How ISO 20022 Improves Sanctions Screening Data

Every cross-border payment is screened against sanctions lists before it can complete. The screening engine compares the names and addresses in the payment against watchlists of sanctioned people, entities and places. That comparison is only as good as the data it receives — and for decades the data was terrible. Legacy formats crammed critical party information into short, unstructured free-text fields. ISO 20022 changes the raw material of screening by carrying rich, structured, discrete data. The result is better hit detection and fewer false alarms.
The problem with legacy free text
The old workhorse of cross-border messaging, the SWIFT MT format, squeezed the ordering customer and beneficiary into fields like field 50 and field 59. These were narrow free-text blocks — typically four lines of thirty-five characters. Everything about a party — name, street, city, country — was jammed together, often abbreviated or truncated to fit. A screening engine reading that blob cannot reliably tell which words are the name and which are the address. It has to guess, and guessing produces both misses and noise.
Structured data changes the input
ISO 20022 replaces the free-text blob with a structured party model. Instead of one cramped field, a party such as the debtor or creditor is described with discrete, labelled elements:
- Name as its own field, separate from address.
- PostalAddress broken into structured sub-elements: street name, building number, town, post code and, critically, a country code.
- Identification that can carry an organisation identifier such as an LEI, or structured personal identification.
- Distinct roles for debtor, creditor, ultimate debtor and ultimate creditor, so the true originator and beneficiary are visible even when intermediaries are involved.
When the screening engine knows that a value is a name rather than an address line, it can apply name-matching logic to names and location logic to countries, instead of matching everything against everything.
Fewer false positives
False positives are the tax that screening imposes on operations. Every alert must be investigated by a human, and legacy data generated enormous volumes of them because address words collided with name lists. Consider a sanctioned individual sharing a common surname with a city on an address line — unstructured screening flags it; structured screening does not, because it knows the surname is in the address, not the name field. By letting the engine target the right field, ISO 20022 reduces spurious hits, which frees analysts to focus on genuine risk and shortens payment delays.
Fewer missed hits
Structure cuts the opposite error too. When data is truncated to fit a legacy field, part of a sanctioned name can be lost, and a true match is missed. ISO 20022's longer, dedicated fields mean names and identifiers are not clipped. The presence of a structured country code lets engines screen against sanctioned jurisdictions reliably rather than hoping a country name appears somewhere in free text. And the explicit ultimate-party fields expose the real originator and beneficiary that legacy formats could hide behind intermediary banks.
Identifiers, not just names
Names are ambiguous; identifiers are not. A powerful improvement is the ability to carry a Legal Entity Identifier for organisations and other structured IDs. Screening a payment against a precise LEI is far more decisive than fuzzy-matching a company name that might be spelled several ways. As list providers add identifiers to their entries, structured payments allow deterministic matching that both catches true hits and clears innocent parties instantly.
Why the migration is mandatory, not optional
Regulators and market infrastructures have not left this to goodwill. The migration of cross-border payments and high-value systems to ISO 20022 comes with a firm expectation that structured address and party data be used, with fully structured addresses required after a transition period. The reason is precisely the compliance benefit: supervisors want screening fed clean, discrete data. Firms that keep stuffing structured fields with old-style free text undermine the whole point and invite scrutiny.
Key takeaways
- Sanctions screening quality depends on the quality of party data in the payment message.
- Legacy formats crammed names and addresses into short free-text fields, causing misses and noise.
- ISO 20022 carries discrete name, structured address, country code and identification fields.
- Structure cuts false positives by letting engines match the right field, and cuts misses by avoiding truncation.
- Carrying identifiers like the LEI enables deterministic matching, and regulators now mandate structured data.