Sanctions screening is often described as a name check: compare a customer or counterparty with a list, then clear or escalate the result. That is incomplete. Sanctions can restrict funds, economic resources, services, trade, investment, transport and other activity. Some restrictions extend to unlisted entities through ownership or control. A name screen can identify a question; it cannot decide every legal issue.
The practical task is to connect law, data and operations:
Map legal perimeter → identify applicable regimes and restrictions → define the screening population and data → select trigger points → investigate potential matches → assess ownership, control and the relevant prohibition → apply the authorised disposition → retain evidence → test and improve the control.
This guide explains that model for compliance, financial-crime, product and operations teams.
What sanctions screening is—and what it is not
Sanctions screening is a control that compares relevant identifying information with sanctions data so that a firm can identify possible exposure and investigate it. The subject may be an individual, organisation, vessel, aircraft or another object represented in official data. The relevant question may arise at onboarding, when a counterparty is introduced, during a transaction, after an ownership change, or when an authority changes a designation or programme.
The UN Security Council Consolidated List brings together individuals and entities subject to Security Council sanctions measures, but the measure that applies depends on the relevant regime and its implementation by Member States.1 In the United States, OFAC publishes the SDN List and consolidated non-SDN data; those sources do not represent one uniform restriction, and the SDN List is not the whole OFAC sanctions framework.2 In the United Kingdom, the UK Sanctions List is the current source for UK designations, but firms still need the applicable regime legislation and guidance to understand the legal effect.3
Screening is not the same as complete sanctions compliance. A clean name result does not resolve sectoral restrictions, prohibited services, restricted goods, geographic measures, ownership or control, or attempts to evade sanctions. FCA supervisory findings make the same operational point: customer and payment screening may not identify trade restrictions, sectoral sanctions or evasion, so other controls may be needed.4
Screening is distinct from adjacent controls:
- KYC and KYB maintain identity, business and ownership information that can support a sanctions investigation, but the controls have different purposes.
- PEP screening identifies political exposure for risk-management and enhanced-due-diligence purposes. PEP status does not by itself mean that a person is sanctioned. See the separate PEP screening guide.
- AML transaction monitoring looks for suspicious patterns. Sanctions analysis asks whether a restriction affects a party, property or activity. The controls may exchange data, but neither replaces the other. See the AML compliance guide.
- Adverse-media screening can provide risk context and investigative leads. It is not an official designation source.
The first design principle follows: do not ask only, “Which list should we load?” Ask, “Which legal restrictions can apply to our legal entities and activities, and what control evidence is needed to identify and manage that exposure?”
Separate binding rules from guidance and implementation choices
Compliance procedures become unreliable when every source is described as a “requirement.” A control owner should be able to classify each important statement in a policy, rulebook or configuration decision.
| Legal-status layer | What it means | Examples | How to write or use it |
|---|---|---|---|
| Binding law or sanctions measure | A prohibition or obligation that applies within the measure’s jurisdiction and scope. | EU regulations, UK sanctions regulations, US sanctions regulations and reporting rules. | Use words such as “requires” or “prohibits” only after identifying the rule and scope. |
| Official authority guidance | An authority’s explanation of sanctions operation or compliance. | OFSI General Guidance; OFAC FAQs and Compliance Framework; Council EU sanctions best practices. | Attribute the position to the authority and check whether the document is binding. |
| Supervisory guidance or expectation | Material a supervisor uses to assess systems and controls in its remit. | FCA Financial Crime Guide and supervisory findings; EBA restrictive-measures guidelines. | Apply it to firms within scope; do not present it as a global statute. |
| International standard | A standard aimed principally at jurisdictions for implementation in national systems. | FATF Recommendations 6 and 7. | Say that FATF calls on countries to implement targeted financial sanctions; then check local law. |
| Implementation recommendation | A control-design choice derived from legal, authority and supervisory sources. | Trigger events, queue design, evidence fields, testing scenarios and management information. | Label it as recommended practice and tailor it to the organisation. |
FATF describes its Recommendations as international standards that countries should implement and adapt to their legal, administrative and financial systems.5 Recommendations 6 and 7 address countries’ implementation of targeted financial sanctions concerning terrorism and terrorist financing, and proliferation respectively.67 They influence national frameworks; they are not self-executing private-sector legislation.
The Council of the EU describes its sanctions best-practices document as non-binding and non-exhaustive.8 It is useful implementation material, but it should not be cited as if it were an EU regulation. OFAC’s Compliance Framework similarly presents a risk-based model built around management commitment, risk assessment, internal controls, testing and auditing, and training.9 It does not replace programme-specific US rules.
Start with legal perimeter, not a global list
The sanctions perimeter is the set of regimes and restrictions that can apply to the organisation, people, property and activity. Establish it before configuring matching.
Map the legal entities, branches and people involved; incorporation and operating locations; customer and counterparty locations; products, services, assets and transaction types; currencies, payment rails and intermediaries; ownership, control and agency relationships; and any contractual or policy controls beyond the legal minimum.
UK financial sanctions apply to persons and activities within UK territory, and to UK nationals and legal entities established under UK law wherever they operate.10 That is a UK scope statement, not a shortcut for deciding UK nexus in every cross-border case. US sanctions analysis is programme-specific; avoid reducing it to slogans about a currency, server location or customer nationality. EU measures apply according to their own scope provisions and the facts of the activity.
Build a regime-and-programme matrix with legal input where needed. Separate legally applicable sources from those adopted under risk appetite, customer commitments or policy. Risk assessment can shape additional coverage, workflow and testing; it does not change the effect of an applicable rule.
Authority, nexus and source matrix
| Authority or framework | Starting source | Nexus or scope question | What the source does not decide by itself |
|---|---|---|---|
| UN Security Council | Consolidated List and regime-specific resolutions. | Which UN measures has the relevant Member State implemented, and how? | It does not state every private-sector duty under domestic law or give every listed person the same restriction. |
| European Union | Applicable EU legal act, EU sanctions resources and the relevant national competent authority. | Does the EU measure apply to the legal entity, person, activity, funds or economic resources? | The consolidated financial-sanctions data does not capture every sectoral, trade or service restriction. |
| United Kingdom | UK Sanctions List, regime regulations and OFSI guidance. | Is there UK territorial or person nexus, and what does the applicable regulation prohibit? | A designation result alone does not resolve exceptions, licensing, ownership/control or reporting. |
| United States | OFAC programme pages, SDN and relevant non-SDN lists, regulations and FAQs. | Which programme and US jurisdictional connection are relevant to the party, property or activity? | The SDN List is not the entire OFAC framework, and list status does not decide every non-SDN restriction. |
| FATF | Recommendations and targeted-financial-sanctions guidance. | How has the relevant country implemented the international standard? | FATF material is not itself the organisation’s domestic private-sector law. |
The Commission’s overview links EU sanctions resources and national competent authorities.11 Use it as a route to authoritative material, not a substitute for the legal act. OFAC’s Sanctions List Service provides SDN and non-SDN data.2 Use the UK Sanctions List with the applicable regulation and OFSI material.3
Assign an owner to monitor each official source and identify affected populations. The UN publishes additions, amendments and removals.12 OFAC states that its SDN List has no predetermined update timetable.13 Authorities do not follow one universal schedule.
Decide who and what enters the control
The screening population follows the legal perimeter and business model. It can extend beyond the named customer to counterparties, owners/controllers, payees, suppliers, intermediaries and relevant assets. Map when each subject becomes known, which identifiers are available, what decision can still be paused and which legal entity owns it.
| Party or object | When it may enter the relationship | Identifiers that may help resolve a candidate | Control question |
|---|---|---|---|
| Individual customer or authorised user | Onboarding, account access or an authority change. | Full name, aliases, date and place of birth, nationality, address, document or tax identifiers. | Is this the listed person, and is the person’s role relevant to an applicable restriction? |
| Company or organisational customer | Onboarding, contracting or account creation. | Legal and trading names, registration number, address, jurisdiction, directors and group structure. | Does the entity match directly, or is ownership/control analysis needed? |
| Beneficial owner or controller | KYB review, corporate change or escalation. | Ownership percentages, voting rights, board rights, control evidence, source and effective date. | Does the applicable jurisdiction’s ownership or control test affect the entity? |
| Counterparty, payee, beneficiary or supplier | Contracting, recipient creation, invoice, order, transfer or payout. | Name, account or registration identifier, address, country, institution and relationship context. | Does this new party create exposure not resolved at onboarding? |
| Financial institution or intermediary | Payment routing, custody, settlement, trade finance or correspondent activity. | Legal name, BIC or other institution ID, location, role, route and message data. | Is it a technical participant, restricted party, or part of a prohibited route or service? |
| Vessel or aircraft | Shipping, insurance, finance, ownership, charter or transport activity. | Name, IMO or registration number, flag, call sign, owner, operator and historical identifiers. | Does the asset or its owner/operator engage a designation or activity restriction? |
| Transaction, asset, service or geography | At order, instruction, execution, settlement or delivery. | Currency, location, route, goods or service description, asset identifiers and purpose. | Is the concern outside a direct name match—for example, sectoral, geographic or service-based? |
Not every identifier is appropriate in every relationship. Know which data is reliable at each decision point and where thin data prevents a defensible resolution.
Choose screening and reassessment moments
There is no universal global rule that every customer must be screened daily, continuously or at every transaction.1415 Define timing from applicable law and a documented control model.
Useful trigger categories include:
| Trigger | Why exposure may change | Operational response | Status caution |
|---|---|---|---|
| Initial onboarding or contracting | The relationship and known parties first enter scope. | Assess the relevant parties and retain the source, input data and result before the defined activation point. | Exact duties depend on sector, activity and regime. |
| New counterparty, payee or supplier | A new party enters a commercial or value chain. | Determine whether the party and available context need assessment before commitment or release. | Do not assume every supplier is treated identically. |
| Transaction or activity event | A new recipient, intermediary, asset, location, service or purpose appears. | Assess sanctions questions not resolved by customer onboarding. | Transaction controls are product- and jurisdiction-specific. |
| Official list or regime change | A previously clear party or activity may become restricted. | Identify the affected population, pending activity and assets; route candidates to an owned decision process. | Follow any earlier trigger set by the applicable rule. |
| Name, identifier or relationship change | Better or changed data can alter an earlier result. | Reassess the affected subject and link the new evidence to the previous decision. | Treat as an implementation trigger unless a specific rule says otherwise. |
| Ownership or control change | An unlisted entity may enter or leave a restricted position. | Obtain current corporate evidence and apply the relevant jurisdictional test. | EU, UK and US tests are not interchangeable. |
| New product, country, corridor or partner | The legal perimeter, parties, available data and intervention point can change. | Update the regime, population and data maps before relying on the existing control. | This is recommended change governance, not a universal statutory approval process. |
| Periodic review | It provides a backstop for changes not captured through events. | Set and document a frequency based on applicable rules, risk and residual data limitations. | No single cross-jurisdictional interval applies to all firms. |
A narrow payment example
Payment controls illustrate why cadence should follow the exact rule. Article 5d of Regulation (EU) No 260/2012 requires PSPs offering instant credit transfers to verify their payment service users immediately after relevant targeted financial restrictive measures enter into force or are amended, and at least once each calendar day.15 During execution, the payer’s and payee’s PSPs do not perform an additional Article 5d verification of those payment service users; the provision preserves other restrictive-measures and Union AML/CFT obligations.15 That specific model should not be generalised to every payment, product or jurisdiction. The detailed workflow belongs in the specialist guide on sanctions screening for payment institutions.
Assess ownership and control beyond the listed name
A clean company-name result may not close the sanctions question. Depending on the applicable regime, an unlisted company can be affected through ownership or control by a designated or blocked person. The legal tests are not a single global “50 percent rule,” and an AML beneficial-owner threshold should not be substituted for a sanctions test.
| Jurisdiction | Ownership position | Control position | Practical implication |
|---|---|---|---|
| European Union | EU asset-freeze regulations can cover funds and economic resources owned, held or controlled by listed persons. In its expressly non-binding best practices, the Council discusses a 50% or majority-interest ownership criterion and aggregation by listed persons.168 | The Council best practices discuss indicators such as board appointment rights, voting arrangements and dominant influence; the applicable legal act and facts remain decisive.8 | Review the specific regulation, EU guidance, national competent-authority position and corporate facts. Do not treat the best-practices percentage as a self-standing universal rule. |
| United Kingdom | OFSI guidance describes ownership as directly or indirectly holding more than 50% of shares or voting rights.10 | The guidance also identifies rights to appoint or remove a majority of the board, or a reasonable expectation that a person can ensure the entity’s affairs are conducted according to their wishes.10 | An unlisted entity may be subject to relevant restrictions where the applicable UK ownership or control test is met. Escalate fact-sensitive cases. |
| United States | Under OFAC’s 50 Percent Rule, an entity owned directly or indirectly 50% or more in aggregate by one or more blocked persons is itself considered blocked.17 | Control without 50%-or-more blocked ownership does not by itself automatically block the entity under that rule, although dealings involving a blocked person or other programme restrictions can raise separate issues.17 | Aggregate blocked ownership through the chain. Keep the automatic ownership rule separate from other restrictions and due-diligence concerns. |
For corporate subjects, record the source date, direct and indirect holdings, voting and appointment rights, relevant agreements, intermediate entities and any uncertainty. A generic UBO record is evidence, not a legal conclusion. The analyst needs to know which jurisdictional test is being applied and why.
This is also where KYC and sanctions controls should exchange information without becoming the same process. Corporate records collected for KYB may reveal an owner or controller that changes sanctions exposure. Conversely, a sanctions alert may show that the ownership record needs refreshing. See the beneficial ownership and UBO guidance for the underlying corporate-data context.
Design matching to generate explainable candidates
Matching should generate candidates for investigation with enough context to resolve them. A score is not a legal result, and no universal 90%, 95% or 99% threshold establishes compliance.
The design usually needs to address:
- normalisation of case, punctuation, spacing and common legal-form differences;
- aliases, former names, reordered names and transliteration;
- non-Latin scripts and language-specific name structures;
- dates and places of birth, nationality and address;
- passport, tax, registration, vessel, aircraft and other stable identifiers;
- subject type, because a person, entity, vessel and aircraft require different comparison fields;
- data quality, truncation, field length and missing identifiers; and
- treatment of weak aliases and broad generic terms.
OFAC’s potential-match guidance tells reviewers to compare the complete sanctions entry with available identifiers, including name, address, nationality, passport or tax ID, place and date of birth, former names and aliases, and to obtain additional information where needed.18 OFAC also recognises “weak AKAs” as broad or generic aliases that can create substantial false hits.19 These are useful investigation principles; they do not prescribe one algorithm or threshold for every organisation.
FCA’s 2026 supervisory findings identified weaknesses involving inaccurate or outdated lists, configuration, delayed updates, reference data, name variants, non-Latin names, titles, character limits, alert rationale, testing and over-reliance on vendors.4 Convert those observations into test cases rather than generic policy language.
Build a representative test pack
Test exact names, aliases, spelling changes, transliteration, non-Latin scripts, common names with conflicting identifiers, missing dates of birth, truncated entity names, weak aliases, asset identifiers and ownership chains. For each case, record the source/version, input and transformation, expected and actual behaviour, downstream workflow, and remediation owner. Test the complete path from official update through ingestion, population selection, candidate creation, analyst access, disposition and evidence—not only the matching engine.
Investigate the alert before deciding the legal action
An alert says that configured logic found a similarity or rule condition. It does not prove identity, establish ownership or control, identify the applicable prohibition, or decide whether activity should be released, refused, frozen, blocked or rejected.2010
Use a staged investigation so that identity resolution remains separate from legal disposition.
| Alert stage | Analyst question | Evidence to obtain or preserve | Decision owner or next action |
|---|---|---|---|
| 1. Establish context | Which person, entity, asset or transaction field generated the candidate? What activity is pending? | Alert and subject IDs, timestamps, source/version, input fields, relationship and transaction context. | Queue owner confirms whether the relevant business step can or should be paused under the approved procedure. |
| 2. Compare identity | Does the available information point to the listed subject or a different person/entity/object? | Complete entry, aliases, subject type, date/place of birth, nationality, address, document, registration, vessel or aircraft identifiers. | Clear with a documented rationale, request more data, or escalate. |
| 3. Examine ownership and control | Is an unlisted organisation affected under the relevant jurisdictional test? | Current filings, ownership chain, voting and board rights, control agreements, source dates and gaps. | Sanctions specialist or legal owner reviews material or uncertain structures. |
| 4. Identify regime and restriction | Which legal act, programme or restriction applies to this organisation, party, property or activity? | Authority source, programme, legal nexus, role, property interest, geography and transaction/service context. | Authorised sanctions or legal decision owner determines the applicable path. |
| 5. Decide and communicate | What action is legally appropriate, and are an exception, licence or reporting path relevant? | Decision rationale, approver, timestamps, advice, licence/exception analysis and communications. | Apply the authorised jurisdiction-specific disposition and reporting procedure. |
| 6. Learn and reassess | Did the case reveal a data, configuration, source, capacity or policy weakness? | Root cause, affected population, control version, owner, remediation and retest result. | Correct under change governance and reassess affected subjects where appropriate. |
OFAC’s US guidance distinguishes transactions that involve blockable interests from transactions that are prohibited but should be rejected rather than blocked.20 Do not export that terminology as a universal model: EU and UK measures have their own freezing, prohibition, licensing and reporting structures. Under UK asset-freeze guidance, funds or economic resources that are in fact subject to an asset freeze are to be frozen immediately by the person possessing or controlling them.10 That statement applies after the relevant legal criteria are established; it does not turn every unresolved fuzzy alert into confirmed frozen property.
Where UK reporting rules apply to a defined relevant firm, OFSI says the firm is to inform OFSI as soon as practicable when the specified knowledge or reasonable-suspicion conditions are met.10 OFSI also explains that reporting to another regulator or submitting an NCA suspicious activity report does not replace an applicable OFSI reporting duty.10 Keep jurisdiction-specific reporting procedures separate and current.
The operating lesson is simple: configure separate states for candidate, under investigation, identity resolved, ownership/control review, legal escalation and final disposition. A single “hit” status conceals both uncertainty and authority.
Retain evidence that makes the decision reproducible
A defensible case record should allow a reviewer to reconstruct what the organisation knew, which source and rule it considered, how the analyst compared the subject, who approved the decision and what happened next.
For a material alert, retain the subject and identifiers; the underlying customer, counterparty, transaction, ownership or asset record; authority, programme, source version and retrieval time; fields supporting and contradicting the candidate; relevant ownership/control and activity context; analyst rationale; escalation, reviewer and timestamps; final disposition and any advice, exception, licence or reporting reference; operational outcome; and later QA or review.
Link evidence to configuration. If an alert was created under a particular matching rule, source version or threshold, preserve that context. If it was cleared through a reusable false-positive rule, record the distinguishing identifiers and conditions under which that rule remains valid.
Weak audit trails do more than frustrate an auditor. They prevent the firm from identifying affected cases after a source correction, ownership change or control defect. FCA findings emphasise documented alert rationales, quality assurance, escalation and sufficient resources.4
Govern, test and oversee the complete control
Technology can support screening, but governance determines whether the control stays aligned with legal scope and operational reality. OFAC’s compliance framework describes five components—management commitment, risk assessment, internal controls, testing and auditing, and training—as part of a risk-based sanctions compliance programme.9 FCA guidance likewise stresses senior-management responsibility and oversight of screening resources supplied by group functions or third parties.21
Assign clear accountability for:
- legal-perimeter and regime interpretation;
- official-source monitoring and update ingestion;
- population and data mapping;
- matching configuration and change approval;
- alert queues, ageing and escalation;
- ownership/control review;
- disposition, licensing and reporting procedures;
- quality assurance and independent testing;
- incidents, outages and missed updates; and
- management information and policy maintenance.
Outsourcing does not remove control ownership
A provider may supply data, technology or review support. The organisation still needs to understand delegated scope, sources, data, configuration, alert ownership and outage handling.
Test vendor output with cases drawn from your own products and data. Reconcile source updates, sample cleared candidates, inspect unresolved queues, review service failures and maintain an exit or recovery path. FCA supervisory material warns against uncritical reliance on group or vendor resources without sufficient internal understanding, oversight and testing.214
The OFSI Bank of Scotland enforcement discussion provides a concrete reminder: the authority described an automated-screening failure involving a spelling variation and highlighted contingency, escalation, training and prompt reporting.22 The lesson is not that automation is ineffective. It is that a screening system needs tested matching, people who can recognise failure, and an owned response when the automated path does not work.
Management information should show control health
Report candidate volumes and ageing by product and source; outcomes; cases awaiting data or legal review; overrides; source-update completion; failed jobs; QA and test exceptions; ownership/control escalations; and overdue remediation. Interpret the figures with sampled evidence: fewer alerts can indicate better calibration or missing data, while a fast queue can conceal weak rationale.
Teams evaluating sanctions screening software should therefore assess data lineage, configuration transparency, explainable candidate evidence, workflow ownership, auditability, source-change handling and testing support. Product selection is one control decision inside the wider framework; it is not a compliance conclusion.
Practical sanctions-screening checklist
Use this checklist as a control-design aid, not as a substitute for legal analysis.
Frequently asked questions
What is sanctions screening?
Sanctions screening is a control that compares relevant party or object data with sanctions information to identify possible exposure for investigation. It can apply to people, entities, vessels, aircraft and other data represented in official sources. It is not the legal prohibition itself, and it does not identify every sectoral, geographic, service, ownership or evasion restriction.
Is sanctions screening legally required for every company?
There is no accurate universal yes-or-no answer. Substantive sanctions prohibitions can apply broadly within a jurisdiction, while explicit screening-system, reporting and supervisory requirements vary by jurisdiction, sector and activity. For example, UK financial sanctions apply to persons in UK territory and UK persons wherever they operate, while particular OFSI reporting duties apply to defined relevant firms under specified conditions.10 Establish the organisation’s legal perimeter rather than copying another firm’s list or frequency.
Which sanctions lists should a company screen?
Start with regimes legally relevant to the organisation’s legal entities, locations, products and activity. Then document additional sources adopted because of risk, policy or contractual commitments. Do not assume that every company worldwide is legally required to screen UN, EU, UK and all OFAC lists. OFAC itself provides SDN and multiple non-SDN datasets, and programme restrictions cannot always be reduced to list membership.2
Who should be included in sanctions screening?
The relevant population can include customers, organisational entities, authorised users, counterparties, payees, suppliers, owners/controllers, intermediaries, vessels or aircraft, depending on the applicable regime and business model. Map how each party enters the relationship and what decision the control supports. This is a perimeter and risk question, not a universal command to screen every possible party identically.
How often should customers be rescreened?
There is no universal global cadence. Combine applicable legal requirements with event triggers such as official list changes, corrected identifiers, ownership changes and new relationships, plus a documented periodic backstop. EU Article 5d provides a deliberately narrow counterexample: it sets immediate-after-change and at-least-daily verification for payment service users of in-scope instant-credit-transfer PSPs.15 Do not generalise that cadence beyond its scope.
Does a company have to appear on a sanctions list to be restricted?
No. An unlisted entity may be affected through ownership or control, but the tests differ. OFAC’s automatic rule uses direct or indirect aggregate ownership of 50% or more by blocked persons.17 UK guidance uses separate ownership and control criteria.10 EU analysis starts with the applicable regulation and may use expressly non-binding Council best practices as interpretive implementation material.168
How should a potential false positive be investigated?
Compare the complete official entry with reliable identifiers available for the subject. Check subject type, aliases, date and place of birth, nationality, address, document or tax identifiers, registration data and other relevant descriptors. Obtain more information where the available data cannot resolve the candidate. OFAC publishes this comparison approach and separate guidance on weak aliases.1819 Document why conflicting identifiers are sufficient—or insufficient—to clear the case.
Does an alert mean a transaction must be frozen?
No. An alert is a candidate. Resolve identity, ownership/control, legal nexus, programme and restriction before applying the authorised action. Under US rules, OFAC distinguishes blocking from rejection depending on the programme and whether a blockable interest is involved.20 UK freezing duties apply where the applicable asset-freeze criteria are met.10 Other jurisdictions use their own legal structures, exceptions, licences and reporting paths.
What evidence should be retained for a screening decision?
Retain enough to reproduce the decision: screened data, subject and relationship identifiers, authority and source version, candidate fields, conflicting descriptors, ownership/control evidence, activity context, analyst rationale, escalation, approver, timestamps, final disposition and later QA or review. The exact record depends on the case and retention framework, but a bare “clear” or “hit” status is not an adequate investigation history.
Can sanctions screening be outsourced?
Data, technology and review work can be supported externally, but the organisation still needs to govern its control. Document provider scope, sources, data flow, configuration, update handling, service failures, alert ownership, testing and recovery. FCA material specifically warns against over-reliance on vendors or group resources without sufficient internal understanding and oversight.214
Closing perspective
A strong process begins with legal perimeter and ends with evidence an accountable team can explain. Map the regimes, parties and data; reassess when exposure changes; separate identity, ownership and legal analysis; apply the jurisdiction-specific decision path; and test the complete chain. Use the sanctions screening guide hub for related authority, process and industry resources.
References
Footnotes
-
UN Security Council, United Nations Security Council Consolidated List. ↩
-
OFAC, Sanctions List Service. ↩ ↩2 ↩3
-
UK Government, The UK Sanctions List. ↩ ↩2
-
Financial Conduct Authority, Sanctions systems and controls: our firms, our findings. ↩ ↩2 ↩3 ↩4 ↩5
-
FATF, The FATF Recommendations. ↩
-
FATF, Best practices on targeted financial sanctions related to terrorism and terrorist financing—Recommendation 6. ↩
-
FATF, Targeted financial sanctions related to proliferation—Recommendation 7. ↩
-
Council of the European Union, EU Best Practices for the effective implementation of restrictive measures. ↩ ↩2 ↩3 ↩4
-
OFSI and HM Treasury, UK financial sanctions general guidance. ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10
-
European Commission, Overview of EU sanctions and related resources. ↩
-
UN Security Council, List updates to the UN Security Council Consolidated List. ↩
-
OFAC, Frequently asked questions. ↩
-
EUR-Lex, Regulation (EU) No 260/2012, consolidated text including Article 5d. ↩ ↩2 ↩3 ↩4
-
EUR-Lex, Council Regulation (EU) No 269/2014. ↩ ↩2
-
OFAC, FAQs on entities owned by blocked persons and the 50 Percent Rule. ↩ ↩2 ↩3
-
OFAC, FAQs on identifying and resolving potential matches. ↩ ↩2
-
OFAC, FAQs on weak aliases. ↩ ↩2
-
Financial Conduct Authority, Financial Crime Guide: financial sanctions. ↩ ↩2 ↩3
-
Office of Financial Sanctions Implementation, Sanctions compliance in practice: lessons from OFSI's Bank of Scotland penalty. ↩