# Methodology: structured identifiers and names in two sanctions snapshots

Version 1.0.0 · 30 September 2026 · SanctionsKit

## Scope and unit

This is a census of two downloaded official XML files, not a sample or a screening benchmark. The unit is a source record: one OFAC `sdnEntry` or one UK `Designation`. A record is not necessarily a unique person, business or ship. Records are not matched or deduplicated across sources, regimes or real-world identities. There is no combined denominator or overall quality score.

| Source | Official file date | Capture time (UTC) | Records |
|---|---|---|---:|
| OFAC SDN, legacy XML | `09/30/2026` (`Publish_Date`) | 30 September 2026, 19:19:59 | 19,452 |
| UK Sanctions List, XML | `29/09/2026` (`DateGenerated`) | 30 September 2026, 19:19:59 | 6,339 |

The full SHA-256 digests, exact download URLs, byte lengths, response status and retrieval timestamps are in [source-manifest.json](source-manifest.json). The file date is publisher metadata, not a claim that every record changed that day. OFAC's legacy XML is the selected format; this study does not measure the enhanced or advanced formats.

The two lists have different populations, regimes, schemas and designation practices. Percentages are descriptive within each source and entity type. Differences are not a league table, evidence of bad data, or evidence that an agency should know a missing fact. No source feed was selected based on the results.

## Field definitions

Whitespace is trimmed and consecutive whitespace collapsed. Empty values and the literal case-insensitive values `na`, `n/a`, `unknown`, `none`, `-`, `not known`, `not available` and `nil` count as absent. All other nonempty values count as present. Presence does not verify the information's truth, currency, uniqueness or usefulness. Free-text remarks and narrative reasons are not mined for identifying facts.

Each metric counts records with at least one qualifying value, divided by all records of that source and applicable entity type. Multiple values do not increase the numerator. Percentages in CSV/JSON are rounded to two decimals. The report uses those same values.

| Metric | OFAC SDN field rule | UK Sanctions List field rule |
|---|---|---|
| Alias present | At least one `akaList/aka` with first or last name; includes a.k.a., f.k.a. and n.k.a. | At least one `Names/Name` whose case-insensitive `NameType` is `Alias`, with a populated `Name1`–`Name6` part |
| Alias quality | The same qualifying alias has category `strong` or `weak` | Qualifying alias has strength `Good quality a.k.a` or `Low quality a.k.a` |
| Primary-name variation | Not measured separately in this format | Qualifying name has `NameType` = `Primary Name Variation`, case-insensitively |
| Alias or primary-name variation | Not a separate metric | Record has either of the preceding UK name types; union, not sum |
| Address country | `addressList/address/country` | `Addresses/Address/AddressCountry` |
| DOB present, individuals only | `dateOfBirthList/dateOfBirthItem/dateOfBirth` | `IndividualDetails/Individual/DOBs/DOB` |
| Full calendar DOB value, individuals only | Entire value matches day + English abbreviated month + four-digit year and is a valid calendar date | Entire value matches `dd/mm/yyyy` with numeric day/month/year and is a valid calendar date |
| Passport number, individuals only | Nonempty `idNumber` in an `idList/id` whose `idType` contains `passport`, case-insensitively | `IndividualDetails/Individual/PassportDetails/Passport/PassportNumber` |
| Source national-ID field, individuals only | `idType` is exactly `National ID No.` with a populated `idNumber` | `IndividualDetails/Individual/NationalIdentifierDetails/NationalIdentifier/NationalIdentifierNumber` |
| Nationality, individuals only | `nationalityList/nationality/country`; separate citizenship fields are not combined | `IndividualDetails/Individual/Nationalities/Nationality` |
| Non-Latin name | Not measured | `NonLatinNames/NonLatinName/NameNonLatinScript` |
| Business registration number, entities only | Not measured | `EntityDetails/Entity/BusinessRegistrationNumbers/BusinessRegistrationNumber` |
| IMO number, ships only | Not measured | `ShipDetails/Ship/IMONumbers/IMONumber` |

The OFAC `idList` also contains attributes such as gender, website and sanctions information. Its existence does not establish that a record has a passport or national identifier. The selected national-ID field metric is deliberately narrow and does not count all possible document types or country-specific identifiers. It is not comparable as an exhaustive identifier-coverage measure across sources.

DOB categories partition all individual records: (1) at least one valid full calendar value, (2) some DOB value but none full, or (3) no qualifying structured DOB value. Years, month/year values, ranges, `circa` expressions, placeholders for unknown date components and invalid calendar dates do not qualify as full. A record with both a year-only and full value is in category 1. A full-form value may still be qualified elsewhere in the record; this study does not infer certainty. Multiple-DOB counts count value elements, without semantic deduplication. The "neither DOB nor passport" metric is the intersection of absence in those two specified fields only.

UK aliases and primary-name variations are distinct publisher categories. The [FCDO format guide](https://www.gov.uk/guidance/format-guide-for-the-uk-sanctions-list) explains the distinction and allows partially known dates. Case normalization accommodates the capitalization variants in the actual XML. Alias-quality categories can overlap on a record and are not mutually exclusive. An unclassified alias is not assigned a quality. Country presence is an address-field measurement; it does not establish domicile, nationality or geographic risk.

## Reproduction and checks

The standard-library [analysis script](analyze.py) verifies each input against the pinned manifest before calculating. It rejects missing or duplicate source IDs, unknown entity types, unknown UK name types, empty feeds and a mismatch between OFAC's declared and parsed record counts. It checks metric bounds and the DOB partition for every individual record. [Synthetic tests](test_analysis.py) cover date precision, invalid dates, multiple DOBs, placeholders, passport typing, capitalization, empty aliases, duplicate IDs and count mismatches.

Run with Python 3.9 or later:

```sh
python3 -m unittest discover -s public -v
python3 public/analyze.py --ofac private/snapshots/ofac-sdn.xml --uk private/snapshots/uk-sanctions.xml --out reproduced
```

The public package contains no original records. Original official files are retained privately for audit. Official download URLs are mutable: downloading them later may return different data. The hashes allow exact-version verification but do not by themselves supply the historical bytes. Exact reproduction needs the matching snapshots; the script fails if a newer file is substituted. This is a bounded reproducible method with a pinned private evidence archive, not a claim that historical raw data is publicly hosted.

## Sources and reuse

OFAC publishes its [Sanctions List Service](https://ofac.treasury.gov/sanctions-list-service). This study uses official factual list fields and publishes independently computed aggregates, without reproducing records, narratives, logos or seals. The [U.S. Copyright Office](https://www.copyright.gov/title17/92chap1.html) supplies the government-work framework in sections 101 and 105; this is not a blanket licence for third-party material on government websites.

The [UK Sanctions List publication](https://www.gov.uk/government/publications/the-uk-sanctions-list) identifies the official downloads and the site's Open Government Licence terms. Contains public sector information licensed under the [Open Government Licence v3.0](https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/). Personal data, third-party rights and official marks are excluded from that licence; this package publishes aggregate measurements rather than personal records. SanctionsKit independently analyzed the sources; neither government endorses this study.

The UN consolidated source was considered but excluded from direct download and analysis because the [UN website terms](https://www.un.org/en/about-us/terms-of-use) restrict the stated reuse grant and no applicable commercial derivative permission was established. This does not imply that UK or OFAC records with UN-related designations were removed: each included file was analyzed as published by its own authority.

These findings do not measure screening accuracy, false positives, false negatives, legal compliance, list completeness, coverage of unlisted owned entities, or SanctionsKit's production data coverage. They do not establish a trend; only one snapshot per source was measured.
