Platform
Solutions
Resources
Company
Resources
Solutions

Employee screening: internal controls and periodic renewal

Identity details of employees and candidates can be compared against sanctions, PEP, adverse media, and internal lists within your organization's legal and regulatory framework. TruvaLI records these checks and supports periodic re-screening as lists change.

Employee screening involves checking active staff and job candidates against sanctions lists, politically exposed person (PEP) records, adverse media, and internal watchlists. For obliged parties, this check is not a one-time onboarding step: it is an ongoing control repeated as lists change.

Who performs employee screening?

In practice, three distinct drivers converge on the same individual: the organization's obligation to comply with sanctions regimes, internal fraud risk, and reputational risk. A single screening must address all three, as they all focus on the same person.

In obliged parties, appointments within the compliance unit are bound by written procedures and principles. Knowing the organization's own personnel and performing checks during role changes are integral parts of these procedures. In banking, electronic money, payment, and capital markets institutions, employee reliability is also subject to internal control and internal audit regulations.

Which lists are screened against?

ListWhat it containsWhere it comes fromRefresh frequency
SanctionsIndividual and entity decisions, along with the issuing authority and countryInternational and national sanctions listsAs published by the source
PEP and associatesPublic office, term of office, family and close associate relationshipsOfficial government pages and list sourcesAt defined intervals
Adverse mediaNews regarding crimes, investigations, and sanctions related to the individualKeyword, language, and country-based news feedsRegular polling
Internal listThe organization's own blacklist and restricted individualsInternal records, document uploads, or source definitionsAs updated by the organization

Organizations can build their own lists through official source definitions, feed streams, or document uploads. Details are available on the custom screening lists page.

How is a match confirmed?

Name similarity alone is not a sufficient basis for a decision. Whether a match is genuine is tested against secondary information stored in the record.

SignalPurpose
Alias and transliterationBridges the gap between Cyrillic, Arabic, and Latin scripts
Date and year of birthDistinguishes individuals sharing the same name
ID and passport numberThe strongest confirmation, sufficient on its own
Nationality, country, and cityEliminates geographically impossible matches
PhotoRetrieved from the source and displayed with a confidence score
Record effective datePrevents lifted sanctions from generating alerts

The cost of a false positive is different for employees than for customers: it does not just delay a transaction, it directly impacts an individual's job and reputation. Therefore, in employee screening, a match is not a conclusion, but the beginning of an investigation.

How are lists kept up to date?

A screening is only as good as the freshness of the underlying data. Three methods work in tandem.

The official source itself is monitored. Some countries' PEP and sanctions data are not available in pre-packaged lists. In such cases, the source itself is defined: a parliamentary member list, a cabinet page, or a national sanctions announcement. The page is read at defined intervals, sub-links are crawled, and the resulting records enter screening along with their source link. The type of source also determines the classification: a record from a parliamentary list is flagged as a PEP, while a record from a sanctions announcement is flagged as sanctions.

Adverse media feeds are polled. Keywords, languages, and countries are defined; news feeds are regularly polled, and relevant publications are queued for review. Records are not created automatically: a human decides which news item is converted into a record.

Regulatory bulletins are parsed. A bulletin, decision text, or PDF list can be uploaded directly; the text is parsed, and the individuals and entities within it are converted into structured records. Capital markets bulletins are processed this way.

Every record is stored with its source link. When asked why a match exists, the answer traces back to the exact page the record originated from. The entire screening infrastructure is detailed on the sanctions, PEP, and adverse media screening page.

Screening is not a one-time event

As lists change, re-screening is performed, and any new match generates a new alert. A person who clears screening today might match a decision published three months later; what catches that decision is not the screening at the time of hiring, but continuous screening. The customer-side equivalent of this logic is detailed on the ongoing monitoring page.

Records, authorization, and privacy

Every screening is recorded: who was screened, when, against which list, and what the outcome was can be audited later. A match initiates a decision chain; the decision is recorded with its justification, and access is restricted by authorization. Who accessed employee data is stored in an immutable audit trail. The details of this mechanism are on the maker-checker, authorization, and audit trail page.

Employee data is personal data, and the relationship between the employee and the organization establishes a different legal basis for data processing than a customer relationship. This distinction is addressed on the KVKK and GDPR pages. With an on-premise deployment, all data remains within the organization's own infrastructure: for a matter like employee screening, where data resides is not a technical preference, but a legal requirement.

The decision remains with humans

The decision is linked to the case with its justification and evidence; information on who decided, with what authority, and when is written to the immutable audit trail. The entire case workflow is detailed on the alert and case management page.

Common questions

Is employee screening a separate product?
No. It is the application of the same customer screening infrastructure to a different subject. Sanctions records, internal lists, and adverse media entities reside in the same place.
Which lists are screened against?
Sanctions lists, PEP and associate records, adverse media, and the organization's own watchlists. Organizations can add their own lists via official source definitions, feed streams, or document uploads.
How is the risk of false positives reduced?
Name similarity alone is not a sufficient basis for a decision. Aliases and transliterations, date of birth, ID and passport numbers, nationality and city details, and photo confirmation are evaluated together; the record's effective date is also checked.
Is there a difference between candidate screening and employee screening?
The screening is the same, but the legal basis and retention periods differ. Candidate data is processed for the duration of the recruitment process, while employee data is processed for the duration of the employment relationship and as prescribed by legislation.
Is screening repeated?
Yes. Re-screening is performed as lists change, and any new match generates a new alert. A person who clears screening today might match a decision published later.
How up to date are the lists?
Three methods work in tandem: official source pages are read at defined intervals, adverse media feeds are regularly polled, and regulatory bulletins are uploaded and converted into structured records. Every record is stored with its source link.
Is access to employee data logged?
Yes. Access is restricted by authorization, and who accessed employee data and when is written to the immutable audit trail.
Does data leave the organization?
Not with an on-premise deployment. All screening and records remain entirely within the organization's own infrastructure.

Related