Aggregation and provenance
Most banks screen against an aggregated watchlist built from many official lists — convenient, powerful, and a new layer of risk to govern.
IN ONE LINE
An everyday analogy: instead of checking visitors against four separate stacks of posters, the gatekeeper works from a single binder into which someone has merged all the stacks — plus a few in-house posters the building has added from its own experience.
The binder is far more convenient, but it introduces new questions.
Was every poster copied in correctly? When the same person appears in two stacks, were the copies merged well — or were two different people accidentally merged into one? And when a source stack changes, how quickly does the binder catch up? The binder is the watchlist, and its quality is now part of the gate's quality.
WHAT IT ACTUALLY IS
A watchlist is the combined dataset a screening system actually runs against.
It typically merges: the official sanctions lists the institution must obey; additional lists chosen for risk reasons; and internal lists — parties the institution itself has decided to flag or exit.
Many banks buy the aggregation from commercial data vendors, who collect issuer files, normalise them into one schema, deduplicate overlapping records, and enrich entries with extra identifiers.
Aggregation adds real value — one format, one feed, cross-references between issuers — but it inserts a processing layer between the legal source and the screening engine, and every layer can introduce delay, mapping errors, or merge mistakes.
Provenance — knowing which official entry a watchlist record came from — is what keeps the layer honest.
HOW IT WORKS
Practitioners govern the aggregation layer like any critical supplier.
Latency is measured per source list: the vendor's processing time adds to the issuer-to-live gap, and contractual update commitments are checked against observed reality.
Coverage is reconciled: periodic comparisons between the watchlist and the official lists it claims to contain, catching dropped or mangled records.
Merge quality is sampled, since over-merging can hide an alias under the wrong identity and under-merging inflates alert volume.
Internal lists need their own governance — criteria for adding a name, an owner, and a review cycle — because an unmanaged internal list grows forever and nobody remembers why half its entries exist.
However good the vendor, the regulatory obligation stays with the institution.
THE WORDS
- Watchlist
- Any list of names a bank screens against — sanctions lists plus other data such as PEP registers, adverse media, or internal lists.
READ FIRST
CONNECTED TO
SOURCES
- Wolfsberg Group Sanctions Screening Guidance — The Wolfsberg Group
- Payments Signal editorial teaching models — Payments Signal
Derived from Aggregation and provenance. Every claim on this card is sourced on that page.