DISPATCHES · Summit Cognitive

← All dispatches

StandingThe CasebookJuly 27, 20265 min read

The name that matched the list

A fuzzy match against a list can freeze a person's account, block a payment, or stop them at a border over a name that was never theirs — and clearing it means disproving a suspicion the system will not fully describe.

A payment does not go through. The person trying to send it has done nothing unusual — a routine transfer, the kind they have made a hundred times — but this time the screen returns a message that is polite and final. The transaction cannot be completed. When they call, a representative reads from something on their own screen and says, with what sounds like genuine regret, that the account cannot be served at this time for compliance reasons. Which list, which entry, which fields matched, how confident the system was that the match was real — none of that is offered, because the representative does not have it either. Somewhere upstream, an automated screen compared a name to a roster of names it must not do business with, found the two close enough, and stopped. The name on the roster belongs to someone else. It always did. But the person on the phone is now, in the eyes of the system, a possibility that has to be ruled out — and no one will tell them exactly what they are suspected of resembling.

This is the ordinary shape of a watchlist false positive, and it is worth sitting with how ordinary it is. A common surname. A transliteration from another alphabet that a matching algorithm renders three plausible ways. A shared date of birth. None of these is a coincidence in the interesting sense; they are the statistical texture of names, the reason millions of people share identifiers with a few thousand entries on sanctions and screening lists. The match did not find a person. It found a resemblance — and then a system, and everyone downstream of it, treated the resemblance as if it were a finding.

Matched, not identified

The first thing to see clearly is the distance between two words that the process quietly collapses. To match is to note that two strings are similar under some measure of similarity. To identify is to conclude that two records describe the same human being. Fuzzy matching does the first and is routinely read as if it had done the second. The algorithm reports a score — a number expressing how alike two names are — and somewhere in the pipeline that score crosses a threshold and becomes a status: hit. The person is no longer someone whose name is similar to a listed name. They are a hit. The grammar has changed, and with it the burden.

Underneath the collapse sits a base-rate problem that screening systems are structurally tempted to ignore. When the thing you are searching for is rare and the identifiers you search on are common, the overwhelming majority of your matches will be false — not because the algorithm is bad, but because there are so many more innocent people who happen to share a name than there are actual entries on the list. A screen tuned to catch nearly every true match will, of mathematical necessity, sweep up a large multiple of people who are not on any list at all. The individual experiences this as a personal accusation. It is closer to a coincidence of data — their identifiers fell inside a net cast wide on purpose. The system knows this in the aggregate and acts, at the level of the single case, as if it did not.

Proving you are not someone else

Now consider what the matched person is actually being asked to do. Not to explain a decision they made, or to justify a transaction, or to correct a fact about themselves. They are being asked to prove a negative about a stranger: I am not the person on your list. This is close to the hardest thing anyone can be asked to demonstrate, and the process makes it harder still by withholding the one thing that would make it tractable. You cannot rebut a match you cannot see. If you are not told which entry you matched, on which fields, at what confidence, you are reduced to protesting your innocence in general — and general protestations of innocence are exactly what a guilty person would also offer, which is why they persuade no one.

Screening asks the state's question — is this the person? — and then hands the person the impossible job of answering it about themselves, in the dark, against a file they are not allowed to read.

The asymmetry is not an accident of design; it is the rational output of the screener's incentives. Weigh the two errors the screener can make. Clear a match that turns out to be a true one, and the institution has facilitated a prohibited transaction — a catastrophic outcome, potentially a legal and reputational disaster. Block a match that turns out to be false, and the institution has inconvenienced a customer who will find it very difficult to prove they were wronged and even more difficult to make anyone pay for it. Faced with that lopsided ledger, any institution acting in its own interest will over-block and under-explain. Caution is free to the screener and expensive to the screened. The result is a machinery that resolves its uncertainty by transferring the entire cost of that uncertainty onto whichever individual happened to match.

This is where the abstract idea of standing stops being abstract. Standing is the claim to a real place in a process that is deciding about you — a right to be heard by someone with the authority to act, on the actual grounds of the decision, before the decision hardens into a permanent fact of your life. The matched person has, at present, no standing at all. They are the subject of a determination they cannot see, made by a process they cannot reach, defensible only by disproving a suspicion no one will describe to them. Everything else in their situation follows from that missing foothold.

What standing requires, even under secrecy

The honest objection to all of this is that watchlist screening is not like other automated decisions, because secrecy here is not always a cover for laziness — sometimes it is a genuine security requirement. The internal composition of certain lists, the reasoning behind particular entries, the tradecraft that assembled them: there are real cases where disclosing these would defeat their purpose. That objection is legitimate and must be taken seriously rather than waved away. But it proves far less than it is usually made to prove, because it conflates two very different kinds of confidentiality.

Separate what must genuinely stay secret from what need not. The internal detail of a sensitive list — why an entry exists, what it connects to — can remain confidential without any cost to the matched person's ability to defend themselves. What need not stay secret, and what standing actually requires, is far more modest: that a match occurred at all; on what class of identifiers it occurred — name, date of birth, nationality — so the person knows what feature of theirs collided with what; at what confidence, so a weak coincidental match is not treated as a strong one; and, decisively, a route to a human being with the authority to adjudicate identity — the one question that is not secret, because it is a question about the person standing right there, not about the list. None of that discloses the list. All of it lets the person say the true and relevant thing: I share a name, and I am not that name.

And underneath the live process, a preserved record — a Decision Receipt of the screen: the identifiers compared, the confidence returned, the threshold applied, the human adjudication and its result — held so that an oversight body can later audit whether the system was blocking real risks or merely blocking people. This is the part that distinguishes accountable screening from its counterfeit. A system that over-blocks and keeps no contestable record of why is not doing security. It is doing unaccountability with a compliance label on it — declining to serve people, declining to explain, and declining to leave behind anything that would let anyone check whether the declining was ever justified. Security that cannot be audited is not more secure. It is only less answerable, and it asks the wrong person to bear the cost of that.

The scenario above is illustrative — a composite drawn to show a pattern, not an account of any real person, company, list, or event.

— Dispatches · Summit Cognitive

Continue from here

Turn the argument into a practice.

Get new dispatches, assess how your organization handles consequential decisions, or explore Summit Cognitive.