Sanctions Screening: Why Checking a Name Isn’t Checking a Company

In short
A clean sanctions screen only proves a supplier’s name isn’t on a list — it says nothing about who actually controls the entity behind it. Beneficial ownership, multi-jurisdiction list coverage, alert calibration and continuous rescreening are what separate a screening programme that holds up under scrutiny from one that only looks convincing on paper.
Most sanctions screening failures have nothing to do with the software running the check. The name gets matched correctly, the list is up to date, the alert logic works exactly as designed. The failure sits one layer deeper: in what the name itself can and cannot tell you about the company behind it. A supplier can pass every name-based screen a company runs and still be effectively controlled by a sanctioned party — not because the screening tool missed something, but because ownership structure was never what a name match was built to catch.
What name screening actually catches, and misses
Name screening does one thing well: it compares a registered company name, and sometimes known aliases, against consolidated sanctions and watch lists, and flags a match or a close variant. That is a real and necessary filter. An entity or individual listed under its own name will, in a properly run programme, get caught.
What it cannot do is look behind the name. A supplier’s legal name tells you nothing about who owns the shares, who sits on the board, who actually directs the entity’s decisions, or which other companies sit above it in a holding structure. A perfectly clean name is entirely compatible with a supplier that is majority-owned, or otherwise controlled, by a party that is itself sanctioned. Passing a name screen confirms that the front door is clear. It says nothing about who owns the building.
This is not a tooling gap that a better list or a smarter matching algorithm fixes. It is a structural limit of what name-based screening is designed to answer, and it is why a name check should be treated as the first filter in a due diligence process, not the conclusion of one.
Ownership and control: how indirect exposure works
Take a simple structure. Supplier A trades under a clean name that appears on no sanctions list anywhere. Supplier A is 60% owned by Holding Company B. Holding Company B is wholly owned by Individual C, who is sanctioned. Supplier A’s own name has never been listed and never will be, because it was never the target — but under the ownership-aggregation logic that most major sanctions regimes apply, a supplier majority-owned or controlled by one or more sanctioned parties is generally treated as if it carried the same exposure, whether or not it appears separately on any list.
Two things make this harder than it sounds. First, aggregation runs across layers, not just the immediate shareholder — regimes typically look through intermediate holding companies to identify who ultimately benefits from and directs the entity, which means the exposure can sit two, three or four steps above the name a company actually contracts with. Second, control does not require a majority stake at all: board appointment rights, veto rights over key decisions, or a contractual relationship that gives one party effective direction over another can create the same exposure that ownership would, even where no single shareholding crosses any threshold. A screening programme built only to match names against a list will never surface either of these — it has no ownership data to run the aggregation against in the first place.
Antoine Beaume-Dessertaine, Director of Internal Control and Compliance at Antin+, described what changed once ownership and integrity screening moved from a name-only check into a structured, automated evaluation process across the organisation’s 2,000 third parties:

We have digitised and structured our entire third-party creation and evaluation process. Across our 2,000 third parties, we have been able to map risk levels, automate controls, and integrate integrity reports — a genuine step up in maturity for our organisation.

Antoine Beaume-Dessertaine
Director of Internal Control and Compliance | Antin+
EU, UK and US lists don’t align
The operational consequence here matters more than the legal detail, and it is easy to underestimate if a company only deals with one regime day to day. The EU, the UK and the US each maintain and administer their own sanctions lists, through separate authorities, on separate timelines, using their own criteria for adding and removing names. Nothing requires these three processes to move in step, and in practice they don’t: a listing added under one regime does not automatically appear under another, delistings happen on different schedules, and the scope of what each regime reaches — including how far it extends beyond entities physically located within its own jurisdiction — is not identical across the three.
For a company operating in one jurisdiction, this rarely surfaces as a problem. For a multi-jurisdiction group, it becomes a concrete operational question rather than an abstract legal one: a supplier can be entirely clear against the list a headquarters team screens by default, and still be exposed under the list that applies to a subsidiary trading in a different market. Screening against a single list because it is the one closest to head office is a coverage decision, whether or not anyone intended it as one — and for a group that sells, buys or moves goods across several of these jurisdictions, that decision needs to be made deliberately, not by default.
False positives: the cost nobody budgets
Name matching against sanctions lists is, by design, biased toward over-triggering. Common names, transliteration variants, and companies that simply share a word with a listed entity all generate hits that have nothing to do with actual exposure. Every one of those hits needs a human to look at it, understand why it fired, and close it out with a reasoned decision.
Nobody budgets for that review capacity. Companies buy or subscribe to a screening tool, calibrate it loosely because a tighter calibration feels like more work up front, and end up with an alert volume that overwhelms whoever is supposed to review it. What happens next is predictable: reviewers start clearing alerts faster than they can genuinely assess them, exceptions get waved through under time pressure, and the programme that was meant to catch real exposure quietly becomes a formality nobody trusts, least of all the people running it.
This is a calibration problem, not a staffing problem, and it is usually solvable without simply hiring more reviewers. Matching logic can be tuned to the risk actually being screened for — a supplier operating in a low-risk sector and geography does not need the same sensitivity as one in a jurisdiction with heavy sanctions exposure — and alerts can be triaged so that genuinely ambiguous matches reach a reviewer while clearly irrelevant ones are resolved automatically, with the reasoning logged rather than silently discarded. A screening programme’s credibility is not set by whether it generates alerts. It is set by whether the volume of alerts stays inside what the review team can actually work through with judgement intact, and whether the team trusts what reaches them enough to look at it properly rather than clearing it on autopilot.
Onboarding screening vs continuous rescreening
A screening check run at onboarding answers one question: was this supplier clear on that day. It says nothing about the day after. Sanctions lists change — names are added and removed on an ongoing basis — and ownership structures change independently of any list update: a shareholder sells a stake, a sanctioned individual acquires a position in a company that was clean when the relationship began, a holding structure is restructured. A supplier that was genuinely clear at onboarding can become exposed eighteen months into the relationship without anyone at either company doing anything differently.
Treating screening as a single onboarding event, rather than something that runs continuously or is triggered by specific events, is one of the most common gaps in otherwise well-built programmes.
Thibaut Rongier, an IT project manager at Eiffage, described what shifted once compliance tracking stopped depending on someone remembering to re-check a file:

Integrating Aprovall directly into our procurement tool lets us secure our processes without changing our teams’ habits. Documents are collected once, pooled at group level and immediately accessible. That improves the quality of our supplier data, simplifies ongoing compliance tracking, and brings real operational value across every business line.

Thibaut Rongier
IT project manager | Eiffage
Evidencing a screening decision
None of this matters if a company cannot show, after the fact, exactly what it did. When a regulator, an auditor or a customer’s own compliance team asks about a specific supplier relationship, the question is rarely just “did you screen them.” It is what was checked, against which lists, on what date, what the result was, and — where a hit required judgement — who made the decision to proceed and on what basis. A screening record that cannot answer all of those specifically is not evidence of due diligence; it is a claim of due diligence, which is a materially weaker thing to be holding when someone is asking.
Building that record inside the systems a company already runs, rather than as a parallel manual log, is what makes it sustainable rather than something that decays the moment the person who set it up moves on. Alain Chenal, Procurement Methods & Performance Director at EGIS, described this as the real value of embedding the process into existing procurement infrastructure:

Aprovall was a full partner in building our new ERP ecosystem. Their involvement in the implementation, and their ability to align with our procurement strategy, played a key role in the project’s success.

Alain Chenal
Procurement Methods & Performance Director | EGIS
A name match is a fast, necessary, and entirely insufficient first step. What separates a screening programme that would actually hold up under scrutiny from one that only looks convincing on a policy page is whether it reaches past the name to the structure behind it, runs continuously rather than once, and leaves a record specific enough to answer the only question that ever really gets asked: not whether the company was screened, but whether it can prove it.
Book a meeting at our booth
Don’t miss this opportunity to connect with our team, see our solutions in action, and discuss how Aprovall can help you drive procurement excellence and stronger supplier risk management.
These articles might interest you
-
09 March 2026Supplier Information Management: Why Spreadsheets Fail Beyond 200 VendorsDue DiligenceSupplier Information: From Spreadsheets to Scalable Vendor Governance Supplier information becomes increasingly difficult to manage once vendor ecosystems exceed a few hundred partners. What begins as a simple spreadsheet often evolves into a fragile system of duplicated files, manual updates, and inconsistent data. At this scale, procurement teams need structured supplier information management to maintain […]Read more
-
27 April 2026Risk indicators for third-party managementDue DiligenceRisk indicators for third-party management Risk indicators help procurement teams spot early warning signals in supplier relationships before disruption occurs. Des plateformes comme Aprovall centralisent les données fournisseurs et structurent le suivi des risques tiers, avec 1,800+ customer organisations using the platform. Procurement teams are under pressure to keep operations running while increasing oversight expectations […]Read more
-
24 June 2026GRC: why ROI isn’t the right metric for measuring the value of your programmeDue DiligenceWhy ROI Is No Longer the Best Metric for Measuring GRC Programme Value When organizations evaluate Governance, Risk and Compliance (GRC) initiatives, the discussion almost always starts with ROI. How much time will be saved? How many manual tasks will disappear? How many operational costs will be reduced? These questions are legitimate — but they […]Read more
-
10 July 2026Supplier onboarding: why the first few weeks set the tone for the entire relationshipDue DiligenceThe Moment That Defines Everything That Follows Every supplier relationship has a founding moment. It is not the signing of the contract, nor the first invoice, nor the first delivery. It is the onboarding process, those first few weeks during which a new supplier discovers how your organisation works, what it expects, and whether it […]Read more