Guides
Aug 25, 2026

Crypto Watchlist and PEP Screening Explained

Sanctions screening is only one list. PEP, adverse media and entity screening carry different obligations and different false-positive problems — here is how each works in crypto.

Crypto Watchlist and PEP Screening Explained

Most teams say "screening" and mean sanctions. Sanctions is the hard legal prohibition, so it gets the attention. But a compliance programme is assessed on several distinct screening obligations, each with its own list, its own risk treatment and its own failure mode.

Confusing them is common and expensive — usually in the form of a false-positive rate nobody can work through.

The four types

1. Sanctions screening

Binary and absolute. If a party is designated, you may not transact. There is no risk-based override and no commercial judgement to exercise. Lists come from OFAC, the EU, the UN and national regimes.

Failure here is a legal breach, not a control weakness. Covered in depth in best sanctions screening software.

2. PEP screening

Politically exposed persons — senior public officials, their close associates and family members. Being a PEP is not a prohibition. It triggers enhanced due diligence: source of wealth, source of funds, senior sign-off, more frequent review.

This is where teams most often go wrong in both directions. Some block PEPs outright, which is over-compliance that loses legitimate customers. Others flag and ignore, which is under-compliance. The correct answer is a documented EDD process with a named approver.

PEP status is also tiered — a head of state and a municipal official carry different risk — and it persists for a period after leaving office. Any tool that returns a flat yes/no is too blunt.

3. Adverse media

Negative news screening for financial crime, fraud, corruption or organised crime. It is the fuzziest category and generates the worst noise: common names, stale articles, and stories where your customer is the victim rather than the perpetrator.

Look for structured classification by allegation type and recency, not a keyword search over a news index.

4. Entity and UBO screening

When onboarding a business you screen the company, its directors, and its ultimate beneficial owners. The chain matters — a clean company owned through two holding structures by a sanctioned individual is a sanctioned exposure.

This is the hardest to automate because ownership data quality varies enormously by jurisdiction. Covered in KYB compliance requirements and best KYB software for crypto.

Why crypto makes this harder

Traditional finance screens names against lists. Crypto has to screen names and addresses, and the two rarely reconcile.

  • Address screening tells you about on-chain exposure — whether funds passed through a mixer or a designated wallet
  • Name screening tells you about the customer's identity and status

A customer can clear name screening perfectly and still deposit from an address with direct sanctioned exposure. Both checks are mandatory, and they need to feed the same risk score — otherwise you get two systems with two answers and no reconciliation.

The false-positive problem

The commercial risk in PEP and adverse media screening is not missing a match. It is generating so many that the queue stops being worked.

Practical mitigations:

  • Tune thresholds by customer risk. A retail user depositing EUR 200 does not need the same match sensitivity as a corporate onboarding EUR 2m.
  • Use secondary identifiers. Date of birth and nationality collapse most name collisions instantly.
  • Whitelist resolved matches. Once a false positive is cleared with a written rationale, it should not resurface every cycle.
  • Measure the rate. If more than roughly 95% of alerts are false, the configuration is wrong, not the analysts.

What auditors ask for

  • Which lists you screen, from which provider, refreshed how often
  • Your match threshold and the rationale for it
  • Evidence of periodic re-screening, not just at onboarding
  • Written disposition for every alert — including cleared ones
  • Your EDD process for confirmed PEPs, with the approver named
  • How address screening and name screening reconcile into one customer risk score

That last point is the one most often missing.

Writing a screening policy that survives an audit

The tooling question is downstream of a policy question most teams never write down. An examiner will ask to see the document that says which lists you screen against, at what match threshold, how often, who reviews a hit, and who may clear one. If that document does not exist, the quality of your vendor is irrelevant — you cannot evidence a control you never defined.

A workable policy fixes five things in writing:

  • Scope. Which lists, and for which customer types. Sanctions for everyone. PEP and adverse media usually risk-tiered.
  • Thresholds. The fuzzy-match score above which a hit is generated, stated as a number, with the reasoning for that number.
  • Frequency. At onboarding, on every list update, and on a periodic cycle for the standing book.
  • Roles. Who triages, who approves a clear, and the rule that the approver cannot be the person who raised it.
  • Retention. How long you keep the screening record, including the negative results.

The last one catches people out. Firms retain their true positives carefully and discard the noise. But the evidence that you screened a customer and got nothing is exactly what proves the control ran. Keep the clean results too.

Tuning false positives without quietly under-screening

Every screening programme sits on one dial: loosen the match threshold and you drown in noise, tighten it and you miss real hits. Both failure modes are serious, and only one of them is visible day to day — which is why unmanaged programmes drift toward tightening until they catch nothing.

Three techniques move the trade-off rather than just sliding along it:

  • Secondary identifiers. A name match alone is weak. Date of birth, nationality and identity document number turn a 200-hit name into one or zero. Any tool that screens on name only will generate volume you cannot clear.
  • Name-culture awareness. Transliteration from Arabic, Cyrillic and Chinese produces multiple valid spellings, and patronymic conventions mean the same person appears several ways. Matching logic that assumes Western given-name/surname order fails on a large share of the world.
  • Documented whitelisting. When you clear a hit, record the decision so the same customer does not regenerate the same alert every cycle. Whitelists must be reviewed and must expire — an unreviewed permanent whitelist is how a genuine later designation gets suppressed.

Track your false-positive rate as a managed metric with a target, not as a complaint. A programme where 99% of alerts are noise is not a strict programme; it is one where the real hit will be cleared by a tired analyst at the end of a queue.

Point-in-time versus ongoing obligations

Sanctions screening is continuous by nature: designations change, and the obligation attaches the moment they do. PEP status is different — it changes with appointments and elections, persists for a period after a person leaves office, and extends to close associates and family who are far harder to detect. Adverse media is continuous in principle and impossible to run continuously in practice at full sensitivity, which is why most programmes run it at onboarding, at periodic review, and on trigger events such as a large transaction or a jurisdiction change.

Set those cadences deliberately and write them down. A programme that screens everything at onboarding and never again is the single most common finding in crypto compliance reviews, and it is the easiest to fix.

Where it fits

Screening is the gate. Behavioural monitoring is what runs afterwards — see crypto transaction monitoring software. Identity verification comes first, in best crypto KYC providers. And if you are starting with no budget, free crypto sanctions screening sets out what that does and does not cover.

The full programme is in our crypto AML compliance guide. If you are building toward authorisation, the cost of all this together is broken down in CASP licence cost in 2026.

Frequently asked questions

What is the difference between sanctions screening and PEP screening?

Sanctions screening is a legal prohibition: if a party is designated, you may not transact, and there is no risk-based override. PEP screening is a risk trigger, not a prohibition — identifying a politically exposed person means you apply enhanced due diligence, document source of wealth and funds, and obtain senior sign-off. Blocking every PEP is over-compliance that costs you legitimate customers.

Do I have to screen for PEPs if I am not in the EU?

In most regulated markets, yes. PEP obligations derive from FATF recommendations that have been implemented in the great majority of national AML regimes, so the requirement travels well beyond the EU. What varies is the scope of "domestic" PEPs and how long the status persists after leaving office. Check your own regulator's definition rather than assuming the EU one applies.

How often should customers be re-screened?

Sanctions: on every list update, automatically. PEP: at onboarding and on a periodic cycle set by customer risk rating, typically annually for standard risk and more frequently for high risk. Adverse media: at onboarding, at periodic review, and on trigger events. The point is that the cadence is defined and evidenced, not that a specific number is universally correct.

Why do crypto firms get more false positives than banks?

Partly customer base — crypto skews international, so a larger share of names require transliteration and fall outside the Western name conventions most matching engines were tuned on. Partly data — crypto onboarding often collects fewer secondary identifiers than a bank account opening, and secondary identifiers are what resolve a name match. Collecting date of birth and nationality at onboarding measurably reduces alert volume.

Is address screening the same as name screening?

No, and you need both. Name screening checks the person against sanctions, PEP and adverse-media lists. Wallet address screening checks the on-chain counterparty against designated addresses and, in better tools, against indirect exposure — funds that reached the address through an intermediary hop. A customer can pass name screening cleanly and still be receiving funds from a sanctioned entity.

Can a small team run this manually?

At genuinely low volume, sanctions screening can be run manually against official lists if the process is documented and the results retained. PEP and adverse media are much harder to do by hand because they require ongoing monitoring rather than a lookup. See free crypto sanctions screening for where the manual approach stops being defensible.

About the author.

Co-Founder at JewelSwap & CMO at iDenfy. Viktor brings his successful track record of superb development & project management.