask every vendor

  1. Which lists do you screen against today, and how quickly is a list change reflected in results?
  2. Can I see the list version used for any past check?
  3. How do you handle aliases, transliteration and partial names?
  4. Can I adjust the match threshold, and what secondary data is used to rank results?
  5. What happens to a cleared false positive when the record is screened again?
  6. How does monitoring work, and how many monitored records does my plan include?
  7. Are webhooks signed, and is the API documentation public?
  8. What exactly is stored in the evidence record, and can I export it?
  9. How is customer data protected, and where can I read your security details?
  10. What happens if I exceed my monthly checks?

Buyer checklist

  • Requirements written down: who, when, how and which lists.
  • Test set prepared, including misspelled and transliterated list names.
  • Matching quality checked on your own data, not only the demo.
  • False positive workflow tried end to end.
  • Batch upload and API tested with real formats.
  • Monitoring alert observed after a list update.
  • Evidence record exported and reviewed.
  • Roles and case handling confirmed for your team size.
  • Total cost calculated for a normal and a busy month.

Frequently asked questions

Does the software make the compliance decision

No. Screening results support your decision. A person on your team reviews potential matches and decides whether a match is true, and the tool records that decision.

Is a free name search enough

A one off search, like an OFAC check, is useful for a quick look. It does not give you monitoring, case handling or a lasting record, which most regulated businesses need.

Does name screening cover the 50 percent rule

Only partly. Companies owned 50 percent or more by blocked persons are often not listed by name. You need to screen owners too, as explained in our post on the OFAC 50 percent rule.

Where OfacScanner fits

OfacScanner is sanctions screening software that screens people and companies in real time, in CSV batches and through a REST API with signed webhooks. It uses fuzzy matching with aliases and transliteration, keeps records in monitoring with alerts after every list update, and stores an evidence record for each check, along with case management and false positive review. It starts with the OFAC SDN and Consolidated lists, with an architecture built for UN, EU, UK, Canadian and Australian lists. OfacScanner is not affiliated with OFAC or the U.S. Treasury.

Plans start at $49 a month, yearly billing halves the price, and there are no overage fees. See the pricing page, or explore how our sanctions screening platform fits your onboarding and payment flow.

Want to see a result before anything else? Screen one name now with the OFAC search on our home page and look at the matches, scores and list date it returns.