· Yair Knijn
Sanctions screening was a back-office task, until it became a board-level liability the directors never tracked
The Risk and Compliance Director treats sanctions screening as plumbing. It runs, analysts clear alerts, the vendor sends an invoice, and nothing about it ever reaches a board pack. The assumption is that silence equals health: no alarms, no agenda item. That holds right up until an enforcement matter lands, and then the first question is not "did you screen?" but "what did the board know, and when?"
The honest answer in most of these cases is: nothing. The directors saw no coverage figures, no backlog, no list-freshness number, no count of confirmed hits. There is no minute, no dashboard, no signed-off review. The program may have been working fine, but there is zero evidence it was being governed, and to a regulator that absence is the finding.
Why enforcement reads as a governance failure, not just an operations one
OFAC's A Framework for OFAC Compliance Commitments puts management commitment first among its five components, and it is specific about what that means: senior leadership, including the board, reviews and approves the program, ensures compliance has authority and direct reporting lines, and is itself subject to oversight. It is not enough for analysts to clear alerts below the waterline. The framework expects the program's performance to be reviewed at board or executive level, and it treats a weak compliance culture as a root cause, not a footnote.
So when a missed designation surfaces, the regulator is not only asking whether one name slipped through. They are asking whether the people accountable for the firm built a system to catch it and could see whether that system worked. A director who cannot produce a single piece of upward reporting has answered that question in the worst possible way.
The screening KRIs a board should be seeing: coverage, freshness, backlog, true hits
Boards do not need raw alert volumes. They need a small set of indicators that show the program is complete, current, and under control. If you report nothing else quarterly, report these:
- Coverage: what percentage of in-force parties, including UBOs and beneficial owners through the corporate layers, were screened in the period, and what was excluded and why.
- List freshness: the lag between a list publication and your re-screen against it, expressed in hours or days, per source (OFAC
SDN, EU, UKOFSI, UN). - Backlog: open alerts older than your service threshold, and the trend, because a growing queue is where a real hit hides.
- True hits: confirmed matches, what was done about each, and the time from alert to disposition.
Four numbers, one slide. The point is not the slide. The point is that producing it forces the program to actually measure these things, and the trend lines tell the director where the risk is moving before someone outside the building tells them.
Personal accountability and the "effective program" standard
The shift over the last few years is that "we have a vendor" no longer reads as a defence. The standard regulators apply is whether the program was effective, risk-based, and overseen, and effectiveness is demonstrated with records, not assertions. Mitigation credit in enforcement turns heavily on whether senior management owned the function and responded to identified deficiencies. The director is the person that accountability attaches to, by name. A program with no oversight evidence does not just expose the firm; it removes the director's own defence.
Producing oversight evidence the directors can actually point to
Evidence is mundane and that is the point. It is the dated KRI pack in the board minutes. It is the annual program review with someone's signature on it. It is the audit trail showing a fuzzy match was reviewed, who cleared it, and on what basis, with the raw match response retained. It is the re-screen log proving a party screened clean at bind was checked again the day a new list dropped. None of this is exotic. It is the difference between "we believe we screen well" and "here is the record that we do."
InsureGuardAI is built to make that record fall out of the work rather than be assembled in a panic. Continuous re-screening against refreshed lists, UBO resolution through ownership layers, retained match responses, and a per-decision audit trail all accumulate inside the customer workspace, so coverage, freshness, backlog, and true-hit metrics are queryable rather than reconstructed. When the board asks what it knew, the answer should already be sitting in the workspace. See how it works.