Sanctions Screening Evidence: Reviewable Decision Records
How to preserve structured screening evidence for audit, from first query to exportable decision record.
Decision contract
A zero-match result is not enough on its own.
The API returns the conditions a caller must check before treating a screening result as clear. A retrieved candidate is not a confirmed identity, and an unavailable, partial, or capped result is not complete coverage.
- screening_mode
- An `exact_only` result may never be read as a clearance. The mode deliberately skips fuzzy, phonetic, transliteration and typo recovery, so “no exact candidate” is not evidence the party is unlisted.
- clearance_eligible
- When false, no combination of other fields makes the result clean. Treat it as unresolved regardless of `risk_level`.
- coverage_status
- Partial or unavailable coverage cannot clear. Absence of a hit in the sources that answered says nothing about the ones that did not.
- candidate_set_complete
- A truncated set cannot clear. No-hit inside a capped set is not no-hit — it is no-hit in the part that was examined.
Why evidence matters
Regulators and auditors do not ask "Did you screen?" They ask what was checked, which list version was active, and why you cleared this entity. When its evidence state reports available, a Verifex Evidence Capsule can preserve the recorded decision context as structured data rather than memory.
In OFAC enforcement actions, the ability to produce documented evidence of screening has been a key part of an internal control record. Whether and how a regulator evaluates a record depends on the applicable legal framework and facts. The Evidence Capsule is designed to provide exactly this documentation.
What regulators ask for during audits
Based on published examination manuals from OFAC, FinCEN, and the EBA, auditors typically request:
- A complete list of screening policies and procedures, including risk thresholds and escalation paths
- Timestamped records of every screening query, including the name screened, lists checked, and results returned
- Documentation of which sanctions list versions were active at the time of each screening
- Records of reviewer decisions (clear, review, escalate) with reviewer identity, timestamp, and rationale
- Evidence of periodic re-screening, including schedule, scope, and results
- Training records showing that compliance staff understand screening policies and procedures
Why list versions matter
Sanctions lists change daily. A name that was not on a list yesterday may be added today. If a regulator asks why you cleared an entity on a given date, you need to prove that the entity was not on any relevant list as of that date. Without version tracking, you cannot prove a negative.
The Evidence Capsule captures the exact list versions checked at screening time. If OFAC published an update at 2:00 PM and you screened at 1:30 PM, the capsule records that the screening used the pre-update version. This is critical for audit defense.
Evidence checklist
- Store request_id from every screening response in your case management system
- Capture evidence_capsule_id and evidence_capsule_url only when evidence_persistence reports available
- Record the deciding engine, policy context, and screening contract supplied by the response
- Record sources checked, plan exclusions, unavailable sources, and coverage status
- Record list versions checked at the time of screening, since they change over time
- Preserve the full match rationale including confidence score, match type, and source severity
- Document reviewer action (clear, review, escalate) with timestamp and user ID
- Export Evidence Capsules quarterly for external audit review
- Confirm the current retention policy and any contractual recordkeeping terms before relying on a retention period
Building your audit trail
An audit trail is more than a log file. It is a reviewable record of each screening decision your business keeps. A robust audit trail includes a query record (the exact name, type, and optional data submitted), a response record (all matches found, confidence scores, match types, and source lists), a decision record (the action taken, who made it, when, and why), a list-version record, and the matching-engine version that produced the results.
When evidence_persistence reports available, the Verifex Evidence Capsule records this context in a structured JSON document. A pending or unavailable evidence state is not a retrievable durable record.
Compliance caveat: Evidence Capsules are decision-support records. They preserve screening context to support audit review but do not guarantee regulatory outcomes, certify counterparties, or replace a regulated business's risk-based compliance program.
Frequently asked questions
What is screening evidence?
Screening evidence is the structured record of what was checked, when, against which sources, and what decision context the response supplied. It includes the clearance fields and the evidence-persistence state, so a pending or unavailable record is not described as durable evidence.
Why do list versions matter?
Sanctions lists change daily. A name that was not on a list yesterday may be added today. Proving which list version was active at screening time is essential for audit defense.
Can I export evidence in bulk?
Available export routes depend on your plan and configuration. Confirm the current capability before designing an audit workflow around bulk export.
Is a zero-match result a clearance?
No. A zero-match result supports a clearance only when the result is clearance-eligible, Standard Screening was used, source coverage is complete, and the candidate set is complete. An available Evidence Capsule records the result; it does not make a weaker result clear.
This is educational material about screening operations. Verifex provides screening infrastructure and evidence records, not legal advice, transaction approval, or a replacement for your risk-based compliance program.
Continue reading
Run a screening and inspect the decision record.
The free plan includes OFAC and UN screening. Coverage stays explicit when a required source is unavailable.