Skip to main content
Category: AML and KYC

Sanctions Screening

Also known as: Sanctions Screening Process
Simply put

Sanctions screening is the process of checking individuals, entities, or transactions against official lists of sanctioned parties issued by governments and international bodies. Businesses use it to identify potential risks and to help meet their legal compliance obligations. It applies to customers, businesses, and transactions, and in some contexts extends to identifying sanctioned persons, entities, and cryptocurrency wallets.

Formal definition

Sanctions screening is a compliance control that compares individuals, entities, or transactions against global sanctions lists maintained by governments and international authorities to detect potential matches with sanctioned parties. It supports adherence to applicable legal and regulatory requirements by identifying persons, entities, or wallets subject to sanctions before or during business relationships and transaction processing. In crypto contexts, screening extends to identifying sanctioned wallets, and regulators require it as part of broader financial crime risk management. Note that screening is a detection and risk-identification control; the evidence provided does not detail match-resolution methodologies, false-positive or false-negative trade-offs, or list-refresh cadence, which depend on implementation.

Why it matters

Sanctions screening is a foundational financial crime control because businesses that process payments or onboard customers are legally obligated to avoid dealing with individuals, entities, or transactions tied to sanctioned parties. Screening against official lists issued by governments and international authorities helps organizations identify potential exposure before or during a business relationship, supporting adherence to applicable legal and regulatory requirements.

The consequences of failing to screen effectively extend beyond a single transaction. Because sanctions obligations are set by government and international authorities, non-compliance can carry legal and regulatory implications for the business. Screening serves as a detection and risk-identification control that flags potential matches so they can be investigated and resolved, rather than allowing prohibited relationships or transactions to proceed unexamined.

The scope of screening continues to broaden. In cryptocurrency contexts, screening extends to identifying sanctioned wallets in addition to persons and entities, and regulators require it as part of broader financial crime risk management. It is important to note that screening identifies potential risk; it does not by itself resolve matches. Match-resolution methodology, false-positive and false-negative trade-offs, and how frequently lists are refreshed depend on implementation and are not specified here.

Who it's relevant to

Compliance and Financial Crime Teams
Compliance officers rely on sanctions screening to help meet legal and regulatory obligations and to identify persons, entities, or wallets subject to sanctions. They typically own the process of investigating and resolving potential matches, though the specific match-resolution methodology depends on the organization's implementation.
Payment Processors and Acquirers
Organizations that process transactions use screening to check transactions against official lists before or during processing, helping identify potential exposure to sanctioned parties within the transaction flow.
Merchant Onboarding and Risk Teams
Teams responsible for onboarding customers and businesses screen individuals and entities against government and international sanctions lists to identify potential risks at the start of and throughout a business relationship.
Cryptocurrency Businesses
In crypto contexts, screening extends to identifying sanctioned wallets in addition to persons and entities. Regulators require sanctions screening as part of broader financial crime risk management for these businesses.

Inside Sanctions Screening

Watchlist and Sanctions List Matching
The process of comparing customer, merchant, or transaction party identifiers against government and international sanctions lists, such as those maintained by national authorities and multilateral bodies. Screening typically covers names, aliases, addresses, dates of birth, and related identifiers, and may use exact, fuzzy, and phonetic matching techniques.
Screening Points in the Transaction Lifecycle
Sanctions screening may occur at onboarding, during periodic re-screening as lists change, and at the point of a transaction or payment. Note that sanctions screening addresses regulatory and legal risk and is distinct from payment card fraud detection controls, though both may run on transaction data.
Match Alerting and Disposition
When a potential match is generated, it is routed for review and disposition, which may confirm a true match, clear a false positive, or escalate for further investigation. Disposition typically involves recorded rationale and, where required, reporting to the appropriate authority.
Data Inputs Used for Screening
Screening relies on party and transaction attributes such as names, addresses, and identifiers. Where payment data is involved, cardholder data such as PAN or cardholder name may be part of the record; sensitive authentication data such as full track data, CAV2/CVC2/CVV2/CID, and PINs or PIN blocks must not be retained after authorization and is not a basis for sanctions matching.
Governance, Tuning, and Audit Trail
Effective screening includes documented list sources and update cadence, tuning of matching thresholds, periodic testing, and retention of audit records for regulatory examination. Thresholds involve trade-offs between false positives and false negatives that must be calibrated and documented.

Common questions

Answers to the questions practitioners most commonly ask about Sanctions Screening.

Is sanctions screening the same thing as fraud detection or PCI DSS compliance?
No. Sanctions screening checks parties to a transaction against government and regulatory watchlists (such as those maintained by OFAC, the EU, the UN, and other national authorities) to identify prohibited persons, entities, or jurisdictions. Fraud detection is intended to identify unauthorized or deceptive transaction activity, and PCI DSS governs the protection of cardholder data. These address different obligations, and satisfying one does not satisfy the others. Sanctions screening is driven by legal and regulatory sanctions regimes rather than by payment card security standards.
Does a name match against a sanctions list definitively confirm that a transaction involves a sanctioned party?
No. A screening hit is an alert that requires investigation, not a confirmation. Name-based matching commonly produces false positives because of common names, transliteration variations, incomplete data, and shared identifiers. A potential match is intended to prompt review and disposition, which may include gathering additional identifying information before a decision is made. Treating an unconfirmed match as a confirmed hit, or dismissing hits without documented review, both create risk. Confirmed matches are typically escalated according to applicable regulatory and internal procedures.
What data elements are typically screened, and where in the flow does screening occur?
Screening is commonly applied to party-related information such as names, addresses, and jurisdictional or geographic indicators associated with the customer or counterparty, depending on the program's design and available data. It may occur at customer onboarding, during transaction processing, or on a periodic re-screening basis as lists change. The specific fields, timing, and points in the flow depend on the institution's role, applicable regulations, and risk assessment, and should be defined by the organization's sanctions compliance program.
How should match sensitivity and fuzzy matching thresholds be tuned?
Thresholds involve a trade-off: looser fuzzy matching may catch more variations of a listed name but raises false positives and review workload, while tighter matching reduces noise but may increase the risk of false negatives. Tuning is typically informed by a documented risk assessment, testing against known scenarios, and periodic calibration. Changes to matching logic should be governed, tested, and documented so that adjustments can be justified and are not made solely to reduce alert volume.
How often should watchlists be updated and existing records re-screened?
Sanctions lists change over time, so both list content and screened records should be kept current. Programs commonly refresh list data on a defined schedule aligned to how frequently authorities publish updates, and re-screen existing customers or records when lists change. The appropriate frequency depends on the organization's risk profile, regulatory expectations, and operational capacity, and the chosen cadence should be documented and monitored for adherence.
How should screening alerts be investigated and documented?
Alerts are generally handled through a defined workflow that includes review by trained personnel, collection of additional identifying information where needed, a disposition decision (such as clearing a false positive or escalating a confirmed match), and record-keeping that supports auditability. Escalation of confirmed or potential true matches typically follows applicable regulatory reporting and blocking or rejection procedures. Maintaining documented rationale for each disposition helps demonstrate that the program operates as intended and supports regulatory examination.

Common misconceptions

Sanctions screening is a component of PCI DSS compliance.
Sanctions screening is a legal and regulatory obligation governed by applicable sanctions authorities and financial regulators, not by PCI DSS. PCI DSS governs the protection of cardholder data and sensitive authentication data. The two may operate on overlapping systems, but satisfying one does not satisfy the other, and readers should confirm PCI DSS requirements against the current published standard.
A clean screening result means a party is definitively not sanctioned.
Screening outcomes depend on the lists used, their update cadence, the quality of input data, and matching thresholds. Screening may produce false negatives if lists are stale or data is incomplete, and false positives that require manual review. Screening is intended to help identify potential matches, not to guarantee a party's status.
Sanctions screening also detects payment fraud such as account takeover or card-not-present fraud.
Sanctions screening addresses regulatory exposure to prohibited parties and jurisdictions. It is a separate control from fraud detection, which targets card-present fraud, card-not-present fraud, account takeover, chargeback and first-party fraud, and synthetic identity fraud. A single control should not be assumed to cover both objectives.

Best practices

Maintain current, authoritative sanctions list sources and document the update cadence so screening reflects recent list changes rather than a static snapshot.
Calibrate and periodically test matching thresholds, explicitly documenting the trade-off between false positives that burden review teams and false negatives that create regulatory exposure.
Screen at multiple points, including onboarding, periodic re-screening, and transaction processing, and record the rationale for each match disposition to support regulatory examination.
Keep sanctions screening logically distinct from PCI DSS controls and from fraud detection systems, recognizing each addresses a different objective even when they share underlying data.
Ensure screening inputs and stored records handle payment data appropriately, applying masking, truncation, or tokenization where suitable and never retaining sensitive authentication data after authorization.
Preserve auditable records of list versions, thresholds, alerts, and dispositions, and confirm any regulatory reporting obligations against the current requirements of the applicable authority.