AML screening is the process of checking customers, beneficial owners, directors, counterparties and payments against sanctions lists, politically exposed person (PEP) data, watchlists and adverse media. It is the control that stops a regulated business from doing prohibited business, and the one most likely to be tested first in an inspection.
It sounds simple — compare a name to a list — and it is not. Names transliterate differently, entities restructure, sanctions regimes change weekly, and a screening engine tuned too tightly misses risk while one tuned too loosely buries analysts in noise.
What gets screened, and against what
| Data domain | Typical sources | Risk it addresses |
|---|---|---|
| Sanctions | UN, EU, OFAC, UK OFSI and national regimes | Prohibited dealings; strict-liability breaches. |
| PEP | Global PEP databases with role, tier and relatives/close associates (RCA) | Bribery and corruption exposure requiring enhanced due diligence. |
| Watchlists | Regulatory enforcement, debarment, law enforcement and internal lists | Known bad actors and previously exited relationships. |
| Adverse media | Structured negative news, screened by predicate offence category | Reputational and predicate-crime risk not yet on any list. |
Who must be screened
- The customer — natural person or legal entity.
- Beneficial owners above the applicable ownership threshold, and controllers below it.
- Directors, officers and authorised signatories.
- Counterparties and payment participants where the risk assessment requires it.
- Suppliers and third parties in higher-risk categories.
- Employees, where regulation or internal policy requires it.
How matching actually works
A screening engine normalises the input name, generates variants (transliteration, word order, initials, nicknames, corporate suffixes), compares them to list entries using phonetic and edit-distance algorithms, and scores the similarity. Anything above the configured threshold becomes a potential match for review.
Accuracy improves most when secondary identifiers are available: date of birth, nationality, registration number, address, and role. A name-only screen against a global PEP database will always be noisy; a name plus date of birth plus nationality screen is a different control entirely.
- Exact and fuzzy name matching with configurable thresholds by risk tier.
- Transliteration handling for Arabic, Cyrillic, Greek and Chinese-origin names.
- Entity matching using registration number, jurisdiction and legal form.
- Secondary identifier confirmation to promote or discount a hit.
- Whitelisting of confirmed non-matches, with expiry and re-review.
Onboarding screening versus ongoing screening
Screening at onboarding establishes whether a relationship can be entered at all. Ongoing screening establishes whether it can continue. Both are required, and the second is where supervisors most often find failings, because customer populations are large and list changes are constant.
- Batch rescreening of the whole population against updated lists, typically daily.
- Event-driven screening triggered by a change of address, ownership, director or product.
- Periodic review cadence set by the customer's risk score, not a uniform annual cycle.
- Payment screening in real time for institutions processing cross-border transfers.
Controlling false positives without losing coverage
- Tune thresholds by risk tier rather than applying one global setting.
- Enrich the input record — a missing date of birth is the single biggest cause of noise.
- Use good-guy lists with mandatory expiry so discounted hits are periodically re-tested.
- Segment adverse media by predicate offence so unrelated news does not generate alerts.
- Measure and report the true-positive rate per analyst and per list; treat it as a KPI.
- Re-test any tuning change against a historical alert set before promoting it to production.
What a defensible screening record contains
- The exact input data submitted and the timestamp of the screen.
- The list versions and data sources in force at that moment.
- The threshold and configuration applied.
- Every hit returned, with the similarity score and matched fields.
- The reviewer, the decision, the written rationale and any four-eyes approval.
- Any resulting escalation, EDD step or SAR/STR reference.
Frequently asked questions
What is AML screening?
AML screening is the process of checking customers, beneficial owners and counterparties against sanctions lists, PEP data, watchlists and adverse media to identify parties a regulated business is prohibited from dealing with or must apply enhanced due diligence to.
What is the difference between sanctions screening and PEP screening?
Sanctions screening identifies parties subject to legal prohibitions — a positive match usually blocks the relationship or payment. PEP screening identifies politically exposed persons, which is not prohibitive but triggers enhanced due diligence, source-of-wealth checks and senior approval.
How often should AML screening be performed?
At onboarding, then continuously. Most institutions rescreen the full population daily against list updates, screen in real time on payments where relevant, and rescreen on trigger events such as ownership or address changes.
Why does AML screening produce so many false positives?
Because name-only matching over global datasets is inherently ambiguous. Adding secondary identifiers such as date of birth, nationality and registration number, tuning thresholds by risk tier and segmenting adverse media typically reduces noise substantially without weakening coverage.
Is adverse media screening mandatory?
It is not universally mandated by name, but supervisors and the FATF expect a risk-based approach to reputational and predicate-offence risk, and adverse media screening is the accepted way to evidence it — particularly for higher-risk customers and enhanced due diligence.
Can AML screening be automated end to end?
Matching, rescreening and alert prioritisation are automated. Discounting or confirming a hit remains a documented human decision in most regimes, so the goal is to reduce the number of alerts requiring review, not to remove the reviewer.
Compliance insights, straight to your inbox
Monthly analysis on AML, screening and risk technology from the teams behind ComplianceSuite, RISQO and API4ALL. No spam — unsubscribe anytime.
