Back to blog

How Should a Sanctions Screening Tool Report a Check It Cannot Complete?

The one vendor test that exposes optimistic screening: ask what your tool says when it cannot complete a check. Honest screens report pending, not clean.

July 21, 2026By OilFlow Intelligence6 min readbuyer_intent

Screening a specific counterparty? Full 7-step dossier — $25, no account, report by email within the hour.

How Should a Sanctions Screening Tool Report a Check It Cannot Complete?

An honest sanctions screen reports an unverifiable check as pending or unverifiable, never as clear. Under FATF Recommendation 10, customer due diligence must be completed before or during onboarding, and OFAC's strict-liability standard means a missed match against the SDN List can trigger enforcement regardless of intent. A screening tool that collapses "could not verify" into "no hit" is manufacturing false confidence, and that false-negative posture is the single most revealing thing a buyer can audit before signing.

With Brent trading around $88.66 and Dubai firm, the Brent/Dubai EFS near $2.00/bbl is again favoring Eastern sour buyers, and Iran-linked barrels dominate the tape. That is precisely the market where mislabeled cargoes, opaque mandate chains, and dark fleet tonnage put pressure on screening. When the counterparty risk is highest, the difference between a tool that admits what it does not know and one that pretends it knows everything becomes a direct compliance liability. This is a test you can run in a single demo.

Why False Negatives, Not False Positives, Survive the Audit

Most procurement conversations obsess over false positives. Buyers want fewer alerts, less analyst fatigue, faster onboarding. That is an operational preference, not a compliance one. A false positive costs you an analyst's time. A false negative costs you an enforcement action.

The asymmetry is total. When an examiner reviews your file after the fact, a false positive shows up as work you did that turned out to be unnecessary. A false negative shows up as a designated party you cleared. OFAC operates on a strict-liability basis for many programs, meaning you do not need to have intended the violation to be liable for it. The record that survives the audit is the record of what you cleared, not what you flagged.

This is why the treatment of incomplete checks matters more than any accuracy percentage a vendor puts in a slide deck. An accuracy figure averages over the checks the system completed. It says nothing about the checks it silently abandoned. If a tool cannot resolve a beneficial-owner query, cannot reach a list source, or cannot parse a transliterated name, the honest outcome is to say so. The optimistic outcome is to return "clear" and move the onboarding forward.

The Three States an Honest Screen Must Report

A defensible screen distinguishes three outcomes, not two:

  • Hit. The system matched the subject against a designation or watchlist entry and is escalating for review.
  • No-hit. The system completed the check against current, refreshed lists and found nothing.
  • Could-not-verify (pending). The system attempted the check but could not complete it, because a source was unreachable, a name could not be disambiguated, an ownership chain could not be resolved, or a list was stale.

The entire test reduces to one question: does the vendor's tool have a genuine third state, or does it force every result into hit or no-hit?

Optimistic vendors collapse pending into no-hit. From the outside, the onboarding looks complete. Green light, clear, proceed. But the check never happened. You have a layer of the mandate chain that was never actually screened, presented in your system of record as though it were. That is a layer cake of unverified counterparties dressed as verified ones, and it is exactly the structure that lets a dark fleet operator or a front company slide through onboarding.

List-Coverage Transparency: What Was Checked, and When

The pending state only means something if you also know what "complete" would have required. A tool that reports no-hit against a thin or stale list universe is delivering a false negative by omission. So the second half of the audit is list-coverage transparency.

Ask the vendor to enumerate, per check, exactly which lists were queried:

  • OFAC SDN List and the OFAC Consolidated (Non-SDN) lists, including sectoral programs.
  • OFAC Sectoral Sanctions Identifications (SSI) List, which restricts specific dealings rather than full blocking, and is frequently missed by tools built only for the SDN binary.
  • EU Consolidated List of persons and entities subject to financial restrictions.
  • UK OFSI Consolidated List of asset freeze targets.
  • UN Security Council Consolidated List.

Coverage alone is not enough. Two mechanics separate honest coverage from a checkbox:

Ownership aggregation. OFAC's 50 Percent Rule provides that any entity owned 50 percent or more, directly or indirectly, by one or more blocked persons is itself blocked, even if it never appears on the SDN List by name. A tool that screens only the named entity and does not attempt to resolve the ownership chain will return no-hit on a blocked subsidiary. Ask the vendor: when the tool cannot resolve ownership to the 50 percent threshold, does it return no-hit or pending? The correct answer is pending. The subject is unverified, not clean.

List refresh recency. A list checked against a snapshot from three weeks ago is not the current list. New designations post continuously. Ask the vendor to show you, on a given result, the timestamp of the list version that was queried. If the tool cannot tell you when its OFAC or OFSI data was last refreshed, then no-hit is a claim it cannot actually support.

How to Make a Vendor Demonstrate a Pending State Live

Do not accept a verbal answer. Make the vendor produce a pending state in front of you in the demo. Three ways to force it:

  1. Submit an ambiguous name. Provide a common transliterated name with a plausible near-match to a designated party, without enough identifiers to disambiguate. An honest tool cannot confirm or exclude the match and should surface an unverifiable state, not a clean pass.
  1. Submit an entity behind an opaque ownership chain. Give the tool a corporate name whose beneficial ownership cannot be resolved from available data. Watch what it returns. If it returns no-hit rather than flagging the unresolved 50 Percent Rule exposure, you have found the false-negative posture.
  1. Ask to see the result record for a source failure. Ask what the system writes to the audit trail when a list source is unreachable at query time. If the result silently becomes no-hit, that is a manufactured clear. If it becomes pending with the failure logged, that is a screen you can defend to an examiner.

The MLRO signing off on this vendor is signing off on how these three scenarios resolve. If the demo cannot produce a pending state on demand, the tool very likely does not have one, and every incomplete check it has ever run is sitting in the record as clean.

This is the design principle OilFlow builds around: an incomplete check is reported as incomplete, so the compliance record reflects what was actually verified rather than what the workflow assumed. You can request a demo to run the three-scenario test above against live output.

What Compliance Teams Should Do

  • Add one question to every screening RFP: "When your tool cannot complete a check, what does the result say?" If the answer is "clean" rather than "pending" or "unverifiable," that is the false-negative posture you are buying.
  • Require a live pending-state demonstration. Use an ambiguous name, an unresolvable ownership chain, and a simulated source failure. Confirm each produces an unverifiable result, not a no-hit.
  • Audit list coverage per check. Confirm the tool queries OFAC SDN, OFAC Consolidated and SSI, EU Consolidated, UK OFSI, and UN lists, and can display the refresh timestamp for each.
  • Test the 50 Percent Rule directly. Confirm that an unresolved ownership chain returns pending, not clean, in line with OFAC's aggregation standard.
  • Map the vendor's posture to FATF Recommendation 10. Your CDD obligation is not satisfied by a check the system abandoned. If the tool cannot show which steps completed, it cannot evidence completed due diligence.

Most procurement processes never ask the one question that matters. The vendor's treatment of the check it could not finish is the whole test. Ask it plainly, make them prove it live, and you can audit a screening vendor's honesty before you ever sign.

For evergreen sanctions typology briefings written for MLROs and compliance officers, subscribe to the OilFlow Intelligence newsletter.

Verified trade-fraud patterns, sanctions deltas, and regulator actions. Weekly, for compliance and risk teams.

Double opt-in. No spam. The quarterly Compliance Index ships to subscribers first.

This article is part of our scam-cluster intelligence series. Screening a specific counterparty? Run the free check, or order the full 7-step dossier.