Skip to the operations

Compliance

OpenSanctions in a decision flow.

5 OpenSanctions operations a decision flow can call directly, with the credentials your own contract issued. The response is data the rest of the flow reads, branches on, and keeps in the trace.

Category
Compliance
Type
Integration
Authentication
API key
Test environment
Production host only

Who they are

An open database of sanctions targets, PEPs and watchlists.

OpenSanctions collects the lists governments and international bodies publish, reconciles the entities that appear across them, and republishes the result as open data with an API. It is free for non-commercial use and licensed commercially. Because every source is public, so is the provenance of any match it returns.

What a flow can call

5 operations, each one a step you can place on the canvas.

  1. POST/match/default

    Screen a person

    The screening call. Send the identity you hold and get scored candidates back.

  2. POST/match/default

    Screen a company

    Same call for a business — dealer, employer, or a commercial borrower.

  3. GET/search/default

    Free-text search

    Full-text lookup for an analyst reviewing a hit, not for automated screening — use Screen a person for that, which scores properly.

  4. GET/entities/$data.opensanctions_entity_id

    Fetch one entity

    The full record behind a match: every alias, listing, source dataset and relationship.

  5. GET/catalog

    List datasets

    Which lists the key can screen against, and when each was last updated.

Where it sits in the decision

Compliance calls have a natural place in a flow.

Screening answers the parts of a decision a regulator will ask about, so what matters is not only the verdict but the record of it. A partial match is the interesting case: rarely a decline on its own, and usually the point where the flow opens a case for a reviewer with the match evidence attached.

Whatever OpenSanctions returns is part of the run, so it is part of the record. When someone asks months later why an applicant was declined, the answer cites what came back at the time rather than re-fetching from a service whose answer has since changed.

  • 01Add OpenSanctions as a connection authenticating with an API key.
  • 02OpenSanctions has one host for both environments, so guard test runs with your own credentials and limits.
  • 03Place a Connection node and pick an operation — “Screen a person” is usually the first one a flow needs.
  • 04Map the response into the fields your rules read, then test the whole path before it carries live traffic.

Common questions

Using OpenSanctions in a flow.

How do I connect OpenSanctions to a decision flow?

Add OpenSanctions as a connection in your workspace authenticating with an API key, with the credentials your own contract issued — ArboRule calls the provider as you, and never holds a contract on your behalf. Once the connection exists, any flow in the workspace can place a Connection node and choose one of its operations. The credentials live on the connection, not in the flow, so a policy owner can use OpenSanctions in a decision without ever seeing the secret.

Can I test OpenSanctions without touching production?

OpenSanctions exposes one host for both environments, so there is no separate sandbox to point at. Test runs still execute in Sandbox and are recorded separately in decision history, but the call goes to the same place as production — so guard it with your own test credentials, rate limits, or data.

What can a flow call on OpenSanctions?

5 operations, including “Screen a person”, “Screen a company”, “Free-text search”. Each one is a step you place on the canvas and map into the fields your rules read, and most flows start with “Screen a person”. The list comes from the same manifest the engine uses to make the call, so this page cannot describe an operation the product does not have.

Where in a decision should OpenSanctions be called?

Screening answers the parts of a decision a regulator will ask about, so what matters is not only the verdict but the record of it. A partial match is the interesting case: rarely a decline on its own, and usually the point where the flow opens a case for a reviewer with the match evidence attached.

Ready when you are

Wire OpenSanctions into a real decision.

Build the flow in Sandbox, connect your account, and watch the decision pull what it needs before it answers.

Read the docs