List currency and change control
Where each list comes from, how quickly updates reach your systems, and the evidence that every update was loaded and applied. The exact failure behind the June 2026 penalties, tested directly.
Sanctions screening is where Bank Negara Malaysia keeps finding failures, and they are rarely about the law. They are about a list that was not updated, a customer screened a day late, or a match nobody froze. We test your programme the way an examiner would, and fix what we find before they do.
An independent review and remediation service for sanctions screening programmes at reporting institutions. We test whether your lists are current and applied, whether you screen the right parties at the right time, whether your matching and alert handling hold up, and whether a true match would be frozen, rejected and reported correctly, then help you close the gaps.
Across 2025 and 2026, Bank Negara Malaysia has penalised banks, insurers and takaful operators, e-money issuers, money services businesses and a corporate services provider for sanctions screening failures: databases not kept current, customers not screened in time, and matches not rejected, frozen or reported. On 10 June 2026, Standard Chartered Bank Malaysia Berhad and Standard Chartered Saadiq Berhad were each penalised RM132,000 for failing to keep up with updates to the Domestic List. Every institution believes its screening works. Few have tested the evidence behind it.
Scoped to your institution type and screening set-up. A money services business with one system and a bank with several need very different reviews.
Where each list comes from, how quickly updates reach your systems, and the evidence that every update was loaded and applied. The exact failure behind the June 2026 penalties, tested directly.
Who is screened, including beneficial owners, directors and payment counterparties, and when: at onboarding, on every list change and at transaction time. The gaps between those points are where most failures sit.
Testing matching against Malay, Arabic, Chinese and Tamil name variants, aliases and identifiers, and checking that thresholds were set on evidence rather than to cut alert volume.
A sample of closed alerts re-performed: were the reasons documented, reviewed and defensible, and were service levels met.
Walking a true match through your procedures and systems to confirm that funds would be frozen without delay, the relationship or transaction rejected, and the report made correctly.
Ownership, independent testing, board reporting and the metrics senior management should see, so the programme is overseen rather than assumed.
The failures in BNM's published actions are testable. Testing them first turns a potential enforcement finding into an internal remediation item.
An examiner asks for proof that each list update was applied. The review builds that evidence trail so the answer is a document, not a reassurance.
Tuning based on tested data can reduce alert volume without weakening coverage, and records why each threshold was set.
We do not sell or implement screening systems, so the recommendation is what your programme needs, whether that is configuration, process or a different tool.
Clear management information on list currency, alert backlog and testing results gives directors something to oversee, which is what supervisors expect of them.
Our two-day sanctions screening course is HRD Corp claimable and follows the same structure, so operations and compliance staff can sustain the improvements.
Your institution type, systems, lists, screening points and recent audit or examination findings.
Tracing the end-to-end screening process with operations, compliance and IT, from list source to report.
List update sampling, coverage and timing tests, matching tests with name variants, and re-performance of closed alerts.
A simulated match through freeze, reject and report, to prove the procedure works in practice.
Findings ranked by enforcement risk, with owners, actions and timelines, and support closing them.
A summary for senior management and the board, and the metrics to track from then on.
End-to-end view of lists, systems, screening points and hand-offs.
List currency sampling, coverage and timing tests, matching tests and alert re-performance, with evidence.
The result of the simulated match through freeze, reject and report.
Gaps ranked by enforcement risk, with remediation actions, owners and timelines.
Evidence-based threshold and rule changes, with the rationale recorded.
Position statement for directors and the ongoing metrics to monitor.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
Reporting institutions in Malaysia screen against the United Nations Security Council lists and the Domestic List declared by the Minister of Home Affairs, and must address proliferation financing under the Strategic Trade Act 2010. Foreign regimes such as OFAC, EU and UK sanctions are usually a matter of risk appetite and correspondent relationships rather than Malaysian law.
The system is only as good as the lists loaded into it, the parties sent to it, the thresholds set and the people handling alerts. The failures in BNM's enforcement actions were mostly in those areas, not in the software itself.
On 10 June 2026, Standard Chartered Bank Malaysia Berhad and Standard Chartered Saadiq Berhad were each penalised RM132,000 for failing to keep up with updates to the Domestic List. List currency is the first thing our review tests.
Often, yes, but only with evidence. We test matching against real name variants and your own alert history before recommending changes, and record why each threshold is set, so tuning does not become the next finding.
No. The review is vendor-neutral. If your system needs reconfiguring we specify what, and if it genuinely needs replacing we say so and help you set requirements.
No. BNM's actions have covered insurers, takaful operators, e-money issuers, money services businesses and a corporate services provider. The review is scaled to your institution and your screening set-up.
Tell us your institution type, the screening system and lists you use, and any recent audit or examination findings. We will come back with a review scope and a fixed quotation.