The Sanctions Screening Problem in Africa: When Names, Identities and Data Don’t Match

Why sanctions screening is not simply a name-matching exercise

A customer opens a bank account.

The name is entered into the screening system.

A potential sanctions match appears.

The compliance analyst looks at the result.

The names are similar.

But the date of birth is different.

The nationality does not match.

The customer has a different passport number.

The address is in another country.

Is this a sanctions match?

Or is it simply a false positive created by imperfect data?

This is one of the most common challenges in sanctions screening.

And in African financial markets, the problem can become particularly complex because names, identity documents, addresses and customer data do not always fit neatly into the structures expected by automated screening systems.

Sanctions screening is therefore not just about asking:

“Does this name match a sanctions list?”

It is about asking:

“Do the available identifiers demonstrate that this is actually the same person or entity?”

That distinction is critical.


A name is not an identity

One of the fundamental problems with automated sanctions screening is that a name is only one identifier.

The United Nations Security Council Consolidated List, for example, contains multiple fields that can help identify individuals, including original and Latin-script names, aliases, date and place of birth, nationality, passport numbers, national identification numbers and addresses.

This is important because two completely different people can have similar or even identical names.

Consider:

Mohamed Ahmed

That name alone tells an investigator very little.

Now imagine two customers:

Customer A

  • Mohamed Ahmed
  • Born in 1988
  • Senegalese
  • Passport ending 4821

Sanctions subject

  • Mohamed Ahmed
  • Born in 1964
  • Sudanese
  • Passport ending 7714

The names may generate an alert.

But the additional information may strongly suggest that they are different individuals.

This is why a screening alert should normally be treated as the beginning of an investigation, not the conclusion.


African naming conventions can make screening harder

There is no single African naming convention.

Across the continent, names can reflect different combinations of:

  • Family names
  • Given names
  • Patronymics
  • Multiple surnames
  • Religious names
  • Traditional names
  • Clan names
  • Maternal or paternal family names
  • Nicknames
  • Names adopted later in life

The way a person’s name is recorded can therefore vary between documents and systems.

A person’s passport might show:

Mamadou Abdoulaye Diallo

while another database might store:

Diallo Mamadou A.

A mobile-money account might contain:

Mamadou Diallo

And an international payment might display:

M. A. Diallo

To a human investigator, these records may obviously relate to the same person.

To an automated screening system, they can produce very different results.

The opposite problem can also occur.

Two different individuals may be represented by very similar names.

This creates both:

false positives

and potentially:

false negatives.


Transliteration creates another layer of complexity

Names can also change when they move between writing systems.

The UN sanctions lists themselves recognise this problem by providing names in original scripts as well as Latin script where relevant.

A name written in Arabic, for example, may have multiple possible Latin-script transliterations.

The same individual could therefore appear under different spellings.

A similar issue can arise when names are converted from other scripts or when local databases standardise names differently.

For example, a name might appear as:

Abdel Rahman

Abdulrahman

Abdelrahman

Abd al-Rahman

These may or may not refer to the same person.

The problem is not simply linguistic.

It becomes a compliance problem when an institution relies heavily on automated matching without sufficient contextual information.


Weak data creates strong screening problems

Screening technology can only work with the information available to it.

If a customer record contains:

Name: John Doe

but no:

  • Date of birth
  • Nationality
  • Passport number
  • Address
  • Place of birth

then the analyst has limited information with which to determine whether a potential match is genuine.

This is why customer-data quality matters so much.

The UN sanctions framework itself provides a useful illustration: its consolidated list contains numerous identifiers precisely because names alone are often insufficient for positive identification. The list distinguishes between “good quality” aliases that may support positive identification and “low quality” aliases that are probably insufficient on their own.

The lesson for financial institutions is straightforward:

Better KYC data produces better sanctions screening.


The false-positive problem

False positives are not just an inconvenience.

They can become an operational problem.

Imagine a financial institution screening 500,000 customers.

A relatively common surname generates thousands of potential alerts.

Analysts now need to review those cases.

Each investigation may involve:

  • Comparing names
  • Checking dates of birth
  • Reviewing nationality
  • Examining addresses
  • Checking passport information
  • Reviewing aliases
  • Conducting additional research
  • Documenting the decision

If the screening system is poorly calibrated, compliance teams can spend enormous amounts of time clearing customers who were never genuinely at risk.

OFAC explicitly recognises the problem of generic or “weak” aliases, explaining that they can generate large volumes of false hits when used in computer-based screening.

This creates a classic AML problem:

Too many alerts can become almost as problematic operationally as too few alerts.


But reducing false positives cannot mean ignoring genuine matches

There is an important balance.

A financial institution should not simply reduce its screening sensitivity because analysts are receiving too many alerts.

That could create a different problem:

false negatives.

A genuine sanctions subject could potentially be missed because their name was recorded differently.

The objective should therefore not be:

“Generate fewer alerts.”

It should be:

“Generate more meaningful alerts.”

That requires better data and better matching logic.


The African identity-data challenge

This is where the African context becomes particularly interesting.

Customer identification systems across the continent are developing rapidly.

National digital-ID programmes, biometric identification, mobile-money registration and electronic KYC solutions are expanding.

But coverage and data quality are not identical across every country or customer population.

Some customers may have:

  • Recently issued identity documents
  • Different documents containing slightly different names
  • Limited digital records
  • Changes in address
  • Multiple phone numbers
  • Different spellings across databases
  • Names recorded differently by banks, telecom operators and government systems

A customer may therefore be completely legitimate while appearing inconsistent across different datasets.

This creates a difficult question for compliance teams:

Is the inconsistency itself suspicious, or is it simply a data-quality issue?

The answer requires context.


Screening should connect to KYC

A sanctions screening system should not operate in isolation.

Consider a customer named:

Ahmed Ibrahim

A screening system generates a potential match.

Looking only at the name, the alert may appear significant.

But the KYC record shows:

  • Different date of birth
  • Different nationality
  • Different country of residence
  • Different passport number
  • Different occupation

The evidence may strongly support a false-positive decision.

Now consider the opposite.

The name matches closely.

The date of birth is identical.

The nationality is the same.

The customer’s passport number is consistent with information in the sanctions record.

The address is also connected.

Suddenly, the risk picture is very different.

This is why effective sanctions investigations should bring together:

Screening data + KYC data + customer context.


Entities have the same problem

This issue is not limited to individuals.

Companies can also have multiple names.

A business may have:

  • Legal name
  • Trading name
  • Former name
  • Abbreviation
  • Local-language name
  • Parent company
  • Subsidiaries
  • Branches

The UN sanctions framework includes entity names, acronyms, former names, addresses, subsidiaries, affiliates and other identifying information because these relationships can be important when establishing identity.

A company could therefore appear differently in:

Corporate registry → Bank account → Invoice → Payment message → Sanctions database

The compliance challenge is connecting those records.


The investigator still matters

Automation is extremely valuable.

A financial institution cannot realistically screen large customer populations manually.

Technology can:

  • Compare names
  • Identify aliases
  • Apply fuzzy matching
  • Prioritise potential matches
  • Screen transactions
  • Monitor changes to sanctions lists
  • Reduce repetitive manual work

But technology does not eliminate the need for human judgement.

A screening system may tell you:

“Potential match.”

It does not necessarily tell you:

“This is the sanctioned individual.”

That decision requires investigation.

OFAC’s own guidance illustrates this approach by directing users to compare the complete sanctions-list entry against the information available for the customer, including identifiers such as address, nationality, passport, tax ID and date of birth.

This is where the AML investigator adds value.


What should African financial institutions do?

There is no single solution, but several improvements can make a significant difference.

1. Improve customer-data quality

Capture as many reliable identifiers as possible during onboarding.

A name alone should not become the foundation of an important sanctions decision.

2. Standardise data carefully

Names should be stored consistently while preserving the original information.

Over-normalisation can sometimes remove useful information.

3. Use multiple identifiers

Where available, combine:

  • Date of birth
  • Nationality
  • Passport number
  • National ID
  • Address
  • Place of birth
  • Gender
  • Aliases

4. Understand local naming conventions

Screening teams should understand the markets in which they operate.

A system designed around one naming convention may perform poorly in another.

5. Separate screening from investigation

An alert is not necessarily a match.

The investigation should determine whether the available evidence supports a genuine match or a false positive.

6. Document the rationale

A cleared alert should have a clear explanation.

For example:

“Name similarity identified, but date of birth, nationality and passport number do not match the listed individual.”

This creates an audit trail and supports future reviews.

7. Review screening rules periodically

If a system generates huge volumes of low-quality alerts, the institution should investigate why.

The answer may be:

poor data rather than insufficient compliance.


The bigger AML lesson

Sanctions screening is often presented as a technology problem.

But it is also a data problem.

And ultimately, it is an identity problem.

The better an institution understands its customers, the better it can distinguish between:

a similar name

and

the same person.

This is particularly important in African markets, where naming conventions, identity documentation, languages and data infrastructure can vary significantly.

The answer should not be to lower screening standards.

Nor should it be to treat every name similarity as a potential sanctions violation.

The answer is better information.


Final Thoughts

The future of sanctions screening in Africa will not be determined simply by having faster screening software.

It will depend on the quality of the information behind the screening.

A name can generate an alert.

An identity can establish context.

And the combination of identifiers can help an investigator determine whether the alert represents a genuine sanctions concern.

That is the difference between:

screening for names

and

screening for people and entities.

For African financial institutions, that distinction matters.

Because when names, identities and data don’t match perfectly, the role of the AML professional is not to assume the worst.

It is to investigate.

A sanctions alert tells you where to look.

Good data and good judgement help you understand what you are looking at.

Leave a Reply

Discover more from FinCrime Africa

Subscribe now to keep reading and get access to the full archive.

Continue reading