Sanction / Watchlist Entry: Data Point Intelligence Guide
A sanctions hit is not an answer. It is a name, a legal basis and a programme code telling you which authority cares, why, and what you are now obliged to do.
A sanctions hit is not an answer. It is a name, a legal basis and a programme code telling you which authority cares, why, and what you are now obliged to do.
Understanding the Sanction / Watchlist Entry as an intelligence artifact
A sanctions or watchlist entry is a structured record published by a government or multilateral body designating a person, entity, vessel, aircraft or security. A typical entry carries a unique reference, a primary name and alias set, entity type, dates and places of birth or incorporation, identity document numbers, addresses, one or more programme codes describing the legal authority, and a listing date. Adjacent datasets include export-control denial lists, procurement debarment lists and politically exposed person databases, which are risk indicators rather than prohibitions.
Formats diverge sharply. US lists carry programme tags plus a separate ownership rule that extends blocking to majority-owned subsidiaries not themselves listed. EU measures are published per regulation with a statement of reasons. UN designations are transposed into national law unevenly and with delay. Aliases are graded strong or weak. Designations increasingly attach to asset identifiers such as vessel IMO numbers or security ISINs rather than to people.
Why it matters
A designation converts a name into a legal fact with a date, an issuing authority and a stated reason. It supplies verified identifiers rarely available anywhere else: passport and national identity numbers, dates of birth, historic addresses, aliases and explicitly linked entities. It anchors network analysis because ownership and control rules extend the restriction beyond the listed name. And it creates obligations, since a match drives blocking, reporting and licensing decisions that must be documented.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Programme codes reveal the legal authority and therefore the conduct alleged, from proliferation finance to narcotics to human-rights abuse.
- Alias sets expose transliteration variants and trading names used to open accounts and incorporate companies elsewhere.
- Listed addresses and incorporation dates give direct registry pivots into the designated entity's wider corporate footprint.
- Delisting and amendment history reveals contested designations, successful appeals and corrections to identifying particulars.
- Cross-listing across US, EU, UK and UN registers indicates coordinated action rather than a unilateral national measure.
- Vessel, aircraft and security identifiers embedded in entries provide immediate asset-level pivots into movement data.
- Family members and close associates named in PEP datasets map the influence network surrounding a designated official.
- Ownership percentages disclosed in listing narratives support fifty-percent-rule analysis of unlisted subsidiaries.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- OFAC SDN and Consolidated Lists — US designations with programme codes, aliases, identity documents and vessel or aircraft identifiers.
- EU Consolidated Financial Sanctions List — EU designations per regulation, with legal basis and full identifying particulars.
- UK OFSI Consolidated List — UK designations across regimes, each with a published statement of reasons.
- UN Security Council Consolidated List — Multilateral designations that member states transpose into national law at varying speed.
- OpenSanctions — Aggregated and deduplicated global sanctions, PEP and watchlist data with entity resolution.
- trade.gov Consolidated Screening List — Combined US export-control entity, denied-person and debarred-party lists behind one API.
- World Bank Debarred Firms — Procurement debarments reflecting fraud or corruption findings, distinct from financial sanctions.
- INTERPOL public notices — Extracts of red and other notices for wanted or restricted individuals.
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Match, do not assume — Score the candidate on name, date of birth, nationality and document numbers, and record match strength instead of a binary hit.
- Read the entry in full — Capture programme code, listing date, legal instrument and statement of reasons, since these define scope, not the name alone.
- Screen every register — Check US, EU, UK, UN and relevant national lists, because coverage differs and a single clean result proves very little.
- Extend by ownership — Apply ownership and control rules to identify unlisted subsidiaries that inherit the restriction from a designated parent.
- Pivot on identifiers — Use passport numbers, addresses, vessel IMO numbers and entity identifiers to reach registry, shipping and corporate records.
- Version the result — Snapshot the list file with its publication date, since designations change and yesterday's screen does not evidence today's position.
- Escalate through compliance — Route positive matches into the sanctioned decisioning process rather than acting unilaterally on an analyst's view.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Collected by these disciplines
- Sanctions Intelligence — Screening, Designations, and Evasion Detection
- Geospatial Intelligence — Intelligence Derived from Place
- Financial Intelligence — Following Value Through the Financial System
- Corporate Intelligence — Understanding Companies, Structure, and Control
- Legal Intelligence — Law, Litigation, and Regulatory Intelligence
- Maritime Intelligence — Vessels, Shipping, and the Maritime Domain
- Technical Intelligence — Technology Capability, Design, and Exploitation
- Accounting Intelligence — Financial Statements and Accounting Analysis
- Economic Intelligence — Economic Conditions, Trade, and Market Signals
- Logistics Intelligence — Cargo, Freight, and Physical Movement
Investigated in these domains
- Weapons Trafficking
- Financial Crime
- Anti-Money Laundering
- Sanctions Evasion
- Corruption & Governance
- WMD / Proliferation
- Energy Security
- Risk Analysis
Pivots to these data points
- Cryptocurrency Address — Blockchain wallet address for receiving or sending crypto assets.
- Transaction Hash — A blockchain transaction identifier for tracing fund flows.
- Stock Ticker / Security — An exchange-listed security symbol, pivoting to filings, ownership, and market data.
- Bank Account / IBAN — A bank account identifier (IBAN, SWIFT/BIC, routing + account) central to financial tracing.
Inside the platform: where Sanction / Watchlist Entry lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
sanctions.php— Sanction / Watchlist Entry profiledatapoint.php?dp=dp_sanction— Data point hubdomain.php?d=weapons— Weapons Trafficking dashboardblockchain.php— Financial Crime dashboardsearch.php— Advanced search, filter and pivotcorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Enrichment Runner
- Enrichment → Local
- Correlate Infrastructure
- Export STIX/MISP
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Match, do not assume is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Screen every register turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Escalate through compliance feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Sanction / Watchlist Entry
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Designation data supports force protection, partner vetting and contracting integrity far more than it supports targeting. Before a unit contracts local haulage, fuel or security, screening the vendor, its owners and its vehicles against consolidated lists prevents funding an adversary-linked network and prevents a legal problem for the command. Vessel and aircraft designations feed maritime interdiction planning and airspace watch lists, since a designated hull gives a lawful basis for boarding under a national or coalition authority. Constraints are important: a designation is an economic and legal measure, not a determination of hostility under the law of armed conflict, and it never by itself renders a person or object a lawful military objective.
🕵 National intelligence
Sanctions data is a requirements-driven collection anchor. A designation tells you which authority has already assessed a network, on what legal basis, and with which identifiers verified to an evidential standard, which lets an all-source analyst redirect scarce collection toward the parts of the network that are not yet described. Identity particulars in listings, particularly passport and national identity numbers and dates of birth, are unusually reliable selectors for fusion with classified holdings. Handling should reflect that: the listing itself is open, but the fact that a designated identifier matched a classified selector is not, and products should be written so the unclassified backbone can be released to partners and industry.
👮 Law enforcement
For law enforcement a designation creates a criminal offence surface: breaching a sanction, facilitating a breach, or dealing in blocked property. The list entry is a public record admissible with minimal foundation, and the legal instrument behind it establishes the prohibition on a specific date. Investigators must prove knowledge and the identity of the defendant with the listed person, which is where match quality matters: record name, date of birth, document numbers, addresses and the scoring logic used. Non-public material such as account records, ownership documents and communications requires production orders, and cross-border evidence requires mutual legal assistance. Retain the dated list version used, because designations are amended and delisted.
🔍 Private investigation and corporate security
Screening is the workhorse of private due diligence, onboarding and third-party risk. The private actor's job is to establish whether a counterparty, its owners above the relevant threshold and its officers appear on any applicable list, and to document the decision. What a private actor may not do is treat a politically exposed person hit as a finding of criminality, publish an unverified match, or use pretexting or unlawfully obtained records to resolve an ambiguity. Where a hit affects someone's access to banking, employment or travel, the person has data-protection rights including correction and, in many regimes, an explanation. Escalate through compliance rather than deciding unilaterally.
📰 Journalism and OSINT media
For reporting, a designation is a documented act by a named authority with a date, which is a strong and safe factual spine. What it is not is proof of the underlying conduct: statements of reasons are administrative assessments, sometimes contested and occasionally overturned on appeal. Quote the programme and the issuing authority precisely, check whether the entry has been amended or delisted, and distinguish designation from conviction in the wording. Give the designated party or their counsel a genuine right of reply, note any successful legal challenge, and remember that reporting on a person who has been delisted without saying so invites both a correction and a claim.
🌍 NGO, humanitarian and human rights
Human-rights organisations use targeted designations as an accountability tool: submitting evidence dossiers for listing under human-rights sanctions regimes, and monitoring whether existing designations are enforced. Practice is victim-centred, which means the survivors and witnesses whose testimony supports a submission must give informed consent, understand that listing processes are partially public, and be protected from retaliation, including by withholding identifying detail from the submission. Humanitarian actors face the mirror problem: sanctions can obstruct aid delivery, so know the humanitarian exemptions in each regime and document reliance on them. Duty of care extends to staff, who may face reprisal in-country for a submission made abroad.
🎓 University and research
Researchers use sanctions data for compliance, evasion and effectiveness studies, and the methodological demands are exacting. Lists are living documents: any analysis must state the snapshot date and ideally use a versioned archive, because delistings and amendments silently change the population. Entity resolution across regimes requires a documented matching method and an accuracy estimate, not a vendor black box. Personal identifiers in listings are lawfully published but remain personal data, so most institutional review boards will expect a data-management plan even where full ethics review is not required. Deposit code, matching thresholds and the exact list vintage so that another researcher can reproduce the population you analysed.
Playbook: working Sanction / Watchlist Entry end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Establish the obligation
Determine which regimes actually bind you or your client before screening anything: nationality of the parties, currency of the transaction, location of assets and any contractual undertakings. A European entity, a US dollar clearing leg and a UK counterparty may bring three separate authorities into play. A good output names the applicable regimes and the reason each applies. Stop when you can say which lists are mandatory, which are advisory and which you are screening only for reputational risk.
Phase 2 — Assemble the subject set
List every party requiring screening: the counterparty, its parents, its subsidiaries above the ownership threshold, directors and beneficial owners, and any assets with their own identifiers such as vessels, aircraft or securities. Include known aliases and transliterations. A good output is a subject table with entity type, jurisdiction and known identifiers. Stop when adding another related party no longer changes the risk picture, which is usually two ownership layers up and one down.
Phase 3 — Snapshot the lists
Download the authoritative files from each issuing authority with their publication dates and store them immutably. Do not screen against a mirror or an aggregator alone for decisions with legal consequence. Record file names, versions and hashes. A good output is a dated list archive you can re-run screening against months later. Stop when every regime identified in phase one has a stored snapshot with a publication date.
Phase 4 — Match with scoring
Run fuzzy matching across name, date of birth, nationality, address and document number, and produce a score with the contributing fields rather than a binary hit. Tune thresholds using a labelled sample. Common names and non-Latin transliterations require different thresholds than rare ones. A good output is a candidate list with scores and the fields that drove them. Stop when the review queue is small enough for a human to adjudicate every entry properly.
Phase 5 — Adjudicate each candidate
For each candidate, read the full entry: programme code, legal instrument, listing date, statement of reasons, identity documents. Compare against what you actually know about your subject and record a decision of match, no match or insufficient information, with the reviewer name and date. A good output is an audit trail where any decision can be re-read and defended. Stop when no candidate sits unadjudicated, including the ones you are confident are noise.
Phase 6 — Apply ownership and control
Where the subject is owned or controlled by a designated person, the restriction usually extends to the subject even if it is not itself listed. The thresholds and the aggregation rules differ between regimes, so apply each one separately rather than picking the strictest and assuming it covers you. A good output is an ownership chain diagram with percentages, sources and a per-regime conclusion. Stop when every path from a designated person to your subject has been tested under each applicable rule.
Phase 7 — Pivot on the identifiers
Use the verified particulars in the entry as collection seeds: passport numbers into travel and registry records, addresses into company registers, vessel IMO numbers into shipping data, securities identifiers into holdings data. This is where a designation converts from a compliance answer into an intelligence lead. A good output is a set of new entities and assets discovered from listing identifiers. Stop when new pivots stop returning entities outside what you already hold.
Phase 8 — Test for adaptation
Compare pre-designation and post-designation behaviour: new intermediaries, changed banking corridors, renamed vessels, fresh incorporations at the same address, transfers to family members. The listing date is the natural pivot point. A good output is a dated comparison showing what changed within weeks of designation. Stop when the pattern is either clearly established or clearly absent from the available record. Adaptation is evidence of awareness, so date it precisely against the publication of the measure.
Phase 9 — Escalate and decide
Route positive and ambiguous matches into the formal decisioning process: compliance, legal, or in law enforcement the case officer. Analysts recommend; designated functions decide on blocking, reporting, licensing and rejection. Where an obligation to report exists, meet the deadline. A good output is a decision record naming the decision maker, the basis and the date. Stop when the decision is recorded, not when the analysis is finished.
Phase 10 — Manage false positives as data
A rejected match is still personal data about a real person who was screened. Store it minimally, restrict access, and record it well enough to avoid re-adjudicating the same person weekly, using a whitelist tied to verified distinguishing attributes. A good output is a documented whitelist that reduces repeat review without suppressing genuine hits. Stop when repeat false positives fall and no whitelist entry is broader than the individual it was created for.
Phase 11 — Re-screen on a schedule
Designations are added, amended and revoked continuously, so a screen evidences only the moment it was run. Set a re-screening cadence proportionate to the relationship, and trigger an immediate re-screen on list updates for high-risk portfolios. A good output is a rescreening log showing coverage and gaps. Stop when every ongoing relationship has a next-screen date rather than only a last-screen date.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| OFAC specially designated nationals and consolidated lists | Open | United States designations with programme codes, aliases, identity documents and vessel, aircraft and securities identifiers. | The authoritative file for US measures, and the source that must be cited rather than any mirror in a compliance decision. |
| EU consolidated financial sanctions list | Open | European Union designations published per regulation with legal basis, statement of reasons and identifying particulars. | Establishes the EU legal instrument and reasons behind a listing, which differ in scope from the US equivalent. |
| UK OFSI consolidated list of financial sanctions targets | Open | United Kingdom designations across regimes, each with a statement of reasons and unique group identifier. | Required for UK obligations and useful because the published reasons are often more detailed than other regimes. |
| UN Security Council consolidated list | Open | Multilateral designations adopted under Chapter VII, with narrative summaries of reasons for listing. | Baseline for global obligations, and the narrative summaries are among the most citable public accounts of a network. |
| OpenSanctions | Open | Aggregated, deduplicated and entity-resolved sanctions, watchlist and politically exposed person data with historical snapshots. | Fast cross-regime screening and historical reconstruction of what a list looked like on a past date. |
| Consolidated Screening List | Open | Combined United States export-control entity, denied-person, unverified and debarred-party lists behind a single search and API. | Covers export-control restrictions that sit outside financial sanctions but bite on the same networks. |
| BIS Entity List and related restrictions | Open | Export administration restrictions naming foreign parties subject to licence requirements for controlled items. | Identifies procurement-focused restrictions that frequently precede full financial designation of the same network. |
| World Bank listing of ineligible firms and individuals | Open | Procurement debarments arising from fraud, corruption, collusion or obstruction findings in bank-financed projects. | Adds integrity risk on contractors that no financial sanctions list will show, with cross-debarment across development banks. |
| INTERPOL notices | Open | Public extracts of red and other international notices for wanted or restricted individuals. | Corroborates identity particulars and shows criminal-justice interest distinct from administrative designation. |
| EU Official Journal | Open | Primary publication of the regulations and decisions that create and amend European sanctions measures. | The instrument of record when you must cite the legal basis and exact date a restriction took effect. |
| Court of Justice of the European Union case law | Open | Judgments on annulment actions brought by designated persons against European listing decisions. | Shows which designations have been challenged, upheld or annulled, which is essential before publishing about a listed person. |
| FATF publications and jurisdiction statements | Open | Standards, typologies and lists of jurisdictions under increased monitoring or subject to countermeasures. | Places a designation in a wider risk context and drives enhanced due diligence expectations for the corridor. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Sanction / Watchlist Entry. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- OpenSanctions yente — Self-hosted entity matching API for screening name lists against consolidated data; scoring must be calibrated locally or transliterated names swamp the review queue.
- Elasticsearch with phonetic and n-gram analysers — Flexible fuzzy name search across list snapshots; requires script-aware configuration because default analysers handle Arabic, Cyrillic and Chinese names poorly.
- OpenRefine — Clusters alias and transliteration variants during subject list preparation; the clustering algorithms are heuristic and every merge needs analyst confirmation.
- Aleph — Cross-references screening subjects against documents, leaks and registers in one index; coverage varies sharply by jurisdiction and absence proves nothing.
- OpenCorporates and registry APIs — Resolves ownership chains needed for control-rule analysis; percentages are often unstated in registries, forcing reliance on filings or narrative sources.
- Version-controlled list archive — Storing dated list files in a repository gives reproducible historical screening; requires discipline because authorities republish files without changing filenames.
- Case management with audit logging — Records adjudication decisions, reviewers and timestamps for regulatory defensibility; value depends entirely on analysts recording reasoning rather than only outcomes.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Enrichment Runner — Walks the indicator set through a chosen provider in time-boxed, cursor-based batches that resume rather than restart.
- Enrichment → Local — Materialises enrichment into the local store so dashboards render from your own database instead of a live third-party call.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Export STIX/MISP — Streams the selection in CTI standard formats for sharing with partners and ISACs.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- A hit is a hypothesis about identity, not a fact about a person. The discriminating evidence is almost never the name: it is date of birth, document number, nationality and address in combination. Record which fields matched and which were simply absent.
- Screen the asset, not only the person. Modern designations attach to vessel IMO numbers, aircraft serials and securities identifiers precisely because names change easily. An asset identifier match is often stronger evidence than a name match.
- Read the delisting record before you write. Designations are annulled on appeal and removed on policy grounds, and describing a delisted person as sanctioned is both wrong and actionable. Check the amendment history, not just the current file.
- Regime scope differs more than analysts expect. The US ownership rule aggregates holdings across designated persons, the EU applies a control test as well as a threshold, and the UK publishes reasons the others do not. Never generalise one regime's logic to another.
- Treat aggregators as discovery and authorities as decision. Mirrors lag publication by hours or days and occasionally drop entries during reprocessing, which is invisible until it matters. Cite the issuing authority's own file in anything with legal consequence.
- A clean screen is a statement about your matching, not about your counterparty. Record the list versions, the thresholds and the fields you had available, so that the negative result is interpretable when someone challenges it two years later.
- Politically exposed person status is exposure, not allegation. Conflating the two produces both bad analysis and genuine legal liability, and it is the single most common failure in commercially produced due diligence reports.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Sanction / Watchlist Entry is producing anything, and they are worth baselining before you change process or tooling.
- False positive rate per thousand screened subjects after threshold tuning, tracked by name-script family rather than as a single aggregate.
- Median time from an authority publishing a designation or amendment to that change being reflected in operational screening.
- Proportion of positive matches adjudicated with a recorded reviewer, decision basis and date, audited by sample rather than self-reported.
- Number of previously unknown entities or assets discovered by pivoting on listing identifiers, as a measure of intelligence yield rather than compliance volume.
- Coverage of ongoing relationships that carry a scheduled next-screen date rather than only a last-screen date, reported as a percentage of the portfolio.
- Rate of delisted entries persisting in downstream systems after the authority removed them, measured by periodic reconciliation against the source file.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Common names generate heavy false positives, and transliteration from non-Latin scripts multiplies variants that defeat exact matching.
- Delisted parties persist in cached datasets and stale vendor feeds long after the legal restriction has ended.
- PEP status is a risk indicator, not a finding of wrongdoing, and treating it as guilt creates genuine legal exposure.
- Ownership rules differ between regimes, so a subsidiary blocked under one authority may be entirely permissible under another.
- Aggregator coverage lags official publication, so decisions should cite the issuing authority's file rather than a mirror.
- A negative screening result records only that a name was not matched, never that the party is actually clean.
Legal and ethical considerations
Screening outcomes affect access to finance, travel and employment, so accuracy and documentation are not optional extras. Record the list version, matching logic and reviewer for every decision and preserve that trail for the retention period your regulator sets. False-positive data is still personal data: minimise it, restrict access and correct it promptly. Never publish an unverified match as fact; describe the designation and the identity evidence, and let the compliance function make the determination.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Sanction / Watchlist Entry, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 10 intelligence disciplines, 8 mission domains, 4 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
The name matches but the date of birth is missing. Do I treat it as a hit?
You treat it as unresolved, and you say so. A name-only match with no corroborating particular is weak evidence, particularly for common names and for names transliterated from non-Latin scripts where dozens of spellings are equally valid. Record what matched, what was absent and what you attempted to obtain. In a compliance context this normally means escalating for additional customer information rather than either blocking or clearing. In an intelligence or journalistic context it means writing possible identity match with the missing fields named. Never let an unresolved match silently become a fact in the next document.
Does a designation of the parent automatically block the subsidiary?
Frequently, but the rules differ and you must apply each regime separately. The US approach blocks entities owned fifty per cent or more, directly or indirectly, by one or more designated persons, aggregating holdings and without the subsidiary itself being listed. European measures apply both an ownership threshold and a separate control test that can capture entities below the threshold. UK practice is similar with its own guidance. So the same subsidiary can be blocked under one regime and permitted under another. Diagram the ownership chain with percentages and sources, then state a conclusion per regime rather than one global answer.
Can I publish that a company is evading sanctions?
Only if you can evidence the elements or you are clearly framing it as assessment. Evasion implies knowledge and intent, which documents rarely show directly. What you can usually state as fact is documented: the designation and its date, the corporate relationship from registry records, the shipment or payment from a primary record, and the timing. Then state your assessment separately, with confidence and reasoning. Offer the company a specific right of reply naming the transactions concerned. This is not just legal caution; separating record from inference is also what makes the analysis usable by a regulator or prosecutor later.
How do I screen a name written in Arabic, Cyrillic or Chinese?
Screen the original script and the transliterations, and treat them as different problems. Keep the name in its original script in your records, generate transliteration variants using a documented scheme rather than ad hoc spelling, and use matching configured for that script rather than a default Latin analyser. Lists themselves carry graded aliases, strong and weak, and weak aliases should not drive a block on their own. Be aware that name order conventions differ, that patronymics and honorifics may or may not be included, and that the same person may appear twice on the same list under different transliterations.
How do humanitarian exemptions interact with screening?
Most modern regimes contain carve-outs permitting humanitarian activity, and several have adopted broad exemptions for the provision of aid. They are not automatic in every regime and they do not remove the obligation to screen. The practical approach for an aid organisation is to identify the exemption or licence relied on for each programme, document that reliance in advance, screen partners and suppliers as normal, and record where an exemption rather than a clear screen justified proceeding. Banks may still de-risk regardless, so engaging the financial partner early with that documentation is usually more effective than arguing after a payment is rejected.
How far back should a historical screen go?
Screen against the list as it stood on the date of the conduct you are examining, not today's list. This matters constantly in investigations: a transaction in 2019 was lawful or unlawful by reference to designations in force then, and using today's file will both miss subsequently delisted parties and wrongly implicate later-designated ones. Use archived list snapshots, record the vintage in your notes, and where you cannot obtain a contemporaneous snapshot, say that your screen used a current list and explain the limitation. This is one of the most common evidential errors in retrospective sanctions analysis.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- FATF Recommendation 6 and 7 set the international expectations for implementing targeted financial sanctions on terrorism and proliferation financing.
- UN Security Council resolutions adopted under Chapter VII create the multilateral designations that member states transpose, with narrative summaries published by the relevant committee.
- EU Council Regulations, published in the Official Journal, are the binding instruments for European measures and define scope, exemptions and derogations per regime.
- The UK Sanctions and Anti-Money Laundering Act 2018 provides the domestic legal framework for designations, licensing and challenge.
- The US International Emergency Economic Powers Act underpins most OFAC programmes and defines the property and interests in property that are blocked.
- Wolfsberg Group guidance sets industry expectations for sanctions screening controls, list management and false-positive handling in financial institutions.
- ISO 20275 entity legal forms and ISO 17442 legal entity identifiers support consistent resolution of listed legal persons across regimes.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- Specially Designated Nationals and Blocked Persons List — Office of Foreign Assets Control, US Department of the Treasury. The primary United States designation file and supporting programme guidance.
- EU Sanctions Map — Council of the European Union. Regime-by-regime overview of European measures with links to the underlying regulations.
- Financial sanctions guidance and consolidated list — Office of Financial Sanctions Implementation, HM Treasury. United Kingdom designations, licensing guidance and statements of reasons.
- Security Council sanctions committees and consolidated list — United Nations. Multilateral designations with committee narrative summaries.
- OpenSanctions datasets and methodology — OpenSanctions. Open, versioned aggregation of global sanctions and politically exposed person data.
- The FATF Recommendations — Financial Action Task Force. International standards including targeted financial sanctions obligations.
- Consolidated Screening List — International Trade Administration, US Department of Commerce. Aggregated export-control and debarment restrictions with public API.
- Case law of the Court of Justice of the European Union — Court of Justice of the European Union. Judgments on challenges to European sanctions listings.
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: screens entities against consolidated global lists and expands hits through ownership and asset links. Explore the platform, or browse the rest of the library by following any tag above.