Which Data to Collect and When to Launch Sanctions Screening
Sanctions screening begins not with checking against lists but with the correct collection of input data. An incomplete name, an outdated address, or a missing registration number at the input — and the system will either produce a false match or miss a real hit. The quality and completeness of the collected information determine whether AML screening against OFAC, the EU, and the UK works as a reliable filter or becomes a source of operational losses.
Which Data to Collect on an Individual
The minimum set for launching sanctions screening of an individual includes identification and contextual fields, each of which solves a specific task when reconciling against records in the OFAC SDN List, the EU consolidated list, and the UK Sanctions List.
| Category | Description |
|---|---|
| Full name and all spelling variants | Sanctions lists contain aliases, transliterations, and abbreviations. OFAC publishes an «a.k.a.» section with alternative names for each listed person. When collecting data, the following are recorded: first and last name in Latin script (as in the passport or ID), the name in the original language (if the document is not in Latin script), all known former surnames (maiden name, from a previous marriage), and common transliteration variants. The more spelling variants passed to the screening system, the more accurate the fuzzy matching and the lower the share of false positives. |
| Date of birth | The main discriminator when resolving matches on common names. The OFAC, EU, and UK lists indicate a date or year of birth for most records. If the customer and the person from the list have matching full names but diverging dates of birth, this is a weighty argument for rejecting the match. The date of birth is collected in a format suitable for automatic matching: the full date (day, month, year), and in the absence of an exact date — at least the year. |
| Citizenship and country of residence | These data determine the jurisdictional context of the check. Citizenship of a country against which sectoral programs are in effect (Iran, North Korea, Syria, Russia, etc.) raises the risk profile and may require enhanced due diligence (EDD). The country of residence makes it possible to account for regional restrictions: the EU and the UK apply territorial prohibitions under certain programs that affect not only citizens but also residents of specific jurisdictions. |
| Identity document data | The passport or national ID number is the second most significant discriminator after the date of birth. In a number of SDN List records, OFAC publishes passport and national identifier numbers. Having the document number during screening makes it possible to unambiguously confirm or dismiss a match, especially when the full name and date of birth give an indeterminate result. The following are recorded: document type, number, country of issue, expiry date. |
| Address | The full residence or registration address is not a mandatory field in all sanctions lists, but it is indicated in many records — especially in the EU consolidated list of financial sanctions and in the UK Sanctions List. The address helps in resolving matches and reduces the share of false positives. At a minimum, the following is collected: country, city, street (if available). |
Which Data to Collect on the Company, Representatives, and Ultimate Beneficiaries
For legal entities the data set is broader, since the check covers the company itself, its executives, and the ownership chain up to the ultimate beneficial owners (UBO).
For the company the following are collected: the full legal name and all registered trade names, the country of registration (incorporation), the registration number (the equivalent of the OGRN in Russia, the Company Number in the UK, similar identifiers in other jurisdictions), the legal address, the INN or tax identifier (TIN/EIN). The registration number is the key identifier for accurate matching against records in sanctions lists: OFAC and the EU indicate companies’ registration data in SDN and consolidated-list records. Without the number, the check comes down to matching by name, which for typical names generates a large number of false matches.
For representatives and executives. For each director, member of the board of directors, and person authorized to act on behalf of the company, the same data is collected as for an individual: full name with aliases, date of birth, citizenship, document number. Sanctions extend to organizations that act on behalf of or at the direction of a sanctioned person. In the EU and the UK, the «acting on behalf or at the direction of» criterion serves as an independent basis for asset freezing, separate from ownership and control.
For ultimate beneficial owners (UBO). It is necessary to establish the ownership chain down to the individuals who directly or indirectly own or control the company. For each UBO the following is collected: full name, date of birth, citizenship, ownership percentage (direct and indirect), the nature of control (through voting shares, the right to appoint or remove a majority of directors, other mechanisms of influence). The ownership percentage is critically important for applying the 50 percent rule: in the OFAC and EU jurisdictions (since July 2024), a company is considered sanctioned if 50% or more of its shares belong to one or more sanctioned persons — including aggregated ownership. In the UK, as of March 2026, the threshold formally remains at «more than 50%» without aggregation, although OFSI is actively considering aligning it with the international standard. The mechanics of applying the 50 percent rule in each jurisdiction are examined in the corresponding sections.
Establishing the UBO chain down to the ultimate individuals and checking the applicability of the 50 percent rule at each level is a task that takes hours to do manually and does not scale as the flow of customers grows. The NeuroVision KYB module automatically builds the ownership structure from the registers of 100+ countries and reconciles each beneficiary, director, and authorized representative against the OFAC, EU, and UK sanctions lists.
We will aggregate shares, identify connections with designated persons, and route ambiguous cases to manual review by a compliance officer. The average API response time is under 1 second, and up to 90% of standard checks are handled without operator involvement. You will need to pass the counterparty’s basic details — name, jurisdiction of registration, and registration number — and you will receive the result in a structured form suitable for documenting the decision and for audit.
The ownership structure must be gathered at least to the level at which all individuals with a share of 25% and above are identified (the threshold required by most KYC regulations in the EU, the UK, and the FATF Recommendations), and ideally in full down to the ultimate beneficiaries, in order to check the applicability of the 50 percent rule at each level of the chain.
When to Launch the First and Repeat Check in Onboarding
Initial screening — before establishing a business relationship. The sanctions check must be completed before opening an account, signing a contract, or executing the first transaction. This follows directly from the requirements of all three regimes. OFAC applies a strict-liability regime: the very fact of conducting an operation with a sanctioned person constitutes a violation, regardless of the company’s awareness of the counterparty’s sanctions status. In the EU and the UK, the obligation to freeze funds arises immediately upon establishing a connection with a sanctioned person. In practice, screening is embedded in the onboarding process as a blocking step: until the check is passed and the matches resolved, the customer cannot be accepted.
Repeat check — upon list updates and trigger events. Sanctions lists are updated frequently and irregularly. OFAC makes changes to the SDN List several times a month, while the EU and the UK do so as new regulations and decisions are adopted. Each update can turn an active customer into a sanctioned person. The standard practice is automatic rescreening of the entire customer base at each list update. For organizations with a high risk profile, the repeat check is performed daily in a batch-screening format.
In addition to scheduled checks, rescreening is launched upon the occurrence of trigger events: a change in customer data (change of name, address, citizenship), a change in the company’s ownership structure, a change in the composition of management or beneficiaries, the customer’s transition to a high-risk jurisdiction, the arrival of information from external sources (adverse media, a regulator’s notification). The FATF Recommendations and those of most national regulators require companies to apply a risk-based approach to the frequency of review: for high-risk customers — at least once a year (and against sanctions lists — at each update), for medium- and low-risk customers — at increased intervals but no less often than provided for by internal policy.
Ongoing monitoring is not a replacement for periodic rescreening but a supplement to it. Transaction monitoring identifies suspicious operations in real time but does not check whether the customer’s own sanctions status has changed. Rescreening solves precisely this task and must be singled out as an independent process in the compliance program.
The gap between the update of a sanctions list and the repeat check of customers is a window in which a company works with a potentially sanctioned person without knowing it. The NeuroVision AML module is connected to 1,700+ databases and sources; key sanctions lists — including the OFAC SDN, the EU consolidated list, and the UK Sanctions List — are updated daily. We will configure automatic batch rescreening at each change of the lists and notifications when the status of any customer in your base changes.
Automating screening and case management reduces the manual load on the compliance team by up to 80%. Integration of the AML loop takes 1–2 days depending on the sources connected and information-security requirements. To start, it is enough to pass your current customer base in an agreed-upon format — we will conduct the initial screening and launch continuous monitoring with a full event log for each decision.
How to Check a Customer Against the OFAC Lists
OFAC (the Office of Foreign Assets Control) is part of the structure of the US Department of the Treasury and administers sanctions programs directed against states, organizations, and individuals that pose a threat to the national security and foreign policy of the United States. For companies building international onboarding, checking against the OFAC lists is mandatory not only in the presence of dollar operations or direct connections to the US jurisdiction. The extraterritorial nature of a number of sanctions programs means that even non-US persons may face secondary sanctions for interacting with blocked entities.
OFAC sanctions screening is built around two key lists: the SDN List and the Non-SDN Consolidated Sanctions List. Each of them covers different categories of subjects and implies a different scope of restrictions. A correct verification procedure requires reconciling the customer against both lists, as well as accounting for indirect ownership — the 50 percent rule.
Where to Look for a Record in the OFAC Lists
OFAC publishes and maintains two main data arrays for screening: the SDN List and the Non-SDN Consolidated Sanctions List. Both lists are available through the Sanctions List Service (SLS) on the ofac.treasury.gov website. The Sanctions List Search is also posted there — a fuzzy name-search tool that makes it possible to search for matches across the SDN and Non-SDN lists simultaneously. In addition to the online search, OFAC provides files in XML, CSV, and PDF formats for download and integration into automated screening systems.
The frequency of updates is not fixed: changes can be made several times a week depending on the geopolitical situation. For automated screening, it is critically important to load the current version before each verification cycle or to configure daily synchronization with the source.
SDN List
The SDN List (Specially Designated Nationals and Blocked Persons List) is OFAC’s main sanctions list. It includes individuals, companies, organizations, maritime and air vessels connected to target countries, terrorism, drug trafficking, the proliferation of weapons of mass destruction, and other threats.
The legal consequences of appearing in the SDN List are a full block: the subject’s assets located within the US jurisdiction or under the control of US persons are subject to freezing. Any transactions with persons from this list are prohibited for US citizens and companies unless OFAC has issued a special license. For non-US companies, interaction with SDN List subjects creates the risk of secondary sanctions — the loss of access to the US financial system.
Each record contains a set of identifiers: the full name or title, known aliases, date of birth (for individuals), nationality, addresses, passport and other document numbers, as well as the sanctions program under which the subject was listed. It is precisely these fields that serve as the basis for matching during screening.
Non-SDN Consolidated Sanctions List
In addition to the SDN List, OFAC maintains several supplementary sanctions lists combined into the Non-SDN Consolidated Sanctions List. The consolidated file includes records from the following lists:
— SSI (Sectoral Sanctions Identifications List) — subjects operating in certain sectors of the economy, primarily the Russian one. The restrictions concern specific types of financing and debt instruments rather than a full block.
— CAPTA (List of Foreign Financial Institutions Subject to Correspondent Account or Payable-Through Account Sanctions) — foreign financial institutions for which the opening of correspondent and payable-through accounts in the US is prohibited or restricted.
— NS-CMIC (Non-SDN Chinese Military-Industrial Complex Companies List) — companies connected to the military-industrial complex of the PRC, against which restrictions on securities transactions are in effect.
— NS-MBS (Non-SDN Menu-Based Sanctions List) — subjects subject to targeted restrictions not equivalent to a full block: a ban on certain goods and services, conditional import restrictions.
— FSE (Foreign Sanctions Evaders List) — persons and organizations that violated the sanctions regimes concerning Syria and Iran.
— NS-PLC (Palestinian Legislative Council List) — members of the Palestinian Legislative Council elected on the lists of organizations recognized as terrorist.
The fundamental difference between Non-SDN records and SDN: the restrictions on them, as a rule, do not imply a full block of assets but are sectoral or targeted in nature. The specific set of restrictions varies for each record and each program. The same person may be present simultaneously in the SDN List and in one of the Non-SDN lists — in which case the strictest restrictions apply.
For onboarding purposes, checking against the SDN List alone is insufficient. Reconciliation with the Non-SDN Consolidated Sanctions List makes it possible to identify subjects against whom sectoral restrictions are in effect — a ban on certain financial operations or investments. Ignoring these lists does not exempt from liability.
How to Account for the 50 Percent Rule
The 50 Percent Rule extends the effect of sanctions beyond the records explicitly listed in the SDN List. The essence: if one or more blocked persons collectively own 50 or more percent of the shares (stock) of a company — directly or indirectly — such a company is considered blocked, even if it does not appear in any OFAC list. All the restrictions applicable to an SDN extend to it in full.
Aggregation of shares. The shares of different blocked persons are summed. If two SDN subjects each own 25% of a company, the aggregate ownership reaches 50% — and the company is considered blocked. It is not required that any one of them individually own a controlling stake.
Indirect ownership. It is accounted for through a chain: if a blocked person owns 50% or more of company A, and company A owns 50% or more of company B, then company B is also recognized as blocked. If in an intermediate link the blocked person’s share is below 50%, the chain is broken: indirect ownership through such a link is not counted.
Ownership, not control. The 50 percent rule operates specifically on the category of ownership rather than control. A company that a blocked person controls but does not own at 50% or more is not automatically blocked under this rule. OFAC reserves the right to include such a company in the SDN List by a separate decision, and working with it remains a zone of heightened risk.
The absence of a separate list. OFAC does not publish a register of companies falling under the 50 percent rule. The responsibility for identifying such connections lies with the organization conducting the screening itself. A standard search of the lists must be supplemented by an analysis of the ownership structure — especially for corporate customers and complex legal structures.
In practice, accounting for the 50 percent rule during onboarding requires three components: access to data on the counterparty’s beneficial ownership, tools for building ownership chains through intermediate structures, and regular review — a change in shares or the addition of a new SDN subject among the co-owners can at any moment move the company into the category of blocked.
For companies with a multi-level ownership structure, holdings, nominee shareholders, and trusts, determining the real share of blocked persons may require enhanced due diligence. When it is impossible to obtain reliable ownership data, the reasonable practice is to record this fact, document the steps taken, and escalate the case to manual review by a compliance officer.
How to Check a Customer Against the EU Sanctions Lists
The European Union maintains its own regime of restrictive measures, legally binding for all member states, EU residents, and any legal entities registered under the law of a member state. EU sanctions are adopted by Council Decisions and enacted by Council Regulations, which are published in the Official Journal of the European Union. Each regulation contains an annex with a list of persons and organizations to whom asset freezing and a prohibition on providing funds apply.
For onboarding purposes, any operator obliged to comply with EU sanctions legislation must check the customer — an individual, a company, its representatives, and ultimate beneficiaries — against the current consolidated list before establishing a business relationship. Unlike OFAC, where the main check comes down to searching the SDN List and applying the 50% rule, the European regime requires parallel analysis along two lines: formal ownership (the ownership test) and control (the control test). Both lines are described in the updated EU Council document — EU Best Practices for the Effective Implementation of Restrictive Measures (revised July 3, 2024, document 11623/24). The document is not legally binding, but in practice it serves as the main reference point for both national regulators and obliged persons.
Where to Obtain the EU Consolidated List of Financial Sanctions
The primary source is the Financial Sanctions Database (FSD) portal, maintained by the European Commission. The current web interface address for downloading files is webgate.ec.europa.eu/fsd/fsf. For access through a browser, an EU Login account is required; for automatic file downloading, direct links with a token are available.
The consolidated list (Consolidated List of Persons, Groups and Entities Subject to EU Financial Sanctions) is published in three machine-readable formats: XML (per the XSD schema versions 1.0 and 1.1), CSV, and PDF. For automated screening, the XML file is optimal: it contains structured records with names (including aliases and transliterations), dates of birth, document identifiers, addresses, jurisdictions, and references to the specific regulations that served as the basis for inclusion. The CSV file is suitable for quick loading into spreadsheet tools but is inferior to XML in field completeness. The PDF is used mainly as a reference document.
The Commission updates the list at each change in the regulations, and between the publication of a new sanctions package and the appearance of the updated file, usually only a few hours pass. For the onboarding loop, it is recommended to configure daily automatic downloading of the file with a checksum verification, which the FSD portal publishes together with each file.
In addition to the FSD portal, the European Commission provides a visual tool — the EU Sanctions Map (sanctionsmap.eu). It is convenient for a one-time reference check and for navigating sanctions programs but is not intended for integration into an automated screening pipeline.
A number of EU member states maintain additional national lists. France, for example, publishes its own restrictive measures, which may go beyond the EU consolidated list. When working with customers from specific EU jurisdictions, it makes sense to clarify the existence of such additional lists with the relevant national regulator.
How to Account for Ownership and Control in the EU
The European regime applies two parallel tests, each of which can lead to the extension of restrictions to a person not included in the sanctions list.
The ownership test. Since July 2024, the ownership threshold for the purposes of asset freezing is 50% or more of the proprietary rights in a legal entity. Before the update, the threshold of «more than 50%» was considered the practice. The change is enshrined in the updated EU Best Practices and harmonizes the EU’s position with the OFAC 50% rule, but creates a divergence with the UK, where the threshold is still «more than 50%».
The aggregation principle: the shares of several sanctioned persons in one legal entity are added together. If two listed persons each own 25% of a company’s shares, the aggregate share is 50%, and the company is considered sanctioned. This approach extends to all EU sanctions programs, not just the Russian package, where it was applied earlier on the basis of the European Commission’s FAQ of April 2022.
For onboarding this means the need to collect data on the ownership structure of a customer that is a legal entity down to the ultimate beneficiaries and to check each participant in the chain against the consolidated list. If the total share of sanctioned persons reaches 50%, the legal entity falls under the restrictions, even if it does not appear in the list itself.
The control test. Even if the 50% threshold is not reached, a legal entity may be considered controlled by a sanctioned person. The EU Best Practices list the criteria of control: the right to appoint or remove a majority of the board of directors, the right to dispose of a majority of votes, the right to profit or assets upon liquidation, and — since 2024 — the de facto ability to exert dominant influence over a legal entity without a formal right.
The updated Best Practices additionally single out a non-exhaustive list of indicators (red flags) signaling possible control:
— The sanctioned person is the largest shareholder of the company, even if their share is below 50% (the EU Council’s example — 40%);
— The presence of a buyback option on favorable terms held by a former owner who has fallen under sanctions;
— The transfer of a significant stake shortly before or after inclusion in the sanctions list;
— The use of front persons;
— The use of trusts, shell companies, or complex corporate structures.
Each indicator by itself is not equivalent to establishing control, but it obliges the operator to conduct an in-depth analysis and check whether the formal criteria of control are met. If, based on the results of the check, the operator cannot unambiguously rule out control, it is recommended to escalate the case to manual review.
The EU Best Practices separately introduce the concept of «acting on behalf or at the direction» of a sanctioned person. The EU Council treats the consequences of this status on par with ownership and control: if a legal entity acts at the direction of a sanctioned person — the same restrictions apply to it.
For the correct implementation of both tests within onboarding, it is necessary to request from the customer current data on the ownership structure and management bodies, reconcile each beneficiary, director, and authorized representative against the EU consolidated list, and, if matches are found, check the applicability of the ownership test (taking aggregation into account) and the control test (taking into account the formal criteria and indicators), and document the course of the analysis and the justification for the decision. Documentation is necessary in case of a request from the national competent authority (NCA) of the relevant EU member state.
The parallel application of the ownership test and the control test means that reconciling the consolidated list alone does not close the obligations to the regulator — it is necessary to establish each beneficiary and assess whether the control criteria are met even at a share below the 50% threshold. The NeuroVision AML and KYB modules automatically check all participants in the chain against the EU consolidated list of financial sanctions with daily updates, aggregate the shares of sanctioned persons, and record indicators of possible control.
Every check is saved in the case-management system with a full audit log: from the moment of the alert to the final decision, including the justification and the responsible employee. The reduction in manual load reaches 80% through automatic routing of standard cases. Documentation is generated in a format suitable for submission to the national competent authority upon request.
How to Check a Customer Against the UK Sanctions List
The UK has its own sanctions regime, independent of the EU and the US, and maintains a separate register of restrictive measures. The legal basis is the Sanctions and Anti-Money Laundering Act 2018 (SAMLA) — a law that empowers the government to establish, administer, and enforce sanctions on a wide range of grounds: from asset freezing to trade and transport restrictions. Checking customers against the UK Sanctions List is a mandatory element of international sanctions screening for any company operating in the British jurisdiction, working with British counterparties, or processing transactions in pounds sterling.
A key feature of the British regime is strict liability for violating financial sanctions. Since June 2022, the regulator has had the right to impose monetary fines for violating sanctions without having to prove that the violator knew or suspected the fact of the violation. It is enough to establish the fact of the prohibited operation itself. The current fine ceiling is 1 million pounds or 50% of the value of the violation (the greater of the two is taken). In January 2026, OFSI announced its intention to double the bar to 2 million pounds or 100% of the violation amount — this requires the adoption of the corresponding legislative act by parliament.
The administration of sanctions is distributed between two agencies. The Foreign, Commonwealth & Development Office (FCDO) is responsible for sanctions policy and forms the list, while the Office of Financial Sanctions Implementation (OFSI), a division of HM Treasury, oversees the enforcement of financial sanctions, issues licenses, conducts investigations, and imposes fines.
Where to Look for a Record in the UK Sanctions List
Since January 28, 2026, the UK Sanctions List (UKSL) has become the sole official source of data on UK sanctions designations. Before that date, the OFSI Consolidated List of Asset Freeze Targets existed in parallel, covering only financial sanctions. The consolidated list is closed and no longer updated — all current designations are contained exclusively in the UKSL.
The list is published on GOV.UK and available for download in seven formats: ODT, ODS, XML, HTML, CSV, PDF, and TXT. The data in all formats is identical and contains information on individuals, legal entities, and vessels subject to sanctions. For each designation, the applied measures (asset freezing, immigration restrictions, trade and transport bans), the grounds for inclusion, and the identifiers are indicated.
For each designated person, the UKSL assigns a unique identifier — a Unique ID. Persons included in the register before January 28, 2026 retain an additional OFSI Group ID, which is still accepted in license applications and reports. For new designations, an OFSI Group ID is not assigned. If internal screening systems are tied to the old identifier, they must be reconfigured to work with the Unique ID.
In addition to the downloadable files, an online search tool is available on GOV.UK — the UK Sanctions List Search (search-uk-sanctions-list.service.gov.uk). It makes it possible to search for records by name, address, and other details, filter results by the type of sanctions measures, and uses fuzzy search to detect matches with inexact name spelling. For the timely receipt of notifications about changes, the FCDO provides an email-alert service — a subscription is arranged on the same GOV.UK page.
When building automated screening within onboarding, XML and CSV are the most convenient formats for machine parsing and regular loading into an AML system. The frequency of UKSL updates is determined by the activity of the sanctions regimes: in periods of new designations, the list may be updated several times a week. A one-time check at onboarding is insufficient — ongoing monitoring with periodic reloading of the current data is necessary.
How to Account for Ownership and Control in the UK
UK sanctions extend not only to persons directly indicated in the UKSL. If a legal entity is owned by a designated person or controlled by them — directly or indirectly — it is treated as a designated person for the purposes of financial sanctions, even if its name is not on the list.
The ownership and control test is enshrined in the sanctions regulations adopted under SAMLA — in particular, in Regulation 7 of the Russia (Sanctions) (EU Exit) Regulations 2019 and analogous norms for other regimes. The test includes two independent conditions; for a company to be recognized as controlled by a designated person, meeting at least one of them is sufficient.
The first condition — formal ownership. The designated person directly or indirectly owns more than 50% of the shares or voting rights of the company or holds the right to appoint or remove a majority of the board of directors. The threshold is set precisely as «more than 50%» (strictly more than) rather than «50% or more», which distinguishes it from the OFAC and EU approach, where the threshold value includes exactly 50%. HM Treasury, in February 2026, publicly stated that it is considering a transition to a «50% or more» model to align with international partners, but as of the date of this article’s preparation, the legislative changes have not yet been adopted.
Another fundamental difference: OFSI, as a rule, does not aggregate the shares of several designated persons in one company to reach the 50% threshold. Aggregation is allowed only in the presence of a joint agreement between the designated persons or when one of them controls the rights of another. The British government is also studying the possibility of legislatively enshrining an aggregation model analogous to the OFAC rule and the EU approach, but no specific timeframes have been indicated.
The second condition — actual control. A company is recognized as controlled if, taking all circumstances into account, it is reasonable to expect that the designated person could (if they wished) ensure that the company’s affairs are conducted in accordance with their will — in most cases or in significant aspects, by any means, directly or indirectly.
The criterion is deliberately formulated broadly: it covers not only legal mechanisms but also actual influence — through informal connections, economic dependence, the appointment of trusted persons to management, and other forms of pressure.
It is precisely the second condition that causes the greatest difficulty in practice. In 2023, the Court of Appeal of England, in the case Mints v PJSC National Bank Trust [2023] EWCA Civ 1132, interpreted the control test extremely broadly, which led to a discussion of whether all Russian companies fall under it through the figure of the head of state. In response, OFSI and the FCDO issued clarifications: the government does not consider that the head of state controls all companies in the country by default; the decision is made on a case-by-case basis on the basis of sufficient evidence. The uncertainty remains: in February 2026, OFSI launched a public collection of opinions (call for evidence) on the practice of applying the control test, open until April 13, 2026.
For onboarding, this means a concrete set of actions. When screening a legal entity, it is not enough to check only its name against the UKSL — it is necessary to establish the beneficial owners and the persons actually controlling the company and to check each of them. OFSI directly states that it expects businesses to conduct good-faith and reasonable due diligence proportional to the level of sanctions risk. In the event of a violation, the regulator assesses the quality of the check conducted as a mitigating or aggravating factor when imposing a fine. No single mandatory due-diligence standard is established — the approach is determined by the nature of the operation, the counterparty’s jurisdiction, and the degree of risk.
In practice, a reasonable ownership and control check usually includes an analysis of registry data on the ownership structure, a study of the composition of the board of directors and management bodies, a search for information about connections with designated persons through open sources and, in the presence of signs of a complex structure or high risk, a request for additional information from the counterparty. If the assessment is difficult — for example, because of a multi-level ownership chain through offshore jurisdictions — this is a signal to escalate the case and engage a specialized compliance officer or lawyer.
How to Confirm or Dismiss a Match in Onboarding
Sanctions screening during onboarding almost inevitably generates potential matches — alerts that the system creates on the basis of the similarity of customer data to records in sanctions lists. By industry estimates, more than 95% of such alerts turn out to be false positives: the name partially matched, the fuzzy-search algorithm reacted to a phonetically close record, or the system captured a «weak» alias. The task of the compliance procedure is to separate false and true matches quickly, accurately, and with a documentary trail sufficient for the regulator and audit.
The review of an alert is built on unified logic for all three jurisdictions (OFAC, EU, UK): first the identifying data of the individual or company is compared, then a decision is made — dismiss the alert as a false positive, confirm the match, or pass the case to manual review.
How to Reconcile Full Name, Aliases, Date of Birth, and Documents
The starting point is the methodology described by OFAC in FAQ 5 on the official website (ofac.treasury.gov/faqs/5). It is applicable as a reference point for working with other jurisdictions as well, since it describes a universal sequence for assessing the quality of a match.
- Determine which list specifically triggered the alert: SDN, Non-SDN Consolidated, the EU consolidated list, or the UK Sanctions List. If the system screens several registers at once, it is critically important to understand the source, because the set of applicable restrictions and the order of actions depend on it.
- Compare the record type. If the customer is an individual while the record in the sanctions list relates to a vessel, organization, or legal entity (or vice versa), the alert is dismissed as an obvious non-match.
- Assess the completeness of the name match. A partial match on the surname alone or on a single component of the name with a divergence of the remaining elements, as a rule, indicates a false positive. OFAC divides aliases into «strong» and «weak». Weak aliases are short, common, or geographically conditioned nicknames that OFAC does not expect to be used as an independent screening criterion. They serve only as additional confirmation if a match has already been found by other parameters.
- Compare secondary identifiers. Records in sanctions lists often contain a date of birth, citizenship, address, passport or other identity document number, tax identifier (INN, Tax ID, cédula). If the customer and the sanctions record diverge in date of birth, citizenship, and document number — the match is, as a rule, false. If the data matches on several secondary parameters simultaneously — this is grounds for escalation.
A separate case is customers with common names («Mohammed Ali», «John Smith», their analogs in other languages). Standard name matching is insufficient for them. It is necessary to collect and check the maximum number of secondary identifiers: the full date of birth, address, document, citizenship. The decision to dismiss an alert on a common name is recorded with a detailed justification.
How to Reconcile Company Name, Registration Number, Address, and Jurisdiction
For legal entities, the set of identifying data differs from that of individuals, but the principle of sequential narrowing is the same.
The company name is matched taking into account variations in spelling, abbreviations, transliterations, and language versions. Organizations often have official names in several languages, and sanctions lists may contain both the original and the transliterated spelling.
The key secondary identifiers for companies: the registration number (Company Registration Number), the jurisdiction of registration, the legal and actual addresses, the INN or Tax ID. The EU consolidated lists and the UK Sanctions List usually indicate the jurisdiction and, if available, the registration number. A name match with a divergence of jurisdiction and registration number is a standard marker of a false positive.
For the EU and the UK, checking the ownership chain is of particular importance. Both jurisdictions extend restrictions to companies in which sanctioned persons own a threshold share — directly or indirectly — even if the company itself is not on the list. OFAC applies an analogous approach through the 50 percent rule. When screening a legal entity, it is necessary to reconcile not only the company itself but also its ultimate beneficiaries (UBO) and the persons exercising actual control.
The concept of control is interpreted broadly by regulators. OFSI indicates that control may exist if a sanctioned person is able to ensure that the company’s affairs are conducted in accordance with their interests — even without formal ownership of a controlling stake. In the case of an ambiguous ownership structure, it is necessary to request from the customer supporting documents on the composition of shareholders and beneficiaries and, if necessary, engage legal expertise.
When to Halt Onboarding and Pass the Case to Manual Review
Automated screening is capable of dismissing obvious false positives — for example, when the subject type diverges or the basic identifiers do not match. A number of situations, however, require the mandatory involvement of a compliance officer.
Onboarding is halted and the alert is passed to manual review if: the match covers the full name (or company name) and at least one secondary identifier; the customer’s data is incomplete and does not make it possible to unambiguously reject the match; the customer is connected to a high-risk jurisdiction appearing in active sanctions programs; the company’s ownership structure is opaque or contains persons from jurisdictions with active sanctions; the match score exceeds the threshold value established by the organization’s internal policy.
Until the manual review is completed, one cannot open an account, conduct a transaction, or provide services. Upon confirmation of a match with an SDN record, it is necessary to block the customer’s funds and assets rather than simply reject the operation — OFAC clearly distinguishes between blocking and rejection, and the reporting format depends on the type of action. Upon confirmation of a match against the EU or UK lists, the financial assets are frozen, and the discovery is reported to the relevant authority — OFSI for the UK, the competent authority of the EU member state for the European jurisdiction.
If, after exhausting the available information, the match remains indeterminate, OFAC suggests seeking clarification through the online platform on its website. Similarly, OFSI allows a direct request for consultation if confidence in the match or its absence remains insufficient.
How to Document a False and a True Match
Documentation is a mandatory element of a compliance program, which is assessed by the regulator during inspections and audits.
For each alert — regardless of the result — the following are recorded: the date and time of screening; the version of the sanctions lists loaded into the system at the moment of the check; the full name (title) of the customer being checked in the form in which it was passed to the system; the identifier of the record in the sanctions list that triggered the alert; the fields against which the matching was conducted (full name, date of birth, address, document, jurisdiction, registration number); the result of the matching for each field; the final decision — false positive or confirmed match (true match); the full name and position of the employee who made the decision; the date of the decision.
When documenting a false positive, the justification must be specific: by which exact parameters the customer differs from the sanctions record. The wording «does not match» or «different persons» without an indication of the divergence criteria is not accepted by the regulator. A practical guideline: the record must contain enough information for any other compliance specialist, upon reading it, to arrive at the same conclusion without additional requests.
For a true match, the following are documented: the fact of asset blocking or operation rejection; the notification to the regulator (OFAC — within 10 business days through the OFAC Reporting System; OFSI — immediately in the presence of a freeze; the competent EU authority — in accordance with the national legislation of the member state); all actions taken with respect to the customer and their funds; the chronology of events from the alert to the final decision.
Records are stored for no less than five years from the date of the check — the minimum period indicated in OFAC’s guidelines. For organizations subject to banking regulation, the practice often provides for retention of up to ten years. A number of EU jurisdictions set their own retention periods, which it is advisable to clarify in the current regulations of the specific member state.
Organizations maintaining so-called false hit lists (lists of previously checked and dismissed matches) must take OFAC’s recommendations into account: such lists must be periodically reviewed, since sanctions records are updated and a previously dismissed alert may become relevant after new identifiers are added to a record in the list. Automatic suppression of alerts based on outdated false hit lists is one of the typical shortcomings identified during audits.
More than 95% of alerts in sanctions screening turn out to be false positives, yet it is precisely the quality of their documentation that the regulator assesses during an inspection. The NeuroVision AML module automatically records the version of the loaded lists, the time of the check, the matching fields, and the result for each of them — the compliance officer receives a ready-made alert card with data for making a decision rather than a blank form.
The system maintains a full audit log for each case: the chronology of events, the justification, the responsible employee, and the date of the decision. The records are protected from retrospective editing, which corresponds to the expectations of OFAC, OFSI, and the EU competent authorities. Case-management automation reduces the manual load by up to 80% and eliminates typical errors — including the suppression of alerts based on outdated data about previously dismissed matches. For an assessment, it is enough to describe the current volume of checks and the sanctions regimes applied — we will propose a module configuration for your compliance loop.
A compliance module integrated into the onboarding platform is capable of simplifying this process: automatically recording the version of the lists and the time of the check, providing the compliance officer with an alert card containing the data for matching, and preserving a full audit trail for each decision. When designing such a loop, the records must be protected from retrospective editing — regulators assess precisely the original documentation created at the moment of the decision.
Checking customers against three sanctions regimes stops being a source of operational losses when each stage is built sequentially: the correct collection of data at the input, reconciliation against the SDN, the EU consolidated list, and the UK Sanctions List taking into account the differences in ownership thresholds and control criteria, and then — documented resolution of alerts capable of withstanding a regulator’s request. The differences between jurisdictions — the aggregation of shares, the interpretation of actual control, the reporting format for a true match — do not complicate the process if they are built into the screening logic in advance rather than discovered during the review of a specific case.
The practical resilience of such a loop is determined not by a one-time configuration but by the regularity of review: updating the lists, rechecking the customer base upon trigger events, revising previously dismissed matches. Companies that build these cycles into their compliance program and record every decision with sufficient detail gain not only protection from sanctions risks but also a transparent evidence base for an audit in any of the three jurisdictions.