Sanctions Red Flags & Evasion Typology Reference — CSSE by Riskpro

CSSE badge
CSSE · Certified Sanctions Screening Expert

Sanctions Red Flags & Evasion Typology Reference

A working reference of the evasion patterns a sanctions screening program has to defend against — name manipulation, intermediaries, structuring, front companies, routing, and document discrepancies — with the specific red-flag indicators investigators look for in each.

Name & Transliteration Manipulation

Deliberately or coincidentally altering how a name is written to avoid triggering a screening match, exploiting the legitimate variance transliteration and spelling naturally produce.

  • A single-character substitution or transposition in an otherwise exact name match, with no other corroborating identifiers on file
  • A name rendered in an unusual or inconsistent transliteration compared to how the same underlying name normally appears
  • Name order reversed or reformatted in a way that happens to avoid a straightforward field-by-field match
  • An alias or "also known as" variant appearing on supporting documents that doesn't match the name used in the transaction itself

Intermediaries & Shell Entities

Using an ostensibly unconnected company or individual to insert distance between a sanctioned party and a transaction, obscuring true beneficial ownership or involvement.

  • A payment purpose (consulting fee, service payment) routed through a third-country entity with no disclosed business relationship or contractual nexus to the underlying activity
  • A beneficiary company with no verifiable trading history, physical presence, or public information
  • Ownership or control structures that terminate in undisclosed or unverifiable ultimate beneficial owners
  • Sudden introduction of a new intermediary into a previously direct payment relationship, with no stated business reason

Structuring Below Screening Thresholds

Splitting a transaction, or routing it through aggregation, specifically to stay under a screening or reporting threshold rather than reflecting genuine, unstructured business activity.

  • Multiple smaller payments to the same or related beneficiaries clustered just under a known threshold
  • A pattern of consolidated small payments through a third-country aggregator before a final transfer to the true beneficiary
  • Payment timing or sizing that only makes sense as an attempt to avoid a specific control, not as ordinary commercial practice

Front Companies

A company that exists primarily to give a sanctioned party a facade of ordinary commercial activity, concealing their actual involvement or control.

  • A company whose declared business activity does not match the nature or scale of the payments passing through its accounts
  • A registered address shared with numerous unrelated entities, or matching a known formation-agent address
  • Directors or signatories with no apparent operational role, replaced frequently with no clear reason

Third-Country Routing

Routing a payment through a jurisdiction that has no genuine connection to either party or to the underlying commercial activity, specifically to distance the transaction from a sanctioned party or program.

  • A trade-finance or freight payment routed through a country not appearing anywhere on the shipping manifest
  • A correspondent banking chain that includes an unnecessary hop through a high-risk or historically-evasion-linked jurisdiction
  • A payment chain that happens to pass through a second, separately sanctioned jurisdiction with no commercial rationale
  • Sequential wires through several jurisdictions before reaching a final beneficiary, adding distance without adding commercial substance

Document & Identifier Discrepancies

Missing, truncated, or inconsistent fields in a payment message or supporting documentation, whether from genuine sloppiness or a deliberate attempt to strip identifying detail before it reaches a screening filter.

  • A beneficiary or ordering-customer field truncated to a generic placeholder ("Customer," "valued client") rather than a real name
  • A cover payment (e.g. MT202COV) with the underlying party details present in the original message but stripped from the cover
  • Party details relocated into a non-standard free-text field rather than the structured field a screening filter actually scans
  • A SWIFT gpi tracker reference that doesn't match earlier legs of the same payment chain, suggesting the message was altered mid-route

This reference is part of Riskpro's Certified Sanctions Screening Expert (CSSE) programme.

See the CSSE course →