Youverify
  • Developers
Login

Subscribe to our newsletter

Subscribe to our weekly newsletter for expert insights, regulatory updates, and actionable tips to optimize your compliance strategy.

By subscribing, you'll receive updates from Youverify.

Solution

    Customer OnboardingFraud InsightsTransaction MonitoringRegulatory ReportingVyra AIPricing

Industry

    Commercial banksFintech & PaymentsGamingGig WorkersGovernment

Company

    About UsCompliance CertificationsPress and MediaPartnersCareersContact Us

Resources

    BlogsGlossaryDevelopersIndustry ReportsData SourcesFAQsCountry CoverageAI Governance

Legal

    Privacy PolicyTerms of UseCookies PolicyPAIAInformation Security PolicyGDPR Compliance StatementResponsible AI

    Customer OnboardingFraud InsightsTransaction MonitoringRegulatory ReportingVyra AIPricing

youverify-logo

©2026 Copyright. All Rights Reserved

KYC Screening: What It Checks and How to Judge a KYC Screening Tool
Know Your Customer (KYC)

KYC Screening: What It Checks and How to Judge a KYC Screening Tool

ByTemitope Lawal
September 10, 2026•5mins Read

Key Takeaways

  • 1. KYC screening covers four data sources: sanctions lists, PEP data, adverse media and your own internal records, each answering a different question about the customer
  • Sanctions screening carries strict liability, so a breach is an offence whether or not you intended it, which is why it is the one check that cannot be risk-tiered away
  •  
  • 2. Under OFAC's 50 Percent Rule, an entity owned 50 per cent or more in aggregate by blocked persons is itself blocked even though it appears on no list, so name matching alone cannot catch it
  •  
  • 3. The Wolfsberg Group states plainly that screening effectiveness depends on the type, availability, completeness and quality of your own data, not on the vendor's list
  •  
  • 4. Fuzzy matching thresholds are the single most consequential setting in a screening tool and are usually left at a default nobody documented
  •  
  • 5. The CBN Baseline Standards for Automated AML Solutions require human judgement on sanctions matches, annual independent model validation and documented false positive and false negative thresholds

KYC screening checks a customer's name and details against sanctions lists, politically exposed person data, adverse media and internal watchlists, at onboarding and continuously afterwards. It answers a different question from identity verification: not whether this person is real, but whether you are allowed to do business with them.

 

What Is KYC Screening?

KYC screening is the process of checking a customer's identifying details against lists and data sources that indicate whether a relationship is prohibited, high risk, or acceptable. It runs at onboarding, then repeats for the life of the relationship as lists change and customers change.

 

Two things are often confused. Identity verification confirms that a person exists and that the applicant is them. KYC screening takes that verified identity and asks a separate question: given who this is, what are we permitted and willing to do? A customer can pass identity verification perfectly and still be someone you must refuse.

 

The output of screening is a match, a possible match, or nothing. Possible matches are where the work is, because a screening engine deliberately returns more than it is certain about, and someone has to resolve the difference.

 

You will see the control called AML KYC screening, name screening or customer screening depending on the vendor. They describe the same thing: comparing customer reference data against risk data sources. What genuinely differs between products is which sources they load, how often they refresh, and what happens to a possible match once it is raised.

 

What Does the KYC Screening Process Look Like?

The KYC screening process has five stages: capturing screenable data at onboarding, running the match against selected lists, resolving possible matches, escalating and recording the decision, and rescreening the book continuously.

 

The middle three are where programmes are made or lost, and they are the three vendors demonstrate least.

 

1. Capturing Screenable Data at Onboarding

Screening compares what you captured against what the lists hold, so the fields you collect determine the ceiling on accuracy. Full legal name in a consistent order, date of birth, nationality, and for corporate customers the directors and beneficial owners.

A name captured with an honorific attached, or a date of birth left blank because the form allowed it, degrades every screening run that customer will ever go through.

 

2. Running the Match Against Selected Lists

The engine compares the captured data against each loaded list using either exact or fuzzy matching, depending on how that list is configured. Sanctions lists normally run fuzzy because designated parties do not spell their names helpfully. Internal lists often run exact because you control the data on both sides.

 

3. Resolving Possible Matches

An analyst opens the alert, compares the customer's full record against the list entry, and decides: true match, false positive, or insufficient information. This is the work, and it is where headcount goes.

 

Resolution quality depends on how much context arrives with the alert. A score and two names forces the analyst into other systems. A score with the customer's verified identity, ownership structure and prior alert history attached is a decision rather than an investigation.

 

4. Escalating and Recording the Decision

A confirmed sanctions match freezes the relationship and triggers a report. A confirmed PEP match triggers enhanced due diligence and senior management approval. A discounted match needs the reasoning recorded, because a true match wrongly closed is the most serious failure in AML KYC screening and the record is the only defence.

 

5. Rescreening the Book Continuously

Every list update is rescreened against the whole customer base, not just new applicants. This is the stage institutions skip when volumes grow, and the one that catches the customer who was clean at onboarding and was designated eighteen months later.

 

What Does KYC Screening Actually Check?

KYC screening checks five data sources: sanctions lists, politically exposed person data, adverse media, your own internal records and watchlists, and beneficial ownership.

Most vendors sell the first three and treat the last two as optional, which is where programmes develop holes.

 

1. Sanctions Lists: The Check With Strict Liability

Sanctions screening tests a customer against lists published by OFAC, the UN, the EU, the UK and, for Nigerian institutions, the Nigeria Sanctions List maintained under the Terrorism (Prevention and Prohibition) Act 2022.

 

This is the only KYC screening check that carries strict liability. Dealing with a sanctioned party is an offence regardless of whether you knew, intended it, or profited. Every other check is risk-based. This one is not, which is why it cannot be reduced for low-risk customers and why FATF Recommendation 6 requires targeted financial sanctions to be implemented without delay.

 

2. Politically Exposed Persons: Risk, Not Prohibition

PEP screening identifies customers who hold or held prominent public functions, plus their family members and close associates. Being a PEP is not a reason to refuse business. It is a reason to apply enhanced due diligence.

 

FATF Recommendation 12 requires senior management approval for the relationship, reasonable measures to establish source of wealth and funds, and enhanced ongoing monitoring. The compliance failure here is rarely missing a PEP. It is flagging one and then treating the flag as the whole obligation.

 

3. Adverse Media: What the Lists Have Not Caught Yet

Adverse media screening searches news and public records for allegations of financial crime, corruption, fraud or regulatory action against a customer. Its value is timing. A person under investigation appears in the press long before they appear on any list, sometimes years before.

It is also the noisiest source. Name collisions, retracted stories and decade-old allegations all surface identically, which is why adverse media screening produces more unusable alerts than the other sources combined.

 

4. Internal Records and Watchlists: Your Own History

The customer you declined last year, the account you exited for suspicious activity, the applicant whose documents failed authentication. That data lives in your systems and most screening configurations never query it.

The Wolfsberg Guidance on Sanctions Screening treats internal lists as part of list management alongside the regulatory lists loaded for global watchlist screening, and your own records are the cheapest source you own outright.

 

5. Beneficial Ownership: The Blocked Entity That Appears on No List

This is the gap that matters most and the one almost no article about KYC screening mentions.

Under OFAC's 50 Percent Rule, set out in FAQ 399, an entity owned 50 per cent or more in the aggregate by one or more blocked persons is itself blocked. Ownership aggregates: if one blocked person holds 25 per cent and another holds 25 per cent, the entity is blocked. And that entity does not appear on the SDN List.

A screening tool that matches names against published lists will return nothing on that company, because there is nothing to match. Catching it requires ownership data and the ability to resolve a corporate structure, which is a different capability from name matching. Note the limit too: OFAC FAQ 398 confirms that control alone, without 50 per cent or more ownership, does not automatically block an entity, though it remains a serious risk indicator.

 

When Must KYC Screening Be Performed?

KYC screening must be performed at four points: at onboarding before the relationship begins, continuously for the life of the relationship, whenever the customer's own data changes, and on any material change to the relationship such as a new product, jurisdiction or volume profile.

 

Institutions typically get the first right and the other three wrong. Onboarding screening has to complete before any transaction is processed. Continuous screening matters because sanctions lists change without notice and a customer clean on Monday can be designated on Tuesday. Data-change screening matters because a new director, address or ownership structure creates a new set of names nobody has ever checked.

 

Continuous rescreening is where most programmes quietly fall behind. Screening a customer once at onboarding and again at periodic review leaves months in which a designation can sit undetected in your book.

 

What Is the Difference Between KYC Screening and Transaction Screening?

 

The difference is what each control examines. KYC screening checks customer reference data held in your records: names, dates of birth, addresses and ownership. Transaction screening checks payment messages in flight, testing counterparties, destinations and intermediaries at the moment value moves.

 

The Wolfsberg Guidance on Sanctions Screening draws that line formally at sections 4.1 and 5, defining reference data screening as analysis of customer information separate from transactional records, and transaction screening as analysis of the movement of value between parties or accounts.

 

 KYC screeningTransaction screening
What it examinesCustomer reference data: names, dates of birth, addresses, ownershipPayment messages in flight
When it runsOnboarding, continuously, on data changeAt the moment of payment
CatchesA prohibited or high-risk customerA prohibited counterparty, destination or intermediary
Misses on its ownA clean customer paying a sanctioned third partyA sanctioned customer transacting only domestically
What is the difference between KYC screening and Transaction screening?

 

A customer who passes KYC screening can still send money to a designated party, and a bank running only transaction screening will not know who it has onboarded. Both are required.

 

Why Does KYC Screening Fail?

KYC screening fails for four reasons, and all four sit on your side of the vendor contract: poor data quality in your own records, fuzzy matching thresholds nobody documented, list coverage gaps, and false positive volume that buries real hits.

It rarely fails because the vendor's list was wrong.

 

1. Poor Data Quality in Your Own Records

The Wolfsberg Group is unusually direct on this. Section 2.2 states that the effectiveness of screening as a control varies between institutions according to the type, availability, completeness and quality of data.

 

A customer record with a misspelled name, no date of birth and a partial address cannot be screened well by any engine. Nigerian institutions face a specific version of this problem: inconsistent name ordering, multiple spellings of the same name across NIN, BVN and account records, and honorifics captured as part of the legal name. Screening runs on what you captured at onboarding, so onboarding data quality is a screening control.

 

2. Fuzzy Matching Thresholds Nobody Documented

Fuzzy matching lets a screening engine catch "Mohammed" against "Muhammad". The threshold decides how loose that comparison is, and it is the single most consequential setting in the system.

 

Set it tight and you miss transliterated names, which is precisely how sanctioned individuals from non-Latin-script jurisdictions evade detection. Set it loose and you generate thousands of alerts your analysts cannot clear. The Wolfsberg guidance expects institutions to determine which lists use fuzzy matching and which use exact matching, and to document the choice. Most institutions inherit a vendor default and never revisit it.

 

3. List Coverage Gaps

Which lists are loaded, how often they refresh, and how quickly a new designation reaches your production environment. A list refreshed nightly leaves a day in which a newly designated party can onboard cleanly.

 

Coverage also means scope. An institution screening only OFAC and UN lists while serving customers with EU and UK exposure has a gap it can describe precisely and has chosen not to close.

 

4. False Positive Volume That Buries Real Hits

A screening system producing a 98 per cent false positive rate is not a screening system. It is a queue. Analysts clearing hundreds of obvious non-matches daily stop reading carefully, and the real match arrives in the same format as the noise.

Wolfsberg addresses this through whitelisting: eliminating hits caused by the interaction of certain list terms and frequently encountered data, such as customer names already confirmed as false positives. That reduces volume without loosening detection, which tuning the threshold alone does not.

 

How Do You Access a KYC Screening Tool?

You access a KYC screening tool on six questions: which lists it covers and how fast a designation reaches production, what the fuzzy matching threshold is and who owns it, the false positive rate on your own data, whether it resolves beneficial ownership or only matches names, what the record captures when an analyst discounts a match, and how long a full-book rescreen takes.

 

Most KYC screening tools answer the first three well and fail on the last three, which is where the cost lives.

 

1. Which lists are covered, and what is the lag from designation to production? Ask for the number in hours. "Real time" means nothing until someone commits to it.

 

2. What is the fuzzy matching threshold, who set it, and how is a change recorded? If the answer is a default with no owner, you have an undocumented control on your highest-liability check.

 

3. What is the false positive rate measured on our data? A benchmark from a European retail portfolio says nothing about a Nigerian corporate book with mixed name formats.

 

4. Does it resolve beneficial ownership, or only match names? Without ownership resolution it cannot catch a 50 Percent Rule entity, and it should say so plainly rather than implying coverage it does not have.

 

5. What does the alert record contain when an analyst discounts a match? A discounted true match is the worst outcome in compliance, and the only defence is the reasoning captured at the time.

 

6. Can it rescreen the entire book against a new designation, and how long does that take? This is the question that separates a screening tool from a screening programme.

 

What Do Nigerian KYC Regulators Expect From KYC Screening?

 

Nigerian regulators expect four things from KYC screening: human judgement on every sanctions match, models that are explainable and independently validated at least annually, tamper-proof audit trails covering configuration changes as well as alert dispositions, and documented false positive and false negative thresholds.

 

All four come from the CBN Baseline Standards for Automated Anti-Money Laundering Solutions, issued 10 March 2026, which moved them from good practice to requirement. Deposit money banks have 18 months to comply, other financial institutions 24.

 

Each one changes something operationally. Human judgement on sanctions matches means automated disposition of a sanctions hit is not available to you at all. Tamper-proof audit trails covering configuration mean a threshold change is a logged, reviewable event rather than an internal adjustment. And documenting a false negative threshold requires stating in writing how much undetected risk you accept, which is uncomfortable and now expected.

 

Alongside this sit obligations under the Money Laundering (Prevention and Prohibition) Act 2022 and the NFIU's reporting requirements, and the Nigeria Sanctions List under the Terrorism (Prevention and Prohibition) Act 2022, which is a domestic list separate from the international ones your vendor loads by default. Confirm it is in scope.

 

KYC Screening That Catches What the List Misses With Youverify

Most KYC screening tools match a name against a list and return a score. That handles the easy case. It does not handle the entity that is blocked by ownership while appearing on no list, the transliterated name a tight threshold skips, or the real match an analyst closed at four in the afternoon with no reasoning recorded.

 

Youverify Customer Onboarding runs document, anti-deepfake liveness and government-source checks in one journey, scored to a risk tier, with screening inside that same journey rather than bolted on after it. Because the screening result and the identity evidence are produced together, a possible match arrives with the customer's verified data already attached instead of sending an analyst to three systems to resolve one name.

 

Vyra AI works the alert queue with you, assembling the entity picture behind a possible match and drafting the assessment a reviewer would otherwise write from scratch. The reviewer still decides, which is what the CBN standard requires on a sanctions match, and the decision is what the audit trail keeps.

 

Every threshold, list refresh, match and discounted hit is recorded against the customer file, including the reasoning. Regulator-ready before the regulator asks.

 

Book a free demo with our compliance team and we will screen a sample of your existing book to show you what your current tool is not returning.

 

FAQs

Frequently Asked Questions

Related Articles

What is KYC in Finance?
Know Your Customer (KYC)
Emmanuel Agwu•April 26, 2022

What is KYC in Finance?

Read More
Understanding the Central Bank of Nigeria’s (CBN) 3-Tiered Know-Your-Client KYC Process
Know Your Customer (KYC)
Emmanuel Agwu•November 2, 2022

Understanding the Central Bank of Nigeria’s (CBN) 3-Tiered Know-Your-Client KYC Process

Read More
Why is Negative News Screening (NNS) Important?
Know Your Customer (KYC)
Lola, Edited by Emmanuel Agwu•April 25, 2023

Why is Negative News Screening (NNS) Important?

Read More