Sanctions screening false positives happen when a name looks similar to that of a listed individual or entity but belongs to someone else. A true positive is when the alert identifies the individual or entity exactly as intended. However, the real cost begins when a Compliance Team opens a case, identifies the individual(s), and determines whether there is a match; this ultimately involves no identification or connection to the screened individual.
False positives generated by sanctions screening are likely to be the source of most alerts from these systems. Rates vary significantly based on each institution’s processes (screening types) and data quality. Any singularly referenced rate should therefore be viewed as an estimate. This article addresses what causes false positives, how much these false positives cost Compliance Teams in terms of time and effort to address, and the specific Identifier, Data, and Matching Rule modifications that will reduce the number of false positives while ensuring that actual matches are not missed.
What Is a Sanctions Screening False Positive?
A sanctions screening alert fires when a name or a related data point resembles an entry on a sanctions list. The alert flags a possible match. An analyst confirms identity separately, comparing identifiers such as date of birth, nationality, address, or associated organization against the watchlist entry. Diverging identifiers close the case as a false positive. Aligning identifiers moves forward as a potential true match.
A company screening “James Walsh” might match a sanctioned individual sharing that name. The date of birth, nationality, and address on file belong to two different people, so the case closes as a false positive despite the shared name.
What Causes Sanctions Screening False Positives?
Several factors drive false-positive alerts. Common surnames, name order differences, and partial entries raise the odds of a resemblance match. Transliteration causes a second problem: “Yevgeny,” “Evgeniy,” and “Yevgenii” can represent one Russian name written three ways in Latin script, and a system built to catch every variant also catches every look-alike.
Identifiers narrow that uncertainty when present, but a record missing date of birth, nationality, address, or aliases forces an analyst back onto name similarity alone. Outdated or inconsistent data has the same effect. The matching rule itself is the last factor: broad rules raise alert volume, narrow rules raise the risk of missing a genuine match, and the right balance depends on risk appetite and jurisdiction.
Does the False Positive Rate Differ by Screening Type?
Onboarding screening runs once against a full set of identifiers, so its volume tracks customer growth. Transaction screening runs continuously against payment details that carry fewer identifiers, so the same name overlap produces far more alerts. Periodic rescreening adds a third pattern: one new designation can spike alerts across the whole customer base overnight, even when nothing about the customer has changed.
A false-positive rate quoted without naming which of these three produced it and how often that screening runs compares different things under one number. A rate from continuous transaction screening at high volume is not the same measurement as a rate from onboarding checks run a few hundred times a month.
What Risks Do Sanctions Screening False Positives Create?
Analysts investigate every alert regardless of outcome. Manual review runs 5 to 20 minutes per alert, so a team clearing 100 alerts a day loses roughly 8 to 33 hours to investigation, most of it on false positives. The same delay slows customer onboarding, vendor approval, and payments while alerts sit in the queue.
High volume also drives alert fatigue: analysts give each case less attention over a long shift, and two reviewers under that pressure can reach different conclusions on comparable alerts. That inconsistency is the real risk, since a genuine match handled with the same rushed attention as an ordinary false positive is what concerns a regulator, far more than the analyst hours involved.
How to Reduce Sanctions Screening False Positives?
Screen against more than a name. These identifiers give analysts context beyond the name itself and narrow the range of possible matches before an alert reaches manual review:
- Date of birth
- Nationality
- Address or location
- Passport or company registration number
- Known aliases
- Associated entities
That context only helps when the data behind it is complete and current, and thresholds should reflect the organization’s own risk appetite and jurisdiction exposure rather than a setting copied from elsewhere. Comprehensive sanctions, PEP, and criminal entity data give analysts more complete records to compare against. Review recurring alerts for a pattern worth adjusting, though a common surname triggering repeatedly isn’t automatically a flaw, and keep the underlying data current, since outdated records produce both stale false positives and missed updates.
Also Read – How to improve compliance with global sanctions screening
Vendor Data or In-House Matching: Which Cuts More False Positives?
Some institutions build matching logic against sanctions lists they maintain internally. Others license a vendor’s combined feed and apply their own thresholds on top of it. The trade-off centers on maintenance, not accuracy. An in-house list needs someone tracking every OFAC, UN, and EU update on a schedule that competes with other compliance priorities. A vendor feed shifts that maintenance to a dedicated team, though the institution still owns the matching thresholds and the investigation process built around what the vendor returns.
Neither choice fixes false positives by itself. A vendor with stale data produces the same accuracy problems as an unmaintained in-house list. What decides it is which side has the resources to keep the data current, not which approach is inherently more accurate.
Also Read – 8 Best Sanctions Screening Providers in 2026 (Verified Sanctions, PEP, and Criminal Entity Data)
How to Investigate a Potential Sanctions Match
Reducing false positives and investigating a potential match are two different tasks. Even a well-tuned system generates alerts that need a human decision, typically following this sequence:
Alert generated → Identifiers reviewed against the watchlist entry → Discrepancies checked → Decision documented → Case closed as false positive or escalated for further review
An aligned match escalates to compliance or legal staff, who decide whether to pause the relationship pending review. A company screening “Elena Petrova,” for instance, might find the date of birth, nationality, and passport number all match a sanctioned individual, moving the case straight into that escalation. Procedures for sign-off differ by organization and jurisdiction.
Sanctions screening also rarely runs alone. Most compliance programs check the same party against PEP and criminal entity records too, and those checks proceed on their own regardless of how the sanctions alert resolves. Sanctions Database covers global sanctions lists, PEP records, and criminal entities and outstanding warrants so analysts can review these additional risk indicators alongside sanctions screening when assessing a party.
Reducing False Positives Without Missing Genuine Matches
False positives come from matching against identity data that is incomplete, inconsistent, or written differently across sources. Catching every genuine match means accepting alerts on names that only resemble one. Better identifiers, current data, and carefully configured matching rules cut the unnecessary alerts and leave analysts with the cases that actually matter.
Explore Sanctions Database | Contact Us
Frequently Asked Questions
What is the difference between a false positive and a false negative?
A false positive is an alert that does not relate to the screened person or entity after investigation. A false negative is a genuine match that the screening system fails to flag at all, which carries a different and more serious compliance risk.
Does a high false-positive rate itself raise regulatory concern?
A high rate on its own is not typically a finding, since some volume is expected from broad name matching. Regulators tend to focus on whether the review process behind those alerts is consistent and well documented, not on the raw number of alerts a system produces.
Should compliance teams track their false-positive rate over time?
Tracking the rate helps a team spot drift in matching rules or data quality before it becomes a bigger problem. A rate that climbs steadily, or that concentrates around one list or rule, usually points to something specific worth adjusting.
Can automation fully replace manual review of a false positive?
Automation can pre-filter obvious non-matches and surface the right identifiers faster, but an expert still makes the final call on any alert with real ambiguity. Full automation carries its own risk if a genuine match gets closed without review.
How is a resolved false positive documented for audit purposes?
A typical record includes the alert details, the identifiers compared, the reason the match was ruled out, and who made the decision. That record is what an auditor or regulator reviews later to confirm the process was followed consistently.