Sanctions List

A sanctions list is a published register of people, entities, vessels and aircraft that a government or international body has restricted dealings with. Screening against one is a legal obligation for financial institutions and many other businesses. The critical thing to understand about these lists is that they are not a complete inventory of restricted parties — ownership rules extend the restrictions well beyond the names printed on them.

Principal U.S. list The OFAC Specially Designated Nationals and Blocked Persons List (SDN List)
Other U.S. lists OFAC’s Consolidated Sanctions List, covering non-SDN programs
International UN Security Council Consolidated List; EU Consolidated List; UK OFSI Consolidated List
Administered by (U.S.) The Office of Foreign Assets Control, U.S. Department of the Treasury
Liability standard (U.S.) Strict — a violation does not require intent or knowledge
The 50 Percent Rule Entities owned 50% or more, in aggregate, by blocked persons are blocked even if unnamed
Update frequency Continuously, without notice
Core screening difficulty Name variation, transliteration, and sparse identifying data on many entries

The rule that makes the list insufficient

This is the point most summaries omit, and it changes how screening has to be designed.

Under OFAC’s 50 Percent Rule, any entity owned 50 percent or more — directly or indirectly, individually or in aggregate — by one or more blocked persons is itself blocked, whether or not it appears on the SDN List. The list names the designated parties; the rule captures everything they control.

Two consequences follow. A company can be fully blocked while being entirely absent from every published list, so a clean name match is not a clean result. And because the rule aggregates across multiple blocked owners, two designated individuals holding 30 and 25 percent of a company block it between them, even though neither reaches the threshold alone. Establishing this requires beneficial ownership data, not list data — which is why beneficial ownership and sanctions compliance are the same problem viewed from two directions.

Why screening is harder than matching

Sanctions screening looks like a lookup and behaves like a fuzzy-matching problem with legal consequences on both sides.

Difficulty Why it arises
Transliteration Names originating in non-Latin scripts have many valid English renderings
Aliases Entries carry numerous known aliases, and designated parties adopt new ones
Sparse identifiers Many entries have no date of birth or identification number to disambiguate against
Common names A frequent name generates large numbers of false matches against ordinary customers
Constant change Lists update without notice, so a screen is only valid as of the moment it ran
Threshold setting Loosen it and false positives overwhelm analysts; tighten it and true matches escape

The threshold problem has no clean answer. The cost of a false negative is a strict-liability violation; the cost of a false positive is an analyst’s time and a delayed customer. Institutions generally tune toward over-matching and absorb the review burden, which is why alert volume is the usual operational complaint about sanctions programs.

Why this matters for identity verification

Screening compares a name against a list. Everything it produces depends on that name being correct and belonging to the person who presented it — and nothing in the screening process itself establishes either.

The failure runs in both directions. A customer who opened an account with a false or synthetic identity is screened under a name that was never theirs, so the screen is accurate and meaningless. And weak identity data makes disambiguation impossible: matching a common name with no date of birth against an SDN entry with no date of birth cannot be resolved, so it goes to manual review and stays there.

Verifying identity against an authenticated document supplies exactly what screening needs — a name taken from an issuing authority rather than a keyboard, with a date of birth and document number to disambiguate against. That reduces false positives and makes true matches meaningful, which is the practical argument for pairing identity document verification with AML, PEP and sanctions screening rather than treating them as separate steps.

What a sanctions list can’t do

It does not list every blocked party. The 50 Percent Rule blocks entities that appear nowhere on it, and identifying them requires ownership data.

A clean screen is not a defense. U.S. sanctions liability is strict. Screening diligently and missing a party is still a violation.

It is out of date the moment it is downloaded. Designations take effect on publication, without notice, which is the argument for ongoing monitoring rather than a check at onboarding only.

It cannot disambiguate on its own. Many entries carry too little identifying data to separate a designated person from an ordinary customer with the same name.

Frequently asked questions

What is the SDN List?

The Specially Designated Nationals and Blocked Persons List, maintained by the U.S. Treasury’s Office of Foreign Assets Control. It names individuals, entities, vessels and aircraft whose property is blocked and with whom U.S. persons are generally prohibited from dealing.

What is the OFAC 50 Percent Rule?

Any entity owned 50 percent or more — directly or indirectly, and in aggregate across multiple blocked owners — by designated persons is itself blocked, even though it does not appear on any published list. It means a clean name match against the SDN List does not establish that a counterparty is permissible.

How often do sanctions lists change?

Continuously and without advance notice. Designations take effect on publication, so a screen is only valid as of the moment it ran. This is why ongoing monitoring against updated lists is expected rather than a one-time check at onboarding.

Why does sanctions screening produce so many false positives?

Because it matches names that vary in transliteration and spelling, against list entries that frequently lack a date of birth or identification number to disambiguate. Institutions tune toward over-matching because a missed true match is a strict-liability violation, so the false-positive burden is a deliberate trade.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data