Skip to content

Risk · Sanctions screening

Screen every verified name against the lists that matter.

The extracted name, and the date of birth when there is one, are screened against the OFAC SDN list with its aliases and the UN Security Council consolidated list. Lists download from their official sources into an in-memory index inside KYCVerify.

kycverify · productaml
lists: OFAC SDN and UN consolidated
2
default match threshold
0.90
default review threshold
0.82
OFAC SDN · UN

What it checks

AML screening, check by check.

Each rule below is what the engine actually runs. The result is written as a aml check with its score and warnings.

  • Normalised names

    Diacritics are stripped, punctuation and honorifics dropped, whitespace collapsed. Aliases of every quality are indexed, as are original-script names.

  • Order-insensitive matching

    A token-set Jaro-Winkler blend scores names regardless of order, so "Hussein Saddam" meets "Saddam Hussein".

  • Date of birth

    A supplied date that falls inside a listed date, year or range raises the score; one that conflicts lowers it. "Circa" years match within a year.

  • Never declined on a hit alone

    A potential match sends the AML check to review with the matched entry, its programme and a reference link. If another check fails and auto-decline is on, the session is declined and the hit is recorded in the decision.

Try it

See why a name scores what it scores.

Normalisation, order-insensitive token pairing, Jaro-Winkler credit, the coverage blend and the date-of-birth adjustment, worked through on fictional names. No real list is sent to your browser.

  • The rules are ported line for line from the Rust engine, and the page names the file.
  • Everything runs locally in this tab. No request is made while you type.
  • Reset puts the example back; nothing is saved.

Sanctions name scoring, step by step

Runs in your browser
Try

From the verified identity.

A fictional entry for this demo.

Date of birth

1 · Normalise and pair tokens

  • erikssoneriksson1.00
  • annaanna1.00
  • mariamaria1.00

2 · Blend coverage, adjust for date of birth

0.6 × 1.000 + 0.4 × 1.000 = 1.000 → 1.000

review 0.82match 0.90

Potential match (severity high): sent to review

A hit never fails the AML check by itself: the check goes to review, and the reviewer sees the listed entry, its programme and a link to the source. If another check fails and auto_decline is on, the session is declined and the hit is recorded in the decision.

Simplified for the browser. The server also blocks candidates through a trigram and consonant-skeleton index, weighs particles and legal-form words down, merges compounds and credits initials, so its scores can differ from these.

Logic ported from backend/crates/kyc-aml/src/index.rs. Nothing you type leaves this page.

How it works

What happens, in order.

  1. 1

    Refresh

    An admin refreshes each list from the console. The API follows the official redirects, parses the files and rebuilds the index.

  2. 2

    Screen

    At submit, the identity is screened against the lists the workflow names, with the review threshold as the floor for a hit.

  3. 3

    Decide

    No hits passes. Any hit goes to review with a potential_match warning. A list that is not loaded sends the session to review rather than passing it.

Configuration

The workflow keys and their defaults.

Workflow · json
"aml": {
  "enabled": true,
  "lists": ["ofac_sdn", "un_consolidated"],
  "match_threshold": 0.90,
  "review_threshold": 0.82
}
KeyDefaultMeaning
listsbothWhich lists to screen against.
match_threshold0.90Scores at or above are high-severity hits.
review_threshold0.82The minimum score that counts as a potential match.

Reference

How listed dates of birth are compared.

Lists record dates with different precision. Each form becomes a date range; a supplied date inside it adds 0.05, outside it subtracts 0.10.

How listed dates of birth are compared.
Listed asMeansExample source wording
1960-01-31That exact dateDOB 31 Jan 1960
1960-01Any day of that monthDOB Jan 1960
1960Any day of that yearDOB 1960
1960-1962Any day in the year rangeDOB 1960 to 1962; UN BETWEEN
circa 19601959 to 1961circa 1960; UN APPROXIMATELY

Reasons and warnings

Exact codes, as they appear in the check's data and warnings, so you can branch on them.

AML screening codes
CodeOutcomeWhen
aml_potential_matchreviewAt least one entry scored at or above review_threshold; severity high at or above match_threshold.
aml_lists_not_loadedreviewA list named in the workflow has not been downloaded on this server.
aml_no_namereviewNo name was extracted to screen.

API

Screen a name without a session.

POST /v1/checks/aml with a full name, and optionally a date of birth (YYYY-MM-DD or YYYY) and nationality. Each match carries the listed entry, its programmes and a link to the source.

In a session

Screening a name directly

aml check · json
POST /v1/checks/aml
{ "full_name": "Anna Maria Eriksson", "date_of_birth": "1974-08-12" }

200 OK
{
  "matches": [],
  "screened_at": "2026-10-03T09:12:44Z",
  "lists": [
    { "list": "ofac_sdn", "version": "…", "fetched_at": "…" },
    { "list": "un_consolidated", "version": "…", "fetched_at": "…" }
  ]
}

Screen a name without a session.

curl -X POST https://kycverify.me/api/v1/checks/aml \
  -H "x-api-key: $KYC_API_KEY" \
  -H "content-type: application/json" \
  -d '{
    "full_name": "Anna Maria Eriksson",
    "date_of_birth": "1974-08-12",
    "nationality": "SWE"
  }'

200 OK

{
  "matches": [],
  "screened_at": "2026-10-03T09:12:44Z",
  "lists": [
    { "list": "ofac_sdn", "version": "…", "fetched_at": "…", "entity_count": …, "status": "ok" },
    { "list": "un_consolidated", "version": "…", "fetched_at": "…", "entity_count": …, "status": "ok" }
  ],
  "warnings": []
}

Limits

What it does not do.

Stated up front, so you can decide what to pair it with.

  • Two lists only. No PEP lists, no adverse media, no other national lists, and no ongoing monitoring of past sessions.
  • Lists are as fresh as your last refresh. Schedule refreshes to match your compliance policy.

FAQ

AML screening: questions.

Where do the lists come from?

The OFAC SDN and alias CSVs from the US Treasury and the consolidated XML from the UN Security Council, downloaded by KYCVerify from their official URLs.

Can I screen without a session?

Yes. POST /v1/checks/aml takes { full_name, date_of_birth?, nationality? }, and the console has a screening tool for reviewers.

Try it in the sandbox today.

Every check is available from the first sign-up, with test keys and a default workflow. Talk to us when you are ready to verify real people.