Skip to content
iGaming Times

Independent industry intelligence in your inbox. Unsubscribe any time - every newsletter carries a one-click link.

Lesson 6 of 7 · 15 min

Sanctions and Screening

Strict liability, not risk-based. Who and what has to be screened, why name matching is genuinely hard, and the well-meaning refund that commits the prohibited act.

In this lesson

  • Explain why sanctions obligations are strict liability and what follows for screening design
  • Identify everything that must be screened, including payment counterparties and B2B partners
  • Handle matching trade-offs using secondary identifiers, reviewable whitelisting and evidenced tuning
  • Execute the freeze, escalate, assess, report sequence without tipping off or making funds available

Sanctions follow a different logic

Everything else in this course is risk-based. Sanctions are not, and mixing the two is the most common conceptual error in this area.

Anti-money-laundering obligations turn on suspicion, materiality and proportionate response. Sanctions obligations are, in most regimes, strict liability: dealing with a designated person or entity, or making funds or economic resources available to them, is prohibited regardless of intent, knowledge or amount. There is no threshold below which it is permitted, no risk rating that excuses it, and no de minimis.

That difference drives everything about how screening is built. A monitoring rule can be tuned for volume. A sanctions screen cannot be tuned down because the false positives are annoying.

The regimes and lists

Several authorities designate persons and entities, and an operator is subject to more than one at a time.

United Nations designations flow into national regimes through domestic implementation.

National and bloc regimes include the European Union's consolidated list, the United Kingdom's list maintained by its financial sanctions authority, and the United States lists administered by the Office of Foreign Assets Control, of which the Specially Designated Nationals list is the best known.

Jurisdictional reach is the trap. US sanctions can apply to non-US firms through use of the US dollar, US persons, US-origin goods or US financial infrastructure. An operator with no US presence can still be exposed through its payment chain, and "we are not a US business" is not an analysis.

Ownership and control rules extend designations beyond the named person. An entity owned or controlled by a designated person is generally treated as designated whether or not it appears on any list, with thresholds and definitions varying by regime. Screening only against the published names therefore misses a category of exposure by design.

Who and what gets screened

Customers, at onboarding and on an ongoing basis. Initial screening alone is insufficient because lists change, and the whole point of a designation is that it happens at a moment in time.

List changes against the existing book. When a list updates, the entire customer base must be rescreened against the delta. An operator that screens at onboarding and never again will not notice a customer designated last month.

Payment counterparties, including the names on instruments funding an account and the destinations of payouts.

Business relationships: affiliates, suppliers, B2B partners, and their beneficial owners. This is the area most often neglected, and the values involved are usually larger than any individual customer's.

Employees and contractors, in some regimes and most policies.

Geography. Some regimes are comprehensive and territorial, prohibiting most dealings with an entire jurisdiction rather than with named persons. That is a market access question, not a screening question, and it belongs in the geoblocking and licensing design rather than in a name-matching engine.

Matching, which is where the difficulty lives

Name matching sounds trivial and is not.

Transliteration produces many valid spellings of the same name from non-Latin scripts. Common names generate very large numbers of coincidental matches. Diminutives and given-name conventions vary by culture. Ordering of family and given names differs. Dates of birth are frequently absent from list entries and from customer records alike.

Systems therefore use fuzzy matching with a similarity threshold, and the threshold is a genuine trade-off. Set it loose and the team drowns in false positives, which leads to superficial clearing, which is how a true match gets closed as noise. Set it tight and true matches with a spelling variation pass through.

Three practices make this workable.

Use secondary identifiers. Date of birth, nationality and place of birth cut false positives dramatically where both records carry them. Collecting date of birth at onboarding is worth it for this reason alone.

Whitelist deliberately and reviewably. A customer cleared against a recurring false match should not be re-alerted every time, but the whitelist entry must record who cleared it, when and on what basis, and must be re-examined when the underlying list entry changes.

Tune with evidence and record it. Threshold changes need a documented rationale and a before-and-after measurement. This is the single most likely area for a supervisor to ask why a number is what it is.

When there is a match

The sequence is prescriptive and the order matters.

Freeze first. Do not process the transaction, do not release funds, do not return the deposit. Making funds or economic resources available to a designated person is the prohibited act, and returning a deposit is making funds available.

Escalate immediately to the nominated officer or sanctions lead. This is not a decision for a first-line agent.

Assess whether the match is genuine, using all available identifiers and the list entry's own detail.

Report to the relevant competent authority within the required timeframe if the match is confirmed. Reporting obligations here are separate from and additional to suspicious activity reporting.

Apply for a licence or authorisation if any dealing is needed, including releasing funds. Some regimes provide licensing routes for specific purposes; none of them permit acting first and asking later.

Do not tip off. The constraints that apply to money laundering reporting generally apply here too.

The error to avoid is the well-meaning one: a customer matched, an agent apologises and refunds the deposit to close the complaint, and the operator has just committed the prohibited act while documenting that it knew.

Adverse media and the wider screen

Adverse media screening searches public sources for information suggesting a customer is involved in financial crime, corruption or other relevant conduct. It is not universally mandated but is standard in enhanced due diligence and is expected for politically exposed persons and high-risk relationships.

Its value is real and its limits should be stated. Coverage is uneven across languages and jurisdictions. Allegation is not conviction, and a hit is a prompt for assessment rather than a conclusion. Name matching has the same difficulties as sanctions screening without the discipline of an authoritative list. And data protection constraints apply to retaining and acting on this material.

The useful discipline is to treat an adverse media hit like any other piece of evidence: record what was found, assess what it means for this relationship, record the conclusion and the reasoning, and set a review trigger. A folder of press cuttings with no assessment is the same failure as a folder of bank statements with no assessment.

Testing the screen

Sanctions screening is testable in a way most controls are not, and an operator that has not tested it has no basis for confidence in it.

Seed a test record matching a real list entry and confirm it alerts. Seed near-miss variations, a transliteration, a middle name dropped, a date of birth one day out, and see which the threshold catches. Push a list update and confirm the existing book is rescreened rather than only new customers. Check that payment counterparty names, not just account holder names, reach the screen. Confirm that B2B partners and affiliates are screened at all, because in many operators they are not.

Each of these takes a day and each has been a published finding somewhere.

Key terms

Strict liability
Liability without a requirement of intent or knowledge. Dealing with a designated person is prohibited whether or not the firm knew, which is why sanctions cannot be treated as risk-based.
Ownership and control
Rules extending a designation to entities owned or controlled by a designated person, whether or not the entity itself appears on a list.
Fuzzy matching
Name matching with a similarity threshold, needed because of transliteration, diminutives, name ordering and missing dates of birth. The threshold is a genuine trade-off.
Whitelisting
Suppressing a recurring false match for a cleared customer. Acceptable only with a record of who cleared it, when and why, and re-examination when the list entry changes.
Adverse media screening
Searching public sources for information suggesting involvement in financial crime or corruption. A prompt for assessment rather than a conclusion, with uneven coverage across languages and jurisdictions.

Key takeaways

  • Sanctions are strict liability in most regimes: no suspicion threshold, no intention requirement, no de minimis, so a screen cannot be tuned down for volume.
  • US sanctions can reach a non-US operator through the dollar, US persons or US financial infrastructure. "We are not a US business" is not an analysis.
  • Ownership and control rules extend designations to entities not named on any list, so screening published names alone misses exposure by design.
  • When a list updates, the entire existing book must be rescreened against the delta, not just new customers.
  • Returning a matched customer’s deposit is making funds available, which is the prohibited act. Freeze first, escalate, then assess.

Check your understanding

3 questions · answer them all, then check.

  1. 1. Why can a sanctions screen not be tuned down when false positives overwhelm the team?

  2. 2. An operator screens every customer at onboarding and never again. What does it miss?

  3. 3. A support agent apologises to a sanctions-matched customer and refunds their deposit to close the complaint. What has happened?

Sign in to track your progress through the course.

Cookie Preferences

Choose which cookies you want to accept. Essential cookies are required for the website to function properly.

Required

Necessary for the website to function. Cannot be disabled.

Help us understand how visitors interact with our website.

Used to deliver relevant advertisements and track ad performance.

Remember your preferences and settings for a better experience.

Sanctions and Screening - Learning hub | iGaming Times