Sanctions screening software checks the parties to a case against a restriction list
Sanctions screening software checks the people and organisations involved in a case against government and international restriction lists, before anybody commits to them. It matches a name, usually with a date of birth, nationality, address or registration number, against sanctions designations, politically exposed person data and adverse media, then returns either a clear result or possible matches to resolve.
The obligation behind it is unusually hard-edged. Most compliance controls are risk-based, so a defensible judgement is an acceptable answer. Sanctions are not. Dealing with a designated party is prohibited outright in most jurisdictions, regardless of intent. That is why screening is a discrete control rather than one more factor somebody weighs.
The exposure is far wider than banking. A lender screens applicants, guarantors and beneficial owners. An insurer screens the claimant and the repairer being paid. A freight forwarder screens the shipper, the consignee and the vessel. A procurement team screens a new supplier and the bank account it wants paid into. Same check, different paperwork, and in all of them it sits in front of a decision somebody is about to make. We build Floowed, the decision platform, so we will be plain about where we sit and where we do not.
Three datasets, three different obligations
One word covers three datasets carrying three different legal weights. Conflating them produces over-rejection and under-protection at the same time.
Sanctions lists. Designations published by governments and international bodies: the OFAC Specially Designated Nationals list, the UN Security Council Consolidated List, the EU consolidated list, the UK OFSI list, and national lists elsewhere. A confirmed match is a prohibition, with no risk tier to assign. The lists change constantly, and a change takes effect on publication, not on the day your provider syncs it.
Politically exposed person data. A PEP holds or has held a prominent public function, along with their family members and close associates. PEP status is a risk indicator, not a prohibition and not an accusation. Regulators expect enhanced due diligence, and blanket refusal of all PEPs is itself a supervisory concern because it drives exclusion. Our guide to PEP screening works through the categories and the hit handling.
Adverse media. Unstructured reporting linking a party to financial crime, corruption or enforcement action. No list and no designation, only text, which makes it the noisiest of the three and the most dependent on resolving the right person from a common name. It is also where risk often surfaces first, before anything reaches a formal register.
Then there is scope. The named party is rarely the whole exposure. Beneficial owners sit behind a corporate applicant, directors can be designated while the entity is not, and counterparties, vessels and addresses carry designations of their own. OFAC's 50 percent rule blocks an entity majority-owned by blocked persons even when it appears on no list. A clean check on the name at the top of the form can still be a match once you screen what sits behind it.
Why the matching is the hard part
Running a name against a list is trivial. Deciding whether two names are the same person is not, and that is where the cost of the control lives.
Names transliterate several defensible ways from Arabic, Cyrillic, Chinese and Thai. Name order varies by culture and gets reversed on entry. Corporate names carry suffixes and trading names that never match exactly. Dates of birth are missing or partial. So engines use fuzzy matching, with a threshold deciding how close is close enough. Tighten it and a real designation slips through on a spelling variant. Loosen it and the alert volume becomes unworkable.
False positives dominate list screening everywhere. The overwhelming majority of alerts are not the person on the list. Where a small number of surnames are shared by millions of people, the ratio is worse. That number should shape the purchase. Screening is cheap. Clearing what it returns is expensive, and the real question is what it costs in hours and delay to clear the ones it gets wrong.
What sanctions screening software cannot do
This matters more than the feature grid, because every gap below has been bought over by somebody who assumed one control covered another.
It does not verify identity. Screening compares the name you were given against the list. It has no view on whether the person is who they claim to be. Registry checks on a national ID, face matching and liveness are separate controls from different vendors. A fabricated identity carrying no designation screens perfectly clean, which is the point of using one. Screening and identity verification fail independently.
A clear result is a moment, not a state. Designations are added continuously. A party screened clean at onboarding can be designated the following week, and nothing about the original result changes to tell you. A programme that screens once protects the day the case arrived and no day since.
It cannot see ownership hidden from it. The 50 percent rule only bites where you can establish the ownership. Nominee shareholders, layered structures and thin registry disclosure defeat it, and no engine resolves what the corporate record does not show.
It does not decide anything. This is the gap that matters most and gets discussed least. A hit is not an answer. Somebody still has to determine what a possible match on a former municipal official means for this case, at this value, in this jurisdiction. Screening returns evidence. The decision is a separate layer, and in most organisations it is undocumented.
Our own boundary, stated plainly: we do not maintain, license or sell sanctions, PEP or adverse media data. We do not monitor transactions. We do not verify government identity documents or run biometric checks.
AML screening software: the wider category this sits inside
"AML screening software" is often typed as a synonym for sanctions screening, and it is broader. Anti-money laundering compliance is four controls, running at different moments, catching different things, usually owned by different teams. List screening is one of them.
| Control | Question it answers | When it runs | Representative vendors |
|---|---|---|---|
| Due diligence and identity | Is this party real, and who is behind it? | At onboarding | Sumsub, Onfido, Jumio, Persona, Alloy, Socure |
| Sanctions, PEP and adverse media screening | Is this party restricted, exposed, or reported? | At onboarding, then continuously | LSEG World-Check, Dow Jones Risk and Compliance, Moody's, LexisNexis Risk Solutions, ComplyAdvantage, Napier AI, Fenergo |
| Transaction monitoring | Does the money movement look like laundering? | Continuously, after an account exists | NICE Actimize, Feedzai, Featurespace, Unit21, Hawk |
| Case management and reporting | Can we evidence and file what we found? | On alert and on filing | NICE Actimize, Napier AI, Unit21, in-house systems |
These are complements, not substitutes. Transaction monitoring never sees an application, so it cannot tell you the guarantor was designated. Identity verification confirms the person exists, not that dealing with them is permitted. The same shape shows up in fraud detection software for banks, where three separate surfaces get bought as though they were one.
The same list check, in six vocabularies
Restriction lists are indifferent to industry. What changes is which party carries the exposure and which document names them.
Lending and credit. Applicants, co-borrowers, guarantors, directors and beneficial owners, screened at application and again before disbursement on facilities that draw down months later.
Insurance. The policyholder at underwriting, then the claimant, the beneficiary and the repairer being paid at claim. Payment is where a designation actually bites, and it is the point most often screened least.
Shipping, freight and trade. The densest sanctions surface outside banking. Shippers, consignees, notify parties, charterers, vessel owners, and the vessels themselves, which carry designations in their own right. Ownership moves between voyages and flags change, so the counterparty has to be permissible on the day the cargo moves, not the day the contract was signed.
Banking and fintech onboarding. Corporate customers, their ultimate beneficial owners, board members and source-of-funds counterparties. Non-credit decisions, the same three datasets.
HR and workforce. Senior hires and contractors in regulated functions, where a designation or a disqualification bars the appointment outright and the check has to be evidenced rather than remembered.
Procurement and supply chain. New suppliers, their owners, and the bank details they submit. A supplier onboarded without a screen is an unrestricted payment channel, and it is the control most often skipped because procurement rarely reports to compliance.
Be exact about what that list is. It is capability, not a customer list. The check runs on a consignee the way it runs on a guarantor, because a name matched against a list does not know what industry it is in. Our production deployments are in lending, and our numbers are lending numbers.
Screening beside the decision is where it breaks
Almost every screening programme we meet has the same architecture and the same failure. The check runs in the provider's portal. Somebody opens it, pastes a name, reads the result and passes it back by email or a spreadsheet, while the case waits in the operational system on a result nobody can see from there.
Cases stall, not because screening is slow, since most checks return in seconds, but because the handoff is manual. Treatment varies by whoever opened the portal that day, because the policy governing what a hit means is a document rather than an executed rule. Evidence fragments across a portal, an operational system and a shared drive, so the full picture for an examiner has to be reconstructed by hand. And re-screening becomes a project somebody schedules rather than a process that runs, which is how a designation added in March gets noticed in November.
Screening as a variable in the decision, not a tool somebody opens
The fix is architectural rather than a better portal. The screening result belongs inside the decision, as a data point the rules read, alongside everything else the case contains.
That is how Floowed handles it. A case arrives by whichever of three routes it takes, and all three feed the same decision: from your own systems over the API and the integrations, from external sources such as bureaus, registries and KYC providers, or from documents, including the scanned, photographed and handwritten files other platforms cannot read. Screening runs as an agent inside that flow, on every case, calling the provider our customer already holds access to. We orchestrate the call and read the result. We maintain no lists and have no opinion on what the data says.
What comes back lands as first-class variables in the Decision Engine: whether there was a match, which dataset it came from, the match strength, the category and the jurisdiction. The customer's own rules act on it from there. A confirmed sanctions designation is a hard gate that blocks automated approval regardless of how strongly the rest of the case scores. A weaker PEP indication can route the case to manual review with the reason attached and any override logged. A clear result lets the case continue with nobody touching it. Outcomes are explicit and named: recommended to approve, manual review, or reject.
Two properties follow. The screen happens on every case, because it is a step in the flow rather than something an operator remembers to open. And the result is part of the decision record: which rule fired, on which version of the policy, on what evidence, retrievable years later.
On consistency we will be precise, because this is where the category over-promises. Reading a document is machine learning, so we will not claim the pipeline end to end returns identical output on every run. The determinism claim belongs to the rules. Given the same inputs, the Decision Engine produces the same outcome every time, and it shows you the inputs it used and the version of the rules that ran. See also what a credit decisioning platform is and turning risk appetite into decision rules.
How to choose sanctions screening software
1. Which lists, refreshed how often, and who is screened? Establish which sources are covered and the lag between a designation being published and it being screenable in your environment, because lag never appears on the feature grid. Then map your real exposure: beneficial owners, directors, guarantors, counterparties, vessels, addresses, bank accounts.
2. Test the matching on your own names. Run a real sample from your own book, including transliterated names, common surnames, missing dates of birth and entities with trading names. Measure alert rate and resolution time, not the demo.
3. What happens after the hit? This is the question that separates a control from a report. Ask precisely how the result changes the outcome, automatically, under rules your team wrote in advance. A signal that lands in a queue degrades under volume: the queue grows, alerts get cleared faster than they can be read, and the control quietly stops controlling.
4. Is re-screening a process or a project? Continuous or event-driven re-screening against list updates, with the same rules applied to what comes back, is the difference between a live control and an annual exercise. If it needs somebody to export a list and upload it somewhere, it will slip.
5. What does the audit trail look like? An examiner will ask why a specific case proceeded. You need one record showing the screening result, which rule evaluated it, the version of that policy, the evidence and the outcome, without reconstruction from three systems and an inbox.
Where Floowed fits, and where it does not
We are the answer when screening sits outside the decision it is supposed to govern. We put the screen inside the flow, land the finding as a variable, and let the rules your team wrote act on it identically on every case. Same rules. Every case. Every time. No exceptions.
Where we are not the answer: we are not a sanctions or PEP data provider, we are not an AML platform and we do not monitor transactions or file reports, we do not verify government identity documents, and we are not the system of record for the process we sit in front of. Your system of record stays yours, and we integrate in both directions. The bound is deliberately narrow: anywhere a complex operational process reads a case and decides something. A workflow with no judgement in it does not need us.
On proof, the honest position. Every customer we have came off a manual process rather than off a competing platform, and our deepest experience is in lending because that is where we have been longest. The one customer number we can put behind a fraud or compliance claim is from Alon Capital, where the platform caught three times more statement fraud than the prior manual review in the first 90 days. That is a document fraud figure, at a named lender, in lending. It is not a screening number, and we will not stretch it into one.
FAQ
What is sanctions screening software? Software that checks the parties to a case against government and international restriction lists before an organisation deals with them, matching names and identifiers against sanctions designations, politically exposed person data and adverse media, and returning a clear result or possible matches to resolve.
Is sanctions screening the same as AML screening software? No. List screening is one control inside anti-money laundering compliance, alongside due diligence and identity, transaction monitoring, and case management and reporting. "AML screening software" is often used loosely for list screening specifically, so establish which of the four a vendor covers before comparing.
What is the difference between sanctions screening and PEP screening? A sanctions designation is a prohibition: dealing with the party is not permitted. PEP status is a risk indicator requiring enhanced due diligence, not a bar. They usually run in the same pass against a combined dataset, and they must be treated differently once a match is confirmed.
Does sanctions screening only apply to banks? No. The obligation applies to anybody dealing with a designated party. Insurers screen claimants and payees, freight and trade operators screen counterparties and vessels, procurement screens suppliers and their bank details, HR screens senior hires in regulated roles. The check is the same, the exposed party differs.
Does Floowed provide the sanctions lists? No. We do not maintain, license or sell sanctions, PEP or adverse media data, and we do not rank or weight what it says. The call goes to the provider our customer already holds access to, the result lands as a variable in the decision, and the customer's own rules decide what it means.
The bottom line
Sanctions screening is a narrow control with an unforgiving obligation attached. Match the parties to a case against lists that change daily, cover the network behind the name and not only the name, and accept that most of what comes back is noise you still have to clear.
The software is only half the purchase. The other half is what happens to the result, and that half is usually undocumented: a hit in a portal, a judgement made under time pressure, and a trail nobody can reassemble a year later. A screen that does not change the outcome by itself, under rules somebody wrote down in advance, is not a control. It is a report with a compliance budget attached.
Start free or book a demo and run a real case through it, screening included.