AML screening software is the system a regulated business uses to check the people and organisations it deals with against sanctions lists, politically exposed person (PEP) records and adverse media — and, where digital assets are involved, against blockchain wallet risk data. It turns a legal obligation into a repeatable, evidenced process: every customer is screened before onboarding and re-screened over time, and each check leaves a record that can be shown to an auditor or a supervisor.
For a crypto exchange, an electronic-money institution or a payment firm, this is not an optional feature. Anti-money-laundering rules in both the United Kingdom and the European Union require regulated firms to identify sanctioned parties, understand who they are onboarding and monitor that relationship for the life of the account. Screening software is how that requirement is met at scale and consistently, rather than by manual list-checking that cannot keep pace with onboarding volumes or with lists that change daily.
This article explains what AML screening software is, what it screens against, what distinguishes a serious platform, where it fits and how to evaluate one.
What AML Screening Software Does
At its core, AML screening software compares an identity — a person or a company — against structured watchlists and risk data, then returns a result a compliance function can act on. A match is not a verdict; it is a signal that a defined process, and often a person, must review. Capable software makes that signal precise, so the compliance team spends its time on genuine risk rather than on noise.
Screening is distinct from transaction monitoring, and the two are often confused. Screening asks who a party is: are they sanctioned, are they politically exposed, is there credible negative news about them and, for a crypto wallet, is the address linked to illicit activity. Transaction monitoring asks what a party does over time. A mature programme needs both, and a firm should be clear about which capability it is buying.
What It Screens Against
A screening platform is only as strong as the data behind it and the logic that matches against it. Four categories matter most: sanctions lists, PEP data, adverse media and, for digital-asset businesses, blockchain wallet risk.
Sanctions screening checks a party against consolidated sanctions and watchlists maintained by public bodies; sources such as OFAC and the OpenSanctions dataset feed this layer. PEP screening identifies individuals who hold, or are close to, prominent public positions and therefore warrant closer scrutiny. Adverse media screening surfaces credible negative news that may indicate financial-crime risk. For crypto exchanges, wallet risk screening assesses whether a blockchain address is associated with sanctioned entities, known theft or other illicit sources across several blockchains.
Core Capabilities
The capabilities below separate a platform that can support a regulated operation from a simple list-lookup. Grumpio provides them through Legichain, its AML and KYC product, with every result available through both an API and a web panel and drawn from a single credit pool; pricing and product detail are published on the Legichain site.
| Capability | What it provides |
|---|---|
| Person and company screening | Screens both individuals and organisations against the same risk sources from one workflow. |
| Sanctions and PEP screening | Matches parties against consolidated sanctions and politically-exposed-person data. |
| Adverse media screening | Surfaces credible negative news linked to financial-crime risk. |
| Blockchain wallet risk screening | Assesses whether a wallet address across several blockchains is tied to illicit sources. |
| Risk scoring | Expresses each result as a score so clear cases pass quickly and only real risk is escalated. |
| Evidence reporting | Produces a PDF record of each check for audit and regulatory files. |
| Ongoing screening | Re-screens existing customers periodically as lists change, not only at onboarding. |
Where AML Screening Fits
AML screening operates at two moments: at onboarding, before a customer is allowed to transact, and continuously afterwards, because a party who was clear yesterday can appear on a list tomorrow. A crypto exchange screens new users and their wallet addresses; an electronic-money institution or payment firm screens account holders and the businesses it serves. Screening usually sits alongside identity verification (KYC), which confirms a customer is who they claim to be. In every case the result feeds a decision the regulated firm — not the software vendor — owns and records.
The regulatory backdrop makes this non-negotiable. In the United Kingdom, firms handling cryptoassets must register under the money-laundering rules and operate customer due diligence, sanctions screening and monitoring; that registration is a financial-crime control and does not by itself amount to full authorisation to operate. In the European Union, anti-money-laundering supervision is consolidating under a single European authority that is now operational, with a single rulebook taking effect across the bloc in 2027. New crypto and payment projects should be built for these expectations from the outset, an exercise in regulatory readiness rather than a later retrofit.
Deployment and Data Residency
Screening can be consumed as a hosted API or deployed so that data stays inside the firm's own environment. For many businesses a hosted service is sufficient. For firms with stricter data-residency or control requirements, on-premises or dedicated storage keeps screening data within a controlled boundary — the same architectural choice that recurs across regulated fintech platforms. The right model depends on the firm's obligations, its risk appetite and where its supervisors expect data to sit, not on a default preference.
Scope and Boundaries
AML screening software has clear limits, and understanding them prevents both over-reliance and mis-buying. Screening a company against AML sources is not the same as full know-your-business (KYB) verification; a screening result is a risk signal, not an onboarding decision; and no dataset covers every jurisdiction or every source without gaps. A clean result still leaves the regulated firm responsible for the judgement it makes on it. We do not provide legal opinions or guarantee authorisation. We implement regulatory and audit requirements across technology, infrastructure and operations.
Note: Screening supports a compliance decision; it does not make it. The regulated firm remains accountable for onboarding and monitoring outcomes, and for the periodic review of parties that were previously cleared.
Summary and Next Steps
AML screening software checks the parties a regulated business deals with against sanctions, PEP, adverse-media and — for digital assets — wallet-risk data, at onboarding and on an ongoing basis, and evidences every check. It is a control the United Kingdom and European Union frameworks require, not an optional add-on, and it works best when it is precise enough to focus reviewers on real risk and deployable in the model a firm's obligations demand.
Choosing well means looking past the feature list to data quality, the clarity of results, the evidence trail and the deployment model — and staying clear about the boundary between screening and the decisions that remain the firm's own.
Building or reviewing an AML screening capability? Grumpio designs and implements screening that fits a regulated crypto, e-money or payments operation.