Where sanctioned party screening breaks
Screening usually breaks where data changes hands. Partner records arrive incomplete, possible matches wait in a queue with no clear owner, and transactions slip through before a hit is cleared. Delay mostly comes from false positives worked by hand. Risk mostly comes from records nobody rescreened after a list update.
Partner data too thin to screen
The screening engine can only compare what it is given. Sales or procurement teams create the customer or vendor record. They often enter a trading name with no legal name, no country, no address line and no registration number. A name alone produces a flood of weak matches. A name with a typo produces none at all.
The fix gets pushed back upstream. A compliance analyst emails the requester for more detail, waits, then screens again. That loop is the single biggest source of rework in most teams.
How to tell: count how often analysts reopen a record to ask for missing fields. Look at whether the onboarding form makes those fields mandatory or merely suggests them. Check for records where the country field holds a placeholder value.
The match queue with no owner
A potential hit leaves the system and lands in a shared mailbox or a work queue. Then it stalls. Legal thinks compliance owns it. Compliance thinks the business owner should confirm the counterparty's identity. Nobody has authority to close it.
False positives make this worse. When most alerts turn out to be common names, analysts start skimming. The real hit then looks exactly like the noise around it.
How to tell: pull the oldest open alerts and ask who is working each one. If the answer is vague, ownership is broken. Read a sample of closure notes too. A note that only says "not a match" with no reason recorded will not survive an audit.
Release before clearance
This is where screening meets the payment run. A vendor passes screening at onboarding, gets paid for months, and then a list update flags it. The hold should stop the next payment. In many setups it does not, because the block sits in the trade compliance tool and the payables system never reads it.
The same gap appears with shipments. A warehouse releases goods against a sales order while the customer's alert is still open. Foreign payments carry extra exposure. The beneficiary bank and any intermediary bank need screening as well as the payee, and those fields are often captured only at the moment of payment.
How to tell: compare the list of blocked parties with recent payment and shipping history. Any transaction to a party under review is a control failure. Ask payables staff what a failed validation hold looks like on their screen, and whether a sanctions block shows up the same way.
Lists that change after approval
Screening done once at onboarding goes stale. Lists are amended constantly, and ownership structures shift underneath a counterparty without any change to its own name. Teams that rescreen only on new records miss all of this.
Some rescreen the full master file on a schedule but suppress previously cleared names. That suppression can hide a genuine new designation that happens to match an old false positive.
How to tell: find out when the master data was last rescreened in full. Ask how suppressed or whitelisted names get reviewed, and by whom. Check whether ownership and control checks exist at all, or whether only the direct party name is ever tested.
Workarounds that quietly become the process
When the official route is slow, people build their own. A buyer creates a one time vendor to avoid the onboarding queue. An analyst lowers the match threshold to clear a backlog. Someone keeps a spreadsheet of "known good" names and approves anything on it without looking.
Each of these feels sensible in the moment. Together they mean the documented control no longer describes what actually happens.
How to tell: look for spikes in one time or sundry vendor use. Review the change log on screening settings. Ask to see any local lists kept outside the system.
Questions to ask the people who run it
The written procedure rarely matches the daily routine. These questions tend to surface the difference.
- What do analysts do when a record arrives with only a name?
- Who can close an alert, and who actually closes most of them?
- Has anyone ever been told to release a payment or shipment while a review was still open?
- When was the last time a cleared name turned into a real hit?
- Which alerts get skipped or batch closed when the queue is long?
- Where do the payables and logistics teams see a sanctions block, if anywhere?
- Are there names that never get screened because they are considered safe?
- What changed in the screening settings recently, and who approved it?
- How does a list update reach existing vendors and customers?
Listen for hesitation and for answers that start with "normally". Those usually point straight at the workaround.
Sources
APQC's Process Classification Framework® (PCF) is an open standard developed by APQC, a nonprofit that promotes benchmarking and best practices worldwide. To download the full PCF or to view definitions and measures, please visit www.apqc.org/pcf.