Articles

Sanctions Screening: Who Must Do It, and When It Has to Run

Sanctions screening is not an AML-only duty. Every business is barred from dealing with listed parties. What you check, how often, and where it belongs.

Sanctions Screening: Who Must Do It, and When It Has to Run

Introduction

Most compliance obligations come with a threshold. Screen the client if the transaction is over this amount, run enhanced checks if the risk rating says so, file a report if the pattern looks wrong.

Sanctions rules don't work like that. There's no threshold, no de minimis, no exemption for small companies. If a person or entity is on a sanctions list, you may not make funds or economic resources available to them. That's the whole rule, and it applies to a two-person consultancy exactly as it applies to a bank.

Which means a lot of businesses are subject to sanctions screening without knowing the phrase, having read it in an AML context and concluded it was somebody else's problem.

It Binds Everyone, Not Just Banks

This is the point that surprises people, so it's worth being precise about why.

Anti-money-laundering duties attach to a defined list of obliged entities: banks, payment firms, notaries, estate agents, accountants and so on. The line between the two rulebooks is the subject of KYC vs AML. If you're not on the list, most of the AML rulebook doesn't reach you.

Sanctions work through a different mechanism. In the European Union they arrive as regulations that apply directly in every member state, to every natural and legal person. There's no obliged-entity list to be outside of. The prohibition on making funds available binds the freelance designer invoicing a client the same way it binds a clearing house.

What that means in practice

You can't take payment from a listed party. You can't pay one. You can't employ one, supply one, or sign a contract that transfers anything of value to one.

And the consequence for getting it wrong isn't a supervisory letter. In most jurisdictions breaching sanctions is a criminal matter, with liability reaching individuals, not just the company.

Which Lists You Actually Check

There isn't one global list, which is the first thing that trips firms up.

United Nations lists are the baseline. Member states implement them, so they end up inside the regional lists rather than being checked separately.

European Union maintains a consolidated list of persons, groups and entities subject to financial sanctions. This is the operative one for any business inside the EU.

United States OFAC publishes the Specially Designated Nationals list. It matters far beyond America: dollar transactions, US-origin goods and US persons in your supply chain all pull you into its reach.

The United Kingdom keeps its own consolidated list through OFSI, which diverged from the EU list after Brexit and has to be checked separately if you trade there.

Add national lists on top where they exist. Sanctions screening sits alongside the PEP check rather than replacing it, and the two are usually run together on the same record: see politically exposed person. The practical answer for most firms is a screening service that maintains all of them, because the lists change on no fixed schedule and a manual process will miss updates.

Who Gets Screened

Wider than most firms assume, and this is where the gaps show up in audits.

  • Customers and clients, before the first transaction and on an ongoing basis
  • Suppliers and subcontractors, including the ones you inherited rather than chose
  • Business partners, joint venture parties, agents and distributors
  • Beneficial owners behind corporate counterparties, because a clean company can be controlled by a listed person
  • Employees and job applicants in some jurisdictions, on the same funds-availability logic: paying a salary is making funds available

The employee strand catches people off guard. In Germany it's an established practice with its own data-protection constraints, and it exists for the plain reason that a wage is a transfer of value like any other.

How Often It Has to Run

Screening once at onboarding is the single most common failure, and it fails for a reason that has nothing to do with your process. The lists change, not the client.

A counterparty who was clean when you signed can be designated three months later, and the moment they are, continuing to pay them becomes a breach. Nobody sends you a notification.

So the honest answer has three parts. Screen before you enter the relationship. Screen again whenever the lists update, which means an automated feed rather than a quarterly calendar reminder. And screen at each transaction of consequence, which in a contract business means at signature.

Worth saying plainly: this is why manual screening stops working past a handful of counterparties. Not because checking a name is hard, but because checking every name again every time a list moves is not something a person does reliably.

False Positives Are the Real Workload

Screening matches names, and names are terrible identifiers.

Transliteration alone produces a dozen spellings of the same Arabic or Cyrillic name. Common surnames generate hits constantly. A fuzzy-matching threshold tuned tight enough to avoid noise will eventually miss a real match, and tuned loose enough to catch everything will bury your team.

Two things make this manageable rather than miserable.

First, use more than the name. Date of birth, place of birth, nationality and address turn a possible match into a decided one, which is why identity verification and sanctions screening work better together than apart.

Second, write down the discounting decision. A dismissed hit with no recorded reasoning is indistinguishable from a hit nobody looked at, and a supervisor cannot tell them apart either.

Where the Check Belongs: The Signature

Sanctions screening usually lives in a system that has never met the contract it protects, and the gap between them is what fails under examination.

The pattern repeats across firms. Procurement screens the supplier and files a PDF. Sales signs the agreement through a separate tool. Six weeks later, when the counterparty is designated and somebody asks what was known on the day of signing, there are two records with no link and a gap in the middle that nobody can close retrospectively.

Running the screen in the signing flow removes the gap. The identity check, the sanctions and PEP result, and the signature land in one audit trail, anchored so the entry can't be rewritten afterwards. The question "what did you know when you committed?" has a single answer with a timestamp on it.

It also solves the recurrence problem quietly. If screening is part of how documents get signed, it reruns every time the counterparty signs something, which for most contract relationships is exactly the cadence you want.

Sanctions and PEP Screening Inside the Signing Flow

Document verification, liveness, and sanctions and PEP screening run in the same flow as the agreement, with one tamper-evident audit trail covering the check and the signature.

Four Mistakes That Cost Money

Assuming it's an AML duty. It isn't. AML reaches obliged entities, sanctions reach everyone, and a firm that skipped screening because it isn't a financial institution has misread which rulebook applies.

Screening the company but not the people behind it. A counterparty with a clean corporate name can be owned or controlled by a designated person, and the prohibition follows control.

Checking one list is the third. The EU, OFAC and UK lists diverge, and which ones bind you depends on your currency, your goods and your customers rather than your postcode.

Treating a dismissed hit as nothing happened. The discounting reasoning is the evidence that you ran a process at all. Without it, a clean screening history and no screening history look identical.

Sanctions lists change without a fixed schedule, and the regimes that bind a given business depend on its currency, goods, customers and group structure. Treat this article as the shape of the obligation and confirm your specific exposure with counsel before you build a procedure on it.

Conclusion

Sanctions screening is the rare compliance duty with no entry threshold. Every business is inside it, the lists move without warning, and the penalty for a miss is criminal rather than administrative.

The two failures worth designing against are opposite in shape. One is never starting, on the assumption that this is a banking topic. The other is starting once, at onboarding, and treating a six-month-old clean result as current.

If you fix one thing, make the check recur at the moment you commit to something. A screening result attached to the signature answers the only question that gets asked afterwards, and it answers it from one record instead of two.

Tags

#sanctions-screening#aml-compliance#compliance#client-onboarding#identity-verification
FAQ

Frequently Asked Questions

Answers to popular questions about Chaindoc and secure document workflows.

Sanctions screening is checking the people and organisations you deal with against official lists of parties subject to financial sanctions, so that you do not make funds or economic resources available to someone you are barred from dealing with. It covers customers, suppliers, business partners and, in some jurisdictions, employees.

No, and this is the most expensive misunderstanding in the area. Anti-money-laundering duties attach to a defined list of obliged entities. Sanctions arrive as regulations that apply directly to every person and company, with no threshold and no small-business exemption.

It depends on your exposure rather than your address. The European Union consolidated list is the operative one for businesses in the EU. The United States OFAC list reaches far beyond America through dollar transactions, US-origin goods and US persons in the chain. The United Kingdom maintains a separate consolidated list through OFSI that diverged after Brexit. Most firms use a screening service that maintains all of them, because the lists update on no fixed schedule.

Before the relationship starts, again whenever the lists change, and at each transaction of consequence. The lists move, not the counterparty, so a clean result from six months ago says nothing about today.

Do not dismiss it on the name alone. Use date of birth, nationality, place of birth and address to decide whether the match is real, and record the reasoning either way. A dismissed hit with no written justification is indistinguishable from a hit that nobody examined.

Related Content

More e-signature and blockchain guides

Practical guides on electronic signatures, blockchain audit trails, and secure document management — handpicked to build on what you just read.

View All Articles