The choice between manual and automated sanctions screening is not a simple contest between spreadsheets and software. It is a control-design decision: can the current process screen the right parties at the right time, resolve alerts, preserve evidence and repeat the work reliably?
There is no universal number of customers, searches or alerts at which a business must automate. Applicable law creates sanctions prohibitions—for example, the UK Russia Regulations and EU Regulation 269/2014 impose regime-specific asset-freeze rules.12 Sector and regulatory guidance may shape control expectations. The technology should fit the organisation's exposure, scale and operating model.
This guide focuses on that operating decision. For the wider programme—from scope and screening populations to escalation and governance—use the practical sanctions screening guide.
What counts as manual sanctions screening?
“Manual” can describe several workflows. The useful distinction is not whether software appears somewhere in the process, but who initiates each check, how the population moves through the control, and what triggers another screen.
Manual list searches
An analyst enters one person or organisation into an official list-search tool or another search interface, reviews the returned candidates and saves the result. This can be workable for occasional checks, but the team must still control:
- which parties are searched;
- which sources and identifiers are used;
- when the search is repeated;
- how potential matches are escalated; and
- how the input, result, source, date and decision are retained.
An official search page can help locate candidates.3 It does not define the firm's full sanctions perimeter or decide what action follows a match.
Spreadsheet-led screening
A spreadsheet may serve as the population list, task queue, evidence log or input to another screening service. Excel itself is not necessarily performing the matching.
The risk depends on the complete process. A well-controlled, low-volume sheet may be more reliable than a poorly configured automated system. As the process grows, however, version control, duplicate records, missing identifiers, manual copying, list-change response and evidence reconstruction can become harder to manage.
Manual batch screening
CSV batch screening sits between one-by-one searches and event-driven automation. A person still prepares and uploads the file, while software compares the records and returns candidates in bulk.
That means the matching is automated but the operational trigger may remain manual. It can remove repetitive searches without requiring an API, while leaving the team responsible for population completeness, upload timing, failed rows, candidate review and future re-screening.
When can manual sanctions screening still work?
A manual process may remain proportionate when the workload is low and predictable and the organisation can demonstrate that the complete control remains effective. The question is not “Do we use a spreadsheet?” but “Can we operate and evidence the required process reliably?”
Check whether the team can consistently:
- identify every in-scope party and screening trigger;
- use current, applicable source data;
- collect enough identifying information to resolve candidates;
- complete checks before the relevant business decision;
- review and escalate alerts without an ageing backlog;
- apply quality control to manual work;
- preserve a reconstructable decision record; and
- repeat screening when the firm's policy requires it.
FCA guidance for firms in its scope explicitly contemplates both manual and automated screening and describes an appropriate mixture as possible good practice.4 OFAC likewise promotes a risk-based compliance programme tailored to an organisation's characteristics rather than prescribing one universal technology.5
These sources do not create a global safe harbour for manual work. They do show why “automation is always legally required” is not a defensible general statement.
Where manual screening starts to break down
Migration should be driven by observable control problems. A growing customer count can contribute, but volume alone says little about the timing, complexity and review burden of the work.
Re-screening becomes a manual control problem
Onboarding checks are easier to remember because a business event initiates them. Re-screening is harder when it depends on someone noticing a list change, maintaining a calendar, finding the correct population and rerunning the work.
Warning signs include late list updates, uncertain last-screened dates, missed population changes and repeated manual reconciliation. Ongoing monitoring can automate more of the trigger, but the firm must still define which changes matter and verify that the monitoring process works.
Alert queues exceed available review capacity
Automation does not remove alerts. It often exposes the queue that one-by-one screening previously hid.
If candidates wait beyond internal deadlines, ownership is unclear, staff absence stops the process or quality checks are skipped to reduce the queue, the problem is review capacity and control—not merely search speed. FCA supervisory findings have highlighted backlogs, weak alert handling and non-resilient manual processes.6
Evidence becomes difficult to reconstruct
Screenshots, email approvals, separate notes and spreadsheet cells can record a decision, but fragmentation makes it harder for another reviewer to answer:
What was screened, against which source, what candidate appeared, which identifiers were compared, who decided, and why?
When evidence must be reconstructed after the event, a controlled portal or case workflow may provide more value than faster matching alone. The detailed evidence model belongs in how to document a sanctions alert investigation.
Screening needs to happen inside a business event
Manual initiation becomes a structural constraint when a decision cannot proceed until a screening result is available—for example during digital onboarding, supplier activation or another defined product event.
An API can place the screening request and structured response inside that workflow. It does not decide whether a candidate is the same party or which legal action is appropriate. Those decisions still require the firm's approved review and escalation process.
Portal, CSV, API or ongoing monitoring: which problem does each solve?
Automation is a continuum. Choose the workflow that addresses the actual failure point rather than treating every organisation as if it must move directly from spreadsheets to real-time API screening.
| Workflow | Best-fitting problem | What remains human |
|---|---|---|
| Manual search | Occasional, low-volume checks that the team can trigger, review and evidence reliably | Search, interpretation, evidence, escalation and re-screening |
| Screening portal | Analysts should keep initiating searches but need one controlled review and evidence environment | Initiation, candidate review and decision |
| CSV batch screening | A known population must be screened or remediated in bulk without live integration | File preparation, reconciliation, failed rows and alerts |
| Real-time screening API | Screening must run inside an onboarding or other business event | Investigation, escalation and legal/compliance decision |
| Ongoing monitoring | Approved parties must be re-screened without relying entirely on a manual calendar | Reviewing relevant changes and reconsidering prior decisions |
These modes can be combined. A firm might use an API for new onboarding, batch files for a legacy portfolio, a portal for ad-hoc searches and monitoring for approved relationships.
For a deeper technical comparison of file and integration workflows, see API vs batch sanctions screening.
What changes when screening is automated?
Automation reallocates repetitive work. It does not remove judgement, accountability or control risk.
Alert review becomes exception-led
In a one-by-one process, the analyst initiates and assesses every search. With batch, API or monitoring, the system can compare more records and route candidates, so analysts spend more time on exceptions.
That makes queue ownership, priorities, service levels, escalation and quality assurance more visible and more important. A generated alert is still a candidate—not a sanctions conclusion.
Previous false-positive decisions can be retained
A controlled platform can preserve earlier dispositions and reduce repeated work when the same irrelevant candidate returns. Reuse should follow policy and should be reconsidered when the customer's data, source record or other meaningful facts change.
Software does not automatically solve false positives. Poor data or overly broad or narrow configuration can still produce bad outcomes. See the dedicated guide to reducing sanctions-screening false positives for matching and tuning detail.
Evidence becomes structured
The intended improvement is a connected record of the input, source result, timestamp, reviewer, rationale, escalation and outcome. Structured evidence can make review and reconstruction easier, but auditability still depends on what the organisation records and whether that record is complete.
Re-screening becomes a configured control
Monitoring can replace part of the manual reminder and rerun process. The control question changes from “Did someone remember?” to “Are the correct populations, sources, triggers and routing rules configured, tested and operating?”
The firm should know what causes a new review, how earlier decisions are treated, how failures are detected and who owns unresolved alerts.
Automation introduces configuration and integration risk
New technology replaces some manual dependencies with different risks:
- incorrect source-system field mapping;
- incomplete identifiers or populations;
- stale or failed list updates;
- inappropriate match configuration;
- batch rows that fail without reconciliation;
- API timeouts, retries or downstream failures; and
- excessive reliance on a vendor without independent assurance.
OFAC has identified screening-software failures, missing identifiers and failure to account for alternative spellings among enforcement lessons.5 FCA findings also warn firms to understand and test systems rather than rely only on supplier assurances.6
What to test before replacing a manual process
Treat migration as a control change. Use the organisation's own representative records and expected outcomes rather than a vendor demonstration built only from easy cases.
| Test area | What to verify |
|---|---|
| Population and mapping | Every in-scope record arrives with stable IDs and the intended identity fields |
| Matching | Known names, authentic variants, transliterations, common names and incomplete records behave intelligibly |
| Reconciliation | Duplicate, invalid and failed CSV rows or API requests are visible and recoverable |
| Review workflow | Candidates have an owner, priority, escalation route and quality-control path |
| Evidence | Another reviewer can reconstruct the input, result, source, rationale, approval and outcome |
| Re-screening | A realistic source or customer-data change creates the intended new review |
| Previous decisions | Earlier false-positive conclusions are reused or reopened according to policy |
| Failure handling | Source delays, integration errors, queue growth and stale data are detectable |
Run at least one true candidate, one irrelevant candidate and one unresolved identity through the complete workflow. For monitoring, clear a known false positive and then simulate a meaningful data change to confirm what is retained and what is reviewed again.
This is a migration acceptance test, not a complete vendor procurement exercise. Once software is the likely route, use how to choose sanctions screening software for the full requirements and proof-of-concept framework.
A practical decision framework
Choose the smallest controlled change that solves the demonstrated problem:
| Current condition | Practical direction |
|---|---|
| Low, predictable workload; reliable triggers, QC, evidence and re-screening | Keep the manual process and test it periodically |
| Analyst-led searches work, but evidence and review are fragmented | Move work into a controlled portal |
| Repeated bulk screening or remediation dominates | Add CSV batch screening and reconciliation |
| Screening must occur inside a live business workflow | Integrate an API at the defined event |
| Re-screening depends on calendars or manual list-change checks | Add ongoing monitoring for the approved population |
| Several conditions apply | Combine modes under one policy, evidence and escalation model |
The endpoint is not “maximum automation.” It is an effective, proportionate and testable control whose failures are visible and whose decisions can be reconstructed.
Checklynx supports sanctions screening through portal, CSV batch, API and ongoing-monitoring workflows, with case review and audit evidence. These capabilities can execute the firm's approved screening control; the customer remains responsible for its perimeter, policy, review and legal decisions.
Sanctions screening workflows
Move beyond manual work at the right point
Compare Checklynx portal, batch, API and monitoring options against the operational problem your team needs to solve.
Frequently asked questions
Is manual sanctions screening inherently non-compliant?
No. Suitability depends on the applicable framework and whether the complete control remains effective, proportionate and evidenced. Manual work becomes a concern when triggers, list updates, review, quality control, records or re-screening are unreliable.
Is automated sanctions screening legally mandatory?
Not universally. Particular laws, sectors or regulators may create specific expectations, but the reviewed authorities do not establish one global requirement for every regulated business to automate sanctions screening.
Do we need an API to automate sanctions screening?
No. A portal can control analyst-led work, CSV can scale known populations, and monitoring can automate re-screening triggers. An API is most useful when screening must occur inside a defined business-system event.
Is CSV batch screening manual or automated?
Both descriptions can be valid. A person may manually prepare and upload the population while software performs the matching. Define the trigger, matching, reconciliation and review workflow instead of relying on a binary label.
Does software eliminate sanctions-screening false positives?
No. Outcomes still depend on source data, customer identifiers, matching configuration and testing. Software may retain previous decisions and reduce repeated work, but it can also be configured poorly.
What is the clearest signal that a manual process needs to change?
Look for control failures: late or missed re-screening, growing alert backlogs, repeated re-keying, fragmented evidence, inconsistent review or a business event that cannot reliably wait for manual initiation. There is no universal numerical cutoff.
What should be tested before migration?
Test representative records, data mapping, matching, row and API failures, reconciliation, queue routing, evidence reconstruction, meaningful-change triggers and the treatment of previous false-positive decisions.
Official sources
Footnotes
-
UK legislation, The Russia (Sanctions) (EU Exit) Regulations 2019, Regulation 11, example of a regime-specific binding asset-freeze prohibition, accessed 9 September 2026. ↩
-
European Union, Council Regulation (EU) No 269/2014, example of a regime-specific binding EU asset freeze and prohibition, accessed 9 September 2026. ↩
-
US Department of the Treasury, Office of Foreign Assets Control, Sanctions List Search and sanctions-list file FAQs, official operational guidance contemplating manual search and software workflows, accessed 9 September 2026. ↩
-
Financial Conduct Authority, Financial Crime Guide, chapter 7: Sanctions, asset freezes and proliferation financing, guidance on proportionate manual and automated screening controls for firms in scope, version shown from 29 November 2024, accessed 9 September 2026. ↩
-
US Department of the Treasury, Office of Foreign Assets Control, A Framework for OFAC Compliance Commitments, risk-based programme and technology-control guidance, published 2019, accessed 9 September 2026. ↩ ↩2
-
Financial Conduct Authority, Sanctions systems and controls in our firms: our findings, supervisory findings on screening, data, alerts, resilience and vendor oversight, published 28 May 2026, accessed 9 September 2026. ↩ ↩2