· Yair Knijn
Your sanctions program is a shared spreadsheet, and only one person knows the macros
The Claims Operations Director has a screening process that works. A new party comes in, an analyst pastes the name into the OFAC SDN Search page, eyeballs the hits, and logs a row in screening_log.xlsx on the shared drive. It has run that way for years without a missed deadline. The Director calls it a control. It is not a control. It is a habit that one person happens to keep.
The mistake is treating activity as evidence of a program. Names get checked, so screening must be happening. But a regulator does not ask whether you screen. They ask you to reproduce a specific decision from eighteen months ago and explain the methodology behind it, and that is where the spreadsheet goes quiet.
Why manual list lookups don't scale and can't be audited
OFAC's own SDN Search tool runs fuzzy logic to surface approximate matches, and that is exactly the problem when a human is the only thing standing between a near-match and a cleared row. The tool returns a score; the analyst decides. Nothing records what threshold they applied, which of three "Mohammed Al-" results they ruled out, or whether they checked the list version current that day or a cached page from last quarter. The lookup is stateless by design. Your case file inherits that statelessness.
A spreadsheet captures the outcome and almost none of the reasoning. You get a name, a date, and a green cell. You do not get the raw match response, the list publication date, the disposition rationale, or who actually made the call. When OFAC's framework asks for documented internal controls and regular independent testing, a column of "CLEAR" entries is not documentation. It is a tally.
Key-person risk: when the screening process walks out the door
Here is the failure mode that ends careers. The analyst who built the spreadsheet understands the conditional formatting, the unwritten rule about when a partial match needs a second look, and the reason column F is hidden. Then they take a job somewhere else, or they are out for six weeks, and the entire screening capability leaves with them. The macros are still there. The judgment that made them mean something is gone.
The Director discovers this the hard way: the replacement clears a name the old analyst would have escalated, or escalates ten the old analyst would have cleared, and now your screening consistency is visibly tied to which human was at the keyboard. A control that produces different results depending on who runs it is not a control. It is a personality.
Consistency and reproducibility as regulatory expectations, not nice-to-haves
OFAC penalties and settlements in 2025 ran well past two hundred million dollars, a sharp jump from the prior year, and the cases that hurt are rarely about missing an obvious name. They are about a program that could not demonstrate consistent, tested, repeatable controls. Reproducibility is not a quality-of-life feature you add later. It is the thing being examined.
Two analysts screening the same party on the same day should reach the same disposition for the same recorded reason, and you should be able to prove it a year later. That requires a few things a spreadsheet structurally cannot provide:
- The exact match response retained as evidence, not a summary of it
- The list version and timestamp tied to each decision
- A disposition rationale captured at the moment of the call, attributed to a named person
- An immutable trail so a cleared row cannot be quietly edited after the fact
Moving from ad-hoc lookups to a tenant-scoped case system of record
The fix is not a better spreadsheet or a stricter naming convention. It is a system of record where every screen is a durable case, every match keeps its raw response, and every disposition carries its reasoning and its author. The process stops depending on one person's memory because the memory lives in the record, where the next analyst and the next examiner can both read it.
InsureGuardAI gives each customer a tenant-scoped workspace where screening produces auditable cases instead of disposable lookups, so the methodology survives the analyst who built it and the case file answers the regulator before they finish asking. If your sanctions program currently lives in a shared drive and one person's head, that is the gap to close first.