A payments firm processing a trade-finance transaction discovers, mid-flow, that one of the named beneficiaries shares an exact transliteration with an entry on the OFAC SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The question is not abstract: is this a true match, a false positive, or something in between? And which of the regimes in scope – OFAC, OFSI, the EU lists, the UN Consolidated List – applies first? The answer changes the legal consequence, the reporting obligation, and the timeline for action.
Name and entity screening is the process of comparing customer, counterparty, and ownership data against designated-persons lists published by sanctions authorities. As of July 2026, businesses with a cross-border footprint must run screening against multiple parallel lists – OFAC (US), OFSI (UK), the EU consolidated list, the UN Consolidated List, and, depending on the transaction route, the national lists of Switzerland, Canada, Australia, Singapore, Japan, and the UAE. Where two or more regimes apply simultaneously, the stricter prohibition governs.
This guide walks through the screening process step by step: how to set up the list architecture, how to conduct the matching analysis, how to resolve hits across divergent regime standards, what to record, and when to escalate to counsel.
Step 1 – Map the regimes that apply to your transaction
Before you screen a single name, you need to know which lists are legally mandatory for your business. The governing principle is that jurisdiction follows nexus: OFAC reaches any US-person or US-dollar transaction; OFSI reaches any UK-person, UK-incorporated entity, or UK-routed transaction; the EU consolidated list binds any EU-incorporated entity and, under the relevant Council regulations, any transaction conducted within EU territory.
In our experience, the first mistake cross-border businesses make is treating this as a binary US-or-EU choice. A trade-finance transaction that is denominated in US dollars, cleared through a US correspondent bank, involves an EU-incorporated exporter, and is insured by a UK underwriter simultaneously engages OFAC, the EU consolidated list, and OFSI. Each imposes distinct prohibitions. The transaction must clear all three before it proceeds.
The mapping step should produce a written nexus analysis for each transaction type or counterparty category. This need not be a lengthy document, but it must record: the currencies in use, the nationalities and domiciles of all entities in the payment chain, the routing of the underlying goods (if any), and the regimes that follow from those facts. The analysis forms the audit trail. Regulators reviewing a screening failure will ask what you decided was in scope and why.
For businesses with operations in or touching Singapore, Japan, or the UAE, the layering continues. Singapore's MAS regime, Japan's METI controls, and the UAE's Executive Office lists each carry their own currency of applicability. None of them displaces OFAC or OFSI – they add to the stack. Where regimes diverge on a designation, the stricter prohibition always governs.
Step 2 – Build the list architecture: which lists, how often refreshed?
The list architecture is the technical foundation on which accurate screening depends. It must cover, at minimum: the OFAC SDN List and its sector-specific companion lists; the OFSI consolidated list; the EU Financial Sanctions database; the UN Consolidated List; and any additional national lists required by the nexus analysis in Step 1. Lists update without warning. OFAC adds and removes entries at any point; the EU publishes updates to Council regulations in the Official Journal on the date the regulation enters force.
A list that is even one day out of date can produce a false negative – you screen a name, it is clear, you proceed, and the designation that was added overnight makes the transaction a breach. In our cross-border practice, we regularly advise clients who have discovered that their screening vendor was not updating on an intraday basis. That gap is a compliance gap, not a vendor inconvenience.
The practical standard for high-volume or high-risk transaction streams is intraday refresh, with a documented update log. For lower-volume operations, a daily confirmed refresh is the floor. The refresh schedule should be formalised in the firm's screening policy and tested periodically by compliance. Each list version used for a given screening decision should be recorded: the list name, the version date, and the result. Five years is the standard minimum record-keeping period under most major regimes, though the applicable requirement varies by jurisdiction and should be verified against the rules in force.
List currency is not the only architecture question. You also need to decide whether screening is pre-transaction only, or continuous. Ongoing monitoring – screening existing customers against updated lists – is explicitly required under UK and EU financial-sanctions obligations for regulated firms, and is an expectation under OFAC's compliance-programme guidance. A counterparty that was clear on day one may be designated tomorrow.
Step 3 – Run the name-matching analysis: fuzzy logic, transliterations, and aliases
The matching stage is where screening produces both its most useful results and its most operationally costly problems. List entries frequently appear in transliterated form – an Arabic, Cyrillic, Persian, or Chinese name rendered into the Latin alphabet – and the same name can be transliterated differently across the OFAC, OFSI, and EU databases. A name that clears one list at a particular spelling may hit another list at an alternative rendering.
Matching algorithms use fuzzy-logic scoring to surface partial matches. The sensitivity threshold – the minimum score at which an alert is generated – is a core compliance decision. Set the threshold too high and false negatives increase; set it too low and your team drowns in false positives that do not represent real exposure. What is the right threshold for your transaction mix? There is no single answer, but it must be documented and justified.
Aliases and alternative name forms compound the problem. OFAC list entries carry "a.k.a." and "f.k.a." fields. The EU database includes name variants in Cyrillic, Arabic, and other scripts. OFSI entries may differ again. A screening tool that reads only the primary name field and ignores alias fields is not conducting thorough screening; it is producing a systematic blind spot.
Date-of-birth, nationality, and identification-number matching are the tie-breakers. Where a name match exists but the date of birth on file for your counterparty does not match the list entry, the probability of a false positive increases substantially. But the fields must be present in your customer data to be used. This is where KYC quality feeds directly into screening accuracy: incomplete customer records produce unreliable screening results.
In a recent matter, a financial institution in the payments sector was processing B2B transfers across three currency corridors. Its screening tool was generating a high volume of alerts on a single common name variant. The alerts were being closed as false positives without a documented matching rationale. We conducted a screening-logic review, identified the threshold configuration that was producing the surplus alerts, and redesigned the escalation matrix so that alerts with partial date-of-birth matches received a different review path from pure name matches. The change reduced false-positive volume materially while tightening the process for alerts that warranted closer examination.
Step 4 – Resolve the alert: the hit-assessment decision sequence
When an alert fires, the question is not "is this a sanction?" but "is this a match?" The two are different. An alert is a potential match; a confirmed match triggers the legal prohibition; an unresolved alert requires a hold until the analysis is complete.
The hit-assessment sequence should follow a fixed decision path:
- Retrieve the full list entry. Pull the designation record, including all aliases, identification numbers, dates of birth, addresses, and any ownership or control data attached to the listed person or entity.
- Compare against all available customer data. Name, date of birth, nationality, address, registration number, tax identification. Do the identification points align or diverge?
- Apply the relevant ownership-and-control test. If the alert is on a name in the ownership chain rather than the direct counterparty, the analysis must determine whether the listed person's interest triggers a blocking or asset-freeze obligation. OFAC applies a mechanical 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked). OFSI and the EU apply a broader ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person) that can catch entities even below the 50 percent threshold where control is exercised in other ways. The two tests can produce different results on the same facts.
- Record the analysis. Document every data point reviewed, every source consulted, and the conclusion reached. If the alert is closed as a false positive, record why. If it is escalated, record to whom and when.
- Escalate where the analysis is inconclusive. An alert that cannot be resolved on available data is not a false positive. It is an unresolved alert. The transaction must remain on hold until resolution or until a decision is made to decline.
The regime dimension matters here. A hit on the OFAC SDN List requires a block of the property and a report to OFAC within a short statutory window. A hit on the OFSI list requires an asset freeze and, for regulated businesses, reporting within the period specified in the applicable UK regulations. An EU hit requires a freeze under the relevant Council regulation. These are parallel obligations where two or more regimes apply – completing one does not discharge the others.
How does the cross-border dimension change the screening obligation?
Operating across borders does not merely multiply the number of lists; it creates points of divergence between regimes that change the substantive outcome of the same screening decision. Three areas of divergence recur most often in cross-border practice.
First, designations differ across lists. A person who is listed by OFAC may not appear on the EU list, and vice versa. A company designated by the EU under a specific thematic programme may be entirely absent from the OFAC SDN List. Clearing a counterparty against only one list does not clear them against the other. Multi-regime screening must treat each list as independent and return a clear result on each before a transaction proceeds.
Second, the ownership-and-control test diverges. OFAC's 50 percent rule is mechanical: aggregate direct and indirect ownership by blocked persons, and if it reaches 50 percent or more, the entity is treated as blocked regardless of who controls it operationally. OFSI and the EU extend the analysis to control – a listed person who directs an entity's affairs or holds effective decision-making power over it can bring that entity within the prohibition even where ownership is below the threshold. This means an entity that is clear under OFAC may be caught under OFSI or the EU rules. In our practice, we advise clients to apply the more expansive control test as the working standard, so that an entity that passes that test will also pass the more mechanical one.
Third, secondary-sanctions risk adds an extraterritorial layer. OFAC's secondary-sanctions programmes can affect non-US businesses that transact with certain designated persons or in certain sectors, even where no US nexus exists. This means a European business screening purely against EU and UK lists may still carry residual US exposure if the counterparty falls within a secondary-sanctions programme. Secondary-sanctions risk requires its own analysis and does not follow automatically from the primary-list screening result.
The position above covers the standard architecture. Your transaction mix – the counterparties, currencies, routing, and sectors involved – changes the analysis at each step. For an assessment of your screening obligations across the regimes that apply to your business, contact Calder & Vance at info@caldervance.com.
Step 5 – Record-keeping, reporting, and ongoing monitoring
Screening is not complete at the moment a transaction clears or a hit is resolved. The compliance obligation extends forward in time through record-keeping and backward through an audit trail that must survive regulatory review.
Record-keeping requirements apply across all major regimes. The record must show, at minimum: the list version used at the time of screening; the names and identifiers screened; the result returned; the disposition of any alert; and the date. Where a hit was escalated, the escalation record and the resolution must be included. Five years is the standard minimum retention period across several major regimes, but the applicable requirement for each jurisdiction should be confirmed against the relevant rules as currently in force.
Reporting obligations arise in specific circumstances. A regulated firm in the UK that identifies a customer or counterparty as a designated person under OFSI's regime must report within the period set by the applicable regulations – and must not tip off the subject of the report. Under OFAC's rules, a US person or entity holding blocked property must report that fact within a defined window and must not release the property without authorisation. These are distinct obligations that run alongside each other where both regimes apply.
Ongoing monitoring closes the gap that arises from the time between initial screening and transaction completion or customer lifecycle. A counterparty screened and cleared at onboarding may be designated at any point thereafter. Periodic re-screening of the existing customer and counterparty base – at a frequency calibrated to risk – is the standard that regulators expect. For regulated financial institutions, the obligation is typically explicit. For non-financial businesses, it is part of a defensible sanctions-risk programme.
If a transaction has already been flagged, or if a filing or report has been refused or queried, an early legal review preserves options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.
What are the most common risk flags in cross-border screening programmes?
Screening failures that surface in regulatory investigations share a recognisably short list of causes. Understanding them is the starting point for a programme that does not repeat them.
Incomplete list coverage. A programme that screens against OFAC only, or that omits the UN Consolidated List, has structural gaps. In cross-border transactions, incomplete list coverage is the single most common finding in compliance audits.
Stale lists. A list that is not refreshed on at least a daily confirmed basis is a liability. Intraday refreshes are the standard for high-volume or high-risk flows.
Inadequate alias and transliteration coverage. Screening that reads only the primary name field and ignores alias fields, alternative scripts, and transliteration variants misses exactly the cases that adversaries exploit most often. Does your tool screen all name fields in each regime's database, or only the headline entry?
Threshold misconfiguration. Matching thresholds that are set without documented justification – or that are adjusted without governance sign-off – are a finding waiting to happen. The threshold must be risk-calibrated and reviewed periodically.
Ownership analysis limited to direct counterparties. A business that screens the named counterparty but does not examine the ownership chain behind it will miss the 50 percent rule and the EU/UK control test entirely. The obligation is to know who ultimately owns and controls the entity you are dealing with.
Inconsistent alert disposition. Alerts closed without a documented matching rationale, or escalated without a clear decision record, produce an audit trail that cannot support a compliance defence. Consistency matters as much as accuracy.
No secondary-sanctions overlay. A programme that treats secondary-sanctions risk as someone else's problem leaves cross-border businesses exposed to US extraterritorial reach. Secondary-sanctions analysis should be integrated into the standard review for high-risk counterparty categories.
One misconception we regularly encounter is the belief that a clean automated alert – a result of "no match" from the screening tool – discharges the compliance obligation. It does not. The automated result is the start of the analysis, not the end. Where the counterparty operates in a high-risk sector, jurisdiction, or ownership structure, manual review of the automated output is part of a defensible programme. Compliance counsel cannot substitute the tool for judgment.
Related practices
- Sanctions compliance audit and testing – programme review and gap analysis for Australia and cross-border regimes
- Name and entity screening – cross-border guide part 2: advanced ownership analysis and control tests
- Name and entity screening – cross-border guide part 3: alert management and regulatory reporting