Fraud Intelligence
What Does a Free Counterparty Pre-Screen Actually Prove, and Where Does It Stop?
A free counterparty pre-screen is a fraud-cluster pattern match, not a sanctions or UBO check. What "no match" proves, what it misses, and when to escalate.
Screening a specific counterparty? Full 7-step dossier — $25, no account, report by email within the hour.
What does a free counterparty pre-screen actually prove, and where does it stop?
A free counterparty pre-screen is a first-party pattern match. It checks one name, entity, vessel, email domain, or contact identifier against fraud clusters a research desk has documented first-hand, and it answers exactly one question: have we seen this counterparty inside a pattern we already traced? It is not a screen against the OFAC Specially Designated Nationals (SDN) List, the UK OFSI consolidated list, the EU consolidated list, or the UN Security Council consolidated list. It is not a beneficial ownership trace under OFAC's 50 Percent Rule, and it does not discharge customer due diligence under FATF Recommendation 10. A "no match" result means screening has not yet been performed. It never means cleared.
That distinction is the whole article. Everything below is scope discipline.
Why scope confusion gets expensive on this tape
Brent at 89.46, WTI at 83.79, Dubai at 87.46. Brent-Dubai EFS sitting near 2.00, WTI-Brent near minus 5.67. Wide arbs move barrels onto routes that a given desk has never traded, and a Hormuz-driven risk premium adds urgency to every quote.
That combination produces a predictable operational pattern: unfamiliar counterparties surface on unfamiliar lanes, introduced by intermediaries nobody in the room has transacted with before. Deal tempo rises. Documentation gets thinner and later. The commercial pressure to say yes arrives before the diligence file is anywhere near complete.
This is precisely the environment in which a fast, free negative signal gets over-read. A trader forwards a screenshot of a clean pre-check result to the MLRO, the MLRO files it, and a narrow pattern-match negative silently becomes an institutional statement about legitimacy. That is a category error, and it is the error worth engineering against.
The one question a cluster pre-check answers honestly
A fraud cluster is a documented set of linked identifiers: company names and their re-registrations, individual names and aliases, phone numbers, email domains, document templates, bank corridors, and the mandate chains that route introductions between them. Clusters are built by tracing actual approaches, actual document sets, and actual payment instructions, then linking them where the evidence supports a link.
A hit against that corpus is high-value and immediately actionable, because it is not probabilistic reputation scoring. It means this identifier appeared inside a pattern that has already been mapped. Practically, a hit tells you three useful things at once:
- Where in the chain the counterparty sits. Principal, mandate, intermediary, or document supplier. In a layer cake structure, the same fraud operator commonly appears at several tiers under different corporate wrappers, and the cluster shows the tiers.
- Which typology to expect next. Advance-fee patterns built on unsolicited EN590 offers, LOI and ICPO exchanges that never mature into a lifted cargo, tank storage receipts that cannot be verified with the terminal, or pressure to open a DLC MT700 against a seller who will not accept an inspection regime.
- What documents to demand and disbelieve. Cluster work exposes reused templates, recycled tank numbers, and signature blocks that migrate between entities.
A hit is the cheapest useful thing in counterparty screening. It is also the only thing a free pre-check is designed to deliver.
The four things a free pre-screen does not answer
1. It is not a sanctions screen
A cluster match says nothing about designation status. Sanctions exposure is a separate obligation discharged against primary sources: the OFAC SDN List and OFAC's Non-SDN lists, the UK sanctions list maintained by OFSI under the Sanctions and Anti-Money Laundering Act 2018, the EU consolidated list, and the UN Security Council consolidated list. Counterparties, vessels, and controlling persons all require screening, at onboarding and on an ongoing basis, against current list versions.
In crude and products, this extends to vessel-level checks. Dark fleet activity, AIS gaps, ship-to-ship transfers in known transhipment zones, and attestation gaps under the price cap regimes are sanctions and trade-control questions. No fraud cluster corpus substitutes for them.
2. It is not a beneficial ownership trace
FATF Recommendation 10 requires that financial institutions identify the beneficial owner and take reasonable measures to verify that identity, understand the ownership and control structure, and understand the purpose and intended nature of the relationship. OFAC's 50 Percent Rule adds an aggregation test that no name-matching exercise reaches: an entity owned 50 percent or more, directly or indirectly, in the aggregate, by one or more blocked persons is itself treated as blocked even though it does not appear on the SDN List by name.
Aggregation across nested holdings is exactly what a layer cake is built to defeat. Establishing ultimate beneficial ownership requires corporate registry work, register access under the EU's anti-money laundering framework where available, and structured questioning of the counterparty about who controls the entity and who benefits from the trade. A pre-screen does none of that.
3. It is not an adverse-media sweep
Negative news, litigation history, insolvency filings, regulatory enforcement actions, and politically exposed person status sit outside a fraud cluster corpus. FATF Recommendation 12 sets the PEP expectations separately: senior management approval for the relationship, reasonable measures to establish source of wealth and source of funds, and enhanced ongoing monitoring. A counterparty can be entirely absent from any documented fraud cluster while carrying a PEP profile, an unresolved enforcement matter, or an adverse-media footprint that changes the risk rating outright.
4. Absence of a match reflects the corpus boundary, not the counterparty
This is the one that matters most. A negative result describes the edge of what has been documented. Newly incorporated entities, first-time approaches, jurisdictions where a research desk has thinner coverage, and operators who have not yet been traced all return the same clean-looking output as a genuinely legitimate refiner.
Read literally, the output is: this identifier does not appear in the clusters we have documented. Read carelessly, it becomes: this counterparty is fine. The second reading converts a narrow negative signal into a false positive on legitimacy, and it is the single most damaging way to misuse a free tool.
The escalation ladder
Scope discipline only works if there is a defined next step. Treat the pre-check as tier one of three.
Tier one, free cluster pre-check. Use it on every new name, early, before commercial terms harden. A hit stops the deal and reroutes it to the MLRO. A miss advances nothing on its own.
Tier two, paid counterparty dossier. At 25 dollars, a dossier exists to close the gap between "not in our clusters" and "we have looked properly at this specific entity." Escalate here whenever any of the following is present:
- First-time counterparty with no transaction history at your institution.
- An unfamiliar intermediary or mandate holder, particularly where the mandate chain has more than one tier between you and the claimed principal.
- Payment routing that diverges from the trade lane, for example a Gulf-origin EN590 cargo settling through a corridor with no commercial connection to the loadport or the buyer's domicile.
- Documentation that arrives late, arrives edited, or arrives with metadata inconsistent with the issuing party.
- Refusal to accept an independent inspection regime, or pressure to move to a DLC MT700 before the seller's title and tank position can be verified.
- Vessel nomination showing AIS gaps, recent flag changes, or ownership that resolves into a structure consistent with dark fleet operation.
Tier three, full counterparty diligence. Sanctions screening against primary lists, UBO resolution with 50 Percent Rule aggregation, PEP and adverse-media checks, source of funds, and documented risk rating with a decision owner named. This is what FATF Recommendation 10 and your domestic transposition actually require, and it is the only tier that produces an audit trail capable of surviving a supervisory review.
How to record the result so it cannot be misread
The fix is largely a language fix inside your own file notes. Three practices, all cheap:
- Ban the word "clear" for tier-one output. The permitted phrasings are "no known cluster match" and "cluster match, escalated." Nothing else.
- Timestamp and scope every entry. Record what was checked, what was not checked, and against which corpus. A note reading "pre-check run, sanctions and UBO outstanding" is defensible. A note reading "screened, clean" is not.
- Make escalation a control, not a judgement call. If a trigger from the tier-two list is present, the dossier is mandatory regardless of how the pre-check returned. Traders should not be able to close a file with a negative pattern match alone.
What compliance teams should do
- Run the free pre-check first, on every new name. It is the cheapest point in the process to catch a documented operator, and a hit is worth more than any amount of later reconstruction. Start at the free cluster pre-screen.
- Write the limitation into the procedure, not the training deck. The onboarding checklist should state in terms that a cluster pre-check does not satisfy sanctions screening, UBO identification, adverse-media review, or PEP assessment.
- Screen sanctions against primary sources, always separately. OFAC SDN and Non-SDN lists, OFSI, EU, and UN consolidated lists, at onboarding and on an ongoing basis, covering counterparties, controlling persons, and vessels.
- Aggregate ownership deliberately. Apply the 50 Percent Rule across indirect holdings and document the arithmetic. Where a layer cake blocks resolution, treat unresolvable ownership as a risk finding in its own right, not an open question to be revisited later.
- Escalate on trigger, not on instinct. First-time counterparty, extra mandate tier, off-lane payment routing, late or edited documents, inspection refusal, or a vessel with dark fleet indicators. Any one of these moves the file to a counterparty dossier and then to full diligence.
- Give the MLRO the negative results too. Patterns in what a desk is being approached with matter as much as individual hits. Aggregated approach data is how new clusters get documented in the first place.
The honest claim for any free pre-screen is narrow: it tells you whether a counterparty is already inside a documented fraud pattern. Wide arbs and elevated freight risk premia will keep pushing unfamiliar names onto your screens, and the temptation to treat a fast negative as clearance will keep rising with deal tempo. Hold the line on the reading. No known match, screening not yet performed.
For weekly typology work on mandate chains, layer cake structures, and dark fleet documentation patterns, subscribe to the OilFlow Intelligence briefing.
OilFlow Intelligence
Verified trade-fraud patterns, sanctions deltas, and regulator actions. Weekly, for compliance and risk teams.
Double opt-in. No spam. The quarterly Compliance Index ships to subscribers first.