Infocredit Group
Insight

How to choose compliance software

A 10-step selection process, an evaluation scorecard, the questions to ask vendors, and the mistakes that make buyers replace their platform within two years.

Choosing compliance software is a data-quality decision disguised as a software decision. Two platforms can present near-identical screens and produce very different outcomes, because one resolves ultimate beneficial ownership from primary registries in your markets and the other does not. The selection process below is designed to expose that difference before you sign.

It works for firms buying their first compliance management system and for teams consolidating several point tools into one.

Step 1 — Write the obligation map first

List the regulations you are actually supervised against, the supervisory authority for each, and the specific evidence they ask for at inspection. This becomes your requirements baseline. If a requirement is not traceable to an obligation or an internal risk decision, it is a nice-to-have.

Step 2 — Quantify the operational load

  • New customers or suppliers onboarded per month, and peak versus average.
  • Percentage that are corporate entities requiring UBO resolution.
  • Jurisdictions involved, and which registries those imply.
  • Current alert volume, false-positive rate and average handling time.
  • Number of analysts, and the review model (maker-checker, four-eyes).

Step 3 — Test data coverage in your markets

Ask for coverage evidence per country you operate in, not global averages. For each market, confirm the source of company registry data, refresh frequency, whether UBO data is derived or registry-sourced, and how gaps are handled. A platform with excellent US coverage can be near-useless for Cyprus, Malta, Greece or the Gulf.

Step 4 — Measure screening quality on your own data

Supply a sample of real historical records containing known true positives, known false positives and a few deliberately fuzzy names with transliteration variants. Compare recall (did it catch every true hit?) and precision (how much noise?) across vendors on the same sample. Ask how fuzzy matching thresholds are tuned and whether you can tune them per risk band.

Step 5 — Check monitoring, not just onboarding

  • Is rescreening event-driven or batch, and at what latency after a list update?
  • Are corporate structure changes and adverse media monitored, or only sanctions lists?
  • Can risk scores be recalculated automatically when an input changes?
  • What happens to alerts raised on customers who are already offboarded?

Step 6 — Interrogate the evidence trail

Ask to see a real export of everything the system would hand a regulator for a single customer: the checks run, the source records retrieved, the matched and discounted hits, the reviewer, the timestamp and the rationale. If the vendor cannot produce that in the demo, assume you will be assembling it manually later.

Step 7 — Map the integrations

  • APIs for onboarding flows, with documented rate limits and sandbox access.
  • Webhooks for alerts and status changes.
  • Connectors or export paths to your CRM, core banking or case system.
  • SSO, SCIM and role-based access aligned to your segregation of duties.
  • Data residency and retention controls that satisfy GDPR and local rules.

Step 8 — Score the vendors consistently

CriterionWeightWhat evidence proves it
Data coverage in your markets20%Per-country source list and refresh cadence
Screening precision and recall20%Results on your own test sample
Evidence and audit exports15%A live regulator-ready export
Workflow fit and analyst efficiency15%Timed handling of ten real cases
Integrations and API quality10%Sandbox access and docs
Security, residency and certifications10%ISO 27001, penetration test summary
Commercials and total cost10%Cost per onboarded customer at your volumes

Step 9 — Model total cost of ownership

Include the platform fee, per-check and per-report charges at realistic volumes, implementation and data migration, integration engineering, training, and the analyst hours consumed by false positives. A cheaper licence with a 30% higher false-positive rate is usually the more expensive system.

Step 10 — Plan the first 90 days before signing

  • Agreed success metrics: alert volume, handling time, onboarding turnaround.
  • A migration plan for existing customers and their historical evidence.
  • A parallel-run period against the current process.
  • Named implementation contacts and an escalation path in the contract.

Common mistakes

  • Buying on demo polish rather than tested match quality.
  • Ignoring UBO depth until the first complex corporate structure arrives.
  • Skipping the proof of concept because timelines are tight.
  • Underestimating integration effort into the onboarding funnel.
  • Choosing a global vendor with thin coverage in your actual operating markets.

Frequently asked questions

How do I choose compliance software?

Start with your regulatory obligations and onboarding volumes, shortlist vendors against per-market data coverage, then run a proof of concept using your own historical records to compare screening precision and recall, evidence exports and analyst handling time before comparing price.

What questions should I ask a compliance software vendor?

Ask for per-country data sources and refresh frequency, how UBO data is derived, how fuzzy matching is tuned, whether rescreening is event-driven, what a regulator-ready evidence export contains, API and sandbox availability, security certifications, and total cost at your projected volumes.

How long does a compliance software implementation take?

A focused onboarding and screening deployment typically takes 4 to 12 weeks, depending on integration depth and historical data migration. Multi-entity, multi-jurisdiction rollouts with custom risk models take longer.

Should we build compliance tooling in-house instead?

Building the workflow is feasible; sourcing, licensing and maintaining registry, sanctions, PEP and adverse media data is where in-house projects usually stall. A common middle path is to buy the data through an API and keep your own workflow.

What is the biggest cost driver in compliance software?

Analyst time spent clearing false positives. Improving match precision usually reduces total cost more than negotiating the licence fee.

Newsletter

Compliance insights, straight to your inbox

Monthly analysis on AML, screening and risk technology from the teams behind ComplianceSuite, RISQO and API4ALL. No spam — unsubscribe anytime.