Operated function · identity and screening

Ask what proportion of your review queue turns out to be the wrong person.

Most operations cannot answer, because the outcome is recorded as cleared rather than as a false positive. It is usually the majority — and every one of them is a customer who wanted to open an account and is instead waiting behind a backlog caused by a shared surname.

What the review queue is actually made of

A customer applies. An automated check runs against sanctions, politically-exposed-person and adverse-media sources, and it is tuned conservatively — correctly, because the cost of a miss is regulatory and the cost of a false alarm lands on somebody who is not in the room.

The result is a queue. Common names generate matches constantly, and the same customer can generate a new match every time the source list updates. Somebody has to look at each one and establish that this person, with this date of birth, in this country, is not the person on the list.

That work is comparison against a written standard where one exists and against experience where one does not. What counts as sufficient to discount a match varies by reviewer, and the safest individual behaviour is always to escalate — so the escalation queue fills with cases that did not need it.

Meanwhile the customer is waiting, usually with no explanation, because telling somebody why they are delayed is constrained. From their side an application simply stops, and a meaningful share leave. Nobody records that as a screening cost.

And the documents arrive badly. A photograph of a document taken at an angle in poor light fails an automated check for reasons that have nothing to do with identity, and the customer is asked again with no explanation of what was wrong with the first one.

Nobody measures the false-positive rate, so nobody can manage it

Review outcomes are recorded as cleared or escalated rather than as true or false matches, so the proportion of the queue that was never the right person is unknown — and an unmeasured cost cannot be reduced.

That single measurement changes the conversation. When the queue is mostly name collisions on a handful of common names, the tuning question becomes concrete rather than theoretical, and it can be discussed with a compliance officer using evidence instead of instinct.

The second move is a written discounting standard: what specific evidence is sufficient to establish that a customer is not the listed person. Date of birth mismatch, nationality, a document that resolves it. Written down, versioned, owned by your financial crime function — which makes the clearing consistent and makes an audit defensible.

With that standard, clearing the obvious collisions is bounded work. Anything that does not clear cleanly under the standard escalates immediately, without an approximation — the same rule as everywhere else in this wave, and it matters more here because the alternative is a wrong decision about a person.

The third is document quality. Rejections for photo quality are recoverable in the moment if the customer is told specifically what was wrong while they still have the document in their hand, and unrecoverable a day later.

What never moves is the decision. Whether to onboard, whether a match is real, whether to file a report and whether to exit a relationship are regulated determinations that belong to named officers in your organisation.

What moves, and how you would know

The false-positive rate, measured for the first time — measured by review outcomes recorded as wrong-person versus genuine match, against a baseline that recorded only cleared or escalated.

Time a customer waits in review — measured by elapsed hours from flag to resolution, median and tail, where the tail is where abandonment happens.

Consistency of clearing — measured by clearances citing the specific discounting evidence under a written standard, as a share of all clearances.

Escalations that did not need to escalate — measured by escalated cases subsequently cleared as collisions, which is the direct measure of standard clarity.

Document rejections recovered in the moment — measured by resubmissions completed in the same session after a specific quality message, against next-day resubmission rates.

Customers lost during verification — measured by applications abandoned while in review, attributed to screening rather than to general drop-off.

any onboarding decision, any determination that a match is genuine, any suspicious activity report, any risk rating and any decision to decline or exit a relationship. Those are regulated acts performed by named officers in your organisation. Nothing here decides about a person, and nothing here changes your screening tuning — tuning is your compliance function’s decision.

Beside your screening provider, inside your onboarding record

Screening stays with your provider and at your tuning. This operation does not replace, re-tune or second-guess it — it works the queue that comes out, which is where the cost actually sits.

Case state stays in your onboarding or financial crime system. No second record of a customer’s screening status exists, because two records of whether somebody cleared is an audit finding waiting to happen.

The discounting standard is yours: written by your financial crime function, versioned, owned. It is the artefact an auditor will ask to see, and it keeps working if the engagement ends.

Handling identity documents and screening outcomes

Identity documents are among the most sensitive things a customer will ever hand over, and the retention position is stated rather than implied: they live in your store, under your retention schedule, and are not copied elsewhere.

Screening results are handled under the same constraint as your own team handles them. Where regulation limits what may be disclosed to a customer about why they are delayed, that limit is respected — a helpful explanation that breaches a disclosure rule is not helpful.

Every clearance records the specific evidence that discounted the match and the standard version applied. A clearance with no recorded basis is the finding an auditor writes up, and it is what this operation exists to eliminate.

Operational access is not permission to train. Identity and screening data does not become material improving anything serving another organisation, and identity documents are never used as training material in any form.

The money laundering reporting officer, and your regulator’s expectations

Your reporting officer owns the discounting standard and the escalation boundary, and both need to exist in writing before anything is delegated. A standard supplied by a vendor would be a governance failure in this domain specifically.

The audit question is what an examiner will see, and the answer improves: clearances that currently record an outcome will record the specific evidence and the standard version. That is a stronger position than the one being replaced.

Where an obligation attaches through your regulator, your licence conditions or a jurisdiction, it is marked applicability-gated rather than presented as standing.

Measure the false-positive rate. Clear nothing.

One trailing period of review-queue outcomes — read-only, nothing cleared and no tuning changed — reclassified into genuine matches and wrong-person collisions.

The observation phase produces the number almost nobody has: what proportion of the review queue was never the right person. It clears nothing, changes no tuning, and touches no live case.

It also shows the concentration. Where a small number of common names drive a large share of the queue, that is a tuning conversation your compliance function can have with evidence, and it may be the entire fix — no operated review required.

If you continue, the first delegation is clearing collisions that resolve cleanly under a written standard on one product, with everything else escalating immediately and no decision of any kind delegated.

Questions buyers actually ask

This is regulated activity. We cannot let an outside party touch screening.

The regulated acts are not delegated: no decision to onboard, no determination that a match is genuine, no risk rating, no report and no exit. Those stay with your named officers, and the scope says so before anything is connected. What is delegated is clearing collisions that resolve cleanly against a standard your own reporting officer wrote, with everything else escalating. If your position is that even that is a regulated act, the observation phase alone still produces the false-positive number.

Our screening vendor already handles this.

Screening generates the queue; the cost is in working it. The specific question worth putting to your vendor is what your false-positive rate is — most cannot answer, because outcomes are stored as cleared rather than as wrong-person. If yours can, and the rate is low, this is not your constraint.

Reducing false positives means loosening controls.

It would if the tuning were changed, and this changes no tuning — that is explicitly your compliance function’s decision and it is left alone. What changes is that the queue coming out is worked consistently against a written standard, with anything that does not clear cleanly escalating rather than being approximated. That is a tighter control than reviewer-by-reviewer custom, not a looser one.

Customers waiting is unfortunate but it is the cost of compliance.

Some of it is. The part that is not is the share of the queue that was never the right person, and until that number is measured the two are indistinguishable — which means the genuine compliance cost is being used to justify an unmeasured operational one. The first phase separates them and costs nothing but a read-only look at outcomes you already hold.