Section 01

Introduction: The invisible gatekeepers of the financial world

Every time you open a bank account, apply for a mortgage, or make a large international transfer, something happens behind the scenes that most people never see. Within milliseconds, your name is checked against hundreds of thousands of records — sanctioned individuals, politically exposed persons, criminal databases, and global news archives.

This process is called financial crime screening, and it is one of the most critical — yet least understood — functions in modern finance. It is the invisible layer that separates legitimate financial transactions from money laundering, terrorism financing, and sanctions evasion.

In 2023 alone, global financial institutions paid over $6.6 billion in AML fines. Banks that failed to screen properly found themselves enabling drug cartels, terrorist organisations, and sanctioned regimes. The consequences — financial, reputational, and criminal — can be existential.

$6.6B
AML fines paid globally in 2023
2-5%
of global GDP laundered annually
40+
major sanctions lists worldwide
300K+
sanctioned individuals & entities

This guide will walk you through everything — from the fundamental concepts to the cutting-edge technology — so that whether you are a compliance student taking your first steps, or a seasoned professional looking to deepen your knowledge, you leave with a complete picture of how financial crime screening really works.

💡
How to use this guide
Each section builds on the last. As you read, you will find interactive elements — quizzes, expandable explanations, and real-world examples. At key points, we invite you to test concepts on a live screening tool. Learning by doing is far more effective than reading alone.
Section 02

What is financial crime screening?

Financial crime screening is the process of checking individuals, businesses, and transactions against a set of lists, databases, and information sources to identify potential risks of financial crime — including money laundering, terrorism financing, sanctions evasion, bribery, and corruption.

At its core, screening asks one fundamental question: "Should we be doing business with this person or entity?"

The three pillars of screening

Modern financial crime screening is built on three interconnected pillars. Each addresses a different type of risk, and together they create a comprehensive picture of who you are dealing with.

🛡️ Sanctions
Is this person legally prohibited from transacting?
🔍 PEP
Does this person hold political power that creates corruption risk?
📰 Adverse Media
Has this person been linked to financial crime in the news?

Who conducts screening?

Screening is not exclusive to large banks. A wide range of organisations are required — legally or by best practice — to screen their customers and counterparties:

  • Banks and financial institutions — the primary obligated entities under AML law
  • Payment service providers and fintechs — including e-money institutions like Revolut, Wise, and Rapyd
  • Insurance companies — particularly for large or complex products
  • Law firms and accountants — subject to AML regulations as "gatekeepers"
  • Estate agents — required to screen buyers and sellers of high-value property
  • Cryptocurrency exchanges — increasingly regulated globally
  • NGOs and charities — to prevent aid from reaching sanctioned individuals
"Screening is not a compliance checkbox — it is an organisation's first line of defence against being used as a vehicle for financial crime."
🛡️ See it in action
Now you understand what screening is — see what it actually looks like
Try searching a well-known name and see how the three pillars work together in real time.
Try the screening tool →
Section 03

Why financial crime screening matters

To understand why screening matters, it helps to understand the scale of the problem it is designed to solve.

The scale of financial crime

The United Nations Office on Drugs and Crime (UNODC) estimates that between 2% and 5% of global GDP — approximately $800 billion to $2 trillion — is laundered through the financial system every year. Less than 1% of this is ever detected and seized.

Money laundering is not a victimless crime. It enables:

  • Drug trafficking and organised crime
  • Terrorism financing — funding attacks and extremist groups
  • Human trafficking and modern slavery
  • Corruption and kleptocracy — allowing authoritarian regimes to plunder their countries
  • Tax evasion — depriving governments of funds for public services
⚠️
Real consequence
In 2012, HSBC was fined $1.9 billion by US authorities after it was found to have processed hundreds of millions of dollars for Mexican drug cartels. The bank's AML screening had failed to catch transactions linked to the Sinaloa cartel. This remains one of the largest AML fines in history.

The regulatory imperative

Beyond the moral case, financial crime screening is a legal obligation for most financial institutions. Failure to screen properly can result in:

  • Massive regulatory fines — often running into hundreds of millions of pounds
  • Criminal prosecution of senior executives
  • Revocation of operating licences
  • Reputational damage that can destroy customer trust overnight
  • Derisking — being cut off from correspondent banking relationships
🧠 Quick check
Which of the following is NOT a consequence of failing to conduct proper financial crime screening?
Section 04

Sanctions screening: The hard stop

Sanctions are restrictions imposed by governments or international bodies against specific countries, individuals, or entities. They are one of the most powerful tools in foreign policy and financial crime prevention.

Unlike other financial crime risks which involve judgement and risk assessment, sanctions are binary: if a person or entity is on a sanctions list, you cannot transact with them. Full stop. No exceptions. No mitigation. Proceeding knowingly is a criminal offence.

Who issues sanctions?

🇺🇸 OFAC (US Treasury) 🇬🇧 OFSI (UK) 🇪🇺 EU 🇺🇳 UN Security Council 🇦🇺 DFAT (Australia) 🇨🇦 OSFI (Canada) 🇨🇭 SECO (Switzerland)

Types of sanctions

  • Individual sanctions — named persons are prohibited from accessing the financial system. Examples: Russian oligarchs, North Korean officials, terrorist financiers.
  • Entity sanctions — companies, organisations, or vessels are designated. Examples: Wagner Group, state-owned banks in sanctioned countries.
  • Country sanctions — comprehensive restrictions on entire jurisdictions. Examples: North Korea, Iran, Cuba (varying degrees).
  • Sectoral sanctions — restrictions on specific sectors of an economy. Example: Russian energy sector sanctions after 2022.
  • Thematic sanctions — targeted at specific activities regardless of nationality. Example: cyber sanctions, human rights sanctions.

Key sanctions lists to know

List Issuer Jurisdiction Extraterritorial?
SDN List OFAC US Yes — most powerful
Consolidated List OFSI UK Limited
Financial Sanctions EU EU member states Within EU
UN Consolidated UN Security Council Global Yes — all member states
DFAT List DFAT Australia No
🔑
Why OFAC matters everywhere
OFAC sanctions have extraterritorial reach — meaning non-US banks can be fined by the US if they process USD transactions involving sanctioned parties, even if the transaction has no other US connection. This is why OFAC compliance is considered mandatory globally for any bank that clears USD.
🛡️ Try sanctions screening
Search for a sanctioned individual and see which lists they appear on
Try names like "Wagner Group", "Kim Jong Un", or "Bashar al-Assad" to see real sanctions data.
Screen now →
Section 05

PEP screening: The grey zone of political risk

If sanctions screening is black and white, PEP screening lives in the grey zone. A Politically Exposed Person (PEP) is not a criminal — they are simply someone whose position of power creates an elevated risk of corruption, bribery, or abuse of public funds.

The logic is straightforward: a finance minister who controls billions in public spending, or a central bank governor who sets interest rates, has access to power that can be — and historically has been — abused for personal financial gain. Financial institutions must identify PEPs and apply enhanced due diligence.

Who qualifies as a PEP?

Under FATF guidelines and the UK's Money Laundering Regulations 2017, PEPs include:

  • Heads of state and government — presidents, prime ministers, monarchs
  • Senior government ministers — cabinet members, secretaries of state
  • Senior judicial officials — supreme court judges, attorney generals
  • Senior military officials — chiefs of staff, generals
  • Senior executives of state-owned enterprises — CEOs of national oil companies, state banks
  • Senior political party officials — party leaders, senior officials
  • Members of parliament and legislative bodies
  • Ambassadors and high commissioners
  • Central bank governors and board members
  • Board members of international organisations — UN, IMF, World Bank

Domestic vs. foreign PEPs

The treatment of PEPs differs depending on whether they are domestic (from your own country) or foreign:

TypeRisk LevelEDD Required?Examples
Foreign PEPHighAlwaysForeign head of state opening UK account
Domestic PEP (UK)MediumRisk-basedUK MP applying for a mortgage
International Org PEPMediumRisk-basedSenior IMF official
RCA (Relative/Close Associate)MediumRisk-basedSpouse or business partner of a PEP

How long does PEP status last?

This is one of the most commonly misunderstood aspects of PEP screening. Under FATF guidance, a person who leaves a prominent public function should continue to be considered a PEP for at least 12 months after leaving office. Many institutions apply a 12–24 month "cooling off" period, and some apply enhanced scrutiny indefinitely for very high-risk roles.

🎭
The Marcos case
Ferdinand Marcos, former President of the Philippines, and his family allegedly looted between $5–10 billion from the Philippine state during his 20-year rule. Imelda Marcos's famous collection of 3,000 pairs of shoes became a symbol of kleptocracy. Proper PEP identification and enhanced due diligence is specifically designed to prevent such abuse of power.
🔍 Try PEP screening
Search for a world leader or government official
Try "Emmanuel Macron", "Rachel Reeves", or "Mohammed bin Salman" to see PEP profile data.
Screen a PEP →
Section 06

Adverse media screening: What the news tells you

Sanctions lists and PEP databases are structured, curated data sources. But financial crime does not announce itself on official lists. Some of the most important warning signs appear first in the press — a corruption investigation, a regulatory probe, a criminal conviction. This is where adverse media screening comes in.

Adverse media screening (also called negative news screening) involves systematically searching news sources, court records, and other public information for negative coverage related to your customer or counterparty.

What counts as adverse media?

Money laundering Fraud Corruption Bribery Drug trafficking Tax evasion Terrorism Human trafficking Regulatory action Criminal charges Civil litigation Sanctions violations

Why adverse media matters

Consider this: a person may not yet be on a sanctions list, but they might be under investigation by the FBI, mentioned in the Panama Papers, or the subject of a OCCRP investigation into corruption. None of this would appear in a sanctions or PEP search — but it is absolutely material to a risk assessment.

Adverse media screening bridges the gap between what is officially designated and what is publicly known. It is particularly important for:

  • Enhanced Due Diligence (EDD) — required for high-risk customers
  • Ongoing monitoring — catching risks that emerge after onboarding
  • Correspondent banking — assessing the risk profile of partner banks
  • Trade finance — screening counterparties in complex multi-party transactions
📰
The OCCRP effect
The Organised Crime and Corruption Reporting Project (OCCRP) has exposed financial crime involving billions of dollars — from the Azerbaijani Laundromat to the Pandora Papers. OCCRP investigations have led to prosecutions, sanctions designations, and regulatory actions worldwide. This is why OCCRP is one of the sources in FinCrimeRadar's adverse media engine.
📰 Try adverse media search
See what the news says about a company or individual
Try "HSBC", "Wirecard", or "Glencore" to see adverse media results from live news sources.
Search adverse media →
Section 07

How screening actually works: The process

Understanding what screening checks is one thing. Understanding how those checks are performed is where the real technical insight lies. This section walks through the mechanics.

The screening workflow

1

Data ingestion

Screening begins with the data you are checking against. Sanctions lists, PEP databases, and adverse media sources are downloaded, parsed, and structured into a searchable index. Lists are updated daily — or in real time for critical designations.

2

Name normalisation

The input name (e.g. "Mohammed Al-Rashid") is cleaned and standardised — removing titles, punctuation, and special characters — to prepare it for matching.

3

Name matching

The normalised name is compared against the database. This is where the sophistication lies — see the section below on matching algorithms.

4

Score generation

Each potential match is given a score (typically 0–100%) reflecting how similar the input is to the database record. Higher scores indicate closer matches.

5

Threshold filtering

Results below a set threshold (e.g. 80%) are discarded. Results above it are returned as potential matches for review.

6

Human review (for high scores)

Potential matches above a higher threshold (e.g. 95%) may require a compliance analyst to review and determine whether it is a true match or a false positive.

The name matching challenge

Name matching sounds simple. It is not. The same person can appear in databases under dozens of different spellings, transliterations, and aliases. Consider:

  • Muammar Gaddafi — also written as Qaddafi, Qadhafi, Kaddafi, Kadafi (over 100 recorded variations)
  • Mohammed — one of the world's most common names, appearing in dozens of transliterations
  • Chinese names — different romanisation systems produce different spellings
  • Aliases — many individuals on sanctions lists use aliases, nicknames, or maiden names

This is why modern screening systems use fuzzy matching algorithms rather than simple exact-match lookups. Fuzzy matching calculates similarity scores between strings, catching variations that an exact match would miss.

⚙️
How FinCrimeRadar does it
FinCrimeRadar uses RapidFuzz — a high-performance fuzzy matching library — with the WRatio algorithm. This catches spelling variations, transliteration differences, and partial name matches. You can adjust the sensitivity using the threshold slider on the screening tool. Try lowering it to 60% on a name search to see what additional matches emerge.
⚙️ Try the threshold
See how matching thresholds affect results
Search "Qaddafi" and adjust the threshold slider — see how 60% vs 90% changes what matches appear.
Try it now →
Section 08

Risk scoring and the art of the false positive

The screening process generates matches — but not every match is a real hit. This is one of the most significant operational challenges in AML compliance: the false positive problem.

True hits vs. false positives

TypeWhat it meansAction required
True positive The matched person IS the sanctioned/PEP individual Block transaction, file SAR, escalate immediately
False positive The matched person shares a name but is NOT the same individual Document the false positive, clear the alert, proceed
False negative A sanctioned person was NOT matched (worst case) Review screening configuration, threshold, and data quality

The false positive problem

In large financial institutions processing millions of transactions daily, false positive rates can be enormous. Some banks report false positive rates of 95–99% — meaning that for every 100 screening alerts, only 1–5 are genuine matches. The rest are innocent customers who happen to share a name with a sanctioned person.

This creates a real tension:

  • Set the threshold too high (e.g. 95%) → miss genuine matches → regulatory risk
  • Set the threshold too low (e.g. 50%) → flood of false positives → operational cost

The art of good screening configuration is finding the right balance for your risk appetite and customer base.

🧠 Quick check
A bank screens 10,000 transactions per day and gets 500 alerts. Of those, only 10 are genuine matches. What is the false positive rate?
Section 09

The regulatory framework: Who makes the rules?

Financial crime screening does not exist in a vacuum. It is embedded in a complex web of international standards, national laws, and regulatory guidance. Understanding this framework is essential for any compliance professional.

The international standard: FATF

The Financial Action Task Force (FATF) is the global standard-setter for AML and counter-terrorism financing (CTF). Founded in 1989, FATF has 37 member jurisdictions and produces the internationally recognised "40 Recommendations" — the blueprint for AML frameworks worldwide.

FATF conducts mutual evaluations of member countries, assessing the effectiveness of their AML systems. Countries that fail evaluations can be placed on the "grey list" (increased monitoring) or "black list" (call for action) — which can have severe consequences for their banking sector.

Key regulatory milestones

1989
FATF established
Founded by G7 to combat money laundering. Original 40 Recommendations published.
2001
FATF expands to terrorism financing
Post 9/11, FATF adds 8 Special Recommendations on terrorist financing.
2003
PEP definition formalised
FATF formally defines Politically Exposed Persons and requires enhanced due diligence.
2012
Revised 40 Recommendations
Risk-based approach embedded. Virtual assets and tax crimes added to scope.
2017
UK MLR 2017
UK Money Laundering Regulations 2017 transposed EU 4th AMLD into UK law.
2022
Russia sanctions surge
Following invasion of Ukraine, OFAC, OFSI and EU issued unprecedented waves of sanctions against Russian individuals and entities.

UK-specific framework

For those operating in the UK, the key legislative and regulatory framework includes:

  • Proceeds of Crime Act 2002 (POCA) — primary money laundering legislation
  • Terrorism Act 2000 — terrorism financing offences
  • Money Laundering Regulations 2017 (as amended) — detailed AML obligations
  • Financial Services and Markets Act 2000 (FSMA) — FCA's regulatory powers
  • The Sanctions and Anti-Money Laundering Act 2018 — post-Brexit UK sanctions regime
  • FCA's Financial Crime Guide — practical guidance on implementing AML obligations
🔍 See regulation in action
Search for entities on UK (OFSI) sanctions lists
Try screening names to see which are on UK OFSI lists vs US OFAC — and see how different regulators designate differently.
Compare lists →
Section 10

The real challenges of financial crime screening

Theory is one thing. The practical reality of operating a financial crime screening programme is filled with challenges that textbooks rarely address.

1. Data quality

Screening is only as good as the data you feed it. Customer records with missing middle names, inconsistent transliterations, or outdated addresses lead to missed matches and unnecessary false positives. "Garbage in, garbage out" is never more true than in screening.

2. Beneficial ownership

Criminals and sanctioned individuals rarely put their own name on accounts. They use shell companies, nominees, and complex ownership structures to obscure their identity. Effective screening must look through these structures to identify the ultimate beneficial owner (UBO) — but this data is often unavailable or unreliable.

3. Speed vs. accuracy

In real-time payments (faster payments, SWIFT, crypto), there may be milliseconds to screen before a transaction completes. This creates tension between thoroughness and speed. Batch screening (end-of-day checks) allows more time but misses real-time risk.

4. List proliferation

There are over 40 major sanction lists globally, updated at different frequencies, in different formats, with different legal implications. Keeping all of them current, integrated, and accurately weighted is a significant operational challenge.

5. De-risking

Faced with the compliance burden, many large banks have simply exited entire markets or customer segments — closing accounts for money service businesses, charities operating in conflict zones, or correspondent banks in high-risk jurisdictions. This "de-risking" can leave vulnerable populations without access to financial services, and pushes activity into unregulated channels.

⚠️
The de-risking paradox
When Barclays closed accounts for money transfer operators sending remittances to Somalia in 2013, it cut off a financial lifeline for millions of Somali diaspora. The fear of AML exposure led to an action that ironically increased financial crime risk by pushing transfers into unmonitored cash networks.
Section 11

Technology and AI: The future of screening

Financial crime screening is being transformed by technology. What was once a manual, rule-based process is rapidly becoming an AI-driven, adaptive system.

From rules to machine learning

Traditional screening systems used simple exact-match or basic fuzzy-match rules. Modern systems use machine learning to:

  • Learn from analyst decisions to reduce false positives over time
  • Identify unusual patterns in transaction behaviour
  • Link entities across multiple data sources
  • Predict risk before a transaction even completes

Natural Language Processing (NLP)

NLP is transforming adverse media screening. Instead of keyword searches that return anything mentioning "fraud", NLP systems can understand context — distinguishing between "John Smith was convicted of fraud" and "John Smith's company helped uncover a fraud".

Graph analytics and network analysis

Financial crime rarely involves a single individual acting alone. Graph analytics maps the relationships between entities — revealing networks of shell companies, shared addresses, and common directors that might not be visible when looking at customers individually.

The role of open-source intelligence (OSINT)

The growth of open-source data — from company registries to social media to leaked documents — has transformed what is possible in due diligence. Platforms like OpenSanctions aggregate publicly available sanctions and PEP data from dozens of sources into a single, machine-readable format. This is the data that powers FinCrimeRadar.

🤖
AI in compliance
Financial institutions are increasingly using large language models (LLMs) to assist with KYC document review, SAR drafting, and regulatory interpretation. The compliance function is becoming one of the highest-growth areas for AI adoption in financial services — making this an excellent time to develop both domain knowledge and technical literacy.
🤖 Experience AI screening
FinCrimeRadar uses real fuzzy-matching AI — try it yourself
Search a misspelled name — e.g. "Vladiir Putin" or "Kim Jong-un" — and see how the AI still finds the right match.
Try AI screening →
📋 3-Part Series

UK AML Compliance: The Complete Guide

FCA guidelines, MLR 2017, POCA 2002, Terrorism Act 2000, CDD, SARs, record keeping, staff training, transaction monitoring, and enforcement — everything regulated firms need to know, split into three focused parts.

Part 1
The Legal Framework
MLR 2017 · POCA · Terrorism Act · SAMLA
Part 2
Core Obligations
Risk assessment · CDD · SARs · Record keeping
Part 3
Controls & Enforcement
Training · TM · Governance · FCA enforcement
Start Part 1 →
Section 12

Frequently asked questions

What is the difference between AML and KYC? +

KYC (Know Your Customer) is the process of verifying customer identity and understanding their business. AML (Anti-Money Laundering) is the broader framework of policies, controls, and procedures designed to prevent money laundering. KYC is a component of AML — you need to know who your customer is (KYC) before you can assess the risk they pose (AML). Screening sits within both: it is part of the KYC onboarding process and ongoing AML monitoring.

How often should screening be conducted? +

At minimum, screening should occur at onboarding (before the customer relationship begins) and on an ongoing basis. Most institutions screen at onboarding and then conduct periodic rescreening — typically annually for standard risk customers, more frequently for high-risk. Many institutions also screen in real time at the point of transaction. Trigger-based rescreening (when new information emerges about a customer) is also best practice.

What is Enhanced Due Diligence (EDD)? +

Enhanced Due Diligence (EDD) is a more thorough level of customer due diligence applied to higher-risk customers — including PEPs, customers from high-risk jurisdictions, and those in higher-risk business sectors. EDD typically involves: obtaining additional information about the source of funds and wealth, senior management approval for the relationship, more frequent monitoring, and additional adverse media searches. EDD is required under UK Money Laundering Regulations 2017 for PEPs and certain other high-risk categories.

What is a Suspicious Activity Report (SAR)? +

A Suspicious Activity Report (SAR) is a report filed with the financial intelligence unit (in the UK, the National Crime Agency's UKFIU) when a firm knows or suspects that a person is engaged in money laundering or terrorist financing. If a screening match turns out to be a genuine hit — or if transaction monitoring reveals suspicious patterns — the institution's MLRO must consider whether to file a SAR. In the UK, filing a SAR and obtaining a "defence against money laundering" (DAML) consent can protect the institution from prosecution if they proceed with a transaction.

Can I use FinCrimeRadar for actual compliance screening? +

FinCrimeRadar is an educational tool designed to help students and compliance professionals understand how screening works. It should not be used as a substitute for regulated compliance screening solutions. For actual compliance purposes, you should use FCA-approved or equivalent commercial screening platforms with full audit trails, complete data coverage, and legal accountability. FinCrimeRadar is excellent for learning, testing concepts, and understanding the mechanics — but it is not a compliance tool.

What qualifications are available in financial crime compliance? +

Several professional qualifications are widely recognised in the UK and globally: ICA (International Compliance Association) — offers Certificates and Diplomas in AML and compliance; ACAMS (Association of Certified Anti-Money Laundering Specialists) — offers the CAMS certification, widely regarded as the gold standard globally; ACFE (Association of Certified Fraud Examiners) — offers the CFE for fraud professionals; ICA Diploma in Financial Crime Prevention — UK-specific qualification. Many employers in financial crime compliance look for at least one of these certifications in addition to relevant experience.

What is the difference between screening and transaction monitoring? +

Screening checks who you are dealing with — it is identity-focused and compares names against lists. Transaction monitoring checks what is happening — it analyses patterns of transactions over time to identify unusual or suspicious behaviour (e.g. structuring, unusual cash deposits, rapid movement of funds). Both are required under AML regulations. Screening typically triggers at onboarding and rescreening points; transaction monitoring runs continuously on account activity.

🎓 You've read the guide — now experience it
Put your new knowledge to work on a real screening tool
Free, open-source, and built for exactly this moment. No sign-up required.
🛡️ Launch the tool →