Governance and policy
Screening is defensible only when someone owns it: written policy, a documented risk assessment, and change control over every setting.
IN ONE LINE
An everyday analogy: the gate works not because any guard is heroic but because the operation is owned.
There are written rules for how guards check and what they record; a named person is accountable for the whole gate; decisions about how strict to be are written down with their reasons; and nobody rewires a scanner without approval and a record of who changed what.
When something goes wrong — and eventually something does — the first questions are "who decided this?" and "where is it written?".
A gate that cannot answer those questions is treated as broken even on days it catches everyone, because nobody can show that its catches were design rather than luck.
WHAT IT ACTUALLY IS
Market practice describes a screening programme resting on four supports.
Policies and procedures define what is screened, against which lists, how often, and how alerts are adjudicated.
A responsible person carries accountability, with genuine expertise in both sanctions and the screening technology.
A documented risk assessment connects the institution's exposure to its control choices, so every configuration answers to an identified risk.
And internal controls with independent testing verify the machinery does what the documents claim.
The thread through all four is articulation: the institution should be able to state the specific sanctions risk each control addresses — including honest documentation of what the system cannot catch, because acknowledged limitations are managed while unacknowledged ones are simply blind spots.
HOW IT WORKS
Day to day, governance is a working rhythm rather than a binder.
A change forum approves filter modifications — thresholds, list scope, suppression rules — with evidence attached, so configuration drift cannot happen silently.
Management information flows to the accountable owner: alert volumes, backlog aging, disposition mix, list-update latency; a queue growing quietly for weeks is a governance failure before it becomes a compliance one.
Escalation paths to legal counsel and senior management are defined before the crisis that needs them.
Outsourcing complicates none of the accountability: a vendor may aggregate the watchlist and an offshore team may work alerts, but the regulatory obligation stays with the institution, so vendor oversight — coverage reconciliation, quality sampling, commitments checked against reality — is part of the programme, not a procurement afterthought.
THE WORDS
- Three lines of defence
- The standard split of control responsibility: the business that owns the risk, the compliance function that oversees it, and internal audit that tests both.
READ FIRST
CONNECTED TO
SOURCES
- Wolfsberg Group Sanctions Screening Guidance — The Wolfsberg Group
- Payments Signal editorial teaching models — Payments Signal
Derived from Governance and policy. Every claim on this card is sourced on that page.