← Back to Blog
March 13, 2026 · 7 min read

AML Screening Explained: Sanctions, PEPs, and Watchlists

What is AML screening?

AML screening checks a customer against sanctions lists, politically exposed person databases and adverse media to establish whether you are permitted to serve them. A sanctions match (OFAC, UN, EU, UK) is an absolute prohibition; a PEP or adverse media match triggers enhanced due diligence rather than refusal. Lists change daily, so screening must repeat.

Anti-Money Laundering screening is one of the most fundamental compliance obligations for any business that moves money. Whether you are a bank onboarding a new account holder, a fintech issuing virtual cards, or a crypto exchange processing withdrawals, regulators expect you to know who you are doing business with and whether those individuals or entities appear on sanctions lists, are politically exposed persons, or have been flagged in adverse media.

Despite its importance, AML screening is often misunderstood. Teams conflate it with KYC, confuse sanctions screening with PEP screening, or treat it as a one-time checkbox rather than an ongoing obligation. This guide breaks down what AML screening actually involves, how the major watchlists work, and what to look for when building or buying a screening solution.

What Is AML Screening?

AML screening is the process of checking a person or entity against databases of known risks — sanctions lists, politically exposed persons registries, law enforcement watchlists, and adverse media sources — to determine whether doing business with them poses a financial crime risk.

It sits within the broader AML compliance framework alongside transaction monitoring, suspicious activity reporting, and customer due diligence. But screening is typically the first line of defense: it happens at onboarding and, for well-run programs, continuously throughout the customer relationship.

Regulators across jurisdictions mandate AML screening, though the specifics vary. In the United States, the Bank Secrecy Act and OFAC regulations require it. In the EU, the Anti-Money Laundering Directives (now in their sixth iteration) set the framework. The UK's Money Laundering Regulations and the Proceeds of Crime Act apply post-Brexit. Regardless of where you operate, the core requirement is the same: screen your customers and do not facilitate transactions with sanctioned parties.

Key Concepts: Sanctions, PEPs, and Adverse Media

AML screening typically covers three categories of risk, each with different implications for how you handle a match.

Sanctions Lists

Sanctions are legal restrictions imposed by governments or international bodies that prohibit transactions with specific individuals, entities, or entire countries. A sanctions match is not a risk signal to evaluate — it is a hard block. Doing business with a sanctioned party can result in severe penalties, including criminal prosecution.

Politically Exposed Persons (PEPs)

A PEP is someone who holds or has recently held a prominent public function — heads of state, senior government officials, judges, military leaders, and their close family members and associates. PEP status does not mean someone is corrupt. It means they occupy a position where corruption is more likely, and regulators expect you to apply enhanced due diligence accordingly.

Adverse Media

Adverse media screening (sometimes called negative news screening) checks whether a person or entity has been mentioned in connection with financial crime, fraud, corruption, terrorism financing, or other relevant offenses. This can surface risks that have not yet made it onto formal watchlists.

How AML Screening Works

At its core, AML screening is a matching problem. You take a customer's name and identifying details, then compare them against entries in one or more watchlist databases. The challenge is that this matching needs to be both precise enough to catch real threats and flexible enough to account for the messiness of real-world data.

Exact and Fuzzy Name Matching

Simple exact-match comparison will miss most real hits. Names are transliterated from different scripts (Arabic, Cyrillic, Chinese), abbreviated, misspelled, or recorded in different orders across cultures. Effective screening engines use fuzzy matching algorithms — phonetic matching, edit-distance calculations, and token-based comparisons — to catch variations while keeping false positive rates manageable.

Risk Scoring

Rather than returning a binary match/no-match result, modern screening systems assign a confidence score to each potential match. A score of 95% on an OFAC SDN entry demands immediate attention. A score of 60% on an adverse media mention from a low-reliability source might be deprioritized. Good screening solutions let you configure score thresholds and routing rules so your compliance team focuses on what matters.

Secondary Identifiers

Names alone produce too many false positives. Date of birth, nationality, national ID numbers, and addresses serve as secondary identifiers that help disambiguate matches. The more data points you collect at onboarding, the more accurately you can screen.

Sanctions Lists Explained

There is no single global sanctions list. Instead, multiple authorities maintain their own lists, and which ones you need to screen against depends on your jurisdiction, the currencies you handle, and where your customers are located.

OFAC SDN List (United States)

The Office of Foreign Assets Control maintains the Specially Designated Nationals and Blocked Persons List. This is arguably the most consequential sanctions list in the world because it applies to any transaction that touches the US financial system or involves US dollars — which means it effectively has global reach. The SDN list includes individuals, companies, and vessels. OFAC also maintains several other lists, including the Sectoral Sanctions Identifications List and the Non-SDN Menu-Based Sanctions List.

UN Consolidated List

The United Nations Security Council maintains a consolidated list of individuals and entities subject to sanctions under various UN resolutions. All UN member states are obligated to implement these sanctions, making this list a baseline for global compliance. It covers terrorism financing, nuclear proliferation, and targeted sanctions on specific regimes.

EU Consolidated Sanctions List

The European Union maintains its own sanctions regime, which incorporates UN sanctions and adds EU-specific designations. Since the EU can act independently of the UN Security Council, this list often includes additional entries, particularly related to human rights violations and regional conflicts. Post-2022, the EU sanctions landscape expanded significantly with Russia-related designations.

UK HMT Sanctions List

Since Brexit, the UK maintains its own sanctions list through His Majesty's Treasury. The Office of Financial Sanctions Implementation (OFSI) publishes and enforces the consolidated list. While it overlaps substantially with the EU list, there are divergences, and businesses operating in the UK need to screen against this list specifically.

Other Lists

Depending on your business, you may also need to screen against additional lists: INTERPOL wanted persons, FBI Most Wanted, national law enforcement databases, and industry-specific registries. Many screening providers aggregate hundreds of these sources into a single API call.

PEP Screening: Who Qualifies and Why It Matters

PEP screening is a distinct but related obligation. The Financial Action Task Force (FATF) defines PEPs broadly, and most jurisdictions have adopted some version of this definition.

The following categories typically qualify as PEPs:

When you identify a PEP, the requirement is not to reject them outright. It is to apply enhanced due diligence: understand the source of their wealth, monitor the relationship more closely, and obtain senior management approval for the account. The risk is that PEPs may use their position to launder proceeds of corruption, and your business could unwittingly become a conduit.

PEP status is not permanent. Most frameworks consider someone a PEP for a period after they leave office — typically one to five years, depending on the jurisdiction. Your screening solution needs to account for this decay period.

Common Challenges

False Positives

This is the single biggest operational challenge in AML screening. Common names generate enormous numbers of potential matches that compliance analysts must manually review and clear. A name like "Mohammed Ali" or "John Smith" can return dozens of hits across global watchlists. Without intelligent scoring and secondary identifier matching, your compliance team will spend most of its time dismissing irrelevant alerts.

Name Transliteration

Names originally written in non-Latin scripts — Arabic, Chinese, Cyrillic, Korean — can be transliterated into English in multiple valid ways. A single Arabic name might have four or five common romanizations. Screening engines need to handle this through phonetic algorithms and variant-aware matching, not just simple string comparison.

Data Quality and Coverage

Sanctions lists are updated frequently. OFAC can add new designations at any time, and the EU and UK publish regular updates. Your screening data needs to be current — screening against a list that is even a few days out of date can mean missing a newly designated entity. This is why relying on manually downloaded CSV files is impractical at scale.

Ongoing Monitoring Burden

AML regulations do not just require screening at onboarding. They require ongoing monitoring of your customer base against updated lists. If a current customer is added to a sanctions list, you need to know immediately. For businesses with large customer bases, rescreening on every list update creates a significant computational and operational burden.

Continuous Monitoring vs. One-Time Screening

The difference between one-time screening and continuous monitoring is one of the most important distinctions in AML compliance, and it is where many programs fall short.

One-time screening checks a customer against watchlists at the point of onboarding. It answers the question: "Is this person sanctioned right now?" But sanctions lists change constantly. Someone who was clean at onboarding could be designated next week.

Continuous monitoring automatically rescreens your entire customer base whenever underlying watchlists are updated. When a new name is added to the OFAC SDN list, every customer in your database is checked against that new entry. When a customer's risk profile changes — a PEP leaves office, an adverse media article is published — continuous monitoring surfaces it.

The regulatory expectation is clear: ongoing monitoring is required, not optional. The practical question is how to implement it efficiently. Batch rescreening on a schedule (daily or weekly) is the minimum. Event-driven screening — triggered by list updates in real time — is the standard for mature programs.

How to Choose an AML Screening Provider

If you are evaluating AML screening solutions, these are the factors that matter most:

  1. Data coverage — How many sanctions lists, PEP databases, and adverse media sources does the provider aggregate? Are they updated in real time or on a delay?
  2. Matching quality — Does the engine handle transliteration, partial matches, and name reordering? What is the false positive rate in practice, not just in marketing materials?
  3. Continuous monitoring — Can you set up ongoing screening with automatic alerts, or is it limited to one-time batch checks?
  4. Configurability — Can you adjust match thresholds, define risk-based rules, and whitelist cleared false positives so they do not resurface?
  5. Integration — Is there a clean API? Can screening be embedded into your onboarding flow without requiring customers to leave your product?
  6. Audit trail — Does the system log every screening decision, including who reviewed a match and what action was taken? Regulators will ask for this.
  7. Latency — Screening that takes seconds is fine for onboarding. Screening that takes minutes will break your user experience.

Platforms like Verifa integrate AML screening directly into identity verification workflows, so sanctions and PEP checks happen alongside document verification and biometric matching — without requiring separate vendor relationships or manual processes.

Conclusion

AML screening is not a feature you bolt on as an afterthought. It is a core compliance function that protects your business from regulatory penalties, reputational damage, and the operational headache of discovering sanctioned relationships after the fact.

The fundamentals are straightforward: screen customers against sanctions lists, PEP databases, and adverse media sources at onboarding and on an ongoing basis. The implementation details — matching algorithms, data freshness, false positive management, continuous monitoring — are where the complexity lives.

Getting this right means choosing tools that handle that complexity for you, so your compliance team can focus on genuine risk decisions rather than clearing thousands of false alerts.

Automate AML screening in your onboarding flow

Verifa runs sanctions, PEP, and watchlist checks alongside identity verification — one API, real-time results, continuous monitoring built in.

Start for Free