Governance / Sanctions Compliance

Sanctions Screening Review in Malaysia

Sanctions screening is where Bank Negara Malaysia keeps finding failures, and they are rarely about the law. They are about a list that was not updated, a customer screened a day late, or a match nobody froze. We test your programme the way an examiner would, and fix what we find before they do.

Built around BNM's 2025 and 2026 enforcement record List currency, timing, matching and alert handling tested Vendor-neutral: we do not sell screening software
Overview

Sanctions Screening Review

What it is

An independent review and remediation service for sanctions screening programmes at reporting institutions. We test whether your lists are current and applied, whether you screen the right parties at the right time, whether your matching and alert handling hold up, and whether a true match would be frozen, rejected and reported correctly, then help you close the gaps.

Why organisations need it

Across 2025 and 2026, Bank Negara Malaysia has penalised banks, insurers and takaful operators, e-money issuers, money services businesses and a corporate services provider for sanctions screening failures: databases not kept current, customers not screened in time, and matches not rejected, frozen or reported. On 10 June 2026, Standard Chartered Bank Malaysia Berhad and Standard Chartered Saadiq Berhad were each penalised RM132,000 for failing to keep up with updates to the Domestic List. Every institution believes its screening works. Few have tested the evidence behind it.

Key features

What the engagement covers

Scoped to your institution type and screening set-up. A money services business with one system and a bank with several need very different reviews.

List currency and change control

Where each list comes from, how quickly updates reach your systems, and the evidence that every update was loaded and applied. The exact failure behind the June 2026 penalties, tested directly.

Screening coverage and timing

Who is screened, including beneficial owners, directors and payment counterparties, and when: at onboarding, on every list change and at transaction time. The gaps between those points are where most failures sit.

Name matching and tuning

Testing matching against Malay, Arabic, Chinese and Tamil name variants, aliases and identifiers, and checking that thresholds were set on evidence rather than to cut alert volume.

Alert handling and adjudication

A sample of closed alerts re-performed: were the reasons documented, reviewed and defensible, and were service levels met.

Freeze, reject and report

Walking a true match through your procedures and systems to confirm that funds would be frozen without delay, the relationship or transaction rejected, and the report made correctly.

Governance and management information

Ownership, independent testing, board reporting and the metrics senior management should see, so the programme is overseen rather than assumed.

Business value

What the business gets out of it

You find it before BNM does

The failures in BNM's published actions are testable. Testing them first turns a potential enforcement finding into an internal remediation item.

Evidence, not assurance

An examiner asks for proof that each list update was applied. The review builds that evidence trail so the answer is a document, not a reassurance.

Fewer false positives without more risk

Tuning based on tested data can reduce alert volume without weakening coverage, and records why each threshold was set.

A vendor-neutral view

We do not sell or implement screening systems, so the recommendation is what your programme needs, whether that is configuration, process or a different tool.

The board sees the real position

Clear management information on list currency, alert backlog and testing results gives directors something to oversee, which is what supervisors expect of them.

Your team learns the method

Our two-day sanctions screening course is HRD Corp claimable and follows the same structure, so operations and compliance staff can sustain the improvements.

How it works

How the engagement runs

01

Scoping

Your institution type, systems, lists, screening points and recent audit or examination findings.

02

Walkthrough

Tracing the end-to-end screening process with operations, compliance and IT, from list source to report.

03

Testing

List update sampling, coverage and timing tests, matching tests with name variants, and re-performance of closed alerts.

04

True match scenario

A simulated match through freeze, reject and report, to prove the procedure works in practice.

05

Findings and remediation

Findings ranked by enforcement risk, with owners, actions and timelines, and support closing them.

06

Board reporting

A summary for senior management and the board, and the metrics to track from then on.

Deliverables

What you receive

Screening process map

End-to-end view of lists, systems, screening points and hand-offs.

Test results

List currency sampling, coverage and timing tests, matching tests and alert re-performance, with evidence.

True match walkthrough

The result of the simulated match through freeze, reject and report.

Findings report

Gaps ranked by enforcement risk, with remediation actions, owners and timelines.

Tuning recommendations

Evidence-based threshold and rule changes, with the rationale recorded.

Board summary and MI pack

Position statement for directors and the ongoing metrics to monitor.

Who it is for

Who this is built for

Industries

Banks and Islamic banksInsurers and takaful operatorsE-money issuersMoney services businessesPayment system operatorsCapital market intermediariesDigital asset platformsCompany secretaries and corporate service providers

Company sizes

Licensed financial institutionsMid-sized reporting institutionsDNFBPsRegional institutions with a Malaysian entity

Departments

Compliance and AMLOperations and onboardingPayments and trade financeIT and screening system ownersInternal auditBoard risk committee
Why Orbix

Why organisations choose Orbix

A governance approach, not a tool sale

We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.

Recommendations you can actually implement

Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.

Consultants who have sat on your side of the table

Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.

Built for the Malaysian operating context

Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.

HRD Corp expertise where it applies

Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.

Questions

Questions we get asked

Which lists do we have to screen against?

Reporting institutions in Malaysia screen against the United Nations Security Council lists and the Domestic List declared by the Minister of Home Affairs, and must address proliferation financing under the Strategic Trade Act 2010. Foreign regimes such as OFAC, EU and UK sanctions are usually a matter of risk appetite and correspondent relationships rather than Malaysian law.

Our screening system is from a major vendor. Is that not enough?

The system is only as good as the lists loaded into it, the parties sent to it, the thresholds set and the people handling alerts. The failures in BNM's enforcement actions were mostly in those areas, not in the software itself.

What did the June 2026 penalties involve?

On 10 June 2026, Standard Chartered Bank Malaysia Berhad and Standard Chartered Saadiq Berhad were each penalised RM132,000 for failing to keep up with updates to the Domestic List. List currency is the first thing our review tests.

Can you reduce our false positives?

Often, yes, but only with evidence. We test matching against real name variants and your own alert history before recommending changes, and record why each threshold is set, so tuning does not become the next finding.

Do you sell or implement screening software?

No. The review is vendor-neutral. If your system needs reconfiguring we specify what, and if it genuinely needs replacing we say so and help you set requirements.

Is this only for banks?

No. BNM's actions have covered insurers, takaful operators, e-money issuers, money services businesses and a corporate services provider. The review is scaled to your institution and your screening set-up.

Get started

Test it before the examiner does

Tell us your institution type, the screening system and lists you use, and any recent audit or examination findings. We will come back with a review scope and a fixed quotation.