Pricing
Language

Guide · Updated 27 August 2026 · 15 min read

Supplier Sanctions Screening Checklist for Procurement

Use this procurement-focused sanctions screening checklist to define supplier data, scope, ownership review, alerts, approvals, evidence and monitoring.

Share

Supplier sanctions screening can fail even when a name search takes place. Procurement may hold the supplier record, finance may see a new beneficiary, and compliance or legal may need ownership information. Unless those inputs reach the same control, a screening result can be operationally unusable.

This checklist gives procurement teams a control model for approval and later review. Procurement owns operational inputs, change capture and the approval gate. Compliance and legal determine applicable requirements, ownership or control analysis, and the authorised response.

For the broader process, use the guide to sanctions screening for suppliers and third parties. This page focuses on procurement's control record.

What a supplier sanctions screening checklist should control

Sanctions law and a supplier-screening policy are related, but they are not the same thing. Applicable regimes create restrictions and duties. Screening, data standards, review triggers, workflow holds and evidence fields are operational controls an organisation designs to help manage that exposure.

There is no single worldwide supplier-screening rule. Relevant restrictions depend on the parties, geography, activity, transaction and legal nexus. OFAC encourages risk-based controls and identifies counterparties and supply chains as risk inputs. UK guidance directs organisations to current legislation and regime-specific guidance.

A useful checklist makes sure the right facts reach the right decision-maker before the relationship progresses.

Supplier sanctions screening checklist at a glance

This is a control-design model, not a universal legal checklist. Adapt its gates, owners and evidence fields to the organisation's applicable requirements, supplier population and risk.

ControlProcurement or operational actionCompliance or legal decisionEvidence retained
Supplier dataCapture the legal entity name, useful alternate names, registration identifier, jurisdiction, address and policy-required identifiersDefine the minimum information for reliable screening and how incomplete records are handledSubmitted data, source, collection date and record version
ScopeIdentify the contracting party, relationship, countries, goods or services and relevant payment partiesDetermine applicable regimes and which relationships enter the screening policyScope rationale and policy version applied
TimingRun the required gate before policy-defined approval or commitment and after specified changesDefine risk- and policy-based triggers without inventing a universal intervalTrigger, screening time and review status
Ownership and controlObtain or route available owner and controller information from approved sourcesApply the relevant jurisdictional test and decide whether more information is neededOwnership chain, percentages or control facts, source and analysis
Related partiesCapture relevant owners, controllers, agents, intermediaries or beneficiaries when requiredDefine which roles matter to the applicable regime and riskParty role and reason for inclusion
Screening resultRoute a potential match rather than treating it as clearance or designationCompare identifiers, source entry, programme and relationship contextQuery, source result and matching attributes
Alert handlingApply the organisation's defined hold and escalation state while required review is openResolve or escalate the match and determine the applicable responseReviewer, reasoning, escalation and outcome
ApprovalProgress the supplier only through the authorised workflowProvide or obtain the required compliance or legal decisionApprover, date, conditions and case reference
MonitoringFeed relevant supplier changes back into screening or reviewDefine event-led and policy-based reassessment rulesTrigger event, new review and outcome
GovernanceMaintain control owners and escalation contactsOwn the legal framework, policy interpretation and specialist escalationPolicy version, responsibilities, testing and remediation

An internal hold is not a legal asset freeze. Policy can pause supplier activation or payment during review. Whether law requires freezing, rejection, reporting or another response is a separate determination.

Collect supplier data and define scope before screening

Start with usable supplier identity data

A name alone is often insufficient. Capture the full legal entity name and, where relevant, trading names, registration number, jurisdiction, address and other policy-required identifiers. Record the source and collection date.

OFAC's potential-match guidance illustrates why this matters: a reviewer should compare the nature of the party and available identifiers, not decide from name similarity alone. Reliable identifiers also reduce the risk of screening the wrong entity within a corporate group.

An incomplete record creates a control question: is the information sufficient, or must procurement obtain more before approval? Policy should define who can accept an exception and what supports it.

Define the relationship, not only the contracting name

The record should identify what the organisation is approving: the contracting entity, goods or services, countries, agents, intermediaries, payment beneficiary and other policy-required parties.

This does not mean every party in every relationship must be screened. Compliance and legal should identify the applicable jurisdictions and restrictions; policy should then define the supplier and related-party population needed to operate the control. Procurement's job is to make the relationship visible and route material gaps or changes.

Retain which entity was screened, which connected parties entered scope, which policy applied and why.

Screen the correct supplier entity

Screen the legal entity that will enter the relationship using the approved sources and configuration. If a group brand, local subsidiary and payment recipient are different parties, do not treat one clean result as evidence for all three. Capture their roles and apply the policy-defined checks to each relevant record.

Name screening is not a complete sanctions analysis. Restrictions can also concern programmes, sectors, activities, goods, services or geography.

Apply ownership and control rules by regime

An unlisted supplier can still be affected through ownership or control rules. The analysis is regime-specific.

Under OFAC's 50 Percent Rule, an entity is blocked when blocked persons own, directly or indirectly and in aggregate, 50% or more. The rule concerns ownership, not control alone. UK guidance includes broader control tests. EU analysis starts with the applicable legal act; one programme's guidance is not universal.

For a fuller comparison, see sanctions ownership and control. Beneficial-ownership information may be an important input, but an AML UBO threshold is not automatically the applicable sanctions test.

Procurement should route the ownership and control information required by policy. Compliance or legal determines which test applies and whether more research is necessary.

Owners, controllers, directors, agents, distributors, intermediaries, payment beneficiaries and other related parties can matter in different relationships. Avoid a blanket instruction to screen every person connected with every supplier. Instead, record the party's role and why it enters scope under the applicable control.

UBO and related-party context can keep supplied ownership percentages, control relationships, roles and source information connected to screening and review. It should not be described as automatically discovering every owner or registry change.

Investigate alerts before an authorised decision

A potential match is a question, not a verdict

Screening software can return a similar name when other identifiers do not align. OFAC advises comparing the complete sanctions entry with available information and does not prescribe a universal name-match score threshold. A score can support prioritisation; it is not proof that the supplier is sanctioned.

Procurement should not clear the alert independently or assume every alert requires a legal asset freeze. Its role is to preserve the supplier and relationship context, place the record into the policy-defined hold or escalation state, and prevent uncontrolled progression while the required review remains open.

Compare identity and relationship context

An investigation should establish:

  1. which supplier or connected party generated the alert;
  2. which names, aliases, entity type, addresses, jurisdictions, registration details and other identifiers align or conflict;
  3. which sanctions source, entry and programme produced the result;
  4. whether ownership, control, party role or transaction context changes the assessment;
  5. what material information remains missing; and
  6. who is authorised to resolve or escalate the case.

Retain the compared attributes and rationale. “False positive” alone is difficult to defend when a supplier record or sanctions entry later changes.

Identity resolution, legal applicability and operational response are separate decisions. A credible identity match may still require analysis of jurisdiction, programme, ownership or control, party role, transaction, licences, exceptions and reporting duties.

Policy should identify who can close a non-match, determine whether a restriction applies and authorise progression. Procurement controls the gate; compliance and legal own the sanctions disposition.

Sanctions screening software can connect screening results, supplied identifiers and relationship context to controlled cases, evidence and review. It does not determine whether the organisation may legally transact.

Decide when a supplier returns to screening or review

Authorities update designations, suppliers restructure, and new beneficiaries, intermediaries or jurisdictions enter relationships. Policy should define which events return a record to review.

Useful policy triggers can include:

  • a relevant designation, sanctions-source or programme change;
  • a change to the supplier's legal name, registration data, address or operating jurisdiction;
  • a share transfer, new parent, controller change or restructuring;
  • a new agent, distributor, intermediary, end user or other policy-relevant party;
  • a new payment beneficiary, bank, account or payment destination;
  • a material change to goods, services, route, destination or relationship; and
  • a scheduled review used as a risk-based backstop.

These are control-design examples. OFAC supports risk-responsive assessments, while OFSI discusses review at appropriate times and monitoring where appropriate. Neither sets a universal interval.

The guide on when to rescreen suppliers for sanctions explains how to combine meaningful-change events with a policy-defined backstop. Ongoing monitoring can rescreen configured records and return relevant changes to review; the organisation still decides which records and changes enter scope.

Keep approvals, evidence and governance reviewable

A control should reconstruct its decision. OFAC describes escalation and recordkeeping as effective internal controls. OFSI considers whether ownership and control diligence was proportionate and evidenced.

A practical supplier record should retain:

  • the supplier and connected parties considered, including each role;
  • the operational and jurisdictional scope applied;
  • submitted identifiers and their sources and dates;
  • relevant ownership or control information and analysis;
  • screening source, input, timestamp and result;
  • alert attributes compared and missing information requested;
  • reviewer, specialist escalation, rationale and outcome;
  • authorised approver, date and any conditions; and
  • later changes, reassessments and the current decision status.

Responsibilities should be explicit. Procurement maintains inputs, captures changes and operates the gate. Finance captures payment-party changes and respects holds. Compliance or legal defines the framework, oversees material alerts and determines the sanctions response. Control owners test the workflow.

Retention periods and reporting requirements vary by jurisdiction, sector and activity. The record above is an operational evidence model, not a universal statutory retention schedule.

Frequently asked questions

Is sanctions screening mandatory for every supplier?

Applicable laws create restrictions an organisation must manage, but the reviewed authorities do not require one identical process for every supplier worldwide. Determine the applicable jurisdictions, activities and exposure, then design a proportionate control.

Which sanctions lists should procurement use?

There is no safe answer of “all global lists.” Compliance or legal should identify the relevant jurisdictions, programmes and restrictions. The organisation may add other sources under policy or risk appetite, but it should retain which sources and configuration supported each decision.

Must we screen shareholders, UBOs and directors?

It depends on the applicable rules, party roles and policy. OFAC's 50 Percent Rule concerns ownership; UK guidance includes separate control tests; EU analysis follows the relevant legal act. An AML UBO threshold or director role is not proof of sanctions status.

How often should suppliers be rescreened?

No universal interval is supported by the reviewed official guidance. Use applicable requirements, risk, meaningful-change events and policy-defined review points. Scheduled reviews can act as a backstop but should not delay a response to a material change.

What should procurement do after a potential match?

Preserve the supplier context, route the record under the organisation's hold and escalation procedure, and prevent uncontrolled progression where policy requires review. An authorised reviewer should compare identifiers and assess the applicable sanctions context before the relationship proceeds.

Can an unlisted supplier still be restricted?

Potentially. An applicable regime can extend restrictions through ownership, control or another legal mechanism even when the supplier's name is absent from a list. The tests and consequences differ by jurisdiction and programme, so current specialist analysis is required.

Make the checklist part of supplier approval

A workable supplier control connects procurement data, defined scope, relevant-party screening, alert investigation, authorised approval, evidence and later change. Checklynx can help teams screen suppliers and relevant related parties, keep supplied third-party and ownership context connected to controlled review, retain supporting evidence and decisions, and monitor configured records for meaningful changes.

See how Checklynx supports sanctions screening, controlled review and ongoing monitoring for supplier relationships.

Official sources

Footer

Supplier Sanctions Screening Checklist for Procurement