Custom trade compliance software development
Anyone who imports or exports goods needs to be able to show, for each counterparty and each shipment, that checks were carried out: against the EU consolidated sanctions list, against the dual-use rules, and against the commodity code under which the declaration is made. The hard part is rarely the rule itself, but the judgement behind it and the record that remains. Appfront builds software that supports and records that judgement within your own order and shipping process.
What trade compliance covers, and who it is for
Trade compliance is the set of checks around a cross-border flow of goods: may you supply this party, does the product fall under export control, which commodity code applies to the customs declaration, and is a licence required with capacity still remaining? These questions touch sales, the warehouse, dispatch and the customs team at the same time, so they often happen outside the system: in a spreadsheet, an email thread and the memory of one experienced employee.
We build this type of software for wholesalers, manufacturers and machinery builders, for electronics and chemicals companies, and for logistics service providers. The common thread is that the check has to sit inside the order process, not beside it.
Is this the right page for you? If you screen business relations because the Dutch Money Laundering and Terrorist Financing (Prevention) Act (Wwft) requires customer due diligence, you are looking at KYC and AML, and you will find KYC and AML compliance software more useful. The matching technique is related, but the trigger and the supervisory authority are not. If your question concerns setting up processing activities and the record of processing, that belongs in a GDPR compliance platform. This page is about goods that cross borders.
Sanctions screening is at its core a name-matching problem
The consolidated list of persons, groups and entities subject to EU financial sanctions is published by the European Commission and contains multiple name variants for each entry. This is necessary: names in Cyrillic, Arabic or Chinese have no single correct Latin spelling. The same person may appear as Aleksandr, Alexander and Aleksander, with or without a patronymic. Companies are listed under their registered name while you know them by a trading name, or you are dealing with a subsidiary that is not itself listed.
This is where the real difficulty lies. If you set the matching tightly, a transposed letter or a missing second forename slips through unnoticed. If you set it loosely, a common Dutch surname collides with a listing and your team receives daily hits that almost all mean nothing. Both problems never disappear entirely; you choose a position on that scale and must be able to explain it.
Name matching stops being useful for ownership and control. A counterparty that is not itself listed still falls under the freezing measure when it is owned for 50% or more by listed parties, aggregated across several holdings, and control can exist even below that threshold. That is a question for a shareholder structure, not for a list; the EU Sanctions Helpdesk helps small and medium-sized businesses with this free of charge.
Every hit that does not drop out automatically is reviewed by a person, and that judgement must be recorded. Without a file, a correctly cleared hit cannot be distinguished from a missed one.
- List version and reference date of the screening
- The rule and score that produced the hit
- Fields compared: name, address, date of birth, country
- Name, role and timestamp of the reviewer
- The justification for clearance or blocking
- When an exception expires
When you screen determines who is affected
Screening is not a one-off action, and where it sits in the process determines what happens when something comes up. The moments below all occur, usually in combination. The choice comes down to where you accept the delay.
The screening runs separately from the operation, so a hit does not add to order lead time. The verdict simply goes out of date straight away and says nothing about the shipment that leaves later.
There is still room to manoeuvre here: a hit means a delay in the order confirmation, not a standstill in the warehouse. The price is a reviewer who is available when orders come in, including outside office hours.
The most current check, and the only one that takes in the actual delivery address and the ultimate consignee. The cost is immediate: a hit halts a picked shipment and creates pressure to release it quickly.
Lists are updated, so a relationship that was clean last month may be hit today. Re-checking the entire customer base is a process in its own right, with its own backlog.
A goods code is a judgement, not a lookup
The foundation is the Harmonised System of the World Customs Organization: six digits that apply worldwide. The EU adds two digits to reach the eight-digit CN code of the Combined Nomenclature for exports, and two more to reach the ten-digit TARIC code for imports. That code determines import duty, anti-dumping measures, prohibitions and licensing requirements; one subheading's difference changes what you pay and what you are allowed to do.
The correct code is rarely self-evident, though. The same product can fall under a different heading depending on its composition, degree of processing or the form in which it is presented: a mixture follows the component that gives it its essential character, and a part is classified differently from the machine it belongs to. That is a classification judgement based on the General Rules for the Interpretation and on case law, not a search in a table. Software records that judgement and makes it reusable; a binding tariff information ruling from Customs, valid for three years, belongs in the same product file.
Export control is a second, separate classification. A product may carry an ordinary CN code and still fall under Annex I of Regulation (EU) 2021/821, the dual-use regulation covering goods, software and technology with both civil and military applications. Article 4 also provides a safety net: even a product not listed becomes subject to licensing once you know that the end use is problematic. Licences for strategic goods are applied for through the Central Import and Export Office (CDIU) of Customs.
On top of that come measures tied to goods codes: the list of common high priority items flags HS codes at elevated risk of diversion to Russia, and Article 12g of Regulation 833/2014 requires exporters, for certain annexes, to include a contractual prohibition on re-export there. Both belong in the system: as a risk signal at article level and as a condition attached to the order.
What such a system must do in your process
Screening and classification are only half the work. The other half is handling whatever comes up, and making sure the operation does not start working around it.
Blocking at the right level
A hit on a single order line should not freeze the entire order, and a blocked relationship should not be supplied anyway through a second debtor number.
Licences that run alongside
An export licence has a validity period, destination, end user and quantity. For partial deliveries, usage is deducted per shipment, so it is visible when the remaining allowance runs out.
Re-screening as a separate workflow
When a list version changes, only the difference is run against the customer base, with the results placed in a separate queue. Otherwise re-screening drowns in the order flow.
Test your idea first: a working prototype in 1 day
With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.
Explore OneDayBuild →When custom is not the answer
To start with: nobody builds the sanctions data from scratch. The EU, US and national lists, the name variants, the daily changes and the ownership and control information are bought in from a specialist provider. That remains the case even when the software around it is custom.
For common situations, mature packages also exist that combine screening, classification, licence management and customs documentation, with data feeds and regulatory maintenance included in the subscription. For a manageable portfolio, fixed destinations and an ERP for which such a package provides an integration, that is almost always the more sensible route. Factor in what you take on when building in-house: if a regulation or list format changes, that maintenance falls to you.
Custom development pays off in two cases. The first is deep integration: the check must intervene in the middle of your order and shipping process, with blocks at line level, release by a specific role, and an integration that genuinely stops picking. The second is a portfolio with unusual classification and licensing questions, such as configurable machines whose code differs by composition.
Often the answer is also not one or the other: a package for the screening engine and data, and custom development for the shell that ties it into your process. If you are a financial entity with questions about ICT risk management and incident reporting, have a look at DORA compliance software.
- Blocking must happen at order line level, not customer level
- The classification differs by product configuration or specification
- Your ERP or WMS has no existing package integration
- Licence usage must track partial deliveries
- Multiple entities with different export regimes
- A supplier does not put a critical request on its roadmap
What the system connects to
A trade compliance system holds little data of its own. It relies on item master and order data from your ERP, shipment data from the warehouse, a sanctions data feed and the nomenclature. On the outbound side, it supplies the code, the licence number and the status to the software you use to file declarations in the Douane Management Systeem. Recommendation (EU) 2019/1318 from the European Commission provides a workable framework for the surrounding set-up, with transaction screening, record-keeping and internal controls as the core separate elements.
Frequently asked questions about trade compliance software
No, and nor should you want us to. The consolidated EU sanctions list, the national and US lists, and the ownership and control data come from specialised data providers. We build the layer around them: ingesting the feed, version control on the list, the reference date for each screening, and re-screening as soon as a list version in use changes.
There is no good number for that. Every match threshold is a trade-off between hits you miss and hits someone has to review, and you need to be able to justify that choice. What can be done: make the threshold adjustable per list and per field, run a change against historical data first, and keep releases revocable should the listing change.
You often have to do that too. Mature packages exist that combine screening, classification, licence management and customs documentation, including data feeds and regulatory maintenance. For a manageable portfolio, fixed destinations and an ERP with an integration to that package, that is the more sensible route. Custom development makes sense when the check must reach deep into your order and shipping process, or when your products raise classification questions the package doesn't cover.
In essence, you had a process and you followed it. For each reviewed hit, record the list version and reference date, the data compared, the reviewer, and the justification for release or blocking. For each shipment, record the commodity code and the basis for that classification, and where applicable the licence number with the volume drawn down.
The source code belongs to the client and sits in a repository under your own account. We work with widely used languages, databases and API conventions, and document the data model and screening logic in readable documentation. The sanctions data remains the property of your data provider and is licensed through your own subscription.
No. The system prepares and records: it retrieves the correct list version, shows which fields match, and stores previous decisions about the same relationship. Whether a hit concerns the right party, and whether a product falls under a particular commodity code or under Annex I of the dual-use regulation, remains a human decision. Responsibility for declarations and exports stays with the exporter.
Related services
If you are screening clients rather than goods flows, because the Dutch Money Laundering and Terrorist Financing (Prevention) Act (Wwft) requires you to carry out client due diligence and transaction monitoring, then KYC and AML compliance software is the right page.
If you are a financial entity with questions about ICT risk management, resilience testing and incident reporting, see DORA compliance software.
If the matter is the processing of personal data itself, including the processing register, retention periods and data subject requests, that belongs with a GDPR compliance platform.
If you want to check your relationships against sanctions lists on an ongoing basis, take a look at our sanctions list screening tool.
If you want to track how many CBAM goods you import each year, take a look at our CBAM goods tonnage monitor.
Want your trade compliance built into your systems?
Tell us how your order process runs, where screening currently takes place, and which part of your portfolio raises the most difficult classification and licensing questions. We will help you judge whether an existing package will suffice or whether a custom layer built around your process is the better investment.