RDCPASSBusiness
AML & CTF Screening · Compliance

Screen customers against sanctions and PEP lists, then keep monitoring them

AML & CTF Screening checks a person or company against international and national sanctions lists, politically exposed persons, adverse media, watchlists and high-risk jurisdictions. Turn on monitoring and we check again every time a covered list changes, so you hear about a new match without re-running anything.

  • Sanctions, PEP and adverse media
  • Ongoing monitoring
  • People and companies
Sandbox example

Screen a person

Subject
Mbuyi Ilunga Nsimba
Lists
Sanctions · PEP · adverse media
  1. Signing request · HMAC-SHA256
  2. Encrypting payload · AES-256-GCM
  3. Screening sanctions and PEP lists
  4. Scanning adverse media

Result

check types in one request
5
check types in one request
monitoring after onboarding
Ongoing
monitoring after onboarding
subject types: people and companies
2
subject types: people and companies
records per batch
10,000
records per batch

Why businesses choose AML & CTF Screening

1

Far fewer false positives

When you screen by RDCPASS ID, we use the certified name, date of birth and nationality. A common name no longer buries your analysts in homonyms.

2

One request instead of five searches

All the checks run together and come back as a single risk level, with the hits that produced it.

3

Review what changed, not the whole portfolio

Monitored customers are re-screened automatically. You only get an alert when something material changes.

How it works

  1. 01

    You choose who to screen

    A customer by RDCPASS ID or identity document, a counterparty by name, or a company by its RCCM, ID NAT or NIF.

  2. 02

    You send the request with its purpose

    Include the checks you want and the reason, such as onboarding or regulatory compliance.

  3. 03

    We run the selected checks

    The subject is matched against the sanctions, PEP, adverse-media, watchlist and high-risk jurisdiction sources you picked.

  4. 04

    You get a risk level and the hits behind it

    Low, medium or high, with an explanation for each hit. If you asked for monitoring, it starts at this point.

Capabilities

What you receive

Each screening returns an auditable result:

  • An overall risk level (low, medium or high) and a risk score
  • Every matched list entry, with its source list, its category and how closely it matches
  • The subject’s PEP status, level and positions held
  • Whether ongoing monitoring is active for the subject
  • Basic KYC and any approved data scopes, when the subject is matched to a certified RDCPASS identity
01

Five checks in one call

Sanctions, politically exposed persons, adverse media, watchlists and high-risk jurisdictions. Run all of them or only the ones you need.

02

International and national lists

The major international sanctions lists and the CENAREF national list, kept in sync with their publishers.

03

PEP detail your analysts can use

Whether a person is a domestic, foreign or international-organisation PEP, which positions they held and when.

04

People and companies

Screen individuals by identity or by name. Screen businesses by their official registry numbers.

05

Ongoing monitoring

You are alerted to a new hit, a change in risk level or a change in PEP status.

06

Portfolio re-screening

Before an audit or after a major list update, re-screen your customer base in batches of up to 10,000 subjects per request.

Integration

One integration for sandbox and production

Requests are HTTPS calls with JSON bodies, signed and encrypted. The sandbox returns the same formats as production, so the code you test with is the code you ship.

  1. 1

    Create an application

    Sign up, create a sandbox application and select the services and data scopes you need.

  2. 2

    Make your first call

    Start from an official SDK or from the samples on the right. Eight languages are covered.

  3. 3

    Go live

    After due diligence, replace the sandbox keys with production keys and add your mTLS certificate. The request code stays the same.

Request modes

Single · sync

One record, answered immediately.

Single · async

One record, result by webhook.

Batch · sync

Up to 50 records per call.

Batch · async

Up to 10,000 records, result by webhook.

mTLSHMAC-SHA256AES-256-GCMAudit log
screen-customer.sh
# Body shown in plaintext — encrypt it per /docs/authentication before sending.
curl https://api.rdcpass.cd/v1/aml/screenings \
  -X POST \
  -H "X-RDCPASS-Key-Id: key_live_8f2a1c0e9b" \
  -H "X-RDCPASS-Timestamp: 1790418900" \
  -H "X-RDCPASS-Nonce: 8d4b2f6e-1a7c-4e93-b05d-6c2e9a1f3b78" \
  -H "X-RDCPASS-IV: Lm3sR9wQ0tYc2VxN" \
  -H "X-RDCPASS-Signature: e82c5a...41f6" \
  -H "Idempotency-Key: c1a7e3f9-4b2d-4a68-9e0c-7d5b3f1a2e84" \
  -H "Content-Type: application/json" \
  -d '{
    "reference": "cust-0001",
    "subject": { "identifier": { "type": "rdcpass_id", "value": "COD-1907-5521-0386" } },
    "checks": ["sanctions", "pep", "adverse_media", "watchlists", "high_risk_jurisdictions"],
    "monitoring": true,
    "purpose": "regulatory_compliance",
    "scopes": ["kyc.addresses", "kyc.professions"]
  }'
200 OK
{
  "id": "aml_3f9b2c7e10",
  "object": "aml_screening",
  "livemode": true,
  "reference": "cust-0001",
  "status": "completed",
  "subject": {
    "type": "individual",
    "identifier": { "type": "rdcpass_id", "value": "COD-1907-5521-0386" }
  },
  "checks": ["sanctions", "pep", "adverse_media", "watchlists", "high_risk_jurisdictions"],
  "risk_level": "medium",
  "risk_score": 48,
  "hits": [
    {
      "list": "PEP database",
      "category": "pep",
      "match_score": 0.97,
      "matched_name": "Mbuyi Ilunga Nsimba",
      "listed_on": "2019-07-15",
      "details_url": "https://api.rdcpass.cd/v1/aml/screenings/aml_3f9b2c7e10/hits/0"
    },
    {
      "list": "Adverse media",
      "category": "adverse_media",
      "match_score": 0.74,
      "matched_name": "M. Ilunga Nsimba",
      "listed_on": "2024-02-09",
      "details_url": "https://api.rdcpass.cd/v1/aml/screenings/aml_3f9b2c7e10/hits/1"
    }
  ],
  "pep": {
    "is_pep": true,
    "level": "domestic",
    "positions": [
      {
        "title": "Provincial Minister of Finance",
        "jurisdiction": "Haut-Katanga",
        "start_date": "2019-07-15",
        "end_date": "2024-05-31"
      }
    ]
  },
  "monitoring": { "enabled": true, "monitor_id": "mon_6a1d9c4e27" },
  "account": {
    "rdcpass_id": "COD-1907-5521-0386",
    "status": "active",
    "certified": true,
    "created_at": "2024-11-02T08:47:19Z",
    "level_of_assurance": "LOA3"
  },
  "kyc": {
    "basic": {
      "full_name": "Mbuyi Ilunga Nsimba",
      "first_name": "Mbuyi",
      "last_name": "Nsimba",
      "date_of_birth": "1979-09-21",
      "age": 47,
      "gender": "female",
      "nationality": "COD"
    },
    "addresses": [
      {
        "province": "Haut-Katanga",
        "city": "Lubumbashi",
        "commune": "Lubumbashi",
        "quartier": "Makutano",
        "avenue": "Avenue Lumumba",
        "number": "112",
        "is_primary": true,
        "verified_at": "2025-01-14T10:03:00Z"
      }
    ],
    "professions": [
      {
        "title": "Consultant",
        "employer": "Nsimba Conseil SARL",
        "sector": "Professional services",
        "since": "2024-07-01"
      }
    ]
  },
  "scopes_applied": ["kyc.basic", "kyc.addresses", "kyc.professions"],
  "scopes_withheld": [],
  "purpose": "regulatory_compliance",
  "created_at": "2026-09-26T10:15:02Z"
}

Trust & privacy

  • Supports the customer due diligence and sanctions checks expected by the Banque Centrale du Congo and CENAREF. What to do about a hit remains your institution’s decision.
  • Every request states its purpose, and every screening and alert is logged for audit.
  • Results are compliance information and are never shown to the person screened.
  • Requests are signed, encrypted end to end and sent over mutually authenticated connections.

Pricing

Billed per screening.

Ongoing monitoring is billed per monitored subject per month. If the subject is matched to an RDCPASS identity, each additional scope that returns data adds a small surcharge. Batch items cost less, and requests rejected with an error are never billed.

Frequently asked questions

Can I screen someone who has no RDCPASS identity?+

Yes. Screen an individual by name, ideally with a date of birth and nationality to cut down false positives. Companies can be screened by RCCM, ID NAT or NIF.

How does ongoing monitoring work?+

We re-screen each monitored subject every time a covered list changes and whenever their identity is updated. You are alerted only when something material changes. Your compliance officer can stop a monitor at any time, for example when the relationship ends.

Does screening replace my own suspicious transaction reports?+

No. It gives your controls an auditable check. Your compliance programme, your decision on each hit and your reporting obligations stay with you.

Can I try it before going live?+

Yes. The sandbox is free and returns the same fields as production, using synthetic test subjects.

Start using AML & CTF Screening

Building and testing in the sandbox is free. You go live once your business and application have passed due diligence.