Research · Architecture reference

What is fail-closed trade compliance?

A fail-closed trade-compliance system does not treat missing, unavailable, or insufficiently verified compliance data as evidence that a transaction is clear. Instead, it holds, escalates, or prevents the decision from proceeding until the required evidence is available.

Written and published by Veredis Decision Systems.

Last updated: · Version 1.1

An architectural reference, not legal advice or a statement of regulatory approval.

Why the distinction matters

In sanctions and export-control screening, “no result” is not the same as “confirmed clear.”

A completed search with no match is evidence about the sources, identities and search scope actually checked. A failed lookup, unavailable source or incomplete identity check cannot support that same conclusion. Neither result, on its own, establishes that a whole transaction is lawful.

Fail-closed describes how a system handles that uncertainty. It preserves an unresolved state rather than silently turning a technical failure or evidence gap into clearance. It does not mean that an unavailable source proves a sanctions match or a legal prohibition.

Fail-open vs fail-closed

Illustrative system behaviour when required evidence is missing
ConditionFail-open handlingFail-closed handling
Required sanctions source unavailableMay let the decision proceed without the check.Keeps the check unresolved; holds or escalates the decision.
Counterparty identity insufficiently verifiedMay interpret no returned match as clearance.Requests enough evidence to resolve the identity before clearance.
Decision recordMay leave the missing check implicit.Records the missing evidence, reason and review state explicitly.

These are architectural choices, not universal descriptions of products or statutory decision labels. Applicable obligations depend on the transaction and jurisdiction.

A practical example

A screening service times out while checking the buyer on an invoice. The application receives no usable response. A fail-open implementation might convert that empty response into “no match” and allow the decision to continue.

A fail-closed implementation records “source unavailable,” keeps clearance pending and routes the case for retry or authorised review. A later successful search is recorded separately; it does not rewrite the failed attempt as a completed check.

Veredis’s design principle

Missing evidence must never be represented as evidence of clearance.

This is a design and governance principle of Veredis Decision Systems. Missing evidence must remain distinguishable from a supported no-match result.

The principle calls for explicit source availability, sufficient identity evidence and a traceable decision record. It is not a claim that regulators prescribe Veredis’s architecture or endorse its software.

Related context: how Veredis combines evidence into a compliance decision.

Authoritative references and their scope

The following official sources inform the compliance context. The architectural definition and comparison above are Veredis’s analysis.

  • OFAC: A Framework for OFAC Compliance Commitments (PDF). The internal-controls section describes policies and procedures for identifying and handling potentially prohibited activity, escalation and recordkeeping. It supports the importance of effective controls; it does not prescribe a particular software failure mode.
  • BIS: “Know Your Customer” Guidance and Red Flags, Supplement No. 3 to Part 732. The guidance calls for inquiry when red flags arise, reevaluation after inquiry, and refraining from a transaction or seeking BIS consideration when concerns remain. It also explains that, absent red flags or an express EAR requirement, exporters have no general affirmative duty to investigate beyond customer representations. It does not make every missing data field a prohibition.
  • OFSI: UK financial sanctions general guidance — using the UK Sanctions List. The guidance distinguishes a name match from a target match and explains how identifying information helps resolve the distinction. Where uncertainty remains after consulting the list, it says OFSI can be contacted for assistance. This supports careful identity assessment; it does not prescribe Veredis’s software architecture or make an unavailable lookup evidence of a sanctions match.

Consult the current official sources and qualified advisers for transaction-specific obligations. Veredis is a software publisher, not a regulator or a source of law.