Ongoing PEP & Sanctions Screening for Business Customers: Full Guide

On this page
Onboarding a business customer is a snapshot. The entity you approve today can appear on a sanctions list tomorrow, restructure ownership next quarter, or install a politically exposed person as a director next year. Point-in-time screening at onboarding is therefore a starting condition, not a control. The best way to screen business customers for PEP and sanctions on an ongoing basis requires a continuous program: structured cadences, documented matching logic, disciplined hit handling, and an audit trail that regulators can inspect at any time.
This playbook covers the operational design of that program. It goes beyond defining terms and explains exactly how to build and run ongoing sanctions and PEP screening for business customers, from watchlist coverage through EDD triggers to reportable outcomes.
Why ongoing PEP and sanctions screening must be continuous
The distinction between onboarding screening and ongoing monitoring is not semantic. Onboarding establishes a baseline risk profile at a fixed point in time. Ongoing monitoring is what keeps that profile accurate as facts change.
Ownership structures change. Legal representatives are replaced. Businesses relocate to higher-risk jurisdictions. A customer's UBO may be appointed to a government role, creating a PEP exposure you never anticipated. A counterparty entity you cleared at onboarding may be designated under a new EU or OFAC sanctions package tomorrow. None of these changes are visible without a live monitoring program.
Operationally, "ongoing" has three components: (1) regular periodic re-screening against updated lists on a defined schedule, (2) event-triggered re-screening whenever material changes occur (new UBO, director change, ownership restructure, geographic expansion), and (3) transaction or behavioral triggers that prompt a contextual recheck outside the periodic cycle.
The Netherlands provides a clear regulatory frame for this. According to Business.gov.nl guidance on the Dutch Sanctions Act, financial and investment firms are obligated to check customers against sanctions registers and to act when a client is listed, which can include freezing funds or stopping services depending on the applicable regime. The AFM, which supervises investment firms, explicitly frames regulated entities as "gatekeepers" responsible for continuous sanctions screening alongside their broader Wwft (Anti-Money Laundering and Counter-Terrorist Financing Act) obligations. DNB performs the equivalent supervisory function for other financial institutions. Neither authority treats onboarding as sufficient. The expectation is a documented, repeatable control that operates throughout the customer lifecycle.
This expectation is consistent across EU member states and most FATF-aligned jurisdictions. The principle: if your screening program does not detect a designation that occurred after onboarding, you have a control failure, not a gap in information.
Scope: what you must screen for business customers
Business KYB screening against sanctions lists covers substantially more surface area than individual KYC screening. The required screening targets for a legal entity customer include:
The registered legal entity name and all known trading names or aliases
Ultimate Beneficial Owners (UBOs) above your ownership threshold (typically 25%, though risk-based policy may set a lower bar)
Legal representatives: directors, authorized signatories, and managing officers
Associated entities in complex structures (holding companies, subsidiaries with shared directors)
The entity's registered jurisdiction and any operating jurisdictions flagged in the profile
PEP screening and sanctions screening carry different obligations, and conflating them creates operational mistakes.
A sanctions match is typically a binary compliance obligation: a designated entity cannot receive funds or services, and the relationship must be blocked or terminated depending on the applicable regime. Reporting to the relevant authority is mandatory. There is no discretion on whether to continue the relationship.
A PEP hit is a risk signal, not a block. PEPs are not prohibited customers. They present elevated corruption risk and trigger a requirement for enhanced due diligence and, in most cases, senior management approval to onboard or continue. The specific EDD obligations are risk-based and must be documented.
False positives are structurally unavoidable in both categories. Name-only matching against any major consolidated list will produce large volumes of non-matches that share surface-level name similarity with a listed entity. The hit triage function is not an administrative afterthought. It is a designed component of the control. If your program does not have a documented false positive management process, it is incomplete.
Control design: the minimum viable workflow for ongoing screening
A compliant ongoing screening program has seven sequential steps. Every step must be documented and repeatable.
Step 1: Identity data quality and enrichment. Screen against clean, normalized input. This means validating legal entity names, resolving aliases, and confirming UBO data is current before each screening run. Poor input quality is the single largest driver of both false positives and false negatives.
Step 2: Sanctions and PEP list screening. Run the normalized entity data (including UBO and representative names) against all applicable lists. Coverage must include EU consolidated lists, UN lists, OFAC SDN, and any jurisdiction-specific national lists relevant to your customer base. Missing a list is a coverage gap, and coverage gaps constitute residual risk.
Step 3: Hit triage. Every alert is reviewed against documented triage criteria. The analyst classifies the hit as: (a) confirmed clear/no match, (b) potential match requiring further investigation, or (c) confirmed match. Each classification requires documented rationale.
Step 4: Enhanced due diligence. Potential matches, PEP proximity flags, and adverse media relevance triggers initiate EDD. EDD scope is risk-proportionate: source of funds, ownership structure depth, third-party business registry checks, and senior management notification where required.
Step 5: Disposition decisioning. The case reaches a documented decision: clear, resolve as false positive, continue with enhanced monitoring, block/terminate, report to authority. Decisions with material risk implications require four-eyes review and independent sign-off.
Step 6: Ongoing monitoring triggers. The disposition feeds back into the monitoring schedule. A case resolved as false positive should be suppressed for future identical alerts (with rationale stored). A case resulting in heightened risk scores should increase screening frequency.
Step 7: Records and audit trail. Every action in steps 1 through 6 is logged with timestamps, input data snapshots, list version and date, analyst identity, decision outcome, and any escalation events.
A simple disposition decision tree:
Alert generated → Is it a name-only coincidence with no corroborating identifiers? → Clear, document rationale
Partial match with corroborating identifiers → Investigate → False positive? → Resolve with documented reasoning → True match? → Determine sanction vs. PEP type
Sanctions match → Block/freeze → Report to AFM (investment firms) or DNB (other financial institutions) within required timeframe
PEP match → Trigger EDD → Senior management approval → Continue with enhanced monitoring or decline
Escalation path for disagreement: record dissenting rationale, escalate to MLRO or equivalent
The automated case management infrastructure underpinning this workflow is as important as the workflow design itself. Without it, consistency breaks down and audit trails become fragmented.
Data and watchlists: how to manage list coverage and update cadence
Watchlist coverage is not a static procurement decision. Lists change constantly, as SmartSearch's sanctions compliance resource notes: multi-jurisdiction list changes and the complexity they create are among the most persistent operational challenges in ongoing screening.
Minimum list coverage for EU-headquartered firms serving business customers includes the EU Consolidated Sanctions List, UN Security Council Consolidated List, OFAC SDN and CAPTA lists, HM Treasury Financial Sanctions Targets list, and any national lists relevant to your customer jurisdictions (for the Netherlands, this includes the Dutch national sanctions register maintained under the Sanctiewet 1977).
In addition to consolidated lists, your program should ingest sector-specific lists (e.g., BIS Entity List for technology companies) and adverse media signals as a supplementary risk layer.
Watchlist update cadence. EU sanctions lists update irregularly but frequently, sometimes multiple times per week following geopolitical events. At minimum, your list data should refresh daily. After any material geopolitical event or published EU Council Regulation amending the sanctions regime, an unscheduled re-screen of your entire business customer portfolio is appropriate.
Periodic re-screen schedule. For standard-risk business customers, quarterly full portfolio rescreens are a defensible baseline. For elevated-risk customers (those with PEP connections, operations in higher-risk jurisdictions, or prior hit history), monthly or continuous daily monitoring is the appropriate control.
Data normalization. Before screening, normalize entity names by removing legal form suffixes (B.V., GmbH, S.r.l., LLC) and their common abbreviations. Apply transliteration rules to names entered in non-Latin scripts. Standardize address components and jurisdiction identifiers. Unormalized input is the root cause of most avoidable false positives. Platforms with deep localization across 210+ local registries handle this normalization structurally rather than relying on analyst judgment each time.
Matching logic: how to reduce false positives without missing real matches
Name-only matching is insufficient for business entity screening and produces false positive rates that make the program operationally unmanageable. Industry data from McKinsey suggests 90 to 95% false positive rates are common in screening and transaction monitoring programs. That rate is only acceptable if your triage process can handle the volume. A well-designed matching engine targets below 30%.
Effective matching logic for business entities uses multiple corroborating dimensions:
Entity name (with fuzzy matching tolerance calibrated by risk level)
Known aliases and former names
Registration number or tax identifier where available on the list
Registered address and jurisdiction
UBO identifiers (names, dates of birth, nationalities)
Legal representative names and identifiers
Matching confidence scoring should assign weight to each dimension. A name match alone at 85% fuzzy similarity is insufficient to flag a hit. A name match plus jurisdiction match plus a shared UBO identifier is a high-confidence potential match requiring escalation regardless of the fuzzy score on the name.
Document your scoring rationale. If a regulator asks why a specific alert was resolved as a false positive, the answer cannot be "the analyst used their judgment." It must be: "the matching criteria were X, Y, and Z; the entity in question differed on criteria Y and Z; the case was reviewed by [name] and approved by [four-eyes reviewer] on [date]."
Calibrate thresholds periodically using adjudicated outcomes. If your historical false positive rate on a specific list is above 40% at your current confidence threshold, you have grounds to tighten the threshold for that list. If you are clearing potential matches that later turn out to be true matches (false negatives), you need to loosen it. This is a control effectiveness question, not just an efficiency one.
The guide to reducing false positives in KYB covers the technical mechanics of this calibration process in depth, including how to store analyst decisions to suppress repeat false positives on future screening cycles.
Hit handling and escalation: from triage to EDD to disposition
The PEP hit triage SOP is where most compliance programs lack sufficient documentation. Here is the minimum viable structure.
Classification. On receiving a hit, the analyst first determines: is this the same legal entity or person as the listed subject? Apply the multi-factor matching criteria described above. If two or more corroborating identifiers match, treat as a potential match and proceed to investigation.
Evidence collection for potential matches. Collect: the listed entity's full profile from the relevant list (including listing date, citing regulation, and any listed identifiers), the customer's verified profile from your own records and any registry data, and any adverse media results relevant to the hit. Document each source.
EDD triggers. Enhanced due diligence is required when any of the following apply:
PEP designation confirmed for a UBO, director, or representative (first or second degree)
Sanctions "related to" or "associated with" indicator present on the list entry
Adverse media results are relevant and credible
Customer's declared information conflicts with registry data or list data
The customer operates in a jurisdiction under heightened FATF monitoring or an active EU sanctions regime
For PEP-related EDD, the scope typically includes verified source of funds and wealth, updated beneficial ownership mapping, and senior management approval. The four-eyes review requirement for sanctions and elevated PEP cases is standard practice and should be specified in your screening policy.
Escalation and disagreement handling. When analysts disagree on a disposition, both positions must be documented. The MLRO (or equivalent) makes the final determination, and their reasoning is recorded. Suppressing dissenting views in the case file is a documentation failure that creates significant audit risk.
The policy engine layer matters here. Translating these escalation rules into code-enforced workflow ensures they are applied consistently, not only when the most experienced analyst happens to be reviewing a case.
Auditability and reporting: what regulators expect you to prove
Regulators do not assess compliance programs based on your intentions. They assess them based on what you can demonstrate. The audit trail for each screening decision must contain, at minimum:
A snapshot of the input data used for the screening run (entity name, UBO names, identifiers, as of the screening date)
The list version and date used at the time of screening
The match rationale: which criteria triggered the alert and at what confidence level
The analyst's triage notes, including the evidence reviewed
The disposition outcome and the name of the approving reviewer
The timestamp of each action in the workflow
For escalated cases: the full escalation log including any dissenting views
For Dutch-regulated firms, the reporting obligations are specific. Business.gov.nl guidance identifies AFM as the relevant notification channel for investment firms and DNB for other financial institutions when a sanctions match is confirmed. Notification timelines are governed by the applicable sanction regime and should be codified in your response procedure, not left to ad hoc judgment.
Testing your controls. Audit readiness is not the same as running the program. You must also test it. Recommended testing cadence:
Quarterly QA sampling of analyst decisions (minimum 5% of resolved cases reviewed by an independent reviewer)
Bi-annual false positive/false negative rate analysis across each list you cover
Annual full control effectiveness review against your documented screening policy
Immediate review after any regulatory update to the relevant AML or sanctions frameworks
The lifecycle compliance capabilities required to operationalize these testing cadences, including policy versioning and periodic review automation, are a distinguishing feature between platforms that support compliance programs and those that only support onboarding.
Technology evaluation checklist for ongoing screening
If you are evaluating platforms or vendors to support this program, the following questions establish minimum viable capability. Treat any vendor that cannot answer them with specific, evidenced responses as a procurement risk.
Functional requirements:
Does the platform support continuous (daily or real-time) screening in addition to batch runs?
Can matching thresholds be configured per list or per customer risk tier, with documented rationale for each configuration?
Does the platform maintain versioned watchlist history so you can prove which list version was used for any past screening event?
Does the platform support multi-factor matching (name plus identifiers plus jurisdiction plus UBO attributes) rather than name-only matching?
Is there a built-in case management workflow with four-eyes review enforcement, analyst notes, and exportable decision records?
Can the platform generate audit-ready case exports that include input data snapshots, list version, match rationale, and disposition chain?
Technical requirements:
What is the data refresh SLA for each watchlist? Can the platform trigger an unscheduled portfolio rescreen after a major list update?
What is the throughput and latency for screening a portfolio of 50,000+ business entities?
How does the platform handle deduplication of alerts across multiple screening runs?
What is the API model for integrating screening triggers from your CRM or KYB system?
Procurement red flags:
A vendor claims a specific false positive rate but cannot provide methodology or reference deployments. Ask for evidence.
The platform provides list screening but no case management or workflow tooling. That splits your audit trail across systems.
Configuration requires vendor professional services for every rule change. Ongoing screening programs require fast iteration as regulations change.
No watchlist versioning means you cannot prove which list you screened against at any point in time. That is an audit liability, not a product feature gap.
Duna's platform addresses all of these requirements through its integrated data platform for KYC data orchestration, configurable policy engine, automated case management, and lifecycle compliance workflows for daily screening and periodic reviews. The operational outcomes reported by Duna customers, including 4.8x analyst efficiency gains, reflect what becomes possible when screening, triage, and case management are unified rather than stitched together across point solutions.
FAQ: common questions on ongoing PEP and sanctions screening
How often should we re-screen business customers? At minimum, run full portfolio re-screens quarterly for standard-risk customers. Run daily monitoring for elevated-risk customers and any customer with a prior alert or PEP connection. Always run an unscheduled rescreen after a material list update affecting relevant jurisdictions.
Should we screen only at onboarding or also on ownership changes? Ownership changes are a mandatory re-screening trigger. Any change in UBO, director, or legal representative should initiate a new screening run for the new individuals. Changes in the entity's registered jurisdiction or operating profile may also trigger a full profile reassessment.
What's the difference between a sanctions match and a PEP hit? A confirmed sanctions match requires immediate action: block the transaction or relationship, and report to the relevant supervisory authority (AFM or DNB in the Netherlands). A PEP hit is a risk-based trigger for enhanced due diligence and senior management approval. The relationship may continue, but only with documented EDD completed and approval recorded.
How do we handle false positives operationally? Document the triage rationale with full evidence: which identifiers matched, which did not, and why the analyst concluded no true match exists. Store the decision in the case record with reviewer sign-off. Use the resolved false positive to suppress the same alert on future screening cycles for that entity-list pair, while preserving the original record for audit purposes.
What evidence should we store to defend decisions? Keep the input data snapshot (as of the screening date), the list version used, the matching criteria and confidence output, analyst triage notes with sources cited, the disposition outcome, the approving reviewer's identity, and the timestamp chain. For escalated or reported cases, retain all communication with supervisory authorities. Minimum retention periods vary by jurisdiction, but five years from the end of the relationship is the standard EU baseline under Wwft.
The reboarding and ongoing monitoring challenge is not primarily a technology problem. It is a program design problem. Technology makes the program scalable and auditable. The design decisions, screening cadence, matching logic, hit handling SOPs, escalation rules, and record-keeping structure, are what determine whether you have a defensible control or a compliance process in name only.
Onboarding a business customer is a snapshot. The entity you approve today can appear on a sanctions list tomorrow, restructure ownership next quarter, or install a politically exposed person as a director next year. Point-in-time screening at onboarding is therefore a starting condition, not a control. The best way to screen business customers for PEP and sanctions on an ongoing basis requires a continuous program: structured cadences, documented matching logic, disciplined hit handling, and an audit trail that regulators can inspect at any time.
This playbook covers the operational design of that program. It goes beyond defining terms and explains exactly how to build and run ongoing sanctions and PEP screening for business customers, from watchlist coverage through EDD triggers to reportable outcomes.
Why ongoing PEP and sanctions screening must be continuous
The distinction between onboarding screening and ongoing monitoring is not semantic. Onboarding establishes a baseline risk profile at a fixed point in time. Ongoing monitoring is what keeps that profile accurate as facts change.
Ownership structures change. Legal representatives are replaced. Businesses relocate to higher-risk jurisdictions. A customer's UBO may be appointed to a government role, creating a PEP exposure you never anticipated. A counterparty entity you cleared at onboarding may be designated under a new EU or OFAC sanctions package tomorrow. None of these changes are visible without a live monitoring program.
Operationally, "ongoing" has three components: (1) regular periodic re-screening against updated lists on a defined schedule, (2) event-triggered re-screening whenever material changes occur (new UBO, director change, ownership restructure, geographic expansion), and (3) transaction or behavioral triggers that prompt a contextual recheck outside the periodic cycle.
The Netherlands provides a clear regulatory frame for this. According to Business.gov.nl guidance on the Dutch Sanctions Act, financial and investment firms are obligated to check customers against sanctions registers and to act when a client is listed, which can include freezing funds or stopping services depending on the applicable regime. The AFM, which supervises investment firms, explicitly frames regulated entities as "gatekeepers" responsible for continuous sanctions screening alongside their broader Wwft (Anti-Money Laundering and Counter-Terrorist Financing Act) obligations. DNB performs the equivalent supervisory function for other financial institutions. Neither authority treats onboarding as sufficient. The expectation is a documented, repeatable control that operates throughout the customer lifecycle.
This expectation is consistent across EU member states and most FATF-aligned jurisdictions. The principle: if your screening program does not detect a designation that occurred after onboarding, you have a control failure, not a gap in information.
Scope: what you must screen for business customers
Business KYB screening against sanctions lists covers substantially more surface area than individual KYC screening. The required screening targets for a legal entity customer include:
The registered legal entity name and all known trading names or aliases
Ultimate Beneficial Owners (UBOs) above your ownership threshold (typically 25%, though risk-based policy may set a lower bar)
Legal representatives: directors, authorized signatories, and managing officers
Associated entities in complex structures (holding companies, subsidiaries with shared directors)
The entity's registered jurisdiction and any operating jurisdictions flagged in the profile
PEP screening and sanctions screening carry different obligations, and conflating them creates operational mistakes.
A sanctions match is typically a binary compliance obligation: a designated entity cannot receive funds or services, and the relationship must be blocked or terminated depending on the applicable regime. Reporting to the relevant authority is mandatory. There is no discretion on whether to continue the relationship.
A PEP hit is a risk signal, not a block. PEPs are not prohibited customers. They present elevated corruption risk and trigger a requirement for enhanced due diligence and, in most cases, senior management approval to onboard or continue. The specific EDD obligations are risk-based and must be documented.
False positives are structurally unavoidable in both categories. Name-only matching against any major consolidated list will produce large volumes of non-matches that share surface-level name similarity with a listed entity. The hit triage function is not an administrative afterthought. It is a designed component of the control. If your program does not have a documented false positive management process, it is incomplete.
Control design: the minimum viable workflow for ongoing screening
A compliant ongoing screening program has seven sequential steps. Every step must be documented and repeatable.
Step 1: Identity data quality and enrichment. Screen against clean, normalized input. This means validating legal entity names, resolving aliases, and confirming UBO data is current before each screening run. Poor input quality is the single largest driver of both false positives and false negatives.
Step 2: Sanctions and PEP list screening. Run the normalized entity data (including UBO and representative names) against all applicable lists. Coverage must include EU consolidated lists, UN lists, OFAC SDN, and any jurisdiction-specific national lists relevant to your customer base. Missing a list is a coverage gap, and coverage gaps constitute residual risk.
Step 3: Hit triage. Every alert is reviewed against documented triage criteria. The analyst classifies the hit as: (a) confirmed clear/no match, (b) potential match requiring further investigation, or (c) confirmed match. Each classification requires documented rationale.
Step 4: Enhanced due diligence. Potential matches, PEP proximity flags, and adverse media relevance triggers initiate EDD. EDD scope is risk-proportionate: source of funds, ownership structure depth, third-party business registry checks, and senior management notification where required.
Step 5: Disposition decisioning. The case reaches a documented decision: clear, resolve as false positive, continue with enhanced monitoring, block/terminate, report to authority. Decisions with material risk implications require four-eyes review and independent sign-off.
Step 6: Ongoing monitoring triggers. The disposition feeds back into the monitoring schedule. A case resolved as false positive should be suppressed for future identical alerts (with rationale stored). A case resulting in heightened risk scores should increase screening frequency.
Step 7: Records and audit trail. Every action in steps 1 through 6 is logged with timestamps, input data snapshots, list version and date, analyst identity, decision outcome, and any escalation events.
A simple disposition decision tree:
Alert generated → Is it a name-only coincidence with no corroborating identifiers? → Clear, document rationale
Partial match with corroborating identifiers → Investigate → False positive? → Resolve with documented reasoning → True match? → Determine sanction vs. PEP type
Sanctions match → Block/freeze → Report to AFM (investment firms) or DNB (other financial institutions) within required timeframe
PEP match → Trigger EDD → Senior management approval → Continue with enhanced monitoring or decline
Escalation path for disagreement: record dissenting rationale, escalate to MLRO or equivalent
The automated case management infrastructure underpinning this workflow is as important as the workflow design itself. Without it, consistency breaks down and audit trails become fragmented.
Data and watchlists: how to manage list coverage and update cadence
Watchlist coverage is not a static procurement decision. Lists change constantly, as SmartSearch's sanctions compliance resource notes: multi-jurisdiction list changes and the complexity they create are among the most persistent operational challenges in ongoing screening.
Minimum list coverage for EU-headquartered firms serving business customers includes the EU Consolidated Sanctions List, UN Security Council Consolidated List, OFAC SDN and CAPTA lists, HM Treasury Financial Sanctions Targets list, and any national lists relevant to your customer jurisdictions (for the Netherlands, this includes the Dutch national sanctions register maintained under the Sanctiewet 1977).
In addition to consolidated lists, your program should ingest sector-specific lists (e.g., BIS Entity List for technology companies) and adverse media signals as a supplementary risk layer.
Watchlist update cadence. EU sanctions lists update irregularly but frequently, sometimes multiple times per week following geopolitical events. At minimum, your list data should refresh daily. After any material geopolitical event or published EU Council Regulation amending the sanctions regime, an unscheduled re-screen of your entire business customer portfolio is appropriate.
Periodic re-screen schedule. For standard-risk business customers, quarterly full portfolio rescreens are a defensible baseline. For elevated-risk customers (those with PEP connections, operations in higher-risk jurisdictions, or prior hit history), monthly or continuous daily monitoring is the appropriate control.
Data normalization. Before screening, normalize entity names by removing legal form suffixes (B.V., GmbH, S.r.l., LLC) and their common abbreviations. Apply transliteration rules to names entered in non-Latin scripts. Standardize address components and jurisdiction identifiers. Unormalized input is the root cause of most avoidable false positives. Platforms with deep localization across 210+ local registries handle this normalization structurally rather than relying on analyst judgment each time.
Matching logic: how to reduce false positives without missing real matches
Name-only matching is insufficient for business entity screening and produces false positive rates that make the program operationally unmanageable. Industry data from McKinsey suggests 90 to 95% false positive rates are common in screening and transaction monitoring programs. That rate is only acceptable if your triage process can handle the volume. A well-designed matching engine targets below 30%.
Effective matching logic for business entities uses multiple corroborating dimensions:
Entity name (with fuzzy matching tolerance calibrated by risk level)
Known aliases and former names
Registration number or tax identifier where available on the list
Registered address and jurisdiction
UBO identifiers (names, dates of birth, nationalities)
Legal representative names and identifiers
Matching confidence scoring should assign weight to each dimension. A name match alone at 85% fuzzy similarity is insufficient to flag a hit. A name match plus jurisdiction match plus a shared UBO identifier is a high-confidence potential match requiring escalation regardless of the fuzzy score on the name.
Document your scoring rationale. If a regulator asks why a specific alert was resolved as a false positive, the answer cannot be "the analyst used their judgment." It must be: "the matching criteria were X, Y, and Z; the entity in question differed on criteria Y and Z; the case was reviewed by [name] and approved by [four-eyes reviewer] on [date]."
Calibrate thresholds periodically using adjudicated outcomes. If your historical false positive rate on a specific list is above 40% at your current confidence threshold, you have grounds to tighten the threshold for that list. If you are clearing potential matches that later turn out to be true matches (false negatives), you need to loosen it. This is a control effectiveness question, not just an efficiency one.
The guide to reducing false positives in KYB covers the technical mechanics of this calibration process in depth, including how to store analyst decisions to suppress repeat false positives on future screening cycles.
Hit handling and escalation: from triage to EDD to disposition
The PEP hit triage SOP is where most compliance programs lack sufficient documentation. Here is the minimum viable structure.
Classification. On receiving a hit, the analyst first determines: is this the same legal entity or person as the listed subject? Apply the multi-factor matching criteria described above. If two or more corroborating identifiers match, treat as a potential match and proceed to investigation.
Evidence collection for potential matches. Collect: the listed entity's full profile from the relevant list (including listing date, citing regulation, and any listed identifiers), the customer's verified profile from your own records and any registry data, and any adverse media results relevant to the hit. Document each source.
EDD triggers. Enhanced due diligence is required when any of the following apply:
PEP designation confirmed for a UBO, director, or representative (first or second degree)
Sanctions "related to" or "associated with" indicator present on the list entry
Adverse media results are relevant and credible
Customer's declared information conflicts with registry data or list data
The customer operates in a jurisdiction under heightened FATF monitoring or an active EU sanctions regime
For PEP-related EDD, the scope typically includes verified source of funds and wealth, updated beneficial ownership mapping, and senior management approval. The four-eyes review requirement for sanctions and elevated PEP cases is standard practice and should be specified in your screening policy.
Escalation and disagreement handling. When analysts disagree on a disposition, both positions must be documented. The MLRO (or equivalent) makes the final determination, and their reasoning is recorded. Suppressing dissenting views in the case file is a documentation failure that creates significant audit risk.
The policy engine layer matters here. Translating these escalation rules into code-enforced workflow ensures they are applied consistently, not only when the most experienced analyst happens to be reviewing a case.
Auditability and reporting: what regulators expect you to prove
Regulators do not assess compliance programs based on your intentions. They assess them based on what you can demonstrate. The audit trail for each screening decision must contain, at minimum:
A snapshot of the input data used for the screening run (entity name, UBO names, identifiers, as of the screening date)
The list version and date used at the time of screening
The match rationale: which criteria triggered the alert and at what confidence level
The analyst's triage notes, including the evidence reviewed
The disposition outcome and the name of the approving reviewer
The timestamp of each action in the workflow
For escalated cases: the full escalation log including any dissenting views
For Dutch-regulated firms, the reporting obligations are specific. Business.gov.nl guidance identifies AFM as the relevant notification channel for investment firms and DNB for other financial institutions when a sanctions match is confirmed. Notification timelines are governed by the applicable sanction regime and should be codified in your response procedure, not left to ad hoc judgment.
Testing your controls. Audit readiness is not the same as running the program. You must also test it. Recommended testing cadence:
Quarterly QA sampling of analyst decisions (minimum 5% of resolved cases reviewed by an independent reviewer)
Bi-annual false positive/false negative rate analysis across each list you cover
Annual full control effectiveness review against your documented screening policy
Immediate review after any regulatory update to the relevant AML or sanctions frameworks
The lifecycle compliance capabilities required to operationalize these testing cadences, including policy versioning and periodic review automation, are a distinguishing feature between platforms that support compliance programs and those that only support onboarding.
Technology evaluation checklist for ongoing screening
If you are evaluating platforms or vendors to support this program, the following questions establish minimum viable capability. Treat any vendor that cannot answer them with specific, evidenced responses as a procurement risk.
Functional requirements:
Does the platform support continuous (daily or real-time) screening in addition to batch runs?
Can matching thresholds be configured per list or per customer risk tier, with documented rationale for each configuration?
Does the platform maintain versioned watchlist history so you can prove which list version was used for any past screening event?
Does the platform support multi-factor matching (name plus identifiers plus jurisdiction plus UBO attributes) rather than name-only matching?
Is there a built-in case management workflow with four-eyes review enforcement, analyst notes, and exportable decision records?
Can the platform generate audit-ready case exports that include input data snapshots, list version, match rationale, and disposition chain?
Technical requirements:
What is the data refresh SLA for each watchlist? Can the platform trigger an unscheduled portfolio rescreen after a major list update?
What is the throughput and latency for screening a portfolio of 50,000+ business entities?
How does the platform handle deduplication of alerts across multiple screening runs?
What is the API model for integrating screening triggers from your CRM or KYB system?
Procurement red flags:
A vendor claims a specific false positive rate but cannot provide methodology or reference deployments. Ask for evidence.
The platform provides list screening but no case management or workflow tooling. That splits your audit trail across systems.
Configuration requires vendor professional services for every rule change. Ongoing screening programs require fast iteration as regulations change.
No watchlist versioning means you cannot prove which list you screened against at any point in time. That is an audit liability, not a product feature gap.
Duna's platform addresses all of these requirements through its integrated data platform for KYC data orchestration, configurable policy engine, automated case management, and lifecycle compliance workflows for daily screening and periodic reviews. The operational outcomes reported by Duna customers, including 4.8x analyst efficiency gains, reflect what becomes possible when screening, triage, and case management are unified rather than stitched together across point solutions.
FAQ: common questions on ongoing PEP and sanctions screening
How often should we re-screen business customers? At minimum, run full portfolio re-screens quarterly for standard-risk customers. Run daily monitoring for elevated-risk customers and any customer with a prior alert or PEP connection. Always run an unscheduled rescreen after a material list update affecting relevant jurisdictions.
Should we screen only at onboarding or also on ownership changes? Ownership changes are a mandatory re-screening trigger. Any change in UBO, director, or legal representative should initiate a new screening run for the new individuals. Changes in the entity's registered jurisdiction or operating profile may also trigger a full profile reassessment.
What's the difference between a sanctions match and a PEP hit? A confirmed sanctions match requires immediate action: block the transaction or relationship, and report to the relevant supervisory authority (AFM or DNB in the Netherlands). A PEP hit is a risk-based trigger for enhanced due diligence and senior management approval. The relationship may continue, but only with documented EDD completed and approval recorded.
How do we handle false positives operationally? Document the triage rationale with full evidence: which identifiers matched, which did not, and why the analyst concluded no true match exists. Store the decision in the case record with reviewer sign-off. Use the resolved false positive to suppress the same alert on future screening cycles for that entity-list pair, while preserving the original record for audit purposes.
What evidence should we store to defend decisions? Keep the input data snapshot (as of the screening date), the list version used, the matching criteria and confidence output, analyst triage notes with sources cited, the disposition outcome, the approving reviewer's identity, and the timestamp chain. For escalated or reported cases, retain all communication with supervisory authorities. Minimum retention periods vary by jurisdiction, but five years from the end of the relationship is the standard EU baseline under Wwft.
The reboarding and ongoing monitoring challenge is not primarily a technology problem. It is a program design problem. Technology makes the program scalable and auditable. The design decisions, screening cadence, matching logic, hit handling SOPs, escalation rules, and record-keeping structure, are what determine whether you have a defensible control or a compliance process in name only.
Continue reading
Industries
Customers
Company
Resources

Industries
Customers
Company
Resources

Industries
Customers
Company
Resources

