We built the the most comprehensive PEP database for Sri Lanka and learned the data was only half the job

Every conversation about customer screening in Sri Lanka lands in the same place. No comprehensive database for PEPs exists and sanctions screening is the basic level of hygiene the regulator expects. So many just stop there.

Mudith Uswatta profile photo

Mudith Uswatta

Chief Commercial Officer - Dossiers

Sanctions screening is solved, but often overpriced by vendors 

Sanctions screening is essential and non-negotiable — the first control any serious institution puts in place. It's also tractable, because the raw material is public and finite: the consolidated UN, OFAC, EU, DFAT and CBSL-specified lists are published and maintained by the bodies that issue them. Match your book against them, keep them current, flag matches for review. Every credible provider can do it. 

However, we frequently see vendors convincing buyers that sanctions screening completes their screening obligations and overcharge for this service. However, only very few individuals or entities ever get sanctioned, so the real risks live one level deeper. 

The hard part: who counts as a PEP?

A politically exposed persons list isn't something you can download. PEP status is about position and relationships — a senior official, someone who controls public funds, and their family members and close associates. It changes over time, and in Sri Lanka the information is scattered across gazettes, disclosures, news and court records, almost none of it packaged as screening data and there is no central registry. 

The regulator recognises this as a genuinely hard data problem — but the obligation stands. Rule 59 of the Customer Due Diligence Rules (No. 01 of 2016), under the Financial Transactions Reporting Act No. 6 of 2006, requires institutions to identify PEPs, apply enhanced due diligence, get senior-management sign-off before onboarding, and monitor on an ongoing basis. The requirement was clear. The data to meet it wasn't there.

And the high-risk customers who aren't on any list

PEPs and sanctioned parties are only part of the picture. A high-risk customer may appear on no official list at all and still carry obvious risk — someone named in adverse media, tied to fraud, financial crime or corruption, facing court proceedings or regulatory action, or linked to organised crime. They can clear a sanctions screen and a PEP check and still be someone no institution should knowingly bank. The danger is never the customer you turn away; it's the one you onboard. A simple web search will very likely miss these risks. The bank knows the customer by their full name. But in the media, for example in a crime related news story they appear by part of their name or an alias. 

So we built it

That's the gap Dossiers set out to close — and the work we're proudest of. We built a PEP and high-risk database for Sri Lanka from scratch, locally, using a novel AI-driven approach that continuously gathers and structures information from public sources into screenable profiles. We built the dataset by collating three decades of the public record — government and regulatory websites, government gazettes, parliamentary Hansard, Colombo Stock Exchange filings for listed companies, and media archives going back 30 years — and we keep it current as new information appears. Crucially, our name-matching understands how names actually work here — a single person written a dozen ways across Sinhala, Tamil and English — so local names get recognised, without throwing up thousands of false positives for popular names like “Perera” or “Fernando”. The database updates continuously, and it goes beyond PEPs: the same engine continuously scans news and public records for adverse-media hits, so a customer who surfaces in a negative story — fraud, a court case, a regulatory action — is flagged rather than missed. The research behind it was recognised by Google with a US$350,000 grant. This grant is now helping us to actively increase our coverage in our immediate neighbourhood of South Asia. 

How this compares to the global vendors

The big international tools are excellent at what they were built for — deep coverage of global and Western figures. Point them at Sri Lanka and that advantage disappears:


Global Screening Vendors

Dossiers

Sri Lankan PEP Coverage

Thin to non-existent

Built locally, from scratch

Name Matching

Trained on Western names; misses local ones

Sinhala, Tamil & English, built for this market

Pricing Model

Per-seat / per-search / volume tiers

Flat, module-based – no per-record penalty

Effect on Behaviour

Screening more, more often, costs more less frequent, partial screening

Screen the whole book continuously at no extra cost

Data Residency

Typically cloud-hosted, PII leaves the institution

On-premise, customer data never leaves your environment

That last point matters for compliance too: our on-premise deployment supports the Personal Data Protection Act No. 9 of 2022 and CBSL's data-residency expectations by design.

The data is only the starting line

Having a dataset is necessary and nowhere near sufficient. The work that decides whether screening survives an audit is operational: running hundreds of thousands of customers against that data, continuously, and turning the output into something a regulator accepts. Done by hand in quarterly batches, that's thousands of mostly-false-positive alerts reviewed under deadline, the real hit buried, and little evidence left afterward. This is exactly where enforcement is landing — in its most recent round, the Financial Intelligence Unit fined eleven institutions a total of Rs. 14.6 million for AML/CFT non-compliance.

So we built the operational layer alongside the data:

  • Always-on bulk screening across the entire customer book, plus API screening of every new customer at onboarding. No need for manual batch screening. The compliance team is alerted when a sanction list update, new PEP hit or adverse media affects any client. They only deal with the alerts 
  • Retained false positives — each kept with the reason it was cleared. No need to keep clearing the same flags again and again
  • Case-management workflow — assign flags to specific officers, comment, attach evidence, track to closure
  • Tamper-evident audit trail — every action fully attributed and regulator-ready

These aren't bolt-ons. They're what it actually takes to run screening inside a large institution — the difference between generating alerts and producing evidence.

Where this leaves us

Sanctions screening was solved before we began, and it remains an essential foundation. What Sri Lanka lacked was a real PEP and high-risk dataset — and the automation to screen against it, across the whole book, continuously, in a form a regulator accepts. We built all of it. Because just a database won’t do.