Sanctions Screening Beyond the List: A Best-Practice Guide

Sanctions Screening Beyond the List A Best-Practice Guide

Sanctions Screening Beyond the List: A Best-Practice Guide

Sanctions screening is no longer simply an exercise in matching customer names against designation lists. Effective frameworks must also identify ownership and control, indirect exposure, circumvention indicators and risks arising through transactions, trade, shipping and commercial networks. 

Geopolitical fragmentation, sophisticated evasion techniques and opaque corporate structures have widened the sanctions risk landscape. Advanced analytics and artificial intelligence can help firms identify relationships that traditional name matching may miss—but they also introduce new governance and accountability considerations. 

Regulatory expectations are increasing too. The European Banking Authority’s Guidelines on restrictive measures, applicable since 30 December 2025, establish common expectations concerning governance, risk assessment, policies, procedures and controls. Separate Guidelines set out more specific screening and due-diligence requirements for payment service providers and crypto-asset service providers when carrying out transfers. 

The challenge for firms is therefore not merely to show that screening took place. They must demonstrate that their controls are appropriately designed, effectively implemented and capable of identifying the sanctions risks to which the organisation is exposed. 

Why Sanctions Screening Must Evolve 

The pace of geopolitical and regulatory change is testing many established screening frameworks. 

In April 2026, the EU’s 20th sanctions package against Russia introduced 120 additional individual listings and added 46 vessels, bringing the number of designated shadow-fleet vessels to 632 at that time. The 21st package followed in July 2026, adding 218 individual and entity listings and a further 41 vessels. Given the pace of designations, firms should treat these totals as indicative of the trajectory rather than a current count, and verify the latest figures directly against the EU Sanctions Map or the Commission’s own package summaries before relying on them operationally. 

These developments demonstrate how sanctions exposure can arise through banks, vessels, insurers, ports, payment providers, crypto-asset platforms and third-country intermediaries—not only through a firm’s named customers. 

The enforcement environment is also becoming more demanding. Directive (EU) 2024/1226 requires EU Member States to establish minimum rules concerning criminal offences and penalties for violations and circumvention of EU restrictive measures. Its transposition deadline was 20 May 2025, though implementation has been uneven: the European Commission opened infringement proceedings against a majority of Member States in mid-2025 for failing to transpose the Directive on time, and several jurisdictions only brought national implementing measures into force well after the deadline. Firms must therefore consider the specific implementing laws and enforcement practices of each relevant Member State, rather than assume the Directive’s framework is uniformly in force across the EU. 

Organisations with UK exposure must monitor the UK framework separately. Since 28 January 2026, the UK Sanctions List has been the sole current source for UK sanctions designations following the closure of the OFSI Consolidated List. 

As a matter of good practice, firms should maintain regulatory and geopolitical horizon scanning supported by sanctions exposure mapping. This means understanding where sanctions risk could enter the organisation through its jurisdictions, customers, suppliers, payment corridors, shipping routes, ownership structures, products and services. 

Improving Matching Quality and Data 

Some of the most significant sanctions exposures are those that a screening system fails to identify. 

Poorly calibrated matching can produce large volumes of false positives, diverting investigators from genuinely significant cases. Settings that are too restrictive, however, can increase the risk of false negatives. 

Aliases, incomplete records, transliteration and alternative spellings make this balance more difficult. Differences between writing systems can produce several legitimate versions of the same name, while weak customer data may prevent investigators from distinguishing a true match from an unrelated party. 

Effective screening therefore depends on more than the screening engine itself. Firms need reliable, complete and consistently structured data. They must understand how their systems treat alternative spellings, abbreviations, missing fields, non-Latin scripts and changes in customer information. 

Screening thresholds should be tested regularly against the organisation’s sanctions exposure assessment. Firms should be able to explain why particular settings were selected, how they affect false-positive and false-negative risk, and what evidence demonstrates that the system remains effective. 

Ownership, Control and Circumvention 

A customer or entity does not necessarily need to appear by name on a sanctions list for restrictions to apply. 

Under EU sanctions rules, an asset freeze and the prohibition on making funds or economic resources available may extend to an unlisted entity that is owned or controlled by a listed person. 

Ownership must be assessed by reference to the applicable sanctions regime. Depending on the relevant legal instrument and official guidance, the test may be expressed as 50% or more, more than 50%, or the possession of a majority interest. Control is a separate, fact-specific assessment. 

Firms may also need to consider direct and indirect ownership and, where applicable, the aggregation of holdings held by more than one listed person. 

Changes in ownership should not automatically result in clearance. A transfer that reduces a listed person’s recorded shareholding below the relevant threshold may still require investigation, particularly where there are indications that the person continues to exercise control over, or benefit from, the entity. 

Other potential circumvention indicators include: 

• indirect transactions with no clear economic rationale; 

• unnecessarily complex ownership or payment structures; 

• the use of shell companies; 

• sudden changes in directors or shareholders; 

• unexplained changes in payment or delivery arrangements; and 

• dealings involving jurisdictions associated with elevated circumvention risk. 

Entity-resolution technology can help connect information such as company names, directors, addresses, telephone numbers, wallet addresses and ownership interests. An unlisted distributor, for example, may share a director, address and controlling shareholder with a sanctioned group. Its legal name may not generate an obvious match, but the combined information may reveal a relationship requiring investigation. 

Looking Beyond Names and Customers 

A customer may appear low risk when screened in isolation, while the transaction or commercial arrangement surrounding that customer tells a different story. 

Depending on their activities and risk profile, firms may need to examine intermediaries, suppliers, payment corridors, crypto-assets, vessels, ports, transport providers, goods, end users and trade routes. 

Consider an exporter selling sensitive technology to an apparently legitimate distributor. The distributor is not listed, but payments are received through an unexpected intermediary jurisdiction, the stated end user cannot be verified and shipping arrangements change repeatedly. 

Each detail may have a reasonable explanation when considered separately. Taken together, however, they may indicate a pattern requiring enhanced due diligence. 

Graph analysis can help investigators see relationships between customers, companies, directors, vessels, payments and designated parties. This technology does not replace legal analysis or investigative judgement, but it can reveal connections that may remain hidden when records are reviewed individually. 

Cross-border firms must also ensure that their systems reflect each applicable sanctions regime. EU and UK controls, for example, require separate and continuously updated logic because their designation, ownership-and-control and licensing frameworks may produce different outcomes. 

Using AI Without Losing Accountability 

AI-supported tools can strengthen fuzzy matching, entity resolution, relationship analysis and alert prioritisation. They may help firms identify unusual transactional patterns and focus investigative resources on cases presenting the greatest potential risk. 

More advanced technology, however, creates important governance questions: 

• Can the firm explain the basis for a recommendation? 

• Can the decision and supporting information be reconstructed? 

• Can investigators challenge the system’s output? 

• Is performance monitored for errors, bias and deterioration? 

• Who remains accountable for the final decision? 

Sanctions-screening systems are not automatically classified as high-risk under the EU AI Act. The legal position depends on the system’s intended purpose, functionality, deployment context and the decisions it supports. Each use case should therefore be assessed individually, including against relevant data-protection, record-keeping and governance requirements. 

Even where an application is not legally classified as high-risk, sound governance should include reliable data, appropriate documentation, access controls, performance monitoring, effective human oversight and a clear allocation of responsibility. 

Best practice is not autonomous compliance. It is technology-supported screening in which material decisions remain subject to competent human review. AI should help focus human judgement where it matters most, not quietly replace it. 

A Practical Best-Practice Checklist 

An effective sanctions framework should be proportionate to the organisation’s business model, geographic exposure, customer base, products, services and delivery channels. 

Core components include: 

• a documented sanctions exposure assessment; 

• reliable customer and transaction data; 

• screening against relevant and current official lists; 

• risk-calibrated matching rules and thresholds; 

• ownership-and-control analysis; 

• procedures for identifying circumvention indicators; 

• clear investigation and escalation routes; 

• decisions that can be reconstructed and independently reviewed; 

• quality assurance and independent testing; 

• role-specific staff training; and 

• senior-management oversight and accountability. 

Measurement should go beyond the number of alerts processed. Useful indicators may include false-positive rates, confirmed matches, ageing alerts, escalation times, recurring data-quality problems and weaknesses identified through retrospective testing. 

Firms should also test for cases their controls may have missed. Known designated parties, alternative spellings, historical cases and deliberately constructed scenarios can help determine whether screening rules operate as intended. 

Technology can strengthen this framework, but it cannot compensate for weak governance, poor data or insufficient expertise. 

From List Checking to Sanctions Intelligence 

Sanctions screening is developing into a broader intelligence and risk-management discipline. 

Leading firms are moving from isolated name matching towards a more complete understanding of customers, ownership structures, transactions and commercial relationships. They are combining periodic checks with event-driven monitoring and using network analysis to investigate connections that traditional screening may overlook. 

The firms best prepared for regulatory scrutiny will be those that can demonstrate not only that screening took place, but also that their controls were appropriately designed, regularly tested and effective in practice. 

Develop Your Sanctions-Screening Capability with EIMF 

EIMF’s seminar, Sanctions Screening: A Best Practice Guide, equips compliance professionals with practical approaches to sanctions screening, ownership-and-control analysis, alert management and the governance of technology-supported controls. 

Explore the seminar and view upcoming dates through the EIMF website. 

Note: This article is provided for general information and educational purposes only. It does not constitute legal, regulatory or professional advice. Sanctions requirements vary by jurisdiction and may change at short notice. Organisations should assess the requirements applicable to their activities and obtain appropriate professional advice where necessary. 

Key Resources 

• EU Sanctions Map 

• European Banking Authority Guidelines on restrictive measures 

• Directive (EU) 2024/1226 

• European Commission sanctions resources 

• Consolidated FAQs on EU sanctions against Russia 

• The UK Sanctions List 



Days
Hours
Minutes
Seconds

Early bird discount

13 November 2025

Navigating Conflict for Collaborative Teams: Leading with Confidence

Join us to gain insights from Alana Hill, learn practical strategies for turning conflict into opportunity, and discover how challenges can drive growth and stronger team performance.

Days
Hours
Minutes
Seconds

Limited Time

30% Discount

On All Self-Paced eLearning CPD Courses in Financial Regulation

Days
Hours
Minutes
Seconds

Limited Availability

05 June 2025

Corporate Governance Today: Trends and Challenges

Hosted by the EIMF and the Chartered Governance Institute

Engage with 20+ leading experts and earn 6 CPD units in Financial Regulation.

Get Inspired by Our Head of Accounting

Think. Choose. Grow.

Not sure if it’s right for you? Let’s talk.

Days
Hours
Minutes
Seconds

limited time

PAIR UP AND SAVE

BUY ONE, GET ONE FREE

Short Self-Paced Online Courses

Days
Hours
Minutes
Seconds

Limited time

New Year, new you

10% discount on All Courses

Discount Coupon: NYNY10

Valid until 31 Jan 2025 23:59

EIMF's Christmas Advent Calendar

Unwrap the Gift of Knowledge this Festive Season!

Register now to receive a valuable educational resource each day and be automatically entered into our Grand Christmas Draw on 24th December – Don’t miss out!

Days
Hours
Minutes
Seconds

Limited time

black friday has arrived

up to 40% discount

On Self-Paced eLearning Courses

Days
Hours
Minutes
Seconds

Limited Availability

17 October 2024

Regulatory & AFC Compliance Conference

Hosted by the ACAMS Cyprus Chapter and the EIMF.

Engage with 17 leading experts, explore 12 critical areas, earn 6 CPD units in Financial Regulation, gain 4 ACAMS credits, and receive a Certificate of Participation.

Celebrate 9 Years with EIMF

EIMF Has Assisted 6,000+ Professionals Get Certified

 

Ready for your next professional certification? Choose from 9 self-paced eLearning courses and enjoy a 30% discount!

*complete your purchase before 21 April 2024

Starts 20 February 2024

Master in Governance,
Risk & Compliance

Accredited by the CyQAA, our GRC programme empowers you to navigate complex regulations, manage risks, and fortify governance structures. Dive into a dynamic learning experience that ensures ethical operations, regulatory compliance, and risk reduction.

✅ Explore Scholarships & Financial Aid ✅ Discover the Match Funding Scheme