Key takeaways
- Comsol Sanscreen screens customers, vendors and sales and order addresses against sanctions and terror lists, directly from Dynamics NAV and Business Central.
- Screening runs individually, as a batch across the whole address base, or process-integrated inside the document.
- Covered by default are the consolidated EU list (EU_CFSP), the UK list (GB_HMT) and the US SDN list; further lists can be licensed.
- The screening itself is performed by Comsol's partner BEX; the result comes back into the document.
- The value lies less in the individual query than in the screening sitting inside the process and being documented.
Why the check belongs inside the process
The requirement is awkwardly phrased: it is not enough to establish once that a business partner is not listed. Lists change, ownership changes, and the duty applies at the time of the transaction — not at the time of the last check.
Anyone covering that with a spreadsheet and a quarterly review has documentation but not assurance. The gap sits exactly where the risk is: with the order created between two reviews, and with the new delivery address nobody recognised as a new business partner.
So the interesting part of a solution like Sanscreen is not the query itself but where it happens. When the check hangs on the customer, the order and the delivery address, it becomes part of the workflow rather than a task somebody has to remember.
The three ways to screen
Sanscreen offers screening in three forms, which in practice complement rather than exclude each other.
- Single check: one specific address at the press of a button, for instance before releasing an order
- Batch run: the entire address base at once, useful at rollout and after list changes
- Process-integrated: the check hangs on the transaction and runs with it, without anyone triggering it
- Customers, vendors and sales and order addresses are screened
- Results land in the document and are therefore traceably documented
Which lists are covered — and what that does not replace
By default the solution screens against the consolidated EU list of persons, groups and entities subject to financial sanctions, the UK list of Financial Sanctions Targets, and the US SDN list. Further lists can be licensed on top, which becomes relevant as soon as you supply markets whose regime is not covered.
Technically the check works by passing the address from Business Central to Comsol's partner BEX, matching it against the activated lists there, and returning the result. For data protection that means business partner data leaves the building — a point that belongs in your record of processing activities and should be settled with your data protection officer.
And one distinction that matters: a hit, or a clean result, is a screening outcome rather than a legal assessment. What a hit means for a specific transaction, which reporting or licensing duties apply, and how to handle name similarities belongs with your legal counsel. The software makes sure you ask the question in time at all.
Frequently asked questions
- Sanctions lists are not limited to export business — they concern relationships with listed persons and organisations regardless of where they are based. Whether and to what extent screening duties apply to your company is a legal question and should be settled with your legal counsel, not from a product description.
- The result is documented on the transaction so the decision stays traceable. What to do next is not for the software to decide: name similarities are common, and a hit is first of all an indication. How you handle it — release, hold, investigate further — belongs in a process agreed in advance and in consultation with your legal counsel.
- With the process-integrated variant, no — that is its actual purpose. The single check at the press of a button remains useful alongside it for special cases, and the batch run for rollout and for reconciling after list changes.
- The address being screened is passed to a service provider. That is processing on behalf of a controller and has to be documented accordingly — record of processing activities, data processing agreement, information to data subjects where applicable. Settle it with your data protection officer before rollout, not after.