How fast should risk screening be? Speed benchmarks for due diligence teams

By Beady Team Jul 28, 2026

A due diligence lead benchmarking the team’s screening speed is usually chasing the wrong figure, or at least an incomplete one. The trouble is that “risk screening” isn’t one activity. Clearing a new counterparty before a deal closes, refreshing a company already in the portfolio, and running first-time diligence on a target are separate jobs, each with its own reasonable pace, and lumping them into a single benchmark misreads at least two of the three.

The sections below give an honest range for each. But there’s a figure that matters more than any of them, and it belongs at the top: not how fast a screen runs, but how fast it produces an answer you can trust and defend. Call it time-to-trustworthy-answer. A quick result you have to re-check yourself was never really quick.

Why speed on its own is the wrong benchmark

Speed is easy to measure, which is exactly why it gets over-weighted. It is also easy to fake.

A screening tool can return a result in seconds by matching a name against a single sanctions list and stopping there. That is fast, and it is close to worthless, because it has missed adverse media, beneficial ownership, corporate structure, litigation, and every other thing that a real screen is supposed to catch. The seconds saved are an illusion, because a shallow pass has to be redone properly later, or worse, is trusted and isn’t.

The benchmark that actually means something is how quickly a screen produces an answer that is trustworthy at the moment it arrives. Verifiable against a primary source. Low enough in false positives that a human can act on it without wading through noise. Complete enough to cover the real risk surface, not just the easiest list to check. A fast answer that has to be manually re-verified is slower, in real terms, than a slower answer that arrives already checkable.

Hold onto that phrase, time-to-trustworthy-answer, because it changes what each of the benchmarks below is really measuring. Speed only counts once the output can be trusted.

The four screening jobs, and what fast means for each

Screening splits into four distinct jobs. They look similar from the outside and behave completely differently on the clock.

Onboarding screening: minutes, sometimes hours

The onboarding target is two numbers, not one: minutes for a simple entity, longer for a complex one, and never faster than the entity actually warrants.

The reason speed matters here at all is that the screen blocks a live transaction. A counterparty is waiting, and the delay is expensive in a visible way: a half-finished signup, a deal losing its momentum. So for a clean, low-risk entity, minutes is right, and the tooling delivers it. But the reason speed can’t be the only target is what happens to the harder entities under that same pressure. Cut the screen to whatever returns fastest and you get a name-against-list check that clears in seconds and looks like diligence, right, while the beneficial owner on a watchlist, two layers down, goes unexamined because the shallow check was never built to look there.

That’s the case for treating the harder entities differently instead of forcing everything through one fast path. Simple entities can share the quick lane safely. Complex ones, with layered ownership or a cross-border, high-risk profile, need the deeper check to take the time it needs, on a track of its own.

Ongoing screening: continuous, or close to instant

This is re-checking an entity you already know, after something about it may have changed. And it is where the most time gets wasted, for a specific and avoidable reason.

The baseline already exists. The heavy work of building a picture of this entity was done at onboarding, so a refresh should be watching for what has changed since, not reconstructing the whole picture from scratch. Done right, that is fast, because deviation from a known baseline is a much smaller question than a first assessment.

Yet plenty of firms treat re-screening as a periodic manual project, running the full screen again quarterly or annually as if the entity were new each time. That is slow because it is doing the wrong thing: rebuilding rather than monitoring. If re-screening a company you already hold takes days, the process has quietly reverted to first-assessment mode, and the speed problem is really a design problem.

The honest benchmark here is that ongoing screening should approach continuous, triggered by change rather than by the calendar. The full argument for why periodic re-screening fails, and continuous monitoring replaces it, is set out here.

Deep diligence: days to weeks, and rushing it is the risk

Here, speed is the enemy, and any benchmark pushing for more of it is giving bad advice.

Deep diligence is investigation rather than screening. Building a full picture of a target means working through its people, its ownership history, its litigation record, its reputation and what it actually does for a living, and that work legitimately runs to days or weeks. The depth is the whole point. A fund that squeezes it to fit a deal timeline isn’t being efficient. It’s giving up the very thing diligence is there to provide.

The pressure is real, and it comes from deal timelines and impatient investors, and it’s precisely where funds most often miss the fact that turned out to matter. The right benchmark is simple to state: fast enough to keep a live deal moving, and no faster. When the choice is between rushing the work and slowing a deal by a few days, those few days are almost always cheaper than what a hurried screen overlooks. Tooling helps here, but by taking over the mechanical parts, the searching and the collating, so more of the available time goes to human judgment. It does not help by shortening the judgment.

Event-triggered screening: hours, against an external clock

This is the only screening job where the clock isn’t yours. Something happens out in the world- a sanctions listing, a news story about a portfolio company, a criminal charge against a counterparty’s owner- and your exposure begins at that moment, whether or not you’re aware of it yet.

The screening part, once you know, is quick. It’s a focused question, so hours is a reasonable ceiling. But focusing on that number misses the point, because the time that actually determines your exposure isn’t the hour spent screening. It’s the days or weeks that may have passed before you knew there was an event to screen at all. That gap is the thing worth measuring, and it’s what the next section is really about.

The benchmark almost nobody measures: detection latency

For everything except onboarding, the speed that determines your real risk is not how fast you screen once you begin. It is how long passes between something changing and you knowing to look.

Consider a team that can run a screen in three minutes. Impressive, on paper. Now suppose that the team re-checks its portfolio once a quarter. The time between a portfolio company’s owner being sanctioned and the team finding out is not three minutes. It is up to ninety days. The three-minute screening speed is irrelevant next to a detection gap measured in months, because the screen only runs after someone thinks to run it.

For anything already in your book, the metric that governs the whole thing is detection latency — the time between a real change and you knowing about it. That’s the number. Screening speed sits inside it as a rounding error. A screen that takes ninety seconds but runs continuously will always beat a screen that runs in three seconds but only four times a year.

And detection latency is not a property of your screening tool. It is a property of whether anything is watching in between screens. That is a continuous-monitoring question, not a screening-speed one, which is why teams that optimize only for screening speed can still be months behind on the thing that hurts them.

What lets screening be fast and trustworthy at the same time

Speed and trust are usually posed as a trade-off, and they don’t have to be, provided a few things are true.

Breadth in a single pass. Speed that comes from checking fewer sources is not speed, it is a narrower screen wearing a stopwatch. The kind worth having covers sanctions, adverse media, corporate registries, ownership and more in one sweep, so being fast doesn’t mean being shallow.

Source traceability. An answer that links back to a primary source a person can open is trustworthy at the moment it arrives, with no manual re-verification stage bolted on afterward. This is what makes a fast answer genuinely fast rather than fast-then-slow. It is also what a regulator or an investment committee expects: a screen they can audit, not a conclusion they have to take on faith. The cadence of external changes that make this necessary, from OFAC designations onward, does not slow down to wait for anyone.

Noise filtering. A screen that returns four hundred possible matches has not saved anyone time, it has moved the work from searching to sifting. Real speed means the output is already filtered to what warrants a human look, false positives stripped out before they reach a person.

Continuous baselines. When an entity is already being monitored, a refresh is watching for change rather than starting over, which is what makes ongoing screening near-instant instead of a repeat project. Some of this is achievable by hand for a handful of entities. Across a real portfolio it is not, which is where tooling stops being a convenience and becomes the only way the numbers work. The cost side of getting this wrong, the price of a signal caught late, is worked through here.

The benchmarks, in one table

Pulling the four jobs together, with honest ranges and the caveat that every one of them shifts with the complexity of the entity in question.

Screening jobHonest time rangeWhat drives itThe trust caveat
OnboardingMinutes to a few hoursIt gates a live transaction, so delay has a direct costSpeed pressure is where shallow checks hide; complex entities need longer
Ongoing / refreshContinuous to near-instantThe baseline exists, so it is watching change, not rebuildingIf it takes days, the process has reverted to first-assessment mode
Deep diligenceDays to weeksIt is investigation; depth is the whole pointRushing it is the actual risk, not a sign of efficiency
Event-triggeredHours once you knowAn external clock; exposure runs from the eventTime-to-awareness matters more than time-to-screen

Frequently asked questions

How long should risk screening take?

Onboarding should be completed in minutes for the majority of cases, with a small tail extending into hours. Ongoing monitoring of existing counterparties should be near-instant or continuous, embedded into the operating environment rather than run as a discrete task. Deep diligence — the kind performed ahead of an acquisition, joint venture, or high-exposure relationship — is properly measured in days or weeks, and the timeline reflects the depth of the work rather than any inefficiency. Event-triggered screening should close within hours of the underlying event being recognised. A single benchmark cannot fairly represent all four, and attempting to impose one usually reveals a gap in how the programme has been designed.

Is faster screening always better?

For onboarding and monitoring, sure — quicker is better, and if it’s slow, something’s usually wrong with how it’s set up. But deep diligence isn’t the same job. It’s an investigation, and investigations don’t reward speed. Try to shave the timeline and you’re really just producing paperwork, not findings. There’s a broader point underneath all this that gets missed a lot. A result you can’t rely on isn’t fast at all — you either redo the work later or you make a decision you’ll come to regret. Speed matters, but only once you can trust what you’re looking at.

What is detection latency in risk screening?

Say a team can screen an entity in three minutes but only re-checks its portfolio once a quarter. If a company’s owner is sanctioned the day after a check, the team won’t know for up to ninety days. That ninety-day gap, not the three minutes, is the number that matters, and it has a name: detection latency, the lag between a material change and your awareness of it. It comes down to whether anything monitors between screens, which is why it’s a continuous-monitoring question, not a screening-speed one.

How fast is sanctions screening?

Seconds to minutes, if all you’re doing is matching a name against a sanctions list. But that’s worth being careful about, because a name match isn’t really a screen. It says nothing about adverse media, nothing about the beneficial owner two layers down, nothing about the corporate structure around the entity. A screen that skips all of that is quicker because it’s doing less, so the number that matters is how fast a full, checkable screen runs, not the bare sanctions lookup.

Why do fast screening results still need verification?

A result is only worth anything if you can trust it the moment you get it. When an answer can’t be traced to a primary source, someone still has to go and confirm it by hand, which quietly eats the time the fast screen looks like it saved. Screening that links each result to a source you can open is what keeps speed real, and it’s what an auditor or investment committee will want to see anyway.

The short version

How fast should risk screening be? Fast enough for whatever’s in front of you — which is minutes onboarding, continuous for ongoing, hours once an event lands, and as long as diligence honestly needs when you’re going deep. A single number doesn’t cover it, and anyone offering one is selling that number rather than answering the question.

Here’s the part that gets skipped. For anything ongoing, speed isn’t the right thing to be measuring. What you actually care about is detection latency — the time between a change happening and you finding out. That comes down to whether something is watching in between, not by how fast you can run a screen once you start. Speed only counts when the answer is trustworthy the moment it lands.

That combination, fast, source-traceable, and continuous so detection latency stays low, is what Beady AI is built for: monitoring the entities you’re exposed to across sanctions, adverse media, ownership and impersonation, with every signal linked back to its source. A session will show what that looks like against a real set of entities, and how short the gap between a change and knowing about it can actually be.

Beady Team

The team behind Beady, building risk intelligence and compliance software. We write about sanctions, due diligence, KYC, and screening — drawing on what we see across hundreds of millions of sources every day. Practical insight for compliance, risk, and investment teams.

Risk Intelligence, Straight to Your Inbox

Guides, regulatory updates, and lessons from real screening cases. Written for compliance, risk, and investment teams who need to know what's coming next.

    Follow Beady Where You Already Work

    Risk alerts, regulatory changes, and screening insight — posted where your team already spends its day. Join us on the most popular social networks.

    Ready to get started?

    Helping you go live in days, not weeks.