Skip to content
  • There are no suggestions because the search field is empty.

Configure the Confidence Score Threshold

How Industry, Geography, and Risk Appetite Shape Your Optimal Score Threshold Setting

One of the most common questions we receive at sanctions.io is:

"What threshold should I use?"

While our default recommendation is 0.88, the right answer depends significantly on the environment your organization operates in, specifically, your industry, geographic exposure, and risk appetite.

This guide is designed to help compliance teams make an informed, defensible decision about their min_score configuration. It covers the key factors that influence threshold selection, provides industry-specific guidance, and explains the trade-offs involved.


Understanding the Confidence Score

Every screening result in sanctions.io includes a Confidence Score between 0 and 1, where 1.0 represents a 100% exact match. This score is not a simple name-match percentage; it is a weighted calculation across some parameters included in your search request (name, date of birth, and country).

The min_score parameter acts as a filter: any result below your chosen threshold is excluded from the output. This means:

  • A lower threshold returns more results, including weaker matches → useful when cast-wide compliance coverage is required.

  • A higher threshold returns fewer, higher-confidence results -> useful when reducing false positives, and reviewer workload is the priority.

Important: Setting min_score to 1.0 is not recommended. A score of 1.0 would only return character-for-character exact matches, missing true positives caused by transliteration, spelling variants, or data entry inconsistencies; all of which are common in real-world sanctions lists. This creates significant compliance risk.


The Four Factors That Should Drive Your Threshold

There is no one-size-fits-all configuration. The optimal threshold for your organization depends on the interplay of four key factors:

1. Risk Appetite

How much risk is your organization prepared to accept? Highly regulated industries or those with strict internal compliance policies will typically set a lower threshold, accepting more false positives in exchange for maximum coverage. Organizations with lower regulatory exposure may prioritize operational efficiency with a higher threshold.

2. Data Quality

The completeness and accuracy of your customer and counterparty data directly affect match quality. If you are only screening by name without additional identifiers like date of birth or country, the confidence score is based on less information, and more false positives are likely at lower thresholds. Enriching your data allows you to maintain coverage at a higher threshold.

3. Exposure to High-Risk Elements

The extent to which your customer base, transaction flow, or supply chain involves high-risk jurisdictions, politically exposed persons (PEPs), or sectors known for sanctions exposure (e.g., energy, arms, financial services) is a critical driver of threshold configuration.

4. Compliance Resources

How many alerts can your team realistically review? A lower threshold produces more alerts, each of which needs human review. If your compliance team is small or resource-constrained, an overly broad threshold can create a backlog that paradoxically increases compliance risk by slowing down the resolution of true positives.


Industry-Specific Threshold Guidance

The table below provides starting-point recommendations by industry. These are guidelines, not rules; always align your configuration with your organization's specific risk assessment and regulatory obligations.

 
 
 
 
Industry
Risk Level
Suggested Threshold
Notes
Banking & Financial Services
HIGH
0.88
Strict regulatory requirements (BSA, AML). Lower threshold justified by high regulatory scrutiny.
Crypto / Virtual Assets
HIGH
0.88
FATF Travel Rule and VASP obligations require broad coverage. High volume of anonymized counterparties.
Trade Finance & Logistics
HIGH
0.88
Dual-use goods risk. Must screen vessels, companies, and UBOs. Geographic exposure is critical.
Insurance
MEDIUM-HIGH
0.88 – 0.90
Varies by line of business. Marine and political risk lines require broader coverage.
Legal & Professional Services
MEDIUM-HIGH
0.88 – 0.90
AML obligations apply in many jurisdictions. PEP screening especially important for client onboarding.
Real Estate
MEDIUM-HIGH
0.88 – 0.90
High risk of use in money laundering. UBO screening critical. Geographic exposure matters.
Technology / SaaS
MEDIUM
0.88 – 0.92
Export control compliance (EAR/ITAR) is key. Screen against the BIS lists where applicable.
Healthcare & Pharma
MEDIUM
0.88 – 0.92
Limited direct sanctions exposure unless operating in restricted jurisdictions.
E-commerce / Retail
LOW-MEDIUM
0.88 – 0.95
Lower inherent risk. A higher threshold is acceptable if data quality is good and volume is high.
NGOs & Non-Profits
VARIES
0.88
High risk of diversion to sanctioned parties. OFAC guidance recommends robust screening for humanitarian orgs.
 

The Threshold Trade-Off: False Positives vs. False Negatives

Every threshold decision involves balancing two types of error:

False Positive

False Negative

A match is returned that is NOT a true sanctions hit.

Result: Unnecessary manual review, operational friction.

Caused by: Threshold too low or insufficient data enrichment.

A true sanctions hit is NOT returned because it fell below the threshold.

Result: Compliance violation, regulatory risk, reputational damage.

Caused by: Threshold too high or missing data.

False negatives are generally far more serious than false positives from a compliance and regulatory standpoint. When in doubt, err on the side of broader coverage and invest in better data quality and reviewer capacity to manage the resulting alert volume.


A Practical Approach to Setting Your Threshold

Rather than picking a single number and never revisiting it, we recommend the following iterative approach:

  1. Start at 0.88. This is our recommended default and a solid starting point for most industries.
  2. Enrich your data first. Before adjusting the threshold, add the date of birth, country, and entity type to your screening requests. This often resolves false positive issues without sacrificing coverage.
  3. Review a sample of results. After running initial screens, review a representative sample of both matches and near-misses. This will tell you whether your threshold is too broad or too narrow for your specific data.
  4. Adjust and document. Any change to your threshold should be documented with a rationale tied to your risk assessment. Regulators expect you to be able to justify your configuration choices.
  5. Review periodically. Your risk environment changes. Regulatory requirements evolve, your customer base shifts, and your data quality improves. Revisit your threshold configuration at least annually or when significant changes occur.

We're here to help!

If you have any questions or need more help, please contact our support team anytime!