Screening Audit Trails: What Evidence to Retain, in What Format, and for How Long

Compliance teams routinely discover during an audit that they can prove a screen happened but not what it was screened against, at what threshold, or why an alert was cleared. Using NYDFS's 2017 findings against Habib Bank as a real example of what happens when disposition rationale goes undocumented, this post specifies the evidence set a defensible screening trail requires, the format considerations that make it usable years later, and retention periods across the US, UK, and EU.

Basit Nayani
,
September 15, 2026

In August 2017, NYDFS issued a Notice of Hearing and Statement of Charges against Habib Bank Limited's New York branch alleging 53 separate violations, among them that the bank had disposed of 855 "batch-waived" transaction alerts without appropriate review or any documented rationale for waiving them. 

A separate finding identified a defective internal exclusion list containing 154 terms that matched entries on OFAC's SDN list, which let more than 4,000 transactions worth over $250 million pass unscreened. 

The bank, the largest in Pakistan, faced a potential penalty of nearly $630 million. It settled for $225 million and chose to surrender its New York banking license entirely rather than continue operating under the remediation NYDFS was prepared to impose. Even though the bank had screened and generated alerts, it could not produce, when examiners asked, a documented reason for why 855 of those alerts had been cleared.

You Can Prove You Screened. Can You Prove What You Screened Against?

You may have a lengthy retention policy, but a record kept for the legally required number of years is worthless in an examination if it only proves that a screening event occurred, not what the screen was run against, what threshold applied, or why a human being decided a match was not a concern.

Looking at HBL, nobody at NYDFS alleged that the bank failed to screen transactions. Alerts were generated, which means a system was running and producing output. The fin

ding was that when those alerts were cleared in batches, no one recorded the reason why. A regulator examining the file years later could see that a decision was made but could not reconstruct the basis for it. Screenings should be defensible, and provable. 

The Evidence Set a Defensible Trail Actually Requires

List version and timestamp at time of screen

Sanctions and watchlist data changes constantly. A record that shows a name was screened is incomplete without a record of which version of the list it was screened against and exactly when. 

Without this, there is no way to later demonstrate that a screen run on a given date reflected the sanctions landscape as it actually existed at that moment.

Match score and threshold configuration at that moment

A fuzzy-matching system's threshold is essentially a configuration choice that can and does change over time. A defensible record captures that a match scored below the alert threshold, as well as what threshold was set to on the date of the screen. There’s a big difference between a threshold that was 85 in January and 75 in June, and only a timestamped configuration record can show which one applied to a given transaction.

Analyst disposition with written rationale

This is the area we see most teams underinvesting in. A status change from "alert" to "cleared" is not sufficient documentation. A written rationale, specific to the match in question, explaining why the analyst concluded the party was not the sanctioned entity the system flagged, is documentation. 

The HBL 855 batch-waived alerts were not necessarily wrong decisions, but there was no way to know, because nothing was written down.

Full search parameters

What name was actually submitted, in which format, with what supplementary identifiers (date of birth, nationality, entity type), needs to be part of the record, not assumed or reconstructed after the fact. 

A screen run against "John Smith" and a screen run against "John Smith, DOB 03/1985, UK national" are different searches with different evidentiary weight.

System-generated records over manual ones

A log entry created automatically by the screening system at the moment of the event carries more evidentiary weight than a manually maintained spreadsheet updated after the fact, because the manual version is vulnerable to the exact failure mode HBL exhibited. Entries that reflect what someone remembers happening, or what should have happened, rather than a contemporaneous record of what the system actually returned and what was decided. 

{{snippets-guide}}

Format and Export: What Makes a Record Usable Years Later

A record that technically exists is not the same as a record that is usable when it is needed. 

A screenshot of a screening result is a snapshot of a user interface at one moment, dependent on that interface's design, resolution, and whatever the vendor's platform looked like at the time. 

Five or ten years later, when the interface may have changed and the vendor may not exist in the same form, that screenshot may be unreadable, unverifiable, or simply lost. Structured data, exported in a format that does not depend on any particular vendor's current UI, can survive platform migrations, vendor changes, and personnel turnover.

A record with a timestamp that can be shown to have been generated automatically by the system, rather than entered manually by a user, carries far more weight in an examination, because it cannot be backdated or reconstructed after the fact.

An examiner wants to know whether you can produce a specific record, for a specific transaction, in a form they can review, within a reasonable window. A retention policy that technically satisfies a jurisdiction's minimum period but produces records that take weeks to locate, or that come back in a format nobody can interpret without the original vendor's help, does not meet the practical standard.

Retention Periods by Jurisdiction

  • United States. OFAC's recordkeeping requirement under 31 CFR 501.601 doubled from five years to ten, effective March 12, 2025, to align with the extended statute of limitations for sanctions violations under the 21st Century Peace through Strength Act. Bank Secrecy Act recordkeeping requirements for customer due diligence and related records generally sit at a five-year baseline, so a US institution subject to both regimes needs to track two different clocks depending on the record type.
  • United Kingdom. The Money Laundering Regulations 2017, Regulation 40, sets a five-year retention period from the end of a business relationship or the date of an occasional transaction. The regulation is explicit that the format or medium of storage does not matter, provided the firm can retrieve the relevant information and evidence without delay when asked.
  • European Union. Article 40 of the EU's Anti-Money Laundering Directive sets the same five-year baseline, with member states permitted to require an additional retention period of up to five more years, for a maximum of ten, where they can justify the extension as necessary and proportionate. In practice this has produced variation across the bloc, with some member states applying the five-year minimum and others requiring the full ten.

Five years is close to a universal floor, ten years is the ceiling that US sanctions work now requires, and the specific number that applies to any given record depends on which regulator, which record type, and in the EU's case, which member state.

Auditing Your Own Logs

Run your own current screening records against the checklist below. Each item maps directly to a specific failure mode covered above, not a generic best practice.

  • Can you show which list version and date applied to a specific past screen?
  • Can you show what threshold configuration was active on a given past date?
  • Do cleared alerts have a written, match-specific reason, not just a status change?
  • Are the exact submitted search terms retained, not just the result?
  • Are records generated automatically by the system, with tamper-evident timestamps?
  • Can records be exported in a structured, vendor-independent format?
  • Can you produce a specific record, for a specific transaction, within days, not weeks?
  • Does your retention schedule match the correct period for each record type and regulator?

{{snippets-case}}

If the program has gaps in the first three rows, you might be looking at the exposure HBL’s New York branch faced: no way of proving that screening happened, what was screened, or why decisions were made. 

Our Sanctions Screening Guide covers how audit logging fits into a broader screening implementation, and the Unified Guide to Screening: Sanctions, PEP & Adverse Media works through documentation standards across screening types beyond sanctions alone. The Vendor Selection Guide covers the specific questions to ask a screening provider about what evidence their system captures automatically versus what your team would still need to log manually.

sanctions.io is a highly reliable and cost-effective solution for real-time screening. AI-powered and with an enterprise-grade API with 99.99% uptime are reasons why customers globally trust us with their compliance efforts and sanctions screening needs.

To learn more about how our sanctions, PEP, and criminal watchlist screening service can support your organisation's compliance program: Book a free Discovery Call.

We also encourage you to take advantage of our free 7-day trial to get started with your sanctions and AML screening (no credit card is required).

New Sanctions Screening Guide
Download our free Sanctions Screening Guide
Download our FREE Sanctions Screening Guide and learn how to set up an effective sanctions screening process in your organization.
Download our FREE Sanctions Screening Guide and learn how to set up an effective sanctions screening process in your organization.
New Case Study
The Comprehensive, Unified Guide to Screening
Discover how technology companies streamline global sanctions compliance with sanctions.io
Our Unified Guide to Screening covers everything you need to know about setting up a comprehensive, unified screening process and workflow for the 3 ain pillars: sanctions, PEP and adverse media screening.
Basit Nayani
With experience in digital marketing, business development, and content strategy across mainland Europe, the UK and Asia, Basit Nayani joined the team as Head of Marketing & Growth in 2025.
Enjoyed this read?

Subscribe to our Newsletter right now and never miss again any new Articles, Guides and more useful content for your AML and Sanctions compilance.

Success! Your email has been successfully registered for our newsletter.
Oops! Something went wrong while submitting the form.