Sanctions screening is the process a firm uses to check its customers, transactions and counterparties against official sanctions lists, so it doesn’t do business with a person, company or country its government has banned. It runs at onboarding, on every relevant payment, and continuously as the lists change.
Get it wrong and the penalties are among the largest in finance. In 2014, BNP Paribas pleaded guilty and paid $8.9 billion, the biggest sanctions-related settlement ever, after it systematically stripped the names of sanctioned parties out of payment messages to slip them past exactly this kind of screening. The lesson regulators drew was simple: sanctions screening isn’t a formality, and defeating it is a crime.
What is sanctions screening, in practice?
Sanctions are restrictions a government or international body places on named people, entities, vessels or whole countries, usually to pressure a regime or disrupt terrorism, proliferation or organised crime. Sanctions screening is how a regulated firm makes sure it stays on the right side of them.
The check compares the names and details a firm holds, a customer, a company’s directors and owners, the parties to a payment, against the relevant lists. A match, or a close-enough match, stops the transaction or the onboarding until a human decides whether it is real. Most of the work sits in that decision, catching the true hits without stopping thousands of legitimate customers along the way.
Which lists does sanctions screening check against?
There is no single global list. A firm screens against every regime that applies to it, and a bank operating internationally applies several at once.
| Body | List | Applies to |
|---|---|---|
| United States | OFAC Specially Designated Nationals (SDN) and consolidated lists | Anyone touching the US financial system or US dollars |
| United Nations | UN Security Council Consolidated List | Member states worldwide |
| European Union | EU Consolidated Financial Sanctions List | EU persons and entities |
| United Kingdom | OFSI (HM Treasury) consolidated list | UK persons and entities |
| United Arab Emirates | The UAE Local Terrorist List and UN-linked lists, overseen by the Executive Office for AML/CTF | UAE-licensed firms |
The US OFAC lists carry the most weight, because their reach follows the US dollar and the US financial system, which most cross-border payments touch. That is why a firm with no US presence still screens against OFAC.
The types of sanctions a screening programme has to catch
Sanctions don’t all take the same shape, and a screening engine handles some far better than others.
Comprehensive sanctions target a whole country or regime, as with Iran, North Korea, Syria and Cuba, where dealing with almost anyone in the jurisdiction is restricted. Targeted sanctions name specific people, companies or vessels, and these are what a name-matching engine is built for.
Sectoral sanctions restrict particular activities or industries, such as parts of Russia’s energy, defence and financial sectors, rather than named parties. Secondary sanctions reach beyond the sanctioning country’s own persons and threaten to penalise a foreign firm that deals with a sanctioned party, which is another reason a bank outside the US still screens against OFAC.
The distinction matters because a matching engine screens names well and screens everything else badly. Comprehensive and sectoral sanctions arrive as narrative rules, not clean lists, so a firm has to translate them into its own screening logic and monitoring on top of the name lists. The ones that cause firms the most trouble are usually the sanctions that don’t sit neatly on a list at all.
Who has to run sanctions screening?
Sanctions obligations reach far wider than banks. Any business that could move value to a sanctioned party is exposed, which now covers payment firms and fintechs, money-service businesses, insurers, law and accountancy firms, crypto exchanges, and increasingly ordinary companies with international suppliers and customers.
Two features make the reach so broad. Sanctions are strict-liability in most regimes, so a breach can be an offence even without intent, which is why firms screen rather than rely on judgement. And US sanctions in particular follow the dollar and the US financial system, so a firm with no American office is still exposed the moment a payment touches a correspondent bank in New York. In practice, if you take payments across borders, sanctions screening applies to you.
How does the sanctions screening process work?
The sanctions screening process happens in two main places, and the better programmes run both continuously rather than as a one-off.
The first is name screening. When a customer is onboarded, or a company’s owners and directors are checked, their details are matched against the lists. Because names are messy across languages, spellings and transliterations, the matching is fuzzy rather than exact: it flags close variants, reversed name orders and phonetic near-matches, which is what makes a sanctioned “Vladimir” hard to hide as “Wladimir”. The same screen usually runs against politically exposed person and adverse-media data at the same time, because those risks overlap with sanctions risk.
The second is transaction, or payment, screening. Every payment is checked against the lists before it settles, looking at the sender, the receiver and any intermediary. Real-time sanctions screening is what stops a live payment to a sanctioned party. Batch screening re-runs the whole customer base whenever the lists change, catching a customer who was clean yesterday and listed today.
An alert that survives review is not just a risk call. Depending on the regime, the firm may have to freeze the funds or block the payment and report it, for example a blocked-property report to OFAC. A confirmed sanctions hit is a legal event.
Underneath all of it sits list management. Sanctions lists change constantly, sometimes several times a week, so a screening programme is only as current as its last update. A firm running week-old lists is checking against rules that have already moved on.
Why a name check isn’t enough: the OFAC 50% rule
Screening a name against the lists is necessary but not enough. A sanctioned party can hide behind a company that isn’t itself on any list, and that is what firms tend to miss.
Under OFAC’s 50 percent rule, any entity owned 50% or more, directly or indirectly, by one or more sanctioned persons is itself blocked, even though its name never appears on the SDN list. OFAC doesn’t publish a list of these owned entities. It expects firms to work out the ownership themselves.
That turns sanctions screening into an ownership problem as much as a name-matching one, which is why sanctions screening and Know Your Business run together. To apply the rule you have to trace who really owns a counterparty, the same beneficial-ownership work that KYB does.
A firm that screens the company name, finds no match and stops there can still be dealing with a blocked entity through the back door of its ownership. This is exactly where sanctioned Russian individuals hid after 2022, behind companies that never appeared on a list. OFAC has since gone further, signalling that the 50% threshold is a minimum for diligence rather than the limit of it.
The false-positive problem
Sanctions screening’s hardest operational problem isn’t missing true hits. It’s the flood of false ones.
Fuzzy matching, set loose enough to catch a disguised name, also flags thousands of innocent customers who happen to share a name with, or resemble, someone on a list. A common name can generate hundreds of alerts, almost all of them noise. Every alert has to be reviewed by a person, so a badly tuned system buries its analysts and slows every payment while they dig, and a system tuned too loose to avoid that risks waving a real hit through.
Getting the balance right, high enough sensitivity to catch evasion, tight enough to keep the alert volume workable, is the central craft of running a screening programme. It is why firms invest heavily in the matching model and in ways to clear the obvious false positives automatically, so analysts spend their time on the alerts that might be real.
How sanctions get evaded, and why screening fails
The BNP Paribas case is the clearest lesson in how screening is beaten. The bank didn’t get caught out by a match it narrowly missed. It deliberately stripped the names of Sudanese, Iranian and Cuban parties out of payment messages so the screening filters at US banks had nothing to catch. Take away the data the screen reads, and the screen passes everything.
That is the pattern behind most sanctions evasion. Payments get routed through intermediaries and shell companies to break the link to the sanctioned party, identifying information is stripped or altered, ownership is buried under enough layers to make the 50% rule hard to apply, and goods are trans-shipped through a third country to hide where they are really going.
None of it is caught by matching a clean name against a list, which is why screening has to sit alongside transaction monitoring and beneficial-ownership checks rather than stand on its own.
What sanctions screening software has to do
Because names, lists and evasion are all moving, sanctions screening software has to do more than match strings. Good tools maintain and update the lists automatically, run fuzzy matching that catches spelling and transliteration variants without flooding analysts, screen both customers and live payments, and tie into ownership data so the 50% rule can be applied rather than ignored. The test of a good one is how few of its alerts turn out to be wrong, and how few real hits it misses.
Where sanctions screening sits in financial crime compliance
Sanctions screening is one control inside a wider anti-money-laundering programme, and it is easy to confuse with the others. KYC and KYB verify who a customer is and who owns them. Transaction monitoring watches for suspicious patterns over time. Sanctions screening asks a narrower question: is this party, or its owner, someone the firm is legally banned from dealing with right now?
The difference is consequence. A suspicious pattern gets investigated and maybe reported. A sanctions hit stops the transaction cold and can require frozen funds and a filing the same day. Sanctions screening also runs against a moving external list rather than the firm’s own risk model, so it changes the instant a government adds a name. The controls feed each other: the ownership data from KYB is what makes the 50% rule workable, and transaction monitoring is what catches the evasion a static name-screen misses.
Sanctions screening after 2022: the Russia effect
Sanctions screening changed scale after Russia’s 2022 invasion of Ukraine. The US, EU, UK and allies imposed the largest and fastest wave of designations in modern history, adding thousands of individuals, companies, banks and vessels, and layering on sectoral sanctions and export controls that go well beyond a simple name list.
Two things made this harder for screening specifically. The volume and pace of new designations meant lists changed almost daily, straining the update process. And the heavy use of complex ownership structures by sanctioned Russian individuals pushed the 50% rule to the centre of compliance, because many of the entities that matter aren’t named on any list and have to be found through their ownership. A firm that treated Russia sanctions as a name-matching exercise missed most of the risk.
The practical effect was a step change in workload. Compliance teams had to re-screen entire books against lists that moved almost daily, chase ownership through opaque structures, and watch for evasion routed through third countries. After 2022 sanctions screening stopped being a background control and became a front-line one, and it has stayed that way.
Sanctions screening in the UAE and the Gulf
The UAE offers a live example of how central sanctions screening has become. In March 2022 the Financial Action Task Force placed the UAE on its “grey list” of jurisdictions under increased monitoring, citing weaknesses in its financial-crime controls. Implementing targeted financial sanctions properly was one of the reforms it had to make.
The UAE built the machinery, including an Executive Office for AML and CTF that oversees sanctions implementation, and pushed firms to screen against UN-linked and local lists and to understand sanctions-evasion risk. In February 2024 the FATF removed the UAE from the grey list. For a compliance team in the region, the direction is set: sanctions screening is now an examination priority, and a firm licensed in the UAE screens against its own local list on top of the international regimes.
The challenges that persist
Beyond false positives, the same problems keep coming back. Lists change faster than many systems can update, so staying current is a constant battle. Ownership is deliberately hidden, so the 50% rule forces diligence a name check alone cannot provide. And more and more sanctions arrive as narrative rules and sectoral restrictions rather than clean name lists, which a matching engine cannot screen for on its own.
None of that makes screening optional. It means the programme needs constant upkeep rather than a one-off setup.
FAQs
What is sanctions screening in simple terms?
It is checking your customers, their owners and your payments against official sanctions lists, so your firm doesn’t deal with a person, company or country it is banned from dealing with. It runs at onboarding, on relevant payments, and continuously as lists change.
What lists does sanctions screening use?
The main ones are the US OFAC SDN and consolidated lists, the UN Security Council Consolidated List, the EU Consolidated Financial Sanctions List, and the UK’s OFSI list, plus national lists such as the UAE’s. OFAC’s lists carry the widest reach because they follow the US dollar.
What is the OFAC 50% rule?
Any entity owned 50% or more by one or more sanctioned persons is itself blocked, even if it isn’t named on a list. OFAC doesn’t publish these entities, so firms must trace ownership themselves, which is why sanctions screening and beneficial-ownership checks go together.
What is the difference between real-time and batch screening?
Real-time screening checks a payment against the lists before it settles, stopping a live transaction to a sanctioned party. Batch screening re-runs the whole customer base when the lists change, catching a customer who becomes sanctioned after onboarding.
Why does sanctions screening produce so many false positives?
Fuzzy matching is set to catch disguised and misspelt names, so it also flags innocent people who share a name with someone on a list. Managing that alert volume without missing a real hit is the core challenge of running a screening programme.
Who has to comply with sanctions screening?
Any business that could move value to a sanctioned party, including banks, payment firms and fintechs, money-service businesses, insurers, crypto exchanges and companies with international suppliers. US sanctions follow the dollar, so a firm outside the US is still exposed once a payment touches the US financial system.
Is sanctions screening a legal requirement?
Yes. In most regimes sanctions breaches are strict-liability offences, meaning a firm can be penalised even without intent to break the rules. That is why regulated firms screen systematically rather than relying on judgement, and why a confirmed hit triggers freezing and reporting obligations.
Next read
The 50% rule turns sanctions screening into an ownership question, which is the work Know Your Business checks do. For that and the rest of our regtech coverage, see the Compliance hub.