Ask a trade compliance team what their screening system does all day and the honest answer is: generates work. Industry analyses consistently put sanctions screening false positive rates above 95%, and many programmes run higher. Hundreds of alerts cleared for every genuine risk found, by analysts whose expertise is spent confirming, over and over, that this Rodriguez is not that Rodriguez.
The scale of the matching problem is real. Hundreds of thousands of sanctioned and restricted entities across dozens of lists and jurisdictions, transliterated names, aliases, shell structures. But the false positive rate is not an inevitable tax on that scale. It is the output of a specific design choice, made so long ago it has become invisible: the tools screen strings, while the regulation regulates ownership.
The list is not the law. The list is an index into an ownership graph, and the tools only read the index.
What the regulation actually says
OFAC's 50 percent rule is explicit: an entity owned 50% or more, directly or indirectly, by one or more sanctioned parties is itself sanctioned, whether or not it appears on any list. Indirect ownership aggregates and cascades. Two sanctioned parties at 30% and 25% of a holding company put that holding company, and everything it majority owns, in scope. The US export control regime has been moving the same way, extending restrictions through ownership to affiliates of listed parties.
Read those rules as an engineer and the conclusion is immediate: the compliance question is a graph traversal. Start from the counterparty, walk the ownership chain upward through every parent and aggregation, and determine whether sanctioned control accumulates past the threshold anywhere above. The name on the invoice is one node at the bottom of the structure the regulation actually addresses.
Wrong in both directions
String screening, measured against that regulation, fails on both sides at once:
- Too loud where the law is quiet. Every fuzzy resemblance between a counterparty and one of the hundreds of thousands of listed names fires an alert, though the vast majority have no ownership connection to any sanctioned party. This is the 95%: not caution, but a category error generating noise at industrial scale.
- Silent where the law speaks. The cleanly named trading company two ownership layers beneath a sanctioned parent matches nothing, because it is on no list, and the rule that puts it in scope was never about its name. The most serious exposure is structurally invisible to the tool the programme relies on.
The false positives and the false negatives have the same root cause. Fixing the noise and fixing the blind spot are one fix, not two.
The enforcement climate has removed the comfort margin. Penalties for export control violations now run to nine figures: BIS settled with Applied Materials for $252.5 million in February 2026, the second-largest civil penalty in the agency's history behind Seagate's $300 million in 2023. Enforcement agencies increasingly expect programmes to know who stands behind their counterparties, not merely who they are named after.
Screening the graph
The graph-first architecture inverts the pipeline. Counterparties are resolved to entities, entities into an ownership graph assembled from corporate registries and ownership data, and the 50 percent arithmetic runs as a traversal: aggregate sanctioned ownership, direct and indirect, computed per counterparty, continuously, so a Tuesday change in a parent's status reprices every exposure beneath it by Wednesday.
Alerts change species. Instead of "this name resembles a listed name", the analyst receives "this counterparty is 55% owned, through these two named chains, by these sanctioned parties, as of this date", with the evidence attached. The queue shrinks by an order of magnitude, and what remains is the actual regulatory question: is this ownership assessment right, and what do we do about it? The analyst's expertise finally lands where it pays. On judgement, not string disambiguation.
Screen the ownership, and the false positives fall out for the same reason the false negatives do: you are finally testing what the regulation tests.
The measure of a screening programme is not how many alerts it clears. It is whether the analyst's next hour goes on judgement or on string disambiguation. Prophesee's Trade module screens the graph so it goes on judgement. Run your counterparty file through it.