How Sanctions Screening, PEP Checks, and Risk Profiling Work After Customer Identification

Customer identification is completed in seconds, but it is precisely after it that the chain of checks begins that determines whether this customer will become a source of a regulatory fine or a safe business partner. Sanctions screening, PEP checks, and risk profiling use the data collected at the KYC stage to determine whether the customer is connected to restrictive lists, public authority, or other factors of elevated risk — and what level of control to apply to them. Below we break down how each of these stages is arranged after identification, what data flows into them, by what algorithms decisions are made, and why continuous monitoring turns a one-time check into an ongoing process, without which the compliance loop loses relevance within a few days.

Which Identification Data Is Needed for Sanctions Screening, PEP Checks, and Risk Profiling

Sanctions screening, PEP checks, and customer risk profiling begin not with a query to external databases but with the set of data the system obtains at the identification stage. The quality, completeness, and structure of these data determine the accuracy of the subsequent AML checks and the volume of false positives that will have to be handled manually.

At the KYC stage, the system collects and verifies the customer’s identification attributes: full name (including transliterations and Latin-script spelling variants), date of birth, citizenship, country of residence, and country of document issue. These five fields are the minimum mandatory set for launching sanctions screening. FATF Recommendation 10 directly establishes that a financial institution is obliged to identify the customer and confirm their identity using reliable independent documents before the start of the business relationship. Without confirmed data, any reconciliation against lists lacks a reliable foundation: the system will be unable to correctly match the customer against records in sanctions registries and PEP databases.

For a PEP check, the same basic attributes are required, but information about the position, place of work, and country of authority is additionally critical — if it was collected during questionnaire completion or extracted from documents. Compliance platforms use these fields to precisely determine the PEP category: whether the customer is a foreign, national, or international politically exposed person. Data on family and business connections (if available at the identification or enhanced due diligence stage) makes it possible to identify RCA (Relatives and Close Associates) — persons in the PEP’s circle to whom enhanced due diligence measures also apply.

Risk profiling relies on a broader data set. In addition to identification attributes, calculating the risk profile requires: the type and jurisdiction of the document, the method of identification (remote or in person), the results of biometric verification and the liveness check, the outcomes of the anti-fraud analysis, the declared purpose of establishing the business relationship, and the expected nature of operations. Each of these parameters contributes to the final score: a customer from a higher-risk jurisdiction (included in the FATF grey list) automatically receives a higher starting score, even if no matches are found against sanctions lists and PEP databases.

Data normalization plays a special role. An identification document may contain a name in Arabic, Cyrillic, or hieroglyphs, while sanctions lists are maintained predominantly in Latin script. If the platform does not bring the name to a standard form and does not generate transliteration variants, the screening will miss a match or, conversely, produce an excessive number of false positives. Modern AML platforms solve this task through fuzzy-matching and phonetic-comparison algorithms, but the quality of their work directly depends on which fields and in what form are passed from the identification module.

In practice this means: the more confirmed attributes the customer provided at the KYC stage and the more accurately they are extracted and normalized, the less manual work will be required when reviewing alerts at the following stages. The automated linkage of identification and AML checks works as a conveyor: data from AI-OCR, biometrics, and the anti-fraud loop arrives at the compliance module in structured form (usually JSON with a set of fields, scores, and flags), and the completeness of this package determines the speed and accuracy of all subsequent decisions.

Set up data transfer from KYC to the AML loop without losses

Every missed field or transliteration error at the identification stage increases the volume of false positives during screening — and, consequently, the load on the compliance team. The NEUROVISION software package combines AI-OCR with a document recognition accuracy of up to 99.85%, biometric verification, and the AML module into a single pipeline: the extracted data arrives at the compliance loop in structured form, without manual transfer and loss of attributes.

We will audit your current process from document collection to screening, identify the points where information is lost or discrepancies arise, and propose a configuration with automatic normalization and transliteration. Integration of the AML loop takes one to two days when connected via API, and deployment is possible in the cloud or within the perimeter of your infrastructure.

Request an audit of the KYC → AML data flow

How Sanctions Screening Works After Customer Identification

As soon as the identification system has extracted and confirmed the customer’s data — full name, date of birth, citizenship, document number — it arrives at the sanctions screening loop. The task of this stage is to determine whether the customer or persons associated with them appear in sanctions lists and lists of restrictions. Screening is performed automatically, as a rule, within a single pipeline with identification, and takes seconds.

The system reconciles the customer’s identification data with records in the connected databases. The reconciliation happens not by exact match but by fuzzy-comparison algorithms that account for variations in name spelling, transliteration, abbreviations, and cultural naming particularities. The result is a list of potential matches (alerts), each of which requires assessment: whether it is a true match or a false positive.

The quality of screening is determined by two interrelated metrics. The first is the ability to detect a real match (minimizing misses): an undetected sanctioned person threatens fines and criminal liability. The second is precision: according to a study by Kim & Yang, published in the journal Frontiers in Artificial Intelligence (2024), the share of false positives in typical sanctions screening programs exceeds 90% of the total number of alerts. Without proper tuning of the algorithms, the compliance department spends its main resource on reviewing irrelevant matches. Reducing this load is one of the priority tasks when implementing an AML loop.

Reduce the share of false positives in sanctions screening

When more than 90% of alerts turn out to be irrelevant, compliance analysts spend the bulk of their working time not on real threats but on reviewing matches by common surnames and transliteration variants. The AML module of the NEUROVISION software package reconciles customers against more than 1,700 databases and sources with daily updates, while context enrichment — matching not only the name but also the date of birth, citizenship, and identification numbers — automatically weeds out irrelevant matches and reduces the manual load on the team by up to 80%.

We will review the structure of your customer base, assess the current level of false positives, and configure the screening thresholds and rules for your profile. To get started, data on the composition of the customer base and a list of the applied sanctions lists are enough — based on these inputs we will prepare configuration recommendations.

Get a consultation on screening configuration

Against Which Lists and Restrictions a Customer Is Reconciled

The set of lists for screening depends on the jurisdiction, license, and activity profile of the organization. Most AML solutions support parallel reconciliation against dozens and hundreds of sources. The main categories:

CategoryDescription
International sanctions listsThe consolidated list of the UN Security Council (UN Security Council Consolidated List) is mandatory for all UN member states. It includes persons and organizations connected to terrorism, the proliferation of weapons of mass destruction, and the violation of international resolutions. Updates are published as new resolutions are adopted or existing ones are revised.
National sanctions listsThe OFAC SDN List (Specially Designated Nationals and Blocked Persons, USA) is one of the most widely applied in global practice, since its effect extends to any transactions in US dollars and to operations involving persons subject to US jurisdiction. Besides the SDN, OFAC maintains additional lists (SSI, FSE, NS-CMIC, and others) for sectoral and thematic restrictions. The EU sanctions lists (EU Restrictive Measures) and the UK ones (HMT/OFSI) are similar in structure but have their own legal basis and differ in the composition of the listed persons.
The Russian regulatory frameworkIn Russia, sanctions screening obligations are regulated by Federal Law No. 115-FZ «On Countering the Legalization (Laundering) of Proceeds of Crime and the Financing of Terrorism». Organizations are obliged to reconcile customers against the Rosfinmonitoring list (persons involved in extremist activity and terrorism), as well as against lists compiled on the basis of UN Security Council decisions. After the publication of an updated list, no more than 20 hours are allotted for reconciliation — within this period the organization must check the customer base and, if matches are found, apply measures to freeze funds.
Lists of international organizationsA number of organizations — for example, the World Bank (World Bank Listing of Ineligible Firms and Individuals) — maintain lists of persons debarred from participating in the projects they finance. Reconciliation against them is relevant for companies working with international financing and government contracts.
Lists of higher-risk jurisdictionsFATF updates two lists three times a year: «High-Risk Jurisdictions Subject to a Call for Action» (jurisdictions for which countermeasures are recommended) and «Jurisdictions Under Increased Monitoring» (the so-called grey list). As of February 2026, the high-risk jurisdictions include the DPRK, Iran, and Myanmar. At the FATF plenary session in February 2026, Kuwait and Papua New Guinea were added to the grey list. A customer’s affiliation with a jurisdiction from these lists automatically raises their risk profile and may require enhanced due diligence measures.

In addition to the above, depending on the industry and geography of the business, the national lists of other countries, lists of terrorist organizations, embargo databases, and export restrictions are connected. Professional AML platforms make it possible to flexibly configure the set of sources: to connect or disconnect lists, set priorities, and set the update frequency.

How Potential Matches Are Verified and False Positives Are Filtered Out

Image

Automatic screening is the first stage, generating alerts. Next comes the match verification process — a combination of algorithmic filtering and expert analysis.

Algorithmic filtering. Fuzzy matching by name is the main generator of alerts and at the same time the main source of false positives. The reasons: common surnames, matches during transliteration (for example, the name «Muhammad» can be written in more than 30 ways in Latin script), partial matches with organization names. Several approaches are used to reduce the noise:

— Context enrichment: the system reconciles not only the name but also the date of birth, citizenship, address, document identification numbers. Each additional attribute that matches or does not match a record in a sanctions list substantially changes the probability of a true match.

— Tuning matching thresholds: too low a threshold (for example, 70% string similarity) produces a mass of irrelevant alerts, too high a one (99%) risks missing a real match with an altered spelling. The optimal threshold is selected individually for the profile of the customer base and calibrated based on testing results.

— Whitelists: for customers who have already passed manual review and been confirmed as a «non-match», the system remembers the decision and does not generate a repeat alert at the next scan on the same grounds.

Manual verification. Alerts not filtered out automatically are passed to a compliance analyst. The analyst studies the customer’s full profile, the context of the operation, reconciles the biographical data with the record in the sanctions list, and makes a decision: a confirmed match (true positive), a false positive, or an indeterminate result requiring escalation. Each decision is recorded in the case-management system with justification and a link to specific identifiers — this is critically important for audit and regulatory inspections.

A working paper of the US Federal Reserve Board of Governors (FEDS Working Paper No. 2025-092, Allen & Hatfield, September 2025) showed that applying language models (LLMs) in a cascaded architecture — where simple cases are handled by fuzzy-matching algorithms and ambiguous ones are escalated to the model — makes it possible to reduce the number of false positives by 92% while simultaneously increasing detectability by 11% compared with the best classical algorithms. The results are still experimental: the speed of an LLM is four orders of magnitude lower than that of classical methods, which limits its application in real-time mode. Nevertheless, the study points to the direction of the industry’s development: hybrid architectures combining deterministic rules and machine learning, with cascaded routing by the level of uncertainty.

What Happens After a Confirmed Match

If a compliance analyst or the system confirms that the customer indeed matches a record in a sanctions list, a chain of mandatory actions is launched. The specific set of measures depends on the jurisdiction and the type of sanctions regime, but the general logic is universal.

Immediate freezing of funds and blocking of operations. The organization is obliged to freeze all the customer’s assets without prior notice. In the US jurisdiction, per OFAC rules (31 CFR §§ 501.603–501.604), the blocked funds are placed in an interest-bearing account, and a report of the blocking is sent to OFAC within 10 business days. For Russian organizations, Federal Law 115-FZ provides for the immediate freezing of funds with subsequent notification of Rosfinmonitoring. In the EU, similar requirements are established by regulations on the implementation of restrictive measures.

Notifying the regulator. In addition to the freezing report, in many jurisdictions the organization is obliged to file a suspicious activity report (SAR, or its local equivalent). In Russia this is a report on an operation subject to mandatory control or on a suspicious operation — through the Rosfinmonitoring personal account.

Denial of service. If a match is identified at the onboarding stage, the customer is not admitted to service. If a match is discovered for an existing customer (for example, after a sanctions list is updated), the organization ceases service and restricts access to accounts and services within the applicable sanctions regime.

Documentation and audit. All decisions, the data on which they are based, and the chronology of actions are recorded in the case-management system. A full audit trail — from the moment of the alert to the final decision — is a mandatory element of the compliance program. During an inspection, regulators assess not only the fact of screening but also the quality of the investigation: on what data the decision was made, how long the processing took, who approved the result.

Interaction with the customer. A customer whose funds are blocked has the right to turn to the regulator or an authorized body for clarification and, if there are grounds, for obtaining a license to unblock or for delisting. The organization, as a rule, notifies the customer of the fact of the freeze but does not disclose the details of the internal investigation.

Speed of response is critical. In a number of jurisdictions, the wording «without delay» is interpreted as immediate action, and a delay of even a few hours can be qualified as a violation. Therefore, automating screening and alert routing is a basic requirement for the AML loop of any organization dealing with financial operations.

How PEP Checks Work After Customer Identification

Sanctions screening and PEP checks after customer identification solve different tasks, although they are often performed within a single AML pipeline. Sanctions screening determines whether a person or organization is under direct restrictions. PEP screening identifies the elevated risk of corruption, abuse of authority, and money laundering associated with public power.

A Politically Exposed Person (PEP) is a person who is or has been entrusted with prominent public functions. FATF, in Recommendations 12 and 22, defines a PEP through potential vulnerability to corruption rather than through a presumption of guilt.

PEP status by itself does not mean unlawful activity — it means that the level of control must be higher than standard, proportional to the real risk.

In Russian legislation, an analogous category is enshrined in Federal Law 115-FZ under the term «public official» (PDL). The law obliges financial monitoring entities to identify PDLs among customers, their representatives, beneficiaries, and beneficial owners. Russian legislation distinguishes three groups: foreign public officials (IPDL), officials of public international organizations (DLPMO), and Russian public officials (RPDL). For IPDL and DLPMO, the requirements are traditionally stricter — in particular, determining the sources of the origin of funds is mandatory.

A PEP check after customer verification uses the same data that was extracted at the identification stage: full name (including transliterations and spelling variants), date of birth, citizenship, country of residence. The system reconciles them against PEP profile databases and lists of officials. The AML module of the NEUROVISION software package conducts such a check automatically within the compliance loop, in parallel with sanctions screening, and returns the result as a structured report indicating the type of PEP status, the level of match, and associated persons.

Who Is Checked for PEP Status Along with the Customer

Image

PEP screening is not limited to the customer themselves. The FATF Recommendations and the requirements of Federal Law 115-FZ extend the check to three additional categories of persons.

The first is close relatives of a PEP. In Russian legislation, these include spouses, children, parents, brothers and sisters (including half-siblings), adoptive parents and adopted children, grandfathers, grandmothers, and grandchildren. EU Regulation 2024/1624 (AMLR) expands the concept of «family member» for certain categories of PEPs: for heads of state, heads of government, ministers, and their deputies, brothers and sisters are also included as family members. For companies with an international customer base, differences between jurisdictions in the definition of PEP relatives require attention when configuring screening.

The second is close business partners and associated persons (close associates). These are people connected to the PEP through joint business, beneficial ownership of assets, or other financial interests. This also includes persons acting as nominal owners of assets that actually belong to the PEP.

The third is the beneficial owners of a customer that is a legal entity. If the ultimate beneficiary of a company is a PEP, enhanced measures are applied to the entire business relationship with this company, not just to the individual.

It is precisely the depth of coverage that makes a PEP check technically more complex than sanctions screening. Sanctions lists contain specific persons and organizations. PEP databases must additionally map connections: family, business, corporate. The quality of PEP screening directly depends on the completeness and relevance of the connection graph in the sources used. When performing a check, the AML module of the NEUROVISION software package uses data from more than 1,700 databases and sources with daily updates, which makes it possible to track not only direct matches but also affiliated persons.

Example: if during a KYB check it is established that the beneficial owner of a counterparty is the spouse of a sitting member of the national parliament, the company is obliged to apply enhanced measures to this business relationship — regardless of whether the member of parliament themselves undergoes any checks.

How the Level of PEP Risk and the Need for Enhanced Due Diligence Are Assessed

Not all PEPs carry the same level of risk. FATF directly recommends a risk-based approach: calibrating the depth of control to specific circumstances rather than applying a single template to all officials.

Factors determining the level of PEP risk:

The type of PEP status. Foreign PEPs are by default assigned to a higher risk category in most jurisdictions. For national PEPs, in a number of countries, including the EU, enhanced due diligence (EDD) is also mandatory, but the depth of control may vary depending on the position and level of authority.

The level of the position and the scope of authority. A head of state or a finance minister represents a fundamentally different level of corruption vulnerability than a municipal deputy. PEP scoring systems take this into account through hierarchical models that assign a higher weight to positions with direct access to budget funds, government procurement, or regulatory decisions.

Country context. A PEP from a jurisdiction with a high level of corruption (per Transparency International indices, FATF data on jurisdictions of increased attention) carries greater risk than an official of a similar rank from a country with stable anti-corruption institutions. As of February 2026, FATF classifies Iran, the DPRK, and Myanmar as jurisdictions with serious strategic deficiencies, and it also maintains an expanded grey list of countries under increased monitoring.

The recency of the status. A former PEP remains an object of increased attention. FATF does not establish a fixed period after which PEP status ceases to apply — the decision is made on the basis of an individual risk assessment. EU Regulation 2024/1624 establishes a minimum EDD period of 12 months after leaving office. In practice, many organizations maintain enhanced control for 12–24 months, and for positions with high authority — longer.

The nature of the business relationship. A one-time currency conversion and a long-term loan for a large amount require different depths of verification. The volume and frequency of operations, the declared purpose of the relationship, and its correspondence to the PEP’s activity profile are factors that influence the final assessment.

Based on the totality of these factors, the system assigns the PEP record a risk level. For customers with elevated PEP risk, the EDD procedure is launched: in-depth verification of the sources of income and property, senior management approval, a shortened profile-review cycle, and enhanced monitoring of operations. The decision to accept for service, continue the relationship, or refuse is made taking into account all factors and recorded in case management with a full history of actions — for the audit trail and reporting to the regulator.

PEP status is a trigger for enhanced control, not a stop factor. Automatic denial of service solely on the basis of PEP status contradicts the FATF Recommendations and may be regarded as unjustified de-risking. The task of the compliance system is to ensure an adequate level of verification and monitoring, not to exclude an entire category of customers from service.

Build PEP checks accounting for connections and the recency of status

Refusing a customer solely on the basis of PEP status creates reputational and regulatory risks, while insufficient depth of verification means missing affiliated persons and hidden beneficiaries. The task is to calibrate control to specific circumstances: the type of position, the jurisdiction, the recency of authority, and the circle of associated persons. The AML module of the NEUROVISION software package performs PEP screening automatically, in parallel with sanctions reconciliation, using more than 1,700 databases with daily updates, and returns a structured report with the type of PEP status, the level of match, and a list of associated persons.

We will assess your current approach to PEP checks, determine which categories of connections and jurisdictions require enhanced attention, and propose a configuration of screening rules with escalation thresholds and a review frequency. To begin work, a description of the customer base and the current internal procedures is enough.

Submit a request for PEP screening configuration

How a Risk Profile Is Assigned to a Customer After Identification

Sanctions screening and PEP checks answer the question «does the customer have direct restrictions or a special status». Risk profiling sets a broader task: to determine the aggregate level of threat that a business relationship with this customer may pose from the standpoint of money laundering, terrorism financing, and other financial crimes. It is precisely the risk profile that sets the scale of further measures — from the depth of verification to the frequency of monitoring and operation limits.

The process is built on the risk-based approach (RBA), enshrined in FATF Recommendation 1: the higher the assessed risk, the stricter the control; the lower it is, the simpler the procedures. Russian legislation, through Federal Law 115-FZ and the regulations of the Bank of Russia, implements the same principle: every financial monitoring entity is obliged to have an internal methodology for assessing the customer’s degree of risk, recorded in the internal control rules (ICR). The European directives (AMLD) and the EBA guidelines impose similar requirements on EU institutions.

Technically, the risk profile is formed automatically on the basis of the data obtained during identification and the screening results. The system aggregates the factors, assigns each a weighted score according to the internal model, and outputs the final assessment: low, medium, or high risk level. Some organizations use a more granular scale with a numerical score and intermediate gradations, but the three-level classification remains the base one. In Russian regulation, the Bank of Russia applies a «traffic light» system (green, yellow, red), distributing legal entities and sole proprietors into risk groups on the basis of its own criteria and data from credit organizations.

If incomplete information was extracted at the identification stage or document recognition produced errors, the scoring model will receive a distorted signal. The accuracy of AI-OCR, face verification, and the correctness of data matching directly affect the adequacy of the final risk assessment.

Which Factors, Besides Sanctions and PEP, Are Part of the Risk Profile

Sanctions status and PEP affiliation are strong but far from the only parameters. A comprehensive risk-profiling model takes into account several categories of factors.

Customer factors — the characteristics of the customer themselves and their activity. For an individual, this is citizenship, country of residence, occupation, source of income and origin of funds, age, the presence of criminal records, bankruptcies, debts under enforcement proceedings (Federal Bailiff Service), self-employed status, or connections with legal entities. For a legal entity — the organizational and legal form, industry, ownership structure, data on founders and ultimate beneficiaries (UBO), the age of the company, financial indicators, and affiliation with other organizations. A customer from a high-risk industry — gambling, cryptocurrencies, arms trading, the jewelry sector — will, all other things being equal, receive a higher score.

Geographic factors — country risk. The jurisdictions of registration and business operations, citizenship, and tax residency are taken into account. The reference points are the FATF lists (jurisdictions under increased monitoring and high-risk jurisdictions), Transparency International assessments, and national lists of high-risk countries compiled by the regulator. A customer with business interests in a jurisdiction from the FATF grey list will receive an additional risk score even in the absence of other red flags.

Product-and-channel factors — which product or service is requested and through which channel. Remote onboarding without physical contact is assessed as more risky compared with in-person. Products involving cross-border transfers, cash handling, or anonymous instruments raise the risk score. The use of complex corporate structures or nominee schemes to open an account is a separate factor.

Transactional factors — the expected nature of operations. At the onboarding stage, the customer usually declares the expected volume and direction of payments. If the declared profile of operations does not correspond to the type of activity, the scale of the business, or the market average, the model records an anomaly. Subsequently, during continuous monitoring, actual transactions are compared with the declared ones — discrepancies can initiate a profile review.

Data from external sources — checks against databases and registries beyond sanctions and PEP. Information about tax debts, court proceedings, bankruptcy registries, Ministry of Internal Affairs wanted databases, registries of disqualified persons, data on the connections of individuals with organizations noted in suspicious operations. In Russian practice, the Bank of Russia daily distributes to credit organizations updated risk groups of legal entities and sole proprietors along with typologies of suspicious operations, which directly affects the profile review.

Each organization independently determines the set of factors and their weighting coefficients — depending on the specifics of the business, the customer base, and the requirements of the regulator. A bank working with international transfers gives greater weight to geographic factors. A microfinance organization issuing short-term loans emphasizes credit history and trustworthiness scoring. The model is always calibrated to the specific context.

How Adverse Media and Reputational Signals Change the Risk Level

Image

Adverse media (a negative media background) is publicly available information indicating a person’s possible connection to unlawful or dubious activity: fraud, corruption, tax evasion, participation in organized crime, terrorism financing, violation of the sanctions regime. The sources are news agencies, business media, court registries, publications of regulators and anti-corruption agencies, and in some cases — verified data from open internet sources.

FATF recommends including an adverse media check in the customer due diligence (CDD) and enhanced due diligence (EDD) program as an element of the risk-based approach. EU Regulation 2024/1624 (AMLR) and AMLD6, which is due to apply from July 2027, emphasize continuous monitoring of negative publications. BaFin in Germany, the FCA in the UK, MAS in Singapore — all these regulators directly point to the need to take media information into account when assessing risk. In Russian practice, checking reputational signals is part of internal financial-monitoring procedures and is usually enshrined in the ICR.

The fundamental value of adverse media is its ability to identify risks before they are formalized. A person may be involved in an investigation but not yet appear in any sanctions list and not have PEP status. Media publications record this intermediate zone earlier than official registries and give a signal for preventive action.

Adverse media screening works as follows. The system performs an automatic search by the customer’s name (and its spelling variants) in the negative news database. The results undergo filtering: NLP-based algorithms determine the relevance of the found material, weed out namesakes and irrelevant mentions, and classify the type of negativity by category (financial crimes, corruption, terrorism, organized crime, fraud, environmental violations, and others). Each category is assigned a weighting coefficient depending on the severity of the threat.

If the screening identifies a confirmed negative media background, the system automatically raises the customer’s risk level. The degree of increase depends on several variables: the severity of the accusations, the recency of the publications, the authority of the source, the presence of confirmation from several independent sources, the current status of the case (the investigation is ongoing, a verdict has been rendered, the charges have been dropped). A single publication in a little-known outlet without confirmation will receive less weight than a series of materials in leading business media, backed by court documents.

The flip side of the process is false positives. Name matches, outdated publications, and unverified sources are capable of generating false alerts. Therefore, a high-quality adverse media system includes verification mechanisms: filtering by date, relevance, geography, source type, as well as the ability for an analyst to conduct a manual review with the decision and justification recorded in case management. The balance between the sensitivity of the system and the level of false positives determines the operational efficiency of the screening.

How the Risk Profile Affects the Decision and the Depth of Control

The assigned risk profile is not a reference label but a control parameter. It determines the set of measures the organization is obliged to apply to the customer throughout the entire lifecycle of the relationship.

Low risk — standard customer due diligence (CDD) procedures. The organization has the right to apply simplified measures: a reduced set of requested documents, automatic approval without manual verification, a standard frequency of profile review (as a rule, once a year or less often). Restrictions on operations are minimal, and monitoring works in the basic mode.

Medium risk — enhanced attention. The CDD procedures are performed in full, operations are tracked with increased frequency, and the frequency of profile updates is reduced. Depending on the internal rules, additional confirmation of the source of funds or approval at the level of a department head may be required.

High risk — mandatory enhanced due diligence (EDD). This is an extended set of measures: in-depth verification of the source of the origin of funds and wealth, detailed analysis of the beneficial ownership chain, additional checks against external databases, obtaining approval from senior management to establish or continue the business relationship. Transaction monitoring is configured with lowered trigger thresholds. The frequency of profile review is reduced to six months (a requirement of a Rosfinmonitoring information letter for Russian entities under Federal Law 115-FZ) or more often — depending on the organization’s policy.

A high risk level is not equivalent to denial of service. Legislation and the FATF Recommendations point to the need for proportional measures rather than automatic termination of the relationship. Refusal without sufficient grounds (de-risking) is itself regarded by regulators as a problem: it pushes customers into the shadow sector, reduces the transparency of the financial system, and contradicts the goals of financial inclusion. The organization has the right to refuse service, but the decision must be substantiated by specific factors, documented, and backed by the analysis conducted.

The risk profile also determines the routing within the compliance platform. A low-risk customer passes onboarding automatically — the system makes the decision without operator involvement. Medium risk may be routed to an analyst for review only in the presence of additional flags. High risk almost always requires manual case review with mandatory recording in the audit log: who checked, what decision was made, on the basis of what data.

Automating this process is one of the factors of scalability. With manual risk-profile assignment, an analyst spends from a few minutes to several hours on a single case. An automatic scoring model integrated with data sources and the case-management system reduces the time to seconds for standard cases and frees up the compliance team’s resources for work on complex and high-risk scenarios. When choosing a compliance platform, it is worth assessing not only the coverage of sources but also the flexibility of configuring the scoring model, the quality of false-positive filtering, and the completeness of the audit trail — it is precisely these parameters that determine the practical effectiveness of risk profiling.

Automate risk-profile assignment and case routing

Manual risk-profile assignment takes from a few minutes to several hours per case, and incomplete information from OCR or failures of biometric verification distort the final assessment before the analyst even begins the analysis. The NEUROVISION software package forms the risk profile automatically: AI-OCR with accuracy up to 99.85% and face verification with 99.74% accuracy ensure the quality of the input data, while the scoring model aggregates customer, geographic, and product factors into a final assessment with routing — automatic approval at low risk, escalation to an analyst at medium risk, mandatory manual review at high risk.

We will analyze your risk assessment methodology and propose a configuration of weighting coefficients for the specifics of your customer base and regulatory requirements. Deployment is possible in the cloud or within the secure perimeter of your infrastructure with a 99.99% availability SLA.

Request a risk-profiling automation estimate

How Ongoing Monitoring Works After Customer Identification

Image

Onboarding records the state of the customer at a specific moment: the documents are valid, there are no sanctions matches, the risk profile is calculated. A week later, the situation may change — the customer will end up on a sanctions list, receive PEP status, or become a subject in a criminal case. If the organization does not track such events, its compliance loop stops reflecting reality.

Ongoing monitoring is a mechanism that maintains the relevance of all the checks performed during identification throughout the entire period of the business relationship with the customer. It covers three directions: repeat sanctions screening when lists are updated, tracking changes in PEP status, and reviewing the risk profile when new factors appear. FATF, in Recommendation 10, directly states that CDD is not a one-time action but a continuous process that includes monitoring operations and the timely updating of customer data. Federal Law 115-FZ enshrines a similar requirement: organizations are obliged to update information on customers and beneficiaries at least once a year, and if doubts arise about its reliability — immediately.

Continuous monitoring is implemented in two modes. The first is event-driven: the system automatically reacts to specific triggers, such as a sanctions list update or the arrival of a negative publication. The second is periodic: a scheduled review of the file and risk profile at a frequency determined by the customer’s current risk level. High-risk customers, including PEPs and persons from jurisdictions under FATF increased monitoring, are checked more often — once a quarter or every six months. For low-risk customers, an annual review is sufficient. The trend of recent years is a shift to the perpetual KYC (pKYC) model, in which periodic reviews are replaced by continuous updating of the profile based on streaming data.

Which Changes Trigger Repeat Sanctions Screening, PEP Checks, and Risk-Profile Review

The triggers of continuous monitoring are divided into external and internal. External ones do not depend on the customer’s actions — they are generated by changes in the regulatory and information environment. Internal ones are related to the customer’s behavior and changes in their profile.

The main external triggers:

— Sanctions list updates. When OFAC, the EU, the UN, HMT/OFSI, Rosfinmonitoring, or another regulator adds, changes, or removes entries, the system automatically reconciles the entire customer base against the updated version of the list. The frequency of synchronization is critically important: reliable compliance platforms are updated daily, and for the most volatile lists (OFAC SDN, the Rosfinmonitoring list) — within a few hours of the publication of changes.

— A change in PEP status. Appointment to a public position, leaving a post, a change of jurisdiction, the appearance of new associated persons — each of these events can change the PEP risk category. The data sources are official registries, structured PEP databases, and media monitoring.

— The appearance of adverse media. The publication in the media or court registries of information about a customer’s involvement in corruption, fraud, criminal prosecution, bankruptcy, or other reputationally significant events triggers a reassessment of the risk level. Modern monitoring systems use NLP algorithms to automatically analyze publications and filter out irrelevant mentions.

— Changes in regulatory lists of jurisdictions. The inclusion of a country in the FATF «under increased monitoring» list or in the list of high-risk jurisdictions directly affects the assessment of the geographic risk of customers connected to that country. At the FATF plenary session in February 2026, Kuwait and Papua New Guinea were added to the grey list — customers with business connections in these jurisdictions automatically receive an elevated level of geographic risk.

The main internal triggers:

— Uncharacteristic transactional activity. A sharp rise in turnover, the appearance of cross-border transfers to higher-risk jurisdictions, breaking up operations into amounts below the mandatory-control thresholds (structuring), atypical counterparties — any significant deviation from expected behavior forms an alert.

— A change in questionnaire data. A change of citizenship, registration address, beneficial owner, the organizational structure of the company, the type of activity. For legal entities, a change of UBO or director also serves as a trigger.

— A request for a new product or service channel. The transition from a standard settlement account to international transfers, connecting cryptocurrency services, opening an account in another jurisdiction — each of these steps changes the product and channel component of the risk profile.

— The expiration of documents. A passport or other identification document that has expired requires repeat verification. Without updating the documentary base, further service may violate KYC requirements.

When any trigger fires, the system does not limit itself to a single check. A sanctions list update launches a repeat screening, but if a potential match is discovered in the process, both the risk profile as a whole and the need to apply EDD are reviewed. The triggers act in a cascade: one event can activate a chain of checks across several directions simultaneously.

Launch continuous monitoring with cascading triggers

Cascading check logic — when a sanctions list update launches a repeat screening, and a discovered match reviews both the PEP status and the risk profile — requires a platform capable of processing chains without delays and manual intervention at each link. The AML module of the NEUROVISION software package updates key sources daily and automatically reconciles the customer base at every change of lists, reducing the manual load on the compliance team by up to 80%. Case management — from alert to final decision — is conducted with a full audit trail: check cards, comments, a history of actions, and the generation of reporting for the regulator.

We will review your current monitoring process, determine which triggers and sources need to be connected first, and configure the rules for escalation and automatic closure of irrelevant alerts. Integration of the AML loop via API takes one to two days, after which you will be able to track changes in customer statuses in real time.

Submit a request to connect monitoring

How Alerts, Cases, and the History of Changes Are Handled

Each trigger generates an alert — a signal requiring assessment. Alert management is one of the most resource-intensive tasks of compliance: as the customer base scales, the number of triggers grows quickly, and a significant share of them turns out to be false positive. In classic rule-based systems, the share of false positives reaches 90–95% (per PwC and industry analysts’ estimates). Platforms using ML models and context scoring reduce this figure by 40–50%, freeing up analysts’ resources for work on confirmed risks.

Handling an alert goes through several stages. At the first stage, the system automatically assesses the significance of the signal — determines whether it requires manual review or can be closed by pre-configured rules.

A typical example of automatic closure is a name match with a sanctioned person with a complete divergence of all additional identifiers (date of birth, country, INN).

If an alert is deemed significant, it is escalated into a case — a structured unit of investigation. The case contains all the relevant information: customer data, the history of previous checks, a description of the trigger, the results of automatic reconciliations, and the system’s recommendations. An analyst of the compliance unit studies the case, requests additional documents from the customer if necessary, and makes one of the decisions: close the case as a false positive, adjust the risk profile, apply enhanced due diligence, restrict operations, or send a suspicious activity report (SAR/STR) to the authorized body — Rosfinmonitoring in the Russian Federation, FinCEN in the USA, the relevant FIU in EU countries.

Each action is recorded in the audit log. During inspections, regulators assess not only the presence of a monitoring system but also the quality of documentation: who made the decision, on the basis of what data, within what deadlines. FATF, in the fifth round of mutual evaluations (2024–2027), emphasizes demonstrable effectiveness — an organization must demonstrate not only the presence of controls but also their practical operability. A complete history of risk-profile changes, cases, and decisions made forms the evidence base necessary for passing audits and regulatory inspections.

On the technical side, alert and case management is implemented through a case-management module integrated with the other components of the compliance loop. The NEUROVISION software package, within the AML module, provides such a loop: continuous customer monitoring with notifications when a status changes, case management with check cards, comments, and a history of actions, and the generation of reporting for the regulator. With daily updating of sources and a claimed reduction of the manual load by up to 80% through the automation of screening and case management, the platform enables the compliance team to focus on the substantive analysis of confirmed risks rather than on reviewing an array of false positives.

Conclusion
Why sanctions screening, PEP checks, and risk profiling work only as a single continuous loop

Sanctions screening, PEP checks, and risk-profile assignment solve different tasks but become effective only in a common linkage — from the completeness of the data passed at the identification stage to the cascading triggers of continuous monitoring that maintain the relevance of each decision throughout the entire period of the business relationship.

The quality of this chain is determined by how precisely each subsequent stage uses the results of the previous one: normalized customer attributes reduce the share of false positives during screening, the connection graph expands the coverage of the PEP check to relatives and business partners, and the totality of customer, geographic, product, and reputational factors forms a risk profile proportional to the real threat.

A break in any link — incomplete data from KYC, the absence of regular profile review, a delay in updating sanctions lists — turns the compliance loop into a formality and creates blind spots that regulators record during inspections and participants in illegal schemes exploit in practice. Organizations that build this process as a closed loop with automatic alert routing, transparent case management, and a full audit trail gain not only protection from fines but also an operational advantage: the compliance team’s resources are directed at analyzing confirmed risks rather than at manually reviewing irrelevant matches.