How It Works?
Business AML Screening evaluates a business, and related subjects such as vessels and aircraft, against Shufti's connected watchlists and returns every record that resembles them, each with a match score you can act on. This page explains the full pipeline: how you search, what you search against, how matches are scored, and how results are monitored and resolved.
The screening pipeline
Every screening follows the same five stages:
- Collect the subject's details: business name (required) and, ideally, incorporation date, plus any optional refining parameters.
- Select the data sources: either pick categories directly or apply a saved search profile.
- Search and score: the name-matching engine compares the input against each source and assigns every record an AML Match Score.
- Return results: records at or above your match threshold are returned in the response; the rest are suppressed.
- Resolve and monitor: review matches through case management, apply a decision, and optionally enroll the subject in ongoing monitoring.
Supported entity types
| Entity type | Description |
|---|---|
| Company | Corporate entities flagged for regulatory breaches or financial crime. |
| Organisation | Non-corporate bodies under investigation or listed for non-compliance. |
| Vessel | Ships and maritime vessels flagged by regulatory or law-enforcement bodies. |
| Aircraft | Aircraft linked to sanctioned parties or under regulatory scrutiny. |
Screening modes
AML screening can source the subject's details in two ways:
| Mode | How details are supplied |
|---|---|
| Search-based | Business name and incorporation date are provided by the end user or merchant via the API and searched against AML data sources. |
| Document-based | Business name and incorporation date are extracted directly from a document supplied by the end user. |
Search options
You control which data sources a screening runs against in one of two ways.
Search by Databases
Shufti's AML data sources span 4,000+ global watchlists, covering millions of high-risk entity profiles across 240+ countries and territories, all drawn from reputable international and local databases. When searching by database, you select which sources to screen against from these categories:
- Sanctions
- Warnings and Regulatory Enforcement
- Fitness & Probity
- Adverse Media
- Insolvency
- Special Interest Entity (SIE)
Search by Profile
A search profile is a custom, reusable set of data sources, created and managed in AML Settings, that fixes the exact scope of a check in advance. Search profiles are a shared feature used across both Individual and Business AML Screening. When building a search profile, sources are grouped under three headings, each with its underlying sources individually included or excluded:
- PEP: PEP Level 1, PEP Level 2, PEP Level 3, and PEP Level 4.
- Warnings and Regulatory Enforcement: Fitness & Probity, Regulatory Enforcements, Special Interest Persons (SIP), Special Interest Entities (SIE), and Insolvency.
- Sanctions: underlying sanctions sources that can be filtered by country.
Because a search profile is shared across both products, it may include PEP and Special Interest Person (SIP) sources. These apply to individuals only, so a Business AML screening will not return matches from them even when the selected profile has them enabled.
At search time, the request carries a Search By key. You either choose Select Databases Manually and pick categories directly, or choose Use Search Profile, which reveals a dropdown of your preconfigured search profiles to screen the subject against. Using a saved search profile gives you consistent, repeatable checks.
Search parameters
These are the parameters that drive a Business AML screening. Business Name is the foundation of every search; the rest refine, filter, or organize results. For request formats and limits, see Onsite and Offsite.
| Parameter | Required | Description |
|---|---|---|
| Business Name | Yes | Primary identifier and the basis of every search. Carries the highest weight in scoring. |
| Incorporation Date | No | Supporting identifier that distinguishes businesses with similar names and improves precision. |
| Entity Type | Yes | The type of entity being screened: Company, Organization, Vessel, or Aircraft. |
| Unique Identifier | No | Registry, tax ID, or registration number. Does not affect the score; promotes records with a matching identifier to the top of results. |
| Country(s) | No | Pre-search filter by country. Filters out non-matching records before scoring, with no effect on the score itself. |
| Search By | Yes | Sets the data scope: select databases manually, or use a saved search profile. |
| Custom Risk Engine | Yes | The risk scoring engine applied to results. If none is selected, the default engine is applied. |
| Match Score | No | Minimum match threshold, set with a 0 to 100 slider. An Exact Match checkbox sets the score to 100. |
| Enable Ongoing AML? | No | Enables continuous re-screening so the entity is monitored against database changes over time. |
| Enable Ongoing Adverse Media? | No | Available only when Adverse Media is among the selected databases. Enables continuous adverse media monitoring. |
| Enable AI Compliance Co-Pilot? | No | Enables AI-assisted review of results. Additional subject data is passed through the context key. |
| Additional Configurations | No | Search for Relatives & Close Associates (RCA), and Search for Aliases & Alternate Names. |
Business Name
Business Name is the primary and mandatory parameter. The engine evaluates name similarity using phonetic analysis, alias resolution, transliteration, and name-variation handling, so spelling differences, alternative trading names, abbreviations, and cross-jurisdictional representations are all accounted for. As the core identifier, it carries the greatest weight in scoring.
Incorporation Date
Incorporation date is a supporting parameter. When provided, it differentiates between businesses that share similar names, increasing confidence and reducing ambiguity. It is not mandatory, but supplying it significantly improves reliability, especially for commonly named entities or records spanning multiple jurisdictions.
Entity Type
Entity Type is a mandatory parameter that sets the kind of entity being screened. The available options are Company, Organization, Vessel, and Aircraft. Selecting the correct type focuses the search on the relevant records.
Unique Identifier
A specific identification number, such as a business registry number, tax identification number, or company registration number, used to narrow the search toward a specific business. It does not affect the match score. Instead, after scoring, records whose identifier matches or closely aligns with the value provided are promoted to the top of the results, while others remain visible but ranked lower.
Country(s)
The country filter narrows results to records associated with one or more selected countries, removing unrelated jurisdictions and reducing noise.
The country filter is a pre-search filter only. Records that do not match the selected country never appear in results; records that pass through are scored on business name and incorporation date as usual, so the filter has no effect on the match score itself.
Search By
Search By sets the scope of data the entity is screened against. You either choose Select Databases Manually and pick categories directly, or choose Use Search Profile and select one of your preconfigured search profiles. See Search by Databases and Search by Profile for the available sources.
Custom Risk Engine
The risk engine applies your configured scoring criteria to the returned results. It is mandatory: if no custom engine is selected, the default risk engine is applied automatically. For configuration details, see the Custom Risk Scoring Engine.
Match Score
Match Score sets the minimum score a record must reach to be returned, configured with a 0 to 100 slider. A separate Exact Match checkbox is available; when enabled, the score is set to 100 by default. For how scores are calculated and the recommended threshold, see AML Match Score.
Enable Ongoing AML
When enabled, the entity is enrolled in continuous re-screening, so any future changes across the connected databases are surfaced without resubmitting the check. See Ongoing monitoring.
Enable Ongoing Adverse Media
This option appears only when Adverse Media is among the databases selected for screening. When enabled, the entity is continuously monitored for new adverse media coverage in addition to standard ongoing AML updates.
AI Compliance Co-Pilot
Enabling the AI Compliance Co-Pilot adds an AI-assisted review layer over the screening results. Additional subject information can be passed into the request to give the Co-Pilot richer data for its assessment, passed through the context field. When AML runs alongside KYB verification, this data can be enriched with details extracted during KYB, such as document number and address, combined with anything the merchant supplies. See the AI Compliance Co-Pilot section for what it returns.
Additional Configurations
Two optional toggles extend the scope of a search:
- Search for Relatives & Close Associates (RCA): extends the search to relatives and close associates of the entity. Parties who are not themselves listed may still pose indirect risk through shared finances, business relationships, or personal ties. RCA coverage brings beneficial-ownership structures, family-held assets, and associate networks into scope.
- Search for Aliases & Alternate Names: screens the entity against aliases, alternative trading names, transliterations, and name variations across all connected databases. Shufti applies fuzzy matching and transliteration logic so that non-exact variations are still captured, reducing false negatives.
Data sources and categories
The following categories are supported across Shufti's AML databases.
| Category | Description |
|---|---|
| Sanctions | Penalties or restrictions imposed by authorities on individuals, organizations, or countries for violating laws or international norms. View source list |
| Warnings and Regulatory Enforcement | Alerts to rule violations, plus penalties or legal actions for non-compliance with laws and regulations. View source list |
| Fitness and Probity | Evaluation of an individual's or entity's competence, skills, integrity, and ethical conduct in financial services. View source list |
| Adverse Media | Negative or damaging information about individuals, organizations, or entities that can pose significant risk. View source list |
| Special Interest Entity (SIE) | Companies or organizations presenting a heightened level of risk due to suspected or confirmed involvement in criminal activity. View source list |
| Insolvency | Companies and organizations that are unable to pay the debts they owe or have been declared bankrupt by a judicial process. View source list |
Adverse media screening
Shufti's adverse media screening searches a network of 50,000+ integrated global sources, including news outlets, regulatory publications, court records, and watchlist databases. The engine applies sentiment analysis to each piece of coverage, scoring its tone on a scale from -3 to +3: -3 severely negative, -2 moderately negative, -1 negative, 0 neutral, and +1 to +3 increasingly positive. This lets reviewers prioritise the most damaging coverage rather than treating every mention equally.
Searches run against keywords derived from FATF's 21 designated predicate offences for money laundering, supplemented by the 6th EU Anti-Money Laundering Directive (6AMLD), organized into these categories:
- Financial Crimes: money laundering, fraud, bribery, corruption, tax evasion, embezzlement, sanctions evasion, counterfeiting, insider trading.
- Organized Crime & Trafficking: drug, arms, and human trafficking, migrant smuggling, sexual exploitation, racketeering, smuggling of stolen goods.
- Terrorism & Proliferation: terrorist financing, proliferation financing, extremism, weapons of mass destruction.
- Violent & Serious Crimes: murder, kidnapping, hostage-taking, robbery, theft.
- Regulatory & Legal Violations: court convictions, criminal investigations, enforcement actions, sanctions violations, regulatory breaches, license revocations.
- Environmental & Cybercrime: illegal trafficking of natural resources and protected species, cybercrime, hacking, ransomware, data breaches (introduced under 6AMLD).
- Reputational & Political Risk: PEPs, abuse of power, conflict of interest, government misconduct, links to shell companies or offshore structures.
The name-matching engine
At the core of scoring is a proprietary name-matching engine built for global AML screening. Its goal is reducing false positives, matches that look plausible but refer to a different entity, without missing genuine hits obscured by spelling, cultural differences, or data quality. It handles four categories of name variation:
- Phonetics and diacritics: names that sound identical but are spelled differently. José Hernández and Jose Hernandez, or Mohamed and Muhammad, are treated as equivalent.
- Structural and spacing differences: hyphenation, multi-part names, suffixes, and spacing. Kim-Jong Un and Kim Jong Un are treated as structurally identical.
- Error and alias handling: OCR, legacy-system, and manual-entry errors are normalised, and known aliases, AKAs, and transliteration variants are linked into one subject profile.
- Cultural name variations: non-Western naming structures are handled natively rather than treated as errors.
AML Match Score
The AML Match Score is a value between 0% and 100% generated for every returned record. It quantifies how closely the subject's details, primarily name and incorporation date, match a record in Shufti's sanctions, watchlist, or other AML databases.
Match threshold
The match threshold is a configurable minimum cut-off. Only records scoring at or above it are returned; records below it are suppressed entirely.
- Set it too high and you risk missing genuine matches where data varies slightly across sources.
- Set it too low and you return loosely related results, burdening compliance teams.
Recommended threshold A threshold of 85% is recommended as the optimal balance between accuracy and coverage. The threshold is configurable per screening, so you can control sensitivity for each individual check rather than only globally.
Worked examples
These examples illustrate how the engine treats different kinds of business name variation, and the role a matching incorporation date plays. Assume each row is screened against a watchlist entry for Pacific Maritime Holdings Ltd.
| Search input | Incorporation date | How the engine treats it |
|---|---|---|
| Pacific Maritime Holdings Ltd | Not provided | Exact match on every token. A strong, high-confidence match on name alone. |
| Pasific Maritime Holdngs Ltd | Provided | Minor spelling variants (Pacific/Pasific, Holdings/Holdngs) are still recognised as the same name. A matching incorporation date adds further confidence. |
| PMH Ltd | Provided | If PMH is recorded as a registered trading name or alias for the entity, alias resolution links it to the full name. Without a known alias, an abbreviation alone carries lower name confidence. |
| Maritime Holdings Ltd | Provided | A name token (Pacific) is missing, so name confidence is lower. The result may fall closer to the threshold and warrant manual review. |
Three things to note from these examples:
- Name similarity is the primary driver. The closer the name match, the higher the confidence. A partial name match lowers confidence and may push a result below the threshold.
- Trading names and abbreviations rely on alias data. Alternative trading names, abbreviations, and acronyms match when they are recorded as aliases for the entity. An unrecognised abbreviation is treated as a weaker, partial name.
- Incorporation date is a supporting signal. A matching date increases confidence and helps separate businesses with similar names, but it does not by itself rescue a weak name match.
Multilingual and transliteration matching
Business names derived from Arabic, Persian, Urdu, and other scripts may appear under multiple valid spellings, none matching the input exactly, common with trading companies, family-owned businesses, and conglomerates recorded inconsistently across registries. The phonetic algorithm resolves these by matching on sound rather than spelling. For supported languages, see AML Supported Languages.
Ongoing monitoring
Watchlists and regulatory requirements change constantly. Ongoing monitoring keeps enrolled records current with real-time updates, reducing the risk of missed alerts from stale data.
How monitoring works
The monitoring engine runs automatically in the background, re-screening active profiles against the latest AML databases at a configurable frequency. The default interval is 15 minutes, so status changes are detected with minimal delay and no manual intervention. When an entity is added to or removed from any watchlist, the system triggers an alert.
Alerts can be delivered through one or more channels:
- Webhook: automated event notifications sent to your integrated system.
- Back Office: notifications surfaced in the Shufti merchant dashboard.
- Registered Email: alerts sent to your registered address.
Monitoring alert triggers
| Event | Description |
|---|---|
| New information found | The entity appears in a watchlist or database they were not previously associated with. |
| Existing information updated | Details for the entity on an existing list have been modified or revised. |
| Entity added or removed from a source | The entity has been newly added to, or delisted/removed from, a watchlist they are tracked against. |
Adverse media monitoring
Alongside watchlist monitoring, Shufti continuously scans for adverse media about the screened subject. If new adverse media is detected, the status is updated and an alert is sent automatically.
Enabling ongoing monitoring
Set ongoing = 1 to enable watchlist monitoring and ongoing_adverse_media = 1 for adverse media monitoring. Both are available on production accounts only.
Compliance tooling
AI Compliance Co-Pilot
The AI Compliance Co-Pilot is an AI-powered review layer that performs an automated first-line review of flagged profiles. It evaluates matches against sanctions, watchlist, and adverse media sources and returns a structured, evidence-backed risk summary, helping teams manage alert volume. It can be enabled while you run a screening or applied afterwards, and it is also available in ongoing monitoring.
When you enable the Co-Pilot during a screening, a form appears so you can supply context about the entity. None of these fields are mandatory; the more you provide, the sharper the assessment. For a business, the entity-specific context covers business name, date of incorporation, business registration number, known alias, IMO number (vessels), and tail number (aircraft).
You can also configure how the Co-Pilot runs:
- Records analysed per screening: any value from 5 to 50, in steps of 5.
- Use IDV data for context: turn on "Use Identity Verification (IDV) data for AI Compliance context?" to let the Co-Pilot reuse data already captured during verification. Only successfully extracted and verified fields are shared; anything not captured is excluded automatically.
- Co-Pilot in ongoing monitoring: when ongoing monitoring is enabled, you can have the Co-Pilot re-run on cases that receive updates, at one of four frequencies: instantly (on a new hit or update), daily, weekly, or monthly.
- Risk-change alerts: notify analysts when the Co-Pilot detects a risk change, by email or webhook.
Advisory only The Co-Pilot does not make final determinations or define AML policy. All outputs are advisory and subject to human review and override.
Custom Risk Scoring Engine
The Custom Risk Scoring Engine lets you define your own risk-assessment criteria instead of relying on a fixed model. Risk configuration defines threshold ranges across three levels, Low, Medium, and High, with a decision assigned to each level.
Scoring is distributed across three components:
| Component | What it scores |
|---|---|
| Country | One or more countries assigned a custom risk score |
| Category | AML watchlist categories scored by the risk they carry in your context |
| Criminal Records | Entities convicted by a court, and entities with a criminal penalty enforced |
Each component is assigned a weightage that determines its proportional contribution, and the three weightages must total 100%, keeping the model balanced and complete.
Risk decision is separate from the verification decision The detected risk level and its associated risk decision are returned separately from the main verification decision (accepted or declined). Treat the risk level as a parallel signal for your compliance workflow rather than the verification outcome itself.
Case Management
Case Management provides a structured, fully auditable workflow for reviewing and resolving screening results.
- Case assignment: every screening result becomes a case, assigned to the admin by default and reassignable to secondary team members. Assignees are notified by email and in the Back Office.
- Comments: added at the report level (whole report) or entity level (a specific entity), with support for tagging team members and attaching files.
- Activity logs: a complete history per case: creation time, report-viewed events, assignee changes, and status changes with timestamps.
- Case resolution: every case opens with a status of potential match by default. Assignees review the case and update the status to mark it a true positive or false positive.
- Alerts and notifications: assignees are notified instantly, in the Back Office and by email, on assignment and unassignment.
Only users with the appropriate role and permissions can update a case's resolution status. All status changes are recorded in the Activity Log for full auditability.