Screening a person is a name problem. Screening a company is a structure problem. That single distinction is the reason entity screening trips up so many compliance programs that handle individual screening perfectly well. A person has one name, maybe a few variations of it, and a handful of identifiers that pin down who they are. A company has a legal name, trading names, subsidiaries, directors, shareholders, and a chain of owners that may run through several jurisdictions before it reaches an actual human being. Screening the company name alone tells you almost nothing about the risk sitting behind it.
This gap matters because a perfectly clean corporate name can conceal a sanctioned owner, a politically exposed controller, or an ownership structure that is blocked by operation of law without ever appearing on a list. What follows breaks down how individual and entity screening actually differ, why company names are harder to match than personal ones, and what a screening program needs to handle both without leaving the structural risk unexamined.
The distinction is not academic. Some of the most expensive compliance failures on record trace back not to a missed name on a list but to a failure to look behind a corporate counterparty and see who actually owned it. A company can present flawless paperwork, a legitimate-sounding name, and a clean direct screening result while being controlled, at one or two removes, by exactly the party the screening was meant to catch. Understanding why that happens, and how to prevent it, is the whole purpose of separating entity screening from individual screening as distinct disciplines rather than treating them as one process applied to two kinds of names.
The following topics are going to be covered in this article;
- Individual vs Entity Screening: The Core Difference
- Individual Screening: Person-Level Checks
- Entity Screening: Company-Level Checks and the Ownership Cascade
- Why Entity Names Are Harder to Match
- Building a Screening Program That Handles Both
- How Sanction Scanner Helps
1. Individual vs Entity Screening: The Core Difference
Individual screening checks a person against sanctions lists, politically exposed person (PEP) databases, and adverse media. The question it answers is direct. Is this specific human being a restricted, high-risk, or negatively reported party? The inputs are a name and a set of identifying details, and the output is a decision about one person.
Entity screening checks a company, but it cannot stop at the company name. It has to cascade to the people behind the entity, meaning the directors, shareholders, and ultimate beneficial owners who own or control it. A business is a legal construct. Sanctions risk, PEP risk, and adverse media risk ultimately attach to the real people connected to that construct, not to the registered name on the incorporation certificate.
That is the core difference stated plainly. Screening an individual is, for the most part, a single-name problem. Screening an entity is a structure problem, because the entity is screened and so is everyone who owns or controls it. A program that treats a company as just another name to run against a list has already missed the point of what entity screening is for.
The practical consequence of this difference shows up in effort and depth. An individual screen resolves in a single pass against the lists, with secondary identifiers cleaning up the ambiguous cases. An entity screen is closer to an investigation than a lookup. It starts with the company, expands outward to every director and shareholder, drills down through holding companies and intermediate entities to reach the natural persons at the end of the chain, and then screens each of them. A single company can generate a dozen or more individual screens once the structure is fully mapped. This is why entity screening consumes disproportionately more time and data than individual screening, and why underinvesting in it is such a common and costly mistake.
2. Individual Screening: Person-Level Checks
The person-level side is the more contained of the two, though it carries its own difficulties.
What gets screened is the individual's full name against sanctions, PEP, and adverse media sources. The mechanics are well established, and a competent screening engine runs the check in milliseconds. The complications come from the names themselves.
Name variations are the first challenge. A single individual may appear as "Robert," "Bob," or "Rob," or carry a middle name in some records and not others. Transliteration compounds this considerably, since a name originally written in Arabic, Cyrillic, or Chinese characters can be rendered into the Latin alphabet in several equally valid spellings, none of which match each other exactly. A screening system that cannot bridge those name variations will let a sanctioned individual pass simply because their name reached the system spelled differently than it sits on the list. Common names create the opposite problem, generating a flood of potential matches where a frequently occurring name collides with a listed party who happens to share it.
Disambiguation is how a program turns an ambiguous name match into an actual decision. Secondary identifiers do the work here. A date of birth, a nationality, a national identification number, or a place of birth attached to the record lets the system confirm or rule out a match that the name alone leaves uncertain. Without these identifiers, a common name produces an unresolvable pile of possible matches. With them, most of that pile resolves cleanly, and the analyst is left with only the genuinely ambiguous cases that warrant a closer look.
The quality of disambiguation depends entirely on the quality of the data collected at onboarding. A screening system can only match on the identifiers it has been given. If a customer record contains a name and nothing else, every namesake on every list becomes a potential match that a human has to clear by hand. If the record includes a date of birth and a nationality, the same screen returns a fraction of the alerts, because the system can discard the matches whose identifiers do not line up. This is why individual screening effectiveness is often less about the sophistication of the matching algorithm than about the completeness of the customer data feeding it. A modest algorithm with rich identifiers outperforms a powerful one working from a bare name.

3. Entity Screening: Company-Level Checks and the Ownership Cascade
The entity side is where screening gets genuinely harder, because the work does not end when the company name comes back clean.
Screening starts with the legal entity name checked against sanctions and dedicated entity lists, but it does not end there. It has to reach the ownership and control structure sitting behind that name. The company is one data point. The people and entities that own or direct it are the rest, and they carry risk that the company name will never reveal on its own.
The cascade is the defining feature of entity screening. A program screens the entity, then works through its directors, its shareholders, and its ultimate beneficial owners (UBO). A company with an impeccable name and a clean corporate record can have a sanctioned individual sitting in its ownership chain or a PEP among its controllers. If screening stops at the entity name, that risk stays invisible. The beneficial ownership threshold generally sits at 25 percent ownership or control, following the standard that most regulators apply, which means the cascade has to reach every owner at or above that line as well as anyone who exercises control by other means.
The OFAC 50 percent rule raises the stakes on getting the cascade right. Under this rule, a company that is owned 50 percent or more, in the aggregate, by one or more parties on the Specially Designated Nationals (SDN) list is itself blocked, even when the company never appears on any list by name. The aggregation matters, because two sanctioned parties holding 30 and 20 percent separately still combine to trigger the block. This is precisely why entity screening must assess ownership rather than the entity name alone. A name check against the SDN list will clear a company that is, in legal fact, fully blocked through its owners. Only an ownership assessment catches it.
The difficulty of the cascade scales with the complexity of the structure. A small company with two named shareholders is straightforward. A multinational with layers of holding companies incorporated across several jurisdictions, some of them in secrecy havens that do not publish ownership data, is a genuine investigative challenge. Sanctioned parties who wish to stay hidden deliberately build structures of exactly this kind, routing their ownership through intermediate entities and nominee arrangements designed to keep any single visible stake below the reporting threshold while preserving aggregate control. An entity screening program that cannot follow ownership through multiple layers will clear these structures every time, because at each individual layer nothing looks wrong. The risk only becomes visible when the layers are assembled into a complete picture and the aggregate ownership is calculated across the whole chain.
4. Why Entity Names Are Harder to Match
Beyond the ownership cascade, the entity name itself is harder to match than a personal name, for reasons that are specific to how companies are named and registered.
Legal suffixes are the first complication. The same company may appear as "Acme Ltd," "Acme LLC," "Acme GmbH," "Acme S.A.," or "Acme Pty," depending on jurisdiction and document, and sometimes with no suffix at all. A matching system has to recognize these as the same core entity rather than treating the suffix as a distinguishing feature. Abbreviations and acronyms push in the other direction, where "International Business Machines" and "IBM" refer to one company through strings that share almost no characters. Trading names diverge from legal names, so the brand a company operates under may bear no resemblance to its registered corporate title. Translations and transliterations of company names introduce the same cross-language variation that personal names suffer from. Name changes, mergers, and rebrands add a temporal layer, where the entity that signed a contract last year now operates under a different name entirely.
The matching implication is that entity screening leans heavily on token-based and edit-distance methods tuned for longer strings. Company names are typically longer and more structured than personal names, which suits algorithms like Levenshtein that handle long strings, provided the fuzzy matching configuration is calibrated for the length and format that corporate names actually take.
Calibration for entity names is its own discipline, distinct from tuning for personal names. The legal suffix problem, for instance, means a matching engine should often be configured to weight the core name far more heavily than the suffix, or to normalize suffixes away entirely before comparing, so that "Acme Ltd" and "Acme LLC" are recognized as the same core entity rather than penalized for their differing endings. The abbreviation problem pulls in the opposite direction and cannot be solved by string similarity alone, since "IBM" and "International Business Machines" share too few characters for any edit-distance measure to connect them. Catching that link requires maintaining alias and known-abbreviation data rather than relying on the matching algorithm to infer it. The upshot is that entity name matching is less forgiving of a default, out-of-the-box configuration than individual name matching, and a program that simply points its personal-name settings at company names will produce both missed matches and excess noise.
|
Dimension |
Individual Screening |
Entity Screening |
|
Primary target |
A single person |
A company and its ownership structure |
|
Core problem |
Matching one name and its variations |
Mapping and screening an entire structure |
|
What gets screened |
Full name against sanctions, PEP, adverse media |
Legal and trading names, plus directors, shareholders, and UBOs |
|
Name challenges |
Spelling variations, transliteration, common names |
Legal suffixes, abbreviations, trading names, rebrands, translations |
|
Disambiguation |
Secondary identifiers (DOB, nationality, ID number) |
Ownership and control data, corporate registry records |
|
Key legal trigger |
Direct designation of the individual |
Direct designation plus the 50 percent rule on aggregate ownership |
|
Matching methods |
Name-focused fuzzy and phonetic matching |
Token-based and edit-distance methods tuned for longer strings |
5. Building a Screening Program That Handles Both
A program that covers both sides properly needs to do a specific set of things, and the checklist below captures them.
- Individual: Screen the full name plus secondary identifiers against sanctions, PEP, and adverse media sources
- Entity: Screen the legal name and all trading names against sanctions and entity lists
- Cascade: Identify and screen directors, shareholders, and ultimate beneficial owners at the 25 percent ownership or control threshold
- Apply the 50 percent rule: Assess aggregate SDN ownership, not just the entity name
- Handle entity name variations, including legal suffixes, abbreviations, trading names, and translations
- Re-screen on ownership changes and new designations rather than treating screening as a one-time check
- Use corporate registries and beneficial ownership registers as data sources to map the structure accurately
The item that most often gets neglected is re-screening on change. Ownership is not static. A company that was clean at onboarding can be acquired by a sanctioned party, or have a PEP take a controlling stake, months later. A new designation can turn a previously clear owner into a blocked one overnight. Screening once at onboarding and never again leaves the entire structure exposed to exactly these shifts, which is why ongoing re-screening against both ownership changes and list updates is not optional for any program that takes entity risk seriously.
The data-source point deserves equal weight. The cascade is only as good as the ownership data feeding it. Corporate registries and beneficial ownership registers are what allow a program to see past the entity name into the structure behind it. Where that data is thin, incomplete, or unavailable, the cascade breaks down, and the program is left screening a name it cannot actually see behind. Investing in quality ownership data is therefore not a background task but a core part of making entity screening work at all.
A final point ties the two disciplines together. The individual and entity sides are not separate silos but two ends of the same chain, and the strongest programs recognize this explicitly. Every entity screen eventually resolves into a set of individuals to be checked, and many individual screens gain their full meaning only when the person is placed in the context of the companies they control. A program that keeps rigorous individual screening but weak entity screening, or the reverse, has a gap that risk will find. Coverage has to be genuinely end to end, from the registered company name through every layer of ownership down to the natural persons at the bottom, and back up again to the companies those persons control elsewhere.
6. How Sanction Scanner Helps
Sanction Scanner handles both sides of the problem in a single system. On the individual side, it screens a person's name together with secondary identifiers such as date of birth and nationality against sanctions, PEP, and adverse media data, turning ambiguous name matches into clear decisions rather than unresolved alerts.
On the entity side, Know Your Business capabilities carry the screening through the ownership cascade, reaching directors, shareholders, and ultimate beneficial owners rather than stopping at the registered company name. The 50 percent rule is assessed against the actual ownership structure, so a company blocked through aggregate SDN ownership is caught even when it never appears on a list by name. Underpinning both is real-time screening and monitoring that keeps individuals and entities checked on an ongoing basis, and sanctions coverage spanning the major global lists. The result is a program that treats a company as what it actually is, a structure to be mapped and screened, rather than just another name to run against a list.
The value of handling both in one system rather than two is that the individual and entity sides constantly feed each other. A beneficial owner surfaced during an entity screen becomes an individual to be screened in their own right, and a person flagged in one context may reappear as a controller of a company in another. Running these as separate, disconnected processes forces analysts to bridge that gap manually and invites the exact oversight that entity screening exists to prevent. A unified view, where the person behind the company and the company behind the person resolve into a single risk picture, is what turns entity screening from a box-ticking exercise into a control that actually sees the structure it is meant to examine.
Sources
[1] Office of Foreign Assets Control, U.S. Department of the Treasury. OFAC FAQ 401: Revised Guidance on Entities Owned by Blocked Persons (50 Percent Rule). 2025.
[2] Financial Action Task Force. FATF Recommendations: Transparency and Beneficial Ownership of Legal Persons (Recommendation 24) and Glossary Definition of Beneficial Owner. 2025.
FAQ's Blog Post
Re-screening runs on two triggers, not on a calendar: A change in the ownership structure, and a change in the lists, which OFAC and the EU publish without advance notice. A clean company can be acquired by a sanctioned party months after onboarding, and a new designation can turn a cleared owner into a blocked one overnight.
Fuzzy matching compares characters, and IBM shares almost none with International Business Machines. No edit-distance threshold connects them without also connecting thousands of unrelated names. The link has to come from alias and known-abbreviation data held alongside the list, not from the algorithm. A program relying on string similarity alone will miss every acronym in its book.
Personal-name settings applied to company names produce both missed matches and excess noise. Legal suffixes need normalizing or heavy down-weighting so Acme Ltd and Acme LLC read as one entity, while edit-distance measures such as Levenshtein need calibrating for longer, more structured strings. A default configuration pointed at corporate names is a tuning decision nobody made.
KYB is the wider process of verifying a business, covering incorporation documents, corporate registry and beneficial ownership register records, licences and ownership mapping. Entity screening is the check that runs the entity and every party in that ownership map against sanctions, PEP and adverse media lists. KYB produces the structure. Screening tests it.
Company names carry variation that personal names do not. The same entity appears as Acme Ltd, Acme LLC, Acme GmbH or Acme Pty depending on jurisdiction, trades under a brand unrelated to its registered title, and changes name outright through mergers and rebrands. A personal name varies in spelling. A company name varies in form, brand and time.
Beneficial ownership is not only a shareholding test. The 25 percent line captures owners by stake, but control exercised through other means, such as board appointment rights, voting agreements or nominee arrangements, brings a person into scope with no qualifying shares at all. Structures are built to keep every visible stake under the line while preserving aggregate control.
OFAC 50 percent rule combines the stakes of every blocked person rather than testing them one by one. Two designated parties holding 30 and 20 percent separately reach the 50 percent line together, and the company is blocked. Indirect ownership through intermediate entities counts the same way. Testing each shareholder in isolation clears a company that is blocked in law.
Companies are blocked automatically when parties on the SDN list own 50 percent or more of them in the aggregate, with no separate designation of the company. OFAC publishes no list of these entities, so they are invisible to a name check. Only an ownership assessment finds them, which is why entity screening cannot stop at the name.
Entity screening covers the legal name, every trading name, and then the people: Directors, shareholders, and ultimate beneficial owners, plus the intermediate holding companies in between. EU anti-money laundering law sets the beneficial ownership threshold at 25 percent plus one share, and most regimes follow that line. Control exercised by other means counts regardless of shareholding.
Entity screening checks a company against sanctions and entity lists, then cascades to the directors, shareholders and ultimate beneficial owners behind it. A business is a legal construct, so the sanctions, PEP and adverse media risk attaches to the real people who own or control it. Under OFAC rules a company can be blocked purely through those owners. The name never shows it.