Compliance teams talk about screening as if it is one thing. It is not. It is at least four different things, glued together by convention.
Sanctions lists are government-issued. OFAC, UN, EU, HMT, NG — each one is a legally-enforced list of parties you cannot transact with. Coverage here is not optional and cadence is publisher-driven.
PEP lists are risk-based. Politically Exposed Persons are not on any prohibited list. They are individuals who present elevated risk because of their role. Screening them is due diligence, not enforcement. What you do with the hit is a policy question.
Industry lists are ecosystem-specific. Card-scheme files like MATCH and VMSS record merchants who have been terminated or flagged. Coverage requires a partner relationship with the scheme or a data provider.
Internal lists are yours. Every OneAI customer maintains their own merchant and transaction watchlists — with reasons, evidence, and expected end dates.
Good screening means: knowing which lists you screen against, what the refresh cadence is, what happens on a positive hit, and being able to prove it. Everything else is theatre.