
15 June 2026
Swarmer and Molfar Partner to Integrate Verified Intelligence Data for Autonomous Systems
Partnership connects combat-proven drone autonomy software with verified intelligence data sets to improve AI decision-making.
Sanctions screening identifies whether a person, company, payment or commercial relationship may be subject to restrictions under an applicable regime. A reliable process combines list matching with identity verification, ownership research and documented alert review.
For UK businesses, screening matters at onboarding, before relevant payments and throughout a relationship. A counterparty may become restricted after a new designation or ownership change. A clear result supports compliance; it does not prove that a relationship is sanctions-free.
Sanctions screening compares data about customers, suppliers, beneficial owners, representatives and transactions with official sanctions data. Relevant identifiers can include aliases, dates of birth, addresses, nationalities, registration numbers, vessel identifiers and bank details.
The control often sits alongside KYC compliance and customer due diligence, but these controls are not interchangeable. KYC establishes identity and supports relationship risk assessment. Anti-money laundering controls address financial crime more broadly. Sanctions controls apply the prohibitions and restrictions of specific regimes. One case may engage all three.
Sanctions are not limited to parties connected with terrorism or organised crime. They also respond to armed conflict, proliferation, human rights abuses and other foreign-policy or national-security concerns.
A missed exposure can lead to frozen funds, disrupted transactions, regulatory investigation and commercial damage. Under the UK financial sanctions framework, OFSI can impose a civil monetary penalty without proving that a person knew or had reasonable cause to suspect a breach. Appropriate due diligence can still affect its enforcement assessment.
Screening helps a company decide whether to proceed, investigate, seek a licence or legal advice, or report where required. Its audit trail records the data, applicable rules and reason for clearing or escalating an alert.
For suppliers, agents and distributors, screening belongs within third-party due diligence. Exposure may arise through owners, intermediaries, end users or trade routes rather than the contracted entity alone.
There is no universal sanctions rulebook. A business should identify the regimes relevant to its location, staff, counterparties, banks, currencies, transaction routes and activities. US, EU or other exposure depends on the facts, not a generic “global” software setting.
Names alone rarely resolve identity. The company needs enough accurate information to distinguish the subject from similar names. For organisations, that may include jurisdiction, registration number, trading names, address, directors and ultimate beneficial owners.
Software can compare collected data with relevant lists using exact, fuzzy, phonetic and transliteration matching. The system should record the source version and check time, then ingest updates at a speed suited to the organisation’s risk profile.
An alert is a lead, not a confirmed match. An analyst should compare identifiers, examine ownership and control, review the designation and establish the restrictions. Common names or inconsistent transliteration produce false positives; poor thresholds or incomplete data also create false negatives.
Confirmed or unresolved matches need a defined escalation route. Staff should not reject, freeze or report a party merely because software generated an alert; the response depends on the law and facts. Retain each material source, step and conclusion in an auditable record.
The scope should reflect how the organisation can acquire exposure. Common controls include:
Higher-risk relationships may need more frequent review. Timing is risk-based and jurisdiction-specific; real-time checks are useful in many payment environments but are not a universal standard for every screening activity.
Start with the official sources for each applicable regime:
A list provider can aggregate data, but it does not decide which law applies. Nor do designation lists capture every sectoral, geographic, trade, technology or service restriction. Screening belongs within wider regulatory compliance risk management.
A company may be restricted even when absent from a list. This is where database checking ends and investigation begins.
Under UK rules, an asset freeze and certain other measures can extend to an entity owned or controlled by a designated person. Tests include more than 50% of shares or voting rights, the right to appoint or remove a board majority, or the ability to ensure that the entity acts according to that person’s wishes.
The US test differs. OFAC’s 50 Percent Rule blocks an entity when one or more blocked persons own, directly or indirectly and in aggregate, at least 50%. Control below that threshold does not itself trigger this rule, although it can still create risk.
Analysts may need to map shareholders, voting rights, parent entities, directors, trusts, proxies and recent transfers. A restructuring does not settle who still benefits or directs the business. Molfar’s Supercam sanctions-evasion investigation shows how name-only checks can miss successor entities and proxy procurement channels.
Automation helps at scale. Matching engines identify aliases, spelling variants and different scripts; graph tools surface relationships; workflow systems route alerts and preserve decisions. Machine-learning models may help rank alerts.
Models can inherit poor data, produce unexplained scores or miss opaque ownership. Technology should assist analysts, not make irreversible decisions without accountable review. Teams should test thresholds, track false positives and negatives, and validate material findings against primary sources.
An effective programme should:
The main operational challenge is balance. Overly broad matching can bury analysts in alerts, while narrow rules can miss aliases or transliterations. Weak customer data makes both problems worse. Sanctions rules also differ between jurisdictions, so one decision cannot be copied across every market without checking the governing regime.
Sanctions screening is a continuing detection and investigation process, not a one-time list search. It works best when accurate identity data, current official sources, ownership analysis, calibrated technology and human judgement operate together.
A clean name result is only one finding. Before a high-risk payment or relationship proceeds, the business may still need to establish who owns and controls the counterparty, where value will flow and which legal regimes apply. If your team needs to assess direct or indirect exposure, contact Molfar Intelligence.
A match is reached only after an alert has been reviewed against sufficient identifiers and the relevant official designation. Similarity in a name alone is not proof that the screened party is designated.
Frequency should reflect the relationship and sanctions risk. Rescreening is commonly triggered by official list changes, new customer information, ownership changes and periodic review cycles.
They are related controls, but they answer different questions. A politically exposed person or a subject of negative reporting is not necessarily sanctioned. These checks can inform enhanced due diligence and escalation.
No. AI can prioritise alerts and improve matching, but it cannot determine legal applicability or resolve opaque ownership reliably without verified evidence and accountable human judgement.
Not always. Restrictions may extend to an unlisted entity through ownership or control rules. The exact test differs by regime, so the analysis must follow the applicable law.
Pause the relevant action where appropriate, preserve the evidence and follow the internal escalation procedure. Confirm the identity, restrictions and legal nexus before deciding whether blocking, licensing, rejection or reporting is required.
Author

15 June 2026
Partnership connects combat-proven drone autonomy software with verified intelligence data sets to improve AI decision-making.

2 March 2026
A €900M EU real estate deal under investigation shows why institutional reputation cannot replace structured due diligence.
Behind every case is a client who needed clarity in uncertainty. Browse our work to see how we uncover what others miss — and what that means in practice for businesses and decision-makers.
Revealed how a high-stakes Defence Tech investment was halted after OSINT-driven due diligence uncovered a co-founder’s links to Russian-origin money laundering and a seized 2.6 billion UAH gambling enterprise, protecting a global firm from severe reputational and regulatory fallout.
Investment
Conducted a full pre-employment background investigation for a high-security aerospace role, covering court registry checks, financial record verification, ideological risk assessment, and social media OSINT analysis across relevant jurisdictions.
Space
Revealed how Russian drone manufacturers circumvent international sanctions by exploiting a critical design flaw (sanctions applied to company names rather than underlying legal entity identifiers), enabling Supercam to increase production tenfold despite being designated.
Finance
Conducted a comprehensive cybersecurity audit of a long-standing European IT infrastructure, identified critical internal data leaks involving financial plans and performance reviews, and implemented high-level security protocols to mitigate regulatory and operational risks.
Cybersecurity
Let’s connect to explore how tailored intelligence can strengthen your decisions, reveal opportunities, and minimise uncertainty.
Let’s connect to explore how tailored intelligence can strengthen your decisions, reveal opportunities, and minimise uncertainty.