KibiPay
HomeBlog › ISO 20022

How ISO 20022 Improves Sanctions Screening Data

7 min read ISO 20022
ISO 20022Sanctions screeningCompliance
How ISO 20022 Improves Sanctions Screening Data

Every cross-border payment is screened against sanctions lists before it can complete. The screening engine compares the names and addresses in the payment against watchlists of sanctioned people, entities and places. That comparison is only as good as the data it receives — and for decades the data was terrible. Legacy formats crammed critical party information into short, unstructured free-text fields. ISO 20022 changes the raw material of screening by carrying rich, structured, discrete data. The result is better hit detection and fewer false alarms.

The problem with legacy free text

The old workhorse of cross-border messaging, the SWIFT MT format, squeezed the ordering customer and beneficiary into fields like field 50 and field 59. These were narrow free-text blocks — typically four lines of thirty-five characters. Everything about a party — name, street, city, country — was jammed together, often abbreviated or truncated to fit. A screening engine reading that blob cannot reliably tell which words are the name and which are the address. It has to guess, and guessing produces both misses and noise.

Structured data changes the input

ISO 20022 replaces the free-text blob with a structured party model. Instead of one cramped field, a party such as the debtor or creditor is described with discrete, labelled elements:

When the screening engine knows that a value is a name rather than an address line, it can apply name-matching logic to names and location logic to countries, instead of matching everything against everything.

Fewer false positives

False positives are the tax that screening imposes on operations. Every alert must be investigated by a human, and legacy data generated enormous volumes of them because address words collided with name lists. Consider a sanctioned individual sharing a common surname with a city on an address line — unstructured screening flags it; structured screening does not, because it knows the surname is in the address, not the name field. By letting the engine target the right field, ISO 20022 reduces spurious hits, which frees analysts to focus on genuine risk and shortens payment delays.

Fewer missed hits

Structure cuts the opposite error too. When data is truncated to fit a legacy field, part of a sanctioned name can be lost, and a true match is missed. ISO 20022's longer, dedicated fields mean names and identifiers are not clipped. The presence of a structured country code lets engines screen against sanctioned jurisdictions reliably rather than hoping a country name appears somewhere in free text. And the explicit ultimate-party fields expose the real originator and beneficiary that legacy formats could hide behind intermediary banks.

Identifiers, not just names

Names are ambiguous; identifiers are not. A powerful improvement is the ability to carry a Legal Entity Identifier for organisations and other structured IDs. Screening a payment against a precise LEI is far more decisive than fuzzy-matching a company name that might be spelled several ways. As list providers add identifiers to their entries, structured payments allow deterministic matching that both catches true hits and clears innocent parties instantly.

Why the migration is mandatory, not optional

Regulators and market infrastructures have not left this to goodwill. The migration of cross-border payments and high-value systems to ISO 20022 comes with a firm expectation that structured address and party data be used, with fully structured addresses required after a transition period. The reason is precisely the compliance benefit: supervisors want screening fed clean, discrete data. Firms that keep stuffing structured fields with old-style free text undermine the whole point and invite scrutiny.

Key takeaways

See these rails in motion

KibiPay connects UK Faster Payments, Bacs, CHAPS, Mojaloop mobile money and Solana behind one API, with ISO 20022 messaging and real-time fraud & AML screening.

Open the live console How it works