Sanctions Intelligence (SANCINT): Intelligence Discipline Guide
A sanctions hit is not a finding. It is the start of one, and the work is proving whether the name in front of you is the designated party, and whether control runs to them through people who were never listed.
A sanctions hit is not a finding. It is the start of one, and the work is proving whether the name in front of you is the designated party, and whether control runs to them through people who were never listed.
What Sanctions Intelligence is as a discipline
Sanctions intelligence is the practice of screening people, companies, vessels, aircraft and assets against designation regimes and then adjudicating what the screen returns. It combines list management across OFAC, EU, UN, UK and national regimes, name matching across scripts and transliterations, ownership and control analysis, and evidence-backed disposition of every alert. The discipline is as much about clearing false positives at scale as catching true matches, and about detecting the structures designated parties build to keep moving value after the designation lands.
Sub-methods include list ingestion and normalisation, fuzzy and phonetic matching tuned per script, politically exposed person and adverse-media adjacency, ownership aggregation under the fifty percent rule, and typology-driven evasion detection covering front companies, layered shipping ownership and trade-based value transfer. In the intelligence cycle it lives mainly in processing and analysis: collection is largely public, and the value sits in disambiguation, aggregation and timely re-screening as lists change.
Why it matters
Only sanctions intelligence answers whether a counterparty, payment or shipment is legally prohibited rather than merely uncomfortable. It separates a coincidental name collision from a designated person, establishes whether an unlisted company is nonetheless blocked through aggregated ownership, and identifies the successor entities that appear in the weeks after a designation. It also defines what remains permitted under general licences and wind-down authorisations, which is a question no generic risk score can answer.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Alias and transliteration matches supported or broken by hard identifiers such as date of birth, passport number or company registration number.
- Ownership chains where designated parties hold aggregated stakes crossing the fifty percent threshold through several unlisted intermediaries.
- Company formations in the weeks after a designation sharing directors, registered addresses or contact numbers with the designated entity.
- Vessels changing flag, name, registered owner or transponder behaviour shortly after a designation touches their operator or charterer.
- Trade routes rerouted through non-implementing jurisdictions with re-invoicing at prices detached from published market benchmarks.
- Delisting, amendment and correction notices that change the legal position of a counterparty you previously blocked or cleared.
- Formation-agent addresses reused across dozens of registered entities, indicating a service provider working for designated networks.
- The precise scope of general and specific licences, which defines what business remains lawful rather than prohibited.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- OFAC SDN and Consolidated Sanctions List — US designations with aliases, identifiers, vessel and aircraft detail, plus dated action notices
- EU Consolidated Financial Sanctions List — EU designations in structured format with legal basis and regulation references per entry
- UN Security Council Consolidated List — Designations binding on all member states, with narrative summaries of reasons for listing
- UK OFSI Consolidated List — UK asset freeze targets with identifiers, group references and dated amendments
- OpenSanctions — Aggregated, deduplicated sanctions, PEP and watchlist data with cross-references and bulk access
- GLEIF LEI data — Legal entity identifiers with parent relationships, anchoring ownership analysis to a register
- National company and beneficial ownership registers — Shareholding, director and address data that ownership aggregation depends on
- FATF public statements — Jurisdictions under increased monitoring or countermeasures, shaping regime and typology context
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Set the regime perimeter — Determine which regimes bind the client through nationality, currency, incorporation, personnel and supply nexus, then document that reasoning before screening anything.
- Ingest and normalise lists — Load each authoritative list with its publication date, normalise names and identifiers, and keep the original record so an alert can be traced back.
- Screen and tune — Run matching with thresholds tuned per script and name type, then measure false positive and false negative behaviour against a labelled test set.
- Adjudicate with identifiers — Resolve each alert using date of birth, passport, registration or address data, and record the evidence that confirmed or discounted the match.
- Trace ownership and control — Aggregate direct and indirect holdings across registers, and assess control rights that never appear as shareholdings, such as board appointment powers.
- Test evasion hypotheses — Check for post-designation formations, address and director reuse, routing changes, and pricing inconsistent with market benchmarks.
- Record and re-screen — Store the disposition with its evidence, then re-screen the book on every list update because designations and delistings change positions daily.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Applied in these mission domains
- Weapons Trafficking
- Mining & Resource Crime
- Financial Crime
- Anti-Money Laundering
- Sanctions Evasion
- WMD / Proliferation
- Energy Security
- Maritime Security
- Aviation Security
Operates on these data points
- Company / Organization — A legal entity — corporation, LLC, NGO, or business.
- Shipment / Bill of Lading — A consignment record linking shipper, consignee, goods, and route.
- Sanction / Watchlist Entry — An entry on a sanctions list, watchlist, or PEP database.
- HS Commodity Code — The Harmonized System code classifying a traded good — the key to trade-flow analysis.
- Vessel / Ship — A maritime vessel identified by IMO, MMSI, or call sign.
- Location / Coordinates — A geographic point, place, or region — the basis of GEOINT analysis.
- GPS Coordinates — Precise latitude/longitude coordinates identifying an exact point on Earth — the atomic unit of GEOINT analysi
- Facility / Site — A physical installation — plant, base, port, data centre — with a fixed footprint and function.
- Cryptocurrency Address — Blockchain wallet address for receiving or sending crypto assets.
- Person / Name — A named individual — the subject of identity resolution and profiling.
Related disciplines
- Accounting Intelligence — Financial Statements and Accounting Analysis
- Corporate Intelligence — Understanding Companies, Structure, and Control
- Cryptocurrency Intelligence — Tracing Value on Public Ledgers
- Economic Intelligence — Economic Conditions, Trade, and Market Signals
- Financial Intelligence — Following Value Through the Financial System
Inside the platform: where Sanctions Intelligence lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
discipline.php?d=SANCINT— Discipline hubsource-catalog.php?disc=SANCINT— Source catalogue filtered to this disciplinesearch.php— Company / Organization profilesanctions.php— Sanction / Watchlist Entry profiledomain.php?d=mar— Vessel / Ship profilecorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Export STIX/MISP
- Correlate Infrastructure
- Run Alert Rules
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Set the regime perimeter is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Screen and tune turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Record and re-screen feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Sanctions Intelligence
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence analysts use sanctions intelligence to understand adversary procurement and revenue rather than to enforce designations. It supports interdiction and boarding decisions under Security Council authorisations, identifies vessels and operators associated with prohibited transfers, and informs force protection by screening local contractors, landlords, fixers and logistics providers before a contract is let. It feeds J2 reporting on economic pressure effects and supports intelligence preparation of the environment by mapping which supply routes remain open to a sanctioned actor. Constraints are firm: designation and enforcement authority rests with treasury and customs bodies, military reporting must not substitute for a competent authority determination, and evidence handed to civil authorities must be releasable.
🕵 National intelligence
National agencies run sanctions work as a requirements-driven collection and fusion problem. The requirement is rarely does this name appear on a list; it is how does the designated network still move value, and who are the unlisted facilitators. Analysts fuse open designation data with financial reporting, trade records, communications derived reporting and partner liaison, then build designation packages for treasury or foreign ministry action. Product handling matters: the evidentiary core of a package must be releasable to the designating body and often to courts on challenge, so tearlines and sanitised annexes are drafted from the outset. Dissemination extends to allied regimes to keep multilateral designations aligned.
👮 Law enforcement
Investigators treat a screening hit as a lead, not a fact. Establishing the offence requires proving the counterparty is the designated party, that the defendant knew or should have known, and that a prohibited transaction occurred. That means dated snapshots of the list as it stood on the transaction date, hashed and exhibited, plus production orders or account monitoring orders for bank records and MLAT requests for foreign registry and payment data. Ownership and control findings need registry certificates rather than aggregator extracts. Tipping-off provisions restrict what may be disclosed to the subject, and disclosure duties require retention of the exculpatory material that cleared alternative candidates.
🔍 Private investigation and corporate security
Corporate compliance and private investigators run screening for onboarding, third-party due diligence, transaction review and litigation support. The value added is adjudication: showing why a fuzzy hit is or is not the designated party, and evidencing aggregated ownership from primary registry filings. A private actor may not obtain bank records, tax filings or telephony data without legal process, may not deceive a target into disclosing beneficial ownership, and may not run pretext calls to registries. Where a confirmed match arises, the lawful route is escalation to the client's money laundering reporting officer and the competent authority, not independent action or informal warnings to counterparties.
📰 Journalism and OSINT media
Newsrooms use sanctions data to establish that a person or company is legally designated and to trace successor structures. The verification standard is the primary designation notice from the issuing authority, quoted with its date and legal instrument, never an aggregator record alone. Common-name collisions are the main publication risk, so hard identifiers such as date of birth, passport number or registration number must anchor the identification before a name is printed. Right of reply is offered to the named party and to any unlisted company being described as controlled. Corrections policy matters because delistings and amendments change the legal position after publication.
🌍 NGO, humanitarian and human rights
Humanitarian organisations need sanctions intelligence defensively: to keep programmes lawful, to argue for licences and exemptions, and to document the harm caused by over-compliance. Analysts map which counterparties, banks and suppliers in a response area are actually restricted rather than merely uncomfortable, then evidence that distinction to correspondent banks that have de-risked an entire corridor. Documentation for accountability includes recording denied payments, delayed shipments and closed accounts with dates and reasons. Duty of care extends to local staff who may be exposed by screening records, so partner data is minimised, and vetting is limited to what the donor agreement genuinely requires rather than blanket collection.
🎓 University and research
Researchers study designation regimes for effectiveness, spillover and evasion typologies. Reproducibility depends on archiving dated list snapshots, because regimes amend and delist continuously and an undated screen cannot be replicated. Matching methodology must be published in full: normalisation rules, transliteration handling, threshold settings and the adjudication protocol for borderline scores. Ethics review is required where individuals are profiled, and outputs should report false-positive and false-negative rates rather than raw hit counts. Data sharing is constrained by aggregator licences, so publish code and derived statistics with pointers to the authoritative public lists rather than redistributing licensed extracts.
Playbook: working Sanctions Intelligence end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Scope the screening question
Establish which regimes bind the client or programme by nexus: currency of settlement, incorporation, ownership, staff nationality and place of performance. Write the applicable regime list down and date it. Decide whether the requirement is onboarding screening, transaction screening, portfolio remediation or an evasion investigation, because each drives a different threshold and evidence standard. A good output is a one-page scope note naming the regimes in force, the entity population in scope, the match threshold, and who signs off a block. Stop when the scope note is approved by the person accountable for the decision.
Phase 2 — Ingest and normalise the lists
Pull the authoritative machine-readable files directly from the issuing authorities rather than a single aggregator, and record the publication timestamp and file hash of each. Normalise names across scripts, expand aliases and weak aliases, split composite records, and preserve hard identifiers such as date of birth, place of birth, passport and national identity numbers, registration numbers and vessel IMO numbers. Retain the original record untouched alongside the normalised form. A good output is a versioned list store where any historic screen can be re-run against the list as it stood on any past date.
Phase 3 — Prepare the subject data
Clean the counterparty side before matching. Reconcile legal name against registry filings, capture jurisdiction, registration number, incorporation date and registered address, and separate trading names from legal names. For individuals, capture full name order, transliteration variants, date of birth and nationality where lawfully held. Poor subject data produces both missed matches and alert floods, and no threshold tuning fixes it. A good output is a subject record where every attribute has a source and a date. Stop when the identifier coverage is good enough that a match can be confirmed or broken on evidence.
Phase 4 — Run the match and triage
Apply deterministic matching on strong identifiers first, then scored fuzzy and phonetic matching tuned per script, since Latin, Cyrillic and Arabic name structures need different rules. Triage output into three lanes: confirmed on hard identifier, discountable on hard identifier contradiction, and requiring investigation. Record the algorithm version and threshold with every alert so the result is reproducible. A good output is a queue where the investigative lane is small enough to be worked properly. Stop tuning when a labelled test set shows false negatives are not being traded away for a smaller queue.
Phase 5 — Adjudicate the alerts
Work each investigative alert to a documented disposition. Seek the identifier that decides it: a differing date of birth, a registration number that does not exist in the claimed jurisdiction, a passport series inconsistent with the issuing state. Negative evidence is as valuable as positive and must be recorded, because the next analyst will otherwise repeat the work. Write the reasoning in a sentence a regulator could read cold. A good output is an alert file with the evidence attached, the decision, the decision maker and the date. Stop when every alert has an evidenced disposition.
Phase 6 — Resolve ownership and control
Move beyond the named entity to aggregated ownership. Pull primary registry filings, shareholder registers and beneficial ownership declarations, then aggregate holdings of designated parties across the chain to test the fifty percent threshold in the relevant regime, and separately test control through board appointment rights, veto rights, financing dependence or acting-in-concert arrangements. Note that control tests differ between OFAC, EU and UK guidance. A good output is a diagrammed chain with a source document cited at every edge. Stop when the chain either crosses the threshold or is broken by a documented, verifiable holding.
Phase 7 — Test for evasion structures
Where a designation is recent, look for the structures that follow it: new incorporations sharing directors, addresses or contact details with the designated entity, transfers of shareholding to relatives or long-serving employees, vessels changing name, flag or registered owner, and re-invoicing through non-implementing jurisdictions. Compare formation dates against designation dates. Corporate service provider addresses reused across many entities are a strong cue. A good output is a named set of candidate successor entities with the shared attributes evidenced. Stop when candidates are either evidenced to the standard the client can act on or explicitly parked as unproven.
Phase 8 — Check licences and exemptions
Determine what remains lawful. Read the general licences, wind-down authorisations, humanitarian carve-outs and derogations applicable to the regime and the sector, and record their expiry dates. Many blocks are unnecessary because the activity is expressly authorised, and over-blocking humanitarian and remittance flows is itself a regulatory and ethical failure. A good output is a note stating exactly which activities are permitted, under which authorisation, until when, and what conditions attach. Stop when the operational teams have a clear, dated answer rather than a general instruction to avoid the jurisdiction.
Phase 9 — Decide and document
Produce the decision record: block, clear, exit, or escalate for a specific licence application. State the regimes considered, the evidence relied on, the identifiers that confirmed or broke the match, the ownership analysis and the licence position. Where the decision is to exit a relationship, record why calibrated mitigation was not sufficient. A good output is a file that a supervisory examiner or a court could follow without a briefing. Stop when the accountable decision maker has signed and the record is stored immutably with its supporting artefacts.
Phase 10 — Report and preserve
Where a confirmed match or a suspicion of evasion arises, follow the reporting duties owed to the competent authority within the prescribed period, and observe the prohibition on tipping off the subject. Preserve the entire evidence file including the list snapshot, the match output, the registry documents and the internal correspondence, hashed and time-stamped. A good output is a report that the authority can act on without follow-up requests. Stop when the report is filed, acknowledged where the regime provides for acknowledgement, and the internal preservation hold is in place.
Phase 11 — Re-screen on change
Sanctions positions decay. Re-screen the portfolio whenever a bound regime publishes an amendment, and on a fixed periodic cycle for the rest. Watch for delistings and corrections as closely as new designations, because continuing to block a delisted party creates its own liability. Re-run ownership analysis when a registry filing changes, not only when a list changes. A good output is a change log showing which relationships changed status, when, and on what trigger. Stop only when the relationship ends, since dormant accounts still carry the obligation.
Phase 12 — Review the model
On a defined cadence, test the screening system rather than the alerts. Run a labelled set of known true matches and known collisions through the current configuration, measure false negatives explicitly, and check that new alias types, scripts and identifier formats are handled. Review a sample of cleared alerts to see whether adjudication quality has drifted. A good output is a tuning report with before-and-after error rates and a documented rationale for any threshold change. Stop when the results are recorded and any configuration change is version controlled and approved.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| OFAC Specially Designated Nationals and Blocked Persons List | Open | US Treasury designations with aliases, addresses, identifiers, vessel and aircraft data, plus sectoral and non-SDN lists. | Primary authority for US designations; provides the hard identifiers used to confirm or break a name match. |
| EU Consolidated Financial Sanctions List | Open | Consolidated list of persons and entities subject to EU restrictive measures, published with legal basis references. | Establishes EU designation status and the regulation under which a restriction applies, needed for legal-basis citation. |
| EU Sanctions Map | Open | Regime-by-regime overview of EU restrictive measures showing scope, legal instruments and sectoral measures by country. | Determines which regime applies to a given country or sector before screening, and locates the governing regulation. |
| United Nations Security Council Consolidated List | Open | Names designated under all Security Council sanctions committees, with narrative summaries of reasons for listing. | Baseline multilateral designations that member states are obliged to implement; narratives support ownership and network work. |
| UK OFSI Consolidated List of Financial Sanctions Targets | Open | UK designations with identifiers, group IDs and listing dates, alongside guidance and licensing information. | Authority for UK financial sanctions status and for the UK ownership and control test, which differs from OFAC guidance. |
| OpenSanctions | Open | Consolidated, machine-readable aggregation of global sanctions lists, politically exposed persons and related entity data. | Fast cross-regime coverage and entity linkage for triage; always confirmed against the issuing authority before action. |
| GLEIF Legal Entity Identifier data | Open | Global register of legal entity identifiers with legal name, address, registration authority and direct and ultimate parent relationships. | Disambiguates similarly named companies and provides a documented parent chain to start ownership aggregation. |
| OpenCorporates | Registration | Aggregated company registry data across many jurisdictions with officers, filings and cross-jurisdiction identifiers. | Locates candidate entities and directorship overlaps that indicate successor structures after a designation. |
| Open Ownership register | Open | Beneficial ownership data published to the Beneficial Ownership Data Standard from participating jurisdictions. | Supports aggregated ownership analysis where a jurisdiction publishes beneficial owners rather than only legal shareholders. |
| IMO Global Integrated Shipping Information System | Registration | Official ship particulars, registered owner and company data, and history of name, flag and ownership changes. | Tests whether a vessel changed identity or ownership close to a designation date affecting its operator or charterer. |
| Equasis | Registration | Ship safety and identity database aggregating class, inspection, ownership and management information from multiple providers. | Corroborates registered owner, manager and technical operator when a designation touches a maritime chain. |
| UN Comtrade | Open | Reported bilateral merchandise trade statistics by commodity, partner and period, with mirror data from both sides. | Detects rerouting and re-invoicing patterns by comparing declared trade flows against mirror statistics after a designation. |
| World Bank listing of ineligible firms and individuals | Open | Entities debarred or cross-debarred from World Bank financed contracts following sanctions proceedings. | Adds a distinct integrity restriction that is not a financial sanction but is relevant to counterparty adjudication. |
| ICIJ Offshore Leaks Database | Open | Structured records from leaked offshore service provider files linking entities, intermediaries and beneficial owners. | Generates leads on historic offshore structures around a designated party; used as a lead source, never as proof. |
| Basel AML Index | Registration | Country-level money laundering and terrorist financing risk scores built from public governance and compliance indicators. | Contextualises jurisdiction risk when assessing whether a routing change after designation is commercially plausible. |
| FATF public statements and jurisdiction lists | Open | Standards, mutual evaluation reports and lists of jurisdictions under increased monitoring or subject to countermeasures. | Frames the control expectations regulators apply and identifies jurisdictions where evasion routing is most likely. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Sanctions Intelligence. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- Screening engine with configurable fuzzy matching — Applies deterministic and probabilistic name matching across scripts at portfolio scale. Limitation: tuning to reduce alert volume silently increases false negatives unless measured against a labelled set.
- Versioned list store with dated snapshots — Retains every published version of each list so a historic screen can be reproduced. Limitation: requires disciplined ingestion from authorities, since aggregator history is often incomplete.
- Transliteration and name normalisation library — Handles Arabic, Cyrillic, Chinese and Korean name structures and romanisation variants. Limitation: no single scheme covers all naming conventions, so per-script rules must be maintained by hand.
- Corporate registry aggregators — Provide cross-jurisdiction company and officer search from a single interface. Limitation: coverage and freshness vary sharply, and extracts are not certified filings acceptable as evidence.
- Graph and link analysis platform — Visualises ownership chains, shared directors and shared addresses across large entity sets. Limitation: graphs suggest association, not control, and unweighted edges overstate the strength of shared-address links.
- Vessel tracking and maritime data services — Combine transponder history with ownership and port call data to show behaviour changes. Limitation: transponder data can be spoofed or switched off, so gaps require independent corroboration.
- Adverse media screening with entity resolution — Surfaces reported allegations tied to a resolved entity rather than a keyword. Limitation: reporting quality is uneven and repetition across syndicated outlets can be mistaken for corroboration.
- Case management with immutable audit trail — Records every alert, disposition, decision maker and attached evidence item. Limitation: only as good as the adjudication text, which must be written for an external reader rather than internal shorthand.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Export STIX/MISP — Streams the selection in CTI standard formats for sharing with partners and ISACs.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Screening is an evidence discipline, not a search discipline. The decisive artefact is usually a single hard identifier that either confirms or destroys the match, so spend the effort finding a date of birth or registration number rather than reading more adverse media.
- Record negative evidence with the same rigour as positive. A documented note that the subject's passport series is inconsistent with the designated party saves the next analyst hours and defends the clearing decision if it is ever examined.
- Ownership and control tests differ materially between regimes. Aggregation of holdings, treatment of indirect chains and the weight given to non-equity control are not the same under OFAC, EU and UK guidance, and applying one test globally produces both over-blocking and gaps.
- Date everything against the list version in force at the time of the transaction. A screen that was correct on the day it ran is not made wrong by a later designation, and a defence often rests on proving what the list said then.
- Delistings deserve the same monitoring intensity as designations. Continuing to block a delisted counterparty causes real commercial and humanitarian harm and is a defensible complaint against the screening programme.
- Treat the weeks after a designation as the highest-yield collection window. New incorporations, share transfers to family members, vessel renamings and address changes cluster tightly in that period and are visible in primary filings before any list reflects them.
- Aggregator hits are triage, not authority. Always pull the designation notice from the issuing body before a block, a report or a publication, because aggregator records lag amendments and occasionally carry transcription errors in identifiers.
- Blanket de-risking is a failure mode, not a control. Where a regime provides humanitarian carve-outs or general licences, read them and write down what remains permitted, because exiting a whole corridor transfers risk to people who cannot absorb it.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Sanctions Intelligence is producing anything, and they are worth baselining before you change process or tooling.
- Proportion of alerts closed with a hard identifier cited in the disposition, rather than closed on analyst judgement alone. Rising share indicates the evidence discipline is holding under volume.
- False-negative rate measured against a maintained labelled test set of known matches and known collisions, reviewed after every threshold or algorithm change.
- Median time from publication of a designation amendment by a bound regime to completion of portfolio re-screening, measured per regime rather than in aggregate.
- Share of ownership determinations supported by primary registry filings rather than aggregator extracts, tracked separately for high-risk jurisdictions.
- Number of humanitarian or remittance relationships retained under an identified general licence or carve-out, as a counterweight to exit volume.
- Rate at which regulator or auditor sampling of cleared alerts finds the reasoning adequate without further explanation from the analyst.
- Count of successor or facilitator entities identified before they appear on any list, later validated by a subsequent designation or a corroborated finding.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Treating a name match as a designation. Without identifiers or ownership evidence the alert is unresolved, not confirmed.
- Screening against one regime because the payment looked domestic. Applicability follows legal nexus, not intuition about currency.
- Ignoring ownership aggregation, which captures entities that never appear on any list under their own name.
- Working from a stale list snapshot, so a clean screen taken last month proves nothing about today.
- Match thresholds tuned on English names that quietly miss Arabic, Cyrillic and Chinese transliteration variants.
- Confusing sanctions with export controls or entity lists. Different authorities, different prohibitions, different consequences.
Legal and ethical considerations
Screening decisions carry direct legal consequence, so document the reasoning behind every block, clear or exit. Designation data about individuals remains personal data with accuracy, retention and subject-rights obligations. Blanket de-risking harms humanitarian and remittance flows and is itself a regulatory concern, so calibrate rather than exit wholesale. Where a match is confirmed, follow the reporting duties owed to the competent authority, observe any prohibition on tipping off, and preserve the evidence file behind the decision.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Sanctions Intelligence, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 10 data points, 9 mission domains, 5 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
A name matches a designated person but the client insists it is a different individual. What settles it?
Identifiers, not assertions. Ask which hard attribute distinguishes the two: date of birth, place of birth, passport or national identity number, or in the corporate case registration number and incorporation date. Obtain documentary evidence of that attribute from a source independent of the client, ideally a registry filing or an identity document verified through your normal process. If the designation record carries the same identifier, the match stands regardless of what the client says. If the designation record carries no identifiers at all, which is common on older listings, document the residual uncertainty and escalate rather than clearing on comfort.
Does the fifty percent rule mean anything under fifty percent is safe?
No. Aggregation is the first trap: separate holdings by two or more designated parties are added together, so two forty percent holders block the entity. Control is the second: several regimes treat an entity as restricted where a designated party can appoint or remove a majority of the board, direct its affairs, or exercise decisive influence through financing or contractual rights, irrespective of equity. UK and EU guidance on control is broader than a pure percentage test. Treat the threshold as a floor for analysis, evidence the control question separately, and record which regime's test you applied.
Can a private firm investigate a suspected evasion network itself?
Within limits. You may analyse registry filings, published designations, trade statistics, corporate ownership records and open reporting, and you may draw evidenced conclusions from them. You may not obtain bank records, tax filings, telephony data or communications without legal process, and you may not use pretext or deception to extract beneficial ownership information. Where the analysis supports a suspicion, the lawful route is internal escalation and a report to the competent authority, observing any prohibition on tipping off. Passing findings informally to counterparties or to the press before that report can itself create liability.
How often should a portfolio be re-screened?
Event-driven first, periodic second. Any amendment published by a regime that binds you should trigger re-screening of the affected population within a defined service level, typically measured in hours to a few days depending on sector. On top of that, run a full portfolio re-screen on a fixed cycle to catch subject-side changes such as a new director or a changed registered address, since screening only against list changes misses the case where the counterparty moved toward a designated party rather than the reverse. Record the trigger for every re-screen.
What evidence does a bank or regulator expect behind a block decision?
A file that stands alone. It should contain the dated list snapshot showing the entry as published, the match output with algorithm version and threshold, the identifiers that confirmed the match, any registry documents supporting ownership or control analysis, the licence position considered, the reasoning in plain language, and the identity and date of the person who decided. Internal shorthand and links to systems that may change are not sufficient. The test is whether an examiner who knows the regime but not your organisation can follow the decision without asking you a question.
How do humanitarian exemptions actually get used?
By reading them and writing down the result. Most regimes now carry humanitarian carve-outs or general licences covering the provision of relief, medical supplies, or specified payments, each with conditions and an expiry. The practical failure is that operational teams receive a general instruction to avoid a jurisdiction and never see the authorisation. Produce a dated note naming the authorisation, the permitted activities, the conditions and the expiry date, share it with treasury, procurement and logistics, and re-issue it when the authorisation is amended. Track denied payments so the harm from over-compliance is visible.
Is adverse media enough to treat a counterparty as sanctioned?
No, and conflating the two is a common error. Adverse media is a risk signal that may justify enhanced due diligence, a different pricing decision or a reporting consideration. It is not a legal prohibition. Only a designation by a regime that binds you, or ownership and control by such a designated party, creates a blocking obligation. Keep the two determinations separate in the file and in the wording of your product, characterise media allegations as reported and attributed, and note that treating unproven allegations as designations creates defamation exposure and unjustified exclusion.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- FATF Recommendations, in particular Recommendations 6 and 7 on targeted financial sanctions, which set the international expectation for freezing without delay and for national implementation frameworks.
- OFAC fifty percent rule guidance, which governs aggregation of ownership interests held by blocked persons and the treatment of entities not themselves named on the list.
- UK OFSI guidance on ownership and control, which applies a control test broader than equity and governs licensing, reporting and the treatment of designated persons.
- EU Best Practices for the effective implementation of restrictive measures, which set out expectations on ownership and control, due diligence and derogations across member states.
- Wolfsberg Group guidance on sanctions screening, which frames control design, list management, alert handling and testing expectations for financial institutions.
- GDPR principles of lawfulness, accuracy, minimisation and storage limitation, which apply in full to designation data and screening records relating to identifiable individuals.
- UN Security Council Resolution 2664, which establishes a humanitarian carve-out across UN sanctions regimes for the provision of assistance and other activities supporting basic human needs.
- ISO 20022 and related payment message standards, which determine the structured fields available for screening and constrain what identifiers travel with a transaction.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- Specially Designated Nationals and Blocked Persons List — US Department of the Treasury, Office of Foreign Assets Control. Authoritative US sanctions designation list with identifiers and programme tags
- EU Sanctions Map — European Union. Regime-level reference showing the legal instruments and scope of EU restrictive measures
- Security Council Sanctions Committees and Consolidated List — United Nations Security Council. Multilateral designations with narrative summaries of reasons for listing
- Financial sanctions guidance and consolidated list — UK Office of Financial Sanctions Implementation. UK designations, ownership and control guidance, licensing and reporting duties
- FATF Recommendations — Financial Action Task Force. International standards on combating money laundering, terrorist financing and proliferation financing
- Global LEI Index — Global Legal Entity Identifier Foundation. Open reference data on legal entities including parent relationships
- OpenSanctions datasets and documentation — OpenSanctions. Consolidated open dataset of sanctions and politically exposed person records
- Beneficial Ownership Data Standard — Open Ownership. Structured standard for publishing and exchanging beneficial ownership information
- UN Comtrade Database — United Nations Statistics Division. Official bilateral merchandise trade statistics used for mirror analysis
- Global Integrated Shipping Information System — International Maritime Organization. Official ship identity, ownership and company records including change history
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: continuously refreshed designation data, ownership aggregation and documented alert adjudication in one workspace. Explore the platform, or browse the rest of the library by following any tag above.