A Scalable Microservices Architecture for Event-Based Sanctions Screening Systems

Authors

  • Zaheer Syed Sr Software Engineer, USA. Author
  • Hani Patel Software Engineer II, USA. Author
  • Juwaria Naaz Senior Data, USA. Author

DOI:

https://doi.org/10.63282/3050-922X.IJERET-V7I3P106

Keywords:

Microservices, Event-Driven Architecture, Sanctions Screening, Financial Compliance, Aml, Kafka, Distributed Systems, Cloud Computing, Containerization, Real-Time Processing

Abstract

Banking organizations as well as other financial firms are increasingly requiring sanctions screening solutions as they attempt to ensure adherence to ever-changing global regulations as they process massive volumes of transactions in real time. Modern demands on conventional monolithic screening platforms are hard to satisfy because they lack scalability, are slow to process, and have high coupling between parts and low fault tolerance, resulting in inefficiencies and slower compliance decisions. This paper outlines a scalable microservices architecture for event-based sanctions screening systems, built using “cloud-native” design approaches, using asynch event-based communication, and distributed processing to enhance system responsiveness and resilience. The proposed architecture consists of core compliance functions (transaction ingestion, watchlist management, screening, match evaluation, alert generation, case management, audit logging, reporting), as distinct entities which can be deployed independently and use an event streaming platform to connect them. The research methodology involves analyzing the architectural structure, designing microservices, creating a workflow model, and studying the responses to various events and evaluating performance as the number of transactions increases, thereby measuring the services' scalability, availability, and operational effectiveness. The framework includes container orchestration, horizontal auto-scaling, API gateway management, centralized monitoring and resilient messaging, and is designed to facilitate continuous operations and regulatory compliance. Experimental metrics show significant gains in throughput, response times, fault isolation and resource utilization over the traditional monolithic approach with minimal loss of processing power during times of peak transactions. The findings highlight the compelling advantages of event handling microservices in making sanctions screening platforms more scalable, maintainable, and reliable, offering financial institutions a flexible and future-proof framework for real-time compliance, swift regulatory changes, and enterprise-level digital transformation.

References

[1] Lodi, G., Aniello, L., Di Luna, G. A., & Baldoni, R. (2014). An event-based platform for collaborative threats detection and monitoring. Information Systems, 39, 175-195.

[2] Hohpe, G., & Woolf, B. (2002, July). Enterprise integration patterns. In 9th conference on pattern language of programs (pp. 1-9).

[3] Evans, E. (2004). Domain-driven design: tackling complexity in the heart of software. Addison-Wesley Professional.

[4] Dragoni, N., Giallorenzo, S., Lafuente, A. L., Mazzara, M., Montesi, F., Mustafin, R., & Safina, L. (2017). Microservices: yesterday, today, and tomorrow. Present and ulterior software engineering, 195-216.

[5] Jamshidi, P., Pahl, C., Mendonça, N. C., Lewis, J., & Tilkov, S. (2018). Microservices: The journey so far and challenges ahead. IEEE Software, 35(3), 24-35.

[6] Richards, M. (2015). Microservices vs. service-oriented architecture (pp. 22-24). Sebastopol: O'Reilly Media.

[7] Newman, S. (2021). Building microservices: designing fine-grained systems. " O'Reilly Media, Inc.".

[8] Villamizar, M., Garces, O., Ochoa, L., Castro, H., Salamanca, L., Verano, M., ... & Lang, M. (2016, May). Infrastructure cost comparison of running web applications in the cloud using AWS lambda and monolithic and microservice architectures. In 2016 16th IEEE/ACM International Symposium on Cluster, Cloud and Grid Computing (CCGrid) (pp. 179-182). IEEE.

[9] Ponce, F., Soldani, J., Astudillo, H., & Brogi, A. (2022). Smells and refactorings for microservices security: A multivocal literature review. Journal of Systems and Software, 192, 111393.

[10] Reile, C., Chadha, M., Hauner, V., Jindal, A., Hofmann, B., & Gerndt, M. (2022, March). Bunk8s: Enabling easy integration testing of microservices in kubernetes. In 2022 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER) (pp. 459-463). IEEE.

[11] Sarika, P. K., Badampudi, D., Josyula, S. P., & Usman, M. (2023, June). Automating microservices test failure analysis using kubernetes cluster logs. In Proceedings of the 27th International Conference on Evaluation and Assessment in Software Engineering (pp. 192-195).

[12] Davis, C. (2019). Cloud native patterns: Designing change-tolerant software. Simon and Schuster.

[13] Muthusamy, K. (2025). Event-Driven Data Engineering in Microservices Architectures. International Journal of Emerging Trends in Computer Science and Information Technology, 6(1), 36-43.

[14] Endo, P. T., Rodrigues, M., Gonçalves, G. E., Kelner, J., Sadok, D. H., & Curescu, C. (2016). High availability in clouds: systematic review and research challenges. Journal of Cloud Computing, 5(1), 16.

[15] Vashisht, A. (2025). Microservices and Real-Time Processing in Retail IT: A Review of Open-Source Toolchains and Deployment Strategies. arXiv preprint arXiv:2506.09938.

[16] Park, J. S., Sandhu, R., & Ahn, G. J. (2001). Role-based access control on the web. ACM Transactions on Information and System Security (TISSEC), 4(1), 37-71.

[17] Dias, W. K. A. N., & Siriwardena, P. (2020). Microservices security in action. Simon and Schuster.

[18] Chatterjee, A., Gerdes, M. W., Khatiwada, P., & Prinz, A. (2022). Sftsdh: Applying spring security framework with TSD-based oauth2 to protect microservice architecture apis. Ieee Access, 10, 41914-41934.

[19] Vollem, S. (2018). Architecting real-time systems with event-driven streaming pipelines: A unified log-centric approach using Apache Kafka. Journal of Scientific and Engineering Research, 5(1), 293-303.

[20] Oyeniran, O. C., Adewusi, A. O., Adeleke, A. G., Akwawa, L. A., & Azubuko, C. F. (2024). Microservices architecture in cloud-native applications: Design patterns and scalability. International Journal of Advanced Research and Interdisciplinary Scientific Endeavours, 1(2), 92-106.

[21] Ranjan, R., Zhao, L., Wu, X., Liu, A., Quiroz, A., & Parashar, M. (2010). Peer-to-peer cloud provisioning: Service discovery and load-balancing. In Cloud computing: Principles, systems and applications (pp. 195-217). London: Springer London.

[22] Cao, Y., & Yang, L. (2010, December). A survey of identity management technology. In 2010 IEEE International Conference on Information Theory and Information Security (pp. 287-293). IEEE.

[23] Jangam, S. K., Karri, N., & Muntala, P. S. R. P. (2022). Advanced API Security Techniques and Service Management. International Journal of Emerging Research in Engineering and Technology, 3(4), 63-74.

Downloads

Published

2026-07-08

Issue

Section

Articles

How to Cite

1.
Syed Z, Patel H, Naaz J. A Scalable Microservices Architecture for Event-Based Sanctions Screening Systems. IJERET [Internet]. 2026 Jul. 8 [cited 2026 Jul. 21];7(3):64-73. Available from: https://ijeret.org/index.php/ijeret/article/view/651