Licensed API · ongoing CDD · ODD · pKYC

VerifyNow AML for FICA ongoing due diligence

Enrol a person or company on VerifyNow AML through the licensed API, run the initial screen, then keep that customer on ongoing CDD and ongoing due diligence (ODD) against refreshed sources in the contracted licence scope. PEP and RCA screening requires the full financial-crime licence. Rescreen on your RMCP cadence. Screening supports CDD and EDD reviews after onboarding.

Ongoing AML monitoring

Keep customer screening current after onboarding.

Enrol identified people and companies, rescreen against refreshed lists and withdraw subjects through the licensed VerifyNow AML API.

  • Initial screening
  • 0-credit licence rescreens
  • Dataset notifications

For FICA accountable institutions — banks, insurers, financial services, attorneys, estate agents, gambling operators, crypto and other Schedule 1 businesses — plus fintech, iGaming and marketplaces whose RMCP calls for post-onboarding screening.

Annual licence. First enrol on AML/PEP credits. Same-subject rescreens use 0 credits within the contracted population, request limit and usage rules.

VerifyNow AML licensed API: desktop POST /api/external/aml-ongoing JSON, dataset-update webhook, and a phone reading SANCTIONS and PEP from a 200 response
Coverage and cadence

Lists, refresh and rescreen

Official UN, OFAC, UK and EU lists are checked every 60 minutes. Selected sanctions sources share that cycle. Most other configured sources refresh every six hours.

You enrol people and companies. Each screen uses the source versions present in its dataset version. The configured catalogue includes publisher lists for persons, companies, entities, vessels and aircraft. Source availability can change during publisher outages or failed refreshes.

60m

UN, OFAC, UK and EU

Core TFS files are checked every 60 minutes. A dataset webhook notifies a list version change.

6h

Other lists

Most remaining configured publisher sources refresh every six hours. Sanctions, crime, wanted, regulatory and debarment are available on the ongoing licence. PEP and RCA require the full financial-crime licence.

Illustrative simulation

See watchlists update

VerifyNow checks each source on schedule. When a list changes, this feed shows when it changed and how many records were added, updated or removed.

Refresh window25 Aug 2026 · 07:00 SAST
Cycle progress0 / 5 checked

How it works

  1. 01Lists are checked
  2. 02Changes are dated
  3. 03Your team is notified
  4. 04You rescreen when required

Illustrative watchlist refresh feed dated 25 August 2026. It shows publisher lists being checked in sequence and records which entries were added, updated or removed.

Dataset notification prepared

Your team receives an email and signed webhook when visible list content changes. Your system runs the rescreen when your RMCP calls for it.

Targeted financial sanctions (TFS)

FIC requires accountable institutions to screen against targeted financial sanctions (TFS). VerifyNow AML supports that screening with configured United Nations, OFAC, UK, EU and Australian sources. Each result records the dataset version used for the screen.

  • United Nations Security Council
  • United States OFAC SDN
  • United States OFAC consolidated
  • United Kingdom
  • European Union
  • Australia
Configured source catalogue+

This catalogue shows configured publisher sources. A source may be unavailable during an outage or failed refresh. Enterprise due diligence can include a dated source-status record.

Core TFS lists

  • UN Security Council Consolidated Sanctions
  • US OFAC Specially Designated Nationals List
  • US OFAC Consolidated Non-SDN List
  • UK Sanctions List
  • EU Financial Sanctions Files
  • Australian Sanctions Consolidated List

South Africa

  • South Africa Wanted Persons
  • South Africa FSCA Enforcement Actions
  • South Africa Cabinet Ministers and Deputy Ministers
  • South Africa CIDB Removed Contractors
  • South Africa Companies Tribunal Decisions and Orders
  • South Africa Municipal Leadership
  • South Africa NCR Credit Providers Cancelled by Tribunal
  • South Africa Prudential Authority Administrative Sanctions
  • South Africa Register of Tender Defaulters
  • South Africa Restricted Suppliers

Sanctions

  • Argentina RePET Entities
  • Argentina RePET Persons
  • Austrian National Bank Terrorism Financing Restrictions
  • Belgian Consolidated Financial Sanctions
  • Canada Freezing Assets of Corrupt Foreign Officials: Tunisia
  • Canada Justice for Victims of Corrupt Foreign Officials Sanctions
  • Canada Listed Terrorist Entities
  • Canada Special Economic Measures Act Sanctions
  • Canadian Named Research Organizations list
  • Czech National Anti-Terrorism Designations
  • Czech Republic National Sanctions List
  • Estonia Government National Sanctions Subjects
  • EU Geographic Restrictive Measures
  • French National Asset Freezing Register via Open Licence Catalogue
  • Georgian Otkhozoria-Tatunashvili List
  • India MHA Terrorist Organizations
  • India MHA Unlawful Associations
  • Ireland Unlawful Organisation Orders
  • Japan METI Russian Export Restriction Entities
  • Kyrgyz National List
  • Latvia FIU Sanctions and Asset Freezes
  • Latvia's Magnitsky Law Sanctions List
  • Malaysia Ministry of Home Affairs Designations
  • Monaco Fund Freezing List
  • Morocco CNASNU Local List
  • Nepal Prohibited Persons List
  • Netherlands National Sanctions List for Terrorism
  • New Zealand Designated Terrorist Entities
  • New Zealand Russia Sanctions Register
  • Nigeria Sanctions Committee List
  • Philippines Anti-Terrorism Council Designations
  • Poland GIIF Article 118 AML/CFT Sanctions
  • Poland National Sanctions List
  • Singapore Terrorism Suppression of Financing Act Schedule
  • Switzerland SECO Sanctions and Embargoes
  • UK Russia Financial and Investment Restrictions List
  • Ukraine SFMS Terrorist List
  • UN Security Council 1718 Designated Vessels
  • United Arab Emirates Local Terrorist List
  • United Kingdom Geographic Sanctions Regimes
  • United Kingdom Proscribed Organizations
  • United Nations Security Council Sanctions Regimes
  • US Consolidated Screening List: Commerce and State Sources
  • US Department of Defense Section 1260H List
  • US FinCEN 311 and 9714 Special Measures
  • US State Department Cuba Prohibited Accommodations List
  • US State Department Cuba Restricted List
  • US State Department Foreign Terrorist Organizations
  • US State Department Terrorist Exclusion List

PEP and RCA

  • Argentina Chamber of Deputies Members
  • Brazil Politically Exposed Persons
  • Cayman Islands Members of Parliament
  • CIA World Leaders and Cabinet Members of Foreign Governments
  • Croatia State Registry of Public Officials
  • Current Members of the European Parliament
  • Current Members of the Netherlands House of Representatives
  • French Mayors
  • French National Assembly Members and Parliamentary Collaborators
  • French Senators
  • Hong Kong Principal Officials
  • Israel Knesset Members
  • Latvian Saeima
  • Members of the Riigikogu
  • Members of the Seimas of the Republic of Lithuania
  • Mexico Chamber of Deputies
  • Mexico Senate
  • Slovakia Public Officials
  • UN Heads of State & Foreign Ministers
  • Uruguay Politically Exposed Persons
  • US Periodically Listing Updates to Management Reporting
  • US State Department Senior Officials
  • Wikidata Current Public Office Holders

Crime and wanted

  • FBI Wanted
  • Netherlands Police Nationale Opsporingslijst
  • Polish Police Wanted Persons
  • UK NCA Most Wanted
  • US FBI Lazarus Group Stake.com Cryptocurrency Addresses
  • US ICE Most Wanted Fugitives
  • US Secret Service Most Wanted Fugitives

Regulatory

  • Bank of Lithuania Illegal Financial Services Websites
  • Brazil Entities Prohibited from Offering Auditing Services
  • Brazil Ministry of Labour Employer Register
  • Brazil Register of Persons Disqualified from Senior Roles
  • Brazil TCU List of Individuals Disqualified from Public Service
  • ESMA Suspensions and Removals Register
  • EU ESMA Sanctions Register
  • EU High-Risk Third Countries for AML and CFT
  • EU Non-Cooperative Jurisdictions for Tax Purposes
  • FATF High-Risk and Monitored Jurisdictions via HM Treasury
  • France AMF Illegal Financial Services List
  • France Non-Cooperative States and Territories
  • Inter-American Development Bank Sanctioned Firms and Individuals
  • Japan METI Foreign End User List
  • Malaysia Financial Consumer Alert List
  • UK Companies House Disqualified Directors
  • US BIS Antiboycott Requester List
  • US CBP Withhold Release Orders and Findings
  • US DDTC Penalties and Oversight Agreements
  • US FDA Clinical Investigator Disqualification Proceedings
  • US FDA Current Debarments
  • US FDIC Failed Banks
  • US Federal Reserve Enforcement Actions
  • US HHS OIG List of Excluded Individuals and Entities
  • US SEC Public Alert: Unregistered Soliciting Entities
  • US UFLPA Entity List

Debarment

  • Brazil National Register of Disreputable and Suspended Companies
  • Brazil TCU List of Debarred Bidders
  • US SAM Procurement Exclusions
Matching

How the matching engine works

VerifyNow AML compares enrolled customers to publisher-direct official lists with a proprietary matching engine built by VerifyNow. The lists are the public sanctions, PEP and related files in the coverage catalogue. The engine is how a possible match is scored for ongoing CDD.

  1. Compare to official lists

    VerifyNow’s proprietary matching engine compares the enrolled name and identifier against publisher-direct official lists.

  2. Score names and identifiers

    The engine scores names, aliases, identifiers, dates of birth and countries. An identifier match after normalisation is a strong signal.

  3. Corroborate the legal name

    Where a short name produces several hits, the engine corroborates against the fuller legal name to reduce false positives. Possible matches return with scores and source evidence for analyst review, including EDD.

Licensed VerifyNow AML API

Enrol, rescreen and withdraw

POST name plus identifier. The first call enrols and screens. The same payload rescreens that enrolled subject against the lists above. Your system reads Success, Found and match count.

Licensed organisations get a dataset webhook when lists change, and an email notification — TFS sources are called out in that email. Rescreen is still your API call.

API documentation

  1. Enrol

    POST name plus identifier. The first call enrols the subject and runs the onboarding AML screen.

  2. Rescreen

    Rescreen as often as your RMCP requires. Send the same name and identifier again. Same-subject rescreens use 0 credits within the contracted population, request limit and usage rules of an active licence. Licensed organisations get a dataset webhook and email when lists change. Rescreen remains your API call.

  3. Withdraw

    Remove the subject from the active population when the relationship ends. Enrolment and operational audit metadata remains for seven years.

How it works

How ongoing monitoring works

  1. Enrol identified customers

    Add people or companies you already know to VerifyNow AML so they stay on the monitoring list.

  2. Get notified when lists refresh

    When a source changes, your team receives the dataset and source update. Your platform selects the subjects for rescreening.

  3. Rescreen and keep the evidence

    Run the follow-up screen on your own cadence and keep the report with the customer file.

VerifyNow AML

POST /api/external/aml-ongoing

POST200

Request

{
  "mode": "production",
  "name": "SAMPLE MATCH PERSON",
  "entity": 0,
  "country": "za",
  "dataset": "all",
  "identifierType": "sa_id",
  "identifierValue": "8001015009087"
}

Response

{
  "success": true,
  "requestId": "enrol-sample-match-01",
  "results": {
    "Success": true,
    "ResponseCode": 200,
    "Messages": [
      "Possible financial-crime matches found"
    ],
    "Header": {
      "SearchDate": "2026-08-17T08:00:00.000Z",
      "ReportName": "SAMPLE MATCH PERSON",
      "ReportReference": "amlmon_enrolsamplematch0100000000000000",
      "ClientReference": "enrol-sample-match-01",
      "ReportType": "Ongoing Financial Crime Monitoring",
      "AuditReference": "amlmon_enrolsamplematch0100000000000000",
      "DatasetVersion": "aml_20260817_sample",
      "DatasetPublishedAt": "2026-08-17T07:12:00.000Z",
      "ScreenedAt": "2026-08-17T08:00:00.000Z",
      "CategoriesRequested": [
        "sanctions",
        "crime",
        "wanted",
        "regulatory",
        "debarment",
        "pep",
        "rca"
      ],
      "DataOrigin": "publisher_direct"
    },
    "SearchResults": {
      "InputName": "SAMPLE MATCH PERSON",
      "InputMinScore": "90",
      "InputIdentifierMatchBoostingThreshold": "",
      "InputCountry": "ZA",
      "Found": true,
      "Message": "Possible financial-crime matches found",
      "RecordCount": 1,
      "EntityMatchCount": 1,
      "JurisdictionRiskCount": 0,
      "HasNextPage": false
    },
    "PossibleMatches": {
      "Found": true,
      "Message": "Possible financial-crime matches found",
      "HasNextPage": false,
      "Results": [
        {
          "Name": "SAMPLE MATCH PERSON",
          "AltNames": [
            "SAMPLE MATCH ALIAS"
          ],
          "EntityId": "vn-a1b2c3d4e5f6789012345678",
          "EntityType": "Person",
          "CountryResidence": [
            "ZA"
          ],
          "DateOfBirth": [
            "1980-01-01"
          ],
          "Identifiers": [],
          "Address": [],
          "ConfidenceScore": 0.972,
          "RiskCategories": [
            "sanctions"
          ],
          "Topics": [
            "sanction"
          ],
          "MatchExplanations": {
            "name_match": {
              "score": 1,
              "weight": 1,
              "impact": 1,
              "query": "SAMPLE MATCH PERSON",
              "candidate": "SAMPLE MATCH PERSON",
              "detail": "Best comparison across the submitted name and source aliases."
            }
          },
          "SourceEvidence": [
            {
              "Name": "US OFAC Specially Designated Nationals List",
              "ShortName": "us_ofac_sdn",
              "RecordReference": "sample-sdn-0001",
              "ListVersion": "us_ofac_sdn:sample",
              "PublishedAt": "2026-08-17",
              "DataOrigin": "publisher_direct",
              "Attribution": null
            }
          ],
          "FieldEvidence": {
            "lastName": [
              {
                "value": "PERSON",
                "source": "us_ofac_sdn",
                "recordReference": "sample-sdn-0001",
                "listVersion": "us_ofac_sdn:sample"
              }
            ]
          },
          "DataSource": {
            "Name": "US OFAC Specially Designated Nationals List",
            "ShortName": "us_ofac_sdn",
            "RecordReference": "sample-sdn-0001",
            "ListVersion": "us_ofac_sdn:sample",
            "PublishedAt": "2026-08-17",
            "DataOrigin": "publisher_direct",
            "Attribution": null
          },
          "Program": [
            "SDGT"
          ],
          "ListedOn": "2024-01-15",
          "Designation": "Sample designation for documentation",
          "Comments": "Linked To: SAMPLE MATCH ENTITY",
          "Remarks": "Linked To: SAMPLE MATCH ENTITY Listed on 2024-01-15",
          "remarks": "Linked To: SAMPLE MATCH ENTITY Listed on 2024-01-15",
          "sanctions": "Linked To: SAMPLE MATCH ENTITY Listed on 2024-01-15",
          "Relationships": [],
          "name": "SAMPLE MATCH PERSON",
          "aliases": "SAMPLE MATCH ALIAS",
          "schema": "Person",
          "entity_type": "Person",
          "countries": "ZA",
          "birth_date": "1980-01-01",
          "addresses": "",
          "identifiers": "",
          "score": 0.972,
          "matched_name": "SAMPLE MATCH PERSON",
          "source": "US OFAC Specially Designated Nationals List",
          "source_key": "us_ofac_sdn",
          "source_record_id": "sample-sdn-0001",
          "source_version": "us_ofac_sdn:sample",
          "dataset": "default",
          "dataset_version": "aml_20260817_sample"
        }
      ]
    },
    "JurisdictionRisks": {
      "Found": false,
      "Message": "No jurisdiction risk indicators found",
      "RecordCount": 0,
      "Results": []
    }
  },
  "remainingCredits": 1840,
  "screened_name": "SAMPLE MATCH PERSON",
  "screened_entity_type": "Person",
  "screened_country": "ZA",
  "screened_dataset": "all",
  "operation": "onboarding"
}

Dataset webhook and email

Licensed organisations get aml_monitoring.dataset_updated on the registered HTTPS webhook, HMAC-SHA256 signed. Organisation owner and admin contacts also get an email; TFS source changes are called out there. These are notifications — enrolled subjects are not rescreened automatically. POST the same name and identifier after the webhook or email, or on your RMCP review dates.

{
  "id": "evt_amlmon_aml_20260817_sample",
  "type": "aml_monitoring.dataset_updated",
  "createdAt": "2026-08-17T07:12:00.000Z",
  "data": {
    "datasetVersion": "aml_20260817_sample",
    "sourceStatus": "current",
    "dataOrigin": "publisher_direct"
  }
}

Headers: x-verifynow-event-id, x-verifynow-timestamp, x-verifynow-signature (v1= hex HMAC). Same payload for the first enrol and later rescreens: name plus identifier. Sample JSON uses synthetic names.

Read full API reference

Security

Data minimisation and purpose-limited retention

VerifyNow AML keeps enough to attach later rescreens to the same identified customer and maintain the operational audit trail. Screening queries stay transient at match time.

  1. Match-time queries

    The name and identifier used to search the lists are inputs at match time. They are not kept as a customer portfolio in the screening dataset.

  2. Hashed identifiers

    The enrolment registry stores an HMAC-hashed identifier and a name digest, scoped to your organisation. Plaintext ID numbers are not stored in the subject table. You send the name and identifier on every rescreen.

  3. Encrypted replay

    Full screening responses are stored as ciphertext for 48 hours so the same request can be replayed. After that window the ciphertext is purged.

  4. Purpose-limited retention

    Enrolment and operational audit metadata is retained for seven years. Withdrawal removes the customer from the active population.

Licence

Request a VerifyNow AML licence for your book

Annual licence. First enrol on AML/PEP credits. Same-subject rescreens use 0 credits within the contracted population, request limit and usage rules. Request a licence sized to your customer book. The first enrol of each person or company uses the same credits as an AML/PEP screen. After that subject is enrolled, same-subject rescreens on an active licence use no extra credits within the contracted population, request limit and usage rules.

First enrol

AML/PEP

Initial onboarding screen

The first enrol for a name and identifier uses the same credits as an AML/PEP screen.

After enrolment

0 credits

0-credit same-subject rescreens

Later screens of that enrolled identifier use no extra credits within the active licence population, request limit and usage rules.

Choose the right AML tool

One-shot, batch or VerifyNow AML

Comparison of AML/PEP screening, batch AML and VerifyNow AML
If you need toUseWhat it is
Screen one name nowAML/PEP ScreeningOne-shot dashboard or API screen. Identifier optional.
Screen a customer book from a fileBatch AML Screening10 to 1,000 spreadsheet rows. Manual, repeatable file review.
Keep the same customer in scope after onboardingVerifyNow AMLLicensed API. Identifier required. Enrol, rescreen on your RMCP cadence, withdraw when the relationship ends.
People also ask

VerifyNow AML questions

How does VerifyNow AML support FICA ongoing due diligence?

VerifyNow AML is built for accountable institutions that must perform ongoing due diligence under FICA. After onboarding identity is in place, enrol the identified person or company, rescreen against the source categories included in the licence, and withdraw when the relationship ends. Compliance officers get the screening result, dataset version, screening time, dataset webhook and match evidence to run ongoing CDD and support EDD reviews. Product and engineering teams wire rescreens to list-version changes and the review dates in the RMCP.

How often must FICA ongoing due diligence be conducted?

The institution’s RMCP sets the cadence. VerifyNow AML checks core TFS and selected sanctions sources every 60 minutes. Most other configured sources run on a six-hour refresh cycle. Licensed organisations get a dataset webhook and email when lists change. TFS sources are called out in that email. Rescreen remains your API call, on that signal or on the review dates in your RMCP.

How do we enrol, rescreen and withdraw customers on the API?

POST name plus identifier. The first call enrols the subject and runs the onboarding AML screen. The same payload rescreens that enrolled customer. Licensed organisations get a dataset webhook when lists change, and an email notification — TFS sources are called out in that email. Rescreen is still your API call, on that signal or on RMCP review dates. Withdraw through the licensed API when the relationship ends. Enrolment is API-first; there is no dashboard enrolment. Your system reads Success, Found and match count — the artefacts a compliance officer files with the CDD review.

Which lists does VerifyNow AML screen against?

The configured source catalogue covers sanctions, PEP, RCA, crime, wanted, regulatory and debarment sources from publisher-direct official lists. Each screen uses the source versions present in its dataset version. Source availability can change during a publisher outage or failed refresh. PEP and RCA screening requires the full financial-crime licence. The core targeted financial sanctions sources include the United Nations, United States OFAC, United Kingdom, European Union and Australia.

Why does enrol need an ID number or company number?

Ongoing CDD has to attach later screens to the same identified customer. People enrol with a South African ID or passport. Companies enrol with a CIPC registration number, LEI or tax number. Product teams use that identifier as the join key from onboarding through ops. One-shot AML/PEP checks can still run on a name only.

How does the matching engine decide a possible match?

VerifyNow’s proprietary matching engine compares names, aliases, identifiers, dates and countries against publisher-direct official lists. An identifier match after normalisation is a strong signal. Where a short name produces several hits, the engine corroborates against the fuller legal name to reduce false positives. Possible matches return with scores and source evidence for analyst review, including EDD.

What customer data does VerifyNow AML keep?

Screening queries are transient at match time. The enrolment registry stores an HMAC-hashed identifier and a name digest, not plaintext ID numbers in the subject table. You send the name and identifier on every rescreen. Full responses are encrypted for 48 hours, then the ciphertext is purged. Enrolment and operational audit metadata is retained for seven years. Withdrawal removes the customer from the active population.

Built for accountable institutions that must perform ongoing due diligence under FICA.

Keep customers in scope after onboarding

Annual licence. First enrol on AML/PEP credits. Same-subject rescreens use 0 credits within the contracted population, request limit and usage rules. Enrol, rescreen and withdraw through the licensed API.