TL;DR: A false positive in KYC screening is a watchlist hit on a customer who is not the listed person. In the FCA's May 2026 sanctions tests, 90% of alerts correctly identified the sanctioned party when the name matched exactly, and 75% when the name was only slightly varied. Cutting those hits means tightening list scope, transliteration, and secondary identifiers before anyone tries to work the queue faster.
What a KYC screening hit actually is
KYC screening false positives appear while a firm checks a new customer, a beneficial owner, or a related party against a sanctions, PEP, or adverse media list. The engine compares a string from the onboarding file with a string on a list, and similar strings raise a hit even when the customer shares nothing with the listed person beyond the name.
The Wolfsberg Group's sanctions screening guidance separates two controls firms often run as one. Customer or name screening looks for listed people and entities at onboarding and across the relationship. Transaction screening looks for listed parties inside a payment. Each has its own queue and its own standard for closing a hit. False positives in transaction monitoring follow a different set of rules.
An alert is the start of a check. Wolfsberg treats it as the first step toward a possible sanctions exposure, which further information then confirms or discounts. OFAC's match guidance says many potential matches are false positives, including a customer whose name resembles a vessel on a sanctions list. The way through is to compare the full list entry with what the firm already holds, and to keep that comparison.
Variant names are where onboarding screening slips
Exact-name screening is the part most firms can already show a supervisor. The FCA's May 2026 findings, from assessments of more than 150 firms since February 2022, put a number on the rest. In the FCA's sanctions screening tests, 90% of alerts correctly identified the relevant sanctioned party when names matched exactly. When names appeared in slightly different forms, such as minor spelling variations, that figure was 75%. Customers still apply under spellings a designation never used.
The same tests showed how ordinary handling creates both misses and noise. Honorifics, suffixes, and titles pulled scores under the alert threshold. One-word names and names containing digits were excluded by default. Long names hit a character limit and failed with no alert. Names outside the Latin alphabet were a separate failure: a transliterated application and a listed original-script name either never met, or met as a fuzzy collision with someone else.
Customer records were often too thin to finish what the name score started. The FCA found dates of birth that were missing, incomplete, or stored as placeholder values, which leaves the name score standing. Over a quarter of the firms then took three to five days to close name screening alerts, so a common-name applicant waits while the file is still silent on whether the hit is the listed person.
Where the false hit is created

Most of the hit volume is fixed before an analyst opens the case. Four setup choices do the work: which lists are in scope, how names are matched across scripts and word order, whether date of birth and geography can contradict a hit, and where the similarity threshold sits.
List scope and weak aliases
Each list added at onboarding multiplies the strings a legitimate name can collide with. Sanctions lists are designation records. PEP screening covers a wider set of public roles, relatives, and close associates. Adverse media screening matches reporting that was never built as a legal list. One fuzzy setting across all three imports the noisiest dataset into the strictest control.
Weak aliases are the clearest case for a narrower scope. Wolfsberg describes them as broad or generic aliases — nicknames, common acronyms, short strings, numeric aliases — that generate a large volume of false hits, and treats screening them as typically unproductive. OFAC allows a tool to exclude aliases it has marked as weak when that exclusion is documented. The FCA flagged the opposite: dropping sanctioned-name categories with no rationale, and vendor feeds with errors, omissions, and late updates. A sound exclusion names the alias class, the list, the approver, and the review date.
Transliteration, word order, and the name score
One person can have several correct Latin spellings. Arabic, Cyrillic, Chinese, and Korean names each have more than one accepted romanization, and patronymics and compound surnames shift with the document the customer used. Family-name-first order, or a spouse's surname added at account opening, moves the score without changing the person. An engine that treats every difference as a typo will alert on ordinary names and miss the listed spelling.
Edit distance, phonetic keys, and token order are covered in how fuzzy name matching scores a sanctions hit. For onboarding, the configuration has to alert when a real variant arrives, with a second field ready so common variants do not all become cases. Retest after list updates and matching-logic changes. A threshold set at go-live and left alone has already drifted.
Date of birth and geography
A name score cannot separate two people who share it. Secondary identifiers can, when both sides of the comparison hold real values.
OFAC walks the comparison in that order. A hit where only a first or last name agrees, while date of birth, an identification number, or nationality differs, is a weak basis for treating the customer as the listed person. An address match on its own is also weak, because many businesses share a building. Several agreeing identifiers, with nothing that disqualifies the hit, move it to the likely-match procedure.
Wolfsberg treats date of birth, nationality where the law allows it, and place of birth as identifying information for assessing an alert after the name has hit. Screening a date as another free-text string adds collisions. A missing or placeholder date is an absence of evidence. Only a contradiction between two populated values counts, including when a mailing address and a nationality have been collapsed into one location.
The threshold is a policy
The threshold is the similarity score at which the firm is willing to see a hit. Wolfsberg treats how exact or how fuzzy to set the filter as a risk-based decision that has to be written down, tested, and owned. The FCA treats a system that is too sensitive, or too dull to catch name variations, as poor practice. One number on every list is how sanctions screening inherits the false-hit pattern of a news archive.
Testing is what makes the number defensible. Run known sanctioned names, slight variants, and transliterations through the live configuration, then a sample of ordinary customer names, and read the two results together before locking the score.
A 2025 Federal Reserve study measured a richer comparison against fuzzy matching. Language models reduced sanctions-screening false positives by 92% and raised detection by 11% relative to the best fuzzy baseline, on pairwise name and address comparisons. The models were orders of magnitude slower, so the authors aim them at slower work such as account opening, and the result still has to be retested on the firm's own book. Teams comparing KYC software for compliance teams should ask for alert rate by list, the share of hits cleared on secondary identifiers, and detection on a variant-name set the firm controls.
What still has to stay with a person
Some hits should stay open until a person looks. OFAC sends the firm to its likely-match procedure when several pieces of information agree — a full name and a date of birth, or an organization name and a location — and nothing disqualifies the hit. A public figure whose passport disagrees with the customer is a judgment, as is a common name where one identifier agrees and another is blank. Automatic clearance of that pattern is how a true match leaves with a clean stamp.
Suppression lists are the repeat-hit version of the same judgment. Wolfsberg covers them as suppression rules or "good guy" lists, and as whitelists for terms that reliably collide with list entries. They stop a cleared customer from generating the same case on every rescreen, and they stay valid only with a written rationale, a named owner, and a reopen when the list entry gains an alias, a date of birth, or an address.
Supervisors read the record. OFAC expects a complete account of the steps taken and the information relied on, and it does not confirm matches or false positives for a firm. The FCA's poor-practice examples include no audit trail where a potential target match was judged a false positive. The note should say which fields were compared, which contradicted the list entry, which were blank, and who accepted what remained.
Where Sphinx fits
Sphinx compares the onboarding name with the lists in scope, then applies date of birth, geography, and party type before a hit reaches an analyst. The identifiers behind the disposition are written into the case record. Production use of that screening step has shown 87% fewer false positives, and hits that still show several agreeing identifiers, or that sit on blank customer data, stay with a person.
Frequently Asked Questions
What counts as a false positive in KYC screening?
A KYC screening false positive is a hit raised while screening a customer, beneficial owner, or related party against a sanctions, PEP, or adverse media list, where the customer is not the listed person. The hit comes from similarity in the name. Date of birth, nationality, identification numbers, and geography are what show the two records refer to different people.
Will a tighter match threshold reduce KYC false positives safely?
A tighter threshold reduces hits, and it also reduces detection of spelling variants, transliterations, and reordered names. The FCA's 2026 tests saw exact-name identification at 90% and slightly varied names at 75%, which is the gap a blunt threshold widens. The defensible approach is documented testing above and below the chosen score, with a separate setting for each list.
Should date of birth be screened, or only used after a name hits?
Date of birth, nationality, and place of birth are for judging a name hit. The Wolfsberg Group treats them as identifying information used after an alert, and OFAC's match guidance uses a conflicting date of birth, identification number, or nationality to disqualify a potential match. A blank or placeholder date of birth disqualifies nothing.
Why do PEP and adverse media checks produce more false positives than sanctions lists?
Sanctions lists are designation records, often with aliases, dates, and addresses attached. PEP and adverse media datasets are broader, refresh on different cycles, and match names that are common in public life. Each list needs its own scope and its own standard for closing a hit.
Can a suppression list replace review of repeat name hits?
A suppression list, sometimes called a good-guy list, stops a known false hit from returning on every rescreen. It holds up only with a documented reason, an owner, and a review when the underlying list entry changes. OFAC does not confirm false positives for a firm, so the record has to show which identifiers were compared and which ones contradicted the list entry.

.png)