Screen against the lists. Then keep screening.
A name clear at onboarding is not clear forever. Lists change, people become exposed, and an obligation that ended at signup is an obligation you failed. This is how screening works here, and what reaches the regulator.
Coverage
Which lists.
OFAC, the EU consolidated list, the UN Security Council list, UK OFSI, and Sri Lanka designated persons. Alongside them, politically exposed person handling and adverse media, so a match is not only a legal designation but a reputational one.
A hit does not decide anything on its own. It returns as a structured outcome you can route to a human, which is what the review queue in the console is for — screening that silently auto-declines is screening you cannot defend to a regulator.
Over time
Re-screening, not one screening.
Customers go into a register that is re-screened when a list changes, so a name that becomes sanctioned after you onboarded still surfaces. Politically exposed persons are escalated to enhanced due diligence and carry periodic review rather than sitting on a single cleared result from months ago.
Reporting
What reaches FIU-CBSL.
Suspicious Transaction Report and Cash Transaction Report drafts are exported as goAML XML, the format the Financial Intelligence Unit of the Central Bank of Sri Lanka accepts. Drafts, deliberately: the filing decision and its contents remain yours, and a system that files on your behalf is a system that files your mistakes.
Next step
Screen a name against the live lists.
Screening runs from the console with no integration at all, or from the API with the same request shape as every other check.
