Expertise · Data & automation
Automate compliance — once the data is right
Automating a process built on wrong master data does not save time: it industrialises the error and makes it harder to detect. We handle both, in order.
In most organisations, compliance data exists in three copies: a commodity code in the ERP, another in the export team's spreadsheet, a third at the customs broker. None is officially wrong; none is officially right. Any automation built on that situation will reproduce the ambiguity at scale.
We start by establishing a single master and deciding who owns it, and only then automate the controls that can be automated — leaving judgement calls to people.
The compliance product master
| Attribute | Used for | Who must populate it |
|---|---|---|
| Commodity code (HS / CN) | Duties, preferences, trade defence, adjacent regulation | Customs team, on written reasoning |
| Origin (preferential / non-preferential) | Preference access, marking, trade defence | Customs team from purchasing data |
| Export status (dual-use, ECCN, Swiss) | Licence requirement, destination blocking | R&D / engineering, validated by compliance |
| Product sanctions status | Sectoral restrictions by destination | Compliance, from current lists |
| Weight, statistical value, units | Declaration accuracy and statistics | Logistics / order management |
Design rule
A compliance attribute that can be changed without trace, by any user, at any time, is not a compliance attribute. The first useful automation is often the simplest: lock the field and log the changes.
What automates, and what does not
- Automatable: party screening against lists, blocking a prohibited product/country combination, completeness checks before sending data to the broker, reconciliation between declarations lodged and orders, alerts on expiring supplier declarations, re-screening triggered by a list update.
- Not automatable: classifying a new product, assessing a doubtful end use, determining indirect ownership, deciding to stop a shipment. These can be supported by tools; they cannot be delegated to a rule.
Checking the declarations lodged in your name
Few companies systematically reconcile the declarations lodged by their broker against their own order data. It is one of the most profitable controls to automate: it surfaces classification differences, wrong values, misapplied procedures and incorrectly declared origins — before an audit finds them.
We implement this reconciliation from the declaration data you can obtain, with a set of variance rules and a monthly dashboard a non-specialist can use.
Dashboards and audit trail
A compliance framework must answer three questions at any moment: where do we stand, what did we decide, and can we prove it. We build simple dashboards — share of items classified and justified, screening alerts handled and their lead time, declarations in variance, authorisations approaching expiry — and make sure every decision leaves a timestamped, attributed record.
Deliverables
What we put in place
Master data model
The attributes, their definition, owner, update rule and locking mechanism.
Control specifications
The rules to implement in your tools, written to be picked up directly by your IT team or integrator.
Declaration reconciliation
The process for checking declarations lodged in your name, with its variance rules.
Compliance dashboard
A short, readable indicator set fed by data you already hold.
Tool requirements document
If software is needed: the real requirements, the evaluation protocol and the comparison — with no vendor link.
Data remediation plan
How to clean up the existing base without stopping the business, in prioritised batches.
Method
Approach
Audit the data
Extract and analyse the quality of existing compliance attributes. The output is a rate, item by item.
Establish the master
One source, one owner, one update rule. This step is organisational before it is technical.
Automate the controls
Specify then test the rules, starting with those that block a real risk.
Measure
Dashboard, monthly review, and tuning of noisy rules — a control that generates too many alerts stops being applied.
Frequently asked questions
Do we need dedicated software to be compliant?
No. Compliance rests on accurate data, traceable decisions and accountable people. Many mid-sized companies maintain a solid framework with their ERP, a screening tool and documentary discipline. Dedicated software becomes relevant when the number of items, destinations or list updates exceeds what an organisation can handle manually. We help locate that threshold and, if it is crossed, write a requirements document describing your real needs rather than the market's feature list.
Do you work with a particular vendor?
No, deliberately. We resell nothing and take no referral commission. We work on the tool you already have, or help you choose one through an evaluation protocol defined with you. That independence is what allows us to tell you, when it is the case, that a software investment will not solve your problem.
How long does it take to clean up a product master?
It depends on the number of active items and the initial data quality, but the usual order of magnitude is six to twelve weeks for a few thousand items, working in prioritised batches by revenue and risk. Processing everything at once is rarely realistic and almost always counterproductive: secure the items carrying most of the flows and most of the risk first.