Beyond the watchlist: why a data feed isn’t a compliance programme

For twenty years, "buying compliance" has meant buying a list. A subscription to a premium watchlist and PEP database, billed per record or per search, and the quiet assumption that a name-check against it is due diligence.

For twenty years, “buying compliance” has meant buying a list. A subscription to a premium watchlist and PEP database, billed per record or per search, and the quiet assumption that a name-check against it is due diligence.

It isn’t. A watchlist is an ingredient, not a meal.

The gap between data and a decision

A regulator doesn’t ask whether you searched a database. They ask whether you identified the customer, assessed their risk, documented the decision, monitored them over time, and can prove all of it years later. A raw data feed does none of that. Between the feed and the audit file sits everything that actually matters:

  • matching logic that doesn’t drown analysts in false positives
  • a risk score that weighs sanctions, PEP status, adverse media and jurisdiction into a defensible rating
  • beneficial-ownership unpacking for corporates, trusts and vessels
  • case management, escalation and four-eyes sign-off
  • continuous monitoring, not a once-a-year re-check
  • and an immutable audit trail the whole way through.

Buy only the list, and you build — and maintain — all of that yourself. Or you don’t, and you hope the auditor doesn’t look too closely.

The per-record trap

Premium data is also priced to punish the thing you want most: growth. Per-record and per-search metering means every new customer, every re-screen, every monitoring pass adds cost. Compliance becomes a variable tax on your book rather than a fixed capability you own.

There’s a quieter cost too — lock-in. When your entire control framework is wired to one vendor’s data schema and pricing, you’ve handed a critical dependency to a third party.

A different answer: aggregate, don’t rent

Here’s the part the incumbents would rather you didn’t notice: the authoritative sources are largely open. OFAC, the UN, the EU, the UK, World Bank debarment, Interpol notices — these are official, published lists. Court and enforcement records (DOJ, SEC, national courts) are public. Adverse media is, by definition, in the media. Curated open aggregators consolidate much of it.

SonarPulse was, in its early days, built on a premium PEP feed. We deliberately moved off it — not because the data was bad, but because we could reach comparable coverage by aggregating official, open and alternative sources and add a localised in-country PEP database on top. The result: our clients get broad, defensible coverage without a premium data subscription, without per-record metering, and without lock-in.

From “did we search?” to “can we prove it?”

The point of aggregating sources isn’t just cost. It’s that once the data flows into a platform rather than a search box, everything downstream becomes possible: consistent matching, a transparent risk score, UBO hierarchies, perpetual monitoring, and a one-click due-diligence report with a complete audit trail.

That’s the difference between owning a list and running a compliance operation.

A watchlist tells you a name might be risky. A platform tells you what to do about it — and proves you did.

SonarPulse is an end-to-end compliance platform, delivered as an in-country cloud service (on-premises optional). Request a compliance health check.

Start with a compliance health check.

A working session with your compliance team, then a walkthrough against your own risk appetite: the lifecycle end to end, scoring weights set to your policy, and a review of the audit trail the system produces.

Or write to info@sonarpulse.mu