The False Positive Crisis
Sanctions screening is among the most operationally intensive obligations in financial services compliance. Major global banks screen hundreds of millions of transactions daily against lists that collectively contain hundreds of thousands of names, entities, and identifiers. Yet the ratio of genuine hits to false positives in most programmes ranges from 1:100 to 1:1,000 — meaning that for every true match escalated to compliance, analysts are reviewing and dismissing dozens or hundreds of irrelevant alerts.
This is not a marginal efficiency problem. In large institutions, sanctions screening operations employ hundreds of analysts. Alert fatigue is real and dangerous: analysts processing thousands of false positives per day are statistically more likely to dismiss a genuine hit as noise. The problem is both a cost driver and a compliance risk.
Improving this ratio requires a technically rigorous approach to matching methodology, list management, and workflow design — while maintaining absolute coverage of confirmed sanctioned parties.
---
Understanding Sanctions Lists
Effective screening starts with understanding what you are screening against.
OFAC (US Treasury Office of Foreign Assets Control):
The Specially Designated Nationals (SDN) List is the primary US sanctions list, maintained in real time. OFAC also maintains the Consolidated Sanctions List, which includes the SSI (Sectoral Sanctions Identifications) List, Foreign Sanctions Evaders list, and Non-SDN Palestinian Legislative Council List, among others. US persons — including US financial institutions and their foreign branches — must comply with all OFAC lists. Non-US institutions face compliance obligations as they relate to USD transactions, correspondent relationships, and US counterparty exposure.
EU Consolidated Sanctions List:
Maintained by the European Commission, covering sanctions regimes for Russia, Iran, Syria, North Korea, Belarus, and dozens of country- and theme-based programmes. Significant expansion post-2022 has made EU list management substantially more complex.
UK OFSI (Office of Financial Sanctions Implementation):
Post-Brexit, the UK maintains its own sanctions regime. UK sanctions largely mirror EU designations for existing regimes, but divergences are increasing — particularly for Russia-related designations.
FATF Blacklist/Greylist:
Not a sanctions list per se, but designations as high-risk or under increased monitoring carry AML programme implications and affect correspondent banking decisions.
Other lists:
UN Consolidated List, HMT Consolidated List, Australian DFAT list, and numerous sector-specific and country-level lists. Global screening programmes typically screen against 30-50 distinct lists.
---
Name Matching: The Technical Core of Screening
The primary source of false positives is imprecise name matching — algorithms that generate hits for names that sound or look similar to a sanctioned party but bear no other relationship.
Fuzzy Matching and Its Problems
Phonetic algorithms (Soundex, Metaphone, Double Metaphone) and edit-distance algorithms (Levenshtein distance, Jaro-Winkler) are widely used to catch transliteration variants, spelling errors, and name variations across scripts. They are necessary — a sanctions evader will not helpfully use the exact same name formatting as their OFAC entry — but they are the primary generator of false positives.
Common false positive scenarios:
- Common names in screening geographies: "Mohammed Ali" generates hits against multiple SDN entries across different individuals with no relationship to the subject
- Business name similarities: "Russia Trade Services" matching against Russia-related SDN entries on the basis of the word "Russia" appearing in both
- Transliteration multiplicity: Arabic, Chinese, Persian, and Cyrillic names can be romanised in dozens of legitimate variants, creating both false positive and false negative risks depending on the algorithm
Reducing False Positives Without Losing Coverage
Date of birth matching: Where DOB is available both from the customer record and the sanctions entry, DOB-confirmed non-matches should be suppressible. OFAC provides DOBs for individual SDN entries where available. DOB matching requires careful handling — many customers don't provide exact DOBs, and many sanctioned individuals have partial or multiple DOBs listed.
Nationality and country matching: Individual SDN entries frequently include nationality. A customer with a British passport whose name matches an Iranian SDN entry can have the confidence threshold adjusted based on the nationality mismatch — without automatically dismissing the match if other factors are present.
Identifier matching: Passport numbers, tax IDs, and IMO numbers (for vessels) provide high-confidence matching where available. Programmes should be designed to use identifier-based matching as a primary path and name matching as a secondary/catch-all layer.
Entity type matching: Screening "Jones Manufacturing Ltd" against individual-person SDN entries should carry a lower confidence weight than screening it against entity entries.
Minimum name length thresholds: Very short or very common words in screening names (e.g. "Ali", "Kim", "Lee") should carry reduced weight in matching algorithms unless accompanied by other corroborating fields.
Structured vs Unstructured Data
Payment messaging standards (SWIFT MT, ISO 20022) provide structured fields for name and address data. Unstructured narrative fields — payment references, memo lines — are a significant source of false positives because they contain contextual text that includes sanctioned-party names incidentally. "Payment for oil — not related to Russia" contains "Russia." Structured field matching is more precise; unstructured field matching requires more aggressive filtering with compensating controls.
---
List Management: Version Control and Update Cadence
OFAC updates the SDN list frequently — sometimes multiple times per day when major designations occur. EU and UK lists update with less frequency but have seen rapid expansion since 2022 in the context of Russia sanctions.
Operational requirements:
- New list versions must be ingested and deployed to screening engines within a defined SLA — typically within 24 hours for normal updates, with emergency procedures for major batch additions
- List version control must be maintained so that the list version in use at the time of each transaction screen can be reconstructed for audit purposes
- List additions must be applied retroactively to the extent required by the relevant sanctions regime — OFAC's 50% Rule means that entities 50% or more owned by SDN parties are themselves blocked even if not individually listed
---
Workflow and Escalation Design
Even with excellent matching algorithms, some alert volume is inevitable. Workflow design determines how efficiently genuine hits are identified.
Risk-tiered review: Not all alerts carry the same risk. A transaction from a politically exposed person (PEP) with a name that phonetically matches an SDN should be reviewed more urgently than a small consumer payment with a name that shares two characters with a sanctioned entity. Queue management should reflect this risk differentiation.
Pre-populated dismissal reasons: Analysts should have structured dismissal reasons available (DOB mismatch, nationality mismatch, entity type mismatch, known false positive) that generate a documented audit trail. Unstructured "not a match" dismissals are a regulatory risk.
Known false positive suppression: Where an alert has been reviewed and dismissed multiple times — always for the same reason — it can be systematically suppressed with documented rationale and management sign-off. This is the single highest-ROI efficiency measure available to mature programmes.
Escalation paths: Genuine potential matches must escalate to a designated sanctions officer with authority to block or release transactions. Escalation SLAs — typically two to four hours for real-time transactions — must be defined and monitored.
---
The 50% Rule and Beneficial Ownership
OFAC's 50% Rule states that any entity owned 50% or more (directly or indirectly) by an SDN is itself blocked, even if not individually listed. This is arguably the most compliance-risky element of the US sanctions framework because it requires institutions to screen beneficial ownership chains — not just the transacting entity — against the SDN list.
Practically, this requires:
- Beneficial ownership data collection at onboarding for corporate customers, to the natural person level
- Ongoing monitoring for changes in beneficial ownership
- Screening of all identified beneficial owners against sanctions lists
- Documented procedures for handling indirect ownership scenarios where a partial ownership chain can be confirmed but cannot be traced to a definitive conclusion
RiskLex provides financial crime intelligence that supports sanctions programme design, including guidance on beneficial ownership standards and emerging sanctions regime developments. Explore RiskLex to see how structured intelligence supports your compliance team.
