Sanctions and PEP screening are no longer tick-box exercises. Regulators across Malta, Gibraltar, the Isle of Man and the UK are conducting increasingly granular AML inspections, and the evidence shows that operators with immature screening architectures are the ones receiving remediation notices and financial penalties. This article is aimed at teams that have the basics in place and are ready to move their programme to a genuinely defensible standard.
Understanding the Screening Obligation in Depth
Most operators understand that they must screen customers against sanctions lists such as OFAC, the UN Consolidated List, the EU Common Foreign and Security Policy list and the UK Financial Sanctions Register. Fewer appreciate that the obligation is continuous, not event-driven. A customer who was clean on registration may appear on a sanctions list tomorrow, and the burden is on the operator to detect that change in near real time, not at the next periodic review.
PEP screening carries a parallel but distinct obligation. A politically exposed person is not automatically high-risk; the requirement is to treat them as higher-risk by default and apply enhanced due diligence. The practical challenge is that PEP status is dynamic: politicians lose office, family members move in and out of scope, and close associates change. A static PEP flag set at onboarding decays rapidly without ongoing data refresh.
List Coverage: Why One Vendor Is Rarely Enough
Commercial screening vendors aggregate lists from multiple sources, but coverage varies materially. Operators serving regulated markets in multiple jurisdictions should audit their vendor's list coverage on at least a quarterly basis, asking specifically:
- Which national PEP databases are included, and how frequently are they refreshed?
- Does the feed include regional and municipal politicians, not just heads of state and ministers?
- Are adverse media signals integrated, or does the vendor rely solely on structured list data?
- How is list latency measured, and what is the SLA for a new designation appearing in the screening engine?
For operators in markets where local lists are thin, such as emerging regulated jurisdictions, supplementing a tier-one vendor with a secondary data source for that specific geography is often the only way to achieve adequate coverage.
Fuzzy Matching and Threshold Calibration
Screening engines use probabilistic name-matching algorithms to surface potential hits. Setting the match threshold too high produces false negatives; setting it too low buries analysts in false positives that erode alert quality over time. There is no universal correct threshold. The right calibration depends on your player base demographics, the language scripts your customers use and the volume of alerts your team can realistically review.
Operators processing names in Arabic, Chinese or Cyrillic script need transliteration logic that handles multiple romanisation conventions. A compliance team reviewing only the latin-character version of a name is running a materially incomplete screen. Validate your vendor's transliteration coverage before you rely on it.
Threshold calibration is not a one-time configuration task. It should be reviewed whenever alert volumes shift significantly or when a new player acquisition channel is opened into a new geography.
Operationalising Continuous Screening
Batch overnight screening was acceptable practice five years ago. Today, regulators expect operators to demonstrate that the gap between a new designation and a player account being flagged is measured in hours, not days. The architecture to support this requires a screening engine that processes watchlist delta feeds as they are published, matches them against the full active player population in real time and routes confirmed hits to a case management queue with an automated account restriction trigger.
Key operational controls that experienced teams should have documented and tested include:
- A written procedure for what happens in the first hour after a sanctions hit is confirmed, including who holds authority to restrict the account and at what threshold that decision escalates to the MLRO.
- A tested process for reporting to the relevant Financial Intelligence Unit within mandated timeframes, which differ by jurisdiction.
- A clear record of how false positives were dispositioned, with analyst reasoning captured in the case management system.
- A periodic back-test comparing historic alerts against known designations to verify that your configuration would have caught them.
PEP Enhanced Due Diligence in Practice
Identifying a PEP is only the first step. The EDD obligation requires the operator to understand the source of wealth, the expected nature of the gaming relationship and to obtain senior management approval before establishing or continuing that relationship. In practice, this means your EDD questionnaire must be calibrated to PEP risk, not simply the generic high-risk template.
Operators should also document their policy on close associates and family members explicitly. Regulators have cited operators for screening PEPs but failing to apply proportionate scrutiny to an account clearly linked to a flagged individual.
Testing, Governance and Record-Keeping
Regulators expect to see evidence that the screening programme works, not just that it exists. Annual independent testing of the screening configuration, documented governance over threshold changes and a clear audit trail from alert through to disposition are the minimum expected standards for a mature programme as of early 2026.



