In short: Sanctions and PEP alert review is the work of deciding whether each screening hit is a true match to a designated person or entity, or a false positive to be discounted. Zyphe runs it as an operated desk: agents pull the customer record and the list entry, compare names, dates and identifiers against your matching policy, and produce a written disposition for every alert. Your analysts approve. The decisions EU law reserves for the obliged entity, including the customer risk profile and whether to enter a business relationship, stay with your team.
Desk description last reviewed 2026-08-20.
What arrives at this desk?
The work this desk takes off your team, stated as the queue it actually receives.
Onboarding screening hits
Name matches raised when a new customer is screened against sanctions, PEP and watchlist sources before you onboard them.
Re-screening hits on list changes
Alerts raised on existing customers when a designation is added, amended or lifted on OFAC, the EU consolidated list, UK OFSI or UN sources.
PEP and close associate matches
Hits that turn on a relationship rather than on identity, where the question is whether the connection is real and current, not whether the name matches.
Reopened alerts
Customers already cleared once, surfacing again on a list update, where the prior disposition should inform the new one rather than be re-derived from scratch.
How does the sanctions and PEP alert review desk work?
Five steps, the same way every time, because consistency is what an audit is actually testing for.
- 1
Pull the whole picture
The agent retrieves the customer record you hold, the list entry that triggered the alert, and every previous disposition on the same customer, so a hit discounted last quarter is not investigated from a blank page.
- 2
Compare against your policy
Names, dates and places of birth, nationality and any document identifiers are compared using your matching rules and thresholds, not a generic default the vendor prefers.
- 3
Write the disposition
Each alert gets a plain-language rationale: which fields matched, which did not, which sources were checked, and why the conclusion follows from them.
- 4
Escalate what is not clear
Genuine identity overlap, a weak but plausible match, or a designation that has changed in substance goes to your analyst with the evidence already assembled and the open question stated.
- 5
Hand over a file, not a verdict
Every alert leaves the desk with its evidence and reasoning attached, in a form your case management system and your audit trail can both accept.
What we prepare, and what you approve.
Agent-prepared, human-approved is not a hedge in the marketing copy. It is the shape EU law requires, and it is the reason this desk can be bought by a regulated firm at all.
| Stage | The agent prepares | Your team approves |
|---|---|---|
| Alert triage | Compares the hit against your matching policy and drafts the disposition with its reasoning | Approves the discount, or overturns it |
| Customer risk profile | Assembles every piece of evidence that bears on the customer's risk | Sets the risk profile AMLR Art. 18(3)(c) |
| Onboarding | Prepares the complete decision-ready file | Decides whether to enter into the business relationship AMLR Art. 18(3)(d) |
| Suspicious activity | Drafts the narrative and gathers the supporting facts | Decides whether to report, and files with the FIU AMLR Art. 18(3)(e) |
| Matching policy | Applies the thresholds and rules you have set | Owns and approves the detection criteria AMLR Art. 18(3)(f) |
Why the split is drawn there
Article 18 of Regulation (EU) 2024/1624, the EU anti-money laundering regulation that applies from 10 July 2027, permits obliged entities to outsource tasks to service providers, and requires the supervisor to be notified before the provider starts. Article 18(2) then treats the service provider as part of the obliged entity, leaves the entity fully liable, and requires it to be able to demonstrate to its supervisor that it understands the rationale behind the activities the provider carries out. Article 18(3) lists tasks that cannot be outsourced under any circumstances. Every one of them sits on your side of this table.
That demonstrability requirement is the reason each case leaves this desk with its reasoning written out rather than with a score. A confidence number cannot be explained to a supervisor. A rationale can.
What this desk will not do
- Set or tune your matching thresholds
- Decide a customer's risk rating
- Approve or reject an onboarding
- File a suspicious activity report on your behalf
- Change your screening policy
What do you actually receive?
A decision-ready file, in the systems you already run.
- A disposition for every alert, with the reasoning in writing
- The evidence used, linked back to the source that produced it
- A queue worked to an agreed service level rather than left to accumulate
- An export into the case management system you already run
The software behind this desk
If you would rather run the work yourself than have it operated, these are the same capabilities as a product surface.
Frequently asked questions about sanctions and PEP alert review.
Can sanctions alert review be outsourced under EU rules?
Yes, within limits. Article 18(1) of Regulation (EU) 2024/1624 allows obliged entities to outsource tasks to service providers, and requires the entity to notify its supervisor before the provider starts work. Article 18(3) then lists tasks that shall not be outsourced under any circumstances, including the decision on the risk profile attributed to a customer, the decision to enter into a business relationship, and reporting to the FIU. The Regulation applies from 10 July 2027. A desk that prepares alerts and leaves those decisions with your MLRO sits inside that boundary. One that disposes of alerts on your behalf without approval does not.
Who is liable if an alert is dispositioned wrongly?
You are. AMLR Article 18(2) provides that service providers are regarded as part of the obliged entity, and that the obliged entity remains fully liable for any act or omission connected to the outsourced tasks. The same article requires you to be able to demonstrate to your supervisor that you understand the rationale behind the activities your provider carries out. That is the reason every disposition leaving this desk carries its reasoning rather than a score.
Does this replace our screening engine?
No. The desk works the alerts your existing engine produces, whichever engine that is, and writes back into the case management system you already use. Replacing the engine is a separate decision, and not one this desk asks you to make.
What happens to a customer we have already cleared?
The prior disposition travels with the customer. When a list change resurfaces someone you cleared before, the agent starts from what was decided last time and examines what actually changed in the designation, rather than re-running the whole comparison and producing a fresh opinion that may contradict your own file.
Where does our customer data sit while the desk works?
Zyphe does not build a central archive of your customers' personal data. Records are split into encrypted fragments held across independent nodes, and the key stays on your side, so there is no consolidated store on the Zyphe side for a breach to reach. Your case files and audit trail remain in your systems, which is also where AMLR retention obligations sit.
The other desks
Most teams start with one queue and add the next once the first is clearing.
Adverse media review
Reads the underlying coverage rather than the headline, resolves whether the story is actually about your customer, classifies it against your risk taxonomy, and summarises with citations.
See the deskUBO and EDD review
Walks the ownership chain through corporate registries to the natural persons behind it, screens them, and assembles the enhanced due diligence file including what could not be resolved.
See the deskTransaction monitoring alert triage
Reconstructs the account history behind each rule-triggered alert, tests it against that customer's own baseline and your typologies, and drafts either a reasoned close or a narrative your investigator can amend and file.
See the deskKYC periodic review and refresh
Re-runs the checks on customers falling due, compares what it finds against the file you already hold, and reports what actually changed rather than rebuilding a dossier nobody reads.
See the deskBook a demo
Put the sanctions and PEP alert review queue on a desk.
Book a demo and bring a real slice of your queue. We will work it, show you the files, and you will see exactly what your team still has to approve.