Adversarial-Cost Screening
A Validation Framework for Export Control, Sanctions, and Supply-Chain Counterparty Programs
- Type
- Working paper — a validation framework for counterparty screening in export control, sanctions, and defense supply-chain compliance. Preliminary draft; comments welcome.
- Governing judgment
- Screening programs validated only by process metrics cannot estimate their own failure rate. Three structural defects — endogenous label generation, unmeasured entity resolution, and dependence on adversary-controlled attributes — are corrected by an exogenous sampling requirement, an entity-resolution maturity measure, an attribute-cost tiering scheme, and an evaluation battery that produces defensible estimates of screening effectiveness.
- Keywords
- False Claims Act; Civil Cyber-Fraud Initiative; export controls; economic sanctions; counterparty screening; third-party risk; NIST SP 800-171; CMMC; program evaluation; strategic classification; compliance effectiveness; materiality; scienter.
- JEL classification
- K23, K42, D82, H56.
- Companion assessment
- Cleared Does Not Mean Examined (SB-2026-03), the practitioner version of this framework.
- Revision history
- Version 1.7, 13 August 2026; supersedes versions 1.0–1.6. On SSRN as abstract 7252300.
Counterparty screening programs in export control, sanctions, and defense supply-chain compliance are validated almost exclusively by process metrics — alert volume, clearance rate, list-coverage currency, screening latency. None of these measure whether the program detects the conduct it exists to detect. This paper identifies three structural defects common to these programs and specifies a validation framework that corrects them.
The defects are: (1) endogenous label generation, in which outcome data is observable only for counterparties the program already flagged, making measured performance a function of the screening policy rather than of the threat; (2) entity resolution as the unmeasured binding constraint, in which screening accuracy is capped by the ability to recognize that nominally distinct counterparties are one operation, a capability no program reports on; and (3) adversary-controlled attribute dependence, in which screening weight concentrates on attributes the screened party can change at negligible cost while structurally costly attributes go unused.
The framework specifies an exogenous sampling requirement, an entity-resolution maturity measure, an attribute-cost tiering scheme, and an evaluation battery that produces defensible estimates of screening effectiveness. It applies the result to reasonable-care determinations under EAR Part 732, to sanctions-compliance testing under OFAC’s Framework, and to scienter and materiality analysis under the False Claims Act, including cybersecurity certification under the Civil Cyber-Fraud Initiative, where recent settlements supply worked illustrations of each failure mode.
A screening program learns only from the counterparties it flags. The ones it clears teach it nothing, so its performance numbers describe its own past decisions, not the threat. A random-sample audit of cleared counterparties is the one design change that yields an unbiased estimate of what the program missed.
Read the paper
What this paper does not establish
The framework estimates screening effectiveness against conduct that enhanced review can detect; it does not bound exposure to conduct that no available review method would catch.
The legal applications describe how the framework bears on reasonable-care, materiality, and scienter analysis under current authority. Named enforcement matters are settlements, cited only for what their public records establish.
Nothing in this paper is legal advice or a substitute for counsel. It is a working paper: comments are welcome, and conclusions may change in later versions.
Suggested citation
George, Collin B. Adversarial-Cost Screening: A Validation Framework for Export Control, Sanctions, and Supply-Chain Counterparty Programs. Working paper SCREEN-01, version 1.7. Sanctir LLC, 13 August 2026. SSRN 7252300.