Lesson 1 of 5

Why AML exists

Money laundering is the process of making money from crime look as if it came from a legitimate source. Criminals need to do this to use the proceeds of fraud, corruption, drug trafficking or other offences without drawing attention to where they came from.

Laundering is usually described in three stages:

  • Placement: getting criminal cash or funds into the financial system, for example through deposits, purchases or mobile-money transfers.
  • Layering: moving the money through many transactions, accounts, products or countries so that its origin becomes hard to trace.
  • Integration: bringing the money back into the legitimate economy, for example as property, business investment or apparently ordinary income.

Terrorist financing is related but different. The money may come from legitimate sources; what is hidden is its purpose.

International standards for fighting both are set by the Financial Action Task Force (FATF), an intergovernmental body whose Recommendations countries are expected to put into their own laws. In Kenya, the main law is the Proceeds of Crime and Anti-Money Laundering Act, 2009, and the Financial Reporting Centre is the national body that receives suspicious transaction reports.

Regulated institutions are expected to follow a risk-based approach: understand where their money-laundering risks are highest, and put the most effort there. Screening customers and payments against sanctions lists and lists of politically exposed persons is one of the core controls.

Lesson 2 of 5

Sanctions and watchlists

Sanctions are legal restrictions placed on named people, organisations, vessels or countries. They can include asset freezes, bans on making funds available, travel bans and trade restrictions. A financial institution that deals with a sanctioned party can face serious penalties, so it must check its customers and payments against the lists that apply to it.

Widely used lists include:

  • the United Nations Security Council Consolidated List, which UN member states are required to implement;
  • the Specially Designated Nationals and Blocked Persons List published by the US Office of Foreign Assets Control (OFAC);
  • the European Union consolidated list of persons and entities subject to financial sanctions;
  • the UK Sanctions List, published by the UK Foreign, Commonwealth & Development Office, which replaced the OFSI Consolidated List as the UK's single source in January 2026.

Which lists an institution must screen against depends on where it operates, the currencies it handles and who it deals with. That decision belongs to its compliance function and legal advisers.

Lists change often: names are added, details are corrected and people are delisted. Good screening therefore depends on two habits: always screening against the current version of each list, and re-screening existing customers when the lists change, not only at onboarding.

Lesson 3 of 5

Politically exposed persons

A politically exposed person (PEP) is someone who holds, or has held, a prominent public function: for example a head of state, senior politician, senior judge, senior military officer or senior executive of a state-owned company. FATF standards distinguish foreign PEPs, domestic PEPs and people with prominent functions in international organisations.

The same standards extend to a PEP's family members and close associates, because they can be used to hold or move money on the PEP's behalf.

Being a PEP is not wrongdoing. It means the person's position could expose them to bribery or corruption, so an institution applies enhanced due diligence. Typical measures include establishing the source of wealth and source of funds, getting senior management approval for the relationship, and monitoring it more closely over time.

When someone leaves office, they do not automatically stop being treated as a PEP. How long the extra measures continue should be a risk-based decision, not an automatic date.

Lesson 4 of 5

Why name matching is hard

Screening compares a name, such as a new customer or the beneficiary of a payment, with the names on the lists. Exact matching alone fails, because the same person's name can appear in many forms:

  • spelling variants, such as Mohammed, Muhammad and Mohamed;
  • transliteration from other scripts, such as Arabic, Cyrillic or Chinese, where there is more than one accepted way to write a name in Latin letters;
  • name order, missing middle names, initials, titles and honorifics;
  • typing errors and aliases.

Screening systems therefore use fuzzy matching. Common techniques include edit distance (how many single-character changes turn one name into the other), phonetic codes (whether two names sound alike), and token overlap (how many words two names share, whatever their order).

The result is a similarity score, and a threshold decides which scores become alerts. This is a trade-off. A lower threshold catches more true matches but produces more false alarms; a higher one produces fewer alerts but risks missing a real match. Setting it is a documented, risk-based decision.

Secondary identifiers such as date of birth, nationality and identity numbers are what turn a possible match into a confirmed one, or rule it out.

Lesson 5 of 5

Reviewing alerts well

Most screening alerts are false positives: a customer who happens to share a name with a listed person. Reviewing them well is where much of the day-to-day work of a screening team happens.

  • Compare identifiers, not just names: date of birth, nationality, address, identity numbers and any other details on the listing.
  • Record your reasoning. A decision that cannot be explained later is hard to defend to an auditor or regulator.
  • Use a second reviewer for high-risk decisions (often called the four-eyes principle), so no single person can clear or confirm a serious match alone.
  • Escalate true or likely matches according to your organisation's procedures and the law where you operate. That can mean freezing funds and reporting to the relevant authority.
  • Do not tip off the customer. In many jurisdictions it is an offence to tell someone that a suspicious transaction report has been or will be made about them.

Screening teams also measure their own performance: how many alerts turn out to be real (precision), and how many real matches the system finds (recall). Improving one often costs the other, which is why thresholds are reviewed and tested rather than set once.

In Saolix Eagle, a name-only match is sent to an analyst rather than blocked automatically, high-scoring cases need a second approver, and every interactive screening decision is written to a tamper-evident audit log. You can try this in the Eagle simulator.

Knowledge check

Ten questions

Answer all ten questions, then check your answers. You need 8 out of 10 to pass, and you can try as many times as you like. Your answers, progress and times are kept only in this browser.