Over 625,000 Filipinos have the surname Dela Cruz about one in every 162 people in the country. Garcia, Reyes, Santos, and Bautista come next in number. This is no cultural coincidence; it’s the result of a specific historical event, the Claveria Decree of 21 November 1849, when the Spanish colonial government issued a list of surnames and required Filipino families who didn’t already have one to take a surname from it.
While most of the global conversation about “difficult names to screen” in sanctions and AML compliance centers on the transliteration of Arabic, Chinese, and Cyrillic names, none of it accounts for what happens when a name-matching system runs into a country where a significant share of the population shares one of a small number of surnames. When surnames are concentrated at this level, relying on the name alone stops being useful a screening system unable to resolve ambiguity across multiple identity fields will either overwhelm analysts with false positives or, worse, go numb to the point where a real match gets lost in the noise.
Every sanctions screening vendor says it can handle “difficult names.” Look at the material they actually produce whitepapers, blog posts, comparison pages and it’s almost always the same small set of issues: inconsistent Arabic transliteration, reversed surname order in Chinese names, multiple valid Romanizations of Cyrillic names. These are real problems, but they aren’t the Philippines’ problem, or at least not its most particular one. The Philippine case is structural, and it has nothing to do with transliteration and everything to do with an administrative decision made 175 years ago. The name is already in clean, standard, Latin-script form there’s nothing to transliterate. The issue is that a screening system built to ask “does this name appear on the list” returns a technical yes for a very large number of people, continually, for reasons that have nothing to do with real risk.
Where the surname concentration comes from
On 21 November 1849, Governor-General Narciso Claveria y Zaldua issued a decree in response to what Spanish colonial administrators considered disorderly Filipino naming customs: many Filipinos used only a single given name, some changed names across generations, and record-keeping was inconsistent between parishes and provinces. The decree’s solution was the Catálogo alfabético de apellidos, an alphabetical list of Spanish, Chinese, and indigenous surnames sent out to towns across the archipelago. Families without a hereditary surname had to choose one from the list often assigned alphabetically by town, which is part of why certain surnames still cluster in certain regions today.
Religious surnames were especially popular. Recently converted Catholics tended to take names like de los Santos, de la Cruz, del Rosario, and Bautista names tied to religious devotion rather than family descent. Two centuries later, the preference is still visible in the data: Dela Cruz is held by over 625,000 Filipinos, roughly 1 in every 162 residents, making it the country’s most common surname; Garcia, Reyes, and Santos sit at a similarly high concentration.
It’s a genealogical fact, not a data quality issue. When a screening system encounters “Maria Dela Cruz,” it isn’t looking at a messy or ambiguous record it’s looking at a name that hundreds of thousands of real, separate people in the Philippines actually have.
Why this breaks name-only matching
Sanctions and PEP screening compares a customer’s declared identity against watchlists, sanctions lists, and internal risk databases to look for a name match. It rests on an assumption that’s generally valid in most countries: a name match indicates potential risk, even if imperfect, because most names aren’t shared by a large share of the population.
That assumption breaks down against Philippine surname concentration. Any individual anywhere in the world named Cruz, Reyes, Santos, or Garcia would show up against a watchlist, and thousands of watchlist entries contain common surnames of Spanish origin so a system matching on name alone produces a match for a significant share of the Philippine population, regardless of any real link to risk.
The result isn’t one bad day for an analyst; it’s a chronic problem. A large institution onboarding thousands of customers, frequently encountering common Filipino surnames, ends up with one of two outcomes: a flood of false positives if the threshold is tuned to catch every possible match, burying real signals in noise the same way alert fatigue does in transaction monitoring or, if sensitivity is reduced to keep false positives under control, a true match on a common surname is more likely to be waved through as ordinary noise instead of properly investigated.
Neither outcome is a failure of the screening concept. It’s a mismatch between a name-based detection method and a population where names alone carry very little discriminative information.
What actually disambiguates a match
The fix isn’t a smarter name-matching algorithm. Fuzzy matching, phonetic matching, and transliteration-aware logic all help with Arabic, Chinese, and Cyrillic script problems but none of it matters when the real problem is that the name is spelled correctly, romanized correctly, and shared by 600,000 actual people.
The difference between a genuine Dela Cruz match and a false positive lies in everything normally treated as secondary to the name check: date of birth, address, citizenship, business or entity information, assessed together rather than as an afterthought. A watchlist entry for “Juan Dela Cruz, born 1978, based in a particular province” and a customer named “Juan Dela Cruz, born 1995, from a different area” share a name and nothing else. A system that only states whether the name matches has no way to surface that distinction. A system that scores each field separately, and shows the analyst which fields matched and at what confidence, gives them something concrete to act on.
Multi-field matching is good practice everywhere, but in the Philippines it isn’t a nice-to-have. When surnames are this concentrated, an organization that hasn’t built screening around multi-field disambiguation isn’t running a slightly less efficient process it’s running one incapable of telling a real match from background noise at the volume the Filipino surname distribution produces.
Closing the gap
The Watchlist Screening module of Fyscal Arcx compares multiple identity and entity fields at once against a watchlist of around six million entries AMLC’s list, the UN sanctions list, PEP databases, and adverse media. Instead of a simple pass-or-fail, each match returns an explainable score per field, so an analyst looking at a Dela Cruz or Garcia record can see at a glance whether the date of birth and other identifying details actually match the flagged individual, or whether it’s only the name in common.
This matters beyond day-to-day analyst efficiency. If a BSP examiner asks how a screening programme handles false positives from common surnames, “we match on name and citizenship” is a very different answer from “we can show you, field by field, why this match was cleared or escalated.” The first is a statement of policy. The second is a demonstrable, auditable process exactly what an examination looks for.

