Counterparty checks that keep up — even as the lists change

Your team checks the same document pack hundreds of times a year, and the lists it checks against keep moving underneath. That is a different problem from deal due diligence — and it is the one that does not survive being done by hand.

from $30,000Solution Blueprint: volume counted, thresholds set, fixed price, in 5–6 weeks
from $150,000typical build — completeness, matching and re-screening, 4–6 months
Fixed pricequoted against the Blueprint scope — no time and materials
On-prem or cloudcounterparty files stay inside your perimeter, GPUs in the same contract

This is for you if

In your words rather than ours. Three of these true and we have built for your situation before.

You check counterparties constantly, and the process never got builtIt grew. Someone does it in a spreadsheet with a folder of PDFs, and it works right up until the volume moves or that person is on leave.
Every counterparty sends a different packCompleteness is established by a human noticing what is missing. Nobody can say what the required set even is without opening a previous file.
The lists change and nobody re-checks the old onesOnboarding screening happened. Since then, nothing — because re-reading several hundred files by hand is not a thing anyone is going to do.
Screening runs through one personThey are the bottleneck, they know it, and the risk of that arrangement is discussed once a year and then not acted on.
A shipment is waiting on a checkThe cost is not the analyst's forty minutes. It is the container, the letter of credit and the customer asking where their order is.

Deal checks vs ongoing checks — we build the ongoing one

Most material on AI in due diligence describes the left-hand column. If your problem is the right-hand one, that advice is scoped against the wrong economics.

Deal due diligenceContinuous screening
How oftenA few times a yearHundreds to thousands
Document setUnique, unpredictable, largeLargely the same pack every time
Who does itLawyers, billed by the hourProcurement and compliance, salaried
Tolerates manual workYes — cost is proportionate to deal valueNo — cost scales with counterparty count
What we automateLittle worth automatingCompleteness, agreement, entity matching, and re-screening when lists change

The last row is the one that decides the project. The full split, with the payback arithmetic →

When we tell you not to do this

The first of these disqualifies more enquiries than everything else on this page combined, and we would rather put it in writing than discover it in month two.

Under roughly 2,000 checks a yearOn labour savings alone a custom build does not pay back below that — at 400 checks a year the arithmetic says thirteen years. Buy a commercial screening service or improve the manual process. Two things legitimately change this: a check sitting on the critical path of a shipment, and an error that costs a licence rather than an invoice.
No counterparty registerIf who you deal with lives across three spreadsheets and an ERP with duplicate records, screening has no subject. That cleanup comes first and it is not an AI project.
The problem is contractual, not proceduralIf exceptions arise because nobody agreed what documents a supplier owes you, automation produces disputes faster. Settle the policy; the software is the easy part.
You want the verdict automatedWe will not build a system that decides the ambiguous cases on its own. The error asymmetry below is why, and it is not negotiable for us.

What we build, and what we decline

Two halves, and they are not the same engineering problem. Most vendors quote them as one line, which is how the second half arrives late.

The lists — automates completely
  • Matching an entity against a list is deterministic by construction: the normalised entity, the list, and the version of that list on a given date. Given those three the answer is fixed permanently.
  • So it needs ingestion, version pinning and delta detection against a source that moves without telling you.
  • The list version is the audit trail. A screening decision without it attached cannot be re-derived, however good the rest of your logging is.
The documents — automates partially
  • Whether this certificate is the one the policy requires, whether the entity on page four is the entity on page one — no enumerable input set, so no deterministic answer.
  • So it needs configuration per counterparty type, and a human at exactly one place: the boundary where interpretation stops being enumerable.
  • Everywhere else a human is cost without benefit — which is why “human in the loop” as a general posture is a design failure rather than a safeguard.

The reference standard is double for the same reason. For the documents it is your procurement or deal requirements, which change from deal to deal and are set by you. For the parties it is the current lists, which change on their own and are set by someone else.

FirstSecondNot at all
Both halves above: list ingestion with version pinning and delta re-screening, and the document layer — required-pack completeness plus cross-document agreement on names, addresses and registration numbersOwnership-chain reconstruction, expiry and renewal tracking, an exception queue with evidence attached, integration into procurement and ERPA legal opinion on a counterparty. A reputational assessment scraped from open sources without verification. Any autonomous decision on an ambiguous match.
Missing a listed party → a regulatory event, a licence, a penalty.
Flagging a clean party → a few minutes of human review.

Those two costs differ by orders of magnitude, so the system is tuned deliberately over-sensitive. It clears the unambiguous majority automatically and escalates everything else. We report the false-negative rate and the queue volume as two separate numbers, because a single accuracy figure hides exactly the thing you are accountable for.

Export control screening

A different layer of check, not one more list to match against. Screening runs against the OFAC SDN list, the BIS Entity List and the Denied Persons and Unverified lists — and then asks three questions that no list answers.

It asks more than who

Ordinary screening asks who the counterparty is. Export control also asks who the actual end user is, what the item will be used for, and whether the destination is permitted for that specific item classification — so a transaction that is routine for one product is prohibited for another with the same customer and the same paperwork.

What automates, and what does not

The assembly automates: pulling parties and end user from the pack, normalising them, matching the lists, checking classification against destination, and putting a complete file in front of the person who signs. The signature does not automate, and we will not build it that way.

Where the rules live

The regulatory substance — EAR scope, end-user certificates, red flags, consequences — is set out in export controls and dual-use IT hardware. This page is about the shape of the work, not the content of the rules.

How the work runs

Three phases, each with what we need from you. The first is a product you can buy on its own.

PHASE 01
Volume, pack and thresholdsWe count your annual check volume by counterparty type, define the required document pack for each, and set the escalation thresholds with a named owner — before any model exists. Output is a build-ready specification, a fixed price and a timeline. This phase is the AI Solution Blueprint, from $30,000, credited against the build; the spec is yours to implement with anyone.You provide
  • 50–100 completed counterparty files, awkward ones included
  • Annual volumes and who currently does the work
  • Which lists you are obliged to screen against
PHASE 02
Completeness, agreement, matchingThe document layer on your real files: required-pack checking, cross-document field agreement, entity normalisation and list matching, with the false-negative rate and queue volume measured separately from the start.You provide
  • A counterparty register, however imperfect
  • One named owner for it
  • Access to the list sources you subscribe to
PHASE 03
Re-screening, queue and handoverDelta re-screening when lists change, an exception queue a person can actually work, evidence retained per decision so it can be reconstructed years later, and integration into procurement or ERP.You provide
  • A named owner for the exception queue
  • Retention and residency requirements
  • An acceptance owner who can sign

What this looks like when it is built

The closest thing we have shipped: cross-document agreement checked automatically against a regulation, with a specialist signing. Client name withheld under NDA. See full case studies →

Aviation · MRO

Cross-pack consistency, machine-checked and human-signed

An autonomous computer-vision service that classifies each page of a maintenance pack into six document types, detects missing signatures and stamps, finds unfilled checklist cells, and verifies that work-card and task numbers agree across the pack — returning an annotated report before a specialist signs off. Advisory by design: it decides what a human must look at, never what the answer is. Read the case →

6 document types classified4 classes of check on one packCLI + API delivery
What was hard

Three things, none of them the model. Telling a stamp from a printed logo on a scanned page, where the visual difference is smaller than the scanning noise. Agreeing what “empty” means for a checklist cell — a dash, an initial and a blank are three different intentions and only one is a defect. And pages that belong to no document type at all, which turned out to need an explicit low-confidence fallback rather than a forced classification, because forcing one produced confident wrong answers exactly where a human most needed to look.

No surprises

Your data

The pipeline runs on-premises or air-gapped on open-weight models, with no counterparty document leaving your network, and GPU hardware quoted in the same contract. Details in security and compliance and private AI infrastructure.

Your decisions

List matching, completeness and field agreement are versioned deterministic rules, not learned behaviour. A screening decision made today can be reconstructed exactly as it was made when someone asks in two years — which a hosted model cannot promise.

Your budget

Fixed price against a scope agreed before the build starts, and a first phase whose honest output may be “your volume does not justify this”. No time and materials, no discovery that bills indefinitely.

Frequently asked questions

How is a due diligence automation project scoped and priced?

Scope first, price second, and both numbers are published. The specification is a product: the AI Solution Blueprint, one system, 5–6 weeks, from $30,000, credited in full against the build if implementation starts within 90 days. It counts your annual check volume, maps the required document pack per counterparty type, sets the escalation thresholds with a named owner, and returns a fixed price and a timeline. Builds of this kind typically start around $150,000 over 4–6 months.

At what volume does this stop being worth building?

On labour savings alone, below roughly two thousand checks a year a custom build does not pay back — and we will say so rather than sell into it. Two things change that arithmetic and both are legitimate: a screening step sitting on the critical path of a shipment, where the cost is the delay rather than the analyst's time, and an error that carries a licence rather than an invoice. If neither applies at your volume, a commercial screening service or a better manual process is the correct purchase.

Do you cover export control and sanctions screening?

Yes. Screening against the OFAC SDN list, the BIS Entity List and the Denied Persons and Unverified lists is part of what we build. Export control asks more than who the counterparty is: it asks who the end user is, what the item will be used for, and whether the destination is permitted for that specific item classification.

Can the screening decision itself be automated?

The clearing, yes. The flagging, no — deliberately. Missing a listed party is a regulatory event; re-checking a clean one costs a few minutes. Those costs differ by orders of magnitude, so the system is tuned to be over-sensitive: it clears the unambiguous majority automatically and routes everything uncertain to a person, accepting a false-positive rate that would be unacceptable in almost any other application.

What happens when a sanctions list changes?

The system re-screens the existing counterparty base against the delta and raises only what changed. This is the capability that separates a real system from a faster manual process: a counterparty cleared in March is not cleared in September, and nobody re-reads several hundred files by hand. Any design that checks at onboarding and never again provides false comfort.

Can it run on our own infrastructure?

Yes. The pipeline runs on-premises or air-gapped on open-weight models, with no counterparty document leaving your network, and the GPU hardware quoted in the same contract. Screening decisions are reproducible by design, so a decision made today can be reconstructed exactly as it was made when someone asks in two years.

Related practices

Tell us how many counterparties you check

An engineer replies, not an account manager. If the volume does not justify a build, you will hear that first.

Want the spec first? AI Solution Blueprint — from $30,000, credited against the build.

We reply within one business day. Prefer email? sales@haink.org