Why sanctions screening can't wait
Sanctions duties are strict-liability and apply to everyone — not only financial institutions.
Executive summary
Sanctions are prohibitions, not just AML risk factors.Continuous screening matters because lists change.Ownership and control can matter even without a direct name match.Unlike much of the AML framework, sanctions obligations are absolute: you may not do business with a listed person or entity, regardless of intent or risk appetite. They apply to every business, and breaches carry serious penalties.
The hard part is that lists change constantly and the official EU list can lag the underlying legal designation by days. Screening once at onboarding is not enough — you must re-screen when the lists move.
The defensible approach is continuous: re-check your client base against each list update, screen on every change, and keep dated proof of each check. That evidence is what demonstrates you met the duty even when the answer was 'no match'.
Who this applies to
This guide is for any office that accepts clients, counterparties, sellers, buyers, beneficial owners or payors and must avoid dealing with sanctioned persons or controlled entities.
- Clients, UBOs and directors
- Buyers, sellers and counterparties
- Payors, beneficiaries and third-party funders
- Companies owned or controlled by listed persons
- Existing clients when lists update
Legal and supervisory context
Sanctions screening is different from ordinary risk scoring. If a legal prohibition applies, the office cannot choose to accept the risk. The question is whether there is a true match, whether ownership/control rules capture the entity, and what freeze or reporting obligations follow.
Because sanctions lists can change frequently, the defensible position is dated continuous screening. A clean result is still evidence: it proves the office checked at the relevant time.
What the office must actually do
The office should screen before acting, resolve matches quickly, stop unsafe activity where a true match exists, and keep evidence of both matches and clean results.
- Screen names with aliases, transliteration and dates of birth where available.
- Screen UBOs and controllers, not just the client entity.
- Re-screen on list updates and material file changes.
- Escalate possible matches to a named reviewer.
- Record false-positive reasoning.
- Keep dated proof of the list version used.
What good evidence looks like
Good evidence shows the list source, list version or capture date, matching fields, reviewer, decision and any freeze, refusal or report action.
Common mistakes supervisors find
- Only screening the contracting entity.
- Not checking beneficial owners or controllers.
- Treating all fuzzy matches as false positives without a reason.
- Not keeping the list version or date.
- Failing to re-screen existing clients.
Practical checklist
- Screen client, UBOs and counterparties.
- Review ownership/control concerns.
- Resolve false positives with reasons.
- Escalate possible true matches.
- Record list source and date.
- Repeat screening when data changes.
- Keep evidence in the client file.
- Runs EU FSF and OpenSanctions-backed screening where configured.
- Stores structured match comparisons.
- Creates review tasks for possible hits.
- Re-screens after list updates.
- Keeps clean and hit evidence in the ledger.
FAQ
Is sanctions screening only for banks?
No. Sanctions prohibitions apply broadly and non-financial offices must avoid prohibited dealings too.
Does a clean screening result matter?
Yes. It is dated evidence that the office checked and found no match at that time.
What if only the UBO is listed?
Ownership and control rules can still make the relationship prohibited or require escalation, even if the company name is not directly listed.
Official references
From knowledge to compliance
Reading is a start. Sceau turns these obligations into a workflow that runs itself and proves itself.
Book a demo