AML false positives: why name matching fails and how to cut them

Louise Toulemonde
September 8, 2026

What is a false positive in AML screening?
A false positive in AML screening is a hit that matches your customer's name on a sanctions, PEP or adverse media list but turns out to be someone else. It is the normal output of name matching, not a malfunction: over the past year, 99.1% of the screening hits reviewers resolved on Dotfile were false positives, and fewer than 1 in 100 was the customer.
Each hit has to be read and closed with a reason, and the one true match sits somewhere in the pile. Alert fatigue is what happens when the pile wins: reviewers clear hits by habit, and the habit lets the real one through.
Why does name matching produce so many false positives?
Names are a weak identifier, so screening engines match loosely on purpose. Every source of looseness adds hits:
- Common names. A Maria Garcia or a Mohamed Ali matches dozens of listed people, none of whom is your customer.
- Transliteration. The same Cyrillic or Arabic name has several Latin spellings, so the engine matches variants: Mariya, Maria, Marija.
- Partial names. A list entry with only a surname and an initial matches every customer who shares the surname.
- Missing secondary identifiers. Many list entries carry no date of birth or nationality, so nothing in the data can rule them out automatically.
- Fuzziness. The higher the tolerance for spelling differences, the more near-names come back.
- Weak aliases. Lists record aliases such as nicknames or single words, and a weak alias matches almost anyone.
- Broad list coverage. Adverse media and warning lists are large and loosely structured. They generate more hits than sanctions lists, and more of them are noise.
None of these can be switched off for free. The question is which ones you tune, for which customers and how you document it.
What do regulators expect when you discard a hit?
Regulators expect you to screen against the lists the law names, and every discard to rest on a reason you can show.
Today, sanctions screening does not come from the anti-money laundering directive. It follows from the EU restrictive measures themselves: the asset freeze and the prohibition on making funds available to listed persons, for instance in Article 2 of Council Regulation (EU) No 269/2014. PEP screening comes from Article 20(a) of Directive (EU) 2015/849, which requires risk management systems to determine whether a customer or beneficial owner is a politically exposed person, as transposed into national law.
From 10 July 2027, the EU Anti-Money Laundering Regulation brings both into customer due diligence. Article 20(1)(d) of Regulation (EU) 2024/1624 requires you to verify whether the customer or its beneficial owners are subject to targeted financial sanctions, and Article 20(1)(g) to determine whether they are PEPs. Article 26(4) makes the sanctions check recurring, and for credit and financial institutions it must also run upon any new designation.
Two provisions decide how you handle the false positives, today and under the AMLR. You must be able to demonstrate that your measures are appropriate to the risks (Article 13(4), Directive (EU) 2015/849; Article 20(4), Regulation (EU) 2024/1624), which covers how you tuned the matching. From 2027, Article 21(3), Regulation (EU) 2024/1624 also requires records of the decisions taken, with the supporting documents and justifications. A hit discarded with no comment is a decision with no record.
The consequence is simple: you can reduce false positives by matching better, never by screening less. Dropping a sanctions list because it is noisy is a coverage gap, not a tuning decision.
How do you cut false positives without missing a true match?
You cut false positives by giving the engine more to compare and by matching each customer at the level of risk it carries. Five levers, in the order they pay off:
- Collect secondary identifiers at onboarding. Date of birth, nationality and country of residence for individuals; registration country and number for companies. Most discards are made on one of these, and a hit cannot be ruled out on data you never collected.
- Filter on what the list entry says. A country filter, the removal of weak aliases and the exclusion of deceased or delisted entries close hits before anyone reads them, because the list itself says they cannot be your customer.
- Set fuzziness per [risk segment](https://www.dotfile.com/resources/risk-scoring-in-kyb-methods-and-best-practices), not once for everyone. Tight matching on a low-risk retail segment, broader matching where the risk assessment calls for it. Write down why: supervisors will ask (Article 13(4) of the directive today, Article 20(4) of the AMLR from 2027).
- Handle PEP inactivity deliberately. A person who left a public function years ago is a different risk from a sitting minister. Former PEPs stay under extra measures for at least 12 months after they leave office: "appropriate and risk-sensitive measures" today (Article 22, Directive (EU) 2015/849), at least one enhanced due diligence measure under the AMLR (Article 45(2), Regulation (EU) 2024/1624). An inactivity filter shorter than 12 months is a gap.
- Let AI clear the obvious ones, under rules your team sets, for the hit types you choose. An AI agent can read each hit, compare the identifiers, close "false positive, different date of birth" with that reason written down and send the rest to a reviewer. Your team decides which hit types it may close on its own.
Worked example: one common name, four hits
A fictional customer, Maria Garcia, born on 14 March 1984, Spanish national living in Lyon, opens an account. Screening returns four hits.
| Hit | List | What it says | Outcome |
|---|---|---|---|
| Maria Garcia | PEP | Regional councillor in Mexico, born 1961 | False positive: year of birth |
| María García López | Adverse media | Fraud trial in Valencia, defendant aged 52 | False positive: age in the article |
| M. Garcia | Fitness and probity | US broker barred by a regulator, no date of birth | False positive: US resident, the record describes a man |
| Mariya Garsiya | Sanctions | Transliterated name, born 1984, Russian national | Needs a human |
Three hits close on an attribute the list entry carries, and each comment names it. The fourth does not: same birth year, a plausible transliteration, a different nationality, and nationality alone does not rule out a sanctioned person, who may hold two. The reviewer compares the full date and place of birth on the list entry with Maria's identity document, finds both differ and discards with that evidence attached.
How many AML hits are false positives? 99 in 100
Based on AML screenings run on Dotfile over the past year; aggregates only.
- 99.1% of the hits reviewers resolved were false positives. Fewer than 1 in 100 was the customer.
- The ratio depends on the list. Among resolved hits, about 1 in 370 sanctions hits was a true match, against about 1 in 80 adverse media hits and 1 in 50 PEP hits.
- The load is uneven. A screening that returns hits brings a median of 2, but the top tenth bring 25 or more each.
Read together: sanctions hits are the rarest true positives and the most expensive ones to miss, which is why they deserve the slowest review, not the fastest.
Frequently asked questions
What is a good false positive rate for AML screening?
There is no regulatory target, and a low rate is not a goal in itself: a rate near zero usually means the matching is too tight to catch spelling variants. Judge the setup on whether true matches are caught and every discard is documented, then reduce the noise around that.
Can AI clear AML false positives automatically?
Yes, within limits you set. AI agents can clear the obvious false positives with a written reason for each and send the rest to a reviewer. You decide which hits it may close on its own, sanctions and PEP included, and every closure keeps its reason. From 2027, Article 21(3), Regulation (EU) 2024/1624 expects the record of each decision, and the written reason is that record.
What is fuzzy name matching in sanctions screening?
Fuzzy matching scores how close a name is to a list entry instead of requiring an exact match, so spelling variants, transliterations and reordered names still come back. The tolerance is a setting: on ComplyAdvantage Mesh it runs from 0 (exact) to 100 (broad), and more tolerance means more hits.
What is the difference between a false positive and a false negative?
A false positive is a hit that is not your customer; it costs review time. A false negative is a true match the screening missed; on a sanctions list, it can cost you a breach. Every lever that cuts false positives has to be checked against the second number, not just the first.
Does ongoing monitoring create more false positives?
Yes, every list update can produce new hits on existing customers; see our guide to ongoing KYB monitoring. The same levers apply, and our guide to AML screening and monitoring covers how rescreening works. For PEP-specific steps, see the PEP screening process.
Where Dotfile fits
Dotfile's AML screening runs on ComplyAdvantage or LSEG World-Check, for individuals and companies. With ComplyAdvantage Mesh you choose the categories and lists to screen, set fuzziness from 0 to 100 and switch on filters that cut noise at the source: country filter, weak alias removal, exclusion of deceased or delisted entities and inactive PEP filters at 1 or 5 years. Up to four additional screening configurations per workspace let you match different segments differently.
On ComplyAdvantage screenings, the AML AI assistant qualifies each hit as a true positive, a false positive or one for manual review, and writes the reason: over 90% of hits come back pre-qualified, and reviewers confirm them in bulk where the reasons hold. Autonomy goes one step further: its AML agent discards the false positives and validates the true ones under rules your team sets, for the hit types you choose, with a line-by-line reasoning report on every hit. With World-Check, hits are reviewed in World-Check One, linked from the check.

Ready for Anywhere?
Verify any business, enter any market, defend every decision. Every signal orchestrated, every decision traceable, from one platform.



