Sanctions screening is not optional. Whether you are a bank onboarding a corporate client, an executive search firm placing a CFO, or a family office vetting a new advisor, you need to know which lists to check, when each applies, and how to document that you did it properly.
The problem: there is no single “sanctions list.” There are at least three major regimes — the European Union, the US Office of Foreign Assets Control (OFAC), and the United Nations Security Council — plus national lists like SECO in Switzerland. Each has different scopes, different legal bases, and different consequences for missing a match.
This guide explains the differences, when each list matters, and how to build a screening process that holds up in an audit.
The three major sanctions regimes
European Union (EU)
Legal basis: Common Foreign and Security Policy (CFSP), implemented through Council Regulations.
Scope: Applies to all EU persons and entities, and to anyone doing business in the EU. This includes EU subsidiaries of non-EU companies.
Lists: The EU maintains consolidated lists of persons, groups, and entities subject to financial sanctions. These include asset freezes, travel bans, and arms embargoes.
Key point: If you are an EU entity or have EU operations, EU sanctions are mandatory. The lists are updated frequently — sometimes daily — and you are expected to screen against the current version.
US OFAC
Legal basis: US sanctions programs under the International Emergency Economic Powers Act (IEEPA), Trading with the Enemy Act (TWEA), and other statutes.
Scope: Applies to US persons, entities organized under US law, and — critically — to transactions with a US nexus. This includes USD clearing, US-origin goods, and US financial institutions.
Lists: OFAC maintains the Specially Designated Nationals (SDN) list, the Consolidated Sanctions List, and various program-specific lists (e.g., Iran, Russia, North Korea).
Key point: OFAC has extraterritorial reach. A German bank processing USD payments for a Swiss client can face US enforcement action if the client is on the SDN list. This is why many non-US companies screen OFAC even when not legally required.
United Nations Security Council
Legal basis: UN Charter Chapter VII, implemented through Security Council Resolutions.
Scope: UN sanctions are binding on all UN member states. Each member state implements them through national legislation.
Lists: The UN Security Council Consolidated List covers all active sanctions regimes (e.g., ISIL/Al-Qaida, Taliban, DPRK, Libya).
Key point: UN sanctions are the baseline. If someone is on the UN list, they are effectively sanctioned everywhere. However, the UN list is narrower than EU or OFAC lists — many EU and US designations go beyond UN requirements.
When does each list apply?
| Situation | EU | OFAC | UN |
|---|---|---|---|
| EU bank onboarding a corporate client | Required | Recommended (if USD involved) | Required |
| Swiss executive search placing a CFO in Germany | Required | Recommended | Required |
| US private equity fund acquiring a German company | Required | Required | Required |
| Family office in Zurich vetting a new advisor | Recommended | Recommended | Required |
| German manufacturer exporting to Turkey | Required | Required (if USD or US goods) | Required |
The practical rule: screen EU + OFAC + UN for any cross-border business. Add SECO for Swiss nexus. Add national lists (e.g., UK OFSI, French Tracfin) if you have specific jurisdictional exposure.
How to build a defensible screening process
1. Screen at onboarding and periodically
One-time screening at onboarding is not enough. Sanctions lists change. A client who was clean in January may be designated in March. Best practice: screen at onboarding, then re-screen quarterly or when there is a trigger event (new beneficial owner, new jurisdiction, adverse media hit).
2. Use fuzzy matching, not exact matching
Names are transliterated differently. “Mohammed” vs “Muhammad” vs “Mohamed.” A good screening tool uses fuzzy matching algorithms to catch variants. But fuzzy matching creates false positives. You need a documented process for resolving them.
3. Document every decision
When you get a potential match, you must document: what the match was, why you concluded it was a false positive (or true match), who made the decision, and when. This documentation is what regulators ask for.
4. Screen beneficial owners, not just the entity
If you are onboarding a company, you must screen its beneficial owners (typically anyone with 25%+ ownership or control). A clean company with a sanctioned UBO is a sanctions violation.
5. Have an escalation process
What happens when you get a true match? Who decides whether to exit the relationship? What do you tell the client? These decisions must be documented and consistent.
Common mistakes
- Screening only the entity, not the UBOs: This is the most common gap. Regulators expect UBO screening.
- Using stale lists: Sanctions lists change daily. Using a list from last month is a compliance failure.
- No false positive documentation: “It was a false positive” is not enough. You need to show your reasoning.
- Ignoring OFAC because “we are not a US company”: If you touch USD, US goods, or US financial institutions, OFAC applies.
- No periodic re-screening: Onboarding-only screening misses designations that happen after onboarding.
What a defensible report looks like
A defensible sanctions screening report includes:
- The lists screened (EU, OFAC, UN, SECO, others)
- The date of the list versions used
- The search terms and matching logic
- All potential matches identified
- The resolution of each match (false positive / true match / escalated)
- The name of the person who made the final decision
- The date of the decision
This is what auditors and regulators expect. Not a screenshot of a database query — a documented decision trail.
Bottom line
Sanctions screening is complex because there is no single list. EU, OFAC, and UN each have different scopes and legal bases. The practical approach: screen all three, document everything, re-screen periodically, and have a clear escalation process for true matches.
The cost of getting it wrong: fines, reputational damage, and in some cases criminal liability. The cost of doing it right: a documented process that takes minutes per case and holds up in any audit.
This article provides general information and does not constitute legal advice. For specific compliance questions, consult qualified legal counsel.