# Watchlist Misidentification <iframe width="100%" height="20" scrolling="no" frameborder="no" allow="autoplay; encrypted-media" src="https://w.soundcloud.com/player/?url=https%3A//api.soundcloud.com/tracks/soundcloud%253Atracks%253A2406525546&color=%23ff5500&inverse=false&auto_play=false&show_user=true"></iframe><div style="font-size: 10px; color: #cccccc;line-break: anywhere;word-break: normal;overflow: hidden;white-space: nowrap;text-overflow: ellipsis; font-family: Interstate,Lucida Grande,Lucida Sans Unicode,Lucida Sans,Garuda,Verdana,Tahoma,sans-serif;font-weight: 100;"><a href="https://soundcloud.com/bryantmcgill" title="Bryant McGill" target="_blank" style="color: #cccccc; text-decoration: none;">Bryant McGill</a> · <a href="https://soundcloud.com/bryantmcgill/harms-incurred-while-bringing" title="Harms Incurred While Bringing Preventive Systems Online" target="_blank" style="color: #cccccc; text-decoration: none;">Harms Incurred While Bringing Preventive Systems Online</a></div> **Entity class:** Distributed identity-resolution harm **Domains:** Terrorism screening / entity resolution / watchlisting / redress / distributed systems ## Definition **Watchlist misidentification** is an umbrella term for two distinct failures: 1. **[[wiki/Identity Collision|Identity collision]]:** the encountered person is not on the watchlist, but a screening system provisionally matches that person to somebody else's listed identity because names, dates of birth, documents, transliterations, biometrics, or other selectors resemble one another. 2. **[[wiki/Erroneous Watchlist Inclusion|Erroneous or stale inclusion]]:** the system has identified the correct person, but the watchlist state attached to that person is mistaken, unsupported, incomplete, obsolete, or no longer warranted. The first is a **wrong-person-to-record** failure. The second is a **right-person-to-wrong-state** failure. Both can produce adverse encounters, but they require different remedies: identity disambiguation for the first; evidentiary review, modification, or removal for the second. The complete three-state taxonomy is: **NOT LISTED + COLLISION → misidentified person** **LISTED + SUPPORTED CURRENT RECORD → valid positive match** **LISTED + BAD OR OBSOLETE STATE → erroneous inclusion** The governing harm is not merely delay at an airport. It is **compounding downstream destruction across mobility, immigration, employment, education, family, reputation, finances, psychological stability, relationships, and future opportunity** when a hidden identity state becomes portable across institutions and persistent across time. ## The documented scale GAO reported in 2006 that frontline agencies sent tens of thousands of unresolved potential matches to the [[wiki/Terrorist Screening Center|Terrorist Screening Center]] between December 2003 and January 2006, and about half were misidentifications. That does not mean half of everyone screened was misidentified; it means about half of the ambiguous matches escalated to the center were resolved as the wrong person. GAO documented intensive questioning, searches, missed flights, travel delays, and denied entry at the border. The Justice Department Inspector General found a second problem inside the data. In 2007 it examined 105 records that had already passed routine quality review and found that **38 percent still contained errors or inconsistencies**. Among 388 closed redress complaints, 52 concerned people who were not the listed identity, 136 positive-match records remained unchanged, 97 were modified, and 76 were removed. The Inspector General concluded that 45 percent of the positive-match records involved in the reviewed redress complaints required modification or removal. GAO's 2025 report shows that correction remains consequential. Of roughly 20,000 U.S.-person DHS TRIP inquiries filed from December 7, 2021 through September 30, 2023, GAO identified 289 as watchlist-related, and 88 of those people were removed during redress. **Nearly one-third is the correction yield within a self-selected, watchlist-related redress cohort; it is not a watchlist-wide error-rate estimate.** GAO issued 24 recommendations to seven agencies concerning nomination quality, redress, quality-control timeliness, and related weaknesses. ## Why collisions occur Watchlist matching is an adversarial [[wiki/Entity Resolution|entity-resolution]] problem. Exact matching misses aliases, spelling changes, transliteration variants, incomplete dates of birth, degraded records, and deliberately altered identifiers. Fuzzy matching and wider tolerances recover more true matches while increasing collisions with innocent people. GAO documented this tradeoff in Secure Flight. Matching settings assign different weights to identifiers, define score thresholds, and choose which name or date-of-birth variations count as potential matches. TSA officials told GAO that widening the accepted date-of-birth range would detect additional simulated matches but generate an unacceptable increase in false positives. The system therefore balances two security costs: **maximize recall → increase collision burden** **maximize precision → increase evasion risk** The objective cannot be perfect certainty at the first screen. It must be rapid, accurate, and minimally harmful uncertainty resolution. ## Error becomes distributed state The most consequential failure is not the first stop. It is identity error becoming a [[wiki/Distributed Erroneous State|distributed state]]. The FBI says the terrorism watchlist supports: - visa and passport screening by the Department of State; - border and international-entry screening by CBP; - aviation screening by TSA; - immigration screening by USCIS; - access decisions at U.S. military bases; - FBI investigations; - support to federal, state, local, tribal, and territorial law enforcement; and - NCIC-accessible screening during routine police encounters. Each downstream component can behave correctly according to its own rules while producing the wrong external result because the root identity assertion is wrong. **Predictive security can therefore fail before prediction begins: if entity resolution binds the wrong person to the threat state, every later correlation, forecast, and intervention can be internally correct and externally wrong.** This is [[wiki/Identity-Rooted Error Amplification|identity-rooted error amplification]]. The 2024 federal watchlisting overview confirms the distributed character from the correction side: when a record is modified or removed, the [[wiki/Terrorist Screening Center|Terrorist Screening Center]] verifies that the change is carried into the various receiving screening systems. If correction must propagate, error can propagate too. In March 2025 the organization was renamed the [[wiki/Threat Screening Center|Threat Screening Center]] as its mission expanded beyond terrorism screening. ## The Ibrahim cascade [[wiki/Rahinah Ibrahim|Rahinah Ibrahim]] provides the canonical documented case. An FBI agent misunderstood a watchlist nomination form and checked boxes exactly contrary to its instructions, unintentionally nominating her to the No Fly List and IBIS. The erroneous state contributed to her being handcuffed and detained at San Francisco International Airport while recovering from a hysterectomy and traveling with her fourteen-year-old daughter, missing her flight, later being prevented from returning to the United States, the revocation of her student visa, later visa denials, watchlist exports to Canadian and Australian systems, and years of litigation. Her daughter was later prevented from boarding a flight to attend the trial, and the appellate record described litigation costs exceeding $3.6 million. In [[wiki/Ibrahim v. Department of Homeland Security|Ibrahim v. Department of Homeland Security]], the government ultimately conceded that she posed no threat to national security, had never posed such a threat, and should never have been placed on the No Fly List. The record demonstrates the cascade: **incorrect form input → erroneous threat state → distribution across screening systems → physical intervention → mobility and immigration consequences → years of correction effort** ## Recursive and life-trajectory harm Once repeated anomalies become visible, a person rationally begins observing the system back: documenting stops, filing DHS TRIP inquiries, requesting records, contacting congressional offices, hiring counsel, changing travel, comparing encounters, and asking family or colleagues what occurred. Those actions create new records. The system's treatment changes the person's behavior, and the changed behavior returns to the system as fresh observation. That loop does not require a coordinated decision to persecute anyone. It can emerge from ordinary institutional behavior around a shared bad state. The original classification changes encounters; encounters change the person; adaptation produces new administrative and behavioral signals; later actors interpret those signals through the earlier state. A root error can therefore become self-reinforcing. The endpoint is [[wiki/Life-Trajectory Harm|a life trajectory organized around an erroneous hidden state]]: **compounding downstream destruction across mobility, immigration, employment, education, family, reputation, finances, psychological stability, relationships, and future opportunity**. Travel becomes unreliable. Work, education, deployment, conference, and client opportunities requiring travel become harder to accept. Family members experience delays, separation, expense, and the fear of another encounter. International relationships and immigration plans erode. Money and attention move into workarounds, documentation, and litigation. Each institution sees a local event; the person carries the aggregate burden. Historical FBI records-system notices show why relational effects matter. The Terrorist Screening Records System included possible matches, people accompanying or traveling with them, misidentified persons, associated individuals, encounter locations, the screening entity, and positive or negative resolution. A wrong root identity can therefore generate encounter exhaust around family and associates even when they are not themselves watchlisted. ## The anti-collision identity layer The system's remedy for collision is another persistent identity object. The FBI's 2007 Terrorist Screening Records System notice explicitly maintained **misidentified persons** and additional attributes used only to distinguish them from a listed person with similar identifiers. DHS TRIP assigns a Redress Control Number that travelers can place in future reservations to help prevent repeat misidentification. Earlier Secure Flight documentation called the parallel object a cleared-list record. This is a [[wiki/Negative Identity Assertion|negative identity assertion]]: **this person is not that watchlisted person** The architecture is: **listed identity → collision → negative resolution → persistent disambiguation record → future collision suppression** The cure for repeated misidentification requires remembering that the misidentification occurred. Clearance does not mean the encounter leaves no record; it means the record is retained and used to stop the same fusion from recurring. ## Correction latency and residual harm Correction at the authoritative node does not instantly erase every downstream copy or encounter artifact. DOJ OIG found that TSC redress reviews closed in an average of 67 days during the reviewed period; some open cases exceeded 180 days. It also identified a case in which CBP took more than 130 days to make a requested change in IBIS. [[wiki/Correction Latency|Correction latency]] is the interval during which a recognized error can continue producing operational consequences. Even after correction propagates, encounter histories, audit trails, redress files, disambiguation records, and records of associated people may persist for legitimate system-integrity reasons. That persistence creates a difference between **corrected current state** and **erased historical state**. The system needs provenance to prevent recurrence, but the retained trace must not silently recreate the adverse state it was designed to suppress. ## Measuring the real burden A mature [[wiki/The Second Error Function|second error function]] should measure watchlist error as a distributed event, not a single bad match. The relevant ledger includes: - collision frequency and negative-match resolution rate; - erroneous-inclusion correction yield within defined cohorts; - time from first adverse encounter to complaint; - redress review time; - propagation time from correction to every receiving system; - repeat encounters after correction; - number of downstream systems reached before correction; - number of derivative decisions made while the state was active; - associated or accompanying people recorded; - direct financial cost, lost work, lost travel, lost education, and legal cost; - behavior changed in response to the system; - residual records and effects after authoritative correction; and - [[wiki/Cumulative Downstream Burden|cumulative downstream burden per corrected root error]]. ## Financial-systems boundary The federal terrorism watchlist should not be used as evidence that a particular bank-account closure, credit denial, money-transfer block, or unemployment-benefit decision flowed from TSDS. The FBI states that the federal terrorism watchlist is not used for those financial decisions. AML and counter-terrorist-financing de-risking supply a separate, documented analogue of distributed risk-state harm and should remain a distinct evidentiary route. ## Relationships - **master harm map:** [[wiki/Security Harms Topology|Security Harms Topology]]. - **two root failures:** [[wiki/Identity Collision|Identity Collision]] and [[wiki/Erroneous Watchlist Inclusion|Erroneous Watchlist Inclusion]]. - **distributed effects:** [[wiki/Distributed Erroneous State|Distributed Erroneous State]], [[wiki/Identity-Rooted Error Amplification|Identity-Rooted Error Amplification]], [[wiki/Life-Trajectory Harm|Life-Trajectory Harm]], and [[wiki/Cumulative Downstream Burden|Cumulative Downstream Burden]]. - **correction mechanics:** [[wiki/Negative Identity Assertion|Negative Identity Assertion]], [[wiki/Correction Latency|Correction Latency]], [[wiki/Watchlist Redress|Watchlist Redress]], and [[wiki/Surveillance Record Persistence|Surveillance Record Persistence]]. - **canonical case:** [[wiki/Rahinah Ibrahim|Rahinah Ibrahim]] and [[wiki/Ibrahim v. Department of Homeland Security|Ibrahim v. Department of Homeland Security]]. - **identity layer:** [[wiki/Entity Resolution|Entity Resolution]], [[wiki/Identity Fusion|Identity Fusion]], [[wiki/Misidentification|Misidentification]], and [[wiki/Terrorist Screening Database|Terrorist Screening Database]]. - **encounter layer:** [[wiki/Threat Screening Center|Threat Screening Center]], [[wiki/Terrorist Screening Center|Terrorist Screening Center]], [[wiki/Watchlist Encounter Process|Watchlist Encounter Process]], [[wiki/National Crime Information Center|National Crime Information Center]], and [[wiki/Redress Opacity|Redress Opacity]]. - **accounting frame:** [[wiki/The Second Error Function|The Second Error Function]] and [[wiki/Graph Error Propagation|Graph Error Propagation]]. - **analysis:** [[research/Harms Incurred While Bringing Preventive Systems Online|Harms Incurred While Bringing Preventive Systems Online]]. - **collection:** [[collections/Terrorism, Counterterrorism, and the Intelligence Environment|Terrorism, Counterterrorism, and the Intelligence Environment]]. ## Sources / Provenance - [GAO-06-1031 — Terrorist Watch List Screening: Efforts to Help Reduce Adverse Effects on the Public](https://www.gao.gov/assets/gao-06-1031.pdf) (2006-09-29). - [DOJ Office of the Inspector General — Follow-up Audit of the Terrorist Screening Center, Audit Report 07-41](https://oig.justice.gov/archives/reports/FBI/a0741/exec.htm) (2007-09). - [GAO-09-292 — Aviation Security: TSA Has Completed Key Activities Associated with Implementing Secure Flight](https://www.gao.gov/assets/a289639.html) (2009-05-13). - [FBI — Terrorist Screening Records System, 72 FR 47073](https://www.fbi.gov/how-we-can-help-you/more-fbi-services-and-information/freedom-of-information-privacy-act/fbi-privacy-act-systems/72-fr-47073) (2007-08-22). - [DHS — Secure Flight Privacy Impact Assessment](https://www.dhs.gov/xlibrary/assets/privacy/privacy_pia_secureflight2008.pdf) (2008-10-20). - [DHS TRIP — Frequently Asked Questions](https://trip.dhs.gov/s/faq-page?language=en_US) (accessed 2026-09-23). - [FBI — Overview of the U.S. Government's Terrorist Watchlisting Process and Procedures](https://www.fbi.gov/file-repository/terrorist-watchlisting-transparency-document-april-2024-050224.pdf) (2024-04). - [FBI — Threat Screening Center](https://www.fbi.gov/investigate/terrorism/tsc) (accessed 2026-09-23). - [GAO-25-108349 — Terrorist Watchlist: Nomination and Redress Processes for U.S. Persons](https://www.gao.gov/products/gao-25-108349) (2025-08-14). - [GAO-26-108650 — Terrorist Watchlist: FBI Should Improve Outreach Efforts to Nonfederal Users](https://www.gao.gov/products/gao-26-108650) (2026-01-12). - [*Ibrahim v. Department of Homeland Security*, 912 F.3d 1147](https://cdn.ca9.uscourts.gov/datastore/opinions/2019/01/02/14-16161.pdf) (9th Cir. 2019-01-02). **As of:** 2026-09-23