← InsureGuardAI blog

The regulator asked to see your screening evidence. Your system showed a green light and nothing else.

The MLRO signs off on the screening control because the control runs. Every party gets checked, the dashboard is green, the quarterly attestation goes up the chain. Then the regulator sits down for the exam and asks one thing: show me you screened this party on the day you bound the policy. The system returns a status flag. CLEARED. Nothing under it.

That is the trap. Running the control and proving the control ran are two different problems, and most programs solve only the first. The screen fires, a decision is recorded, and the raw material that justified it is discarded the moment it stops being operationally useful. The control existed. The evidence that it ran did not.

What "show me you screened this party" actually demands in artifacts

An examiner is not asking whether you own a screening tool. They are asking you to reconstruct a specific decision at a specific moment, which needs the inputs and context that produced it, frozen as they were. The case file has to hold:

Retaining the raw provider response, list version, and decision metadata as a unit

The common failure is keeping these fields, but scattered. The decision lives in case management. The provider response lives in an API log that rotates after 30 days. The list version lives nowhere, because the vendor manages it and never wrote it down on your side. At exam time you are stitching three half-records together and hoping the timestamps line up.

Treat the screening event as one immutable artifact: raw response, list version, score, threshold, timestamp, and decider written together, keyed to the case, at the moment of the screen. A decision without its underlying response is an assertion. A decision bundled with the raw_response and the list snapshot is evidence, and that difference is the entire exam.

OFAC's move from 5- to 10-year recordkeeping and why your retention has to follow

This stopped being a best-practice argument in 2025. OFAC issued an interim final rule, effective March 12, 2025 and finalized later that month, extending the recordkeeping requirement under its Reporting, Procedures and Penalties Regulations from five years to ten. It tracks the extension of the statute of limitations for IEEPA and Trading with the Enemy Act violations to ten years, so OFAC can now look back twice as far, and you must keep full and accurate records of covered transactions for at least ten years.

If your evidence retention was tuned to a five-year horizon, half of your exposure window is now uncovered. A policy bound in 2026 can be examined against a designation that posts in 2034, and the question will be what you recorded at bind. Log rotation, vendor data lifecycle, and case purge all have to be re-checked against ten years.

Tenant-scoped, immutable case evidence as the difference between pass and fail

Retention is necessary but not sufficient. The evidence also has to be trustworthy: not editable after the fact, not commingled across clients. An examiner who suspects a record was reconstructed after the request treats the whole file as unreliable. Immutability and clean tenant boundaries make the artifact credible, not just present.

InsureGuardAI captures the screening event as a sealed record inside each customer's workspace: raw provider response, list version, score, timestamp, and decider written together and held for the full retention horizon, scoped so one client's evidence never touches another's. When the regulator asks you to prove the screen ran, the case file answers with the artifact, not a green light. See how the workspace keeps screening evidence.