
How Often Should You Re-Screen Your Customer Base? Setting Frequency by Risk Tier
Most firms either rescreen everyone on a fixed annual cycle, which is expensive and slow to catch new designations, or rescreen only on trigger events, which leaves the gaps regulators have flagged for years. This post lays out a risk tier matrix with recommended cadence per tier, the event triggers that should override any schedule, and the tradeoff between full-base rescreening and delta screening against list changes only.
In December 2010, OFAC settled with Discover Financial Services over a personal credit card account it had maintained for a Specially Designated Narcotics Trafficker for nearly two years.
The customer wasn't sanctioned when the account was opened; he was designated afterward, and the account simply kept running, generating 28 transactions worth $23,252 before anyone caught it.
The penalty itself was modest, $8,720, reduced for voluntary disclosure of a relatively low-dollar violation. However, this clearly demonstrates that a customer who passes screening once does not stay clean forever.
The gap between a designation being published and an existing customer being rescreened against it is where this exact failure keeps happening in institutions of every size.
A Risk Tier Matrix for Rescreening Cadence
A single rescreening cadence applied to an entire customer base is either too slow for the riskiest segment or too expensive for the safest one. The logic that should set cadence is the same probability-times-consequence framework that governs screening architecture generally: how likely is a match at this risk level, and how costly is a delayed detection if one occurs.
The FFIEC BSA/AML Examination Manual's OFAC section directs examiners to assess whether a bank's OFAC compliance program, including its screening frequency, is appropriate given its specific risk profile, products, services, customers, and geographic exposure, not whether it meets some fixed, generic cadence.
A tiered rescreening policy is the practical expression of that risk-based standard. A single blanket cadence applied to an entire base, whatever the number, is harder to defend as risk-based because it isn't actually responsive to risk.
- High risk. Customers in elevated-risk jurisdictions, those with complex or opaque ownership structures, or those flagged during onboarding as requiring enhanced due diligence should be rescreened against every relevant list update, effectively continuous monitoring rather than a scheduled cycle. The probability of a match is elevated enough, and the consequence of a delay serious enough, that batching this tier into a periodic cycle defeats the purpose of having a tier at all.
- PEP-linked. Politically exposed persons and their known close associates carry a different risk profile than sanctions risk specifically, PEP status itself isn't a designation, but PEP status correlates with elevated exposure to corruption, adverse media developments, and status changes (a PEP leaving office, a family member becoming newly prominent) that a static annual review will miss for months at a time. A monthly or list-update-triggered rescreen, combined with a periodic adverse media refresh, is proportionate here without the cost of full continuous monitoring.
- Standard. The bulk of a typical customer base, retail or commercial customers without elevated risk indicators, is reasonably served by a rescreen cadence tied to sanctions list update frequency rather than a fixed calendar date. In practice this usually means rescreening against new designations as they publish (which, given how frequently OFAC, the EU, and the UN update their lists, functions closer to weekly or biweekly than annually) rather than waiting for a scheduled review.
- Low risk. Long-tenured customers with no elevated risk indicators, stable relationships, and low transaction complexity can reasonably sit on a slower cycle, quarterly or semi-annual full rescreens, provided the delta-screening layer described below still catches new designations against this segment in the meantime. With the Discover case, the customer in that case would likely have sat in a standard or low-risk tier at onboarding, which is precisely why a tier-only policy without a list-update layer would have missed him.
{{snippets-guide}}
The Triggers That Override Any Schedule
Tier-based cadence focuses on frequency and glosses over what happens between scheduled reviews when something material changes about a specific customer. That should override the scheduled cadence regardless of which tier a customer sits in.
An adverse media hit on a customer should trigger an immediate rescreen, not wait for the next scheduled cycle for that tier. A change in beneficial ownership, particularly relevant given how often sanctions exposure flows through ownership structures rather than a directly designated name, should trigger the same.
A customer's business expanding into a new high-risk jurisdiction, a new correspondent banking relationship, or a law enforcement or regulatory inquiry touching the customer should all independently trigger a rescreen outside the normal schedule. FATF Recommendation 6 sets the underlying standard here: countries are required to implement targeted financial sanctions "without delay" once a designation is made, freezing all funds and assets owned or controlled by a designated party, directly or indirectly.
A purely scheduled rescreen cadence, however well-tiered, cannot meet that standard on its own. Triggers exist precisely to close the gap between a designation happening and the next scheduled touch point for that customer.
Full Rescreen vs. Delta Screening Against List Changes
A full rescreen re-runs every customer in a given segment against the current state of every relevant list, regardless of what has or hasn't changed. This is easy to audit, but it scales linearly with base size every time it runs. A full rescreen of 500,000 customers costs roughly the same compute and generates roughly the same alert volume whether the underlying lists changed by one entry or five hundred since the last run.
Delta screening runs the comparison the other direction. Instead of re-checking every customer against the whole list, it checks only what changed on the list since the last update against the existing customer base. Structurally, this means the processing load and alert volume scale with the size of the list update, not the size of the customer base. A list update adding a handful of new designations touches a handful of potential new matches across the base, not a full re-evaluation of every customer against every entry.
There is a trade-off: full rescreening is the more expensive and slower approach at the population level, but it's the only approach that also re-validates historical false negatives, matches missed the first time due to data quality issues, name variant coverage, or match threshold changes made since the last full run.
Delta screening is cheaper and faster to run at whatever cadence you choose, but it only catches new designations, not gaps in how past screens were run.
A mature program typically runs both: delta screening at high frequency (daily or near-real-time, closing the gap the Discover case exposed) layered under periodic full rescreens (quarterly for standard and low-risk tiers, more frequently for higher tiers) that catch what delta screening structurally cannot. The exact cost comparison depends on your base size, list update frequency, and current match rate, etc.
Our Sanctions Screening API vs Manual Batch Screening decision guide works through the same delta-versus-full architecture question from the transaction-screening side, rather than the periodic rescreening side covered here.
Defending Your Chosen Frequency
Whatever cadence and architecture you land on, the frequency itself needs to be defensible, not just operationally chosen. OFAC's own Economic Sanctions Enforcement Guidelines list the adequacy of a regulated entity's risk-based compliance program as one of the general factors weighed in determining an enforcement response, which means a documented, risk-based rescreening cadence can directly affect penalty exposure if something does slip through.
The rationale doesn't need to be elaborate, but it needs to exist, in writing, tied to the specific risk factors that justify why a given tier gets a given cadence, and it needs to be revisited when the underlying risk assessment changes, not left static for years after the customer base or the sanctions landscape has moved on.
The Sanctions Screening Guide covers how to build the tier assignment itself into your broader risk assessment.
{{snippets-case}}
Final Thoughts
Treating rescreening as a single blanket policy, whether that's "annual for everyone" or "only when something triggers it," is how a customer like the one in the Discover case slips through for two years without anyone noticing.
The fix involves separating cadence, triggers, and architecture into three decisions that are each made deliberately, documented with a risk-based rationale, and revisited as your customer base and the sanctions landscape both change.
sanctions.io is a highly reliable and cost-effective solution for real-time screening. AI-powered and with an enterprise-grade API with 99.99% uptime are reasons why customers globally trust us with their compliance efforts and sanctions screening needs.
To learn more about how our sanctions, PEP, and criminal watchlist screening service can support your organisation's compliance program: Book a free Discovery Call.
We also encourage you to take advantage of our free 7-day trial to get started with your sanctions and AML screening (no credit card is required).
