What is a false negative in sanctions screening?
A quiet alert queue can mean there is nothing to find, or that the configuration is not finding it, and nothing on the screen separates the two. A false negative is a genuine match that screening failed to return: a designated party who passed the check unnoticed.
False negatives are the failure that produces breaches, and they are structurally hard to spot, because nothing appears in the queue to review. They are found by testing rather than by operating: seed known list entries and their variants into a screening run and check that the system returns them. Thresholds set too high, missing alias or transliteration handling, incomplete list scope and stale data are the usual causes.
What this workflow covers
SCOPE- Test with seeded records, verify list freshness, and confirm the list scope against your legal nexus.
- An engine configured for exact matching misses a listed name written with a different transliteration of the same Cyrillic original.
- Name screening alone reports nothing on a counterparty blocked because a designated person owns 50 percent or more of it.
- A no-match is not a false negative. No-match means nothing met the criteria in the sources checked; a false negative means the criteria or the data were wrong.
Compliance glossary
TERMS- Model testing
- Deliberately running known list entries and variants through screening to measure whether the configuration returns them.
- List scope
- The set of registers a firm screens against, chosen from its legal nexus, currencies and counterparties; gaps in scope produce structural false negatives.
Authoritative references
SOURCES- 01A Framework for OFAC Compliance Commitments
U.S. Department of the Treasury — OFAC
- 02The FATF Recommendations — targeted financial sanctions (Recommendations 6 and 7)
Financial Action Task Force
Frequently asked questions
Q&A- How would we even know we have false negatives?
- By testing, not by monitoring. Seed known list entries, aliases and transliteration variants into a run and confirm the system returns them. Independent testing of the screening configuration is a standard expectation in sanctions compliance programmes, and it is the only control that looks for this failure.
- What causes most of them?
- Stale or incomplete list data, and configurations tuned tightly to suppress noise. Missing alias handling and no transliteration support are close behind, particularly for names originally written in non-Latin scripts.
- Does a no-match mean the counterparty is not sanctioned?
- No. It means no match was found in the sources checked, on that date, with those identifiers. Ownership rules, non-public data and lists outside your scope can all leave a genuinely restricted party unmatched.