One Name, Six Spellings: The Blind Spot in KYC and Sanctions Screening

As banks, fintechs, and sportsbooks scale across markets, the hardest part of onboarding isn't the tech. It's the name.
Look at any global sports roster and you see the challenge of sanctions screening in miniature. A Major League roster spans nearly 20 countries. A top European football club fields names that arrive in Latin, Cyrillic, Arabic, and CJK scripts, each with several valid romanizations.
A single Arabic given name can be spelled Mohamed, Mohammed, or Muhammad. A Cyrillic surname can transliterate half a dozen ways into English. It's charming on a jersey but a nightmare in a sanctions filter. These variations make name transliteration one of the most persistent challenges in global screening.
The More Locales You Serve, the Harder KYC and Screening Become
When one name has many spellings, two things happen at once: genuine sanctions and PEP matches can slip through under an unexpected transliteration, while thousands of harmless customers get flagged because their common surname fuzzy-matches a watchlist entry. Name-based screening is where this bites hardest, and the numbers are brutal. Financial institutions routinely report false-positive rates above 90–95%, meaning analysts and MLRO teams spend the overwhelming majority of their time clearing noise created by spelling and transliteration variants, not catching bad actors.
A 2026 FCA review of more than 150 UK firms put a hard number on the miss rate: screening correctly caught the sanctioned party in 90% of exact-match tests but only 75% when the same name appeared in a slightly different form, missing roughly one in four names with minor variations. The FCA was blunt about where the buck stops: accountability cannot be outsourced to a screening vendor.
The Stakes Are Enforcement-Grade
This is not hypothetical, and it isn't always about scale. In early 2026, the UK's Office of Financial Sanctions Implementation fined Bank of Scotland £160,000 after a UK-designated individual under the Russia regime opened a Halifax account with a passport that rendered his name in a Russian-to-English transliteration variant the bank's screening never reconciled. Two dozen payments worth about £77,000 moved to and from a sanctioned person's account before it was caught. The failure wasn't exotic. It was a spelling.
The bigger cases show the same root cause priced at scale. On August 3, 2026, FinCEN assessed a record $125 million penalty against UBS for repeat, willful AML failures, after the firm left tens of thousands of foreign-currency wires under-monitored, years after settling over the same weakness. It's the latest in a decade where screening and monitoring gaps carried nine- and ten-figure price tags: TD Bank paid about $3.09 billion in 2024, the largest Bank Secrecy Act penalty on record; Standard Chartered paid $1.1 billion in 2019 for processing transactions tied to sanctioned countries; and BNP Paribas paid nearly $9 billion in 2014 for concealing sanctioned-party transactions. When a sanctioned name slips through under an unfamiliar spelling, that is the downside on the table.
Why This Is Getting Harder in 2026
Two forces are converging. First, regulation is centralizing: the EU's new Anti-Money Laundering Authority (AMLA) began operating from Frankfurt in July 2025, and a directly applicable "single rulebook" takes effect across all 27 member states from July 2027, introducing perpetual KYC. A digital bank adding markets can no longer treat multilingual KYC and screening as a per-country afterthought.
Second, whole new regulated sectors are scaling into the same obligation. Legal sports betting has exploded across the US and Europe, and operators must run KYC, AML, and sanctions checks on millions of bettors across jurisdictions and languages, an obligation actively reinforced by European industry bodies such as the EGBA. This is already biting: in October 2025, the UK Gambling Commission fined Platinum Gaming, the operator of Unibet, £10 million for AML and safer-gambling failures, its second enforcement action in two years. More markets, more scripts, more names that don't match cleanly.
What Good Looks Like
The fix isn't a better black-box algorithm. It's getting the language layer right: multilingual KYC and onboarding, plus sanctions-ready name transliteration and matching, so core client processes and screening hold up consistently, regardless of the market or script in which the name appears. Done well, it performs two jobs at once: keeping genuine sanctions exposure from hiding behind a spelling variation, and cutting the false-positive load that buries review teams as you add markets.
Regulators have also made clear that this is the firm's job, not the vendor's. After its 2026 review, the FCA expects institutions to demonstrate with evidence that their screening is tested, tuned, and effective against name variations, not just exact matches. Leading US and European financial institutions already lean on this capability to keep onboarding clean and reduce MLRO review load as they expand. The name on the shirt should be the same name your screening sees, in every language.
Explore our Financial Services solutions: https://www.transperfect.com/financial