TL;DR: AML screening takes time because each hit is a research job. The hours go into list updates, fuzzy and transliterated names, weak aliases, context the sanctions entry does not hold, and a written disposition. The FCA's May 2026 review of sanctions systems found that around 44% of firms close name screening alerts within one working day, while more than a quarter take three to five days.
A hit is a candidate, and the candidate is the work
AML screening is slow for a reason that has little to do with how fast a name scorer runs. The engine compares a customer, a payment party, or a beneficial owner to a sanctions or watchlist entry and returns a candidate. Closing that candidate means deciding whether the two records are the same person or the same company, then recording the decision so an examiner can replay it.
That decision is a sequence of comparisons. OFAC's match guidance, updated in September 2026, walks through them: confirm which list produced the hit, read the full entry including aliases and non-Latin names, and compare date of birth, nationality, identification numbers, and address before treating the match as valid. A similar name with a contradictory date of birth can be cleared. A close name with several matching attributes has to be escalated. The comparison starts by finding attributes the alert did not arrive with.
How the scorer builds the candidate is covered in sanctions screening name matching. The time question starts after the score clears the threshold. From there, five kinds of work absorb the minutes: refreshing the book when the list changes, judging fuzzy and transliterated names, separating strong aliases from weak ones, gathering context the list entry does not contain, and writing the disposition.
List changes put the whole book back in the queue

A quiet customer file becomes screening work the moment a list changes. A new designation, a new alias, or an amended identifier requires the existing book to be run again. The customer stayed put. The list moved, and every customer who now resembles the new text is a fresh case.
The FCA's May 2026 findings show how uneven that refresh is. Around two-thirds of firms in the FCA's proactive work said they applied sanctions list updates within one day of notification. The same review found errors and omissions in vendor-supplied lists, from poor data quality and transfers between systems, plus delays in updating the UK Sanctions List. Those delays produced alert backlogs.
Firms often cannot see how a list was ingested, which fields were dropped, or which aliases a vendor suppressed. When the feed is late or partial, the gap shows up as a payment that already moved, and the hours arrive afterward as a lookback. The FCA described a returned payment that was not re-screened against the updated list because the return message was thin and the manual handling was weak.
Queue growth has its own causes, set out in why screening alerts pile up. A single designation can still consume a day when the queue is short, because every near match on the new alias has to be opened, compared, and written up.
Fuzzy matches and weak aliases refuse to resolve on the score alone
Exact equality would be fast, and it would miss the names sanctions screening exists to catch. The FCA's sanctions screening testing found firms generally effective when names matched exactly: 90% of alerts raised in that testing correctly identified the sanctioned party. When the same parties appeared with minor spelling variations, the share fell to 75%. Honorifics and suffixes pulled scores under the alert threshold. Some firms excluded one-word names and names containing digits by default. Long names hit character limits and failed without an alert, or they required someone to intervene by hand.
Transliteration widens the same gap. A name written in Arabic, Cyrillic, or Chinese characters can have several accepted Latin-script forms, and the customer record usually stores only one of them. The FCA found firms that could not readily detect variant names, including names with non-Latin characters. Each plausible rendering is another file to open. Phonetic rules tight enough to stay quiet will miss a true variant, as the FCA saw when a retail bank's spelling rules failed to alert on a designated person. Rules wide enough to catch that variant also catch people who merely look similar.
A strong alias is another real name for the listed party. A weak alias is a low-quality alternate, often a common given name or a fragment shared by unrelated people. OFAC says screening tools may exclude weak aliases as a risk-based decision. Once the alert exists, the reviewer still has to show the customer is someone else. FATF's 2013 best practices on targeted financial sanctions describe these false positives as potential matches that arise from the common nature of the name or from ambiguous identifying data, and that prove not to be matches only after examination. The examination is the time.
The list entry stops, and the customer file begins
Sanctions list entries carry what the designating authority had at designation: names, aliases, and sometimes a date of birth, a nationality, a passport number, or an address. They do not carry the institution's KYC file, a prior clear on a similar name, or the passport image collected at onboarding. OFAC tells firms to compare every detail on the listing with the information available on the party, and to gather more when the file is thin. The examples in that guidance are a birth certificate, a driver's license, or a company's registration documents.
Customer records are often thinner than the procedure assumes. The FCA found dates of birth that were missing, incomplete, or stored as placeholder values. A blank date of birth cannot contradict a listed date of birth, so the reviewer goes looking in another system, a document store, or a prior alert nobody indexed. OFAC notes that an exact address match can be meaningless when several businesses share a location, so the reviewer has to know the building, not just the string. In commercial books the search also crosses ownership, because a company hit can become a hit on a shareholder the original entry never named. Teams that run this by hand absorb it as overtime and aging queues, the pattern in how to reduce compliance officer burnout.
The disposition is a record, and the record takes time to write
The control is the written record of the clear. OFAC expects organizations to keep complete records of the steps taken and the information relied on, and it may request those records under 31 C.F.R. § 501.602. OFAC does not confirm false positives for firms. The institution makes the risk-based call, and the write-up is what makes that call examinable later.
The FCA treats that write-up as part of alert management. Stronger firms had internal service levels, documented investigation rationales, quality assurance over outcomes, and escalation between the first and second line. Weaker handling showed up as alerts resolved incorrectly, assets moved before a freeze, and escalation skipped under pressure to meet internal targets.
Timeliness is already uneven. Around 44% of firms told the FCA they resolve name screening alerts within one working day on average. More than a quarter take three to five days. Some firms could not produce management information on resolution time at all. Three to five days measures the research and the write-up, waiting on data that was never attached to the hit.
A LexisNexis Risk Solutions study, conducted by Forrester and published in March 2024, found the workload moving in one direction across Asia Pacific. Screening alerts had increased at 79% of the financial institutions surveyed, and 75% cited labor costs as a primary driver of rising financial-crime compliance cost. Extra analysts absorb the dispositions. The path from hit to written reason stays the same length until the context and the write-up arrive with the alert.
What to inspect when the minutes stay high
Review time stays high when any of those steps is still a hunt. A useful check follows one alert from list update to disposition, which is a different question from how large the queue has grown. Reducing screening alert review time depends on whether the following work is already assembled when the case is opened.
Read cleared alerts the way an examiner would. The note should name the list, the alias that fired, the identifiers that matched, the identifiers that contradicted, the documents consulted, and the reason for the decision. Then ask how long a new alias takes to screen against the existing book, which aliases are suppressed and who approved that, and what happens when date of birth is blank. A program that cannot answer will keep spending the same hours on every near match.
Where Sphinx fits
Sphinx puts an agent on that same path: read the list entry, compare the identifiers already held on the customer, retrieve the context that sits outside the screening tool, and write the disposition with the reasoning attached. Across production workloads that work has produced an 80% reduction in case review time, with 98% of cases resolved the same day. The AML efficiency gap narrows when that reconstruction is done before an analyst opens the alert. The institution still owns the decision standard.
Frequently Asked Questions
Why does one AML screening alert take so long to close?
The screening engine only proposes a candidate. Closing the alert means comparing the list entry to the customer file, filling gaps the list does not cover, and writing why the names do or do not refer to the same person. The FCA's May 2026 review found that around 44% of firms close name screening alerts within one working day, while more than a quarter take three to five days.
Do sanctions list updates create new review work when the customer has not changed?
A new designation, alias, or amendment requires the existing book to be screened again, and a late or incomplete feed turns that delta into a backlog. The FCA found that around two-thirds of firms in its proactive work applied list updates within one day, and that delays in those updates were a direct cause of alert backlogs.
What makes a weak alias slower to clear than a strong name match?
A weak alias is a low-quality alternate name on a sanctions entry, often a common given name or a fragment that many unrelated people share. OFAC allows a risk-based decision to exclude weak aliases from screening, but once an alert is raised the reviewer still has to show the customer is not the listed person using whatever stronger identifiers exist.
Why can't the sanctions list entry resolve the alert by itself?
List entries often lack a date of birth, an identification number, or an address that lines up with the customer record, and customer files often store those fields as blanks or placeholders. OFAC's match guidance tells firms to gather documents such as a passport, a driver's license, or a corporate registration before deciding whether the hit is valid.
Does a same-day disposition weaken the sanctions control?
Speed and quality come apart when reviewers skip the comparison or the write-up to meet a target. The FCA described cases where pressure to hit internal deadlines produced incomplete checks and weak documentation. A same-day close holds up when the identifiers, the contradictions, and the reason for the decision are on the record.

.png)