Cutting Screening False Positives: How Banks Reduce Noise Without Increasing Risk
Reviewed by: Tom Devlin, Managing Director at KYC360
Last Updated 04/09/26
For banks handling large customer books, high volumes of false-positive screening alerts can place significant pressure on compliance operations. The challenge is to reduce unnecessary review without weakening the effectiveness of the screening control. Achieving that balance depends on understanding what is driving low-value alerts, calibrating matching logic to risk, improving the quality of screening data and testing changes to ensure genuine matches remain detectable.
The FCA has identified weaknesses at both ends of the calibration spectrum: some screening systems generated high numbers of false positives, while others were not sensitive enough to detect sanctioned individuals. Effective false-positive reduction therefore depends on risk-based calibration, better data and evidence that detection has been preserved.
The Challenge of False Positives in Banking
A false positive occurs when a customer, counterparty or payment resembles a sanctions or watchlist record closely enough to trigger an alert, but further review shows it is not the listed party. Common names, incomplete identifiers, transliteration differences and inconsistent address data can all add noise.
At banking scale, small inefficiencies multiply quickly. Where alerts reach manual review, analysts must compare names and secondary identifiers, document decisions and escalate genuinely ambiguous cases. The FCA's 2023 review found significant backlogs in the assessment, escalation and reporting of screening alerts at some firms. It warned that increased volumes and pressure on sanctions teams could delay action on true positives and increase the risk of errors. This is why screening at scale is as much a question of precision as capacity. Adding reviewers may relieve a queue, but it does not address the data or calibration issues producing low-value alerts in the first place.
The Over-Tuning Trap
Reducing screening sensitivity can lower alert volumes, but poorly judged changes can also weaken detection. The FCA has identified weaknesses at both ends of the calibration spectrum: some screening systems generated high numbers of false positives, while others failed to detect relatively minor name variations. Its testing also found systems unable to generate alerts against certain names on what was then OFSI's Consolidated List, with some firms unable to reasonably justify the omissions.
A lower alert count can therefore conceal a detection gap. The more effective approach is to improve the precision of matching rather than suppress alerts indiscriminately. This is where risk-based configuration becomes important: screening parameters can be adjusted according to the risk presented by a customer or relationship, rather than applying the same matching criteria across an entire customer book. KYC360's 3D risk-based screening supports this approach through configurable parameters based on predetermined customer risk, with metadata such as country and date of birth used to narrow low-value matches while retaining visibility of higher-risk potential hits.
Calibrating Screening to Risk
Calibration should begin with the risks the system needs to detect, not a target alert volume. The FCA's May 2026 review says screening and alert-management processes should be proportionate to risk exposure, appropriately calibrated, and regularly tested and reviewed. Secondary identifiers matter because a name alone may not support a reliable decision. OFSI guidance points to information including date and place of birth, nationality, passport details and addresses when distinguishing a name match from a target match. Used appropriately, these attributes give screening teams more information to resolve clear non-matches while retaining closer scrutiny where uncertainty remains.
Different customers, products and jurisdictions can also present different sanctions risks. A configurable sanctions screening platform allows firms to align matching rules more closely with their risk assessment and provide a documented rationale for how those settings are applied.
Fixing Data Quality Before Matching
Screening accuracy is constrained by the quality of the data entering the system. The FCA's review found gaps in firms' internal customer records, including dates of birth that were missing, incomplete or entered as placeholders. It also identified systems that struggled to detect obfuscated, variant and non-Latin names, while poor underlying reference data made matching more difficult. Improving screening data quality therefore starts upstream. Structured names, reliable dates of birth, consistent country information and usable addresses give matching engines more attributes with which to distinguish a genuine hit from a namesake.
KYC360's data-quality assessment capability applies the same principle before screening takes place. Users can identify potential defects in input data and rectify them before screening. KYC360 also integrates screening datasets from providers including Dow Jones, LSEG World-Check and LexisNexis, giving firms flexibility over the underlying data used for matching.
Testing and Evidencing Tuning Decisions
Tuning is not complete when alert volumes fall. Firms need evidence that the revised configuration still identifies the risks it is meant to detect. Wolfsberg guidance recommends documented, risk-based decisions around screening rules and threshold settings, supported by independent testing and validation. Testing should establish that expected alerts are generated and that threshold or suppression rules behave in line with the firm's risk appetite. The FCA similarly highlights periodic calibration, quality assurance testing and retesting following changes to matching logic as examples of effective practice.
After a material tuning change, firms should test expected matches and relevant variants, document the rationale and results, and retain clear configuration and approval records. Version control provides a useful evidential trail of what changed, when it changed and what supported the decision. The same discipline should apply across ad-hoc and batch screening. Firms should be able to explain how the logic works, why it is configured that way and how they know it remains effective.
What Good Screening Looks Like
Effective screening systems make alerts more meaningful before they reach an analyst. Better data removes avoidable ambiguity, risk-based configuration concentrates sensitivity where it is needed, and disciplined testing provides assurance that efficiency gains have not weakened coverage. That gives analysts more time for cases requiring judgement, while compliance teams gain a clearer evidential trail and management can assess screening performance using more than raw alert volumes.
Conclusion
As screening volumes grow, weaknesses in data, calibration or workflow create operational friction and control risk. Effective false-positive reduction addresses those weaknesses at source rather than simply suppressing alerts. When data quality, risk-based configuration and testing work together, banks can create capacity while preserving human judgement for the cases that need it.
For a broader view of screening strategy, data, controls and implementation, read the Definitive Guide to Customer Screening for Banking. KYC360 applies these principles through risk-based configuration, data-quality assessment, flexible screening data and centralised alert handling. Request a demo to see how the KYC360 AML Screening Platform can support efficient screening at scale.
FAQs
A false positive is a potential match generated because customer, counterparty or payment information resembles a sanctions-list record, but further review establishes that it is not the listed party. OFSI distinguishes between a simple "name match" and a "target match", with secondary information helping determine whether the parties are genuinely the same.
Banks can reduce false positives by improving input-data quality, using relevant secondary identifiers and calibrating matching rules according to risk. Thresholds and filters should be supported by documented rationale and testing so that fewer low-value alerts do not come at the expense of detecting genuine sanctions exposure.
Over-tuning can cause relevant names to fall below alert thresholds, particularly where there are spelling variations, additional name elements, transliterations or non-Latin characters. FCA testing has identified systems that failed to generate expected alerts, demonstrating why lower alert volumes should not be treated as evidence of better screening on their own.
Firms should document configuration changes and their rationale, then test the revised system against expected matches and relevant name variants. Clear records of testing, approvals and configuration changes help demonstrate that efficiency improvements have not weakened the control. The FCA identifies periodic calibration and assurance testing among examples of effective screening practice.
Banks should avoid simply lowering matching thresholds. Risk-based calibration, reliable secondary identifiers, better source data and testing against spelling, transliteration and formatting variations can help reduce low-value alerts. Thresholds, filters and exclusions should be documented and regularly tested so efficiency improvements do not introduce gaps in detection.
The KYC360 platform is an end-to-end solution offering slicker business processes with a streamlined, automated approach to Know Your Customer (KYC) compliance. This enables our customers to outperform commercially through operational efficiency gains whilst delivering improved customer experience and KYC data quality.
Consolidate your system stack and data vendor relationships with one platform to cover all Onboarding, Screening, Perpetual KYC (pKYC) and CLM tasks, with market-leading data sources pre-integrated under a single license agreement. Live risk scoring and automated data collection enables a shift from periodic to event-driven review, while providing a single actionable picture of real-time risk with all documents and data in one place.