Supplier sanctions screening can fail even when a name search takes place. Procurement may hold the supplier record, finance may see a new beneficiary, and compliance or legal may need ownership information. Unless those inputs reach the same control, a screening result can be operationally unusable.
This checklist gives procurement teams a control model for approval and later review. Procurement owns operational inputs, change capture and the approval gate. Compliance and legal determine applicable requirements, ownership or control analysis, and the authorised response.
For the broader process, use the guide to sanctions screening for suppliers and third parties. This page focuses on procurement's control record.
What a supplier sanctions screening checklist should control
Sanctions law and a supplier-screening policy are related, but they are not the same thing. Applicable regimes create restrictions and duties. Screening, data standards, review triggers, workflow holds and evidence fields are operational controls an organisation designs to help manage that exposure.
There is no single worldwide supplier-screening rule. Relevant restrictions depend on the parties, geography, activity, transaction and legal nexus. OFAC encourages risk-based controls and identifies counterparties and supply chains as risk inputs. UK guidance directs organisations to current legislation and regime-specific guidance.
A useful checklist makes sure the right facts reach the right decision-maker before the relationship progresses.
Supplier sanctions screening checklist at a glance
This is a control-design model, not a universal legal checklist. Adapt its gates, owners and evidence fields to the organisation's applicable requirements, supplier population and risk.
| Control | Procurement or operational action | Compliance or legal decision | Evidence retained |
|---|---|---|---|
| Supplier data | Capture the legal entity name, useful alternate names, registration identifier, jurisdiction, address and policy-required identifiers | Define the minimum information for reliable screening and how incomplete records are handled | Submitted data, source, collection date and record version |
| Scope | Identify the contracting party, relationship, countries, goods or services and relevant payment parties | Determine applicable regimes and which relationships enter the screening policy | Scope rationale and policy version applied |
| Timing | Run the required gate before policy-defined approval or commitment and after specified changes | Define risk- and policy-based triggers without inventing a universal interval | Trigger, screening time and review status |
| Ownership and control | Obtain or route available owner and controller information from approved sources | Apply the relevant jurisdictional test and decide whether more information is needed | Ownership chain, percentages or control facts, source and analysis |
| Related parties | Capture relevant owners, controllers, agents, intermediaries or beneficiaries when required | Define which roles matter to the applicable regime and risk | Party role and reason for inclusion |
| Screening result | Route a potential match rather than treating it as clearance or designation | Compare identifiers, source entry, programme and relationship context | Query, source result and matching attributes |
| Alert handling | Apply the organisation's defined hold and escalation state while required review is open | Resolve or escalate the match and determine the applicable response | Reviewer, reasoning, escalation and outcome |
| Approval | Progress the supplier only through the authorised workflow | Provide or obtain the required compliance or legal decision | Approver, date, conditions and case reference |
| Monitoring | Feed relevant supplier changes back into screening or review | Define event-led and policy-based reassessment rules | Trigger event, new review and outcome |
| Governance | Maintain control owners and escalation contacts | Own the legal framework, policy interpretation and specialist escalation | Policy version, responsibilities, testing and remediation |
An internal hold is not a legal asset freeze. Policy can pause supplier activation or payment during review. Whether law requires freezing, rejection, reporting or another response is a separate determination.
Collect supplier data and define scope before screening
Start with usable supplier identity data
A name alone is often insufficient. Capture the full legal entity name and, where relevant, trading names, registration number, jurisdiction, address and other policy-required identifiers. Record the source and collection date.
OFAC's potential-match guidance illustrates why this matters: a reviewer should compare the nature of the party and available identifiers, not decide from name similarity alone. Reliable identifiers also reduce the risk of screening the wrong entity within a corporate group.
An incomplete record creates a control question: is the information sufficient, or must procurement obtain more before approval? Policy should define who can accept an exception and what supports it.
Define the relationship, not only the contracting name
The record should identify what the organisation is approving: the contracting entity, goods or services, countries, agents, intermediaries, payment beneficiary and other policy-required parties.
This does not mean every party in every relationship must be screened. Compliance and legal should identify the applicable jurisdictions and restrictions; policy should then define the supplier and related-party population needed to operate the control. Procurement's job is to make the relationship visible and route material gaps or changes.
Retain which entity was screened, which connected parties entered scope, which policy applied and why.
Screen the supplier, ownership structure and relevant related parties
Screen the correct supplier entity
Screen the legal entity that will enter the relationship using the approved sources and configuration. If a group brand, local subsidiary and payment recipient are different parties, do not treat one clean result as evidence for all three. Capture their roles and apply the policy-defined checks to each relevant record.
Name screening is not a complete sanctions analysis. Restrictions can also concern programmes, sectors, activities, goods, services or geography.
Apply ownership and control rules by regime
An unlisted supplier can still be affected through ownership or control rules. The analysis is regime-specific.
Under OFAC's 50 Percent Rule, an entity is blocked when blocked persons own, directly or indirectly and in aggregate, 50% or more. The rule concerns ownership, not control alone. UK guidance includes broader control tests. EU analysis starts with the applicable legal act; one programme's guidance is not universal.
For a fuller comparison, see sanctions ownership and control. Beneficial-ownership information may be an important input, but an AML UBO threshold is not automatically the applicable sanctions test.
Procurement should route the ownership and control information required by policy. Compliance or legal determines which test applies and whether more research is necessary.
Include related parties for a defined reason
Owners, controllers, directors, agents, distributors, intermediaries, payment beneficiaries and other related parties can matter in different relationships. Avoid a blanket instruction to screen every person connected with every supplier. Instead, record the party's role and why it enters scope under the applicable control.
UBO and related-party context can keep supplied ownership percentages, control relationships, roles and source information connected to screening and review. It should not be described as automatically discovering every owner or registry change.
Investigate alerts before an authorised decision
A potential match is a question, not a verdict
Screening software can return a similar name when other identifiers do not align. OFAC advises comparing the complete sanctions entry with available information and does not prescribe a universal name-match score threshold. A score can support prioritisation; it is not proof that the supplier is sanctioned.
Procurement should not clear the alert independently or assume every alert requires a legal asset freeze. Its role is to preserve the supplier and relationship context, place the record into the policy-defined hold or escalation state, and prevent uncontrolled progression while the required review remains open.
Compare identity and relationship context
An investigation should establish:
- which supplier or connected party generated the alert;
- which names, aliases, entity type, addresses, jurisdictions, registration details and other identifiers align or conflict;
- which sanctions source, entry and programme produced the result;
- whether ownership, control, party role or transaction context changes the assessment;
- what material information remains missing; and
- who is authorised to resolve or escalate the case.
Retain the compared attributes and rationale. “False positive” alone is difficult to defend when a supplier record or sanctions entry later changes.
Route the legal response to authorised specialists
Identity resolution, legal applicability and operational response are separate decisions. A credible identity match may still require analysis of jurisdiction, programme, ownership or control, party role, transaction, licences, exceptions and reporting duties.
Policy should identify who can close a non-match, determine whether a restriction applies and authorise progression. Procurement controls the gate; compliance and legal own the sanctions disposition.
Sanctions screening software can connect screening results, supplied identifiers and relationship context to controlled cases, evidence and review. It does not determine whether the organisation may legally transact.
Decide when a supplier returns to screening or review
Authorities update designations, suppliers restructure, and new beneficiaries, intermediaries or jurisdictions enter relationships. Policy should define which events return a record to review.
Useful policy triggers can include:
- a relevant designation, sanctions-source or programme change;
- a change to the supplier's legal name, registration data, address or operating jurisdiction;
- a share transfer, new parent, controller change or restructuring;
- a new agent, distributor, intermediary, end user or other policy-relevant party;
- a new payment beneficiary, bank, account or payment destination;
- a material change to goods, services, route, destination or relationship; and
- a scheduled review used as a risk-based backstop.
These are control-design examples. OFAC supports risk-responsive assessments, while OFSI discusses review at appropriate times and monitoring where appropriate. Neither sets a universal interval.
The guide on when to rescreen suppliers for sanctions explains how to combine meaningful-change events with a policy-defined backstop. Ongoing monitoring can rescreen configured records and return relevant changes to review; the organisation still decides which records and changes enter scope.
Keep approvals, evidence and governance reviewable
A control should reconstruct its decision. OFAC describes escalation and recordkeeping as effective internal controls. OFSI considers whether ownership and control diligence was proportionate and evidenced.
A practical supplier record should retain:
- the supplier and connected parties considered, including each role;
- the operational and jurisdictional scope applied;
- submitted identifiers and their sources and dates;
- relevant ownership or control information and analysis;
- screening source, input, timestamp and result;
- alert attributes compared and missing information requested;
- reviewer, specialist escalation, rationale and outcome;
- authorised approver, date and any conditions; and
- later changes, reassessments and the current decision status.
Responsibilities should be explicit. Procurement maintains inputs, captures changes and operates the gate. Finance captures payment-party changes and respects holds. Compliance or legal defines the framework, oversees material alerts and determines the sanctions response. Control owners test the workflow.
Retention periods and reporting requirements vary by jurisdiction, sector and activity. The record above is an operational evidence model, not a universal statutory retention schedule.
Frequently asked questions
Is sanctions screening mandatory for every supplier?
Applicable laws create restrictions an organisation must manage, but the reviewed authorities do not require one identical process for every supplier worldwide. Determine the applicable jurisdictions, activities and exposure, then design a proportionate control.
Which sanctions lists should procurement use?
There is no safe answer of “all global lists.” Compliance or legal should identify the relevant jurisdictions, programmes and restrictions. The organisation may add other sources under policy or risk appetite, but it should retain which sources and configuration supported each decision.
Must we screen shareholders, UBOs and directors?
It depends on the applicable rules, party roles and policy. OFAC's 50 Percent Rule concerns ownership; UK guidance includes separate control tests; EU analysis follows the relevant legal act. An AML UBO threshold or director role is not proof of sanctions status.
How often should suppliers be rescreened?
No universal interval is supported by the reviewed official guidance. Use applicable requirements, risk, meaningful-change events and policy-defined review points. Scheduled reviews can act as a backstop but should not delay a response to a material change.
What should procurement do after a potential match?
Preserve the supplier context, route the record under the organisation's hold and escalation procedure, and prevent uncontrolled progression where policy requires review. An authorised reviewer should compare identifiers and assess the applicable sanctions context before the relationship proceeds.
Can an unlisted supplier still be restricted?
Potentially. An applicable regime can extend restrictions through ownership, control or another legal mechanism even when the supplier's name is absent from a list. The tests and consequences differ by jurisdiction and programme, so current specialist analysis is required.
Make the checklist part of supplier approval
A workable supplier control connects procurement data, defined scope, relevant-party screening, alert investigation, authorised approval, evidence and later change. Checklynx can help teams screen suppliers and relevant related parties, keep supplied third-party and ownership context connected to controlled review, retain supporting evidence and decisions, and monitor configured records for meaningful changes.
Official sources
- OFAC framework for sanctions compliance commitments
- OFAC FAQ 11: persons subject to OFAC regulations
- OFAC FAQ 5: evaluating a potential sanctions-list match
- OFAC FAQ 398: ownership and control under the 50 Percent Rule
- OFAC 50 Percent Rule FAQs
- OFAC name-matching FAQs
- UK financial sanctions general guidance
- OFSI financial sanctions enforcement and monetary penalties guidance
- Council Regulation (EU) No 269/2014, consolidated text
- European Commission FAQs on Russia-related asset freezes
- European Commission sanctions FAQs