Screening customers and partners against sanctions and PEP lists falls into the category partially: AI can perform the match, but a human reviews every hit and approves or rejects it, with reason. This is not a task you hand over to AI and then leave alone. It is a task where AI speeds up the investigative work while the human continues to make the decision.
Three factors determine the outcome here: compliance, cost of errors, and volume. That last one, volume, is actually favourable for automation: many companies screen hundreds to thousands of relationships, often repeated with every transaction or periodic reassessment. That is exactly the kind of repeatable, structured work AI is good at — hence the score of 4 on structuredness.
But compliance and cost of errors both score a 1, and those pull the outcome towards 'partially'. Sanctions legislation (such as the Sanctions Act 1977, EU regulations and the Wwft) is mandatory law. A false negative — a hit that is not recognised as a hit — can mean a company does business with a sanctioned party. The cost of errors is then not symbolic: it involves fines, criminal liability and reputational damage. A false positive costs time and irritation, but is recoverable. That asymmetry is precisely why regulators expect a human to make the final assessment, not an algorithm.
Added to that is judgment latitude: a score of 2. Matching names is technically straightforward, but assessing a hit — is 'Mohammed Al-Rashid' from your CRM the same person as the identically named entry on the EU sanctions list, or a coincidental namesake? — requires context, source documents and sometimes further inquiry. That is human work, and it remains so even as the tooling improves.
A wholesaler enters a new supplier into the CRM. The screening tool automatically matches the company name and the name of the director against the current EU, OFAC and national sanctions lists. A hit comes up: a director with a similar name appears on a PEP list (politically exposed person). That does not automatically mean a problem — PEP status is a risk indicator, not a prohibition — but a compliance officer must investigate: is it the same person, and if so, what enhanced due diligence is then required? That assessment, with substantiation, is the part that remains human work.
At a company with few international relationships and a low risk profile — think of a local service provider working almost exclusively with known, domestic customers — the volume of screenings is so low that automation yields little benefit. There, manual review can work just as well without an automated tool adding value.
Conversely: at a financial institution, a trading company with many cross-border relationships, or a company under enhanced supervision, the volume is so high and the obligation so strict that manual screening without AI support is barely feasible anymore. There, a screening tool with up-to-date lists is not a luxury but practically a necessity — with the understanding that assessing hits remains human work.
This pattern — high volume, high cost of errors, strict regulation — occurs more broadly. Compare it with what can AI take over in wholesale, where international trade raises similar compliance issues, or with the healthcare sector, see what can AI take over in healthcare, where patient safety brings the same asymmetric cost of errors.
An AI agent can today: automatically match new and existing relationships against current sanctions and PEP lists, apply fuzzy matching to name variants and transliterations, prioritise which hits are most likely relevant, and prepare a file with source documents for the reviewer. That saves a significant amount of investigative work.
The preconditions, however, are: the linked sanctions lists must be up to date — lists change regularly, sometimes urgently — and every hit is manually reviewed by someone with the authority and knowledge to approve or reject it, with a recorded reason. Without these two preconditions, it is not a compliant process.
This page describes a task, not a role or a team. Whether and how you deploy the freed-up time of a compliance officer or risk manager differently is a choice that lies with the employer. Decisions affecting staffing are subject to their own legal requirements, which this page does not address.
Would you like to know how many of the hours in your role or department can already be supported by AI today? The free quickscan from ftetoai consists of twelve questions, requires no account, and gives an indication of the portion of your tasks that can already be taken over by AI. The full work scan, which goes deeper into specific processes such as sanctions screening, is still under development — so we do not yet offer it, but we will announce it here as soon as it becomes available.
Vraag maar. Ik ken de kennisbank van deze site; wat ik niet weet, zeg ik erbij.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.