TrustSphere Vendor Assessment: Refinitiv, Sanctions Data and Compliance Integration


Refinitiv (the LSEG successor to Thomson Reuters financial data operations) occupies an unusual position in sanctions compliance: it is neither a primary regulator nor a pure technology vendor, but a provider of data that flows into both vendor platforms and direct institutional deployments. Institutions often acquire Refinitiv sanctions data through one of two channels: a direct subscription to Refinitiv's World-Check One product line, or embedded within a transaction monitoring or compliance platform that licenses Refinitiv data as a backend source. This dual role creates both strength and complexity. The strength is that Refinitiv's data pedigree is strong; it aggregates multiple official sources (OFSI, OFAC, UN, EU lists, and others) at source fidelity with limited derivative reworking. The complexity is that institutions sometimes overestimate what the data alone can do, or underestimate the operational work required to integrate it with transaction flows and investigation workflows.
TrustSphere's assessment of Refinitiv in 2028 reflects this mixed picture. Refinitiv's data quality and update frequency are first-tier. Its integration ecosystem and documentation are strong enough that a competent technical team can deploy it successfully. But institutions considering Refinitiv must understand what it does and does not do: it is a data provider, not a platform, and it solves the data-sourcing problem, not the alert investigation or governance problem. The false positive challenge described in today's theme post, for example, cannot be solved by swapping to Refinitiv data; it requires organisational choices about alert threshold and investigation methodology that sit above the data layer.
Refinitiv's Risk Index score is 6.74 out of 10, placing it in the upper-middle band. The score reflects strong data capability (7.8), excellent integration (7.2), and very good operational support (7.1), offset by limitations in AI-driven fuzzy matching (5.9) and minimal guidance on alert prioritisation or investigation governance (5.4). For institutions that have built their own investigation workflows and alert prioritisation rules, Refinitiv is an excellent choice. For institutions that need the data source plus embedded workflow methodology, other vendors may offer more comprehensive solutions at the cost of less granular control.
What Refinitiv Does Well
Refinitiv's core strength is data aggregation and update velocity. World-Check One ingests data from official sources (OFSI, OFAC, EU Council, UN sanctions lists) and maintains a consolidated schema across them. The update latency for official list changes is typically four to eight hours from source publication, which means a transaction flagged against a newly sanctioned entity reaches compliance officers within a business day. This is material. Smaller vendors or institutions relying on externally maintained consolidated lists sometimes face 24 to 48 hour delays, which can be operationally significant if an entity is sanctioned during intraday trading.
The second strength is the integration ecosystem. Refinitiv maintains API connectors to most major transaction monitoring platforms (Actimize, SAS, Actimized-via-NICE, and others), and maintains data feeds compatible with custom-built workflows. An institution with an internal transaction monitoring system can integrate Refinitiv sanctions data via SFTP batch feeds, real-time APIs, or embedded database replication. The documentation is detailed and the support for integration challenges is responsive. This matters because sanctions data integration is not trivial; entity identifiers vary across lists (OFAC uses numeric IDs; OFSI uses entity names and registration numbers; UN lists use transliterated names), and institutions need clear guidance on deduplication and entity resolution. Refinitiv provides that guidance better than most alternatives.
The third strength is the breadth of supplementary data. Beyond official sanctions lists, Refinitiv includes enhanced compliance data: politically exposed person (PEP) lists, regulatory enforcement actions, adverse media, and sanction watch lists maintained by intelligence services and industry bodies. An institution can run a transaction against Refinitiv's PEP database without a separate subscription, and can cross-check individuals against regulatory enforcement history. This consolidation saves operational complexity and reduces the number of vendor relationships required.
Where the Limitations Matter
Refinitiv's weakness is the assumption that the data alone can solve the sanctions screening problem. The first limitation is fuzzy matching capability. Refinitiv applies rules-based name matching (exact matches, phonetic variants, common transliteration rules) but does not use machine learning or probabilistic matching to identify high-confidence near-matches. An institution trying to catch name-variant forms (Ahmed vs. Ahmad, transposed surnames, etc.) will need to build its own fuzzy matching layer or accept that Refinitiv's matching rules will miss some variants. Competing vendors with native AI-driven matching sometimes achieve higher detection rates on fuzzy matches, though at the cost of more false positives. Refinitiv's approach is more conservative, which is defensible if an institution has built its own fuzzy matching logic upstream.
The second limitation is the investigation-side burden. Refinitiv provides the data; it does not provide methodology for investigating alerts, prioritising cases, or managing the false positive rate. An institution using Refinitiv must build or acquire separate tools for alert triage (why is this alert more severe than that one?), case management, and escalation logic. If the institution has a robust internal case management system and trained investigators, this separation of concerns is actually an advantage: the data is decoupled from process. But institutions expecting Refinitiv to "solve" sanctions screening operationally often discover that the tool solves data sourcing, not the investigation workflow. This is a common disappointment in vendor selection, where institutions conflate data quality with overall platform maturity.
The third limitation is emerging sanctions regimes and sanctions velocity. Refinitiv's data is strong on official sanctions lists from major jurisdictions (US, UK, EU, UN), but less comprehensive for secondary sanctions or sanctions applied by regional bodies (e.g., Australian, Canadian, or Asian regional sanctions). This is not a criticism; the data reflects the reality that Refinitiv serves a global audience and the primary enforcement burden falls on the US and UK. But an institution with exposure to secondary-jurisdiction sanctions will need to supplement Refinitiv with additional data sources. Refinitiv acknowledges this and provides import functionality for supplementary lists, but the onus is on the customer to identify and manage them.
The fourth limitation is guidance on alert thresholds and governance. This is perhaps the most subtle but consequential gap. As the theme post discusses, the real cost of sanctions compliance is not the data; it is the operational work of investigation. Refinitiv can flag a transaction that matches a common name against a historical or delisted sanctions list. It cannot tell an institution whether that match is worth investigating, or with what priority. Some institutions using Refinitiv run all matches as alerts (high sensitivity, high false positives). Others apply statistical thresholds to filter low-confidence matches (lower sensitivity, lower false positives). Refinitiv provides no guidance on what threshold yields defensible compliance, and no built-in tools for measuring false positive rates or tuning alert sensitivity. An institution must develop that methodology independently.
Who Refinitiv Fits, and Who It Does Not
Refinitiv is an excellent choice for tier 1 banks and large financial institutions that have invested in custom transaction monitoring systems and have trained compliance teams. These institutions have the technical capability to integrate Refinitiv data, the governance maturity to develop their own alert thresholds and investigation methodology, and the operational scale to justify the integration investment. For these users, Refinitiv is a best-in-class data source with minimal vendor lock-in; if they need to swap it out, they can, because they own the downstream workflow.
Refinitiv is also suitable for payment service providers and regional banks that want to white-label sanctions screening. Refinitiv's API and data feeds can be embedded in a bank's own customer-facing products, allowing PSPs to offer sanctions screening as a service without building the data aggregation pipeline themselves.
Refinitiv is less suitable for smaller institutions without in-house transaction monitoring development capability, or for institutions expecting a vendor to provide end-to-end guidance on investigation methodology and alert governance. Smaller firms often need a more packaged solution that includes investigation workflow and case management out of the box. Refinitiv can be integrated with case management systems (Actimize, SAS, etc.) but does not provide case management itself.
Refinitiv is also less suitable for institutions with heavy exposure to emerging markets or secondary sanctions jurisdictions, unless they are willing to layer supplementary data sources and manage the integration complexity themselves. The core Refinitiv data is strong on primary jurisdictions; emerging-market exposure requires active supplementation.
Five Questions a Vendor Cannot Answer with a Slide
1. "How do you define and measure false positive rate in your deployment, and what is the acceptable range for a tier 1 bank?" Refinitiv will not have a standard answer, because false positive rate is not a Refinitiv metric; it is determined by the institution's alert threshold and investigation methodology. If a vendor claims to solve false positives, it is conflating data quality with alert design.
2. "What is the integration latency between Refinitiv's last update of an OFSI list and the moment an alert lands in our transaction monitoring system?" This depends on your infrastructure and update frequency, not on Refinitiv alone. Refinitiv publishes data; your system ingests it. The gap is your responsibility.
3. "Which historical sanctions lists do you maintain, and for how long?" Refinitiv maintains current lists and a rolling 7-year history. If you need 10-year history (for transaction review or litigation), you may need supplementary data.
4. "How do you handle entity resolution when the same individual or company appears on multiple lists under different identifiers?" Refinitiv applies deterministic matching (exact name, official ID if available). Probabilistic matching across IDs requires your own logic or a partner tool.
5. "What support do you provide in defending a sanctions investigation decision to OFSI or OFAC if challenged?" Refinitiv provides audit trails of which list version was used and when. It does not provide legal or compliance argumentation; that is your responsibility and your counsel's.
Verdict
Refinitiv is a strong data product in a strong position. It is not a complete sanctions compliance platform, and it does not aim to be. For institutions that understand this distinction and have the operational capability to build investigation methodology on top of the data layer, Refinitiv is a first-choice provider. The data quality and integration support are excellent. The cost is reasonable relative to the data breadth.
For institutions expecting a vendor to solve the sanctions compliance problem end-to-end (including alert investigation, case management, and governance guidance), Refinitiv will disappoint because it is fundamentally a data product. In those cases, a more integrated platform vendor may be a better fit, even if the data quality is slightly lower.
The landscape in 2028 is increasingly segmented between institutions that can manage the integration complexity and want granular control (Refinitiv's sweet spot) and institutions that want more packaged solutions (competing platforms). Refinitiv's strength is deepening in the former camp. For the latter, the risk is that Refinitiv becomes a component of a more complex integration rather than a standalone solution.
Suggested Next Steps
* Assess whether your institution has the integration capability and governance maturity to manage sanctions data independently, or whether you require more end-to-end platform guidance. This decision should drive the vendor choice; it is not a Refinitiv-specific question, but it determines whether Refinitiv or a more integrated alternative is appropriate.
* If pursuing Refinitiv, request a detailed integration plan from Refinitiv or your system integrator that maps Refinitiv data feeds to your transaction monitoring system, defines alert threshold logic, and documents how you will measure and review false positive rate. This plan becomes your governance document.
* Define your supplementary data requirements (secondary sanctions, regional lists, emerging-market exposure) and establish how they will be sourced, deduplicated against Refinitiv data, and integrated. This is often the most underestimated part of sanctions data deployment.
* Establish a quarterly review cycle for your alert threshold and false positive rate, using the measurement methodology established in your integration plan. This is not a Refinitiv-specific task, but it is essential to operationalise Refinitiv data effectively.
Sources: Refinitiv World-Check One product documentation (2028), LSEG Risk Intelligence service (2028), Financial Conduct Authority sanctions compliance guidance (2024), Office of Financial Sanctions Implementation enforcement guidance (2026), TrustSphere Risk Index, April 2026.
TrustSphere helps financial institutions design and deploy intelligent fraud and financial crime detection solutions. Visit www.trustsphere.ai



Comments