Helping a firm choose screening technology through a risk and control lens
Experts assessed and challenged shortlisted sanctions and adverse media screening solutions, testing vendor capabilities against known risks, control requirements and future operating model needs. The review provided a defensible basis for vendor selection while establishing clear requirements for implementation, governance and go-live assurance.
Brief
A diversified global financial services firm required an independent assessment of whether its sanctions and adverse media (AM) framework to identify risk issues in the design and implementation of controls across a complex and rapidly evolving business. The challenge extended beyond conventional customer screening. Senior management needed clarity on whether the right customers, related parties, transactions and higher-risk activities were consistently identified, screened and governed across legal entities, regions and specialist platforms.
The firm’s activities included correspondent and omnibus relationships, payments, securities, trade-related activity, vessels and physical delivery, digital channels and other specialist businesses. Organic growth, acquisitions, legacy systems and partially integrated processes had created different screening arrangements across the group.
The review therefore needed to distinguish isolated operational exceptions from wider weaknesses in population coverage, data flows, system configuration, decision making and governance. It also needed to provide a practical basis for immediate risk mitigation and a broader programme of sustainable enhancement capable of supporting the firm’s continued growth.
Challenge
HKA was asked to provide independent second line support to a global diversified financial services firm selecting a replacement screening solution. The firm had identified weaknesses in its existing screening environment and wanted confidence that a replacement solution would address those issues while supporting the risks arising from its specialist businesses, customer relationships and activities.
The requirement went beyond buying a system with the broadest feature set. The solution needed to support proportionate screening across the full in-scope population, while clearly distinguishing routine screening from the enhanced due diligence required for higher-risk relationships, activities or results.
Initial vendor responses covered false-positive reduction, payment and vessel screening, data coverage, APIs, calibration, case management, reporting, access controls and operational support. However, headline scores did not always show whether a capability was standard, separately licensed, dependent on premium data or professional services, configurable after selection, or still on the product roadmap.
The firm therefore needed an evidence-led way to compare vendors and connect the selection decision to known risks and issues. It also needed to understand the data, workflow, governance, contractual and operating-model changes required to make the chosen technology effective in practice.
Solution
HKA translated identified control weaknesses, known screening challenges and future state requirements into a structured second line requirements framework covering 14 decision areas. These included screening scope, configuration and calibration, source and linked-party coverage, testing, population reconciliation, historical screening, sanctions and adverse media workflows, AI overlays, Group and local profiles, user acceptance testing, production controls, decision rights, management information, auditability, resilience, contractual protections and exit.
We structured the decision across four stages: selection, contracting, implementation and go-live. This separated the capabilities needed to select a credible vendor from the firm specific integrations, workflows, reporting and data controls that would need to be delivered before production use. It also brought change notification, resilience, audit rights, data access, portability and exit into the commercial discussion rather than treating them as assumed platform features.
HKA designed a controlled testing approach to validate vendor claims and assess whether shortlisted solutions could address known screening weaknesses. This included screening misses and cases selected to challenge language and source coverage, aliases and transliterations, direct and linked-party detection, matching behaviour and analyst visible outputs. We defined the limits of the exercise clearly: test results could compare aspects of screening performance, but could not by themselves demonstrate population completeness, workflow effectiveness, management information quality, resilience or readiness of the future operating model.
For each shortlisted vendor, we mapped proposal evidence against the requirements and developed focused walkthrough and testing questions. We distinguished between capabilities that were documented, demonstrated, independently tested, contractually committed or unsupported. This enabled consistent challenge and highlighted where initial scores needed further evidence or commercial clarification
Results
The firm gained a more defensible basis for screening vendor selection by linking technology decisions directly to identified risks, control requirements and implementation considerations.
The assessment moved the evaluation beyond feature comparisons and vendor marketing claims, providing a structured approach to testing whether shortlisted solutions could address known weaknesses in the existing screening environment.
The work also established clear requirements for contracting, implementation and go live assurance, helping reduce the risk of selecting a platform that met procurement requirements but failed to deliver the required control outcomes in practice.
- Risk-led requirements framework built around identified control weaknesses and future state screening requirements.
- A controlled testing approach designed to assess whether shortlisted solutions could address known screening weaknesses.
- Clear visibility of modules, premium data, professional services, configuration and roadmap dependencies before selection.
- A reusable framework supporting vendor challenge, contracting, implementation assurance and go-live approval.
- Reduced risk of replacing technology without addressing underlying data, workflow and governance issues.