Working Paper · SCREEN-01

Adversarial-Cost Screening

A Validation Framework for Export Control, Sanctions, and Supply-Chain Counterparty Programs

Published
Status Working paper
Supersedes Versions 1.0–1.6
Version 1.7
Author Collin B. George, CISSP
License CC BY 4.0
Unclassified // Open Source
Paper record
Type
Working paper — a validation framework for counterparty screening in export control, sanctions, and defense supply-chain compliance. Preliminary draft; comments welcome.
Governing judgment
Screening programs validated only by process metrics cannot estimate their own failure rate. Three structural defects — endogenous label generation, unmeasured entity resolution, and dependence on adversary-controlled attributes — are corrected by an exogenous sampling requirement, an entity-resolution maturity measure, an attribute-cost tiering scheme, and an evaluation battery that produces defensible estimates of screening effectiveness.
Keywords
False Claims Act; Civil Cyber-Fraud Initiative; export controls; economic sanctions; counterparty screening; third-party risk; NIST SP 800-171; CMMC; program evaluation; strategic classification; compliance effectiveness; materiality; scienter.
JEL classification
K23, K42, D82, H56.
Companion assessment
Cleared Does Not Mean Examined (SB-2026-03), the practitioner version of this framework.
Revision history
Version 1.7, 13 August 2026; supersedes versions 1.0–1.6. On SSRN as abstract 7252300.
Abstract

Counterparty screening programs in export control, sanctions, and defense supply-chain compliance are validated almost exclusively by process metrics — alert volume, clearance rate, list-coverage currency, screening latency. None of these measure whether the program detects the conduct it exists to detect. This paper identifies three structural defects common to these programs and specifies a validation framework that corrects them.

The defects are: (1) endogenous label generation, in which outcome data is observable only for counterparties the program already flagged, making measured performance a function of the screening policy rather than of the threat; (2) entity resolution as the unmeasured binding constraint, in which screening accuracy is capped by the ability to recognize that nominally distinct counterparties are one operation, a capability no program reports on; and (3) adversary-controlled attribute dependence, in which screening weight concentrates on attributes the screened party can change at negligible cost while structurally costly attributes go unused.

The framework specifies an exogenous sampling requirement, an entity-resolution maturity measure, an attribute-cost tiering scheme, and an evaluation battery that produces defensible estimates of screening effectiveness. It applies the result to reasonable-care determinations under EAR Part 732, to sanctions-compliance testing under OFAC’s Framework, and to scienter and materiality analysis under the False Claims Act, including cybersecurity certification under the Civil Cyber-Fraud Initiative, where recent settlements supply worked illustrations of each failure mode.

If you read nothing else

A screening program learns only from the counterparties it flags. The ones it clears teach it nothing, so its performance numbers describe its own past decisions, not the threat. A random-sample audit of cleared counterparties is the one design change that yields an unbiased estimate of what the program missed.


Full text

Read the paper

Adversarial-Cost Screening: A Validation Framework for Export Control, Sanctions, and Supply-Chain Counterparty Programs

The full working paper, with the statistical treatment, the entity-resolution maturity measure, the attribute-cost tiering scheme, and the legal applications. The practitioner version is SB-2026-03. View · Download · SSRN
SCREEN-01 · 15 pp

Limitations

What this paper does not establish

The framework estimates screening effectiveness against conduct that enhanced review can detect; it does not bound exposure to conduct that no available review method would catch.

The legal applications describe how the framework bears on reasonable-care, materiality, and scienter analysis under current authority. Named enforcement matters are settlements, cited only for what their public records establish.

Nothing in this paper is legal advice or a substitute for counsel. It is a working paper: comments are welcome, and conclusions may change in later versions.


Citation

Suggested citation

Suggested citation

George, Collin B. Adversarial-Cost Screening: A Validation Framework for Export Control, Sanctions, and Supply-Chain Counterparty Programs. Working paper SCREEN-01, version 1.7. Sanctir LLC, 13 August 2026. SSRN 7252300.


Author

About the author

Collin B. George, CISSP, is the principal of Sanctir LLC, an independent research and advisory practice working on national security, export controls, sanctions, and defense industrial base risk.

Sanctir is a solo practice. This paper was prepared in the author’s personal capacity, is not official U.S. government analysis, and is not affiliated with any government agency, academic institution, or defense contractor.

ORCID 0009-0007-8162-6839 · SSRN author page · Full background · Contact