False Positive

False Positive

False Positive

A false positive is an alert or match that a screening or detection system flags as genuine risk, but which turns out, on review, not to be. In formal statistical terms, it’s a Type I error: incorrectly classifying a true negative as positive. The concept applies identically whether it’s a medical test, a spam filter, or a sanctions screening hit, and understanding the underlying statistical framework explains why false positives can never be fully eliminated without creating a different, more dangerous problem.

Key takeaways

  • A false positive is an individual alert that turns out, on review, not to represent genuine risk, distinct from the aggregate false positive rate.
  • Formally, a false positive is a Type I error, the exact same statistical concept used across medicine, spam filtering, and machine learning, not something unique to compliance.
  • Precision (true positives divided by all flagged positives) falls directly as false positives rise; loosening a threshold to catch more risk mechanically increases false positives.
  • Common causes in screening include name collisions, transliteration variants, incomplete identifying information, and deliberately loose thresholds.
  • Most screening systems accept an elevated false positive rate deliberately, since a missed genuine match is far costlier than an unnecessary review.
  • Resolving a false positive properly requires documenting what distinguished the flagged person, what source confirmed it, and who decided, not just clearing the alert.
  • Chronically high false positive volume causes alert fatigue, which can degrade review quality for genuine risk hidden inside the noise.

What a false positive actually is

A false positive is an individual alert or match that a screening or detection system flags as genuine risk, but which turns out, once reviewed, not to be. In sanctions and PEP screening terms, it’s typically a name match that a human analyst confirms doesn’t actually relate to the sanctioned or politically exposed individual it superficially resembles. This is distinct from the false positive rate, which is the aggregate percentage of all alerts a system generates that turn out this way; a false positive is the individual event, the rate is the summary statistic across many of them.

The formal statistical framework: Type I error

A false positive has a precise, formal definition borrowed directly from statistics and machine learning classification theory, not something specific to compliance. Every binary classification decision, is this a match or not, produces one of four outcomes, organised into what’s called a confusion matrix: a true positive (correctly flagged as a match), a true negative (correctly cleared), a false negative (a real match the system missed), and a false positive, a Type I error, where the system incorrectly flags something as a match when it genuinely isn’t one.

This exact framework applies identically across wildly different domains: a medical test incorrectly indicating a healthy patient has a disease, a spam filter incorrectly flagging a legitimate email, and a sanctions screening system incorrectly flagging an innocent customer are all, formally, the same category of error.

Precision, and why false positives are a direct trade-off

Precision measures the proportion of positive alerts that are actually correct: true positives divided by the sum of true positives and false positives. Every false positive directly reduces precision, and there’s a structural trade-off that no threshold setting escapes: loosening a matching threshold to catch more genuine risk, improving recall, mechanically increases the number of false positives generated, reducing precision. Tightening the threshold to cut false positives risks missing genuine matches instead, the opposite error, a false negative. No single threshold optimises both simultaneously; every choice is a deliberate trade-off along that same axis.

What specifically causes false positives in sanctions and PEP screening

In a screening context specifically, false positives cluster around a recognisable set of causes: common names generating matches across a global reference dataset far larger than the population actually being searched for, transliteration variants of names from non-Latin scripts producing spelling-based near-matches, incomplete identifying information, missing date of birth or nationality, that leaves a system unable to distinguish between two different people sharing a name, and deliberately loose matching thresholds set to minimise the risk of a missed genuine hit at the cost of generating more noise.

Worth knowing. A screening system tuned to produce zero false positives would mechanically produce more false negatives instead, missing genuine matches by being too conservative about flagging anything. That’s precisely why most systems deliberately accept a high false positive rate rather than optimising to minimise it directly.

Why false positives can’t simply be eliminated

A screening system tuned to produce zero false positives would, mechanically, also produce more false negatives, missing genuine matches specifically because it’s being conservative about flagging anything at all. Given that a missed sanctions match carries a far more severe consequence than an unnecessary manual review, most screening systems are deliberately tuned to accept a meaningfully elevated false positive rate as the price of minimising missed genuine risk, rather than optimising for a low false positive count as the primary goal.

How an individual false positive actually gets resolved

Resolving a false positive requires a documented decision, not just a dismissed alert. A sound disposition records what specifically distinguished the flagged individual from the listed one, name spelling, date of birth, nationality, or other identifying detail, which source was checked to confirm that distinction, and who made the call. That documentation matters as much as the decision itself, since an examiner reviewing a cleared alert months later needs to see the reasoning, not just a status marked “cleared.”

The real cost of a high false positive volume

Beyond the direct analyst time each false positive consumes, a chronically high false positive volume creates a second-order risk: alert fatigue, where reviewers working through large volumes of low-value alerts become less attentive to any individual one, genuine risk included. A screening system generating an unmanageable false positive volume doesn’t just waste resources; it can actively degrade the quality of review applied to every alert, including the rare genuine one buried inside the noise.

What actually reduces false positives without increasing missed risk

The durable fixes work on data quality and context rather than simply loosening thresholds: improving identifying information collected at onboarding so matches can be distinguished more precisely, layering multiple matching algorithms so a single method’s blind spot doesn’t dominate results, and adding customer context, industry, transaction history, expected activity, that helps distinguish a genuine match from a coincidental name collision, rather than relying on name comparison alone.

Frequently asked questions

What is a false positive?

A false positive is an individual alert or match that a screening system flags as genuine risk, but which turns out, on review, not to be. It’s distinct from the false positive rate, which is the aggregate percentage across many alerts.

What is the difference between a false positive and a Type I error?

They’re the same thing. False positive is the applied term used in screening and detection contexts; Type I error is the formal statistical term for the identical concept: incorrectly classifying something as positive when it’s actually negative.

What is the difference between a false positive and a false negative?

A false positive incorrectly flags something as a match when it isn’t. A false negative misses a genuine match entirely, failing to flag something that actually is one. They represent opposite kinds of classification error.

Why can’t false positives simply be eliminated?

Tightening a matching threshold to reduce false positives increases the risk of false negatives, missed genuine matches, instead. Since a missed sanctions match is far more costly than an unnecessary review, most systems accept an elevated false positive rate deliberately.

What specifically causes false positives in sanctions screening?

Common names generating matches across large reference datasets, transliteration variants from non-Latin scripts, incomplete identifying information, and deliberately loose matching thresholds set to avoid missing genuine hits.

What is precision, and how do false positives affect it?

Precision is the proportion of flagged matches that are actually correct, calculated as true positives divided by true positives plus false positives. Every false positive directly reduces precision.

What does resolving a false positive properly require?

A documented decision recording what specifically distinguished the flagged individual from the listed one, what source confirmed that distinction, and who made the call, not just a dismissed alert.

What is alert fatigue?

Alert fatigue is the effect where reviewers working through a high volume of low-value false positives become less attentive to any individual alert, genuine risk included, degrading review quality across the board.

Read more: our ultimate guides, whitepapers and templates

Related guides and resources to help you act on what you just read.

Last reviewed July 19, 2026 · 9 min read · Written for compliance and risk professionals · By the WhoWiki editorial team

Key takeaway: A false positive is an alert or match that a screening or detection system flags as genuine risk, but which turns out, on review, not to be. In formal statistical terms, it’s a Type I error: incorrectly classifying a true negative as positive. The concept applies identically whether it’s a medical test, a spam filter, or a sanctions screening hit, and understanding the underlying statistical framework explains why false positives can never be fully eliminated without creating a different, more dangerous problem.

Learn & stay current

A compliance reference that keeps up with the regulators

Plain-English explainers, country rules, and data you can cite, updated as the landscape moves.

Comparing tools before you commit?

See how WhoWiki lines up against the platforms you already know, and which free tools fit which job.

See how current your screening could be

Book a walkthrough with our team, or start with the tools today. No account needed to run your first check.