Podcasts
Watch videos featuring supply chain experts
Overnight, a bank's screening system generates 340 potential matches against the previous day's transaction batch. By 9 a.m., a compliance team has to work through that queue, and nearly all of it will turn out to be noise: a customer named Mohammed Ahmed flagged against a designated individual with the same common name, a shipping company flagged because its address string partially matches a sanctioned entity's old registered office. Buried in that queue, on a bad day, is one real match.
That queue is the sanctions screening process in miniature. Understanding how it actually works, from the moment a name enters the system to the moment a decision gets documented, is what separates a compliance program that catches the real match from one that either misses it or burns out its own reviewers chasing false positives.
Quick answer: Sanctions screening works by comparing the names and identifying details of transaction parties against government sanctions lists using matching algorithms, generating alerts for potential matches, and routing those alerts to a reviewer who investigates supporting details (date of birth, address, nationality, aliases) to confirm or dismiss the match before a documented decision is made and, if required, reported to the relevant authority.
Key takeaways
The sanctions screening process is not a single check. It's a sequence of steps that runs every time a new counterparty is onboarded, a transaction is executed, or a sanctions list updates.
Before any comparison happens, the system needs clean data on both sides: the sanctions list content and the counterparty information being screened. This step involves normalizing names (handling different alphabets, name order conventions, and abbreviations), parsing addresses, and capturing available identifiers such as date of birth, nationality, passport number, or, for vessels, an IMO number. Poor data quality at this stage, such as a transaction record with only a partial name, is one of the most common causes of both missed matches and false positives downstream.
The system compares the counterparty's name against every name and alias on the relevant sanctions lists using one or more matching techniques:
Most sanctions screening software blends these techniques and assigns a match confidence score, rather than relying on any single method alone.
Any comparison that crosses the system's configured match threshold generates an alert. Where that threshold is set matters enormously: set it too loose, and reviewers drown in false positives; set it too tight, and genuine matches slip through unflagged. This threshold should be calibrated based on the organization's risk profile and revisited periodically, not set once and left alone.
An alert is not a finding. It's a starting point for investigation. A reviewer examines supporting details, such as date of birth, address, nationality, passport number, or known aliases, to determine whether the alert reflects the same person or entity as the listed party, or a different party who happens to share a name.
OFAC's own guidance on resolving a potential match confirms this framing directly: when a "hit" occurs, the first questions are whether it's actually hitting against the SDN List (or another OFAC list) or a targeted country, and whether the identifying information genuinely lines up, before treating it as an actual issue. In practice, most alerts resolve as false positives once compared against a fuller identity picture.
Alerts that survive initial review typically escalate to a compliance officer or legal counsel. The outcome, whether the transaction proceeds, is rejected, or the property is blocked, gets documented with the supporting rationale. This documentation matters as much as the decision itself, because it's what a regulator or auditor will review later to assess whether the program is functioning as designed.
For U.S. persons, OFAC's recordkeeping requirements under 31 CFR Part 501 apply to the underlying transaction records, not just the final decision. As of March 12, 2025, OFAC extended its general recordkeeping period from five years to ten years for transactions subject to its regulations, and blocked property must be documented for as long as it remains blocked plus the retention period after it is unblocked. Where property is actually blocked or a transaction rejected, OFAC generally requires an initial report within 10 business days, along with annual reports for property that remains blocked as of June 30 each year.
"Sanctions lists" is often used as a catch-all term, but screening programs typically need to account for several distinct categories of list, each serving a different purpose.
| List Type | Example | What It Restricts |
|---|---|---|
| Comprehensive blocking lists | OFAC's SDN List | Full asset freeze; U.S. persons generally prohibited from any dealings |
| Sectoral or targeted lists | OFAC's Sectoral Sanctions Identifications (SSI) List | Specific categories of transactions (such as new financing beyond certain maturities) with designated sectors, without a full asset freeze |
| Regional consolidated lists | EU Consolidated List, UK Sanctions List | Financial sanctions, asset freezes, and travel bans under regional legal frameworks |
| Global lists implemented locally | UN Security Council Consolidated List | Not directly enforceable on businesses; implemented through each member state's domestic law |
| Politically exposed person (PEP) lists | Domestic and foreign PEP databases | Not a sanction itself, but a risk indicator requiring enhanced due diligence |
| Ownership and beneficial ownership data | Corporate registries, UBO databases | Used to detect indirect exposure through ownership rules like the 50% Rule, rather than name-based hits |
A common misconception is treating PEP screening as equivalent to sanctions screening. A politically exposed person is not automatically restricted from doing business; being a PEP is a risk factor that typically warrants enhanced due diligence, not an automatic block. Sanctions lists, by contrast, carry direct legal prohibitions once a party is designated.
Screening requirements vary by jurisdiction and by industry, but a few baseline principles recur across most regimes:
Requirements outside the U.S. differ in detail, though the EU, UK, and most other major sanctions authorities apply comparable expectations around screening, ownership analysis, and documentation.
Treat a match as a question, not an answer. OFAC's own guidance frames a potential match as the beginning of an inquiry: confirm the list, confirm the identifying details, and only then decide whether it's genuine. Programs that skip straight to disposition, in either direction, create risk.
Calibrate matching thresholds deliberately and revisit them. A threshold set once during implementation and never reviewed tends to drift out of step with the organization's actual customer base and risk profile. Periodic testing and tuning, one of the five components in OFAC's compliance Framework, exists specifically to catch this.
Screen beyond the primary name. Aliases, transliterations, and incomplete name fields are where genuine matches most often get missed. A screening process that only checks the primary listed name against a clean, fully formatted counterparty name will underperform against real-world data.
Build ownership analysis into the process, not around it. Since the 50 Percent Rule and equivalent international provisions create liability that name-based screening cannot detect, ownership and beneficial ownership checks need to run alongside name screening, not as a separate, occasional exercise.
Re-screen continuously, not just at onboarding. Sanctions lists change without a fixed schedule. A counterparty screened clean six months ago is not necessarily clean today, and ongoing monitoring is what catches a change in status before it results in a live transaction issue.
Document the reasoning, not just the outcome. A cleared alert with no documented rationale looks the same to an auditor as an alert that was never actually reviewed. The rationale, not just the disposition, is what demonstrates a functioning program.
Match retention practices to current rules. With OFAC's recordkeeping period now extended to 10 years, programs still operating on a five-year retention assumption are out of step with current requirements.
Manual review can handle low volumes of straightforward name checks, but the mechanics described above, fuzzy and phonetic matching, threshold calibration, ownership tracing, and continuous re-screening, are difficult to sustain manually once transaction or counterparty volume grows. This is the operational gap that dedicated sanctions screening software is built to close, and it's covered in more depth in our guides to sanctions screening and global sanctions compliance and denied party screening software.
Trademo's Sanctions & PEP Screening applies AI-assisted matching, including alias, phonetic, and transliteration handling, across more than 675 global sanctions, PEP, and restricted-party lists sourced from 440-plus government and regulatory sources, refreshed on a six-hour cycle, with a full audit trail across search history, matched lists, and reviewer disposition for every screening e