Correct Answer:
D. The institution uses internally managed whitelists and calibrates the threshold to reduce false positives.
Explanation:
Sanctions and Compliance Domains outline that institutions must maintain effective and reliable sanctions screening systems. This includes screening all incoming and outgoing payment messages, and institutions may not rely solely on correspondent banks for sanctions controls. Screening tools must also be capable of detecting alternative spellings, transliterations, and name variations of sanctioned parties.
Sanctions list updates must be incorporated immediately or as soon as practicable after publication. Monthly updates would be considered insufficient.
The use of controlled internal whitelists, combined with proper governance, periodic review, and controlled threshold calibration, is an accepted method used to reduce false positives while maintaining compliance integrity. Threshold adjustments must always follow documented validation, testing, and oversight procedures.
Reference from Sanctions and Compliance Domains:
Requirements for screening all payment messages, including incoming SWIFT transfers.
System expectations for matching name variations and alternative spellings.
Regulatory expectations for timely list updates.
Recognition of whitelist use and threshold calibration as acceptable screening optimization methods.