Beyond the watchlist: why a data feed isn’t a compliance programme

It is tempting to treat compliance as something you buy: a subscription to a watchlist and PEP database, and the quiet assumption that a name-check against it is due diligence.

Illustration for “Beyond the watchlist: why a data feed isn't a compliance programme”

It is tempting to treat compliance as something you buy: a subscription to a watchlist and PEP database, and the quiet assumption that a name-check against it is due diligence.

It isn’t. A watchlist is an ingredient, not a meal.

The gap between data and a decision

Take the EU’s Anti-Money Laundering Directive, Directive (EU) 2015/849, as a benchmark of what the law actually asks for. It requires Member States to make obliged entities identify the customer and verify that identity from a reliable and independent source. Firms must identify and assess their money-laundering and terrorist-financing risks, taking into account risk factors relating to customers, countries or geographic areas, products, services, transactions and delivery channels. Those risk assessments must be documented and kept up to date, and firms must be able to demonstrate to their supervisor that their measures are appropriate to the risks identified.

The duty does not stop at onboarding. The Directive requires ongoing monitoring of the business relationship, including scrutiny of transactions and keeping the documents, data and information held up to date. For legal persons, trusts, companies, foundations and similar arrangements, firms must take reasonable measures to understand the ownership and control structure. And customer due diligence records must be kept for five years after the business relationship ends.

A raw data feed does none of that. Between the feed and the audit file sits the work that matters:

  • matching logic that doesn’t drown analysts in false positives;
  • a risk rating that weighs sanctions, PEP status, adverse media and jurisdiction, and that you can defend;
  • ownership analysis for companies and trusts, and for sanctions exposure beyond people and companies: OFAC’s SDN list also lists maritime vessels and aircraft blocked by OFAC;
  • case management, escalation and four-eyes sign-off;
  • monitoring for the life of the relationship, not a one-off check;
  • and a complete record the whole way through.

Buy only the list, and you build and maintain all of that yourself.

Questions to ask about the data contract

Coverage is only one part of a data decision. Before renewing, ask how the contract charges for re-screening and monitoring as your customer book grows, and how much of your control framework is wired to one supplier’s data schema. Those two answers decide whether screening is a capability you own or a dependency you rent.

Many authoritative lists are published by the bodies that issue them

These authoritative sources, for example, are published by their issuers:

  • OFAC runs a Sanctions List Service with list data ready for download, from the Specially Designated Nationals (SDN) List or the Consolidated (non-SDN) List.
  • The UN Security Council provides its Consolidated List in XML, HTML and PDF formats.
  • The UK publishes the UK Sanctions List, which is now the only source for all UK sanctions designations; the OFSI Consolidated List of Asset Freeze Targets closed on 28 January 2026.
  • The World Bank publishes its listing of debarred firms and individuals, who are ineligible to participate in World Bank-financed contracts for the periods indicated.

Enforcement authorities publish too: the US Department of Justice’s Office of Public Affairs, for example, is responsible for ensuring that the public is informed about the Department’s activities. Adverse media is, by definition, in the media.

How SonarPulse approaches it

This section describes SonarPulse’s own product.

SonarPulse was, in its early days, built on a premium PEP feed. We deliberately moved off it, because we could reach comparable coverage by aggregating official, open and alternative sources, with a localised in-country PEP database on top. Our clients get that coverage without a premium data subscription, without per-record metering and without lock-in.

Once the data flows into a platform rather than a search box, the rest follows in one place: consistent matching, a transparent risk score, UBO hierarchies, perpetual monitoring, and a one-click due-diligence report with a complete audit trail.

From “did we search?” to “can we prove it?”

The law asks you to identify, assess, document, monitor and keep the record. A list, on its own, does none of those. That is the difference between owning a list and running a compliance operation.

> A watchlist tells you a name might be risky. A platform tells you what to do about it — and helps you prove you did.

SonarPulse is an end-to-end compliance platform, delivered as an in-country cloud service (on-premises optional). [Learn more / request a demo].


Sources

This article draws on the following sources. Follow the links for the original text.

Start with a compliance health check.

A working session with your compliance team, then a walkthrough against your own risk appetite: the lifecycle end to end, scoring weights set to your policy, and a review of the audit trail the system produces.

Or write to info@sonarpulse.mu