us

216.73.217.98

Back
Blogs

Sanctions Screening and its Working in AML

Sanctions Screening and its Working in AML
Madiha Khatoon JULY 9, 2026 16 minutes read
Sanctions screening checks customers, payments, and counterparties against government prohibition lists. Here is how it works, and where it quietly fails.

Ask most compliance teams to describe sanctions screening and the answer will usually be a description of matching, in which a customer’s details are compared against government lists and an alert is raised whenever the two look close enough. That description is accurate as far as it goes, and it helps explain why many screening programmes fail their first serious inspection: the matching engine is rarely the component that breaks.

Supervisors have quite a while penalising firms whose name matching worked exactly as designed, usually because a control had quietly stopped running, an ownership chain had never been traced, or a decision that was entirely correct on the facts arrived too late to count. 

What is Sanctions Screening?

Sanctions screening is the control that checks the people, organisations and payments that are dealt with against official lists of parties that governments and international bodies have restricted or prohibited. When an identity or payment detail matches an entry, the relationship is held for review before any business proceeds.

The scope for this, however, is wider than most teams assume. Screening covers natural persons, legal entities, vessels, aircraft, crypto wallet addresses, and in some regimes entire jurisdictions. A payment routed through a sanctioned port, or an aircraft leased from a designated operator, sits inside the same obligation as a customer whose name appears on a list.

Within an anti-money laundering compliance program, screening answers one narrow question, which is whether this party is prohibited. That question is separate from customer due diligence, which establishes who someone is, and separate from transaction monitoring, which watches how they behave afterwards. Screening is one of the first controls applied at onboarding and one of the very few that must keep running for the entire life of the relationship, because a customer who was clear yesterday can be designated tomorrow.

Which sanctions lists does screening cover?

There is no single global list, so a defensible programme screens against every regime with jurisdiction over its business, its currency and its customers. Four regimes do most of the work for most firms.

Regime Issued by Primary list Liability standard
United States Office of Foreign Assets Control (OFAC) Specially Designated Nationals (SDN) list, plus consolidated non-SDN lists Strict liability, so a breach can occur without knowledge or intent
European Union Council of the EU, implemented by member states EU Consolidated Financial Sanctions List Set by each member state’s national implementing law
United Nations UN Security Council and its sanctions committees UN Consolidated List Implemented into national law by member states
United Kingdom Foreign, Commonwealth and Development Office designates, HM Treasury enforces through the Office of Financial Sanctions Implementation (OFSI) UK Sanctions List, the sole source since 28 January 2026 Strict civil liability for breaches on or after 15 June 2022

The UK row carries a change that has caught out a lot of screening configurations this year. On 28 January 2026, the UK moved to a single list, and OFSI’s Consolidated List of Asset Freeze Targets stopped being updated. Any programme still pulling that feed as its UK source is now screening against a file which has been frozen since January, so the UK Sanctions List has to be the ingest point.

Beyond these four, most programmes screen additional national regimes, regional bodies, and law enforcement or regulatory warning registers depending on where they operate. A payments firm serving Southeast Asia and the Gulf will carry a materially different list set from a domestic UK lender.

Two things matter more than the count of lists. The first is whether each list is refreshed on the cadence which the regulator expects rather than the cadence the vendor finds convenient. The second is whether the same subject is also run through watchlist screening and adverse media, because sanctions lists are deliberately narrow and a great deal of genuine risk never reaches a formal designation.

To understand the underlying regimes and how designations are made, see Shufti’s reference on sanctions lists.

What are the types of sanctions screening?

Sanctions screening breaks into five related controls that run at different moments and catch different things. Most programmes deploy the first well and assume it covers the rest, which is where exposure quietly builds.

Type What it checks When it runs What it catches that others miss
Customer and name screening Applicant and existing customer identity data against list entries At onboarding, then on every list refresh The designated individual applying directly
Transaction and payment screening Payment messages, including originator, beneficiary, banks and free-text fields In-flight, before settlement A clean customer sending funds to a designated counterparty
Counterparty and supply chain screening Vendors, distributors, agents, brokers and intermediaries At contracting, then periodically Exposure that never touches your customer file
Ownership and control screening The corporate ownership chain behind an entity At business onboarding and on structural change A company that is blocked despite appearing on no list
Real-time versus batch screening The same data, but on different clocks Continuously, or on a scheduled cycle Designations published between batch runs

Customer, transaction and counterparty screening

Customer screening is the control everyone builds first, and it is the one that fails least often. Transaction screening is harder, because payment messages carry truncated names, missing identifiers and free-text remittance fields where a sanctioned party’s details can hide in plain sight. Counterparty screening is the one most commonly skipped altogether, because vendors and agents are onboarded by procurement rather than compliance, and procurement rarely runs a sanctions check.

Real-time sanctions screening

Real-time sanctions screening evaluates a subject against the current list state at the moment of the check rather than against a snapshot which is taken overnight. In practice, it means two things that are working together. New designations are ingested continuously as regimes publish them, and every enrolled profile is re-evaluated against the updated data rather than waiting for the next scheduled sweep. The alternative, a nightly or weekly batch, builds a predictable gap between the moment a party is designated and the moment your systems know it.

How does the sanctions screening process work?

The sanctions screening process moves from raw customer data to a documented decision in six steps, and each step has a failure mode that regulators have penalised.

1. Capture and normalise the data: Collect the full legal name, known aliases, date of birth, nationality, national identifiers and, for entities, the registration number and jurisdiction. Then the format must be normalised so that name order, diacritics and script variants do not defeat the comparison.

Failure Mode: Thin input data, because a screening engine cannot distinguish two people who share a name when the only field it holds is that name, results in a failure mode.

2. Match against the relevant lists: Run exact, fuzzy, phonetic, and transliteration matching in parallel against every list in scope. A Cyrillic or Arabic designation must surface the same record as its Latin transliteration.

Failure mode:  Single-script matching, which silently misses designations that were never published in the alphabet your systems expect.

3. Score the match: The engine assigns a confidence score and raises an alert wherever that score crosses the configured threshold. 

Failure mode: Accepting a vendor’s default threshold instead of setting one that reflects your own risk appetite, product lines, and markets.

4. Adjudicate the alert: An analyst confirms a true match or clears a false positive, and records the reasoning behind that call. 

Failure mode: Clearing on gut feel, because an alert cleared without written rationale is indistinguishable from an alert nobody looked at once an inspection begins.

5. Act on the outcome: Block the onboarding, freeze the funds, escalate internally, or report to the relevant authority within the deadline that applies in your jurisdiction. 

Failure mode: Correct decisions filed late, which is now a recognised enforcement pattern in its own right.

6. Evidence for the whole chain: Retain the input data, the list version screened against, the score, the analyst decision, the rationale and the timestamps. 

Failure mode: An audit trail assembled retrospectively, which supervisors read as an absence of control rather than a documentation gap.

Steps one and two get almost all the attention in vendor demonstrations. Steps four, five and six are where programmes actually come apart, because they depend on people, ownership and process discipline rather than on software.

what-is-sanctions-screening

Why do sanctions screening systems produce so many false positives?

Sanctions screening systems produce high alert volumes by design, because the cost of a missed designation is regulatory and the cost of an extra alert is operational. Matching is therefore deliberately broad. A customer who happens to share a common surname with a listed individual will generate a hit, and so will a transliterated name that has a partial overlap with a recorded alias.

The instinct is to tighten the threshold until the queue looks manageable. That instinct is the trap, because the same adjustment that removes the noise also removes the marginal true matches, and the marginal true matches are exactly the ones a determined party carefully engineers.

Umair Hameed, Regional VP of Sales, MENA at Shufti, has framed the problem in the following way:

 “We’ve spent years treating this as a matching problem when in reality it’s a context problem. There’s no perfect fuzzy-match score between 50 and 100. The real shift is from screening names to making better, more informed decisions in context.”

That difference decides what you are able to fix. If the problem is matching, your only tool is the match threshold, which is the dial that sets how close two names have to be before an alert fires. Turning it up gives you a shorter queue, but it also stops you catching the misspelled versions of a listed name, and those are the ones a sanctioned party is most likely to use. Every turn of that dial swaps one mistake for another.

If the problem is context, your tool is how much you know about the person. For example, a list entry reads Ivan Petrov, born 1962, and your customer is an Ivan Petrov born in 1988. The date of birth settles it, so you close the alert on proof and leave the dial exactly where it was, which means every other Petrov on the list is still caught.

One warning, because this is where teams get into trouble. Plenty of list entries carry no date of birth at all, and a blank field is not a mismatch. If you close an alert because your customer’s details differ from a field the list left empty, you have not cleared a false positive; you have missed a real match.

The three blind spots a name match does not catch

Even a perfectly tuned matching engine leaves three gaps open, and every one of them has produced enforcement action.

Ownership, where an entity is blocked without ever being listed

Under OFAC’s 50 Percent Rule, any entity owned 50 percent or more, directly or indirectly and in the aggregate, by one or more blocked persons is itself blocked, whether or not it appears on the SDN list. Ownership held by persons who are designated under different sanctions programmes is added together to reach that threshold. The consequence is stark, because you can screen a company against every list, get a clean result, and still be dealing with blocked property. One limit is worth knowing precisely, because OFAC’s rule speaks to ownership and not to control, so an entity that a blocked person controls without majority ownership is not automatically blocked, and OFAC instead urges caution and due diligence on exactly such cases.

The EU applies a comparable ownership test and then goes further. EU Sanctions Helpdesk guidance treats a shareholding of 50 percent or more as creating a presumption of control over the entity’s funds and economic resources, combines the holdings of multiple listed persons, and warns that control can exist below 50 percent where, for example, a shareholder agreement grants the power to appoint the majority of the board. A firm operating across both regimes therefore has to run two tests rather than one, because a structure that clears OFAC’s ownership arithmetic can still be caught by the EU’s control criterion.

Neither test is answerable by name screening. Both require the corporate structure to be traced through its layers to the natural persons at the top, which makes this a business verification problem that happens to surface as a sanctions failure. A closely related trap sits alongside it, where a non-US firm faces designation for dealing with a sanctioned party outside US jurisdiction, which is covered in Shufti’s guide to secondary sanctions.

Timing, where the list moved before your systems did

The Financial Action Task Force (FATF) requires countries to apply targeted financial sanctions “without delay”, and its guidance on Recommendation 6 defines that phrase as ideally within a matter of hours of a designation. A screening cycle that runs overnight therefore concedes a gap the standard does not contemplate, and the funds most likely to move in that gap belong to the party who just learned they were about to be designated.

Timing failure is now a distinct enforcement theme in its own right. Speaking on a Shufti compliance webinar in November 2025, Ray Blake, co-founder of The Dark Money Files and a former head of compliance and MLRO, pointed to a recent pattern in which supervisors accepted that firms had appropriate systems and reached the right conclusions, then penalised them anyway because those conclusions were not reached consistently, reliably or quickly enough. Owning the control is no longer the test, because the test is now whether it runs on the regulator’s clock.

Operation, where the control was switched off, and nobody checked

The third gap is the one that caught TradeStation, and it is the least discussed. Two layers of geo-blocking sat between the platform and sanctioned jurisdictions. One had been degraded by a software change in 2018 so that it read a US server address instead of the user’s. The other was disabled during a routine update in June 2021 and never re-enabled. An automated testing tool for the firm’s on-premises servers was discontinued in November 2021 without replacement, which left no working test of the geo-blocking controls at all, and the daily OFAC alert emails stopped arriving in September 2021 when a subscription lapsed, unaddressed for more than eight months. The aggravating detail is that OFAC had already sent TradeStation a Cautionary Letter earlier in 2021 about geo-blocking deficiencies, so the firm had been told where to look and still did not test.

OFAC’s own conclusion is worth reading twice. “Controls only work if they are effectively implemented. The most well-designed sanctions compliance program can be rendered wholly ineffectual by human and technical errors.” The release goes on to warn firms against a “set it and forget it” approach, which is the same point Ray Blake makes about compliance technology generally: that a system nobody maintains is a system that has already stopped working.

Sanctions screening vs transaction monitoring

These two controls are routinely confused because both live inside AML software, but they answer different questions and fail in different ways.

Criteria Sanctions screening Transaction monitoring
Question answered Is this party prohibited? Does this behaviour look suspicious?
Trigger Onboarding, plus every list refresh, plus each payment Activity over time
Data used Identity attributes matched against list entries Transaction value, frequency, counterparties and patterns
Output A blocked or cleared party, and a freeze or report where confirmed An alert for investigation, and a suspicious activity report where confirmed
Discretion None once a match is confirmed Judgement based on risk and context
Typical failure A designation that was never surfaced A pattern that was never modelled

A complete programme runs both, because they cover for each other. Screening keeps prohibited parties out, and transaction monitoring catches the ones who got in legitimately and then started behaving like someone else.

Is sanctions screening a legal requirement?

Yes, for regulated businesses in most jurisdictions, and the obligation comes from three directions at once.

FATF sets the global baseline. Recommendations 6 and 7 require countries to implement targeted financial sanctions relating to terrorism, terrorist financing and the proliferation of weapons of mass destruction, and to freeze the assets of designated parties without delay. National AML law then translates that baseline into binding duties on banks, payment firms, crypto businesses and other obliged entities to screen, freeze and report.

Regime-specific enforcement is the sharpest edge. OFAC operates on strict liability, so a US person or a firm using the US financial system can be penalised for a breach it did not know it was committing. The UK moved the same way in 2022, and under OFSI’s monetary penalties guidance, the requirement to prove that a firm knew or had reasonable cause to suspect a breach was removed for conduct on or after 15 June 2022.

Strict liability changes what “reasonable effort” is worth. Intent is not a defence, and neither is a vendor’s assurance, so the only meaningful protection is a control that demonstrably ran, on current data, with the decision recorded.

How Shufti handles ownership and control in sanctions screening

The hardest sanctions exposure to see is the entity that appears on no list at all, because the designation sits two layers up its ownership chain. Name screening returns a clean result, the file passes, and the breach is only visible once someone traces who actually owns the counterparty.

Shufti’s sanctions screening resolves ownership and control alongside the name match, capturing companies indirectly sanctioned through the OFAC 50 percent rule and the equivalent EU and UK ownership and control rules, so an entity that is blocked without being listed surfaces as a hit rather than as an audit finding. Screening runs against 215+ sanctions regimes with a maximum 15-minute data refresh. That interval is what closes the window between a designation being published and your existing book being re-tested against it.

See how ownership and control resolution changes what your screening actually catches, then book a 20-minute demo.

Frequently Asked Questions

What are the types of sanctions screening?

There are five. Customer and name screening, transaction and payment screening, counterparty and supply chain screening, ownership and control screening, and real-time versus batch screening. Most programmes build the first well and leave ownership and counterparty exposure uncovered.

Is sanctions screening a legal requirement?

Yes, in most regulated sectors. FATF Recommendations 6 and 7 set the global baseline, national AML law makes it binding on obliged entities, and regimes such as OFAC and OFSI enforce directly on a strict liability basis, meaning a firm can be penalised without knowledge or intent.

What is the difference between sanctions screening and transaction monitoring?

Screening asks whether a party is prohibited by matching identity data against sanctions lists. Monitoring asks whether behaviour looks suspicious by analysing transaction patterns over time. Screening controls who you deal with, and monitoring watches what they do afterwards.

How often should sanctions screening be run?

At onboarding, and then every time a relevant list changes. FATF defines the required "without delay" standard as ideally within hours of a designation, so a nightly or weekly batch leaves a gap that supervisors increasingly treat as a control weakness rather than an operational choice.

What is real-time sanctions screening?

Real-time screening evaluates a subject against the current state of the sanctions lists at the moment of the check, with new designations ingested continuously and enrolled profiles re-evaluated on every refresh. It removes the window between a designation being published and your systems recognising it.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Join the
Shufti Sphere Newsletter

Get the latest trends, insights, and expert opinions on KYC, AML, fraud prevention, and more, straight to your inbox.

    Pitch a piece and get a verified byline in the Media room.

    Partnership Inquiries?
    Email us at [email protected]

    iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
    Copyright © 2026 Shufti. All rights reserved.