Sanctions screening identifies whether a person, company, payment or commercial relationship may be subject to restrictions under an applicable regime. A reliable process combines list matching with identity verification, ownership research and documented alert review.

For UK businesses, screening matters at onboarding, before relevant payments and throughout a relationship. A counterparty may become restricted after a new designation or ownership change. A clear result supports compliance; it does not prove that a relationship is sanctions-free.

What Is Sanctions Screening?

Sanctions screening compares data about customers, suppliers, beneficial owners, representatives and transactions with official sanctions data. Relevant identifiers can include aliases, dates of birth, addresses, nationalities, registration numbers, vessel identifiers and bank details.

The control often sits alongside KYC compliance and customer due diligence, but these controls are not interchangeable. KYC establishes identity and supports relationship risk assessment. Anti-money laundering controls address financial crime more broadly. Sanctions controls apply the prohibitions and restrictions of specific regimes. One case may engage all three.

Sanctions are not limited to parties connected with terrorism or organised crime. They also respond to armed conflict, proliferation, human rights abuses and other foreign-policy or national-security concerns.

Why Sanctions Screening Matters

A missed exposure can lead to frozen funds, disrupted transactions, regulatory investigation and commercial damage. Under the UK financial sanctions framework, OFSI can impose a civil monetary penalty without proving that a person knew or had reasonable cause to suspect a breach. Appropriate due diligence can still affect its enforcement assessment.

Screening helps a company decide whether to proceed, investigate, seek a licence or legal advice, or report where required. Its audit trail records the data, applicable rules and reason for clearing or escalating an alert.

For suppliers, agents and distributors, screening belongs within third-party due diligence. Exposure may arise through owners, intermediaries, end users or trade routes rather than the contracted entity alone.

How the Sanctions Screening Process Works

1. Define the applicable regimes

There is no universal sanctions rulebook. A business should identify the regimes relevant to its location, staff, counterparties, banks, currencies, transaction routes and activities. US, EU or other exposure depends on the facts, not a generic “global” software setting.

2. Collect reliable identifiers

Names alone rarely resolve identity. The company needs enough accurate information to distinguish the subject from similar names. For organisations, that may include jurisdiction, registration number, trading names, address, directors and ultimate beneficial owners.

3. Match the data against current sources

Software can compare collected data with relevant lists using exact, fuzzy, phonetic and transliteration matching. The system should record the source version and check time, then ingest updates at a speed suited to the organisation’s risk profile.

4. Investigate alerts

An alert is a lead, not a confirmed match. An analyst should compare identifiers, examine ownership and control, review the designation and establish the restrictions. Common names or inconsistent transliteration produce false positives; poor thresholds or incomplete data also create false negatives.

5. Escalate and document the decision

Confirmed or unresolved matches need a defined escalation route. Staff should not reject, freeze or report a party merely because software generated an alert; the response depends on the law and facts. Retain each material source, step and conclusion in an auditable record.

What and When Should a Business Screen?

The scope should reflect how the organisation can acquire exposure. Common controls include:

  • Customer screening: onboarding checks followed by risk-based rescreening.
  • Payment screening: checks on senders, recipients, banks and transaction information.
  • Batch screening: recurring review of customer, employee, investor or supplier records.
  • Event-driven screening: review after a list update, ownership change, new director, altered payment route or merger.
  • Third-party screening: checks on relevant suppliers, agents, distributors, logistics providers, end users and owners.

Higher-risk relationships may need more frequent review. Timing is risk-based and jurisdiction-specific; real-time checks are useful in many payment environments but are not a universal standard for every screening activity.

Which Sanctions Sources Should UK Businesses Check?

Start with the official sources for each applicable regime:

  • The UK Sanctions List contains all current UK designations. Since 28 January 2026, it has been the only source for them; the former OFSI Consolidated List is no longer updated.
  • OFAC publishes the US Specially Designated Nationals and Blocked Persons List and several non-SDN lists.
  • The European Commission provides consolidated financial sanctions data for screening, while the underlying EU legal acts remain authoritative.
  • The UN Security Council consolidates names subject to committee measures, which jurisdictions implement through their legal frameworks.
  • Canada, Australia, Singapore and other jurisdictions maintain national regimes.

A list provider can aggregate data, but it does not decide which law applies. Nor do designation lists capture every sectoral, geographic, trade, technology or service restriction. Screening belongs within wider regulatory compliance risk management.

Why a Clear Name Result Is Not Enough: Ownership and Control

A company may be restricted even when absent from a list. This is where database checking ends and investigation begins.

Under UK rules, an asset freeze and certain other measures can extend to an entity owned or controlled by a designated person. Tests include more than 50% of shares or voting rights, the right to appoint or remove a board majority, or the ability to ensure that the entity acts according to that person’s wishes.

The US test differs. OFAC’s 50 Percent Rule blocks an entity when one or more blocked persons own, directly or indirectly and in aggregate, at least 50%. Control below that threshold does not itself trigger this rule, although it can still create risk.

Analysts may need to map shareholders, voting rights, parent entities, directors, trusts, proxies and recent transfers. A restructuring does not settle who still benefits or directs the business. Molfar’s Supercam sanctions-evasion investigation shows how name-only checks can miss successor entities and proxy procurement channels.

How Technology Supports Screening

Automation helps at scale. Matching engines identify aliases, spelling variants and different scripts; graph tools surface relationships; workflow systems route alerts and preserve decisions. Machine-learning models may help rank alerts.

Models can inherit poor data, produce unexplained scores or miss opaque ownership. Technology should assist analysts, not make irreversible decisions without accountable review. Teams should test thresholds, track false positives and negatives, and validate material findings against primary sources.

Sanctions Screening Best Practices

An effective programme should:

  • assign clear ownership for policy, review and escalation;
  • determine applicable regimes through a documented risk assessment;
  • use current official data and preserve the time and source of each check;
  • collect enough identifiers to resolve potential matches;
  • assess ownership and control instead of relying only on listed names;
  • rescreen after relevant list, customer or transaction changes;
  • tune matching thresholds and independently test the control;
  • train staff to recognise evasion indicators and escalate uncertainty;
  • retain a proportionate audit trail of alerts, evidence and decisions.

The main operational challenge is balance. Overly broad matching can bury analysts in alerts, while narrow rules can miss aliases or transliterations. Weak customer data makes both problems worse. Sanctions rules also differ between jurisdictions, so one decision cannot be copied across every market without checking the governing regime.

Conclusion

Sanctions screening is a continuing detection and investigation process, not a one-time list search. It works best when accurate identity data, current official sources, ownership analysis, calibrated technology and human judgement operate together.

A clean name result is only one finding. Before a high-risk payment or relationship proceeds, the business may still need to establish who owns and controls the counterparty, where value will flow and which legal regimes apply. If your team needs to assess direct or indirect exposure, contact Molfar Intelligence.

Frequently Asked Questions

What is a sanctions screening match?

A match is reached only after an alert has been reviewed against sufficient identifiers and the relevant official designation. Similarity in a name alone is not proof that the screened party is designated.

How often should existing parties be rescreened?

Frequency should reflect the relationship and sanctions risk. Rescreening is commonly triggered by official list changes, new customer information, ownership changes and periodic review cycles.

Are PEP and adverse-media checks part of sanctions screening?

They are related controls, but they answer different questions. A politically exposed person or a subject of negative reporting is not necessarily sanctioned. These checks can inform enhanced due diligence and escalation.

Can AI replace a sanctions analyst?

No. AI can prioritise alerts and improve matching, but it cannot determine legal applicability or resolve opaque ownership reliably without verified evidence and accountable human judgement.

Does a company have to appear on a list to be restricted?

Not always. Restrictions may extend to an unlisted entity through ownership or control rules. The exact test differs by regime, so the analysis must follow the applicable law.

What should a business do with a possible match?

Pause the relevant action where appropriate, preserve the evidence and follow the internal escalation procedure. Confirm the identity, restrictions and legal nexus before deciding whether blocking, licensing, rejection or reporting is required.

Author

Former British Army officer, trained in surveillance and target acquisition, and Bain and Company engagement manager, with more than a decade of experience working in consulting, private equity and venture capital across Western Europe.

Recent posts

View all
View all
White Plus Icon
View all
View all
White Plus Icon

Related posts

View all
View all
White Plus Icon
No items found.
View all
View all
White Plus Icon
Turn Intelligence Into Action
Order a service
Order a service
Black Plus Icon

Our cases

Behind every case is a client who needed clarity in uncertainty. Browse our work to see how we uncover what others miss — and what that means in practice for businesses and decision-makers.

View all cases
View all cases
White Plus Icon
Expanded Plus Icon

Investor Due Diligence: Mitigating Reputational Risks in Defence Tech

Revealed how a high-stakes Defence Tech investment was halted after OSINT-driven due diligence uncovered a co-founder’s links to Russian-origin money laundering and a seized 2.6 billion UAH gambling enterprise, protecting a global firm from severe reputational and regulatory fallout.

Investment

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Pre-Employment Screening for a Spacecraft Manufacturing Role

Conducted a full pre-employment background investigation for a high-security aerospace role, covering court registry checks, financial record verification, ideological risk assessment, and social media OSINT analysis across relevant jurisdictions.

Space

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Sanctions Gaps — Supercam Drone Production Continues

Revealed how Russian drone manufacturers circumvent international sanctions by exploiting a critical design flaw (sanctions applied to company names rather than underlying legal entity identifiers), enabling Supercam to increase production tenfold despite being designated.

Finance

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Cybersecurity Audit and Internal Data Exposure Mitigation

Conducted a comprehensive cybersecurity audit of a long-standing European IT infrastructure, identified critical internal data leaks involving financial plans and performance reviews, and implemented high-level security protocols to mitigate regulatory and operational risks.

Cybersecurity

Learn more
Learn more
White Plus Icon
Gain the Clarity You Need to Move with Confidence

Let’s connect to explore how tailored intelligence can strengthen your decisions, reveal opportunities, and minimise uncertainty.