Skip to main content
Version: 3.2

Install and configure

The guide details how to install and configure the Name Sanction Screening (NSS) skill.

Prerequisites

Before installing the NSS skill, make sure your environment meets the following requirements.

Hardware

The server requirements for the skill are the same as for the Work.AI Platform. To run screening, you don't need the RPA server.

ServerRecommended OSCPU (cores)RAM (GB)HDD (GB)
MasterRHEL/CentOS 8.x832750
AgentRHEL/CentOS 8.x832150
Superset AnalyticsRHEL/CentOS 8.x2450
MS SQLMicrosoft Windows Server 2022, 2019416500

For the architecture deployment diagram, refer to Install AI Agents | View architecture deployment.

Software

  • You have installed Work.AI v.10.2.8+ and have Control Tower (CT) and Analytics components enabled. See the installation guide.
  • You have obtained the bundles with the NSS Business Processes and machine learning (ML) models from your Account Managers.
  • You have received the credentials for the required watchlists or licenses for the external screening software to be integrated with the skill.
  • You have enabled the Advanced Package Import and Import/Export permissions in CT. For detailed instructions, read Manage Control Tower roles and permissions.

Performance

NSS leverages BEP servers that can be horizontally scaled for higher volumes.

Below is a sample of the volumes that can be expected when using the provided version and configuration. The system shows stable performance and resource consumption throughout the entire test, without unexpected spikes, any critical errors, or warnings in logs.

Testing results on Evelyn v2.2

Testing has been performed with the disabled Factiva provider as it is not possible to run the skill with big test data without Factiva blocking it due to a large amount of requests.

Configuration:

Skill versionEnvironment topologyTested Work.AI versionNumber of OCR WorkersML Worker configurationCT Worker configuration
2.23 / 6 / 20 Agents10.2.771 CPU / 4 GB memory0.4 CPU / 2 GB memory

Results:

Number of AgentsNumber of screened namesDurationNumber of CT tasksNumber of CT WorkersAML task throughput
320,0001 hr 30 min5,242290.317
620,0001 hr9,450590.647
2020,00021 min29,1832401.823

Install

For instructions, see the Install AI Agents guide.

note

Evelyn v3.2 provides two versions of an AI Agent package:

  • Standard Asset Bundle: names-screening-package-3.2.0.zip
  • Asset Bundle without Thomson Reuters ongoing monitoring: names-screening-package-3.2.0-no-tr.zip

Configure

Once NSS is installed, configure the skill before running it for the first time:

  1. Set up Secrets Vault entries to use external data providers and Manual Tasks.
  2. Select an input source.
  3. Configure the selected input source.
  4. Configure the model.
  5. Configure enrichment with location data.
  6. Configure manual review.
  7. Set up output options.

You can configure multiple variations or sets of parameters for NSS, for example, a different media provider or a set of keywords per variation. For more information, see the Manage AI Agent Variations.

warning

A secret entry is not a part of the AI Agent package. You must configure it manually after you install Evelyn.

Set up API credentials in Secrets Vault

To use external data providers, set up credentials in Secrets Vault. For instructions, see the guide.

The following external data providers are supported:

  • Dow Jones Factiva REST API v1.0
  • World-Check One v2.2.0
  • Firco Trust Case Manager API v5.4.22
  • Thomson Reuters CLEAR
tip

Before setting the above data providers, make sure you have obtained required licenses with credentials.

Set up Workspace URL in Secrets Vault

To use Manual Tasks in the Work.AI v10.2.8 environment, set up a secret entry for the Workspace URL in Secrets Vault. Add a new secret entry and specify the following settings:

  • Alias: workspace_url

  • Key: URL to Workspace, for example, https://my-company-ws.cloud.workfusion.com/workspace

  • Value: any value

info

If you fail to create a secret entry, your environment is assumed to be Work.AI v10.2.9, which may cause issues. The request status service will display the Error status accompanied by a message prompting you to create a secret entry.

Select input source

To select a screening provider, do as follows:

  1. In the Control Tower menu, go to Digital Workers, find your newly installed NSS skill and click the Prepare button.

  2. In the configuration window, on the Input step, select from where to source input data for the configured NSS skill:

  3. Configure the selected input source.

Configure input

To configure the selected input source, specify relevant parameters. For detailed setup instructions, see the sections below.

Screening system

If you select Screening system as the input source, the NSS skill will search for records about an entity or individual in the system you choose in the appropriate drop-down list.

To configure the screening system to work with the NSS skill, follow the steps below:

  1. Choose how you want entities or individuals to be screened:

    The following options are available:

    • Retrospectively using a risk-based approach if you want the screening to be executed upon request.

    • Proactively using event-based monitoring if you want screening to be automatically executed based on monitored events.

  2. Choose a screening system. Depending on the screening method you choose in Step 1, the NSS skill supports the systems listed in the table below. Dow Jones Risk & Compliance is the default choice for the retrospective screening and Thomson Reuters CLEAR for the proactive screening.

    Screening methodSupported screening systems
    Retrospectively using a risk-based approach
    • Dow Jones Risk & Compliance
    • World-Check One
    • Firco Trust Case Manager API
    • Thomson Reuters CLEAR
    Proactively using event-based monitoring
    • Thomson Reuters CLEAR
  3. To configure a screening system integration, follow the instructions below.

  • API URL. Select the address of the Dow Jones Risk & Compliance API. Available options are as follows:

    • https://api.beta.dowjones.com
    • https://djrc.api.dowjones.com
  • Credentials location. Specify the Secrets Vault alias storing the credentials for the Dow Jones Risk & Compliance system.

  • Number of hits in one request. Specify the number of hits to be processed per request for a particular entity from Dow Jones Risk & Compliance API. This parameter impacts how many requests are sent to Dow Jones Risk & Compliance API. The default value is 500.

  • Desired search type. Set the desired tolerance for the search in the Dow Jones Risk & Compliance system. By default, it is Precise. Available options are as follows:

    • Precise: the mode requires an exact match between the search input and the data in the database. It is highly specific, meaning that the names, dates, or other identifying information must be identical or very close to the input.

      The mode is best suited for situations where you have complete and accurate information about the search entity. It minimizes false positives but might miss matches if there are minor discrepancies in the data (for instance, slight variations in spelling).

    • Near: the mode allows for minor variations in the search input. It is less strict than the precise search, accommodating small differences, such as typos, abbreviations, and slight spelling variations.

      It is most useful when the information might not be entirely accurate or complete. It balances the need to catch more potential matches while still reducing the number of false positives, as compared to the Broad search.

    • Broad: the mode is the least restrictive, allowing for significant variations and partial matches between the search input and the database entries. It casts a wide net to catch as many potential matches as possible.

      The mode is perfect when the information is highly uncertain or incomplete. It maximizes the likelihood of identifying potential matches but generates more false positives, requiring more manual review to filter out irrelevant results.

  • Use developer's mode after configuration. Select Yes to enable the Developer mode for a Business Process. The Developer mode caches requests and responses from the Dow Jones Risk & Compliance API to avoid a ban from Dow Jones due to a massive number of queries.

    For the production configuration, set the value to No.

A little more about cache

The cache is meant to reduce the number of requests to screening systems. It is implemented as a separate Data Store.

After you install the skill, the cache Data Store is empty by default. The hit data is received in responses when a bot sends a name request to an external screening system. The received data is then saved to the cache.

Most screening systems send one response that contains all necessary hit data. But in some cases, there can be two requests:

  • The first one obtains brief information on all hits. The data is saved to the search cache.
  • The second one with the hit ID obtains detailed information on the specific hit. The received data is saved to the hit cache.

The skill supports caching both for searches and for hits.

Search cache
warning

Activate the search cache (with the Developer mode) in development environments only. If enabled in the production environment, the skill operates with obsolete data.

The search cache implies that hits for particular names are used from the cache instead of the real-time API. In such a situation, the stored data will soon become outdated. This is why the search cache is intended for the Developer mode only.

The operation flow with the enabled search cache is the following:

  1. The skill sends a search request to the API.
  2. All data received from the API is stored in the search_cache Data Store.
  3. Next time, when input contains the same name for the search, the skill will obtain all hits for this particular name from the cache instead of DJ API.
Hit cache

The hit cache is always enabled to reduce requests to the Dow Jones API and improve BP performance.

The operation flow of the hit cache is the following:

  1. The skill sends a search request to the API and receives a list of hits with short data for this name.
  2. The skill performs the second request with a specific hit_id to get the hit's detailed info.
  3. The hit details are saved to the hits_cache Data Store. It also stores the date when the hit was updated last time in the database.
  4. Next time, when the skill requests hit details, the system checks whether the hit cache contains up-to-date hit details.
  5. If the hit details in the hit cache are outdated, the skill sends a new request for the hit details and updates the cache for this particular hit.

WorkFusion API

Select WorkFusion API for full alert screening via REST API.

For more details on data transfer via API, refer to Run screening | Call NSS REST API.

Upload CSV file

Select Upload CSV file for historical data evaluation. The uploaded CSV file should contain historical data and Watchlist Entity data.

Click Download format file to get a CSV file template and ensure the uploaded file corresponds to the provided format. Keep in mind that only the CSV format is supported.

To complete the configuration, provide the following data:

  • Input format file location. Specify the path to the format file location in S3 MinIO.
  • Input data location. Specify the path to the S3 MinIO folder or file where the historical data is located. Ensure the input file contains input_id (a unique identifier) to minimize unintended volume usage.

For more information on the historical data evaluation flow, see the guide.

Configure model

In the configuration window, on the Model tab, you can change the following model-related settings:

  • Leave the Use latest model version selected by default to apply the default prepackaged model.

    To change the model version, deselect the option and select the required version in the drop-down list.

  • Leave the Include all criteria in the decision narrative option deselected if you want the model's decision narrative to include only the most significant factors for the strong match and weak mismatch (if available).

    Select the Include all criteria in the decision narrative option if you want the model's decision narrative to include all factors for the strong match and weak mismatch (if available).

  • Open the Rules section and specify the factors based on which the model should treat a hit as false positive. You can define rules by selecting the Name, Location, Date, Type, Gender checkboxes.

    Empty values in rules are allowed. If only one factor is required to make a false positive decision, there is no need to select others. To add a new field, start by removing all existing rules. For more details on setting rules, see Configure classification model.

  • Open the Thresholds section and set the similarity factors for comparing names and dates. You can define thresholds based on Name, Date, and Location. For more details on setting thresholds, see Configure classification model.

  • The Stopwords section contains several groups where you can specify keywords. These are specific words to be removed from compared input and hit data. NSS contains default stopwords out of the box.

    Enter stopwords in the relevant input fields, separating them by commas, or upload a CSV file. For more details on setting stopwords, see Configure classification model.

Configure location enrichment

In the configuration window, on the Location enrichment tab, leave the Location lookup empty to skip address enrichment.

When you choose to use the address enrichment feature, select a provider. The NSS skill retrieves detailed information about the location from the provider system and enriches ScreenedData and WleData. Available options are as follows:

  • Google Geocoder. One call for each address is created, returning appropriate information.

  • Google Places Api. Firstly, NSS calls https://maps.googleapis.com/maps/api/place/autocomplete/json to retrieve a list of predicted addresses. Then, the list of predicted addresses is sent to https://maps.googleapis.com/maps/api/place/details/json, and detailed address information is returned.

Configure the following parameters:

  • API key: specify the key to be used for retrieving geolocation data from the selected provider.

  • Connection type: specify the connection type for connecting to the selected geolocation provider. The Direct option is selected by default, enabling you to call the provider directly.

  • Lookup settings: specify when to perform an address lookup. In case both input entity and watchlist entity are required for enrichment, select both the checkboxes.

    • Lookup on input entity applies the address enrichment feature only to input data.

    • Lookup on watch list entity applies the address enrichment feature to hit data.

For more details on location enrichment, see Perform data enrichment.

Configure manual review

The Human in the Loop step allows you to verify or modify the decisions of the NSS classification model by providing all available information that might be too complex for the model to process. Alerts chosen for manual review remain available in Workspace till manually submitted.

To set the Human in the Loop step, follow the steps below:

  1. Select whether and how you want to check the NSS skill output manually in Workspace:

    • Enable in all cases: the NSS skill sends all alerts with hits to manual review.

    • Enable for Need More Information alerts only: Evelyn creates manual review assignments for alerts where the model decision was Need more information.

    • Enable for False Positive alerts only: Evelyn creates manual review assignments for alerts evaluated as False Positive.

    • Disable in all cases: the skill skips the manual review step in all cases, sticking to the model decisions.

    Additionally, for the Enable for Need More Information alerts only and Enable for False Positive alerts only options, type in the exact alert categories that should be forced or skipped.

    info

    The above configuration can be overridden by using the mt_force parameter. For details, read Run screening | REST API configuration map.

  2. Select Auto quality check to enable the AI Agent to randomly submit the defined percentage of false-positive alerts for additional manual review in the selected screening system.

    • Percentage of false positive alerts. Specify the percentage of false positive alerts to be submitted for additional manual review. The associated screening system is updated to indicate that the AI Agent marked this alert for the auto quality check.

    • If in step 1 you choose Enable for Need More Information alerts only or Enable for False Positive alerts only, choose if you want the alerts flagged for the automatic quality check to be sent for manual review.

Configure output

On the Output step, choose the format for screening request reports that become available after the Business Process execution:

  • .csv: Quality Check report
  • .html: HTML report
    • Do you want to generate a single page combined HTML report?: select Yes to get a single-page HTML report.