Skip to main content
Why Sanctions Screening Fails When Lists DivergeAnti-Corruption & AML
6 min readFor Compliance Training Managers

Why Sanctions Screening Fails When Lists Diverge

When Russia invaded Ukraine in 2022, compliance teams faced what felt like a sanctions emergency. Thousands of new designations appeared within weeks. The immediate challenge was clear: expand your screening capacity quickly enough to catch these additions.

Three years later, regulators issued nearly 4,000 net new designations across 265 list updates in 2025. While the volume remains high, the real issue has shifted. Your screening program isn't failing due to the number of names on lists. It's failing because those lists no longer align with each other.

Why These Mistakes Keep Happening

Sanctions programs were designed for a world where major regulators moved in parallel. When OFAC designated an entity, the EU and UK typically followed within weeks. Your team could rely on a single source of truth, assuming that covering one major list provided reasonable protection across jurisdictions.

That assumption no longer holds. Regulators now pursue distinct geopolitical and economic objectives. EU and UK authorities increased sanctions activity by 46% and 175% respectively in 2025, while OFAC reduced net additions by approximately 50% year over year. Russia-related designations accounted for 88% of net additions to the EU list and 66% to the UK list, while Iran represented 48% of OFAC net additions.

When your compliance framework assumes coordination that doesn't exist, every process built on that assumption becomes a vulnerability.

Mistake 1: Treating All Sanctions Lists as Interchangeable

Your screening system flags matches against "the sanctions list" as if there's only one. In reality, you're managing multiple lists with different scopes, timing, and definitions of prohibited conduct.

Why it happens: Legacy screening tools were designed when sanctions programs moved together. Vendors marketed "comprehensive coverage," and compliance teams assumed that meant functional equivalence across jurisdictions.

The consequence: Your EU subsidiary clears a transaction because the counterparty isn't on OFAC's list, not realizing the EU designated that entity two months earlier for Russia sanctions evasion. You discover the exposure during an audit, after dozens of transactions have cleared.

The fix: Map your screening coverage to your actual jurisdictional exposure. If you operate in the UK, screen against UK lists first, not as an afterthought. If your supply chain touches the EU, prioritize EU designations in your escalation protocols. Stop assuming that OFAC coverage provides adequate protection for non-US operations.

Mistake 2: Screening Only at Onboarding

Your customer due diligence process includes sanctions screening when you open an account or onboard a vendor. After that, you rely on periodic batch rescreening, maybe quarterly or annually.

Why it happens: Onboarding feels like the natural control point. It's where you gather documentation, verify identities, and make risk decisions. Ongoing monitoring seems redundant when you've already cleared someone.

The consequence: A logistics provider you onboarded in 2024 appears on the EU's Russia sanctions list in 2025 for involvement in shadow fleet operations. Your quarterly rescreen hasn't run yet. You continue processing shipments for three months before the next batch cycle catches the designation. By then, you've created an enforcement exposure that could have been avoided with real-time monitoring.

The fix: Implement continuous screening that triggers alerts when existing relationships match newly designated entities. This doesn't require manual review of every customer every day. It requires automated monitoring that compares your active counterparty list against daily list updates and surfaces matches immediately.

Mistake 3: Ignoring Geographic Exposure in Third Countries

Your sanctions program focuses on designated countries and named individuals. When the EU designates entities in Hong Kong, Türkiye, or the UAE under its Russia sanctions packages, your team treats these as edge cases rather than core risks.

Why it happens: Sanctions training emphasizes embargoed countries. Teams learn to watch for transactions involving Russia, Iran, or North Korea. They don't expect sanctions risk in jurisdictions they consider low-risk trading partners.

The consequence: Your procurement team sources components through a Hong Kong distributor. That distributor appears on the EU's sanctions list for facilitating Russian military procurement. Your compliance team never flagged the relationship because Hong Kong wasn't on anyone's watch list. You discover the issue when a European customer refuses shipment of products containing those components.

The fix: Reframe sanctions screening as network-based, not geography-based. The EU has imposed sanctions on entities located in a dozen third countries under its 2025 Russian sanctions packages. Train your team to recognize that sanctions risk now follows networks, not borders. Screen all counterparties regardless of location, and investigate beneficial ownership and supply chain relationships that could create indirect exposure.

Mistake 4: Relying Solely on Automated Screening Without Transaction Context

Your screening system flags potential matches based on name similarity. Your team reviews the alert, confirms the name doesn't match exactly, and clears the transaction. The system never considers what the transaction involves, who benefits, or how the relationship fits into a broader pattern.

Why it happens: Automated screening tools excel at name matching but struggle with contextual analysis. Compliance teams process hundreds of alerts daily and lack the time to investigate every relationship in depth. Clearing obvious false positives becomes the priority.

The consequence: You clear a series of payments to a shipping company that doesn't match any sanctioned entity. Six months later, investigators reveal that company was created specifically to evade sanctions, using a similar name to a legitimate business. Your screening caught the name discrepancy but missed the evasion pattern. Regulators view this as a control failure, not a reasonable false positive.

The fix: Layer transaction monitoring on top of name-based screening. When a payment involves shipping, logistics, or commodities that align with known evasion patterns, escalate for enhanced review even if the name doesn't match exactly. Train your team to recognize red flags: newly formed entities, circuitous payment routes, reluctance to provide ownership details, or business relationships that don't align with stated activities.

Mistake 5: Treating Sanctions Compliance as a Point-in-Time Exercise

Your annual compliance review includes a sanctions section. Your team confirms that screening systems are running, staff completed training, and no enforcement actions occurred. Leadership signs off, and everyone moves on until next year.

Why it happens: Compliance programs are structured around annual cycles: budgets, audits, training refreshes. Sanctions feel like one item on a long checklist, not a continuous operational requirement.

The consequence: Regulatory priorities shift mid-year. The UN relists 121 individuals and entities in one of its most significant sanctions actions in years. Your team doesn't learn about it until the next quarterly compliance meeting. By then, you've processed transactions involving two of those entities. Your annual review cycle didn't account for the possibility that sanctions risk could materialize and require response within days, not quarters.

The fix: Build sanctions monitoring into your daily operations, not your annual review calendar. Assign someone to track regulatory updates from OFAC, the EU, the UK, and the UN weekly. When major list updates occur, brief relevant teams immediately. Sanctions compliance isn't an annual certification. It's an ongoing interpretation of shifting regulatory positions that requires real-time adjustment.

Prevention Checklist

Use this checklist to audit your current sanctions compliance approach:

Screening Coverage

  • We screen against all sanctions lists relevant to our jurisdictional exposure, not just OFAC
  • Our screening system updates daily with new designations from all relevant regulators
  • We've mapped which business units face exposure to which sanctions regimes

Monitoring Cadence

  • We conduct continuous screening of existing relationships, not just at onboarding
  • Alerts trigger immediately when a current counterparty matches a new designation
  • We've eliminated reliance on quarterly batch rescreening as our primary control

Geographic Scope

  • Our sanctions training addresses third-country exposure, not just embargoed nations
  • We screen all counterparties regardless of location
  • We investigate beneficial ownership and supply chain relationships for indirect exposure

Contextual Analysis

  • Our escalation protocols consider transaction context, not just name matches
  • We've trained staff to recognize evasion patterns beyond exact name matches
  • We layer transaction monitoring on top of name-based screening for high-risk sectors

Regulatory Intelligence

  • Someone on our team monitors sanctions updates from multiple regulators weekly
  • We brief relevant business units immediately when major list updates occur
  • We've abandoned annual-only sanctions reviews in favor of continuous monitoring

Cross-Functional Coordination

  • Procurement, finance, and logistics teams understand their role in sanctions compliance
  • We've established clear escalation paths when sanctions questions arise mid-transaction
  • Our compliance framework can adapt to regulatory changes within days, not quarters

The sanctions landscape won't return to the coordinated environment compliance teams once relied on. Divergence is now the norm. Your controls must reflect that reality, or they'll continue to fail in ways that feel predictable only in hindsight.

You Might Also Like