Ten questions, answered privately

Screening Readiness Check

Ten questions that commonly decide whether a screening file survives review, scored in your browser so nothing you answer is sent anywhere, with the weakest area named first.

Last updated

Neoclassical facade with a sculpted pediment above a tall stone colonnade

Ten questions

  1. Risk assessment

    1Is your risk assessment written down, dated, and approved by a named person?

    An undated assessment cannot be shown to have preceded the controls it justifies.

    Is your risk assessment written down, dated, and approved by a named person?
  2. Risk assessment

    2Can you name, for any given control, the specific risk it exists to address?

    This is the link that makes a programme risk-based rather than merely thorough.

    Can you name, for any given control, the specific risk it exists to address?
  3. Screening

    3Do you verify identity before screening, rather than the other way round?

    Screening an unverified identity returns a clean result against the wrong person.

    Do you verify identity before screening, rather than the other way round?
  4. Screening

    4Are existing customers re-screened as lists change, not only at onboarding?

    A customer who was clear at onboarding can be listed the following week.

    Are existing customers re-screened as lists change, not only at onboarding?
  5. Screening

    5Does a closed alert record which identifiers were compared, not just the outcome?

    Without that, a careful dismissal is indistinguishable from a careless one.

    Does a closed alert record which identifiers were compared, not just the outcome?
  6. Due diligence

    6Is beneficial ownership resolved to named individuals, not to another company?

    Stopping at a corporate shareholder leaves the chain recorded as complete but unresolved.

    Is beneficial ownership resolved to named individuals, not to another company?
  7. Due diligence

    7For high-risk customers, is source of wealth established separately from source of funds?

    A customer can explain the transfer perfectly and leave the wealth unexplained.

    For high-risk customers, is source of wealth established separately from source of funds?
  8. Due diligence

    8Does the expected-activity profile from due diligence reach your monitoring rules?

    A profile that stays in the file is a document, not a control.

    Does the expected-activity profile from due diligence reach your monitoring rules?
  9. Oversight

    9Has anyone independent sampled real files to check the evidence is actually there?

    Testing that a control exists is not testing that it worked.

    Has anyone independent sampled real files to check the evidence is actually there?
  10. Oversight

    10In the last year, has the process caused you to decline or exit a customer?

    A programme that never declines anyone may not be applying its own risk appetite.

    In the last year, has the process caused you to decline or exit a customer?

What this is

Ten questions. They are not a checklist of obligations, and they are not weighted towards anything we happen to sell. They are the questions that, in our experience of how screening files get reviewed, most often separate a process that can show its work from one that cannot.

Each is answerable in a few seconds by someone who runs the process. If a question needs a meeting to answer, that is itself informative.

How it is scored

Every question scores two for a full yes, one for partly, nothing for no. The questions are grouped into four areas — risk assessment, screening, due diligence and oversight — and the result lists those areas weakest first, each linked to the checklist that covers it.

The overall percentage is the least useful number on the page. A business at 80% with one area at 25% has a clearer problem than a business at 60% spread evenly, and the ordering is what shows that.

Why nothing is sent anywhere

The value of a self-assessment depends entirely on whether people answer it honestly, and honest answers here are a description of where a control is weak. Asking for those in exchange for an email address would guarantee optimistic answers and make the output worthless.

So the tool has no submit step, no result email and no stored state. If you want a record, screenshot it.

What to do with the result

The weakest area names the checklist to read next. Beyond that:

  • Risk assessment weak — start with whether the assessment predates the controls, and whether any control can be traced to a specific risk. See the customer risk assessment checklist.
  • Screening weak — usually a sequencing or a record-keeping problem rather than a tooling one. See the sanctions alert review checklist.
  • Due diligence weak — most often ownership resolved to a company rather than a person, or an expected-activity profile that never reached monitoring. See the enhanced due diligence checklist.
  • Oversight weak — the hardest to fix internally, because it needs someone independent. See the AML/CTF programme checklist.

None of that requires buying anything. If, having read them, the gap turns out to be a tooling one, talk to us — but the checklists are the useful part and they are free.

Questions

Common questions about screening readiness check.

Is anything I enter here sent to MemberCheck?
No. The questions, your answers and the score all stay in your browser — there is no form submission, no analytics event and no stored result. Closing the tab discards it. That is deliberate: honest answers to these questions describe control weaknesses, and nobody should have to hand those to a vendor to get something useful back.
Is this an assessment of whether we are compliant?
No, and it should not be used or cited as one. It reflects ten questions that come up repeatedly in file reviews, which is not the same as your obligations. What your business is required to do depends on your jurisdiction, your sector and your own risk assessment, and only your regulator's guidance and your own advisers can tell you whether you meet it.
Why are the results ordered weakest first?
Because the useful output is not a grade, it is a direction. A programme with one weak area and three strong ones needs attention in one place, and an overall percentage hides exactly that. The ordering is the recommendation.
Why does answering 'no' to the last question count against us?
Because a process that has never caused a business to decline or exit a customer may not be applying its own risk appetite. It is not proof of a problem — a small, low-risk customer base can genuinely produce that answer — but it is worth knowing which of those two situations you are in.