PAYMENTS SIGNAL REFERENCE ARCHITECTURE · SYNTHETIC / TRAINING ONLY
Sanctions screening, list ingestion, matching, alert, investigation, tuning, and governance architecture
Trace how current sanctions data becomes a controlled screening decision, a reviewable alert, and evidence that tuning did not silently remove coverage.
Payments Signal reference architecture v1 · reviewed 2026-07-23
Reference architecture—not a scheme mandate. This architecture teaches the control chain from authoritative list through policy, matching, hold, investigation, decision, and assurance. It does not prescribe legal scope, list combinations, matching mathematics, threshold, auto-disposition, release authority, record retention, or reporting duties.
Components
Official lists and regulatory obligations
Provides authoritative sanctions designations, changes, identifiers, programmes, and legal context.
- Kind
- external-network
- Owner
- Sanctions authorities and compliance legal team
- Responsibilities
- Obtain current authoritative list data
- Interpret programme and jurisdiction scope before configuring controls
- Inputs
- Authorised business instruction and correlated state
- Outputs
- Versioned result, status, and audit evidence
- Controls
- Source authenticity
- Publication timestamp
- Jurisdiction and programme scope
- Failure modes
- Source unavailable
- Malformed update
- Legal scope misunderstood
- Recovery
- Retain the last verified version
- Escalate legal ambiguity before release decisions
- Non-functional requirements
- Durable correlation through stable business and technical identifiers
- Capacity and availability matched to the service-level objective
- Auditable state changes, configuration, and operator actions
List ingestion, quality, and publishing hub
Normalises authoritative records while retaining source lineage, effective time, identifiers, scripts, and change history.
- Kind
- data-store
- Owner
- Sanctions data management
- Responsibilities
- Validate and version every list update
- Publish a complete, signed screening snapshot
- Inputs
- Authorised business instruction and correlated state
- Outputs
- Versioned result, status, and audit evidence
- Controls
- Completeness totals
- Schema and identifier checks
- Dual approval
- Rollback point
- Failure modes
- Partial list published
- Duplicate identity merged incorrectly
- Transliteration lost
- Recovery
- Stop publication
- Restore the last approved snapshot
- Correct and republish with audit history
- Non-functional requirements
- Durable correlation through stable business and technical identifiers
- Capacity and availability matched to the service-level objective
- Auditable state changes, configuration, and operator actions
Screening policy and field-coverage map
Defines who and what is screened, at which lifecycle points, from which message fields, under which jurisdictional and product rules.
- Kind
- control
- Owner
- Sanctions compliance governance
- Responsibilities
- Map every in-scope field to a screening attribute
- Name timing, hold, rescreen, and release policy
- Inputs
- Authorised business instruction and correlated state
- Outputs
- Versioned result, status, and audit evidence
- Controls
- Approved scope
- Message-version coverage
- No silent field omission
- Change impact assessment
- Failure modes
- New message field not screened
- Wrong jurisdiction profile
- Released payment not rescreened after material change
- Recovery
- Hold affected traffic
- Correct the coverage map and replay controlled test cases
- Non-functional requirements
- Durable correlation through stable business and technical identifiers
- Capacity and availability matched to the service-level objective
- Auditable state changes, configuration, and operator actions
Matching and screening engine
Compares normalised party, bank, geography, vessel, goods, and narrative data with the approved list snapshot and policy.
- Kind
- service
- Owner
- Screening platform engineering
- Responsibilities
- Apply deterministic normalisation and matching
- Return candidates with score, matched fields, list version, and policy version
- Inputs
- Authorised business instruction and correlated state
- Outputs
- Versioned result, status, and audit evidence
- Controls
- Authenticated configuration
- List and policy version
- Deterministic replay
- Capacity and latency limits
- Failure modes
- Engine unavailable
- Configuration drift
- False negative from parsing or threshold
- Recovery
- Hold or route under approved continuity policy
- Replay from retained input and versions
- Non-functional requirements
- Durable correlation through stable business and technical identifiers
- Capacity and availability matched to the service-level objective
- Auditable state changes, configuration, and operator actions
Payment hold and release gate
Prevents the payment from advancing while an in-scope screening result is unresolved.
- Kind
- control
- Owner
- Payment operations and sanctions control
- Responsibilities
- Bind every screening result to the exact payment version
- Release, reject, block, or escalate only with authorised evidence
- Inputs
- Authorised business instruction and correlated state
- Outputs
- Versioned result, status, and audit evidence
- Controls
- Fail-closed or approved continuity posture
- No self-release
- State and amount integrity
- Failure modes
- Payment advances before screening
- Release applied to changed payment
- Duplicate release
- Recovery
- Stop downstream processing
- Re-screen changed data
- Use maker-checker release
- Non-functional requirements
- Durable correlation through stable business and technical identifiers
- Capacity and availability matched to the service-level objective
- Auditable state changes, configuration, and operator actions
Alert queue and case service
Creates one reviewable case with candidate, payment, party, list, policy, and matching evidence.
- Kind
- application
- Owner
- Sanctions operations
- Responsibilities
- Deduplicate related candidates without hiding evidence
- Prioritise by documented risk and deadline
- Inputs
- Authorised business instruction and correlated state
- Outputs
- Versioned result, status, and audit evidence
- Controls
- Queue completeness
- Stable case key
- No unsupported auto-close
- Failure modes
- Alert lost
- Duplicate cases obscure ownership
- Priority starvation
- Recovery
- Rebuild from immutable screening outcomes
- Assign and age every open case
- Non-functional requirements
- Durable correlation through stable business and technical identifiers
- Capacity and availability matched to the service-level objective
- Auditable state changes, configuration, and operator actions
Investigation and disposition
Compares reliable identifiers, ownership, context, and source evidence before recording a reasoned decision.
- Kind
- operations
- Owner
- Sanctions investigators and escalation teams
- Responsibilities
- Eliminate or confirm using specific evidence
- Escalate unresolved ownership, control, and legal questions
- Inputs
- Authorised business instruction and correlated state
- Outputs
- Versioned result, status, and audit evidence
- Controls
- Four-eyes release where required
- Evidence citation
- Conflict and authority controls
- Failure modes
- Generic disposition
- True match released
- Personal data copied outside the case
- Recovery
- Reopen and contain
- Escalate to compliance and legal
- Correct downstream reporting and payment action
- Non-functional requirements
- Durable correlation through stable business and technical identifiers
- Capacity and availability matched to the service-level objective
- Auditable state changes, configuration, and operator actions
Tuning, testing, governance, and audit
Measures performance above and below thresholds, approves changes, samples decisions, and proves that coverage remains effective.
- Kind
- operations
- Owner
- Sanctions governance, quality assurance, model risk, and internal audit
- Responsibilities
- Test known positives, variants, and near misses
- Approve and monitor list, parser, rule, and threshold changes
- Inputs
- Authorised business instruction and correlated state
- Outputs
- Versioned result, status, and audit evidence
- Controls
- Independent validation
- Below-threshold testing
- Change rollback
- Management information
- Failure modes
- Threshold suppresses true matches
- Test data does not represent production formats
- Change deployed without approval
- Recovery
- Restore the last approved configuration
- Rescreen affected records
- Investigate control failure and report where required
- Non-functional requirements
- Durable correlation through stable business and technical identifiers
- Capacity and availability matched to the service-level objective
- Auditable state changes, configuration, and operator actions
Interfaces
Authoritative list update
sanctions-sources → sanctions-list-hub
Ingest a signed or otherwise authenticated source publication.
- Contract
- file · batch
- Controls
- Authentication and authorisation
- Integrity and replay protection
- Correlation and audit evidence
- Failure treatment
- Do not publish a partial or unverifiable update.
Approved list snapshot
sanctions-list-hub → sanctions-engine
Publish a complete versioned screening snapshot.
- Contract
- file · batch
- Controls
- Authentication and authorisation
- Integrity and replay protection
- Correlation and audit evidence
- Failure treatment
- Keep the previous approved snapshot active until the new one is proven complete.
Policy and field map
sanctions-policy → sanctions-engine
Apply the approved scope, fields, timing, rules, and thresholds.
- Contract
- control · synchronous
- Controls
- Authentication and authorisation
- Integrity and replay protection
- Correlation and audit evidence
- Failure treatment
- Reject unknown message versions or route them to a controlled hold.
Payment screening request
sanctions-payment-gate → sanctions-engine
Screen the exact payment and party version before release.
- Contract
- message · synchronous
- Controls
- Authentication and authorisation
- Integrity and replay protection
- Correlation and audit evidence
- Failure treatment
- Hold under policy when no conclusive result is available.
Screening outcome
sanctions-engine → sanctions-payment-gate
Return clear, alert, unavailable, or error with versions and correlation.
- Contract
- control · synchronous
- Controls
- Authentication and authorisation
- Integrity and replay protection
- Correlation and audit evidence
- Failure treatment
- Never turn timeout or error into clear.
Candidate alert
sanctions-engine → sanctions-alerts
Create a durable case for every reviewable candidate.
- Contract
- event · asynchronous
- Controls
- Authentication and authorisation
- Integrity and replay protection
- Correlation and audit evidence
- Failure treatment
- Replay safely from retained outcomes after queue failure.
Investigation assignment
sanctions-alerts → sanctions-investigation
Assign complete candidate and payment evidence.
- Contract
- operator · operator
- Controls
- Authentication and authorisation
- Integrity and replay protection
- Correlation and audit evidence
- Failure treatment
- Escalate ageing and missing evidence.
Authorised disposition
sanctions-investigation → sanctions-payment-gate
Release, reject, block, or escalate the exact held version.
- Contract
- control · operator
- Controls
- Authentication and authorisation
- Integrity and replay protection
- Correlation and audit evidence
- Failure treatment
- Reject a disposition from an unauthorised role or for changed data.
Approved configuration change
sanctions-assurance → sanctions-policy
Publish tested rule, parser, and threshold changes.
- Contract
- control · operator
- Controls
- Authentication and authorisation
- Integrity and replay protection
- Correlation and audit evidence
- Failure treatment
- Rollback changes that fail production or below-threshold monitoring.
Outcome and performance evidence
sanctions-engine → sanctions-assurance
Measure coverage, latency, alert volume, and threshold behaviour.
- Contract
- event · asynchronous
- Controls
- Authentication and authorisation
- Integrity and replay protection
- Correlation and audit evidence
- Failure treatment
- Keep sensitive data minimised and access controlled.