Skip to content
AITISHTECH
SAP GTS

A screening hit nobody owns is not a control. It is a queue.

SAP GTS compliance projects are usually scoped as configuration. The configuration is the easy half — the half that determines whether the control is real is the operating model behind it.

GTS compliance implementations have a reliable pattern. Configuration goes well. Sanctioned party list screening goes live. Documents start blocking.

And then a queue forms.

Not because the configuration is wrong — usually it is fine — but because nobody decided in advance who releases a blocked document, on what evidence, inside what timeframe, and with what authority. Within a fortnight there is pressure to loosen the match strategy, because sales orders are stopping and someone senior has noticed.

Loosening the strategy is how a compliance control becomes a compliance theatre.

False positives are managed, not eliminated

Screening compares your business partners against watchlists containing transliterated names, partial addresses and common surnames. A strategy tight enough to never produce a false positive will also miss real matches. That is not a tuning failure; it is the nature of the problem.

So the design question is not “how do we stop false positives” but “how do we clear them reliably and fast enough that the business does not route around the control”.

Three levers, in order of durability:

Business partner data quality. The single highest-return investment, and the least popular because it is unglamorous and sits outside the project. Complete, structured addresses with country codes reduce false positive volume more than any strategy tuning will.

Match strategy tuning. Real, and worth doing — but do it against measured volumes after go-live, not against assumptions before it. Tuning during design is guessing.

A maintained cleared-party list. Parties confirmed as non-matches, recorded with the evidence and the date. This is where most of the ongoing reduction actually comes from, and it only works if the clearing decisions are captured properly in the first place.

The operating model is the deliverable

Before go-live, four questions need answers with names attached:

  1. Who reviews a hit? A named team, not “compliance”. With cover for absence and for volume spikes.
  2. What evidence is sufficient to release? Written down. Consistent across reviewers. Auditable three years later, when the reviewer has left.
  3. What is the response window? An order blocked for four hours is friction. Blocked for four days is a business problem that will generate pressure to weaken the control.
  4. Who escalates, and to whom? Genuine ambiguity needs a path that does not default to whoever is loudest.

None of this is SAP configuration. All of it determines whether the control functions.

Sequence by exposure, not by module

The instinct is to implement GTS as a product: compliance, customs and risk management together, one go-live.

Better to sequence by exposure:

Screening and embargo first. Sharpest exposure, fastest to deliver, and the results are immediately visible. It also builds the exception-handling discipline everything else will depend on.

Customs second, country by country. Customs filing is national. Each country brings its own authority, message formats, broker relationships and edge cases. A country template plus a documented local delta scales. A single global customs go-live does not.

Preference last. Preferential origin determination depends on complete bill-of-material data and on vendor declarations you have to solicit and chase. That solicitation cycle is measured in months and does not compress. It is genuinely valuable — often the largest hard-currency saving in the whole programme — but it cannot be rushed into an early phase.

The uncomfortable question

Worth asking during design, out loud: what happens today when a match would have been found?

The answer is often that the check happens in a separate tool, on a batch, some time after the transaction — or that it is assumed to be covered by someone else in the chain.

If that is the honest answer, then GTS is not automating an existing control. It is introducing one. That is a bigger organisational change than a system project, and it should be resourced and communicated as such — because the first time a real hit blocks a real order for a real customer, the reaction will be very different in an organisation that was told this was coming.

Next step

Tell us the actual problem.

Not a capabilities request — the constraint you are up against. A wave that will not release in time, a rollout country that keeps slipping, a screening queue nobody owns. That gets a useful answer back.

Monday–Friday, 09:00–18:30 IST (UTC+5:30)