Wallet screening catches addresses that a sanctions authority has published, matched exactly. It misses unlisted addresses controlled by the same person, funds that passed through intermediaries, and anything published after your last check.
A PEP match means you must confirm the person and classify them, not refuse them. Foreign PEPs always need senior management approval, source of wealth and funds, and enhanced monitoring; domestic PEPs need it only when your risk assessment says the relationship is higher risk.
Most sanctions false positives come from thin customer data, not oversensitive matching. Screen with verified date of birth, nationality and ID numbers, record why each match was cleared so it does not return, and leave fuzzy matching alone.
In June 2025 the FATF revised Recommendation 16: standard originator and beneficiary data above USD/EUR 1,000, a defined start to the payment chain and new checks against misdirected payments. Countries are expected to implement by the end of 2030.
The Travel Rule requires the sending VASP to collect originator and beneficiary information, pass it to the receiving VASP immediately and securely, and make it available to authorities. The hard parts are finding the counterparty, handling self-hosted wallets and jurisdictions that disagree.
The FATF's seventh targeted update, published 16 July 2026, finds most jurisdictions now have Travel Rule laws but few enforce them, and asks VASPs to strengthen wallet screening, unhosted-wallet due diligence and scrutiny of offshore platforms.
On 19 June 2026 the FATF added Bosnia and Herzegovina and Iraq to its grey list and removed Algeria and Namibia. A grey listing is a risk factor to weigh, not an instruction to apply enhanced due diligence or to exit a market.
All three laws treat biometric data as a special category. Nigeria names facial images and limits sensitive data to listed grounds, Kenya treats biometric processing as high risk, and POPIA prohibits it unless an authorisation applies. Plan a lawful ground, a DPIA and minimisation.
Device and IP signals describe the handset and connection, not the person. Emulators and datacentre IPs are strong warnings; shared devices, IP velocity and IP location are weak. Use them as corroboration, and trust IP location at country level only.
Rank shared artefacts by what they prove. A repeated verified ID number means the same person. A repeated face is strong evidence for review. A shared device, phone or address is common in families, so treat it as corroboration and count distinct people before acting.
Attackers either hold fake media up to a real camera (a presentation attack) or feed it straight into the data stream (an injection attack). Each needs its own defence, and the strongest checks add evidence a camera cannot supply.
The EU AML Regulation applies directly from 10 July 2027 and replaces national CDD rules with one text. Build to the Regulation now: its data list, verification routes, 25% ownership test and refresh ceilings are fixed, while AMLA's detailed CDD standards were still in draft as of September 2026.