Table of Contents

Author

Former British Army officer, trained in surveillance and target acquisition, and Bain and Company engagement manager, with more than a decade of experience working in consulting, private equity and venture capital across Western Europe.

A customer may pass every onboarding check and present a different risk profile six months later. A sanctions designation, change in beneficial ownership, public appointment or credible report of misconduct can alter the assessment.

Screening and monitoring are useful operational labels, not uniform legal terms. Their scope, frequency and response depend on the jurisdiction, sanctions programme, regulated status, product and risk profile.

Screening and monitoring address different moments in that lifecycle. Screening establishes what the available evidence shows at a defined point in time. Monitoring looks for relevant changes and prompts a new assessment. Neither control should turn a database result into an automatic decision.

The controls may share data and workflows, but they do not create the same consequences.

What Is Screening?

Screening checks a person, company or transaction against selected sources at a particular moment. Organisations commonly screen before onboarding, approving a supplier, opening an account, completing a transaction or entering a relationship.

The scope should follow the decision and applicable rules. It may include beneficial owners, controllers, directors, authorised representatives and relevant counterparties. Good matching uses more than a name. Dates of birth, addresses, company numbers, identity documents, aliases and transliterations help resolve uncertain identities.

A clean result means the selected sources produced no confirmed issue at that time. It does not prove that every relevant record is available or that ownership has been established.

What Is Ongoing Monitoring?

Ongoing monitoring reassesses a relationship when relevant information changes. It may combine event-driven rescreening, scheduled reviews and updates to customer or counterparty data.

The process can detect a new designation, public appointment, adverse report or ownership change. It can also respond to a new address, jurisdiction, business activity or expected transaction profile.

Monitoring is not necessarily a constant real-time search across every source. The required frequency and speed depend on the relevant jurisdiction, restriction, product, relationship and risk. A defensible programme states which events trigger immediate review, which parties are checked on a schedule and why that design is proportionate.

Why Screening and Monitoring Must Remain Distinct

Monitoring often initiates another screening event. Combining the controls into one vague process makes it harder to assign responsibility, set response times and explain a decision.

The distinction also prevents three different risk domains from being treated as equivalent:

  • a confirmed sanctions exposure may create a legal prohibition or another mandatory action under the applicable regime;
  • PEP status is a risk factor that may require enhanced due diligence, but it is not evidence of wrongdoing;
  • adverse media is information that requires verification and context, not a formal designation.

These checks can sit within wider KYC compliance and customer due diligence, with separate rules for evidence, escalation and action.

Sanctions Screening and Monitoring

Initial sanctions screening should start by identifying which regimes apply. That assessment may depend on where the organisation and parties are established, the currencies and payment channels involved, the location of activity, and the goods, services or technology in scope.

Relevant names should then be checked against current data from official sanctions lists. A name-only search is not enough. An unlisted company may still be restricted through ownership or control by a designated person. Sectoral, geographic and activity-based measures can also apply without a listed-name match. Where a result needs context, sanctions screening services can test identifiers, ownership and control.

A possible match is an alert. Analysts should compare available identifiers, resolve aliases and examine ownership before deciding whether it concerns the same person or entity. If the result is confirmed, the required response depends on the specific rule. It may involve freezing or blocking assets, rejecting or pausing activity, seeking a licence, making a report or proceeding under an applicable authorisation.

A sanctions report and an AML suspicious-activity report have different triggers, recipients and deadlines; one does not automatically replace or trigger the other.

Ongoing monitoring should respond to changes in official measures and the relationship. A list update may require prompt rescreening. A new owner, controller, intermediary, destination or payment route may require wider review even if the customer name is unchanged. Sanctions controls can connect with AML compliance and investigations without becoming the same legal regime.

PEP Screening and Monitoring

PEP screening seeks to establish whether an individual is or has been entrusted with a prominent public function. Depending on the applicable framework, measures may also extend to defined family members and known close associates.

At onboarding, the organisation should verify identity, role, institution and term dates. A commercial PEP database can accelerate the search, but there is no complete universal list. Public records, official appointments and reliable reporting may be needed to confirm whether the role meets the relevant definition.

A PEP match does not require automatic rejection. It should trigger the assessment and measures required by the applicable rules. These may include senior approval, establishing source of wealth and source of funds, and enhanced monitoring. The intensity of enhanced measures should reflect the person’s actual authority, jurisdiction, product exposure, ownership links and expected activity.

PEP monitoring captures later appointments and changes in connected parties or authority. Former PEP treatment also varies by jurisdiction and residual risk; no single global period applies. The file should show why enhanced measures were retained, reduced or ended.

Adverse Media Screening and Monitoring

Adverse media screening searches for credible public reporting that may affect the initial assessment. Relevant subjects can include fraud, corruption, money laundering, sanctions evasion, organised crime, serious misconduct or regulatory action. The categories should reflect the organisation’s risk model; the objective is not an unrestricted search for negative commentary.

Every result requires context. Analysts should confirm identity, assess the source and date, and seek independent corroboration. They should distinguish an allegation from an investigation, charge, conviction, regulatory finding or sanction. Repetition across copied articles is not independent confirmation.

Monitoring can identify later reporting, retractions, acquittals or findings that change the assessment underlying an earlier alert. A source-led adverse media screening process helps separate credible signals from duplicated, outdated or misattributed reporting.

What Should Trigger a New Review?

Useful triggers fall into three groups.

External changes include sanctions-list amendments, new public appointments, court decisions, regulatory actions and credible adverse reporting.

Relationship changes include new owners, directors or representatives; a change of jurisdiction or activity; and new products, counterparties or payment routes.

Behavioural changes include activity inconsistent with the stated purpose of the relationship, unexplained transactions or exposure to higher-risk locations. These signals usually belong to transaction monitoring or fraud controls, but they can trigger renewed sanctions, PEP or adverse media screening.

Define which triggers require immediate escalation and which enter a scheduled review. Record the source, timestamp and data state that produced the alert.

How to Set a Monitoring Cadence

There is no single schedule for every organisation or risk type. Cadence should begin with applicable legal duties, then account for the speed at which a change could create exposure.

Sanctions updates may require prompt action, while PEP and adverse media sources have different publication cycles and reliability. Higher-risk relationships may justify more frequent PEP and adverse-media reviews. Where applicable rules permit, lower-risk cases may follow a lighter scheduled review, while sanctions-list and material-change triggers remain active.

Technology can shorten the delay between a source update and an alert, but speed alone does not prove effectiveness. Excessive sensitivity produces alert fatigue; thresholds that are too narrow create false negatives. Document the cadence, test detection and revisit the design when exposure changes.

Monitor the Risk Graph, Not Only the Customer Name

This is where many monitoring programmes lose visibility. They repeatedly check the name of the contracted entity while the real exposure moves through its relationships.

A useful monitoring scope maps the nodes that can change the decision:

  • the direct customer, supplier or investment target;
  • ultimate beneficial owners and people with significant control;
  • directors, authorised representatives and relevant intermediaries;
  • parent companies, subsidiaries and material affiliates;
  • PEP family members and known close associates where the applicable rules require it;
  • payees, key suppliers or financing parties whose involvement creates indirect exposure.

The map should record why each relationship matters and which changes require rescreening. A clean name result may become irrelevant if a designated person gains control, a new intermediary enters the payment chain or an affiliate faces a credible investigation.

This does not mean monitoring everyone connected to a company. It means defining relationships capable of changing the conclusion. Third-party due diligence can establish those connections before monitoring rules are set.

Common Screening and Monitoring Failures

Several weaknesses recur across programmes:

  • Treating onboarding as final. The initial result becomes stale when lists, roles, ownership or reporting change.
  • Using one cadence for every risk. Uniform schedules ignore different legal duties, source-update cycles and exposure levels.
  • Screening poor data. Missing identifiers and outdated ownership records increase both false positives and false negatives.
  • Relying on names alone. Aliases, transliterations, common names and indirect ownership require additional identifiers and relationship analysis.
  • Closing alerts mechanically. A system detects a possible change; it does not determine identity, credibility or the required action.
  • Keeping permanent false-positive exclusions. Suppression rules can become unsafe after data changes.
  • Ignoring source limitations. PEP databases can be incomplete, adverse media can be wrong, and sanctions lists do not contain every restricted activity or indirectly affected entity.
  • Losing the decision trail. Retain the evidence, rationale, reviewer and action in line with applicable recordkeeping and data-protection rules.

Building a Defensible Control Framework

Start by defining the parties, regimes and decisions in scope. Collect sufficient identifiers and map relevant ownership and control. Select authoritative list data and reliable public or licensed sources, then set matching rules appropriate to the languages and jurisdictions involved.

Establish separate workflows for sanctions, PEP and adverse media alerts. Specify the reviewer, required evidence, escalation point and available actions. Connect them to wider regulatory compliance risk management, while preserving each legal test.

Record the source version, inputs, review time, identifiers, ownership analysis, decision and approval. Test the controls through quality reviews, scenarios and samples of closed alerts. Examine false-positive and false-negative patterns, data freshness, source coverage and response time.

Automation can compare large datasets and identify changes quickly. Analysts must still verify identity, evaluate evidence and explain the conclusion. The purpose of technology is to direct attention, not replace judgment.

Conclusion

Screening establishes a documented view of risk at a defined moment. Monitoring identifies changes that may make that view obsolete. Effective programmes commonly combine both, but the required controls depend on applicable law and risk. Sanctions, PEP and adverse media should not be collapsed into one undifferentiated alert queue.

A defensible control is traceable from source to decision. It shows who was checked, what changed, how the alert was resolved and why the organisation acted. If ownership, political exposure or reputational evidence remains unclear, contact Molfar Intelligence.

Turn Intelligence Into Action
Order a service
Order a service
Black Plus Icon

Recent posts

View all
View all
White Plus Icon
View all
View all
White Plus Icon

Related posts

View all
View all
White Plus Icon
View all
View all
White Plus Icon
Gain the Clarity You Need to Move with Confidence

Let’s connect to explore how tailored intelligence can strengthen your decisions, reveal opportunities, and minimise uncertainty.