Practical guide
AML compliance software: a screening-focused buying checklist
Evaluate AML software by actual scope: sanctions sources, identity controls, case management, monitoring, integrations, retention, and operational costs.
On this page
Start with the controls you need to operate
“AML software” can describe identity tools, screening databases, transaction-monitoring systems, case platforms, reporting products, or combinations of them. A useful evaluation starts with the required controls, not a feature count. FinCEN’s CDD framework illustrates why customer identity, ownership, and ongoing diligence are separate concerns.
This checklist focuses on the screening component. SanctionsKit supports selected-source screening, evidence, case review, and monitoring. It does not claim to replace the whole AML technology stack.
Test coverage at the source level
Ask for the authority, list purpose, supported entity types, source identifiers, update handling, and current availability. Distinguish supported production screening from reference material or planned coverage. Ask how overlapping source records are represented.
A large list count can include many related feeds or duplicate entries. It does not tell you whether a necessary source is present or whether the application preserves the underlying restriction.
Evaluate the reviewer’s evidence, not only the match score
Ask to see the submitted facts beside the source facts, including aliases, partial dates, identifiers, supporting fields, conflicts, and unknowns. A reviewer should be able to explain why the candidate was returned and how the identity decision was reached.
Use a representative synthetic sample. Include common names, different scripts, missing dates, organizations with similar trading names, and mismatched identifier issuers. Compare the explanation quality as well as the number of candidates.
Follow a case through its full lifecycle
Test assignment, comments, evidence references, independent review, corrected decisions, and exports. Confirm how the original screening result differs from the analyst’s later determination. Test access restrictions with a user who should not see the file.
Do not assume that a document link means the platform stores the document. In SanctionsKit, approved external document references point to records maintained outside the case platform. Repository access and retention remain important.
Test integration failure and monitoring recovery
For APIs, test timeout handling, idempotent retries, invalid payloads, rate limits, unavailable sources, and evidence retrieval. For monitoring, test a changed source record, a failed rescreen, a paused subject, and webhook redelivery.
A control that looks effective in a demonstration can fail at the boundaries between systems. Ask who owns the exception queue and how the team detects that a supposedly monitored subject is not receiving successful checks.
Compare total workload and commercial terms
Estimate initial checks, periodic rescreens, event-triggered checks, batch volumes, analyst time, retention needs, and exports. Separate an HTTP request from a billable completed screening; replay and retrieval behavior matter. Use current pricing and the vendor’s terms rather than an old comparison article.
Finish with a written acceptance record: which controls passed, which remain external, known limitations, operational owners, and review dates. Buying a screening tool is not evidence that the organization’s entire AML program is compliant.