September 19, 2025

# From Noise to Signal: How to Tune Your Screening Platform Without Failing an Audit

Getting a screening or monitoring platform live is the easy part. The real challenge begins afterward: shaping how the system behaves so it surfaces true risks without overwhelming your team with noise and driving up your staffing costs.

This process — known as **tuning** — is the work of configuring rules, thresholds, and filters so the platform reflects your [regulatory obligations](/content/blog/regulatory-compliance/index.html), risk profile, and operational capacity. In other words, tuning bridges the gap between broad vendor defaults and a defensible, regulator-ready program.

Vendor defaults are deliberately conservative, designed to “catch everything.” That minimizes the chance of missed risks across a wide customer base but rarely fits a specific firm’s exposure. For example, a common name like _John Smith_ might generate dozens of alerts against [global watchlists](/content/glossary/global-watchlist/index.html). Without tuning, analysts could spend hours chasing false positives — but set thresholds too tightly and you risk missing the one _John Smith_ who really is sanctioned.

Regulators don’t care whether you run the platform “out of the box.” They care whether your configuration captures the risks you’re obligated to monitor, has been tested for effectiveness, and is supported by clear documentation.

Tuning is about striking that balance: meeting obligations, keeping workloads sustainable, and maintaining a process you can defend with evidence in front of regulators, partners, or your board. This guide provides a practical playbook for compliance officers tuning a platform for the first time, with advice and guardrails to get it right.

## **Understand Your Regulatory Mandate**

Before you start tuning, you need to be clear about **what you are legally required to screen for**. This is your _regulatory baseline_ — the floor you cannot go below. From there, you can layer on additional screening if your risk profile or business partners demand it.

### **Licensed Jurisdictions**

The rules in the places where you hold a license or registration are non-negotiable. If you are regulated in the U.S., you must comply with the Bank Secrecy Act and screen against OFAC lists. In the UK, the FCA expects compliance with the Money Laundering Regulations. In Singapore, MAS Notices set the standards, including stricter controls around onboarding PEPs. In Australia, AUSTRAC requires suspicious matter reports within strict timeframes — as little as 24 hours for terrorism suspicions.

### **Extraterritorial Rules**

Some obligations follow you across borders. U.S. sanctions apply to any transaction that touches a U.S. bank, even if neither party is American. EU and UK rules can apply if you serve customers through a branch or local establishment.

### **Partner and Counterparty Expectations**

Often your obligations don’t stop with the regulator. Banks and payment partners may impose their own screening standards as a condition of doing business with you. For example, a U.S. partner bank might require OFAC screening on _all_ customers, even those outside the U.S. A global PSP might require adverse media checks, even if not strictly mandated by law.

### **Risk-Based Additions**

Finally, regulators expect you to go beyond the minimum where your business risk calls for it. That could mean lowering beneficial ownership thresholds for certain entities, screening PEPs’ family members and close associates, or including reputational adverse media categories. What matters is not that you “do everything everywhere,” but that you can explain _why_ your settings make sense for your risk profile.

## **Set Clear Objectives for Tuning**

Tuning only makes sense if you know what you’re trying to achieve. The goal isn’t simply to lower alert volumes; it’s to configure the platform so it meets regulatory obligations, produces alerts that matter, and operates in a way your team — and regulators — can defend. Every adjustment should map back to one of four objectives.

### **Regulatory Compliance**

This is the non-negotiable floor. Every sanctions, PEP, and adverse media alert must be dispositioned, and suspicious activity reporting timelines must be met — whether that’s 24 hours for terrorism suspicions in Australia or 30 days under FinCEN. Regulators won’t accept “we tuned it out” if a true positive slips through.

**Some metrics you might aim for:**

- 100% of sanctions alerts dispositioned within SLA.
- 0% missed true positives.
- Precision (true positive rate) trending upward over time.
- 100% of alert decisions documented with rationale.

### **Operational Effectiveness**

A system that generates endless alerts may look thorough, but it wastes resources and slows investigations. Tuning should make the workload sustainable while keeping quality high.

**Some metrics you might aim for:**

- Hit rate, which is the % of total entities with hits, between 0.2 – 0.6% of total screened entities.
- False positive rate, which is the % of alerts that were not real matches, reduced from 95–99% to 50–70%.
- Median case resolution time under 2.5 minutes.
- Alert backlog cleared within 2 business days.

### **Managing Customer Friction**

Compliance isn’t about creating a “frictionless” onboarding process, but poorly tuned systems can block legitimate customers or create unnecessary delays. The objective is to minimize that collateral impact without compromising obligations.

**Some metrics you might aim for:**

- Onboarding abandonment due to screening below 0.5%.
- Escalations of legitimate customers reduced quarter over quarter.
- Low-risk false positives cleared within 24–48 hours.

### **Strategic Alignment**

Tuning should evolve as your business and risk landscape change. Entering new markets, adding new products, or onboarding new customer types all require recalibration.

**Some metrics you might aim for:**

- 100% of high-risk customers enrolled in enhanced due diligence workflows.
- Formal tuning review conducted at least quarterly.
- Adjustments implemented within 60 days of a new market or product launch.
- Immediate adjustments following material regulatory changes or new sanctions regimes.

## **Learn the Levers of Tuning**

Every screening system gives you a set of levers to adjust. Each one shapes the balance between detecting real risks and drowning in noise. Understanding how they work — and the trade-offs they introduce — is the foundation of responsible tuning.

### **Match Thresholds**

The foundation of watchlist screening is comparing a customer’s name against sanctions, PEP, or adverse media lists. The system produces a similarity score, and the threshold you set determines whether that score becomes an alert. Lower thresholds capture more potential matches but also generate more false positives. Higher thresholds reduce noise but risk missing true matches — a serious regulatory concern, especially for sanctions. The safest approach is to keep thresholds broad for sanctions lists, where regulators expect zero tolerance for missed matches, and more risk-based for PEP or adverse media lists, where proportionality is acceptable.

Legacy systems typically use simple string or phonetic algorithms like Jaro-Winkler or Soundex, which work for minor variations but struggle with transliterations or cultural differences.

Socure improves on this with a **machine learning–powered Name Match Score** that recognizes spelling differences, different alphabets, and varied name orders. On top of that, Socure introduces an **Entity Correlation Score (ECS)** that evaluates multiple attributes — like name, date of birth, and nationality — together. ECS makes it easier to prioritize alerts that have strong multi-attribute alignment, while deprioritizing noise without missing true risks

### **Secondary Identifiers**

Adding more context drastically improves match quality. A common name on its own can generate dozens of potential matches, but with date of birth, nationality, or government ID included, the results narrow quickly. Date of birth in particular is powerful. Some systems let you set tolerances such as:

- Exact match: DOB must match exactly across both the input and the watchlist record.
- ±1 year tolerance: Allows for minor errors or typos in birth year.
- Digit transposition: Accounts for common mistakes like “1986” vs. “1968.”
- Partial date handling: Some systems allow matches even when only year or month/year are present.

For sanctions lists, strict DOB matching is usually expected, while PEP and adverse media screening often requires more flexibility because the data is less complete.

The more identifiers you provide, the more alerts your team can resolve at first glance. Regulators will also expect you to monitor data completeness — for example, knowing what percentage of your records include DOBs or addresses — and document how identifier use improves accuracy.

Socure makes all of these settings accessible in a single dashboard. Compliance teams can toggle between strict and flexible DOB radiuses, switch between ALL and ANY logic, and apply filters on identifiers without needing custom code or vendor intervention. These options give teams a straightforward way to fine-tune strictness based on list type (e.g., sanctions vs. PEPs) and data quality, while maintaining full transparency for audits.

### **Adverse Media Filters**

Adverse media is a powerful risk indicator but can easily overwhelm if left unfiltered. Most systems allow you to tune by **category** (fraud, corruption, terrorism), **recency** (e.g., limit to the last 3–5 years), and **source type** (credible outlets vs. blogs). This narrows alerts to material AML risks and keeps analysts focused.

Socure goes further by using **natural language processing (NLP)** and machine learning to understand the context of articles. Instead of treating every keyword mention as an alert, Socure distinguishes between someone accused of misconduct and someone simply mentioned in an article, which helps compliance teams avoid irrelevant review

### **Alert Prioritization**

Not every match deserves the same level of attention. Prioritization rules make sure the right ones are handled first. A wire transfer from a high-risk jurisdiction, for instance, should surface ahead of a routine domestic payroll payment, even if both names score similarly.

Sanctions alerts should always be reviewed within 24 hours, reflecting strict liability expectations. PEP and adverse media alerts can follow structured timelines based on risk, such as 48–72 hours for PEPs and up to five business days for low-confidence adverse media.

For compliance officers, the key is defensibility: risk scoring logic should be documented, reviewed regularly, and approved through governance. Regulators will expect to see evidence that scoring reflects your risk assessment and that changes are tested for effectiveness, not just made to reduce volumes.

Strong governance around prioritization means documenting your SLA targets, monitoring adherence, and being prepared to show regulators why your timelines make sense for your risk profile.

**Governance and Testing**

Whichever lever you pull, regulators will want evidence. Industry best practice is to maintain logs of your thresholds, run backtesting and sensitivity analysis, and review your settings regularly. Many legacy systems leave testing largely manual, requiring CSV exports and offline analysis.

Socure bakes governance into the platform: every decision, adjustment, and match is logged; correlation scores provide transparency for investigators; and built-in reporting creates an audit trail regulators can understand without translation.

## **Step-by-Step Tuning Workflow**

Tuning is not just about adjusting settings. Regulators will also expect you to demonstrate not only what you configured but also why you did it, how you validated it, and how you recorded the decision. A repeatable workflow turns tuning from a reactive task into an ongoing program of continuous improvement.

### **1. Establish a Regulatory Baseline**

The starting point is to establish a regulatory baseline. That means enabling the watchlists and filters required in the jurisdictions where you’re licensed — OFAC in the U.S., HMT in the UK, MAS lists in Singapore, and so on. This ensures your configuration meets the non-negotiable legal floor. From there, you can extend coverage where it makes sense, such as broader global sanctions, additional PEP categories, or adverse media when required by partners or your own risk appetite.

### **2. Run Backtesting and Analysis**

With the baseline in place, the next step is backtesting. This means running historical or sample data to measure how often matches occur, what percentage of them are false positives, and whether alerts can realistically be cleared within regulatory timeframes. The goal is to validate that your settings are both effective and practical.

Backtesting usually includes several types of tests. **Name degradation tests** deliberately introduce variations such as misspellings, transliterations, nicknames, or swapped name orders to confirm that the system still surfaces the correct matches. **Sensitivity tests** adjust thresholds up or down in a controlled way to measure how changes affect hit rate, false positive rate, and precision. Together, these reveal the trade-offs between broad coverage and operational noise.

Many compliance teams also compare performance against a previous system or legacy configuration. This helps demonstrate whether the new settings improve recall (the ability to capture true matches) without overwhelming investigators with unnecessary alerts. Regulators will expect to see this type of structured testing and evidence in change logs, rather than changes made blindly.

### **3. Adjust Thresholds and Filters**

Armed with those insights, you can start adjusting thresholds and filters. Keep sanctions screening broad, since missing a true sanctions hit is unacceptable, and take a more risk-based approach for PEPs and adverse media. Tune DOB tolerances, logic operators, and list filters to reduce irrelevant alerts. Every adjustment should be recorded with its rationale, the data used to justify it, and who signed off.

### **4. Pilot Changes in Production**

Before rolling out widely, run a pilot. Apply your updated configuration to a limited population while keeping your baseline live in parallel. This lets you compare results side by side — are analysts spending less time on noise, are meaningful alerts still coming through, and is onboarding unaffected? Pilots create a safe proving ground before scaling changes across the board.

### **5. Gather Analyst Feedback**

Feedback from analysts should then shape further refinement. Investigators are closest to the alerts and can quickly flag which ones waste time or which true positives slipped through. Building their observations into your evidence base not only improves outcomes but also shows regulators you have a feedback loop in place.

### **6. Document and Approve Changes**

Every change must be documented and approved through governance. Regulators will ask why thresholds are set at a certain level, and your answer should come from a change log backed by test results and approval records. Governance means aligning with written policies, maintaining clear audit trails, and ensuring senior compliance leaders sign off. Socure automatically maintains audit reports of all your policy changes for easy audit-readiness.

### **7. Review and Refresh Regularly**

Finally, tuning must be reviewed and refreshed on a regular schedule. Quarterly reviews are a common minimum, but you should also trigger reviews after major regulatory changes, new sanctions regimes, or significant business shifts like launching in a new market. Continuous validation — through backtesting, sandbox testing, and internal audit — is what keeps your system effective and defensible over time.

### **In summary**

A defensible workflow follows a loop — baseline, test, adjust, pilot, gather feedback, document, and review. Followed consistently, it ensures your platform reflects your regulatory perimeter, keeps workloads sustainable, and leaves you with the evidence to show regulators and partners that your program is under control.

## **Best Practices and Common Pitfalls**

Tuning is as much about **governance and discipline** as it is about technical settings. The following principles will help first-time compliance officers avoid costly mistakes and build a program that regulators trust.

### **Best Practices**

1. **Anchor to Your Regulatory Perimeter** Always start with what’s legally required in the jurisdictions where you’re licensed. Then consider risk-based additions (global sanctions coverage, inactive PEP exclusions, media filters) if they align with your risk appetite or partner expectations.
2. **Take a Risk-Based Approach** Not all customers, geographies, or products carry equal risk. Segment where possible: low-risk flows (like payroll) don’t need the same treatment as high-risk flows (like cross-border payments).
3. **Tune Iteratively, Not All at Once** Make one change at a time, test, and measure impact before moving on. This makes it easier to defend decisions and to isolate what actually worked.
4. **Involve the Front Line** Analysts know where noise comes from. Build a feedback loop so their observations directly shape tuning decisions.
5. **Document Everything** Every regulator will ask _“Why did you set this threshold here?”_ Keep change logs, performance metrics, and approval records. Even “failed” experiments show that you tested responsibly.
6. **Keep it Continuous** Tuning is not a one-time project. Schedule quarterly reviews, and refresh settings whenever regulatory lists change, you enter new markets, or partner expectations evolve.

### **Common Pitfalls**

1. **Relying on Vendor Defaults** Default settings are designed to be broad and conservative. They rarely align with your specific regulatory perimeter or risk profile.
2. **Over-Tuning for Efficiency** Cutting false positives feels good until you miss a true sanctions match. Regulators will judge you on what you _missed_, not how efficient you were.
3. **Ignoring Governance** Even strong configurations fail if you can’t show the process behind them. Regulators expect to see policies, approvals, and logs.
4. **One-Size-Fits-All Thresholds** Treating sanctions, PEPs, and adverse media the same is a recipe for noise or blind spots. Sanctions demand maximum recall; PEPs and media can tolerate more nuance.
5. **No Clear SLA Prioritization** If everything lands in the same queue, critical sanctions hits can get buried under lower-risk media alerts. Prioritization is non-negotiable.

**Putting It All Together** A well-tuned platform is balanced, risk-based, and defensible. The best compliance officers combine careful configuration with strong governance — and avoid the shortcuts that regulators see as red flags. By embedding best practices and steering clear of common pitfalls, your tuning process becomes not just a technical exercise, but a cornerstone of your AML program.

## **What to Look for in a Good Vendor**

Tuning a watchlist platform isn’t just about lowering false positives — it’s about proving to regulators that your program is effective, efficient, and defensible. That means choosing a vendor that gives your compliance team control, transparency, and confidence.

With **Socure**, you can screen across more than 1,400 global sanctions and enforcement lists, 2.4 million PEP profiles, and 100,000+ adverse media sources. These lists are refreshed continuously — sanctions in near real time, PEPs and media daily — so you’re never caught relying on stale data.

Just as importantly, you can adjust thresholds, tolerances, and filters – all without waiting on engineering. Test changes safely in a sandbox with sensitivity and name degradation tests before moving them to production. Every adjustment is logged automatically, creating a clear audit trail you can hand directly to regulators.

Socure’s dual scoring — a machine learning Name Match Score paired with an Entity Correlation Score — reduces false positives by up to 70% while maintaining maximum recall for sanctions. That means your analysts spend less time clearing noise and more time on true risks, with metrics like hit rate and precision to validate performance.

Finally, all of this is wrapped in strong governance and auditability. From case management dashboards to comprehensive screening reports, Socure ensures you get the audit trail and defensible governance regulators expect – built-in not only what your system flagged, but why you tuned it the way you did.
