Book a Discovery Call

A Comprehensive Guide to Testing and Auditing

Identifying and Avoiding Blind Spots in Screening Systems

Dear compliance and risk professionals

Cedric Iggiotti
Cedric Iggiotti

VP of Screening Product

In the digital and instant payments era, effective customer screening is essential not only for maintaining compliance but also enhancing the customer experience. A streamlined onboarding process can reduce friction and drive growth.

However, recent setbacks faced by well-known financial institutions have highlighted the serious consequences of inadequate AML screening practices — including sanctions, watchlists and enhanced due diligence. These failures can result in regulatory constraints that limit growth until organizations can demonstrate improved compliance measures.

This white paper is designed to support compliance officers, AML managers, and screening teams by providing practical insights. At ThetaRay we subscribe to rigorous testing with the delivery of our solutions, recognizing that many emerging financial organizations may lack the resources to manage these processes in-house.

That’s why we offer this guide for conducting ongoing audits and testing of screening systems. Our goal is to help banks and fintechs build a smart and future-proof screening framework that supports rapid growth while effectively addressing compliance challenges.

01
Executive Summary

A comprehensive screening testing and auditing framework is required to ensure efficient operations and continuous improvement. This white paper outlines the 6 key system testing areas that organizations should focus on to achieve effective screening and maintain compliance in an ever-changing regulatory landscape.

  • 01

    Data Integration Flow Testing involves verifying the accuracy, completeness, and timeliness of the data flowing between an organization’s core systems and its sanctions screening system.

    This testing ensures that the data transfer process between the core and watchlist systems is clean, complete, and properly formatted, and that the system can accurately and efficiently process the data. The alert processing workflow should be thoroughly tested based on all possible business scenarios, simulating both true and false alerts to verify that the workflow functions properly from end-to-end. By performing these tests, investigators can ensure the workflow as expected and that the screening system effectively identifies potential risks.

  • 02

    Unit Testing ensures that each component of the system works as intended.

    It involves verifying that the sanctions lists are activated, the matching engine is effective, the data is up to date, the response generated is correct, and the overall algorithm configuration works as expected. Thorough unit testing of a screening system is necessary to ensure its effectiveness and compliance with regulatory requirements. Failure to verify match effectiveness, to ensure data freshness, and to properly configure screening algorithms can result in compliance program breakdown.

  • 03

    Effectiveness Testing is essential to minimize the risk of false negatives that can result in severe damage to an organization’s legal and reputational status.

    This involves testing name-matching and geo-matching rules to ensure satisfactory performance on a large volume of names and high-risk locations, including variations such as misspellings, typos, and permutations. Practical recommendations include creating a list of all possible variations, using a mix of exact and fuzzy matches, including diverse naming conventions and high-risk locations. The system’s ability to handle variations in structured and free-format fields must be tested. By following these recommendations, organizations can make necessary adjustments to their configuration and ensure that their screening system works effectively.

  • 04

    Efficiency Testing is crucial to reduce false positives while maintaining effectiveness.

    To accurately evaluate the efficiency of a system, it is essential to use representative data to estimate the hit rate. Statistical techniques can be applied to identify significant variables, or “big hitters,” and make targeted adjustments to the screening configuration. A/B testing is also used to fine-tune the configuration and strike a balance between efficiency and effectiveness. The objective is to achieve a low hit rate based on available resources while maintaining the highest level of effectiveness possible. To optimize accuracy and effectiveness, the screening system should offer a high degree of configurability and be complemented by human expertise. Technology vendors should be prepared to support complex implementations.

  • 05

    Performance Testing helps to evaluate a system’s ability to function under expected workload conditions.

    Defining performance criteria, preparing representative data, and evaluating latency and throughput are important steps in this process. Adjustments to the screening engine infrastructure and technical optimizations, such as optimizing thread usage, can be implemented to improve performance. Load testing and capacity planning exercises should refine these optimizations to ensure the system can handle anticipated workloads. Collaboration between site reliability engineers and technical experts is crucial to identify and implement appropriate optimizations for network latency. Overall, performance testing ensures the system functions efficiently and effectively, meeting defined performance criteria.

  • 06

    Continuous Testing involves regularly reviewing all testing areas and reassessing the testing framework as risk exposure evolves over time.

    Continuous testing is critical for maintaining a system’s functionality over time. To achieve this, several recommendations should be considered, including regression testing, automation, adaptability, risk reassessment, and documentation. Regression testing ensures that the system remains functional even after changes have been made. Automation can help to reduce the risk of human error during the testing process. Adaptability is essential for responding to rapidly changing circumstances and ensuring that the system remains effective. Risk reassessment should take into account changes in the regulatory environment that may affect the system’s configuration and performance. Documentation is necessary to demonstrate compliance with regulatory requirements.

Having a reliable and efficient watchlist screening system is crucial for organizations in today’s global landscape. Through various testing methodologies, organizations can ensure that their screening system is effective, accurate, and efficient. It is important to approach screening as an ongoing process requiring continuous improvement, regular testing, and the adaption to changing circumstances. By following the recommendations provided in this white paper, organizations can enhance their screening system’s capabilities, reduce their exposure to risk, and ensure compliance with regulatory requirements. Investing in a comprehensive watchlist screening system is not only a legal obligation but also a strategic decision that can help organizations build trust with their stakeholders and demonstrate their commitment to ethical business practices.

02
Introduction

Watchlist screening is essential to organizations’ compliance programs, as the consequences of noncompliance can be severe. Failure to comply with regulations can result in hefty fines, reputational damage, and even legal action. However, effective screening goes beyond merely ticking boxes on a compliance checklist. A comprehensive testing and auditing framework is required to ensure the system operates effectively and efficiently. This white paper outlines the key system testing areas that organizations should focus on to achieve effective screening and maintain compliance in an ever-changing regulatory landscape.

Firstly, it is imperative to recognize that watchlist screening cannot follow a ‘one-size=fits-all’ approach. The adequacy of a compliance program will depend on various factors, including the type of business involved, its size and complexity, the products and services offered, the customers and counterparties, and the geographic locations served. Organizations are encouraged to employ a risk-based approach to watchlist compliance by developing, implementing, and regularly updating a screening program that takes into consideration the following risk factors:

1

Geographic Risk
This involves assessing the risk level associated with a country or region where the organization operates or engages in transactions. High-risk countries may include those that are known to support terrorism or have a high level of corruption.

2

Product/Service Risk
Certain products or services may be more susceptible to misuse or diversion for sanctioned activities. Organizations need to evaluate the level of risk associated with the products or services they offer and the potential for use in sanctioned transactions.

3

Customer Risk
The risk level associated with the customers of the organization is an essential factor to consider. This includes the customers’ geographic location, industry, and other factors that may increase their risk of engaging in sanctioned transactions.

4

Transaction Risk
The type and value of transactions processed by the organization can also pose a risk of violating sanctions. Organizations need to assess the risk of specific transactions and take steps to mitigate any potential sanctions risk.

5

Screening System Risk
The effectiveness of the screening system itself is also a critical factor to consider. The screening system should be evaluated to ensure that it accurately identifies potential sanctions risks and that the appropriate actions are taken when potential risks are identified.

6

Third Party Risk
Organizations may also engage with third parties, such as suppliers or agents, that pose a risk of violating sanctions. Businesses need to assess the risk associated with these third parties and take steps to ensure compliance with sanctions requirements.

 

By considering all these risk factors, organizations can design a risk-based watchlist compliance program that accurately identifies potential sanctions risks and effectively tests and audits the screening system’s ability to detect such risks.

As appropriate, the risk assessment will be updated to account for the root causes of any apparent violations or systemic deficiencies identified by the organization during business as usual. The organization is responsible for enhancing its program, including all program-related software, systems, and other technology, to remediate any identified compliance gaps.

This paper aims to provide guidance on testing and auditing screening systems across multiple essential components, thus avoiding blind spots that could lead to sanctions violations, reputational damages, enforcement actions, and financial loss.

03
Data Integration Flow Testing

Data serves as the backbone of information systems, providing essential support for compliance and risk management. Just as a strong backbone ensures stability, maintaining the integrity of data is crucial for effective operations. Data integration flow testing verifies the accuracy, completeness, and timeliness of the information exchanged between an organization’s core systems and its screening system.

The core systems typically generate or store data used to screen for sanctions risks, such as customer onboarding and relationship management systems (CRM), payment processing platforms, and other data sources containing information about the supply chain, intermediaries, counterparties, commercial and financial documents, and transactions. This information is utilized in the watchlist screening process to prevent violations. Data integration flow testing ensures that the data transfer process between the core and screening systems is clean, complete, and properly formatted. It also verifies that the screening system can accurately and efficiently process the data, which is crucial for effective sanctions compliance.

The information used for screening may include the following elements at onboarding, periodic reviews, and when processing customer transactions:

Individuals Entities Transactions
  • Legal name
  • Date of birth
  • Place of birth
  • Physical address
  • Email address
  • Nationality
  • IP addresses associated with transactions and logins
  • Bank information, and
  • Government identification and residency documents
  • Entity name (trading and legal name)
  • Line of business
  • Ownership information
  • Physical address
  • Email address
  • Location information
  • IP addresses associated with transactions and logins
  • Information about where the entity does business
  • Bank information
  • Any relevant government documents
  • Originator name and address
  • Beneficiary name and address
  • Originating and beneficiary institutions’ names and identifiers
  • Correspondent and intermediary institutions’ names and identifiers
  • Virtual currency addresses
  • Underlying transactional data (e.g., remittance information, sender-to-receiver information)

When conducting data integration flow testing, it is imperative to review fields that can be a source of friction given the free format nature of the information (e.g., free format names and addresses) or potential mismatches between data types (e.g., address information matching against names).

Understanding the type and nature of the fields flowing between the core and the watchlist screening systems is also crucial to determine what type of screening logic can be applied to these data elements:

  • Fuzzy matching for all free format information
  • Exact matching for structured identifiers (e.g., ISO country codes, BICs, LEIs)

This screening logic should equally focus on matching names of listed persons AND prohibited locations (e.g., countries or geographic regions subject to trade-based restrictions or embargoes). Similarly, data integration flow testing should be performed to verify the accuracy, completeness, and timeliness of the information flowing from the watchlists to the screening system. This testing should cover the following types of data:

Alert Processing Workflow

In case of one or several hits returned by the screening system, data integration flow testing should ensure that the information contained in the response message is fresh, complete, and unaltered. For each hit, the response may include the following information:

This information is essential to understand the nature of a hit to help operations distinguish a true match from a false match, and maintain an audit trail of all screening activities.

After receiving a response from the screening system (hit or no hit), ensure that the alert processing workflow is well integrated with the organization’s core systems and messaging queues. Testing that the workflow functions properly from end-to-end is crucial to guarantee seamless business operations.

Every step of the alert processing workflow should be thoroughly tested based on all possible business scenarios. Investigators can simulate both true and false alerts to verify that the workflow is functioning properly.

In the case of a false alert: investigators can deliberately input data that will trigger an alert, then verify that the alert is flagged and properly dismissed after further investigation. Additionally, investigators can input again the same data to test the whitelisting functions of the screening system. This test ensures that the system correctly identifies false positives and minimizes unnecessary alerts.

In the case of a true alert: investigators can input data that will trigger an alert, then follow the workflow to verify that the alert is properly escalated and investigated until a resolution is reached. This test ensures that the system correctly identifies true positives and that alerts are promptly and effectively addressed.

By performing both types of tests, investigators ensure that the alert processing workflow is working as expected and that the screening system is effectively identifying potential risks. Ultimately, based on their decisions, investigators can verify that the outcomes of the workflow are properly transferred to the organization’s core systems and that any pending message is moved to the right queue.

High-Level Screening Flow

The diagram below provides an overview of the flow of a screening request

04
Unit Testing

Unit testing ensures that each component of the system works as intended. It involves verifying that the various algorithms, configurations, and data sources that make up the system are functioning correctly. This chapter outlines the key aspects of unit testing for a screening system, including activating and matching sanctions lists, data freshness, response verification, and algorithm configuration.

By performing thorough unit testing, organizations can ensure that their screening system is accurate, efficient, and effective at identifying potential risks.



Activation of Sanctions Lists
It is important to verify that all configured sanctions lists are activated and applied correctly during the screening process. This ensures that potentially risky individuals or entities do not slip through the screening process.

Match Effectiveness
The unit testing process should verify that the screening engine effectively matches individuals, entities, or identifiers (e.g., BIC, LEI, or government identification numbers) against the configured sanctions lists. Testing should be performed for exact and fuzzy matches to identify all possible matches on all data elements (including names, addresses and identifiers), configured lists and entity types. Testing how the screening system should respond to low-quality aliases and identifiers on sanctions lists is also important.

Data Currency
It is essential to ensure that the watchlist list data is up-to-date and that the latest updates are incorporated into the screening system. This helps to minimize the risk of missing any newly added sanctioned individuals or entities.

Failure to verify match effectiveness, to ensure data currency, and to properly configure screening algorithms can result in compliance program breakdowns, as seen in past OFAC administrative actions.



Response Verification
The unit testing process should include verification of the response generated when a match is detected by the screening engine. This includes ensuring that all relevant list data is correctly returned to the core system and that it is properly visible in the alert presented to the investigators.

Algorithm Configuration
Ensuring that the screening algorithms are properly configured is essential to minimizing false positives and false negatives. Unit testing should verify that the overall configuration of the screening algorithms works as expected. This includes testing the name-matching thresholds and the sensitivity of any configured date matching, geo-matching and identifier-matching algorithms. The effect of any configured synonyms (i.e., alternative spellings, nicknames, and diminutives), stopwords (i.e., terms that add no meaning to names and can be discarded from name matching), prefixes, and suffixes (i.e., terms placed “before” or “after” a name such as titles, honorifics, qualifiers, or legal forms of companies) should also be carefully considered when designing unit tests.

Thorough unit testing of a screening system is necessary to ensure its effectiveness and compliance with regulatory requirements. Failure to verify match effectiveness, ensure data freshness, and properly configure screening algorithms can lead to breakdowns in a compliance program. This has been highlighted in past OFAC administrative actions where organizations have, at times, failed to update their screening software with the latest SDN or SSI List updates, neglected to include pertinent identifiers like SWIFT BICs for designated, blocked, or sanctioned financial institutions, or overlooked for alternative spellings of sanctioned countries or parties — especially in regions where such variations are common (i.e., Habana for Havana, Kuba instead for Cuba, Soudan for Sudan, etc.)”

05
Effectiveness Testing

Effectiveness testing helps reduce the risk of false negatives, where the system fails to identify potential risks such as sanctioned individuals or entities. This can lead to legal, reputational, financial, and regulatory consequences for the organization. This section will explore the different aspects of effectiveness testing and provide practical recommendations to ensure the screening system works effectively.

Testing Name-Matching Rules
An important aspect of effectiveness testing is verifying that the name-matching rules perform well when applied to a large volume of names, accounting for all potential variations and alterations while also aligning with the organization’s risk tolerance. This includes concatenations, initialized names, permutations, misspellings, and typos. A thorough name-matching effectiveness test should cover both exact and fuzzy matches to ensure that the screening system can identify potential risks accurately. Here are some practical recommendations for testing name-matching rules:

Example: John Smith can be spelled as “Jon Smyth”, “J. Smith”, “John Smythe”, “Jonh Smith”, and “John Smth”. An effective screening system should be able to match all these variations to the same individual and flag potential risks accurately.

The screening logic should prioritize matching the names of listed persons and prohibited locations equally configured, including different variations of high-risk countries and place names.


Testing Geo-Matching Rules

Another aspect of effectiveness testing is to ensure that the geo-matching rules are satisfactory. The screening logic should prioritize matching the names of listed persons and prohibited locations equally. The system should be able to match high-risk locations according to the settings configured, including different variations of high-risk countries and place names.

Here are some practical recommendations for testing geo-matching rules:

  • Test the system’s ability to handle variations in both structured and free format fields.
  • Use a mix of exact and fuzzy matches to test the system’s ability to match high-risk locations accurately.
  • Ensure that the geo-matching rules work as expected on the list of prohibited locations (countries, cities, and regions) established by the organization.
  • Create a list of high-risk countries and place names based on all possible variations and alterations, including different spellings, country codes, name concatenations, and abbreviations (e.g., “Jalta, Krimea” instead of “Yalta, Crimea” etc.).
  • For transaction screening, test the system ability to match addresses, including physical, digital wallet, and IP addresses, and other relevant information with potential links to sanctioned persons or jurisdictions.

Example: A high-risk country such as Iran can be spelled as “Iran”, “Islamic Republic of Iran”, or “IR”. An effective screening system should be able to match all these variations to the same country and flag potential risks accurately.

By following the practical recommendations for geo-matching, organizations can apply appropriate amendments to their configuration and ensure that their screening system works effectively.

06
Efficiency Testing

Unlike effectiveness testing, which aims to reduce the risk of false negatives, efficiency testing focuses on minimizing the risk of false positives. This section provides guidelines for evaluating the efficiency of a screening system.

Data Preparation
To conduct efficient testing, it is necessary to use representative data that accurately reflects live screening environment The data used should be significant enough to end up with a representative hit rate, and the larger the data volume, the more accurate the hit rate will be. It is recommended to use data that is representative of production data on one or several typical days of operations or during a peak period. Additionally, the data should cover a broad range of scenarios and include potential false positive cases.

Hit Rate Estimation
The hit rate is the metric used to evaluate the system’s efficiency. A low hit rate is desirable as it means that fewer false positives are generated while maintaining an acceptable level of effectiveness. A high hit rate may generate too many false positives, leading to unnecessary work for analysts and delays in processing. The objective of efficiency testing is to evaluate whether the screening configuration can produce a low hit rate. To achieve this, it is necessary to estimate the hit rate using the representative data prepared in the first step. The hit rate estimation process should be rigorous and comprehensive as it forms the basis for evaluating the efficiency of the screening configuration.

Identifying Big Hitters
Once the hit rate has been estimated, the next step is to identify the significant variables, known as “big hitters,” that contribute the most to the hit rate. These big hitters can be identified using statistical techniques like correlation analysis. Identifying the big hitters makes it possible to determine which variables and screening rules significantly impact the hit rate and make targeted adjustments to the screening configuration.

Without efficiency, effectiveness is just a pipe dream.


Iterating through A/B Testing
To achieve the appropriate balance between efficiency and effectiveness, it is necessary to fine-tune the screening configuration through iterative A/B testing. In the context of testing the efficiency of sanctions screening systems, A/B testing involves making adjustments to the screening configuration and comparing the performance of the adjusted configuration to the original configuration. It is essential to review the system’s effectiveness and efficiency together following any changes to the screening configuration. The objective is to achieve a low hit rate while maintaining an acceptable level of effectiveness and minimizing the risk of false positives.

Optimizing Effectiveness and Efficiency
Size the hit rate according to the available resources for analyzing the alerts produced by the system. The hit rate should be set in a way that ensures the compliance team can manage and review the flagged cases within the given timeframe and with the available resources. To obtain the desired outcome, a flexible technology with a high level of configurability and control is fundamental. This means that the screening system should offer a wide range of granular options, rules, and algorithms that can be customized to the specific needs and risk appetite of the organization.

Technology should be complemented by human expertise to optimize the accuracy and effectiveness of the screening system. Technology partner assistance should be readily available to organizations, particularly when faced with complex screening implementations that require specialized skills to fully utilize the potential of the technology.

Compliance teams should feel empowered by a technology that can screen information in a way that reflects their thought processes, considering all the nuances and complexities that the human brain is capable of. This is were AI and machine learning can make a big difference.
07
Performance Testing

The primary focus of performance testing is to evaluate the system’s ability to perform under expected workload conditions. By conducting performance testing, we can ensure that the screening system can handle a high volume of transactions in real-time, without experiencing latency or throughput issues that could negatively impact its stability or efficiency.

Defining Performance Criteria
Defining performance criteria should be completed during the business requirement definition phase of the project. The customer and the vendor can collaborate to establish exact performance criteria, such as P99 latency (the amount of time it takes for 99% of requests to be processed successfully), that the screening system must meet. This alignment between performance expectations and technical optimizations ensures that the screening system delivers the required performance.

Data Preparation
Using representative data to simulate the expected workload ensures that the screening system is tested under realistic conditions. To achieve this, it is important to use data that is based on the expected peak period for the system, as this is when it will be most heavily utilized.

Latency and Throughput Testing
During performance testing, two key metrics to evaluate are latency and throughput. Latency measures the time it takes for the system to complete a transaction, from initiation to final processing. In contrast, throughput tracks the volume of transactions the system can handle within a specific time frame. Together, these metrics provide a clear picture of how efficiently the system performs, both in terms of response time and its ability to process large volumes of transactions.

Optimization should be refined through load testing and capacity planning exercises to ensure that the screening system can handle the anticipated workload with optimal performance.


Performance Optimizations
Once performance testing is complete, adjusting the screening engine infrastructure may be necessary to meet the required performance criteria. This can involve either vertical or horizontal scaling. Vertical scaling increases the resources of a single server, while horizontal scaling adds more servers to the existing infrastructure.

In addition to adjusting the infrastructure, there are several technical optimizations that can be implemented to improve the performance of the screening system. One such optimization is thread usage. Threads are a fundamental concept in computer programming and refer to the smallest sequence of instructions that a scheduler can manage independently.

Optimizing thread usage is typically done on the screening system, as it involves managing the number of threads the screening engine uses to process incoming messages. However, optimizing performance may also involve adjustments to the core system that exchanges messages with the screening system.

Other potential optimizations include adjusting the number of messages sent and processed in parallel and utilizing caching mechanisms to alleviate the system’s workload. These optimizations should be refined through load testing and capacity planning exercises to ensure that the screening system can handle the anticipated workload with optimal performance.

Additionally, network latency can significantly impact the overall system performance, and therefore site reliability engineers and technical experts should collaborate to identify and implement appropriate optimizations when needed.

By thoroughly testing the system’s latency and throughput using representative data and adjusting infrastructure resources and performance optimizations as necessary, the system can be optimized to meet defined performance criteria.

08
Continuous Testing

To maintain the effectiveness of a sanctions screening system, it is important to conduct continuous testing. This involves regularly reviewing all testing areas covered in the previous sections and reassessing the testing and auditing framework as the organization’s risk exposure evolves over time. The following recommendations provide practical guidance for continuous testing.

Regression Testing
Regression testing involves regularly conducting tests in a pre-production environment, particularly when your screening vendor releases a new version of the software. This ensures that the system continues to function correctly after any changes are made. Adopting a zero-trust approach to test the impact of any change affecting your screening environment. Once initial tests are satisfactory, take a snapshot of the configuration and reuse all test plans to create a baseline for regression testing.

Adaptability
It is important to have all the necessary tools and resources to adapt to rapidly changing circumstances in the sanctions landscape. Maintain active and continuous contacts with partners, vendors, industry peers, and interest groups to reduce vulnerabilities and understand current threats. Learn from public enforcement actions to identify any weaknesses and deficiencies, then enrich, update and amend your testing and auditing framework to close any loopholes.

Adopt a zero-trust approach and test the impact of any change affecting your screening environment.



Risk Reassessment
The baseline of your testing and auditing framework should be reassessed as your organization’s risk exposure evolves over time. This reassessment should consider factors such as new products and services, new client segments, or new geographies of operations. The risk assessment should also consider any changes in the regulatory environment, such as new sanctions programs or changes to existing programs.

Documentation
Documentation of all test results and maintenance of a record of all changes made to the screening system is important. This documentation can be used to demonstrate history of all changes made, compliance with regulatory requirements and provide evidence of due diligence. The documentation should be regularly reviewed and updated to reflect any testing and auditing framework changes.

09
Travelex Bank Deploys ThetaRay Screening to Drive Growth

Executive Summary
Travelex is the world’s largest exchange business specialist, with a presence in more than 20 countries. In Brazil, the Group consists of the brokerage Travelex Confidence and Travelex Bank, the first exclusive bank for foreign exchange transactions regulated by the Banco Central do Brasil (Bacen). Travelex Bank offers a range of international money transfer products including import/export, remittances, and mass payments.

Project Scope
In a highly regulated country like Brazil, assessing money laundering risks is a serious concern for money-transfer companies. The day-to-day business involvement of the central bank requires Travelex to check and pre-check all clients, and all transactions, to meet increasingly stringent regulations.

Travelex sought support with the detection of suspected money laundering and watchlist screening and sanctions risk violations.

Client Objectives
Travelex was seeking to deploy a robust AI solution delivering effective and efficient watchlist screening.

Travelex’s main concerns included:

  • Finding a more efficient and technologically advanced solution to support a risk-based approach to anti money laundering (AML).
  • Enabling and protecting a large and growing volume of transactions with an AI transaction monitoring solution that was robust enough to run at high speed and ensure seamless customer service.
  • Deployment of a reliable and efficient sanction screening software able to handle all data and scale of global operations.
  • Introduction of a low impact solution that would not cause friction to customers – and ensure ease of integration with existing AML programs.
  • Integration with a system that would automate and alert on all sanction flags to ensure compliance with continuously changing global sanctions lists in all jurisdictions of operations.

Results

“Using ThetaRay, we can now grow our business by 30-40%.”
Celia Pizzi
Chief Compliance Officer, Travelex

 

30,000 clients per minute

Proof of Concept (POC)
The POC was completed in only 3 days and Travelex was able to process 30,000 clients per minute.

Fast implementation
The full implementation was completed in 3 weeks, compared to eight months for other solutions.

False positives decline by 10x
Alerts plummeted from a high of 3,000 to 4,000 to mere hundreds of high quality alerts.

Alert quality
Travelex noted that the quality of the alerts was far superior and the compliance team was empowered with increased capacity to support growing transactions.

“We are talking about almost 80 features going into the project. I’ve been in this market for 10 years. That was the fastest integration that I’ve ever seen.”
Edson dos Santos Almeida Jr.
AML Data Manager, Travelex
10
Conclusion

A comprehensive screening system that effectively manages risks and maintains compliance is critical for organizations operating in today’s global landscape. Organizations can ensure that their screening system is reliable, accurate, and efficient through the various testing methodologies outlined in this white paper, such as data integration flow testing, unit testing, effectiveness testing, efficiency testing, performance testing, and continuous testing.

The importance of having a robust screening system cannot be overstated, as failure to detect sanctioned entities can lead to severe consequences such as legal and financial repercussions, reputational damage, and loss of trust from customers and stakeholders.

Investing in a comprehensive screening system is not only a legal obligation but also a strategic decision that can help organizations build trust with their stakeholders and demonstrate their commitment to ethical business practices.



Therefore, it is essential to approach customer and transaction screening as ongoing processes that call for continuous improvement, regular testing, and adapting to changing circumstances. By following the recommendations provided in this white paper, organizations can enhance their screening system’s capabilities, reduce their exposure to risk, and ensure compliance with regulatory requirements.

Glossary of Terms

ISO: International Organization for Standardization
BIC: Bank Identifier Code
LEI: Legal Entity Identifier
OFAC: Office of Foreign Assets Control
SDN: Specially Designated Nationals and Blocked Persons List
SSI: Sectoral Sanctions Identification List