customer screening · OFAC · sanctions
Fintech Customer Screening: OFAC, PEP & AML Checks
Fintech customer screening is the control that stops you from onboarding a sanctioned individual, a Politically Exposed Person you failed to escalate, or a fraudster who passed a selfie check but appears on a watchlist.
Regulators and banking partners ask the same question in every exam: show us the OFAC result for this customer on the day they signed up — and prove you rescreened when the list changed.
This guide explains how KYC OFAC AML checks fit together, which lists matter, how to handle false positives, and why screening must run continuously — not only at signup.
Customer screening in the AML stack
Think of screening as one layer in a stack:
| Layer | What it does | When it runs |
|---|---|---|
| KYC / CIP | Verifies identity | Onboarding |
| Customer screening | List & media checks | Onboarding + ongoing |
| Risk scoring | Tiers the customer | After screening |
| Transaction monitoring | Behavior analysis | Continuous |
| SAR filing | Reports suspicious activity | When triggered |
Screening answers: Is this person or entity on a list that prohibits or complicates the relationship? It does not replace customer due diligence or ongoing monitoring — it feeds both.
What gets screened: OFAC and global lists
OFAC (US Office of Foreign Assets Control)
OFAC administers US economic sanctions. Fintechs with US persons, US-dollar flows or US banking partners must screen against:
- SDN List — Specially Designated Nationals and Blocked Persons
- Consolidated sanctions programs — sectoral and country programs
- Non-SDN lists where applicable to your risk assessment
A confirmed OFAC match generally means block the relationship and follow OFAC reporting procedures. There is no "soft approve."
Beyond OFAC
A credible fintech customer screening program typically includes:
| List | Source | Why it matters |
|---|---|---|
| UN consolidated | United Nations | Global baseline, GAFI-aligned |
| EU consolidated | European Union | EU nexus customers and partners |
| UK HMT | HM Treasury | UK corridors and GBP products |
| PEP databases | Commercial / government | Enhanced due diligence trigger |
| Adverse media | News / NLP | Risks not yet on formal lists |
Neobanks operating in LATAM also screen against local lists (e.g., SENACLAFT, COAF, UAF). See our fintech compliance page for LATAM-specific coverage.
How a KYC OFAC AML check runs in practice
A typical automated flow for a retail neobank user:
- Collect identity data — name, DOB, nationality, document number
- Normalize — transliteration, alias handling, entity vs individual
- Screen in parallel — OFAC, UN, EU, PEP, adverse media
- Score the match — fuzzy logic + secondary identifiers
- Decision — auto-clear, auto-reject, or route to analyst queue
- Log — immutable record with list version and timestamp
- Rescreen — on list updates and profile changes
Target latency for standard retail: under two seconds for the screening call so onboarding does not stall.
Fuzzy matching and false positives
Exact string matching fails in the real world:
- Mohamed vs Muhammad
- Missing middle names on IDs
- Common names ("John Smith") generating noise
Fuzzy matching uses algorithms (phonetic, edit distance, token overlap) plus secondary filters (date of birth ±N years, country, ID number) to rank potential matches.
| Match strength | Typical action |
|---|---|
| Strong (name + DOB + country) | Block pending analyst review |
| Medium | Analyst queue, SLA 24h |
| Weak | Auto-clear with logged rationale |
Analysts must document why a hit was cleared. Examiners request these notes.
PEP screening: not just a list check
Politically Exposed Persons require identification even when they are not sanctioned. PEP status triggers:
- Enhanced due diligence
- Senior management approval
- Higher monitoring cadence
- Source-of-wealth documentation
Read our PEP guide for role definitions and controls.
Adverse media: screening beyond lists
Sanctions lists lag reality. Adverse media screening uses news and public records to surface fraud, corruption, trafficking or terrorism allegations before formal designation.
Use risk-based thresholds: auto-escalate HIGH categories; sample-review LOW noise. LLM-assisted summarization helps analysts but should not auto-approve without human review for material hits.
Ongoing screening vs. one-time checks
The most common exam finding: screening ran on day one, never again.
Ongoing sanctions screening means:
- Event-driven rescreen when OFAC publishes updates (often within 24 hours)
- Scheduled batch rescreen of the full customer base (daily/weekly by risk tier)
- Triggered rescreen on legal name change, nationality change or new beneficial owner
This is distinct from but complementary to transaction monitoring.
Neobanks compliance solutions for screening
When evaluating neobanks compliance solutions, ask vendors:
- Which lists are included and how fast are updates applied?
- Can we see the list version used for each historical screening?
- What is median false-positive rate for our demographic?
- Is there an API + analyst UI + audit export?
- Does rescreening run automatically without engineering tickets?
Fragmented stacks (IDV vendor + separate screening API + manual spreadsheets) create audit gaps. Unified platforms keep KYC, OFAC checks and disposition in one customer file.
See neobank compliance for program-level context or our fintech landing.
Operational checklist
- Screening blocks account activation until clear or approved
- List versions stored with each result
- Analyst queue with SLA and escalation
- PEP and adverse media policies documented
- Rescreening automated on OFAC updates
- Sample QA of cleared hits monthly
Conclusion
Fintech customer screening — OFAC, PEP and AML checks together — is non-negotiable for neobanks and payment fintechs. Done well, it is invisible to good customers and invisible-except-to-examiners for bad ones: sub-two-second checks, low false positives, continuous rescreening and audit trails that survive partner diligence.
Run OFAC and PEP screening in one platform
Legal Talent automates fintech customer screening with OFAC, UN, EU, PEP and adverse media — plus KYC onboarding and continuous monitoring.
Start free and screen your first customer in minutes.
Frequently asked questions
What is fintech customer screening?
Customer screening is the process of checking each user against sanctions lists (OFAC, UN, EU), PEP databases, adverse media and internal watchlists before account opening and on an ongoing basis.
What is a KYC OFAC AML check?
It is the combined workflow of verifying customer identity (KYC), screening against OFAC and other sanctions lists, and applying broader AML controls such as PEP identification, risk scoring and transaction monitoring.
When must OFAC screening run?
At onboarding before the customer transacts, when material customer data changes, and continuously when sanctions lists are updated. Many programs also rescreen the full customer base daily or on list publication events.
What lists should a fintech screen against?
At minimum OFAC SDN and consolidated programs, UN consolidated list, EU and UK HMT sanctions, plus a PEP database. Many firms add adverse media and local lists depending on markets served.
How do you reduce false positives in sanctions screening?
Use fuzzy matching tuned with date of birth, nationality and secondary identifiers; apply risk-based thresholds; and maintain an analyst queue with documented disposition for each potential match.
Is customer screening the same as transaction monitoring?
No. Customer screening evaluates the person or entity against static lists. Transaction monitoring analyzes payment behavior over time for suspicious patterns. Both are required in a complete AML program.
Do neobanks need different screening than banks?
The lists and regulatory expectations are the same. Neobanks must deliver the same rigor with faster automated decisions and mobile-friendly flows.