Back to blog

Sanctions Screening Vendor Evaluation: Does "Clear" Mean Checked, or Just Not Checked?

Sanctions screening vendor evaluation: how to tell a completed check from a silent failure. The pending-bucket test, the OFAC 50 Percent Rule, and a 7-question script.

August 18, 2026By OilFlow Intelligence8 min readbuyer_intent

Screening a specific counterparty? Full 7-step dossier — $25, no account, report by email within the hour.

Sanctions screening vendor evaluation: how do I tell whether "clear" means the check was completed, or just that it failed silently?

Ask the vendor to show you a screening output that contains at least one check the tool could not complete, with the reason attached. A defensible product distinguishes three states: matched, checked and clean, and unresolved. A tool that collapses the third state into the second is not being conservative, it is converting missing data into a false negative, and FATF Recommendation 10 already treats "CDD could not be completed" as an actionable condition rather than a pass. OFAC's own compliance guidance is consistent on the same point: list screening is not a substitute for risk-based due diligence, and a name that does not appear on the OFAC SDN List has not thereby been cleared.

If you have three vendor demos booked this month, this is the one question that will separate the products from the dashboards. Every demo shows you the hits. The hits are easy. What you need to see is the misses by omission.

The three possible answers, and why only one survives an examination

Put the question to the sales engineer in plain terms. A counterparty ownership chain terminates in a jurisdiction with no accessible beneficial ownership registry. A vessel's IMO number does not reconcile with the name on the bill of lading. The list snapshot in the index is older than the last publication cycle at one of the sources. What does the output say?

There are only three answers.

It says "clear." This is disqualifying, and it should end the procurement conversation. The tool has taken an absence of evidence and rendered it as evidence of absence. When your regulator or your correspondent bank later asks what you knew about the ultimate beneficial owner, the audit trail will say the system checked and found nothing adverse. It did not check. Nobody in the room will be able to tell the difference retrospectively, which is precisely the problem.

It says nothing. The field is blank, the row is absent, the section is omitted. This is close to as bad, because a null is operationally indistinguishable from a pass to the analyst working a queue at volume. If the only way to detect an incomplete check is for a human to notice which fields are empty, the control depends on attention rather than design.

It says "pending" or "unverified," and names the step that failed. Ownership chain unresolved at tier three, registry inaccessible. IMO to name mismatch, manual confirmation required. List source last ingested outside expected cadence. This is the only output that an MLRO can defend, because it produces a decision point rather than a false comfort. It also produces a record that the institution considered the gap and either escalated, sought additional documentation, or declined.

The OFAC 50 Percent Rule turns ownership into an arithmetic problem your screen may not be doing

OFAC's 50 Percent Rule states that an entity owned 50 percent or more, directly or indirectly, in the aggregate, by one or more blocked persons is itself blocked, whether or not it appears on the SDN List. The operative words are indirectly and in the aggregate. Two designated shareholders holding 26 percent each through separate intermediate holding companies produce a blocked entity that no name-matching engine will ever flag, because the entity's own name is not on any list.

That is an ownership-aggregation calculation, and it requires complete data at every tier of the structure. When a tier is opaque, the arithmetic cannot be performed. A screening tool has two honest options at that point: report the aggregation as indeterminate, or state which tier it could not resolve. Reporting "no match" is a category error. It answers a question about name matching when the question on the table is about ownership.

This is where the layer cake structures common in intermediated physical trade become a screening problem rather than merely a documentation problem. A mandate chain running through several jurisdictions, each layer holding a minority interest, each layer nominally independent, is not necessarily fraudulent. It is, however, exactly the structure that defeats aggregation logic quietly. The distinction between a chain you resolved and found clean, and a chain you could not resolve, is the entire control.

List coverage is a cadence question, not a checkbox

Vendors will tell you they cover the major lists. Make them enumerate the sources and state the ingestion cadence for each one separately. Four that any physical energy programme touches routinely are the OFAC SDN List, the UK sanctions list maintained by OFSI, the EU consolidated list, and the UN Security Council consolidated list. These are distinct authorities publishing on their own schedules. They are not synchronised with each other, and there is no reason to expect them to be.

A product that presents them as a single merged index without exposing the freshness of each component has hidden the risk rather than managed it. If the EU list in the index is current and one of the others is not, the correct output is a partial result with the stale component identified. If you cannot see per-source freshness in the interface, you cannot know which of your "clear" results rested on a snapshot that predated a designation.

Ask directly: if one source fails to ingest overnight, does the morning screening run still return results, and do those results say which source was missing?

Vessel-side unresolved states are their own category

On the counterparty side the failure mode is ownership. On the vessel side it is identity. An IMO number is durable, a vessel name is not, and transliteration across alphabets produces variants that fuzzy matching handles inconsistently. Dark fleet operating patterns compound this, because the whole point of the practice is to make identity resolution expensive: name changes, flag changes, registry gaps, and AIS transmission gaps that cannot be reconciled against a plausible voyage.

An AIS gap is not by itself evidence of anything. Equipment fails, coverage is imperfect. But an AIS gap that a tool cannot reconcile is an unresolved check, and it should be reported as one, with the window and the location. The wrong output is a green tick on the vessel screen because the current name did not match a listed name. The right output is a vessel record that says identity confirmed to IMO, position history incomplete between these dates, escalate before releasing documents.

This matters most at the point where a screening result meets a documentary trigger. When an LOI is presented, when an ICPO arrives from an intermediary you have not transacted with, when a DLC is advised by MT700 against an EN590 parcel, somebody is about to act on a screening result. If that result cannot tell them what it did not check, the control has already failed.

Why the current freight picture multiplies the chains a screen can fail to resolve

Crude opened firmer with Brent around $91.08 and WTI at $84.87, and with the Brent-Dubai EFS near $2.00 the economics continue to push Atlantic Basin barrels east. Longer, more intermediated East-of-Suez voyages mean more counterparties per cargo, more intermediate title transfers, and more ownership chains for a screen to attempt and potentially fail to resolve. The volume of unresolved checks in a programme is not a constant. It rises with routing complexity, which means a tool that hides them hides more of them precisely when the exposure is greatest.

The procurement script

Use this in the demo. It takes under five minutes.

  1. "Show me a screening output, redacted as you need, that contains at least one unresolved check." If they cannot produce one, the product does not have the state.
  2. "Where in this output does it tell me why the check did not complete?" Look for a named failing step, not a generic warning banner.
  3. "If an ownership tier is opaque, does the record say no match, or does it say aggregation indeterminate at tier N?"
  4. "Show me per-source list freshness for OFAC, OFSI, the EU consolidated list, and the UN consolidated list."
  5. "If one source fails to ingest, does the run still return, and does the result disclose the omission?"
  6. "Can I report on the population of unresolved checks over a period, and their ageing?" An unresolved state that nobody can enumerate is not a control, it is a footnote.
  7. "Does the audit trail preserve the unresolved state, or does it record only the final disposition?" Examiners ask what you knew at the time.

OilFlow Intelligence is built around the pending state as a first-class output rather than an error condition, with the failing step named and multi-source list provenance exposed per check. That is a design position, and it is the position we would apply to any vendor including ourselves: request a walkthrough and hold it to the same seven questions.

What compliance teams should do

  • Make the pending bucket a written procurement requirement. Not a nice-to-have in the scoring matrix. A gate. A tool that cannot express "could not check" cannot support a risk-based programme under FATF Recommendation 10, which contemplates declining the transaction where CDD cannot be completed.
  • Demand the redacted artefact before contract. A screenshot of a hit is a marketing asset. A screenshot of an honest failure is evidence of engineering.
  • Separate name matching from ownership aggregation in your own procedures. Record them as two results. The OFAC 50 Percent Rule is not satisfied by a clean SDN name check.
  • Instrument unresolved checks as a metric. Count them, age them, and review the oldest weekly. If the number is always zero, the state is decorative.
  • Tie vessel identity resolution to documentary release. No LOI acceptance, no MT700 action on an EN590 or comparable parcel while vessel identity or position history sits unresolved.
  • Have the MLRO sign off on the definition of "clear." Whatever the tool means by that word becomes your institutional position under examination. Read it before you buy it.

The most expensive result any screening system can return is a clean one it did not earn. Ask to see the pending bucket. If there isn't one, you are buying theatre.

Verified trade-fraud patterns, sanctions deltas, and regulator actions. Weekly, for compliance and risk teams.

Double opt-in. No spam. The quarterly Compliance Index ships to subscribers first.

This article is part of our scam-cluster intelligence series. Screening a specific counterparty? Run the free check right here, or order the full 7-step dossier.

Paste any company, person, or vessel name. Free, no signup, answer in seconds.