What is Sanctions Screening?
Sanctions screening is the process of checking individuals, entities, and transactions against official government and international watchlists to ensure that no business is conducted with restricted parties. It is a legal obligation for banks, payment firms, fintechs, and a wide range of other regulated businesses and, as enforcement actions make clear, the cost of getting it wrong is severe.
Key Takeaways
- Sanctions screening checks customers and transactions against official government and international watchlists.
- It is a legal requirement for banks, fintechs, and other regulated businesses under AML/CFT frameworks.
- Sanctions lists can be updated daily. Ongoing monitoring is as important as onboarding checks.
- AI-powered fuzzy matching reduces false positives while catching name variations, aliases, and transliterations.
- Non-compliance can result in fines running into billions, criminal penalties, and reputational damage.
- The EU’s new Anti-Money Laundering Regulation (AMLR), coming into force in 2027, will significantly raise the bar for all EU-regulated firms.
What Are Financial Sanctions?
Financial sanctions are legally binding restrictions imposed by governments or international bodies on designated individuals, entities, or entire countries. They restrict financial transactions, asset transfers, and commercial dealings with the designated parties, and are distinct from criminal convictions. A party can be sanctioned based on national security risk, political considerations, or human rights concerns, without being charged with any crime.
Sanctions are issued and maintained by several key bodies, each with its own scope and legal force:
- UN Security Council: globally binding on all 193 UN member states; the foundational layer of the international sanctions framework.
- EU: over 40 active sanctions regimes enforced through EU Council Regulations; applies to all EU citizens, entities, and activities within EU territory, regardless of nationality.
- OFAC (US Office of Foreign Assets Control): issues the Specially Designated Nationals (SDN) list; applies to all US persons and to any transaction cleared in US dollars globally.
- HM Treasury / OFSI (UK): maintains the UK Consolidated List; operates as an independent regime since Brexit, with significant overlap with EU sanctions but its own designations.
- National competent authorities: EU member states each have their own enforcement body (e.g. BaFin in Germany, ACPR in France) responsible for implementing EU and national sanctions frameworks.
For regulated businesses, the practical implication is that sanctions compliance is a multi-regime obligation. A European bank processing US-dollar payments must comply simultaneously with EU, OFAC, UK, and UN sanctions, none of which are fully harmonised.
EU update: The EU’s new Anti-Money Laundering Regulation (AMLR) goes live in 2027. It will centralise direct supervision of the highest-risk entities across the EU and introduce harmonised technical standards for sanctions screening, ending the current patchwork of national approaches.
What Is a Sanctions List?
A sanctions list is a publicly available register of individuals, entities, vessels, and jurisdictions subject to legal restrictions on financial dealings. Regulated businesses are required to screen their customers, counterparties, and transactions against these lists before proceeding with any business relationship or payment.
The most widely used sanctions lists include:
- OFAC SDN List: the US Treasury’s Specially Designated Nationals list; one of the most comprehensive and regularly updated sanctions databases in the world.
- EU Consolidated Financial Sanctions List: maintained by the European External Action Service (EEAS); covers all EU sanctions regimes in a single downloadable database.
- UK HM Treasury Consolidated List: the UK’s post-Brexit list of financial sanctions targets, maintained by the Office of Financial Sanctions Implementation (OFSI).
- UN Security Council Consolidated List: the baseline international list covering individuals and entities subject to UN-mandated measures.
Lists are not static. A firm that screens customers only at onboarding, and does not monitor lists for changes, is exposed to significant ongoing risk.
Types of Sanctions Screening
Not all sanctions screening is the same. Regulated firms use several distinct screening types, each targeting a different risk surface:
| Screening Type | What It Checks | When It’s Applied |
| Customer Screening (Name Screening) | Individual and entity names matched against sanctions lists at the point of onboarding, and again whenever personal details change. | Before a business relationship is established; repeated on profile updates. |
| Transaction Screening (Payment Screening) | All parties to a financial transaction — sender, recipient, and any intermediary banks — verified against sanctions lists before the payment is processed. | In real time or near-real time for cross-border payments, correspondent banking, and trade finance instruments. |
| Batch Screening | An entire existing customer base or portfolio re-checked against the latest sanctions lists in bulk. | Periodically (frequency determined by risk level); used alongside real-time screening to catch customers designated after onboarding. |
| Adverse Media Screening | Negative news, court records, and open-source intelligence scanned for links to sanctioned parties, criminal networks, or financial crime. | Continuously, in parallel with sanctions list checks, as part of a broader AML programme. |
| PEP Screening | Whether a customer is a Politically Exposed Person — a current or former senior public official, or a close associate or family member — who requires enhanced due diligence. | At onboarding and on an ongoing basis; PEP status can change and lists are updated regularly. |
What Is Sanctions Screening in Banking?
Sanctions screening in banking refers to the systematic process banks and financial institutions use to verify that customers, transactions, and counterparties are not subject to government or international sanctions. It is one of the most operationally intensive compliance obligations in the financial sector.
Banks face a particular challenge because they operate across multiple channels simultaneously — retail onboarding, corporate account opening, correspondent banking, international wire transfers, trade finance, and securities transactions — each with its own risk profile and screening requirements.
For international payments, SWIFT’s Sanctions Screening service and similar tools check all message fields against multiple sanctions lists, not just the account holder name, but alos beneficiary, ordering institution, intermediary banks, and free-text payment references. A single unscreened field can generate a sanctions violation.
The consequences for banks are well-documented. Regulators have imposed multi-billion dollar fines on banks found to have processed transactions for sanctioned parties, including Commerzbank, Standard Chartered, and BNP Paribas. In the most serious cases, banks have faced criminal prosecution alongside civil penalties.
Key principle for banking: it is not sufficient to screen only the named account holder. Banks must screen all parties involved in a transaction, including beneficiaries, intermediaries, and ultimate beneficial owners (UBOs).
Sanctions Screening in AML Compliance
Sanctions screening is a critical component of a broader Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) compliance programme. While AML and sanctions are technically separate legal frameworks — AML targets the concealment of criminal proceeds, sanctions target designated parties regardless of criminal activity — they overlap significantly in practice and are often managed together.
A complete AML compliance programme incorporates four interconnected layers:
- KYC (Know Your Customer): identity verification and risk classification of customers before and during a business relationship.
- Sanctions screening: checking customers, counterparties, and transactions against official government and international watchlists.
- PEP screening: identifying Politically Exposed Persons and applying enhanced due diligence where required.
- Transaction monitoring: analysing patterns of behaviour across a customer’s transaction history to detect money laundering, terrorist financing, or sanctions evasion.
Running sanctions screening in isolation is a common compliance gap. A customer who passes a sanctions check at onboarding may appear in adverse media two months later, or may be designated on a new sanctions list following a geopolitical event. A robust AML programme treats sanctions screening as a continuous, integrated activity, not a one-time gateway check.
For a comprehensive introduction to how AML and KYC frameworks fit together in practice, see IDnow’s AML and KYC overview.
EU regulatory update: Under AMLR 2027, EU-regulated firms will be required to demonstrate a risk-based, continuous approach to all four layers. Periodic, tick-box checks will not meet the standard. Firms that have invested in integrated AML screening infrastructure will be significantly better positioned for the transition.
The Sanctions Screening Process: Step by Step
The sanctions screening process follows a defined sequence. Each step matters. A failure at any stage, from data collection to ongoing monitoring, can create compliance exposure.
1. Collect customer data
Gather the identifying information required to perform an accurate screen: full legal name (including all known aliases), date of birth, nationality, country of residence, and, for corporate entities, company registration details, jurisdiction of incorporation, and ultimate beneficial owner (UBO) information. Data quality at this stage determines screening accuracy. Incomplete or inaccurate data generates both false negatives (missed matches) and unnecessary false positives.
2. Match against sanctions lists
Run the collected data through a screening engine that compares it against the relevant sanctions lists in scope for the business, typically OFAC SDN, EU Consolidated List, UK HM Treasury Consolidated List, and UN SC Consolidated List as a baseline, plus any jurisdiction-specific lists. Modern screening engines use AI-powered fuzzy matching to handle spelling variations, transliterations from non-Latin scripts (Arabic, Cyrillic, Chinese), name-ordering differences (given name vs family name order), and common abbreviations. This is essential. Sanctions evaders frequently exploit name variation to evade detection.
3. Flag potential matches
Potential matches generate alerts, commonly called “hits”. Every hit requires human review to determine whether it is a true positive (a genuine match with a sanctioned party) or a false positive (a different individual or entity that shares similar name characteristics). High false-positive rates are a persistent operational problem. Some firms screen tens of thousands of names per day and must manage alert queues efficiently.
4. Investigate and adjudicate
Compliance officers assess flagged matches against the full customer context: additional identifying information, transaction history, and the specific details of the sanction entry. Enriching customer data at this stage (for example, adding a date of birth where previously missing) significantly improves the accuracy of adjudication. True positives must be reported to the relevant authority; false positives are cleared with documented rationale.
5. Report and freeze
Where a true match is confirmed, the firm must immediately halt any planned transaction, freeze relevant assets where legally required, and report to the competent authority: OFSI in the UK, OFAC in the US, or the relevant national authority in the EU. Failing to report is itself a criminal offence in most jurisdictions. Timing matters: regulatory reporting obligations are typically strict.
6. Monitor continuously
Sanctions lists change without warning. New designations are issued in response to geopolitical events, criminal investigations, and regulatory actions, sometimes with hours’ notice. Continuous monitoring re-screens existing customers and counterparties whenever lists are updated, ensuring that a customer who was clean at onboarding is caught if they are subsequently designated. This ongoing layer of protection is where many firms fall short.
Who Is Required to Perform Sanctions Checks?
The obligation to avoid transacting with sanctioned parties applies to all businesses. Processing a payment to a sanctioned entity is illegal regardless of whether a formal compliance programme is in place. However, certain sectors face explicit statutory obligations to operate a documented sanctions screening programme.
Legally required (regulated financial sector)
- Banks and credit institutions
- Payment institutions and e-money firms
- Investment firms and asset managers
- Insurance companies and intermediaries
- Virtual Asset Service Providers (VASPs): required under FATF guidance, EU MiCA, and AMLD6
Designated Non-Financial Businesses and Professions (DNFBPs)
- Casinos and online gambling operators
- Estate agents and property lawyers
- Dealers in high-value goods (precious metals, stones, art, luxury vehicles)
- Lawyers, notaries, accountants, and tax advisers when handling client funds or transactions
- Trust and company service providers
All businesses: best-practice obligation
Any company that transacts internationally with customers or counterparties should conduct at minimum basic sanctions screening as part of its due diligence and regulatory compliance requirements. The fact that a business is not formally regulated does not provide immunity from sanctions law. If you knowingly or recklessly deal with a sanctioned party, you are exposed to criminal liability regardless of your regulatory status.
When Must Sanctions Screening Be Performed?
Sanctions screening must be performed before onboarding a new customer, before processing any significant transaction, and on a continuous basis throughout the entire customer relationship, not just at the point of account opening.
Specific triggers for a sanctions check include:
- Before onboarding: screen before the business relationship is formally established. A positive match at this stage means the relationship should not proceed.
- Before significant transactions: particularly high-value or cross-border payments, international wire transfers, and trade finance instruments.
- Periodic re-screening: existing customers should be re-screened against updated lists at intervals determined by their risk level. High-risk customers warrant more frequent re-screening.
- Event-triggered reviews: when a customer’s personal information changes, when unusual or suspicious activity is detected, or when a significant geopolitical event results in new designations.
- Counterparty due diligence: suppliers, business partners, and correspondent banks should be screened before establishing or continuing commercial relationships.
- List update triggers: when OFAC, the EU, HM Treasury, or the UN issue new designations, the entire relevant customer base should be re-screened against the updated list as rapidly as operationally possible.
The gap between onboarding screening and ongoing monitoring is where most real-world compliance failures occur. A customer designated six months after account opening represents an ongoing liability that a one-time check cannot address. Continuous, automated monitoring is the only operationally scalable solution.
Sanctions Screening Tools
The sanctions screening market offers a range of solutions, from standalone list-matching tools to fully integrated compliance platforms. The right choice depends on the volume of customers and transactions, the number of sanctions regimes in scope, and the degree of integration required with existing compliance and KYC infrastructure.
Standalone screening engines
Purpose-built platforms that check names and transaction data against a curated database of sanctions lists. Typically offered by data providers as a SaaS or API service. Suitable for firms with lower transaction volumes or simpler compliance needs.
Integrated AML and compliance platforms
End-to-end platforms that combine sanctions screening with KYC, PEP screening, adverse media monitoring, and transaction monitoring in a single system. This integrated approach is increasingly preferred by regulators — and under AMLR 2027, it will be more or less required — because it enables a single customer risk view rather than managing multiple disconnected point solutions.
Real-time payment screening services
Designed specifically for high-volume payment flows. These solutions plug directly into payment processing infrastructure and screen transactions in milliseconds, flagging suspicious payments for review before they are processed. Required by banks and payment processors handling large volumes of international transfers.
Key capabilities to evaluate
- Multi-list coverage: screens against OFAC, EU, UK, UN, and relevant national lists simultaneously.
- AI-powered fuzzy matching: handles transliterations, aliases, name variations, and spelling differences without generating unmanageable false-positive volumes.
- Real-time and batch modes: supports both transactional real-time screening and periodic bulk re-screening.
- Continuous monitoring: automatically re-screens existing customers when lists are updated.
- Audit trail and case management: maintains a documented record of all screening decisions for regulatory review.
- API and SDK integration: connects cleanly to existing onboarding, KYC, and payment infrastructure.
- Risk-based tuning: allows compliance teams to adjust matching thresholds by customer risk level, reducing false positives for low-risk populations while maintaining sensitivity for high-risk segments.
IDnow’s AML Screening solution combines real-time sanctions screening, PEP checks, and adverse media monitoring in a single API- and SDK-integrated platform, designed to help regulated firms meet their AMLR 2027 obligations without building multiple disconnected systems.
Common Challenges in Sanctions Screening
Despite the availability of sophisticated tooling, sanctions screening remains operationally complex. Understanding these challenges is the first step to managing them effectively.
Rapidly changing lists. Sanctions lists can be updated multiple times per day during periods of geopolitical tension. Manual or batch-only screening programmes cannot keep pace — automated, real-time list monitoring is the only operationally viable solution for firms with significant customer bases.
Name matching complexity. Sanctioned parties routinely use aliases, name variations, and transliterations to evade detection. A screening engine that only matches exact strings will miss them. AI-driven fuzzy matching with contextual weighting — accounting for name length, transliteration conventions, and common alias patterns — is required.
False positive management. Overly broad matching generates alert volumes that compliance teams cannot process. A firm screening 50,000 customers per day with a 2% false positive rate produces 1,000 alerts that require human review every day. The goal is high recall (catching all true matches) with high precision (minimising unnecessary alerts).
Multi-regime complexity. A European firm processing US-dollar payments must comply simultaneously with EU, OFAC, UK, and UN sanctions. These lists are not harmonised. An entity may appear on one list but not others, and the restrictions associated with each listing may differ. A unified screening platform that handles all regimes in a single workflow is essential.
Association and ownership risk. Some sanctions regimes extend to entities owned or controlled by designated individuals, even if those entities are not themselves listed. The OFAC “50% rule” provides that any entity owned 50% or more by a sanctioned party is itself subject to sanctions, regardless of whether it appears on the SDN list. Detecting this requires network analysis and UBO screening beyond simple list-matching.
See How IDnow Handles Sanctions Screening.
IDnow’s AML Screening solution checks customers and counterparties in real time against global PEP, sanctions, and adverse media lists, combining all three in a single integrated platform.
FAQs about Sanctions Screening
What is sanctions screening?
Sanctions screening is the process of checking individuals, entities, and transactions against official sanctions lists issued by governments and international bodies such as the UN, EU, and OFAC. It ensures that businesses do not engage in financial dealings with restricted parties and is a core requirement under AML/CFT frameworks in most regulated industries.
What are the different types of sanctions screening?
The main types are:
– Customer (name) screening: checking individuals and entities at onboarding;
– Transaction (payment) screening: checking the parties to individual financial transactions in real time;
– Batch screening: periodic bulk re-screening of an existing customer base;
– PEP screening: identifying Politically Exposed Persons;
– Adverse media screening: monitoring open-source intelligence for links to sanctioned or high-risk parties.
Most compliance programmes use all of these in combination.
How do you do a sanctions check?
A sanctions check involves five steps: (1) collect the subject’s full name, date of birth, nationality, and — for entities — registration details; (2) run the data through a screening engine that matches it against relevant sanctions lists using fuzzy matching to catch name variations and aliases; (3) review any alerts generated to determine true or false positives; (4) report true matches to the relevant authority and freeze associated assets where required; (5) monitor the subject on an ongoing basis as lists are updated.
Who is required to do sanction checks?
All regulated financial institutions (banks, payment firms, insurers, investment firms, and VASPs) face explicit legal obligations to screen customers and transactions. Designated Non-Financial Businesses and Professions (DNFBPs), including estate agents, lawyers, accountants, and dealers in high-value goods, are also required to screen. Practically, any business that transacts internationally is exposed to sanctions risk and should conduct baseline screening, whether or not they are formally regulated.
When should sanctions screening be performed?
Sanctions screening should be performed before onboarding a new customer, before processing any significant transaction, particularly cross-border payments, and on a continuous basis throughout the entire customer lifecycle. When sanctions lists are updated with new designations, firms should re-screen their existing customer base against the updated list as quickly as operationally possible. Relying solely on onboarding screening is a common and costly compliance gap.
What is the difference between sanctions screening and AML screening?
AML screening is the broader compliance programme, encompassing KYC identity checks, transaction monitoring, PEP screening, and adverse media monitoring, as well as sanctions screening. Sanctions screening is a specific check within that programme: it verifies whether a party is legally restricted from transacting. All regulated firms need both, and they are most effective when run together on an integrated platform.
What is payment screening?
Payment screening is the application of sanctions checks to individual financial transactions, verifying that all parties to a payment (sender, recipient, and any intermediary banks) are not on a sanctions list before the payment is processed. It operates in real time or near-real time and is distinct from customer onboarding screening, which only checks the account holder at the point of account opening.
