Learn more about the latest security and privacy threats

Review desk

Sanctions and PEP alert review desk

Screening engines produce hits. Most of them are a namesake, a stale designation, or the same customer you already cleared last quarter. This desk works that queue against your policy, discounts what is not a match with the reasoning written down, and escalates what is.

Screening alert · name match open YOUR CUSTOMER Record #8812 LIST ENTRY Designated person COMPARED AGAINST YOUR MATCHING POLICY Full name Strong match Date of birth Differs by 11 years Nationality Does not match Passport number No overlap Drafted: discount as a false positive Rationale, sources and prior dispositions attached AWAITING YOUR APPROVAL

In short: Sanctions and PEP alert review is the work of deciding whether each screening hit is a true match to a designated person or entity, or a false positive to be discounted. Zyphe runs it as an operated desk: agents pull the customer record and the list entry, compare names, dates and identifiers against your matching policy, and produce a written disposition for every alert. Your analysts approve. The decisions EU law reserves for the obliged entity, including the customer risk profile and whether to enter a business relationship, stay with your team.

Desk description last reviewed 2026-08-20.

What arrives at this desk?

The work this desk takes off your team, stated as the queue it actually receives.

Onboarding screening hits

Name matches raised when a new customer is screened against sanctions, PEP and watchlist sources before you onboard them.

Re-screening hits on list changes

Alerts raised on existing customers when a designation is added, amended or lifted on OFAC, the EU consolidated list, UK OFSI or UN sources.

PEP and close associate matches

Hits that turn on a relationship rather than on identity, where the question is whether the connection is real and current, not whether the name matches.

Reopened alerts

Customers already cleared once, surfacing again on a list update, where the prior disposition should inform the new one rather than be re-derived from scratch.

How does the sanctions and PEP alert review desk work?

Five steps, the same way every time, because consistency is what an audit is actually testing for.

  1. 1

    Pull the whole picture

    The agent retrieves the customer record you hold, the list entry that triggered the alert, and every previous disposition on the same customer, so a hit discounted last quarter is not investigated from a blank page.

  2. 2

    Compare against your policy

    Names, dates and places of birth, nationality and any document identifiers are compared using your matching rules and thresholds, not a generic default the vendor prefers.

  3. 3

    Write the disposition

    Each alert gets a plain-language rationale: which fields matched, which did not, which sources were checked, and why the conclusion follows from them.

  4. 4

    Escalate what is not clear

    Genuine identity overlap, a weak but plausible match, or a designation that has changed in substance goes to your analyst with the evidence already assembled and the open question stated.

  5. 5

    Hand over a file, not a verdict

    Every alert leaves the desk with its evidence and reasoning attached, in a form your case management system and your audit trail can both accept.

What we prepare, and what you approve.

Agent-prepared, human-approved is not a hedge in the marketing copy. It is the shape EU law requires, and it is the reason this desk can be bought by a regulated firm at all.

What the Zyphe agent prepares, and what your team approves, at each stage of the review
Stage The agent prepares Your team approves
Alert triage Compares the hit against your matching policy and drafts the disposition with its reasoning Approves the discount, or overturns it
Customer risk profile Assembles every piece of evidence that bears on the customer's risk Sets the risk profile AMLR Art. 18(3)(c)
Onboarding Prepares the complete decision-ready file Decides whether to enter into the business relationship AMLR Art. 18(3)(d)
Suspicious activity Drafts the narrative and gathers the supporting facts Decides whether to report, and files with the FIU AMLR Art. 18(3)(e)
Matching policy Applies the thresholds and rules you have set Owns and approves the detection criteria AMLR Art. 18(3)(f)

Why the split is drawn there

Article 18 of Regulation (EU) 2024/1624, the EU anti-money laundering regulation that applies from 10 July 2027, permits obliged entities to outsource tasks to service providers, and requires the supervisor to be notified before the provider starts. Article 18(2) then treats the service provider as part of the obliged entity, leaves the entity fully liable, and requires it to be able to demonstrate to its supervisor that it understands the rationale behind the activities the provider carries out. Article 18(3) lists tasks that cannot be outsourced under any circumstances. Every one of them sits on your side of this table.

That demonstrability requirement is the reason each case leaves this desk with its reasoning written out rather than with a score. A confidence number cannot be explained to a supervisor. A rationale can.

What this desk will not do

  • Set or tune your matching thresholds
  • Decide a customer's risk rating
  • Approve or reject an onboarding
  • File a suspicious activity report on your behalf
  • Change your screening policy

What do you actually receive?

A decision-ready file, in the systems you already run.

  • A disposition for every alert, with the reasoning in writing
  • The evidence used, linked back to the source that produced it
  • A queue worked to an agreed service level rather than left to accumulate
  • An export into the case management system you already run

The software behind this desk

If you would rather run the work yourself than have it operated, these are the same capabilities as a product surface.

Frequently asked questions about sanctions and PEP alert review.

Can sanctions alert review be outsourced under EU rules?

Yes, within limits. Article 18(1) of Regulation (EU) 2024/1624 allows obliged entities to outsource tasks to service providers, and requires the entity to notify its supervisor before the provider starts work. Article 18(3) then lists tasks that shall not be outsourced under any circumstances, including the decision on the risk profile attributed to a customer, the decision to enter into a business relationship, and reporting to the FIU. The Regulation applies from 10 July 2027. A desk that prepares alerts and leaves those decisions with your MLRO sits inside that boundary. One that disposes of alerts on your behalf without approval does not.

Who is liable if an alert is dispositioned wrongly?

You are. AMLR Article 18(2) provides that service providers are regarded as part of the obliged entity, and that the obliged entity remains fully liable for any act or omission connected to the outsourced tasks. The same article requires you to be able to demonstrate to your supervisor that you understand the rationale behind the activities your provider carries out. That is the reason every disposition leaving this desk carries its reasoning rather than a score.

Does this replace our screening engine?

No. The desk works the alerts your existing engine produces, whichever engine that is, and writes back into the case management system you already use. Replacing the engine is a separate decision, and not one this desk asks you to make.

What happens to a customer we have already cleared?

The prior disposition travels with the customer. When a list change resurfaces someone you cleared before, the agent starts from what was decided last time and examines what actually changed in the designation, rather than re-running the whole comparison and producing a fresh opinion that may contradict your own file.

Where does our customer data sit while the desk works?

Zyphe does not build a central archive of your customers' personal data. Records are split into encrypted fragments held across independent nodes, and the key stays on your side, so there is no consolidated store on the Zyphe side for a breach to reach. Your case files and audit trail remain in your systems, which is also where AMLR retention obligations sit.

Book a demo

Put the sanctions and PEP alert review queue on a desk.

Book a demo and bring a real slice of your queue. We will work it, show you the files, and you will see exactly what your team still has to approve.