IDCanopy
IDCANOPY TRUST · IDENTITY · COMPLIANCE
Request a walkthrough
SANCTIONS · PEP · ADVERSE MEDIA

The lists are bought.
The judgment is ours.

Sanctions, PEP and adverse media screening, sold on its own or wired directly into the customer risk model, CDD/EDD triggers and ongoing due diligence.

Source-neutral
Three sourcing models, one workflow
66
Risk categories you can scope
Outside
The EU AI Act
Live
Risk engine, Poros back office
The framing

Everybody can buy the same lists.

UN, EU, OFAC, HMT, national and regional lists. Two vendors screening the same name against the same sources return the same hit. That is not where a screening programme wins or loses.

Commodity

The data

Sanctions, PEP and adverse-media lists. Priced on volume, interchangeable between vendors, and identical in what they oblige you to find.

The actual work

The workflow

Matching and threshold tuning, fuzzy and transliteration handling, risk-scored alert triage, human review, escalation, SLA, audit trail.

The real differentiator

The destination

A hit lands inside a risk model that decides accept, escalate or decline, not in a spreadsheet someone reviews when they get to it.

Before the how

Do you actually need it, and for whom?

Screening everyone is expensive and screening nobody is indefensible. The first question in every engagement is which part of your book carries the obligation.

Lending & credit · recommended

Where you extend credit

Sanctions and PEP screening at origination is standard practice for any lending activity, not a sector-specific requirement. Screening a borrower before extending credit, and re-screening on an ongoing basis, is the baseline expectation wherever a loan or financing product exists. This is the clear case: yes, recommended.

Broad customer base · scope it

Where the trigger is not yet confirmed

For a broad consumer base with no credit exposure, whether screening is required depends on facts specific to you: which segments carry meaningful financial exposure (large contracts, device financing, business accounts), and what your own risk policy or regulator expects. We would usually scope this as a defined subset, not the full base.

How it works

One engine turns three global feeds into a decision.

Sanctions, PEP and adverse media orchestrated through one matching and risk layer, not three separate lookups.

SANCTIONS

UN, EU, OFAC, HMT + national and regional

  • Explicit listings and trade embargoes
  • Tagged with the official listing, so you can screen list by list
  • Re-checked on every publication, not on a refresh cycle

PEP

Global and domestic, relatives and close associates

  • Primary and secondary exposure held apart
  • State-owned and state-invested entities and their officers
  • Graded by proximity to office, so scoring is not a flat flag

ADVERSE MEDIA

Negative news and enforcement action

  • Pre-conviction and post-conviction held apart
  • Sourced from reported enforcement, not sentiment
  • Every record classified against the risk-category taxonomy

This is where the 66 categories do their work.

The taxonomy is not a coverage boast, it is the scoping control. Because every adverse record carries its category, "which risks are we screening for" becomes a setting your risk team owns rather than an all-or-nothing switch. Screen tax and customs violations but not disciplinary actions, pre-conviction fraud but not pre-conviction everything. See all 66 categories ↓

Fuzzy matching · transliteration · name variants

IDCANOPY SCREENING ENGINE

Your chosen sourcing model · configurable thresholds · explainable, auditable match decisions.

Risk scoring + explainability

APPROVE

Auto-cleared, on file

REVIEW

Analyst queue, SLA-bound

REJECT

Escalated, decline on record

↻ CONTINUOUS MONITORING · re-screened on every list update, trigger-based re-checks
We check against, locally and globally

One matching layer, every risk category.

The taxonomy behind every hit: sanctions and watchlist categories, financial crime, and the adverse-media risk indicators the engine classifies against.

🏃Absconder or Fugitive 🏛️Abuse of Office 🤝Aiding and Abetting ✈️Aircraft Hijacking and Aviation Crime ⚖️Antitrust Violation or Unlawful Competition 🔫Arms and Ammunition Possession 🚚Arms and Ammunition Trafficking 🔥Arson and Destruction of Property 📜Breach of Fiduciary Duty 💸Bribery and Corruption 🤫Conspiracy or Collusion 🛍️Consumer Protection Violation 📋Control or Regulation Violation 🦹Counterfeiting or Piracy 🛑Crimes Against the State 💻Cybercrime 🔓Data Privacy Breach 🚷Deported or Exiled 👩‍⚖️Disciplinary Action 🚫Disqualified and Debarred 📉Dissolved Company ⚡Energy Crime 🌳Environmental Crime 🚫Explicit Sanctions 🧒Exploitation of Children 💣Extortion 💰Financial Services Warning 👷Forced and Slave Labour ✒️Forgery and Uttering ⛔Former Explicit Sanctions ⚠️Former Implicit Sanctions 💳Fraud 🧊Frozen and Seized Assets 🧑🤝🧑Hate Crime 🏥Healthcare Fraud ✋Human Rights Violation 🚶Human Trafficking 🎰Illegal Gambling 🛂Illegal Immigration 💼Illegal Possession or Sale 🚪Illegal Restraint or Kidnapping ⚠️Implicit Sanctions 📈Insider Trading 📉Insolvency, Liquidation or Bankruptcy 🛠️IP Rights Infringement 🛠️Labour Rights Violation 📝Licence Revocation 💵Money Laundering 💊Narcotics Trafficking ⚖️Obstruction of Justice 🕵️Organised Crime 💊Pharmaceutical Trafficking 🚫Sanctions Related 🛑Securities Violation 👩Sexual Exploitation 📦Smuggling 💵Tax and Customs Violation 📝Tender Violation and Restrictions 💣Terror Related 🦹Theft and Embezzlement 📦Trafficking in Stolen Goods ✈️Travel or Visa Restriction 💵Unlawful Money Lending 🪓Violent Crime ⚔️War Crime 🐘Wildlife Crime

66 risk categories mapped today. Coverage grows with the underlying source, not with a rebuild here.

The cost nobody prices in

A false positive at onboarding costs an hour. Under monitoring it costs an hour a month.

Match quality looks like a feature until you turn monitoring on. Then it is the running cost of the whole programme.

Screen once, and a bad match costs one review

At onboarding you look at it, dismiss it, and move on. That is the version of false positives everyone budgets for, and it is the cheap one.

Monitor, and the same bad match comes back

Every cycle. For every subject. The rate does not add up, it multiplies by how often you re-screen and by how many people are on your book. Nothing about the match got worse. You simply meet it again, and again.

Which is why the cheapest rate per check is not the cheapest programme

Weaker matching and a monthly full-price re-screen are the same decision seen from two sides. You pay the full screening rate every month to regenerate the same false positives your analysts dismissed last month.

Cumulative alerts to review, per 1,000 subjects
Illustrative

Monthly monitoring, at a 2.0% and a 0.7% alert rate. The rates are a worked example, not measured figures. Your own numbers depend on your book, your thresholds and which categories you scope in.

Cumulative alerts to review under monthly monitoring Illustrative. Per 1,000 subjects, weaker matching accumulates 720 reviews over 36 months against 252 for stronger matching. 0 250 500 750 0 6 12 18 24 30 36 Months of monitoring The gap is your operating cost 720 reviews weaker matching 252 reviews stronger matching
Weaker matching Stronger matching
View as a table
MonthWeaker matchingStronger matchingDifference
0 (onboarding only)20713
1224084156
24480168312
36720252468
The judgment, made concrete

Deciding whether a result is worth looking at.

A change to a record can arrive graded by how material it is: a subject appearing on a sanctions list at one end, a corrected middle initial at the other. Where the line falls, and what happens either side of it, is the workflow, and that is the part you are actually buying. Set it too low and your analysts read spelling corrections. Set it too high and you find out what you missed from someone else.

Whether that grading arrives with the data at all is one of the real differences between the sourcing models, not a detail. One of the three grades changes explicitly. One handles the noise its own way. One does not separate a material change from a cosmetic one, which is why its monthly re-screen returns the whole match set every time. Compare the three ↓

Inside the risk stack

Built to be configured, not locked in.

A confirmed sanctions match doesn't add points to a score. It overrides it outright and forces the highest risk tier, regardless of every other factor, and it is demoable live today in the Poros risk engine.

01

Explainable matching

Fuzzy match, transliteration and name-variant logic, with thresholds a bank can tune to its own risk appetite.

02

False-positive triage

Risk-scored alert prioritisation so reviewers work the alerts that matter first.

03

Workflow automation

Approve, review or reject routing, with escalation paths and an SLA on resolution.

04

Case management

Every decision, escalation and review inside one case file and audit trail.

05

API-first

Send a name, get a scored, reviewed result back. No onboarding platform required.

06

Continuous monitoring

Periodic and trigger-based re-screening, not a one-time onboarding gate.

07

Provider flexibility

Three sourcing models behind one interface. Change the model without rebuilding the screening workflow around it.

08

Clean on the AI Act

Mechanical, third-party-sourced screening sits entirely outside the EU AI Act.

Integration shape

Your engineers get an API. Your analysts get a screen.

One screening call, two audiences. What the developer integrates and what the compliance team sits in front of are different problems, and pretending otherwise is how screening projects stall after go-live.

YOUR SYSTEM
Onboarding flow, CRM or core banking. One request, name plus secondary identifiers.
SCREENING CALL
REST, your chosen sourcing model behind it. Synchronous, or queued for an overnight run.
NO MATCH
Onboarding continues, decision on file
MATCH
Held, routed to an analyst queue
Included · ours

The review console

Where the held cases land. Scored, categorised, with the record and the decision trail attached, so a reviewer can clear or escalate without leaving the case.

Nothing extra to license. If you would rather your analysts never leave your own system, the same case actions are on the API.
Optional · licensed extra

The vendor back office

Both the Expert and World Check models come with their own case and list management interfaces, and they are good ones. Teams that already work natively in them can keep doing so, with our engine handling the screening call.

// illustrative request shape
{
  "name": "Josef Hauer",
  "dob": "1958-03-12",
  "country": "AT"
}

// illustrative response shape
{
  "decision": "review",
  "tier": "high",
  "hits": [{ "list": "PEP", "score": 100 }],
  "dossier_url": "…"
}
Case and list management UIs are priced separately by the provider. We will tell you what they cost before you decide you need them. The exact contract is confirmed per engagement against the agreed data source and risk configuration.
The failure that does not announce itself

A false positive costs you an hour. A false negative costs you the licence.

Everything on this page so far has been about false positives, because those are the ones you can see. The other kind of miss produces no alert, no queue entry and no work. Nothing tells you it happened. That is the entire problem with it.

Loud

The false positive

Lands in the queue, takes an analyst's time, gets dismissed. Expensive, measurable, and on somebody's dashboard by Friday.

Silent

The false negative

The name is never matched, so no alert is raised and no record of the near-miss exists. You find out when a regulator, a correspondent bank or a journalist finds out.

Screening a name in one spelling is screening a guess.

Most misses are not exotic. They are the same person written the way a different system, a different alphabet or a different culture writes them.

ScriptCyrillic ↔ Latin
Александр Кузнецов Aleksandr Kuznetsov Alexander Kouznetsov
One subject, one record
ParticlesArabic transliteration
محمد السيد Muhammad al-Sayed Mohamed El Sayed
One subject, one record
Name orderFamily name first
李明 Li Ming Ming Li
One subject, one record

Illustrative examples of name variance, not screening results. Matching in the original script matters because a subject is recorded the way their own jurisdiction records them, and the transliteration your onboarding form captured is only one of several defensible spellings. Getting this wrong lowers your alert count, which is exactly why it is easy to mistake for good performance.

Sourcing models

We run three, rather than reselling one.

The right answer depends on your volume, your tolerance for false positives, and whether you need an immediate result or can wait for an overnight run. Everything above (matching, triage, workflow, audit trail) applies to all three.

Budget

Lowest cost per check

Cheapest per check by a wide margin. Sanctions and PEP only, and no real monitoring: the same name is re-screened monthly at full screening price each time. Name matching is the weakest of the three, and changes to a record are not graded by materiality at all.

Our experience: it finds what it is told to find, but loose matching produces noticeably more false positives, and with nothing separating a material change from a cosmetic one, every monthly re-screen hands you the whole match set again.

Priced on request

Expert

Our default recommendation

Screening and monitoring priced separately, with a year of monitoring costing roughly two screenings. Strong false-positive reduction with its own built-in noise handling, list management and maintenance included, fully configurable via API, adverse media a small optional surcharge. PEP coverage runs down to level 4.

Our experience: the best of the three at keeping analyst workload down. Source snippets stay in the original language and additionally carry an English translation and summary, so nothing is lost or gated behind the source text when a decision has to be defended.

Priced below, our default recommendation

World Check Co-sell

LSEG, flat licence band

One price per person, no screening/monitoring split: check once a year or a hundred times for the same cost. Covers sanctions, crime and adverse media, plus ownership-derived indirect sanctions (OFAC 50% rule) the others do not carry. Batch upload, ongoing screening and adverse media are separately licensed modules.

Our experience: stronger crime lists and better close-relative coverage than the premium alternative, weaker adverse media, and no PEP level 4. It grades record changes by materiality explicitly, which is the cleanest control over monitoring alert volume of the three.

Priced on request, flat licence band

Budget and World Check Co-sell are quoted against your actual volume. Tell us roughly how many checks a year and whether you need results in real time, and we will come back with both.

Indicative pricing

The commercial split that actually moves the number.

The rates below are the Expert model, our default recommendation and the one most clients end up on. Budget and World Check Co-sell are priced on request: both depend on annual volume and, in World Check's case, on a committed licence band rather than a per-check rate.

Expert model, list pricePriceSetup
Sanctions & PEP screening (core)€0.24 / checknone
Adverse media (add-on)+€0.04 / checkn/a
Ongoing monitoring, sanctions & PEP€0.48 / subject / yearn/a
Ongoing monitoring, adverse media (add-on)+€0.08 / subject / yearn/a
Also offered Sanctions and PEP are the core service. Adverse media screening (negative news and risk-indicator monitoring) is available as a separate add-on, not bundled by default.
  • This is a configurable framework: you supply the risk thresholds and rules that decide approve / review / reject, not a fixed black box.
  • Screening is mechanical and third-party-sourced, so it sits outside the scope of the EU AI Act.
  • None of the above is legal or regulatory advice. The scoping recommendation for a broad customer base in particular should be confirmed against your own risk policy and applicable regulation.
  • Pricing above is indicative and subject to final scope (volume, ongoing monitoring cadence, integration effort).
Where to start

Standalone, or wired into the full risk stack.

Either way, the conversation starts the same place: what sources, what thresholds, what review workflow and what evidence trail your risk and compliance teams need to sign off on.

Bernie Reiterer
Bernie Reiterer
Founder & CEO, IDCanopy Flexco
bernie@idcanopy.com · Vienna
idcanopy.com