Sanctions Evasion Red Flags: Typologies and Indicators to Monitor

Sanctions evasion red flags across six typologies: front companies, ownership obfuscation, transshipment, AIS manipulation, and trade misdescription.
Alexandre Berkovic

TL;DR: Sanctions evasion red flags are observable patterns in ownership, payments, trade documentation, and vessel behavior that indicate a designated party sits behind an apparently clean counterparty. According to OFAC's April 2025 shipping advisory, Iranian networks typically run three to five successive ship-to-ship transfers within a single shipment to obscure cargo origin, a pattern OFAC notes serves little commercial purpose. Screening against designation lists catches names. Catching evasion requires monitoring behavior.

What a Sanctions Evasion Red Flag Actually Signals

A sanctions evasion red flag is an observable characteristic of a counterparty, transaction, shipment, or vessel that suggests a designated person or restricted destination sits behind an arrangement that looks legitimate on its face. A red flag is not evidence of a violation. It is a trigger for enhanced review, and its value lies precisely in surfacing exposure that list matching cannot detect.

Designation lists are a lagging record. The designated entity's name sits in the data. The freight forwarder it books through, the free trade zone company that issues its invoices, the single-ship SPV that owns the tanker lifting its cargo — those names typically do not. Evasion networks are engineered to survive a name match, which is why sanctions screening systems catch the designated party and miss the structure built around it.

OFAC made this reasoning explicit in its March 2026 advisory on sham transactions, which defines a sham transaction as an arrangement where blocked persons operating through proxies or intermediaries conceal — rather than genuinely extinguish — a continuing interest in property. OFAC states it will disregard the form of a transfer in favor of the underlying practical and economic realities. The question is no longer whether a counterparty appears on a list, but whether the economics of the arrangement make sense without a designated party behind them.

Six Typologies That Recur Across Enforcement Actions

Six evasion typologies recur across OFAC advisories, FinCEN alerts, and Department of Justice indictments. They are not mutually exclusive — a single network usually combines four or five, which is why detection depends on correlating indicators rather than treating each in isolation.

Shell and Front Companies

Front companies are the foundational layer of nearly every evasion structure. FinCEN's May 2026 alert on Islamic Revolutionary Guard Corps money laundering describes multi-jurisdictional shadow banking networks built from exchange houses, trading companies, and front companies that open bank accounts outside Iran so sanctioned entities can reach the international financial system without repatriating funds. The pattern FinCEN highlights is specific: general trading companies in free trade zones, controlled from a sanctioned jurisdiction, transacting with counterparties in Hong Kong and Singapore.

The observable signals are mundane. Entities with little or no web presence. Registered addresses that are residential, nonexistent, or shared with dozens of unrelated companies. Directors with no relevant experience for the goods or volumes involved.

Ownership Structured Below the Designation Threshold

Networks routinely arrange ownership so no single blocked person holds a stake that triggers the 50 Percent Rule — two blocked persons at 30% each, or a nominal owner holding shares under an informal agreement. The sham transactions advisory lists red flags that operate independently of percentage ownership: transfers on terms that are not commercially reasonable or lack adequate consideration, transfers to family members or close associates acting as proxies, transfers with no discernible business purpose, unduly complex legal structures in higher-risk jurisdictions, and the blocked person's continued involvement in the use, management, or disposition of the property.

Ownership screening on percentages alone is therefore insufficient. Effective beneficial ownership identification tests for control — who directs the entity, who benefits economically, and who was involved before a transfer conveniently occurred near a designation date.

Transshipment Through Non-Sanctioning Jurisdictions

Rather than exporting controlled goods directly to a restricted destination, networks route them through jurisdictions that have not adopted equivalent export controls, where local intermediaries re-export with falsified end-use documentation. The scale is measurable. A SUERF policy brief analyzing mirror trade data found that the post-invasion rise in Russian imports from non-sanctioning countries offsets roughly 45% of the decline in broad technology categories and nearly 70% for the high-priority dual-use goods list compiled by the EU, US, UK, and Japan.

The FinCEN and BIS joint alert names 18 jurisdictions as common transshipment points, including Armenia, Georgia, Kazakhstan, Serbia, Turkey, and the United Arab Emirates. Geography alone is not a red flag — legitimate trade flows through all of these. What matters is geography combined with product sensitivity, a counterparty with no operating history in that product line, and payment routing that does not match the stated trade.

Ship-to-Ship Transfers and AIS Manipulation

Maritime evasion has developed the most distinctive behavioral fingerprint of any typology, because vessels broadcast their own position. OFAC's shipping advisory identifies successive ship-to-ship transfers — three to five per shipment — as a strong risk factor, particularly when conducted at night, in unsafe waters, near sanctioned terminals, or involving a vessel with missing or manipulated AIS data. Vessels disable transponders during sensitive legs, broadcast false MMSI or IMO numbers, and claim flags they are no longer registered with. OFAC treats three flag registration changes within a single year as grounds for requesting additional ownership and voyage documentation.

Ownership follows the same pattern: vessel-owning SPVs in low-transparency jurisdictions, held by individuals with no public profile, often sharing naming conventions and courtesy-of addresses reflecting the ship manager's jurisdiction.

Digital Assets and Alternative Value Transfer

FinCEN identifies stablecoins as the preferred digital asset instrument for sanctions evasion, citing their liquidity, ease of settlement, and exchange rate stability. Iranian activity documented in the May 2026 alert includes stablecoin minting, movement between large-volume issuers, and the creation of proprietary stablecoins. The alert points to Iran-based digital asset service providers, nested exchanges, and peer-to-peer exchangers as the connective tissue to the global digital asset ecosystem, exploiting uneven onboarding, geolocation, and AML controls across jurisdictions.

The red flags here are profile mismatches rather than blockchain anomalies. A petroleum trading company settling in stablecoins. Account activity inconsistent with a customer's stated business model. Exposure to exchanges with no meaningful registration or KYC posture.

Trade Misdescription of Dual-Use Goods

Networks reclassify controlled items as uncontrolled ones, often targeting EAR99 goods that require no license for most destinations, and engage complicit shippers or customs brokers to obscure the nature of the goods or their ultimate destination. The joint alert lists indicators drawn from actual suspicious activity reporting: freight-forwarding firms named as the product's final end customer, atypical shipping routes, last-minute changes to transaction parties, and entities describing their work as "special purpose projects" — a Russian designation that typically means military use.

The Indicators Worth Monitoring

Red flags become useful only when assigned to a control that owns them. The grouping below maps each indicator category to the function best positioned to detect it — distributed across onboarding, monitoring, and trade review rather than concentrated in one sanctions team.

Indicator category What to look for Owning control
Counterparty profile No web presence, residential or shared registered address, directors without relevant expertise, incorporation date shortly before first material transaction Onboarding and KYB
Ownership and control Stakes structured just below designation thresholds, nominal owners, transfers near a designation date, blocked person still directing the entity UBO mapping and periodic review
Payment behavior Payments from third parties unconnected to the trade, routing through free trade zone entities, last-minute beneficiary changes, values inconsistent with stated business Transaction monitoring
Trade documentation Freight forwarder named as end customer, atypical routing, certificates of origin from jurisdictions known for obfuscation, goods descriptions inconsistent with declared HS codes Trade finance review
Vessel behavior AIS gaps or position spoofing, successive ship-to-ship transfers, repeated flag changes, false flags recorded in IMO GISIS, untested or sanctioned insurers Maritime and vessel due diligence
Digital assets Stablecoin settlement inconsistent with business profile, exposure to unregistered exchanges, nested exchange activity, counterparties in sanctioned jurisdictions Blockchain analytics and monitoring

Every one of these advisories carries the same caveat: no single red flag is determinative, and surrounding circumstances must be weighed before concluding that activity is suspicious. That caveat is operationally load-bearing. A control requiring correlation across two or three categories — a newly incorporated free trade zone counterparty paying for high-priority HS code goods routed through a transshipment jurisdiction — produces alerts worth an analyst's time. A control escalating on any single indicator produces noise.

Turning Red Flags Into Controls That Fire

Vertical flowchart showing four sequential steps for operationalizing sanctions evasion red flags: Scope, Encode, Escalate, Document
Turning a red flag list into working controls runs through four sequential steps: scope to real exposure, encode as detection logic, define escalation, then document and report.

Publishing a red flag list does nothing. The work is converting indicators into logic that runs against real data, with thresholds calibrated to actual exposure. Four steps carry most of the weight.

Start by scoping to the typologies the institution can plausibly encounter. A community bank with no trade finance book does not need vessel behavior monitoring. A payments firm serving marketplace sellers in the Gulf needs free trade zone counterparty logic far more than maritime coverage. Honest scoping prevents a red flag program from becoming a document that exists solely for examiners.

Next, encode the indicators as detection logic. High-priority HS codes belong in trade screening as data, not as a reference annex. Corporate registry signals — incorporation age, address reuse, director overlap — can be checked programmatically at onboarding. Third-party payers and last-minute beneficiary changes fit into transaction monitoring scenarios. Vessel data requires a maritime intelligence feed; AIS gaps cannot be inferred from payment messages.

Then define what escalation requires. A red flag hit should produce a specific set of questions, not a generic enhanced due diligence request. For a suspected transshipment case: who is the end user, what is the end use, what documentation supports it, and does the answer change under follow-up. OFAC lists evasive or inconsistent responses to due diligence inquiries as a red flag in its own right, which makes the answer itself evidence.

Finally, close the loop with documentation and reporting. Every disposition needs a record complete enough that a supervisor reviewing the file independently could reach the same conclusion. Where activity warrants a filing, the SAR narrative should state which indicators fired and what the investigation established, and use the applicable key terms — FinCEN and BIS ask institutions to reference FIN-2022-RUSSIABIS for Russia-related export control evasion and FIN-2023-GLOBALEXPORT for evasion tied to other jurisdictions.

Where Sphinx Fits

Sphinx operates at the investigation layer, where red flags turn into dispositions. When a screening or monitoring system escalates an evasion indicator, Sphinx's agents gather supporting evidence, trace ownership and counterparty relationships, assess whether the pattern is corroborated across indicator categories, and document the reasoning for audit. Every recommendation is logged, source-linked, and subject to analyst override — faster dispositions without thinning the documentation supervisors expect to see.

Frequently Asked Questions

What are the most common sanctions evasion red flags?

The indicators cited most often across OFAC and FinCEN guidance are front companies with minimal web or physical presence, ownership arranged to fall below designation thresholds, payments from third parties unconnected to the underlying trade, transshipment through jurisdictions without equivalent export controls, freight forwarders listed as the final end customer, and vessels with AIS gaps or repeated flag changes. No single indicator is determinative on its own.

How is sanctions evasion detection different from sanctions screening?

Sanctions screening matches names and identifiers against designation lists. Evasion detection looks for behavioral and structural patterns indicating a designated party operates behind an entity that is not itself listed. Screening is necessary and insufficient, because networks are built specifically to pass a name match.

Does the OFAC 50 Percent Rule still cover ownership obfuscation?

The 50 Percent Rule remains in force, but OFAC's March 2026 sham transactions advisory makes clear it is not the only test. OFAC will look through arrangements where a blocked person retains a continuing interest regardless of nominal ownership percentages, examining commercial reasonableness, the relationship between the blocked person and the nominal owner, and whether the blocked person still directs the property.

Which SAR key terms apply to suspected export control evasion?

FinCEN and BIS ask institutions to reference FIN-2022-RUSSIABIS in SAR field 2 and the narrative for suspected Russia-related export control evasion, and FIN-2023-GLOBALEXPORT for suspected evasion unrelated to Russia. Where it is unclear which applies, institutions are instructed to use both key terms.

How should a smaller institution prioritize evasion red flags?

By scoping to actual exposure rather than adopting every published indicator. An institution without a trade finance or maritime book gains far more from corporate registry checks at onboarding, third-party payer detection, and counterparty geography analysis. The defensible position is a documented rationale for which typologies were assessed as in-scope.

Get Your Free AI Compliance Handbook

What compliance leaders need to know about AI-driven fraud, autonomous laundering, and how your team can
fight back.
Submit
Thank you! Your submission has been received!
Something went wrong while submitting the form. Please try again.