AML Scenario Gap Finder

Sanctions name screening

Which screening runs on which payment types, is it before the payment is released, and when were the lists and the fuzzy-match settings last tested?

A scenario that places here

example

"Sanctions name screening on outgoing wires (daily batch)"

Read this scenario

Channels it applies to

8 of the 20 in the dictionary

ACH WDM WIN RTP P2P REM FXC COR

ACH and direct entry, domestic wires, international wires, real-time payments, person-to-person payments, remittance and money transfer, foreign exchange and correspondent accounts: one sector each on the coverage chart, hatched where no scenario reaches it.

Obligations

5 regimes
RegimeObligation
Bank Secrecy Act and its regulations (31 CFR Chapter X)BSA BSA-AML-14 OFAC Sanctions Screening
FATF 40 RecommendationsFATF R.10 Customer due diligence · FATF R.6 Targeted financial sanctions related to terrorism and terrorist financing
FATF Recommendation 16, payment transparency, by paragraphFATF R.16 R16-TFS Freezing action and prohibited transactions with designated persons in the payment chain
Anti-Money Laundering and Counter-Terrorism Financing Act (Australia)AUSTRAC AMLCTF-SANCTIONS Sanctions Screening
OFAC framework for sanctions compliance commitmentsOFAC OFAC-SCP-3.2 Transaction Interdiction and Blocking · OFAC USOFAC-3 Internal Controls (Screening, Interdiction, Recordkeeping)

The obligations, quoted

BSA BSA-AML-14 OFAC Sanctions Screening

Institutions shall screen customers, beneficial owners, counterparties and transactions against OFAC and other applicable sanctions lists in real time.

What an examiner asks to see: Screening engine config; List update cadence; Blocked/rejected transaction reports; OFAC annual reports
Where programmes usually fall short: List updates lag; No fuzzy matching tuning
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
FATF R.10 Customer due diligence

Financial institutions may not keep anonymous accounts or accounts in obviously fictitious names and must, by a principle set out in law, undertake customer due diligence when establishing a business relationship, carrying out an occasional transaction above USD or EUR 15,000 or a payment or value transfer covered by INR.16, when money laundering or terrorist financing is suspected, or when they doubt previously obtained identification data: identify and verify the customer from reliable independent sources; identify the beneficial owner and take reasonable measures to verify that identity, understanding the ownership and control structure of legal persons and arrangements; understand and where appropriate obtain information on the purpose and intended nature of the relationship; and conduct ongoing due diligence and transaction scrutiny consistent with the customer's profile including, where necessary, the source of funds. The extent of each measure follows a risk-based approach; verification takes place before or during establishment of the relationship, or as soon as reasonably practicable after it where risks are managed and business would otherwise be interrupted; an institution that cannot complete CDD does not open the account or perform the transaction, or terminates the relationship, and considers a suspicious transaction report; the requirements apply to new customers and, on materiality and risk, to existing ones. The Interpretive Note sets the risk-based approach, enhanced and simplified measures, the specific measures for legal persons, arrangements and beneficiaries of life insurance, reliance on prior verification and the timing rules.

What an examiner asks to see: CDD policy and procedures with triggers and thresholds; Customer files with identity, beneficial ownership, purpose and risk rating; Ongoing monitoring and periodic review records
Where programmes usually fall short: Beneficial owner identified but never verified; Ownership and control structure of corporate customers not understood
Source: FATF 40 Recommendations
FATF R.6 Targeted financial sanctions related to terrorism and terrorist financing

Countries implement targeted financial sanctions regimes giving effect to the UN Security Council resolutions on terrorism and terrorist financing, freezing without delay the funds and other assets of persons and entities designated by or under the authority of the Security Council under Chapter VII (resolution 1267 and successors) or designated by the country under resolution 1373, and ensuring that no funds or assets are made available to or for their benefit; the Interpretive Note sets the designation authorities and procedures, the freezing obligations without delay and without prior notice, the prohibitions, the communication of designations, the reporting duties of institutions, the delisting and unfreezing procedures and access to frozen funds for basic expenses.

What an examiner asks to see: Legal basis for freezing without delay; Designation and delisting procedures and the competent authority; Communication mechanism for designations to institutions and their reporting of frozen assets
Where programmes usually fall short: Freezing dependent on a court order that takes days; No domestic designation mechanism under resolution 1373
Source: FATF 40 Recommendations
FATF R.16 R16-TFS Freezing action and prohibited transactions with designated persons in the payment chain

In processing payments or value transfers, financial institutions take freezing action and do not conduct transactions with persons and entities designated under the UN Security Council resolutions on terrorism and terrorist financing (resolution 1267 and its successors and resolution 1373) and on the financing of proliferation of weapons of mass destruction; the Recommendation does not prescribe whether or how message information is screened against sanction lists, since different mechanisms can achieve compliance with targeted financial sanctions.

What an examiner asks to see: Sanctions screening design for payment messages; Freeze and rejection records; List update procedures
Where programmes usually fall short: Screening of originator only, never beneficiary; Designated parties processed because names were unstructured
Source: FATF Recommendation 16, payment transparency, by paragraph
AUSTRAC AMLCTF-SANCTIONS Sanctions Screening

Screen customers and transactions against DFAT consolidated list and UN sanctions to comply with autonomous sanctions.

What an examiner asks to see: Sanctions screening against DFAT consolidated list
Where programmes usually fall short: No sanctions screening
Source: Anti-Money Laundering and Counter-Terrorism Financing Act (Australia)
OFAC OFAC-SCP-3.2 Transaction Interdiction and Blocking

The organization must operate controls that block or reject transactions involving sanctioned persons or property and report blocked or rejected transactions to OFAC within required timeframes.

What an examiner asks to see: Blocking and rejection procedures; Evidence of blocked property segregation in interest-bearing accounts; Initial reports of blocked or rejected transactions filed within 10 business days; Annual report of blocked property filed by 30 September each year
Where programmes usually fall short: Rejected transactions not reported because firm treats them as declined business; Blocked funds held in non-interest-bearing accounts
Source: OFAC framework for sanctions compliance commitments
OFAC USOFAC-3 Internal Controls (Screening, Interdiction, Recordkeeping)

Per OFAC: Policies and Procedures + Transaction Screening + Interdiction and Escalation + Recordkeeping (5 years per OFAC).

What an examiner asks to see: evidence guidance not held for this clause
Where programmes usually fall short: Screening + testing + training partial
Source: OFAC framework for sanctions compliance commitments

Other typologies in sanctions screening and interdiction