Article
"Not to be confused with…": we went hunting for our own false positives
Name-collision false positives are a hidden tax on every screening program — analyst hours spent clearing hits against people and companies with nothing to do with a listing, and real harm when an innocent namesake gets de-risked by mistake. Our deep-research program now proactively hunts these namesakes, verifies each one against a primary source, and surfaces the safe ones directly on the entity page.
Published 2026-08-04 · ProofAML editorial
Every AML analyst has cleared this exact kind of alert: a screening hit fires, the name matches, and twenty minutes later it turns out the "match" is an actor, a footballer, or a company two time zones away that has never touched the sanctioned party's business. Nothing was wrong with the screen — the name really is that close. The cost isn't a bug, it's structural: sanctioned entities don't get to pick unique names, and neither do the unrelated people and companies who happen to share one.
That cost has two faces. The first is the analyst hours — every name-collision alert has to be manually reviewed, documented, and dismissed, on a workflow where under-reacting to a real hit is a compliance failure and over-reacting to a false one is just expensive. The second face gets less attention but matters more: the innocent namesake. A business that shares a name, an address, or a registration-number pattern with a sanctioned entity can get swept into informal de-risking — a bank quietly closing an account, a counterparty declining to deal — with no findings against them at all, just proximity to a name. Both costs are avoidable with the same fix: know about the collision before it becomes an alert.
Hunting namesakes on purpose
We already run a deep-research program that attaches verified, sourced facts to entity pages — aliases, addresses, corporate interests, status changes — built entity by entity, reverse-chronologically from the newest listings. Wave 1 of that program covered 40 entities from a July 2026 EU sanctions package and added 61 individually-sourced findings to the corpus.
The same pass now does something else on purpose: it goes looking for the namesakes. For every entity researched, we run a same-name scan against our own corpus — reusing the identical name-matching logic our screening engine uses, so what the research turns up is exactly what a customer's screen would flag — plus a targeted web sweep for public-figure namesakes, brand-name collisions, and transliteration variants. Every hit gets adjudicated against a strict rubric: a shared name alone is never enough. We require a genuine identifying contradiction — a different tax ID, a different registration number, a different date of birth, a different jurisdiction — before we'll call two records definitively different entities. When a hit turns out to be the same entity our own system just failed to merge across two lists, that's a data-quality fix, not a namesake story, and it's routed there instead.
Wave 1's proactive hunt surfaced 18 candidate namesakes. Only 13 cleared every gate required to publish: the confusable has to be a public-facing party (a company, a public figure, someone in public office — never a private individual), every fact about them has to be neutral and protective with zero adverse implication, every fact has to trace to a source we actually checked, and we have to be genuinely confident the two records are different entities, not the same one recorded twice. The other 5 didn't clear that bar and stay in research memory, unpublished, precisely because we couldn't be fully sure. In one of those cases, a first-pass finding that initially looked like a probable identity match between two same-named bank records didn't survive a second, adversarial look — the addresses and registration numbers involved couldn't be reconciled with confidence in either direction, so rather than publish a guess, we held it back and marked the identity question genuinely open for a future wave. When the question is "is this a false positive, or is it actually the same party," guessing wrong in either direction is a real failure — so when in doubt, we don't publish.
Four collisions worth knowing about
A watch factory at the sanctioned firm's own street address. Centro científico e técnico Vostok, listed under the EU's July 2026 Russia package, shares its registered address — 127F/1 Engels Street, Chistopol, Tatarstan — with a company that has nothing to do with the listing: the maker of Vostok watches, the internationally-sold Komandirskie and Amfibia lines. Same street number, different tax ID, and a business that is, straightforwardly, a watch factory. A name-and-address screen would surface both; the tax ID and the industry don't agree on anything else.
A UK security firm one word-break away from a sanctioned Russian armor company. ARMORGRUPP, a Nizhny Novgorod-registered GmbH, is close enough in name to "ArmorGroup" that a name-only screen would return both — except ArmorGroup International plc was a London-headquartered protective-security firm, acquired by G4S in 2008, and hasn't operated as an independent company since. Different country, different corporate form, different legal identifiers, and one of the two companies stopped existing seventeen years before the other was ever sanctioned.
Two refineries, adjacent reference numbers. The EU's own designation numbering nearly did the confusing for us here. Novokuybyshevsk Oil Refinery carries EU reference number EU.14641.12; a separate, also-sanctioned refinery in the Kuibyshevsky district of Samara city — JSC Kuibyshevsk Oil Refinery — carries EU.14640.13, one digit removed, under a near-identical name missing only a "Novo-" prefix. Both are real, both are sanctioned, and they are not the same facility. A second pair in the same package repeats the pattern: Oil Refinery "Northern Kuzbass" sits at the Anzhero-Sudzhensk Yaisky complex, while a separately-designated LLC "Anzhersky Oil Refinery" sits in Novokuznetsk — different registration, different city, under its own listing entry in the same regulation. Because both confusables in this pair are themselves already in our corpus, the entity page can link straight to the other real record instead of just describing it — the clearest version of the warning we can give.
A sanctioned bank and its own sister company, same building. Banca FINAM S.A. — the sanctioned FINAM bank — shares its Moscow office building, 7 Nastasyinsky Lane, Building 2, with JSC Investment Company FINAM, the brokerage arm of the same corporate group. That one is a genuine sister company, not a coincidence: same brand, same address, and still a different legal entity with its own registration numbers and its own license class, licensed to trade securities rather than run a bank.
What shows up on the page
Each of the 13 publishable rows now renders as a "Not to be confused with…" panel on the relevant entity page — placed right after Related Entities as its deliberate inverse. Related Entities shows real connections; this panel shows the opposite: parties that look connected by name but demonstrably aren't. It uses the same caution-yellow styling across the site, never the red reserved for actual designations, because coloring an innocent namesake like a sanctioned party would be exactly the mistake the panel exists to prevent. Every row states who the confusable actually is, why the mix-up happens, the specific facts that separate them, and — where the confusable is itself a record in our corpus — a direct link to it.
Why "when in doubt, don't publish" is the whole point
The discipline here is the same one that governs every fact we publish, just aimed at protecting a different party. Normally the risk of a wrong fact is misidentifying a sanctioned entity's own attributes. On this panel the risk inverts: a careless entry would misidentify an innocent party as worth a second look, on a page about someone else entirely. So the bar is deliberately conservative — public-facing only, neutral language only, sourced only to something we actually fetched and checked, and published only when we're genuinely confident the two records are different. 5 of wave 1's 18 candidates didn't clear that bar and stayed unpublished. That's not a shortfall — a research-only namesake still suppresses re-research on a future pass, and an unpublished namesake we're unsure about is a much better outcome than a published one we got wrong.
We'll keep running this alongside every future research wave, oldest false-positive traps found first as the corpus grows. If you're evaluating a screening program's false-positive handling, the panel is worth checking directly against a live example — start with any of the entity pages linked above.
Turn this into a screening action
Screen against the sources behind this post
Monthly · free
The sanctions enforcement digest
New designations and enforcement actions, with the screening lesson behind each. One email a month.