95 percent false positives is a design choice

Industry estimates regularly put sanctions screening false-positive rates above 95%, and many compliance teams accept that as the cost of caution. It is not. Most screening systems check names. The law is concerned with ownership.

3 min read

Sanctions screening tools generate vast numbers of alerts, and compliance teams clear them every day. False-positive rates above 95% are often accepted as an unavoidable part of managing risk.

It feels reasonable. Sanctions enforcement is a difficult problem. Hundreds of thousands of sanctioned individuals and entities sit across multiple lists, names change between languages, and aliases are often designed to obscure who is really involved.

But the complexity of sanctions is not what creates most of the noise. Most screening systems check names. The law is concerned with ownership. So analysts spend hours proving that this Rodriguez is not that Rodriguez, while the real risk may sit inside a perfectly ordinary company name that appears on no sanctions list at all.

The tools check the name on the door. The law cares who owns the building.

What the law actually says

OFAC, the US sanctions authority, makes the distinction explicit. Its 50 percent rule states that a company owned half or more, directly or indirectly, by one or more sanctioned parties is itself blocked, even if its own name appears on no list. And ownership is aggregated. If two sanctioned parties own 30% and 25% of the same company, their interests combine, and the company is blocked even though neither shareholder individually holds a controlling stake. US export controls have been moving the same way.

The implication is straightforward. The critical compliance question is not whether a counterparty's name resembles one on a watchlist. It is who ultimately owns the counterparty, and how much sanctioned ownership exists throughout its structure.

Why name screening fails twice

Measured against that standard, name-based screening breaks down in two different ways.

It generates alerts where the law sees little or no risk. Every company whose name resembles a listed entity becomes a potential match, and in the overwhelming majority of cases the investigation finds no connection to any sanctioned party. That is where the 95% comes from.

And it misses the situations the law is explicitly designed to catch. A trading company owned through multiple layers of holding companies may have a completely clean name. No match appears, no alert is raised, and the entity may still be blocked because of who ultimately owns it. The system stays silent precisely where the regulation applies.

Both failures stem from the same design choice, which is screening names instead of screening ownership. That is why reducing false positives and improving detection are not separate problems. They have the same solution.

The cost of getting it wrong

Every false positive consumes analyst time. Every false negative creates exposure, and the exposure now runs to nine figures. BIS, the US export-control enforcement agency, settled with Applied Materials for $252.5 million in February 2026, the second-largest civil penalty in its history behind Seagate's $300 million in 2023. Regulators increasingly expect organisations to understand who stands behind their counterparties, not simply what they are called.

Screen what the law screens

Start by working out which real-world company each counterparty actually is, so that multiple spellings, aliases and local registrations stop generating separate investigations. Then build the ownership chain, tracing owners through each corporate layer and adding up sanctioned ownership across the structure. Then apply the regulatory test continuously, so a change in a parent company's ownership or status automatically updates the assessment of every subsidiary beneath it.

The output changes completely. Instead of "this name resembles a listed name", the analyst sees "this counterparty is 55% owned, through these ownership chains, by these sanctioned parties, as of this date", with the evidence attached. The queue shrinks, the quality of what remains rises, and analyst time moves from untangling names to making compliance decisions.

Measure what matters

The true measure of a screening programme is not how many alerts it generates. It is whether the analyst's next hour goes on assessing genuine risk or on untangling spelling variations.

The Prophesee Compliance Suite screens ownership structures, applies ownership rules continuously and updates assessments as corporate structures change.

Because the law does not screen names. It screens ownership. Your system should too. Run your counterparty file through it.

New essays land on LinkedIn first. Follow 3RDi to catch them, or get a demo to see Prophesee on your own data.