One vendor charges by user. Another charges by the number of business partners. A third charges by screening volume, API calls, list packages, or modules. Buyers put the quotes next to each other and look for the lowest annual price.
But the licence is only the visible cost.
Once the software starts screening, it produces alerts. Those alerts have to be investigated, cleared or escalated, reviewed, and documented. That work returns every day and grows with the number of business partners you screen.
Two systems can have the same licence price and create very different operating costs. A product that generates 1,000 alerts a month will cost more to run than one that generates 200, even if both subscriptions cost the same. A system that remembers previous decisions will cost less to operate than one that asks analysts to clear the same namesakes again after every re-screening run.
The useful question is therefore not only: How much does the software cost?
It is: How much does it cost to determine and document a sanctions decision?
How much does sanctions screening software cost?
There is no single market price for sanctions screening software. The quote normally depends on several factors:
- The number of business partners or records screened
- The number of users
- The countries and sanctions lists included
- How often existing records are re-screened
- Whether screening runs manually, in batches, or through an API
- Whether the software connects to an ERP, CRM, procurement, or master-data system
- Whether ownership, adverse media, PEP, or other risk data is included
- Whether case management and audit documentation are included
- The level of implementation, support, and training required
Some products are sold as simple cloud subscriptions. Others are part of wider trade compliance or risk-data platforms. Some vendors publish an entry price. Others only provide a quote after reviewing your volumes, systems, and list requirements.
This makes a direct licence comparison difficult. It also means a low starting price may describe only the smallest part of the setup.
A useful pricing request should therefore state exactly what has to be included: the records, screening frequency, list coverage, integrations, data sources, workflow, storage, support, and expected growth. Without that detail, two quotes may appear comparable while describing completely different controls.
What is normally included in the licence?
A basic sanctions screening licence usually gives the company access to the matching engine and a defined package of sanctions or restricted-party lists.
Depending on the product, it may also include:
- Manual name searches
- Batch screening
- Scheduled re-screening
- User management
- Match thresholds
- Search history
- Standard reporting
- An audit log
Other capabilities may be separate modules or paid data packages:
- Corporate ownership information
- Beneficial ownership data
- Adverse media
- Politically exposed persons
- State-owned company data
- Vessel and aircraft data
- Export-control lists
- ERP and CRM integrations
- API access
- Long-term evidence storage
- Advanced reporting
The distinction matters because list screening alone answers only whether a name resembles an entry on a selected list.
It does not necessarily tell the analyst whether the party is owned or controlled by someone listed. It does not say whether the transaction falls within the relevant regime, whether the business predates the designation, or why the alert can be cleared.
Those questions create additional data and workflow costs, whether they are paid to the software vendor or absorbed by the compliance team.
Why is the licence fee not the total cost?
Sanctions screening creates work after the match. Someone has to determine whether the business partner is the listed party and what the result means for the transaction.
A typical alert may require the analyst to:
- Compare the names and aliases.
- Check addresses, countries, dates of birth, and registration numbers.
- Review the original sanctions entry.
- Search corporate registries and company records.
- Check ownership and control.
- Review open-source information.
- Consider the relevant list, jurisdiction, transaction, and dates.
- Decide whether to clear, hold, or escalate.
- Record the evidence and reasoning.
- Obtain a second review where required.
A simple name mismatch may take only a few minutes. A company with weak identifiers, complex ownership, transliterations, or links to higher-risk jurisdictions can take much longer.
The investigation process is covered in What Happens After a Sanctions Alert? The important pricing point is that the work does not disappear because the screening software is automated. The system automates detection. The company still pays for resolution.
How much does one sanctions alert cost?
The cost of an alert depends on three variables:
- How many alerts the system produces
- How long each alert takes to resolve
- The hourly cost of the people doing the work
The basic calculation is: Annual alert-resolution cost = monthly alerts × average resolution time × 12 × loaded hourly cost
Take a company receiving 125 alerts each month.
Assume each alert takes an average of 10 minutes to investigate and document. That creates 1,250 minutes of work each month, or about 20 hours.
Across one year, the team spends roughly 250 hours resolving alerts.
At an analyst cost of €60 per hour, the annual alert-resolution cost is approximately €15,000.
That does not include:
- Second-level review
- Legal escalation
- Requests for information from the business
- Ownership data
- Translation
- Audit reconstruction
- Time spent correcting weak case notes
- Delays to orders and payments
The example is not a market benchmark. It is a model. A company should replace the assumptions with its own alert volumes, resolution times, and staff costs.
The exercise usually reveals something important: a small change in alert volume can be worth more than a large change in licence price.
Why does false-positive volume change the real price?
Screening vendors often describe false-positive reduction as a usability benefit. It is also a direct cost factor. Every false positive consumes analyst time. Even an obvious mismatch has to be opened, reviewed, decided, and recorded.
If one product generates 75 fewer alerts each month, and each alert takes eight minutes to close, the difference is 10 analyst hours every month. That is 120 hours a year.
The cheaper licence may therefore become the more expensive system if it produces substantially more alerts.
The opposite can also happen. A system may suppress alerts aggressively and lower the workload, but create a weaker control by missing relevant variations. The goal is not the lowest alert count. It is the lowest unnecessary alert count without weakening detection.
This is why buyers should test products on their own business partner data. A demonstration using selected names tells you how the interface works. It does not tell you what your operational workload will be.
A meaningful test should measure:
- Total alerts produced
- Unique alerts produced
- Repeated alerts
- Alerts requiring external research
- Average time to a decision
- Percentage escalated
- Percentage cleared as false positives
- Quality of the resulting case record
These numbers show more about cost than the licence quote alone.
What happens when previous decisions do not carry forward?
Re-screening can make the same operating cost return repeatedly.
A business partner called Mohammad Ali, Alexander Ivanov, or Global Trading may generate the same candidates every night. The analyst checks the identifiers and clears the match.
If the system does not preserve and reuse that reasoning, the same candidates return on the next run. The team performs the same comparison again. The work has already been done. The software simply does not let it count.
Decision carry-forward changes the economics of screening because it allows a previous clearance to remain valid until something material changes, such as:
- A new sanctions entry
- A new alias
- A changed address
- A change in ownership
- A changed registration number
- A different list or program
- A change in internal policy
Without carry-forward, the alert count may look stable while the team repeatedly pays for the same decisions.
This is one reason the cost of screening should be measured per documented decision, not per name checked. Screening millions of names is inexpensive for software. Investigating thousands of repeated alerts is expensive for people.
Which costs are often missing from the proposal?
A software quote may not include all the work required to make the system operational. Before comparing proposals, ask whether the following costs are included or separate.
Data
- Does the licence include only official sanctions lists, or also ownership, adverse media, PEP, vessel, aircraft, and other risk data?
- Which countries have usable corporate ownership coverage? How frequently is the information updated?
Integration
- Is API access included?
- Are ERP, CRM, SAP, Salesforce, procurement, and master-data connectors included, or priced separately?
- Who pays for internal IT work, testing, mapping, and maintenance?
Implementation
- Does the price include data preparation, configuration, threshold testing, user roles, workflows, migration, and training?
- How much work remains with the customer?
Re-screening
- Is nightly or daily monitoring included?
- Is pricing based on the number of stored business partners, the number of screening events, or both?
- Does a full re-screen count as a new charge for every record?
Case management
- Can the analyst investigate and document the case inside the product?
- Are evidence, sources, reasoning, reviews, and attachments stored with the decision?
- Or does the company still need spreadsheets, shared drives, email, and another case-management system?
Retention and reporting
- How long are records kept?
- Can the company export a complete case file years later?
- Is long-term storage included, and does the record preserve the list version and evidence available at the time?
Alert tuning
- Who configures match thresholds and name-matching logic?
- Is tuning included during implementation? Is later tuning covered by support, professional services, or the customer’s internal team?
Escalation
- How many alerts require senior compliance or legal review?
- A difficult alert may consume hours from more expensive staff, even if most alerts are cleared quickly.
- These costs do not always appear in the subscription line. They still belong in the business case.
Support and maintenance
- Is ongoing support included in the licence, or billed separately as an annual percentage of it?
- What does the base level cover: response times, hours of cover, software updates, and new sanctions-list additions? Is faster support a paid upgrade?
How should total cost of ownership be calculated?
A practical annual model is: Annual sanctions screening cost = software and data fees + annualised implementation costs + integration and support costs + alert-resolution labour + review and escalation costs + documentation and audit rework
Implementation costs can be divided across the expected contract or system life. For example, a €60,000 implementation spread across three years contributes €20,000 to the annual cost model.
The result can then be divided by the number of completed decisions: Cost per documented decision = annual sanctions screening cost ÷ completed alert decisions
This number is more useful than cost per screening check. The software may run one million checks with little effort. The expensive unit is the case that requires a person to investigate and decide.
A second useful measure is: Average resolution time = total analyst time spent on alerts ÷ completed decisions
A third is: Time to documented decision = time from alert creation to completed, reviewable case record
Together, these measures show whether the software is reducing operating work or simply producing detection faster.
What should buyers ask sanctions screening vendors?
Before selecting a product, ask questions that expose the operating cost.
- How many alerts will the product generate on our own data? Do not accept a generic false-positive rate. Run a representative sample.
- Will previous clearances carry forward? Ask what change causes the system to reopen a decision.
- What data is included? Separate official lists, ownership, adverse media, PEP, vessel, aircraft, and other datasets.
- How is re-screening priced? Clarify whether charges are based on stored records, screening events, API calls, or list updates.
- What does the analyst see inside the alert? Can the analyst access identifiers, original list information, ownership links, sources, and previous decisions in one place?
- How is the decision documented? Ask whether the system captures evidence, sources, reasoning, reviewer, status, and next action.
- Which integrations are included? Ask for the full price of the planned ERP, CRM, procurement, and API setup.
- How are complex cases handled? Can the workflow support ownership checks, legal escalation, information requests, holds, and second-level review?
- What can be exported for an audit? Ask to see the complete record for one cleared alert, not only a dashboard or activity log.
- What is the expected time from alert to documented decision? If the vendor only measures screening speed, it is measuring the beginning of the process.
These questions are also useful when applying the framework in How to Evaluate Sanctions Screening Software.
What does cheaper sanctions screening software mean?
Cheaper software is not necessarily the product with the lowest subscription. It is the product that lets the company reach reliable, documented decisions with the least unnecessary work.
That may mean paying more for better data. It may mean paying for an integration that removes manual exports. It may mean accepting a higher licence price because the system produces fewer repeated alerts and gives analysts the evidence they need in one place.
It may also mean that a simple product is the right choice. A small company with a stable business partner base and low alert volume may not need complex ownership data, advanced workflows, or a large integration project.
But every buyer should include the same hidden line in the calculation: what happens after the alert appears.
The licence is the visible cost. Alert resolution is the recurring one. A vendor quote tells you what it costs to run the screening software. Your alert volumes, investigation time, and documentation process tell you what it costs to operate the control. The number worth comparing is not the price per check. It is the cost per documented decision.
☰