BizBot

Sanctions Screening Compliance Guide 2026

Sanctions Screening Compliance Guide 2024

Sanctions screening means checking individuals, entities, and transactions against government-issued lists of sanctioned parties. Getting it wrong carries civil penalties and, in serious cases, criminal exposure.

An editorial note. This guide previously held up HSBC as a model of effective sanctions screening. That example has been removed. It was unsourced, and it sits badly against the public record: HSBC paid a $1.9 billion settlement to U.S. authorities in 2012 over sanctions and anti-money-laundering failures and operated under a deferred prosecution agreement with an independent monitor for years afterwards. Presenting it as a success story was wrong. What replaces it is a section on what actually distinguishes a screening programme that works, plus the one case study here that could be verified against a primary source.

Key Takeaways:

  • Stay current with regulatory changes – lists and regimes change constantly, sometimes daily.
  • Take a risk-based approach matched to your own exposure rather than copying a template.
  • Use proven screening technology, and understand how its matching logic behaves.
  • Review and audit the programme regularly, including the alerts you dismissed.
  • Train the staff who handle alerts, not just the compliance team.

Major Sanctions Lists:

List Maintained by Focus
OFAC (Office of Foreign Assets Control) List US Department of the Treasury Terrorism, narcotics trafficking, weapons proliferation, and country programmes
UN Sanctions List United Nations Threats to international peace and security
EU Sanctions List European Union Human rights violations, terrorism, and nuclear proliferation

These lists are not interchangeable. A party designated by one authority may be absent from another, and screening only against OFAC is a common gap for businesses with European or UN-facing obligations.

Industries Requiring Screening:

  • Financial Institutions
  • Healthcare Providers
  • Virtual Assets Service Providers
  • Designated Non-Financial Businesses and Professions
  • Exporters and Importers

Effective Screening Program Components:

  • Clear policies and procedures
  • Accurate customer data management
  • Up-to-date sanctions lists and databases
  • Screening technology you understand
  • Employee training and awareness

Sanctions Lists and Regimes

Keeping Up with List Changes

Sanctions lists change frequently, and additions take effect immediately. Ways to keep current:

  • Monitor official sources directly: OFAC, the EU consolidated list, the UN Security Council list, and the UK’s OFSI list all publish updates on their own sites.
  • Subscribe to update feeds: several providers push list changes in near real time, which matters because a designation that lands on a Friday afternoon is still binding on Friday afternoon.
  • Automate screening: software that refreshes lists automatically removes the manual step where updates get missed.

Also screen your existing book, not only new customers. A designation applies to relationships you already have, and rescreening the back book on every list update is what catches those.

Types of Sanctions

Comprehensive, Sectoral, and Targeted Sanctions

Type of Sanction Description Examples
Comprehensive Sanctions Broad restrictions on trade and financial transactions with a country or territory Country programmes such as those covering North Korea, Iran and Cuba
Sectoral Sanctions Restrictions targeting specific industries within a country Russian financial, energy and defence sectors
Targeted Sanctions Measures aimed at named individuals, entities or organisations Asset freezes, travel bans, transaction restrictions

Country programmes are amended regularly – restrictions get added, eased, and occasionally lifted – so check the current scope of any programme against the issuing authority rather than a summary like this one.

The type matters operationally. Comprehensive programmes are largely a jurisdiction question. Sectoral programmes require knowing what a counterparty does, not just who they are. Targeted designations require name matching, and bring the ownership question with them: in many regimes an entity owned 50% or more by designated parties is itself restricted even though it appears on no list. That indirect exposure is where most screening programmes are weakest.

Industries Requiring Sanctions Screening

Industry Reason for Screening
Financial Institutions Prevent money laundering, terrorist financing, and prohibited transactions
Healthcare Providers Confirm employees, contractors, vendors and physicians are eligible to participate in federal healthcare programs
Virtual Assets Service Providers Prevent transactions with sanctioned individuals, entities, or jurisdictions
Designated Non-Financial Businesses and Professions Prevent money laundering through property, legal and accounting channels
Exporters and Importers Comply with export control regulations and end-user restrictions

Software and services companies belong on this list too, as the Microsoft case below shows. Sanctions exposure follows your end users, not your sector classification.

Setting Up a Screening Program

Key Program Components

Component Description
Clear policies and procedures Written policies setting out the screening process, roles, and who decides on a match.
Data management Accurate customer data – names, addresses, identification numbers, and dates of birth where available.
Sanctions lists and databases Current lists from every authority whose rules apply to you, not only OFAC.
Screening technology Software that automates matching and logs every decision for audit.
Training and awareness Training for the people who clear alerts, since that is where errors have consequences.

Using Technology for Screening

Screening software should:

  • Automate screening: check large volumes of customer and transaction data against multiple lists.
  • Manage false positives: use fuzzy matching that you can tune, with the threshold documented and justified.
  • Produce audit evidence: a record of what was screened, when, against which list version, and who cleared each alert.
  • Integrate: connect with CRM and AML systems so screening happens at onboarding and at payment, not as a separate exercise.

That third point is the one examiners test. A programme that produces the right answer but cannot evidence how it got there is a finding waiting to happen.

Screening Challenges

Managing False Positives and Negatives

False positives flag legitimate parties; false negatives miss sanctioned ones. Tuning to reduce one increases the other, which is the central trade-off in this discipline and cannot be engineered away.

Causes

Cause Description
Broad matching criteria Loose thresholds generate large alert volumes that overwhelm review capacity.
Poor data quality Incomplete or badly structured customer data causes both misses and spurious alerts.
Name matching complexity Transliteration, cultural naming conventions, spelling variants and common names all defeat naive matching.

Strategies

Strategy Description
Improve data quality Capture dates of birth, nationality and identifiers at onboarding – these are what let you discount a common-name match confidently.
Tune thresholds deliberately Document why a threshold was set where it was, and test it against known-positive samples.
Use better matching technology Modern matching handles transliteration and phonetic variation. Ask vendors to run your own data, not their demo set.

Do not tune for alert volume alone. A programme that reduced alerts by tightening thresholds without testing recall has traded a workload problem for a compliance one.

Keeping Up with Regulatory Changes

Strategy Description
Monitor regulatory bodies Track updates from every authority with jurisdiction over your business.
Automate list updates Automatic refresh removes the manual gap between publication and application.
Review and audit Periodic independent testing of the screening engine, including sample known-positive cases.

Best Practices for Screening

Regular Reviews and Audits

Review Area Description
Screening Criteria Test matching thresholds against known-positive cases, not just live traffic
Customer Data Assess completeness of the identifiers screening depends on
False Positives/Negatives Sample cleared alerts to confirm they were cleared correctly
Sanctions Lists Confirm every applicable list is loaded and current
Training and Awareness Check the people clearing alerts have current training

Sampling cleared alerts is the review step most often skipped and the most revealing. A backlog cleared quickly under pressure is where false negatives hide.

Staff Training and Awareness

Training Area Description
Sanctions Regulations The regimes that apply to your business specifically
Screening Technology How the matching works and what its limits are
Identifying Potential Matches How to escalate rather than clear when uncertain
Awareness Programs Refreshers tied to regime changes rather than the calendar
Culture of Compliance Escalation without penalty for the person raising it

What a Working Programme Looks Like

As noted at the top, the success story that used to occupy this section named a bank whose sanctions record is a cautionary tale rather than a model. Rather than substitute another company we cannot verify, here is what separates programmes that hold up from those that fail, drawn from the pattern of published enforcement actions.

The gap is usually indirect exposure, not direct. Very few companies knowingly transact with a designated party. Penalties overwhelmingly arise from resellers, distributors, foreign subsidiaries, and end users several steps removed from the contracting entity. If your screening covers only your direct counterparty, it covers the easy case.

Ownership rules catch people out. An entity that is majority-owned by designated persons is restricted in many regimes without appearing on any list. Screening names against a list will not find it. Ownership data will.

Voluntary self-disclosure changes the outcome materially. OFAC’s penalty framework treats voluntary disclosure as a substantial mitigating factor. Finding a problem yourself and reporting it is worth a great deal more than a clean-looking file.

Screening at onboarding only is not enough. Designations happen after onboarding. Rescreening the existing customer base on every list update is what turns a point-in-time check into a control.

A Verified Case: Microsoft, 2023

On April 6, 2023, OFAC announced a settlement with Microsoft Corporation for $2,980,265.86. The action appears in OFAC’s 2023 enforcement information, with the full enforcement release available from the same page.

The relevant lesson for anyone selling software or services: the exposure came through end users and downstream distribution rather than through a direct relationship with a designated party. Screening your direct customers does not tell you who is ultimately using the product. If you sell through resellers, that gap is your largest sanctions risk, and it is not addressed by any amount of tuning on your onboarding screen.

Conclusion

Key Takeaway Description
Stay current with regulatory changes Lists and regimes change constantly; monitor the authorities that have jurisdiction over you.
Take a risk-based approach Match the programme to your actual exposure – geography, channel, and customer type.
Use technology you understand Know how the matching works and be able to justify your thresholds.
Review and audit Test against known-positive cases and sample the alerts you cleared.
Train the people who decide Alert reviewers make the decisions that matter. Train them accordingly.

And screen past the first hop. The published enforcement record is largely a record of companies that screened their customers and not their customers’ customers.

FAQs

How can you ensure sanctions compliance?

Best Practice Description
Use reliable screening tools Load every list that applies to you and keep them current automatically
Take a risk-based approach Size the programme to your exposure, and document why
Rescreen continuously Check the existing book on every list update, not only at onboarding
Build screening into the process Screen at onboarding and at payment, inside the workflow rather than beside it
Train and refresh Focus on the staff who clear alerts and on the regimes that apply to you

One thing no programme can promise is that you will never have a violation. What it can do is make one less likely, catch it faster when it happens, and put you in a position to disclose it – which, under OFAC’s framework, is the difference that most affects the penalty.