When OFAC and the EU Spell the Same Name Differently, What Are You Liable For?
It is a question experienced practitioners run into constantly but rarely see answered head-on. A person is designated by both OFAC and the EU. OFAC’s SDN entry romanizes the name one way; the EU’s Official Journal renders it another. Your screening system matches one string cleanly and scores the other below threshold. If a transaction slips through against the spelling you did not catch, what exactly is the liability – and is “we ran a standard edit-distance match” a defense?
The short version: you are liable for the person, not the spelling, and the expectation clearly goes beyond raw edit distance. Here is the reasoning, with the supporting regulatory language.
1. The obligation attaches to the designated person, not to a romanization
OFAC’s prohibitions run against the designated person and that person’s property and interests in property. The name spellings, aliases, and other identifiers published in an SDN entry are aids to identification; they are not the legal definition of the target. That distinction matters because it means a spelling discrepancy between OFAC’s list and another regulator’s list is not, by itself, a shield. You cannot defend a missed match by pointing out that OFAC and the EU transliterated the underlying name differently, because your obligation was never keyed to a specific Latin string in the first place.
This is reinforced by the strict-liability character of most OFAC prohibitions. Civil liability under IEEPA-based programs does not require intent or knowledge, so “the file we screened against spelled it differently” is not a recognized excuse. It goes to mitigation, not to whether an apparent violation occurred.
2. Each list is authoritative in its own jurisdiction – so you screen against each as published
OFAC, the EU, the UN, and OFSI transliterate Arabic, Cyrillic, Farsi, and Chinese names using different conventions. The same human being legitimately produces different Latin strings across the lists – Mohammed / Muhammad / Mohamed; Qadhafi / Gaddafi / Kadafi; hyphenated, spaced, or dropped “Al-” prefixes. Each list is, in its own jurisdiction, the authoritative legal instrument. A firm subject to more than one regime is therefore expected to screen against each list as published and to reconcile the fact that one person maps to several spellings across them. There is no regulator that publishes an explicit “you must reconcile our transliteration against the EU’s” rule – the expectation is inferred from how the obligations are framed and enforced, not from a single on-point statement.
3. Does the expectation go beyond standard edit-distance matching? Yes – and OFAC has said so in substance
Edit distance (Levenshtein, Jaro-Winkler, and similar) is treated as necessary but not sufficient. OFAC does not prescribe an algorithm, but its guidance and enforcement record point squarely at the failure modes that character-level distance handles poorly.
In A Framework for OFAC Compliance Commitments (May 2, 2019), OFAC identifies deficient screening as a recurring root cause of apparent violations, and it specifically calls out the failure to account for alternative spellings of designated parties. Commentators summarizing the Framework note that OFAC warns screening software must, among other things, account for alternative spellings of prohibited firms or people – the Habana / Havana example is OFAC’s own. That is the closest thing to a direct statement that naive string matching is not enough.
Why edit distance alone falls short in the cross-list transliteration scenario:
- Cross-alphabet variance. Two valid romanizations of one name can sit at a large character-level distance from each other. “Qadhafi” versus “Kadafi” is a big edit distance but the same person. A threshold tight enough to suppress false positives will miss these; a threshold loose enough to catch them floods the review queue.
- Phonetic equivalence. Names that sound alike but score as distant (the “Mohammed” / “Muhammad” family) are better bridged by phonetic logic (Soundex, Metaphone) or transliteration-aware normalization than by raw distance.
- Name-order and segmentation. Arabic kunya/nasab structures, Chinese surname-first ordering, and dropped or added particles defeat token-by-token distance scoring.
- Culture and script-specific normalization rather than a single global threshold applied to every population.
4. The enforcement record: tool tuning for name variants is a cited deficiency
Two settlements make the point concretely, and neither turns on willful conduct – both are about how the screening tool was configured.
Apple / SIS (FNKSR, 2023 settlement). As part of resolving apparent violations tied to a designated Slovenian developer, OFAC highlighted remedial measures Apple undertook, including reconfiguring its primary screening tool to fully capture spelling and capitalization variations and to account for country-specific business suffixes, plus annual review of the tool’s logic and configuration. The remediation itself tells you what OFAC viewed as the gap: a tool that did not adequately capture variant spellings.
JPMorgan Chase (FNKSR and Syria, 2018 Finding of Violation). OFAC found that the bank’s screening system, as configured over a multi-year period, failed to identify customer names with hyphens, initials, or additional middle or last names as potential matches to identical or similar names on the SDN List – and that staff did not escalate the red flags despite matching addresses and dates of birth. Again, the deficiency is in the matching logic and the procedures around it, not in the absence of screening.
The through-line: OFAC does not penalize you for the existence of a spelling difference. It looks at whether a reasonable, risk-appropriate program – with fuzzy matching, phonetic and transliteration handling, and periodic tuning and testing – should have caught the target. A tool that “ran” but was mis-tuned to variant spellings is treated as a deficient program.
5. How the liability actually resolves
Put the pieces together and the liability is not “for the spelling” as such. It is for processing a transaction involving a designated person you should reasonably have identified. If your program screens against OFAC’s spelling with matching logic calibrated to catch reasonable variants, and a genuinely divergent EU transliteration was the only version that would have matched, OFAC’s inquiry is whether a reasonable, risk-based program should have caught it anyway. A documented, risk-based methodology – fuzzy plus phonetic and transliteration-aware matching, with periodic tuning and testing – is simultaneously the compliance expectation and, under OFAC’s Economic Sanctions Enforcement Guidelines, a mitigating factor if something still slips through.
Bottom line
No regulator publishes an express “reconcile our transliteration against the EU’s” instruction. But the combination of three things – strict liability, the principle that the obligation runs to the designated person rather than to a designated spelling, and OFAC’s explicit citation of alternate-spelling failures as an enforcement root cause – produces a clear expectation. Screen against each authoritative list as published, and use matching logic that goes beyond raw edit distance to account for transliteration, phonetic, and structural name variation. Edit distance alone, without transliteration and phonetic handling and risk-based tuning, would most likely be viewed as a deficient program.
Source confidence. The Framework‘s treatment of alternate spellings as a screening root cause, and the Apple/SIS and JPMorgan Chase remediation details, are well supported by OFAC’s published materials and settlement summaries. The broader proposition – that this framework requires cross-list transliteration reconciliation – is inference drawn from the Framework, the enforcement record, and the strict-liability structure, rather than from a single on-point OFAC statement, because OFAC has not issued express guidance addressing cross-regulator transliteration divergence directly.
Key references: OFAC, A Framework for OFAC Compliance Commitments (May 2, 2019), Appendix root-cause analysis; OFAC settlement with Apple Inc. under the Foreign Narcotics Kingpin Sanctions Regulations; OFAC Finding of Violation involving JPMorgan Chase (FNKSR and Syrian Sanctions Regulations, 2018).
Category: Regulatory Listings
-
-
Prompt #1:
Why do some OFAC listings include “secondary sanctions risk” wording and others do not? Are there listings where the risk does exist but the wording doesn’t appear? If so, why not? What are the implications – from a regulatory or practical sense – of that wording appearing? Check your response against your sources and flag anything that is not well-supported by the sources
First response:
Why some listings carry the wording and others don’t
The “Secondary sanctions risk:” line is a remark field OFAC appends to an SDN (or SSI) entry to point the reader to the specific legal authority under which dealings with that person could expose a non-US person to secondary consequences. In the entries you’ll see, it takes forms like “Secondary sanctions risk: See Section 11 of Executive Order 14024” for Russia-EO14024 designations, “Ukraine-/Russia-Related Sanctions Regulations, 31 CFR 589.201” for legacy Ukraine/Russia entries, and program-specific citations like “section 1(b) of Executive Order 13224, as amended by Executive Order 13886” on a terrorism-linked entry.
The presence or absence tracks the program, not the individual designee. Secondary sanctions authority is program-specific: it exists for Iran, Russia (EO 14024/14114 §11 and CAATSA §231), North Korea, and certain counterterrorism/narcotics authorities, but not for every OFAC program. An SDGT/SDNTK designation carries the tag where the underlying EO 13224/13886 authority provides for it; a designation under a program with no secondary-sanctions statute behind it won’t have the line because there’s no secondary authority to cite.
A second driver is timing. OFAC added the remark to many pre-existing entries retroactively. In mid-2024, following EO 14114’s revision of Section 11 of EO 14024, OFAC amended existing SDN and SSI list entries to include an explicit reference to “secondary sanctions risk” pursuant to revised Section 11 of Executive Order 14024. So an entry designated before that authority existed (or before OFAC did the bulk update) might not carry wording that a functionally identical entry added later would.
Are there listings where the risk exists but the wording doesn’t appear?
Yes — and this is the practically important part. The remark is informational, not a determination of your exposure.Two mechanisms produce risk without the tag:
The 50% Rule. Entities owned 50%-or-more by blocked persons are themselves blocked without being separately listed at all. Under OFAC guidance, any entity owned 50% or more, individually or collectively, by sanctioned persons is itself treated as blocked, and entities may be subject to sanctions even if they are not expressly listed. An unlisted subsidiary of a secondary-sanctionable parent carries the parent’s risk profile but has no SDN entry, hence no remark.
Retroactive-tagging gaps and program coverage. Because the tagging was applied program-by-program and in batches, and because OFAC “overwrites rather than versions” its public data, an entry can lag the current legal reality. The tag reflects OFAC’s citation choice at a point in time, not a guarantee that no secondary authority reaches the party.
⚠️ Flag — not well-supported by my sources: I could not, in these searches, locate an OFAC FAQ or a data-specification document in which OFAC itself explicitly states that the “secondary sanctions risk” field is non-determinative and that its absence does not mean no risk exists. That characterization is the well-established practitioner reading (and it follows logically from how the 50% Rule and program-specific authorities operate), but I’m presenting it as sound inference rather than a sourced OFAC statement. If you want to publish it as OFAC’s own position, that specific claim should be verified against the SDN List data specification or the relevant FAQ before it goes out.
Implications of the wording appearing
The remark does not change what is prohibited for US persons — they are already barred from dealings with any blocked party regardless of whether the line appears. Its function is a signal to non-US persons, particularly foreign financial institutions.
For an FFI, the tag flags that dealing with this party could expose the institution itself to consequences that amount to exclusion from the US financial system — OFAC can require US banks to close the foreign bank’s correspondent or payable-through accounts, or designate the foreign bank itself on the SDN List.
Critically, the exposure typically turns on a “significant transaction” standard with no bright line. OFAC weighs the size, number, and frequency of the transactions; their nature; the level of management awareness and whether they form a pattern of conduct; and the nexus to sanctioned persons. There is no bright-line dollar threshold for significance.
Two practical points worth making for your audience:
The tag has become a de facto compliance trigger ahead of formal enforcement. Financial institutions in jurisdictions such as China, the UAE, and Turkey began restricting or delaying Russia-related transactions due to perceived secondary sanctions risk — banks act as gatekeepers before regulators formally move. So the wording’s real-world effect is often screening-driven de-risking rather than a government action.
And the wording is a pointer to an authority, not the scope of that authority. The cited EO or CFR section is where the actual conditions, thresholds, and exemptions live; the remark just tells you which door to open.
Follow-up prompt:
Are companies treating the secondary sanctions wording as a risk rating? Is there a pattern to this – e.g. by industry, by asset class, by geography or otherwise?
And the response:
This is the sharper version of the “Burning Questions” angle from before — whether the field is being read as a rating rather than a citation, and whether that misreading clusters anywhere. Let me search for evidence rather than reason from priors, because the honest answer may be that this specific behavior is under-documented.That gave me adjacent material (screening mechanics, one vendor that tags secondary sanctions as a labeling feature) but not direct evidence of firms misreading the field as a rating. Let me look specifically at the de-risking / over-compliance pattern, which is where any geographic or asset-class clustering would show up.I now have solid material on the de-risking pattern and where it clusters, but I want to be honest about a distinction: the question asks specifically whether firms treat the wording as a rating, and most of what I’ve found is about firms reacting to the underlying risk. Those aren’t the same thing, and I don’t want to conflate them. Let me do one more targeted search on the data-field-as-signal angle.I have enough to give an honest, well-bounded answer. The key finding I need to be upfront about: the sources document a strong de-risking pattern around the underlying secondary-sanctions risk, but almost nothing directly documents firms reading the remark field itself as a rating. Those are different claims, and the interesting piece for a practitioner audience is precisely that gap.
The short answer
There’s a real, well-documented behavioral pattern here — but it’s not quite the one the question names, and the distinction matters.
What the sources robustly support: firms, especially foreign financial institutions, are over-reacting to secondary-sanctions exposure, cutting off parties well beyond what the law strictly prohibits. What the sources do not directly support: that firms are specifically reading the SDN entry’s “Secondary sanctions risk:” remark text as a risk score or rating. I found essentially no direct documentation of that narrower claim. So I’ll give you the pattern that is evidenced, then be explicit about where your framing outruns the record — which is itself the interesting part.
The pattern that is well-supported: de-risking as over-compliance
The dominant behavior is precautionary avoidance driven by the threat of secondary sanctions rather than by any single data field. Banks in Asia, Africa, and the Middle East have disengaged from Russian-linked transactions even where the dealing is technically legal, and many have cut off clients only remotely linked to Russian entities where no direct violation exists. This is firms treating the possibility of secondary exposure as a reason to exit, which is functionally “risk-rating” behavior — just triggered by the designation and its program, not by parsing the remark.
OFAC appears to have designed for exactly this. Davis Polk’s read is that the US has historically been highly selective in imposing secondary sanctions, and that the expanded FFI measures seem calibrated to have a broad deterrent effect and to encourage de-risking. In other words, the deterrent-by-ambiguity is intentional; the over-compliance is a feature, not an accident.
Where the pattern clusters
The evidence does show clustering, and it’s worth laying out by the axes you asked about.
By asset class / sector. Energy is the clearest. After the Rosneft and Lukoil designations, purchasers in India and major companies in China tended to avoid buying from sanctioned sellers or intermediaries, and third-country operators and banks were deterred from ongoing business with those firms. Correspondent banking is the other concentration: documentary credits and guarantees involving Russian exporters became high-risk instruments, and trade finance is where much of the avoidance shows up.
By geography. The avoidance concentrates in the transshipment and energy-buyer jurisdictions — China, India, Turkey, the UAE — precisely the third countries OFAC’s FFI authority targets. OFAC’s own updated FFI advisory flags that small- and medium-size institutions in jurisdictions that continue significant Russia trade present particularly high risk, which pushes correspondent banks to de-risk entire categories of respondent institutions in those markets.
By institution type. Smaller FFIs without deep compliance benches de-risk more bluntly, because nuanced analysis of “significant transaction” thresholds is expensive and the downside — loss of US correspondent access — is existential. Larger banks can afford the granular analysis; smaller ones exit the whole exposure.
The common thread: the clustering tracks the programs that actually carry secondary-sanctions authority (Russia, Iran, North Korea) and the choke points (correspondent banking, energy trade finance) — not the presence or absence of the remark text on any given entry.
Where your framing outruns the sources — and why that’s the actual story
⚠️ Flag — not supported by my sources: I could not find direct evidence that compliance teams or screening systems ingest the “Secondary sanctions risk:” remark field and treat it as a rating that ranks one designee above another. That specific claim should not be published as established.
Two things from the record actually cut against it, and they’re useful to you:
The remark lives in the remarks field — the same catch-all field OFAC historically used for information that didn’t fit existing structured categories, and where weak AKAs and identifiers also sit. It’s descriptive text pointing to a legal authority, not a structured, scored data element. Screening vendors that do differentiate secondary-sanctions exposure describe it as a labeling / tagging feature they add — referencing the specific regulation or executive order under which a sanction applies — which implies the raw list doesn’t hand them a rating; they construct one.
And modern screening guidance pushes the opposite of field-reading: a name match is only the beginning, and analysts are expected to work from ownership, nexus, transaction context and the 50% Rule rather than from a line of remark text. The sophisticated read of secondary risk is contextual (who owns whom, is the transaction “significant,” is there a US nexus), and none of that is legible from the remark.
So the honest synthesis, and the sharper “Burning Question,” is this: firms are absolutely treating secondary-sanctions exposure as a risk gradient — but they’re inferring that gradient from the program, the sector, and the geography, not from the remark field. The remark is a citation; the market has built its own rating on top of it. The failure mode worth writing about isn’t “firms misread the field as a rating” (I can’t evidence that) but the inverse risk: because the field is a citation, not a rating, its presence tells you which authority applies, not how much risk you carry, and its absence tells you nothing — yet the de-risking reflex behaves as though listed-with-tag equals hot and untagged equals cool. Given the 50% Rule and the retroactive-tagging gaps we discussed last time, that reflex is exactly backwards for the unlisted-subsidiary and pre-tagging-batch cases.
If you want to make the piece defensible, the claim to lead with is the evidenced one (over-compliance clusters in Russia/Iran energy and correspondent banking, in China/India/Turkey/UAE, among smaller FFIs) and to frame the “reading the field as a rating” idea explicitly as a hypothesis you’re raising, not a documented practice — then invite practitioners to tell you whether their screening logic actually weights the field. That’s both the intellectually honest move and, for your readership, probably the thing that generates the most useful responses.
One caveat on my own evidence base: most of what I found on the behavioral pattern comes from law-firm client alerts and vendor blogs, which are reliable on the direction of travel but have an obvious interest in emphasizing risk. I’d treat the existence and rough clustering of the de-risking pattern as well-established, and any specific magnitude claims as softer.
-
The prompt to Claude:
What is the purpose of OFAC’s use of “Linked To” in its designations? What informational, practical and/or legal implications are there to this information? How does it inform data analytics and KYC/CDD efforts – and where do those fall in the range from requirement to nice to have for even the most high-profile firms? Is there anything else we ought to know about this data? Write your response for sanctions profesionals who are not lawyers.
The response:
The “Linked To” field is one of the more misunderstood pieces of SDN metadata, so it’s worth unpacking carefully.
What “Linked To” actually is
When OFAC designates a party, it frequently establishes a relationship between that party and an existing sanctions target or program. In the SDN data, this surfaces as a “Linked To” relationship – typically visible in the consolidated data files and on the SDN Search interface as a note that Entity A is “Linked To” Entity B (or to a specific program).
The core purpose is to document why a party was designated and to whom or what they connect. OFAC rarely designates in a vacuum. A person gets added because they own or control a blocked entity, act on behalf of a designated party, materially assist a sanctioned regime, are a family member operating as a front, and so on. “Linked To” is OFAC’s way of preserving that connective tissue in the structured data.
The critical distinction: derivative vs. standalone designation
Here’s the nuance that trips people up. “Linked To” is a relationship attribute; it is not itself the legal basis for blocking. Every party on the SDN List is blocked in its own right by virtue of being on the list, regardless of what it’s linked to. The linkage tells you the narrative and often the authority under which OFAC acted, but the legal consequence – block the property, reject or freeze the transaction – flows from the SDN listing itself, not from the link.
This matters because practitioners sometimes treat a “Linked To” entry as if it were a secondary target that also needs screening. It isn’t a screening target on its own; the linked party is either already an SDN in its own entry (in which case it’s screened directly) or it’s a program/authority reference. Don’t confuse the relationship pointer with an actionable name.
Informational implications
The field gives you three useful things:
Attribution and context. It answers “why is this party here?” That’s valuable for alert adjudication, narrative building in SARs, and explaining a hit to a business line that wants to know the story.
Network mapping. Aggregated across the list, “Linked To” relationships let you reconstruct the designation networks OFAC sees – the web of ownership, control, and agency around a primary target. This is the raw material for understanding a sanctioned oligarch’s corporate structure or a proliferation network’s front companies.
Program inference. The linkage often clarifies which program or authority is in play, which affects how you handle related risk (e.g., a party linked to a Russia-program target carries different downstream implications than one linked to a counter-narcotics target).
Practical and legal implications
The practical caution: “Linked To” does not substitute for a 50 Percent Rule analysis. OFAC’s 50 Percent Rule blocks entities owned 50% or more, in aggregate, by one or more blocked persons – even if those entities are not on the SDN List and have no “Linked To” entry pointing at them. The “Linked To” field captures relationships OFAC chose to document; it does not capture every ownership relationship that triggers derivative blocking. Treating the field as a complete ownership map is a real compliance failure mode. The regulator’s position is that the obligation to identify 50%-owned entities rests with the filer, using ownership data that frequently lives entirely outside the SDN metadata.
The legal reality, stated plainly: the block attaches to the listed party. “Linked To” is descriptive metadata, not an operative legal element you act on independently. You don’t “unblock” something because its link looks tenuous, and you don’t gain a separate blocking obligation because a link exists.
Data analytics and KYC/CDD – requirement vs. nice-to-have
Let me separate the layers, because the answer differs sharply by layer.
Screening the SDN List itself: requirement, full stop. Every US person and most firms with US touchpoints must screen against the SDN List. That’s non-negotiable and doesn’t depend on “Linked To” at all – you screen the names, you resolve the hits.
Using “Linked To” for alert adjudication and enrichment: strongly expected, effectively a de facto requirement at scale. For a high-profile firm, examiners and regulators expect a risk-based program that uses available context to make sound decisions. The field isn’t itself mandated, but a sophisticated institution that ignored readily available OFAC-provided context in its adjudication would struggle to defend that as reasonable. So in practice it sits closer to “requirement” than “nice to have” for large, high-risk firms – not because a rule names the field, but because using it is part of what a defensible risk-based program looks like.
Network analytics / graph analysis built on “Linked To”: genuinely nice-to-have, but increasingly table stakes for the top tier. Reconstructing designation networks to get ahead of 50% Rule exposure, identify likely front companies before they’re listed, and map beneficial ownership risk is advanced practice. No rule requires you to build a graph database of OFAC linkages. But for globally systemic institutions and firms with heavy exposure to Russia, Venezuela, or proliferation-finance risk, this kind of analytics has moved from differentiator toward expected capability. The honest framing: not a legal requirement, but the gap between “compliant” and “credible at the frontier” increasingly runs through exactly this work.
The through-line: the listing drives requirements; “Linked To” drives quality of judgment. Regulators assess programs on reasonableness and risk-sensitivity, and richer use of context is how you demonstrate both.
Other things worth knowing
A few practical cautions:
Coverage is uneven. Not every designation carries a fully populated “Linked To” set, and the granularity varies across programs and vintages. Older entries were built under different data conventions. So don’t assume the absence of a link means the absence of a relationship.
It’s directional and curated. The field reflects the relationships OFAC decided to memorialize for a given action, not an exhaustive relationship graph. It’s a lens on OFAC’s reasoning, not a complete intelligence picture.
It appears in the enhanced/consolidated data, not the legacy flat SDN file in the same way. If your screening feed only ingests basic name/ID fields, you may not be capturing “Linked To” at all – worth confirming with your data vendor exactly which fields flow into your system versus your analytics environment.
Finally, don’t over-read tenuous links. A documented linkage tells you OFAC saw a relationship material enough to note; it doesn’t quantify the strength or the current status of that relationship, and relationships decay over time while the metadata may not.
