Sanctions and politically exposed person screening are no longer optional extras in the iGaming compliance stack. Regulators across Malta, Gibraltar, the Isle of Man, and emerging markets are actively examining how operators identify, escalate, and resolve matches, and enforcement actions in 2025 have made clear that "we have a tool in place" is not a sufficient answer on its own. What follows is a structured 90-day roadmap that operations and compliance teams can use to build, or meaningfully improve, a screening programme that satisfies both regulatory expectation and practical operational reality.
Why Screening Failures Happen
Most screening failures in gaming do not stem from a complete absence of technology. They stem from misconfiguration, poor alert triage discipline, or a disconnect between the tool and the wider customer lifecycle. A player flagged at registration may be cleared from an incomplete name-match review. A PEP who later acquires political status may never be re-screened because ongoing monitoring was set to annual rather than real-time or near-real-time. The 90-day roadmap below addresses each of these failure modes systematically.
Days 1 to 30: Baseline Assessment and Vendor Selection
The first month is diagnostic. Before procuring or reconfiguring any technology, compliance teams should conduct a gap analysis against three reference points: the operator's current licence conditions, the Financial Action Task Force's Recommendation 12 on PEPs, and any jurisdiction-specific guidance issued by the relevant gaming authority.
- Audit existing customer records to identify what proportion have been screened, when, and against which lists.
- Map the full customer journey to locate every point where a new identity data element is collected, including payment method changes and account updates, and confirm that each triggers a rescreening event.
- Evaluate screening vendors against four criteria: list coverage (UN, OFAC, EU, HMT and national lists), fuzzy matching capability and configurability, API response times compatible with your registration flow, and audit trail completeness for regulatory inspection.
- Appoint a named internal screening owner, typically the MLRO or a deputy, with documented authority to approve configuration changes and escalate complex matches.
Output from this phase should be a written gap report and a vendor shortlist with a documented rationale for the selection decision.
Days 31 to 60: Configuration, Integration, and Internal Controls
Month two is where the technical work happens alongside the policy layer that gives it meaning. Integration priorities should follow a clear hierarchy.
- Connect the screening API to the registration flow so that no account reaches an active state before a sanctions check returns a clear result.
- Configure PEP matching thresholds carefully: overly broad settings generate alert fatigue; overly narrow settings create blind spots. Document the chosen thresholds and the reasoning behind them.
- Build an ongoing monitoring schedule. Industry best practice in 2025 supports continuous or daily batch rescreening for active players, with a documented rationale for any less frequent approach.
- Draft a match-management procedure covering three outcomes: clear match (immediate account restriction and MLRO notification), possible match (time-boxed enhanced due diligence period, typically 48 to 72 hours), and false positive (documented dismissal with named reviewer and timestamp).
Screening configuration is a compliance decision, not a technical default. Every threshold setting should be reviewable by your regulator and explainable in plain language by your MLRO.
Days 61 to 90: Testing, Training, and Governance Embedding
The final month converts a configured system into an auditable programme. Three workstreams run in parallel.
Testing
Run a structured sample of known positive names through the live system and verify that alerts fire correctly. Test the false positive handling pathway with similar names that are not on any list. Document results and resolve any configuration issues before the programme goes fully live.
Training
Customer-facing and risk teams need scenario-based training, not just policy reading. Focus on how to handle a possible match during a live chat interaction, how to apply a temporary deposit restriction without tipping off the player, and how to escalate within the documented timeframes.
Governance
Embed screening performance into the monthly compliance reporting pack. Key metrics should include total alerts generated, average time to disposition, false positive rate, and any matches that resulted in a Suspicious Activity Report or licence-required notification. Set a formal review cadence, at minimum quarterly, to assess whether list coverage and thresholds remain appropriate as the player base evolves.
Ongoing Obligations Beyond Day 90
A 90-day roadmap delivers a functioning programme, not a permanent solution. Sanctions lists update daily. PEP databases change with every election cycle and government reshuffle. Operators should treat screening as a living control that requires the same governance discipline as any other risk management function, with version-controlled configuration records, annual independent reviews, and clear escalation paths to senior management when edge cases arise.



