Blog
RegulationAugust 20, 20269 min read

AMLA is here. “We use a vendor” is no longer an operating model.

AMLA changes the direction of EU AML/CFT supervision. Learn why financial-crime teams need evidence of source state, review and decision-making, not just a vendor name.

For years, many financial-crime programmes have been able to explain a control in one short sentence: “We screen against sanctions lists using Vendor X.” It is a useful beginning. It is not an operating model.

The European Union’s Anti-Money Laundering Authority, AMLA, makes the direction of travel hard to ignore. The new authority is part of the EU’s broader AML/CFT architecture. Its role includes supporting supervisors and, for selected cross-border obliged entities, direct supervision. That does not mean every fintech needs to redesign its programme overnight. It does mean that a vendor name is a weaker answer to an increasingly practical question: show us how the control worked.

This article is not legal advice and it is not a checklist for whether an individual firm falls within AMLA’s scope. It is about the operational lesson every compliance team can take now.

Short answer

AMLA does not turn sanctions screening into a box-ticking exercise with a new logo on it. The safer operating assumption is the opposite: teams need to be able to explain their screening control end to end. That means the sources in scope, their freshness, the query that was run, the candidates that appeared, the reason an alert was cleared or escalated, the person who approved the outcome, and what happened when information later changed.

“The system gave us a green result” is not the same as “we can reconstruct the decision.”

Why a vendor name does not answer the important questions

Imagine an auditor asks about a customer accepted eight months ago. A plausible response needs more than a purchase order and a screenshot:

  • Which lists and datasets were in scope that day?
  • Were they current, unavailable, stale or excluded?
  • What input did the organisation screen?
  • Did the system return candidates or a clear result?
  • If candidates existed, which identifiers were compared?
  • Who decided the alert was a false positive, and what evidence did they consider?
  • Was the customer re-screened after a material source, ownership or risk change?

Vendor selection is relevant to some of these questions. It does not answer them. A product can have a familiar brand and still leave the customer with no durable record of source state or analyst reasoning. Equally, a smaller product can be operationally strong if it preserves the decision record honestly.

This is the distinction between screening software and screening assurance infrastructure. The first returns a result. The second helps the organisation demonstrate what that result meant at the time it was used.

The five control surfaces to make visible

1. Coverage is a state, not a marketing number

“We screen 100 lists” is not a useful control statement without qualification. A list can be active, stale, under maintenance, removed for licensing reasons or out of scope for a particular decision. The control needs a visible coverage state.

That is why a public source-inventory page is not just a marketing artefact. Internally, the same registry should feed the screening engine, the customer-facing evidence record, the product documentation and all public coverage claims. If those surfaces disagree, the control is already difficult to defend.

2. A candidate is not a match

Name screening is an act of retrieval under uncertainty. A candidate may share a name, an alias, a transliteration or a partial identifier with a list record. Treating every candidate as a confirmed match creates unnecessary friction; treating the absence of a candidate as proof of no risk creates false confidence.

A reviewable system shows why the candidate was returned and lets the reviewer record the facts that supported clearance, escalation or a further-information request. A confidence score alone does not preserve this reasoning.

3. Human review must leave a human trace

Manual review is often where the meaningful decision happens and where the audit record becomes weakest. An “approved” status is not enough. The reviewer should be able to record the identifiers checked, the evidence used, the limitation encountered, the disposition selected and, where required, the second approver.

This is not bureaucracy for its own sake. It prevents the next reviewer from re-investigating the same false positive from zero and helps the business distinguish a real clearance from a decision that was simply never completed.

4. Change must reopen the question

The truth of a screening decision is time-bound. A source update, new beneficial owner, changed payment behaviour, new geography or new transaction purpose can change the risk picture. The system should preserve the original decision and attach the later review to it rather than overwriting history.

That is the point of continuous monitoring: not to create an endless alert stream, but to make a previous answer revisit-able when the facts change.

5. Evidence must be exportable

The final test is simple. Could the team hand a reviewer a compact, intelligible record without hunting across inboxes, spreadsheets and vendor portals? A useful record contains the input, normalised query, source state, candidate reasoning, evidence references, disposition, timestamps and the person or rule that made the decision.

Verifex calls this record an Evidence Capsule. The name is less important than the discipline: the decision needs to survive the moment in which it was made.

What to do this quarter

Compliance leaders do not need to wait for a regulatory event to improve this:

  1. Take ten cleared and ten reviewed historical cases.
  2. Ask whether each can answer the seven audit questions above.
  3. Identify which facts only live in a person’s memory, a screenshot or an old vendor interface.
  4. Define a minimum decision-record schema for every new case.
  5. Set a product-truth rule: coverage and freshness claims must come from one registry, not a sales deck.

The result is not a promise of compliance. It is something more useful: a control that can be inspected.

Where Verifex fits

Verifex is designed around the decision record, not just the risk label. It keeps source context, candidate reasoning, coverage state and a retrievable Evidence Capsule attached to the screening workflow. Teams should validate its current coverage and operating status against the live Sources & Freshness inventory for their own use case.

Sources

This is educational material about screening operations. Verifex provides screening infrastructure and evidence records, not legal advice, transaction approval, or a replacement for your risk-based compliance program.

Run a screening and inspect the decision record.

The free plan includes OFAC and UN screening. Coverage stays explicit when a required source is unavailable.

Start screening free