Sanctions Evasion: Mission Domain Intelligence Guide
Sanctions evasion leaves a documentary shadow: a new intermediary in a familiar corridor, a vessel that stops transmitting for eleven hours, an export code that shifts by one digit. Defence is pattern recognition, not list-checking.
Sanctions evasion leaves a documentary shadow: a new intermediary in a familiar corridor, a vessel that stops transmitting for eleven hours, an export code that shifts by one digit. Defence is pattern recognition, not list-checking.
What Sanctions Evasion covers as a mission domain
Sanctions evasion intelligence covers the detection of attempts to circumvent restrictive measures imposed by the UN, US, EU, UK and other authorities against states, entities, vessels, aircraft and individuals. In practice it means monitoring exposure to designated parties through intermediaries, identifying diversion of controlled and dual-use goods, watching for ownership restructuring designed to fall below control thresholds, testing transport behaviour against declared trade, and detecting financial channels that reintroduce restricted parties to the banking system. The output supports compliance decisions, enforcement referrals and new designation nominations.
The domain is organised by regime type: comprehensive country programmes, sectoral measures, list-based designations and export controls, each with distinct pressure points. Analysts typically maintain three views. The corporate view tracks ownership and control changes around designated persons. The trade view tracks commodity flows and third-country re-export patterns. The transport and finance view covers vessels, aircraft, insurers, freight forwarders and payment intermediaries.
Why it matters
Sanctions are a primary non-military instrument against proliferation, aggression, atrocity and grand corruption, and they only function if circumvention is detected and priced in. Failure exposes banks, insurers, shippers and manufacturers to enforcement penalties, criminal liability and reputational damage, and allows restricted parties to obtain the revenue, technology and materiel the measures were designed to deny. Detection work also generates the evidence base for the next round of designations.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Trade volumes in a controlled commodity rising sharply in a third country with no domestic demand, timed to the imposition of a measure.
- Newly incorporated intermediaries with no trading history inserted between a long-standing supplier and a restricted end market.
- Ownership restructured so each designated shareholder sits just below the applicable control threshold while management remains unchanged.
- Vessels showing prolonged transponder gaps in known transfer areas, or position data inconsistent with reported draught and port calls.
- Flag changes, name changes, ownership transfers and insurance switches clustered into a short window for the same hull.
- Export declarations describing controlled items under adjacent lower-scrutiny commodity codes at values inconsistent with the goods.
- Payment routing through correspondent chains and corridors with no commercial relationship to the underlying trade.
- End-use certificates naming purchasers whose declared business, premises and staffing cannot plausibly consume the quantities ordered.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- OFAC SDN and Consolidated Lists — US designations with aliases, addresses and vessel identifiers, plus guidance on the fifty percent ownership rule.
- EU Consolidated Financial Sanctions List — EU designations and legal bases, published in structured downloadable formats for screening.
- UK OFSI Consolidated List — UK designations, licensing guidance and published enforcement and penalty notices.
- UN Security Council Consolidated List — UN-mandated designations underpinning national implementation across all member states.
- BIS Entity List and Denied Persons List — US export-control restrictions on named foreign parties with end-user screening guidance.
- UN Panel of Experts reports — Investigative detail on procurement networks and circumvention methods across DPRK, Libya and other regimes.
- UN Comtrade and national customs data — Bilateral trade flows supporting mirror analysis and third-country diversion detection.
- IMO GISIS and Equasis — Vessel identity, ownership, flag history and classification data for maritime exposure assessment.
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Fix the legal perimeter — Determine which regimes bind the client or subject, which listings apply, and what ownership and control tests are currently in force.
- Screen and resolve — Run entity, vessel and individual screening, then resolve hits properly against transliterations, aliases, former names and dates of birth.
- Map ownership and control — Trace shareholdings and directorships around any designated party, applying aggregation rules and de facto control indicators.
- Analyse the trade corridor — Compare pre- and post-measure trade flows by commodity and partner to identify diversion routes and newly inserted intermediaries.
- Test transport and finance — Check vessel, aircraft and payment behaviour against declared activity, documenting each anomaly with timestamps and sources.
- Grade and document exposure — Classify findings as confirmed breach, credible risk or unresolved, recording the reasoning in a form that will survive regulator scrutiny.
- Escalate appropriately — Route to licensing application, voluntary self-disclosure, contract termination or designation nomination according to the facts established.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Practised with these disciplines
- Sanctions Intelligence — Screening, Designations, and Evasion Detection
- Financial Intelligence — Following Value Through the Financial System
- Corporate Intelligence — Understanding Companies, Structure, and Control
- Maritime Intelligence — Vessels, Shipping, and the Maritime Domain
- Logistics Intelligence — Cargo, Freight, and Physical Movement
- Legal Intelligence — Law, Litigation, and Regulatory Intelligence
- Geospatial Intelligence — Intelligence Derived from Place
Worked in these data points
- Sanction / Watchlist Entry — An entry on a sanctions list, watchlist, or PEP database.
- Company / Organization — A legal entity — corporation, LLC, NGO, or business.
- Person / Name — A named individual — the subject of identity resolution and profiling.
- Vessel / Ship — A maritime vessel identified by IMO, MMSI, or call sign.
- Shipment / Bill of Lading — A consignment record linking shipper, consignee, goods, and route.
- Cryptocurrency Address — Blockchain wallet address for receiving or sending crypto assets.
- Legal Entity Identifier — A 20-character global identifier for a legal entity participating in financial transactions.
Adjacent mission domains
- Anti-Money Laundering
- Financial Crime
- WMD / Proliferation
- Maritime Security
- Nation State
- Weapons Trafficking
- Energy Security
Inside the platform: where Sanctions Evasion lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
sanctions.php— Sanctions Evasion dashboarddomain.php?d=sanc— Mission domain hubtheater.php?d=sanc— Threat theater viewsearch.php— Company / Organization profiledomain.php?d=mar— Vessel / Ship profilecorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
Relevant playbooks
Of the 14 incident playbooks in playbooks.php, these apply directly to Sanctions Evasion:
- Sanctions Screening & Escalation — a step-checked workflow with the pivots, sources and handling rules already wired in.
- Cryptocurrency Tracing — a step-checked workflow with the pivots, sources and handling rules already wired in.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Threat Hunt
- Correlate Infrastructure
- Run Alert Rules
- Export STIX/MISP
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Fix the legal perimeter is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Map ownership and control turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Escalate appropriately feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Sanctions Evasion
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence analysts use sanctions circumvention indicators to assess how an adversary sustains its industrial base and resupply despite restrictions, which components it still obtains and through which corridors. This supports assessment of production rates, attrition sustainability and the effectiveness of allied measures, and feeds analysis of recovered materiel where foreign-origin components are documented. It also supports force protection and contracting, since deployed procurement must not touch restricted parties. Constraints are strict: the analytical product describes observed indicators of circumvention for detection and enforcement purposes. It never advises on structuring, routing or supplier selection, and analysts should be alert that detailed evasion analysis has obvious dual-use sensitivity and must be handled accordingly.
🕵 National intelligence
National services support the designation process, monitor implementation and assess measure effectiveness. Requirements typically ask which networks are supplying a restricted programme, which third countries are hosting diversion, and what the observable effect of a measure has been on the target's behaviour. Fusion combines customs and trade data, corporate registries, transport transponder data, financial intelligence and diplomatic reporting. Handling is complicated because designation packages must eventually survive legal challenge, so evidence must be reduced to a releasable form. Dissemination priorities are the sanctions authority, export control enforcement, partner services and, in sanitised form, industry advisories.
👮 Law enforcement
Enforcement cases centre on documented dealings with a designated party or export of controlled goods without licence. Evidence is documentary: contracts, invoices, shipping records, end-use certificates, correspondence showing knowledge, and payment records. Most requires production orders and mutual legal assistance, and the jurisdictional analysis matters as much as the facts, since US dollar clearing, EU-origin goods or UK persons each pull in different regimes. Knowledge or wilful blindness is usually the contested element, so communications evidence is decisive. Voluntary self-disclosure by companies is a major source of cases and shapes charging and penalty outcomes substantially.
🔍 Private investigation and corporate security
Compliance and investigative work covers screening, ownership analysis under control thresholds, counterparty diligence, transaction review and investigation of suspected breaches for self-disclosure. The deliverable states exposure with the reasoning and the list versions relied on. A private actor may not access customs or banking records without authority, and must never advise on structuring around measures, since facilitation is itself an offence in most regimes and the professional risk here is severe. Where a breach is identified, the correct route is legal advice and a decision on self-disclosure, not quiet contract termination that destroys the evidence.
📰 Journalism and OSINT media
Investigations rest on trade records, corporate filings, shipping data and, where available, component-level evidence from recovered equipment. Verify any claim that a company supplied a restricted end user against documents rather than a single database entry, since intermediaries and re-exporters break the chain and misattribution is legally dangerous. Distinguish between a company whose goods reached a restricted party through unauthorised re-export and one that knowingly supplied. Protect sources inside logistics and manufacturing firms. Provide detailed right of reply, and expect substantial legal pressure, particularly from intermediaries in permissive jurisdictions.
🌍 NGO, humanitarian and human rights
Civil society organisations monitor implementation, document circumvention and advocate for designations, particularly where measures target atrocity, corruption or proliferation. Documentation should be built to the standard a designation authority requires: identifiers, evidence of the conduct, and the link between the person and the sanctionable behaviour. Do-no-harm requires assessing humanitarian consequences, since sanctions affect populations and over-compliance by banks restricts legitimate aid flows, an effect that should be documented rather than ignored. Duty of care applies to local researchers in the target state, whose exposure for contributing evidence can be extreme.
🎓 University and research
Research covers sanctions effectiveness, trade diversion measurement, compliance behaviour and humanitarian impact. Methodology commonly uses gravity models, synthetic control and mirror trade analysis, each with well-known weaknesses that should be stated rather than assumed away. Reproducibility is strong in this field because trade, listing and shipping data are largely public, so publishing extraction and cleaning code is expected. Ethics approval is needed for interviews with compliance professionals or affected populations. Researchers should be conscious that granular circumvention analysis has dual-use potential and should frame publication around detection and policy evaluation rather than operational method.
Playbook: working Sanctions Evasion end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Fix the applicable regimes
Determine every regime with a claim on the activity: the home jurisdiction, the currency of settlement, the origin of the goods or technology, the nationality of persons involved, and the location of any conduct. Record which measures apply and their current text and dates. Multi-regime exposure is the norm, and analysing only the home regime is the most common structural error. Stop when you can list each applicable regime and the specific prohibition engaged.
Phase 2 — Build the counterparty picture
Resolve every party, vessel and aircraft into a canonical identity with registration numbers, IMO or tail numbers, addresses and known former names. Sanctions evasion runs on identity change, so name history, flag history and ownership transfer history are the working material. Output is an identity record per party with sources. Stop when name variants and prior identities are documented, not merely current details.
Phase 3 — Screen and resolve properly
Run screening across the applicable lists, then resolve every hit against transliteration variants, dates of birth or incorporation, addresses and identifiers. Record the list version and date used. Both outcomes matter: a cleared false positive needs a documented rationale, and an unresolved possible match must be escalated rather than dismissed. Stop when every hit has a written disposition that a supervisor could review years later.
Phase 4 — Apply ownership and control tests
Trace shareholdings around designated persons and apply the relevant aggregation and control rules, which differ by regime. Look for restructuring that places each designated holder just below the threshold while management, premises and business relationships stay unchanged. Consider de facto control indicators such as signing authority, guarantees and family relationships. Output is a control assessment per regime, with the differing thresholds handled separately.
Phase 5 — Analyse the trade corridor
Compare commodity flows before and after the imposition of a measure, by partner and by code. Look for volumes appearing in third countries with no domestic demand, growth that matches the shortfall elsewhere, and new intermediaries with no trading history inserted into an established chain. Output is a corridor assessment with the quantitative evidence and the confounders addressed.
Phase 6 — Test transport behaviour
Examine vessel and aircraft behaviour against declared activity: transponder gaps in known transfer areas, position data inconsistent with reported draught or port calls, flag and name changes clustered in time, insurance and classification society changes, and unusual loitering. Treat each as an indicator requiring corroboration rather than as proof, since equipment failure and coverage limits produce identical patterns.
Phase 7 — Examine the documentary chain
Review end-use certificates, export declarations, commodity codes and invoices for the recurring tells: declared purchasers whose premises and staffing cannot consume the quantity, values inconsistent with the goods, and codes adjacent to but lower-scrutiny than the correct classification. Documentary inconsistency is the most provable element of most cases. Stop when each document has been tested against physical and commercial plausibility.
Phase 8 — Trace the payment path
Establish how settlement occurred: correspondent chains, intermediary banks, non-bank payment institutions, trade finance instruments or virtual assets. Routing with no commercial relationship to the underlying trade is a strong indicator. Where currency choice pulls in an additional regime, record it explicitly. Output is a payment chain diagram with the jurisdictional consequences stated.
Phase 9 — Grade exposure and document reasoning
Classify each finding as confirmed breach, credible risk or unresolved, and write the reasoning against the specific prohibition. Compliance is judged on what was known and reasonable at the time, so the contemporaneous record is the protection. Output is a graded exposure schedule with evidence references. Stop when every item has a grade and a rationale, including the ones you have cleared.
Phase 10 — Decide the response route
Match the finding to the instrument: licence application, voluntary self-disclosure, contract termination with evidence preserved, enhanced conditions on a counterparty, suspicious activity report, referral to enforcement, or a designation nomination. Take legal advice before any step that concedes a breach. Never allow the response to become advice on how to continue the activity differently, which is facilitation.
Phase 11 — Build the designation package where appropriate
Where the objective is a new listing, assemble what the authority actually requires: full identifiers, evidence of the sanctionable conduct, the connection between person and conduct, and sourcing that can survive judicial review. Weak packages waste the opportunity, because a failed designation is difficult to revisit. Stop when each element of the listing criteria has evidence attached.
Phase 12 — Monitor for adaptation
After any action, watch for the network reconstituting: a new intermediary in the same corridor, a re-flagged vessel, a substituted commodity code, or settlement shifting to a different currency or channel. Adaptation is the expected outcome and detecting it quickly is the real measure of the capability. Register the new indicators for continuous monitoring rather than closing the case.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| OFAC sanctions lists and guidance | Open | US designations including SDN and consolidated lists, with aliases, addresses, vessel identifiers and interpretive guidance. | Primary screening source for US measures and the authoritative statement of the fifty percent ownership rule. |
| EU Sanctions Map and consolidated list | Open | EU restrictive measures by regime with legal bases and the consolidated financial sanctions list in structured formats. | Establishes which EU measures apply to a corridor and supplies machine-readable data for screening. |
| UK OFSI consolidated list and guidance | Open | UK financial sanctions designations, sectoral measures, licensing guidance and published enforcement decisions. | Determines UK exposure and the licensing route where an otherwise prohibited activity may be permitted. |
| UN Security Council consolidated list and committee documents | Open | UN-mandated designations, committee reports and Panel of Experts investigative reporting on implementation. | Establishes the binding baseline for all member states and supplies detailed evidence on procurement networks. |
| BIS Entity List and export control regulations | Open | US export control restrictions on named foreign parties, licence requirements and end-user screening guidance. | Identifies restricted end users for controlled technology and the licence position for a proposed transaction. |
| OpenSanctions | Open | Consolidated open dataset of designations across regimes with entity identifiers and relationship data. | Enables reproducible multi-regime screening and detection of the same party appearing under different regimes. |
| UN Comtrade | Registration | Bilateral trade statistics by commodity code from reporting national statistical and customs authorities. | Supports corridor analysis, mirror comparison and detection of third-country volumes with no domestic demand. |
| Equasis | Registration | Free vessel information service aggregating ownership, management, classification and inspection data. | Establishes vessel identity, ownership and management history including changes clustered around a measure. |
| IMO GISIS | Registration | Global integrated shipping information system with ship particulars, company records and port state control data. | Confirms IMO number, registered owner and operator history for vessels under examination. |
| MarineTraffic and AIS providers | Licensed | Historical and near-real-time vessel position data derived from terrestrial and satellite AIS reception. | Detects transponder gaps, loitering in transfer areas and position data inconsistent with declared voyages. |
| OpenCorporates | Registration | Company registry aggregation with officers, addresses and filing histories across many jurisdictions. | Identifies newly incorporated intermediaries and traces ownership restructuring around designated persons. |
| C4ADS research | Open | Data-driven investigative research on illicit networks including sanctions evasion, procurement and shipping. | Provides methodology precedent and documented network findings for corridors under examination. |
| RUSI Centre for Finance and Security | Open | Applied research on sanctions implementation, proliferation finance and financial crime policy. | Supplies analytical frameworks for assessing measure effectiveness and industry implementation quality. |
| WCO Harmonized System resources | Open | Commodity classification framework and guidance underpinning customs declarations worldwide. | Identifies adjacent and lower-scrutiny codes that could be used to describe controlled items in declarations. |
| Wassenaar Arrangement control lists | Open | Multilateral control lists for conventional arms and dual-use goods and technologies with definitions. | Determines whether an item is controlled and under which entry, before any licensing analysis. |
| Conflict Armament Research | Open | Field documentation of weapons and components recovered from conflict zones, traced to manufacturers and supply chains. | Provides component-level evidence that controlled goods reached a restricted end user despite measures. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Sanctions Evasion. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- Screening engines with fuzzy matching — Compare counterparties against consolidated lists across regimes. Limitation: transliteration handling and threshold tuning determine both false positives and silent misses.
- OpenSanctions data and API — Reproducible open designation data with provenance for each entry. Limitation: refresh timing and identifier completeness vary by upstream list.
- AIS analysis platforms — Reconstructs vessel movement history and detects gaps and loitering. Limitation: reception coverage varies by region, so absence of signal is genuinely ambiguous.
- Trade data extraction and mirror analysis — Quantifies corridor shifts by commodity and partner over time. Limitation: reporting lags, code changes and transit effects create artefacts resembling evasion.
- OpenCorporates and registry search — Detects newly incorporated intermediaries and shared officers across jurisdictions. Limitation: ownership is unavailable in exactly the jurisdictions used for layering.
- Bill of lading and shipment databases — Links shippers, consignees and commodities at consignment level. Limitation: coverage is strongest for US-bound trade and descriptions are frequently falsified.
- Satellite imagery — Confirms port activity, ship-to-ship transfers and facility operation independent of transponder data. Limitation: revisit rate and cloud cover limit event capture.
- Case and evidence management with version control — Records which list version and guidance applied at the time of each decision. Limitation: only protects if analysts record contemporaneously rather than retrospectively.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Export STIX/MISP — Streams the selection in CTI standard formats for sharing with partners and ISACs.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Screen the identity, not the string. Evasion runs on identity change, so name history, prior vessel names, flag history and former company names are the working material, and a screening process that only checks current names will miss by design.
- A transponder gap is an indicator, not an event. Equipment failure, reception coverage and weather produce identical data, so a gap only becomes meaningful when combined with draught inconsistency, an unexplained port call or corroborating imagery.
- Watch the intermediary layer rather than the endpoint. Restricted end users rarely change, but the trading company sitting between them and the supplier is replaced constantly, and a newly incorporated firm with no history inserted into an established chain is the single most reliable structural signal.
- Aggregate sub-threshold holdings before concluding. Several designated shareholders each holding a minority can jointly exceed the applicable control test, and the differing thresholds and aggregation rules between regimes mean the same structure can be caught by one and not another.
- Physical plausibility beats price analysis on end-use certificates. A declared purchaser whose premises, staffing and power supply could not consume the quantity ordered is a far stronger and more defensible finding than an argument about unit values.
- Document what you knew and when, with list versions. Compliance is assessed retrospectively against the information reasonably available at the time, so the contemporaneous record with dated list versions is the analytical product that actually protects the organisation.
- Never let analysis drift into advice. Explaining how a measure has been circumvented is detection work; suggesting how an activity could be continued differently is facilitation, which is an offence in most regimes, and the distinction must be visible in how the product is written.
- Expect adaptation and instrument for it. Corridors move, codes change and vessels re-flag within weeks of an action, so a monitoring set that only watches the entities named in the last enforcement action will be blind at exactly the moment it matters.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Sanctions Evasion is producing anything, and they are worth baselining before you change process or tooling.
- Time from designation of a new party to completed exposure assessment across the customer, supplier and vessel base.
- Proportion of screening alerts resolved with a documented rationale, and the false positive rate trend as tuning improves.
- Number of previously unidentified intermediaries detected in monitored corridors before rather than after enforcement action elsewhere.
- Quality of designation nominations measured by acceptance rate and by whether listings survive legal challenge.
- Detection interval for network adaptation after an action, meaning time to identify the replacement intermediary, vessel or corridor.
- Proportion of self-disclosures made proactively rather than following regulator contact, as a measure of internal detection capability.
- Coverage of ownership and control analysis, measured as the share of material counterparties with a documented control assessment under each applicable regime.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Screening names without resolving them, since false positives erode trust in the process and false negatives pass designated parties through.
- Applying only the home regime when a transaction touches US dollars, EU-origin goods or UK persons and triggers several others.
- Treating a transponder gap as proof of illicit transfer, when equipment failure, weather and coverage limits produce identical data.
- Missing indirect ownership aggregation, where several sub-threshold designated holders together exceed the applicable control test.
- Assuming delisting means clean, or that a new listing applies retroactively to contracts lawfully concluded beforehand.
Legal and ethical considerations
Sanctions analysis has direct legal consequence: findings drive licence applications, self-disclosures and contract terminations, all reviewable by regulators after the fact. Keep an auditable record of the list versions, dates and reasoning relied on, because compliance is judged on knowledge at the time. Take care not to advise, even implicitly, on structuring around measures, since facilitation is itself an offence in most regimes. Where subjects contest designation, distinguish the legal fact of listing from assertions about underlying conduct.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Sanctions Evasion, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 7 intelligence disciplines, 7 data points, 7 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
Which regime applies when several could?
Assume several do and analyse each separately. Jurisdiction attaches through the nationality or residence of the persons involved, the location of conduct, the origin of goods or technology, the currency of settlement and the involvement of financial institutions from a given country. A transaction between two non-US parties can be caught by US measures through dollar clearing or US-origin content. The practical discipline is to build a matrix of applicable regimes for each material transaction rather than defaulting to the home regime, because the thresholds, ownership rules and licensing routes differ meaningfully between them.
Is a vessel going dark proof of an illicit transfer?
No. AIS transmission stops for many reasons: equipment failure, power management, reception gaps in areas with poor terrestrial and satellite coverage, and lawful operational reasons. What makes a gap analytically meaningful is corroboration: a gap in a known transfer area, followed by a draught change inconsistent with the declared voyage, or a port call that does not appear in the position record, or satellite imagery showing the vessel alongside another during the gap. Presenting a gap alone as evidence has repeatedly embarrassed analysts and is easily rebutted by an operator.
How do ownership thresholds actually work?
Differently by regime, which is precisely the trap. Some regimes treat an entity as designated if designated persons own fifty percent or more directly or indirectly, aggregating holdings across multiple designated persons. Others apply a lower threshold or a control test that looks at influence rather than percentage, including rights to appoint directors or de facto direction. The correct method is to build the shareholding chain once and then apply each regime's test to it separately, recording the different outcomes. Structures deliberately engineered to sit just below a threshold should trigger a control analysis rather than a clearance.
What makes a designation nomination succeed?
Identifiers and evidenced conduct. Authorities need enough to identify the target unambiguously, which means passport or registration numbers, dates of birth or incorporation, addresses and known aliases, and they need evidence connecting that specific person to conduct that falls within the listing criteria of the relevant regime. Sourcing must be robust enough to survive judicial review, since listings are routinely challenged. A nomination based on media reporting and inference will not proceed. A nomination that packages primary documents against each element of the criteria has a real prospect.
How should a company handle a suspected past breach?
Take legal advice immediately and preserve everything. The instinct to terminate quietly and move on destroys the evidence needed to assess exposure and forfeits the substantial mitigation credit available for voluntary self-disclosure in most regimes. Establish the facts through a properly scoped internal review, determine which regimes are engaged and over what period, and then make a documented decision on disclosure and remediation. Continuing the activity through a restructured arrangement, however superficially compliant, is the worst option available and is how compliance failures become criminal cases against individuals.
Do sanctions actually work?
That question is unanswerable in the abstract and analysts should resist it. Measures have varied objectives: constraining a capability, imposing cost, signalling, creating negotiating leverage, or building an evidence base for later action. Assessment must be against the stated objective, with a measurable indicator and a counterfactual. Constraint effects on specific technology acquisition are measurable through trade and component evidence. Behaviour change effects are much harder and frequently overstated in both directions. Good analysis states which objective is being assessed, what evidence would show success, and what the adaptation costs to the target have been.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- UN Security Council Chapter VII sanctions regimes, which create binding obligations on all member states and are implemented through national law.
- OFAC regulations and the fifty percent rule guidance, governing US measures including secondary sanctions and the ownership aggregation test.
- EU Council Regulations implementing restrictive measures, together with the Commission guidance on ownership and control.
- UK Sanctions and Anti-Money Laundering Act and the regulations made under it, administered for financial measures by OFSI.
- US Export Administration Regulations and the International Traffic in Arms Regulations, governing controlled items, end users and re-export.
- Wassenaar Arrangement, Nuclear Suppliers Group, Missile Technology Control Regime and Australia Group control lists, defining controlled dual-use items.
- FATF Recommendation 7 on targeted financial sanctions related to proliferation financing, and its implementation requirements for institutions.
- Wolfsberg Group guidance on sanctions screening, which sets the industry expectation for screening design and quality assurance.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- Sanctions programs and country information — OFAC, US Department of the Treasury. Authoritative source for US designations, guidance and licensing.
- EU Sanctions Map — European Union. Regime-by-regime record of EU restrictive measures and legal bases.
- UK financial sanctions guidance and consolidated list — Office of Financial Sanctions Implementation. UK designations, licensing framework and enforcement practice.
- Panel of Experts reporting to sanctions committees — UN Security Council. Investigative documentation of procurement and circumvention networks.
- Entity List and export administration regulations — US Bureau of Industry and Security. Restricted end users and licence requirements for controlled technology.
- Dual-use and munitions control lists — Wassenaar Arrangement. Multilateral definitions of controlled goods and technologies.
- Investigations into illicit trade and shipping networks — C4ADS. Open-source network analysis of sanctions evasion methodologies.
- Component tracing from recovered materiel — Conflict Armament Research. Field evidence linking controlled components to restricted end users.
- Research on sanctions implementation and proliferation finance — RUSI Centre for Finance and Security. Applied policy research on measure design and industry compliance.
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: monitors ownership change, trade corridors and transport behaviour for circumvention patterns across major regimes. Explore the platform, or browse the rest of the library by following any tag above.