Reviewing possible AML matches
In brief: Decide each hit, sign off the screening, then approve.
When an AML screening finds names on a sanctions, PEP, adverse media or warnings list that look like your client, the screening comes back as a Possible match or Match. Most of these are people who share your client's name. Your job is to decide, hit by hit, whether each one is your client, and to record why.
The client stays in Review pending until the screening is signed off. A client cannot be approved while the screening is waiting for sign-off.
Where to find it
Open the client, then Overview, then Report on the AML screening evidence row. Each hit is a row you can expand to see the list it came from, the matched name, and any date of birth, nationality, address or position the list holds.
The counters at the top show how many hits are Unreviewed, Cleared, Confirmed, Escalated and Pending.
When the screening marks a match unlikely
The Overview evidence row summarises the latest screening. Earlier checks remain in the full screening history. The card includes Other lists for hits outside sanctions, PEP and adverse media, with the dataset name shown. A screening's own false positive is a suggestion, not the firm's judgement. The row says Possible match, marked unlikely by the screening and the card says To confirm until the MLRO signs off. Choose the confirmation link below the rows to open Full AML screening. After sign-off, the badge shows the firm's outcome.
Step 1: decide each hit
Compare what the list says with what you verified about your client. A name on its own proves very little: common names return many hits.
| What you find | Decision | Reason to record |
|---|---|---|
| Different date of birth or age | Clear false positive | Date of birth / Age |
| Different nationality or country | Clear false positive | Nationality / Geography |
| A different address or area, such as a councillor for a council your client does not live in | Clear false positive | Geography, and say what you compared |
| The listed person has died, and your client passed a live selfie check | Clear false positive | Deceased |
| Different gender | Clear false positive | Gender |
| It is your client | Confirm match | Other, and say how you know |
| You cannot tell and want the MLRO to decide | Escalate | |
| You need something from the client first | Mark pending | Insufficient information |
Always add a note, even when the reason code seems to say it all. "Name only, list entry is a councillor in Bangor LL57, client lives in Llanelli SA15 per ID and proof of address" is a record a supervisor can rely on. "Common name" on its own is not.
For a PEP or sanctions match, including a relative or close associate of a PEP, Certivus will not let you clear it without a note. Say what you compared and what did not match, for example the date of birth or address on the list entry against the client's ID. If a list entry has no date of birth, do not choose "Date of birth mismatch"; pick the reason that matches what you actually checked.
You can change a decision until the case is signed off. The earlier decision is kept in the history.
The client's PEP status follows your decisions on the latest screening. Once every PEP hit is cleared as a false positive, the client stops showing as a PEP. If any PEP hit is confirmed, the client shows as a PEP. While a PEP hit is undecided, escalated or pending, the status from the screening stays.
Step 2: sign off the screening
A firm owner, a manager or the firm's MLRO (or deputy MLRO) presses MLRO Sign-off and chooses an outcome:
- Cleared: every hit is a false positive. Certivus will not accept Cleared while any hit is confirmed, escalated, pending or undecided.
- Confirmed: at least one hit is your client. Certivus will not accept Confirmed unless a hit is marked as a confirmed match, and every escalated or pending hit has been decided.
- Inconclusive: you cannot decide yet. This stops onboarding: the client cannot be approved until you revoke the sign-off, resolve the hits and sign off again.
Signing off locks the hit decisions and removes the item from the MLRO Queue. To change anything afterwards, use Revoke sign-off and give a reason.
Step 3: approve, reject or escalate the client
Use Record decision on the client header.
- Approve needs a completed risk assessment and a signed-off screening. If the screening was signed off Confirmed, more is needed, depending on what was confirmed (see below). The client's identity must be verified too: the full list is in Approving a client. If something is missing, the message tells you what.
- Reject, Escalate and Request additional documents are always available. You never need to finish the review to refuse a client.
Requesting more documents
Request additional documents puts the client on hold and emails them to ask for what you need.
- Use Message to your client to say which documents you want, for example a recent utility bill. If you leave it empty, the client gets a short message saying you need more documents and asking them to get in touch.
- The email comes from your firm, and replies go to your firm's contact email. It also gives your firm's phone number and email, if you have set them.
- Your Rationale notes stay internal. They go on the client's file and are never sent to the client.
- The email reaches your client even if they once unsubscribed from Certivus notification emails, because it is a service message they need, not marketing.
- If it cannot be sent, Certivus tells you why. If the address has bounced, check it with your client, update their record and request again. If your client has marked our emails as spam, or has no email address on file, contact them directly.
- If the client opens their verification link again, they see "More information needed" and how to contact you.
- If the client has no email address, or the email could not be sent, you see a warning. Contact the client yourself in that case.
What the outcome means for the rest of the file
-
Cleared: the hits no longer make enhanced due diligence mandatory on the Client Compliance Status card. A high risk rating on the client still does.
-
Confirmed: enhanced due diligence is required. What else is needed depends on what you confirmed:
- A sanctions match. The client is on a sanctions hold. Do not deal with their money or accept payment from them without a licence from OFSI (the Office of Financial Sanctions Implementation), and report to OFSI as soon as practicable. You must report even if you decide not to act. The client cannot be approved until you record the OFSI report reference and the licence you are relying on, in the Sanctions hold panel on the screening. If you hold no licence, report the suspected breach to OFSI anyway and record it with Record a breach report to OFSI (the OFSI reference, the date, who reported it, and notes). That record is kept on the client's file; it does not lift the hold.
- A politically exposed person, a family member or a close associate. The regulations (MLR 2017 reg 35(5)) require senior management approval, source of wealth, source of funds and enhanced ongoing monitoring. Certivus needs the enhanced due diligence record to carry the approver's name, the approval date, source of wealth and source of funds, all recorded after the screening was signed off. When you confirm a PEP match, Certivus also asks what kind of PEP it is (domestic, foreign, or a senior official of an international organisation), whether the client is the PEP, a family member or a known close associate, and, for a former PEP, the date they left office. A former PEP is treated as a PEP for at least 12 months after leaving office; a family member or close associate may be treated as an ordinary client from the day the PEP leaves office (AMLGAS 5.3.27). The PEP details panel on the screening shows this and lets you update it later.
- Anything else (for example adverse media): an enhanced due diligence record.
If you suspect money laundering, raise an internal suspicious activity report from the client's page. Certivus records the report and the NCA reference; the submission to the NCA itself happens outside Certivus.
In the risk assessment
The client's risk assessment asks whether they are a politically exposed person, on a sanctions list, or (for companies) subject to adverse media. Certivus suggests an answer from the newest screening, with the evidence, and you decide:
- Yes is suggested when a match of that kind was confirmed.
- No is suggested when the screening came back clear, or was signed off Cleared.
- Nothing is suggested while matches are still waiting for a decision.
If you answer No to something the screening confirmed, you must write why before the assessment can be scored. Answers are filled only when you choose Use this or Accept all N on the Risk assessment tab. Accept all fills unanswered, evidence-backed questions and preserves your existing answers. Review them before scoring.
If the client is on ongoing monitoring
Monitoring raises its own alerts, handled on the client's Monitoring tab. A hit you cleared during onboarding can appear once as a monitoring alert, because the two records are kept separately. Close it as Not this client with the same reasoning. See Ongoing monitoring.
Didn't find what you needed?
Contact support