Research Β· Vendor transparency benchmark
The State of Sanctions Data Transparency β 2026
We surveyed 8 sanctions-screening vendors on 6 public-disclosure dimensions. None publish per-source redistribution license terms.
Originally published 2026-07-01 Β· Re-verified 2026-08-24
Author: marketing agent. Original draft finalized for Sprint 1, 2026-07-01. This publish-ready version re-verifies every named-vendor claim against live vendor sites as of 2026-08-24 β see the verification log in Β§3a β because the original 2026-04-24 survey had gone stale on several cells. Grounding: /marketing/research/emerging-commercial/{landscape,positioning-summary}.md, /marketing/research/opensanctions/, /marketing/research/moov-watchman/overview.md, plus this pass's live re-check of complyadvantage.com, gominerva.com, didit.me, sanctions.io, sumsub.com, shuftipro.com, hawk.ai, flagright.com, opensanctions.org, and github.com/moov-io/watchman.
Method and scope: a public-disclosure benchmark, not a product review. We rate vendors only on what they publish on their own public surfaces (homepage, docs, data/sources pages, pricing pages) as of the dates noted β not on what they may internally support or disclose under NDA/sales call. Each scorecard cell reflects a dated survey; vendor sites change, so every comparative claim below carries the specific URL and check date it was verified against, and this page is re-verified at least annually (Β§6).
This is a research document presented as a public report. "What we found" and "what this means" are kept separate. Our own product appears once, at the end, framed as the benchmark we are trying to set β not as a winner we are declaring β and carries no scorecard row of its own yet (see Β§5).
1. The headline finding
Across the emerging commercial sanctions-screening tier, no vendor publishes per-source redistribution license terms β and only a minority name specific issuing authorities at all.
We surveyed the vendors a mid-market regulated fintech actually shortlists and checked six public-disclosure dimensions (Β§2). The sharpest, most consistent finding, re-confirmed live on 2026-08-24: 0 of the 8 vendors we surveyed publish per-source license or redistribution terms for the sanctions, PEP, or watchlist data they screen against. Not one names, for any individual source, what license it redistributes that source under, or whether it has the right to.
Source naming is a more mixed picture than our original April survey found, and we're correcting that here rather than repeating a claim that no longer holds: 3 of the 8 (Sumsub, Shufti Pro, and sanctions.io) now name specific issuing authorities β OFAC, the UN Security Council, the EU Consolidated List, UK HMT/OFSI, Australia's DFAT, Switzerland's SECO, and others β in their public marketing copy, up from essentially one (sanctions.io) in our original pass. None of the three, however, pairs that naming with a per-source license, a per-source update cadence, a version history, or match-to-version lineage β the four dimensions (D2βD5) that turn a marketing mention into an audit-grade catalog. The other 5 of 8 (ComplyAdvantage, Minerva, Didit, Hawk, Flagright) still name no specific authority at all, describing their coverage only in aggregate counts β "1,000+ government data sources," "10,000+ AML datasets," "hundreds of thousands of global sources" β that don't resolve to an enumerated, checkable list.
The transparency leaders remain the open-data and open-source projects, not the commercial vendors: OpenSanctions, which publishes a full public dataset catalog with per-source cadence and a blanket redistribution license (confirmed live, 2026-08-24: opensanctions.org/datasets), and Moov Watchman, whose ingesters are Apache-2.0 and readable source-by-source (confirmed live: github.com/moov-io/watchman).
Licensing opacity is the single most consistent pattern in the commercial category β the one dimension where the survey found zero exceptions on re-verification. That is the finding this report leads with, and it is the gap our product is built to close.
2. What we measured
Six disclosure dimensions, each a yes/no/partial a buyer or examiner can check without a sales call:
| # | Dimension | The buyer question it answers |
|---|---|---|
| D1 | Names sources publicly | "Can I see the actual issuing authorities you screen against, by name?" |
| D2 | Publishes per-source license / redistribution terms | "Under what license do you redistribute each list to me β and have you got the right to?" |
| D3 | Publishes update cadence per source | "How current is each list, and how often do you re-pull it?" |
| D4 | Versions lists / publishes change history | "Can you show me what the list state was on a specific past date?" |
| D5 | Match traceable to source authority + list version | "When you flag someone, can I trace it back to the originating authority and the exact version?" |
| D6 | Open / inspectable ingestion or matching code | "Can I read how you ingest and match, or must I trust the black box?" |
Scoring: β = published / yes; β = partial or implied; β = not found on public surfaces; β = not applicable to that vendor's model.
3. The scorecard
All cells below reflect live re-verification on 2026-08-24 (URLs and specifics in Β§3a). Absence of public disclosure is not proof a capability is absent internally; it is the disclosure that we score.
| Vendor | Category | D1 Names sources | D2 Per-source license | D3 Cadence | D4 Versioning / history | D5 Matchβsource lineage | D6 Open code | Notes |
|---|---|---|---|---|---|---|---|---|
| OpenSanctions | Open data | β | β | β | β | β | β | Transparency leader. Full public dataset catalog (opensanctions.org/datasets) with per-source cadence and entity counts; blanket CC BY-NC 4.0 license confirmed live; FtM schema and yente matcher open. Dataset-level versioning published; per-record point-in-time history is partial. Per-source upstream URL/license is not inline on the catalog index itself β it requires opening each dataset's own sub-page (unconfirmed at that depth this pass). |
| Moov Watchman | OSS tool | β | β | β | β | β | β | Apache-2.0 Go ingesters, readable per source (7 first-party), confirmed live at github.com/moov-io/watchman β data is fetched live from each source (OFAC, EU, UN, UK OFSI, US CSL/FinCEN) at query time, not redistributed, so "license of code is clear; license of data is whatever the issuer publishes" holds exactly. No versioned list history; no case/audit layer β confirmed unchanged. |
| sanctions.io | AML-screening-first | β | β | β | β | β | β | Upgraded since our April survey. sanctions.io/data/sanctions-lists/ now explicitly enumerates named authorities by region (OFAC SDN, EU Consolidated List, UN Security Council Consolidated List, and others) β real naming, not just an aggregate count, though still short of a full catalog with per-source license/cadence/version. Cadence is a blanket "Updated Every 60 Minutes" claim (not per-source), which is why D3 stays β rather than β. "75+ Sanctions Lists" confirmed live verbatim. Pricing/license-terms page returned a 404 this pass β unverifiable, not scored as a negative. Verified 2026-08-24. |
| Sumsub | KYC+AML bundle | β | β | β | β | β | β | Upgraded since our April survey. sumsub.com/aml-screening/ now names OFAC, UN, HMT, EU, and DFAT specifically, alongside an aggregate "50,000+ sources across 240+ countries" claim β no per-source cadence, license, or version claim accompanies the naming. Pricing has moved: the page now shows $1.35/verification on the Compliance-tier plan, not the $1.85 in our original survey β corrected here. Verified 2026-08-24. |
| Shufti Pro | KYC+AML bundle | β | β | β | β | β | β | Upgraded since our April survey, on two dimensions. shuftipro.com/aml-screening/ now names OFAC, UK HMT/OFSI, EU CFSP, the UN Consolidated List, Australia's DFAT, Switzerland's SECO, Japan's MoF, and an Israeli crypto-wallet list β one of the more specific naming disclosures in the survey. It also now claims a blanket "15-minute refresh" cadence (not per-source, hence β not β). On-prem deployment option confirmed live. The "100% in-house identity stack" phrase from our original survey was not found verbatim on the current page β dropped rather than re-asserted. Verified 2026-08-24. |
| ComplyAdvantage | AML-screening-first | β | β | β | β | β | β | Confirmed unchanged, 2026-08-24: complyadvantage.com and /pricing/ name no specific authority, no per-source license, cadence, versioning, or code. "$99/mo Starter" pricing confirmed live verbatim ("From $99 per month"). Real proprietary data (Golden acquisition, 2024) is a separate, unrelated fact from public disclosure. |
| Minerva | AML-screening-first | β | β | β | β | β | β | Confirmed unchanged, 2026-08-24: gominerva.com names only generic categories ("Sanctions lists, Adverse Media, Legal and business registry"), no authorities. "Hundreds of thousands of global sources" is confirmed live but appears inside a customer testimonial quote on the page, not vendor-authored copy β noted here so we don't misattribute it. "147 languages," cited from an unverified CEO interview in our original survey, was not found anywhere on the current site β dropped from this report rather than re-asserted unsourced. |
| Didit | KYC+AML bundle | β | β | β | β | β | β | Two stats corrected, 2026-08-24. didit.me no longer shows "1,300+ watchlists" (our original figure) β current copy reads "10,000+ AML datasets" and "1,000+ government data sources," both aggregate counts, not enumerations. "$0.20/screen" is reworded here to match the site's actual phrasing, "AML Screening $0.20" as a per-module line-item price, not an explicit "per screen" claim. "Daily re-screening" was not found on the current page and is dropped rather than re-asserted. No specific authority named anywhere on the page. |
| Sumsub / Hawk / Flagright note on D5 | β | β | β | β | β | β (Hawk, Flagright only) | β | Hawk (hawk.ai) and Flagright (flagright.com) both confirmed unchanged 2026-08-24: no source naming, no license, cadence, or versioning; their explainability marketing ("fully explainable" / case-narrative decisioning) is alert- and decision-level, not source-or-version lineage, which is why D5 stays β rather than β. Flagright's "AI Forensics" / "2-week integration" framing from our original survey was not found verbatim on the current site β current copy instead cites "20 minutes" to configure an agent and a case study referencing a "7-day integration" β both dropped/reworded here rather than re-asserted as originally phrased. |
Legacy enterprise tier (Dow Jones, LSEG World-Check, LexisNexis Bridger, NICE Actimize) remains out of scope for this scorecard β different buyer, six-figure floors β and was not re-verified this pass; it sells on proprietary data-scale claims (e.g., LexisNexis "180 global sanctions lists, 1,700 enforcement lists"), which are scale claims, not per-source public catalogs either. Flagged as a candidate for a future edition, not asserted here.
3a. What changed since the original April 2026 survey β verification log
| Vendor | What changed | Evidence |
|---|---|---|
| sanctions.io | D1 upgraded β/β β β (stronger): now names OFAC, EU, UN by name | sanctions.io/data/sanctions-lists/, checked 2026-08-24 |
| Sumsub | D1 upgraded β β β: now names OFAC, UN, HMT, EU, DFAT. Pricing corrected $1.85 β $1.35/verification | sumsub.com/aml-screening/, checked 2026-08-24 |
| Shufti Pro | D1 upgraded β β β: names 8 specific authorities. D3 upgraded β β β: claims 15-minute refresh. "100% in-house identity stack" phrase dropped (not found) | shuftipro.com/aml-screening/, checked 2026-08-24 |
| Didit | "1,300+ watchlists" replaced with current site language ("10,000+ AML datasets" / "1,000+ government data sources"); "$0.20/screen" reworded to "AML Screening $0.20" (module pricing, not per-screen); "daily re-screening" dropped (not found) | didit.me, checked 2026-08-24 |
| Minerva | "147 languages" dropped (not found on current site, was sourced from an unverified interview); "hundreds of thousands of global sources" re-attributed as a customer-testimonial quote, not vendor copy | gominerva.com, checked 2026-08-24 |
| Flagright | "AI Forensics" / "2-week integration" dropped/reworded β not found verbatim; current copy cites different figures ("20 minutes," a "7-day integration" case study) | flagright.com, checked 2026-08-24 |
| ComplyAdvantage | No change β all cells and the $99/mo Starter price confirmed live verbatim | complyadvantage.com, /pricing/, checked 2026-08-24 |
| Hawk | No change confirmed | hawk.ai, checked 2026-08-24 |
| OpenSanctions | No change confirmed; full catalog + CC BY-NC 4.0 license live | opensanctions.org/datasets/, checked 2026-08-24 |
| Moov Watchman | No change confirmed | github.com/moov-io/watchman, checked 2026-08-24 |
Unverifiable, flagged rather than guessed: WebFetch-based verification only sees static/server-rendered page content; any JS-gated docs or data pages behind that layer were not checked, and sanctions.io's pricing/license-terms page returned a 404 at check time. None of these gaps were treated as a "confirmed β" β where we couldn't see a page, we said so rather than scoring it as a negative finding.
4. What we found β patterns
- License disclosure is universal opacity, with zero exceptions found on re-verification. All 8 commercial vendors surveyed score β on D2 (per-source license/redistribution terms), unchanged from the original survey and independently re-confirmed live on 2026-08-24. This is now the report's most defensible finding β a clean 0/8 with no partial credit anywhere.
- Source-naming has moved, and we're correcting our own count rather than repeating a stale one. In April, only sanctions.io showed any source-naming. As of August, 3 of 8 (sanctions.io, Sumsub, Shufti Pro) name specific issuing authorities in marketing copy. That's real movement in the category β worth stating plainly rather than eliding to preserve a cleaner "0 of 8" headline that no longer holds.
- Naming a source is not the same as cataloging it. None of the 3 vendors that now name authorities pairs that with a per-source license, per-source cadence, a version history, or match-to-version lineage. Naming OFAC in marketing copy answers "do you screen against OFAC" β it does not answer "under what license," "how often," or "as of which list version." That gap is exactly what D2βD5 measure and exactly where all 8 vendors still score β or β at best.
- Counts still substitute for catalogs among the other 5. ComplyAdvantage, Minerva, Didit, Hawk, and Flagright describe coverage only in aggregate β "1,000+ government data sources," "10,000+ AML datasets," "hundreds of thousands of global sources" β units that aren't comparable to each other (sub-list vs. feed vs. undefined "dataset") and none resolve to an auditable enumeration.
- "Explainability" in the FRAML tier is about alerts, not provenance. Hawk and Flagright market explainable/auditable AI, but on re-verification this is still alert- or case-level explainability ("why did this alert resolve," "why did false positives drop 93%") β not "which signed list version produced this hit." Scored as partial on D5, not full, unchanged from the original survey.
- Marketing-copy claims move faster than the underlying disclosure architecture. Every stat we had to correct this pass (Didit's list count, Minerva's language-count, Flagright's integration-time framing, Sumsub's price) was a marketing-copy number, not a structural disclosure like a license or a versioned catalog β reinforcing that D2/D4/D6 (the harder, structural dimensions) are the more durable things to benchmark year over year, not headline stats that reword themselves every quarter.
- The transparency frontier is still owned by open projects. OpenSanctions sets the public bar on D1βD3 and D5βD6; Watchman sets it on D6. No commercial vendor matches them on source disclosure, and none closed that gap since April.
5. What this means for us
Opinion section, kept separate from the findings above.
- Transparency is a genuine open quadrant β real, but narrower than our first draft claimed. The core finding survives re-verification and is, if anything, sharper on licensing (D2) than we first scored it. But the source-naming trend (finding 2 above) means we should stop saying "no vendor names its sources" in any external copy going forward β three now do, in marketing language if not in a full catalog. Overclaiming a stale absolute would be the kind of error this report exists to call out in others.
- The license column is the sharpest, most defensible edge β now doubly so. D2 is the one dimension with zero exceptions across all 8 vendors on both the April and August surveys. Lead the narrative here, not on source-naming (which is now a mixed 3-of-8 picture) and not on raw source counts (we'd lose a count race against legacy moats). When we describe our own catalog β "we enumerate every source under a per-source license" β quantify it only against our own shipped
data-catalog-page.md/build-report figures; never an invented number. - Position against the open leaders carefully, not competitively. OpenSanctions and Watchman remain the transparency leaders on live re-verification; we stand on OpenSanctions' shoulders and credit it as such. The report names them as the leaders we benchmark ourselves with, and locates our addition precisely: audit-grade lineage (signed list versions, tamper-evident logs, matchβversion lineage as a response field) that neither open project ships today.
- Do not overclaim our own row. We have not earned a published scorecard row until D1βD6 are live and independently verifiable against shipped reality β our own data-catalog page and a signed-list-version audit anchor both need to be public and checkable the same way we checked every vendor above. Until then this report carries no self-row. See our own source license map and the Global PEP Census for what we do publish today toward that bar.
- Make it annual, and now quarterly-checked. This is the flagship tentpole report. The scorecard becomes a year-over-year asset β "who moved" is next edition's headline β but this pass shows movement happens faster than annual cadence catches: recommend a lightweight quarterly spot-check of D1 and the headline pricing/count stats (the fields that moved this pass) between full annual re-surveys, so the next full edition doesn't again publish three stale cells.
6. Publication checklist (completed for this edition)
- β Re-verified every commercial-vendor cell against the live public site on 2026-08-24 (log in Β§3a).
- β Headline reworded to a claim that survives live re-verification: from "no vendor names its sources" to "no vendor publishes per-source license terms; a minority now name sources without cataloging them."
- β Kept the finding a sourced research finding, never a named accusation that a specific vendor misrepresents data β every corrected stat is presented as "this changed" or "not found," not "this vendor lied."
- β Confirmed OpenSanctions / Moov Watchman characterizations against opensanctions.org/datasets/ and github.com/moov-io/watchman on 2026-08-24.
- Not yet done, flagged for next edition: no self-scorecard row β gated on the data-catalog page and signed-list-version anchor both shipping and being independently checkable, per Β§5.
- Recurring instruction for future editions: re-verify every cell against the live public site at publish date, refresh the date stamp, and re-run this checklist in full β do not carry forward a stale verification date.