Sanctions follow a different logic
Everything else in this course is risk-based. Sanctions are not, and mixing the two is the most common conceptual error in this area.
Anti-money-laundering obligations turn on suspicion, materiality and proportionate response. Sanctions obligations are, in most regimes, strict liability: dealing with a designated person or entity, or making funds or economic resources available to them, is prohibited regardless of intent, knowledge or amount. There is no threshold below which it is permitted, no risk rating that excuses it, and no de minimis.
That difference drives everything about how screening is built. A monitoring rule can be tuned for volume. A sanctions screen cannot be tuned down because the false positives are annoying.
The regimes and lists
Several authorities designate persons and entities, and an operator is subject to more than one at a time.
United Nations designations flow into national regimes through domestic implementation.
National and bloc regimes include the European Union's consolidated list, the United Kingdom's list maintained by its financial sanctions authority, and the United States lists administered by the Office of Foreign Assets Control, of which the Specially Designated Nationals list is the best known.
Jurisdictional reach is the trap. US sanctions can apply to non-US firms through use of the US dollar, US persons, US-origin goods or US financial infrastructure. An operator with no US presence can still be exposed through its payment chain, and "we are not a US business" is not an analysis.
Ownership and control rules extend designations beyond the named person. An entity owned or controlled by a designated person is generally treated as designated whether or not it appears on any list, with thresholds and definitions varying by regime. Screening only against the published names therefore misses a category of exposure by design.
Who and what gets screened
Customers, at onboarding and on an ongoing basis. Initial screening alone is insufficient because lists change, and the whole point of a designation is that it happens at a moment in time.
List changes against the existing book. When a list updates, the entire customer base must be rescreened against the delta. An operator that screens at onboarding and never again will not notice a customer designated last month.
Payment counterparties, including the names on instruments funding an account and the destinations of payouts.
Business relationships: affiliates, suppliers, B2B partners, and their beneficial owners. This is the area most often neglected, and the values involved are usually larger than any individual customer's.
Employees and contractors, in some regimes and most policies.
Geography. Some regimes are comprehensive and territorial, prohibiting most dealings with an entire jurisdiction rather than with named persons. That is a market access question, not a screening question, and it belongs in the geoblocking and licensing design rather than in a name-matching engine.
Matching, which is where the difficulty lives
Name matching sounds trivial and is not.
Transliteration produces many valid spellings of the same name from non-Latin scripts. Common names generate very large numbers of coincidental matches. Diminutives and given-name conventions vary by culture. Ordering of family and given names differs. Dates of birth are frequently absent from list entries and from customer records alike.
Systems therefore use fuzzy matching with a similarity threshold, and the threshold is a genuine trade-off. Set it loose and the team drowns in false positives, which leads to superficial clearing, which is how a true match gets closed as noise. Set it tight and true matches with a spelling variation pass through.
Three practices make this workable.
Use secondary identifiers. Date of birth, nationality and place of birth cut false positives dramatically where both records carry them. Collecting date of birth at onboarding is worth it for this reason alone.
Whitelist deliberately and reviewably. A customer cleared against a recurring false match should not be re-alerted every time, but the whitelist entry must record who cleared it, when and on what basis, and must be re-examined when the underlying list entry changes.
Tune with evidence and record it. Threshold changes need a documented rationale and a before-and-after measurement. This is the single most likely area for a supervisor to ask why a number is what it is.
When there is a match
The sequence is prescriptive and the order matters.
Freeze first. Do not process the transaction, do not release funds, do not return the deposit. Making funds or economic resources available to a designated person is the prohibited act, and returning a deposit is making funds available.
Escalate immediately to the nominated officer or sanctions lead. This is not a decision for a first-line agent.
Assess whether the match is genuine, using all available identifiers and the list entry's own detail.
Report to the relevant competent authority within the required timeframe if the match is confirmed. Reporting obligations here are separate from and additional to suspicious activity reporting.
Apply for a licence or authorisation if any dealing is needed, including releasing funds. Some regimes provide licensing routes for specific purposes; none of them permit acting first and asking later.
Do not tip off. The constraints that apply to money laundering reporting generally apply here too.
The error to avoid is the well-meaning one: a customer matched, an agent apologises and refunds the deposit to close the complaint, and the operator has just committed the prohibited act while documenting that it knew.
Adverse media and the wider screen
Adverse media screening searches public sources for information suggesting a customer is involved in financial crime, corruption or other relevant conduct. It is not universally mandated but is standard in enhanced due diligence and is expected for politically exposed persons and high-risk relationships.
Its value is real and its limits should be stated. Coverage is uneven across languages and jurisdictions. Allegation is not conviction, and a hit is a prompt for assessment rather than a conclusion. Name matching has the same difficulties as sanctions screening without the discipline of an authoritative list. And data protection constraints apply to retaining and acting on this material.
The useful discipline is to treat an adverse media hit like any other piece of evidence: record what was found, assess what it means for this relationship, record the conclusion and the reasoning, and set a review trigger. A folder of press cuttings with no assessment is the same failure as a folder of bank statements with no assessment.
Testing the screen
Sanctions screening is testable in a way most controls are not, and an operator that has not tested it has no basis for confidence in it.
Seed a test record matching a real list entry and confirm it alerts. Seed near-miss variations, a transliteration, a middle name dropped, a date of birth one day out, and see which the threshold catches. Push a list update and confirm the existing book is rescreened rather than only new customers. Check that payment counterparty names, not just account holder names, reach the screen. Confirm that B2B partners and affiliates are screened at all, because in many operators they are not.
Each of these takes a day and each has been a published finding somewhere.