top of page

TrustSphere Vendor Assessment: Fircosoft, the Filter That Became Infrastructure

Writer: TrustSphere Network
TrustSphere Network
13 minutes ago
7 min read


Sanctions filtering is one of the few financial crime controls where the technical requirement has been stable for twenty years and the operational burden has grown every single year. The engine still does what it always did: compare strings in a message against entries on a list, apply fuzzy matching logic, stop what it cannot clear, and pass what it can. What has changed is the volume of lists, the rate at which they are amended, the complexity of the matching rules regulators expect, and the size of the operations function required to adjudicate the output.


Fircosoft has occupied this category for longer than most of its competitors have existed. It is a sanctions filtering and watchlist screening engine, strongest in real time payment message filtering across SWIFT and equivalent message formats, with a mature list management layer and tuning capability. It is deployed widely in tier 1 correspondent banking, and in that population it is frequently the incumbent rather than a challenger. That incumbency is the most important fact about it, and it cuts both ways.


Buyers approach this category with one of two questions. The first is whether the filter itself is technically adequate, which for a serious institution is a fair question but rarely the deciding one. The second, and the better question, is what the filter costs to own once you account for list management, tuning, model validation and the operations headcount required to clear what it stops. This assessment is mostly about the second question, because that is where the money and the risk actually sit.


Score and Capability Profile


Fircosoft scores 7.0 out of 10 in the TrustSphere Risk Index, against an index mean of 6.06. That places it materially above average, and the gap is earned in a narrow band of the profile rather than spread evenly across it. The category is watchlist and sanctions filtering infrastructure.


  • Watchlist and Sanctions Screening: 9

  • Transaction Monitoring and Screening: 8

  • Client Lifecycle Orchestration: 5

  • eKYC and KYB: 3

  • Identity Verification and Liveness: 2

  • Document Authentication: 2

  • Fraud Detection: 3

  • Enterprise Fraud Risk Management: 3

  • Behavioural Biometrics: 2

  • Device Intelligence: 2


The shape of that profile is the point of the assessment, and it should be read as a statement of intent rather than as a set of gaps. This is a specialist instrument, not a platform. It scores at or near the top of the index on the one thing it was built for, holds a strong secondary position in message level transaction screening, and makes no serious claim across identity, fraud or lifecycle orchestration. Vendors with flatter profiles at the same overall score are usually generalists who do several things adequately; this profile belongs to a product that does one thing at a standard very few competitors reach and declines to pretend about the rest.


Buyers should draw the obvious conclusion. If your selection is for a sanctions filter, this profile is close to ideal and the low scores are irrelevant to you. If your selection is for a consolidated financial crime platform and someone has placed Fircosoft on the shortlist, the shortlist is wrong, and no amount of demonstration will fix that. The commonest procurement error in this category is comparing a specialist engine against orchestration platforms on a single scorecard and then being surprised by the result.


What It Actually Does Well


The core filtering engine is genuinely strong, and its strength is in the unglamorous properties that matter at scale: throughput under load, deterministic behaviour, and the ability to process high message volumes in real time without becoming the bottleneck in a payment chain. In correspondent banking, where a filter sitting in the critical path can hold up settlement across multiple time zones, this is not a feature to be traded away for a better user interface. Institutions that have run it for years generally trust it, and that trust is based on operational experience rather than on marketing.


List management is the second genuine strength and it is undervalued by buyers who have never had to do it properly. Ingesting, normalising and version controlling sanctions lists from multiple authorities, handling amendments and delistings, maintaining internal and private lists alongside official ones, and being able to demonstrate to an examiner exactly which list version was live at a given moment are all hard problems. Fircosoft handles them with a maturity that reflects two decades of dealing with regulatory examination in the most heavily scrutinised institutions in the market.


The third area of strength is tuning and the evidential trail around it. The engine exposes matching parameters at a granularity that lets a competent team target reductions in false positives without lowering effectiveness in ways they cannot explain, and it produces the artefacts a model validation function and a regulator will ask for. That combination, meaningful configurability plus defensible documentation of the configuration, is rarer than it should be and is the single strongest argument for the product in a regulated selection. It matters because tuning disputes with supervisors are almost never about whether a threshold is correct in the abstract. They are about whether the institution can show its reasoning, its testing and its approval trail. A product that produces those artefacts as a by-product of normal operation saves a remediation programme later.


Where the Limitations Are


The first and most important limitation is one of scope rather than quality. Fircosoft is a filter, and a filter operates on names in messages. It does not solve, and does not claim to solve, the instrument level exposure problem in securities and capital markets: the issuer behind an identifier, the guarantor, the underlying obligor, the beneficial holder several layers down a custody chain, or exposure acquired passively through index construction. A buyer in a securities services business who believes that deploying this product discharges their sanctions obligation has misunderstood their obligation. The control there sits in reference data and operations, and the filter is one component of a much larger picture.


The second limitation is total cost of ownership, and it is systematically underestimated at the business case stage. The licence is the visible number and it is rarely the largest one. The real cost sits in list management, in the tuning and testing cycle, in model validation, and above all in the operations team required to adjudicate alerts. In TrustSphere's engagement data across tier 1 and tier 2 deployments, the fully loaded annual cost of running a sanctions filtering capability typically exceeds the licence cost by a multiple, with alert adjudication headcount the dominant component. Any business case that compares licence prices across vendors and stops there is measuring the wrong thing.


The third limitation is the age and shape of the deployment base. Long incumbency in tier 1 banking means a substantial installed estate of older, heavily customised, on premises deployments, and the modernisation path for those estates is a real question a buyer should press rather than assume. Cloud deployment, upgrade cadence, the effort involved in migrating years of accumulated configuration, and how long a given version will be supported are all live issues. An institution running an old version with bespoke modifications may find that its upgrade is closer to a reimplementation than a patch, and that reality should be surfaced during selection rather than discovered in year three.


The fourth limitation is functional. Native case management, investigation workflow and analytics are thin compared with orchestration platforms built in the last decade, and most serious deployments end up integrating the filter with a separate case management layer. Related to this is the customisation burden: outcomes with this product depend very heavily on configuration quality, which means on the skill of the team configuring it. Two banks running the same version can produce materially different false positive rates and materially different detection outcomes. That places a dependency on the vendor's professional services and tuning practice which buyers should price and contract for explicitly rather than treat as incidental. Integration effort in securities and custody flows, which were never message based in the way payments are, is a further and frequently underestimated cost.


Questions to Press in the Demo


The purpose of the demonstration is to move the conversation off the engine, which will perform well, and onto the operating model around it, which is where the risk and the cost live. Ask for evidence rather than assertion, and ask for named references in institutions of comparable size and complexity.


  • Show us, from a real deployment of comparable volume, the fully loaded annual cost split between licence, professional services, list management and alert adjudication headcount.

  • Take a client currently on a heavily customised on premises version and walk us through their actual upgrade or cloud migration path, including elapsed time, configuration migration effort and what had to be rebuilt.

  • Demonstrate how the product handles an instrument level question: given a security identifier, what can it tell us about issuer, guarantor and underlying obligor designation status, and what must be solved elsewhere.

  • Show the tuning evidence pack you would hand to a model validation function and a regulator, taken from a live client engagement, including how a specific threshold change was justified and tested.

  • Explain precisely which outcomes depend on your professional services team, what happens to our false positive rate if we staff configuration internally, and what you will contract to on tuning performance.


Verdict


Fircosoft should be bought by institutions whose primary problem is high volume real time sanctions filtering of payment messages under close regulatory scrutiny, and who have or will build the operations and tuning capability to run it properly. In that use case, the 7.0 score understates it, because the capability that matters is the one scoring 9. Correspondent banks, large clearers and payment infrastructure operators are the natural buyers, and for them the incumbency and the examination track record are genuine assets rather than inertia.


It should not be bought by institutions looking for a consolidated financial crime platform, by firms whose sanctions exposure is predominantly instrument level rather than message level, or by organisations without the internal capability to own configuration. It pairs naturally with a modern case management and investigation layer, with a securities reference data capability if the exposure sits in capital markets, and with an independent tuning and validation function that is not the vendor. Selected for the right problem and resourced honestly, it is one of the more dependable purchases in this market. Selected as a substitute for a control framework, it will disappoint expensively.


Suggested Next Steps


  • Build the business case on fully loaded cost including adjudication headcount, list management and tuning, not on licence price, and require comparable figures from every bidder.

  • Confirm whether your material sanctions exposure is message level or instrument level before shortlisting, and scope the selection accordingly.

  • Request a documented upgrade and cloud migration path from a reference client with a customised legacy deployment, with elapsed timescales.

  • Contract explicitly for tuning outcomes and knowledge transfer so that configuration quality is not an open ended dependency on vendor services.


Sources: OFSI, OFAC, EU Council and European Commission, HM Treasury, FCA, EBA, Wolfsberg Group, BIS, TrustSphere Risk Index, April 2026.


TrustSphere helps financial institutions design and deploy intelligent fraud and financial crime detection solutions. Visit www.trustsphere.ai

 
 
 

Comments


Recommended by TrustSphere

© 2026 TrustSphere.ai. All Rights Reserved.

  • LinkedIn

Disclaimer for TRUSTSPHERE.AI

The content provided on the TRUSTSPHEREAI website is intended for informational purposes only. While we strive to provide accurate and up-to-date information, the data and insights presented are generated from a contributory network and consolidated largely through artificial intelligence. As such, the information may not be comprehensive, and we do not guarantee the accuracy, reliability, or completeness of any content.  Users are advised that important decisions should not be made based solely on the information provided on this website. We encourage users to seek professional advice and conduct their own research prior to making any significant decisions.  TruststSphere Partners is a consulting business. For a comprehensive review, analysis, or support on Technology Assessment, Strategy, or go-to-market strategies, please contact us to discuss a customized engagement project.   TRUSTSPHERE.AI, its affiliates, and contributors shall not be liable for any loss or damage arising from the use of or reliance on the information provided on this website. By using this site, you acknowledge and accept these terms.   If you have further questions,  require clarifications, or requests for removal or content or changes please feel free to reach out to us directly.  we can be reached at hello@trustsphere.ai

bottom of page