← Back to blog

Sanctions Evasion Typologies: Red Flags and AI Controls for Officers

September 14, 2026
Sanctions Evasion Typologies: Red Flags and AI Controls for Officers

Sanctions evasion typically follows a small set of repeatable typologies: intermediaries and front companies, beneficial ownership obfuscation and sham transactions, virtual-asset channels, and maritime or trade-based concealment. Compliance teams should prioritise resolving beneficial ownership information, monitoring behavioural signals rather than static lists, and filing SARs and STRs that trace the network, not just the transaction.


TL;DR:

  • Identifying sanctions evasion requires monitoring sequences of behavior, such as ownership transfers before designations and vessel transponder disabling, rather than just list-screening.
  • Beneficial ownership obfuscation and sham transactions often involve layered structures, nominee directors, and transfers close to sanctions dates, making functional analysis essential.
  • Virtual asset channels, including no-KYC exchanges and mixing services, enable rapid cross-border value movement that is harder to trace with simple blockchain analysis.
  • Tracking shadow fleet activities involves combining AIS data gaps, satellite imagery, and trade documentation to detect falsified cargo, unusual routing, and ship-to-ship transfers.
  • Continuous, layered monitoring using AI, network analytics, and real-time typology updates is crucial to effectively catch evolving schemes and avoid reliance on static controls.

Aithea
Strengthen Your Compliance Technology Strategy
AITHEA helps compliance teams navigate regulations, AI and technology vendors across the evolving financial crime compliance landscape.
Explore AITHEA

Table of Contents

What are sanctions evasion typologies and why do they matter?

A typology, in operational terms, is a documented pattern of behaviour that criminals or sanctioned entities repeat to move money or goods around a restriction. It is not a single red flag. It is a sequence: a front company formed weeks before a designation, a payment routed through a third country, a vessel that switches off its transponder near a transfer point. Recognising the sequence, not just the individual step, is what separates effective detection from list-screening theatre.

This distinction matters because pure list-based screening (checking names against the OFAC Specially Designated Nationals list or equivalent EU and UK registers) catches only the crudest attempts. The FATF's 2025 report on complex proliferation financing identifies four dominant typology families used to route around exactly that kind of screening: enlisting intermediaries, obscuring beneficial ownership, exploiting virtual assets, and abusing maritime and shipping sectors.

Typology intelligence earns its place in a compliance programme for three concrete reasons:

  • It converts abstract "sanctions risk" into testable monitoring rules and specific data fields to check.
  • It gives investigators a pattern library to match against ambiguous cases, cutting time-to-triage.
  • It aligns institutional controls with the National Crime Agency's enabler categories and OFAC's advisory red flags, which regulators increasingly expect firms to demonstrate they have operationalised, not just read.

Across Europe, the direction of travel is toward supervisors asking firms to show their typology knowledge translates into system logic, not just training slides. That is the gap this article is built to close.

How intermediaries, front companies and nominees conceal sanctioned interests

Enlisting intermediaries is the typology FATF places first, and for good reason: it is cheap, low-skill, and endlessly repeatable. A sanctioned individual or entity recruits a proxy, often a family member, business associate, or a professional enabler, to hold assets, sign contracts, or operate accounts on their behalf.

How the structure typically works:

  1. A front company is incorporated, often in a jurisdiction with weak beneficial ownership disclosure, shortly before or immediately after a designation is announced.
  2. Ownership is registered to a nominee director whose name carries no sanctions hits but who exercises no genuine independent control.
  3. Contracts, invoices, and bank mandates are signed by the nominee, while instructions continue to flow from the sanctioned party through informal channels.
  4. Layers are added when scrutiny increases: a second shell company, a family trust, or a "management services" contract that reroutes the same underlying interest.

The NCA's enabler framework is genuinely useful here because it separates enablers into three categories: criminally complicit, wilfully blind, and unwitting. That distinction changes both the investigative approach and, eventually, any enforcement referral. A wilfully blind company formation agent behaves differently under questioning than someone who genuinely had no idea whose interest they were fronting for, and the NCA's red alert on sanctions evasion mechanisms sets out behavioural indicators for each.

Ownership changes clustered around a designation date are the single most reliable signal. A registry filing that transfers 100% of shares to a distant relative or a junior employee two weeks before an entity appears on a sanctions list is not a coincidence worth ignoring.

Detection in practice means combining three things: routine registry checks against beneficial ownership registers where they exist, network analysis that maps shared addresses, directors, or auditors across seemingly unrelated entities, and cross-firm intelligence sharing so that one bank's suspicious nominee does not go unnoticed by four others onboarding the same person.

Pro Tip: Build a standing query that flags any counterparty whose ownership structure changed within 90 days of a sanctions list update. That single rule catches a disproportionate share of hastily assembled front companies.

Dismantling one shell company rarely ends the pattern. Practitioners consistently observe that the same network simply activates a redundant node, another nominee, another jurisdiction, which is why sustained network monitoring beats one-off enforcement actions against a single entity.

Why beneficial ownership obfuscation and sham transactions matter

Obscuring beneficial ownership information (BOI) is the technical backbone of nearly every sophisticated evasion scheme. If investigators cannot reliably answer "who actually controls this asset", every downstream control, screening, monitoring, reporting, is working with a false premise.

OFAC's approach to this problem is deliberately functional rather than formal: it asks whether a sanctioned person retains a genuine controlling interest, regardless of what the paperwork says. This "substance over form" lens is precisely what compliance teams need to adopt when reviewing corporate structures, because sham transactions are, by design, built to look legitimate on paper.

The 2026 OFAC advisory on sham transactions lists concrete red flags that any transaction monitoring or KYC refresh process should be testing for:

  • Commercially unreasonable transfers, assets sold well below market value, or gifted outright, with no plausible business rationale.
  • Transfers to family members or close associates of a designated or high-risk individual, especially shortly before or after a listing.
  • Continued involvement by the blocked person in the transferred asset, whether through consulting arrangements, board seats held by proxies, or unchanged operational control.
  • Complex corporate structures layered across high-risk jurisdictions with no clear commercial purpose beyond obscuring ownership.
  • Transfers executed suspiciously close to the timing of a designation announcement, suggesting advance knowledge or a rushed restructuring.

Firms applying a functional analysis test, rather than accepting registry documents at face value, catch a materially higher share of sham transfers, because paperwork alone almost never reveals continued control according to OFAC's own advisory guidance.

Applying functional analysis in practice means asking a short set of investigative questions whenever a red flag triggers: Who benefits economically from this arrangement, regardless of legal title? Has the previous owner's behaviour (signing authority, physical access, communication patterns) actually changed since the transfer? Does the price paid reflect any genuine market logic?

Due diligence escalation should trigger automatically once two or more red flags co-occur, a below-market transfer combined with a family relationship, for instance, rather than waiting for a single dramatic indicator. Entity resolution tooling that combines corporate registries, sanctions lists, PEP registries, and available geolocation data gives investigators the cross-referencing power to spot proxy relationships that a manual KYC review would likely miss entirely.

How do criminals use crypto to evade sanctions?

Virtual assets give sanctioned parties a channel that bypasses correspondent banking entirely, and that is precisely their appeal. Cryptocurrency transfers, mixing services, and no‑KYC exchanges let value move across borders without touching a regulated bank account at any point in the chain.

FATF's typology work confirms that blockchain transactions and certain stablecoins are increasingly used to shift value outside regulated rails, and their pseudonymous nature genuinely complicates attribution. That said, FATF is explicit that blockchain analytics and engagement with virtual asset service providers (VASPs) meaningfully reduce this risk rather than leaving it unmanageable.

Risk indicators worth instrumenting directly into monitoring rules:

  • Frequent transfers to or from exchanges with weak or absent identity verification requirements.
  • Use of mixing or tumbling services immediately before funds reach a regulated on-ramp or off-ramp.
  • Structuring of crypto-to-fiat conversions into amounts just below reporting thresholds.
  • Wallet addresses previously linked, even indirectly, to sanctioned entities or known darknet marketplaces.
  • Rapid movement across multiple chains or tokens with no apparent commercial rationale, a pattern sometimes called "chain hopping".

Practical controls fall into three buckets. Blockchain analytics tools trace wallet clusters and flag exposure to sanctioned addresses, giving investigators a visual map rather than a spreadsheet of hashes. Direct engagement with VASPs, including formal information requests, helps close identification gaps that pure on-chain analysis cannot resolve alone. Travel-rule mechanisms, which require originator and beneficiary information to travel with a transaction above a threshold, are increasingly enforceable across European jurisdictions and give compliance teams a legal hook to demand counterparty data from other exchanges.

Pro Tip: Do not treat "uses cryptocurrency" as a red flag in itself. Treat "uses no‑KYC on/off ramps combined with mixing" as the actual signal. The distinction avoids both false positives and, more importantly, missing genuinely low-risk crypto activity.

For teams building out tracing capability, understanding how investigators track funds across blockchain networks is a useful grounding before evaluating commercial analytics vendors, since the underlying tracing logic explains what any tool you buy should actually be doing under the hood.

How does the shadow fleet evade maritime sanctions?

The maritime sector remains the most physically visible, and paradoxically hardest to police, sanctions evasion channel. S&P Global's reporting documents the rapid expansion of what has come to be called the "shadow fleet": ageing tankers, often reflagged and opaquely owned, dedicated to moving sanctioned oil while evading the tracking systems designed to catch them.

Three tactics dominate this typology. Vessels disable their Automatic Identification System (AIS) transponders, effectively going dark for the riskiest legs of a voyage, then reappear once clear of monitored waters. Ships change flag registries repeatedly, sometimes multiple times within a single year, to stay ahead of enforcement attention and insurance scrutiny. Ship-to-ship transfers, cargo moved between two vessels at sea rather than at a port, let sanctioned oil change ownership and apparent origin without ever touching a documented terminal.

Trade-based money laundering (TBML) frequently rides alongside these physical tactics. The tell-tale signs compliance and trade finance teams should be testing for include:

  • Misdeclared cargo, where the bill of lading describes goods inconsistent with the vessel's known trade or the buyer's actual business.
  • Abnormal pricing, invoices set well above or below prevailing market rates to shift value covertly between parties.
  • Circuitous routing, cargo documented as passing through two or three intermediary countries with no obvious commercial logic, often to launder the goods' apparent origin.
  • Falsified bills of lading, documents that misstate the vessel, port of loading, or cargo description to obscure the sanctioned nexus.

The shadow fleet's growth has been rapid enough that S&P Global's analysis treats it as a structural feature of the sanctioned oil trade rather than a temporary workaround, meaning tracking tools built for occasional anomalies now need to handle sustained, organised evasion at scale.

Detection has to combine data sources that, individually, each tell only part of the story. AIS data reveals gaps and route anomalies; satellite imagery confirms whether a vessel was physically where its transponder claimed; trade data and customs filings cross-check whether declared cargo matches known shipping patterns. FATF and USCC analysis both point to China's role as a transshipment hub, where goods and financial flows pass through intermediaries and barter-like arrangements specifically to break the paper trail between origin and sanctioned destination. The mechanics of this, and how compliance teams can spot vessels engineered for invisibility, are explored further in Aithea's analysis of the ghost ship phenomenon.

Trade finance and payment layering: what to watch for

Payment layering is the financial mirror of physical trade-based concealment. Instead of hiding cargo, it hides the money trail behind a chain of correspondent banks and intermediary payment instructions.

The mechanics usually follow a recognisable shape:

  1. A payment originates from a party with no direct sanctions exposure, often a legitimate-looking trading company in a third country.
  2. Funds route through two or more correspondent banks, each hop adding a layer of apparent distance from the ultimate sanctioned beneficiary.
  3. Settlement occurs through a merchant account or trade finance instrument whose stated purpose (an invoice for "consulting services" or "logistics support") bears little relation to the underlying goods movement.
  4. The final beneficiary receives funds that, on the surface, trace back only to the third-country intermediary, not the sanctioned originator.

Payment narratives are where careful analysts find the cracks. Vague descriptions ("services rendered", "settlement of account") on high-value transfers, invoice amounts that do not match typical pricing for the stated goods, and correspondent banking routes through jurisdictions with no obvious trade relationship to either party are all worth flagging automatically rather than relying on manual review to catch them.

Controls that work here rest on two pillars. Enhanced correspondent due diligence means actually reviewing a correspondent's own sanctions exposure and jurisdictional risk profile, not just confirming it holds a licence. Payment analytics that flag statistically unusual routing, a payment that takes an oddly long path for no clear commercial reason, catch layering schemes that narrative review alone would miss. The operational complexity of global trade is precisely what makes this typology hard to police manually, and why automated payment pattern analysis is becoming a baseline expectation rather than a nice-to-have.

Red flags checklist: what should trigger immediate escalation?

Turning typology knowledge into daily triage means having a prioritised list of signals, and knowing which ones justify pulling a case out of the standard queue immediately.

Corporate and ownership red flags:

  • Ownership transfer within 90 days of a sanctions designation or list update.
  • Nominee director with no apparent business background relevant to the company's stated activity.
  • Layered corporate structures spanning three or more jurisdictions with no clear commercial rationale.

Transactional markers:

  • Below-market or above-market pricing with no documented justification.
  • Payments to family members or associates of a designated person.
  • Structuring beneath reporting thresholds across multiple related accounts.

Maritime and trade markers:

  • AIS gaps coinciding with known transfer points or sanctioned waters.
  • Ship-to-ship transfers logged with no commercial explanation.
  • Bills of lading describing cargo inconsistent with the buyer's known trade.
Signal categoryEscalate immediately whenRoute to standard review when
Corporate ownershipOwnership change within 90 days of designation, plus nominee with no relevant backgroundOwnership change with clear, documented commercial rationale
TransactionalTwo or more red flags co-occur (e.g. below-market price plus family relationship)Single anomaly with plausible explanation on file
Maritime/tradeAIS gap near a known transfer zoneShort AIS gap with logged port call confirming location

Triage scoring should weight co-occurrence heavily. A single red flag in isolation, an unusual payment narrative on its own, rarely justifies pulling resources from a full investigative team. Two or three overlapping signals, a below-market transfer to a relative of a recently designated individual, routed through a jurisdiction with weak beneficial ownership disclosure, should escalate automatically and without debate.

How AI and analytics are changing sanctions evasion detection

Operationalising everything above requires infrastructure that goes well beyond a static sanctions list feed. Four capability areas do most of the heavy lifting.

Four AI capabilities for sanctions detection

Screening and name-matching need to move past exact-match logic. Phonetic matching, transliteration handling for non-Latin scripts, and fuzzy logic for common evasion tactics (adding a middle initial, transposing a family name) catch far more genuine hits than legacy screening engines tuned only for precision. BOI resolution flows should pull from corporate registries, sanctions lists, and PEP data simultaneously, rather than checking each in sequence, because proxy relationships often only become visible when those datasets are cross-referenced.

Graph and network analytics are arguably the single highest-leverage investment a compliance team can make against intermediary-based evasion. Mapping shared directors, addresses, auditors, and payment counterparties across a customer base surfaces clusters that a case-by-case review would never connect. A network graph showing five "unrelated" companies sharing one registered agent and two directors is a pattern no human analyst reviewing files sequentially would likely spot unassisted.

Network graph revealing linked corporate entities

AI genuinely earns its place in two specific use cases here, rather than as a blanket upgrade. Anomaly detection models, trained on transaction and behavioural data, flag deviations from an entity's own historical pattern far faster than static rule thresholds. Entity resolution, matching fragmented, inconsistently formatted records across systems into a single confirmed identity, is exactly the kind of pattern-matching task machine learning handles better than rule-based logic. How AI compares to traditional screening methods is worth understanding in detail before committing budget, because the gains are real but not universal across every control function.

Pro Tip: Any AI model deployed for sanctions detection needs documented governance from day one, model logic that can be explained to a regulator, a testing regime that checks for both false positives and missed hits, and a clear escalation path when the model flags something outside its training distribution. Skipping this step is the single most common reason promising pilots stall at the procurement stage.

Cybersecurity and AI increasingly intersect in this space too, since the same network analytics used to spot sanctioned proxy structures often draw on techniques originally built for fraud and cyber threat detection.

Reporting, cooperation and using public advisories effectively

A SAR or STR that simply flags "suspicious transaction, amount £X" gives investigators almost nothing to work with. The value of a report scales directly with the investigative narrative attached to it.

Strong reports include the ownership chain as understood at filing time, the specific red flags triggered (and which ones co-occurred), any network connections identified through registry or transaction analysis, and a clear timeline showing how the suspicious pattern developed relative to any relevant designation date.

Public sanctions lists and advisories should function as active intelligence inputs, not passive screening databases. FATF's own recommendation is that firms treat advisories like the NCA's red alerts as living documents to be re-checked against existing customer portfolios whenever a new one is published, not just applied to new onboarding.

  • Cross-reference newly published typology indicators against your existing book of business quarterly at minimum.
  • Treat OFAC, EU, and UK advisories as a combined set, since evasion networks routinely operate across all three jurisdictions simultaneously.
  • Build a standing process for feeding confirmed typology matches back into monitoring rule logic, not just case files.

Public-private information sharing closes the exact gap that FATF identifies as the biggest structural weakness in current detection: jurisdictional blind spots that let a network switch nodes faster than any single institution can track. A bank in one country flagging a nominee structure and sharing that intelligence, formally or through recognised information-sharing partnerships, gives every other institution touching that same network a head start it would not otherwise have.

What sanctions evasion schemes have been publicly documented?

Three de-identified patterns, drawn from publicly reported enforcement and advisory material, illustrate how these typologies actually combine in practice.

  1. Intermediary and nominee structures around designation. A company facing imminent sanctions designation transferred majority ownership to a family member's name roughly three weeks before the listing took effect. The transferred entity retained the same registered address, the same operational staff, and, according to later investigation, the same signing authority in practice despite the paper transfer. The pattern matches almost exactly the red flags OFAC's advisory sets out for continued involvement by a blocked person, and it is precisely the kind of ownership-timing anomaly a standing 90-day monitoring rule would catch.

  2. Maritime shadow fleet with falsified documentation. A tanker disabled its AIS transponder for a multi-day stretch coinciding with a known ship-to-ship transfer zone, then resumed broadcasting under a different declared destination port. Accompanying bills of lading described a cargo type inconsistent with the vessel's known trading history. Reconstructing the actual route required combining AIS gap data with satellite confirmation, exactly the layered detection approach S&P Global's shadow fleet reporting recommends.

  3. Crypto on-ramp and off-ramp exploitation. Funds moved through a no‑KYC exchange, passed through a mixing service, then re-entered regulated finance through a smaller VASP with looser verification standards than major exchanges. The pattern only became visible once blockchain analytics traced wallet clustering across all three hops, illustrating why single-point crypto screening consistently misses networked evasion of this kind.

How AI-enabled vendor selection strengthens sanctions compliance

Buying the right technology to operationalise these typologies is its own discipline, and it is where many compliance teams lose momentum. A well-scoped RFP should test vendors specifically on entity resolution accuracy across fragmented and multilingual data, model explainability sufficient to satisfy a regulator's questions, data lineage showing exactly how a match or score was generated, and integration points with existing case management and transaction monitoring systems.

Pilot success should be measured against concrete, pre-agreed metrics rather than vendor demo enthusiasm:

  • Time-to-triage for a flagged case, from alert generation to analyst decision.
  • False-positive rate reduction against the existing baseline, measured on the same historical dataset.
  • Coverage improvement, how many previously undetected network connections the new tool surfaces on known historical cases.

Roll-out governance needs cross-functional sign-off before go-live, not after. Legal needs to confirm the model's decision logic is defensible under relevant data protection and non-discrimination rules. IT needs to confirm data pipelines meet security and retention requirements. Data privacy teams need to sign off on any cross-border data transfer implications, particularly for firms operating across multiple European jurisdictions with differing supervisory expectations. Change management matters just as much as the technology itself: analysts trained on a new entity-resolution tool without a clear escalation workflow tend to revert to old habits within weeks.

What sanctions evasion looks like in real estate and financial services

Maritime and trade get most of the enforcement attention, but sanctioned interests move through property and financial services just as readily, often with weaker controls to catch them.

Real estate remains attractive precisely because property purchases in many European jurisdictions historically required limited beneficial ownership disclosure. A sanctioned individual's associate purchases residential or commercial property through a shell company, sometimes using an all-cash structure specifically to avoid the additional scrutiny mortgage lending would trigger. Rental income or resale proceeds then provide a laundering channel that looks, on paper, like ordinary property investment. The gradual tightening of beneficial ownership registers across the EU and UK has closed some of this gap, but enforcement consistency between jurisdictions still varies enough to create arbitrage opportunities for anyone structuring around it.

Financial services face a subtler version of the same problem: correspondent banking relationships and wealth management structures that were built for legitimate cross-border clients get repurposed to hold or move sanctioned assets. Private banking accounts opened years before a designation, with no subsequent activity change, can quietly become a parking spot for sanctioned wealth simply because no one revisited the account after the original onboarding review. Insurance products, particularly life insurance policies with high cash surrender values, have also been flagged in advisory material as an underused laundering channel precisely because insurers' sanctions screening has historically been less mature than banks'.

The common thread across both sectors is the same one running through this entire article: static, point-in-time due diligence misses evasion that only becomes visible through ongoing behavioural monitoring.

Why typology intelligence needs continuous investment, not a one-off project

Adversaries adapt faster than most compliance programmes update their controls, and that asymmetry is the real strategic risk here, not any single typology. A monitoring rule built around 2024's favourite evasion tactic is already partly obsolete by the time it reaches production, because the network on the other side has already noticed which patterns get caught and adjusted.

Board-level attention should go toward funding continuous typology refresh, not a one-time detection system purchase. The quickest wins are usually cheap: a standing 90-day ownership-change query, a shared intelligence relationship with peer institutions, a quarterly re-screen against newly published advisories. None of these need a large technology budget to start.

The realistic roadmap runs from manual red-flag checklists, to network analytics that surface hidden connections, to AI-assisted anomaly detection with proper governance wrapped around it. Skipping straight to the third stage without the first two in place rarely works. Detection maturity is built in layers, and each layer needs to actually function before the next one adds value.

— Aneta

Get practical support choosing the right compliance technology

Choosing screening, entity resolution, or monitoring technology from a crowded vendor market is its own project, and most compliance teams run it alongside a full day job with no dedicated procurement resource. Specialist consultants work alongside compliance and risk teams to scope AI pilots, structure RFPs against key criteria such as explainability, data lineage, and entity resolution accuracy, and manage the vendor evaluation cycle end to end, so the decision rests on tested performance rather than a polished sales demo.

Aithea

That support translates into measurable operational gains: faster time-to-triage once a properly scoped tool is live, and a lower false-positive rate against your existing baseline once monitoring rules are tuned to real typology patterns rather than generic thresholds. Aithea's AI-powered compliance and risk consulting covers exactly this ground, from initial vendor shortlisting through pilot governance.

If your team is weighing whether existing screening infrastructure is still fit for the typologies covered here, get in touch to scope a pilot or an RFP review before your next procurement cycle closes.

Where to verify these typologies and advisories

This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.

Sources

FAQ

What are the common sanctions evasion typologies?

The four dominant families, per FATF's 2025 typology work, are enlisting intermediaries and front companies, obscuring beneficial ownership through sham transactions, exploiting virtual assets and no‑KYC crypto services, and abusing maritime and trade sectors through shadow fleet tactics and TBML.

What are the AML typologies most relevant to sanctions cases?

AML typologies overlap heavily with sanctions evasion once money needs laundering after evasion succeeds, structuring below reporting thresholds, layering payments through correspondent banks, and trade-based money laundering using misdeclared cargo or abnormal invoice pricing.

What are the five categories of sanctions?

Sanctions regimes typically fall into five broad categories: comprehensive country sanctions, targeted or "smart" sanctions against named individuals and entities, sectoral sanctions restricting specific industries, arms embargoes, and diplomatic sanctions; exact categorisation varies by issuing authority (UN, EU, OFAC, UK).

What are the different types of TBML typologies?

Trade-based money laundering typologies include over-invoicing and under-invoicing of goods, multiple invoicing for the same shipment, misrepresenting the quality or quantity of goods, and phantom shipments where documents exist for goods that never actually moved.

How can compliance teams identify sanctions evasion early?

Early identification relies on combining registry checks, network analytics that map shared directors and addresses, and behavioural monitoring for red flags like ownership changes near a designation date, rather than relying on static name-matching against sanctions lists alone.