complysphereadvisory.com

Frequently Asked Questions

What Is Sanction’s Compliance?

Sanctions compliance is the framework of policies, procedures, systems, controls, and governance that helps an organisation identify, assess, and manage sanctions risk while complying with applicable sanctions laws and regulations.

An effective sanctions compliance programme extends beyond checking names against sanctions lists. It may include:

  • A sanctions risk assessment
  • Customer and supplier due diligence
  • Sanctions screening
  • Payment and transaction screening
  • Ownership and control reviews
  • Enhanced due diligence
  • Ongoing monitoring
  • Employee training
  • Escalation and reporting procedures
  • Record keeping
  • Independent testing and assurance

The programme should reflect the organisation’s size, business model, customers, products, services, geographic exposure, transaction activity, and overall risk profile.

Why sanctions compliance matters

Organisations may be exposed to sanctions risk through customers, suppliers, beneficial owners, banks, intermediaries, vessels, products, payment routes, and international trade activity.

A counterparty may not appear directly on a sanctions list but could still present a risk because it is owned or controlled by a designated person or is involved in sanctions circumvention.

Practical example

A UAE trading company receives an order from an overseas customer that does not appear on any sanctions list. An ownership review identifies that the customer is indirectly controlled through several holding companies by a designated individual.

The company escalates the case, performs enhanced due diligence, and decides whether the relationship can proceed under the applicable sanctions requirements.

Best practices

  • Apply a risk-based sanctions compliance framework.
  • Identify all relevant sanctions regimes.
  • Assess direct and indirect exposure.
  • Screen relevant parties and transactions.
  • Review ownership and control.
  • Maintain clear escalation procedures.
  • Keep complete decision records.
  • Review the programme periodically.

Sanctions screening is the process of comparing customers, suppliers, employees, business partners, transactions, vessels, and other relevant parties against applicable sanctions lists to identify potential matches.

It is a core control within a wider sanctions compliance programme, but screening alone may not identify every form of sanctions exposure.

How sanctions screening works

Organisations generally collect identifying information such as:

  • Full legal name
  • Trading names
  • Aliases
  • Date of birth
  • Nationality
  • Address
  • Country of incorporation
  • Registration number
  • Directors
  • Shareholders
  • Ultimate beneficial owners

This information is compared against sanctions data using manual checks or specialist screening software.

A potential match normally generates an alert for review. A compliance analyst then compares the available identifiers to determine whether the alert is:

  • A false positive
  • A possible match requiring further information
  • A confirmed match
  • An indirect ownership or control concern

Practical example

A bank receives a payment involving a customer whose name is similar to that of a designated person. The screening system generates an alert.

The compliance team compares the customer’s date of birth, nationality, address, and identification information with the sanctions record. The differences demonstrate that the customer is not the listed person, and the alert is closed as a false positive.

Best practices

  • Screen before establishing a relationship.
  • Screen relevant transactions before execution.
  • Rescreen following sanctions-list updates.
  • Use reliable and current sanctions data.
  • Investigate alerts using multiple identifiers.
  • Assess ownership and control where appropriate.
  • Document the rationale for every decision.

Sanctions compliance helps organisations identify and manage the risk of dealing directly or indirectly with designated persons, restricted entities, prohibited activities, or sanctioned jurisdictions.

A robust programme supports regulatory compliance while reducing the likelihood of financial loss, operational disruption, reputational damage, and enforcement action.

Common sources of exposure

Sanctions risk may arise through:

  • Customers and beneficial owners
  • Suppliers and distributors
  • Banks and payment intermediaries
  • Agents and brokers
  • Shipping companies and vessels
  • Goods, software, and technology
  • High-risk jurisdictions
  • Third-country transshipment
  • Complex payment routes
  • Changes in ownership or control

Why screening alone is not enough

A party may not be directly named on a sanctions list but may still be restricted because of its ownership, control, activities, or connection to a designated person.

Organisations therefore need to consider screening together with due diligence, ownership analysis, transaction review, geographic exposure, and ongoing monitoring.

Practical example

A logistics company is instructed to reroute goods through several intermediary countries. The consignee is not designated, but the route, goods description, payment structure, and use of multiple intermediaries suggest possible sanctions circumvention.

The company pauses the shipment and conducts enhanced due diligence before deciding whether to proceed.

Best practices

  • Understand the organisation’s sanctions exposure.
  • Apply proportionate controls.
  • Review ownership and control.
  • Monitor transactions and business activity.
  • Escalate unusual or inconsistent activity.
  • Train relevant employees.
  • Test the effectiveness of the programme.

Economic sanctions are restrictive measures imposed by governments or international organisations to influence the behaviour of countries, governments, individuals, entities, sectors, or organisations.

They are commonly used to support foreign policy, national security, international peace, counter-terrorism, human rights, and non-proliferation objectives.

Common types of economic sanctions

Economic sanctions may include:

  • Asset freezes
  • Restrictions on making funds or economic resources available
  • Trade restrictions
  • Import and export prohibitions
  • Investment restrictions
  • Financial-service restrictions
  • Sectoral restrictions
  • Arms embargoes
  • Travel bans
  • Restrictions relating to vessels or aircraft

Some sanctions target specific individuals and entities, while others restrict particular sectors, goods, services, activities, or jurisdictions.

Sanctions and export controls

Sanctions and export controls may overlap, but they are not identical.

Sanctions may restrict dealings with certain persons, jurisdictions, sectors, or activities. Export controls commonly regulate the transfer of particular goods, software, technology, or technical assistance.

A transaction may therefore require both a sanctions assessment and an export-control review.

Practical example

A manufacturer plans to export industrial equipment to an overseas distributor. The distributor is not designated, but the goods may have a dual-use application and the proposed end user operates in a restricted sector.

The manufacturer reviews the parties, destination, end use, export classification, payment arrangements, and applicable licensing requirements before proceeding.

Best practices

  • Determine which restrictions apply.
  • Screen all relevant parties.
  • Review goods, services, and end use.
  • Assess ownership and control.
  • Consider export-control requirements.
  • Keep evidence supporting the decision.

Sanctions are issued by governments, regional bodies, and international organisations to pursue foreign policy, national security, international law, counter-terrorism, human rights, and non-proliferation objectives.

The sanctions regimes relevant to a business depend on its jurisdiction, operations, customers, counterparties, payment flows, currencies, contractual obligations, and international connections.

Major sanctions authorities

Common sanctions authorities include:

  • The United Nations
  • The United States, including the Office of Foreign Assets Control
  • The United Kingdom, including the Office of Financial Sanctions Implementation
  • The European Union
  • The United Arab Emirates
  • Canada
  • Australia
  • Switzerland
  • Other national governments

Which sanctions regimes apply?

An organisation should not assume that every sanctions regime automatically applies in the same way.

Applicability may depend on factors such as:

  • Place of incorporation
  • Location of operations
  • Nationality of employees
  • Currency used
  • Banks involved
  • Location of goods or services
  • Contractual requirements
  • Ownership structure
  • Presence of a US, UK, EU, UAE, or other legal nexus

Some organisations also consider additional sanctions regimes as part of their broader risk appetite, even where direct legal applicability is uncertain.

Practical example

A UAE company plans to supply goods to an overseas customer. The transaction is not prohibited under applicable UAE measures, but the payment will be processed in US dollars through a US correspondent bank.

The company assesses whether US sanctions restrictions or secondary-sanctions risks may affect the transaction before proceeding.

Best practices

  • Identify applicable legal jurisdictions.
  • Map relevant payment and transaction nexuses.
  • Understand contractual screening obligations.
  • Monitor changes across relevant regimes.
  • Seek specialist legal advice where necessary.

A sanctions list is an official record of individuals, entities, organisations, vessels, aircraft, or other parties subject to restrictive measures imposed under a sanctions regime.

The restrictions attached to a listing may include asset freezes, travel bans, financial prohibitions, trade restrictions, or limitations on making funds or economic resources available.

What information appears on a sanctions list?

A sanctions record may include:

  • Full name
  • Aliases
  • Date of birth
  • Place of birth
  • Nationality
  • Address
  • Identification numbers
  • Company registration details
  • Vessel information
  • Reasons for designation
  • Applicable sanctions programme

The available information varies significantly between records. Some entries contain extensive identifying information, while others contain only a name and limited supporting details.

Is every restricted party named on a list?

No. A party may be subject to restrictions even if it is not explicitly listed.

For example, an entity may be treated as restricted because it is owned or controlled by a designated person under the relevant legal framework. Some sanctions also apply to sectors, activities, goods, services, or geographic areas rather than named persons.

Practical example

A company screens a prospective customer and finds no direct sanctions match. However, further due diligence identifies that 60% of the customer is owned by a designated entity.

Depending on the applicable sanctions regime, the customer may itself be subject to restrictions even though its name does not appear separately on the list.

Best practices

  • Use current and reliable sanctions data.
  • Screen aliases and alternative spellings.
  • Consider ownership and control.
  • Review programme-specific restrictions.
  • Do not rely solely on direct name matches.
  • Record the lists and rules considered.

Sanctions compliance and anti-money laundering compliance are related but distinct areas of financial crime risk management.

Sanctions controls are primarily designed to prevent prohibited dealings with designated persons, restricted entities, jurisdictions, sectors, goods, or activities. AML controls are designed to identify and prevent money laundering, terrorist financing, and other forms of financial crime.

Key differences

 

 

        Area

                          Sanctions

                                              AML

Main purpose

Prevent prohibited or restricted dealings

Detect and prevent illicit financial activity

Core control

Sanctions and transaction screening

Customer due diligence and transaction monitoring

Main trigger

Connection to a designated or restricted party, activity, or jurisdiction

Suspicious behaviour, source of funds, transaction patterns, or criminal proceeds

Possible action

Freeze, reject, block, stop, investigate, or report

Investigate, monitor, report suspicious activity, or exit a relationship

Risk approach

Legal prohibitions may apply regardless of risk rating

Generally applies a broader risk-based framework

How they overlap

The same customer or transaction may create both AML and sanctions concerns.

For example, the use of shell companies, nominee shareholders, unexplained payment routes, and third-party payments may indicate:

  • Money laundering
  • Terrorist financing
  • Sanctions circumvention
  • Proliferation financing
  • Fraud or trade-based financial crime

Practical example

A customer sends payments through several unrelated companies in different jurisdictions. The pattern may indicate money laundering, but the use of intermediaries may also be intended to conceal the involvement of a designated party.

The organisation should assess both AML and sanctions risks rather than treating them as separate issues.

Best practices

  • Integrate sanctions and AML information where appropriate.
  • Maintain separate specialist procedures.
  • Escalate overlapping risk indicators.
  • Review ownership, payment flows, and counterparties.
  • Avoid assuming that an AML clearance resolves sanctions risk.

Sanctions and export controls are both forms of trade restriction, but they focus on different aspects of a transaction.

Sanctions commonly restrict dealings with particular persons, entities, jurisdictions, sectors, or activities. Export controls regulate the transfer of specified goods, software, technology, services, or technical information.

Main differences

           Area

                           Sanctions

                                       Export Controls

Main focus

Parties, jurisdictions, sectors, and activities

Goods, software, technology, and technical assistance

Key question

Who is involved and what restrictions apply?

What is being transferred, where, to whom, and for what purpose?

Common controls

Screening, due diligence, ownership review

Classification, licensing, end-use and end-user checks

Typical risk

Dealing with a designated or restricted party

Exporting a controlled item without required authorisation

Where they overlap

A transaction may involve both sanctions and export-control restrictions.

For example, a product may not be prohibited generally, but the end user may be designated. Alternatively, the customer may not be listed, but the goods may require an export licence because of their technical classification, destination, or intended end use.

Practical example

A technology company intends to supply encryption software to an overseas customer.

The customer passes sanctions screening, but the software is controlled and the end user operates in a sensitive industry. The company must assess export classification, end use, destination, licensing requirements, and all relevant parties before proceeding.

Best practices

  • Screen all transaction parties.
  • Classify goods, software, and technology.
  • Verify the end user and end use.
  • Review the final destination.
  • Consider transshipment and diversion risk.
  • Obtain licences where required.
  • Retain supporting documentation.

Primary sanctions generally apply where there is a direct legal connection between a person, organisation, transaction, and the jurisdiction imposing the sanctions.

Secondary sanctions are measures intended to influence the conduct of non-domestic persons by exposing them to restrictions or consequences for engaging in certain activities, even where there is no traditional direct jurisdictional connection.

What are primary sanctions?

Primary sanctions may apply because of factors such as:

      Nationality Place of incorporation

      Location of activity

      Use of a regulated financial system

      Involvement of a domestic person

Use of controlled goods or services

For example, US primary sanctions generally apply to US persons and activities within US jurisdiction, although the precise scope depends on the relevant programme and legal rules.

What are secondary sanctions?

Secondary sanctions may target non-US persons for engaging in specified conduct involving sanctioned countries, sectors, entities, or activities.

Possible consequences may include:

      Restrictions on access to the US financial system Designation

      Limits on correspondent banking relationships

      Restrictions on property or transactions

      Other commercial or financial measures

Practical example

A non-US company enters into a significant transaction with an entity operating in a sector targeted by US secondary sanctions.

The transaction may not involve a US person or US dollar payment, but the company could still face secondary-sanctions exposure depending on the applicable legal measures and activity.

Best practices

      Identify direct legal nexuses.

      Assess secondary-sanctions exposure.

      Review counterparties and ownership structures.

      Understand sector-specific restrictions.

      Consider banking and commercial consequences.

Escalate complex cases for specialist advice.

Sectoral sanctions are restrictions targeting particular sectors of an economy rather than imposing a complete prohibition on all dealings with a country or every entity operating within that sector.

They are often more limited and technically complex than full asset-freeze sanctions.

Which sectors may be targeted?

Sectoral measures may apply to areas such as:

  • Banking and financial services
  • Energy
  • Defence
  • Mining
  • Technology
  • Transport
  • State-owned enterprises
  • Sovereign debt
  • Capital markets

The restrictions may limit particular activities rather than prohibit every transaction with the affected entity.

What restrictions can apply?

Sectoral sanctions may restrict:

  • New debt or equity
  • Financing
  • Investment
  • Certain goods or services
  • Technology transfers
  • Capital-market activity
  • Dealings connected to specific projects
  • Transactions involving identified subsidiaries

The precise wording of the applicable regulation is critical.

Practical example

A company wishes to supply equipment to a large energy business that is subject to sectoral restrictions but not a full asset freeze.

The transaction is not automatically prohibited. However, the company must assess the type of equipment, the project, financing arrangements, payment terms, ownership structure, and any restrictions affecting the relevant energy activity.

Common mistake

A frequent mistake is treating a sectorally sanctioned entity as either completely unrestricted or fully blocked.

In reality, some activities may be permitted while others are prohibited or require a licence.

Best practices

  • Identify the exact sectoral restriction.
  • Review the transaction rather than relying only on the party’s name.
  • Assess goods, services, financing, and payment terms.
  • Review subsidiaries and ownership.
  • Consider export controls.
  • Obtain legal advice for complex transactions.

About Comply Sphere Advisory

Comply Sphere Advisory supports organisations with:

  • Sanctions risk assessments
  • Sanctions gap assessments
  • Sanctions screening reviews
  • Ownership and control assessments
  • Nexus transaction assessments
  • Sanctions investigations
  • Policy and framework development
  • Training and independent assurance

The appropriate approach will depend on the organisation’s business model, applicable jurisdictions, products, customers, and overall sanctions exposure.

Which Sanctions Lists Should Businesses Screen Against?

Businesses should screen against the sanctions lists relevant to their legal, regulatory, contractual, geographic, and risk-based obligations. There is no single combination of lists that is automatically appropriate for every organisation.

The correct screening scope depends on factors including:

  • Where the organisation is incorporated
  • Where it operates
  • The nationality and location of its employees
  • The countries in which its customers and suppliers operate
  • The currencies used for transactions
  • The banks and payment systems involved
  • The goods, services, software, or technology supplied
  • Contractual requirements imposed by banks or business partners
  • The organisation’s sanctions risk appetite

Common sanctions lists

Depending on the organisation’s exposure, relevant sources may include:

  • United Nations Security Council Consolidated List
  • OFAC Specially Designated Nationals and Blocked Persons List
  • OFAC non-SDN sanctions lists
  • UK Sanctions List
  • EU consolidated financial sanctions list
  • UAE Local Terrorist List
  • Other applicable national or regional sanctions lists

The UN Consolidated List includes individuals and entities subject to measures imposed by the UN Security Council. OFAC publishes both its SDN List and consolidated non-SDN data. The UK Sanctions List contains all current UK sanctions designations, while the EU maintains consolidated data covering persons, groups, and entities subject to EU financial sanctions.

Is screening against four major lists enough?

Not necessarily.

Screening against the UN, US, UK, and EU lists may provide broad coverage, but it does not automatically satisfy every organisation’s obligations. Businesses may also need to consider:

  • UAE or other domestic lists
  • Sectoral sanctions
  • Export-control restricted-party lists
  • Vessel and aircraft restrictions
  • Internal risk lists
  • Regulatory enforcement lists
  • Ownership and control rules

A company may also face restrictions through an entity that is not named on a list but is owned or controlled by a designated person.

Practical example

A UAE trading company accepts payments in US dollars, purchases goods from the European Union, and supplies customers across the Middle East and Central Asia.

Its screening framework may need to consider:

  • UAE requirements
  • UN sanctions
  • US sanctions because of the payment nexus
  • EU restrictions affecting the supplier or goods
  • Relevant export-control requirements
  • Restrictions imposed by its banking partners

Best practices

  • Document which lists are used and why.
  • Map the organisation’s legal and transactional nexuses.
  • Include domestic sanctions requirements.
  • Consider sectoral and non-list-based restrictions.
  • Review ownership and control.
  • Reassess coverage when the business model changes.
  • Monitor regulatory and list updates.

The United Nations Security Council Consolidated List contains individuals and entities subject to measures imposed by the UN Security Council. Listings are made under separate sanctions regimes established in response to threats to international peace and security.

The inclusion of names in one consolidated list does not mean that every listed party is subject to the same sanctions programme or listing criteria. Each sanctions regime is administered separately by a relevant Security Council sanctions committee.

Why are individuals and entities listed?

UN sanctions regimes may address issues such as:

  • Terrorism
  • Armed conflict
  • Threats to international peace
  • Nuclear proliferation
  • Weapons proliferation
  • Support for designated groups
  • Political destabilisation
  • Serious violations connected to particular conflicts

The specific reasons for designation depend on the relevant UN sanctions regime.

What measures may apply?

Depending on the programme, measures may include:

  • Asset freezes
  • Travel bans
  • Arms embargoes
  • Restrictions on making funds available
  • Restrictions on making economic resources available
  • Other programme-specific prohibitions

Not every measure applies to every listed person. Businesses should review the relevant regime and legal implementation rather than relying only on the presence of a name.

Who must implement UN sanctions?

UN member states are required to implement Security Council sanctions through their domestic legal frameworks.

For a business, the direct legal obligation generally arises through the laws and regulations of the jurisdictions in which it operates—not merely from the existence of the UN list itself.

Practical example

A company screens a proposed business partner and identifies a possible match to an individual listed under a UN counter-terrorism regime.

The company should:

  1. Pause the relevant activity where required.
  2. Compare all available identifiers.
  3. Determine whether the person is a true match.
  4. Review the measures attached to the designation.
  5. Follow applicable domestic freezing, reporting, and non-disclosure requirements.
  6. Document its decision and actions.

Best practices

  • Use the current UN Consolidated List.
  • Review the relevant sanctions regime.
  • Compare more than the party’s name.
  • Consider aliases and alternative spellings.
  • Understand domestic implementation requirements.
  • Maintain escalation and reporting procedures.
  • Keep records of the review and decision.

The Specially Designated Nationals and Blocked Persons List, commonly called the SDN List, is published by the US Department of the Treasury’s Office of Foreign Assets Control.

It includes individuals, entities, groups, vessels, aircraft, and other persons designated under US sanctions programmes. OFAC states that the list includes persons owned or controlled by, or acting for or on behalf of, targeted countries, as well as parties designated under non-country-specific programmes.

What restrictions apply to an SDN?

As a general principle, property and interests in property of an SDN that come within US jurisdiction are blocked, and US persons are generally prohibited from dealing with the SDN unless authorised by OFAC.

However, the precise restrictions depend on:

  • The legal authority used
  • The sanctions programme
  • Applicable general licences
  • Specific licences
  • Regulatory exemptions
  • The type of transaction involved

Does the SDN List only affect US businesses?

No.

US persons and activities within US jurisdiction are directly subject to applicable OFAC restrictions. Non-US organisations may also be affected where a transaction involves:

  • US persons
  • US financial institutions
  • US-origin goods or services
  • Activity within the United States
  • A US dollar payment routed through the US financial system
  • Conduct creating secondary-sanctions exposure
  • Contractual requirements imposed by banks or partners

Applicability should be assessed carefully rather than assumed.

What is the OFAC 50 Percent Rule?

Under OFAC’s ownership approach, an entity may be treated as blocked where one or more blocked persons own, directly or indirectly and in aggregate, 50% or more of the entity.

This means a company may be restricted even though its own name does not appear on the SDN List.

Is the SDN List OFAC’s only list?

No.

OFAC also maintains several non-SDN lists, which are available through its Consolidated Sanctions List data. The restrictions associated with non-SDN listings may differ from full blocking sanctions.

Practical example

A company screens a prospective customer and finds no direct SDN match. Further due diligence identifies that two blocked persons each own 30% of the customer.

Their combined ownership is 60%. The customer may therefore be treated as blocked under OFAC’s ownership rule, even though it is not separately named on the SDN List.

Best practices

  • Screen the SDN and relevant non-SDN lists.
  • Review the applicable sanctions programme.
  • Assess direct and indirect ownership.
  • Consider aggregation of blocked ownership.
  • Identify any US nexus.
  • Review available licences and authorisations.
  • Seek specialist advice in complex cases.

The UK Sanctions List is the official list of individuals, entities, and specified ships designated under UK sanctions regulations.

Since 28 January 2026, it has been the sole official source for all current UK sanctions designations. The former OFSI Consolidated List of Asset Freeze Targets has closed and is no longer updated.

Who maintains the UK Sanctions List?

The UK Sanctions List is published by the Foreign, Commonwealth & Development Office.

The Office of Financial Sanctions Implementation remains responsible for implementing and enforcing UK financial sanctions, providing guidance, issuing licences, and receiving relevant reports.

What information does the list contain?

A UK Sanctions List entry may contain:

  • Full name
  • Aliases
  • Date and place of birth
  • Nationality
  • Address
  • Identification information
  • Entity registration details
  • Ship information
  • Relevant sanctions regime
  • Measures imposed
  • Statement of reasons
  • Date of designation

What measures may apply?

Depending on the relevant regulations, a designated person may be subject to:

  • Asset freezes
  • Restrictions on making funds available
  • Restrictions on making economic resources available
  • Director disqualification measures
  • Trust-service restrictions
  • Travel bans
  • Transport sanctions
  • Other programme-specific measures

Businesses must examine the designation and the applicable regulations rather than assuming that every listing has the same legal effect.

Are unlisted companies ever restricted?

Yes.

The UK Sanctions List search service expressly notes that prohibitions may also apply to unlisted entities owned or controlled by a designated person.

An ownership and control assessment is therefore essential where a designated person may have direct or indirect influence over a company.

Practical example

A UK-connected company screens an overseas supplier and finds no direct list match. Due diligence identifies that a designated individual owns 40% of the supplier but has contractual rights to appoint the majority of its directors.

The company should assess whether the designated individual controls the supplier under the applicable UK rules, notwithstanding ownership below 50%.

Best practices

  • Use the current UK Sanctions List.
  • Do not rely on the closed OFSI Consolidated List.
  • Review the measures attached to each designation.
  • Assess ownership and control.
  • Monitor designation notices and amendments.
  • Review applicable OFSI guidance and licences.
  • Maintain escalation and reporting procedures.

The EU consolidated financial sanctions list brings together individuals, groups, and entities subject to EU financial sanctions, particularly asset-freeze measures.

It is maintained to help organisations identify persons subject to EU restrictive measures. The European Commission manages and updates the consolidated financial sanctions data whenever necessary.

What does the list cover?

The consolidated list principally supports identification of persons subject to EU financial sanctions, including:

  • Individuals
  • Companies
  • Organisations
  • Groups
  • Other listed entities

The list may contain information such as:

  • Names
  • Aliases
  • Dates of birth
  • Places of birth
  • Nationalities
  • Addresses
  • Identification details
  • Relevant sanctions programme

Does the consolidated list contain every EU restriction?

No.

The consolidated list is an important screening source, but it does not replace a review of the applicable EU regulation.

EU sanctions may also include:

  • Sectoral restrictions
  • Trade prohibitions
  • Export and import restrictions
  • Investment restrictions
  • Restrictions on services
  • Transport measures
  • Capital-market restrictions
  • Controls applying to particular goods or technology

A transaction may therefore be restricted even when none of the parties appears on the consolidated list.

Who must comply with EU sanctions?

EU sanctions generally apply:

  • Within EU territory
  • To EU nationals wherever located
  • To entities incorporated under the law of an EU member state
  • On board aircraft and vessels under member-state jurisdiction
  • In other circumstances defined by the relevant EU regulation

The precise scope must be reviewed against the applicable legal instrument.

Practical example

An EU-incorporated exporter plans to provide industrial machinery to a non-listed overseas customer.

The customer passes sanctions screening, but the product is covered by an export restriction and the intended end user operates in a prohibited sector.

The exporter must assess the relevant EU regulation, end use, destination, and licensing requirements rather than relying only on name screening.

Best practices

  • Screen against current EU consolidated data.
  • Review the applicable EU regulation.
  • Consider sectoral and trade restrictions.
  • Assess ownership and control.
  • Verify end users and end use.
  • Consider member-state licensing requirements.
  • Keep evidence of the legal and compliance assessment.

Sanctions lists do not follow one universal update schedule. Authorities may add, amend, or remove entries whenever a legally effective designation, variation, correction, or delisting occurs.

Updates can happen several times within a short period, particularly during geopolitical crises or major enforcement activity. For example, OFAC’s recent-actions records show multiple sanctions-list updates occurring within the same month.

What types of changes occur?

Sanctions-list updates may include:

  • New designations
  • Delistings
  • Changes to names
  • New aliases
  • Updated addresses
  • New passport or identification details
  • Amended dates of birth
  • Programme changes
  • Corrections to existing records
  • Changes involving vessels or aircraft

Even a minor change may affect the ability of a screening system to identify a match accurately.

How quickly should businesses update their screening data?

The appropriate frequency depends on:

  • Applicable legal obligations
  • Business risk
  • Transaction speed
  • Customer volumes
  • Products and services
  • Regulatory expectations
  • Available technology
  • Whether activity is processed in real time

Financial institutions and other businesses processing high volumes of transactions may require automated and near-real-time updates.

Lower-volume organisations may use periodic processes, but they should ensure that list changes are incorporated quickly enough to avoid conducting prohibited activity.

What should happen after a list update?

Depending on the organisation’s risk and controls, an update may trigger:

  • Rescreening of the customer base
  • Rescreening of beneficial owners
  • Rescreening of suppliers and vendors
  • Review of pending payments
  • Review of open trade transactions
  • Review of vessels, aircraft, or counterparties
  • Escalation of newly generated alerts

Practical example

An existing customer is not designated at onboarding but is added to an applicable sanctions list six months later.

If the organisation relies only on onboarding screening, the change may not be detected. Ongoing rescreening identifies the new designation and allows the company to take required action promptly.

Best practices

  • Use reliable and current data sources.
  • Automate updates where proportionate.
  • Rescreen relevant records after changes.
  • Define update and rescreening timelines.
  • Monitor amendments and delistings.
  • Test whether updates load correctly.

Maintain an audit trail of list changes.

Sanctions screening works by comparing identifying information about a person, entity, transaction, vessel, aircraft, or other relevant party against applicable sanctions data.

Potential similarities generate alerts that are reviewed to determine whether they represent false positives, possible matches, confirmed matches, or indirect sanctions exposure.

Stage 1: Data collection

Effective screening begins with accurate information.

Relevant data may include:

  • Full legal name
  • Aliases
  • Date of birth
  • Place of birth
  • Nationality
  • Address
  • Identification number
  • Company registration number
  • Country of incorporation
  • Directors and shareholders
  • Beneficial owners
  • Vessel name and IMO number

Poor-quality data can significantly reduce screening effectiveness.

Stage 2: List selection

The organisation determines which lists and restrictions are relevant to its:

  • Legal obligations
  • Regulatory requirements
  • Geographic exposure
  • Payment flows
  • Products and services
  • Contractual obligations
  • Risk appetite

Stage 3: Name comparison

Screening systems may use:

  • Exact matching
  • Fuzzy matching
  • Phonetic matching
  • Transliteration
  • Alias matching
  • Word-order variation
  • Character substitution

OFAC’s official search tool, for example, uses fuzzy logic to identify potential matches against the SDN and non-SDN consolidated lists.

Stage 4: Alert investigation

An analyst compares the customer or transaction information with the sanctions record.

Relevant identifiers may include:

  • Name
  • Date of birth
  • Nationality
  • Address
  • Passport number
  • Company registration details
  • Ownership
  • Geographic links

Stage 5: Decision and action

The alert may be:

  • Closed as a false positive
  • Escalated for further information
  • Subject to enhanced due diligence
  • Confirmed as a true match
  • Referred for legal advice
  • Blocked, rejected, frozen, or reported where required

The correct action depends on the applicable sanctions regime.

Practical example

A screening system flags “Mohamed Ali Trading LLC” because of a similar listed name.

The compliance analyst reviews the company registration number, incorporation country, owners, address, and trading activity. The information is inconsistent with the listed entity, and the alert is closed with a documented rationale.

Best practices

  • Obtain complete identifying information.
  • Configure matching thresholds appropriately.
  • Screen aliases and alternative spellings.
  • Train analysts to investigate alerts.
  • Review ownership and control.
  • Maintain escalation procedures.
  • Test screening effectiveness regularly.

Banks use specialist screening systems, customer information, transaction data, and compliance procedures to identify potential exposure to designated persons, restricted entities, sanctioned jurisdictions, or prohibited activities.

Screening normally occurs throughout the customer relationship rather than only when an account is opened.

Customer screening

During onboarding, banks may collect and screen:

  • Customer name
  • Date and place of birth
  • Nationality
  • Address
  • Identification documents
  • Business activities
  • Directors
  • Shareholders
  • Beneficial owners
  • Authorised signatories
  • Connected parties

The customer population may then be rescreened when sanctions lists change or customer information is updated.

Payment screening

Banks may screen information contained in:

  • Domestic transfers
  • Cross-border payments
  • SWIFT messages
  • Correspondent banking transactions
  • Remittances
  • Trade-finance payments
  • Securities transactions

Depending on the message and transaction type, screening may cover:

  • Originator
  • Beneficiary
  • Banks
  • Intermediaries
  • Ordering institutions
  • Free-text fields
  • Addresses
  • Countries
  • Vessel information

Trade-finance screening

Trade transactions may require screening of:

  • Importers
  • Exporters
  • Banks
  • Shipping companies
  • Vessels
  • Ports
  • Insurers
  • Goods descriptions
  • End users
  • Beneficial owners

How are alerts reviewed?

A potential match is reviewed using available identifiers. The analyst decides whether the alert is:

  • A false positive
  • A potential match requiring more information
  • A true match
  • An ownership or control concern
  • A broader transaction-nexus concern

Higher-risk cases may require enhanced due diligence, legal review, freezing, rejection, reporting, or senior approval.

Practical example

A bank receives a cross-border payment involving a company whose name resembles an SDN.

The analyst reviews:

  • Registration number
  • Incorporation country
  • Business activities
  • Ownership
  • Address
  • Payment purpose
  • Counterparties

The company is not the listed entity, but the payment is connected to a restricted sector. The case is escalated for a broader sanctions review rather than closed solely as a name mismatch.

Best practices

  • Screen customers and beneficial owners.
  • Screen payments before execution where required.
  • Apply ongoing customer rescreening.
  • Review transaction context, not only names.
  • Maintain effective list management.
  • Calibrate systems using risk-based thresholds.
  • Independently test screening effectiveness.
  • Retain complete investigation records.

Sanctions screening should be performed at the points in the business relationship where sanctions exposure may arise. It should not be treated as a one-time onboarding exercise.

The frequency should reflect applicable legal requirements, regulatory expectations, transaction activity, and the organisation’s risk profile.

When should screening occur?

Screening may be required:

  • Before onboarding a customer
  • Before appointing a supplier or distributor
  • Before entering a partnership
  • Before processing a payment
  • Before shipping goods
  • Before completing a trade-finance transaction
  • When sanctions lists are updated
  • When ownership or control changes
  • When customer information changes
  • During periodic customer reviews
  • When new geographic risks arise
  • When unusual activity is identified

What is ongoing screening?

Ongoing screening means regularly comparing existing customer and counterparty data against updated sanctions lists.

It helps detect parties that become designated after the original relationship began.

Ongoing monitoring may be:

  • Event-driven
  • Daily
  • Near real time
  • Periodic
  • Triggered by list updates
  • Triggered by customer-data changes

Does every business need real-time screening?

Not necessarily.

Real-time screening may be appropriate for:

  • Banks
  • Payment companies
  • FinTech businesses
  • Remittance providers
  • Virtual-asset businesses
  • High-volume trading companies
  • Businesses processing time-sensitive international transactions

A lower-volume company may apply a different approach, provided its controls remain proportionate and effective.

Practical example

A supplier passes screening when first appointed. Several months later, its majority shareholder is designated.

An event-driven rescreening process generates an alert shortly after the list update. The organisation pauses new orders and assesses whether the supplier is now subject to restrictions.

Best practices

  • Screen before establishing relationships.
  • Screen relevant transactions before completion.
  • Rescreen following list updates.
  • Trigger reviews after ownership changes.
  • Apply enhanced frequency to higher-risk parties.
  • Document the screening frequency and rationale.
  • Test whether event-driven screening works.

Effective sanctions screening requires enough accurate information to distinguish the person or entity being screened from parties appearing on sanctions lists.

A name alone is rarely sufficient, particularly where names are common, transliterated differently, or shared by many individuals and companies.

Information for individuals

Relevant information may include:

  • Full legal name
  • Previous names
  • Aliases
  • Date of birth
  • Place of birth
  • Nationality
  • Country of residence
  • Residential address
  • Passport number
  • National identification number
  • Occupation
  • Employer
  • Gender, where legally permitted and relevant

Information for companies

Relevant information may include:

  • Full legal name
  • Trading names
  • Previous names
  • Registration number
  • Date of incorporation
  • Country of incorporation
  • Registered address
  • Operating address
  • Business activity
  • Directors
  • Shareholders
  • Ultimate beneficial owners
  • Parent companies
  • Subsidiaries
  • Authorised signatories

Information for transactions

Relevant data may include:

  • Originator
  • Beneficiary
  • Banks and intermediaries
  • Payment purpose
  • Currency
  • Countries involved
  • Goods or services
  • Invoice information
  • Shipping route
  • Ports
  • Vessel name
  • IMO number
  • End user
  • Final destination

Why is data quality important?

Incomplete or inaccurate data may cause:

  • Missed true matches
  • Excessive false positives
  • Inconsistent decisions
  • Delays to legitimate transactions
  • Weak audit trails
  • Regulatory concerns

For example, screening “Mohammed Khan” without a date of birth, nationality, or address may produce many possible matches that cannot be resolved efficiently.

Practical example

A company wants to onboard an overseas distributor but collects only its trading name and website.

Screening identifies no direct match. Subsequent due diligence reveals that:

  • The legal name is different.
  • The company recently changed ownership.
  • A designated person holds an indirect majority interest.

Had the company screened only the trading name, the ownership risk might have remained unidentified.

Best practices

  • Collect full and verified legal names.
  • Obtain secondary identifiers.
  • Capture aliases and previous names.
  • Verify company registration details.
  • Identify beneficial owners.
  • Review parent and subsidiary relationships.
  • Maintain current customer records.
  • Ensure screening data is accurately mapped into the system.

About Comply Sphere Advisory

Comply Sphere Advisory supports organisations with:

  • Sanctions screening framework reviews
  • Sanctions-list coverage assessments
  • Screening-system optimisation
  • False-positive reduction
  • Sanctions risk assessments
  • Ownership and control reviews
  • Nexus transaction assessments
  • Sanctions investigations
  • Policy and procedure development
  • Training and independent assurance

The appropriate sanctions framework depends on the organisation’s legal obligations, geographic footprint, business model, customers, products, payment flows, and overall exposure.

Due Diligence and Risk Assessment

How Do You Perform Sanctions Due Diligence?

Sanctions due diligence is the process of collecting and assessing information about a customer, supplier, transaction, business partner, or other counterparty to identify direct and indirect sanctions exposure.

The depth of due diligence should reflect the level of risk. A low-risk domestic customer may require standard checks, while a complex cross-border transaction involving high-risk jurisdictions, intermediaries, or sensitive goods may require enhanced due diligence.

What does sanctions due diligence include?

A sanctions due diligence review may include:

     Verifying the party’s legal identity

     Screening the party against relevant sanctions lists

     Identifying directors and shareholders

     Establishing ultimate beneficial ownership

     Assessing ownership and control

     Reviewing geographic exposure

     Understanding the nature of the relationship

     Reviewing goods, services, and transaction purpose

     Assessing payment and banking arrangements

     Identifying intermediaries and third parties

     Reviewing adverse information

     Considering export-control restrictions

     Assessing sanctions-circumvention indicators

Sanctions due diligence should go beyond determining whether a name appears on a list. A non-listed company may still be restricted because it is owned or controlled by a designated person.

Practical example

A UAE commodities company receives an order from a recently established overseas trading company.

The customer does not appear on a sanctions list. However, further due diligence identifies:

     A shared director with several high-risk companies

     Payment from an unrelated third party

     A shipping route involving multiple intermediary jurisdictions

     Limited evidence of genuine business activity

     A possible connection to a restricted end user

The company escalates the case and conducts enhanced due diligence before deciding whether to proceed.

Best practices

     Apply a documented risk-based approach.

     Verify information using reliable sources.

     Identify beneficial owners and controlling persons.

     Understand the transaction’s commercial purpose.

     Review all relevant jurisdictions and parties.

     Escalate inconsistencies and red flags.

     Record the rationale for the final decision.

Refresh due diligence when risk factors change.

Enhanced Due Diligence, commonly known as EDD, is a more detailed review performed when a customer, counterparty, transaction, jurisdiction, or activity presents elevated sanctions risk.

EDD helps an organisation understand risks that cannot be resolved through standard screening or routine customer due diligence.

When may EDD be required?

Enhanced due diligence may be appropriate where there is:

  • Exposure to a sanctioned or high-risk jurisdiction
  • A complex or opaque ownership structure
  • Possible ownership or control by a designated person
  • Use of nominees or unexplained intermediaries
  • Unusual third-party payments
  • Involvement of sensitive or dual-use goods
  • A high-risk shipping route
  • Adverse media relating to sanctions evasion
  • A connection to a restricted sector
  • An unclear end user or end use
  • A recently incorporated company with limited commercial history
  • Inconsistency between the customer profile and transaction activity

EDD should be proportionate to the identified risk rather than performed as a generic document-collection exercise.

What may EDD include?

An enhanced review may involve:

  • Obtaining additional corporate documents
  • Verifying the source of funds
  • Identifying the source of wealth
  • Mapping the full ownership chain
  • Reviewing shareholder agreements
  • Assessing control rights
  • Verifying the end user and end use
  • Reviewing contracts, invoices, and shipping documents
  • Obtaining an explanation of payment routes
  • Conducting open-source intelligence research
  • Reviewing adverse media
  • Seeking senior-management approval
  • Obtaining specialist legal advice

Practical example

A technology supplier receives an order for advanced electronic components from a distributor in a third country.

The distributor is not designated, but the goods could have military applications and the proposed delivery route creates a risk of diversion.

The supplier performs EDD by verifying:

  • The distributor’s ownership
  • The end user
  • The intended end use
  • The destination
  • The shipping route
  • The payment source
  • Whether export authorisation is required

Best practices

  • Define clear EDD triggers.
  • Tailor the review to the specific risk.
  • Verify information independently.
  • Resolve inconsistencies before approval.
  • Obtain senior approval for higher-risk relationships.
  • Document unresolved concerns.
  • Apply ongoing monitoring after onboarding.
  • Decline the relationship where risks cannot be managed.

The documents required for a sanctions review depend on the nature of the customer, transaction, goods, jurisdictions, and identified risk.

There is no universal document list suitable for every case. The organisation should request enough information to understand who is involved, what is taking place, why the transaction is occurring, and whether any restrictions apply.

Corporate documents

For companies and other legal entities, documents may include:

  • Certificate of incorporation
  • Commercial or trade licence
  • Memorandum and articles of association
  • Company registry extract
  • Shareholder register
  • Director register
  • Organisation chart
  • Ownership structure chart
  • Ultimate beneficial owner declaration
  • Partnership agreement
  • Trust deed
  • Shareholder agreement
  • Board resolutions
  • Authorised-signatory documents

Identification documents

For individuals, directors, shareholders, or beneficial owners, relevant documents may include:

  • Passport
  • National identity card
  • Proof of address
  • Residence permit
  • Date and place of birth
  • Nationality information
  • Employment or occupation details

Transaction documents

A transaction review may require:

  • Contract
  • Purchase order
  • Invoice
  • Payment instruction
  • Bank details
  • Bill of lading
  • Air waybill
  • Packing list
  • Certificate of origin
  • Customs declaration
  • Insurance documents
  • Vessel details
  • Shipping route
  • End-user certificate
  • End-use declaration
  • Export licence
  • Import permit

Supporting commercial information

The organisation may also request:

  • Explanation of the business relationship
  • Purpose of the transaction
  • Source of funds
  • Details of third-party payments
  • Customer or supplier website
  • Evidence of trading history
  • Details of agents or intermediaries
  • Confirmation of the final destination

Practical example

A supplier receives payment from a company that is not named in the sales contract.

Before proceeding, the supplier requests:

  • An explanation of the third-party payment
  • Evidence of the relationship between the payer and buyer
  • The underlying contract
  • Corporate documents for the payer
  • Beneficial ownership information
  • Bank evidence confirming the source of payment

The documents identify an unexplained link to a high-risk intermediary, and the case is escalated.

Best practices

  • Request documents based on the identified risk.
  • Verify documents using independent sources.
  • Check for inconsistencies between documents.
  • Confirm that documents are current.
  • Translate foreign-language documents where necessary.
  • Validate ownership information.
  • Record which documents were reviewed.
  • Avoid treating document collection as proof that risk is resolved.

A sanctions risk assessment is a structured evaluation of the sanctions risks faced by an organisation and the effectiveness of the controls used to manage those risks.

It helps the organisation understand where sanctions exposure may arise and whether its policies, systems, governance, screening, due diligence, and monitoring arrangements are proportionate.

What does a sanctions risk assessment examine?

A comprehensive assessment may consider:

  • Customer types
  • Supplier and counterparty exposure
  • Products and services
  • Geographic exposure
  • Transaction volumes
  • Payment currencies
  • Banking relationships
  • Trade routes
  • Distribution channels
  • Ownership structures
  • Use of agents and intermediaries
  • Goods, software, and technology
  • Sectoral exposure
  • Export-control risk
  • Sanctions-circumvention risk

The assessment should evaluate both inherent risk and the effectiveness of existing controls.

Inherent risk

Inherent risk is the level of sanctions exposure before considering controls.

For example, a business dealing in dual-use technology across high-risk jurisdictions may have a high inherent risk even where it has no known sanctions breaches.

Residual risk

Residual risk is the risk remaining after controls have been considered.

Controls may include:

  • Customer screening
  • Payment screening
  • Ownership reviews
  • Enhanced due diligence
  • Transaction monitoring
  • Training
  • Governance
  • Independent testing

Practical example

A shipping company identifies high inherent risk because it operates:

  • Across multiple jurisdictions
  • Through agents and charterers
  • In sectors vulnerable to sanctions evasion
  • With frequent changes to vessels and counterparties

The company assesses whether vessel screening, ownership checks, route monitoring, and escalation procedures reduce the risk to an acceptable level.

Best practices

  • Define a clear methodology.
  • Assess inherent and residual risk separately.
  • Use relevant and supportable risk factors.
  • Include ownership and control exposure.
  • Consider sanctions circumvention.
  • Record assumptions and limitations.
  • Obtain senior-management approval.
  • Link findings to a remediation plan.
  • Review the assessment periodically.

A sanctions risk assessment is usually conducted by identifying relevant risk factors, evaluating the organisation’s inherent exposure, assessing existing controls, determining residual risk, and agreeing any required remediation.

The methodology should be proportionate to the organisation’s size, activities, and sanctions exposure.

Step 1: Define the scope

The organisation should determine which areas will be assessed, such as:

  • Legal entities
  • Business units
  • Branches
  • Products
  • Customer populations
  • Suppliers
  • Payment activities
  • Trade activity
  • Jurisdictions
  • Technology systems

Step 2: Identify risk factors

Common sanctions risk factors include:

  • Customers connected to high-risk jurisdictions
  • Complex ownership structures
  • Cross-border payments
  • Sensitive goods
  • Use of intermediaries
  • High-risk sectors
  • Correspondent banking
  • Shipping activity
  • Virtual assets
  • Third-country transshipment
  • Exposure to state-owned entities

Step 3: Assess inherent risk

The organisation evaluates the likelihood and potential impact of sanctions exposure before controls are considered.

Risk may be rated using categories such as:

  • Low
  • Moderate
  • High
  • Severe

The scoring system should be clearly defined and consistently applied.

Step 4: Assess controls

Controls may be evaluated based on:

  • Design
  • Implementation
  • Effectiveness
  • Coverage
  • Governance
  • Documentation
  • Testing results
  • Known incidents
  • Regulatory findings

Step 5: Determine residual risk

Residual risk is calculated or assessed after considering the quality of controls.

A high inherent risk may remain high where controls are weak or untested.

Step 6: Agree remediation

Identified weaknesses should be converted into actions with:

  • A clear owner
  • A deadline
  • A priority rating
  • Required resources
  • Evidence of completion
  • Senior oversight

Practical example

A FinTech company identifies high inherent risk because it processes rapid cross-border payments.

Its assessment identifies weaknesses in:

  • Customer-data quality
  • Beneficial-owner screening
  • List-update controls
  • Alert investigation
  • Independent testing

The company prioritises remediation before expanding into additional markets.

Best practices

  • Use evidence rather than unsupported assumptions.
  • Involve relevant business and control functions.
  • Challenge control effectiveness.
  • Validate risk scores.
  • Record the reasons for ratings.
  • Track remediation centrally.
  • Report material risks to senior management.
  • Update the assessment when the business changes.

A sanctions risk assessment should include the factors that could expose the organisation to prohibited, restricted, or high-risk activity.

The factors selected should reflect the organisation’s actual business model rather than relying entirely on a generic template.

Customer risk

Customer-related factors may include:

  • Customer type
  • Legal form
  • Business activity
  • Ownership structure
  • Beneficial owners
  • State ownership
  • Political exposure
  • Reputation
  • Expected activity
  • Use of nominees
  • Connection to sanctioned persons

Geographic risk

Geographic factors may include:

  • Country of incorporation
  • Country of residence
  • Operating locations
  • Customer and supplier locations
  • Payment origin and destination
  • Shipping routes
  • Ports
  • Transshipment jurisdictions
  • Countries subject to sanctions
  • Countries known for diversion activity

Product and service risk

Higher-risk products or services may include:

  • Cross-border payments
  • Correspondent banking
  • Trade finance
  • Commodity trading
  • Shipping
  • Virtual assets
  • Dual-use goods
  • Advanced technology
  • Professional services
  • Company formation
  • High-value goods

Transaction risk

Relevant factors may include:

  • Transaction value
  • Transaction frequency
  • Currency
  • Payment route
  • Intermediaries
  • Third-party payments
  • Unusual commercial terms
  • Goods description
  • End use
  • Final destination

Delivery-channel risk

Risk may also arise through:

  • Non-face-to-face onboarding
  • Online platforms
  • Agents
  • Brokers
  • Distributors
  • Introducers
  • Third-party service providers

Control risk

The assessment should consider whether the organisation has effective:

  • Screening systems
  • Customer due diligence
  • Ownership checks
  • Payment controls
  • Escalation procedures
  • Training
  • Governance
  • Quality assurance
  • Independent testing
  • Record keeping

Practical example

A family office may have a low volume of clients but significant sanctions risk because of:

  • High-value cross-border investments
  • Complex holding structures
  • Clients with international political connections
  • Investments in sensitive jurisdictions
  • Use of trusts and offshore companies

Risk should therefore be assessed by exposure, not simply customer volume.

Best practices

  • Use both quantitative and qualitative factors.
  • Avoid relying solely on country risk.
  • Include ownership and control.
  • Consider products and transaction purpose.
  • Assess indirect and circumvention risks.
  • Review control effectiveness separately.
  • Update factors as the business evolves.

A sanctions exposure assessment is a focused review of how a specific organisation, customer, transaction, product, jurisdiction, or business activity may be connected to sanctions risk.

It is narrower than an enterprise-wide sanctions risk assessment and is often used to support a particular decision.

When is an exposure assessment used?

An assessment may be performed when:

     Entering a new market

     Launching a new product

     Onboarding a high-risk customer

     Reviewing a complex transaction

     Assessing a sanctioned-country connection

     Evaluating a new supplier

     Establishing a banking relationship

     Reviewing indirect ownership

     Responding to a regulatory concern

     Assessing a potential sanctions incident

What does it examine?

A sanctions exposure assessment may consider:

     Applicable legal regimes

     Direct sanctions matches

     Ownership and control

     Customer and counterparty connections

     Geographic nexus

     Payment routes

     Currency

     Banks involved

     Goods or services

     End use and end user

     Sectoral restrictions

     Export controls

     Secondary-sanctions risk

     Circumvention indicators

Practical example

A UAE company plans to provide consulting services to a non-listed company with operations in Russia.

The assessment reviews:

     The customer’s ownership

     The type of services

     Whether any service restrictions apply

     The location of performance

     The banks and currencies involved

     The customer’s sector

     Any US, UK, EU, or UAE nexus

     Whether an exemption or licence may be relevant

What is the outcome?

The assessment may conclude that the activity is:

     Permitted

     Permitted subject to controls

     Higher risk but manageable

     Requiring legal advice

     Requiring a licence

     Outside risk appetite

     Prohibited

Best practices

     Define the precise question being assessed.

     Identify all relevant parties and jurisdictions.

     Distinguish legal prohibition from risk appetite.

     Consider indirect ownership and control.

     Review both sanctions and export controls.

     Clearly state assumptions and limitations.

 

     Record the final recommendation.

The time required to complete a sanctions risk assessment depends on the size, complexity, geographic reach, products, systems, and quality of available information.

A focused assessment for a small business may take several days, while an enterprise-wide assessment for a bank or multinational organisation may take several weeks or longer.

Factors affecting the timeline

The duration may depend on:

  • Number of legal entities
  • Number of business units
  • Geographic footprint
  • Customer volumes
  • Product complexity
  • Transaction volumes
  • Availability of reliable data
  • Number of systems
  • Quality of existing documentation
  • Number of stakeholder interviews
  • Scope of sample testing
  • Level of senior-management review

Indicative examples

A focused assessment may involve:

  • One legal entity
  • A limited number of products
  • A small customer population
  • Basic screening controls
  • Limited international exposure

A more complex assessment may cover:

  • Multiple countries
  • Several regulated entities
  • Cross-border payments
  • Trade finance
  • Correspondent banking
  • Shipping
  • Multiple screening platforms
  • Complex data analysis

What can delay an assessment?

Common causes of delay include:

  • Incomplete customer data
  • Missing policies
  • Unclear ownership of controls
  • Limited system documentation
  • Inconsistent management information
  • Difficulty obtaining transaction data
  • Delayed stakeholder responses
  • Unresolved legal questions

Practical example

A small UAE consultancy with limited cross-border exposure may complete a focused assessment relatively quickly.

A financial institution operating across several countries will require a broader review involving:

  • Multiple sanctions regimes
  • Customer and transaction data
  • Screening systems
  • Business interviews
  • Control testing
  • Governance review
  • Senior approval

Best practices

  • Agree the scope before starting.
  • Identify required data early.
  • Assign internal owners.
  • Set realistic deadlines.
  • Escalate missing information.
  • Separate urgent risks from longer-term improvements.
  • Avoid sacrificing quality to meet an artificial timeline.

A sanctions risk assessment should be reviewed periodically and whenever material changes affect the organisation’s sanctions exposure.

An annual review is common, but the appropriate frequency should reflect the organisation’s risk, regulatory environment, and pace of change.

What events should trigger a review?

A review may be required when the organisation:

  • Enters a new country
  • Launches a new product
  • Changes its customer base
  • Begins serving a new industry
  • Introduces a new payment channel
  • Acquires another business
  • Changes its ownership
  • Appoints new intermediaries
  • Expands shipping or trade activity
  • Implements a new screening system
  • Identifies a sanctions incident
  • Receives a regulatory finding
  • Experiences major geopolitical change
  • Faces significant new sanctions measures

Why is periodic review important?

Sanctions risk can change quickly because of:

  • New designations
  • New sanctions programmes
  • Changes to ownership
  • New trade restrictions
  • Changes to payment routes
  • New circumvention methods
  • Changes to customer behaviour
  • Expansion into new markets

An assessment that was appropriate one year ago may no longer reflect current exposure.

What should the review include?

The organisation should consider:

  • Changes to inherent risk
  • New products and jurisdictions
  • Control improvements
  • Control failures
  • Screening performance
  • Investigation trends
  • Regulatory developments
  • Internal audit findings
  • Remediation progress
  • Residual-risk ratings

Practical example

A business originally sells only within the UAE but later begins exporting industrial products to Central Asia.

Its previous risk assessment may not address:

  • Export controls
  • Diversion risk
  • High-risk shipping routes
  • New banking relationships
  • Third-country intermediaries
  • End-user verification

The company should update the assessment before or immediately after entering the new market.

Best practices

  • Review the assessment at least periodically.
  • Use event-driven reviews for material changes.
  • Document all changes to risk ratings.
  • Link the assessment to business strategy.
  • Report material changes to senior management.
  • Update policies and controls where necessary.
  • Track remediation arising from each review.

About Comply Sphere Advisory

Comply Sphere Advisory supports organisations with:

  • Enterprise-wide sanctions risk assessments
  • Focused sanctions exposure assessments
  • Sanctions gap assessments
  • Customer and transaction due diligence
  • Enhanced due diligence reviews
  • Ownership and control assessments
  • Sanctions-circumvention reviews
  • Policies, procedures, and governance frameworks
  • Remediation planning
  • Independent testing and assurance

Each assessment should be tailored to the organisation’s business model, jurisdictions, products, customer profile, transaction activity, and overall sanctions exposure.

Ownership, Investigations and Circumvention

What Is an Ownership and Control Review?

An ownership and control review is an assessment of whether a company, organisation, trust, or other legal arrangement is directly or indirectly owned or controlled by a designated person.

This review is important because an entity may be subject to sanctions restrictions even when its own name does not appear on an official sanctions list.

What does the review examine?

An ownership and control review may consider:

  • Direct shareholders
  • Indirect shareholders
  • Ultimate beneficial owners
  • Intermediate holding companies
  • Voting rights
  • Board-appointment rights
  • Shareholder agreements
  • Management powers
  • Financing arrangements
  • Trust and nominee arrangements
  • Informal influence
  • Rights to direct the entity’s affairs

The relevant test depends on the applicable sanctions regime. US, UK, EU, UAE, and other rules should not be assumed to operate identically.

Ownership and control are not always the same

Ownership generally concerns shares, voting interests, or other proprietary rights.

Control may exist even where ownership is below a particular percentage. Depending on the legal regime, a person may control an entity through:

  • The right to appoint or remove directors
  • Contractual rights
  • Dominant influence
  • Financial dependence
  • Management authority
  • The practical ability to direct the entity’s affairs

Under UK financial-sanctions rules, entities owned or controlled by a designated person may be subject to the same financial restrictions even when they are not separately listed. Businesses are expected to conduct their own due diligence because no complete official list of all such indirectly restricted entities exists.

Practical example

A designated person owns 35% of a private company.

The remaining shares are widely distributed, but the designated person has contractual rights to:

  • Appoint most directors
  • Approve the annual budget
  • Direct major commercial decisions
  • Remove senior management

Although the person does not own a majority of the shares, these rights may indicate control under the applicable legal framework.

Best practices

  • Map the complete ownership chain.
  • Identify all intermediate companies.
  • Aggregate ownership where the applicable rules require it.
  • Review voting rights and contractual powers.
  • Examine shareholder and financing agreements.
  • Consider both legal and practical control.
  • Document the methodology and conclusion.
  • Obtain specialist advice where control is unclear.

Ultimate beneficial ownership refers to the natural person or persons who ultimately own, control, or benefit from a company, trust, partnership, foundation, or other legal arrangement.

The ultimate beneficial owner, commonly called the UBO, may not be the person whose name appears in the immediate shareholder register.

Why is UBO identification important?

Complex corporate structures can be used legitimately, but they may also conceal:

  • Designated persons
  • Sanctions evaders
  • Corrupt officials
  • Criminal proceeds
  • Undisclosed controllers
  • Nominee shareholders
  • Hidden commercial beneficiaries

FATF identifies transparency of beneficial ownership as an important measure for preventing criminals and sanctions evaders from hiding behind companies, trusts, and complex legal structures.

How is a UBO identified?

A review usually begins with the immediate shareholders and continues through each ownership layer until the relevant natural persons are identified.

The process may involve:

  1. Obtaining the shareholder register.
  2. Identifying corporate shareholders.
  3. Reviewing each intermediate company.
  4. Calculating direct and indirect ownership.
  5. Identifying voting or control rights.
  6. Reviewing nominee or trust relationships.
  7. Confirming the natural persons who ultimately benefit or exercise control.

Is the highest-percentage shareholder always the UBO?

Not necessarily.

A person with a smaller ownership interest may exercise control through:

  • Voting agreements
  • Board rights
  • Family relationships
  • Trust arrangements
  • Financing
  • Management powers
  • Informal influence

Similarly, a shareholder shown in official records may be acting as a nominee for another person.

Practical example

Company A is owned by:

  • Company B: 60%
  • Individual C: 40%

Company B is owned equally by two individuals.

The indirect economic ownership of Company A is therefore:

  • Individual 1: 30%
  • Individual 2: 30%
  • Individual C: 40%

The review should also assess whether any person has additional voting, appointment, or control rights.

Best practices

  • Trace ownership to natural persons.
  • Verify information independently.
  • Review trusts and nominee arrangements.
  • Calculate indirect ownership accurately.
  • Identify persons exercising control.
  • Screen all relevant beneficial owners.
  • Refresh information after ownership changes.

Record any uncertainty or limitation.

Indirect ownership exists where a person holds an interest in an entity through one or more intermediate companies, partnerships, trusts, or other legal arrangements.

It can create sanctions exposure even where the designated person is not shown as a direct shareholder of the entity being reviewed.

How is indirect ownership calculated?

The calculation depends on the applicable sanctions regime and the structure involved.

A simple economic calculation may multiply ownership percentages through each level.

For example:

  • A person owns 80% of Company A.
  • Company A owns 60% of Company B.
  • The person has a 48% economic interest in Company B.

However, sanctions rules do not always use a simple multiplication approach.

Under OFAC’s 50 Percent Rule, indirect ownership is assessed through entities that are themselves owned 50% or more in aggregate by blocked persons. OFAC provides detailed examples showing how direct and indirect interests may be combined.

Why can indirect ownership be difficult?

Complex structures may involve:

  • Multiple ownership layers
  • Cross-shareholdings
  • Nominees
  • Trusts
  • Foundations
  • Different classes of shares
  • Voting rights that differ from economic ownership
  • Joint ownership by several designated persons
  • Recently transferred interests
  • Incomplete registry information

Practical example

A blocked individual owns:

  • 50% of Holding Company A
  • 10% directly in Operating Company B

Holding Company A owns 40% of Operating Company B.

Under OFAC’s published example, the blocked person may be treated as indirectly owning Holding Company A’s 40% interest in Operating Company B. Combined with the person’s direct 10% interest, the total reaches 50%, meaning Operating Company B would be treated as blocked under the OFAC rule.

Common mistake

A common mistake is screening only the immediate shareholder.

This may overlook:

  • A designated person several layers above the customer
  • Aggregated ownership held through several companies
  • Ownership transferred to a family member or associate
  • A controlling trust beneficiary
  • A designated person with significant contractual rights

Best practices

  • Obtain a complete ownership chart.
  • Verify each intermediate entity.
  • Calculate direct and indirect interests.
  • Apply the correct regime-specific methodology.
  • Aggregate interests where required.
  • Review control separately from ownership.
  • Challenge unexplained recent transfers.
  • Document all calculations.

OFAC’s 50 Percent Rule provides that an entity is treated as blocked where one or more blocked persons own, directly or indirectly and in aggregate, 50% or more of that entity.

The entity does not need to be named separately on the SDN List for its property and interests in property to be considered blocked.

How does aggregation work?

Ownership held by multiple blocked persons is aggregated.

For example:

  • Blocked Person A owns 25%.
  • Blocked Person B owns 25%.
  • Combined blocked ownership is 50%.

The entity would generally be treated as blocked under OFAC’s rule.

Does the rule include indirect ownership?

Yes.

OFAC’s rule covers ownership held through intermediate entities where the required ownership conditions are met.

The analysis may require reviewing:

  • Parent companies
  • Holding companies
  • Subsidiaries
  • Joint ventures
  • Cross-shareholdings
  • Aggregated holdings of several blocked persons

Does control alone trigger the OFAC rule?

No.

OFAC states that control without ownership of 50% or more does not automatically cause the controlled entity to be treated as blocked under the 50 Percent Rule.

However, OFAC also advises caution because a controlled company may later be designated, and dealings with the blocked controller may still be prohibited.

What happens if blocked ownership falls below 50%?

OFAC states that an entity is no longer automatically considered blocked under the 50 Percent Rule where blocked ownership is genuinely reduced below 50%.

However, any divestment involving blocked property must comply with applicable US sanctions requirements, and transactions involving blocked persons cannot simply be treated as valid without considering authorisation requirements.

Practical example

A company is owned by:

  • Blocked Person A: 20%
  • Blocked Person B: 15%
  • A blocked holding company: 20%
  • Unrestricted investors: 45%

The combined blocked ownership is 55%.

The company may therefore be treated as blocked even though no single blocked person owns 50%.

Best practices

  • Screen all significant shareholders.
  • Identify blocked persons at every ownership level.
  • Aggregate blocked ownership.
  • Assess direct and indirect holdings.
  • Do not confuse ownership with control.
  • Review recent ownership changes carefully.
  • Reassess the structure after sanctions updates.

Obtain legal advice for complex structures.

Ownership and control are important because sanctions restrictions can extend beyond the persons and entities explicitly named on official sanctions lists.

A business that relies solely on direct name screening may fail to identify a company that is owned or controlled by a designated person.

What risks can be missed?

Without an ownership and control review, an organisation may overlook:

  • A designated ultimate beneficial owner
  • Aggregated ownership held by several designated persons
  • A designated person controlling the board
  • A sanctioned parent company
  • A hidden trust beneficiary
  • A nominee shareholder
  • A recent transfer intended to conceal ownership
  • An unlisted subsidiary treated as restricted

Why is name screening insufficient?

Screening confirms whether the name being checked is similar to a listed record.

It does not automatically establish:

  • Who owns the company
  • Who controls management
  • Who benefits economically
  • Whether shares are held through intermediaries
  • Whether ownership has been transferred to an associate
  • Whether a designated person retains informal influence

The UK ownership and control framework is expressly intended to prevent sanctions from being easily circumvented through unlisted entities.

Practical example

A customer is owned by four companies, each based in a different jurisdiction.

None of the immediate shareholders is designated. An extended review shows that three of the holding companies are ultimately owned by the same designated person.

Without tracing the complete ownership chain, the sanctions exposure would not have been identified.

Consequences of getting the assessment wrong

Potential consequences may include:

  • Processing a prohibited payment
  • Making funds available to a designated person
  • Providing goods or services to a restricted entity
  • Regulatory reporting failures
  • Asset-freezing failures
  • Enforcement action
  • Loss of banking relationships
  • Reputational damage

Best practices

  • Embed ownership reviews into onboarding.
  • Apply enhanced checks to complex structures.
  • Review ownership after material changes.
  • Screen beneficial owners and controllers.
  • Use reliable corporate information.
  • Train analysts in regime-specific rules.
  • Establish specialist escalation procedures.
  • Maintain a clear audit trail.

A sanctions investigation may be triggered when an organisation identifies information suggesting that a customer, transaction, counterparty, or business activity may involve a designated person, restricted entity, prohibited jurisdiction, sanctioned sector, or sanctions-evasion arrangement.

The trigger may arise from screening, transaction monitoring, employee escalation, external intelligence, or a regulatory request.

Common investigation triggers

A sanctions investigation may begin following:

  • A potential sanctions-screening match
  • A newly designated customer or beneficial owner
  • A possible ownership or control connection
  • A payment involving a restricted jurisdiction
  • An unusual third-party payment
  • A change in company ownership
  • An unexplained intermediary
  • A suspicious shipping route
  • A high-risk vessel
  • Inconsistent end-user information
  • A potential dual-use-goods transaction
  • Adverse media
  • A law-enforcement or regulatory enquiry
  • A suspected breach reported internally
  • Activity inconsistent with the customer profile

Does every screening alert require a full investigation?

No.

Many screening alerts can be resolved as false positives by comparing reliable identifiers.

A more detailed investigation is generally appropriate where:

  • Identifiers match closely
  • Information is incomplete
  • Ownership is complex
  • Transaction activity is unusual
  • A high-risk jurisdiction is involved
  • Several sanctions indicators appear together
  • The potential consequences are significant

Practical example

A bank receives a payment involving a non-listed trading company.

The name alert is initially weak, but the transaction also involves:

  • A vessel previously associated with sanctions evasion
  • Payment by an unrelated third party
  • A high-risk transshipment jurisdiction
  • An unclear goods description

The combined indicators justify a broader sanctions investigation.

Immediate steps

Depending on the applicable legal obligations and risk, the organisation may need to:

  • Pause or hold the transaction
  • Preserve relevant records
  • Restrict account activity
  • Escalate the matter
  • Obtain further information
  • Review legal obligations
  • Consider reporting requirements
  • Avoid tipping off relevant parties where prohibited

Best practices

  • Define investigation triggers.
  • Preserve evidence immediately.
  • Assign a qualified investigator.
  • Separate facts from assumptions.
  • Review direct and indirect exposure.
  • Document all investigative steps.
  • Escalate confirmed or unresolved risks.
  • Obtain legal advice where necessary.

A sanctions investigation is conducted by defining the issue, preserving evidence, identifying all relevant parties, reviewing the applicable restrictions, analysing ownership and transactions, and determining whether a breach or exposure has occurred.

The investigation should be proportionate, independent, and fully documented.

Step 1: Define the allegation or concern

The investigator should establish:

  • What triggered the review
  • Which transaction or relationship is affected
  • Which sanctions regimes may apply
  • What immediate risks exist
  • Whether activity should be paused
  • Whether reporting deadlines apply

Step 2: Preserve information

Relevant evidence may include:

  • Customer files
  • Screening alerts
  • Payment messages
  • Emails
  • Contracts
  • Invoices
  • Shipping documents
  • Ownership records
  • System logs
  • Call notes
  • Approval records
  • Internal policies

Step 3: Identify all parties

The investigation should identify:

  • Customers
  • Beneficial owners
  • Directors
  • Counterparties
  • Banks
  • Intermediaries
  • Agents
  • Vessels
  • Freight forwarders
  • Consignees
  • End users
  • Other connected parties

Step 4: Determine the sanctions nexus

The review should consider:

  • Jurisdictions involved
  • Currency
  • Location of persons
  • Nationality
  • Banks and payment routes
  • Goods and services
  • Export origin
  • End use
  • Applicable sectoral restrictions
  • Ownership and control

Step 5: Analyse the activity

The investigator may reconstruct:

  • Payment flows
  • Ownership chains
  • Transaction timelines
  • Shipping routes
  • Communications
  • Changes in documentation
  • Customer explanations
  • Previous related activity

Step 6: Reach a conclusion

The investigation may conclude that:

  • No sanctions exposure occurred
  • The alert was a false positive
  • Controls operated correctly
  • A potential breach occurred
  • A reporting obligation may exist
  • Further legal advice is required
  • Remediation is necessary

Practical example

A company discovers that goods were shipped to a distributor but may have been re-exported to a restricted end user.

The investigation reviews:

  • The original contract
  • End-use statements
  • Shipping data
  • Distributor communications
  • Payment routes
  • Beneficial ownership
  • Prior transactions
  • Applicable export and sanctions restrictions

The final report identifies both the factual findings and weaknesses in the company’s end-use verification process.

Best practices

  • Use a written investigation plan.
  • Preserve evidence.
  • Apply legal privilege where appropriate.
  • Maintain independence.
  • Test customer explanations.
  • Identify control failures.
  • Record unresolved limitations.
  • Agree corrective actions.
  • Report material matters appropriately.

A nexus transaction assessment is a structured review used to determine which sanctions regimes, legal restrictions, banking requirements, and risk considerations may be connected to a transaction.

It examines the links—or nexuses—between the parties, jurisdictions, currencies, goods, services, payment channels, and financial institutions involved.

What types of nexus may be relevant?

A transaction may have a sanctions nexus through:

  • Place of incorporation
  • Nationality
  • Residency
  • Location of activity
  • Currency
  • Correspondent banks
  • Payment systems
  • Origin of goods
  • Destination of goods
  • Vessel flag
  • Aircraft registration
  • Employee involvement
  • Ownership and control
  • Contractual obligations
  • Use of US, UK, EU, UAE, or other financial infrastructure

Why is a nexus assessment necessary?

A transaction may appear unrelated to a particular jurisdiction but still create legal or commercial exposure.

For example:

  • A non-US transaction may involve a US person.
  • A payment may clear through a US correspondent bank.
  • Goods may be of EU origin.
  • A UK employee may approve the transaction.
  • A UAE entity may be subject to domestic targeted financial-sanctions obligations.
  • A non-listed counterparty may be owned by a designated person.

Practical example

A UAE company proposes to sell European-origin technology to a Central Asian distributor and receive payment in US dollars.

The assessment considers:

  • UAE obligations
  • EU export and sanctions restrictions
  • The US dollar-clearing nexus
  • The distributor’s ownership
  • The final end user
  • Diversion risk
  • Contractual requirements imposed by banks

Possible outcomes

A nexus assessment may conclude that the transaction is:

  • Permitted
  • Permitted with enhanced controls
  • Subject to licensing
  • Subject to additional due diligence
  • Outside the organisation’s risk appetite
  • Potentially prohibited
  • Requiring external legal advice

Best practices

  • Map every relevant transaction party.
  • Identify currencies and banks.
  • Review goods, services, origin, and destination.
  • Assess ownership and control.
  • Distinguish legal obligations from commercial risk.
  • Document assumptions and unresolved questions.
  • Obtain appropriate approvals.
  • Retain a complete decision record.

Sanctions circumvention is conduct designed to avoid, bypass, conceal, or frustrate the application of sanctions restrictions.

It may involve restructuring transactions, hiding ownership, using intermediaries, altering shipping routes, or disguising the true source, destination, or beneficiary of funds, goods, services, or economic resources.

How does circumvention occur?

Common methods may include:

  • Front companies
  • Shell companies
  • Nominee shareholders
  • Undisclosed beneficial owners
  • Third-country intermediaries
  • False invoices
  • Misleading goods descriptions
  • Complex payment chains
  • Third-party payments
  • Transshipment
  • Vessel identity manipulation
  • Falsified end-user documents
  • Transfers to relatives or associates
  • Rapid changes in ownership
  • Use of professional facilitators

Complex legal structures are not automatically suspicious, but they may be misused to conceal sanctions evaders or beneficial owners. FATF has highlighted the use of shell companies and complex structures to conceal the activities and property of sanctions evaders.

What is the difference between evasion and circumvention?

The terms are often used interchangeably.

Broadly:

  • Circumvention focuses on arranging activity to bypass sanctions restrictions.
  • Evasion commonly refers to deliberately concealing or misrepresenting prohibited activity.

The precise legal terminology depends on the relevant sanctions regulation.

Practical example

A newly incorporated company orders dual-use electronic components.

The company is not listed, but:

  • It shares directors with high-risk entities.
  • Payment comes from an unrelated third party.
  • The goods are routed through several countries.
  • The stated end user cannot be verified.
  • The company has no obvious commercial presence.

Together, these factors may indicate an attempt to conceal the real beneficiary or destination.

Best practices

  • Assess the full commercial context.
  • Verify ownership and control.
  • Review payment and shipping routes.
  • Confirm the end user and end use.
  • Challenge unexplained intermediaries.
  • Monitor changes in transaction behaviour.
  • Train staff on circumvention typologies.
  • Escalate combinations of red flags.

Sanctions-evasion techniques are methods used to conceal a designated person, restricted destination, prohibited end user, or sanctioned activity.

A red flag does not automatically establish a breach. However, one serious indicator—or several indicators appearing together—may justify enhanced due diligence, transaction suspension, or investigation.

Ownership and corporate red flags

Potential indicators include:

  • Complex ownership without a clear commercial purpose
  • Nominee directors or shareholders
  • Recently transferred ownership
  • Shares transferred to relatives or close associates
  • Frequent changes in directors
  • Use of shell or front companies
  • Inconsistent beneficial-ownership information
  • Multiple companies using the same address
  • Directors connected to numerous unrelated companies
  • Reluctance to disclose ownership

Payment red flags

These may include:

  • Payment by an unrelated third party
  • Payment from a high-risk jurisdiction
  • Multiple intermediaries without explanation
  • Sudden changes in currency or bank
  • Payments split into smaller amounts
  • Overpayments followed by refund requests
  • Payments inconsistent with the contract
  • Use of personal accounts for commercial activity
  • Circular or unexplained payment flows

Trade red flags

Potential indicators include:

  • Vague goods descriptions
  • Misclassification of products
  • Pricing inconsistent with market value
  • Goods inconsistent with the customer’s business
  • Unusual quantities
  • Last-minute changes to destination
  • Incomplete end-user information
  • Refusal to provide end-use documentation
  • Use of high-risk transshipment points
  • Freight routes that make little commercial sense

Shipping red flags

These may include:

  • Frequent vessel-name changes
  • Flag changes
  • Ownership changes
  • Disabled or manipulated tracking signals
  • Ship-to-ship transfers in high-risk areas
  • Unexplained changes in port
  • Inconsistent bills of lading
  • Use of vessels with opaque ownership
  • Multiple intermediaries in the shipping chain

Behavioural red flags

Potential indicators include:

  • Pressure to complete the transaction urgently
  • Unwillingness to answer due-diligence questions
  • Inconsistent explanations
  • Requests to omit information from payment messages
  • Requests to alter invoice descriptions
  • Attempts to avoid normal documentation
  • Use of personal email accounts
  • Excessive secrecy around the end user
  • Unusual concern about specific banks or currencies

Practical example

A machinery exporter receives an order from a small distributor with no relevant industry history.

The customer:

  • Requests removal of the end-user name
  • Pays through a third company
  • Changes the destination after shipment
  • Provides inconsistent product-use information
  • Routes the goods through a known diversion hub

No single indicator proves sanctions evasion, but the combination warrants escalation and enhanced review.

How should red flags be handled?

The organisation should:

  1. Pause the activity where appropriate.
  2. Gather additional information.
  3. Verify explanations independently.
  4. Review ownership and counterparties.
  5. Examine related historic transactions.
  6. Assess sanctions and export-control obligations.
  7. Escalate unresolved concerns.
  8. Document the decision.

Best practices

  • Maintain sector-specific red-flag guidance.
  • Avoid checklist-only decision-making.
  • Assess combinations of indicators.
  • Train commercial and operational employees.
  • Use trade, payment, and ownership information together.
  • Monitor emerging evasion typologies.
  • Escalate unexplained inconsistencies.
  • Report suspected breaches where required.

About Comply Sphere Advisory

Comply Sphere Advisory supports organisations with:

  • Ownership and control reviews
  • Ultimate beneficial-ownership analysis
  • OFAC 50 Percent Rule assessments
  • Complex ownership mapping
  • Nexus transaction assessments
  • Sanctions investigations
  • Circumvention-risk reviews
  • Trade and payment-flow analysis
  • Enhanced due diligence
  • Sanctions policies and investigation procedures
  • Staff training and independent assurance

Ownership, control, and circumvention assessments should be tailored to the applicable sanctions regime, the organisation’s legal nexus, its business model, and the facts of the individual relationship or transaction.

UAE and Industry-Specific Sanctions Compliance

Can a UAE Company Be Fined for Breaching Sanctions?

A UAE company may face regulatory, administrative, civil, or criminal consequences if it fails to comply with applicable UAE targeted financial sanctions, anti-money laundering, counter-terrorist financing, proliferation-financing, or import and export-control requirements.

The precise consequences depend on the applicable legislation, the nature of the breach, the company’s regulated status, the conduct involved, and whether the failure was deliberate, negligent, systemic, or promptly reported.

What sanctions obligations may apply?

UAE organisations may be required to:

  • Screen customers and counterparties
  • Screen beneficial owners and controlling persons
  • Monitor the UAE Local Terrorist List
  • Monitor relevant UN Security Council designations
  • Freeze funds or other assets without delay where required
  • Prevent funds or economic resources from being made available
  • Submit required reports
  • Maintain appropriate policies and procedures
  • Retain supporting records
  • Cooperate with supervisory and competent authorities

Cabinet Decision No. 74 of 2020 establishes the UAE framework for implementing targeted financial sanctions connected to the UAE Local Terrorist List and relevant UN Security Council resolutions.

What can happen following a compliance failure?

Depending on the circumstances, possible consequences may include:

  • Regulatory findings
  • Administrative penalties
  • Financial penalties
  • Restrictions on business activity
  • Licence conditions or suspension
  • Remediation requirements
  • Increased regulatory supervision
  • Criminal investigation
  • Reputational damage
  • Loss of banking or commercial relationships

The consequences are not limited to cases involving an obvious direct sanctions match. Failures relating to ownership, control, reporting, screening, asset freezing, or sanctions-evasion indicators may also create material exposure.

Practical example

A UAE company identifies that an existing customer may be controlled by a person appearing on an applicable sanctions list.

The company continues processing transactions without:

  • Completing an ownership and control assessment
  • Escalating the potential match
  • Considering whether assets should be frozen
  • Making the relevant regulatory report
  • Documenting the reasons for continuing the relationship

The organisation may face scrutiny not only for the underlying transactions but also for weaknesses in its sanctions governance and escalation framework.

What should a company do after identifying a potential breach?

The organisation should consider:

  1. Stopping or restricting the relevant activity.
  2. Preserving all documents and system records.
  3. Escalating the matter to senior compliance and legal personnel.
  4. Determining whether funds or assets must be frozen.
  5. Assessing applicable reporting obligations.
  6. Investigating the underlying facts.
  7. Identifying affected customers and transactions.
  8. Remediating any control failures.

Best practices

  • Maintain a documented sanctions framework.
  • Assign clear responsibility for targeted financial sanctions.
  • Screen relevant parties and transactions.
  • Assess ownership and control.
  • Train employees on freezing and reporting obligations.
  • Investigate potential breaches promptly.
  • Maintain complete records.
  • Obtain specialist legal advice where appropriate.

The UAE Local Terrorist List is the national list of individuals and organisations designated by the UAE in connection with terrorism and terrorist financing.

It forms part of the UAE’s targeted financial-sanctions framework alongside the implementation of relevant United Nations Security Council sanctions.

Who may appear on the list?

The Local Terrorist List may include persons or organisations designated under the UAE’s domestic legal framework because of terrorism-related concerns.

Entries may include:

     Individuals

     Organisations

     Groups

     Associations

     Other designated legal persons or arrangements

Businesses should use the current official information published by the relevant UAE authorities rather than relying on old copies or unofficial databases.

What obligations arise from a listing?

Depending on the applicable UAE requirements, organisations may need to:

     Freeze funds and other assets without delay

     Prevent funds or economic resources from being made available

     Identify accounts, assets, or relationships connected to the listed party

     Submit the required reports

     Refrain from notifying the affected party where disclosure is prohibited

     Maintain records of the actions taken

The UAE targeted financial-sanctions framework applies to relevant financial institutions, designated non-financial businesses and professions, virtual-asset service providers, and other persons within scope.

Should businesses screen only exact names?

No.

Businesses should consider:

     Aliases

     Alternative spellings

     Transliteration differences

     Dates of birth

     Nationality

     Identification numbers

     Addresses

     Associated companies

     Beneficial ownership

     Control relationships

A name similarity should be investigated using all available identifiers before a conclusion is reached.

Practical example

A UAE business screens a new customer and identifies a similar name on the Local Terrorist List.

The company should not automatically conclude that the customer is designated solely because the names resemble each other. It should compare:

     Full name

     Date of birth

     Nationality

     Identification details

     Address

     Associated entities

     Ownership information

Where a true or possible match remains, the case should be escalated and handled in accordance with the applicable freezing and reporting requirements.

Best practices

     Subscribe to official list notifications.

     Update screening data promptly.

     Screen customers and beneficial owners.

     Apply ongoing rescreening.

     Investigate aliases and transliterations.

     Maintain freezing and reporting procedures.

     Record all potential-match decisions.

 

     Train employees on non-disclosure requirements.

The UAE implements targeted financial sanctions arising from relevant United Nations Security Council resolutions and national designations under the UAE Local Terrorist List.

UAE organisations may also need to consider other sanctions and export-control regimes where a transaction has a legal, financial, commercial, or contractual connection to another jurisdiction.

Core UAE targeted financial-sanctions framework

The UAE framework includes:

  • The UAE Local Terrorist List
  • Relevant UN Security Council sanctions concerning terrorism and terrorist financing
  • Relevant UN Security Council proliferation-financing sanctions
  • Asset-freezing requirements
  • Restrictions on making funds or economic resources available
  • Reporting obligations
  • Requirements to monitor applicable designations

Cabinet Decision No. 74 of 2020 provides the principal framework for implementing targeted financial sanctions connected to the Local Terrorist List and relevant UN Security Council resolutions.

Do US, UK, or EU sanctions automatically apply in the UAE?

Not simply because the business is based in the UAE.

However, another sanctions regime may become relevant where there is a connection such as:

  • A US, UK, or EU person
  • A company incorporated in the relevant jurisdiction
  • Activity taking place within that jurisdiction
  • A payment passing through a relevant bank
  • Use of US dollars
  • EU-, UK-, or US-origin goods or technology
  • A branch or subsidiary subject to foreign laws
  • Contractual obligations imposed by a bank
  • Potential secondary-sanctions exposure

An organisation should distinguish between:

  • Direct legal obligations
  • UAE regulatory obligations
  • Contractual requirements
  • Banking restrictions
  • Commercial risk
  • Internal risk appetite

Are sanctions limited to listed names?

No.

Restrictions may also arise through:

  • Ownership or control by a designated person
  • Prohibited goods or services
  • Restricted sectors
  • Export-controlled products
  • Prohibited destinations
  • Sanctions circumvention
  • Terrorist or proliferation-financing exposure

Practical example

A UAE exporter proposes to sell European-origin industrial equipment to an overseas customer and receive payment in US dollars.

The UAE company may need to consider:

  • UAE targeted financial sanctions
  • Relevant UN measures
  • The customer’s ownership and control
  • EU restrictions affecting the goods
  • US sanctions implications arising from payment clearing
  • Export-control and end-use requirements
  • Banking-partner restrictions

Best practices

  • Identify the UAE rules that directly apply.
  • Map foreign legal and transactional nexuses.
  • Screen against relevant official lists.
  • Review ownership and control.
  • Assess goods, services, destination, and end use.
  • Consider bank and correspondent requirements.
  • Document the basis for the decision.
  • Obtain specialist advice for complex transactions.

goAML is the UAE Financial Intelligence Unit’s electronic platform used by reporting entities to submit relevant reports and information.

The correct reporting route for a sanctions-related matter depends on the nature of the match, the applicable targeted financial-sanctions requirements, the reporting entity’s sector, and current instructions issued by the UAE authorities.

What types of sanctions situations may require reporting?

A reporting obligation may arise following:

  • A confirmed match to the UAE Local Terrorist List
  • A confirmed match to an applicable UN designation
  • Identification of funds or assets belonging to a designated person
  • Identification of an entity owned or controlled by a designated person
  • A transaction suspected of sanctions evasion
  • Terrorist-financing concerns
  • Proliferation-financing concerns
  • Attempted activity involving a designated party
  • A false positive, where a specific reporting process requires confirmation

The report type and timeline should be checked against current UAE guidance and the organisation’s supervisory requirements.

Is every screening alert reportable?

No.

A weak name similarity that is clearly resolved as a false positive may not carry the same reporting obligation as a confirmed match or a transaction suspected of sanctions evasion.

The organisation should distinguish between:

  • Initial system alert
  • Possible match
  • Confirmed match
  • False positive
  • Ownership or control match
  • Suspicious circumvention activity
  • Terrorist- or proliferation-financing concern

What information may be required?

A sanctions-related submission may need to include:

  • Customer identification
  • Designated-party information
  • Reasons for concluding that a match exists
  • Accounts, funds, or assets identified
  • Transactions attempted or completed
  • Ownership and control information
  • Actions taken
  • Date and time of freezing
  • Supporting documentation
  • Related counterparties
  • Contact details for follow-up

Should the customer be informed?

An organisation should not inform a customer or other relevant party about a report, investigation, or asset-freezing action where doing so would breach applicable non-disclosure or tipping-off restrictions.

Communications should be controlled by authorised compliance and legal personnel.

Practical example

A financial institution identifies a confirmed match involving a beneficial owner of a corporate customer.

The institution:

  1. Stops relevant transactions.
  2. Identifies affected accounts and assets.
  3. Applies freezing measures where required.
  4. Submits the relevant report through the prescribed channel.
  5. Preserves supporting records.
  6. Restricts internal information to authorised personnel.
  7. Reviews connected customers and transactions.

Best practices

  • Maintain current reporting procedures.
  • Define internal escalation timelines.
  • Train staff to distinguish alert types.
  • Ensure reports contain complete information.
  • Preserve evidence supporting the decision.
  • Maintain confidentiality.
  • Monitor official UAE guidance for changes.
  • Test the reporting process periodically.

FinTech companies may require a sanctions compliance programme where their services expose them to customers, payments, transactions, jurisdictions, or counterparties subject to sanctions restrictions.

The framework should reflect the company’s regulated status, products, delivery channels, customer base, payment flows, and geographic footprint.

Which FinTech activities create sanctions risk?

Exposure may arise through:

  • Digital payments
  • Electronic wallets
  • International transfers
  • Merchant acquiring
  • Payment gateways
  • Buy-now-pay-later services
  • Digital banking
  • Crowdfunding
  • Cross-border payroll
  • Foreign-exchange services
  • Virtual assets
  • Embedded finance
  • Application programming interfaces connecting third parties

The speed and scale of digital transactions can increase the risk that prohibited activity is processed before manual intervention is possible.

What controls may be needed?

A FinTech sanctions framework may include:

  • Customer screening
  • Beneficial-owner screening
  • Merchant screening
  • Payment screening
  • Ongoing rescreening
  • Geographic restrictions
  • IP-address and device monitoring
  • Transaction monitoring
  • Ownership and control reviews
  • Case management
  • Escalation procedures
  • List-update controls
  • Independent system testing

The UAE targeted financial-sanctions framework expressly contemplates obligations for financial institutions and virtual-asset service providers, alongside other regulated sectors.

Why is automated screening important?

High-volume FinTech businesses may process transactions within seconds.

Controls therefore need to be capable of:

  • Screening before execution where required
  • Receiving list updates promptly
  • Identifying spelling variations
  • Preventing duplicate alert creation
  • Holding relevant transactions
  • Escalating potential matches quickly
  • Maintaining an audit trail

Practical example

A digital-payment company onboards small business merchants through an online process.

One merchant passes initial screening but later changes its beneficial ownership. The new owner is connected to a designated entity.

Without event-driven customer updates and ongoing rescreening, the FinTech may continue processing payments without identifying the new risk.

Best practices

  • Complete a product-specific risk assessment.
  • Screen customers, merchants, and beneficial owners.
  • Apply ongoing rescreening.
  • Integrate sanctions controls into product design.
  • Test system matching effectiveness.
  • Monitor geography and transaction behaviour.
  • Maintain rapid escalation procedures.
  • Include sanctions controls when launching new markets.

Commodity trading companies may face significant sanctions, export-control, proliferation-financing, trade-based money laundering, and circumvention risks.

The exposure can arise through goods, customers, suppliers, brokers, banks, vessels, ports, shipping routes, ownership structures, and final end users.

Which commodities may create higher risk?

The risk depends on the destination, end use, and applicable restrictions, but higher-risk areas may include:

  • Oil and petroleum products
  • Gas
  • Coal
  • Metals
  • Gold and precious metals
  • Agricultural products
  • Fertilisers
  • Chemicals
  • Industrial machinery
  • Electronics
  • Dual-use components
  • Defence-related materials

A commodity is not automatically prohibited because it falls into one of these categories. The organisation must review the specific product, origin, destination, end use, parties, and applicable restrictions.

What should commodity traders screen?

Relevant screening may include:

  • Buyer
  • Seller
  • Beneficial owners
  • Agents
  • Brokers
  • Banks
  • Insurers
  • Shipping companies
  • Freight forwarders
  • Vessels
  • Ports
  • Consignees
  • End users

What are common risk indicators?

Warning signs may include:

  • Recently established trading companies
  • Unrelated third-party payments
  • Unusual pricing
  • Vague product descriptions
  • Changes to shipping instructions
  • High-risk transshipment routes
  • Unverified end users
  • Inconsistent certificates of origin
  • Complex chains of intermediaries
  • Goods inconsistent with the buyer’s business

UAE guidance and official typology materials emphasise detecting sanctions-evasion activity connected to terrorist and proliferation financing.

Practical example

A UAE trader receives an order for specialised industrial components from a distributor in a third country.

The customer is not designated, but:

  • Payment comes from an unrelated entity.
  • The final destination is unclear.
  • The goods could have dual-use applications.
  • The proposed route involves a known diversion hub.
  • The customer refuses to identify the end user.

The trader should conduct enhanced due diligence and consider both sanctions and export-control requirements.

Best practices

  • Classify goods accurately.
  • Screen all trade participants.
  • Verify origin and destination.
  • Confirm end use and end user.
  • Review payment and shipping routes.
  • Screen vessels using reliable identifiers.
  • Challenge third-party payments.
  • Maintain documentary evidence.
  • Train commercial and logistics teams.

Shipping companies may require sanctions screening because exposure can arise through vessels, owners, charterers, cargo, ports, insurers, banks, consignees, freight forwarders, and shipping routes.

Screening only the customer’s name is unlikely to be sufficient for businesses operating in international shipping.

Who and what should be screened?

Depending on the activity, relevant parties may include:

  • Vessel owners
  • Registered owners
  • Beneficial owners
  • Ship managers
  • Operators
  • Charterers
  • Cargo owners
  • Shippers
  • Consignees
  • Ports
  • Insurers
  • Classification societies
  • Banks
  • Freight forwarders

Relevant vessel identifiers may include:

  • Current vessel name
  • Previous vessel names
  • International Maritime Organization number
  • Flag
  • Call sign
  • Maritime Mobile Service Identity number
  • Ownership history
  • Management history

What shipping behaviours may indicate sanctions evasion?

Potential indicators include:

  • Automatic Identification System interruptions
  • Unexplained deviations from the stated route
  • Ship-to-ship transfers
  • Frequent flag changes
  • Rapid ownership changes
  • Vessel-name changes
  • Inconsistent bills of lading
  • Unclear cargo origin
  • Use of high-risk ports
  • Opaque ownership structures
  • Falsified location or cargo documents

A tracking interruption does not automatically demonstrate evasion. It must be assessed against weather, safety, technical, geographic, and commercial information.

Practical example

A vessel carrying petroleum products changes its flag, owner, manager, and name within a short period.

During the voyage, its tracking signal is interrupted near a high-risk transfer area, and the cargo documentation contains inconsistent origin information.

The shipping company, insurer, trader, or bank should consider enhanced review before continuing the activity.

Best practices

  • Screen vessels by IMO number.
  • Review ownership and management.
  • Monitor changes in flag and name.
  • Assess route and port exposure.
  • Verify cargo documentation.
  • Review ship-to-ship transfers.
  • Screen charterers and counterparties.
  • Maintain escalation procedures for tracking anomalies.
  • Apply ongoing screening during the voyage.

Trading with a person merely because they are a citizen of a country subject to sanctions is not automatically illegal in every case.

Sanctions generally apply according to the specific persons, entities, sectors, goods, services, territories, and activities covered by the relevant legal framework.

What should businesses assess?

A business should consider:

  • Whether the individual is designated
  • Whether the individual acts for a designated person
  • Whether a company is owned or controlled by a designated person
  • Where the person resides
  • Where the transaction occurs
  • Which banks and currencies are involved
  • What goods or services are supplied
  • Whether sectoral restrictions apply
  • Whether the destination is prohibited
  • Whether export controls apply
  • Whether the transaction creates secondary-sanctions risk

Nationality alone should not replace a proper sanctions assessment.

What is the difference between nationality and location?

A national of a sanctioned country may live and operate legally in another jurisdiction without being designated.

Conversely, a person of another nationality may:

  • Act on behalf of a designated entity
  • Operate in a prohibited territory
  • Control a sanctioned company
  • Facilitate sanctions circumvention
  • Participate in a restricted sector

The assessment should focus on the full legal and commercial context.

Practical example

A UAE business receives an enquiry from a Russian citizen who legally resides in the UAE and owns a UAE company.

The business should not reject the customer solely because of nationality. It should assess:

  • The customer’s identity
  • Sanctions-list status
  • Ownership and control
  • Source of funds
  • Business activity
  • Transaction purpose
  • Banking arrangements
  • Goods or services involved
  • Any relevant Russia-related restrictions

Can a company still decline the relationship?

Yes.

An organisation may decide not to proceed because of:

  • Legal risk
  • Bank restrictions
  • Commercial considerations
  • Inability to complete due diligence
  • Unmanageable circumvention risk
  • Internal risk appetite

The decision should be lawful, consistent, documented, and based on objective risk factors rather than unsupported assumptions about nationality.

Best practices

  • Avoid nationality-only decision-making.
  • Screen the individual and connected entities.
  • Review ownership and control.
  • Identify all relevant jurisdictions.
  • Assess goods, services, and payment routes.
  • Distinguish legal prohibition from risk appetite.
  • Document the reasons for the decision.
  • Escalate complex cases.

Family offices may require sanctions controls because they manage investments, structures, payments, companies, trusts, property, and professional relationships across multiple jurisdictions.

Although transaction volumes may be lower than those of a bank, the value, complexity, and cross-border nature of family-office activity can create significant sanctions exposure.

Where can sanctions risk arise?

Family offices may be exposed through:

  • Family members
  • Beneficiaries
  • Trusts
  • Foundations
  • Holding companies
  • Investment vehicles
  • Portfolio companies
  • Fund managers
  • Banks
  • Professional advisers
  • Real-estate transactions
  • Luxury assets
  • Private aviation
  • Yachts
  • Philanthropic activity

Why can ownership be difficult to assess?

Family-office structures may involve:

  • Multiple generations
  • Trust arrangements
  • Protectors
  • Nominees
  • Foundations
  • Private investment companies
  • Shared family ownership
  • Informal control
  • Assets held through several jurisdictions

A person may exercise influence without appearing as the immediate legal owner.

What controls may be appropriate?

A proportionate framework may include:

  • Screening family principals
  • Screening beneficiaries
  • Reviewing trusts and foundations
  • Screening investment counterparties
  • Reviewing portfolio-company ownership
  • Transaction screening
  • Geographic-risk assessment
  • Source-of-funds review
  • Enhanced due diligence
  • Ongoing monitoring
  • Escalation and approval procedures

Practical example

A family office is asked to invest through an offshore vehicle managed by a long-standing adviser.

The vehicle is not designated, but due diligence identifies that:

  • A minority investor is a designated person.
  • The designated person has veto rights.
  • Funding originates from an unrelated third party.
  • The investment involves a restricted sector.

The family office should complete an ownership, control, and transaction-nexus assessment before proceeding.

Best practices

  • Map the complete family and investment structure.
  • Identify natural-person beneficiaries.
  • Review trustees, protectors, and controllers.
  • Screen portfolio companies and counterparties.
  • Assess high-value assets and transactions.
  • Review geographic and banking exposure.
  • Maintain confidentiality without compromising compliance.
  • Reassess structures after material changes.

A sanctions compliance programme should include proportionate policies, controls, systems, governance, and oversight designed to identify and manage the organisation’s sanctions exposure.

The precise framework should reflect the organisation’s size, sector, jurisdictions, products, customers, transaction activity, and applicable legal obligations.

1. Governance and accountability

The programme should define:

  • Board and senior-management oversight
  • Compliance responsibility
  • Business ownership of controls
  • Escalation routes
  • Decision-making authority
  • Reporting responsibilities
  • Risk-acceptance authority

2. Sanctions risk assessment

The organisation should assess:

  • Customer risk
  • Geographic exposure
  • Product and service risk
  • Transaction risk
  • Delivery channels
  • Ownership structures
  • Goods and technology
  • Sectoral exposure
  • Circumvention risk
  • Proliferation-financing risk

3. Policies and procedures

Written procedures may cover:

  • Customer screening
  • Payment screening
  • Ownership and control
  • Alert investigation
  • Enhanced due diligence
  • Asset freezing
  • Regulatory reporting
  • Record keeping
  • Licensing
  • Transaction rejection
  • Sanctions investigations
  • Breach management

4. Screening and monitoring

Controls may include:

  • Customer screening
  • Beneficial-owner screening
  • Supplier screening
  • Transaction screening
  • Payment screening
  • Vessel screening
  • Ongoing rescreening
  • List-update management
  • Internal watchlists

For regulated UAE financial institutions, CBUAE materials emphasise screening and implementation of targeted financial sanctions, including the Local Terrorist List and relevant UN designations.

5. Due diligence

The organisation should be able to:

  • Verify legal identity
  • Identify beneficial ownership
  • Assess control
  • Understand transaction purpose
  • Verify end users
  • Review payment routes
  • Investigate third-party involvement
  • Apply enhanced due diligence

6. Training

Training should reflect employee responsibilities.

Relevant teams may include:

  • Compliance
  • Operations
  • Payments
  • Customer onboarding
  • Relationship management
  • Trade finance
  • Procurement
  • Sales
  • Logistics
  • Senior management

7. Management information

Useful information may include:

  • Alert volumes
  • True-match and false-positive trends
  • Escalations
  • Reporting activity
  • Screening delays
  • High-risk customers
  • Overdue reviews
  • System performance
  • Training completion
  • Remediation progress

8. Testing and assurance

The programme should be reviewed through:

  • Quality assurance
  • Sample testing
  • System testing
  • Data-quality reviews
  • Independent compliance monitoring
  • Internal audit
  • External assessment
  • Regulatory remediation validation

Practical example

A UAE trading company designs a sanctions programme consisting only of customer-name screening.

A risk assessment shows additional exposure through:

  • Suppliers
  • Vessels
  • Beneficial owners
  • Sensitive goods
  • Third-party payments
  • High-risk shipping routes
  • Overseas distributors

The company expands its controls to address the full transaction lifecycle rather than relying on onboarding screening alone.

Best practices

  • Base the framework on a documented risk assessment.
  • Assign clear accountability.
  • Screen relevant parties and transactions.
  • Assess ownership and control.
  • Integrate sanctions and export-control reviews.
  • Train employees regularly.
  • Test controls independently.
  • Track weaknesses to completion.
  • Update the programme following regulatory or business changes.

About Comply Sphere Advisory

Comply Sphere Advisory supports UAE and international organisations with:

  • Sanctions compliance programme design
  • UAE targeted financial-sanctions reviews
  • Sanctions risk and gap assessments
  • FinTech sanctions frameworks
  • Commodity-trading compliance
  • Shipping and vessel-risk reviews
  • Family-office sanctions assessments
  • Customer and transaction due diligence
  • Ownership and control reviews
  • Sanctions investigations
  • Screening-system optimisation
  • Policies, training, and independent assurance

The appropriate framework should be tailored to the organisation’s regulatory status, sector, business model, geographic exposure, transaction activity, and sanctions risk.

Scroll to Top