For compliance, procurement and engineering buyers

What belongs on a sanctions screening procurement checklist?

Most screening RFPs ask about list coverage and price and stop there. The questions that actually predict whether a decision will survive an audit are about evidence and failure modes, what the tool does when a source is down, whether a no-hit is reconstructable, and whether the vendor tells you the truth about its limits. This is that checklist, with the red flags that should stop a purchase.

Primary sources

Coverage and sources

AskWhy it mattersRed flag
Which sources, and how do you show their state per result?Coverage is only meaningful if you can see which sources answered.Coverage is a marketing count, not a per-result state.
How current is each source, and how do you expose staleness?A stale list produces stale no-hits.No per-source freshness; a single 'daily' claim for everything.
What happens when a source is unavailable?This is where false clears are born.An unavailable source returns an empty match list that looks clean.

Decision and evidence

AskWhy it mattersRed flag
Does a response carry coverage, candidate completeness, mode and eligibility?These are the fields an audit turns on.The response is a score and a label.
Can I retrieve a decision by ID for the full retention period, with integrity?A record you cannot produce is not evidence.No retrieval, no integrity hash, or records that can change silently.
Do you separate a machine result from an analyst disposition?They are different facts.The tool overwrites the machine result with the human action.

Honesty and failure modes

  • Ask which scripts and languages the tool cannot screen, and what it returns for them. A vendor that claims to screen everything is overstating.
  • Ask how it handles the OFAC 50 Percent Rule and ownership it has no data for. The honest answer is 'we report what we have and route the gap to review.'
  • Ask for the benchmark methodology and confidence intervals, and confirm it is labelled self-administered. A single accuracy number with no method is a marketing figure.
  • Ask it to demonstrate a partial-coverage result live. If it cannot show you one, it may not produce one.

Operations and data

  • Where is data hosted and processed, and is that stated plainly rather than implied?
  • What is the record retention, and does it align with your five-year (or longer national) obligation?
  • How are changes to sources detected and turned into re-screening, and is that evidenced?
  • Does the contract disclose limitations honestly, or does it lean on 'compliant' language it cannot stand behind?

Limitations

  • A checklist scores a vendor's claims; it does not test them. Pair it with a test kit run on your own data before you sign.
  • Regulatory obligations vary by member state and entity type. This checklist is a starting point for due diligence, not a compliance determination.
  • No screening product removes your obligation to make the final decision. The strongest tool makes that decision defensible; it does not make it for you.
  • This page is an implementation reference, not legal advice.

Build the evidence, not just the alert

Questions

What is the single most predictive procurement question?

Ask the vendor to show you a live partial-coverage result, a screen where a source was unavailable. Whether it can produce an honest partial result, rather than a clean-looking no-hit, predicts most of what matters.

How do I score 'evidence' objectively?

Score a real response against the open Screening Decision Record. If it carries sources and versions, coverage, candidate completeness, decision, eligibility and an integrity reference, it is a record. If it is a score and a label, it is not.

Should a vendor's 'compliant' marketing reassure me?

No, treat it as a warning. No screening product can, on its own, satisfy your obligations; their interpretation stays with you. A vendor that markets a compliance outcome is describing something it does not control.

This page is an implementation reference for engineering and compliance teams. It is not legal advice and does not certify any regulatory outcome. Regulatory obligations, their interpretation, and the decision to treat any result as clear remain yours. Verifex supports the workflow and preserves the evidence; it does not make the compliance decision.