When must sanctions screening be performed?
MSBs should screen at points where a sanctions risk may arise, based on their products, customers, counterparties, and transaction flows. Common touchpoints include onboarding, beneficial-owner identification, payments or transfers, and periodic rescreening when customer information or sanctions lists change. A risk assessment should define the timing, scope, escalation process, and documentation standards for your specific program.
Is sanctions screening a legal requirement?
U.S. persons and businesses must comply with applicable sanctions programs administered by the Office of Foreign Assets Control (OFAC). The exact control framework varies by business model and risk, but MSBs need reasonable processes to avoid prohibited dealings and identify potential matches. Screening should be integrated with written policies, investigation procedures, escalation, recordkeeping, and any required reporting or blocking obligations.
What are the best tools for sanctions screening?
The best tool is one that fits your MSB’s customer base, payment activity, jurisdictions, volumes, risk profile, and internal workflow. Evaluate list coverage, update frequency, name-matching capabilities, configurable thresholds, case management, audit trails, integrations, and reporting. No platform replaces a sound program; vendor configuration, governance, and trained analysts are essential to effective screening.
What should a sanctions screening policy include?
A sanctions screening policy should identify applicable legal requirements, roles and responsibilities, customer and transaction screening points, list sources, matching and alert-review standards, escalation paths, potential-match disposition, record retention, training, testing, and reporting procedures. It should also explain how the program is governed and updated when products, markets, technology, or sanctions risks change.
How often should an MSB update sanctions lists?
Sanctions lists should be refreshed promptly and reliably through a controlled process, especially when using automated screening technology. Your program should document how updates are received, applied, validated, and evidenced. The appropriate cadence for rescreening existing customers and counterparties should be risk-based, considering your exposure, products, customer relationships, and the nature of transactions you process.
How can we reduce sanctions screening false positives?
False positives can be reduced through thoughtful calibration, not by weakening controls. Review matching thresholds, data quality, transliteration logic, alert rules, customer segmentation, and the information investigators use to clear matches. Test proposed changes, document approvals, monitor outcomes, and confirm that adjustments preserve effective identification of credible potential matches. This creates a more efficient, defensible review process.
What happens when a potential sanctions match is identified?
A potential match should be investigated promptly using documented procedures and reliable identifying information. Analysts should compare available customer, counterparty, transaction, and sanctions-list data; escalate cases that cannot be confidently resolved; and record the rationale for the disposition. If a true match or prohibited activity is confirmed, the business must follow applicable OFAC requirements, including blocking, rejecting, reporting, or seeking legal guidance when appropriate.
Can sanctions screening be outsourced to a vendor?
Technology and operational support can be outsourced, but accountability for an MSB’s compliance program remains with the business and its leadership. Vendor due diligence should assess list coverage, system controls, security, update practices, service levels, documentation, and performance. Maintain internal oversight, clear escalation paths, quality assurance, and evidence that the vendor-supported process operates as intended.