
Sanctions screening means checking individuals, entities, and transactions against government-issued lists of sanctioned parties. Getting it wrong carries civil penalties and, in serious cases, criminal exposure.
An editorial note. This guide previously held up HSBC as a model of effective sanctions screening. That example has been removed. It was unsourced, and it sits badly against the public record: HSBC paid a $1.9 billion settlement to U.S. authorities in 2012 over sanctions and anti-money-laundering failures and operated under a deferred prosecution agreement with an independent monitor for years afterwards. Presenting it as a success story was wrong. What replaces it is a section on what actually distinguishes a screening programme that works, plus the one case study here that could be verified against a primary source.
Key Takeaways:
- Stay current with regulatory changes – lists and regimes change constantly, sometimes daily.
- Take a risk-based approach matched to your own exposure rather than copying a template.
- Use proven screening technology, and understand how its matching logic behaves.
- Review and audit the programme regularly, including the alerts you dismissed.
- Train the staff who handle alerts, not just the compliance team.
Major Sanctions Lists:
| List | Maintained by | Focus |
|---|---|---|
| OFAC (Office of Foreign Assets Control) List | US Department of the Treasury | Terrorism, narcotics trafficking, weapons proliferation, and country programmes |
| UN Sanctions List | United Nations | Threats to international peace and security |
| EU Sanctions List | European Union | Human rights violations, terrorism, and nuclear proliferation |
These lists are not interchangeable. A party designated by one authority may be absent from another, and screening only against OFAC is a common gap for businesses with European or UN-facing obligations.
Industries Requiring Screening:
- Financial Institutions
- Healthcare Providers
- Virtual Assets Service Providers
- Designated Non-Financial Businesses and Professions
- Exporters and Importers
Effective Screening Program Components:
- Clear policies and procedures
- Accurate customer data management
- Up-to-date sanctions lists and databases
- Screening technology you understand
- Employee training and awareness
Sanctions Lists and Regimes
Keeping Up with List Changes
Sanctions lists change frequently, and additions take effect immediately. Ways to keep current:
- Monitor official sources directly: OFAC, the EU consolidated list, the UN Security Council list, and the UK’s OFSI list all publish updates on their own sites.
- Subscribe to update feeds: several providers push list changes in near real time, which matters because a designation that lands on a Friday afternoon is still binding on Friday afternoon.
- Automate screening: software that refreshes lists automatically removes the manual step where updates get missed.
Also screen your existing book, not only new customers. A designation applies to relationships you already have, and rescreening the back book on every list update is what catches those.
Types of Sanctions
Comprehensive, Sectoral, and Targeted Sanctions
| Type of Sanction | Description | Examples |
|---|---|---|
| Comprehensive Sanctions | Broad restrictions on trade and financial transactions with a country or territory | Country programmes such as those covering North Korea, Iran and Cuba |
| Sectoral Sanctions | Restrictions targeting specific industries within a country | Russian financial, energy and defence sectors |
| Targeted Sanctions | Measures aimed at named individuals, entities or organisations | Asset freezes, travel bans, transaction restrictions |
Country programmes are amended regularly – restrictions get added, eased, and occasionally lifted – so check the current scope of any programme against the issuing authority rather than a summary like this one.
The type matters operationally. Comprehensive programmes are largely a jurisdiction question. Sectoral programmes require knowing what a counterparty does, not just who they are. Targeted designations require name matching, and bring the ownership question with them: in many regimes an entity owned 50% or more by designated parties is itself restricted even though it appears on no list. That indirect exposure is where most screening programmes are weakest.
Industries Requiring Sanctions Screening
| Industry | Reason for Screening |
|---|---|
| Financial Institutions | Prevent money laundering, terrorist financing, and prohibited transactions |
| Healthcare Providers | Confirm employees, contractors, vendors and physicians are eligible to participate in federal healthcare programs |
| Virtual Assets Service Providers | Prevent transactions with sanctioned individuals, entities, or jurisdictions |
| Designated Non-Financial Businesses and Professions | Prevent money laundering through property, legal and accounting channels |
| Exporters and Importers | Comply with export control regulations and end-user restrictions |
Software and services companies belong on this list too, as the Microsoft case below shows. Sanctions exposure follows your end users, not your sector classification.
Setting Up a Screening Program
Key Program Components
| Component | Description |
|---|---|
| Clear policies and procedures | Written policies setting out the screening process, roles, and who decides on a match. |
| Data management | Accurate customer data – names, addresses, identification numbers, and dates of birth where available. |
| Sanctions lists and databases | Current lists from every authority whose rules apply to you, not only OFAC. |
| Screening technology | Software that automates matching and logs every decision for audit. |
| Training and awareness | Training for the people who clear alerts, since that is where errors have consequences. |
Using Technology for Screening
Screening software should:
- Automate screening: check large volumes of customer and transaction data against multiple lists.
- Manage false positives: use fuzzy matching that you can tune, with the threshold documented and justified.
- Produce audit evidence: a record of what was screened, when, against which list version, and who cleared each alert.
- Integrate: connect with CRM and AML systems so screening happens at onboarding and at payment, not as a separate exercise.
That third point is the one examiners test. A programme that produces the right answer but cannot evidence how it got there is a finding waiting to happen.
Screening Challenges
Managing False Positives and Negatives
False positives flag legitimate parties; false negatives miss sanctioned ones. Tuning to reduce one increases the other, which is the central trade-off in this discipline and cannot be engineered away.
Causes
| Cause | Description |
|---|---|
| Broad matching criteria | Loose thresholds generate large alert volumes that overwhelm review capacity. |
| Poor data quality | Incomplete or badly structured customer data causes both misses and spurious alerts. |
| Name matching complexity | Transliteration, cultural naming conventions, spelling variants and common names all defeat naive matching. |
Strategies
| Strategy | Description |
|---|---|
| Improve data quality | Capture dates of birth, nationality and identifiers at onboarding – these are what let you discount a common-name match confidently. |
| Tune thresholds deliberately | Document why a threshold was set where it was, and test it against known-positive samples. |
| Use better matching technology | Modern matching handles transliteration and phonetic variation. Ask vendors to run your own data, not their demo set. |
Do not tune for alert volume alone. A programme that reduced alerts by tightening thresholds without testing recall has traded a workload problem for a compliance one.
Keeping Up with Regulatory Changes
| Strategy | Description |
|---|---|
| Monitor regulatory bodies | Track updates from every authority with jurisdiction over your business. |
| Automate list updates | Automatic refresh removes the manual gap between publication and application. |
| Review and audit | Periodic independent testing of the screening engine, including sample known-positive cases. |
Best Practices for Screening
Regular Reviews and Audits
| Review Area | Description |
|---|---|
| Screening Criteria | Test matching thresholds against known-positive cases, not just live traffic |
| Customer Data | Assess completeness of the identifiers screening depends on |
| False Positives/Negatives | Sample cleared alerts to confirm they were cleared correctly |
| Sanctions Lists | Confirm every applicable list is loaded and current |
| Training and Awareness | Check the people clearing alerts have current training |
Sampling cleared alerts is the review step most often skipped and the most revealing. A backlog cleared quickly under pressure is where false negatives hide.
Staff Training and Awareness
| Training Area | Description |
|---|---|
| Sanctions Regulations | The regimes that apply to your business specifically |
| Screening Technology | How the matching works and what its limits are |
| Identifying Potential Matches | How to escalate rather than clear when uncertain |
| Awareness Programs | Refreshers tied to regime changes rather than the calendar |
| Culture of Compliance | Escalation without penalty for the person raising it |
What a Working Programme Looks Like
As noted at the top, the success story that used to occupy this section named a bank whose sanctions record is a cautionary tale rather than a model. Rather than substitute another company we cannot verify, here is what separates programmes that hold up from those that fail, drawn from the pattern of published enforcement actions.
The gap is usually indirect exposure, not direct. Very few companies knowingly transact with a designated party. Penalties overwhelmingly arise from resellers, distributors, foreign subsidiaries, and end users several steps removed from the contracting entity. If your screening covers only your direct counterparty, it covers the easy case.
Ownership rules catch people out. An entity that is majority-owned by designated persons is restricted in many regimes without appearing on any list. Screening names against a list will not find it. Ownership data will.
Voluntary self-disclosure changes the outcome materially. OFAC’s penalty framework treats voluntary disclosure as a substantial mitigating factor. Finding a problem yourself and reporting it is worth a great deal more than a clean-looking file.
Screening at onboarding only is not enough. Designations happen after onboarding. Rescreening the existing customer base on every list update is what turns a point-in-time check into a control.
A Verified Case: Microsoft, 2023
On April 6, 2023, OFAC announced a settlement with Microsoft Corporation for $2,980,265.86. The action appears in OFAC’s 2023 enforcement information, with the full enforcement release available from the same page.
The relevant lesson for anyone selling software or services: the exposure came through end users and downstream distribution rather than through a direct relationship with a designated party. Screening your direct customers does not tell you who is ultimately using the product. If you sell through resellers, that gap is your largest sanctions risk, and it is not addressed by any amount of tuning on your onboarding screen.
Conclusion
| Key Takeaway | Description |
|---|---|
| Stay current with regulatory changes | Lists and regimes change constantly; monitor the authorities that have jurisdiction over you. |
| Take a risk-based approach | Match the programme to your actual exposure – geography, channel, and customer type. |
| Use technology you understand | Know how the matching works and be able to justify your thresholds. |
| Review and audit | Test against known-positive cases and sample the alerts you cleared. |
| Train the people who decide | Alert reviewers make the decisions that matter. Train them accordingly. |
And screen past the first hop. The published enforcement record is largely a record of companies that screened their customers and not their customers’ customers.
FAQs
How can you ensure sanctions compliance?
| Best Practice | Description |
|---|---|
| Use reliable screening tools | Load every list that applies to you and keep them current automatically |
| Take a risk-based approach | Size the programme to your exposure, and document why |
| Rescreen continuously | Check the existing book on every list update, not only at onboarding |
| Build screening into the process | Screen at onboarding and at payment, inside the workflow rather than beside it |
| Train and refresh | Focus on the staff who clear alerts and on the regimes that apply to you |
One thing no programme can promise is that you will never have a violation. What it can do is make one less likely, catch it faster when it happens, and put you in a position to disclose it – which, under OFAC’s framework, is the difference that most affects the penalty.
More on this topic
Browse all 79 articles on Security & Compliance.