Understanding AML screening results

How AML screening works - what gets checked, the difference between the match score and the risk score, and why setting the two thresholds well is the whole job.

Short answer

Every hit carries two scores, and confusing them is the main source of AML pain. The match score asks "is this the same person?" The risk score asks "how serious is it if it is?" The risk score drives the outcome. AML screening is $0.20 per screen and is not in the free tier.

AML screening checks a person or company against sanctions, watchlist, and adverse media sources, and returns a risk-based result you can act on automatically or route for manual review.

#What gets screened

Each screening checks the entity against several source categories:

  • Sanctions lists - government and international sanctions and travel-ban lists.
  • Politically exposed persons (PEP) - individuals with prominent public roles, from heads of state down to relatives and close associates.
  • Criminal and law-enforcement records - global and local databases, including wanted lists.
  • Adverse media - news coverage of financial crime, fraud, or related issues.
  • Regulatory enforcement - warnings, fines, and enforcement actions from financial regulators.

A hit can come from a watchlist database, from adverse media, or both. A person or company can appear in press coverage even when they aren't listed in a formal database, so treat an adverse-media-only hit as a genuine signal rather than a lesser one.

For the full source breakdown, see what lists Didit screens against.

#The two scores

This is the part worth internalising, because nearly every "why did this flag?" question resolves here.

Match score - is this hit actually the same person or company? Calculated from name, date of birth, nationality, and other identifying details. A common name against a large sanctions list produces many low-confidence candidate matches; low-confidence matches are automatically excluded.

Risk score - how serious is this if it is the same entity? Calculated from the category (sanctions versus PEP versus adverse media), the PEP tier, the crime type, and country risk.

The risk score determines the final status: approved, in review, or declined. Both thresholds are configurable per workflow.

#How the risk score is calculated

The risk score is a weighted average of three components, each scored 0 to 100:

ComponentWeightWhat it measures
Category50%Which kind of list the hit is on. Sanctions and top-tier PEPs score 100; a Warnings and Regulatory enforcement listing 80 to 95; lower PEP tiers 70 to 79; adverse media alone 55 to 69 (typically 60)
Country30%The AML/CFT risk of the entity's country on Didit's country table (Luxembourg or Germany in the twenties, high-risk jurisdictions far higher)
Criminal records20%A court conviction scores 100 and an enforced criminal penalty 90. An administrative fine or a regulatory sanction is not a criminal record and scores 0 here

The bands are fixed: Low below 30, Medium 30 to 49, High 50 and above. Which band lands in review or decline is set by your thresholds.

A worked example, because it comes up constantly: a company fined by a financial regulator, where the fine has been reported in the press but the entity is not on a regulator's enforcement list. The hit is adverse media only, so category is 60; a low-risk EU country gives roughly 23; no criminal record gives 0. That is (23 x 0.30) + (60 x 0.50) + (0 x 0.20), about 37: Medium risk, typically In Review rather than Declined. The same fine sourced from the regulator's own enforcement listing would score 95 on category and land in High. So "the sanction wasn't detected" usually means it was detected, from a different kind of source than you expected, and scored accordingly. Full detail: AML risk score.

Important

Setting the match threshold too low is the single most common cause of an unworkable AML queue. Lower it and you catch more true matches - and vastly more people who merely share a name with someone on a list. Start where the defaults are, measure your own false-positive rate, then adjust.

#Company and person screening are separate

For business verification, screening runs at two levels: the company itself, and every identified beneficial owner and officer individually. They're separate checks with separate prices - $0.20 each. See how business verification works.

#Screening without a full verification

If you only need a screen - no document, no selfie - you can call AML screening on its own rather than wrapping it in a full KYC workflow. Note that a standalone API call is billed per call and doesn't draw on any free allowance, and neither does AML in a workflow, since AML isn't a free-tier feature either way.

#Ongoing monitoring

Once someone is approved, a one-time screen only tells you about the day it ran. Ongoing monitoring re-screens daily against updated lists and moves the session if something new crosses your threshold. See ongoing AML monitoring.

#What it costs

Price
AML screening (person or company)$0.20 per screen
Ongoing AML monitoring$0.07 per year

AML is not part of the free tier, so a workflow that includes AML draws on your credit balance from the first session - a frequent surprise for teams who expected a "free KYC" flow to be free. See what the free plan includes.