
Sanctions Investigation Case Studies
Three illustrative examples showing the shape of a sanctions investigation, plus a selection of real scenarios from the course's own 45-scenario Sanctions Investigation Case Library.
The first three examples below are illustrative — invented to show the shape and depth of a real investigation, not an actual candidate's work or a real business's records. The scenarios after them are drawn from the course's 45-scenario Sanctions Investigation Case Library — detailed training scenarios modeled on real-world sanctions-screening red flags and evasion patterns; the names and identifiers in them are illustrative training material built for this course, not real persons or actual historical enforcement cases.
A Fuzzy-Name False Positive Resolved by Identifier Corroboration
Category: False Positive Resolution
Profile: An onboarding screen flags "Mihail Popescu," a new corporate customer, against a Blocking-list entry for a similarly-named individual with a materially different date of birth, nationality, and address on file for the list entry.
Red flags:
- Name similarity alone triggered the hit — a common surname in the relevant region
- No other declared identifier for the customer matched the list entry at intake
Investigation: L1 compares every available identifier: date of birth, declared nationality, and address all differ from the list entry. L2 sends an RFI to the customer's onboarding file for a certified copy of their passport, confirming a different passport number, nationality, and date of birth than the listed individual.
Finding: Illustrative finding: false positive — a coincidental name match with no corroborating identifiers, cleared and documented with the specific contradicting evidence on file (not merely "name doesn't look like a strong enough match," which would not be a defensible clearance on its own).
A Genuine Blocked-List Match Confirmed and Reported
Category: True Match — Blocking Program
Profile: A payment screening hit on an MT103 flags the ordering customer against an OFAC SDN entry with a strong name match and a matching declared nationality.
Red flags:
- Strong name match on a Blocking-list (SDN) entry, not a lower-severity Sectoral hit
- Declared nationality on the payment matches the list entry
Investigation: L2 sends an RFI to the ordering institution requesting date of birth, passport number, and registered address. All three come back as exact matches to the list entry — three independent identifiers now corroborate the name match, ruling out coincidence.
Finding: Illustrative finding: true match, confirmed — the payment is blocked (funds frozen, payment rejected and returned per the applicable program's treatment rules) and the required report is filed with the relevant authority within the mandated deadline, with the full identifier-comparison trail documented in the file.
A Structuring/Evasion Pattern Uncovered at L2
Category: Evasion Typology — Structuring
Profile: A series of payments, each individually unremarkable and below the screening system's per-transaction alert threshold, are flagged only after a periodic pattern review notices they consolidate into a single large transfer to the same ultimate beneficiary via a third-country aggregator.
Red flags:
- Multiple smaller payments clustered just under the alert threshold, to related beneficiaries
- A third-country aggregator with no disclosed commercial relationship to either party
- Payment timing consistent with deliberate avoidance of a known control rather than ordinary business cadence
Investigation: L2 reconstructs the full payment chain across the individually-small transactions, requests supporting documentation on the aggregator's relationship to the beneficiary via RFI, and finds no legitimate commercial rationale for the routing or the structuring pattern.
Finding: Illustrative finding: a pattern consistent with deliberate structuring to evade the screening threshold — escalated to L3, the underlying beneficiary confirmed against the relevant list, and reported accordingly. Recommendation: pattern-based (not just single-transaction) screening review for aggregator relationships going forward.
From the Real Case Library
SAN-B1-001 — Payment screening (MT103)
List hit: OFAC SDN (Blocking) · Algorithm: Fuzzy (Levenshtein, distance=1) · Matched variant: Andrei Sokolov (primary listed name)
L1: escalate_l2 — Single-character fuzzy match (v->b substitution) with no corroborating identifiers on file besides nationality. A Blocking-list hit of this nature cannot be cleared or confirmed without further identifiers. Escalating.
L2: escalate_l3 — DOB, passport, and address all confirmed via RFI as exact matches to the listed entry. This level of identifier correlation rules out coincidence. Escalating to L3 for blocking treatment and reporting.
L3: true_match_blocked_reported — Blocking list confirmed via three independently matched identifiers. Payment rejected and returned, funds blocked, OFAC report filed within the required deadline.
Outcome: Reject & return payment, block funds · Reported to OFAC within 10 business days
SAN-B1-002 — Name screening (onboarding)
List hit: EU Consolidated (Blocking) · Algorithm: Exact-after-normalisation · Matched variant: Jürgen Müller (primary listed name)
L1: escalate_l2 — Despite strong identifier matches (DOB, place of birth, nationality, address), this is a Blocking-list hit and passport/national ID remain unverified. Standing procedure requires L2 confirmation before any Blocking-list match is cleared, regardless of on-file corroboration strength. Escalating.
L2: escalate_l3 — Passport and national ID now confirmed, completing a full identifier match across all available fields. This is conclusively the listed individual. Escalating to L3.
L3: true_match_blocked_reported — Blocking list confirmed across a complete identifier match. Onboarding rejected, relationship frozen, report filed within deadline.
Outcome: Reject onboarding, freeze relationship · Reported to EU within required deadline
SAN-B1-008 — Payment screening (MT103)
List hit: OFAC Non-SDN (NS-CMIC) (Sectoral) · Algorithm: Token/word-level + name-order · Matched variant: Weiming Li (primary listed name)
L1: escalate_l2 — This is a Sectoral (NS-CMIC) list, not Blocking - identity confidence alone does not determine the correct outcome here; both identity confirmation and transaction-type analysis are required. Escalating.
L2: escalate_l3 — Identity confirmed via exact DOB match. The underlying transaction - a securities subscription - is confirmed as falling within NS-CMIC's restricted investment category. Escalating to L3 for sectoral treatment determination.
L3: true_match_sectoral_reported — NS-CMIC restricts new securities investment in this individual's listed holdings, and this transaction falls squarely within that restriction. The payment itself is blocked from proceeding, but this is not a full account freeze - correctly applying sectoral treatment rather than a blanket block. Logged and reported per NS-CMIC procedure.
Outcome: Block this specific transaction (securities investment); do not freeze the full relationship · Reported to OFAC within Not applicable - sectoral logging only
SAN-B2-004 — Payment screening (MT202COV)
List hit: OFAC SDN (Blocking) · Algorithm: Cover payment completeness screening (Wolfsberg Group standard) · Matched variant: N/A
L1: escalate_l2 — This MT202COV cover payment entirely omits the required underlying customer credit transfer detail (Sequence B) - a direct violation of Wolfsberg Group correspondent banking transparency standards specifically designed to prevent this kind of concealment. A $2.85 million cover payment with no underlying party information cannot be screened and cannot be cleared. Escalating with high priority.
L2: escalate_l3 — Underlying originator now confirmed as the designated individual following a delayed RFI response. The complete omission of Sequence B detail in the original cover message is a serious correspondent banking transparency failure independent of the identity confirmation. Escalating to L3.
L3: true_match_blocked_reported — Blocking list confirmed. Payment rejected and returned, $2.85 million blocked, OFAC report filed; correspondent relationship with the ordering institution referred for enhanced correspondent banking risk review given the repeated cover-payment transparency failure.
Outcome: Reject & return payment, block funds · Reported to OFAC within Per standard procedure
SAN-B2-016 — Payment screening (MT103)
List hit: OFAC SDN (Blocking) · Algorithm: Beneficial ownership screening triggered by routing anomaly review · Matched variant: N/A
L1: escalate_l2 — A USD payment between a US manufacturer and a UK consulting firm routed through a Bangkok intermediary bank has no apparent economic or correspondent-banking rationale - neither party has any disclosed connection to Thailand. This routing anomaly alone warrants beneficial ownership investigation of the beneficiary. Escalating.
L2: escalate_l3 — Beneficial ownership confirms the designated individual controls the beneficiary entity, and no legitimate rationale exists for the unexplained third-country routing. This is a confirmed transshipment pattern layering a designated individual's receipt of funds. Escalating to L3.
L3: true_match_blocked_reported — Blocking list confirmed via beneficial ownership. Payment rejected and returned, $620,000 blocked, OFAC report filed; the Bangkok intermediary relationship flagged for review given its unexplained use in this and potentially other transactions.
Outcome: Reject & return payment, block funds · Reported to OFAC within 10 business days
SAN-B2-025 — Payment screening (MT103, multiple)
List hit: OFAC SDN (Blocking) · Algorithm: Exact (final hop) + aggregation pattern detection · Matched variant: Stepan Fyodorovich Gusev (exact match at final consolidation point)
L1: escalate_l2 — Six separate payments, each individually sized just under common reporting thresholds, routed through a third-country payment aggregator with no disclosed connection to any of the six original senders, then consolidated into a single transfer to a beneficiary matching a designated SDN individual exactly. This aggregation-then-consolidation pattern is a sophisticated combination of structuring and layering. Escalating with priority.
L2: escalate_l3 — The final beneficiary is confirmed as the designated individual, and the preceding structured aggregation pattern - six sub-threshold payments from unrelated senders via an unconnected third-country aggregator - has no legitimate explanation. This is a corroborated combined structuring-and-layering scheme. Escalating to L3.
L3: true_match_blocked_reported — Blocking list confirmed. Final consolidated transfer rejected and returned, $51,200 blocked, OFAC report filed with priority flag; the underlying six-payment structuring-and-aggregation scheme referred to the relevant financial intelligence unit given its sophistication and the unrelated senders potentially requiring separate investigation as possible witting or unwitting facilitators.
Outcome: Reject & return final consolidated transfer, block funds · Reported to OFAC within Per standard procedure
This reference is part of Riskpro's Certified Sanctions Screening Expert (CSSE) programme.
See the CSSE course →